Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 1–75

984 questions total · 14pages · All types, answers revealed

Page 1 of 14

Page 2
1
MCQeasy

A company is designing a new microservices-based application on AWS. They need to decouple services and ensure asynchronous communication. Which AWS service should they use?

A.Amazon Kinesis
B.Amazon SQS
C.AWS Lambda
D.Amazon SNS
AnswerB

Amazon SQS provides fully managed queues that decouple producers from consumers, letting microservices communicate asynchronously without direct invocation. This satisfies the asynchronous communication requirement, since messages persist durably until a consumer polls and processes them, absorbing traffic spikes and service failures.

Why this answer

Amazon SQS (Simple Queue Service) is the correct choice because it provides a fully managed message queue that enables asynchronous communication between microservices. By decoupling the components, SQS allows one service to send messages to a queue, and another service to poll and process those messages independently, ensuring fault tolerance and scalability without requiring both services to be available simultaneously.

Exam trap

The trap here is that candidates often confuse Amazon SNS (pub/sub) with SQS (queue), thinking both provide decoupling, but SNS requires subscribers to be active or integrated with a queue, whereas SQS inherently buffers messages for asynchronous consumption.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis is designed for real-time streaming data ingestion and processing (e.g., log streams, clickstreams), not for decoupling point-to-point asynchronous messaging between microservices; it uses shards and records, not queues with individual message visibility. Option C is wrong because AWS Lambda is a compute service that runs code in response to events, not a messaging or decoupling service; it can be a consumer or producer but does not itself provide a queue for asynchronous communication. Option D is wrong because Amazon SNS is a pub/sub messaging service that pushes messages to multiple subscribers (fan-out), but it does not provide a queue for decoupling—subscribers must be available or use a queue integration; SNS alone does not offer the buffering and polling model needed for true asynchronous decoupling.

2
MCQeasy

Refer to the exhibit. A company runs the AWS CLI command to list accounts in AWS Organizations. The company wants to remove the account '444444444444' from the organization. What must the company do first before it can remove this account?

A.Close the AWS account from the management account.
B.Create a support ticket to AWS to remove the account.
C.Remove the account's payment method.
D.The management account can directly remove the account without any prerequisites.
AnswerA

Correct. Closing the AWS account from the management account is the prerequisite for removing a member account that was created within the organization.

Why this answer

To remove a member account that was created within AWS Organizations, the management account must first close the account. This is a prerequisite because accounts created via Organizations cannot be removed directly; only invited accounts can be removed without closing. Closing the account suspends it; after closure, the management account can then remove it from the organization.

The account remains closed and is not converted into an active standalone account.

Exam trap

The trap is that candidates might think removing the payment method (Option C) is sufficient, but AWS requires the account to be closed when it was created within the organization. Also, some may assume the management account can remove it directly (Option D), which only applies to invited accounts.

How to eliminate wrong answers

Option A is wrong because closing the AWS account from the management account is not a prerequisite for removal; closing an account is a separate action that permanently terminates the account, whereas removal from the organization simply detaches it. Option B is wrong because AWS does not require a support ticket to remove an account from an organization; the management account can remove accounts programmatically via the AWS Organizations API or CLI without contacting support. Option D is wrong because the management account cannot directly remove an account without prerequisites; the account must have its payment method removed first, as per AWS Organizations requirements.

3
MCQeasy

A company is designing a new CI/CD pipeline for a web application that will be deployed on Amazon ECS. Which AWS service should the company use to build and test the application code?

A.AWS CodePipeline
B.AWS CodeDeploy
C.AWS CodeCommit
D.AWS CodeBuild
AnswerD

AWS CodeBuild is a fully managed build service that compiles source code, runs unit tests, and produces deployable artefacts, integrating natively with CodePipeline and ECS. This satisfies the requirement to build and test the application code within the CI/CD pipeline.

Why this answer

AWS CodeBuild is a fully managed continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy. For a CI/CD pipeline that requires building and testing application code before deployment to Amazon ECS, CodeBuild is the correct service to perform these build and test actions.

Exam trap

The trap here is that candidates often confuse AWS CodePipeline (the orchestration layer) with the actual build service, mistakenly thinking that CodePipeline itself performs the build and test steps, when in fact it only coordinates other services like CodeBuild.

How to eliminate wrong answers

Option A is wrong because AWS CodePipeline is a continuous delivery service that orchestrates the pipeline stages (source, build, test, deploy) but does not itself build or test code; it relies on other services like CodeBuild for those actions. Option B is wrong because AWS CodeDeploy is a deployment service that automates code deployments to compute services (including ECS) but does not perform build or test operations. Option C is wrong because AWS CodeCommit is a source control service that hosts Git repositories and does not have any capability to build or test application code.

4
MCQmedium

A company is migrating a monolithic e-commerce application to a microservices architecture on AWS. The migration must minimize downtime and allow rollback. Which migration strategy should the company use?

A.Refactor
B.Big bang migration
C.Strangler fig pattern
D.Rehost (lift and shift)
AnswerC

The strangler fig pattern incrementally routes specific functions from the monolith to new microservices behind a facade, so each slice can be released and rolled back independently. This satisfies both the minimal-downtime and rollback constraints, unlike a single big-bang cutover.

Why this answer

The strangler fig pattern incrementally replaces pieces of a monolith with microservices by routing traffic through a facade, allowing new services to be introduced alongside the legacy system. This minimizes downtime because the monolith keeps serving unaffected functionality while migrated components go live, and it enables rollback by simply routing traffic back to the old path. It is the standard AWS-recommended approach for low-risk monolith decomposition.

Exam trap

SAP-C02 often tests whether candidates conflate the general act of refactoring with a specific incremental migration pattern, so pick the option that explicitly describes gradual replacement with rollback capability.

How to eliminate wrong answers

Option A is wrong because refactoring is the broader activity of rewriting code, not a migration strategy that by itself guarantees minimal downtime or rollback — it describes what you do, not how you cut over safely. Option B is wrong because a big bang migration replaces everything at once, maximizing downtime and offering no practical rollback path if the new system fails. Option D is wrong because rehost (lift and shift) moves the monolith to EC2 as-is and does not decompose it into microservices, so it fails the architectural goal.

5
MCQmedium

A company is migrating a monolithic application to AWS. They want to minimize refactoring effort while gaining some benefits of the cloud. Which migration strategy is most appropriate?

A.Refactor / Re-architect
B.Repurchase
C.Rehost (lift-and-shift)
D.Replatform (lift-tinker-and-shift)
AnswerC

Rehosting moves the application to AWS without altering its architecture, satisfying the minimal-refactoring constraint. The monolith runs on EC2 instances, gaining cloud benefits such as elasticity and pay-as-you-go pricing while avoiding code changes. This differs from replatforming, which requires modifying components, and refactoring, which demands architectural redesign.

Why this answer

Rehost (lift-and-shift) involves moving the application as-is to AWS with minimal changes, aligning with the goal of minimizing refactoring effort. Option A is wrong because Refactor/Re-architect requires significant code changes. Option B is wrong because Repurchase involves switching to a different product, often a SaaS solution.

Option D is wrong because Replatform (lift-tinker-and-shift) involves some modifications to the application to take advantage of cloud capabilities, which requires more effort than pure rehost.

6
MCQmedium

A company uses AWS CodePipeline to deploy a web application to an Elastic Beanstalk environment. The deployment pipeline includes a source stage, a build stage using CodeBuild, and a deploy stage. Recently, deployments have been failing in the deploy stage with the error: 'The environment is in an invalid state for this operation.' The developer confirms the build artifacts are correct. What is the MOST likely cause?

A.The environment's load balancer is not available
B.The environment's Auto Scaling group has insufficient capacity
C.The Elastic Beanstalk environment uses a t2.micro instance type which is not supported by CodePipeline
D.Another deployment or configuration update is already in progress on the environment
AnswerD

Elastic Beanstalk permits only one operation at a time; a concurrent deployment or configuration update leaves the environment in an invalid state, so the deploy stage fails until that operation completes. This matches the stem's error precisely, not artifact or build problems.

Why this answer

Elastic Beanstalk rejects a new deployment when the environment is already processing another deployment or configuration update, returning the 'invalid state for this operation' error. Because the build artifacts are confirmed correct, the most likely cause is a concurrent operation still in progress. Waiting for the in-flight operation to complete or canceling it resolves the failure.

Exam trap

SAP-C02 often tests whether candidates blame infrastructure (load balancer, Auto Scaling, instance type) for a state-machine error that is actually caused by a concurrent deployment, so recognize the InvalidState signature.

How to eliminate wrong answers

Option A is wrong because an unavailable load balancer would surface as health-check failures or 5xx errors, not as an invalid-state error during the deploy stage. Option B is wrong because insufficient Auto Scaling capacity typically causes launch failures or degraded health, not a state-validation rejection from the Elastic Beanstalk API. Option C is wrong because t2.micro is a supported instance type for Elastic Beanstalk environments and CodePipeline does not restrict instance families.

7
MCQeasy

A company is migrating a monolithic application to a microservices architecture on AWS. They want to decouple the services and ensure that messages between services are processed asynchronously and durably. Which AWS service should they use for this purpose?

A.Amazon Kinesis Data Streams
B.Amazon Simple Queue Service (SQS)
C.Amazon Simple Notification Service (SNS)
D.AWS Step Functions
AnswerB

Amazon SQS provides durable, fully managed message queues that decouple microservice producers from consumers, satisfying the asynchronous processing requirement. Messages persist across multiple Availability Zones until successfully processed, and standard queues offer at-least-once delivery at scale. This directly meets the stem's need for durable, asynchronous inter-service communication without managing brokers.

Why this answer

Amazon SQS is a fully managed message queue service designed for asynchronous, durable message passing between decoupled components. It stores messages redundantly across multiple Availability Zones, supports at-least-once delivery, and allows producers and consumers to operate independently — exactly matching the requirement for durable asynchronous processing in a microservices architecture.

Exam trap

SAP-C02 often tests whether candidates confuse SNS (push-based pub/sub, no durable storage) with SQS (pull-based queue, durable storage), causing them to pick SNS when the requirement explicitly says messages must be processed durably and asynchronously.

How to eliminate wrong answers

Option A is wrong because Kinesis Data Streams is optimized for real-time streaming and analytics with ordered shards, not for general-purpose durable message decoupling between microservices; it requires more operational overhead and is not a simple queue. Option C is wrong because SNS is a pub/sub fan-out service that pushes notifications to subscribers but does not store messages durably for later retrieval — if a subscriber is unavailable, the message is lost (unless paired with SQS). Option D is wrong because Step Functions is a workflow orchestration service for coordinating stateful, multi-step processes, not a message queue for decoupling services.

8
MCQmedium

A company is using AWS Lambda functions to process data from an S3 bucket. Recently, the function has been timing out. The function has a 5-minute timeout configured. What is the most likely cause of the timeout?

A.The Lambda function was moved to a different VPC.
B.The Lambda function's reserved concurrency is set too low.
C.The Lambda function's memory is too low.
D.The Lambda function is processing larger files than before.
AnswerD

Larger files increase the time spent reading and processing within the same invocation, so execution duration grows until it exceeds the configured 5-minute limit. The timeout is a symptom of longer processing, not of memory, permissions or concurrency settings.

Why this answer

The most likely cause of the timeout is that the Lambda function is processing larger files than before. Lambda timeout is the maximum execution time, and if the function takes longer than the configured 5 minutes due to increased processing time (e.g., larger files), it will time out. Other options like VPC change, concurrency, or memory are less directly related to timeout duration.

Exam trap

SAP-C02 often tests the distinction between timeout and throttling; candidates may confuse concurrency limits with execution time, or overlook that memory affects performance but is not the direct cause of timeout when file size increases.

How to eliminate wrong answers

Option A is wrong because moving the Lambda function to a different VPC could cause network connectivity issues, but it would typically result in connection errors or increased latency, not necessarily a timeout if the function can still access resources; also, it's not the most likely cause given the scenario. Option B is wrong because reserved concurrency being too low would cause throttling (TooManyRequestsException) rather than timeouts; the function would not be invoked. Option C is wrong because insufficient memory can cause longer execution times and potentially timeouts, but the scenario specifically mentions processing larger files, which directly increases processing time; memory might be a factor, but the most likely cause is the increased file size.

9
MCQmedium

A company is planning to migrate its on-premises data warehouse to AWS. The data warehouse runs on a large Oracle RAC cluster with complex stored procedures and ETL jobs. The company wants to minimize migration effort while gaining cloud benefits. Which AWS service should be used as the target?

A.Amazon DynamoDB
B.Amazon RDS for Oracle
C.Amazon Redshift
D.Amazon Aurora PostgreSQL
AnswerC

Amazon Redshift is a petabyte-scale columnar data warehouse supporting SQL, stored procedures and ETL tooling, letting the company migrate with minimal refactoring while gaining managed cloud elasticity. It avoids the re-architecture effort required by serverless alternatives such as Athena.

Why this answer

Amazon Redshift is a petabyte-scale data warehouse service that is optimized for analytical workloads and supports complex SQL queries, stored procedures, and ETL jobs. It is designed to handle large data volumes and can minimize migration effort by providing compatibility with existing SQL and ETL tools. DynamoDB is a NoSQL database not suitable for complex stored procedures, RDS for Oracle is not a data warehouse and may not scale as needed, and Aurora PostgreSQL is an OLTP database, not a data warehouse.

Exam trap

SAP-C02 often tests the misconception that RDS for Oracle is a suitable data warehouse target, but it lacks the analytical scalability of Redshift.

How to eliminate wrong answers

Option A is wrong because DynamoDB is a NoSQL key-value store, not a relational data warehouse; it cannot run complex stored procedures or ETL jobs natively. Option B is wrong because Amazon RDS for Oracle is an OLTP database service, not a data warehouse; it may not provide the performance and scalability required for large analytical workloads. Option D is wrong because Amazon Aurora PostgreSQL is an OLTP database, not a data warehouse; while it can handle some analytical queries, it is not optimized for large-scale data warehousing.

10
MCQhard

A solutions architect is reviewing the above IAM policy attached to an S3 bucket. A user from IP address 10.0.1.5 makes a request over HTTP (not HTTPS). Will the user be able to download an object?

A.No, because the IP address is not in the allowed range.
B.Yes, because the IP address is allowed.
C.No, because the request is not using HTTPS.
D.Yes, because the Allow statement is evaluated first.
AnswerC

The policy's explicit Deny for `aws:SecureTransport: false` overrides any Allow, so the HTTP request from 10.0.1.5 is blocked regardless of source IP. AWS evaluates Deny first, making the insecure transport condition the decisive constraint that prevents the object download.

Why this answer

The IAM policy includes a condition that requires requests to use HTTPS (aws:SecureTransport = true). Since the user's request is over HTTP, the condition fails, and the Allow statement does not apply. Therefore, the request is denied by default, and the user cannot download the object.

Exam trap

SAP-C02 often tests the misconception that if an IP address is allowed, access is granted regardless of other conditions, but the trap is forgetting that all conditions in a statement must be satisfied for the Allow to take effect.

How to eliminate wrong answers

Option A is wrong because the IP address 10.0.1.5 is within the allowed range 10.0.0.0/16, so the IP condition is satisfied. Option B is wrong because although the IP is allowed, the HTTPS condition is not met, so the overall Allow statement does not apply. Option D is wrong because IAM policy evaluation does not simply evaluate Allow statements first; all conditions must be satisfied for an Allow to take effect, and explicit Deny statements override Allow.

11
MCQmedium

A company is migrating a monolithic application to microservices on Amazon ECS. The application needs to communicate with external partners via HTTPS. The company wants to use mTLS for mutual authentication. Which AWS service should be used to handle the mTLS termination?

A.Application Load Balancer (ALB) with mutual TLS
B.Amazon CloudFront with a custom origin
C.Network Load Balancer (NLB) with TLS termination
D.Amazon API Gateway HTTP API
AnswerA

ALB supports mutual TLS termination natively, validating client certificates against a trust store before forwarding traffic. This satisfies the mutual authentication requirement for partner HTTPS connections without running certificate handling on the ECS tasks themselves, simplifying the microservice architecture.

Why this answer

Application Load Balancer (ALB) supports mutual TLS (mTLS) natively by configuring a trust store on the listener that validates client certificates against a Certificate Authority (CA) bundle you upload. This allows the ALB to terminate the HTTPS connection and perform client certificate authentication before forwarding traffic to the ECS service, meeting the requirement for mTLS termination without custom proxy logic.

Exam trap

The trap here is confusing ALB mTLS with NLB TLS termination or assuming API Gateway HTTP API supports mTLS, when in fact only ALB and API Gateway REST API (not HTTP API) offer mutual TLS termination for incoming client connections.

How to eliminate wrong answers

Option B is wrong because Amazon CloudFront does not support mTLS; it can only present client certificates to origins (origin-facing mTLS) but cannot terminate incoming mTLS connections from clients. Option C is wrong because Network Load Balancer (NLB) with TLS termination only validates server certificates and does not support client certificate authentication (mTLS) at the listener level. Option D is wrong because Amazon API Gateway HTTP API does not support mTLS; only API Gateway REST API supports mTLS via mutual TLS authentication, but the HTTP API variant lacks this feature.

12
MCQeasy

A company wants to centralize management of IAM users and groups across multiple AWS accounts. The solution should allow users to access resources in any account without needing separate credentials. Which AWS service should be used?

A.AWS Identity and Access Management (IAM)
B.AWS Organizations
C.AWS IAM Identity Center (AWS SSO)
D.AWS Directory Service for Microsoft Active Directory
AnswerC

IAM Identity Center provides a single directory-backed sign-in and issues temporary credentials per account through permission sets, so users reach resources in any account without separate IAM users. This satisfies the constraint of centralised identity with no per-account credentials.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized identity source that allows users to sign in once with a single set of credentials and then access multiple AWS accounts and applications. It integrates with AWS Organizations to manage user and group permissions across accounts, eliminating the need for separate IAM users in each account.

Exam trap

The trap here is that candidates often confuse AWS Organizations with a user management service, but Organizations only manages accounts and policies, not user identities or authentication.

How to eliminate wrong answers

Option A is wrong because IAM is account-scoped and cannot centralize user management across multiple AWS accounts; it requires creating separate IAM users in each account, which defeats the goal of single sign-on. Option B is wrong because AWS Organizations provides policy-based management and consolidated billing but does not itself offer a user directory or authentication mechanism; it relies on IAM Identity Center or other identity providers for user access. Option D is wrong because AWS Directory Service for Microsoft Active Directory is a managed AD service that can be used as an identity source, but it is not the AWS-native service for centralizing IAM user and group management across accounts; IAM Identity Center is the recommended service for this purpose.

13
MCQmedium

A company has a multi-account AWS environment with a central security account. They want to enable Amazon GuardDuty in all accounts and centrally view findings. The security team has already enabled GuardDuty in the security account and invited all member accounts. However, the security account is not receiving findings from all member accounts. Upon investigation, some member accounts show that GuardDuty is not enabled, and some show that they have not accepted the invitation. The team needs a scalable solution to enable GuardDuty across all accounts and ensure findings are sent to the security account. What should the team do?

A.Use AWS Config rules to detect accounts without GuardDuty and send alerts.
B.Use AWS CloudFormation StackSets to deploy GuardDuty resources in each account.
C.Use AWS Control Tower to enable GuardDuty in all accounts via a custom blueprint.
D.Use the GuardDuty delegated administrator feature with AWS Organizations to automatically enable GuardDuty in all accounts and centralize findings.
AnswerD

The delegated administrator integrates GuardDuty with AWS Organizations, automatically enabling the service in every member account and routing findings to the security account. This replaces the manual invite-and-accept model that left some accounts unenrolled, satisfying the scalable centralised-findings requirement.

Why this answer

The GuardDuty delegated administrator feature integrated with AWS Organizations allows the security account to be designated as the GuardDuty administrator, which can then automatically enable GuardDuty for all existing and future member accounts in the organization. This eliminates the need for manual invitations and acceptances, ensuring that findings are centrally aggregated in the security account without requiring per-account configuration.

Exam trap

The trap here is that candidates may choose CloudFormation StackSets (Option B) thinking it can deploy GuardDuty resources across accounts, but they overlook that StackSets cannot automatically accept GuardDuty invitations or leverage the Organizations delegated administrator model to bypass the manual acceptance step.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can only detect noncompliant resources and trigger alerts or remediation actions, but they cannot automatically enable GuardDuty across accounts or manage the invitation/acceptance workflow required for centralized findings. Option B is wrong because CloudFormation StackSets can deploy resources across accounts, but they require the member accounts to already have accepted the GuardDuty invitation or be part of the same organization; they do not automate the invitation acceptance process or leverage the delegated administrator model to bypass manual steps. Option C is wrong because AWS Control Tower custom blueprints are used to deploy additional governance controls or resources, but they do not natively support the GuardDuty delegated administrator feature; enabling GuardDuty across all accounts in Control Tower is better achieved through Organizations integration, not a custom blueprint.

14
Drag & Dropmedium

Drag and drop the steps to set up AWS CloudTrail for logging API activity in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create the S3 bucket, then create the trail, configure events, enable security features, and verify delivery.

15
MCQmedium

A company runs a critical two-tier application on AWS. The web tier consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The database tier is a single Amazon RDS for MySQL instance. The company wants to improve the availability of the database tier so that it can survive an Availability Zone failure with minimal downtime and no data loss. The application uses the RDS endpoint in its configuration. What should a solutions architect recommend?

A.Create a read replica in another Availability Zone and update the application to use the read replica endpoint.
B.Enable a Multi-AZ deployment for the RDS instance.
C.Enable RDS automated backups with a longer retention period and restore from a snapshot in another Availability Zone if a failure occurs.
D.Migrate the database to an Amazon DynamoDB table with global tables enabled.
AnswerB

Multi-AZ creates a synchronous standby replica in a different Availability Zone. The primary endpoint automatically fails over to the standby during an AZ outage, with no data loss because replication is synchronous. The application continues to use the same endpoint, so no configuration change is required. This meets the requirements of minimal downtime and no data loss.

Why this answer

A Multi-AZ deployment maintains a synchronous standby in a separate Availability Zone. During an AZ failure, RDS automatically fails over to the standby, and the application continues to use the same endpoint. Because replication is synchronous, no committed data is lost.

This provides high availability with minimal downtime and zero data loss, satisfying the requirements without application changes.

Exam trap

The trap here is assuming that a read replica provides automatic failover and zero data loss, when in fact read replicas use asynchronous replication and require manual promotion.

16
MCQeasy

A DevOps engineer notices that a CloudFormation stack update fails with the error: 'UPDATE_ROLLBACK_FAILED'. The stack is in a state where some resources were updated, but others failed to update. The engineer needs to fix the stack and complete the update. What should the engineer do FIRST?

A.Add a new resource to the stack to force a new update
B.Manually correct the resources that are preventing rollback, then use 'ContinueUpdateRollback'
C.Submit another stack update with the original template to overwrite the changes
D.Delete the stack and recreate it with the same template
AnswerB

UPDATE_ROLLBACK_FAILED means CloudFormation cannot roll back because a resource is in an unusable state. The engineer must first manually repair those resources outside CloudFormation, then run ContinueUpdateRollback so the stack can resume rolling back before the update is retried.

Why this answer

When a CloudFormation stack update fails and rollback also fails, the stack enters UPDATE_ROLLBACK_FAILED. The documented recovery path is to manually fix the underlying resource issue that is blocking rollback, then call ContinueUpdateRollback to resume the rollback and return the stack to a stable state. This is the first corrective action before any further updates can be attempted.

Exam trap

The trap is reaching for destructive or workaround actions (delete and recreate, force a new update) instead of the documented recovery API, ContinueUpdateRollback, which is the only supported first step in UPDATE_ROLLBACK_FAILED.

How to eliminate wrong answers

Option A is wrong because you cannot perform a new stack update while the stack is in UPDATE_ROLLBACK_FAILED; CloudFormation rejects updates until the stack is returned to a stable state. Option C is wrong because submitting another update with the original template is not possible in this state and does not address the blocked rollback. Option D is wrong because deleting the stack is a destructive last resort that loses stack history and may fail if resources are still in a bad state; it is not the first step and is generally discouraged.

17
Multi-Selecthard

A company uses AWS Organizations with a dedicated security account. They want to centralize the management of AWS Config rules and ensure that all accounts are compliant with the same set of rules. Which THREE steps should they take?

Select 3 answers
A.Apply a service control policy (SCP) that requires AWS Config to be enabled.
B.Create an AWS Config aggregator in the security account to view compliance status across accounts.
C.Use AWS CloudFormation StackSets to deploy the desired AWS Config rules to all accounts.
D.Enable AWS Config in all accounts across the organization.
E.Use AWS CloudTrail to monitor compliance status.
AnswersB, C, D

An aggregator in the security account collects configuration and compliance data from all member accounts, giving centralised visibility across the organization. It satisfies the requirement to view compliance status centrally, though it does not itself deploy rules. Aggregators are read-only; rule deployment needs Organizations-level Config conformance packs or delegated administrator.

Why this answer

Option B is correct because an AWS Config aggregator in the security account collects configuration and compliance data from multiple accounts and Regions, giving a centralized view of compliance status across the organization. Option C is correct because CloudFormation StackSets deploy the same AWS Config rules (and related resources) consistently to all target accounts and Regions in the organization. Option D is correct because AWS Config must be enabled in each account and Region before rules can evaluate resources and report compliance there.

Option A is not correct because an SCP can restrict or require actions but does not itself enable AWS Config or enforce rule compliance. Option E is not correct because AWS CloudTrail records API activity and does not evaluate resource configuration compliance against Config rules.

Exam trap

The trap here is confusing service control policies (SCPs) with service enablement; SCPs restrict permissions but cannot automatically enable AWS Config, leading candidates to incorrectly select option A as a way to enforce compliance.

18
MCQmedium

Refer to the exhibit. A solutions architect runs the AWS CLI command to check the state of an EC2 instance. The output shows the instance is running. However, the application team reports that the instance is unreachable over SSH. What is the MOST likely cause?

A.The CLI command is querying the wrong instance
B.A security group rule blocks inbound SSH traffic
C.The instance is in a 'stopped' state
D.The instance does not have EBS optimization enabled
AnswerB

The instance state and SSH reachability are independent: a running instance with no inbound TCP/22 allowance silently drops connection attempts. A security group rule blocking port 22 explains the unreachable symptom while the instance remains running, unlike host-level or key-pair issues.

Why this answer

The instance state is 'running', so it is not stopped or terminated. The most likely cause for being unreachable over SSH is that a security group rule blocks inbound SSH traffic (port 22). Option B is correct.

Option A is wrong because the query is for the correct instance. Option C is wrong because the instance is running. Option D is wrong because EBS optimization does not affect network connectivity.

19
Multi-Selecthard

A company is designing a new application that will process streaming data from thousands of IoT devices. The data must be ingested in real time and then processed using Apache Flink. Which services should be used? (Choose TWO.)

Select 2 answers
A.Amazon Kinesis Data Streams
B.AWS Lambda
C.Amazon Kinesis Data Analytics for Apache Flink
D.Amazon Kinesis Data Firehose
E.Amazon Simple Queue Service (SQS)
AnswersA, C

Amazon Kinesis Data Streams ingests thousands of IoT device events in real time with low latency and high throughput, satisfying the stem's real-time ingestion constraint. It integrates natively with Apache Flink through the Kinesis connector, letting Flink consume the stream directly for processing without intermediate storage or batch staging.

Why this answer

Amazon Kinesis Data Streams (A) is correct because it provides a highly scalable, real-time ingestion service that can capture data from thousands of IoT devices with low latency, making it ideal for streaming ingestion. Amazon Kinesis Data Analytics for Apache Flink (C) is correct because it is the managed service that runs Apache Flink applications to process and analyze streaming data in real time, directly integrating with Kinesis Data Streams as a source. AWS Lambda (B) is not designed for continuous stream processing with Apache Flink and is better suited for event-driven, short-lived functions.

Amazon Kinesis Data Firehose (D) is primarily for loading streaming data into destinations like S3, Redshift, or Elasticsearch, not for running Flink processing. Amazon SQS (E) is a message queue for decoupling components, not a real-time streaming ingestion or Flink processing service.

Exam trap

The trap here is that candidates often confuse Kinesis Data Firehose with Kinesis Data Streams, not realizing that Firehose is a delivery service that does not support Apache Flink's requirement for per-record replay and checkpointing, while Data Streams provides the necessary persistent, ordered stream.

20
MCQhard

Refer to the exhibit. An SCP is attached to an OU. A developer in an account under this OU tries to launch a t3.large EC2 instance. What will happen?

A.The instance launch is allowed because the condition uses StringNotEquals, which is not evaluated correctly.
B.The instance launch is denied because the SCP denies any instance type not in the allowed list.
C.The instance launch is denied, but only if the account's IAM policy also denies it.
D.The instance launch is allowed because the SCP has an explicit deny, but it only applies to certain instance types.
AnswerB

SCPs define a permissions boundary that filters every API action in member accounts, and a Deny statement overrides any IAM allow. Because t3.large is absent from the allowed instance-type list, the ec2:RunInstances call fails authorisation, so the launch is blocked.

Why this answer

The SCP explicitly denies any EC2 instance launch where the instance type does not match the allowed list using `StringNotEquals`. Since `t3.large` is not in the allowed list (`t2.micro`, `t2.small`, `t2.medium`), the condition evaluates to true, triggering the explicit deny. SCPs act as a guardrail that overrides any IAM permissions, so the launch is denied regardless of the account's IAM policies.

Exam trap

The trap here is that candidates may think `StringNotEquals` is a misconfiguration or that SCPs only apply if the IAM policy also denies, but in reality, an explicit deny in an SCP is absolute and cannot be bypassed by IAM allows.

How to eliminate wrong answers

Option A is wrong because `StringNotEquals` is evaluated correctly by AWS; it denies actions when the specified value does not match the allowed list, not the other way around. Option C is wrong because SCPs are evaluated before IAM policies and can deny actions even if the IAM policy allows them; an explicit deny in an SCP cannot be overridden by an IAM allow. Option D is wrong because the SCP's explicit deny applies to all instance types not in the allowed list, and `t3.large` is not in that list, so the deny is triggered.

21
MCQeasy

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The application experiences periodic spikes in traffic. The operations team wants to ensure that the application can handle the spikes without manual intervention. What is the MOST cost-effective solution?

A.Use a scheduled scaling policy to add instances during predicted peak hours.
B.Create a target tracking scaling policy using the ALB RequestCountPerTarget metric.
C.Manually add instances when traffic spikes are expected.
D.Use a simple scaling policy based on CPU utilization.
AnswerB

Target tracking on the ALB RequestCountPerTarget metric scales EC2 capacity directly with incoming request load, satisfying the no-manual-intervention requirement during traffic spikes. Because it reacts to demand rather than a fixed schedule, instances are added only when needed and removed afterwards, delivering the most cost-effective elasticity for periodic, unpredictable spikes.

Why this answer

A target tracking scaling policy using the ALB RequestCountPerTarget metric automatically adjusts the number of EC2 instances to maintain a target value for requests per target, which directly correlates with traffic spikes. This is the most cost-effective because it scales in and out dynamically based on actual load, avoiding over-provisioning. It requires no manual intervention and responds to traffic changes in near real-time.

Exam trap

SAP-C02 often tests the choice between target tracking and simple/scheduled scaling; candidates may pick CPU-based simple scaling out of habit, but the exam expects recognition that RequestCountPerTarget target tracking is more direct and cost-effective for ALB-fronted web apps.

How to eliminate wrong answers

Option A is wrong because a scheduled scaling policy only adds instances during predicted peak hours, which may not align with actual spikes and can lead to over-provisioning (cost) or under-provisioning if spikes occur outside the schedule. Option C is wrong because manual scaling requires intervention and is not automated, contradicting the requirement. Option D is wrong because a simple scaling policy based on CPU utilization is less direct for a web application behind an ALB; CPU may lag behind traffic spikes, and simple scaling has cooldowns that can delay response, whereas target tracking on RequestCountPerTarget is more responsive and directly tied to load.

22
Drag & Dropmedium

Drag and drop the steps to deploy a serverless application using AWS SAM in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for deploying a serverless application with AWS SAM is to first write the SAM template (defining resources and configuration), then build the application (compiling code and dependencies), then package the built artifacts (uploading to S3), then deploy the stack (using CloudFormation), and finally test the deployed application to ensure it works as expected. Common mistakes include swapping build and package, writing the template after building, or deploying before packaging, which lead to errors or incomplete deployments.

23
MCQmedium

A financial services company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that member accounts cannot modify or delete these roles, and that new accounts automatically receive the roles. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS CloudFormation StackSets with service-managed permissions to deploy IAM roles to all accounts in the organization, and enable automatic deployment to new accounts.
B.Use AWS Organizations service control policies (SCPs) to deny all IAM actions in member accounts except for a specific role, and manually create that role in each account.
C.Implement a custom AWS Lambda function that assumes a role in each member account and creates the necessary IAM roles, triggered by an Amazon EventBridge rule for new account creation.
D.Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share the role with all member accounts.
AnswerA

AWS CloudFormation StackSets with service-managed permissions integrates with AWS Organizations to deploy IAM roles across all accounts automatically. By enabling automatic deployments, new accounts receive the roles upon creation. Member accounts cannot modify or delete the StackSet-managed roles because the StackSet retains control, and updates are centralized. This approach minimizes operational overhead by eliminating manual role creation and ensuring consistency across the organization.

Why this answer

AWS CloudFormation StackSets with service-managed permissions is designed for centralized deployment across AWS Organizations. It automatically deploys to new accounts when configured, and the StackSet maintains control, preventing member accounts from altering the deployed IAM roles. This reduces operational overhead and ensures consistent cross-account access.

Other options either do not provide automatic provisioning or lack the necessary control to prevent modifications.

Exam trap

The trap here is assuming that AWS Resource Access Manager (RAM) can share IAM roles, or that SCPs can create roles, when in fact RAM does not support IAM roles and SCPs only set permission boundaries.

24
MCQeasy

A company is migrating a stateful application to AWS. The application maintains session state in memory on the application server. Which AWS service should be used to store session state for high availability?

A.Amazon RDS
B.Amazon S3
C.Amazon ElastiCache
D.Amazon EBS
AnswerC

ElastiCache stores session state in a managed Redis or Memcached cluster external to the application servers, so any instance can serve any user and sessions survive instance failure. This satisfies the stem's high availability requirement for a stateful application.

Why this answer

Amazon ElastiCache is an in-memory caching service that supports Redis or Memcached, making it ideal for storing session state with low latency and high availability. It provides sub-millisecond response times and can be configured with Multi-AZ and automatic failover to ensure session data persists even if a node fails. This is the standard AWS solution for externalizing session state in stateless application architectures.

Exam trap

SAP-C02 often tests the misconception that any database can store session state; the trap is that candidates may choose RDS for its durability, but session state requires low-latency, high-throughput access, making ElastiCache the correct choice.

How to eliminate wrong answers

Option A is wrong because Amazon RDS is a disk-based relational database that introduces higher latency and is not optimized for high-frequency session read/write operations; it is better suited for persistent, structured data. Option B is wrong because Amazon S3 is object storage with higher latency and is not designed for frequent, small writes typical of session state, nor does it provide the low-latency access required. Option D is wrong because Amazon EBS is block storage attached to a single EC2 instance and does not provide a shared, highly available store for session state across multiple instances.

25
MCQmedium

Refer to the exhibit. A company has an IAM policy that allows s3:GetObject on all objects in 'my-bucket' but denies access to objects in the 'confidential' folder. A user tries to access 's3://my-bucket/confidential/report.pdf'. What will happen?

A.Access is denied because the Deny statement explicitly matches the resource.
B.Access is allowed because the Deny statement is not evaluated.
C.Access is denied only if the user is not authorized by other policies.
D.Access is allowed because the Allow statement is broader.
AnswerA

The explicit Deny statement matches the resource `arn:aws:s3:::my-bucket/confidential/*`, and AWS evaluates explicit denies before allows, so the request is refused regardless of the broader s3:GetObject Allow. This satisfies the stem's constraint that the confidential folder must remain inaccessible to the user.

Why this answer

In AWS IAM, an explicit Deny always overrides any Allow. The policy denies access to objects in the 'confidential' folder, and the user's request matches that resource. Therefore, access is denied regardless of the Allow statement.

Exam trap

SAP-C02 often tests the IAM policy evaluation logic, and candidates may incorrectly assume that an Allow statement with broader permissions can override an explicit Deny, or that Deny statements are only evaluated if no Allow exists.

How to eliminate wrong answers

Option B is wrong because the Deny statement is evaluated and takes precedence. Option C is wrong because an explicit Deny in any policy overrides any Allow, even if other policies authorize the action. Option D is wrong because the Allow statement does not override an explicit Deny.

26
MCQhard

A company is migrating a legacy .NET application to AWS. The application uses Windows authentication and COM+ components. The company wants to move to a modern architecture with minimal changes to the application code. The application must run on AWS and integrate with Active Directory for authentication. Which solution should the company use?

A.Migrate the application to AWS Lambda with a custom runtime that emulates COM+ components, and use Amazon Cognito for authentication.
B.Migrate the application to Amazon EC2 for Windows Server instances joined to an AWS Managed Microsoft AD domain, and use COM+ components on the instances.
C.Refactor the application to use .NET Core and run it on Amazon ECS with Windows containers, using AWS IAM for authentication.
D.Migrate the application to Amazon RDS for SQL Server and use AWS Directory Service for authentication, keeping the application on-premises.
AnswerB

Amazon EC2 for Windows Server supports Windows authentication and COM+ components natively. By joining the instances to AWS Managed Microsoft AD, the application can use Active Directory for authentication without code changes. This approach provides a familiar environment for the legacy application and minimizes migration effort, aligning with a rehost strategy.

Why this answer

For a legacy .NET application using Windows authentication and COM+ components, the most straightforward migration path is to rehost it on Amazon EC2 for Windows Server instances. Joining these instances to AWS Managed Microsoft AD provides seamless Active Directory integration. This approach requires minimal code changes and preserves the existing architecture, making it the best fit for the company's requirements.

Exam trap

The trap here is assuming that modern services like Lambda or ECS can easily support legacy COM+ and Windows authentication without significant refactoring.

27
Multi-Selectmedium

A company is designing a microservices architecture using Amazon ECS with Fargate. The services need to communicate with each other. The company wants to implement service discovery and load balancing at the application layer. Which TWO services should the company use?

Select 2 answers
A.Amazon API Gateway
B.Network Load Balancer (NLB)
C.AWS Cloud Map
D.Application Load Balancer (ALB)
E.Amazon Route 53
AnswersC, D

AWS Cloud Map provides service discovery for ECS tasks, registering each task's IP address and health status in a namespace so callers resolve healthy endpoints directly. This satisfies the stem's service-discovery requirement for Fargate microservices, where tasks lack stable addresses and no load balancer is needed for discovery itself.

Why this answer

AWS Cloud Map (C) is correct because it provides service discovery for ECS services, allowing microservices to register and discover each other via DNS names or API calls, which is essential for dynamic Fargate tasks. Application Load Balancer (D) is correct because it operates at the application layer (Layer 7) and supports HTTP/HTTPS routing, making it suitable for load balancing microservices traffic. Network Load Balancer (B) is not correct because it works at Layer 4 (TCP/UDP) and does not provide application-layer load balancing.

Amazon API Gateway (A) is not correct because it is primarily for exposing APIs to external clients, not for internal service-to-service communication. Amazon Route 53 (E) is not correct because it is a DNS service, not a service discovery or application-layer load balancing solution for ECS tasks.

Exam trap

The trap here is that candidates often confuse Network Load Balancer (NLB) as an application-layer solution because it can handle TLS termination, but it operates at Layer 4 and lacks the HTTP-aware routing required for application-layer communication.

28
MCQeasy

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM users are created in member accounts. All access must be through federated roles. Which approach should they use?

A.Apply an SCP to the root OU that denies the iam:CreateUser action.
B.Set an IAM password policy in each account that requires strong passwords.
C.Use AWS Config rules to detect IAM users and automatically delete them.
D.Use AWS CloudTrail to monitor for CreateUser and alert the security team.
AnswerA

An SCP attached at the root OU is inherited by every member account and denies iam:CreateUser at the API level, regardless of identity-based policies. This enforces federated-only access across the organisation, satisfying the requirement that no IAM users exist in member accounts.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow the security team to centrally restrict permissions across all member accounts. By applying an SCP to the root organizational unit (OU) that denies the `iam:CreateUser` action, no IAM users can be created in any member account, ensuring all access must come from federated roles. SCPs are evaluated before IAM policies and cannot be overridden by account administrators, making them the most effective preventive control.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config or CloudTrail) with preventive controls (like SCPs), assuming that monitoring or alerting can effectively enforce a policy, whereas only SCPs can proactively block the action across all accounts in an organization.

How to eliminate wrong answers

Option B is wrong because setting an IAM password policy does not prevent the creation of IAM users; it only enforces password complexity requirements for existing users, so it fails to meet the goal of blocking user creation entirely. Option C is wrong because AWS Config rules are detective, not preventive; they can detect IAM users after creation but cannot automatically delete them without custom remediation actions, and even then, there is a window where users exist. Option D is wrong because AWS CloudTrail monitoring is also detective; it can alert on `CreateUser` events but does not prevent the action from occurring, so users could still be created before the security team responds.

29
MCQmedium

A company is designing a new application that requires a relational database with automated backups and multi-AZ redundancy. The database workload is predictable with occasional read replicas for reporting. Which AWS service should be used?

A.Amazon RDS
B.Amazon Redshift
C.Amazon DynamoDB
D.Amazon ElastiCache
AnswerA

Amazon RDS provides automated backups and Multi-AZ standby replication with automatic failover, satisfying both redundancy requirements. Read replicas offload reporting queries from the primary, matching the predictable workload with occasional reporting reads described in the scenario.

Why this answer

Amazon RDS is the correct choice because it provides managed relational databases (e.g., MySQL, PostgreSQL, Oracle, SQL Server) with built-in automated backups and Multi-AZ redundancy for high availability. The workload is predictable and requires occasional read replicas for reporting, both of which are natively supported by RDS without the need for complex configuration.

Exam trap

The trap here is that candidates may confuse Amazon Redshift's columnar storage and read replica-like features (e.g., concurrency scaling) with a relational database, but Redshift is not designed for transactional workloads or automated Multi-AZ failover.

How to eliminate wrong answers

Option B (Amazon Redshift) is wrong because it is a petabyte-scale data warehouse optimized for analytical queries on large datasets, not a transactional relational database for predictable workloads with read replicas. Option C (Amazon DynamoDB) is wrong because it is a NoSQL key-value and document database that does not support relational features like joins or SQL queries, and its read replicas are not designed for occasional reporting in the same manner as RDS. Option D (Amazon ElastiCache) is wrong because it is an in-memory caching service (Redis/Memcached) that does not provide persistent relational storage, automated backups, or Multi-AZ redundancy for a database workload.

30
MCQhard

A healthcare company has a multi-account AWS environment with a central audit account. Compliance requires that all access to Amazon S3 buckets containing protected health information be logged and that logs be immutable for seven years. The company wants to centralize log storage and prevent any account, including the management account, from deleting or modifying the logs. Which combination of steps should a solutions architect take?

A.Enable AWS CloudTrail data events for S3 in all accounts, deliver logs to a central S3 bucket in the audit account, and enable S3 Object Lock in compliance mode on that bucket with a seven-year retention period.
B.Use AWS Config to record S3 bucket changes, store the configuration history in the audit account, and enable S3 Object Lock in governance mode for seven years.
C.Enable AWS CloudTrail management events only, deliver logs to a central S3 bucket, and configure a bucket policy that denies s3:DeleteObject for all principals.
D.Enable S3 server access logging on each bucket, deliver the logs to a central bucket, and use an S3 Lifecycle policy to transition logs to S3 Glacier Deep Archive after 90 days.
AnswerA

CloudTrail data events capture object-level S3 access, and delivering them to a central bucket in the audit account meets the centralized logging requirement. S3 Object Lock in compliance mode prevents any user, including the root user and the management account, from deleting or altering objects for the retention period, satisfying the seven-year immutability requirement.

Why this answer

CloudTrail data events capture object-level S3 operations, and delivering them to a central audit account bucket centralizes storage. S3 Object Lock in compliance mode enforces a write-once-read-many model that no principal, including the management account root user, can override during the retention period, which meets the seven-year immutability requirement.

Exam trap

The trap here is confusing CloudTrail management events with data events, or assuming a bucket policy or governance mode provides the same immutability as compliance mode Object Lock.

31
Multi-Selectmedium

A company wants to implement a cost allocation strategy using tags across multiple accounts in AWS Organizations. Which TWO practices should be followed?

Select 2 answers
A.Define a standardized set of tags (e.g., CostCenter, Owner, Project) and enforce them using AWS Config rules.
B.Enable AWS-generated tags automatically for all resources.
C.Use service control policies (SCPs) to require tags on all resources.
D.Apply tags only at the resource creation time; they cannot be added later.
E.Use AWS Cost Explorer to filter costs by tags across accounts.
AnswersA, E

A standardised tag schema applied consistently across all accounts is the prerequisite for any tag-based allocation; AWS Config rules enforce compliance so untagged or mis-tagged resources are detected. Without this governance, Cost Explorer grouping produces incomplete, unreliable cost attribution across the organisation.

Why this answer

Option A is correct because a cost allocation strategy requires a consistent, standardized tagging schema (such as CostCenter, Owner, and Project) so that costs can be grouped reliably, and AWS Config rules (e.g., required-tags managed rules) can detect and flag non-compliant resources to enforce that schema across accounts. Option E is correct because AWS Cost Explorer can filter and group costs by activated cost allocation tags, and when combined with AWS Organizations it provides cross-account visibility into tagged spend, which is essential for allocating costs across multiple accounts. Option B is wrong because AWS-generated tags are limited to specific service-created metadata and cannot substitute for a deliberate, standardized cost allocation tagging scheme.

Option C is wrong because SCPs control which API actions and services principals may use; they cannot require that a resource carry specific tag keys or values. Option D is wrong because tags can be added, modified, or removed at any time after resource creation, not only at creation time.

Exam trap

The trap here is confusing service control policies (SCPs) with tag enforcement mechanisms; SCPs control permissions, not resource configurations, so candidates often incorrectly select SCPs for tagging requirements instead of AWS Config rules or tag policies.

32
MCQhard

A company is migrating a legacy application that uses TCP on port 8080 to AWS. The application must be accessible from the internet. The company wants to use an Application Load Balancer. What must the company do to ensure the load balancer can accept traffic on port 8080?

A.Configure the security group to allow inbound traffic on port 80 and 443 only.
B.Change the ALB's default port to 8080.
C.Assign an Elastic IP address to the ALB.
D.Create a listener for port 8080 on the ALB.
AnswerD

An ALB listener defines the port and protocol on which it accepts inbound connections, so creating one on port 8080 satisfies the requirement to accept TCP traffic there. The listener then evaluates rules and forwards to a target group. Without a matching listener, the ALB silently drops traffic, regardless of security group configuration.

Why this answer

An ALB requires a listener for each port it accepts traffic on; to accept TCP on port 8080, you must create a listener on port 8080 with rules forwarding to the target group. The security group must also allow 8080, but the listener is the ALB configuration step that enables the port.

Exam trap

The trap is assuming the ALB has a configurable default port or that an Elastic IP is needed — ALBs use listeners, and only NLBs support Elastic IPs.

How to eliminate wrong answers

Option A is wrong because restricting the security group to 80/443 would block 8080 traffic entirely, not enable it. Option B is wrong because ALBs do not have a 'default port' to change; listeners define ports. Option C is wrong because ALBs do not support Elastic IP addresses (only NLBs do), and an EIP would not enable port 8080.

33
MCQhard

A company is migrating an on-premises .NET application to AWS. The application uses a SQL Server database with a large number of stored procedures and triggers. The company wants to reduce licensing costs by moving to an open-source database. Which AWS service should the solutions architect use to automate the database conversion?

A.AWS Database Migration Service (DMS)
B.AWS App2Container
C.AWS Schema Conversion Tool (SCT)
D.AWS Application Migration Service (CloudEndure)
AnswerC

AWS SCT analyses the SQL Server schema and automatically converts stored procedures, triggers and other proprietary objects into the target open-source engine's equivalent syntax. This satisfies the requirement to automate conversion, reducing the manual rewrite effort before data migration.

Why this answer

AWS Schema Conversion Tool (SCT) automates the conversion of database schema and code to a target database like PostgreSQL or MySQL. DMS handles data migration, not schema conversion. App2Container is for containerizing applications.

CloudEndure is for server migration.

34
MCQeasy

A company runs a stateless REST API on six Amazon EC2 instances in a single Availability Zone behind a Network Load Balancer (NLB). The API writes uploaded files to a shared POSIX file system that must remain accessible from every instance. The company wants to make the architecture resilient to an Availability Zone failure with the least operational effort. Which solution should a solutions architect recommend?

A.Deploy an Amazon EFS file system with mount targets in at least two Availability Zones, and launch EC2 instances in an Auto Scaling group across those same Availability Zones.
B.Store the files in an Amazon S3 bucket in the same Region and use the AWS CLI to synchronize the bucket to local instance store volumes on each EC2 instance.
C.Create an Amazon FSx for Windows File Server file system in one Availability Zone and configure AWS DataSync to copy files to a second file system hourly.
D.Attach an Amazon EBS io2 Block Express volume to all six EC2 instances and enable EBS Multi-Attach so every instance reads and writes the same volume.
AnswerA

Amazon EFS is a fully managed, multi-AZ POSIX file system that mounts concurrently on Linux EC2 instances in every Availability Zone where a mount target exists. Spreading the Auto Scaling group across the same zones removes the single-AZ failure domain without requiring the company to build or replicate any file-system layer, which matches the least-operational-effort requirement.

Why this answer

A shared POSIX file system that survives an Availability Zone loss is delivered by Amazon EFS with mount targets in multiple zones, combined with an Auto Scaling group that spans those zones. This is fully managed, requires no replication logic, and keeps the existing Linux application unchanged, which satisfies the resilience goal with the least operational effort.

Exam trap

The trap here is assuming that EBS Multi-Attach provides a cross-Availability-Zone shared file system, when it is limited to a single zone and to block-level access.

35
Multi-Selecthard

A company is using AWS CodePipeline to automate deployments of a web application. The pipeline includes a build stage using AWS CodeBuild and a deploy stage using AWS CodeDeploy to an Auto Scaling group. Recently, deployments have been failing during the deploy stage with an error indicating that the target instances are not in a healthy state. The CodeDeploy agent logs show that the agent is running but the application validation scripts are failing. Which THREE actions should the solutions architect take to troubleshoot and resolve the issue?

Select 3 answers
A.Test the validation script manually on a healthy instance to confirm it works as expected.
B.Increase the deployment timeout in the CodeDeploy deployment group to allow more time for validation.
C.Review the CodeDeploy agent logs on a failing instance to identify the specific error in the validation script.
D.Verify that the AppSpec file includes the correct lifecycle event hooks (e.g., ValidateService).
E.Configure an Auto Scaling lifecycle hook to perform health checks before the instance is placed in service.
AnswersA, C, D

Running the validation script manually on a healthy instance isolates whether the script itself is faulty, independent of CodeDeploy orchestration. This directly addresses the stem's constraint that the agent runs but validation scripts fail, confirming whether the script logic or its environment causes the failure.

Why this answer

Option A is correct because running the validation script manually on a healthy instance isolates whether the script itself is broken or whether the failure is environmental (permissions, dependencies, or runtime context), which is the fastest way to reproduce and diagnose the error. Option C is correct because the CodeDeploy agent logs on a failing instance (typically /var/log/aws/codedeploy-agent/codedeploy-agent.log) contain the exact stderr/stdout and exit code from the failing lifecycle hook, pinpointing the specific validation error. Option D is correct because CodeDeploy only executes scripts mapped to lifecycle event hooks defined in the AppSpec file's hooks section (for EC2/on-premises, e.g., BeforeInstall, AfterInstall, ApplicationStart, ValidateService); if ValidateService is missing or misspelled, the validation script never runs as intended and the deployment fails validation.

Option B is not appropriate because increasing the deployment timeout only masks a script that is failing outright rather than slow, and the logs already show the validation scripts are failing, not timing out. Option E is not appropriate because Auto Scaling lifecycle hooks govern instance launch/termination and do not address CodeDeploy application validation script failures during the deploy stage.

Exam trap

SAP-C02 often tests the misconception that increasing timeouts or adding health checks at the Auto Scaling level will resolve application-level validation failures, when the root cause is typically within the script or its configuration.

36
MCQhard

A company is designing a new global application that will be deployed in multiple AWS Regions. The application uses an Amazon Aurora MySQL database in each Region. The company needs to ensure that the database in each Region can be used for read scaling and that a secondary Region can be promoted to primary within minutes in case of a regional failure. The company wants to minimize data loss. Which solution should a solutions architect recommend?

A.Configure Aurora Multi-Master clusters in each Region and use AWS Global Accelerator to route traffic.
B.Create Aurora read replicas in each Region and use Amazon Route 53 health checks to redirect traffic during a failure.
C.Configure Aurora Global Database with the primary cluster in one Region and secondary clusters in other Regions.
D.Use Amazon RDS for MySQL with cross-Region read replicas and promote the replica in the secondary Region during a failure.
AnswerC

Aurora Global Database uses a dedicated replication infrastructure to replicate data from the primary cluster to secondary clusters with typical latency under one second. Secondary clusters can serve read-only traffic, providing read scaling. In a regional failure, a secondary cluster can be promoted to primary in as little as one minute, with minimal data loss (typically less than one second of replication lag). This meets the requirements for read scaling, fast promotion, and minimal data loss.

Why this answer

Aurora Global Database is designed for global applications requiring low-latency reads and fast regional failover. It replicates data from a primary cluster to secondary clusters in other Regions with minimal lag, allowing secondary clusters to serve read traffic. In a regional failure, a secondary cluster can be promoted to primary in about a minute with minimal data loss, satisfying the requirements for read scaling, fast promotion, and low data loss.

Exam trap

The trap here is assuming that cross-Region read replicas provide the same fast promotion and minimal data loss as Aurora Global Database, when they actually require manual promotion and may have higher replication lag.

37
MCQmedium

A company runs a critical Java application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in local instance memory, and the Auto Scaling group is configured to terminate instances when CPU utilization drops below 20%. During a recent scaling event, users were unexpectedly logged out and lost shopping cart contents. A solutions architect needs to make the application stateless so that instances can be terminated without impacting users, while minimizing changes to the application code. Which solution meets these requirements?

A.Change the Auto Scaling group termination policy to OldestInstance and enable connection draining on the load balancer.
B.Store session state in an Amazon ElastiCache for Redis cluster and update the application to use the ElastiCache endpoint for session data.
C.Enable sticky sessions on the Application Load Balancer and increase the deregistration delay to 300 seconds.
D.Configure the Auto Scaling group to use a lifecycle hook that backs up session data to Amazon S3 before termination, and restore it on new instances.
AnswerB

ElastiCache for Redis provides a highly available, in-memory data store that is external to the EC2 instances. By moving session state to Redis, the application no longer relies on local instance memory, so any instance can be terminated without losing session data. This is the standard approach to make a stateful Java application stateless with minimal code changes, as only the session management layer needs updating.

Why this answer

The application is stateful because it stores session data in local instance memory. To allow instances to be terminated without user impact, session state must be externalized. ElastiCache for Redis is a fully managed, in-memory store that supports high-performance session management and is a common solution for making Java applications stateless.

The other options do not remove the dependency on local instance memory.

Exam trap

The trap here is assuming that sticky sessions or connection draining can preserve session state when an instance is terminated.

38
MCQmedium

A company is designing a new two-tier web application on AWS. The web tier runs on Amazon EC2 instances behind an Application Load Balancer (ALB), and the database tier uses Amazon RDS for MySQL. The company requires that the database credentials be automatically rotated every 30 days without application downtime. The application retrieves credentials from a centralized store at runtime. Which solution meets these requirements?

A.Use IAM database authentication for RDS and store the IAM role credentials in AWS Secrets Manager with automatic rotation.
B.Store the database credentials in an encrypted Amazon S3 object and use an AWS Lambda function to rotate the credentials in RDS and update the S3 object.
C.Store the database credentials in AWS Secrets Manager and enable automatic rotation with a Lambda rotation function.
D.Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter and configure automatic rotation using a Lambda function.
AnswerC

AWS Secrets Manager supports automatic rotation of database credentials using a Lambda rotation function. It can rotate RDS MySQL credentials every 30 days, and the application can retrieve the current credentials from Secrets Manager at runtime, ensuring no downtime. Secrets Manager integrates natively with RDS and provides a secure, centralized store.

Why this answer

The requirement is for automatic rotation of database credentials every 30 days with no application downtime and a centralized store. AWS Secrets Manager provides native support for rotating RDS MySQL credentials using a Lambda rotation function, and applications can retrieve the latest credentials at runtime. This meets all the requirements without custom development.

The other options either lack native rotation, are insecure, or use a different authentication mechanism that does not involve rotating credentials.

Exam trap

The trap here is confusing IAM database authentication with password-based authentication, or assuming Parameter Store provides automatic rotation when it does not.

39
MCQhard

A company runs a critical web application on EC2 instances behind an Application Load Balancer (ALB). During a recent deployment, users experienced errors. The team wants to automatically roll back the deployment if the error rate exceeds 5% within 10 minutes after deployment. Which solution meets these requirements with minimal operational overhead?

A.Configure the Auto Scaling group to use ELB health checks and replace instances if the error rate increases.
B.Use CodeDeploy with manual approval gates and a script that checks error rates.
C.Use CodeDeploy with a CloudWatch alarm on the ALB error rate that triggers a deployment rollback.
D.Use a custom Lambda function that monitors ALB error rates and triggers a rollback via CodeDeploy API.
AnswerC

CodeDeploy integrates CloudWatch alarms directly into deployment monitoring, automatically rolling back to the previous revision when the alarm breaches its threshold. This meets the 5% error-rate and 10-minute window with minimal operational overhead, requiring no custom automation.

Why this answer

AWS CodeDeploy integrates natively with CloudWatch alarms to automatically roll back a deployment when the alarm enters the ALARM state. By creating a CloudWatch alarm on the ALB's HTTP 5xx error rate (or target group error metric) with a threshold of 5% over a 10-minute period, and associating it with the CodeDeploy deployment group, CodeDeploy will trigger an automatic rollback if the alarm fires. This requires minimal operational overhead because it uses built-in integration.

Exam trap

SAP-C02 often tests whether candidates choose custom Lambda or manual gates for rollback automation, when the native CodeDeploy-CloudWatch alarm integration is the lowest-overhead, fully automated solution.

How to eliminate wrong answers

Option A is wrong because Auto Scaling group health checks replace unhealthy instances but do not roll back a deployment or act on application error rates. Option B is wrong because manual approval gates require human intervention and a custom script, adding operational overhead and delay, which violates the 'minimal operational overhead' and automatic rollback requirements. Option D is wrong because a custom Lambda function introduces custom code to maintain and monitor, increasing operational overhead compared to the native CodeDeploy-CloudWatch integration.

40
MCQmedium

A financial services company has an AWS Organizations structure with production and development OUs. The security team wants to prevent any IAM principal in the development OU from disabling AWS CloudTrail logging, even if an account administrator attempts it. They need a solution that applies automatically to all existing and future accounts in the development OU. What should they do?

A.Attach an IAM policy to each account's administrator role that denies CloudTrail stop and delete actions, and use AWS CloudFormation StackSets to deploy it.
B.Create an SCP that denies the cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail actions, and attach it to the development OU.
C.Enable AWS CloudTrail organization trail in the management account and configure S3 bucket policies to deny trail modifications.
D.Use AWS Config rules in each account to detect when CloudTrail is disabled and trigger an AWS Lambda function to re-enable it.
AnswerB

SCPs attached to an OU apply to all member accounts, including future ones, and restrict the maximum permissions for all principals in those accounts. Denying StopLogging, DeleteTrail, and UpdateTrail prevents any IAM principal, including account administrators, from disabling or altering CloudTrail, satisfying the requirement without per-account changes.

Why this answer

Service control policies (SCPs) are the only AWS Organizations mechanism that can enforce preventive guardrails across all accounts in an OU, including future accounts. By denying the specific CloudTrail actions that stop, delete, or modify a trail, the SCP ensures that even account administrators cannot disable logging. This meets the requirement for automatic, centralized enforcement without per-account configuration.

Exam trap

The trap here is assuming that an organization trail alone prevents disabling, when in fact it only centralizes logging and does not block account-level trail modifications.

41
MCQmedium

A company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to prevent any member account from disabling AWS CloudTrail or deleting the organization trail. They also want to ensure that only the management account can create new trails. Which solution meets these requirements with the least operational overhead?

A.Use AWS Organizations service control policies (SCPs) to deny cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:CreateTrail in all member accounts, while allowing these actions in the management account.
B.Use AWS CloudFormation StackSets to deploy a trail in each member account and set the trail to use an S3 bucket in the management account.
C.Create an IAM policy in each member account that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail, and attach it to all IAM roles.
D.Enable AWS Config in all member accounts with a managed rule that checks for CloudTrail logging and automatically remediates with a Lambda function.
AnswerA

SCPs applied at the organization or OU level centrally restrict actions in all member accounts, including the root user, and automatically apply to new accounts. Denying StopLogging and DeleteTrail protects the trail, and denying CreateTrail ensures only the management account can create trails, with minimal ongoing effort.

Why this answer

Service control policies in AWS Organizations provide centralized, preventive control over member accounts, including the root user, and automatically apply to new accounts. Denying StopLogging and DeleteTrail protects the organization trail, while denying CreateTrail ensures trail creation is limited to the management account, meeting the requirements with minimal operational effort.

Exam trap

The trap here is relying on detective controls such as AWS Config or per-account IAM policies, which do not prevent the action before it occurs and do not cover the account root user.

42
MCQhard

A company is designing a new application that will use Amazon DynamoDB as its primary database. The application has two access patterns: one requires strongly consistent reads, and the other requires eventually consistent reads. The company wants to minimize costs while meeting the read consistency requirements. How should the company configure DynamoDB reads?

A.Use strongly consistent reads for all read requests to ensure data accuracy.
B.Use DynamoDB Accelerator (DAX) to cache reads and achieve strong consistency.
C.Use DynamoDB global tables with strongly consistent reads enabled.
D.Use strongly consistent reads for the pattern that requires it, and eventually consistent reads for the other pattern.
AnswerD

DynamoDB charges double read capacity units for strongly consistent reads, so applying them only to the pattern requiring them and eventually consistent reads elsewhere minimises cost while meeting both consistency requirements. Using strongly consistent reads for both patterns would needlessly double capacity consumption.

Why this answer

DynamoDB supports both strongly consistent reads and eventually consistent reads at the API level (via the `ConsistentRead` parameter). Strongly consistent reads return the most up-to-date data but consume twice the read capacity units (RCUs) compared to eventually consistent reads. By using strongly consistent reads only for the access pattern that requires it, and eventually consistent reads for the other pattern, the company minimizes RCU consumption and thus costs while meeting the specific consistency requirements of each pattern.

Exam trap

The trap here is that candidates may assume DAX can provide strong consistency (it cannot) or that global tables are a solution for local consistency requirements, when in fact the correct approach is to use the native DynamoDB `ConsistentRead` parameter selectively based on the access pattern.

How to eliminate wrong answers

Option A is wrong because using strongly consistent reads for all requests would double the RCU consumption for the pattern that only needs eventually consistent reads, unnecessarily increasing costs. Option B is wrong because DAX is an in-memory cache that provides eventually consistent reads by default; it does not support strongly consistent reads, so it cannot satisfy the pattern requiring strong consistency. Option C is wrong because DynamoDB global tables are designed for multi-region replication and provide eventually consistent reads across regions; they do not support strongly consistent reads globally, and enabling them does not help meet local consistency requirements.

43
MCQhard

A company has a legacy application that runs on a single EC2 instance. The application writes logs to a local file. The company wants to centralize log management without modifying the application code. Which solution is MOST operationally efficient?

A.Use AWS CloudTrail to capture log file changes.
B.Modify the application to write logs to stdout and use the awslogs driver.
C.Install and configure the Amazon CloudWatch agent on the EC2 instance.
D.Set up an Amazon S3 bucket and use an AWS Lambda function to periodically copy log files.
AnswerC

Installing the CloudWatch agent lets it tail the existing local log file and stream entries to CloudWatch Logs, so centralised management is achieved with zero application changes — satisfying the no-code-modification constraint. This is more operationally efficient than custom forwarding scripts, since the agent handles rotation, buffering and delivery natively.

Why this answer

The Amazon CloudWatch agent can be installed on the EC2 instance without modifying application code. It reads the local log file and sends the logs to Amazon CloudWatch Logs for centralized management, making it the most operationally efficient solution.

Exam trap

The trap here is that candidates may think modifying the application to use stdout with the awslogs driver is simpler, but that requires code changes, which the question explicitly prohibits.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail captures API activity and management events, not log file changes on an EC2 instance. Option B is wrong because it requires modifying the application code to write logs to stdout, which violates the requirement to not modify application code. Option D is wrong because setting up an S3 bucket and Lambda function to periodically copy log files introduces unnecessary complexity and latency compared to the real-time streaming provided by the CloudWatch agent.

44
MCQhard

A global company uses AWS Organizations with many OUs and accounts. The finance team needs to track costs by cost center, which is tagged on each resource. However, some resources are not tagged. Which solution will provide the MOST accurate cost allocation?

A.Enable cost allocation tags and use AWS Cost Explorer to filter by tag.
B.Create AWS Budgets reports for each cost center using tag filters.
C.Export AWS Cost and Usage Reports to Amazon QuickSight and use tag-based filtering.
D.Use AWS Cost Categories to group costs by tag value and set a default rule for untagged resources.
AnswerD

Cost Categories group costs by tag value and support a default rule that captures untagged resources, so spend without the cost centre tag is still allocated rather than omitted. This directly addresses the stem's constraint that some resources lack tags, giving the most accurate allocation.

Why this answer

AWS Cost Categories allow you to group costs by tag values and, crucially, set a default rule for untagged resources. This ensures that all resources—tagged or not—are assigned to a cost center, providing the most accurate cost allocation across the entire organization. Other options only filter or report on tagged resources, leaving untagged costs unallocated.

Exam trap

The trap here is that candidates assume tag-based filtering or reporting tools (Cost Explorer, Budgets, QuickSight) can handle untagged resources, but they cannot—only Cost Categories with a default rule can allocate costs for untagged resources.

How to eliminate wrong answers

Option A is wrong because enabling cost allocation tags and using Cost Explorer to filter by tag only reports on resources that already have the tag; untagged resources are excluded, leading to incomplete cost allocation. Option B is wrong because AWS Budgets reports with tag filters also only apply to tagged resources; they do not handle untagged resources, so costs from untagged resources are not tracked by cost center. Option C is wrong because exporting CUR to QuickSight and using tag-based filtering still requires tags to be present on resources; untagged resources are not assigned to any cost center, resulting in inaccurate allocation.

45
MCQeasy

A retail company is migrating its e-commerce platform from a monolith running on a single on-premises server to AWS. The current application consists of a Java-based web server, a MySQL database, and a caching layer using Redis. The company wants to modernize the architecture by adopting microservices, using serverless where possible, and minimizing operational overhead. The migration must be completed within six months with minimal disruption to ongoing operations. The solutions architect proposes the following initial steps: containerize the Java application and run it on Amazon ECS with Fargate, migrate the MySQL database to Amazon Aurora Serverless v2, and replace Redis with Amazon ElastiCache for Redis Serverless. However, the team is concerned about the complexity of the migration and the potential for downtime. Which recommendation should the solutions architect make to address these concerns?

A.Rewrite the entire application as microservices from scratch and deploy them in a new AWS environment. Cut over all traffic at once after testing.
B.Use AWS Blue/Green deployment for the monolith to reduce downtime, then migrate to microservices after the deployment is stable.
C.Use the Strangler Fig pattern to incrementally replace monolith functionality with microservices, routing traffic to new services as they are built.
D.Perform a lift-and-shift migration of the monolith to EC2 instances, then gradually refactor into microservices over the next year.
AnswerC

The Strangler Fig pattern incrementally replaces monolith functionality with microservices, routing traffic gradually to new services. This limits migration risk and avoids downtime, satisfying the six-month deadline with minimal disruption while enabling the serverless modernisation the company wants.

Why this answer

The Strangler Fig pattern allows the team to incrementally replace specific functionalities of the monolithic e-commerce platform with microservices, routing traffic to the new services as they are built. This minimizes disruption and downtime by avoiding a big-bang cutover, and it aligns with the goal of modernizing to microservices and serverless within the six-month timeline. The pattern leverages an existing ingress controller (e.g., an Application Load Balancer with path-based routing) to gradually shift requests from the monolith to new services running on Amazon ECS with Fargate, while the database and caching layers are migrated separately with minimal impact.

Exam trap

The trap here is that candidates often confuse Blue/Green deployments (which reduce downtime for a single application version) with the Strangler Fig pattern (which is specifically designed for incremental migration from a monolith to microservices), leading them to choose Option B as a safe but incomplete solution.

How to eliminate wrong answers

Option A is wrong because rewriting the entire application from scratch as microservices and performing a single cutover introduces high complexity, significant risk of downtime, and likely exceeds the six-month timeline, contradicting the requirement for minimal disruption. Option B is wrong because Blue/Green deployment for the monolith reduces downtime during deployment but does not address the migration to microservices; it keeps the monolith intact and defers the modernization, failing to meet the goal of adopting microservices and serverless. Option D is wrong because a lift-and-shift to EC2 instances postpones refactoring for over a year, which violates the six-month migration deadline and does not minimize operational overhead, as it retains the monolithic architecture and requires managing EC2 instances.

46
MCQeasy

A company is designing a new microservices architecture on Amazon ECS with Fargate. Each microservice must be isolated and able to communicate with others only through defined APIs. Which solution provides the BEST isolation and security?

A.Use AWS App Mesh with Envoy sidecars to control traffic between services.
B.Place all microservices in the same security group and allow all traffic.
C.Use an Application Load Balancer per microservice with listener rules.
D.Use VPC peering between each microservice's VPC.
AnswerA

AWS App Mesh injects Envoy sidecar proxies into each Fargate task, giving per-service identity, mutual TLS, and explicit traffic routing so services communicate only through defined APIs. This satisfies the isolation and API-only communication requirements better than security groups alone.

Why this answer

AWS App Mesh with Envoy sidecars provides service-level traffic control, encryption, and observability without modifying application code. It enforces fine-grained routing and security policies (e.g., mTLS, retries, timeouts) between microservices, ensuring isolation and that communication only occurs through defined APIs. This aligns with the microservices principle of strict API boundaries and defense in depth.

Exam trap

The SAP-C02 exam often tests the misconception that network-level controls (security groups, VPC peering) are sufficient for microservice isolation, but the exam requires understanding that application-layer service mesh (like App Mesh) provides the necessary API-level security and observability.

How to eliminate wrong answers

Option B is wrong because placing all microservices in the same security group and allowing all traffic removes network segmentation, violating the isolation requirement and exposing services to unrestricted lateral movement. Option C is wrong because an Application Load Balancer per microservice adds unnecessary complexity, cost, and does not enforce service-to-service API-level security; ALBs operate at Layer 7 but cannot enforce mTLS or fine-grained routing between individual service instances. Option D is wrong because VPC peering between each microservice's VPC is operationally unscalable (n² peering connections), introduces latency, and does not provide application-layer API control or encryption between services.

47
MCQmedium

A company runs a batch processing application on a scheduled EC2 instance that starts every night. The instance processes a large number of files from an S3 bucket and writes results to another S3 bucket. The job takes approximately 6 hours to complete. Recently, the job has been failing after 4 hours with an error indicating that the instance's EBS root volume is full. The instance type is t3.medium with a 20 GB gp2 root volume. The application writes temporary files to the root volume. The company wants to fix this with minimal changes to the application and infrastructure. What should a solutions architect recommend?

A.Create an additional EBS volume and mount it to the instance.
B.Change the instance type to one with instance store volumes.
C.Increase the size of the EBS root volume to 100 GB.
D.Modify the application to compress temporary files.
AnswerC

The application writes temporary files to the root volume, exhausting 20 GB during the six-hour job. Enlarging the gp2 root volume to 100 GB adds capacity without changing the application or instance type, satisfying the minimal-change constraint.

Why this answer

Increasing the root volume size provides more space for temporary files without requiring application changes. Option A is wrong because creating an additional EBS volume and mounting it would require application changes to write to a different path. Option B is wrong because instance store volumes are ephemeral and may not be available on t3 instances, and would also require application changes.

Option D is wrong because compressing temporary files may not be sufficient and requires code changes.

48
Multi-Selecteasy

A company is designing a new VPC with public and private subnets. The company wants to ensure that instances in the private subnets can download updates from the internet, but cannot be directly accessed from the internet. Which THREE components are required to meet these requirements? (Choose THREE.)

Select 3 answers
A.A route table for private subnets with a default route pointing to the NAT Gateway.
B.An Internet Gateway attached to the VPC.
C.A Virtual Private Gateway (VGW).
D.A NAT Gateway in a public subnet.
E.A VPC endpoint for S3.
AnswersA, B, D

Private instances need outbound internet access without inbound reachability. A route table associated with the private subnets carrying a default route (0.0.0.0/0) to the NAT Gateway directs their egress traffic there, satisfying the download-updates requirement while keeping them unreachable from the internet.

Why this answer

Option A is correct because the private subnet's route table must contain a default route (0.0.0.0/0) targeting the NAT Gateway so that outbound internet-bound traffic from private instances is forwarded to the NAT device. Option B is correct because an Internet Gateway must be attached to the VPC to provide the public subnet (and thus the NAT Gateway) with connectivity to the internet; without it, no traffic can reach external update servers. Option D is correct because the NAT Gateway itself must reside in a public subnet, where it has a route to the Internet Gateway, and it performs source NAT so private instances can initiate outbound connections while remaining unreachable from the internet.

Option C is not needed here because a Virtual Private Gateway is used for Site-to-Site VPN or Direct Connect connectivity to on-premises networks, not for general internet access. Option E is not required because a VPC endpoint for S3 only provides private access to S3 (and similar services), not general internet downloads for OS or software updates.

Exam trap

The trap here is that candidates often confuse a Virtual Private Gateway (VGW) with a NAT Gateway, mistakenly thinking a VGW can provide internet access, or they assume a VPC endpoint for S3 is sufficient for general internet downloads, when it only covers S3 traffic.

49
MCQeasy

A company is migrating a legacy application that uses a proprietary binary protocol over TCP. The application must be migrated with minimal changes and requires high throughput. Which AWS service should the architect recommend for load balancing?

A.Network Load Balancer (NLB)
B.AWS Global Accelerator
C.Application Load Balancer (ALB)
D.Classic Load Balancer (CLB)
AnswerA

Network Load Balancer operates at Layer 4, forwarding TCP connections without inspecting or terminating them, so the proprietary binary protocol passes through unchanged. It satisfies the minimal-changes constraint and handles millions of requests per second, meeting the high-throughput requirement that an Application Load Balancer could not.

Why this answer

Network Load Balancer (NLB) is designed for TCP traffic at high throughput with minimal latency, making it ideal for migrating legacy applications using proprietary binary protocols over TCP. Option B (AWS Global Accelerator) improves application performance by directing traffic over the AWS global network but is not a load balancer. Option C (Application Load Balancer) operates at Layer 7 and is best for HTTP/HTTPS traffic, not TCP.

Option D (Classic Load Balancer) is a legacy option that lacks the performance and features of NLB.

50
MCQmedium

A media company is designing a new video transcoding pipeline on AWS. The pipeline receives large video files in an Amazon S3 bucket, and each file must be transcoded into multiple formats. The transcoding jobs take between 10 and 45 minutes, and the company wants to minimize compute cost while ensuring that jobs are not interrupted. The solution must automatically scale based on the number of pending jobs. Which compute option should the company use?

A.AWS Lambda functions with a 15-minute timeout, triggered by S3 event notifications, scaling automatically with concurrency.
B.AWS Fargate tasks on Amazon ECS, triggered by an Application Load Balancer, scaling based on CPU utilization of the tasks.
C.AWS Batch with a managed compute environment using On-Demand EC2 instances, scaling based on the number of jobs in the job queue.
D.Amazon EC2 Spot Instances in an Auto Scaling group, with a launch template that installs transcoding software, scaling based on the SQS queue depth.
AnswerC

AWS Batch is designed for batch computing workloads and can scale compute resources based on the number of runnable jobs in the queue. Using On-Demand instances ensures jobs are not interrupted, and the managed compute environment handles provisioning and scaling automatically, minimizing operational overhead.

Why this answer

AWS Batch with On-Demand instances provides a managed batch processing environment that scales based on job queue depth. It supports long-running jobs beyond the Lambda timeout and avoids the interruption risk of Spot Instances. The managed compute environment automatically provisions and terminates instances, reducing operational overhead while meeting the cost and reliability requirements.

Exam trap

The trap here is assuming that Spot Instances are always the cheapest and therefore best choice, ignoring the interruption risk that conflicts with the requirement that jobs not be interrupted.

51
Multi-Selectmedium

A company is designing a multi-account AWS Organizations architecture. Which TWO considerations should be taken into account when designing the organizational structure?

Select 2 answers
A.Accounts cannot be moved between OUs once created.
B.Each organizational unit (OU) should contain only one account for security isolation.
C.AWS CloudTrail can be configured to log management events across all accounts from the management account.
D.Service control policies (SCPs) can be used to centrally restrict permissions across accounts.
E.SCPs can only be applied to root accounts, not OUs.
AnswersC, D

CloudTrail organisation trails let the management account aggregate management events from every member account into one destination bucket, satisfying the centralised auditing constraint of a multi-account structure. This removes per-account trail configuration and preserves a single immutable log archive, which is essential when accounts are created and removed dynamically.

Why this answer

Option C is correct because AWS CloudTrail supports organization trails: when created in the management account (or a delegated administrator) with the organization setting enabled, it automatically logs management events for all member accounts and delivers them to a central S3 bucket. Option D is correct because service control policies (SCPs) are a core AWS Organizations feature that let you centrally set permission guardrails (allow lists or deny lists) that apply to all IAM principals in the accounts attached to the OU or root, restricting what member accounts can do. Option A is wrong because accounts can be moved between OUs at any time (though each account can belong to only one OU at a time).

Option B is wrong because OUs are meant to group multiple accounts with similar policy needs, and isolation is achieved through separate accounts and SCPs, not by limiting an OU to a single account. Option E is wrong because SCPs can be attached to the organization root, OUs, and individual member accounts — not only to root accounts.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking SCPs can only be applied to the root account, when in fact they can be attached to any OU or account within the organization.

52
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores session state in a local file on each instance. Users report that they are randomly logged out when the ALB routes their requests to a different instance. The company wants to improve the user experience and ensure that sessions persist across multiple instances. The company wants a solution that requires minimal changes to the application code. Which solution meets these requirements?

A.Enable cross-zone load balancing on the ALB and increase the number of instances.
B.Store session state in an Amazon ElastiCache for Redis cluster and update the application to use it.
C.Enable sticky sessions (session affinity) on the ALB target group.
D.Configure the ALB to use a Network Load Balancer (NLB) with sticky sessions.
AnswerC

Enabling sticky sessions on the ALB target group uses a cookie to bind a user's session to a specific instance. This ensures that all requests from that user go to the same instance, so local session files remain accessible. It requires no application code changes and is a quick fix. However, it can lead to uneven load distribution if sessions are long-lived and may not be ideal for high availability, but it meets the minimal-change requirement.

Why this answer

Sticky sessions on the ALB bind a user's session to a specific target instance using a cookie, ensuring that all requests from that user go to the same instance where their session file is stored. This requires no application code changes and directly solves the random logout issue. While not the most scalable long-term solution, it meets the minimal-change requirement and improves user experience.

Exam trap

The trap here is assuming that a Network Load Balancer can provide HTTP cookie-based sticky sessions, which it cannot because it operates at Layer 4.

53
MCQmedium

A company is designing a containerized microservices architecture on Amazon ECS. The services must be able to discover each other using DNS names. Which AWS service should the company use for service discovery?

A.AWS Cloud Map
B.Amazon Route 53 Resolver
C.Elastic Load Balancing (ELB)
D.Amazon Elastic Container Registry (ECR)
AnswerA

AWS Cloud Map provides service discovery with DNS names, letting ECS tasks register and resolve each other automatically. It integrates natively with ECS service discovery, satisfying the DNS-based lookup requirement without custom routing or load balancer workarounds.

Why this answer

AWS Cloud Map is the correct choice because it provides a fully managed service discovery solution that integrates natively with Amazon ECS. It allows microservices to register their DNS names and health checks, enabling other services to discover them via DNS queries or API calls. This directly supports the requirement for containerized services to find each other using DNS names within an ECS cluster.

Exam trap

The trap here is confusing a load balancer (ELB) with service discovery; candidates often think ELB provides DNS-based discovery, but it only routes traffic to a group of targets, not per-instance DNS names for dynamic microservice-to-microservice communication.

How to eliminate wrong answers

Option B (Amazon Route 53 Resolver) is wrong because it is a DNS resolution service for hybrid networks (on-premises to AWS), not a service discovery mechanism for ECS microservices; it does not register or manage service instances. Option C (Elastic Load Balancing) is wrong because it distributes traffic to targets but does not provide DNS-based service discovery for individual service instances; it is a load balancer, not a discovery registry. Option D (Amazon Elastic Container Registry) is wrong because it is a container image repository, not a service discovery tool; it stores Docker images but has no role in DNS resolution or instance registration.

54
MCQhard

A logistics company is designing a new shipment-tracking platform on AWS. The platform ingests telemetry from thousands of trucks, and downstream analytics must query the latest position of any truck within one second. The company also needs to retain six months of raw telemetry for audit at the lowest possible storage cost, and the data must be queryable with standard SQL for ad hoc reports. The company wants a fully managed solution with minimal operational overhead. Which design should the solutions architect recommend?

A.Write telemetry to Amazon S3 and use Amazon Athena with a view that selects the maximum timestamp per truck for latest-position queries
B.Write telemetry to Amazon OpenSearch Service and retain six months of indices for both latest-position lookups and ad hoc SQL reporting
C.Write telemetry to Amazon Kinesis Data Streams, use AWS Lambda to write the latest position to Amazon DynamoDB and the raw records to Amazon S3, and query S3 with Amazon Athena
D.Write telemetry directly to Amazon Redshift, use materialized views for latest positions, and keep all raw data in Redshift for six months
AnswerC

Kinesis Data Streams ingests high-volume telemetry durably, Lambda maintains a DynamoDB table keyed by truck ID for sub-second latest-position lookups, and the same function archives raw records to S3. Athena runs standard SQL directly against S3, and S3 lifecycle policies can move older telemetry to cheaper storage classes, meeting the six-month low-cost audit requirement with no servers to manage.

Why this answer

The design separates the low-latency serving path from the cheap long-term store. Kinesis Data Streams absorbs the telemetry firehose, a Lambda consumer maintains a DynamoDB table keyed by truck ID so the latest position is readable in milliseconds, and the same stream is archived to S3 for audit. Athena then provides standard SQL over the archived data at low cost, and S3 lifecycle rules keep six months of telemetry affordable.

Exam trap

The trap here is trying to satisfy both the sub-second operational lookup and the cheap SQL audit from a single engine instead of splitting the serving and archival paths.

55
MCQmedium

A company is designing a new global web application that will be deployed on AWS. The application must provide low-latency access to users worldwide and must be able to fail over between regions in case of an outage. The company wants to use a single global endpoint and minimize DNS propagation delays during failover. Which solution should a solutions architect recommend?

A.Use Amazon CloudFront with origin failover and multiple regional origins.
B.Use Amazon Route 53 with latency-based routing and health checks to fail over between regions.
C.Use an Application Load Balancer in each region and Route 53 weighted routing with health checks.
D.Use AWS Global Accelerator with endpoint groups in multiple regions and health checks.
AnswerD

AWS Global Accelerator provides a single global anycast IP address that routes traffic to the optimal endpoint based on health, geography, and latency. It uses the AWS global network to reduce latency and provides fast failover (within seconds) by automatically redirecting traffic to healthy endpoints. This meets the requirements for a single global endpoint and minimal failover delay.

Why this answer

AWS Global Accelerator offers a single global anycast IP address and routes traffic over the AWS global network, reducing latency. It performs health checks and automatically fails over to healthy endpoints within seconds, far faster than DNS-based failover. This meets the need for a single global endpoint and minimal failover delay.

Other options rely on DNS, which introduces propagation delays and does not provide a single IP.

Exam trap

The trap here is assuming that Route 53 latency-based routing with health checks provides the same fast failover and single global endpoint as AWS Global Accelerator, when DNS TTL and propagation can cause significant delays.

56
MCQhard

Refer to the exhibit. A CloudFormation template creates an S3 bucket with versioning and a public bucket policy. After deployment, users can access objects in the bucket via the internet. However, the security team requires that all access be logged. What is missing from this configuration?

A.The bucket is not encrypted.
B.The bucket policy does not restrict access to a specific IP range.
C.Bucket versioning is not enabled.
D.No logging configuration is specified.
AnswerD

Server access logging is a separate bucket-level property that CloudFormation does not enable implicitly; versioning and a public policy govern object retention and access, not request auditing. Because the template defines neither an AWS::S3::Bucket LoggingConfiguration nor a target bucket, no access records reach any destination, so the security team's logging requirement remains unmet.

Why this answer

The question states that the security team requires all access to be logged, but the CloudFormation template does not include any logging configuration (e.g., server access logs or AWS CloudTrail object-level logging). Without enabling S3 server access logging or delivering logs to a target bucket, no access records are generated, violating the logging requirement. The bucket policy and versioning are irrelevant to the logging gap.

Exam trap

The trap here is that candidates confuse security controls like encryption, IP restrictions, or versioning with logging, failing to recognize that the specific requirement for 'all access to be logged' can only be met by explicitly configuring a logging destination.

How to eliminate wrong answers

Option A is wrong because encryption (e.g., SSE-S3, SSE-KMS) protects data at rest but does not provide access logging; the security requirement is about logging, not encryption. Option B is wrong because restricting access to a specific IP range controls who can access the bucket but does not enable logging; the requirement is for all access to be logged, not restricted. Option C is wrong because bucket versioning is already enabled per the template description, and versioning preserves object versions but does not log access events.

57
MCQhard

A company uses AWS Organizations and wants to delegate administration of a specific service to a member account. The service must be able to perform actions across all accounts in the organization. Which steps should the company take?

A.Use AWS Organizations to register the member account as a delegated administrator for the service.
B.Create a service-linked role in each account to allow the service to perform actions.
C.Grant the member account IAM permissions to assume the OrganizationAccountAccessRole in all accounts.
D.Create an IAM role in each account with a trust policy that allows the service to assume it.
AnswerA

Registering a member account as a delegated administrator via AWS Organizations grants that account's service the permissions to operate across every account in the organization, satisfying the cross-account requirement without sharing root credentials or building custom IAM roles.

Why this answer

AWS Organizations allows you to designate a member account as a delegated administrator for a specific AWS service. Once registered, that account can perform administrative actions (e.g., creating resources, managing policies) across all accounts in the organization on behalf of that service, without needing individual IAM roles or permissions in each account.

Exam trap

The trap here is that candidates often confuse delegated administration with creating cross-account IAM roles or using the OrganizationAccountAccessRole, not realizing that AWS Organizations provides a native, centralized registration mechanism for service-level delegation.

How to eliminate wrong answers

Option B is wrong because service-linked roles are automatically created by AWS services for their own use, not for delegating administration to a member account; they do not grant cross-account administrative capabilities. Option C is wrong because the OrganizationAccountAccessRole is designed for human administrators to access member accounts via the AWS Management Console or API, not for a service to perform actions programmatically across all accounts. Option D is wrong because creating an IAM role in each account with a trust policy for the service would require manual setup and maintenance in every account, which is not the intended mechanism for delegated administration; AWS Organizations provides a centralized registration process instead.

58
MCQhard

A company is modernizing a legacy monolithic application by moving it to a microservices architecture on AWS. The application currently uses a relational database with complex joins and stored procedures. The company wants to decouple the database and improve scalability. They plan to use Amazon Aurora and need to minimize the risk of data inconsistencies during the transition. Which strategy should they use to gradually migrate the database while ensuring data consistency?

A.Use AWS Schema Conversion Tool (SCT) to split the monolithic database into microservice databases.
B.Use Amazon Aurora Global Database to replicate data across microservice databases.
C.Use AWS Glue to extract, transform, and load data from the monolithic database into microservice databases.
D.Use the strangler fig pattern with AWS Database Migration Service (DMS) to replicate data between the monolithic database and new microservice databases.
AnswerD

The strangler fig pattern involves gradually replacing parts of the monolith with microservices. AWS DMS can replicate data from the monolithic database to new microservice-specific databases, ensuring consistency during the transition. This allows incremental migration, reducing risk. DMS supports ongoing replication, so both systems can operate in parallel until the monolith is fully replaced.

Why this answer

The strangler fig pattern, combined with AWS DMS for continuous replication, allows gradual migration from a monolith to microservices. DMS replicates data changes in near real-time, ensuring consistency between the old and new databases. This approach minimizes risk and allows rollback if needed.

Other options either do not support continuous replication or are not designed for database decomposition.

Exam trap

The trap here is assuming that AWS SCT can split a monolithic database into microservices, but it only converts schemas between engines, not decomposes databases.

59
MCQmedium

A company is designing a new CI/CD pipeline for a containerized application using AWS CodePipeline. The application source code is stored in an Amazon S3 bucket. The pipeline must automatically build a Docker image from the source code and push it to Amazon ECR. Which action should be used as the build provider?

A.AWS CodeDeploy
B.AWS CodeCommit
C.Amazon ECS
D.AWS CodeBuild
AnswerD

AWS CodeBuild natively builds Docker images and pushes them to Amazon ECR, satisfying the pipeline's build-and-push requirement. It integrates directly with CodePipeline as a build action, executing buildspec commands that run docker build and docker push against ECR within the pipeline's S3-sourced workflow, without needing external compute or custom orchestration.

Why this answer

AWS CodeBuild is the correct build provider because it is a fully managed continuous integration service that can compile source code, run tests, and produce Docker images. It integrates natively with CodePipeline and Amazon ECR, allowing you to define a buildspec.yml file that uses the 'aws ecr get-login-password' command and 'docker build/push' commands to build and push the image directly to ECR.

Exam trap

The trap here is that candidates often confuse Amazon ECS (a container runtime service) with a build service, or assume CodeDeploy can handle image building because it supports ECS deployments, but neither service can compile source code or push images to ECR.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a deployment service that automates application deployments to EC2, Lambda, or on-premises instances; it does not build Docker images or push them to ECR. Option B is wrong because AWS CodeCommit is a source control service for hosting Git repositories; it cannot perform build actions or push images to ECR. Option C is wrong because Amazon ECS is a container orchestration service that runs containers on a cluster; it does not build images or act as a build provider in CodePipeline.

60
MCQeasy

A company's security team wants to ensure that all S3 buckets are encrypted at rest. They have thousands of existing buckets. Which approach should a Solutions Architect use to identify noncompliant buckets?

A.Use AWS Trusted Advisor to check bucket encryption.
B.Analyze AWS CloudTrail logs for PutBucketEncryption API calls.
C.Enable S3 Inventory to list all objects and their encryption status.
D.Create an AWS Config rule to evaluate S3 bucket encryption settings.
AnswerD

AWS Config continuously evaluates resource configurations against desired settings, so an S3 bucket-encryption rule flags every noncompliant bucket across thousands of existing accounts without manual auditing. This satisfies the requirement to identify, not remediate, noncompliant buckets at scale.

Why this answer

AWS Config provides managed rules such as 's3-bucket-server-side-encryption-enabled' that continuously evaluate the encryption configuration of every S3 bucket in the account and flag noncompliant resources. Because it works at the bucket-configuration level and scales across thousands of buckets, it is the correct tool for identifying which buckets lack default encryption.

Exam trap

SAP-C02 often tests the distinction between detective services — candidates confuse CloudTrail (API activity logging), Trusted Advisor (best-practice checks), S3 Inventory (object listing), and AWS Config (resource configuration compliance evaluation).

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor only surfaces a limited set of security checks (and the S3 bucket permissions check), not a per-bucket encryption compliance evaluation across thousands of buckets. Option B is wrong because CloudTrail logs only record PutBucketEncryption API calls that were made — it cannot tell you the current encryption state of buckets that were never explicitly configured or that were created before logging was enabled. Option C is wrong because S3 Inventory reports object metadata (including per-object encryption status) but does not evaluate bucket-level default encryption settings and is not a compliance-evaluation service.

61
MCQeasy

A company wants to monitor CPU utilization of their EC2 instances and receive an alert when utilization exceeds 80% for 10 minutes. Which AWS service should be used?

A.Amazon Inspector
B.AWS Config
C.Amazon CloudWatch Alarms
D.AWS CloudTrail
AnswerC

CloudWatch Alarms evaluates metric thresholds over defined periods and triggers actions when breached. Setting a CPUUtilization alarm above 80% with a ten-minute evaluation period matches the stem's duration and threshold constraints exactly, which raw metrics or dashboards alone cannot enforce.

Why this answer

CloudWatch Alarms can monitor metrics and trigger actions when a threshold is breached.

62
Multi-Selectmedium

A company is designing a new application that will run on Amazon ECS with Fargate. They need to store configuration data and secrets securely. Which services should they use? (Choose TWO.)

Select 2 answers
A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon S3
D.AWS CloudFormation
E.AWS KMS
AnswersA, B

Designed for secrets management.

Why this answer

AWS Secrets Manager is correct because it is purpose-built for securely storing, rotating, and managing secrets such as database credentials and API keys throughout their lifecycle. It integrates natively with Amazon ECS to inject secrets into containers at runtime without exposing them in the task definition or environment variables, meeting the requirement for secure configuration data and secrets.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secure strings) with AWS Secrets Manager, but the exam expects you to know that Secrets Manager is the preferred service for secrets that require automatic rotation, while Parameter Store is better for configuration data that does not need rotation, and both are correct in this question because the requirement is to store both configuration data and secrets securely.

63
MCQmedium

A media company is designing a new video transcoding pipeline on AWS. Raw video files (up to 10 GB each) are uploaded by users to an S3 bucket. Each upload must be transcoded into multiple formats (MP4, WebM, HLS) and stored in another S3 bucket. The transcoding job can take up to 30 minutes per file. The company needs a solution that is cost-effective and can handle hundreds of concurrent uploads. The operations team wants to minimize maintenance. Which solution should a Solutions Architect recommend?

A.Use S3 event notifications to invoke an AWS Lambda function that performs transcoding and stores results.
B.Use S3 event notifications to invoke a Lambda function that submits a job to AWS Elemental MediaConvert for each file.
C.Use an Auto Scaling group of EC2 instances with transcoding software installed. Configure S3 events to send messages to an SQS queue, which the instances poll.
D.Use S3 event notifications to trigger an AWS Step Functions workflow that runs an ECS Fargate task for each file.
AnswerB

MediaConvert is a managed transcoding service handling large files and multiple output formats, so it satisfies the cost-effective, low-maintenance requirement. S3 event notifications trigger Lambda per upload, which submits the job, scaling automatically to hundreds of concurrent uploads without servers to manage.

Why this answer

AWS Elemental MediaConvert is a fully managed, serverless media transcoding service designed for high-volume, multi-format video processing. Using S3 event notifications to invoke a Lambda function that submits a job to MediaConvert offloads the transcoding complexity, scales automatically to handle hundreds of concurrent uploads, and requires no infrastructure maintenance, making it both cost-effective and operationally minimal.

Exam trap

The trap here is that candidates may choose Option A (Lambda) without considering the 15-minute timeout limit, or Option D (Step Functions + Fargate) because it sounds serverless, but they overlook that MediaConvert is the fully managed, cost-optimized service specifically designed for this use case.

How to eliminate wrong answers

Option A is wrong because AWS Lambda has a maximum execution timeout of 15 minutes, but the transcoding job can take up to 30 minutes per file, so the Lambda function would time out before completion. Option C is wrong because managing an Auto Scaling group of EC2 instances with transcoding software introduces significant maintenance overhead (patching, scaling policies, instance health) and is not cost-effective for sporadic or bursty workloads compared to a serverless service. Option D is wrong while technically possible, using ECS Fargate tasks orchestrated by Step Functions adds unnecessary complexity and cost compared to MediaConvert, which is purpose-built for video transcoding and natively integrates with S3; Fargate requires custom container images, task definitions, and more operational overhead.

64
Multi-Selecthard

A company is migrating a large number of on-premises VMs to AWS. They need to assess the current environment and track migration progress. Which THREE AWS services should be used together?

Select 3 answers
A.AWS Server Migration Service (SMS)
B.AWS Application Migration Service (MGN)
C.AWS Migration Hub
D.AWS Database Migration Service (DMS)
E.AWS Application Discovery Service
AnswersB, C, E

AWS Application Migration Service replicates source servers block-level into AWS and launches them as EC2 instances, satisfying the migration-execution requirement. It also feeds replication status into Migration Hub, letting the company track progress across the VM fleet.

Why this answer

AWS Application Discovery Service (E) is correct because it performs the assessment phase by collecting on-premises server inventory, configuration, and utilization data (via the Discovery Agent or agentless VMware collector) to build the baseline needed for migration planning. AWS Application Migration Service (B) is correct because it is the recommended lift-and-shift service that replicates on-premises VMs (block-level replication using the AWS Replication Agent) and launches them on AWS as EC2 instances, handling the actual migration of the large VM fleet. AWS Migration Hub (C) is correct because it provides a single console to track migration status and progress across services such as MGN and DMS, giving the centralized progress-tracking capability the company requires.

AWS Server Migration Service (A) is not appropriate because it is a legacy service being deprecated in favor of MGN for VM migrations. AWS Database Migration Service (D) is not appropriate because it targets database migrations specifically, not the general VM migration and assessment scenario described.

65
MCQhard

A company has a multi-account AWS environment and uses AWS Organizations. The security team wants to automatically remediate non-compliant resources, such as S3 buckets that are publicly accessible. Which design should they implement?

A.Use Amazon Inspector to scan for public buckets.
B.Use an SCP to deny making buckets public.
C.Use AWS Config rules to detect public buckets and trigger an AWS Lambda function to make them private.
D.Use AWS CloudTrail to send alerts when a bucket becomes public.
AnswerC

AWS Config rules detect publicly accessible S3 buckets and can invoke an AWS Lambda function as a remediation action, automatically making them private. This provides continuous detection and automated response across all accounts in the organisation.

Why this answer

AWS Config rules can continuously evaluate S3 bucket configurations against a custom or managed rule (e.g., 's3-bucket-public-read-prohibited'). When a bucket is detected as publicly accessible, the rule can invoke an AWS Lambda function via an Amazon CloudWatch Events event to automatically apply a bucket policy that removes public access, achieving automated remediation.

Exam trap

The trap here is that candidates often confuse preventive controls (SCPs) with detective and corrective controls (AWS Config + Lambda), assuming SCPs can automatically fix existing non-compliant resources, when in reality SCPs only block future API actions and do not remediate current state.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is designed for vulnerability management and network accessibility assessments of EC2 instances, containers, and Lambda functions, not for scanning S3 bucket public access configurations. Option B is wrong because Service Control Policies (SCPs) can only deny or allow API actions at the account level (e.g., s3:PutBucketPolicy), but they cannot remediate already-public buckets; they prevent future changes but do not fix existing non-compliant resources. Option D is wrong because AWS CloudTrail logs API calls and can send alerts via CloudWatch alarms when a bucket becomes public, but it does not provide automated remediation; it only notifies, leaving the security team to manually fix the issue.

66
MCQhard

During an on-premises to AWS migration using AWS MGN (Application Migration Service), the replication is stuck at 99% for the last few GB. The source server is a Linux database server with a large InnoDB redo log. What is the most likely cause?

A.High disk I/O on the source server
B.The source server needs reboot after MGN agent installation
C.Insufficient network bandwidth between source and AWS
D.Continuous writes to the database redo logs preventing final sync
AnswerD

Continuous InnoDB redo log writes mean the source volume never reaches a quiescent state, so MGN's final sync cannot converge — each pass replicates new blocks faster than they drain. The 99% stall reflects this ongoing delta, not a network or staging-area fault. Quiescing the database or stopping writes lets the final cutover complete.

Why this answer

AWS MGN uses changed block tracking (CBT) to replicate changed blocks. Large InnoDB redo logs are continuously written, causing constant changes and preventing final sync. Option A (High disk I/O) can slow replication but would not cause a stall at exactly 99%.

Option B (source server reboot) is not required after agent installation and would reset replication, not stall at 99%. Option C (insufficient network bandwidth) would affect all stages, not just final sync. Therefore, continuous writes to the redo logs (Option D) is the most likely cause.

67
MCQmedium

A company uses Amazon DynamoDB as its primary database. The operations team is seeing increased read latency during peak hours. The table has a provisioned read capacity of 1000 RCU, but CloudWatch metrics show that consumed read capacity frequently reaches 1000 RCU. The application uses eventually consistent reads. What is the MOST cost-effective way to reduce read latency?

A.Switch to strongly consistent reads to improve consistency.
B.Enable DynamoDB Accelerator (DAX) to cache frequently read items.
C.Create a global secondary index (GSI) on the table to offload reads.
D.Increase the provisioned read capacity to 2000 RCU.
E.Use Amazon ElastiCache for Memcached as a read cache.
AnswerB

DAX sits in front of DynamoDB and serves eventually consistent reads from an in-memory cache, absorbing repeated item reads so they bypass the table entirely. This reduces latency during peaks without raising provisioned read capacity, keeping cost low.

Why this answer

DAX is an in-memory cache purpose-built for DynamoDB that sits in front of the table and serves eventually consistent reads with microsecond latency, offloading read traffic from the table. Since the application already uses eventually consistent reads and the table is at its RCU ceiling during peaks, caching frequently read items in DAX reduces consumed RCU and latency without over-provisioning capacity. It is the most cost-effective fix because it addresses the root cause (repeated reads of hot items) rather than adding raw capacity.

Exam trap

SAP-C02 often tests whether candidates reflexively choose 'increase capacity' for latency problems — the trap is recognizing that caching (DAX) is more cost-effective than over-provisioning when reads are repetitive and eventually consistent.

How to eliminate wrong answers

Option A is wrong because switching to strongly consistent reads doubles RCU consumption and increases latency — the opposite of the goal. Option C is wrong because a GSI does not offload reads from the base table; it adds another read path that itself consumes RCU and only helps if queries can be served by different partition/sort keys. Option D is wrong because doubling RCU to 2000 addresses capacity but does not reduce latency for hot-item reads and costs more than caching.

Option E is wrong because ElastiCache for Memcached requires application-side cache logic, invalidation handling, and does not integrate natively with DynamoDB APIs like DAX does.

68
MCQmedium

A company is moving a legacy application that uses a shared file system to AWS. The application requires POSIX-compliant file storage that can be accessed by multiple EC2 instances simultaneously. Which AWS storage service should they use?

A.Amazon FSx for Windows File Server
B.Amazon EFS
C.Amazon EBS with Multi-Attach
D.Amazon S3
AnswerB

Amazon EFS provides a POSIX-compliant, shared NFSv4 file system that multiple EC2 instances can mount concurrently across Availability Zones, satisfying the simultaneous multi-instance access requirement. Unlike EBS, which attaches to a single instance, EFS is purpose-built for shared file workloads, making it the appropriate fit for this legacy application.

Why this answer

(Amazon EFS) is correct because it provides a scalable, POSIX-compliant NFS file system that can be accessed by multiple EC2 instances simultaneously. Option A (Amazon FSx for Windows File Server) uses SMB protocol and is not POSIX-compliant. Option C (Amazon EBS with Multi-Attach) only supports a limited number of instances and has specific constraints, and it is not a fully managed shared file system.

Option D (Amazon S3) is object storage and does not provide POSIX compliance.

69
MCQmedium

Refer to the exhibit. An administrator runs this command and sees the output. Which statement about the accounts is correct?

A.The Suspended account was invited to the organization.
B.The Production account is the management account.
C.The Suspended account cannot be used until it is reactivated.
D.The Management account was created directly.
AnswerC

A suspended account is disabled at the directory level, so authentication attempts fail until an administrator reactivates it. This satisfies the stem's constraint that the account's current state determines usability: suspension blocks sign-in entirely, unlike a locked or expired-password state, which the user can often resolve themselves.

Why this answer

The command output shows the account status as 'SUSPENDED'. In AWS Organizations, a suspended account cannot be used for any AWS operations until it is reactivated by the management account. This is a hard state enforced by the service, regardless of how the account was added to the organization.

Exam trap

The trap here is that candidates often confuse account status (SUSPENDED) with the method of account creation (invited vs. created), leading them to incorrectly infer that a suspended account must have been invited, when in fact suspension is independent of how the account joined the organization.

How to eliminate wrong answers

Option A is wrong because a suspended account is not necessarily one that was invited; it could have been created directly or invited and then suspended. The status alone does not indicate the invitation method. Option B is wrong because the 'Production' account is listed as a member account (not the management account), as the management account is the one that initiated the organization and is not shown in the list of member accounts.

Option D is wrong because the management account is the original account that created the organization; it is not 'created directly' within the organization — it is the root account that already existed before the organization was formed.

70
MCQmedium

A company has a centralized networking team that manages a shared VPC with multiple AWS Transit Gateway attachments. Application teams create VPCs in separate AWS accounts and want to connect to the shared VPC. The networking team needs to ensure that only authorized VPCs can connect to the shared VPC. What is the MOST secure and scalable way to manage this?

A.Use a VPN connection from each application VPC to the shared VPC.
B.Use AWS Resource Access Manager to share the Transit Gateway with the application accounts.
C.Use VPC peering between the shared VPC and each application VPC.
D.Create IAM roles in each application account that allow the networking team to create VPC attachments.
AnswerB

AWS Resource Access Manager shares the Transit Gateway with specific application accounts, so only those accounts can create attachments. This satisfies the requirement that only authorised VPCs connect, and scales without manual peering or per-VPC approval workflows.

Why this answer

AWS Resource Access Manager (RAM) allows the centralized networking team to share the Transit Gateway with specific application accounts, enabling authorized VPCs to create attachments without exposing the resource to all accounts. This approach is secure because it uses resource-based policies to grant access only to designated accounts, and scalable because it avoids the administrative overhead of managing individual VPNs or VPC peering connections as the number of application VPCs grows.

Exam trap

The trap here is that candidates often confuse IAM permissions (Option D) with resource-based sharing via RAM, thinking that granting IAM roles to create attachments is sufficient, but RAM provides explicit authorization at the resource level, which is more secure and scalable for cross-account access.

How to eliminate wrong answers

Option A is wrong because using a VPN connection from each application VPC to the shared VPC introduces unnecessary complexity, latency, and bandwidth limitations compared to using a Transit Gateway, and it does not scale well as the number of VPCs increases. Option C is wrong because VPC peering requires a one-to-one connection between each application VPC and the shared VPC, which does not scale and creates a mesh of connections that is difficult to manage, and it also does not provide centralized routing or transitive connectivity. Option D is wrong because creating IAM roles in each application account that allow the networking team to create VPC attachments does not control which VPCs can connect; it only grants permission to create attachments, but any VPC in the application account could potentially attach, and it does not enforce authorization at the resource level like RAM does.

71
MCQhard

A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that when a new member account is added, the required IAM role is automatically created with a trust policy that allows the security account to assume it. The solution must minimize manual steps and work across all current and future accounts. Which approach should be used?

A.Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack set that creates the IAM role in all accounts in the organization, and configure automatic deployment to new accounts.
B.Use AWS Resource Access Manager to share an IAM role from the security account with all member accounts.
C.Implement a solution using AWS Service Catalog to share a portfolio containing the IAM role with all accounts, and require users to provision it manually.
D.Create an IAM role in each member account manually and use an AWS Lambda function triggered by AWS Organizations events to create the role in new accounts.
AnswerA

CloudFormation StackSets with service-managed permissions integrate with AWS Organizations to deploy stacks across all accounts. You can enable automatic deployment so that when a new account is added to the organization, the stack set is automatically deployed, creating the IAM role. This minimizes manual effort and ensures consistency.

Why this answer

CloudFormation StackSets with service-managed permissions are designed to deploy resources across an organization. By enabling automatic deployment, new accounts automatically receive the stack set, creating the required IAM role. This approach is scalable, requires no custom code, and ensures consistent configuration across all accounts.

Exam trap

The trap here is assuming that AWS RAM can share IAM roles or that manual or custom solutions are needed, when StackSets with service-managed permissions and automatic deployment is the native, low-effort solution.

72
MCQmedium

A company is migrating a monolithic application to microservices on AWS. They have identified that some services require high-throughput, low-latency data sharing. Which AWS service should they use for this purpose?

A.Amazon ElastiCache for Redis
B.Amazon RDS
C.Amazon S3
D.AWS Glue
AnswerA

ElastiCache for Redis is an in-memory store delivering sub-millisecond reads and writes at high throughput, which suits services needing fast shared data access. It removes database round trips for frequently accessed data, satisfying the low-latency, high-throughput requirement.

Why this answer

Amazon ElastiCache for Redis is an in-memory data store that provides microsecond latency and high throughput, making it ideal for data sharing between microservices. Option A is correct. Option B (Amazon RDS) is a relational database, not optimized for low-latency data sharing.

Option C (Amazon S3) is object storage with higher latency. Option D (AWS Glue) is an ETL service, not suitable for real-time data sharing.

73
Multi-Selectmedium

A company is designing a new serverless application using AWS Lambda. The application needs to access an Amazon RDS for PostgreSQL database. The database credentials must be rotated automatically every 30 days. Which THREE steps should the company take to securely manage the credentials? (Choose three.)

Select 3 answers
A.Store the database credentials in AWS Secrets Manager.
B.Configure automatic rotation for the secret in AWS Secrets Manager.
C.Grant the Lambda function's IAM role permission to access the RDS database directly.
D.Write custom rotation logic in the Lambda function to change the database password.
E.Grant the Lambda function's IAM role permission to retrieve the secret from Secrets Manager.
AnswersA, B, E

Secrets Manager is purpose-built for storing and retrieving database credentials securely, satisfying the 30-day rotation requirement natively. Unlike Lambda environment variables or Parameter Store, it integrates rotation scheduling and encryption, so credentials never reside in code or configuration files.

Why this answer

Option A is correct because AWS Secrets Manager is the managed service designed to store and protect database credentials, and it natively supports Amazon RDS for PostgreSQL as a rotation target. Option B is correct because Secrets Manager provides built-in automatic rotation, and configuring rotation with a 30-day schedule satisfies the requirement to rotate credentials every 30 days without custom code. Option E is correct because the Lambda function must have an IAM role policy granting secretsmanager:GetSecretValue (and typically DescribeSecret) on the specific secret so it can retrieve the current credentials at runtime.

Option C is not correct because granting the Lambda execution role direct access to RDS does not manage or rotate credentials, and database authentication still requires valid credentials. Option D is not correct because Secrets Manager already supplies rotation logic for RDS for PostgreSQL, so writing custom rotation logic in the application Lambda function is unnecessary and not a secure credential-management step.

Exam trap

The trap here is that candidates often confuse IAM roles for database access (which is only supported for Amazon RDS with IAM database authentication, not for standard PostgreSQL credentials) with the need to retrieve secrets via IAM permissions, leading them to select Option C instead of Option E.

74
MCQeasy

A company is planning to migrate its on-premises Oracle database to Amazon RDS for Oracle. The database is 2 TB in size and the company has a high-speed network connection to AWS. Which AWS service should the company use to migrate the database with minimal downtime?

A.Amazon S3 Transfer Acceleration
B.AWS Database Migration Service (DMS)
C.AWS Snowball Edge
D.AWS Schema Conversion Tool (SCT)
AnswerB

DMS performs continuous replication from the source Oracle database to RDS for Oracle, keeping the target synchronised until cutover. This satisfies the minimal-downtime constraint, since only a brief final switchover is needed rather than a full offline export and import of the 2 TB dataset.

Why this answer

AWS DMS supports Oracle to RDS for Oracle migration with ongoing replication for minimal downtime. Option A is incorrect because S3 Transfer Acceleration is used for accelerating uploads to S3, not for database migration. Option C is incorrect because Snowball Edge is for offline data transfer and not suitable for databases with minimal downtime.

Option D is incorrect because AWS Schema Conversion Tool (SCT) is used for schema conversion, not data migration.

75
MCQmedium

A company is running a production web application on AWS Auto Scaling EC2 instances behind an Application Load Balancer. Recent deployments have caused intermittent errors. The team wants to implement a deployment strategy that minimizes downtime and allows for quick rollback. Which strategy should they use?

A.Deploy a new version to a single instance, test, then scale out.
B.Use blue/green deployment with a second Auto Scaling group and switch the ALB target group.
C.Perform rolling updates with a single Auto Scaling group, updating a few instances at a time.
D.Use an immutable deployment by launching a new Auto Scaling group and terminating the old one.
AnswerB

Blue/green deployment with a second Auto Scaling group satisfies the zero-downtime and quick-rollback constraints: the new version runs in a parallel environment, and the ALB listener shifts traffic by swapping target groups. Rollback is a single target-group switch back, avoiding the gradual instance replacement and mixed-version window of rolling updates.

Why this answer

Blue/green deployment with a second Auto Scaling group and an ALB target group switch provides near-zero downtime and instant rollback. The green environment runs the new version fully warmed up; once validated, the ALB listener rule is flipped to the green target group. If errors appear, the listener is flipped back to blue in seconds, restoring the previous version without redeploying.

Exam trap

SAP-C02 often tests the distinction between immutable and blue/green — candidates pick immutable because it also launches a new ASG, but immutable replaces instances in the same group without an instant traffic-switch rollback path.

How to eliminate wrong answers

Option A is wrong because testing on a single instance and then scaling out is not a controlled deployment pattern — the new version is not validated under production load, and rollback requires re-deploying the old code across all instances. Option C is wrong because rolling updates with a single Auto Scaling group mix old and new versions during the update, so rollback requires another rolling pass and downtime risk if the new version is broken. Option D is wrong because immutable deployment replaces instances in place within the same Auto Scaling group — it does not provide the instant traffic-switch rollback that blue/green with separate target groups delivers, and it still requires the new fleet to be healthy before old instances are terminated.

Page 1 of 14

Page 2