Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 751–825

984 questions total · 14pages · All types, answers revealed

Page 10

Page 11 of 14

Page 12
751
MCQmedium

A company is migrating a legacy on-premises application to AWS. The application uses a shared file system for user home directories. Which AWS service should the company use to minimize changes to the application while providing scalable, highly available file storage?

A.Amazon FSx for Lustre
B.Amazon EBS
C.Amazon S3
D.Amazon EFS
AnswerD

Amazon EFS provides a POSIX-compliant NFSv4 file system that mounts natively on Linux, so the legacy application's existing file paths and locking semantics remain unchanged. Its managed, multi-AZ design delivers the scalable, highly available shared storage the stem requires, minimising migration effort compared with re-architecting onto object or block storage.

Why this answer

(Amazon EFS) is correct because it provides a scalable, fully managed NFS file system that can be mounted by multiple EC2 instances, minimizing application changes. Option A (FSx for Lustre) is for high-performance computing, not general file sharing. Option B (EBS) is block storage attached to a single instance.

Option C (S3) is object storage, not a file system.

752
Multi-Selecthard

A company is deploying a new application on AWS and wants to implement a least-privilege IAM policy for an EC2 instance that needs to read from an S3 bucket (my-bucket) and write logs to CloudWatch Logs. Which TWO statements should be included in the IAM policy? (Choose two.)

Select 2 answers
A.{"Effect": "Allow", "Action": ["s3:GetObject"], "Resource": "arn:aws:s3:::my-bucket/*"}
B.{"Effect": "Allow", "Action": ["s3:*"], "Resource": "arn:aws:s3:::my-bucket/*"}
C.{"Effect": "Allow", "Action": ["logs:CreateLogStream", "logs:PutLogEvents"], "Resource": "arn:aws:logs:us-east-1:123456789012:log-group:my-log-group:*"}
D.{"Effect": "Allow", "Action": ["logs:PutLogEvents"], "Resource": "*"}
E.{"Effect": "Allow", "Action": ["s3:PutObject"], "Resource": "arn:aws:s3:::my-bucket/*"}
AnswersA, C

Granting s3:GetObject on arn:aws:s3:::my-bucket/* authorises reads of objects within the bucket, matching the least-privilege read requirement. The wildcard covers every object key while excluding bucket-level actions such as s3:ListBucket, so only the access the EC2 instance genuinely needs is permitted.

Why this answer

Option A is correct because it grants only the s3:GetObject action needed to read objects from my-bucket, scoped to the bucket's object ARN arn:aws:s3:::my-bucket/*, which satisfies least privilege for read access. Option C is correct because it grants exactly the CloudWatch Logs actions required to write logs (logs:CreateLogStream and logs:PutLogEvents) and scopes them to the specific log group ARN, avoiding broader permissions. Option B is incorrect because s3:* grants all S3 actions on the bucket, violating least privilege.

Option D is incorrect because logs:PutLogEvents on Resource "*" is overly broad and also omits logs:CreateLogStream needed to create the stream. Option E is incorrect because s3:PutObject grants write access to S3, which the instance does not need since it only reads from the bucket.

Exam trap

The trap is that candidates often include unnecessary permissions (like s3:PutObject) beyond what the stem explicitly requires, failing the least-privilege requirement. Always scope permissions to only the actions and resources stated.

753
MCQmedium

A company is designing a new data lake on Amazon S3. They need to query the data using standard SQL and expect to run complex queries that scan large datasets. The query performance should be optimized to minimize data scanned. Which service should they use?

A.Amazon Redshift Spectrum
B.Amazon EMR
C.Amazon Athena
D.Amazon QuickSight
AnswerC

Athena queries S3 data using standard SQL and is serverless, and its columnar Parquet support with partition pruning minimises bytes scanned. This directly satisfies the requirement for complex SQL queries over large datasets with optimised scan performance.

Why this answer

Amazon Athena is a serverless interactive query service that uses standard SQL to analyze data directly in Amazon S3. It is optimized for querying large datasets with a pay-per-query model, and it automatically minimizes data scanned by leveraging features like columnar data formats (Parquet, ORC), partitioning, and compression to reduce the amount of data read per query.

Exam trap

The trap here is that candidates often confuse Amazon Redshift Spectrum with Athena because both query S3 data, but Redshift Spectrum requires a running Redshift cluster and is not serverless, while Athena is fully serverless and designed specifically for minimizing data scanned in a data lake scenario.

How to eliminate wrong answers

Option A is wrong because Amazon Redshift Spectrum is an extension of Amazon Redshift that allows querying data in S3, but it requires an active Redshift cluster and is designed for hybrid queries that combine local and external data, not for a standalone data lake query service with minimal data scanned. Option B is wrong because Amazon EMR is a managed big data platform that supports frameworks like Apache Spark and Hive, but it requires provisioning and managing clusters, and its primary focus is not on minimizing data scanned for ad-hoc SQL queries; it is more suited for complex ETL and processing jobs. Option D is wrong because Amazon QuickSight is a business intelligence (BI) and visualization service, not a SQL query engine for scanning large datasets; it relies on underlying data sources like Athena or Redshift for query execution.

754
MCQmedium

A company is migrating a legacy on-premises application to AWS. The application requires a relational database with Oracle compatibility and the ability to run read replicas across multiple Availability Zones. Which AWS service should the company use to minimize migration effort?

A.Amazon RDS for MySQL
B.Amazon EC2 with self-managed Oracle
C.Amazon DynamoDB
D.Amazon RDS for Oracle
AnswerD

Amazon RDS for Oracle runs the Oracle engine natively, so the existing schema, PL/SQL and drivers migrate unchanged. Multi-AZ deployments provide synchronous standby across Availability Zones, and read replicas can be added, minimising migration effort.

Why this answer

Amazon RDS for Oracle provides a managed Oracle database with Oracle compatibility and supports read replicas across multiple Availability Zones, minimizing migration effort. Option A is wrong because Amazon RDS for MySQL does not offer Oracle compatibility. Option B is wrong because Amazon EC2 with self-managed Oracle requires more operational overhead.

Option C is wrong because Amazon DynamoDB is a NoSQL database, not relational.

755
MCQhard

A company is using t3.large instances in an Auto Scaling group. They want to launch instances that support both x86_64 and arm64 architectures. Based on the exhibit, can they meet this requirement with t3.large?

A.No, because t3.large instances only support x86_64 architecture.
B.Yes, because t3.large supports both architectures.
C.No, because t3.large is not a current generation instance type.
D.Yes, but only if they use a custom AMI that supports both architectures.
AnswerA

T3 instances are exclusively x86_64; arm64 requires Graviton-based families such as t4g, m6g or c7g. Since the stem demands a single instance type supporting both architectures, t3.large cannot satisfy it — no x86 instance does. The requirement is therefore unmet with t3.large.

Why this answer

T3.large instances only support the x86_64 architecture. They do not support arm64. Therefore, the company cannot meet the requirement of supporting both x86_64 and arm64 architectures with t3.large instances.

Options B and D are incorrect because t3.large does not support arm64, and a custom AMI cannot add architecture support beyond what the instance type offers. Option C is incorrect because t3.large is a current generation instance type, but that is not relevant to the architecture support limitation.

756
MCQhard

A financial services company runs a critical application on Amazon EC2 instances in an Auto Scaling group across multiple Availability Zones. The application uses an Amazon RDS for MySQL database with Multi-AZ deployment. The company has a recovery time objective (RTO) of 15 minutes and a recovery point objective (RPO) of 1 hour for the database. During a recent disaster recovery drill, the solutions architect simulated an Availability Zone failure by terminating all EC2 instances and the primary RDS instance in one AZ. The Auto Scaling group launched new instances in the other AZ, and the RDS Multi-AZ failover completed in about 2 minutes. However, the application remained unavailable for 30 minutes because the new EC2 instances could not connect to the RDS secondary instance. The security groups are configured correctly. The RDS instance is not publicly accessible. What is the MOST likely cause of the connectivity issue?

A.The security group for the EC2 instances does not allow outbound traffic to the RDS instance.
B.The RDS Multi-AZ failover took longer than expected, exceeding the RTO.
C.The RDS endpoint DNS record did not update to point to the new primary.
D.The application is using a hardcoded IP address or an endpoint that points to the old primary RDS instance instead of the RDS DNS name.
AnswerD

The application is likely using a hardcoded IP address or an endpoint pointing to the old primary RDS instance instead of the RDS DNS name, which fails after failover. This is the most likely cause. Option D is correct.

Why this answer

The RDS Multi-AZ failover promotes the standby to primary, changing the underlying IP address. If the application uses a hardcoded IP address or an endpoint that points to the old primary, it will fail to connect after failover. The correct approach is to use the RDS DNS name (CNAME) which automatically resolves to the current primary.

Option A is incorrect because the stem states the security groups are correctly configured. Option B is incorrect because the failover completed in about 2 minutes, which is within normal Multi-AZ failover time (1-2 minutes). Option C is incorrect because the RDS endpoint DNS record updates quickly (within seconds) after a failover.

757
Drag & Dropmedium

Drag and drop the steps to recover an Amazon RDS Multi-AZ DB instance after a primary instance failure in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First identify failure, wait for failover, verify promotion, update endpoints, then investigate.

758
MCQmedium

A company runs a web application on Amazon EC2 instances in an Auto Scaling group. The application uses an Amazon RDS for MySQL database. The company wants to improve the performance of read-heavy workloads and reduce the load on the primary database instance. The application currently connects to the primary instance for all read and write operations. The solutions architect needs to implement a solution that requires minimal changes to the application code. Which approach should the solutions architect recommend?

A.Migrate the database to Amazon Aurora MySQL and enable Aurora Auto Scaling for read replicas.
B.Create an RDS read replica and configure the application to direct read queries to the read replica endpoint.
C.Enable Multi-AZ deployment for the RDS instance to automatically offload read traffic to the standby instance.
D.Use Amazon ElastiCache for Redis to cache the results of frequent read queries.
AnswerB

RDS read replicas are designed to offload read traffic from the primary instance. By creating a read replica and updating the application to send read queries to the replica's endpoint, you can distribute the read load and improve performance. This requires minimal code changes, typically just changing the connection string for read operations. It is a standard and effective solution for read-heavy workloads.

Why this answer

Creating an RDS read replica and directing read queries to it is the most straightforward way to offload read traffic from the primary database. It requires only a change to the application's connection configuration for read operations, with no schema changes or major code modifications. This improves read performance and reduces load on the primary instance, addressing the company's needs effectively.

Exam trap

The trap here is assuming that Multi-AZ deployments can be used for read scaling, when in fact the standby instance is not accessible for read operations.

759
MCQhard

A company is migrating a large-scale data analytics workload from on-premises to AWS. The workload uses Apache Spark to process terabytes of data daily. The company wants to use Amazon EMR for the migration. The current on-premises cluster has 20 nodes, each with 64 vCPUs and 256 GB of RAM. The data is stored in HDFS on the cluster. The company wants to minimize costs while maintaining performance. The data sources are in Amazon S3 and on-premises. The company has set up a dedicated AWS Direct Connect connection. Which EMR configuration should the company use?

A.Use EMR with EC2 instances of similar size (e.g., r5.8xlarge) and store data in Amazon S3 using EMRFS.
B.Use EMR with Graviton-based instances and store intermediate data in HDFS on EBS volumes.
C.Use EMR with a mix of On-Demand and Spot Instances, and use S3 for all data storage.
D.Use AWS Glue to run the Spark jobs with the same resource configuration.
AnswerA

Correct. Using EMR with r5.8xlarge instances closely matches the on-premises resources (64 vCPUs, 256 GB RAM per node) and using S3 with EMRFS eliminates HDFS overhead, reducing costs and management effort while maintaining performance via Direct Connect.

Why this answer

It directly maps the on-premises cluster capacity to equivalent EC2 instances (r5.8xlarge provides 32 vCPUs and 256 GB RAM, so two per node would match the 64 vCPUs and 256 GB RAM). Storing data in S3 via EMRFS eliminates HDFS management and leverages S3 durability and scalability. This configuration minimizes costs by avoiding over-provisioning and using S3 for cost-effective storage, while maintaining performance through Direct Connect for data transfer.

Using EMR with similar instance sizes ensures the Spark jobs run efficiently without reconfiguration. Other options introduce unnecessary complexity or higher costs: Option B uses Graviton-based instances which may require code changes, and storing intermediate data on EBS volumes incurs additional costs and management overhead. Option C mixes On-Demand and Spot Instances, which can reduce costs but still requires cluster management and does not align with the goal of minimizing costs while maintaining performance as effectively as option A.

Option D uses AWS Glue, which is a fully managed service but may not provide the same level of control or performance for large-scale workloads; it may also be more expensive for sustained high-volume processing compared to EMR with reserved capacity.

760
MCQmedium

A company is using AWS Organizations with a hierarchical OU structure. The security team wants to enforce that any new account created in the organization automatically inherits a baseline set of AWS Config rules and a VPC with a default CIDR block. What is the MOST efficient way to achieve this?

A.Use AWS CloudFormation StackSets with a stack that creates the VPC and Config rules, and trigger it via an SCP.
B.Create an SCP that denies creation of resources unless they comply with the baseline.
C.Enable AWS Control Tower and configure Account Factory to provision accounts with a baseline blueprint containing the VPC and Config rules.
D.Use AWS Config conformance packs with YAML templates deployed to all accounts via an SCP.
AnswerC

Control Tower Account Factory provisions new accounts through a baseline blueprint, automatically applying the VPC with the specified CIDR and the Config rules. This satisfies automatic inheritance for every new account without custom orchestration per account.

Why this answer

AWS Control Tower provides a managed service that automates the setup of a multi-account environment based on AWS best practices. By enabling Control Tower and configuring Account Factory, new accounts are automatically provisioned with a baseline blueprint that includes the desired VPC and AWS Config rules, ensuring consistent governance without manual intervention or custom orchestration.

Exam trap

The trap here is that candidates often confuse SCPs with automation tools, thinking they can enforce resource creation or trigger deployments, when in reality SCPs only restrict permissions and cannot provision resources or invoke AWS services.

How to eliminate wrong answers

Option A is wrong because SCPs cannot trigger AWS CloudFormation StackSets; SCPs are permission policies that control which AWS API actions are allowed, not event-driven automation triggers. Option B is wrong because an SCP that denies creation of resources unless they comply with a baseline would be impractical to enforce at the point of account creation and does not proactively create the required VPC and Config rules. Option D is wrong because AWS Config conformance packs are deployed to existing accounts to evaluate compliance, not to provision resources like a VPC, and SCPs cannot deploy conformance packs.

761
MCQmedium

A company is designing a new microservices architecture on AWS. They need to ensure that services can communicate asynchronously without direct coupling. Which AWS service should they use to decouple the services?

A.AWS Step Functions
B.Amazon SNS
C.Amazon SQS
D.Amazon Kinesis
AnswerC

Amazon SQS provides fully managed message queues that buffer messages between producers and consumers, so microservices publish without waiting for a response. This satisfies the asynchronous, loosely coupled communication constraint: services interact only through the queue, tolerating consumer failures and scaling independently without direct invocation or endpoint dependencies.

Why this answer

Amazon SQS is the correct choice because it provides a fully managed message queue that enables asynchronous communication between microservices, allowing them to send, store, and receive messages without direct coupling. Services can poll or receive messages from the queue at their own pace, ensuring that the producer and consumer are decoupled and can operate independently, even if one is temporarily unavailable.

Exam trap

The trap here is that candidates often confuse Amazon SNS (pub/sub) with Amazon SQS (queue), but SNS pushes messages to subscribers and does not provide a buffer for asynchronous decoupling, whereas SQS allows services to pull messages at their own pace, which is the key requirement for decoupling.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a serverless orchestration service that coordinates multiple AWS services into a workflow, but it does not inherently decouple services asynchronously; it tightly couples the execution flow and is not a message queue. Option B is wrong because Amazon SNS is a pub/sub messaging service that pushes messages to subscribers, which still requires subscribers to be active and does not provide a buffer for asynchronous decoupling like a queue does. Option D is wrong because Amazon Kinesis is designed for real-time streaming data ingestion and processing, not for simple asynchronous decoupling of microservices; it introduces complexity with shards and retention periods that are unnecessary for basic decoupling needs.

762
Multi-Selecthard

A company is migrating a large e-commerce platform to AWS using a lift-and-shift approach. The application consists of a web tier, application tier, and a MySQL database. After migration, users report intermittent slow page loads. The operations team notices high CPU utilization on the application tier instances. Which THREE steps should the team take to address the performance issues?

Select 3 answers
A.Implement Amazon CloudFront to cache static content and reduce load on the web tier.
B.Create an Amazon RDS read replica for the MySQL database and route read queries to it.
C.Replace the current application tier instances with larger instance types.
D.Move the MySQL database to Amazon RDS for MySQL and enable Multi-AZ deployment.
E.Configure an Auto Scaling group for the application tier to scale based on CPU utilization.
AnswersA, B, E

Reduces requests to the origin servers.

Why this answer

Implementing Amazon CloudFront to cache static content offloads requests from the web tier, reducing the number of dynamic requests that reach the application tier. This directly lowers CPU utilization on the application instances by minimizing the processing overhead for repeated static asset deliveries.

Exam trap

The trap here is that candidates often confuse database-level solutions (like Multi-AZ or read replicas) with application-tier CPU issues, or they default to vertical scaling (larger instances) instead of recognizing the need for horizontal scaling and content caching.

763
Multi-Selecthard

A financial services firm is migrating a latency-sensitive trading analytics workload to AWS. The workload runs on Amazon EC2 instances in a single VPC and requires network throughput of up to 100 Gbps per instance, consistent sub-100-microsecond inter-instance latency, and the ability to place instances close together to minimize hops. The firm also wants the instances to communicate without traversing the public internet. (Choose two.)

Select 2 answers
A.Configure a VPC peering connection between the workload VPC and a shared services VPC in another Region
B.Deploy the instances into a spread placement group across three Availability Zones
C.Attach an Elastic Fabric Adapter (EFA) to the instances and enable it for the application
D.Enable AWS Global Accelerator with endpoint groups pointing to the instances in multiple Regions
E.Launch the instances into a cluster placement group within a single Availability Zone
AnswersC, E

EFA provides a network interface that supports OS-bypass for tightly coupled HPC and analytics workloads, delivering lower and more consistent latency than standard TCP paths. It is designed for the high per-instance throughput the workload demands and works with cluster placement groups to keep traffic private and within a single Availability Zone.

Why this answer

Low-latency, high-bandwidth east-west traffic is achieved by combining a cluster placement group, which minimizes physical distance and hops within one Availability Zone, with Elastic Fabric Adapter, which provides OS-bypass networking for tightly coupled workloads. Together they deliver the required per-instance throughput and consistent latency while keeping traffic on the private AWS network.

Exam trap

The trap here is reaching for a global traffic-optimization service for inter-instance latency when the requirement is really about physical placement and the network interface technology inside a single VPC.

764
MCQmedium

A company runs a web application on a single EC2 instance. They want to improve availability and fault tolerance with minimal architectural changes. What should they do?

A.Attach multiple EBS volumes to the instance.
B.Use an Auto Scaling group with a minimum of two instances across two Availability Zones.
C.Create multiple subnets in the same Availability Zone.
D.Upgrade to a larger instance type.
AnswerB

An Auto Scaling group spanning two Availability Zones replaces the single instance with redundant capacity, so an AZ failure no longer takes the application down. This satisfies the fault-tolerance requirement while keeping the same instance-based architecture, avoiding a redesign.

Why this answer

The correct answer is B because using an Auto Scaling group with a minimum of two instances across two Availability Zones provides high availability and fault tolerance by distributing the application across multiple physically separate data centers. If one Availability Zone fails, the other instance continues to serve traffic, and the Auto Scaling group can automatically replace failed instances. This approach requires minimal architectural changes—just moving from a single instance to an Auto Scaling group—and directly addresses the requirements.

Exam trap

SAP-C02 often tests the misconception that adding more resources to a single instance (like multiple EBS volumes or a larger instance type) improves availability, when in fact true fault tolerance requires distributing the workload across multiple Availability Zones.

How to eliminate wrong answers

Option A is wrong because attaching multiple EBS volumes to a single instance does not improve availability; EBS volumes are tied to a single Availability Zone and if the instance fails, the volumes become inaccessible, and the instance remains a single point of failure. Option C is wrong because creating multiple subnets in the same Availability Zone does not provide fault tolerance; all subnets in the same AZ share the same physical infrastructure, so an AZ failure would still take down the application. Option D is wrong because upgrading to a larger instance type only increases capacity, not availability; it still runs on a single instance in a single AZ, so any failure of that instance or AZ results in downtime.

765
Multi-Selecthard

A company is designing a multi-region disaster recovery solution for a critical application running on Amazon EC2. The application uses an Amazon Aurora MySQL database. The RTO is 15 minutes and RPO is 1 minute. Which THREE steps should the solutions architect take to meet these requirements?

Select 3 answers
A.Pre-provision EC2 instances in the DR region with the application code and configuration.
B.Use Route 53 health checks with failover routing policy to direct traffic to the DR region.
C.Configure a cross-region read replica in the DR region and promote it during failover.
D.Take frequent snapshots of the Aurora cluster and copy them to the DR region.
E.Use Amazon Aurora Global Database for replication to the DR region.
AnswersA, B, E

Ensures compute capacity is ready for failover.

Why this answer

Pre-provisioning EC2 instances in the DR region with the application code and configuration ensures that compute capacity is ready to serve traffic immediately upon failover. This eliminates the time needed to launch and configure instances, which is critical for meeting the 15-minute RTO. Without pre-provisioning, the time to spin up and configure instances would likely exceed the RTO.

Exam trap

The trap here is that candidates often confuse cross-region read replicas (which have higher replication lag and slower promotion) with Aurora Global Database (which provides low-latency, fast failover), leading them to select Option C instead of Option E.

766
MCQmedium

A financial services company uses AWS Organizations with 60 accounts. The security team has enabled AWS CloudTrail organization trails in the management account and wants to prevent any member account administrator from disabling CloudTrail logging in their own account. Which solution will meet this requirement with the LEAST operational overhead?

A.Create an AWS CloudFormation StackSet that deploys a CloudTrail trail in every account and configure drift detection to alert when the trail is modified.
B.Create a service control policy in AWS Organizations that denies the cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail actions for all member accounts.
C.Configure an IAM permissions boundary on every IAM role in each member account that excludes the cloudtrail:StopLogging and cloudtrail:DeleteTrail actions.
D.Use AWS Config with a managed rule that detects when a CloudTrail trail is not logging, and trigger an AWS Lambda function to restart logging when the rule is noncompliant.
AnswerB

SCPs set the maximum permissions for accounts in an organization. Denying the actions that stop or delete a trail prevents member account administrators from disabling CloudTrail logging, and because SCPs apply organization-wide, no per-account scripting is required, meeting the least operational overhead requirement.

Why this answer

A service control policy in AWS Organizations denies the CloudTrail actions that stop, delete, or modify a trail, so member account administrators cannot disable logging even if their IAM policies allow those actions. Because SCPs apply at the organization level to all accounts, this is preventive and requires no per-account resources, satisfying both the security and least-overhead requirements.

Exam trap

The trap here is assuming that deploying a trail in each account or using detective controls such as AWS Config is enough, when only an organization-level service control policy can prevent member administrators from stopping logging.

767
Multi-Selecteasy

A company wants to migrate a legacy .NET application to AWS. The application uses Windows authentication and requires a shared file system. Which TWO AWS services should the company use to modernize this application? (Choose two.)

Select 2 answers
A.Amazon FSx for Windows File Server
B.AWS Elastic Beanstalk
C.Amazon S3
D.Amazon EBS
E.AWS Lambda
AnswersA, B

FSx for Windows File Server provides SMB shares with native NTFS permissions and Active Directory integration, so the legacy .NET application keeps Windows authentication and a shared file system without code changes. It satisfies the shared-storage constraint that Linux-based Amazon EFS cannot meet for this workload.

Why this answer

Amazon FSx for Windows File Server (A) is correct because it provides a fully managed native Windows file system supporting SMB protocol, NTFS permissions, and Active Directory integration, which satisfies the application's Windows authentication and shared file system requirements. AWS Elastic Beanstalk (B) is correct because it supports deploying and scaling .NET applications on Windows Server environments (IIS), allowing the legacy app to be modernized with minimal code changes while preserving Windows authentication. Amazon S3 (C) is object storage and does not provide SMB shares or native Windows ACL/authentication semantics needed for a shared file system.

Amazon EBS (D) provides block storage volumes attached to a single EC2 instance, not a shared file system across multiple instances. AWS Lambda (E) is a serverless compute service that does not support Windows authentication or persistent shared file system access in this legacy .NET context.

768
MCQmedium

A media company has 200 AWS accounts in AWS Organizations. The networking team wants to provide each account with a shared VPC subnet from a central networking account. The central networking account owns the VPC and subnets. Workload accounts must be able to launch resources into the shared subnets, but they must not be able to modify the subnet configuration or delete the shared subnets. Which solution meets these requirements?

A.Create a VPC peering connection from each workload VPC to the central VPC, and grant each workload account IAM permissions to create subnets in the central VPC.
B.Use AWS Transit Gateway to attach each workload VPC to the central VPC, and create a route table entry that allows workloads to use the central subnets.
C.Create an AWS Direct Connect connection between each workload account and the central networking account, and configure a private virtual interface for subnet access.
D.Use AWS Resource Access Manager to share the subnets from the networking account to the organization, and attach a service control policy to workload accounts denying ec2:ModifySubnetAttribute and ec2:DeleteSubnet.
AnswerD

AWS RAM is the supported way to share VPC subnets across accounts in an organization. The participant accounts can launch resources into shared subnets but do not own the subnet. Adding a service control policy that denies subnet modification and deletion actions enforces the restriction that workload accounts cannot alter or remove the shared subnets, meeting both requirements.

Why this answer

Sharing subnets from a central VPC is done with AWS Resource Access Manager, which lets participant accounts launch resources into shared subnets while the owner retains control. To prevent participants from modifying or deleting the shared subnets, a service control policy denies the relevant EC2 subnet actions. Together these meet the requirements for shared use with owner-controlled configuration.

Exam trap

The trap here is assuming VPC peering or Transit Gateway grants subnet usage, when only AWS RAM shares subnets and only a service control policy prevents modification.

769
MCQhard

A financial services company is designing a highly available architecture for a critical application on AWS. The application runs on EC2 instances and uses an Oracle database. The database must be resilient to an Availability Zone failure and must have automated failover. Which database solution meets these requirements?

A.Use Amazon Aurora (MySQL-compatible) with Multi-AZ.
B.Use Amazon RDS for Oracle with a Read Replica in another AZ.
C.Deploy Oracle on EC2 in two Availability Zones and use asynchronous replication.
D.Use Amazon RDS for Oracle with Multi-AZ deployment.
AnswerD

RDS for Oracle Multi-AZ maintains a synchronous standby in a different Availability Zone and performs automated failover, so the database survives an AZ failure without manual intervention. This directly satisfies the resilience and automated failover constraints for the Oracle workload.

Why this answer

Amazon RDS for Oracle with Multi-AZ deployment provides automatic failover to a standby instance in a different Availability Zone, meeting the requirements for high availability and automated failover. Option A is incorrect because Amazon Aurora (MySQL-compatible) is not Oracle-compatible, so it cannot replace an Oracle database. Option B is incorrect because a Read Replica in another AZ does not provide automated failover; it is used for read scaling and requires manual promotion.

Option C is incorrect because deploying Oracle on EC2 with asynchronous replication requires manual failover management and does not provide automated failover.

770
MCQmedium

A company is migrating a stateful application that uses local storage on EC2. They want to modernize to a stateless architecture using Amazon EFS for shared storage. What is the best approach to migrate the existing data?

A.Use AWS Fsx for Lustre with S3 as data repository
B.Copy data from local storage to EFS using AWS DataSync during a maintenance window
C.Detach the EBS volume and attach it to the new EC2 instance
D.Create an EBS snapshot and restore it on the new instance
AnswerB

AWS DataSync performs incremental, scheduled or one-off copies over the network with integrity verification, moving the local EC2 data onto EFS during the maintenance window. This satisfies the constraint of preserving existing stateful data while the application becomes stateless.

Why this answer

The best approach is to use AWS DataSync to copy data from the local EC2 instance storage to Amazon EFS during a maintenance window, then reconfigure the application to use EFS as shared storage. Option A (AWS FSx for Lustre with S3) is overcomplicated and not appropriate for a simple shared file system migration to EFS. Option C (detach EBS volume and attach to new instance) is not stateless and does not enable shared access.

Option D (EBS snapshot restore) retains the stateful nature and does not provide shared storage.

771
MCQeasy

A company needs to share a central Amazon S3 bucket containing common data files with multiple accounts in AWS Organizations. Which approach is most secure and scalable?

A.Make the bucket public with read-only access.
B.Generate presigned URLs for each account to access the bucket.
C.Create IAM roles in each account with permissions to assume a role in the central account.
D.Use an S3 bucket policy that grants access to the organization using aws:PrincipalOrgID condition key.
AnswerD

The aws:PrincipalOrgID condition restricts the bucket policy to principals belonging to the specified organisation, so any current or future member account gains access without editing the policy. This scales automatically as accounts are added and avoids wildcard principal exposure.

Why this answer

Using the `aws:PrincipalOrgID` condition key in an S3 bucket policy allows you to grant access to all principals (users, roles) within your AWS Organization without needing to list individual account IDs. This approach is both secure (no public access) and scalable (automatically includes new accounts added to the organization).

Exam trap

The trap here is that candidates often choose Option C (cross-account IAM roles) because it is a familiar pattern, but they overlook the simpler and more scalable centralized policy approach using the Organization ID condition key, which AWS specifically tests for centralized resource sharing scenarios.

How to eliminate wrong answers

Option A is wrong because making the bucket public with read-only access violates the principle of least privilege and exposes the data to any internet user, not just the intended accounts. Option B is wrong because presigned URLs are temporary and require manual generation and distribution for each account, which is not scalable for multiple accounts and does not provide a persistent, policy-based access control mechanism. Option C is wrong because creating IAM roles in each account with permissions to assume a role in the central account introduces cross-account trust complexity and requires managing role ARNs for every account, whereas the Organization ID condition key provides a simpler, centralized policy.

772
MCQhard

A company is migrating a high-traffic web application to AWS. The application currently runs on physical servers in a data center and uses a shared storage area network (SAN) for storing static assets. The company wants to modernize the application to be highly available and scalable across multiple Availability Zones. The static assets are accessed frequently and must be served with low latency globally. Which solution should the company implement?

A.Deploy Amazon EFS in multiple Availability Zones and mount it to EC2 instances.
B.Use Amazon EBS volumes replicated across Availability Zones with Amazon EC2 Auto Scaling.
C.Store static assets in Amazon S3 and use Amazon CloudFront for global content delivery.
D.Use AWS Storage Gateway to cache on-premises SAN data to AWS.
AnswerC

Amazon S3 provides durable, scalable object storage for static assets, and Amazon CloudFront is a global content delivery network that caches content at edge locations, reducing latency for users worldwide. This combination decouples storage from compute, enables high availability across multiple Availability Zones, and supports global low-latency access. It aligns with modernizing the application to be scalable and highly available.

Why this answer

Storing static assets in Amazon S3 and serving them via Amazon CloudFront provides a highly available, scalable, and globally distributed solution. S3 offers durable storage, and CloudFront caches content at edge locations for low latency. Other options do not provide global content delivery or are not suited for static asset serving at scale.

Exam trap

The trap here is assuming that a shared file system like Amazon EFS is sufficient for static assets, but it lacks the global edge caching that CloudFront provides.

773
MCQeasy

A company is moving its application from on-premises to AWS. They want to use the same third-party software licenses on AWS. Which AWS purchasing option allows them to bring their own licenses?

A.Savings Plans
B.Dedicated Hosts
C.Spot Instances
D.Reserved Instances
AnswerB

Dedicated Hosts give you a physical server with visibility and control over socket and core allocation, which satisfies bring-your-own-licence requirements tied to physical cores or sockets. Other purchasing options, such as Savings Plans or Reserved Instances, do not provide that host-level licensing visibility.

Why this answer

(Dedicated Hosts) is correct because it provides visibility and control over physical servers, allowing you to use your own licenses per socket/core. Option A (Savings Plans) is just a billing discount. Option C (Spot Instances) are interruptible.

Option D (Reserved Instances) is also a billing discount and does not provide the license flexibility of Dedicated Hosts.

774
MCQhard

A company uses AWS Organizations with 50 accounts. The network team wants to centrally manage VPC flow logs for all accounts, storing them in a central S3 bucket in the security account. The flow logs must be encrypted with a KMS key managed by the security account. What is the MOST efficient way to configure this?

A.Manually create VPC flow logs in each account and point to the central S3 bucket
B.Use AWS CloudFormation StackSets to deploy a stack that creates VPC flow logs with the required configuration in all accounts
C.Use AWS Config rules to enforce flow log creation across accounts
D.Use AWS Systems Manager Automation to create flow logs in each account
AnswerB

CloudFormation StackSets deploys the flow-log stack across every organisation account in one operation, including the security-account KMS key ARN and central bucket destination. This satisfies the efficiency constraint by avoiding manual per-account configuration across 50 accounts.

Why this answer

AWS CloudFormation StackSets allows you to deploy a single CloudFormation template across multiple accounts and regions in an AWS Organization. By defining the VPC flow log resource with the central S3 bucket ARN and the KMS key from the security account (using a cross-account KMS key policy), StackSets can automatically create flow logs in all member accounts with the required encryption, making it the most efficient and centralized approach.

Exam trap

The trap here is that candidates often choose AWS Config rules (Option C) thinking they can enforce resource creation, but Config is a detective control, not a provisioning tool, and cannot directly create flow logs without additional automation.

How to eliminate wrong answers

Option A is wrong because manually creating VPC flow logs in each account is not scalable, error-prone, and violates the principle of central management for 50 accounts. Option C is wrong because AWS Config rules can only detect non-compliance (e.g., missing flow logs) and trigger remediation actions, but they cannot directly create or manage the flow log resources themselves; they rely on other services like AWS Systems Manager or Lambda for remediation, adding complexity. Option D is wrong because AWS Systems Manager Automation is designed for operational tasks on EC2 instances or on-premises machines, not for creating VPC flow logs across accounts; it lacks the native multi-account deployment capability that StackSets provides.

775
MCQeasy

A company wants to modernize a legacy monolithic application by decomposing it into microservices. The application handles HTTP requests and uses a MySQL database. The company needs to decouple the microservices and improve scalability. Which AWS services should be used?

A.Amazon SQS for decoupling and Amazon Aurora MySQL for data.
B.Amazon S3 for decoupling and Amazon RDS for MySQL.
C.Amazon SQS for decoupling and Amazon DynamoDB for data.
D.Amazon Kinesis Data Streams for decoupling and Amazon RDS for MySQL.
AnswerA

Amazon SQS provides asynchronous, queue-based decoupling so microservices scale independently without blocking callers, satisfying the decoupling and scalability requirements. Aurora MySQL is wire-compatible with MySQL, so the existing database engine and queries migrate without rewriting, meeting the stem's MySQL constraint.

Why this answer

Amazon SQS is a fully managed message queuing service that decouples microservices, allowing asynchronous communication and improved scalability. Amazon Aurora MySQL is a MySQL-compatible relational database that provides high performance and scalability, making it suitable for the existing MySQL workload. Together, they meet the requirements of decoupling and data management without re-architecting the database engine.

Exam trap

SAP-C02 often tests the confusion between message queuing (SQS) and streaming (Kinesis), and between relational (Aurora/RDS) and NoSQL (DynamoDB) databases, expecting candidates to match the right service to the decoupling and data requirements.

How to eliminate wrong answers

Option B is wrong because Amazon S3 is object storage, not a message queue, and cannot decouple microservices; it is used for storing and retrieving data, not for asynchronous messaging. Option C is wrong because while SQS correctly decouples, DynamoDB is a NoSQL database and would require migrating from MySQL, which is not specified as a requirement and may involve significant changes. Option D is wrong because Kinesis Data Streams is designed for real-time streaming data, not for decoupling microservices in a request-response pattern; it is more suited for analytics and data ingestion, and using RDS for MySQL is fine but the decoupling component is incorrect.

776
Multi-Selecteasy

A company is migrating a web application to AWS and wants to use a microservices architecture. The application needs to communicate synchronously via REST APIs. Which TWO AWS services should the architect consider for implementing API communication?

Select 2 answers
A.Application Load Balancer
B.AWS Step Functions
C.Amazon API Gateway
D.AWS AppSync
E.Amazon Simple Queue Service (Amazon SQS)
AnswersA, C

An Application Load Balancer routes HTTP and HTTPS requests to microservice targets, supporting path- and host-based rules for synchronous REST traffic. It satisfies the REST API communication requirement at layer 7, unlike Network Load Balancer, which balances TCP without HTTP awareness.

Why this answer

Option A (Application Load Balancer) is correct because an ALB operates at Layer 7 and can route HTTP/HTTPS REST requests to microservices targets such as ECS tasks, Lambda functions, or EC2 instances, providing synchronous request/response communication. Option C (Amazon API Gateway) is correct because it is a fully managed service purpose-built for creating, publishing, and securing REST APIs, and it natively supports synchronous REST communication to backend microservices. Option B (AWS Step Functions) is incorrect because it orchestrates workflows asynchronously through state machines rather than providing synchronous REST API endpoints.

Option D (AWS AppSync) is incorrect because it is designed for GraphQL APIs, not REST APIs. Option E (Amazon SQS) is incorrect because it is an asynchronous message queueing service and does not provide synchronous REST API communication.

777
MCQhard

A company has a monolithic application running on a single Amazon RDS for MySQL DB instance. The application is experiencing performance issues due to heavy read traffic. The company wants to implement a solution that offloads read traffic with minimal application changes. What should a solutions architect do?

A.Create a read replica of the RDS instance and modify the application connection string to use the reader endpoint.
B.Migrate the application to use Amazon DynamoDB with global tables.
C.Use Amazon RDS Multi-AZ with a standby instance for read traffic.
D.Implement Amazon ElastiCache in front of the database to cache read queries.
AnswerA

RDS read replicas replicate asynchronously from the primary, and the reader endpoint load-balances connections across all replicas. Pointing the connection string at this endpoint diverts SELECT queries without schema or code rewrites, satisfying the minimal-change constraint while relieving the primary's read pressure.

Why this answer

Creating a read replica of the RDS for MySQL DB instance and modifying the application connection string to use the reader endpoint offloads read traffic from the primary instance with minimal application changes. The reader endpoint automatically distributes connections across all read replicas, reducing the load on the primary instance without requiring code changes beyond updating the connection string.

Exam trap

The trap here is that candidates often confuse Multi-AZ standby instances with read replicas, not realizing that Multi-AZ standby instances are strictly for high availability and cannot serve read traffic, while read replicas are specifically designed to offload read workloads.

How to eliminate wrong answers

Option B is wrong because migrating to Amazon DynamoDB with global tables would require significant application changes to adapt from a relational to a NoSQL data model, which contradicts the requirement for minimal application changes. Option C is wrong because Amazon RDS Multi-AZ with a standby instance does not support read traffic; the standby instance is only for failover and cannot serve read requests. Option D is wrong because implementing Amazon ElastiCache would require application code changes to implement caching logic, which does not meet the minimal application changes requirement.

778
MCQeasy

A company has a central IT team that manages multiple AWS accounts. The team wants to allow developers to create resources in their own accounts but wants to restrict the use of certain expensive services like Amazon Redshift. The developers should not be able to launch Redshift clusters in any account. What is the MOST efficient way to achieve this?

A.Apply an SCP that denies redshift:CreateCluster to the organizational unit containing the developer accounts.
B.Use AWS CloudTrail to monitor cluster creation and alert the security team.
C.Create an IAM policy that denies redshift:CreateCluster and attach it to the developers' IAM groups in each account.
D.Use AWS Config rules to detect Redshift cluster creation and automatically delete them.
AnswerA

An SCP denying redshift:CreateCluster at the OU level applies to every principal in every member account, so developers cannot launch clusters regardless of their IAM permissions, meeting the organisation-wide restriction with one policy rather than per-account edits.

Why this answer

Service Control Policies (SCPs) in AWS Organizations are the most efficient way to enforce guardrails across multiple accounts. Applying an SCP that denies redshift:CreateCluster to the organizational unit containing developer accounts prevents any principal in those accounts from launching Redshift clusters, regardless of their IAM permissions. This is a centralized, preventive control that scales across all accounts in the OU.

Exam trap

SAP-C02 often tests the difference between preventive controls (SCPs) and detective controls (CloudTrail, Config)—candidates pick monitoring or remediation options because they sound operationally safe, but the question asks for the most efficient way to prevent the action.

How to eliminate wrong answers

Option B is wrong because CloudTrail only monitors and logs API activity—it is detective, not preventive, and does not stop cluster creation. Option C is wrong because attaching an IAM policy to each account's developer groups is decentralized and must be repeated per account, making it less efficient and prone to drift. Option D is wrong because AWS Config rules are detective and reactive; they can trigger remediation but do not prevent the initial creation, and auto-deletion is disruptive.

779
MCQmedium

A company runs a containerized application on Amazon ECS with Fargate. The application uses an Application Load Balancer (ALB) to distribute traffic. The company has configured a target tracking scaling policy based on average memory utilization. During a traffic spike, the ECS service scales out, but the new tasks are immediately deregistered and replaced. The CloudWatch logs show that the new tasks are failing the ALB health check. The health check is configured to ping the '/health' endpoint on the container. The solutions architect verifies that the application container correctly responds to the '/health' endpoint with a 200 status code. What is the MOST likely cause of the health check failures?

A.The ALB is not configured with a proper listener rule to forward traffic to the target group.
B.The security group attached to the ECS tasks does not allow inbound traffic from the ALB on the health check port.
C.The deregistration delay (connection draining) is set too high, causing the ALB to think the tasks are unhealthy.
D.The health check path is incorrect; it should be '/index.html' instead of '/health'.
AnswerB

Fargate tasks receive a security group separate from the ALB's. If that group lacks an inbound rule permitting the ALB's health check traffic on the container port, the ALB probes time out and mark tasks unhealthy, triggering deregistration and replacement despite the application returning 200 locally.

Why this answer

Since the application container correctly responds to the '/health' endpoint with a 200 status code, the health check failures are likely due to network connectivity. For Fargate tasks, each task gets an ENI, and the security group attached to the tasks must allow inbound traffic from the ALB on the health check port. If this rule is missing, the ALB cannot reach the health check endpoint, causing tasks to be deregistered.

Option A is incorrect because the ALB listener rule is for routing traffic, not health checks. Option C is incorrect because a high deregistration delay would cause slow draining, not immediate health check failures. Option D is incorrect because the health check path is confirmed correct by the architect.

780
Multi-Selecteasy

A global e-commerce company is migrating its on-premises application to AWS. The application uses Active Directory for authentication and requires integration with AWS Managed Microsoft AD. The company has a multi-account strategy using AWS Organizations. Which TWO steps should the solutions architect take to ensure seamless authentication across the organization?

Select 2 answers
A.Configure an IAM identity provider to use the on-premises Active Directory.
B.Establish a two-way forest trust between the on-premises Active Directory and AWS Managed Microsoft AD.
C.Store AD credentials in AWS Systems Manager Parameter Store and retrieve them at runtime.
D.Use AWS Resource Access Manager to share the AWS Managed Microsoft AD directory with other accounts in the organization.
E.Deploy AWS Managed Microsoft AD in each account and configure replication.
AnswersB, D

This enables users to authenticate with their existing credentials.

Why this answer

Establishing a two-way forest trust between on-premises Active Directory and AWS Managed Microsoft AD allows users authenticated by the on-premises AD to access resources in the AWS cloud without needing separate credentials. This trust enables Kerberos and NTLM authentication to flow seamlessly between the two forests, supporting the company's requirement for integration with AWS Managed Microsoft AD.

Exam trap

The trap here is that candidates often confuse IAM identity providers (Option A) with Active Directory trust relationships, or they incorrectly assume that storing credentials in Parameter Store (Option C) is a valid authentication strategy for directory integration, when in fact the correct approach is to establish a forest trust and share the directory via RAM.

781
MCQmedium

A company is designing a new application that will store sensitive user data in Amazon S3. Compliance requirements mandate that all data must be encrypted at rest using a key that is managed by the company and rotated automatically every year. Which solution meets these requirements?

A.Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS) and enable automatic key rotation.
B.Use client-side encryption with the AWS SDK.
C.Use S3 server-side encryption with customer-provided keys (SSE-C).
D.Use S3 server-side encryption with S3 managed keys (SSE-S3).
AnswerA

SSE-KMS with customer managed keys satisfies the company-managed key mandate, and enabling annual automatic rotation meets the yearly requirement. Rotation re-wraps the key material while retaining the same key ID, so existing objects remain decryptable without re-encryption. AWS managed keys cannot be rotated on a customer-defined schedule.

Why this answer

SSE-KMS with customer managed keys (CMKs) meets the compliance requirements because it allows the company to manage the encryption key lifecycle, including automatic annual rotation. AWS KMS supports automatic key rotation for customer managed keys, which can be configured to rotate every year, satisfying the mandate for company-managed keys with automatic rotation.

Exam trap

The trap here is that candidates often confuse SSE-C (customer-provided keys) with customer managed keys, but SSE-C does not support automatic rotation and requires the customer to manage key material outside AWS, whereas SSE-KMS with customer managed keys provides automatic rotation and is the correct choice for company-managed keys with rotation.

How to eliminate wrong answers

Option B is wrong because client-side encryption encrypts data before it reaches S3, but the key management and rotation are handled by the client application, not by AWS, and the compliance requirement specifies that the key must be managed by the company but does not require client-side control; also, automatic rotation would require custom implementation. Option C is wrong because SSE-C requires the company to provide and manage their own encryption keys, but AWS does not support automatic key rotation for SSE-C—the customer must manually rotate keys and re-encrypt data. Option D is wrong because SSE-S3 uses AWS-managed keys (Amazon S3 managed keys), which are not managed by the company, violating the requirement that the key must be managed by the company.

782
Multi-Selectmedium

A company is designing a multi-account strategy for its AWS environment. Which TWO considerations are important when using AWS Organizations?

Select 2 answers
A.Service control policies (SCPs) apply to all accounts in the organization, including the management account.
B.AWS CloudTrail can be enabled for all accounts from the management account using an organization trail.
C.Each account in an organization must have its own payment method.
D.Consolidated billing allows you to combine usage and receive volume discounts.
E.AWS Config rules cannot be applied across accounts via AWS Organizations.
AnswersB, D

An organisation trail created in the management account automatically applies to every member account, including accounts added later, and delivers events to a central bucket. This satisfies the multi-account consideration that activity logging be consistent and centrally governed rather than configured per account.

Why this answer

Option B is correct because AWS Organizations lets the management account create an organization trail in AWS CloudTrail that automatically applies to all member accounts, providing centralized logging of API activity across the organization. Option D is correct because consolidated billing aggregates usage from all member accounts into a single bill paid by the management account, and this combined usage can qualify for volume pricing discounts on services like S3 and data transfer. Option A is incorrect because SCPs do not apply to the management account; they only affect member accounts (and the management account is exempt to prevent lockout).

Option C is incorrect because AWS Organizations uses consolidated billing, so member accounts do not each need their own payment method—the management account pays the single bill. Option E is incorrect because AWS Config supports organization-wide rules and conformance packs deployed from the management account across member accounts via AWS Organizations.

Exam trap

The trap here is that candidates often assume SCPs apply to all accounts including the management account, but AWS explicitly excludes the management account from SCP effects to prevent accidental lockout of administrative access.

783
MCQhard

A company is migrating a legacy on-premises application to AWS. The application consists of a monolithic .NET application running on Windows Server, with a Microsoft SQL Server database. The company wants to improve scalability and reduce operational overhead. The application experiences variable traffic, with peaks during business hours. The company requires a highly available architecture with automatic failover for the database. Which migration strategy should a solutions architect recommend?

A.Rehost the application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer, and migrate the database to Amazon RDS for SQL Server with Multi-AZ.
B.Refactor the application into microservices running on Amazon ECS with AWS Fargate, and use Amazon Aurora for the database.
C.Retain the application on-premises and use AWS Storage Gateway for backup, and set up a VPN connection to AWS for disaster recovery.
D.Replatform the application to AWS Elastic Beanstalk for .NET, and use Amazon DynamoDB for the database.
AnswerA

Rehosting on EC2 with an Auto Scaling group and ALB provides scalability and high availability for the application tier. Migrating to RDS for SQL Server with Multi-AZ ensures automatic failover and reduces database management overhead. This approach meets the requirements for scalability, high availability, and reduced operational effort with minimal application changes.

Why this answer

Rehosting the application on EC2 with an Auto Scaling group and ALB provides scalability and high availability without code changes. Migrating the database to RDS for SQL Server with Multi-AZ offers automatic failover and reduces management overhead. This strategy balances minimal changes with the desired scalability and availability, making it the most suitable for a legacy application.

Exam trap

The trap here is assuming that replatforming to Elastic Beanstalk or refactoring to microservices is necessary for scalability, but those add complexity and may not be needed for a lift-and-shift migration.

784
MCQhard

A company is migrating a legacy application to AWS. The application requires a shared file system that can be mounted by hundreds of EC2 instances across multiple Availability Zones. The file system must provide high throughput and low latency. Which storage solution meets these requirements?

A.Use Amazon EBS with a multi-attach enabled volume.
B.Use Amazon EFS with provisioned throughput.
C.Use Amazon S3 with S3 File Gateway to present as a file system.
D.Use Amazon FSx for Windows File Server with a single file system.
AnswerB

Amazon EFS is a shared, elastic NFS file system mountable concurrently from EC2 instances in multiple Availability Zones, and provisioned throughput guarantees the required performance. This satisfies the multi-AZ shared access, high throughput, and low latency constraints.

Why this answer

Amazon EFS with provisioned throughput is the correct choice because it provides a fully managed, scalable, shared file system that can be mounted by hundreds of EC2 instances across multiple Availability Zones simultaneously. It uses the NFSv4.1 protocol, delivers high throughput and low latency, and allows you to provision throughput independently of storage size to meet performance requirements.

Exam trap

The trap here is that candidates often confuse Amazon EBS multi-attach with a true shared file system, overlooking its single-AZ limitation and low instance count cap, while also underestimating EFS's ability to handle hundreds of concurrent NFS clients across multiple AZs with provisioned throughput.

How to eliminate wrong answers

Option A is wrong because Amazon EBS multi-attach volumes can only be attached to a maximum of 16 Nitro-based EC2 instances in a single Availability Zone, not hundreds across multiple AZs, and they do not provide a shared file system interface. Option C is wrong because Amazon S3 with S3 File Gateway presents an SMB or NFS file system but is designed for hybrid cloud caching and does not natively provide the low-latency, high-throughput performance required for hundreds of concurrent EC2 instances across AZs; it also introduces gateway latency and throughput limitations. Option D is wrong because Amazon FSx for Windows File Server supports only Windows-based clients via SMB protocol and is not optimized for the high-throughput, low-latency requirements of hundreds of Linux-based EC2 instances across multiple AZs; it also has a single file system that can be accessed across AZs but is not designed for the scale and performance profile described.

785
MCQeasy

A company wants to migrate an on-premises relational database to Amazon RDS for MySQL with minimal downtime. The database is 500 GB in size. Which AWS service should be used for the initial data load and ongoing replication?

A.Use AWS Snowball to transfer the database files to RDS.
B.Use an RDS read replica from the on-premises database.
C.Use AWS Database Migration Service (DMS) with ongoing replication.
D.Export the database to Amazon S3 and import into RDS.
AnswerC

AWS DMS performs the initial full load and then continuous change data capture from the source MySQL binary logs, replicating ongoing changes to RDS for MySQL. This keeps the target synchronised until cutover, satisfying the minimal-downtime constraint for the 500 GB database.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication is the correct choice because it supports both a full load of the 500 GB database and continuous change data capture (CDC) using the MySQL binary log (binlog) to replicate ongoing changes with minimal downtime. DMS can perform the initial load while the source remains operational, then switch to CDC to keep the target in sync until cutover.

Exam trap

The trap here is that candidates often confuse the one-time bulk transfer capability of Snowball or S3 with the need for ongoing replication, failing to recognize that minimal downtime requires a continuous change capture mechanism like DMS CDC, not just an initial data load.

How to eliminate wrong answers

Option A is wrong because AWS Snowball is designed for offline bulk data transfer of large datasets (e.g., terabytes to petabytes) and cannot provide ongoing replication; it would require a separate replication mechanism for changes after the initial load, defeating the minimal-downtime goal. Option B is wrong because an RDS read replica can only be created from an existing RDS instance, not from an on-premises database; it uses MySQL's asynchronous replication which requires the source to be an RDS MySQL instance. Option D is wrong because exporting the database to Amazon S3 and importing into RDS is a one-time, offline process that does not capture ongoing changes, so it would result in significant downtime while the export and import occur, and it lacks CDC capabilities.

786
MCQeasy

A company is running a web application on AWS Elastic Beanstalk with an Auto Scaling group behind an Application Load Balancer. The application stores session state in an Amazon DynamoDB table. During a traffic spike, the application becomes slow and some users are logged out unexpectedly. The operations team notices that the DynamoDB table's read capacity utilization is consistently at 100%. The company needs to improve the performance of the session store without over-provisioning capacity. Which solution should be implemented?

A.Migrate the session store from DynamoDB to Amazon ElastiCache Memcached.
B.Increase the read capacity units (RCU) of the DynamoDB table to handle peak traffic.
C.Move session state to Amazon SQS and have the application poll the queue.
D.Implement Amazon DynamoDB Accelerator (DAX) as a caching layer for the session store.
AnswerD

DAX provides a write-through, in-memory cache for DynamoDB, serving session reads from microseconds-latency memory instead of consuming table read capacity units. This eliminates the 100% read utilisation bottleneck and prevents logouts without raising provisioned throughput.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache purpose-built for DynamoDB that reduces read latency from milliseconds to microseconds and offloads read traffic from the table, directly addressing the 100% read capacity utilization. Because session state is read-heavy and latency-sensitive, DAX is the ideal fit — it requires minimal application changes (just swap the DynamoDB client for the DAX client) and does not require over-provisioning RCUs. This solves both the performance degradation and the unexpected logouts caused by read throttling.

Exam trap

SAP-C02 often tests whether candidates recognize DAX as the DynamoDB-native caching solution — distractors like ElastiCache or increasing RCUs sound plausible but either over-provision or require unnecessary re-architecture.

How to eliminate wrong answers

Option A is wrong because migrating to ElastiCache Memcached changes the session store technology entirely, requires significant application rework, and loses DynamoDB's durability and managed scaling — it is a heavier change than necessary. Option B is wrong because simply increasing RCUs is over-provisioning, which the question explicitly says to avoid, and it does not reduce latency for session reads. Option C is wrong because SQS is a message queue, not a session store — polling a queue for session state is architecturally nonsensical and would add latency, not reduce it.

787
MCQhard

A company is modernizing a legacy application by breaking it into microservices. The application uses a shared MySQL database. The team wants to refactor the database to use Amazon DynamoDB for better scalability. Which migration strategy should be used?

A.Rehost the database to Amazon RDS
B.Use the Strangler Fig pattern to incrementally migrate data to DynamoDB
C.Replatform the database to Amazon Aurora
D.Retire the existing database and switch to DynamoDB
AnswerB

The Strangler Fig pattern routes reads and writes incrementally to DynamoDB while the MySQL database remains authoritative, allowing dual-write or change-data-capture synchronisation. This satisfies the refactor-to-DynamoDB goal without a risky big-bang cutover, since each migrated capability can be validated before decommissioning legacy tables.

Why this answer

The Strangler Fig pattern is the correct migration strategy because it allows for incremental and iterative migration of data and business logic from the legacy MySQL database to Amazon DynamoDB without a full cutover. This approach minimizes risk and enables the team to gradually refactor the application while maintaining continuous operation. Option A (rehost to Amazon RDS) would still use a relational database and not achieve the goal of moving to DynamoDB.

Option C (replatform to Amazon Aurora) also retains a relational model. Option D (retire the existing database and switch to DynamoDB) is risky as it requires a complete cutover without incremental transition.

788
MCQhard

A large financial services company uses AWS Organizations with over 200 accounts. The security team has implemented a Service Control Policy (SCP) that denies access to all services except a whitelist that includes Amazon S3, Amazon DynamoDB, AWS Lambda, and Amazon CloudWatch. Recently, the DevOps team reported that they cannot create new EC2 instances in their development account, even though the administrator explicitly attached an IAM policy allowing ec2:RunInstances. The SCP does not explicitly deny EC2. What is the most likely cause of this issue?

A.The IAM role used by the DevOps team has a trust policy that does not allow EC2 actions
B.The EC2 service has been disabled via AWS Config in that account
C.The development account is in an organizational unit (OU) with a different SCP that denies EC2
D.The SCP denies all services not explicitly allowed, and EC2 is not on the whitelist
AnswerD

The SCP uses a whitelist model: its default is implicit denial of every service not named. Because EC2 is absent from the allowed list, ec2:RunInstances is blocked regardless of the attached IAM policy, since SCPs cap effective permissions.

Why this answer

The SCP uses a deny-all approach with a whitelist of allowed services. Since EC2 is not on that whitelist, the SCP implicitly denies all EC2 actions, overriding any IAM policy that explicitly allows ec2:RunInstances. SCPs act as a guardrail that cannot be bypassed by account-level IAM policies.

Exam trap

The trap here is that candidates may think an explicit IAM allow can override an SCP, but SCPs set the maximum permissions boundary, so any action not explicitly allowed by the SCP is implicitly denied.

How to eliminate wrong answers

Option A is wrong because a trust policy controls which principals can assume a role, not the actions the role can perform; the issue is about authorization, not trust. Option B is wrong because AWS Config is a compliance and monitoring service, not a service control mechanism that can disable EC2; it cannot prevent API calls. Option C is wrong because the question states the SCP does not explicitly deny EC2, and the SCP described is the only one mentioned; while an OU-level SCP could cause this, the most direct and likely cause given the whitelist design is that EC2 is simply not allowed.

789
Multi-Selectmedium

A company is designing a new serverless application that uses AWS Lambda, Amazon DynamoDB, and Amazon API Gateway. The application must handle burst traffic and cannot lose any data. The company wants to use a dead-letter queue (DLQ) for failed Lambda invocations. Which TWO services can be used as a DLQ for Lambda? (Choose two.)

Select 2 answers
A.Amazon DynamoDB Streams
B.Amazon SNS
C.Amazon Kinesis Data Streams
D.Amazon SQS
E.Amazon Simple Email Service (SES)
AnswersB, D

Amazon SNS works as a Lambda dead-letter queue because Lambda supports publishing failed asynchronous invocation records to an SNS topic, satisfying the no-data-loss requirement. Unlike SQS, SNS pushes each failed event to subscribers, enabling fan-out to email, HTTP endpoints or additional queues for immediate alerting on burst-traffic failures.

Why this answer

Amazon SNS and Amazon SQS are the two supported destinations for Lambda's dead-letter queue (DLQ) configuration, but only for asynchronous invocations. When a Lambda function is invoked asynchronously and fails after the configured number of retries, the event can be redirected to an SNS topic or an SQS queue for later reprocessing or analysis. This ensures no data is lost during burst traffic, as failed events are persisted in the DLQ.

Synchronous invocations do not support DLQ.

Exam trap

The trap here is that candidates often confuse Lambda's event sources (like DynamoDB Streams or Kinesis) with supported DLQ destinations, but Lambda only allows SQS and SNS as DLQ targets for asynchronous invocations.

790
MCQmedium

A financial services company is migrating a batch risk-calculation workload to AWS. The workload runs nightly for 90 minutes, requires 64 vCPUs and 256 GiB of memory, and must complete within a 2-hour window. The company wants to minimize cost and is open to interruption because the job can restart from a checkpoint. Which compute option should a solutions architect recommend?

A.Amazon EC2 Spot Instances with a capacity-optimized allocation strategy and checkpointing to Amazon S3.
B.AWS Fargate tasks on Amazon ECS with 16 vCPU and 120 GiB of memory, scaled by a scheduled Application Auto Scaling policy.
C.AWS Lambda functions with 10 GB of memory and a 15-minute timeout, invoked in parallel by AWS Step Functions.
D.Amazon EC2 On-Demand instances launched in an Auto Scaling group with a scheduled scaling policy.
AnswerA

Spot Instances can deliver up to 90% savings versus On-Demand and are ideal for interruption-tolerant batch jobs. The capacity-optimized allocation strategy selects pools with the most available capacity, reducing the chance of interruption during the 90-minute window. Checkpointing to Amazon S3 lets the job resume from the last completed step if a Spot Instance is reclaimed, keeping the workload within the 2-hour completion window.

Why this answer

The workload is short, deterministic, and restartable from a checkpoint, which makes it a strong fit for EC2 Spot Instances. A capacity-optimized allocation strategy improves the likelihood of obtaining and retaining capacity for the full 90 minutes, and checkpointing to Amazon S3 allows recovery if a Spot Instance is reclaimed. This combination minimizes cost while still meeting the 2-hour completion window.

Exam trap

The trap here is dismissing Spot Instances because the job has a deadline, when checkpointing and a capacity-optimized allocation strategy make Spot both safe and far cheaper for interruption-tolerant batch workloads.

791
Multi-Selectmedium

A company is migrating a legacy e-commerce platform to AWS. The platform includes a MySQL database that experiences heavy read traffic. The company wants to improve performance and reduce latency for read operations. Which TWO actions should the solutions architect take?

Select 2 answers
A.Enable Multi-AZ on the RDS instance.
B.Shard the database across multiple RDS instances.
C.Upgrade to Provisioned IOPS for the database.
D.Add read replicas to the RDS MySQL database.
E.Use Amazon ElastiCache in front of the database.
AnswersD, E

RDS MySQL read replicas use asynchronous replication to serve read-only queries from separate instances, offloading the primary and reducing read latency. This directly satisfies the heavy read-traffic requirement by horizontally scaling read capacity without changing application write logic.

Why this answer

Option D is correct because RDS MySQL read replicas use asynchronous replication to offload read-only queries from the primary instance, directly improving read performance and reducing latency for heavy read traffic. Option E is correct because Amazon ElastiCache (Redis or Memcached) caches frequently accessed query results in memory, serving reads in microseconds and dramatically reducing the load and latency on the MySQL database. Option A is not correct because Multi-AZ provides high availability through a synchronous standby that does not serve read traffic, so it does not improve read performance.

Option B is not correct because sharding is a complex manual partitioning strategy typically used for write scaling or very large datasets, not the simplest fix for read-heavy latency. Option C is not correct because Provisioned IOPS improves storage throughput and IOPS for the database volume but does not scale read capacity beyond what a single instance can serve.

792
MCQmedium

A company is designing a multi-tier web application on AWS. They want to ensure that the web tier can scale automatically based on CPU utilization. Which AWS service should they use?

A.Amazon CloudFront
B.Amazon Route 53
C.Auto Scaling groups
D.Elastic Load Balancing
AnswerC

Auto Scaling groups adjust the number of EC2 instances in the web tier based on CloudWatch CPU utilisation metrics, scaling out under load and in when idle. This delivers the automatic, demand-driven scaling the multi-tier design requires.

Why this answer

Auto Scaling groups (Option C) are the correct service because they directly manage the automatic scaling of EC2 instances based on defined policies, such as a target CPU utilization threshold. When CPU utilization exceeds the threshold, the Auto Scaling group launches new instances to handle the load, and it terminates instances when utilization drops, ensuring the web tier scales automatically.

Exam trap

The trap here is that candidates often confuse Elastic Load Balancing with automatic scaling, but ELB only distributes traffic and does not add or remove instances; the Auto Scaling group is the service that actually scales the compute capacity.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations to reduce latency, not a service that scales compute resources based on CPU utilization. Option B is wrong because Amazon Route 53 is a DNS web service that routes end users to internet applications, but it does not provide automatic scaling of compute capacity. Option D is wrong because Elastic Load Balancing distributes incoming traffic across multiple targets (e.g., EC2 instances), but it does not automatically scale the number of instances; it works in conjunction with Auto Scaling groups to distribute traffic to scaled instances.

793
MCQmedium

An IAM policy condition allows launching EC2 instances only if the instance type is t2.micro or t2.small. A developer tries to launch a t2.medium instance. What happens?

A.The launch is denied only if the user does not have a separate policy allowing t2.medium.
B.The launch succeeds because the condition only allows, not denies.
C.The launch succeeds if the user has an additional Allow for t2.medium.
D.The launch is denied because t2.medium is not in the allowed list.
AnswerD

The condition key `ec2:InstanceType` evaluates the requested type against the allowed values, and t2.medium matches neither t2.micro nor t2.small. Because IAM denies any request failing a condition in an Allow statement, the RunInstances call is rejected outright. The developer receives an unauthorised operation error, satisfying the stem's allow-list constraint.

Why this answer

IAM policies are evaluated with an implicit deny by default; an Allow statement with a condition only grants permissions when the condition is satisfied. Since the condition restricts instance types to t2.micro or t2.small, launching a t2.medium does not match the condition, so the Allow does not apply and the request is denied. No separate Deny statement is needed—the absence of a matching Allow results in denial.

Exam trap

SAP-C02 often tests the misconception that a condition in an Allow statement acts as a deny; candidates must remember that a failed condition simply means the Allow does not apply, resulting in an implicit deny.

How to eliminate wrong answers

Option A is wrong because IAM does not require an explicit deny; the condition simply fails to match, so the Allow is not granted, and the request is denied regardless of other policies unless another policy explicitly allows t2.medium. Option B is wrong because conditions in Allow statements do restrict permissions; they are not merely permissive hints. Option C is wrong because while an additional Allow for t2.medium could grant access, the question states the policy only allows t2.micro/t2.small, and the developer has no such additional policy; the launch is denied.

794
MCQeasy

A company uses AWS Organizations with multiple OUs. The DevOps team needs to allow developers to launch EC2 instances only of type t3.micro in the dev OU. Which action should the team take?

A.Create an IAM role with a policy that allows only t3.micro, and attach it to users in the dev OU.
B.Use AWS CloudFormation templates that specify t3.micro.
C.Apply a Service Control Policy (SCP) to the dev OU that denies ec2:RunInstances with instance type not equal to t3.micro.
D.Use AWS Config rules to terminate non-compliant instances.
AnswerC

SCPs define the maximum available permissions for principals in member accounts and apply at the OU level, so attaching this policy to the dev OU blocks RunInstances for any instance type other than t3.micro across every account beneath it, satisfying the OU-wide restriction without per-account IAM edits.

Why this answer

A Service Control Policy (SCP) applied to the dev OU can centrally restrict which EC2 instance types can be launched by all accounts within that OU. The SCP uses a Deny effect with a condition key ec2:InstanceType not equal to t3.micro, which prevents any IAM principal in the OU from launching non-compliant instances, regardless of their IAM permissions. This is the most effective way to enforce a hard boundary at the organization level.

Exam trap

The trap here is that candidates often choose AWS Config rules (Option D) thinking they can prevent launches, but Config is detective, not preventive; SCPs are the correct preventive control at the organization level.

How to eliminate wrong answers

Option A is wrong because an IAM role attached to users does not apply to all principals in the OU; users could still launch instances via other roles or services, and the role does not enforce the restriction across all accounts in the OU. Option B is wrong because CloudFormation templates are not an enforcement mechanism; developers could bypass the template and launch instances manually via the console or CLI. Option D is wrong because AWS Config rules only detect and report non-compliance after the instance is launched; they do not prevent the launch, and terminating instances after creation is reactive and can incur costs and operational overhead.

795
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores session state locally on each instance. The company wants to improve the availability and scalability of the application by making the session state external and allowing any instance to handle any request. The solution must minimize latency for session access and require minimal changes to the application code. Which approach should a solutions architect recommend?

A.Store session state in an Amazon RDS for MySQL database and modify the application to use the database for session storage.
B.Enable sticky sessions (session affinity) on the ALB and keep session state local on each instance.
C.Store session state in an Amazon ElastiCache for Redis cluster and modify the application to use the ElastiCache endpoint for session storage.
D.Use Amazon S3 to store session state and have the application read and write session data to S3 on each request.
AnswerC

ElastiCache for Redis provides a low-latency, in-memory data store that is ideal for session state. By externalizing sessions to Redis, any instance can handle any request, improving availability and scalability. The application code needs to be modified to read and write sessions to Redis, but this is a common and minimal change. Redis also supports high availability with automatic failover when using a multi-AZ replication group.

Why this answer

Externalizing session state to ElastiCache for Redis provides low-latency, high-performance session storage that allows any EC2 instance to handle any request. This improves availability and scalability. Modifying the application to use Redis is a standard pattern and requires minimal code changes compared to other options.

Sticky sessions do not solve the underlying issue, and RDS or S3 introduce higher latency.

Exam trap

The trap here is choosing sticky sessions as a quick fix, which does not externalize session state or improve availability.

796
MCQmedium

A company is designing a data lake on AWS using Amazon S3. They need to run SQL queries on the data without moving it to a separate database. Which AWS service should they use?

A.Amazon EMR
B.Amazon Athena
C.Amazon Redshift
D.AWS Glue
AnswerB

Amazon Athena is a serverless query service that runs standard SQL directly against data in Amazon S3 using the Glue Data Catalog, so no data movement or separate database is needed. This satisfies the requirement to query in place without loading.

Why this answer

Amazon Athena is a serverless, interactive query service that allows you to run standard SQL queries directly against data stored in Amazon S3 without needing to move or transform the data. It uses Presto under the hood and charges only for the data scanned per query, making it ideal for ad-hoc SQL analysis on a data lake.

Exam trap

The trap here is that candidates often confuse AWS Glue (which catalogs and transforms data but does not run SQL queries) with Athena, or they assume Amazon EMR is required for SQL-on-S3, overlooking Athena's serverless and direct-query capability.

How to eliminate wrong answers

Option A is wrong because Amazon EMR is a managed big data platform that requires you to provision and configure clusters (e.g., Hadoop, Spark) to run SQL via tools like Hive or Presto, which adds operational overhead and does not allow querying data directly without moving it into a separate processing framework. Option C is wrong because Amazon Redshift is a fully managed data warehouse that requires you to load data into its columnar storage before querying, which contradicts the requirement of not moving data to a separate database. Option D is wrong because AWS Glue is a serverless data integration service primarily used for ETL (extract, transform, load) and cataloging metadata via the Glue Data Catalog; it does not provide a direct SQL query engine against S3 data.

797
Multi-Selecthard

A company is planning to modernize a legacy Java application that runs on a single on-premises server. The application uses a proprietary file-based storage system. The company wants to migrate to AWS with the following goals: reduce operational overhead, improve availability, and minimize code changes. Which TWO strategies should the company use? (Choose two.)

Select 2 answers
A.Use AWS Application Migration Service (MGN) to migrate the application server to Amazon EC2
B.Use Amazon EFS to replace the proprietary file-based storage
C.Migrate the proprietary storage to Amazon S3
D.Migrate the proprietary storage to Amazon RDS for PostgreSQL
E.Refactor the application into microservices and deploy on Amazon EKS
AnswersA, B

AWS Application Migration Service replicates the on-premises server block-level and launches it on Amazon EC2, so the Java application runs without modification. This lifts operational overhead to AWS and enables multi-AZ resilience while minimising code changes.

Why this answer

AWS Application Migration Service (MGN) enables lift-and-shift of the application server to Amazon EC2 with minimal code changes, reducing operational overhead. Amazon EFS provides a managed NFS file system that can replace the proprietary file-based storage without code modifications, improving availability. Option D (RDS) is incorrect because migrating file-based data to a relational database would require significant application changes, contradicting the goal of minimizing code changes.

Exam trap

Candidates often assume that any managed storage can replace file-based storage without code changes. However, Amazon EFS is a drop-in NFS replacement, while RDS requires application modifications.

798
MCQeasy

A company wants to serve static content (images and videos) to users worldwide with low latency. The content is stored in an Amazon S3 bucket. What is the most cost-effective solution?

A.Use AWS Global Accelerator with endpoints pointing to the S3 bucket.
B.Deploy EC2 instances in multiple Regions and use a load balancer.
C.Use Amazon CloudFront with the S3 bucket as the origin.
D.Host the content directly from the S3 bucket and use S3 Transfer Acceleration.
AnswerC

CloudFront caches objects at edge locations worldwide, so repeated requests are served from the nearest point of presence rather than from the S3 bucket's Region, cutting latency. You pay only for data transfer out and requests, with no upfront cost, satisfying the worldwide low-latency and cost-effectiveness constraints.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches static content at edge locations worldwide, reducing latency for users. Using an S3 bucket as the origin is cost-effective because CloudFront egress costs are often lower than direct S3 data transfer, and you only pay for data transfer out from CloudFront and occasional origin fetches. This solution minimizes origin load and provides low-latency delivery without the overhead of managing servers or additional acceleration services.

Exam trap

The trap here is that candidates confuse AWS Global Accelerator (which optimizes network path but does not cache) with a CDN like CloudFront, or mistakenly think S3 Transfer Acceleration improves download performance for end users when it only accelerates uploads to S3.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator improves TCP/UDP traffic performance via the AWS global network but does not cache content; it would still require all requests to reach the S3 bucket, increasing latency and costs compared to a CDN. Option B is wrong because deploying EC2 instances in multiple Regions to serve static content introduces unnecessary compute costs, management overhead, and complexity, while a CDN like CloudFront provides caching at edge locations more efficiently. Option D is wrong because S3 Transfer Acceleration speeds up uploads to S3 over long distances using AWS edge locations, but it does not cache or accelerate downloads for end users; it would not reduce latency for serving content globally and can incur higher costs per GB transferred.

799
Multi-Selecthard

A company is designing a high-performance computing (HPC) workload on AWS. The workload requires tightly coupled inter-node communication with low latency and high bandwidth. Which THREE services or features should the architect consider to meet these requirements? (Choose three.)

Select 3 answers
A.EC2 instances with enhanced networking and high-throughput (e.g., p4d, p3dn)
B.VPC peering between multiple VPCs
C.AWS Global Accelerator
D.Placement Groups (Cluster Placement Group)
E.Elastic Fabric Adapter (EFA)
AnswersA, D, E

These instance types offer high network bandwidth and EFA support.

Why this answer

EC2 instances like p4d and p3dn are designed for HPC workloads, offering enhanced networking (up to 100 Gbps) and high-throughput capabilities. These instances support Elastic Fabric Adapter (EFA) and are optimized for tightly coupled inter-node communication, providing the low latency and high bandwidth required for HPC.

Exam trap

The trap here is that candidates may confuse VPC peering or Global Accelerator as solutions for inter-node latency, but these services address different problems (cross-VPC connectivity and global traffic optimization) and do not reduce latency for tightly coupled HPC communication within a single cluster.

800
MCQeasy

An organization is planning to migrate a large number of on-premises virtual machines to AWS. The migration must be automated and support replication of live workloads with minimal downtime. Which AWS service is best suited for this task?

A.AWS DataSync
B.AWS Application Migration Service (MGN)
C.AWS Server Migration Service (SMS)
D.AWS Database Migration Service (DMS)
AnswerB

AWS Application Migration Service replicates live source servers continuously at block level, launching them on AWS as EC2 instances. This satisfies the stem's automation and minimal-downtime constraints: agents install automatically, and cutover occurs in minutes, unlike snapshot-based tools requiring manual orchestration or extended outages.

Why this answer

(AWS Application Migration Service) is correct as it automates lift-and-shift migration with continuous replication and cutover. Option A (AWS DataSync) is for data transfer, not live VM replication. Option C (AWS Server Migration Service) is legacy and less capable.

Option D (AWS Database Migration Service) is for databases, not general VM migration.

801
MCQmedium

A company is migrating a legacy on-premises application to AWS. The application uses a shared file system that is accessed by multiple Windows servers. The company wants to use a fully managed AWS storage service that provides SMB file shares and integrates with Microsoft Active Directory for authentication. The solution must be highly available and durable. Which AWS service should the company use?

A.Amazon FSx for Lustre
B.Amazon Elastic File System (Amazon EFS)
C.Amazon S3 with S3 File Gateway
D.Amazon FSx for Windows File Server
AnswerD

Amazon FSx for Windows File Server is a fully managed file storage service built on Windows Server that supports the SMB protocol and integrates with Microsoft Active Directory for authentication. It provides high availability through Multi-AZ deployments and is designed for durability. This service directly meets the requirements for a shared Windows file system with AD integration.

Why this answer

The application requires a shared file system for Windows servers using SMB and integrated with Active Directory. Amazon FSx for Windows File Server is the only AWS service that natively supports SMB and AD integration, and it is fully managed, highly available, and durable. Other options either use different protocols or lack the required AD integration.

Exam trap

The trap here is confusing Amazon EFS or S3 File Gateway with a Windows-native file system, overlooking the need for SMB protocol and Active Directory integration.

802
MCQmedium

A company is migrating a multi-tier web application to AWS. The application uses a commercial database that requires a license. The company wants to reduce licensing costs. Which migration strategy should be considered?

A.Rehost the database to EC2 with the same database software
B.Replatform the database to Amazon RDS for an open-source engine like PostgreSQL
C.Repurchase a Software as a Service (SaaS) alternative
D.Refactor the application to use Amazon DynamoDB
AnswerB

Replatforming swaps the licensed commercial engine for Amazon RDS PostgreSQL, eliminating per-core licence fees while retaining managed backups, patching and Multi-AZ. This satisfies the cost-reduction goal without the re-architecting effort of refactoring the application's data layer.

Why this answer

Replatforming to Amazon RDS for an open-source engine like PostgreSQL eliminates the commercial database license cost because PostgreSQL is open-source and RDS is a managed service. This aligns with the goal of reducing licensing costs while minimizing application changes. The company can still use a relational database with similar capabilities, avoiding the need for a full refactor or repurchase.

Exam trap

SAP-C02 often tests the misconception that any migration to AWS automatically reduces licensing costs, but only strategies that change the database engine to open-source or use managed services without commercial licenses achieve that goal.

How to eliminate wrong answers

Option A is wrong because rehosting to EC2 with the same commercial database software does not reduce licensing costs; the company would still need to pay for the same licenses, and may incur additional costs for managing the database on EC2. Option C is wrong because repurchasing a SaaS alternative involves moving to a different licensing model, which may not necessarily reduce costs and could introduce new subscription fees; it also requires significant changes to the application and business processes. Option D is wrong because refactoring to DynamoDB is a major architectural change that may not be feasible for a multi-tier web application with relational data requirements, and it could increase development and migration costs, outweighing licensing savings.

803
MCQeasy

A company is migrating a web application to AWS and wants to decouple the frontend and backend tiers to improve scalability. The frontend runs on Amazon EC2 behind an Application Load Balancer (ALB). The backend processes orders asynchronously. Which service should the company use to decouple the tiers?

A.Amazon MQ
B.Amazon Simple Queue Service (SQS)
C.Amazon Simple Notification Service (SNS)
D.Amazon Kinesis Data Streams
AnswerB

Amazon SQS decouples the tiers by letting the frontend enqueue order messages while backend workers poll and process them asynchronously. This buffers traffic spikes, allows independent scaling of each tier, and prevents frontend requests from blocking on backend processing, satisfying the asynchronous order requirement.

Why this answer

For decoupling frontend and backend asynchronously, Amazon Simple Queue Service (SQS) is the appropriate service. It allows the frontend to send order messages to a queue, and the backend components poll and process them independently. Option A (Amazon MQ) is a managed message broker for existing protocols like JMS, but SQS is simpler and more scalable for this use case.

Option C (Amazon SNS) is a pub/sub service, not designed for point-to-point decoupling with pull-based consumers. Option D (Amazon Kinesis Data Streams) is for real-time streaming data, not for decoupling web tiers.

804
MCQmedium

A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account for incident response. They need to ensure that the roles can be assumed only by specific IAM principals in the security account and that the permissions are consistent across all member accounts. Which approach meets these requirements with the LEAST operational overhead?

A.Use AWS IAM Identity Center (successor to AWS Single Sign-On) to create a permission set that grants access to the security account, and assign it to all member accounts.
B.Use AWS CloudFormation StackSets to deploy a standardized IAM role in each member account with a trust policy that allows assumption by the security account's incident response role, and manage updates centrally.
C.Implement a custom AWS Lambda function that uses the AWS SDK to create the IAM role in each member account upon a scheduled trigger.
D.Create an IAM role in each member account manually and use AWS Organizations SCPs to enforce that only the security account can assume it.
AnswerB

CloudFormation StackSets allow you to deploy and update IAM roles across all member accounts from a central location. The trust policy can specify the exact security account principal, ensuring only that principal can assume the role. This provides consistency and minimal operational overhead because updates are applied automatically to all accounts.

Why this answer

CloudFormation StackSets provide a centralized, scalable way to deploy and update IAM roles across multiple accounts with consistent trust policies. This ensures only the specified security account principal can assume the roles, and updates are managed from a single place, minimizing operational overhead.

Exam trap

The trap here is assuming that SCPs can restrict which principals can assume an IAM role, when they actually only limit permissions for principals within the account.

805
MCQeasy

A company is migrating a monolithic application to microservices on AWS. They want to implement a continuous improvement process for existing services. Which AWS service should they use to collect and analyze operational metrics and logs from all microservices in a centralized location?

A.AWS Config
B.Amazon Inspector
C.Amazon CloudWatch
D.AWS X-Ray
AnswerC

Amazon CloudWatch aggregates metrics, logs and traces from every microservice into one place, with Logs Insights and dashboards for analysis. This centralised visibility underpins the continuous improvement process the stem requires, unlike per-service tooling that would fragment operational data.

Why this answer

Amazon CloudWatch is the AWS service designed to collect and analyze operational metrics and logs from all microservices in a centralized location. It provides monitoring, dashboards, alarms, and log aggregation, enabling continuous improvement through insights into performance and operational health.

Exam trap

The trap is confusing CloudWatch with X-Ray or Config, as all are monitoring-related, but only CloudWatch is the centralized service for metrics and logs collection and analysis.

How to eliminate wrong answers

Option A is wrong because AWS Config is used for assessing, auditing, and evaluating the configurations of AWS resources, not for collecting operational metrics and logs. Option B is wrong because Amazon Inspector is a vulnerability management service that scans workloads for security exposures, not for operational monitoring. Option D is wrong because AWS X-Ray is used for tracing and analyzing requests in distributed applications, which is more about debugging and performance analysis of individual requests, not centralized metrics and logs collection.

806
MCQeasy

Refer to the exhibit. A company has an Amazon ECS task definition with two containers. The 'web' container is essential, and the 'sidecar' container is not. The 'sidecar' container exits unexpectedly. What will happen to the task?

A.The sidecar container will be marked as essential.
B.ECS will automatically restart the sidecar container.
C.The task continues running as normal.
D.The ECS task will be stopped.
AnswerC

Only essential containers determine task fate; a non-essential container exiting does not stop the task. Since the sidecar is marked non-essential, ECS leaves the web container and the task running, satisfying the stem's scenario where the sidecar exits unexpectedly.

Why this answer

In an ECS task definition, only containers marked as essential cause the entire task to stop if they exit. Since the 'web' container is essential and the 'sidecar' container is not, the sidecar exiting does not stop the task; the task continues running with the web container unaffected.

Exam trap

The trap is that candidates assume any container failure stops the task, or that ECS restarts individual containers — the essential flag is the deciding factor and non-essential containers simply exit without task termination.

How to eliminate wrong answers

Option A is wrong because essential status is a static property defined in the task definition, not something ECS dynamically assigns when a container exits. Option B is wrong because ECS does not automatically restart individual non-essential containers within a running task; restart behavior is governed by the task's restart policy or the service scheduler, not by the container's exit alone. Option D is wrong because the task only stops if an essential container exits — the sidecar is explicitly non-essential, so its failure does not trigger task termination.

807
MCQeasy

A company uses AWS Organizations and wants to delegate administrative tasks for specific AWS services to a member account. Which AWS feature should be used?

A.AWS Control Tower
B.Delegated administrator for AWS services
C.Cross-account IAM roles
D.AWS CloudTrail organization trail
AnswerB

Registering a member account as delegated administrator for a service transfers that service's organisation-wide administrative permissions to it, so the management account no longer needs to perform those tasks. This satisfies the requirement to delegate service administration without granting full organisation control.

Why this answer

Delegated administrator for AWS services allows you to designate a member account in AWS Organizations to perform administrative tasks for specific AWS services, such as AWS IAM Access Analyzer or AWS Security Hub, without granting full organization management access. This feature centralizes control while distributing operational responsibilities, making it the correct choice for delegating administrative tasks for specific services.

Exam trap

The trap here is that candidates often confuse the broad, role-based access of cross-account IAM roles (Option C) with the specific, service-level delegation model of delegated administrators, leading them to overlook the AWS Organizations-native feature designed for this exact purpose.

How to eliminate wrong answers

Option A is wrong because AWS Control Tower is a service for setting up and governing a multi-account environment using pre-built blueprints and guardrails, not for delegating administrative tasks for specific AWS services to a member account. Option C is wrong because cross-account IAM roles provide broad, role-based access to resources in another account but are not designed for the specific, service-level delegation model that AWS Organizations supports for delegated administrators. Option D is wrong because AWS CloudTrail organization trail logs API activity across all accounts in the organization for auditing, not for delegating administrative tasks for specific services.

808
MCQhard

A company uses AWS Organizations and has deployed a multi-account strategy. The security team wants to enforce that all S3 buckets have versioning enabled. They create an SCP that denies the PutBucketVersioning action if versioning is not enabled. However, they find that the SCP is not preventing users in member accounts from disabling versioning on existing buckets. What is the most likely reason?

A.The SCP is overridden by a service control policy that allows the action.
B.The SCP does not have an explicit deny; it uses a default deny.
C.SCPs cannot evaluate the current state of a resource; they can only deny actions based on request parameters.
D.The SCP is not applied to the root organizational unit.
AnswerC

SCPs are evaluated statically against the request's action and parameters, so a condition cannot read whether versioning is currently enabled on the bucket. The deny therefore never matches, letting users disable versioning on existing buckets.

Why this answer

The most likely reason is option C: SCPs cannot evaluate the current state of a resource; they can only deny actions based on request parameters. SCPs do not have visibility into the current configuration of resources like S3 bucket versioning. Therefore, an SCP that attempts to deny PutBucketVersioning if versioning is not enabled cannot work because it cannot check the bucket's current versioning status.

This allows users to disable versioning. Option A is incorrect because SCPs are hierarchical and cannot be overridden by another SCP unless there is an explicit allow, but the core issue is the condition evaluation. Option B is incorrect because SCPs use explicit deny, not a default deny.

Option D is incorrect because applying the SCP to the root OU would not resolve the fundamental limitation that SCPs cannot check resource state.

809
MCQeasy

A startup is designing a new web application that will be hosted on AWS. The application consists of a static frontend and a backend API. The frontend is built with React and the backend is a RESTful API built with Node.js. The startup expects low traffic initially but wants to be able to scale to millions of users. The team wants to minimize operational overhead and cost. Which architecture should they use?

A.Host the frontend and backend on a single EC2 instance using Amazon Lightsail.
B.Host the frontend on Amazon S3 with static website hosting and the backend as AWS Lambda functions behind Amazon API Gateway.
C.Host the frontend on EC2 instances behind an ALB and the backend on EC2 instances behind another ALB.
D.Host the frontend on S3 and the backend on Amazon Elastic Beanstalk with a load balancer.
AnswerB

Serverless architecture minimizes operational overhead and scales automatically.

Why this answer

S3 for static hosting and API Gateway with Lambda provides a serverless, scalable solution with low overhead. Option A is wrong because EC2 requires management. Option C is wrong because Lightsail has limited scalability.

Option D is wrong because Elastic Beanstalk has more overhead than serverless.

810
Multi-Selectmedium

A company is designing a multi-account strategy using AWS Organizations. Which TWO benefits does this approach provide? (Choose TWO.)

Select 2 answers
A.Centrally enforce policies using service control policies (SCPs).
B.Automatically create VPC peering connections between accounts.
C.Simplify cross-region replication for Amazon RDS databases.
D.Isolate workloads and provide a boundary for security and cost management.
E.Reduce the total cost of EC2 instances by aggregating usage across accounts.
AnswersA, D

SCPs attached to the root or OUs define the maximum permissions available to member accounts, letting the organisation apply guardrails once rather than replicating IAM policy in each account. This delivers the central governance benefit the multi-account design requires.

Why this answer

Option A is correct because AWS Organizations lets you attach service control policies (SCPs) to the root, OUs, or individual member accounts, providing centralized permission guardrails that define the maximum available permissions for IAM principals in those accounts. Option D is correct because separate accounts create strong isolation boundaries: resources, IAM roles, and billing are distinct per account, which limits blast radius for security incidents and enables per-account cost tracking and budgets. Option B is not a built-in benefit of Organizations; VPC peering connections must be created and accepted manually (or via automation), and Organizations does not auto-create them.

Option C is not provided by Organizations; RDS cross-region replication (e.g., cross-region read replicas) is configured per database and is unrelated to account structure. Option E is incorrect because EC2 usage is billed per account, and Organizations does not aggregate EC2 usage across accounts to reduce instance costs (though consolidated billing can aggregate volume discounts for some services, it does not reduce EC2 instance pricing in this manner).

Exam trap

The trap here is that candidates often confuse consolidated billing with direct cost reduction for EC2 instances, not realizing that aggregation only enables volume discounts and does not lower the per-instance price automatically.

811
Multi-Selecteasy

A company is planning to migrate its on-premises infrastructure to AWS. The company wants to assess the current environment and create a migration plan. Which TWO AWS services should be used for discovery and assessment?

Select 2 answers
A.AWS Server Migration Service (SMS)
B.AWS Migration Hub
C.Amazon CloudWatch
D.AWS Application Discovery Service
E.AWS Trusted Advisor
AnswersB, D

AWS Migration Hub provides a centralised view of application discovery and migration status across multiple tools, satisfying the need to assess the environment and track migration progress. It aggregates data from AWS Application Discovery Service and Migration Evaluator, letting the company plan migrations from one dashboard rather than per-service consoles.

Why this answer

AWS Application Discovery Service (D) is correct because it is purpose-built to discover on-premises servers and collect configuration, usage, and dependency data (via the agentless Discovery Connector or the Discovery Agent) that feeds migration planning. AWS Migration Hub (B) is correct because it provides a single place to track the migration status of applications across multiple migration tools, including discoveries from Application Discovery Service, which is exactly what is needed to build and monitor a migration plan. AWS Server Migration Service (A) is a migration/replication tool for moving VMs, not a discovery and assessment service.

Amazon CloudWatch (C) is a monitoring service for AWS and on-premises resources' metrics and logs, not an environment discovery tool. AWS Trusted Advisor (E) provides best-practice checks and recommendations for AWS accounts, not on-premises discovery or migration planning.

Exam trap

Candidates may assume AWS Server Migration Service (SMS) is a discovery tool because of its name, but it is actually a replication service used for migrating servers. Discovery is better handled by AWS Application Discovery Service.

812
MCQeasy

A company wants to build a serverless backend for a mobile application. The backend provides user authentication, a REST API for data access, and stores data in a NoSQL database. The company expects the application to have unpredictable traffic, and wants to minimize costs. Which solution should a Solutions Architect recommend?

A.Use IAM for authentication, EC2 instances behind an ALB for the API, and DynamoDB for the database.
B.Use Amazon Cognito for authentication, API Gateway with Lambda for the API, and Amazon DynamoDB for the database.
C.Use Amazon Cognito for authentication, API Gateway with Lambda for the API, and Amazon RDS for the database.
D.Use Amazon Cognito for authentication, API Gateway with Lambda for the API, and Amazon S3 for the database.
AnswerB

Cognito handles user authentication, API Gateway with Lambda provides a fully managed REST API that scales automatically, and DynamoDB offers serverless NoSQL storage. All three scale to zero and bill per request, matching the unpredictable traffic and cost-minimisation constraint.

Why this answer

The requirement is a serverless backend with authentication, REST API, NoSQL storage, unpredictable traffic, and minimized cost. Amazon Cognito provides managed user authentication, API Gateway with Lambda provides a fully serverless REST API that scales automatically, and DynamoDB is a serverless NoSQL database with on-demand capacity. This combination is fully serverless, scales with traffic, and charges only for usage, matching all requirements.

Exam trap

SAP-C02 often tests the misconception that RDS or S3 can serve as a NoSQL database; candidates must recognize that DynamoDB is the serverless NoSQL choice and that EC2/ALB breaks the serverless and cost-minimization requirements.

How to eliminate wrong answers

Option A is wrong because EC2 instances behind an ALB are not serverless; they require provisioning, patching, and incur costs even at idle, which is not cost-effective for unpredictable traffic. Option C is wrong because Amazon RDS is a relational database, not NoSQL, and is not serverless in the same way (Aurora Serverless exists but RDS standard requires provisioning); the question specifies NoSQL. Option D is wrong because Amazon S3 is object storage, not a NoSQL database; it lacks the query and item-level access patterns required for a mobile app's data store.

813
MCQmedium

A company is designing a data lake on AWS using Amazon S3. They need to query the data using standard SQL without moving it to a separate analytics store. Which AWS service should they use?

A.Amazon Athena
B.AWS Glue
C.Amazon QuickSight
D.Amazon Redshift Spectrum
AnswerA

Amazon Athena queries data directly in Amazon S3 using standard SQL, with no loading or transformation into a separate analytics store. This satisfies the stem's requirement to query the S3 data lake in place, since Athena reads S3 objects through its schema-on-read approach.

Why this answer

Amazon Athena is a serverless query service that runs standard SQL directly against data in Amazon S3 without loading it into a separate analytics store. It uses the AWS Glue Data Catalog for schema and charges per TB scanned, making it the correct choice for ad-hoc SQL on a data lake. The other services either catalog data, visualize it, or require a Redshift cluster.

Exam trap

SAP-C02 often tests whether candidates confuse the catalog/ETL role of AWS Glue with the query execution role of Athena — Glue catalogs data, Athena queries it.

How to eliminate wrong answers

Option B is wrong because AWS Glue is a serverless ETL and data catalog service — it discovers, catalogs, and transforms data but does not itself execute SQL queries against S3. Option C is wrong because Amazon QuickSight is a BI visualization tool that consumes data from Athena, Redshift, or other sources; it does not query S3 directly with SQL. Option D is wrong because Amazon Redshift Spectrum requires an Amazon Redshift cluster to be provisioned and running, which contradicts the requirement to avoid a separate analytics store.

814
MCQhard

A company has a multi-account environment with AWS Organizations. The security team wants to enforce that all EC2 instances launched in any account must have a specific tag key 'CostCenter'. Which approach should be used?

A.Create an IAM policy in each account that requires the tag for ec2:RunInstances.
B.Use a Service Control Policy (SCP) that denies ec2:RunInstances unless the request includes the required tag.
C.Use AWS Config rules to detect untagged instances and trigger an AWS Lambda function to tag them.
D.Configure the EC2 service to automatically add the tag to all instances.
AnswerB

An SCP denying ec2:RunInstances unless aws:RequestTag/CostCenter is present enforces the requirement centrally across every account in the organisation, satisfying the multi-account constraint without per-account tooling. Because SCPs gate IAM permissions at the organisation level, no principal in any member account can bypass the tag condition.

Why this answer

A Service Control Policy (SCP) applied at the AWS Organizations root or OU level can centrally deny the ec2:RunInstances action unless the request includes the required 'CostCenter' tag. This enforces the tagging requirement across all accounts in the organization without needing per-account IAM policies, and it cannot be overridden by account administrators.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config) with preventive controls (like SCPs), or assume that IAM policies in each account are sufficient for centralized enforcement, overlooking the fact that SCPs are the only mechanism that can enforce policies across all accounts in an organization without being overridden.

How to eliminate wrong answers

Option A is wrong because IAM policies in each account can be modified or removed by account administrators, so they do not provide centralized enforcement across a multi-account environment. Option C is wrong because AWS Config rules are detective, not preventive; they can detect untagged instances after launch but cannot block the creation of untagged instances, which violates the security team's requirement to enforce tagging at launch time. Option D is wrong because the EC2 service does not have a native feature to automatically add tags to all instances; tags must be explicitly provided in the RunInstances request or added via automation after launch.

815
MCQmedium

A company has an S3 bucket with server-side encryption using S3-Managed Keys (SSE-S3). The IAM policy shown in the exhibit is attached to a user. When the user attempts to download an object using the AWS CLI with no encryption headers, the request fails. What is the MOST likely reason?

A.The object is encrypted with SSE-KMS, not SSE-S3.
B.The user does not have the s3:GetObject permission.
C.The bucket has a bucket policy that denies all requests.
D.The policy condition requires the encryption header in the request.
AnswerD

The IAM policy's condition key evaluates request headers, so a CLI download sent without the required encryption header fails the condition and is denied. SSE-S3 itself needs no client headers, confirming the policy — not the bucket's default encryption — blocks the request.

Why this answer

The IAM policy attached to the user includes a condition that requires the presence of the `x-amz-server-side-encryption-customer-algorithm` header on the request. This header is used for SSE-C (server-side encryption with customer-provided keys) and is the only encryption header a client can supply on a GetObject request. When the user issues a download via the AWS CLI without specifying this header, the condition is not satisfied and the request is denied.

Note that SSE-S3 objects do not require any encryption header on GET requests by default, but an IAM policy can still impose such a condition, causing the request to fail if the header is omitted.

Exam trap

Candidates often assume that encryption headers are only required for uploads, but IAM and bucket policies can also require headers like `x-amz-server-side-encryption-customer-algorithm` for GET requests, even if the bucket uses SSE-S3. This trap highlights the importance of understanding all S3 condition keys.

How to eliminate wrong answers

Option A is wrong because the bucket is configured with SSE-S3, and the question states the object is encrypted with SSE-S3; there is no indication of SSE-KMS. Option B is wrong because the IAM policy explicitly grants `s3:GetObject` permission, so the user has that permission. Option C is wrong because there is no mention of a bucket policy that denies all requests; the failure is due to the condition in the IAM policy, not a blanket denial.

816
MCQmedium

A company is building a serverless data processing pipeline. Data is uploaded to an S3 bucket, which triggers a Lambda function to transform the data and store the result in another S3 bucket. The Lambda function needs to access a VPC-hosted database for enrichment. What is the MOST secure way to allow the Lambda function to access the VPC resources?

A.Assign a public IP to the Lambda function and route through an Internet Gateway.
B.Configure the Lambda function to access the VPC and use a VPC endpoint for S3.
C.Use Lambda@Edge to process data at the edge location.
D.Place the Lambda function in a public subnet and use a NAT Gateway.
AnswerB

Attaching the Lambda function to private subnets lets it reach the VPC-hosted database, while a gateway VPC endpoint for S3 keeps traffic to the bucket on the AWS network, avoiding NAT gateways and internet exposure.

Why this answer

It allows the Lambda function to be attached to a VPC, enabling it to access the VPC-hosted database securely over private IP addresses. Additionally, using a VPC endpoint for S3 ensures that data transfer between Lambda and the S3 buckets remains within the AWS network, avoiding public internet exposure and reducing data transfer costs.

Exam trap

The trap here is that candidates may think Lambda functions can be assigned public IPs or placed in public subnets like EC2 instances, but Lambda's VPC integration uses ENIs and requires private subnets, and the most secure way to access S3 from within a VPC is via a VPC endpoint, not a NAT Gateway.

How to eliminate wrong answers

Option A is wrong because assigning a public IP to a Lambda function is not supported; Lambda functions cannot have public IPs, and routing through an Internet Gateway would expose traffic to the public internet, violating security best practices. Option C is wrong because Lambda@Edge is designed for content distribution and edge processing with CloudFront, not for accessing VPC-hosted databases, and it cannot be configured to access VPC resources. Option D is wrong because placing a Lambda function in a public subnet is not possible; Lambda functions are attached to VPC subnets but do not have public IPs, and using a NAT Gateway would still route traffic through the public internet for S3 access, which is less secure and more costly than using a VPC endpoint.

817
MCQmedium

A company has a production Amazon ECS service running on Fargate. The service needs to be updated to use a new task definition with different environment variables. The company wants to perform a rolling update with minimal impact. What is the correct way to update the service?

A.Delete the existing service and recreate it with the new task definition.
B.Modify the task definition and then restart the service.
C.Update the service with the new task definition and use a rolling update deployment controller.
D.Create a new service with the new task definition and delete the old one.
AnswerC

Updating the service with the new task definition and the rolling deployment controller replaces tasks incrementally, honouring the minimum healthy percent and maximum percent settings. This satisfies the minimal-impact constraint, since capacity remains available throughout, unlike recreate, which stops all tasks before starting replacements.

Why this answer

Updating an ECS service with a new task definition while using the rolling update deployment controller (ECS) performs a controlled replacement of tasks, maintaining the desired count and minimizing downtime. This is the standard, supported way to deploy a new task definition to an existing service.

Exam trap

SAP-C02 often tests the difference between ForceNewDeployment (same task definition, just restart) and UpdateService with a new revision (actual rolling update) — candidates who pick 'restart the service' miss that restart does not change the task definition.

How to eliminate wrong answers

Option A is wrong because deleting and recreating the service causes downtime and loses service configuration, load balancer associations, and service discovery registrations. Option B is wrong because 'restarting the service' via ForceNewDeployment reuses the same task definition — it does not apply a new one. Option D is wrong because creating a new service and deleting the old one is a blue/green-style manual approach that requires duplicating load balancer and networking configuration and is not the minimal-impact rolling update the question asks for.

818
MCQhard

A company is designing a new real-time analytics platform that processes streaming data from IoT devices. The data must be ingested, processed with windowed aggregations, and stored in Amazon S3 for long-term analytics. The solution must handle late-arriving data and provide exactly-once processing semantics. Which combination of AWS services should the architect use?

A.Use Amazon Kinesis Data Firehose to ingest data and AWS Glue for processing.
B.Use Amazon EMR with Spark Streaming to process data from Kinesis Data Streams.
C.Use AWS Lambda to process records from Kinesis Data Streams and store in S3.
D.Use Amazon Kinesis Data Analytics for Apache Flink to process data from Kinesis Data Streams and output to S3.
AnswerD

Apache Flink on Kinesis Data Analytics provides event-time processing with watermarks, enabling windowed aggregations that correctly handle late-arriving IoT records, and its checkpointing delivers exactly-once semantics. Kinesis Data Streams ingests the stream, while the Flink S3 connector writes aggregated results for long-term analytics, satisfying every stated constraint.

Why this answer

Amazon Kinesis Data Analytics for Apache Flink provides built-in support for windowed aggregations, exactly-once processing semantics, and handling late-arriving data via allowed lateness and watermarking. It can output processed results directly to Amazon S3 using a Flink sink, meeting all requirements for a real-time analytics platform.

Exam trap

The trap here is that candidates often choose AWS Lambda or Kinesis Data Firehose for simplicity, overlooking the need for stateful windowed aggregations and exactly-once processing, which are not natively supported by those services.

How to eliminate wrong answers

Option A is wrong because Kinesis Data Firehose is a near-real-time ingestion service that does not support custom windowed aggregations or exactly-once processing; it delivers data with at-least-once semantics. Option B is wrong because Amazon EMR with Spark Streaming can process streaming data but does not natively provide exactly-once processing semantics without additional configuration (e.g., checkpointing and idempotent sinks), and it is not the simplest managed service for this use case. Option C is wrong because AWS Lambda processes records from Kinesis Data Streams but has a maximum execution timeout of 15 minutes and does not support stateful windowed aggregations or exactly-once processing; it is designed for lightweight, stateless transformations.

819
MCQeasy

A company uses AWS CloudFormation to deploy infrastructure. The operations team wants to automatically roll back a stack update if it fails, and receive a notification. What should be configured to meet these requirements?

A.Use AWS CloudTrail to monitor the UpdateStack API call and trigger a rollback via a Lambda function.
B.Use AWS Config rules to detect stack failure and revert changes.
C.Enable rollback on failure in the CloudFormation stack and configure an SNS notification topic.
D.Create a custom resource in the CloudFormation template that performs rollback.
AnswerC

CloudFormation's rollback-on-failure setting automatically reverts the stack to its last known stable state when an update fails, satisfying the automatic rollback requirement. Pairing it with an Amazon SNS topic delivers the failure notification. Both constraints in the stem are met natively, without custom scripting or external orchestration.

Why this answer

CloudFormation natively supports automatic rollback on stack update failure via the 'Rollback on failure' setting. By configuring an SNS notification topic on the stack, the operations team receives alerts when a rollback occurs, meeting both requirements without additional custom logic.

Exam trap

The trap here is that candidates may overcomplicate the solution by adding unnecessary services like Lambda or Config, overlooking CloudFormation's native rollback and notification capabilities that directly satisfy the requirements.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail logs API calls but does not trigger actions directly; invoking a Lambda function from CloudTrail would require additional Amazon EventBridge rules and custom rollback logic, which is unnecessary when CloudFormation provides built-in rollback. Option B is wrong because AWS Config rules evaluate resource compliance against desired configurations and cannot detect stack update failures or revert changes; they are designed for continuous compliance, not stack lifecycle management. Option D is wrong because a custom resource in a CloudFormation template runs during stack operations but cannot perform a rollback of the entire stack; rollback is a stack-level operation controlled by CloudFormation, not by individual resources.

820
MCQhard

A company is modernizing a .NET Framework application to run on AWS. The application currently uses Windows Communication Foundation (WCF) services. The company wants to minimize code changes and run on Linux. Which approach should the company take?

A.Use AWS App2Container to generate Windows containers and run on Amazon ECS with Windows.
B.Rewrite the WCF services as AWS Lambda functions using a custom runtime.
C.Port the application to .NET Core and deploy on Amazon ECS with Linux containers.
D.Containerize the application using AWS Fargate and run on Windows containers.
AnswerC

Porting to .NET Core enables the application to run on Linux, satisfying the platform constraint, while CoreWCF provides WCF service compatibility with minimal code changes. Amazon ECS with Linux containers then hosts the modernised workload, meeting both the "minimise code changes" and "run on Linux" requirements in the stem.

Why this answer

Migrating the .NET Framework application to .NET Core allows it to run on Linux with minimal code changes, as .NET Core is cross-platform. Deploying on Amazon ECS with Linux containers meets the requirement to run on Linux. Option A is incorrect because using AWS App2Container to generate Windows containers would still require Windows, not Linux.

Option B is incorrect because rewriting WCF services as AWS Lambda functions would require significant refactoring, not minimal code changes. Option D is incorrect because AWS Fargate is a compute platform, not a framework, and running Windows containers does not satisfy the requirement to run on Linux.

821
Multi-Selectmedium

A company uses AWS CodeBuild to compile and test code. The build process takes a long time because dependencies are downloaded from the internet each time. The company wants to speed up the build process. Which TWO actions should the company take? (Choose TWO.)

Select 2 answers
A.Use AWS CodeArtifact to store and retrieve dependencies
B.Use a custom Docker image in CodeBuild that includes the dependencies
C.Use local build agents to run builds in parallel
D.Increase the compute type of the build environment
E.Enable the cache feature in CodeBuild to store dependencies in Amazon S3
AnswersB, E

A custom Docker image bakes dependencies into the image layers, so CodeBuild pulls them once from Amazon ECR rather than fetching from the internet on every run. This eliminates the repeated download constraint in the stem and shortens each build.

Why this answer

Option B is correct because using a custom Docker image in CodeBuild that already includes the dependencies eliminates the need to download them from the internet on every build, directly reducing build time. Option E is correct because enabling the CodeBuild cache feature (for example, S3 caching) stores dependencies between builds so they can be reused instead of re-downloaded each time, which speeds up subsequent builds. Option A is not correct because CodeArtifact is a repository for storing and retrieving packages, but it still requires downloading dependencies during each build rather than avoiding the download entirely.

Option C is not correct because local build agents running builds in parallel address throughput, not the per-build dependency download time described. Option D is not correct because increasing the compute type provides more CPU/memory but does not eliminate the repeated dependency downloads that cause the slowdown.

Exam trap

SAP-C02 often tests the misconception that CodeArtifact or larger compute types speed up builds, when the actual bottleneck is repeated internet downloads that only pre-baked images or caching eliminate.

822
Multi-Selecteasy

A company is designing a new cloud-native application on AWS. The application will use a microservices architecture and requires a way to manage configuration data and secrets. Which THREE AWS services can be used to meet these requirements? (Choose THREE.)

Select 3 answers
A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.AWS AppConfig
D.Amazon DynamoDB
E.Amazon S3
AnswersA, B, C

AWS Secrets Manager stores and rotates credentials, API keys and database passwords, directly satisfying the secrets requirement. Its native rotation via Lambda and fine-grained IAM and resource policies suit microservices that must retrieve secrets at runtime rather than embedding them, which the stem's cloud-native constraint demands.

Why this answer

AWS Secrets Manager (A) is correct because it is purpose-built to store, rotate, and retrieve secrets such as database credentials and API keys via API calls, which fits managing secrets in a microservices application. AWS Systems Manager Parameter Store (B) is correct because it provides centralized, hierarchical storage for configuration data and secrets, with SecureString parameters encrypted by KMS, and integrates natively with AWS services and applications. AWS AppConfig (C) is correct because it is a feature of Systems Manager designed to create, validate, deploy, and roll back application configuration updates dynamically, which suits managing configuration for microservices.

Amazon DynamoDB (D) is not a configuration or secrets management service; it is a NoSQL database, so using it for this purpose would be a custom, non-purpose-built solution. Amazon S3 (E) is object storage and, while it can hold files, it lacks native secret rotation, hierarchical parameter management, and configuration deployment/validation features required here.

Exam trap

SAP-C02 often tests whether candidates can distinguish purpose-built configuration/secrets services from general-purpose storage like S3 or DynamoDB, which lack native rotation and deployment features.

823
Multi-Selectmedium

A company is migrating its on-premises applications to AWS. The company has a mix of Windows and Linux servers. The migration team wants to automate the discovery of application dependencies and track the migration progress. Which TWO AWS services should the team use? (Choose TWO.)

Select 2 answers
A.AWS Systems Manager
B.AWS Config
C.AWS Application Discovery Service
D.AWS CloudTrail
E.AWS Migration Hub
AnswersC, E

AWS Application Discovery Service uses agentless or agent-based collection to map server dependencies, network connections and process data across both Windows and Linux hosts. This directly satisfies the stem's requirement to automate discovery of application dependencies before migration, feeding that inventory into Migration Hub for progress tracking.

Why this answer

AWS Application Discovery Service (option C) is correct because it is purpose-built to automatically discover on-premises servers (both Windows and Linux via the Discovery Agent or agentless VMware collector) and map application dependencies, network connections, and performance data to support migration planning. AWS Migration Hub (option E) is correct because it provides a single location to track the progress of application migrations across multiple AWS and partner migration tools, giving the team the migration-tracking capability they require. Together these two services directly address the stated goals of dependency discovery and progress tracking.

AWS Systems Manager (option A) is for operational management of EC2 and hybrid instances (patching, run commands, inventory), not for discovering on-premises application dependencies or tracking migrations. AWS Config (option B) evaluates and records resource configuration compliance, and AWS CloudTrail (option D) logs API activity for auditing — neither performs dependency discovery or migration progress tracking.

824
MCQeasy

A company runs a batch processing job on a schedule using AWS Lambda. The job processes files from an S3 bucket and writes results to another S3 bucket. Recently, the job has been failing with the error 'Access Denied' when trying to write to the destination bucket. The Lambda function's execution role has the following IAM policy attached: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetObject", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::source-bucket/*", "arn:aws:s3:::source-bucket" ] }, { "Effect": "Allow", "Action": [ "s3:PutObject" ], "Resource": "arn:aws:s3:::destination-bucket/*" } ] } The Lambda function also has a VPC configuration to access an RDS instance. The S3 buckets are in the same region. The Solutions Architect verified that the destination bucket policy does not deny access. What is the MOST likely cause of the 'Access Denied' error?

A.The Lambda function is in a VPC without an S3 VPC endpoint, so it cannot reach S3.
B.The Lambda function does not have permissions to read from the source bucket.
C.The IAM policy does not allow s3:PutObject on the destination bucket.
D.The destination bucket policy denies the Lambda function's access.
AnswerA

Lambda functions attached to a VPC lose default internet access, so without an S3 gateway endpoint, traffic to S3 cannot route. The IAM policy already grants s3:PutObject on the destination bucket, making VPC connectivity the actual constraint causing the Access Denied error.

Why this answer

When a Lambda function is configured with a VPC, it loses default internet access and cannot reach AWS public services like S3 unless a VPC endpoint (gateway endpoint for S3) or NAT gateway is configured. The IAM policy already grants s3:PutObject on the destination bucket, and the bucket policy does not deny access, so the most likely cause is the lack of a network path to S3. This is a classic VPC networking issue in Lambda.

Exam trap

SAP-C02 often tests the interaction between VPC configuration and IAM permissions, and a common mistake is to focus solely on IAM policy syntax while ignoring that a Lambda function in a VPC without an S3 endpoint cannot reach S3 at all, regardless of permissions.

How to eliminate wrong answers

Option B is wrong because the IAM policy explicitly allows s3:GetObject and s3:ListBucket on the source bucket, so read permissions are not the issue. Option C is wrong because the policy includes an Allow statement for s3:PutObject on arn:aws:s3:::destination-bucket/*, which is the correct resource ARN for objects in the destination bucket. Option D is wrong because the scenario states the destination bucket policy does not deny access, so a bucket policy denial is not the cause.

825
Drag & Dropmedium

Drag and drop the steps to set up a Direct Connect private virtual interface in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order is: first create the virtual interface in AWS, then configure the on-premises router, establish BGP, verify availability, and finally update route tables.

Page 10

Page 11 of 14

Page 12