Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 826–900

984 questions total · 14pages · All types, answers revealed

Page 11

Page 12 of 14

Page 13
826
MCQhard

A company has a multi-account AWS environment with hundreds of accounts. The security team needs to centrally manage IAM roles for cross-account access. They want to ensure that when a role is created in a member account, it automatically adheres to the principle of least privilege and is auditable. What solution should they implement?

A.Use AWS CloudFormation StackSets to deploy IAM roles from a central template in each account.
B.Use AWS Organizations service control policies (SCPs) to deny creation of IAM roles except through AWS CloudFormation, and use a centrally managed CloudFormation template via StackSets.
C.Configure AWS Config rules to detect non-compliant roles and trigger a Lambda function to remove them.
D.Create a Lambda function that monitors CloudTrail events for role creation and sends alerts.
AnswerB

SCPs restrict member accounts to creating roles only via CloudFormation, and StackSets deploys one centrally governed template across the organisation. This enforces least privilege consistently and keeps every role creation auditable, meeting the multi-account requirement.

Why this answer

AWS Organizations SCPs can be used to deny the creation of IAM roles except through AWS CloudFormation, ensuring that roles are only created via a centrally managed template. By combining this with AWS CloudFormation StackSets, the security team can deploy IAM roles from a single template across all member accounts, enforcing the principle of least privilege and providing full auditability through CloudFormation stack events and AWS CloudTrail.

Exam trap

The trap here is that candidates often choose Option A, thinking that CloudFormation StackSets alone provide enforcement, but they miss the critical need for a preventive control (SCPs) to block manual role creation outside the template.

How to eliminate wrong answers

Option A is wrong because using CloudFormation StackSets alone to deploy IAM roles does not prevent users from creating roles manually outside the template, so it fails to enforce the principle of least privilege or ensure auditability. Option C is wrong because configuring AWS Config rules to detect non-compliant roles and trigger a Lambda function to remove them is a reactive approach that does not prevent the creation of non-compliant roles in the first place, leading to potential security gaps and operational overhead. Option D is wrong because creating a Lambda function that monitors CloudTrail events for role creation and sends alerts is also reactive; it only notifies after a role is created, without enforcing least privilege or preventing non-compliant roles from being created.

827
MCQmedium

A company runs a serverless image-processing pipeline. When an image is uploaded to an S3 bucket, an AWS Lambda function is invoked to resize it and write the output to another S3 bucket. The company wants to reduce the cost of Lambda invocations and improve performance for a new workload that processes large batches of images at scheduled intervals. The images are already stored in S3 and do not require immediate processing. What is the MOST cost-effective solution?

A.Use AWS Lambda with a larger memory allocation and increase the timeout to 15 minutes.
B.Use an AWS Step Functions state machine with parallel branches to orchestrate Lambda functions for each image.
C.Use Amazon ECS with Fargate tasks triggered by an Amazon EventBridge scheduled rule to process the images.
D.Use AWS Batch with a managed compute environment that uses Spot Instances to process the images in parallel.
AnswerD

AWS Batch is designed for batch computing workloads and can automatically provision optimal quantities of compute resources, including Spot Instances, which can significantly reduce cost. It supports parallel processing of large numbers of images and can be scheduled to run at intervals. This aligns with the requirement for cost-effective, scheduled batch processing without immediate processing needs, and avoids Lambda's per-invocation pricing model.

Why this answer

AWS Batch is purpose-built for batch computing, allowing the use of Spot Instances to reduce costs significantly. It can process large volumes of images in parallel and be scheduled to run at intervals, matching the requirement for non-urgent, cost-effective batch processing. Lambda and Fargate are more expensive for long-running, high-volume tasks, and Step Functions adds orchestration overhead without addressing the core compute cost.

Exam trap

The trap here is assuming that serverless options like Lambda or Fargate are always the most cost-effective for any workload, overlooking that batch processing with Spot Instances can be far cheaper for large, delay-tolerant jobs.

828
MCQhard

A company has a multi-account AWS environment with a central shared services VPC in a networking account. They want to allow resources in workload accounts to access a shared Amazon RDS database in the shared services VPC. The RDS database is in a private subnet. The company uses AWS Transit Gateway to connect all VPCs. They have set up a route in the workload VPC route table pointing to the Transit Gateway for the shared services VPC CIDR. However, resources in the workload accounts cannot connect to the RDS database. What is the most likely cause?

A.The security group on the RDS database does not allow inbound traffic from the workload VPC CIDR.
B.The route table associated with the subnet where the RDS database resides does not have a route back to the workload VPC CIDR via the Transit Gateway.
C.The Transit Gateway attachment for the shared services VPC is not associated with the correct Transit Gateway route table.
D.The RDS database is not publicly accessible, and the workload resources are using public IP addresses.
AnswerB

For traffic to flow between VPCs through a Transit Gateway, both the source and destination subnets must have route table entries pointing to the Transit Gateway for the other VPC's CIDR. The workload VPC has a route to the shared services VPC, but the shared services VPC subnet's route table may lack a route back to the workload VPC CIDR. This asymmetric routing causes the return traffic to be dropped, preventing the connection.

Why this answer

When connecting VPCs through a Transit Gateway, routing must be symmetric. The workload VPC has a route to the Transit Gateway for the shared services VPC CIDR, but the shared services VPC subnet's route table must also have a route back to the workload VPC CIDR via the Transit Gateway. Without this return route, the response packets cannot find their way back, and the connection fails.

This is a common pitfall in multi-VPC designs.

Exam trap

The trap here is focusing only on the forward path and forgetting that return traffic requires a route in the destination subnet's route table.

829
MCQhard

A company is designing a multi-region active-active architecture for a web application using Amazon Route 53 latency-based routing. The application runs on EC2 instances in Auto Scaling groups with Application Load Balancers in each region. The application uses an Amazon Aurora global database for its data tier. The architecture must provide the lowest possible RTO and RPO for regional failures. What should the company do to meet these requirements?

A.Configure Amazon RDS for MySQL with a cross-Region read replica and automatic failover.
B.Use Route 53 health checks to detect regional failure and automatically update the Aurora Global Database endpoint.
C.Use the Aurora Global Database failover capability to promote the secondary region to primary.
D.Use Amazon RDS Multi-AZ with synchronous replication across Regions.
AnswerC

Aurora Global Database keeps the secondary cluster continuously replicated with sub-second lag, so promoting it to primary writer achieves the lowest RTO and RPO for a regional failure. This satisfies the active-active requirement without rebuilding the data tier.

Why this answer

Amazon Aurora Global Database provides a managed cross-Region failover capability that can promote a secondary region to primary with an RTO of as low as 1 minute and an RPO of typically less than 1 second, meeting the lowest possible RTO and RPO requirements for regional failures in an active-active architecture. This is achieved through storage-level replication that is asynchronous but very low latency, and the failover operation is a single API call or can be automated via Route 53 health checks, ensuring minimal data loss and downtime.

Exam trap

The trap here is that candidates often confuse Amazon RDS Multi-AZ (which is single-Region) with cross-Region replication, or assume that Route 53 health checks alone can handle the failover without understanding that the database failover must be explicitly managed via Aurora Global Database's promotion capability.

How to eliminate wrong answers

Option A is wrong because Amazon RDS for MySQL with a cross-Region read replica does not support automatic failover; you must manually promote the read replica, resulting in higher RTO, and replication is asynchronous with potential for data loss (higher RPO). Option B is wrong because Route 53 health checks can detect regional failure and update DNS records, but they do not directly manage the Aurora Global Database endpoint; the failover must be initiated separately via the Aurora Global Database failover capability, and simply updating the endpoint does not promote the secondary region to primary. Option D is wrong because Amazon RDS Multi-AZ is designed for high availability within a single Region using synchronous replication, not across Regions; cross-Region synchronous replication is not supported, and Multi-AZ does not provide cross-Region failover.

830
MCQhard

A company has a production AWS account that is part of an AWS Organization. The account has a VPC with a NAT gateway for internet access. The security team wants to ensure that all outbound traffic to the internet flows through a centralized inspection VPC in the security account for traffic inspection. Which architecture should be used?

A.Use AWS Cloud WAN to connect the VPCs and route all outbound traffic through the inspection VPC.
B.Create a VPC peering connection between the production VPC and the inspection VPC, and route all outbound traffic through the peered connection.
C.Create a transit gateway, attach both VPCs, and configure the production VPC's route table to send all internet-bound traffic to the transit gateway, then route it through the inspection VPC's firewall.
D.Place a NAT gateway in the inspection VPC and have the production VPC route internet traffic to the NAT gateway.
AnswerC

A transit gateway provides transitive routing between the production and inspection VPCs, letting the production route table forward 0.0.0.0/0 to the inspection VPC's firewall before egress. This satisfies the requirement that all internet-bound traffic be inspected centrally.

Why this answer

A transit gateway allows you to centralize outbound internet traffic by attaching both the production VPC and the inspection VPC, then configuring the production VPC's route table to send 0.0.0.0/0 traffic to the transit gateway. The inspection VPC can then route that traffic through its firewall (e.g., a third-party appliance or AWS Network Firewall) before it reaches an internet gateway, enabling full traffic inspection while maintaining a single egress point.

Exam trap

The trap here is that candidates often assume VPC peering can be used for transitive routing or that a NAT gateway provides inspection capabilities, but VPC peering is non-transitive and NAT gateways only perform address translation, not deep packet inspection.

How to eliminate wrong answers

Option A is wrong because AWS Cloud WAN is designed for global network connectivity across multiple regions and on-premises locations, not for routing internet-bound traffic through a centralized inspection VPC within a single region; it lacks the granular route table controls needed to force internet traffic through a specific inspection VPC. Option B is wrong because VPC peering does not support transitive routing—traffic from the production VPC to the internet would need to go through the peered connection to the inspection VPC, but the inspection VPC cannot forward that traffic to its internet gateway because VPC peering does not allow a VPC to act as a transit hub for internet-bound traffic. Option D is wrong because placing a NAT gateway in the inspection VPC and routing production VPC traffic to it would require the production VPC to send internet-bound traffic directly to the NAT gateway's private IP, which is not routable across VPC boundaries without additional infrastructure; moreover, the NAT gateway itself does not provide traffic inspection capabilities.

831
MCQmedium

A company is centralizing its logging across multiple AWS accounts using a central logging account. Each application account delivers its CloudTrail logs and VPC Flow Logs to an S3 bucket in the logging account. The security team needs to query these logs using Amazon Athena. The logs are currently in separate S3 prefixes per account. The team wants to create a single Athena table that can query logs from all accounts without having to modify the table definition every time a new account is added. The logs are in CSV format for VPC Flow Logs and JSON format for CloudTrail. What is the MOST efficient solution?

A.Create a view that unions all the tables for each account, and update the view DDL when a new account is added.
B.Use AWS Glue crawlers configured to crawl the S3 bucket with a partition structure based on account ID and log type. Enable partition indexing to improve query performance.
C.Create an Athena table with partitions manually for each account and use MSCK REPAIR TABLE to add new partitions.
D.Convert all logs to Parquet format using AWS Glue ETL jobs and store them in a single prefix.
AnswerB

Glue crawlers discover new account prefixes automatically and register partitions in the Data Catalog, so the single Athena table needs no manual edits as accounts are added. Partition indexing speeds lookups. This satisfies the requirement to query all accounts without modifying the table definition.

Why this answer

Using AWS Glue crawlers configured to crawl the S3 bucket with a partition structure based on account ID and log type allows automatic discovery of new partitions as new accounts are added. The crawler can be scheduled to run periodically, updating the table metadata without manual intervention. Partition indexing improves query performance by reducing the amount of data scanned.

Option A is incorrect because updating a view requires manual DDL changes each time a new account is added. Option C is incorrect because manually managing partitions and using MSCK REPAIR TABLE still requires manual effort to add new partitions. Option D is incorrect because converting logs to Parquet adds overhead and does not solve the need for automatic partition discovery across accounts.

832
MCQeasy

A company wants to automate the creation of new AWS accounts and apply baseline security configurations. Which combination of services should be used to achieve this?

A.AWS Service Catalog and AWS Config.
B.AWS Organizations API and CloudTrail.
C.AWS Control Tower and Service Control Policies (SCPs).
D.AWS CloudFormation StackSets and IAM.
AnswerC

AWS Control Tower automates account provisioning through its Account Factory, applying baseline guardrails via mandatory and strongly recommended controls. SCPs, attached through AWS Organizations, enforce permission boundaries across those accounts, satisfying the requirement to apply baseline security configurations consistently at scale without manual setup.

Why this answer

AWS Control Tower provides a managed service to automate the creation of new AWS accounts through Account Factory, while Service Control Policies (SCPs) enforce baseline security guardrails across all accounts in the organization. This combination ensures that every new account is provisioned with consistent security policies without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Control Tower with AWS Organizations alone, forgetting that Control Tower adds automated account provisioning and pre-built security guardrails (SCPs) that Organizations alone does not provide.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog is used for creating and managing approved IT service catalogs, not for automating account creation, and AWS Config is a configuration auditing service, not a provisioning tool. Option B is wrong because the AWS Organizations API can create accounts programmatically but lacks built-in baseline security configuration enforcement; CloudTrail only logs API activity and does not apply security policies. Option D is wrong because AWS CloudFormation StackSets deploy infrastructure templates across accounts but do not automate account creation itself, and IAM manages user permissions but not account provisioning or baseline security guardrails.

833
MCQhard

A company with multiple AWS accounts wants to centralize CloudTrail logging. They create a CloudTrail trail in the management account that logs all events across all accounts and regions. However, the security team notices that some management events from member accounts are not being logged. What is the most likely cause?

A.The SCPs applied to member accounts are blocking CloudTrail from sending logs.
B.CloudTrail is a regional service and the trail is only in one region.
C.Member accounts have IAM policies that deny CloudTrail logging.
D.The trail was not created as an organization trail.
AnswerD

An organization trail is required for CloudTrail to log events from every member account into the management account's centralized S3 bucket. A standard trail only captures events within its own account, so member-account management events are silently omitted — exactly the gap described in the stem.

Why this answer

When a CloudTrail trail is created in the management account without enabling the 'organization trail' option, it only logs events for the management account itself and not for member accounts. To centralize logging across all accounts in AWS Organizations, the trail must be explicitly created as an organization trail, which automatically applies to all current and future member accounts. Without this setting, member account events are not forwarded to the management account's trail.

Exam trap

The trap here is that candidates often assume that creating a trail in the management account automatically covers all member accounts, but they overlook the explicit requirement to designate the trail as an organization trail during creation.

How to eliminate wrong answers

Option A is wrong because SCPs (Service Control Policies) can only deny or allow actions at the AWS Organizations level, but they do not block CloudTrail from sending logs; CloudTrail delivers logs to an S3 bucket, and SCPs cannot prevent that delivery unless they explicitly deny the `cloudtrail:PutEventSelectors` or similar actions, which is not the described issue. Option B is wrong because the question states the trail logs events across all regions, and CloudTrail trails can be configured as multi-region trails, so a single trail can capture events from all regions. Option C is wrong because IAM policies in member accounts do not affect CloudTrail logging; CloudTrail operates at the AWS service level and does not require IAM permissions in member accounts to log management events, as the trail is managed from the management account.

834
Multi-Selectmedium

A company is designing a data lake on Amazon S3. Data is ingested from multiple sources and stored as Parquet files partitioned by date. The company needs to ensure that only authorized users can access the data, and that the data is encrypted at rest. Which TWO actions should the company take to meet these requirements? (Choose TWO.)

Select 2 answers
A.Enable default encryption with SSE-KMS on the S3 bucket.
B.Use client-side encryption before uploading to S3.
C.Enable S3 server access logging.
D.Use a bucket ACL to grant access to the data lake.
E.Configure an S3 bucket policy that allows access only from specific IAM roles.
AnswersA, E

SSE-KMS default encryption ensures every object written to the bucket is encrypted at rest using AWS KMS keys, satisfying the encryption requirement. It also enables granular key policies and audit trails via CloudTrail, supporting control over who can decrypt the data lake contents.

Why this answer

Option A is correct because enabling default encryption with SSE-KMS on the S3 bucket ensures all objects are encrypted at rest using AWS KMS-managed keys, satisfying the encryption requirement without relying on each uploader to set encryption headers. Option E is correct because an S3 bucket policy that allows access only from specific IAM roles enforces least-privilege authorization, ensuring that only the intended IAM principals can read or write the Parquet data. Option B is not required because server-side encryption with SSE-KMS already meets the encryption-at-rest requirement, and client-side encryption adds key-management complexity without being mandated.

Option C is incorrect because S3 server access logging only records request activity for auditing; it does not control access or encrypt data. Option D is incorrect because bucket ACLs are legacy, coarse-grained access mechanisms and cannot express the fine-grained, role-based authorization that a bucket policy provides.

Exam trap

The trap is selecting client-side encryption or ACLs as primary controls when the question asks for centralized encryption and role-based access — SSE-KMS and bucket policies are the AWS-recommended best practices.

835
MCQeasy

A startup is using a single AWS account for development, testing, and production. They want to isolate environments and improve security. What is the most aligned AWS best practice?

A.Use separate VPCs within the same account.
B.Use IAM policies to restrict access per environment.
C.Create separate AWS accounts for each environment using AWS Organizations.
D.Use resource tagging to separate environments.
AnswerC

Separate accounts give each environment its own blast radius, IAM boundaries and service quotas, satisfying the isolation and security requirement. AWS Organizations centrally manages billing and governance through service control policies, while consolidated billing retains volume discounts. A single account cannot enforce hard environment boundaries, since IAM policies alone permit cross-environment access.

Why this answer

AWS best practice for isolating environments is to use separate AWS accounts for each environment (development, testing, production) managed under AWS Organizations. This provides strong security boundaries, simplifies billing, and allows for centralized governance and service control policies (SCPs).

Exam trap

SAP-C02 often tests the misconception that VPCs or IAM policies provide sufficient isolation; the best practice is to use separate AWS accounts for strong security boundaries.

How to eliminate wrong answers

Option A is wrong because separate VPCs within the same account do not provide strong isolation; IAM policies and resource sharing can still cross VPC boundaries, and a compromised account affects all environments. Option B is wrong because IAM policies alone are not sufficient for isolation; they are complex to manage and do not provide the same level of separation as separate accounts. Option D is wrong because resource tagging is for organization and cost allocation, not security isolation; tags can be easily changed and do not enforce boundaries.

836
Multi-Selecthard

Which THREE design patterns are recommended for decoupling components in a microservices architecture on AWS?

Select 3 answers
A.Use Amazon EventBridge for event-driven integration.
B.Use AWS Direct Connect for private connectivity.
C.Use Amazon SNS topics for pub/sub messaging.
D.Use Amazon SQS queues between services.
E.Use Elastic Load Balancing to distribute traffic.
AnswersA, C, D

Amazon EventBridge provides asynchronous, event-driven integration so producers publish events without knowing consumers, satisfying the decoupling requirement. Its routing rules and schema registry let services evolve independently, and native AWS service targets remove direct point-to-point calls. This contrasts with synchronous request-response patterns, which tightly couple availability and latency between microservices.

Why this answer

Amazon EventBridge (A) is correct because it provides an event bus that routes events between producers and consumers based on rules, so services publish events without knowing subscribers, achieving asynchronous decoupling. Amazon SNS topics (C) are correct because the publish/subscribe model lets a publisher fan out messages to multiple subscribing endpoints (SQS, Lambda, HTTP/S, email) without direct coupling to consumers. Amazon SQS queues (D) are correct because point-to-point queues buffer messages between services, letting producers and consumers operate independently and absorb traffic spikes or consumer downtime.

AWS Direct Connect (B) is not a decoupling pattern but a dedicated private network connection for hybrid connectivity, and Elastic Load Balancing (E) distributes synchronous traffic across targets but still requires the caller to know and directly invoke the load balancer endpoint, so neither decouples components in the event-driven sense.

Exam trap

The trap here is that candidates may confuse network connectivity solutions (Direct Connect) or load balancing (ELB) with true decoupling patterns, but decoupling in microservices requires asynchronous, event-driven or message-based integration, not synchronous request/response or network links.

837
MCQmedium

A company runs a critical application on Amazon RDS for PostgreSQL. The database experiences high read traffic. The application is read-heavy and can tolerate eventual consistency for some queries. What is the MOST effective way to improve read performance without significant architectural changes?

A.Enable Multi-AZ deployment for failover.
B.Create one or more Read Replicas in the same region.
C.Use Amazon ElastiCache to cache frequent queries.
D.Upgrade to a larger instance type.
AnswerB

Read Replicas use PostgreSQL's asynchronous streaming replication, offloading read queries to separate instances while the primary handles writes. This scales read capacity horizontally with minimal application change, and eventual consistency suits the queries that tolerate it.

Why this answer

Read Replicas offload read traffic from the primary RDS instance by serving read-only queries, and they can be created in the same region with minimal architectural change. Since the application is read-heavy and can tolerate eventual consistency for some queries, routing those queries to replicas is the most effective and least disruptive improvement. This scales read capacity horizontally without modifying the application's write path.

Exam trap

SAP-C02 often tests the distinction between high availability (Multi-AZ) and read scaling (Read Replicas) — candidates may pick Multi-AZ thinking it improves performance, but the standby does not serve reads.

How to eliminate wrong answers

Option A is wrong because Multi-AZ is for high availability and failover, not read scaling; the standby instance does not serve read traffic. Option C is wrong because ElastiCache requires application code changes to implement caching logic and does not address all read queries, only cached ones; it is also a larger architectural change. Option D is wrong because upgrading to a larger instance type is a vertical scaling approach that has limits and does not scale as effectively as adding read replicas for read-heavy workloads.

838
MCQeasy

A solutions architect is designing a web application that will run on Amazon EC2 instances behind an Application Load Balancer (ALB). The application requires that users' session data be stored and made available across all instances. Which solution is MOST cost-effective and scalable?

A.Use Amazon ElastiCache for Redis to store session data
B.Store session data on an Amazon EBS volume attached to each instance
C.Store session data in an Amazon RDS database
D.Enable sticky sessions (session affinity) on the ALB
AnswerA

ElastiCache for Redis stores session state in an in-memory, multi-AZ replicated cluster reachable by every EC2 instance, so sessions survive instance replacement and scale horizontally. This avoids the cost and write-contention of a relational database or the latency of per-instance storage.

Why this answer

Amazon ElastiCache for Redis provides a fully managed, in-memory data store that is ideal for storing session state externally from the EC2 instances. This decouples session data from the compute layer, allowing any instance to retrieve the same session data regardless of which instance originally handled the request. Redis offers sub-millisecond latency, built-in replication, and automatic failover, making it both highly scalable and cost-effective for session management at scale.

Exam trap

The trap here is that candidates often confuse sticky sessions (session affinity) as a valid solution for session persistence, but it actually undermines scalability and fault tolerance by tying a user to a single instance, which is the opposite of what a stateless, horizontally scalable architecture requires.

How to eliminate wrong answers

Option B is wrong because storing session data on an EBS volume attached to each instance creates a single point of failure and prevents instances from sharing session data; EBS volumes are tied to a single Availability Zone and cannot be concurrently accessed by multiple instances. Option C is wrong because using Amazon RDS for session data introduces unnecessary relational database overhead, higher latency for simple key-value lookups, and increased cost compared to an in-memory cache like Redis. Option D is wrong because enabling sticky sessions (session affinity) on the ALB forces traffic from a user to the same instance, which reduces scalability and defeats the purpose of horizontal scaling; if that instance fails, the session data is lost.

839
MCQmedium

A company has a multi-account AWS environment managed by AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. The roles must be automatically created in all existing and future accounts, and any changes to the roles must be applied consistently. Which solution meets these requirements with the LEAST administrative effort?

A.Use AWS Organizations service control policies (SCPs) to enforce the creation of IAM roles with specific permissions in all accounts.
B.Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share the role with all member accounts.
C.Develop a script using the AWS CLI that iterates over all accounts and creates the IAM roles, and schedule it to run regularly to catch new accounts.
D.Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack that creates the IAM roles to all accounts in the organization.
AnswerD

AWS CloudFormation StackSets with service-managed permissions can deploy stacks to all accounts in an organization, including automatically to new accounts as they are added. This allows centralized management of IAM roles, and any updates to the stack set are rolled out to all accounts, ensuring consistency with minimal effort.

Why this answer

AWS CloudFormation StackSets with service-managed permissions integrates with AWS Organizations to automatically deploy stacks to all accounts, including new ones. This enables centralized creation and updates of IAM roles across the organization without manual intervention. It provides consistency and reduces administrative effort, making it the ideal solution for this scenario.

Exam trap

The trap here is thinking that SCPs can create resources, but they only define permissions boundaries and cannot provision IAM roles.

840
Multi-Selectmedium

A large enterprise is consolidating 300 AWS accounts under AWS Organizations. The security team needs a way to centrally define and deploy IAM roles that grant break-glass access, must ensure the roles can be assumed only by members of a specific federated group, and must be able to update the roles across all accounts without logging into each account. (Choose two.)

Select 2 answers
A.Create the break-glass role in the management account and grant cross-account access to every workload account using an IAM group with an inline policy that lists each account ID.
B.Attach an SCP at the root that allows iam:CreateRole only from the management account and rely on that as the deployment mechanism for the break-glass role.
C.Define the role trust policy to require the SAML provider and a condition on the group attribute from the identity provider, so only the specified federated group can assume the role.
D.Use IAM Identity Center permission sets with a custom inline policy that embeds the break-glass trust policy, and assign the permission set to the federated group.
E.Use AWS CloudFormation StackSets with service-managed permissions and automatic deployment enabled to deploy the break-glass role to every account in the target OUs.
AnswersC, E

An IAM role trust policy can require sts:AssumeRoleWithSAML and include a condition key such as SAML:aud or a custom attribute mapped from the IdP, which restricts assumption to members of the named group. This is the standard way to scope federated access to a specific group rather than the whole directory.

Why this answer

StackSets with service-managed permissions is the supported way to deploy and update IAM roles across many organization accounts, and a trust policy conditioned on the federated group attribute is what limits assumption to the intended users. Together they satisfy both the centralized deployment and the scoped-access requirements.

Exam trap

The trap here is confusing IAM Identity Center permission sets with a mechanism for distributing an arbitrary custom role, when permission sets only generate their own auto-created roles.

841
MCQmedium

A company runs a three-tier web application on AWS. The database tier uses Amazon RDS for PostgreSQL with a single primary instance and no read replicas. The application experiences heavy read traffic during business hours, causing CPU utilization on the primary to exceed 90%. The team wants to offload read traffic without changing the application's write path. Which solution should a solutions architect recommend?

A.Increase the size of the RDS instance to a larger instance class with more vCPUs and memory.
B.Migrate the database to Amazon DynamoDB with on-demand capacity and update the application to use the DynamoDB SDK.
C.Enable Multi-AZ on the RDS instance and direct read queries to the standby instance.
D.Create an RDS read replica and configure the application to send read queries to the replica endpoint.
AnswerD

RDS read replicas use asynchronous replication from the primary and serve read-only traffic, which directly offloads read queries and reduces CPU on the primary. The application's write path remains pointed at the primary endpoint, so no write logic changes. This is the standard, lowest-effort way to scale read-heavy PostgreSQL workloads on RDS without altering the write tier.

Why this answer

Adding an RDS read replica offloads read-only queries to a separate instance, reducing CPU pressure on the primary while leaving the write path unchanged. The application can be configured to use the replica endpoint for reads and the primary endpoint for writes. This is a minimal-change, cost-effective solution that directly addresses the read-heavy bottleneck.

Exam trap

The trap here is believing that a Multi-AZ standby instance can serve read traffic, when it is a passive failover target that is inaccessible for queries.

842
MCQeasy

A company is designing a new application that will be deployed on EC2 instances across multiple Availability Zones. The application must be highly available and must automatically recover from instance failures. Which solution should the architect recommend?

A.Use a single EC2 instance in one AZ and a standby instance in another AZ
B.Use AWS Elastic Beanstalk with a single instance environment
C.Use AWS CloudFormation to launch a single instance in each AZ
D.Use an Auto Scaling group with a minimum of two instances across two Availability Zones
AnswerD

An Auto Scaling group spanning two Availability Zones with a minimum of two instances provides both multi-AZ redundancy and automatic replacement of failed instances. This directly satisfies the high availability and automatic failure recovery requirements for the EC2 deployment.

Why this answer

An Auto Scaling group with a minimum of two instances across two Availability Zones ensures that if one instance or an entire AZ fails, the remaining instance continues to serve traffic, and Auto Scaling automatically launches a replacement instance to restore the desired count. This architecture provides both high availability and automatic recovery from instance failures without manual intervention.

Exam trap

The trap here is that candidates often confuse 'high availability' with 'fault tolerance' and assume that simply having two instances in different AZs (Option C) is sufficient, but without an auto-recovery mechanism like Auto Scaling, a failed instance remains down and requires manual remediation.

How to eliminate wrong answers

Option A is wrong because a single active instance with a standby instance in another AZ does not provide automatic recovery; failover to the standby would require manual or custom scripting, and the standby instance is idle, wasting resources. Option B is wrong because AWS Elastic Beanstalk with a single instance environment runs only one EC2 instance, which is a single point of failure and cannot automatically recover from instance failures without additional configuration like a multi-instance environment. Option C is wrong because using AWS CloudFormation to launch a single instance in each AZ creates two independent instances but does not include any health-check or auto-replacement mechanism; if one instance fails, CloudFormation does not automatically replace it, and there is no load balancing or failover logic.

843
Multi-Selectmedium

A company is designing a new serverless application that uses Amazon API Gateway, AWS Lambda, and Amazon DynamoDB. The application must handle sudden spikes in traffic without throttling errors and must provide consistent low-latency responses. The company wants to minimize operational overhead. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Use DynamoDB on-demand capacity mode for the table.
B.Configure Lambda provisioned concurrency for the function to reduce cold starts.
C.Configure Lambda function reserved concurrency to ensure sufficient capacity.
D.Configure API Gateway with a usage plan and API keys to limit requests per client.
E.Enable API Gateway caching for the stage to reduce backend requests.
AnswersA, B

DynamoDB on-demand capacity mode automatically scales read and write capacity to handle sudden spikes in traffic without requiring capacity planning. It provides consistent low-latency performance and eliminates the need to manage provisioned throughput, reducing operational overhead. This is ideal for unpredictable workloads.

Why this answer

DynamoDB on-demand capacity mode automatically scales to handle traffic spikes, eliminating the need to provision capacity and reducing operational overhead. Lambda provisioned concurrency pre-warms execution environments, reducing cold starts and ensuring consistent low-latency responses. Together, these actions enable the serverless application to handle sudden spikes without throttling or performance degradation.

Exam trap

The trap here is assuming that reserved concurrency or usage plans help with spiky traffic, when they actually limit or do not address scaling.

844
MCQhard

A company is deploying a new web application on AWS that requires a highly available and scalable architecture. The application consists of a stateless web tier and a stateful database tier. The web tier runs on Amazon EC2 instances behind an Application Load Balancer. The database tier uses Amazon Aurora MySQL. The company expects variable traffic patterns and wants to automatically scale the web tier based on CPU utilization. Additionally, the company wants to ensure that the database can handle increased read traffic without manual intervention. Which combination of actions should the company take?

A.Use an Auto Scaling group with a target tracking scaling policy based on CPU utilization. Enable Aurora Auto Scaling to add read replicas based on CPU or connections.
B.Use an Auto Scaling group with a target tracking scaling policy based on CPU utilization. Use Amazon SQS to queue read requests during peak traffic.
C.Use an Auto Scaling group with a simple scaling policy based on CPU utilization. Use DynamoDB Auto Scaling for the database.
D.Use an Auto Scaling group with a step scaling policy based on CPU utilization. Use ElastiCache Auto Scaling to add cache nodes for read traffic.
AnswerA

Target tracking on CPU scales the stateless web tier automatically with variable load, while Aurora Auto Scaling adds read replicas when CPU or connection thresholds are breached. Together they satisfy both the web-tier scaling and read-capacity requirements without manual intervention.

Why this answer

Option A is correct because it pairs the two native AWS auto-scaling mechanisms that match the stated requirements: an Auto Scaling group with a target tracking policy keeps the stateless web tier's average CPU near a defined target, and Aurora Auto Scaling automatically adds/removes Aurora Replicas when a read-replica-level metric (CPU or connections) crosses a threshold. Both are managed, metric-driven, and require no manual intervention, satisfying the 'variable traffic' and 'increased read traffic' requirements.

Exam trap

SAP-C02 often tests whether candidates confuse 'scaling compute' with 'scaling database reads' — the trap is picking a queue, cache, or DynamoDB option that sounds like it offloads traffic but does not actually add Aurora read capacity.

How to eliminate wrong answers

Option B is wrong because SQS is a message queue for decoupling asynchronous workloads, not a mechanism for scaling read capacity on Aurora; queuing read requests would add latency and does not increase database read throughput. Option C is wrong because a simple scaling policy only triggers on a single CloudWatch alarm threshold with cooldowns and does not track a target value the way target tracking does, and DynamoDB Auto Scaling is irrelevant to an Aurora MySQL database. Option D is wrong because step scaling requires manually defined alarm thresholds and adjustment steps, and ElastiCache Auto Scaling scales cache nodes, not Aurora read replicas, so it does not address database read traffic.

845
MCQhard

A company is running a stateful web application on EC2 instances in an Auto Scaling group behind an ALB. The application stores session data locally on the instance. The company notices that users are frequently logged out and lose session data during scaling events. What is the MOST operationally efficient way to preserve session state?

A.Migrate session data to ElastiCache for Redis and modify the application to use it.
B.Create a custom AMI that pre-populates session data from Amazon S3.
C.Increase the Auto Scaling group's cooldown period to 600 seconds.
D.Enable sticky sessions (session affinity) on the ALB.
AnswerA

ElastiCache for Redis externalises session state into a shared, highly available store, so any instance in the Auto Scaling group can serve any user after scaling events. This removes instance-local dependency without custom replication logic, making it the most operationally efficient fix.

Why this answer

Migrating session state to ElastiCache for Redis provides a centralized, external, and highly available session store that persists independently of EC2 instance lifecycles. This ensures that when instances are terminated or added during Auto Scaling events, session data remains intact and accessible from any instance, eliminating user logouts and data loss. It is operationally efficient as it requires minimal application code changes and leverages a fully managed, in-memory data store optimized for low-latency access.

Exam trap

The trap here is that candidates often choose sticky sessions (Option D) thinking it solves session persistence, but they overlook that sticky sessions only route traffic to the same instance and do not protect against data loss when that instance is terminated during scaling events.

How to eliminate wrong answers

Option B is wrong because pre-populating a custom AMI with session data from S3 is impractical and inefficient: session data is dynamic and changes constantly, so a static AMI cannot reflect real-time session states, and this approach would require frequent AMI rebuilds and complex synchronization. Option C is wrong because increasing the cooldown period to 600 seconds only delays scaling events but does not prevent session loss when instances are eventually terminated; it also reduces the Auto Scaling group's ability to respond to load changes, potentially impacting availability. Option D is wrong because enabling sticky sessions (session affinity) on the ALB only binds a user's session to a specific instance, but if that instance is terminated during a scale-in event, the session data is still lost; it does not provide a durable, shared session store.

846
MCQhard

A company is building a real-time analytics platform that ingests data from thousands of IoT devices. The data must be processed in near real-time and stored in a data lake on Amazon S3 for long-term analysis. The company also needs to run complex SQL queries on the streaming data to detect anomalies. The solution must be highly available and scale automatically. Which combination of AWS services should a solutions architect recommend?

A.Use AWS IoT Core to ingest data, AWS Lambda to process each record, and Amazon S3 to store the data directly.
B.Use Amazon Managed Streaming for Apache Kafka (Amazon MSK) to ingest data, Amazon Kinesis Data Analytics for SQL processing, and AWS Lambda to write to Amazon S3.
C.Use Amazon Kinesis Data Streams to ingest data, AWS Glue for SQL processing, and Amazon Kinesis Data Firehose to deliver to Amazon S3.
D.Use AWS IoT Core to ingest data, Amazon Kinesis Data Analytics for SQL processing, and Amazon Kinesis Data Firehose to deliver to Amazon S3.
AnswerD

AWS IoT Core ingests device data reliably. Kinesis Data Analytics for SQL allows running continuous SQL queries on streaming data to detect anomalies. Kinesis Data Firehose delivers the processed data to S3. This combination is fully managed, scales automatically, and provides near real-time processing and storage.

Why this answer

AWS IoT Core handles IoT device ingestion at scale. Kinesis Data Analytics for SQL enables real-time SQL queries on streaming data for anomaly detection. Kinesis Data Firehose reliably delivers the processed data to S3.

This combination is fully managed, scales automatically, and meets the near real-time and storage requirements.

Exam trap

The trap here is assuming that any processing service like AWS Glue or Lambda can handle real-time streaming SQL, but Glue is batch-oriented and Lambda lacks built-in SQL capabilities.

847
MCQhard

A company is modernizing its application by breaking a monolith into microservices on Amazon EKS. The application uses a shared PostgreSQL database. The company wants to implement a database-per-service pattern. The migration must be done with zero downtime. Which approach should the company use?

A.Implement the strangler fig pattern: gradually migrate functionality and data to new services.
B.Use AWS DMS with CDC to replicate the shared database to multiple target databases.
C.Use Amazon RDS read replicas to create separate databases for each service.
D.Create new databases for each service, migrate data during a maintenance window.
AnswerA

The strangler fig pattern incrementally routes functionality and its data to new microservices while the monolith keeps serving, avoiding a big-bang cutover. This gradual, reversible migration is what achieves zero downtime with a shared PostgreSQL database.

Why this answer

The strangler fig pattern incrementally extracts functionality from the monolith into new microservices, each with its own database, while keeping the monolith running. This allows zero-downtime migration because traffic is gradually shifted, and data can be migrated in phases with dual-write or CDC synchronization. It is the standard approach for decomposing a monolith into a database-per-service architecture without downtime.

Exam trap

SAP-C02 often tests the misconception that DMS or read replicas alone can achieve database-per-service zero-downtime migration, when an incremental strangler fig approach is required.

How to eliminate wrong answers

Option B is wrong because AWS DMS with CDC replicates the shared database to multiple targets but does not address the architectural decomposition or zero-downtime cutover logic; it is a data replication tool, not a migration pattern. Option C is wrong because RDS read replicas are read-only copies of the same database, not separate databases per service, and do not support writes for each service. Option D is wrong because migrating data during a maintenance window implies downtime, violating the zero-downtime requirement.

848
MCQeasy

A company uses AWS Organizations and wants to ensure that all member accounts have AWS CloudTrail enabled and logs are delivered to a central S3 bucket in the management account. Which approach is MOST efficient?

A.Use AWS Config rules to detect accounts without CloudTrail and auto-remediate.
B.Manually enable CloudTrail in each account by logging into every account.
C.Use AWS CloudFormation StackSets to deploy a CloudTrail template to all accounts.
D.Create an SCP that requires CloudTrail to be enabled in each account.
AnswerC

CloudFormation StackSets deploy the same CloudTrail template across every account in AWS Organizations, including new accounts, with a central S3 bucket in the management account. This automates consistent, scalable enablement rather than manual per-account configuration.

Why this answer

AWS CloudFormation StackSets allow you to deploy a single CloudTrail template across all member accounts in an AWS Organization from a central management account. This approach is the most efficient as it automates the deployment, ensures consistent configuration, and delivers logs to the specified central S3 bucket without requiring manual intervention or per-account scripting.

Exam trap

The trap here is that candidates often confuse the capabilities of SCPs (which only control permissions) with resource enforcement, leading them to incorrectly select Option D, not realizing that SCPs cannot create or enable resources like CloudTrail.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can only detect non-compliance and trigger auto-remediation via Systems Manager Automation or Lambda, but they do not natively deploy CloudTrail across all accounts; they react to existing resources rather than proactively provisioning them, making them less efficient for initial deployment. Option B is wrong because manually enabling CloudTrail in each account by logging into every account is not scalable, error-prone, and violates the principle of least effort for a multi-account environment. Option D is wrong because Service Control Policies (SCPs) can only deny or allow API actions, not enforce the presence of a resource like CloudTrail; an SCP cannot require CloudTrail to be enabled—it can only block actions that disable it, which is insufficient to ensure initial enablement.

849
Multi-Selectmedium

A company is designing a new application that will run on Amazon EC2 instances in an Auto Scaling group. The application must be able to distribute incoming traffic across multiple instances. Which TWO AWS services can be used for this purpose? (Choose TWO.)

Select 2 answers
A.Amazon CloudFront
B.AWS Global Accelerator
C.Network Load Balancer
D.Application Load Balancer
E.Amazon Route 53
AnswersC, D

Network Load Balancer operates at layer 4, distributing TCP and UDP traffic across targets in the Auto Scaling group by flow hash. It satisfies the traffic-distribution requirement while preserving the client source IP address and supporting extreme throughput and low latency.

Why this answer

Option C (Network Load Balancer) is correct because it is an Elastic Load Balancing service that operates at Layer 4 (TCP/UDP/TLS) and distributes incoming traffic across targets such as EC2 instances in an Auto Scaling group, using listeners and target groups. Option D (Application Load Balancer) is correct because it is an Elastic Load Balancing service that operates at Layer 7 (HTTP/HTTPS) and also distributes incoming traffic across EC2 instances registered in target groups within an Auto Scaling group. Both load balancers integrate with Auto Scaling groups so that instances added or removed by scaling are automatically registered or deregistered as targets.

Option A (Amazon CloudFront) is a content delivery network that caches and serves content from edge locations, not a load balancer for distributing traffic across EC2 instances. Option B (AWS Global Accelerator) improves global reachability and performance by routing traffic over the AWS global network to endpoints, but it is not the primary service for distributing traffic across multiple EC2 instances in an Auto Scaling group. Option E (Amazon Route 53) is a DNS service that can perform DNS-based routing, but it does not distribute incoming traffic across EC2 instances at the connection level like a load balancer.

Exam trap

The SAP-C02 exam often tests the distinction between services that perform actual load balancing (ALB, NLB) versus services that provide DNS-based routing (Route 53) or content delivery (CloudFront) or global traffic optimization (Global Accelerator), leading candidates to mistakenly select Route 53 or CloudFront as load balancers.

850
Multi-Selecteasy

A company is designing a new application that will process images uploaded by users. The application must automatically resize images and store them in Amazon S3. The solution should be serverless and event-driven. Which THREE AWS services should be used together? (Choose three.)

Select 3 answers
A.Amazon S3
B.AWS Lambda
C.Amazon EC2
D.Amazon Simple Queue Service (SQS)
E.Amazon S3 Event Notification
AnswersA, B, E

Amazon S3 provides the event source: uploads emit `s3:ObjectCreated:*` notifications that trigger downstream compute, satisfying the event-driven requirement without polling. It also serves as the durable storage target for resized images, meeting the serverless constraint since no servers are provisioned or managed for either ingestion or persistence.

Why this answer

Amazon S3 (A) is correct because it serves as the storage layer where users upload the original images and where the resized images are ultimately stored, making it the foundation of this event-driven, serverless design. AWS Lambda (B) is correct because it provides the serverless compute that runs the image-resizing code in response to events, eliminating the need to manage servers. Amazon S3 Event Notification (E) is correct because it is the event source that detects object-created events (e.g., s3:ObjectCreated:*) on the upload bucket and triggers the Lambda function, enabling the required event-driven behavior.

Amazon EC2 (C) is not appropriate because it requires provisioning and managing virtual servers, which contradicts the serverless requirement. Amazon Simple Queue Service (D) is not needed here because S3 Event Notifications can invoke Lambda directly, so no queue is required to decouple the upload from the processing in this scenario.

Exam trap

The trap is over-engineering the solution by adding SQS for 'decoupling' when the question explicitly asks for a serverless, event-driven design that only needs S3, Lambda, and S3 Event Notifications.

851
MCQhard

A company is modernizing a monolithic application by decomposing it into microservices. The application currently uses a single MySQL database. The company wants to use a polyglot persistence approach, with different microservices using the most appropriate database type. The team has limited experience with NoSQL databases. Which strategy should the team use to minimize risk during the migration?

A.Rewrite the entire application as microservices using a new database for each service from the start
B.Use the strangler fig pattern to incrementally replace parts of the monolith with microservices, starting with a non-critical function
C.Migrate the entire monolith to a containerized application on Amazon ECS in one go
D.Use AWS DMS to replicate the monolith's database to multiple target databases simultaneously
AnswerB

The strangler fig pattern routes traffic incrementally to new microservices while the monolith keeps running, so the team can adopt unfamiliar NoSQL stores one bounded, non-critical function at a time and roll back easily, directly minimising migration risk.

Why this answer

The strangler fig pattern allows incremental migration by routing specific functionality to new microservices while the monolith continues to serve the rest. Starting with a non-critical function reduces risk because failures are contained and the team can gain NoSQL experience without impacting core business operations. This approach aligns with the AWS Well-Architected Framework's guidance on evolutionary architectures and minimizes blast radius during modernization.

Exam trap

SAP-C02 often tests the misconception that a full rewrite or lift-and-shift is faster, but the exam expects you to prioritize risk reduction and incremental modernization, especially when teams lack experience with new technologies.

How to eliminate wrong answers

Option A is wrong because a full rewrite with new databases from the start introduces massive risk, requires simultaneous mastery of microservices and NoSQL, and often leads to project failure due to scope and complexity. Option C is wrong because containerizing the monolith in one go does not address polyglot persistence or microservices decomposition; it merely repackages the monolith and still requires a database migration, which is risky if done all at once. Option D is wrong because replicating the monolith's database to multiple targets via AWS DMS does not decompose the application or enable polyglot persistence per microservice; it creates data duplication and consistency challenges without architectural change.

852
MCQhard

A solutions architect attempts to create this stack but receives an error: "Value of property SecurityGroups must be a list of strings". What is the likely cause?

A.The SecurityGroups property should be a list, but the YAML specifies a single reference incorrectly.
B.The security group ingress rule allows SSH from anywhere.
C.There is a circular dependency between the EC2 instance and the security group.
D.The AMI ID is invalid.
AnswerA

CloudFormation expects SecurityGroups as a YAML list, so supplying a bare scalar reference rather than a sequence produces the type error. Correcting the syntax to a list of strings resolves the validation failure described in the stem.

Why this answer

The error 'Value of property SecurityGroups must be a list of strings' occurs because the YAML template specifies the SecurityGroups property as a single string (e.g., !Ref MySecurityGroup) instead of a list of strings (e.g., [!Ref MySecurityGroup]). In AWS CloudFormation, the SecurityGroups property for an EC2 instance expects a list of security group IDs or names, even if only one security group is provided. The YAML syntax must wrap the reference in square brackets to form a list, or the template will fail validation.

Exam trap

The trap here is that candidates may confuse the SecurityGroups property with SecurityGroupIds, or assume that a single reference can be passed as a scalar, but CloudFormation strictly enforces the list type for SecurityGroups even when only one security group is used.

How to eliminate wrong answers

Option B is wrong because allowing SSH from anywhere (0.0.0.0/0) is a security concern but does not cause a 'list of strings' error; it would only trigger a security review or a different validation error if the template explicitly forbids it. Option C is wrong because a circular dependency between the EC2 instance and the security group would cause a stack creation failure with a 'circular dependency' error, not a type mismatch error about SecurityGroups. Option D is wrong because an invalid AMI ID would produce an error like 'AMI ID not found' or 'InvalidAMIID.NotFound', not a property type validation error.

853
MCQmedium

A company is using an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application has a health check endpoint at /health. Recently, the ALB is marking instances as unhealthy even though the application is running. The health check settings are: interval 30 seconds, timeout 5 seconds, unhealthy threshold 2. What is the most likely cause?

A.The health check interval of 30 seconds is too long.
B.The unhealthy threshold of 2 is too high.
C.The health check timeout of 5 seconds is too short for the application to respond.
D.The health check path /health is not accessible from the ALB.
AnswerC

When the application's response exceeds five seconds, the ALB health check times out and counts a failure; two consecutive failures within the 30-second interval mark the instance unhealthy. Lengthening the timeout above the application's response time resolves the false unhealthy status.

Why this answer

The most likely cause is that the health check timeout of 5 seconds is too short for the application to respond to /health within the allotted time (C). If the application takes longer than 5 seconds to respond — due to slow database calls, cold starts, or heavy load — the ALB marks the check as failed. After two consecutive failures (unhealthy threshold 2), the instance is marked unhealthy even though the process is running.

Exam trap

SAP-C02 often tests whether candidates blame the interval or threshold settings when the real culprit is a timeout that is shorter than the application's response time — a classic false-unhealthy scenario.

How to eliminate wrong answers

Option A is wrong because a 30-second interval is a reasonable default; a longer interval would actually delay detection, not cause false unhealthy markings. Option B is wrong because a higher unhealthy threshold would make the ALB more tolerant, not less — the current threshold of 2 is standard and not the cause. Option D is wrong because if /health were inaccessible, the application would fail all checks consistently; the question states the application is running, and the most likely cause is a timeout rather than a routing/path issue (though path misconfiguration is a possible secondary cause, the timeout is the specific setting called out).

854
Drag & Dropmedium

Drag and drop the steps to migrate an on-premises MySQL database to Amazon RDS using AWS DMS in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create the replication instance, then endpoints, then the migration task, start it, and finally cut over.

855
MCQmedium

A financial services company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application is deployed across multiple Availability Zones. The company recently experienced a DDoS attack that overwhelmed the ALB and caused downtime. The security team wants to implement a solution that can absorb DDoS attacks at the edge and only forward legitimate traffic to the ALB. Additionally, the company needs to protect sensitive data in transit using TLS 1.3. What should the solutions architect do?

A.Deploy Amazon CloudFront in front of the ALB with AWS Shield Advanced and enforce TLS 1.3.
B.Use AWS WAF with rate-based rules and associate it with the ALB.
C.Use an AWS Network Firewall and configure stateful rules to block malicious IPs.
D.Enable AWS Shield Standard and use security groups to restrict traffic.
AnswerA

CloudFront absorbs volumetric DDoS at edge locations, forwarding only legitimate traffic to the ALB, satisfying the edge-absorption constraint. Shield Advanced adds enhanced mitigation and cost protection. CloudFront supports TLS 1.3 via security policies, meeting the in-transit encryption requirement. ALB alone cannot absorb edge-level attacks.

Why this answer

Amazon CloudFront is a global content delivery network that caches content at edge locations, absorbing volumetric DDoS attacks before they reach the origin ALB. AWS Shield Advanced provides enhanced DDoS protection with 24/7 access to the AWS DDoS Response Team (DRT) and cost protection, and CloudFront supports TLS 1.3 for encryption in transit. Together, they meet the requirements of edge absorption and TLS 1.3 enforcement.

Exam trap

SAP-C02 often tests the misconception that AWS WAF or Shield Standard alone can absorb large-scale DDoS attacks, but only CloudFront with Shield Advanced provides edge absorption and advanced mitigation.

How to eliminate wrong answers

Option B is wrong because AWS WAF rate-based rules only block requests exceeding a threshold at the ALB, but they do not absorb large-scale DDoS attacks at the edge; the ALB can still be overwhelmed. Option C is wrong because AWS Network Firewall is a VPC-level firewall that inspects traffic after it enters the VPC, not at the edge, and it does not provide DDoS absorption or TLS 1.3 termination. Option D is wrong because AWS Shield Standard is automatically enabled and only protects against common network-layer attacks; it does not provide advanced DDoS mitigation or edge absorption, and security groups cannot mitigate volumetric attacks.

856
MCQmedium

A company is designing a new application that will run on Amazon ECS with Fargate. The application must process messages from an Amazon SQS queue and store results in an Amazon DynamoDB table. The workload is unpredictable and can scale from 0 to thousands of messages per second. What is the MOST cost-effective and scalable architecture?

A.Run an Amazon ECS service with Fargate that polls the SQS queue and writes to DynamoDB. Configure auto scaling based on CPU utilization.
B.Use an Amazon ECS service with Fargate and a target tracking scaling policy based on SQS queue depth.
C.Use Amazon Kinesis Data Streams to ingest messages and an AWS Lambda function to process and write to DynamoDB.
D.Use an AWS Lambda function with an SQS trigger to process messages and write to DynamoDB.
AnswerD

Lambda with an SQS trigger scales automatically from zero to thousands of messages per second and charges only per invocation, eliminating idle Fargate task costs. It writes directly to DynamoDB, making it the most cost-effective and scalable choice for unpredictable workloads.

Why this answer

AWS Lambda with an SQS event source mapping is the most cost-effective and scalable choice because Lambda scales automatically and nearly instantly with the number of messages, charging only per invocation and execution time — with no cost when idle. It natively integrates with SQS (polling in batches, handling visibility timeouts, and deleting messages on success) and can write to DynamoDB with built-in retry and DLQ support. For a workload that can drop to zero, Lambda avoids the baseline cost of running an always-on ECS service.

ECS with Fargate, by contrast, requires at least one running task (or complex scaling to zero) and adds management overhead without a cost advantage at this scale.

Exam trap

SAP-C02 often tests the misconception that ECS/Fargate with auto scaling is always the most cost-effective for variable workloads, when in fact Lambda's scale-to-zero and per-invocation pricing make it the better choice for unpredictable, queue-driven processing.

How to eliminate wrong answers

Option A is wrong because CPU-based auto scaling on ECS/Fargate does not correlate well with SQS queue depth — the service may not scale out fast enough when messages spike, and it cannot scale to zero, so it is neither the most scalable nor the most cost-effective. Option B is wrong because although target tracking on SQS queue depth is better than CPU scaling, an ECS/Fargate service still cannot scale to zero and incurs cost for idle tasks; it also requires more operational overhead than Lambda's native SQS integration. Option C is wrong because Kinesis Data Streams is designed for ordered, high-throughput streaming with provisioned or on-demand shards, not for a simple SQS-style queue; it adds unnecessary cost and complexity, and Lambda with an SQS trigger is simpler and cheaper for this use case.

857
MCQhard

A company is designing a serverless application that uses AWS Lambda to process events from Amazon DynamoDB Streams. The Lambda function updates an Amazon RDS for MySQL database. The company expects a high volume of updates and is concerned about the Lambda function causing too many connections to the database. How should the company design the solution to manage the database connection pool effectively?

A.Increase the Lambda function timeout and use a single database connection per function instance.
B.Use Amazon RDS Proxy to pool database connections, and configure the Lambda function to connect through the proxy.
C.Use a singleton Lambda function with a reserved concurrency of 1 to ensure only one connection is used.
D.Use a Lambda function that batches records from DynamoDB Streams and uses a single database connection per batch.
AnswerB

RDS Proxy maintains a shared pool of database connections and multiplexes Lambda invocations onto them, so each concurrent function no longer opens its own MySQL connection. This directly addresses the stem's concern about excessive connections during high-volume updates.

Why this answer

Amazon RDS Proxy sits between the Lambda function and the RDS database, maintaining a pool of established connections. When Lambda invocations scale up, they reuse connections from the pool instead of opening new ones, preventing the database from being overwhelmed. This is the recommended AWS pattern for serverless applications with high concurrency and relational databases.

Exam trap

The trap here is that candidates often think batching or reducing concurrency is the solution, but the real challenge is managing connection reuse under elastic scaling, which only a dedicated proxy like RDS Proxy can solve without sacrificing throughput.

How to eliminate wrong answers

Option A is wrong because increasing the Lambda timeout does not reduce the number of connections; each concurrent invocation still opens its own connection, and a single connection per instance does not scale safely under high concurrency. Option C is wrong because setting reserved concurrency to 1 cripples throughput and defeats the purpose of using DynamoDB Streams, which expects parallel processing; it also does not address connection pooling, as the single instance still opens one connection per invocation. Option D is wrong because batching records does not reduce the number of concurrent Lambda invocations; each batch still runs in its own instance and opens a separate database connection, so the connection count remains high.

858
MCQmedium

A global company is using a multi-account AWS Organizations setup with a centralized logging account. They want to aggregate CloudTrail logs from all accounts into a single S3 bucket in the logging account. Which combination of steps will meet this requirement?

A.Create an IAM role in each account that allows the logging account to assume and copy logs. Schedule a Lambda function to copy logs hourly.
B.Create an S3 bucket in the logging account with a bucket policy that grants read/write access to all accounts. Configure each account's CloudTrail to deliver to that bucket.
C.Create a CloudTrail trail in the management account that applies to all accounts in the organization, and specify the S3 bucket in the logging account as the destination.
D.Enable AWS Config in each account and stream configuration history to a centralized S3 bucket.
AnswerC

An organisation trail created in the management account automatically applies to every account in the organisation, delivering events to the specified S3 bucket in the logging account. This satisfies aggregation without configuring trails per member account.

Why this answer

AWS Organizations allows you to create a single CloudTrail trail in the management account that automatically applies to all member accounts. By specifying the S3 bucket in the centralized logging account as the destination, CloudTrail delivers logs from every account directly to that bucket without needing cross-account IAM roles or manual copying. This leverages the organization trail feature, which simplifies log aggregation and ensures consistent logging across the entire organization.

Exam trap

The trap here is that candidates often assume they need to configure CloudTrail in each account individually or use cross-account IAM roles to copy logs, but AWS Organizations provides a native organization trail feature that automatically aggregates logs from all accounts into a single S3 bucket in a centralized logging account.

How to eliminate wrong answers

Option A is wrong because it introduces unnecessary complexity and latency by requiring an IAM role in each account and a scheduled Lambda function to copy logs hourly, which is not real-time and violates the principle of least privilege by granting cross-account copy permissions. Option B is wrong because CloudTrail does not support delivering logs to an S3 bucket in a different account using a bucket policy that grants read/write access to all accounts; CloudTrail requires the destination bucket to be in the same account as the trail or uses an organization trail with a bucket policy that grants CloudTrail service principal write access, not all accounts. Option D is wrong because AWS Config streams configuration history and changes, not CloudTrail logs, and it does not aggregate CloudTrail API activity logs; it serves a different purpose for compliance and resource tracking.

859
MCQmedium

A company is designing a new microservices application on AWS. The application consists of several services that need to communicate asynchronously. One service generates orders and sends them to a processing service. The order volume can vary significantly, and the processing service must scale independently. The company wants to use a managed service to decouple the services and ensure that messages are not lost. The processing service is written in Python and runs on AWS Lambda. The solutions architect needs to design the message delivery mechanism. The architect decides to use Amazon SQS. However, the Lambda function sometimes fails to process a message due to a transient error, and the message should be retried. After a maximum of three retries, the message should be moved to a dead-letter queue for analysis. Which configuration should the architect use?

A.Configure the SQS DLQ with a redrive policy that allows messages to be sent back to the source queue after 3 retries.
B.Configure the SQS queue with a visibility timeout of 6 minutes and a redrive policy with maxReceiveCount of 3, pointing to a DLQ.
C.Configure the SQS queue with a visibility timeout of 30 seconds and a redrive policy with maxReceiveCount of 3, pointing to a DLQ.
D.Configure Lambda with a reserved concurrency of 1 and set the SQS queue's redrive policy to maxReceiveCount of 3.
AnswerB

The redrive policy's maxReceiveCount of 3 moves a message to the DLQ after three failed receives, satisfying the retry limit. The visibility timeout must exceed the Lambda function's execution time so the message stays hidden during processing, preventing premature redelivery.

Why this answer

The stem does not state the Lambda function timeout, so the visibility timeout cannot be determined from the given information. The redrive policy with maxReceiveCount of 3 correctly moves messages to a DLQ after three failed receives, but the visibility timeout must be at least the Lambda function timeout to avoid duplicate processing. Since the function timeout is unspecified, the question should either provide the Lambda timeout or focus on the redrive policy configuration rather than an arbitrary visibility timeout value.

Exam trap

The trap is assuming a visibility timeout value without knowing the Lambda function timeout, or misunderstanding that the redrive policy sends messages to a DLQ rather than back to the source queue.

How to eliminate wrong answers

Option A is wrong because a redrive policy does not send messages back to the source queue; it sends them to a DLQ. Option C is wrong because a visibility timeout of 30 seconds might be too short if the Lambda function takes longer, causing duplicate processing. Option D is wrong because reserved concurrency of 1 does not affect retry logic and could throttle processing, but the redrive policy is correct; however, the visibility timeout is not specified, and the main issue is the retry configuration.

860
MCQeasy

A retail company is deploying a new static website on AWS. The website consists of HTML, CSS, JavaScript, and image files. The company wants to serve the content globally with low latency, minimize cost, and avoid managing any servers. The website must use a custom domain name with HTTPS. Which solution should a solutions architect recommend?

A.Host the website on Amazon S3 with static website hosting enabled, and use Amazon Route 53 with a public hosted zone to serve the content over HTTPS directly from the S3 website endpoint.
B.Host the website on Amazon S3 with static website hosting enabled, and use Amazon CloudFront with an AWS Certificate Manager (ACM) certificate for the custom domain.
C.Host the website on AWS Elastic Beanstalk with a load-balanced environment, and configure HTTPS using a self-signed certificate.
D.Host the website on Amazon EC2 instances behind an Application Load Balancer, and use an ACM certificate for HTTPS termination.
AnswerB

S3 static website hosting serves the files without any servers, and CloudFront caches content at edge locations worldwide for low latency. ACM provides a free public certificate for the custom domain, which can be associated with the CloudFront distribution. This combination meets the global low-latency, cost, no-server, and HTTPS requirements.

Why this answer

A static website on S3 with CloudFront provides serverless hosting, global edge caching for low latency, and cost efficiency. ACM issues a free certificate for the custom domain, enabling HTTPS on the CloudFront distribution. This combination meets all requirements without managing servers and is the standard AWS solution for static websites.

Exam trap

The trap here is assuming that an S3 static website endpoint itself can serve content over HTTPS with a custom domain.

861
MCQhard

A company is designing a disaster recovery solution for a critical database using Amazon RDS Multi-AZ. However, they also need to protect against regional failures. Which additional AWS service should they use?

A.RDS Multi-AZ in the same region
B.RDS Cross-Region Read Replicas
C.Amazon S3
D.AWS Database Migration Service
AnswerB

RDS Cross-Region Read Replicas asynchronously copy data to a different Region, providing a standalone database that can be promoted during a regional outage. This satisfies the protection-against-regional-failures constraint that Multi-AZ, confined to one Region, cannot address.

Why this answer

RDS Multi-AZ provides high availability within a single region by synchronously replicating data to a standby instance in a different Availability Zone. To protect against a regional failure, you need a cross-region disaster recovery solution. RDS Cross-Region Read Replicas asynchronously replicate data to a different AWS Region, allowing you to promote the replica to a standalone primary database in the event of a regional outage.

Exam trap

The trap here is that candidates confuse Multi-AZ (which is high availability within a region) with cross-region disaster recovery, assuming Multi-AZ alone provides regional protection.

How to eliminate wrong answers

Option A is wrong because RDS Multi-AZ in the same region only protects against Availability Zone failures, not regional failures; it does not replicate data across AWS Regions. Option C is wrong because Amazon S3 is an object storage service and cannot serve as a direct disaster recovery target for a relational database; it lacks native database replication and failover capabilities. Option D is wrong because AWS Database Migration Service (DMS) is designed for one-time or ongoing migrations, not for automated, low-RPO disaster recovery with automatic failover; it requires manual intervention to promote a target database.

862
MCQmedium

A company has a multi-account environment with a central security account. They want to use AWS Security Hub to aggregate findings from all accounts. What is the correct setup?

A.Set up Amazon EventBridge to forward findings from each account to the central account.
B.Use Amazon CloudWatch cross-account dashboards to view findings.
C.Enable AWS Config aggregator in the central account.
D.Enable Security Hub in the central account and invite member accounts to enable Security Hub.
AnswerD

Security Hub aggregation requires enabling it in the central account as the administrator, then inviting member accounts to enable Security Hub and accept the invitation. Findings from all accounts then flow into the central account, satisfying the multi-account aggregation requirement.

Why this answer

AWS Security Hub uses a multi-account architecture where a central administrator account invites member accounts to enable Security Hub. This allows the administrator account to aggregate findings, insights, and compliance scores from all member accounts into a single view, enabling centralized security monitoring without additional forwarding infrastructure.

Exam trap

The trap here is that candidates confuse Security Hub's multi-account model with other aggregation services like AWS Config aggregator or CloudWatch cross-account dashboards, assuming any cross-account aggregation tool can consolidate Security Hub findings, when in fact Security Hub requires its own dedicated multi-account feature.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge can forward events but is not the native mechanism for Security Hub multi-account aggregation; Security Hub uses its own invitation-based model, and EventBridge would require custom event buses and rules, adding unnecessary complexity and missing native cross-account finding consolidation. Option B is wrong because Amazon CloudWatch cross-account dashboards aggregate metrics and logs, not Security Hub findings; Security Hub findings are not stored in CloudWatch Logs or Metrics by default, so dashboards cannot display them. Option C is wrong because AWS Config aggregator aggregates AWS Config rules and compliance data across accounts, not Security Hub findings; Security Hub findings are separate from AWS Config and require Security Hub's own multi-account enablement.

863
MCQhard

A company uses AWS Organizations with hundreds of accounts. The security team needs to ensure that no IAM user in any account can create a new IAM user or access key. What is the most scalable way to enforce this?

A.Use AWS Config rules to detect and automatically delete any new users or keys.
B.Enable AWS CloudTrail and create a metric filter to alert on these actions.
C.Attach an IAM policy to the Administrator role in each account that denies these actions.
D.Apply a service control policy (SCP) that denies the iam:CreateUser and iam:CreateAccessKey actions.
AnswerD

SCPs apply to all principals in the account.

Why this answer

Service control policies (SCPs) are the most scalable way to enforce restrictions across all accounts in an AWS Organization because they apply to all IAM users and roles in every member account, including the root user. By denying the iam:CreateUser and iam:CreateAccessKey actions at the organization root or OU level, the security team can prevent any IAM user from creating new users or access keys without needing to manage individual account policies or rely on reactive measures.

Exam trap

The trap here is that candidates often choose Option C because they think attaching a deny policy to the Administrator role is sufficient, but they overlook that SCPs are the only mechanism that can restrict the root user and scale across hundreds of accounts without per-account management.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are reactive—they detect non-compliant resources after creation and can trigger auto-remediation, but they do not prevent the action from occurring, leaving a window where the user or key exists and could be used. Option B is wrong because CloudTrail with metric filters and alerts only provides notification after the fact; it does not block the action, so the security violation still occurs. Option C is wrong because attaching an IAM policy to the Administrator role in each account is not scalable for hundreds of accounts—it requires manual per-account configuration and does not prevent actions by the root user or other roles that might bypass the policy.

864
MCQeasy

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application experiences variable traffic patterns, and the operations team wants to optimize costs by using a mix of On-Demand and Spot Instances. The team also wants to ensure that the application remains available even if some instances are terminated. Which solution should a solutions architect recommend?

A.Configure the Auto Scaling group to use a launch template with a mixed instances policy that includes On-Demand and Spot Instances, and enable capacity rebalancing.
B.Create two separate Auto Scaling groups, one for On-Demand and one for Spot, and use an Application Load Balancer to distribute traffic between them.
C.Use a launch template with only On-Demand Instances and enable detailed monitoring to manually replace instances when Spot prices are low.
D.Use a single launch configuration with only Spot Instances and set the Auto Scaling group to use a low desired capacity.
AnswerA

A mixed instances policy allows the Auto Scaling group to launch a combination of On-Demand and Spot Instances, which can reduce costs while maintaining availability. Enabling capacity rebalancing proactively replaces Spot Instances that are at risk of termination, helping to maintain the desired capacity and improve resilience.

Why this answer

The correct solution is to use a mixed instances policy with On-Demand and Spot Instances and enable capacity rebalancing. This allows the Auto Scaling group to automatically manage a mix of instance purchasing options, reducing costs while maintaining availability. Capacity rebalancing helps proactively replace Spot Instances that are at risk of interruption, ensuring the group maintains its desired capacity.

Exam trap

The trap here is assuming that using only Spot Instances with a low desired capacity will be sufficient for availability, when Spot interruptions can cause capacity shortfalls.

865
MCQmedium

A company runs a stateful web application on EC2 instances in an Auto Scaling group. The application uses a shared EFS file system for persistent data. The operations team notices that during scale-in events, some requests fail because the instance is terminated while still processing. What is the BEST way to prevent request failures during scale-in?

A.Use a Network Load Balancer with connection draining enabled
B.Increase the cooldown period for the Auto Scaling group
C.Decrease the scale-in threshold to reduce the frequency of termination
D.Use lifecycle hooks to put the instance in a 'terminating:wait' state and complete request processing
AnswerD

Lifecycle hooks hold the instance in a terminating:wait state before Auto Scaling proceeds, letting in-flight requests finish and the EFS mount unmount cleanly. This directly satisfies the stem's constraint: preventing request failures when scale-in terminates an instance mid-processing. Complete the lifecycle action to release the instance.

Why this answer

Lifecycle hooks allow the Auto Scaling group to put the instance in a 'terminating:wait' state, giving it time to complete processing existing requests before termination. Option A (Network Load Balancer with connection draining) can help drain new connections but does not ensure that in-flight requests are completed, especially for a stateful application using EFS. Option B (increase cooldown) only delays scaling decisions and does not prevent termination of an instance that is already processing.

Option C (decrease scale-in threshold) reduces the frequency of scale-in events but does not prevent request failures when termination occurs.

866
MCQhard

A company is designing a new data lake solution on AWS using Amazon S3 as the storage layer. The data lake will be used by multiple teams for analytics and machine learning. The company needs to enforce fine-grained access control at the object level, enable auditing of data access, and ensure that sensitive data is masked for unauthorized users. Which combination of AWS services should be used?

A.Use S3 bucket policies and S3 access logs for auditing.
B.Use Amazon Macie to discover sensitive data and apply S3 bucket policies to restrict access.
C.Use IAM policies with condition keys and enable AWS CloudTrail for auditing.
D.Use AWS Lake Formation for fine-grained access control and auditing, and Amazon S3 Object Lambda to mask data on the fly.
AnswerD

AWS Lake Formation enforces column-, row- and cell-level permissions at the table level, satisfying the fine-grained access and audit requirements, while Amazon S3 Object Lambda intercepts GET requests to redact or mask sensitive fields before delivery, meeting the masking constraint without duplicating data.

Why this answer

AWS Lake Formation provides fine-grained access control at the column, row, and cell level for data in S3, and it integrates with AWS CloudTrail for auditing data access. Amazon S3 Object Lambda can transform data on the fly, such as masking sensitive fields, before returning it to the requester, meeting the requirement to mask data for unauthorized users.

Exam trap

The trap here is that candidates often assume IAM policies or S3 bucket policies alone can achieve fine-grained access control, but they lack the column/row-level granularity and dynamic data masking that Lake Formation and S3 Object Lambda provide.

How to eliminate wrong answers

Option A is wrong because S3 bucket policies alone cannot enforce fine-grained access control at the object level (e.g., column or row level), and S3 access logs provide basic request logging but lack the granular auditing and data masking capabilities required. Option B is wrong because Amazon Macie discovers sensitive data but does not enforce access control or mask data; S3 bucket policies are too coarse for fine-grained control and cannot mask data on the fly. Option C is wrong because IAM policies with condition keys can restrict access based on attributes like tags or IP, but they cannot provide column/row-level permissions or mask sensitive data; AWS CloudTrail logs API calls but does not enable real-time data masking.

867
MCQhard

A company is migrating a legacy monolithic application to a microservices architecture on AWS. The application has a relational database with complex queries. The team wants to minimize changes to the existing codebase. Which database migration strategy should be recommended?

A.Use Amazon RDS for MySQL or PostgreSQL with read replicas.
B.Use Amazon Aurora Serverless to reduce management.
C.Store data in Amazon S3 and use Athena for queries.
D.Migrate to Amazon DynamoDB for scalability.
AnswerA

RDS for MySQL or PostgreSQL preserves the relational schema and complex SQL, so the application's queries and drivers continue working with minimal code changes. Read replicas offload reporting traffic, and the engine choice matches the existing codebase rather than forcing a rewrite.

Why this answer

Using Amazon RDS with the same database engine (MySQL or PostgreSQL) minimizes code changes, as the application can connect via standard SQL drivers. Read replicas can help with read scaling without altering the codebase. Option B is wrong because Aurora Serverless may require configuration changes and does not necessarily minimize code changes.

Option C is wrong because S3 and Athena are not suitable for transactional relational queries and would require significant architectural changes. Option D is wrong because DynamoDB would require schema redesign and application changes to use NoSQL.

868
Multi-Selecthard

A company is migrating to a multi-account AWS environment. They want to centralize DNS management using Amazon Route 53 private hosted zones. The private zones must be accessible from all VPCs in the organization. Which THREE steps are required to achieve this?

Select 3 answers
A.Create a private hosted zone in the central networking account.
B.Share the private hosted zone with other accounts using AWS Resource Access Manager.
C.Create a public hosted zone with the same name and configure DNSSEC.
D.Associate the private hosted zone with the VPCs in the member accounts.
E.Create a Route 53 Resolver outbound endpoint in each account.
AnswersA, B, D

A Route 53 private hosted zone must exist before any cross-account association can occur, so creating it in the central networking account establishes the single authoritative record container that member VPCs will later resolve against.

Why this answer

Option A is correct because a Route 53 private hosted zone must first be created in the central networking (owner) account, which becomes the zone owner and controls its records and associations. Option B is correct because AWS Resource Access Manager (RAM) is the mechanism used to share the private hosted zone with other AWS accounts in the organization so their VPCs can be associated with it. Option D is correct because after sharing, the private hosted zone must be explicitly associated with each VPC in the member accounts (via AssociateVPCWithHostedZone or the console) for DNS resolution to work in those VPCs.

Option C is wrong because a public hosted zone with DNSSEC does not provide private, internal resolution across VPCs and is unrelated to this requirement. Option E is wrong because a Route 53 Resolver outbound endpoint is used to forward DNS queries from a VPC to on-premises or external resolvers, not to share private hosted zones across accounts.

Exam trap

The trap here is that candidates often confuse the need for a public hosted zone or outbound endpoints with the simpler mechanism of sharing a private hosted zone via AWS RAM and associating it with VPCs, leading them to select unnecessary or incorrect options.

869
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. They have a stack that creates an Amazon RDS for MySQL database. The stack creation fails with the error 'The following resource(s) failed to create: [DBInstance]'. The solutions architect needs to troubleshoot the issue. Which approach should be taken first?

A.Review the CloudFormation stack events in the AWS Management Console.
B.Check the RDS console for any database events.
C.Delete the stack and deploy again with the same parameters.
D.Use AWS CloudTrail to view the CreateStack API call.
AnswerA

CloudFormation records each resource's status and failure reason in stack events; the DBInstance event carries the underlying RDS error message. Reviewing these events first reveals the root cause before deeper investigation, satisfying the troubleshoot-first requirement.

Why this answer

CloudFormation stack events provide the most direct and detailed troubleshooting information for a failed resource creation. When a stack operation fails, the events tab shows a chronological log of each resource's status, including the specific error message returned by the underlying service (e.g., RDS). For a DBInstance failure, the stack event will contain the exact reason, such as an invalid parameter, insufficient permissions, or a subnet issue.

This is the first place to look because it aggregates service-specific errors in the context of the stack operation.

Exam trap

SAP-C02 often tests the misconception that CloudTrail or service-specific consoles provide the fastest troubleshooting path, but CloudFormation stack events are the primary source for resource creation failures.

How to eliminate wrong answers

Option B is wrong because while RDS console events may show database-level activities, they often do not capture the precise CloudFormation provisioning error and lack the stack context; they are secondary. Option C is wrong because deleting and redeploying without diagnosing the root cause will likely reproduce the same failure, wasting time and potentially causing further issues. Option D is wrong because AWS CloudTrail records API calls for auditing, but the CreateStack API call only shows that the request was made; it does not provide the detailed resource-level failure reason that stack events do.

870
MCQhard

A company is migrating a legacy monolithic application to AWS. The application consists of a web tier and a backend that uses a Microsoft SQL Server database. The company wants to modernize the application by decoupling the database from the application and moving to a managed database service. The migration must minimize downtime and ensure data consistency. Which strategy should be used?

A.Use native SQL Server backup and restore to move the database to Amazon RDS for SQL Server, scheduling a maintenance window for the cutover.
B.Use AWS Server Migration Service (SMS) to replicate the entire server, including the SQL Server database, to Amazon EC2, then migrate the database to RDS using native backup and restore.
C.Use AWS DataSync to copy the SQL Server database files to Amazon S3, then use AWS Glue to load the data into Amazon RDS for SQL Server.
D.Use AWS Database Migration Service (AWS DMS) with ongoing replication to migrate the SQL Server database to Amazon RDS for SQL Server, then refactor the application to use the RDS endpoint.
AnswerD

AWS DMS with ongoing replication allows continuous data replication from the on-premises SQL Server to Amazon RDS for SQL Server, minimizing downtime during cutover. After the initial full load, change data capture keeps the target in sync until the application is ready to switch. This approach ensures data consistency and supports modernization by moving to a managed database service.

Why this answer

AWS DMS with ongoing replication is the best strategy because it enables continuous data synchronization from the on-premises SQL Server to Amazon RDS for SQL Server, minimizing downtime and ensuring data consistency. It allows the application to be refactored to use the managed database endpoint after cutover. Other methods either cause downtime or do not support database migration effectively.

Exam trap

The trap here is assuming that a simple backup and restore is sufficient, but it causes downtime and does not handle ongoing changes, which is critical for minimal downtime.

871
Multi-Selectmedium

A company is planning a large-scale migration of hundreds of applications to AWS. Which TWO strategies should the architect consider to reduce migration risks?

Select 2 answers
A.Use only the rehosting strategy for all applications
B.Migrate all applications in a single wave to reduce coordination effort
C.Use a wave-based migration approach with defined groups and dependencies
D.Conduct a pilot migration of a small subset of applications
E.Roll back all migrations if any application experiences issues
AnswersC, D

Wave-based migration groups applications by dependency and business function, so each wave can be migrated, tested and rolled back independently. This directly limits blast radius across hundreds of applications, satisfying the stem's requirement to reduce migration risk rather than attempting a single cutover.

Why this answer

Option C is correct because a wave-based migration approach groups applications by dependencies, business criticality, and technical constraints, allowing the company to validate each wave before proceeding and limit the blast radius of any failures across hundreds of applications. Option D is correct because conducting a pilot migration of a small subset of applications lets the architect test the migration process, tooling (e.g., AWS Application Migration Service, AWS Database Migration Service), and runbooks on a low-risk sample, uncovering issues before committing the full portfolio. Option A is not appropriate because applying only rehosting to every application ignores the benefits of replatforming, refactoring, or repurchasing, and can carry forward technical debt and inefficiencies.

Option B is incorrect because migrating all applications in a single wave maximizes risk, since a failure in one application or shared dependency can disrupt the entire migration with no incremental validation. Option E is incorrect because rolling back all migrations whenever any single application has issues is an overreactive, all-or-nothing response that would halt progress; instead, issues should be isolated and remediated per application or wave.

872
MCQmedium

A company is running a web application on AWS using an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application experiences periodic traffic spikes that cause increased latency. The company wants to implement a solution to automatically adjust capacity in anticipation of traffic changes. What should a solutions architect do?

A.Configure a simple scaling policy based on CPU utilization.
B.Configure a scheduled scaling policy to add instances during known peak hours.
C.Configure a target tracking scaling policy based on average CPU utilization.
D.Configure a predictive scaling policy using historical traffic patterns.
AnswerD

Predictive scaling analyses historical CloudWatch traffic patterns and provisions capacity ahead of forecast demand, satisfying the anticipation requirement that reactive target tracking cannot meet. It scales out before the spike arrives, preventing the latency increase.

Why this answer

Predictive scaling uses historical traffic patterns to forecast future demand and proactively adjust capacity before traffic spikes occur, which directly addresses the requirement to anticipate changes. This approach reduces latency by ensuring sufficient resources are available ahead of time, unlike reactive policies that only respond after utilization increases.

Exam trap

The trap here is that candidates often confuse reactive scaling policies (simple, step, or target tracking) with proactive predictive scaling, assuming that maintaining a target metric like CPU utilization is sufficient to handle anticipated spikes, but only predictive scaling uses historical patterns to act before the load increases.

How to eliminate wrong answers

Option A is wrong because a simple scaling policy based on CPU utilization is reactive, only adjusting capacity after a threshold is breached, which cannot anticipate traffic spikes and may still cause latency during the scaling cooldown period. Option B is wrong because scheduled scaling assumes fixed peak hours, but the scenario describes periodic spikes that may not follow a strict schedule, making it inflexible and potentially wasteful or insufficient. Option C is wrong because target tracking scaling, while more sophisticated than simple scaling, is still reactive—it maintains a target metric (e.g., average CPU) but does not proactively forecast demand, so it cannot eliminate latency during sudden spikes.

873
MCQmedium

A company is migrating a batch processing workload to AWS. The workload runs a Java application that processes files from an S3 bucket. The company wants to minimize operational overhead. Which AWS service should the company use to run the Java application?

A.Amazon EC2
B.Amazon ECS with EC2 launch type
C.AWS Batch
D.AWS Lambda
AnswerD

AWS Lambda runs Java code without provisioning or managing servers, satisfying the minimise-operational-overhead constraint. It integrates natively with S3 event notifications, so uploaded files trigger processing automatically. For batch workloads with intermittent file arrivals, this event-driven model removes idle capacity and patching duties entirely, unlike EC2 or ECS, which require ongoing cluster management.

Why this answer

(AWS Lambda) is correct because it allows running Java code in response to S3 events with no server management, minimizing operational overhead. AWS Lambda supports Java runtime, can be triggered by S3 object creation events, and automatically scales. Options A (Amazon EC2) and B (Amazon ECS with EC2 launch type) require managing EC2 instances or cluster, increasing overhead.

Option C (AWS Batch) is designed for batch jobs but still requires compute environments (EC2 or Fargate) and is more complex than Lambda for simple file processing.

874
MCQeasy

A company is using AWS Config to evaluate resource compliance. They want to receive notifications when a noncompliant resource is detected. Which AWS service should be used to send these notifications to an email endpoint?

A.Amazon Simple Queue Service (SQS)
B.Amazon Simple Notification Service (SNS)
C.Amazon CloudWatch Events
D.AWS Lambda
AnswerB

AWS Config rules publish compliance-change events to an Amazon SNS topic, which then delivers them to email, SMS or HTTP endpoints. SNS provides the pub/sub fan-out the stem's email notification requirement demands, unlike CloudWatch Events alone or direct Lambda invocation.

Why this answer

(Amazon SNS) is correct because Amazon SNS can send email notifications when triggered by AWS Config rules to notify about noncompliant resources. Option A (SQS) is incorrect because SQS is a message queue service that does not directly send email. Option C (CloudWatch Events) can trigger other actions but cannot directly send email to endpoints.

Option D (AWS Lambda) can process notifications but requires additional services like SNS to send email.

875
MCQmedium

A healthcare company is designing a new application that must store protected health information in Amazon DynamoDB. The compliance team requires that all data be encrypted at rest with a customer-managed AWS KMS key so that key rotation and access can be audited centrally. The application runs on Amazon EC2 instances in a private subnet and must access the table over a private network path. The solutions architect needs to configure encryption and network access. Which combination of steps should the architect take?

A.Create a DynamoDB table with a customer-managed KMS key, and create a gateway VPC endpoint for DynamoDB; attach an endpoint policy that restricts access to the specific table.
B.Create a DynamoDB table with a customer-managed KMS key, and create an interface VPC endpoint for DynamoDB; attach an endpoint policy allowing access to the table.
C.Create a DynamoDB table with a customer-managed KMS key, and configure the application to use the DynamoDB Accelerator (DAX) cluster in the VPC for private access.
D.Create a DynamoDB table with an AWS owned key, and create a VPC endpoint for DynamoDB; use the default endpoint policy.
AnswerA

A customer-managed KMS key satisfies the audit and rotation requirement, and a gateway VPC endpoint provides private connectivity from the VPC to DynamoDB without internet access. An endpoint policy can restrict access to the specific table, adding least-privilege control. This combination meets both encryption and network requirements.

Why this answer

Using a customer-managed KMS key for the DynamoDB table meets the compliance requirement for auditable, rotatable encryption. A gateway VPC endpoint for DynamoDB provides private connectivity from the VPC, and an endpoint policy can restrict access to the specific table, satisfying the private network requirement without exposing traffic to the internet.

Exam trap

The trap here is confusing DynamoDB VPC endpoint types and selecting an interface endpoint, when DynamoDB uses gateway endpoints.

876
MCQhard

A company is designing a new application that will process sensitive financial data. They need to ensure that data at rest is encrypted using customer-provided encryption keys (SSE-C) in Amazon S3. Which action is required to enable this?

A.Use AWS KMS to generate a key
B.Enable default encryption on the bucket
C.Provide the encryption key in the request headers
D.Configure a bucket policy to require SSE-C
AnswerC

SSE-C requires the customer to supply the encryption key with every request rather than storing it in S3; S3 uses the key to encrypt or decrypt the object and then discards it. Passing the key via request headers satisfies the stem's customer-provided-key constraint without AWS retaining it.

Why this answer

SSE-C requires the customer to provide the encryption key in the request headers when uploading or accessing objects. Amazon S3 uses the provided key to encrypt data at rest and then discards the key; the customer is responsible for managing the key lifecycle. This is the only way to enforce customer-provided encryption keys at the object level.

Exam trap

The trap here is that candidates confuse SSE-C with SSE-KMS or SSE-S3, assuming that a bucket policy or default encryption alone can enforce customer-provided keys, when in fact SSE-C requires the key to be explicitly supplied in every request.

How to eliminate wrong answers

Option A is wrong because AWS KMS generates AWS-managed or customer-managed keys (SSE-KMS), not customer-provided keys (SSE-C) that are supplied per request. Option B is wrong because enabling default encryption on the bucket applies SSE-S3 or SSE-KMS automatically, not SSE-C, which requires the key to be sent with each request. Option D is wrong because a bucket policy can require SSE-C (e.g., via a condition key like s3:x-amz-server-side-encryption-customer-algorithm), but it does not enable SSE-C itself; the key must still be provided in the request headers.

877
Multi-Selectmedium

A company is deploying a web application on EC2 instances behind an Application Load Balancer. The application experiences high traffic during business hours and low traffic at night. The company wants to automatically scale the instances based on CPU utilization. Which TWO steps are required to achieve this?

Select 2 answers
A.Configure a scheduled scaling policy to add instances during business hours.
B.Replace the ALB with a Network Load Balancer for better performance.
C.Create a dynamic scaling policy based on the average CPU utilization metric.
D.Create an Auto Scaling group and associate it with the ALB.
E.Create a CloudWatch alarm that sends an email when CPU exceeds 80%.
AnswersC, D

A target-tracking dynamic scaling policy adjusts capacity automatically to hold average CPU utilisation at a chosen value, directly satisfying the requirement to scale on CPU utilisation. CloudWatch aggregates the EC2 metric across the Auto Scaling group, so the policy responds to business-hours peaks and nightly troughs without manual intervention.

Why this answer

Option C is correct because target tracking or step scaling dynamic policies use the CloudWatch Average CPUUtilization metric of the Auto Scaling group to automatically add or remove instances as load changes, which is exactly the CPU-based automatic scaling the company requires. Option D is correct because an Auto Scaling group is the foundational resource that manages the EC2 fleet's desired/min/max capacity and health checks, and associating it with the ALB target group lets the load balancer register and route traffic to the instances it launches. Option A is not required because scheduled scaling is time-based rather than CPU-utilization-based, so it does not satisfy the stated requirement.

Option B is wrong because an NLB operates at Layer 4 and is not needed here; the ALB already handles HTTP/HTTPS traffic appropriately. Option E is wrong because a CloudWatch alarm that only sends an email notification does not perform any scaling action.

Exam trap

SAP-C02 often tests the misconception that a CloudWatch alarm alone performs scaling — candidates must remember that the alarm must be tied to a scaling policy, and that the ASG must be attached to the load balancer target group.

878
MCQeasy

A company is migrating its on-premises VMware VMs to AWS. The company wants to use the same management tools and maintain consistency. Which AWS service should be used for this migration?

A.AWS Server Migration Service (SMS)
B.AWS Snowball Edge
C.VMware Cloud on AWS
D.AWS Database Migration Service (DMS)
AnswerC

VMware Cloud on AWS runs the native vSphere stack on dedicated AWS hardware, so existing VMware management tools such as vCenter and vSphere Client keep working unchanged. That directly satisfies the requirement to maintain the same management tooling and operational consistency during migration.

Why this answer

VMware Cloud on AWS is the correct service because it runs the actual VMware SDDC (vSphere, vSAN, NSX) on AWS bare-metal infrastructure, allowing the company to keep using its existing VMware management tools like vCenter and vSphere Client while gaining AWS services. This directly satisfies the requirement to maintain tooling consistency during migration. AWS SMS and DMS are migration tools, not environments that preserve VMware management tooling, and Snowball Edge is a physical data-transfer device.

Exam trap

SAP-C02 often tests whether candidates confuse migration tools (SMS, DMS, MGN) with target platforms (VMware Cloud on AWS); the phrase 'same management tools' is the tell that you need a VMware-preserving environment, not a migration service.

How to eliminate wrong answers

Option A is wrong because AWS Server Migration Service (SMS) is a migration orchestration tool for moving VMs to AWS — it does not preserve VMware management tools after migration and has actually been deprecated in favor of AWS Application Migration Service (MGN). Option B is wrong because Snowball Edge is a ruggedized edge compute/storage device for bulk data transfer, not a VMware hosting platform. Option D is wrong because AWS Database Migration Service (DMS) migrates databases (homogeneous or heterogeneous), not VMware VMs, and provides no VMware management tooling.

879
MCQmedium

A company is designing a new solution to host a static website on AWS. The website content is stored in an Amazon S3 bucket. The company wants to use a custom domain name (e.g., www.example.com) and enforce HTTPS. Which combination of AWS services should the company use?

A.Configure the S3 bucket for static website hosting and attach a custom SSL certificate using AWS Certificate Manager.
B.Use Amazon CloudFront with an SSL certificate from AWS Certificate Manager and point the CloudFront distribution to the S3 bucket.
C.Use Amazon Route 53 with an alias record pointing to the S3 bucket and enable DNSSEC.
D.Use an Application Load Balancer in front of the S3 bucket and attach an SSL certificate from AWS Certificate Manager.
AnswerB

CloudFront terminates HTTPS at the edge using the ACM certificate, then fetches content from the S3 bucket origin. ACM certificates cannot be attached directly to S3 static website endpoints, so CloudFront is required to enforce HTTPS on the custom domain.

Why this answer

Amazon CloudFront can terminate HTTPS at the edge using an SSL certificate from AWS Certificate Manager (ACM), and it can be configured with an origin pointing to an S3 bucket configured for static website hosting. This combination allows the use of a custom domain name (e.g., www.example.com) via a CloudFront alternate domain name (CNAME) and enforces HTTPS for all client connections, which S3 static website hosting alone cannot natively support.

Exam trap

The trap here is that candidates assume S3 static website hosting can directly serve HTTPS with a custom domain and SSL certificate, but S3 does not support SSL termination or custom certificates on its website endpoint, making a CDN like CloudFront mandatory for HTTPS enforcement.

How to eliminate wrong answers

Option A is wrong because S3 static website hosting does not support attaching a custom SSL certificate directly; S3 only serves HTTP on the bucket's website endpoint, and HTTPS is not available without a front-end service like CloudFront. Option C is wrong because Route 53 with an alias record pointing to an S3 website endpoint does not provide HTTPS termination; DNSSEC only secures DNS queries, not the HTTP connection, and the S3 website endpoint itself does not support HTTPS. Option D is wrong because an Application Load Balancer (ALB) cannot be placed directly in front of an S3 bucket as an origin; ALBs require targets such as EC2 instances, IP addresses, or Lambda functions, not S3 buckets.

880
MCQeasy

A company is migrating a monolithic application to AWS. The application currently runs on a single on-premises server and uses a MySQL database. The company wants to minimize changes to the application code during migration. Which migration strategy should the company use?

A.Refactor the application to use microservices and Amazon RDS.
B.Rehost the application on Amazon EC2 and migrate the database to Amazon RDS.
C.Replatform the application to use AWS Elastic Beanstalk and Amazon Aurora.
D.Repurchase the application by adopting a SaaS solution.
AnswerB

Rehosting lifts the application onto Amazon EC2 unchanged, while Amazon RDS runs MySQL with the same engine, so connection strings and SQL remain compatible. This minimises application code changes, which is the explicit constraint the company specified for migration.

Why this answer

Rehosting (lift-and-shift) moves the application to Amazon EC2 and the MySQL database to Amazon RDS with minimal or no code changes, which directly satisfies the requirement to minimize application code changes. This is the fastest migration path and preserves the existing monolithic architecture. Rehosting is the canonical 'minimize changes' strategy in the 7 Rs framework.

Exam trap

SAP-C02 often tests the 7 Rs by pairing 'minimize code changes' with the wrong R (e.g., replatform or refactor), so candidates must map the constraint precisely to rehost.

How to eliminate wrong answers

Option A is wrong because refactoring to microservices requires significant code changes and re-architecture, contradicting the minimize-changes requirement. Option C is wrong because replatforming to Elastic Beanstalk and Aurora involves modifying the runtime environment and database engine, which may require code and configuration changes. Option D is wrong because repurchasing to a SaaS solution abandons the existing application entirely and requires integration work, not minimal change.

881
MCQhard

A multinational corporation uses AWS Organizations with hundreds of accounts. The security team requires that all Amazon S3 buckets across the organization be encrypted with a specific AWS KMS key from the security account. Which combination of controls should be implemented to enforce this requirement?

A.Create an AWS Service Catalog portfolio that restricts bucket creation to encrypted buckets only.
B.Use IAM policies in each account to deny PutBucketEncryption actions that do not specify the required KMS key.
C.Enable AWS CloudTrail and create a CloudWatch Events rule to automatically remediate non-compliant buckets.
D.Apply an SCP to deny s3:PutBucketEncryption with any key other than the required KMS key, and use AWS Config rules to detect and remediate existing non-compliant buckets.
AnswerD

SCPs can deny actions organization-wide, and AWS Config rules can detect and remediate non-compliant buckets.

Why this answer

Applying an SCP to deny s3:PutBucketEncryption with any key other than the required KMS key enforces the encryption requirement across all accounts in the organization. Additionally, using AWS Config rules detects and remediates existing non-compliant buckets, ensuring ongoing compliance. This combination provides preventive and detective controls.

Exam trap

SAP-C02 often tests the difference between preventive controls (SCPs) and detective controls (Config), causing candidates to choose reactive options like CloudTrail remediation instead of a combination of both.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog portfolios restrict resource creation to approved products but do not enforce encryption settings on S3 buckets created outside the portfolio. Option B is wrong because IAM policies in each account are not centrally managed and can be modified, lacking the organization-wide enforcement of SCPs. Option C is wrong because CloudTrail and CloudWatch Events provide reactive remediation but do not prevent non-compliant bucket creation in the first place.

882
Multi-Selecteasy

A company is migrating a legacy .NET Framework 4.7 application to AWS. The application currently uses Windows Authentication and stores session state in-process. The company wants to minimize code changes and use AWS managed services. Which TWO strategies should the company adopt?

Select 2 answers
A.Migrate the application to run on Amazon EC2 instances joined to AWS Managed Microsoft AD.
B.Rewrite the application to .NET Core and deploy on AWS Elastic Beanstalk with Amazon RDS for SQL Server.
C.Store session data in Amazon ElastiCache for Redis using the Redis Session State Provider.
D.Use Amazon Cognito with an Active Directory connector for authentication.
E.Use Amazon DynamoDB to persist session state.
AnswersA, C

Joining EC2 instances to AWS Managed Microsoft AD preserves Windows Authentication (Kerberos) without rewriting the identity layer, and the managed domain removes self-managed domain controller overhead. This meets both constraints: minimal code change and use of an AWS managed service.

Why this answer

Option A is correct because joining Amazon EC2 instances to AWS Managed Microsoft AD preserves Windows Authentication (Kerberos/NTLM) for the legacy .NET Framework 4.7 app, allowing it to authenticate domain users without code changes while using a managed AWS directory service. Option C is correct because moving in-process session state to Amazon ElastiCache for Redis via the Redis Session State Provider requires only configuration changes (web.config) and no application rewrite, and ElastiCache is an AWS managed service. Option B is not appropriate because rewriting to .NET Core and migrating to Elastic Beanstalk with RDS for SQL Server involves significant code changes and does not directly address Windows Authentication.

Option D is not suitable because Amazon Cognito with an AD connector targets modern web/mobile identity federation rather than preserving existing Windows Authentication for a legacy .NET Framework application without changes. Option E is not correct because DynamoDB is not a drop-in session state provider for ASP.NET without custom code, and it does not address the Windows Authentication requirement.

883
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer. Users report intermittent slowdowns. CloudWatch metrics show high CPU utilization on the instances. The company wants to improve performance with minimal architectural changes. What should a solutions architect do?

A.Use Amazon ElastiCache to offload database queries.
B.Configure an Auto Scaling group with a dynamic scaling policy based on CPU utilization.
C.Replace the EC2 instances with a larger instance type.
D.Enable Amazon CloudFront in front of the ALB to cache content.
AnswerB

A dynamic scaling policy targeting CPU utilisation adds or removes instances automatically as load rises, distributing demand across more capacity. This addresses the high CPU constraint with minimal architectural change, since the existing load balancer already spreads traffic across the group.

Why this answer

An Auto Scaling group with a dynamic CPU-based scaling policy directly addresses the root cause (high CPU utilization) by adding more instances when demand rises, distributing load and improving performance. This is a minimal architectural change because the ALB already exists and simply registers new instances automatically. It preserves the existing application design while providing elasticity to handle intermittent spikes.

Exam trap

SAP-C02 often tests whether candidates confuse symptom with cause — high CPU is solved by horizontal scaling, not by caching layers or vertical resizing that don't address elasticity.

How to eliminate wrong answers

Option A is wrong because ElastiCache offloads database reads, but the symptom is high CPU on the EC2 instances themselves, not database latency — caching would not reduce application-tier CPU. Option C is wrong because vertically scaling to a larger instance type is a manual, static change that does not respond to intermittent load and may not resolve the underlying scaling issue. Option D is wrong because CloudFront caches static content at edge locations; it does not reduce CPU load from dynamic application processing and requires DNS/architectural changes.

884
MCQmedium

A company is designing a new application that will run on Amazon ECS with Fargate. The application needs to output logs to CloudWatch Logs. Which configuration should be used to send logs from the container to CloudWatch?

A.Use the awslogs log driver in the task definition and specify the log group.
B.Install and configure the CloudWatch agent in the container image.
C.Output logs to stdout/stderr and use a Lambda function to push them.
D.Configure a sidecar container running the CloudWatch agent.
AnswerA

The awslogs log driver, configured in the Fargate task definition, streams container stdout and stderr directly to a specified CloudWatch Logs log group. This satisfies the requirement without sidecar containers or host-level agents, which Fargate does not permit, since each task runs on isolated, managed infrastructure.

Why this answer

The awslogs log driver is the native, built-in mechanism for Amazon ECS tasks using the Fargate launch type to send container logs directly to CloudWatch Logs. By specifying the 'awslogs' log driver in the task definition and providing the log group name, ECS automatically streams stdout and stderr from the container to the specified CloudWatch log group without requiring any additional agents or infrastructure.

Exam trap

The trap here is that candidates often over-engineer the solution by thinking a separate agent or sidecar is required for log shipping, when in fact the awslogs log driver is the simplest and most efficient native integration for ECS with Fargate.

How to eliminate wrong answers

Option B is wrong because installing the CloudWatch agent inside the container image is unnecessary and adds complexity; the awslogs log driver handles log shipping natively at the container runtime level. Option C is wrong because using a Lambda function to push logs from stdout/stderr is an overly complex, non-standard approach that introduces latency and potential data loss, whereas the awslogs driver streams logs in real time. Option D is wrong because a sidecar container running the CloudWatch agent is redundant and consumes additional resources; the awslogs log driver is the recommended and simpler method for Fargate tasks.

885
Multi-Selecthard

A company is migrating a multi-tier e-commerce application to AWS. The application consists of a web tier, an application tier, and a MySQL database tier. The company wants to improve scalability and availability while reducing administrative overhead. Which THREE actions should the solutions architect take? (Select THREE.)

Select 3 answers
A.Migrate the MySQL database to Amazon RDS Multi-AZ
B.Use Amazon ElastiCache to cache session data
C.Use Amazon EFS for shared storage between web instances
D.Configure an Application Load Balancer and Auto Scaling group for the web tier
E.Use Spot Instances for all EC2 instances to reduce costs
AnswersA, B, D

Amazon RDS Multi-AZ maintains a synchronous standby in a second Availability Zone with automatic failover, satisfying the availability requirement. RDS also removes database patching, backups and replication administration, directly addressing the reduced administrative overhead constraint.

Why this answer

Option A is correct because Amazon RDS Multi-AZ maintains a synchronous standby replica in a second Availability Zone and automatically fails over the DNS endpoint during an AZ outage, which improves database availability while removing the administrative overhead of self-managed MySQL replication and patching. Option B is correct because storing session state in Amazon ElastiCache (Redis or Memcached) externalizes sessions from individual web instances, allowing any instance in the Auto Scaling group to serve any user request and enabling stateless, horizontally scalable web and application tiers. Option D is correct because an Application Load Balancer distributes HTTP/HTTPS traffic across targets in multiple AZs and an Auto Scaling group automatically replaces unhealthy instances and scales capacity with demand, directly delivering the required scalability and availability.

Option C is not appropriate here because Amazon EFS is a shared POSIX file system that is unnecessary once sessions are externalized to ElastiCache, and it adds latency and cost without addressing the stated goals. Option E is not appropriate because Spot Instances can be reclaimed with a two-minute interruption notice, making them unsuitable for all instances of a production e-commerce application; they should be limited to fault-tolerant, stateless workloads.

Exam trap

SAP-C02 often tests whether candidates confuse EFS with ElastiCache for session state and whether they over-apply Spot Instances to production critical workloads, so picking EFS or Spot is the common error.

886
Multi-Selectmedium

A company is building a new application that requires a relational database with high availability across multiple Availability Zones. The database must automatically failover with minimal downtime. Which two AWS services or features meet these requirements?

Select 2 answers
A.Amazon Aurora DB cluster with multiple Availability Zones
B.Amazon RDS Multi-AZ deployment
C.Amazon RDS Single-AZ deployment with automated backups
D.Amazon DynamoDB with global tables
E.Amazon RDS Read Replica
AnswersA, B

An Aurora DB cluster provisions writer and reader instances across multiple Availability Zones, with automatic failover to a reader if the writer fails. Storage is replicated across AZs, meeting the high availability and minimal downtime requirements.

Why this answer

Option A is correct because an Amazon Aurora DB cluster stores data across multiple Availability Zones and automatically fails over to an Aurora Replica (typically within 30 seconds or less) if the primary instance fails, providing high availability with minimal downtime. Option B is correct because an Amazon RDS Multi-AZ deployment maintains a synchronous standby replica in a different Availability Zone and automatically performs a DNS failover to the standby in the event of a primary failure, again with minimal downtime. Option C is incorrect because a Single-AZ deployment has no standby to fail over to; automated backups only enable point-in-time recovery, not automatic failover.

Option D is incorrect because DynamoDB is a NoSQL key-value/document database, not a relational database, even though global tables provide multi-Region replication. Option E is incorrect because RDS Read Replicas are used for read scaling and are asynchronous; they do not provide automatic failover for high availability.

Exam trap

The trap here is that candidates may overlook the 'relational database' requirement and select DynamoDB (a NoSQL service) or assume that RDS Read Replica provides automatic failover, when in fact it requires manual promotion and does not meet the minimal downtime requirement.

887
MCQmedium

A company's AWS CloudTrail logs are stored in an S3 bucket. A Solutions Architect needs to analyze the logs to identify API calls that created or modified IAM roles in the last 30 days. What is the MOST efficient way to perform this analysis?

A.Use Amazon CloudWatch Logs Insights to query the logs.
B.Use Amazon Athena to run SQL queries on the logs.
C.Use an AWS Lambda function to process the logs and export to Amazon Redshift.
D.Use S3 Select to filter the records.
AnswerB

Athena queries CloudTrail logs in S3 in place using standard SQL, letting the architect filter IAM role creation and modification events over the last 30 days without loading or transforming data first, which is the most efficient approach.

Why this answer

Amazon Athena enables running SQL queries directly on CloudTrail logs stored in S3 without the need to move or transform data. This is the most efficient method for analyzing historical CloudTrail data. Option A is incorrect because CloudWatch Logs Insights is designed for logs stored in CloudWatch Logs, not for S3-stored CloudTrail logs.

Option C is incorrect because using Lambda to export to Redshift adds unnecessary complexity and cost compared to querying in place with Athena. Option D is incorrect because S3 Select is limited to filtering data within a single object and does not support complex SQL queries across multiple log files.

888
MCQmedium

A company runs a stateful application on EC2 instances in an Auto Scaling group behind a Network Load Balancer (NLB). The application requires that client sessions are maintained to the same instance. The operations team notices that after scaling events, some clients lose their sessions. Which configuration change should the team implement to ensure session persistence?

A.Disable cross-zone load balancing on the NLB.
B.Enable cookie-based stickiness on the NLB listener.
C.Switch to an Application Load Balancer and enable cookie-based stickiness.
D.Enable source IP stickiness on the NLB target group.
AnswerD

Source IP stickiness on the NLB target group binds each client IP to one target for the flow's duration, so sessions survive scaling events. This satisfies the stem's requirement that clients remain on the same instance behind the Network Load Balancer.

Why this answer

Network Load Balancers operate at Layer 4 and support only source IP-based stickiness, configured on the target group via the 'stickiness.enabled' and 'stickiness.type=source_ip' attributes. Enabling source IP stickiness ensures that a given client IP is consistently routed to the same backend instance, preserving sessions across scaling events.

Exam trap

SAP-C02 often tests the misconception that NLBs support cookie-based stickiness like ALBs — candidates must remember NLB is Layer 4 and only supports source IP stickiness.

How to eliminate wrong answers

Option A is wrong because disabling cross-zone load balancing affects traffic distribution across AZs, not session affinity, and would not fix session loss. Option B is wrong because NLB listeners do not support cookie-based stickiness — that is an ALB (Layer 7) feature. Option C is wrong because switching to an ALB changes the architecture and may not be feasible for the stateful application; while ALB supports cookie stickiness, the question asks for a configuration change to the existing NLB setup.

889
MCQmedium

A company has multiple AWS accounts managed using AWS Organizations. The security team wants to enforce that all new accounts automatically have a specific AWS Config rule enabled to prohibit public S3 bucket access. Which solution requires the least operational overhead?

A.Use AWS CloudFormation StackSets to deploy the AWS Config rule to all accounts.
B.Enable AWS Config in the management account and use an aggregator for all accounts.
C.Use an SCP to automatically enable the AWS Config rule in all accounts.
D.Use an SCP to deny the s3:PutBucketPublicAccessBlock action if a specific tag is not present.
AnswerA

CloudFormation StackSets deploys the Config rule across all accounts in AWS Organizations from one template, automatically applying it to new accounts. This centralised, automated rollout requires the least ongoing operational overhead compared with manual per-account configuration.

Why this answer

AWS CloudFormation StackSets can deploy the AWS Config rule to all accounts in the organization. With automatic deployment enabled, new accounts will automatically receive the rule, requiring minimal operational overhead after initial setup. Option B is incorrect because it only sets up an aggregator and does not enable any rule.

Option C is incorrect because SCPs cannot automatically enable Config rules; they only control API actions. Option D is incorrect because it denies the s3:PutBucketPublicAccessBlock action but does not enable the required Config rule, failing to meet the explicit requirement.

Exam trap

The trap here is that candidates may think SCPs can enforce configuration standards, but SCPs only control API actions and cannot create or enable resources like Config rules. The correct approach is to use a deployment mechanism such as CloudFormation StackSets to automatically deploy the rule across accounts.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation StackSets require manual setup and ongoing maintenance to deploy to new accounts as they are added, which adds operational overhead compared to a policy-based approach. Option B is wrong because enabling AWS Config in the management account and using an aggregator only centralizes compliance data; it does not enforce the Config rule in new accounts automatically. Option C is wrong because SCPs cannot directly enable AWS Config rules; they can only deny or allow API actions, not create or configure AWS resources.

890
MCQhard

A company is migrating a large Hadoop cluster to Amazon EMR. The cluster uses HDFS for storage. The company wants to decouple compute and storage to reduce costs. Which approach should the company take?

A.Use Amazon S3 as the data store and EMRFS
B.Use Amazon FSx for Lustre
C.Use Amazon EFS for HDFS
D.Use EBS volumes for HDFS
AnswerA

EMRFS lets EMR read and write HDFS-compatible data directly in Amazon S3, so the cluster's storage layer persists independently of transient EC2 nodes. This decouples compute from storage, allowing clusters to be terminated between jobs and cutting the cost of maintaining replicated HDFS volumes.

Why this answer

Using Amazon S3 as the data store with EMRFS is correct because it decouples compute and storage — EMR clusters can read/write directly to S3, and the cluster can be terminated without data loss. This reduces costs by allowing transient clusters and eliminating HDFS replication overhead.

Exam trap

SAP-C02 often tests whether candidates understand the difference between decoupling storage and compute versus using a high-performance file system — the trap is choosing FSx for Lustre when the primary goal is cost reduction through S3 decoupling.

How to eliminate wrong answers

Option B is wrong because Amazon FSx for Lustre is a high-performance file system for compute-intensive workloads, but it does not decouple storage from compute in the same cost-effective way as S3; it is typically used as a scratch layer. Option C is wrong because Amazon EFS is a shared file system for Linux workloads, not designed for HDFS replacement in EMR, and it does not provide the same scalability or cost model. Option D is wrong because EBS volumes for HDFS keep storage attached to compute nodes, so data is lost when the cluster terminates and costs remain coupled.

891
MCQeasy

A company is building a serverless application using AWS Lambda. The Lambda function needs to process files uploaded to an S3 bucket. The function should be triggered as soon as a new object is created. How should the architect configure this?

A.Configure S3 to send event notifications to the Lambda function directly
B.Configure S3 to send event notifications to an SNS topic, which triggers the Lambda function
C.Configure S3 to send event notifications to an SQS queue, and have the Lambda function poll the queue
D.Configure S3 to send event notifications to Amazon CloudWatch Events, which triggers the Lambda function
AnswerA

S3 event notifications natively push s3:ObjectCreated events to Lambda through a resource-based policy, invoking the function the moment an object lands. This direct integration satisfies the requirement for immediate, serverless triggering without polling or intermediary services.

Why this answer

Amazon S3 can directly invoke an AWS Lambda function via event notifications when a new object is created. This is the simplest and most direct integration, requiring no intermediate services. S3 publishes an event to Lambda, which then executes the function synchronously, ensuring near-real-time processing of uploaded files.

Exam trap

The trap here is that candidates may overcomplicate the solution by introducing intermediate services like SNS or SQS, not realizing that S3 can directly invoke Lambda with no additional components, which is the simplest and most cost-effective design.

How to eliminate wrong answers

Option B is wrong because while S3 can send notifications to an SNS topic, and SNS can trigger Lambda, this adds unnecessary complexity and latency; the direct S3-to-Lambda integration is simpler and more efficient for this use case. Option C is wrong because S3 can send notifications to an SQS queue, but Lambda would need to poll the queue, introducing polling overhead and potential delays; the requirement is for immediate triggering, not polling. Option D is wrong because S3 does not natively send event notifications to Amazon CloudWatch Events (now Amazon EventBridge); while EventBridge can receive S3 events via CloudTrail or S3 event notifications, this is an indirect path and not the standard configuration for triggering Lambda directly from S3 object creation.

892
Multi-Selecthard

A company is migrating a monolithic application to microservices on Amazon ECS. They want to implement a service mesh for observability and traffic management. Which THREE AWS services should they consider?

Select 3 answers
A.Amazon Route 53
B.AWS X-Ray
C.Amazon CloudWatch
D.AWS App Mesh
E.AWS Step Functions
AnswersB, C, D

AWS X-Ray provides distributed tracing across ECS microservices, capturing request paths and latency between services to satisfy the observability requirement. It integrates natively with ECS tasks and the X-Ray daemon, giving end-to-end visibility that a service mesh alone would not deliver for troubleshooting inter-service calls.

Why this answer

Options B, C, and D are correct. AWS App Mesh is a service mesh that provides observability and traffic management. AWS X-Ray provides tracing for microservices.

Amazon CloudWatch provides monitoring and logs. Option A is wrong because Amazon Route 53 is DNS, not a service mesh. Option E is wrong because AWS Step Functions is for orchestrating workflows, not service mesh.

893
MCQeasy

A company is building a new application that will run on AWS Lambda. The application needs to store and retrieve user preferences in a key-value format. The data is accessed frequently and must be highly available. The company expects low latency for reads and writes. Which AWS service should be used as the data store?

A.Amazon S3
B.Amazon ElastiCache for Memcached
C.Amazon RDS for PostgreSQL
D.Amazon DynamoDB
AnswerD

Amazon DynamoDB delivers single-digit millisecond latency for key-value reads and writes, satisfying the low-latency requirement. Its serverless, multi-AZ design provides the high availability the stem demands, and it scales without managing servers, matching Lambda's operational model. Unlike relational stores, its partition-key access pattern suits frequent preference lookups directly.

Why this answer

Amazon DynamoDB is a fully managed, highly available key-value and document database that delivers single-digit millisecond latency at any scale. It is the natural fit for storing user preferences accessed frequently by Lambda functions, with built-in replication across multiple AZs for high availability.

Exam trap

The trap is that candidates pick ElastiCache for low latency, but ElastiCache is a cache, not a durable data store, and the question requires storing and retrieving preferences persistently.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is object storage, not a low-latency key-value store; it has higher latency and is not designed for frequent small reads/writes. Option B is wrong because ElastiCache for Memcached is an in-memory cache, not a durable data store, and Memcached does not provide persistence or high availability by itself. Option C is wrong because Amazon RDS for PostgreSQL is a relational database that requires provisioning and management, and it does not offer the same seamless key-value scalability and low-latency performance as DynamoDB for this use case.

894
Drag & Dropmedium

Drag and drop the steps to configure an S3 bucket as a static website hosting in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence ensures that the S3 bucket is properly configured for static website hosting. Start by creating the bucket, then enable static hosting, upload your files, apply a bucket policy for public read access, and finally test the website URL.

895
Multi-Selecthard

Which THREE design patterns can help a microservices application achieve loose coupling and independent deployability? (Choose three.)

Select 3 answers
A.Shared database schema across services
B.Circuit breaker pattern to handle service failures
C.Synchronous RESTful HTTP calls between services
D.Event-driven communication using Amazon SNS and SQS
E.API Gateway as a facade for service endpoints
AnswersB, D, E

Circuit breakers isolate failures, allowing services to degrade gracefully without impacting others.

Why this answer

The circuit breaker pattern (B) prevents cascading failures by monitoring for failures and opening the circuit to stop calls to an unhealthy service, allowing it time to recover. This supports loose coupling because the caller does not need to know the internal state of the downstream service, and it enables independent deployability by isolating failures during deployment or scaling events.

Exam trap

The trap here is that candidates often confuse synchronous RESTful calls (C) as a valid pattern for loose coupling, but in reality, synchronous calls create tight temporal coupling and reduce independent deployability, whereas event-driven and facade patterns (D and E) are the correct approaches.

896
MCQeasy

A company wants to deploy a new web application on AWS that uses a microservices architecture. The company expects rapid growth and wants to decouple services to allow independent scaling and development. The team wants to use Docker containers for consistency across environments. Which solution should a Solutions Architect recommend?

A.Use Amazon Lightsail containers to deploy each microservice as a container service.
B.Deploy each microservice on separate EC2 instances behind an Application Load Balancer.
C.Use Amazon ECS with Fargate to run each microservice as a separate task definition, with service auto scaling.
D.Use AWS Elastic Beanstalk with Docker platform to deploy each microservice as a separate environment.
AnswerC

ECS with Fargate runs each microservice as a separate task definition, giving independent scaling and deployment without managing EC2 instances. Fargate provides serverless container hosting, and service auto scaling handles rapid growth, satisfying the Docker consistency and decoupling requirements.

Why this answer

Amazon ECS with Fargate allows running containers without managing servers, and each microservice can be defined as a separate task definition with its own scaling policies. This decouples services, supports independent scaling, and provides container consistency across environments. Fargate eliminates infrastructure management, making it ideal for rapid growth and microservices.

Exam trap

The trap is assuming that any container service (like Lightsail or Beanstalk) is suitable for microservices; candidates may overlook that ECS/Fargate provides the orchestration and scaling needed for independent services.

How to eliminate wrong answers

Option A is wrong because Amazon Lightsail containers are simplified and not designed for complex microservices architectures with independent scaling and orchestration. Option B is wrong because deploying on EC2 instances requires managing servers and does not provide the same level of decoupling or ease of scaling as ECS/Fargate. Option D is wrong because Elastic Beanstalk with Docker is more monolithic and less suited for independent microservice scaling; it manages environments as units, not individual services.

897
Multi-Selecteasy

A company is designing a new application that will run on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be highly available and fault-tolerant across multiple Availability Zones. Which TWO actions should be taken to achieve this? (Choose two.)

Select 2 answers
A.Use an Auto Scaling group to launch instances only in one Availability Zone.
B.Use a Network Load Balancer instead of ALB for better performance.
C.Launch EC2 instances in at least two Availability Zones.
D.Configure the ALB to be internet-facing and register instances from multiple AZs.
E.Launch all EC2 instances in a single Availability Zone for low latency.
AnswersC, D

Multiple AZs provide fault tolerance if one AZ fails.

Why this answer

Launching EC2 instances in at least two Availability Zones (AZs) ensures that if one AZ fails, the application continues to run from the other AZ, providing fault tolerance and high availability. Option D is correct because configuring the ALB to be internet-facing and registering instances from multiple AZs allows the ALB to distribute incoming traffic across healthy instances in different AZs, automatically rerouting traffic if an AZ becomes impaired.

Exam trap

The trap here is that candidates often think a single AZ with Auto Scaling is sufficient for high availability, but true fault tolerance requires distributing resources across multiple AZs to survive an AZ-level failure.

898
MCQhard

A company runs a latency-sensitive trading application on Amazon EC2 instances behind a Network Load Balancer. The application must maintain persistent TCP connections and uses a custom health check on port 8080. During a recent incident, the operations team observed that when an instance became unhealthy, existing connections continued to be routed to it for several minutes, causing failed trades. The team needs to ensure that unhealthy targets are removed from the load balancer rotation as quickly as possible while preserving connection draining for graceful shutdown. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

A.Replace the Network Load Balancer with an Application Load Balancer and use HTTP health checks on port 8080.
B.Configure the NLB health check with a shorter interval and lower unhealthy threshold, and enable connection draining with an appropriate deregistration delay.
C.Enable TCP keepalive on the targets and set the deregistration delay to 0 seconds.
D.Configure the NLB health check with a shorter interval and higher unhealthy threshold, and enable connection draining with a 300-second deregistration delay.
AnswerB

Shortening the health check interval and reducing the unhealthy threshold makes the NLB detect failures faster and remove targets from rotation sooner. Enabling connection draining with a suitable deregistration delay allows existing connections to complete gracefully. This directly addresses the requirement for rapid removal while preserving graceful shutdown, with minimal operational changes.

Why this answer

The NLB health check interval and unhealthy threshold determine how quickly a target is marked unhealthy and removed from rotation. A shorter interval combined with a lower threshold accelerates detection. Enabling connection draining with a deregistration delay ensures that in-flight connections are allowed to complete, satisfying the graceful shutdown requirement.

This approach requires only configuration changes on the existing NLB.

Exam trap

The trap here is assuming that TCP keepalive settings on targets control how quickly the load balancer removes unhealthy targets, when in fact the health check configuration governs that behavior.

899
Multi-Selectmedium

A company runs a web application on EC2 instances in an Auto Scaling group. The application stores session data locally on the EC2 instances. The operations team reports that after scaling events, users lose their sessions. Which TWO actions should the Solutions Architect take to resolve this issue?

Select 2 answers
A.Use a Network Load Balancer instead of an Application Load Balancer.
B.Enable sticky sessions (session affinity) on the Application Load Balancer.
C.Move session data storage from the EC2 instances to Amazon ElastiCache for Redis.
D.Store session data in Amazon DynamoDB.
E.Enable replication in the ElastiCache cluster to handle failover.
AnswersB, C

Sticky sessions route user to same instance.

Why this answer

Options B and C are correct. Enabling sticky sessions (session affinity) on the Application Load Balancer ensures that requests from the same user are sent to the same EC2 instance while it is healthy, preventing session loss during scale-in events. However, sticky sessions do not protect against instance termination.

Moving session data storage from the EC2 instances to Amazon ElastiCache for Redis externalizes the session store so it persists independently of any individual instance. Option A is incorrect because a Network Load Balancer does not support application-layer sticky sessions. Option D is incorrect because DynamoDB is not required when ElastiCache for Redis is used.

Option E is incorrect because replication in ElastiCache provides high availability, not protection against session loss from Auto Scaling instance replacement.

900
MCQeasy

A company wants to decouple a web application frontend from a backend processing service. The frontend sends jobs that are processed asynchronously. Which AWS service is best suited for this decoupling?

A.Amazon SQS
B.Amazon SNS
C.Amazon Kinesis
D.AWS Step Functions
AnswerA

Amazon SQS queues messages between the frontend and backend, so the frontend enqueues jobs and returns immediately while workers poll and process asynchronously. This satisfies the decoupling requirement, absorbing traffic spikes and isolating failures between tiers.

Why this answer

Amazon SQS is the best choice for decoupling a web application frontend from a backend processing service because it provides a fully managed message queue that allows the frontend to send jobs (messages) asynchronously without waiting for the backend to process them. The backend can poll the queue at its own pace, ensuring reliable, scalable, and fault-tolerant communication between the two components. SQS supports standard queues for high throughput and FIFO queues for exactly-once processing, making it ideal for decoupling asynchronous workloads.

Exam trap

The trap here is that candidates often confuse SNS (push-based pub/sub) with SQS (pull-based queue) for decoupling, failing to recognize that asynchronous job processing requires the backend to pull messages, not receive pushes, and that SNS alone does not provide a buffer for unprocessed jobs.

How to eliminate wrong answers

Option B (Amazon SNS) is wrong because SNS is a pub/sub messaging service that pushes messages to multiple subscribers, not a queue; it does not provide the decoupling needed for asynchronous job processing where the backend pulls messages at its own pace. Option C (Amazon Kinesis) is wrong because Kinesis is designed for real-time streaming data ingestion and processing (e.g., logs, metrics), not for decoupling discrete job requests between a frontend and backend; it introduces complexity and cost overhead for simple job queues. Option D (AWS Step Functions) is wrong because Step Functions is a serverless orchestration service for coordinating multiple AWS services into workflows, not a message queue; it is used for stateful workflows, not for decoupling frontend and backend via asynchronous message passing.

Page 11

Page 12 of 14

Page 13