Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 901–975

984 questions total · 14pages · All types, answers revealed

Page 12

Page 13 of 14

Page 14
901
Multi-Selectmedium

A company is migrating a multi-tier web application to AWS and wants to use Infrastructure as Code (IaC) to automate provisioning. Which AWS services can the company use to define and manage infrastructure declaratively? (Choose TWO.)

Select 2 answers
A.AWS Elastic Beanstalk
B.AWS CloudFormation
C.AWS OpsWorks
D.AWS Cloud Development Kit (CDK)
E.AWS CodeDeploy
AnswersB, D

AWS CloudFormation defines infrastructure declaratively through JSON or YAML templates, letting the company version, review and provision the multi-tier stack repeatably. It satisfies the IaC requirement by managing resource creation and dependencies as code rather than manual console actions.

Why this answer

AWS CloudFormation (B) is correct because it lets you define infrastructure declaratively in JSON or YAML templates, and CloudFormation provisions and manages those resources as stacks. AWS Cloud Development Kit (CDK) (D) is also correct because it allows infrastructure to be defined declaratively using familiar programming languages, which then synthesizes into CloudFormation templates for deployment. AWS Elastic Beanstalk (A) is not the best fit because it is a PaaS that deploys applications from code or configuration but does not itself provide a general declarative IaC language for defining arbitrary infrastructure.

AWS OpsWorks (C) uses Chef/Puppet for configuration management and is more procedural/imperative in practice, not a declarative IaC service in the CloudFormation/CDK sense. AWS CodeDeploy (E) is a deployment orchestration service for applications, not an infrastructure definition or provisioning service.

902
MCQmedium

A company is designing a new solution that uses Amazon S3 to store large amounts of archival data. The data must be retained for 7 years and then automatically deleted. Which S3 feature should they use?

A.S3 Replication
B.S3 Versioning
C.S3 Object Lock
D.S3 Lifecycle policies
AnswerD

S3 Lifecycle policies automate object transitions and expiration, satisfying the seven-year retention constraint by permanently deleting objects once the rule's expiration threshold is reached. Unlike manual deletion or versioning alone, lifecycle rules run without intervention, ensuring archival data is removed automatically at the defined interval.

Why this answer

S3 Lifecycle policies allow you to define rules that automatically expire objects after a specified period, such as 7 years. This directly meets the requirement to retain archival data for a fixed duration and then delete it without manual intervention.

Exam trap

The trap here is that candidates often confuse S3 Object Lock's retention period with automatic deletion, not realizing that Object Lock only prevents deletion during the retention window and requires a separate lifecycle rule to actually remove the objects afterward.

How to eliminate wrong answers

Option A is wrong because S3 Replication is used to copy objects across buckets for redundancy or compliance, not to manage retention or deletion based on time. Option B is wrong because S3 Versioning preserves multiple versions of an object and does not provide automatic deletion after a set period; it can actually increase storage costs if not combined with lifecycle rules. Option C is wrong because S3 Object Lock is designed to prevent object deletion or overwrites for a fixed retention period (compliance or governance mode), but it does not automatically delete objects after that period ends—it only prevents premature deletion, and objects remain until manually removed or a lifecycle rule is applied.

903
MCQeasy

A company needs to share a VPC subnet with multiple accounts in the same AWS Organization. What is the MOST secure way to achieve this?

A.Create a Transit Gateway and attach all accounts.
B.Set up a VPN connection between accounts.
C.Use AWS RAM to share the subnet with the organization.
D.Create a VPC peering connection between each account and the VPC owner.
AnswerC

AWS RAM shares the subnet in place, so participant accounts launch resources directly into it without duplicating networking or peering. Sharing within the organisation enables automatic acceptance and centralised governance, satisfying the secure multi-account requirement more tightly than VPC peering or duplicated subnets.

Why this answer

AWS Resource Access Manager (RAM) allows you to share a subnet with other accounts within the same AWS Organization without requiring any intermediate networking appliances or complex routing. This is the most secure approach because the shared subnet remains under the VPC owner's administrative control, and participating accounts can launch resources directly into the subnet while inheriting the VPC's security policies. No traffic traverses external connections or third-party devices, reducing the attack surface.

Exam trap

The trap here is that candidates often confuse network connectivity solutions (Transit Gateway, VPC peering, VPN) with resource sharing, assuming that to 'share' a subnet you must connect the VPCs, when in fact AWS RAM provides a direct, secure, and managed way to share subnets without any network-level interconnection.

How to eliminate wrong answers

Option A is wrong because a Transit Gateway is a network transit hub used to interconnect VPCs and on-premises networks, not a mechanism to share a subnet; attaching accounts via Transit Gateway would require separate VPCs and routing, not direct subnet sharing. Option B is wrong because a VPN connection between accounts would create an encrypted tunnel over the internet, which is unnecessary overhead and introduces latency and complexity for sharing a subnet that should be accessed natively within the same AWS backbone. Option D is wrong because VPC peering connects entire VPCs, not individual subnets, and requires managing multiple peering connections and route tables; it also does not allow the peered accounts to launch resources directly into the owner's subnet.

904
MCQhard

A company is migrating a 10 TB Oracle database to Amazon Aurora PostgreSQL. The migration must have minimal downtime and support ongoing replication. The application uses stored procedures and advanced Oracle features. The company has already set up an AWS DMS replication instance and validated connectivity. However, during the full load, DMS reports errors for certain tables containing LOBs. What is the most likely cause and solution?

A.The DMS replication instance does not have enough memory. Increase the instance size.
B.The target Aurora PostgreSQL cluster does not have enough storage. Increase the allocated storage.
C.The LOB mode is set to 'Limited LOB mode' and some LOBs exceed the maximum allowed size. Set LOB mode to 'Full LOB mode'.
D.The source database is not configured for change data capture (CDC). Enable supplemental logging.
AnswerC

Limited LOB mode truncates or rejects LOBs exceeding the specified MaxLobSize, causing the full-load errors on LOB tables. Switching to Full LOB mode migrates complete LOB values regardless of size, satisfying the requirement for accurate replication of the Oracle data.

Why this answer

AWS DMS offers two LOB handling modes: Limited LOB mode (default) and Full LOB mode. In Limited LOB mode, DMS truncates any LOB larger than the specified MaxLobSize (default 32 KB), which can cause errors or data loss for tables with larger LOBs. Since the migration involves an Oracle database with advanced features and LOBs, it's likely that some LOBs exceed the limit.

Switching to Full LOB mode allows DMS to migrate LOBs of any size, though it may impact performance. This directly addresses the reported errors during full load.

Exam trap

SAP-C02 often tests the misconception that increasing resources (memory or storage) resolves DMS errors, when the actual issue is LOB handling configuration. Candidates may overlook the default Limited LOB mode and its size limit, leading them to choose resource scaling instead of adjusting LOB mode.

How to eliminate wrong answers

Option A is wrong because insufficient memory would typically cause performance degradation or task failures, not specific errors on LOB tables; DMS handles LOBs in chunks and memory is not the primary constraint. Option B is wrong because insufficient storage on the target would result in storage-full errors across all tables, not isolated LOB errors. Option D is wrong because CDC and supplemental logging are required for ongoing replication (change data capture), but the errors occur during the full load phase, not during CDC; enabling supplemental logging would not resolve full load LOB errors.

905
MCQhard

A company is migrating a legacy application to AWS. The application requires a fixed IP address for whitelisting by a third-party service. The application will run on EC2 instances behind an Application Load Balancer. The company needs a solution that provides a static IP address for outbound traffic. What should a solutions architect do?

A.Replace the ALB with a Network Load Balancer and assign Elastic IPs.
B.Assign an Elastic IP address to the Application Load Balancer.
C.Place the EC2 instances in a private subnet and route outbound traffic through a NAT Gateway with an Elastic IP.
D.Attach an Internet Gateway to the VPC and assign an Elastic IP to it.
AnswerC

A NAT Gateway performs source NAT, so all outbound traffic from the private subnet egresses via its attached Elastic IP. This satisfies the third-party whitelisting constraint, which requires a single, fixed public address rather than the dynamic addresses of instances or an internet gateway.

Why this answer

Placing the EC2 instances in a private subnet and routing outbound traffic through a NAT Gateway with an Elastic IP provides a static IP address for outbound traffic. The third-party service whitelists this Elastic IP, and all outbound traffic from the instances will appear to originate from that IP. This is the standard AWS solution for providing static outbound IPs for instances behind an ALB, as ALBs do not support Elastic IPs and cannot provide a static IP for outbound traffic.

Exam trap

The trap is confusing inbound and outbound static IP requirements; candidates may think an ALB can have an Elastic IP or that an NLB provides outbound static IPs, but only a NAT Gateway with an Elastic IP solves the outbound static IP need.

How to eliminate wrong answers

Option A is wrong because replacing the ALB with a Network Load Balancer and assigning Elastic IPs provides static IPs for inbound traffic, not outbound; the question specifically requires a static IP for outbound traffic. Option B is wrong because Application Load Balancers do not support assigning Elastic IP addresses; they use dynamic IP addresses that can change. Option D is wrong because attaching an Internet Gateway to the VPC and assigning an Elastic IP to it is not possible; Internet Gateways do not support Elastic IPs, and this would not provide a static outbound IP for the instances.

906
MCQmedium

A company is migrating a legacy three-tier application to AWS. The application servers run on Amazon EC2 instances behind an Application Load Balancer, and the database is a self-managed MySQL instance on an EC2 instance. The company requires that database credentials never be stored in application code or configuration files, and that credentials be automatically rotated every 30 days without application restarts. Which solution meets these requirements with the LEAST operational overhead?

A.Store the credentials in AWS Systems Manager Parameter Store as SecureString parameters. Use an AWS Lambda function triggered by Amazon EventBridge to rotate the credentials every 30 days, and update the application to read the parameters at startup.
B.Use AWS Identity and Access Management (IAM) database authentication for MySQL. Configure the application to generate an authentication token using the EC2 instance role, and connect to the database using that token.
C.Store the credentials in an encrypted Amazon S3 bucket. Use an EC2 user data script to download and decrypt the credentials at instance launch, and rotate them manually every 30 days by updating the S3 object and restarting the application servers.
D.Store the database credentials in AWS Secrets Manager and configure automatic rotation. Grant the EC2 instance role permission to retrieve the secret, and update the application to fetch credentials from Secrets Manager at startup and on connection failure.
AnswerD

AWS Secrets Manager natively supports automatic rotation for supported databases, including self-managed MySQL on EC2, using a Lambda rotation function. It integrates with IAM roles for EC2, so no static credentials are stored in code or configuration. The application can retrieve credentials via the Secrets Manager API when needed, enabling rotation without restarts.

Why this answer

AWS Secrets Manager is designed to securely store and automatically rotate database credentials for supported databases, including self-managed MySQL on EC2, using a Lambda rotation function. It integrates with IAM roles, eliminating hardcoded credentials, and allows applications to retrieve credentials on demand, so rotation occurs without application restarts. This meets the requirements with minimal operational effort.

Exam trap

The trap here is assuming that AWS Systems Manager Parameter Store provides automatic rotation for database credentials, when it only stores parameters and requires a custom rotation solution.

907
MCQhard

A company is migrating a legacy three-tier application to AWS. The application uses a self-managed Oracle database on an EC2 instance. The company wants to move to Amazon Aurora PostgreSQL with minimal downtime and no data loss. The database is 2 TB and experiences continuous write traffic. A solutions architect must recommend a migration strategy that keeps the source and target databases synchronized until cutover. Which combination of steps should the solutions architect take?

A.Use native Oracle Data Pump to export the database to Amazon S3, then use AWS DMS to import the dump into Aurora PostgreSQL.
B.Use AWS Database Migration Service (AWS DMS) with full load only, then stop the application and run a final incremental load before cutover.
C.Use AWS Database Migration Service (AWS DMS) with ongoing replication, and use AWS Schema Conversion Tool (AWS SCT) only for assessment, not for schema conversion.
D.Use AWS Schema Conversion Tool (AWS SCT) to convert the schema, then use AWS Database Migration Service (AWS DMS) with change data capture (CDC) to replicate ongoing changes until cutover.
AnswerD

AWS SCT converts the Oracle schema and code to Aurora PostgreSQL-compatible objects, and AWS DMS with CDC performs an initial full load followed by continuous replication of ongoing changes. This allows the target to stay synchronized with the source while the application is still writing to Oracle, enabling a cutover with minimal downtime and no data loss. This is the standard approach for heterogeneous database migrations to Aurora.

Why this answer

Heterogeneous migrations from Oracle to Aurora PostgreSQL require both schema conversion and data replication. AWS SCT handles the conversion of schema objects, stored procedures, and other code to PostgreSQL-compatible equivalents. AWS DMS then performs the initial data load and uses change data capture to apply ongoing changes from the Oracle source to the Aurora target.

This combination keeps the target synchronized and allows a cutover with minimal downtime and no data loss, even under continuous write traffic.

Exam trap

The trap here is believing that AWS DMS alone can handle a heterogeneous migration without schema conversion, or that a full load without CDC is sufficient for a database with continuous writes.

908
MCQmedium

A company is designing a new microservices application on AWS. Each microservice will be deployed as a containerized application using Amazon ECS with Fargate launch type. The company expects variable traffic patterns and needs to ensure that the application can scale automatically based on demand. Which scaling solution should be used?

A.Use Amazon EC2 Auto Scaling to add more Fargate tasks.
B.Configure Application Auto Scaling with a target tracking scaling policy based on average CPU utilization.
C.Use AWS Auto Scaling Plans with predictive scaling.
D.Manually adjust the desired count of tasks in the ECS service based on traffic analysis.
AnswerB

Application Auto Scaling with a target tracking policy on average CPU utilisation adjusts the ECS service's desired task count automatically as demand varies. It satisfies the stem's Fargate scaling requirement, since Fargate tasks scale at the service level rather than through EC2 Auto Scaling groups.

Why this answer

Amazon ECS with Fargate uses Application Auto Scaling to automatically adjust the desired count of tasks based on demand. A target tracking scaling policy based on average CPU utilization is the correct approach because it allows you to define a target value (e.g., 70% CPU) and Application Auto Scaling will add or remove tasks to maintain that target, matching the variable traffic patterns described.

Exam trap

The trap here is confusing EC2 Auto Scaling (which manages instances) with Application Auto Scaling (which manages ECS tasks), leading candidates to choose Option A despite Fargate being serverless and not requiring EC2 instance management.

How to eliminate wrong answers

Option A is wrong because Amazon EC2 Auto Scaling manages EC2 instances, not Fargate tasks; Fargate tasks are serverless and scaled via Application Auto Scaling, not EC2 Auto Scaling. Option C is wrong because AWS Auto Scaling Plans with predictive scaling is designed for recurring, predictable traffic patterns (e.g., based on historical data), not for variable, unpredictable traffic patterns as described in the question. Option D is wrong because manually adjusting the desired count of tasks does not meet the requirement for automatic scaling based on demand; it requires human intervention and analysis, which is not automated.

909
MCQeasy

A company has a decentralized IT structure where each business unit manages its own AWS accounts. The central IT team wants to enforce security policies across all accounts but allow business units to retain administrative control. Which solution should the central IT team implement?

A.Deploy AWS CloudFormation StackSets to each account with security templates.
B.Create a shared services account and use IAM cross-account roles for each business unit.
C.Use AWS Organizations with service control policies (SCPs) to enforce baseline permissions, and delegate administration to organizational units (OUs) for each business unit.
D.Migrate all workloads to a single AWS account and use IAM roles for each business unit.
AnswerC

AWS Organizations SCPs set permission guardrails at the organisation root or OU level, capping the maximum permissions available to every principal in member accounts. Delegating each business unit to its own OU preserves their administrative autonomy within those guardrails, satisfying central enforcement without removing local control.

Why this answer

AWS Organizations with SCPs allows the central IT team to enforce baseline security policies across all accounts without removing administrative control from business units. By delegating administration to OUs for each business unit, the central team sets guardrails while business units retain full IAM management within their accounts, satisfying the decentralized structure requirement.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking SCPs remove all administrative control, when in fact SCPs only set upper permission boundaries and allow business units to retain full administrative autonomy within those limits.

How to eliminate wrong answers

Option A is wrong because CloudFormation StackSets deploy resources and templates but do not enforce ongoing security policies; business units could modify or delete the deployed resources, and StackSets lack the ability to set permission guardrails. Option B is wrong because a shared services account with cross-account roles centralizes access control, which contradicts the requirement for business units to retain administrative control over their own accounts. Option D is wrong because migrating all workloads to a single account violates the decentralized IT structure and removes business unit autonomy, while IAM roles alone cannot enforce baseline security policies across separate accounts.

910
MCQeasy

A company is designing a new web application that will run on Amazon EC2 instances behind an Application Load Balancer. They need to offload SSL/TLS termination to reduce CPU usage on the instances. What should they do?

A.Install a self-signed certificate on each EC2 instance
B.Use a Network Load Balancer (NLB) with SSL pass-through
C.Configure the ALB with an SSL certificate
D.Use Amazon CloudFront for SSL termination
AnswerC

Terminating TLS at the Application Load Balancer using an ACM or imported certificate moves the cryptographic handshake and bulk decryption off the EC2 instances, directly satisfying the requirement to reduce their CPU usage while the ALB forwards plaintext HTTP to the targets.

Why this answer

An Application Load Balancer (ALB) can terminate SSL/TLS by installing a certificate on it, reducing CPU load on backend EC2 instances. Option A (self-signed certificate on each instance) does not offload SSL and is less secure. Option B (NLB with SSL pass-through) does not terminate SSL; it passes encrypted traffic through.

Option D (CloudFront) can terminate SSL but is a CDN service, not primarily for SSL offload in this architecture, and adds cost and complexity.

911
MCQhard

A company runs a microservices application on Amazon ECS with the Fargate launch type. The services communicate over a service mesh. The operations team wants to improve observability and reduce troubleshooting time for inter-service communication issues. They need to capture detailed request traces and metrics without modifying application code. Which solution should a solutions architect recommend?

A.Use Amazon CloudWatch Container Insights with enhanced observability for ECS, and enable VPC Flow Logs for the service subnets.
B.Configure the application to use the AWS X-Ray SDK for instrumenting all service calls, and deploy the X-Ray daemon as a sidecar.
C.Enable ECS Exec on all tasks and use AWS Systems Manager Session Manager to run tcpdump on each container.
D.Deploy AWS App Mesh with Envoy sidecar proxies and configure it to emit traces to AWS X-Ray and metrics to Amazon CloudWatch.
AnswerD

AWS App Mesh uses Envoy sidecar proxies to intercept traffic between services, enabling detailed tracing and metrics without code changes. It integrates with X-Ray for distributed tracing and CloudWatch for metrics, providing the required observability for inter-service communication.

Why this answer

AWS App Mesh with Envoy sidecars provides layer 7 observability, including distributed tracing and metrics, without requiring application code changes. It integrates with X-Ray and CloudWatch, giving the operations team detailed visibility into inter-service communication. The other options either require code changes, lack granularity, or are not scalable.

Exam trap

The trap here is assuming that container-level monitoring or manual debugging tools provide the same depth as a service mesh for inter-service tracing.

912
MCQhard

A company is migrating a monolithic application to a microservices architecture on AWS. The application uses a relational database with complex queries. The team wants to decouple the database layer and allow each microservice to own its data. Which design pattern should the team implement?

A.Implement an event-driven architecture using Amazon SQS and AWS Lambda with CQRS.
B.Deploy a read replica of the database for each microservice to offload queries.
C.Use a single Amazon RDS instance with multiple schemas for each microservice.
D.Use a database-per-service pattern with each microservice having its own Amazon DynamoDB table or RDS instance.
AnswerD

Database-per-service gives each microservice exclusive ownership of its schema, satisfying the decoupling constraint. Services choose DynamoDB for key-value access or RDS where complex relational queries persist, and integrate through APIs or events rather than shared tables. This removes the monolithic database as a coupling point and single point of contention.

Why this answer

The database-per-service pattern is the foundational microservices data management approach where each service owns its private datastore, exposing data only through its API. This gives each microservice independent schema evolution, technology choice (polyglot persistence), and failure isolation — directly satisfying the requirement that 'each microservice owns its data.' DynamoDB or a dedicated RDS instance per service enforces this boundary at the infrastructure level, preventing the shared-database anti-pattern that recreates the monolith's coupling.

Exam trap

SAP-C02 often tests whether candidates confuse 'decoupling' mechanisms (SQS, CQRS, read replicas) with actual data ownership — the exam wants you to recognize that only database-per-service removes the shared-schema coupling that blocks independent microservice evolution.

How to eliminate wrong answers

Option A is wrong because CQRS with SQS/Lambda addresses read/write model separation and asynchronous decoupling, not data ownership — services would still share the underlying database, so the coupling problem remains. Option B is wrong because read replicas only offload read traffic from a single primary; all replicas still contain the same schema and data, so services remain tightly coupled to one shared data model and writes still contend on the primary. Option C is wrong because multiple schemas on one RDS instance is the classic 'shared database' anti-pattern — services can still join across schemas, schema changes require coordinated deployments, and one service's heavy query can starve others on the same instance.

913
MCQeasy

A solutions architect is designing a new serverless application using AWS Lambda for business logic, Amazon API Gateway for RESTful APIs, and Amazon DynamoDB for data storage. The application will experience unpredictable traffic spikes. What is the MOST cost-effective way to handle concurrency and scaling?

A.Use Lambda provisioned concurrency to pre-warm instances.
B.Use Lambda reserved concurrency to set a limit on concurrent executions.
C.Configure DynamoDB auto scaling to handle traffic spikes.
D.Set a usage plan in API Gateway with a throttling limit.
AnswerB

Reserved concurrency controls the maximum number of concurrent Lambda invocations, preventing excessive scaling and cost.

Why this answer

Lambda reserved concurrency sets a hard limit on the number of concurrent executions for a function, preventing runaway scaling and controlling costs during unpredictable traffic spikes. It ensures that the function does not consume more concurrency than allocated, which avoids excessive DynamoDB read/write capacity usage and keeps costs predictable without needing to pre-warm instances.

Exam trap

The trap here is that candidates confuse provisioned concurrency (which reduces latency but adds cost) with reserved concurrency (which controls scaling and cost), or they mistakenly think DynamoDB auto scaling or API Gateway throttling directly manages Lambda concurrency.

How to eliminate wrong answers

Option A is wrong because provisioned concurrency pre-warms a fixed number of instances to reduce cold starts, but it incurs additional costs even when idle and does not control scaling or concurrency limits during spikes—it is not cost-effective for unpredictable traffic. Option C is wrong because DynamoDB auto scaling adjusts read/write capacity based on actual traffic, but it does not directly handle Lambda concurrency or scaling; it only manages the database side and can still lead to high costs if Lambda invocations spike. Option D is wrong because a usage plan in API Gateway throttles requests at the API level, but it does not control Lambda concurrency or scaling; it may reject valid requests rather than managing cost-efficient concurrency.

914
MCQmedium

A company has a multi-account AWS environment with AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that only the audit account can assume these roles and that the roles are automatically created in all existing and future accounts. What should they do?

A.Use AWS Organizations to create a service control policy (SCP) that allows sts:AssumeRole only from the audit account, and manually create the roles in each account.
B.Use AWS Identity and Access Management (IAM) to create a role in each account with a trust policy that allows the audit account, and use AWS Lambda to create the roles in new accounts as they are added.
C.Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack set that creates the IAM roles in all accounts in the organization.
D.Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share it with all member accounts.
AnswerC

CloudFormation StackSets with service-managed permissions can automatically deploy stack instances to all accounts in an organization, including future accounts when auto-deployment is enabled. The stack set can create IAM roles with trust policies that allow only the audit account to assume them. This meets the requirements for central management and automatic provisioning.

Why this answer

CloudFormation StackSets with service-managed permissions is designed to deploy resources across all accounts in an AWS Organization, including automatically to new accounts when auto-deployment is enabled. By defining a stack set that creates IAM roles with trust policies restricted to the audit account, the security team can centrally manage and automatically provision these roles. This is the most efficient and native solution.

Exam trap

The trap here is assuming that AWS Resource Access Manager can share IAM roles, but RAM does not support IAM roles as shareable resources.

915
MCQeasy

A company is using AWS Organizations with all features enabled. They want to apply a service control policy (SCP) that denies the ability to delete AWS KMS keys across all member accounts, but they need to allow a specific break-glass role in the management account to delete keys in case of emergency. Which statement is true regarding SCP enforcement in this scenario?

A.SCPs apply to all principals in member accounts, including the root user, but do not apply to the management account, so the break-glass role in the management account is unaffected.
B.SCPs apply to all accounts in the organization, including the management account, so the break-glass role must be explicitly exempted in the SCP.
C.SCPs apply only to IAM users, not to IAM roles, so the break-glass role is unaffected regardless of which account it is in.
D.SCPs apply to member accounts but can be overridden by an IAM policy in the member account that allows kms:ScheduleKeyDeletion.
AnswerA

SCPs are applied to member accounts and affect all principals, including the root user, but they do not apply to the management account. Therefore, a break-glass role in the management account is not restricted by the SCP, allowing key deletion as intended. This matches the requirement.

Why this answer

SCPs are guardrails that apply to all principals in member accounts, including the root user, but they are not evaluated for the management account. Therefore, a role in the management account can perform actions denied by an SCP attached to member accounts. This allows the break-glass role to delete KMS keys without needing an exemption in the SCP.

Exam trap

The trap here is thinking that SCPs apply to the management account or that they can be overridden by IAM policies, when in fact SCPs do not affect the management account and always take precedence over IAM policies in member accounts.

916
MCQhard

A company is migrating a monolithic application to microservices on Amazon ECS with Fargate. The application has variable traffic patterns, with high traffic during business hours and low traffic at night. They want to optimize costs while maintaining performance. Which scaling strategy should they implement?

A.Use target tracking scaling with a schedule to increase minimum capacity during business hours.
B.Use step scaling policies based on memory utilization.
C.Use scheduled scaling to increase capacity during business hours.
D.Use simple scaling policies based on CPU utilization.
AnswerA

Target tracking alone scales on demand but cannot anticipate the predictable daytime peak. Adding a schedule that raises minimum capacity during business hours pre-warms tasks, maintaining performance while target tracking scales down at night to optimise cost.

Why this answer

Combining target tracking scaling with a scheduled action allows the application to dynamically adjust capacity based on actual demand while ensuring a higher baseline during peak business hours. This hybrid approach optimizes costs by scaling down at night and maintains performance by preventing cold starts or lag during traffic spikes, which is ideal for variable patterns on ECS Fargate.

Exam trap

The trap here is that candidates often choose scheduled scaling alone (Option C) thinking it directly handles variable traffic, but they miss that it cannot react to unexpected spikes or lulls within the scheduled window, whereas target tracking with a schedule provides both proactive and reactive scaling.

How to eliminate wrong answers

Option B is wrong because step scaling policies based on memory utilization are less responsive to traffic-driven CPU spikes and can cause thrashing if memory is not the bottleneck; they also lack the predictive baseline needed for variable patterns. Option C is wrong because scheduled scaling alone cannot adapt to real-time fluctuations within business hours, leading to either over-provisioning or under-provisioning if traffic deviates from the schedule. Option D is wrong because simple scaling policies are deprecated in AWS and lack the cooldown and metric stabilization features of target tracking, making them prone to oscillation and inefficient for variable traffic.

917
MCQhard

A company uses AWS CodeBuild to run unit tests. The build process is taking longer than expected. The buildspec.yml file includes a pre-build phase that downloads dependencies from a public repository. What is the most effective way to reduce build time?

A.Configure the build project to use an S3 cache for dependencies.
B.Run the build in parallel across multiple build projects.
C.Increase the compute type of the build environment to use more vCPUs.
D.Reduce the build timeout setting to force faster execution.
AnswerA

An S3 cache bucket stores the downloaded dependencies between runs, so the pre-build phase retrieves them from S3 rather than re-downloading from the public repository. This directly addresses the stem's constraint: repeated dependency downloads inflating build duration. CodeBuild restores the cache before the pre-build phase, cutting that wait.

Why this answer

The pre-build phase downloads dependencies from a public repository, which is the slowest part of the build. Configuring an S3 cache in CodeBuild lets the project persist and reuse files (like downloaded dependencies) between builds, so subsequent builds skip the network download entirely. This directly targets the identified bottleneck and is the most effective, cost-efficient optimization for repeated dependency fetching.

Exam trap

SAP-C02 often tests the misconception that scaling compute (more vCPUs) or parallelism always reduces build time, when the actual bottleneck is often network-bound dependency retrieval that caching solves.

How to eliminate wrong answers

Option B is wrong because running the build in parallel across multiple build projects does not speed up a single build's dependency download; it just runs separate builds concurrently and adds coordination overhead. Option C is wrong because increasing the compute type adds more vCPUs, but the bottleneck is network I/O waiting on a public repository, not CPU-bound work, so more CPU won't help. Option D is wrong because reducing the build timeout does not make execution faster — it only causes the build to fail sooner if it exceeds the limit, which is the opposite of the goal.

918
MCQmedium

A company is migrating a monolithic Java application to AWS. The application uses a shared file system for storing user-uploaded documents. The company wants to refactor the application to use a microservices architecture with decoupled storage and compute. The application currently writes files to a local directory and serves them via a web server. Which AWS service should be used to store the documents to enable stateless compute and independent scaling?

A.Amazon S3
B.Amazon FSx for Windows File Server
C.Amazon Elastic File System (Amazon EFS)
D.Amazon Elastic Block Store (Amazon EBS)
AnswerA

Amazon S3 is a highly durable, scalable object storage service that decouples storage from compute. By storing documents in S3, the application can be stateless, enabling independent scaling of microservices. S3 also provides features like versioning, lifecycle policies, and event notifications that can trigger downstream processing, making it ideal for modernized applications.

Why this answer

Amazon S3 provides durable, scalable object storage that decouples storage from compute, enabling a stateless microservices architecture. Other options like EFS, EBS, and FSx are file or block storage solutions that require mounting and are not optimized for decoupled, independently scaling services. S3 also integrates with other AWS services for event-driven processing.

Exam trap

The trap here is assuming that a shared file system like Amazon EFS is the best choice because it mimics the on-premises file share, but it does not provide the decoupling and statelessness required for a microservices architecture.

919
MCQeasy

A company wants to ensure that no IAM user in any account can create access keys. The company uses AWS Organizations. Which approach should be used?

A.Enable AWS CloudTrail and set up a metric filter for CreateAccessKey
B.Apply an IAM policy to all users in each account that denies iam:CreateAccessKey
C.Attach an SCP to the root OU that denies iam:CreateAccessKey
D.Use AWS Config to detect access key creation and trigger a Lambda to delete the key
AnswerC

An SCP attached to the root OU applies to every member account in the organisation, denying `iam:CreateAccessKey` regardless of identity-based policies. This satisfies the requirement that no IAM user in any account can create access keys, since SCPs set the maximum permissions boundary across all accounts beneath the root.

Why this answer

A Service Control Policy (SCP) attached to the root organizational unit denies the iam:CreateAccessKey action across all accounts in the organization, providing centralized enforcement. Option A is wrong because CloudTrail logs events but does not prevent them. Option B is wrong because applying an IAM policy in each account is not centrally managed and may be overridden by administrator permissions.

Option D is wrong because AWS Config detects but cannot prevent the action, and the remediation Lambda may have a delay.

920
MCQeasy

A company is migrating a monolithic Java application to AWS. The current architecture uses a single Oracle database. The migration plan is to refactor the application into microservices and use separate Amazon RDS for PostgreSQL databases per service. The company also wants to implement a CI/CD pipeline using AWS CodePipeline and AWS CodeBuild. Which tool should the company use to automate the database schema changes for each microservice?

A.Flyway, integrated into the CI/CD pipeline to run database migrations as part of the application deployment.
B.AWS Database Migration Service (DMS) to continuously replicate schema changes from the source Oracle database.
C.AWS CloudFormation with custom resource Lambda functions to run SQL scripts.
D.AWS CLI scripts executed in CodeBuild to run SQL commands against the target databases.
AnswerA

Flyway runs versioned SQL migrations against each service's RDS for PostgreSQL instance, tracking applied changes in its own schema history table. Embedded as a CodeBuild build step, it applies pending migrations before deployment, satisfying the requirement to automate schema changes per microservice within the existing CI/CD pipeline.

Why this answer

Flyway is a database migration tool that integrates directly into CI/CD pipelines, allowing schema changes to be version-controlled and applied automatically during application deployment. For a microservices architecture with separate PostgreSQL databases, Flyway can manage each service's schema independently, ensuring consistency and rollback capability. This aligns with the requirement to automate schema changes per microservice as part of the migration and modernization effort.

Exam trap

The trap here is that candidates may confuse data migration tools (like AWS DMS) with schema migration tools, or assume that any scripting approach (like AWS CLI) is sufficient, overlooking the need for version control, repeatability, and integration with application deployment pipelines that Flyway provides.

How to eliminate wrong answers

Option B is wrong because AWS DMS is designed for continuous data replication and one-time migrations, not for managing version-controlled schema changes in a CI/CD pipeline; it does not integrate with application deployment workflows. Option C is wrong because AWS CloudFormation with custom Lambda functions is overly complex and not purpose-built for database schema migrations; it lacks built-in versioning, rollback, and migration sequencing that tools like Flyway provide. Option D is wrong because AWS CLI scripts executed in CodeBuild to run SQL commands are fragile, error-prone, and lack version control, dependency management, and repeatability; they do not handle migration history or rollbacks reliably.

921
MCQhard

A company uses AWS CloudFormation to deploy infrastructure. The team wants to ensure that all resources are tagged with a CostCenter tag. They want to automatically remediate any stack that creates resources without the required tag. Which approach is MOST effective?

A.Create a Lambda function that tags resources after creation.
B.Use IAM policies to require tagging on all resource creation.
C.Use a CloudFormation stack policy with a deny effect for resource creation without tags.
D.Use an AWS Config rule with auto-remediation via SSM Automation.
AnswerD

An AWS Config rule evaluates resource configuration continuously, detecting any resource missing the CostCenter tag regardless of which stack created it. Auto-remediation through SSM Automation then applies the tag automatically, satisfying the requirement for automatic remediation across all CloudFormation deployments rather than only at stack creation time.

Why this answer

AWS Config rules can evaluate whether resources have the required CostCenter tag, and auto-remediation via SSM Automation can automatically apply the tag or stop/delete non-compliant resources. This provides continuous compliance and automatic remediation, which is the most effective approach. Other options either do not enforce tagging or are not automatic.

Exam trap

SAP-C02 often tests the difference between preventive and detective controls; candidates may choose IAM policies (preventive) but the question asks for automatic remediation, which requires a detective control like AWS Config with SSM Automation.

How to eliminate wrong answers

Option A is wrong because a Lambda function that tags resources after creation is reactive and may not catch all resources or may fail if the function errors; it also requires custom code and maintenance. Option B is wrong because IAM policies can enforce tagging on some resource creation actions via condition keys, but they do not automatically remediate existing untagged resources and are not comprehensive across all services. Option C is wrong because CloudFormation stack policies are used to protect resources from updates, not to enforce tagging; they cannot deny resource creation based on tags.

922
MCQmedium

A company is designing a new data lake on AWS using Amazon S3. The data will be ingested from various sources, including IoT devices, application logs, and streaming data. The data must be processed in near real-time as it arrives. Which combination of services should be used for ingestion and processing?

A.Amazon S3 Transfer Acceleration and AWS Lambda
B.Amazon Kinesis Data Firehose and Amazon Kinesis Data Analytics
C.Amazon Athena and Amazon S3
D.AWS Glue and Amazon Redshift
AnswerB

Kinesis Data Firehose ingests streaming and log data continuously, while Kinesis Data Analytics runs SQL over the stream for near real-time processing. Together they satisfy the low-latency processing constraint across IoT, logs and streaming sources before landing data in S3.

Why this answer

Amazon Kinesis Data Firehose is the correct ingestion service because it can reliably capture and load streaming data into Amazon S3 in near real-time without custom code. Amazon Kinesis Data Analytics then processes the data using SQL or Apache Flink as it arrives, enabling near real-time transformations and analytics before the data lands in the data lake.

Exam trap

The trap here is that candidates often confuse Amazon S3 Transfer Acceleration (a speed optimization for large file uploads) with a streaming ingestion service, or assume that Athena can process data as it arrives, when in fact Athena only queries data at rest in S3.

How to eliminate wrong answers

Option A is wrong because Amazon S3 Transfer Acceleration is a feature that speeds up uploads over long distances using edge locations, but it does not provide streaming ingestion or near real-time processing capabilities; AWS Lambda alone cannot handle continuous high-throughput streaming ingestion without a buffer like Kinesis. Option C is wrong because Amazon Athena is an interactive query service for analyzing data already stored in S3, not a service for ingesting or processing streaming data in near real-time. Option D is wrong because AWS Glue is a serverless data integration service for batch ETL and cataloging, and Amazon Redshift is a data warehouse for analytics on structured data; neither is designed for near real-time streaming ingestion into a data lake.

923
MCQeasy

A company has a single AWS account and wants to implement a multi-account strategy for better isolation. Which AWS service is designed to help centrally manage multiple accounts?

A.AWS IAM
B.AWS Organizations
C.AWS Control Tower
D.AWS Service Catalog
AnswerB

AWS Organizations provides central governance over multiple accounts through organisational units and service control policies, enabling consolidated billing and policy-based guardrails. It directly satisfies the stem's requirement for centrally managing multiple accounts, whereas IAM and Microsoft Entra ID govern identities within or across separate directories rather than provisioning AWS account structure itself.

Why this answer

AWS Organizations is the native AWS service designed to centrally manage multiple AWS accounts. It allows you to create a hierarchy of accounts with organizational units (OUs), apply service control policies (SCPs) for governance, and consolidate billing. This directly addresses the need for a multi-account strategy with centralized management.

Exam trap

The trap here is that candidates often confuse AWS Control Tower (a managed landing zone service) with AWS Organizations (the underlying account management service), but Control Tower relies on Organizations and is not the service designed for direct central management of multiple accounts.

How to eliminate wrong answers

Option A is wrong because AWS IAM is an identity and access management service for a single account; it cannot create or manage multiple accounts. Option C is wrong because AWS Control Tower is a higher-level service that uses AWS Organizations under the hood to set up a multi-account landing zone, but it is not the core service designed for central management—it is an orchestration layer. Option D is wrong because AWS Service Catalog is used to create and manage a catalog of approved IT services (e.g., EC2, RDS) for end users; it does not manage multiple accounts or their structure.

924
MCQeasy

A company uses AWS Organizations with several OUs for different environments (dev, test, prod). They want to restrict the use of specific EC2 instance types in the prod OU only. Which approach should they use?

A.Create a separate AWS account for prod and use an IAM policy on the account.
B.Attach a service control policy (SCP) to the prod OU that denies ec2:RunInstances for non-approved instance types.
C.Attach an IAM policy to all users in the prod accounts that denies non-approved instance types.
D.Use AWS Config to detect non-approved instance types and terminate them.
AnswerB

An SCP attached to the prod OU sets the maximum permissions for every account beneath it, denying ec2:RunInstances unless the instance type is approved. This satisfies the OU-scoped constraint, restricting instance types in production only while leaving dev and test unaffected.

Why this answer

Service control policies (SCPs) are the correct mechanism to centrally restrict permissions across all accounts within an AWS Organizations organizational unit (OU). By attaching an SCP to the prod OU that denies ec2:RunInstances for non-approved instance types, you enforce a guardrail that applies to every principal (including root users) in all accounts under that OU, regardless of IAM policies. This ensures that even if a user or role has an IAM policy allowing all EC2 instances, the SCP will block the non-approved types.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking IAM policies can centrally restrict all accounts in an OU, when in fact SCPs are the only AWS Organizations feature that applies a guardrail across all accounts without requiring per-account configuration.

How to eliminate wrong answers

Option A is wrong because creating a separate account for prod does not by itself restrict instance types; you would still need an SCP or IAM policy to enforce the restriction, and IAM policies on a single account cannot centrally manage multiple accounts. Option C is wrong because IAM policies attached to users in prod accounts can be overridden by other IAM policies or bypassed by users with administrative privileges, and they do not apply to the root user or services running without an explicit IAM role. Option D is wrong because AWS Config is a detective control that can detect non-approved instance types after they are launched, but it cannot prevent the launch; it would require a separate remediation action (e.g., Lambda) to terminate instances, which is reactive and not a preventive restriction.

925
MCQeasy

A company uses AWS Organizations and has a requirement that all root user activities in member accounts must be immediately reported to the security team. Which combination of actions should be taken to meet this requirement? (Choose the best answer.)

A.Enable AWS CloudTrail and use Amazon Athena to query logs periodically and send a report.
B.Enable AWS CloudTrail in all accounts with a trail that logs management events and delivers to a centralized S3 bucket. Use Amazon CloudWatch Events to create a rule that matches root user API calls and sends notifications via Amazon SNS.
C.Use AWS Config rules to detect root user activities and trigger an AWS Lambda function to send an email.
D.Use AWS Trusted Advisor to check for root user usage and generate a weekly report.
AnswerB

CloudTrail with management events captures root user API activity across all member accounts, satisfying the immediate reporting requirement. A CloudWatch Events rule matching those root calls then triggers Amazon SNS notifications, delivering real-time alerts to the security team without polling or delay.

Why this answer

It combines AWS CloudTrail logging of management events across all accounts into a centralized S3 bucket with Amazon CloudWatch Events (now Amazon EventBridge) to detect root user API calls in real time. This setup ensures immediate notification via Amazon SNS, meeting the requirement for instant reporting without manual polling or batch processing.

Exam trap

The trap here is that candidates may confuse AWS Config rules (which monitor resource configurations) with CloudTrail event monitoring, or assume periodic tools like Athena or Trusted Advisor can satisfy an immediate reporting requirement.

How to eliminate wrong answers

Option A is wrong because using Amazon Athena to query logs periodically introduces a delay (not immediate reporting) and requires manual or scheduled queries, which does not meet the real-time requirement. Option C is wrong because AWS Config rules are designed for resource configuration compliance and change detection, not for monitoring API calls like root user activities; they cannot directly capture CloudTrail events or root user login actions. Option D is wrong because AWS Trusted Advisor provides a weekly report on root user usage, which is not immediate and fails the requirement for real-time notification.

926
MCQeasy

A company is migrating its on-premises data warehouse to AWS. The data warehouse contains 50 TB of data and is used for complex analytical queries. The company wants a fully managed, petabyte-scale solution that can handle the queries efficiently. Which AWS service should be used?

A.Amazon RDS for PostgreSQL
B.Amazon S3 with Amazon Athena
C.Amazon Redshift
D.Amazon DynamoDB
AnswerC

Amazon Redshift is a fully managed, petabyte-scale data warehouse service designed for complex analytical queries. It uses columnar storage and massively parallel processing to deliver high performance. It is the ideal choice for migrating an on-premises data warehouse to AWS.

Why this answer

Amazon Redshift is a fully managed, petabyte-scale data warehouse service that uses columnar storage and massively parallel processing to handle complex analytical queries efficiently. It is designed for exactly this use case, making it the correct choice for migrating an on-premises data warehouse.

Exam trap

The trap here is assuming that Amazon S3 with Athena is a direct replacement for a data warehouse, overlooking the performance and management features of Redshift.

927
MCQmedium

A company is migrating a legacy on-premises application to AWS. The application runs on a physical server with a large local PostgreSQL database. The company wants to minimize downtime during the migration and ensure the on-premises and AWS environments remain synchronized until cutover. The application can tolerate a brief period of read-only mode during the final cutover. Which migration strategy should a solutions architect recommend?

A.Use AWS Database Migration Service (AWS DMS) with ongoing replication to migrate the database to Amazon RDS for PostgreSQL, and use AWS Application Migration Service (AWS MGN) to replicate the application server.
B.Use AWS Snowball Edge to transfer a database backup to Amazon S3, then restore it to Amazon RDS for PostgreSQL, and use AWS DataSync to replicate the application server.
C.Use AWS Database Migration Service (AWS DMS) with ongoing replication to migrate the database to Amazon RDS for PostgreSQL, and use AWS DataSync to replicate the application server.
D.Use native PostgreSQL logical replication to an Amazon RDS for PostgreSQL instance, and use AWS Server Migration Service (SMS) to replicate the application server.
AnswerA

AWS DMS supports continuous replication from an on-premises PostgreSQL database to Amazon RDS for PostgreSQL, keeping the target in sync until cutover. AWS MGN replicates the application server block-level, enabling a staged cutover. This combination minimizes downtime and maintains synchronization, aligning with the requirement for a brief read-only period.

Why this answer

AWS DMS provides continuous data replication from on-premises PostgreSQL to Amazon RDS, keeping the target synchronized until cutover. AWS Application Migration Service (MGN) replicates the application server at the block level, allowing a staged cutover with minimal downtime. This combination meets the requirements for synchronization and a brief read-only period during cutover.

Exam trap

The trap here is assuming that AWS DataSync can replicate an entire application server, when it is actually designed for file-based data transfer and cannot capture the server's operating system or installed applications.

928
MCQmedium

A company is building a new order-processing system on AWS. The system uses an Amazon SQS FIFO queue to receive order events from multiple producers. The company requires strict ordering of messages within each order ID and exactly-once processing. To achieve exactly-once processing, the producers must include a deduplication ID with each message. However, the producers currently do not generate deduplication IDs. What should a solutions architect recommend to meet the ordering and exactly-once processing requirements with minimal changes to the producers?

A.Use a standard SQS queue and rely on the order ID as the message deduplication ID.
B.Enable content-based deduplication on the FIFO queue and set the message group ID to the order ID.
C.Configure the FIFO queue with a visibility timeout and use the order ID as the message group ID, but do not set deduplication.
D.Switch to Amazon Kinesis Data Streams with partition key set to the order ID and enable enhanced fan-out.
AnswerB

Content-based deduplication automatically generates a deduplication ID from the message body, so producers do not need to change. Setting the message group ID to the order ID ensures strict ordering within each order. This meets both requirements with minimal producer changes.

Why this answer

For FIFO queues, content-based deduplication automatically creates a deduplication ID from the message body, eliminating the need for producers to supply one. The message group ID ensures that messages within the same group (order ID) are processed in strict order. This solution requires no producer changes and satisfies both ordering and exactly-once processing.

Exam trap

The trap here is assuming that FIFO queues automatically deduplicate without any configuration, when in fact deduplication must be enabled either by providing a deduplication ID or by turning on content-based deduplication.

929
MCQeasy

A company is migrating an on-premises Oracle database to AWS. The database is 2 TB in size and has a low-latency connection to AWS via AWS Direct Connect. The company wants to minimize downtime during the migration. Which AWS service should the architect use for the initial data load?

A.AWS DataSync
B.AWS Snowball Edge
C.AWS Server Migration Service (AWS SMS)
D.AWS Database Migration Service (AWS DMS)
AnswerD

AWS DMS performs the initial full load and ongoing change data capture replication, keeping the source Oracle database available while data transfers over the existing Direct Connect link. This satisfies the requirement to minimise downtime, unlike offline export or backup-based approaches.

Why this answer

AWS Database Migration Service (AWS DMS) is purpose-built for migrating databases to AWS with minimal downtime, supporting homogeneous and heterogeneous migrations, and it performs the initial full load plus ongoing change data capture (CDC) to keep the target in sync until cutover. For a 2 TB Oracle database over Direct Connect, DMS is the correct choice for the initial data load.

Exam trap

SAP-C02 often tests the confusion between DataSync (file transfer), Snowball (offline bulk), and DMS (database migration), causing candidates to pick DataSync for a database workload.

How to eliminate wrong answers

Option A is wrong because DataSync is for file and object data transfer (NFS, SMB, S3, EFS), not database migration. Option B is wrong because Snowball Edge is for offline bulk data transfer when network bandwidth is insufficient — here Direct Connect provides low-latency connectivity, so Snowball is unnecessary. Option C is wrong because AWS SMS (now Application Migration Service) migrates servers/VMs, not databases.

930
MCQmedium

A company is migrating a web application to AWS and wants to automatically scale the application based on CPU utilization. The application runs on a set of EC2 instances behind an Application Load Balancer. Which combination of AWS services should they use?

A.AWS Lambda with scheduled scaling
B.Amazon CloudFront with origin scaling
C.AWS Elastic Beanstalk with environment scaling
D.Auto Scaling group with a simple scaling policy based on CloudWatch CPU alarm
AnswerD

An Auto Scaling group with a simple scaling policy triggered by a CloudWatch CPU utilisation alarm adjusts desired capacity automatically, satisfying the CPU-based scaling requirement. The Application Load Balancer distributes traffic across the scaled instances, keeping the architecture responsive under varying load.

Why this answer

Auto Scaling group with a simple scaling policy based on a CloudWatch CPU alarm. This directly scales EC2 instances in response to CPU utilization, providing automatic scaling. Option A is incorrect because AWS Lambda with scheduled scaling does not dynamically respond to CPU utilization; it's time-based.

Option B (Amazon CloudFront) is a content delivery network, not a scaling mechanism. Option C (Elastic Beanstalk) manages environments but the underlying scaling relies on Auto Scaling groups; the question asks for the combination of services, and the core scaling service is the Auto Scaling group. Therefore, D is the correct choice.

931
MCQeasy

A company wants to deploy a containerized application on AWS. The application requires persistent storage that can be shared across multiple containers running on different EC2 instances. Which AWS service should be used?

A.EC2 Instance Store
B.Amazon EFS
C.Amazon S3
D.Amazon EBS
AnswerB

Amazon EFS provides a shared, elastic NFS file system mountable concurrently from multiple EC2 instances across Availability Zones, meeting the cross-instance shared persistence requirement. EBS volumes attach to a single instance, and instance store is ephemeral.

Why this answer

Amazon EFS provides a fully managed, scalable, and elastic NFS file system that can be mounted concurrently on multiple EC2 instances. This makes it the ideal choice for persistent storage that must be shared across containers running on different EC2 instances, as it supports the NFSv4.1 and NFSv4.0 protocols and automatically scales storage capacity as files are added or removed.

Exam trap

The trap here is that candidates often confuse Amazon EBS with a shared storage solution, but EBS volumes (except for the limited multi-attach feature) can only be attached to a single EC2 instance at a time, making it unsuitable for multi-instance shared access.

How to eliminate wrong answers

Option A is wrong because EC2 Instance Store provides ephemeral block-level storage that is physically attached to the host computer, and data is lost when the instance is stopped or terminated; it cannot be shared across multiple EC2 instances. Option C is wrong because Amazon S3 is an object storage service accessed via HTTP/HTTPS APIs, not a file system that can be mounted directly by multiple EC2 instances for concurrent read/write access with standard file system semantics. Option D is wrong because Amazon EBS provides block-level storage volumes that can be attached to only one EC2 instance at a time (except for multi-attach EBS io1/io2 volumes, which are limited to a small number of Nitro-based instances and are not designed for general-purpose shared file storage across many containers).

932
Multi-Selectmedium

A company uses an Amazon RDS for MySQL DB instance. The database is experiencing high read latency. The team wants to improve read performance with minimal application changes. Which TWO actions should the team take? (Choose two.)

Select 2 answers
A.Create one or more read replicas and direct read queries to them.
B.Enable Multi-AZ deployment for failover support.
C.Migrate the database to Amazon Aurora.
D.Increase the max_connections parameter.
E.Increase the DB instance size (e.g., from db.r5.large to db.r5.xlarge).
AnswersA, E

Read replicas offload read traffic to separate MySQL instances via asynchronous replication, directly relieving the primary's read latency. This satisfies the minimal-application-change constraint because only the read connection endpoint changes, requiring no schema or query rewrite.

Why this answer

Option A is correct because RDS for MySQL read replicas offload read traffic from the primary instance via asynchronous replication, and applications can point read queries at the replica endpoint with minimal changes, directly reducing read latency on the primary. Option E is correct because scaling up the DB instance class (e.g., db.r5.large to db.r5.xlarge) adds more vCPU and memory, which increases the instance's capacity to process read queries and can lower read latency without application changes. Option B is incorrect because Multi-AZ provides synchronous standby failover for high availability, not read scaling, and the standby does not serve read traffic.

Option C is incorrect because migrating to Aurora is a significant architectural change, not a minimal-change action. Option D is incorrect because max_connections controls the number of concurrent connections, not read performance, and raising it can even increase contention.

Exam trap

The trap is confusing high availability (Multi-AZ) with read scaling — candidates often pick Multi-AZ thinking it improves performance, but the standby is not accessible for reads; only read replicas offload read traffic. Similarly, increasing max_connections is a common distractor that does not address latency.

933
Drag & Dropmedium

Drag and drop the steps to set up a cross-region VPC peering connection in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First initiate, then accept, then add routes, then update security groups, and finally network ACLs.

934
MCQeasy

A company is migrating its on-premises file server to AWS. The file server contains 50 TB of data stored on a Windows Server with NTFS permissions. The company needs to maintain the folder structure and permissions after migration. The migration must be completed within one week. The company has a 100 Mbps internet connection. Which approach should the solutions architect recommend?

A.Use AWS Storage Gateway File Gateway to cache data on-premises and sync to S3.
B.Use AWS Snowball Edge to transfer data to an S3 bucket, then use AWS DataSync to copy to Amazon FSx for Windows File Server.
C.Use AWS DataSync to transfer data directly to Amazon EFS over the internet.
D.Use AWS CLI to copy data directly to an S3 bucket, then mount S3 as a file system.
AnswerB

Snowball Edge bypasses the 100 Mbps link, which would take over 46 days for 50 TB, meeting the one-week deadline. DataSync then preserves NTFS discretionary access control lists and the folder hierarchy when copying into Amazon FSx for Windows File Server, satisfying the permission-retention requirement.

Why this answer

AWS Snowball Edge is used to physically transfer large datasets (50 TB) quickly, bypassing the slow 100 Mbps internet connection (which would take ~46 days). After transfer to S3, AWS DataSync can copy the data to Amazon FSx for Windows File Server, preserving NTFS permissions and folder structure. This meets the one-week deadline and maintains permissions.

Exam trap

SAP-C02 often tests the misconception that AWS DataSync can efficiently transfer large datasets over slow connections, or that S3 can directly serve as a Windows file share with NTFS permissions.

How to eliminate wrong answers

Option A is wrong because AWS Storage Gateway File Gateway caches data on-premises and syncs to S3, but it does not preserve NTFS permissions when migrating to a Windows file server, and the initial sync over 100 Mbps would be too slow. Option C is wrong because AWS DataSync over the internet at 100 Mbps would take too long, and Amazon EFS does not support NTFS permissions (it uses POSIX). Option D is wrong because using AWS CLI to copy to S3 does not preserve NTFS permissions, and mounting S3 as a file system is not natively supported for Windows and does not provide NTFS permission preservation.

935
MCQeasy

A company is using Amazon S3 to store critical data. The security team requires that all data at rest be encrypted using AWS KMS with automatic rotation of the customer master key (CMK) every year. What should a solutions architect do to meet this requirement?

A.Use SSE-S3 (Amazon S3-managed keys) and rely on S3's automatic key rotation.
B.Enable S3 default encryption with AWS KMS and enable automatic rotation of the KMS key.
C.Use SSE-C (customer-provided keys) and manage key rotation manually.
D.Use client-side encryption with a KMS CMK and upload the encrypted data.
AnswerB

S3 default encryption with SSE-KMS encrypts every new object at rest under a KMS key, and enabling annual automatic rotation on that customer managed key satisfies both the encryption and rotation requirements without per-object headers.

Why this answer

The requirement is encryption at rest using AWS KMS with automatic annual rotation of the CMK. Enabling S3 default encryption with SSE-KMS satisfies the KMS encryption requirement, and KMS supports automatic key rotation (configurable for customer-managed keys, with a default and minimum of 90 days, commonly set to 365 days). This is the only option that combines KMS-based encryption with managed rotation.

Exam trap

SAP-C02 often tests the distinction between SSE-S3 (AWS-managed, no customer rotation control), SSE-KMS (customer-managed CMK with automatic rotation), and SSE-C (customer-provided keys, no AWS rotation) — candidates confuse 'automatic rotation' across these models.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses S3-managed keys (AES-256) that the customer cannot control or rotate on a schedule — S3 handles rotation transparently but it is not a KMS CMK, so it fails the 'AWS KMS with annual CMK rotation' requirement. Option C is wrong because SSE-C requires the customer to supply and manage their own encryption keys on every request; AWS does not store or rotate these keys, so automatic rotation is impossible. Option D is wrong because client-side encryption with a KMS CMK encrypts data before upload, but KMS automatic rotation only rotates the CMK's backing key material — it does not re-encrypt existing data, and this approach adds complexity without meeting the 'S3 encryption at rest via KMS' framing as cleanly as SSE-KMS.

936
MCQhard

A company uses an AWS CodePipeline to deploy a serverless application. The pipeline includes a build stage that runs on AWS CodeBuild and a deploy stage that updates an AWS Lambda function. The company wants to add a manual approval step before the deploy stage. What is the most efficient way to implement this?

A.Add an AWS Lambda function that sends an email for approval.
B.Use an AWS CloudFormation stack with a wait condition.
C.Configure an Amazon SNS topic to notify approvers.
D.Add a manual approval action in the CodePipeline stage before deploy.
AnswerD

CodePipeline natively supports a manual approval action, which pauses the pipeline and notifies approvers before the deploy stage runs. Inserting it directly into the existing stage avoids custom Lambda polling or external tooling, meeting the requirement for the most efficient implementation.

Why this answer

AWS CodePipeline has a built-in manual approval action that can be added as a stage before the deploy stage, providing the most efficient way to add manual approval. Option A is incorrect because using a Lambda function for approval is unnecessarily complex compared to the built-in action. Option B is incorrect because a CloudFormation wait condition is not designed for approval workflows in CodePipeline.

Option C is incorrect because an SNS topic can notify approvers but does not integrate directly as an approval action in CodePipeline; the manual approval action is the native solution.

937
MCQmedium

A company is planning to migrate a large-scale Hadoop cluster to Amazon EMR. The cluster currently processes batch jobs using a mix of MapReduce and Spark. The company wants to minimize changes to the existing code and operational processes. Which migration approach should the architect recommend?

A.Refactor all jobs to use only Apache Spark on Amazon EMR
B.Retire the cluster and use Amazon Athena for ad-hoc queries
C.Replatform the data processing to use Amazon Redshift Spectrum
D.Rehost the cluster on Amazon EMR using the same MapReduce and Spark configurations
AnswerD

Rehosting on Amazon EMR preserves the existing MapReduce and Spark APIs, so job code and operational tooling transfer with minimal modification. This directly satisfies the stem's constraint of minimising code and process changes, unlike replatforming to serverless or rewriting jobs for a different engine.

Why this answer

Rehosting the Hadoop cluster on Amazon EMR with the same MapReduce and Spark configurations minimizes code changes and operational disruption, which is exactly what the company wants. EMR supports both MapReduce and Spark natively, so existing jobs can run with minimal modification. This is the classic lift-and-shift approach for Hadoop-to-EMR migrations.

Exam trap

SAP-C02 often tests migration strategy selection — the trap is choosing 'refactor' or 'replatform' when the scenario explicitly says 'minimize changes to existing code,' which points to rehost.

How to eliminate wrong answers

Option A is wrong because refactoring all jobs to Spark requires rewriting MapReduce code, which contradicts the requirement to minimize changes. Option B is wrong because retiring the cluster and using Athena for ad-hoc queries does not support batch MapReduce/Spark jobs and would require re-architecting the entire processing pipeline. Option C is wrong because Redshift Spectrum is a query service for data in S3, not a replacement for MapReduce/Spark batch processing, and would require significant rework.

938
MCQmedium

A company is designing a new microservices architecture on AWS. Each service must be independently deployable and scale based on demand. The company wants to minimize operational overhead for container orchestration. Which AWS service should the company use?

A.Amazon Elastic Kubernetes Service (EKS)
B.Amazon EC2 with Auto Scaling
C.Amazon Elastic Container Service (ECS) with AWS Fargate
D.AWS Lambda
AnswerC

Fargate removes the need to provision or manage EC2 instances for the cluster, so each task runs serverlessly while ECS still provides independent deployment and demand-based scaling per service. This directly satisfies the stem's constraint of minimising container orchestration operational overhead.

Why this answer

Amazon ECS with AWS Fargate is the correct choice because it provides a fully managed container orchestration service that eliminates the need to provision, configure, or scale underlying EC2 instances. Fargate runs each container in its own isolated compute environment, allowing each microservice to scale independently based on demand while minimizing operational overhead for cluster management.

Exam trap

The trap here is that candidates often choose Amazon EKS assuming Kubernetes is the only modern orchestration tool, but the question specifically asks for minimal operational overhead, and Fargate's serverless model removes the need to manage any cluster infrastructure, which EKS does not fully eliminate even with managed node groups.

How to eliminate wrong answers

Option A is wrong because Amazon EKS requires you to manage the Kubernetes control plane (or pay for it) and typically involves managing worker nodes or using managed node groups, which adds operational overhead compared to Fargate's serverless model. Option B is wrong because Amazon EC2 with Auto Scaling requires you to manage the underlying instances, including patching, scaling policies, and container orchestration software, which contradicts the goal of minimizing operational overhead. Option D is wrong because AWS Lambda is designed for short-running, event-driven functions with a maximum execution timeout of 15 minutes and limited runtime environments, making it unsuitable for long-running microservices that require container-level isolation and persistent connections.

939
Multi-Selectmedium

A company is deploying a containerized web application on Amazon Elastic Kubernetes Service (Amazon EKS). The application requires persistent storage that must be shared across multiple pods running on different nodes. The storage must support ReadWriteMany (RWX) access mode and provide high throughput for media processing workloads. The company wants to minimize operational overhead and use AWS managed services. Which two solutions should a solutions architect recommend? (Choose two.)

Select 2 answers
A.Use Amazon Elastic File System (Amazon EFS) with the EFS CSI driver to provide a shared file system for the pods.
B.Use Amazon FSx for Lustre with the FSx CSI driver to provide a high-performance shared file system.
C.Use Amazon Elastic Block Store (Amazon EBS) with the EBS CSI driver to provide persistent volumes for the pods.
D.Use Amazon S3 with the Mountpoint for Amazon S3 CSI driver to provide a shared file system.
E.Use AWS Storage Gateway in file gateway mode to provide an NFS mount for the pods.
AnswersA, B

Amazon EFS supports the ReadWriteMany access mode, allowing multiple pods across different nodes to mount and write to the same file system concurrently. The EFS CSI driver integrates with Amazon EKS to dynamically provision persistent volumes. EFS is a fully managed, scalable file system that requires minimal operational overhead and can deliver high throughput for media processing, making it an ideal choice for this scenario.

Why this answer

Amazon EFS and Amazon FSx for Lustre both support the ReadWriteMany access mode and are managed AWS services that integrate with Amazon EKS via CSI drivers. EFS provides scalable, elastic storage suitable for general-purpose shared file systems, while FSx for Lustre delivers high throughput and low latency for compute-intensive media processing. Together, they offer the required shared storage with minimal operational overhead.

Exam trap

The trap here is assuming that Amazon EBS or Amazon S3 can satisfy a ReadWriteMany requirement, but EBS is limited to single-node attachment and S3 is not a POSIX file system.

940
MCQeasy

A company is migrating to AWS and plans to use a multi-account strategy. The management account will be used solely for administrative purposes. Which best practice should be followed when setting up AWS Organizations?

A.Enable all AWS services in the management account to centrally manage them.
B.Use the management account as the payer account and also host production workloads.
C.Restrict access to the management account and use it only for organization management tasks.
D.Use the management account for development environments to avoid creating additional accounts.
AnswerC

The management account holds root-level control over every member account, so credentials there grant sweeping privileges. Restricting access and limiting its use to organisation management tasks satisfies the stem's requirement that it serve solely administrative purposes, reducing blast radius if compromised.

Why this answer

The management account in AWS Organizations should be strictly restricted and used only for organization-wide administrative tasks, such as managing member accounts, applying service control policies (SCPs), and consolidating billing. This follows the AWS Well-Architected Framework's security pillar, which recommends isolating the management account from any workload or resource deployment to minimize the blast radius of a potential compromise. Using the management account for anything other than organization management violates the principle of least privilege and increases security risk.

Exam trap

The trap here is that candidates often confuse the management account's billing role with a permission to host workloads, or they assume that central management requires enabling all services in the management account, when in fact the management account should be kept as a lightweight, resource-free administrative container.

How to eliminate wrong answers

Option A is wrong because enabling all AWS services in the management account for central management is unnecessary and insecure; instead, services should be enabled only in the member accounts where they are needed, and the management account should not host resources. Option B is wrong because while the management account is the payer account, hosting production workloads in it violates the best practice of isolating the management account from workloads, increasing the attack surface and risk of privilege escalation. Option D is wrong because using the management account for development environments defeats the purpose of a multi-account strategy, which is to isolate environments for security and cost tracking; development workloads should be placed in dedicated member accounts.

941
MCQmedium

A company is designing a new application that will use Amazon DynamoDB as its primary data store. The application requires consistent low-latency read and write performance at any scale, and the company wants to minimize operational effort. The data model includes a table with a partition key and a sort key. The workload is expected to have highly uneven access patterns, with some items being accessed much more frequently than others. Which design approach should a solutions architect recommend to meet these requirements?

A.Use DynamoDB on-demand capacity mode and design the partition key to distribute traffic evenly across partitions.
B.Use DynamoDB provisioned capacity mode with auto scaling and choose a partition key that includes a timestamp to ensure even distribution.
C.Use DynamoDB Accelerator (DAX) in front of the table to cache frequently accessed items and absorb read traffic.
D.Use a global secondary index (GSI) with a different partition key to spread the load and enable queries on alternate attributes.
AnswerA

On-demand capacity mode automatically scales to handle workload changes, eliminating capacity planning and minimizing operational effort. Designing a partition key that distributes traffic evenly prevents hot partitions, ensuring consistent low-latency performance even with uneven access patterns. This combination meets the requirements for scalability and low operational overhead.

Why this answer

On-demand capacity mode removes the burden of capacity planning and automatically scales with workload, minimizing operational effort. A well-distributed partition key is essential to avoid hot partitions and ensure consistent performance, especially when access patterns are uneven. Together, they provide low-latency reads and writes at any scale without manual intervention.

Exam trap

The trap here is assuming that DAX can solve all performance issues, but DAX only accelerates reads and does not help with write scalability or hot partitions.

942
MCQeasy

A company is migrating an on-premises Oracle database to Amazon Aurora PostgreSQL. They need to minimize downtime and ensure data integrity. Which AWS service should they use for the migration?

A.AWS Schema Conversion Tool (SCT)
B.AWS Database Migration Service (DMS)
C.AWS DataSync
D.AWS Snowball Edge
AnswerB

DMS performs continuous change data capture from the source Oracle database, replicating ongoing transactions to Aurora PostgreSQL until cutover. This satisfies the minimal-downtime and data-integrity constraints, unlike a one-off snapshot export, because replication keeps the target synchronised right up to the switch.

Why this answer

AWS Database Migration Service (DMS) supports homogeneous and heterogeneous migrations with minimal downtime. Option A is wrong because SCT only helps with schema conversion, not the actual data migration. Option C is wrong because DataSync is for file storage, not databases.

Option D is wrong because Snowball Edge is for large-scale offline data transfer, not online database migration.

943
MCQeasy

A company has a multi-account AWS environment with a centralized network account that hosts a transit gateway. The company wants to share the transit gateway with multiple member accounts. Which AWS service should be used to share the transit gateway?

A.AWS Resource Access Manager (RAM)
B.AWS PrivateLink
C.VPC peering connection
D.AWS Direct Connect
AnswerA

AWS Resource Access Manager is the only service that natively shares a transit gateway across accounts, satisfying the centralised network account requirement. It lets the owner account specify which member accounts may attach VPCs, avoiding duplicated TGWs or peering.

Why this answer

AWS Resource Access Manager (RAM) enables you to share a transit gateway owned by a central network account with other AWS accounts in your organization. This eliminates the need to create separate transit gateway attachments or VPC peering connections, simplifying network architecture and reducing operational overhead.

Exam trap

The trap here is that candidates often confuse VPC peering (which is point-to-point and non-transitive) with transit gateway sharing via RAM, which provides transitive routing and centralized management across multiple accounts.

How to eliminate wrong answers

Option B is wrong because AWS PrivateLink is used to expose services privately within a VPC via interface endpoints, not for sharing transit gateways across accounts. Option C is wrong because VPC peering connects individual VPCs directly but does not provide a centralized hub-and-spoke model or support transitive routing between multiple VPCs and accounts. Option D is wrong because AWS Direct Connect establishes dedicated network connections from on-premises to AWS, not for sharing transit gateways between accounts.

944
MCQeasy

A company wants to provide its developers with access to a shared development environment in AWS. The developers are in different AWS accounts, and they need to assume an IAM role in the development account. What is the secure way to allow cross-account access?

A.Use a service control policy to allow access from other accounts
B.Create IAM users in the development account for each developer
C.Share the access keys of an IAM user in the development account
D.Create an IAM role in the development account with a trust policy that allows the developers' accounts to assume it
AnswerD

A trust policy on the development account's role names each developer account as principal, so cross-account sts:AssumeRole succeeds without sharing long-term credentials. This satisfies the requirement that developers in separate AWS accounts assume a role in the development account, and it works alongside Microsoft Entra ID federation rather than replacing it.

Why this answer

It uses an IAM role with a trust policy that explicitly grants principals from other AWS accounts permission to assume the role. This is the standard secure method for cross-account access, as it avoids sharing long-term credentials and allows temporary, scoped access via AWS Security Token Service (STS) AssumeRole API.

Exam trap

The trap here is that candidates often confuse service control policies (SCPs) with IAM policies, thinking SCPs can grant cross-account access, but SCPs only act as a guardrail and cannot allow access that isn't already explicitly granted by IAM policies.

How to eliminate wrong answers

Option A is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an AWS Organizations hierarchy; they cannot grant access or allow cross-account access—they only deny or allow permissions within the organization. Option B is wrong because creating IAM users in the development account for each developer from other accounts violates the principle of least privilege and requires managing separate credentials, which is insecure and not scalable for cross-account access. Option C is wrong because sharing access keys of an IAM user exposes long-term credentials, which increases the risk of credential leakage and violates AWS security best practices for cross-account access.

945
MCQmedium

A company uses AWS Organizations with consolidated billing. The finance team needs to track costs by department, which are tagged with 'department' tags. However, some resources are not tagged. The team wants to ensure that all new resources are tagged, and existing untagged resources are identified. What should they do?

A.Use a service control policy (SCP) to deny resource creation without the 'department' tag, and use AWS Config rules to detect untagged resources.
B.Use AWS Config rules to enforce tagging on existing resources and automatically tag them.
C.Use AWS Cost Explorer to report on untagged resources.
D.Create an IAM policy that requires tagging for all actions and attach it to all users.
AnswerA

SCPs set the maximum available permissions for accounts in AWS Organizations, so denying resource creation without the 'department' tag enforces tagging on new resources. AWS Config rules continuously evaluate existing resources and flag untagged ones, satisfying both the prevention and detection requirements.

Why this answer

It combines two complementary AWS services to solve both requirements. A service control policy (SCP) can deny the creation of any resource that does not include the required 'department' tag, enforcing tagging at the organization level across all accounts. AWS Config rules can then be used to detect existing untagged resources by evaluating resources against a desired tagging configuration, providing visibility into non-compliant resources without automatically modifying them.

Exam trap

The trap here is that candidates may confuse AWS Config's ability to detect non-compliance with the ability to automatically remediate (e.g., apply tags), or assume that Cost Explorer can enforce tagging, when in fact it only reports on existing tags.

How to eliminate wrong answers

Option B is wrong because AWS Config rules can detect untagged resources but cannot automatically tag them; they only evaluate compliance and can trigger remediation actions (e.g., via Systems Manager Automation), but the statement 'automatically tag them' is misleading as Config itself does not apply tags. Option C is wrong because AWS Cost Explorer is a cost visualization and analysis tool that can filter by tags but cannot enforce tagging on new resources or identify untagged resources in a proactive manner; it only reports on costs associated with tagged resources. Option D is wrong because IAM policies that require tagging for all actions would apply to API calls made by users, but they cannot enforce tagging on resources created by services (e.g., Auto Scaling, CloudFormation) that may not pass the tag condition, and such a policy would be overly restrictive, potentially blocking legitimate operations that do not support tagging.

946
Multi-Selecthard

A company is designing a new multi-tier web application on AWS. The application uses an Auto Scaling group of EC2 instances for the web tier and an Amazon RDS for PostgreSQL DB instance for the database. To improve security, the company wants to ensure that the web tier instances can connect to the database only through a specific port and that the database is not accessible from the internet. Which steps should the company take? (Choose THREE.)

Select 3 answers
A.Launch the database instance in a public subnet.
B.Configure the database security group to allow inbound traffic on port 5432 from the web tier security group.
C.Store database credentials in AWS Systems Manager Parameter Store.
D.Launch the web tier instances in a private subnet.
E.Set the 'Publicly accessible' option of the RDS instance to 'No'.
AnswersB, D, E

Referencing the web tier's security group as the source restricts inbound database traffic to those instances only, on port 5432. This enforces the requirement that connections arrive solely through the PostgreSQL port from the web tier, rather than any broader CIDR range.

Why this answer

Option B is correct because PostgreSQL listens on TCP port 5432, and referencing the web tier's security group as the source in the RDS security group's inbound rule allows only those EC2 instances to reach the database on that port. Option D is correct because placing the web tier instances in a private subnet removes them from direct internet exposure while still allowing outbound access to the RDS endpoint. Option E is correct because setting the RDS instance's 'Publicly accessible' option to 'No' ensures the database receives only a private IP address and cannot be reached from the internet.

Option A is wrong because a public subnet would expose the database to internet routing, contradicting the requirement. Option C, while a good credential-management practice, does not control network access or port restrictions and is therefore not part of the required steps.

Exam trap

The trap here is that candidates may confuse security best practices (like using Parameter Store for credentials) with network-level access controls, leading them to select Option C instead of recognizing that only security group rules and subnet placement directly control connectivity and internet exposure.

947
MCQhard

A company runs a containerized application on Amazon ECS with Fargate. The application needs to securely access an Amazon S3 bucket. The company wants to follow the principle of least privilege. What should a solutions architect recommend?

A.Define an IAM task role with S3 access policies and reference it in the ECS task definition.
B.Attach an IAM role to the underlying EC2 instance.
C.Assign an IAM role to the ECS service using the ECS service-linked role.
D.Store AWS credentials in the container environment variables.
AnswerA

An IAM task role is assumed by the Fargate task itself, so containers receive temporary credentials scoped to the attached S3 policy. This avoids embedding long-lived keys and satisfies least privilege, since permissions are limited to the specific task rather than the host.

Why this answer

An IAM task role is the recommended mechanism for granting least-privilege permissions to ECS tasks using the Fargate launch type. The task role is defined in the ECS task definition and assumed by the container runtime, allowing the application to securely access the S3 bucket without embedding credentials. This approach follows AWS best practices by scoping permissions to the specific task rather than the underlying infrastructure.

Exam trap

The trap here is that candidates may confuse the ECS service-linked role (used for ECS service management) with the IAM task role (used for granting permissions to the containerized application), or incorrectly assume that Fargate tasks require an underlying EC2 instance role.

How to eliminate wrong answers

Option B is wrong because Fargate does not use underlying EC2 instances; the infrastructure is fully managed by AWS, so attaching an IAM role to an EC2 instance is irrelevant and violates the principle of least privilege by granting permissions to all tasks on that instance. Option C is wrong because the ECS service-linked role (AWSServiceRoleForECS) is used by the ECS service itself to manage resources, not by the containers to access S3; assigning it to the service does not grant permissions to the application code. Option D is wrong because storing AWS credentials in container environment variables is insecure, violates the principle of least privilege, and is unnecessary when IAM task roles provide automatic credential rotation via the AWS STS endpoint.

948
MCQmedium

A company is running a stateful web application on Amazon EC2 instances in an Auto Scaling group. The instances store session data in an Amazon ElastiCache for Redis cluster. The company wants to improve the application's fault tolerance and ensure that session data is not lost if an Availability Zone fails. What should the solutions architect do?

A.Enable Cluster Mode on the ElastiCache for Redis cluster and configure Multi-AZ.
B.Configure the ElastiCache for Redis cluster to have multiple read replicas in the same region.
C.Increase the instance size of the EC2 instances to handle more load.
D.Migrate from ElastiCache for Redis to ElastiCache for Memcached.
AnswerA

Cluster Mode with Multi-AZ provides replication and automatic failover across AZs, protecting against AZ failure.

Why this answer

Enabling Cluster Mode on the ElastiCache for Redis cluster and configuring Multi-AZ provides automatic sharding and replication across Availability Zones. This ensures that session data is not lost if an AZ fails, as replicas in other AZs can take over. Option B is incorrect because read replicas alone do not provide automatic failover or data durability across AZ failures unless Multi-AZ is enabled.

Option C is incorrect because increasing instance size does not protect against AZ failure. Option D is incorrect because ElastiCache for Memcached does not support persistence or replication, so data would be lost on node failure.

949
Multi-Selecthard

A company is modernizing a monolithic application into microservices on AWS. The application currently uses a single SQL database. Which THREE AWS services can help decouple the data layer and enable event-driven communication between microservices?

Select 3 answers
A.Amazon Simple Notification Service (SNS)
B.Amazon RDS
C.Amazon Simple Queue Service (SQS)
D.Amazon ElastiCache
E.Amazon EventBridge
AnswersA, C, E

Amazon SNS provides pub/sub messaging, letting microservices publish events to topics and fan out to multiple subscribers without direct coupling. This satisfies the stem's requirement for event-driven communication between microservices, decoupling producers from consumers. It complements database decoupling by removing synchronous point-to-point calls, enabling asynchronous, scalable event distribution across services.

Why this answer

Amazon SNS (A) is correct because it provides a pub/sub messaging service that lets microservices publish events to multiple subscribers (SQS queues, Lambda, HTTP endpoints), enabling fan-out event-driven communication without tight coupling. Amazon SQS (C) is correct because it offers durable, decoupled point-to-point queues that buffer messages between producers and consumers, allowing microservices to communicate asynchronously and independently scale. Amazon EventBridge (E) is correct because it is a serverless event bus that routes events from AWS services, custom applications, and SaaS sources to targets using rules and filters, which is ideal for event-driven microservice architectures.

Amazon RDS (B) is not correct because it is a relational database service, not a decoupling or event-driven messaging mechanism, and the scenario is moving away from a single SQL database. Amazon ElastiCache (D) is not correct because it is an in-memory caching service (Redis/Memcached) for performance, not a service for decoupling data layers or enabling event-driven communication.

Exam trap

SAP-C02 often tests the confusion between services that store data (RDS, ElastiCache) and those that enable event-driven decoupling (SNS, SQS, EventBridge); candidates may incorrectly select RDS or ElastiCache thinking they help decouple.

950
MCQeasy

A company runs a batch processing job on Amazon EC2 instances that are part of an Auto Scaling group. The job runs every night and takes approximately 2 hours. The instances are launched using a launch template with a Spot Instance request. Recently, the job has been failing because Spot Instances are being reclaimed before the job completes. The company wants a cost-effective solution that ensures the job completes reliably. The job can handle interruptions by checkpointing. Which solution should the company implement?

A.Increase the instance size to complete the job faster.
B.Use a mixed instances policy with a percentage of On-Demand Instances as a fallback.
C.Switch to On-Demand Instances only.
D.Use Reserved Instances for the batch job.
AnswerB

A mixed instances policy blends Spot with a percentage of On-Demand capacity, so when Spot capacity is reclaimed the On-Demand fallback keeps the job running. Checkpointing handles interruption, and the blend preserves cost-effectiveness while guaranteeing completion.

Why this answer

The mixed instances policy in an Auto Scaling group allows you to combine Spot and On-Demand Instances, with a configurable percentage of On-Demand capacity to act as a fallback when Spot capacity is unavailable or reclaimed. Since the job checkpoints and can tolerate interruptions, using a base of On-Demand instances ensures the job always has enough capacity to complete, while Spot instances provide cost savings for the remainder. This balances reliability and cost-effectiveness better than switching entirely to On-Demand or Reserved Instances.

Exam trap

SAP-C02 often tests the misconception that Spot Instances alone can be made reliable by simply increasing instance size or that On-Demand is the only reliable option, overlooking the balanced approach of a mixed instances policy with a base of On-Demand capacity.

How to eliminate wrong answers

Option A is wrong because increasing instance size does not prevent Spot reclamation; it may even increase cost and reduce the pool of available Spot capacity, and it does not guarantee completion. Option C is wrong because switching to On-Demand only ensures reliability but sacrifices cost savings entirely, making it less cost-effective than a mixed policy. Option D is wrong because Reserved Instances require a 1- or 3-year commitment and are not suitable for a nightly batch job that runs only 2 hours; they also do not provide the flexibility of Spot instances and would be more expensive for this intermittent workload.

951
Multi-Selecthard

A company is migrating a legacy application to AWS and needs to decouple the application components. The application currently uses a monolithic architecture with direct calls between components. Which AWS services can help decouple the components? (Choose THREE.)

Select 3 answers
A.Amazon Simple Queue Service (SQS)
B.Amazon Simple Notification Service (SNS)
C.AWS Step Functions
D.Amazon Kinesis Data Streams
E.Amazon EventBridge
AnswersA, B, E

Amazon SQS decouples components by providing a durable, fully managed message queue that buffers asynchronous communication, so producers and consumers no longer call each other directly. This directly satisfies the stem's requirement to break the monolithic application's direct component-to-component calls, absorbing traffic spikes and tolerating consumer failures without losing messages.

Why this answer

Amazon SQS (A) is correct because it provides a fully managed message queue that lets producers and consumers communicate asynchronously, removing direct component-to-component calls and buffering messages for reliable decoupling. Amazon SNS (B) is correct because it implements the publish/subscribe pattern, allowing a publisher to fan out notifications to multiple subscribers without knowing or directly invoking them, which breaks tight coupling. Amazon EventBridge (E) is correct because it is a serverless event bus that routes events from producers to consumers based on rules, enabling event-driven decoupling between otherwise independent components.

AWS Step Functions (C) is a workflow orchestration service that coordinates components but still invokes them in a defined sequence, so it does not by itself decouple them. Amazon Kinesis Data Streams (D) is a real-time streaming service for ingesting and processing high-volume data, not a general-purpose application decoupling mechanism in this scenario.

952
MCQeasy

A company wants to automate the deployment of a three-tier web application on AWS. The deployment should include the network, security groups, EC2 instances, and an Application Load Balancer. Which AWS service should they use?

A.AWS Elastic Beanstalk
B.AWS CloudFormation
C.AWS CodeDeploy
D.AWS OpsWorks
AnswerB

AWS CloudFormation provisions the entire stack declaratively from a template, defining VPC subnets, security groups, EC2 instances and the Application Load Balancer as interdependent resources. This satisfies the stem's requirement to automate deployment of all three tiers together, rather than configuring each component manually or scripting only parts of the infrastructure.

Why this answer

AWS CloudFormation is an Infrastructure as Code service that lets you define and provision AWS resources — including VPCs, subnets, security groups, EC2 instances, and Application Load Balancers — declaratively in templates. It is the correct choice for automating the deployment of an entire three-tier architecture with all supporting network and security components.

Exam trap

The trap is confusing deployment orchestration (CodeDeploy) or PaaS abstraction (Elastic Beanstalk) with infrastructure provisioning — only CloudFormation declaratively provisions the full stack including network and load balancer.

How to eliminate wrong answers

Option A is wrong because Elastic Beanstalk is a PaaS that abstracts infrastructure for application deployment; it does not give granular control over VPC, subnets, security groups, and ALB configuration in a single declarative template. Option C is wrong because CodeDeploy is a deployment orchestration service for applications onto EC2, Lambda, or ECS — it does not provision network or load balancer infrastructure. Option D is wrong because AWS OpsWorks (Chef/Puppet-based) is a configuration management service, not a declarative infrastructure provisioning tool, and it is legacy/deprecated for new architectures.

953
MCQmedium

A company is designing a new application that will process sensitive financial data. The data must be encrypted at rest and in transit. The application runs on EC2 instances. Which combination of services meets these requirements?

A.Use Amazon S3 with server-side encryption and enforce HTTPS.
B.Use AWS Key Management Service (KMS) to generate keys and enable encryption on EBS volumes.
C.Use AWS Certificate Manager (ACM) to issue TLS certificates and configure the application to use HTTPS.
D.Enable EBS encryption on the volumes and configure the application to use TLS for all network traffic.
AnswerD

EBS encryption protects data at rest on the attached volumes, while TLS secures data in transit between the application and its clients or services. Together they satisfy both stated requirements for the financial data processed on the EC2 instances.

Why this answer

It addresses both encryption requirements: EBS encryption ensures data at rest is encrypted using AWS KMS-managed keys, and configuring the application to use TLS encrypts data in transit between clients and the EC2 instances. This combination directly meets the stated security needs without relying on external services like S3 or ACM for the EC2-hosted application.

Exam trap

The trap here is that candidates often pick options that address only one requirement (e.g., only encryption at rest or only encryption in transit) or confuse storage services (S3) with compute services (EC2), failing to realize both encryption states must be covered for the EC2-based application.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is a storage service, not the compute platform (EC2) where the application runs; using S3 with server-side encryption and HTTPS does not encrypt data at rest on EC2 EBS volumes or in transit to/from the application. Option B is wrong because enabling encryption on EBS volumes only covers data at rest, but does not address encryption in transit for network traffic. Option C is wrong because ACM-issued TLS certificates and HTTPS only encrypt data in transit, leaving data at rest on EC2 EBS volumes unencrypted.

954
MCQmedium

A company is designing a multi-region active-active application using Amazon DynamoDB. They need to ensure low-latency reads and writes globally. Which DynamoDB feature should they use?

A.Auto Scaling
B.DynamoDB Accelerator (DAX)
C.DynamoDB Streams
D.Global Tables
AnswerD

Global Tables replicate data across chosen AWS Regions with multi-active writes, letting each Region serve local reads and writes at single-digit millisecond latency. This satisfies the active-active, low-latency global requirement, whereas single-Region tables or read replicas cannot accept writes everywhere.

Why this answer

DynamoDB Global Tables provide a fully managed, multi-region, active-active replication solution. They automatically replicate data across chosen AWS Regions, allowing low-latency reads and writes from any region. This directly meets the requirement for a multi-region active-active application with global low-latency access.

Exam trap

SAP-C02 often tests the difference between features that improve performance within a region (like DAX) and those that enable multi-region active-active (Global Tables). Candidates may mistakenly choose DAX for global low-latency, but DAX is region-specific and does not replicate data.

How to eliminate wrong answers

Option A is wrong because Auto Scaling only adjusts read/write capacity based on demand; it does not replicate data across regions. Option B is wrong because DAX is an in-memory cache for DynamoDB that reduces read latency within a single region, but it does not provide multi-region replication or active-active writes. Option C is wrong because DynamoDB Streams captures a time-ordered sequence of item-level changes, but it is not a replication feature; it is used for triggers and change data capture, not for global active-active setups.

955
MCQeasy

A company has a production AWS account with multiple VPCs connected via a transit gateway. The security team wants to centrally capture all VPC flow logs for analysis in Amazon Athena. What is the MOST cost-effective way to store the flow logs?

A.Publish VPC Flow Logs to an Amazon S3 bucket with S3 Intelligent-Tiering enabled.
B.Publish VPC Flow Logs to both CloudWatch Logs and S3 for redundancy.
C.Use Amazon Kinesis Data Firehose to stream flow logs to an S3 bucket.
D.Publish VPC Flow Logs to Amazon CloudWatch Logs and export them to S3 after 30 days.
AnswerA

S3 is cost-effective for log storage, and Intelligent-Tiering automatically moves data to lower-cost tiers.

Why this answer

VPC Flow Logs can be published directly to Amazon S3, and S3 Intelligent-Tiering automatically moves objects between frequent and infrequent access tiers based on usage patterns, minimizing storage cost for log data that is queried sporadically by Athena. This avoids CloudWatch Logs ingestion and storage charges, which are significantly higher per GB.

Exam trap

SAP-C02 often tests whether candidates default to CloudWatch Logs for log aggregation out of habit, missing that direct S3 delivery plus Intelligent-Tiering is the cost-optimized pattern for high-volume log analytics.

How to eliminate wrong answers

Option B is wrong because duplicating flow logs to both CloudWatch Logs and S3 incurs unnecessary CloudWatch ingestion and storage costs, defeating the cost-effectiveness requirement. Option C is wrong because Kinesis Data Firehose adds streaming infrastructure and per-GB delivery charges on top of S3 storage, which is unnecessary when VPC Flow Logs natively support direct S3 delivery. Option D is wrong because CloudWatch Logs ingestion and retention for 30 days is far more expensive than direct S3 delivery, and the export step adds complexity and cost.

956
MCQhard

A company is designing a new application that requires a relational database with high availability and automatic failover across multiple Availability Zones. The database must support read-heavy workloads with minimal latency and must be able to scale read capacity independently. The company wants to minimize administrative overhead. Which solution meets these requirements?

A.Amazon RDS for PostgreSQL with Multi-AZ and a standby replica that can serve read traffic to offload the primary.
B.Amazon Aurora with a Multi-AZ deployment and Aurora Replicas in the same region.
C.Amazon DynamoDB with global tables and on-demand capacity mode.
D.Amazon RDS for MySQL with a Multi-AZ deployment and a read replica in a different region.
AnswerB

Amazon Aurora stores data across multiple Availability Zones and supports Aurora Replicas that can serve read traffic with low latency. It provides automatic failover and allows independent scaling of read capacity by adding replicas. Aurora is fully managed, minimizing administrative overhead. This meets all requirements: high availability, automatic failover, low-latency reads, and independent read scaling.

Why this answer

Amazon Aurora is a MySQL- and PostgreSQL-compatible relational database that provides high availability through storage replication across three Availability Zones and automatic failover. Aurora Replicas can serve read-only traffic, enabling independent scaling of read capacity with low latency. It is fully managed, reducing administrative overhead.

Exam trap

The trap here is assuming that an RDS Multi-AZ standby can serve read traffic, but it cannot; only read replicas can offload reads.

957
MCQeasy

A company is designing a new web application that will be accessed by users globally. The application uses Amazon CloudFront as a CDN and stores static content in Amazon S3. The dynamic content is served from EC2 instances in a single AWS Region. Which of the following will improve performance for users in distant regions with the LEAST operational effort?

A.Deploy EC2 instances in multiple AWS Regions and use Route 53 latency-based routing.
B.Use AWS Global Accelerator to route traffic to the EC2 instances via the AWS global network.
C.Move the dynamic content to Lambda@Edge functions running at CloudFront edge locations.
D.Add an Amazon ElastiCache cluster in front of the EC2 instances to cache dynamic responses.
AnswerB

AWS Global Accelerator provides static anycast IP addresses and routes user traffic onto the AWS global network at the nearest edge location, reducing latency to the single-Region EC2 origin. It satisfies the distant-user performance requirement with minimal operational effort, requiring no application changes or multi-Region deployment.

Why this answer

AWS Global Accelerator uses the AWS global network to route traffic from edge locations to the optimal EC2 endpoint, reducing latency and jitter for distant users without requiring multi-region deployments. This minimizes operational effort because it involves only a single configuration change (creating an accelerator and associating it with the existing EC2 instances) rather than managing infrastructure across multiple regions.

Exam trap

The trap here is that candidates often assume Lambda@Edge can handle all dynamic content at the edge, but they overlook its execution time and resource constraints, making it unsuitable for complex backend logic or database queries.

How to eliminate wrong answers

Option A is wrong because deploying EC2 instances in multiple AWS Regions and using Route 53 latency-based routing requires significant operational overhead for managing, patching, and synchronizing infrastructure across regions, which contradicts the 'least operational effort' requirement. Option C is wrong because Lambda@Edge functions are designed for lightweight compute at edge locations (e.g., header manipulation, authentication) and are not suitable for serving full dynamic content from a backend, as they have execution time limits (5 seconds for viewer events) and cannot maintain persistent connections to databases. Option D is wrong because adding an ElastiCache cluster in front of EC2 instances only caches dynamic responses for repeated requests within a single region, but does not reduce network latency for users in distant regions who still traverse the public internet to reach the origin region.

958
MCQeasy

A company has deployed a web application on Amazon ECS with Fargate. The application needs to access an Amazon RDS database. The security team mandates that the database must not be publicly accessible. What is the best way to securely connect the ECS tasks to the RDS database?

A.Use a NAT gateway to route traffic from ECS tasks to RDS.
B.Attach an internet gateway to the VPC and route through it.
C.Enable public accessibility on the RDS instance and restrict access to the ECS task public IP.
D.Place the ECS tasks and RDS instance in the same VPC, and configure security groups to allow traffic on the database port.
AnswerD

Keeping both the Fargate tasks and the RDS instance in the same VPC lets traffic traverse private addresses, so the database never needs public accessibility. Security groups then restrict inbound access to the database port from the tasks' security group only.

Why this answer

Placing ECS tasks and RDS in the same VPC allows private communication via security groups. This ensures the database is not publicly accessible. Option A is incorrect because a NAT gateway is for outbound internet access, not for inbound traffic to RDS.

Option B is incorrect because an internet gateway would expose the RDS instance to the internet. Option C is incorrect because enabling public accessibility would violate the security mandate even with IP restrictions.

959
MCQmedium

A company is migrating a large-scale batch processing system from on-premises to AWS. The system runs millions of short-lived jobs each day. The company wants to minimize operational overhead and cost. Which AWS compute service should the company use?

A.Amazon EC2 with Spot Fleet
B.Amazon ECS with AWS Fargate
C.AWS Lambda
D.AWS Batch
AnswerD

AWS Batch dynamically provisions optimal compute (Spot or On-Demand) for millions of short-lived jobs, queues and schedules them automatically, and scales to zero between runs. This removes cluster management overhead and cuts cost versus continuously running servers.

Why this answer

AWS Batch is specifically designed for batch computing workloads, handling millions of short-lived jobs efficiently by automatically provisioning compute resources and scaling based on job demand. It integrates with Spot Instances to reduce costs. Option A is wrong because EC2 with Spot Fleet requires manual management of instances and scaling, increasing operational overhead.

Option B is wrong because ECS with Fargate is optimized for containerized applications, but AWS Batch provides more specialized features for batch job scheduling and cost optimization. Option C is wrong because Lambda has a maximum execution timeout of 15 minutes and is intended for short, event-driven functions, not suitable for batch processing.

960
MCQeasy

A company wants to decouple a frontend API from backend processing to improve scalability and fault tolerance. The frontend sends requests that can be processed asynchronously. Which AWS service should be used to decouple the components?

A.Amazon Simple Notification Service (SNS)
B.Amazon Simple Queue Service (SQS)
C.Amazon Kinesis Data Streams
D.AWS Step Functions
AnswerB

Amazon SQS provides a fully managed message queue that buffers requests between the frontend API and backend workers, so components communicate asynchronously without direct coupling. This satisfies the decoupling requirement, absorbing traffic spikes and letting backend processing scale or fail independently of the frontend.

Why this answer

Amazon Simple Queue Service (SQS) is the correct choice because it provides a fully managed message queue that decouples the frontend API from backend processing. The frontend can send requests to an SQS queue, and backend consumers can poll and process messages asynchronously, which improves scalability by buffering traffic spikes and enhances fault tolerance by persisting messages until they are successfully processed.

Exam trap

The trap here is that candidates often confuse SNS (push-based notification) with SQS (pull-based queue) for decoupling, but SNS does not provide the durable, asynchronous message buffer required for decoupling frontend and backend processing.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub messaging service that pushes messages to subscribers (e.g., HTTP endpoints, Lambda, SQS) but does not provide a durable buffer for asynchronous decoupling; it is designed for fan-out notifications, not for queuing where consumers pull messages at their own pace. Option C is wrong because Amazon Kinesis Data Streams is optimized for real-time streaming of large-scale data (e.g., clickstreams, logs) with ordered records and replay capabilities, not for simple request/response decoupling where each message is processed independently by a single consumer. Option D is wrong because AWS Step Functions is a serverless orchestration service for coordinating multiple AWS services into workflows, not a message queue; it does not inherently decouple frontend from backend via asynchronous message buffering.

961
MCQhard

A company is designing a new application that will use Amazon RDS for PostgreSQL. They need to implement read replicas to offload read traffic. However, they are concerned about replication lag affecting read consistency. Which action would minimize replication lag?

A.Increase the allocated storage on the primary instance
B.Use an encrypted connection between the primary and replica
C.Enable Multi-AZ on the primary instance
D.Use instance types with higher network performance
AnswerD

Replication lag on RDS read replicas is primarily bounded by the network throughput between primary and replica and by write volume. Larger instance types with higher network performance let the replica apply the primary's WAL stream faster, reducing lag and improving read consistency.

Why this answer

Using an instance type with higher network performance (option D) reduces replication lag because it provides more bandwidth for the replication process. Option A (increasing allocated storage) does not directly affect replication lag. Option B (using an encrypted connection) does not impact lag; encryption adds overhead but is necessary for security.

Option C (enabling Multi-AZ) is for high availability, not for read replicas.

962
MCQhard

A company uses AWS CodePipeline to deploy a web application to Amazon ECS. The deployment often fails because the ECS service's desired count is not met during the update. The company wants to implement a blue/green deployment with automated rollback on failure. What is the MOST effective approach?

A.Use CodePipeline with a Lambda function to swap target groups and monitor health.
B.Use CodeDeploy with an in-place deployment configuration and a manual approval step.
C.Use CodePipeline with ECS rolling update and CloudWatch alarms to trigger rollback.
D.Use CodePipeline with CodeDeploy to perform a blue/green deployment on ECS and configure automatic rollback.
AnswerD

CodeDeploy's ECS blue/green deployment shifts production traffic between two target groups only after the replacement task set reaches steady state, so the desired-count constraint is verified before cutover. CloudWatch alarms trigger automatic rollback to the original task set, restoring the previous listener rule without manual intervention.

Why this answer

CodePipeline integrated with CodeDeploy for ECS blue/green deployments provides automated traffic shifting, health monitoring, and automatic rollback on failure. CodeDeploy manages the replacement task set, shifts traffic via the load balancer, and rolls back if alarms fire or health checks fail, which directly addresses the desired count issue.

Exam trap

The trap is thinking a custom Lambda or rolling update with alarms is equivalent to CodeDeploy blue/green — only CodeDeploy provides native automated rollback and traffic shifting for ECS.

How to eliminate wrong answers

Option A is wrong because a custom Lambda swapping target groups lacks built-in health monitoring and automated rollback semantics that CodeDeploy provides. Option B is wrong because in-place deployments do not provide blue/green traffic shifting and cannot roll back as cleanly; manual approval also does not automate rollback. Option C is wrong because ECS rolling updates with CloudWatch alarms can trigger rollback but do not provide true blue/green isolation or CodeDeploy's automated rollback hooks.

963
MCQmedium

A company is migrating a stateful web application to AWS. The application uses local storage for user sessions. Which AWS service can help make the application stateless and scalable?

A.Amazon EBS
B.Amazon ElastiCache
C.Amazon RDS
D.Amazon S3
AnswerB

Amazon ElastiCache provides a shared, low-latency external store that offloads session state from instance-local storage. This directly addresses the stem's constraint of local storage for user sessions, letting instances be replaced freely and scaled horizontally behind a load balancer.

Why this answer

Amazon ElastiCache provides a managed in-memory cache that can store session data externally, allowing the web application to be stateless and scale horizontally. Amazon EBS volumes are attached to a single EC2 instance and cannot be shared across instances, so they do not help with statelessness. Amazon RDS is for relational databases and is not optimized for low-latency session state.

Amazon S3 is an object store with higher latency and is not suitable for frequent session reads/writes.

964
MCQhard

A company is migrating a batch processing application to AWS. The application reads large CSV files from an on-premises NFS server, processes them, and writes results to a local database. The company wants to reduce operational overhead and leverage AWS managed services. The migration should be completed with minimal code changes. Which migration approach should be used?

A.Use AWS DataSync to copy the CSV files to Amazon S3, then use AWS Batch to run the existing application in Docker containers on EC2, and store results in Amazon RDS.
B.Move the CSV files to Amazon S3, use AWS Lambda to process each file, and store results in Amazon DynamoDB.
C.Use AWS Storage Gateway File Gateway to provide NFS access to Amazon S3, then run the application on Amazon EC2 and store results in Amazon S3.
D.Use AWS Snowball Edge to transfer the CSV files to Amazon S3, then use Amazon EMR to process the files and store results in Amazon Redshift.
AnswerA

AWS DataSync automates the transfer of files from on-premises NFS to Amazon S3. AWS Batch can run the existing application in Docker containers with minimal changes, as it supports custom AMIs and job definitions. Storing results in Amazon RDS maintains the relational database model. This approach reduces operational overhead by using managed services while minimizing code changes.

Why this answer

The correct approach is to use AWS DataSync to move files to Amazon S3, then AWS Batch to run the existing application in Docker containers with minimal changes, and store results in Amazon RDS. This leverages managed services for data transfer and compute orchestration, reducing operational overhead, while preserving the application's logic and database model, thus minimizing code changes.

Exam trap

The trap here is assuming that serverless options like Lambda are always best, but they may require code changes and have limitations for long-running batch jobs.

965
Multi-Selecthard

A company is designing a new containerized application on Amazon EKS. The application must be able to access secrets (e.g., database credentials) securely. The company requires that secrets be automatically rotated and audited. Which THREE actions should the company take to meet these requirements?

Select 3 answers
A.Mount the Secrets Store CSI Driver volume directly to the pod without using ASCP
B.Use IAM roles for service accounts (IRSA) to grant pods access to Secrets Manager
C.Store secrets in AWS Secrets Manager and enable automatic rotation
D.Use the AWS Secrets and Configuration Provider (ASCP) for the Secrets Store CSI Driver to inject secrets into pods
E.Store secrets in Kubernetes Secrets and use a ConfigMap to reference them
AnswersB, C, D

IRSA maps a Kubernetes service account to an IAM role via the EKS OIDC provider, letting pods retrieve Secrets Manager values without long-lived credentials. This enables fine-grained IAM policies and CloudTrail auditing of each secret access.

Why this answer

Option B is correct because IAM roles for service accounts (IRSA) associates a Kubernetes service account with an IAM role via the cluster's OIDC provider, giving pods scoped, credential-free access to AWS Secrets Manager without embedding long-lived keys. Option C is correct because AWS Secrets Manager natively supports automatic rotation through Lambda rotation functions, and it logs API calls to CloudTrail for auditing, satisfying both the rotation and audit requirements. Option D is correct because the AWS Secrets and Configuration Provider (ASCP) for the Secrets Store CSI Driver mounts Secrets Manager secrets as volumes into pods and can sync them to Kubernetes Secrets, enabling rotation-aware secret delivery to the application.

Option A is wrong because the Secrets Store CSI Driver alone cannot retrieve AWS Secrets Manager secrets without the ASCP provider plugin, so mounting the volume directly would fail. Option E is wrong because Kubernetes Secrets are not automatically rotated and are only base64-encoded by default, and ConfigMaps are not designed for sensitive credential storage or auditing.

Exam trap

The trap here is that candidates may think mounting the CSI driver without ASCP (Option A) is sufficient, but ASCP is the critical component that bridges the CSI driver to AWS Secrets Manager, and without it, the driver cannot retrieve secrets from AWS.

966
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). Users report intermittent 503 errors. The ALB target group health checks are failing. Which step is MOST likely to resolve the issue?

A.Change the health check protocol from HTTP to HTTPS.
B.Use a Network Load Balancer instead of ALB.
C.Increase the number of instances in the target group.
D.Increase the health check timeout and decrease the unhealthy threshold.
AnswerD

Gives instances more time to respond and reduces sensitivity to transient failures.

Why this answer

Increasing the health check timeout gives instances more time to respond before being marked unhealthy, and decreasing the unhealthy threshold allows more consecutive failed health checks before considering an instance unhealthy, reducing false positives. Option A is incorrect because changing the protocol does not address the underlying cause of health check failures; it might even fail if the application does not support HTTPS. Option B is incorrect because using a Network Load Balancer does not resolve health check failures; NLB health checks are different but still need proper configuration.

Option C is incorrect because simply increasing the number of instances does not fix the health check issue; instances may still fail health checks if they are not healthy.

967
MCQeasy

A company wants to assess its on-premises environment for migration to AWS. The company needs to collect utilization data for servers and applications. Which AWS service should the company use?

A.AWS Migration Hub
B.AWS Database Migration Service (DMS)
C.AWS Application Discovery Service
D.AWS Server Migration Service (SMS)
AnswerC

AWS Application Discovery Service gathers on-premises server and application utilisation data, including CPU, memory and network metrics, via agentless or agent-based collection. It satisfies the stem's requirement to assess the existing environment before migration, feeding that data into Migration Hub for planning.

Why this answer

AWS Application Discovery Service collects server and application utilization data from on-premises environments to support migration planning. Option A is wrong because AWS Migration Hub tracks migrations but does not perform discovery. Option B is wrong because AWS Database Migration Service (DMS) is for migrating databases, not for collecting utilization data.

Option D is wrong because AWS Server Migration Service (SMS) is deprecated and was used for migrating individual servers, not for discovery.

968
Multi-Selectmedium

A company is designing a new batch processing system that processes large files from Amazon S3. The processing is CPU-intensive and can take up to 2 hours per file. The company wants to minimize cost and avoid idle compute capacity. Which THREE components should the architect include? (Choose THREE.)

Select 3 answers
A.EC2 Spot Instances to reduce compute costs.
B.AWS Lambda functions to process each file.
C.AWS Batch with a job queue and compute environment.
D.Amazon S3 Event Notifications to trigger the batch job when a new file is uploaded.
E.Auto Scaling group with scheduled scaling policies.
AnswersA, C, D

EC2 Spot Instances use spare AWS capacity at steep discounts, directly addressing the minimise-cost requirement. Because jobs run up to two hours and are interruptible batch work, Spot reclaim risk is acceptable, and capacity releases avoid idle compute.

Why this answer

Option A is correct because EC2 Spot Instances can cut compute costs by up to 90% versus On-Demand, and since the workload is a fault-tolerant batch job that can be retried, Spot interruptions are acceptable, directly supporting the goal of minimizing cost. Option C is correct because AWS Batch is purpose-built for batch computing: it manages a job queue and a compute environment (which can be backed by Spot Instances), dynamically provisioning resources so there is no idle compute capacity. Option D is correct because Amazon S3 Event Notifications can publish an event (e.g., to Amazon EventBridge, SQS, or Lambda) when a new file lands in the bucket, automatically submitting the batch job and eliminating polling or manual triggering.

Option B is not appropriate because Lambda has a maximum execution timeout of 15 minutes, far short of the 2-hour CPU-intensive processing time per file. Option E is not appropriate because an Auto Scaling group with scheduled scaling provisions capacity on a time schedule rather than reacting to file arrivals, which risks idle compute and does not provide the job queue and job management that AWS Batch offers.

Exam trap

The trap here is that candidates often choose AWS Lambda for any event-driven processing without considering its 15-minute timeout limit, overlooking that long-running CPU-intensive tasks require a different compute service like AWS Batch.

969
MCQmedium

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences performance degradation during peak hours. CloudWatch metrics show that the CPU utilization of the EC2 instances regularly reaches 90-100% during these periods. The company wants to ensure the application remains responsive during peak loads while minimizing costs. Which solution should a solutions architect recommend?

A.Configure a target tracking scaling policy on the Auto Scaling group with a predefined metric of ASGAverageCPUUtilization and a target value of 50%.
B.Enable detailed monitoring for the EC2 instances and create a CloudWatch alarm that triggers a step scaling policy when CPU utilization exceeds 80%.
C.Configure a scheduled scaling policy to increase the desired capacity during known peak hours.
D.Configure a target tracking scaling policy on the Auto Scaling group with a predefined metric of ALBRequestCountPerTarget and a target value of 1000.
AnswerA

Target tracking with ASGAverageCPUUtilization at 50% will automatically adjust the number of instances to keep average CPU utilization near the target. This directly addresses the CPU bottleneck by scaling out when utilization rises, ensuring responsiveness during peak loads. It is a simple and effective solution that also minimizes costs by scaling in when demand drops.

Why this answer

The application's performance degradation is directly linked to high CPU utilization on the EC2 instances. A target tracking scaling policy using the ASGAverageCPUUtilization metric with a target of 50% will automatically add or remove instances to keep CPU utilization near that level. This provides responsive scaling during peak loads and cost savings during low demand.

Other options either do not directly address CPU load or require manual tuning and prediction.

Exam trap

The trap here is assuming that scaling based on request count or a fixed schedule is always sufficient, when the actual bottleneck is CPU utilization, which requires a metric that reflects compute load.

970
MCQeasy

A company is using AWS Organizations and wants to allow certain member accounts to create VPCs with specific CIDR ranges. Which mechanism should be used to enforce this restriction?

A.Use AWS Config rules to automatically delete non-compliant VPCs.
B.Use IAM policies with conditions on the ec2:CreateVpc action in each account.
C.Use AWS CloudTrail to monitor VPC creation and alert the security team.
D.Use SCPs with conditions on the ec2:CreateVpc action, specifying allowed CIDR ranges.
AnswerD

SCPs can deny VPC creation if the CIDR does not match allowed ranges.

Why this answer

SCPs (Service Control Policies) are the correct mechanism because they allow you to centrally control the maximum available permissions for all IAM users and roles in member accounts within an AWS Organization. By attaching an SCP with a condition key like `ec2:CreateVpc` and specifying allowed CIDR ranges (e.g., using `StringEquals` or `IpAddress` condition operators), you can enforce that only VPCs with permitted CIDR blocks can be created across all affected accounts, regardless of local IAM policies.

Exam trap

The trap here is that candidates often confuse IAM policies (which are account-specific and can be overridden by local admins) with SCPs (which are organization-wide guardrails that cannot be bypassed by member account administrators), leading them to choose Option B instead of the correct preventive control.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can detect non-compliant VPCs and trigger remediation (e.g., deletion), but they are reactive and cannot prevent the creation of a non-compliant VPC in the first place; the VPC would exist momentarily, potentially causing transient security or networking issues. Option B is wrong because IAM policies with conditions on `ec2:CreateVpc` would need to be applied individually to each member account's IAM roles/users, which is operationally complex and does not prevent a rogue admin with full IAM permissions in that account from bypassing the restriction. Option C is wrong because AWS CloudTrail only logs API calls after they occur; it cannot enforce or block the creation of a VPC, only alert after the fact, which is not a preventive control.

971
MCQhard

A company is migrating a containerized application from on-premises Kubernetes to Amazon EKS. The application requires persistent storage with high IOPS and must be accessible by multiple pods across different Availability Zones. Which storage solution should be used?

A.Amazon S3 mounted as a file system using s3fs.
B.Amazon FSx for Lustre with a scratch file system.
C.Amazon EBS with io2 Block Express volumes.
D.Amazon EFS with provisioned throughput.
AnswerD

Amazon EFS is a shared file system that can be mounted by multiple pods across different Availability Zones within a region. Provisioned throughput mode allows specifying throughput independently of storage size, providing the high IOPS required for the application.

Why this answer

Amazon EFS provides a shared, POSIX-compliant file system that can be mounted by multiple pods across Availability Zones. With provisioned throughput, EFS can deliver high IOPS independent of storage capacity, meeting the performance requirement. Other options are either not shared across AZs, not durable, or not suitable for high-performance file storage.

Exam trap

The trap here is assuming that Amazon EBS Multi-Attach can be used across Availability Zones, but it is limited to a single AZ and cannot satisfy cross-AZ sharing.

972
MCQmedium

A Solutions Architect runs the above AWS CLI command and gets the output shown. The instance is 'running' but the application is not accessible. What should the Solutions Architect check next?

A.Check if the instance is terminated.
B.Check if the instance ID is correct.
C.Check the instance status checks.
D.Check the security group rules for the instance.
AnswerD

A running instance with an unreachable application commonly indicates network filtering rather than instance state. Security group rules govern inbound traffic to the instance, so verifying that the required port is permitted from the client or load balancer is the logical next diagnostic step.

Why this answer

The instance is running but the application is inaccessible, which often indicates that security group rules are not allowing the required inbound traffic. Option A is wrong because the instance is reported as 'running', so it is not terminated. Option B is wrong because the command output successfully returns instance details, meaning the instance ID is correct.

Option C is wrong because status checks relate to the health of the instance OS and system, not network access.

973
MCQhard

A financial services company is migrating 45 on-premises physical servers to AWS. Many servers have underutilized resources and inconsistent tagging. The migration team must right-size instances and reduce costs. They need a service that collects server utilization and dependency data to form migration groups. Which AWS service should they use?

A.AWS Application Migration Service (AWS MGN)
B.AWS Database Migration Service (AWS DMS)
C.AWS Migration Hub
D.AWS Application Discovery Service
AnswerD

AWS Application Discovery Service performs agentless or agent-based discovery of on-premises servers. It collects configuration, usage, and performance data, and it can map network dependencies. This data feeds into migration planning, allowing the team to right-size instances based on actual utilization and to form migration groups based on dependencies, directly addressing the requirements.

Why this answer

AWS Application Discovery Service is purpose-built to discover on-premises servers and collect utilization and dependency data. This information is essential for right-sizing instances and forming migration groups. The other services either perform replication, track migration progress, or migrate databases, but none provide the comprehensive discovery and assessment capabilities required for this migration planning phase.

Exam trap

The trap here is assuming that AWS Application Migration Service (MGN) also handles discovery and assessment; in reality, it is a replication tool that assumes you already have a migration plan.

974
MCQhard

A company is migrating a critical application from on-premises to AWS using a lift-and-shift approach. The application requires consistent low-latency access to an on-premises database. Which network solution should the company implement to meet the latency requirement during the migration?

A.Set up a site-to-site VPN over the internet.
B.Create a VPC peering connection between the on-premises network and AWS VPC.
C.Use AWS Client VPN to connect from the application servers.
D.Establish an AWS Direct Connect connection between the on-premises data center and AWS.
AnswerD

AWS Direct Connect provides a dedicated, private fibre connection from the data centre to AWS, giving consistent low latency and jitter rather than the variable paths of internet-based VPN. This satisfies the stem's requirement for consistent low-latency access to the on-premises database during migration.

Why this answer

AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, offering consistent low latency and high bandwidth compared to internet-based connections. For a lift-and-shift application requiring consistent low-latency access to an on-premises database, Direct Connect is the appropriate solution.

Exam trap

SAP-C02 often tests the difference between VPN (internet-based, variable latency) and Direct Connect (dedicated, consistent latency); candidates may choose VPN for cost savings but miss the 'consistent low-latency' requirement.

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN traverses the public internet, which introduces variable latency and is not suitable for consistent low-latency requirements. Option B is wrong because VPC peering connects two VPCs within AWS; it cannot connect an on-premises network to a VPC. Option C is wrong because AWS Client VPN is designed for remote user access, not for server-to-server or application-to-database connectivity, and it also uses the internet.

975
MCQeasy

A company uses AWS CloudFormation to deploy infrastructure. A recent change to a stack failed because an IAM role name already exists. The company wants to avoid this issue in the future. What should a solutions architect do?

A.Enable termination protection on the stack.
B.Use a DeletionPolicy of Retain on the IAM role resource.
C.Create a custom resource with an AWS Lambda function to generate a random role name.
D.Use the Fn::Sub function with a reference to the AWS::StackName in the IAM role name.
AnswerD

This ensures unique role names across stacks.

Why this answer

Using `Fn::Sub` with a reference to `AWS::StackName` (e.g., `${AWS::StackName}-role`) makes the IAM role name unique per stack, preventing collisions when multiple stacks are deployed in the same account. This is the standard CloudFormation pattern for avoiding hardcoded name conflicts and enabling repeatable deployments.

Exam trap

The trap is picking a 'clever' solution (custom resource with Lambda) when a built-in CloudFormation feature (`Fn::Sub` + `AWS::StackName`) solves the problem more simply — candidates who don't know pseudo-parameters may over-engineer.

How to eliminate wrong answers

Option A is wrong because termination protection only prevents accidental stack deletion; it does nothing to resolve name collisions during updates or parallel deployments. Option B is wrong because a DeletionPolicy of Retain keeps the IAM role after stack deletion, which actually worsens the problem — the orphaned role's name remains reserved and blocks future stacks from creating a role with the same name. Option C is wrong because a custom resource with Lambda to generate random names adds unnecessary complexity, cost, and operational overhead; CloudFormation's built-in pseudo-parameter `AWS::StackName` already provides uniqueness without custom code.

Page 12

Page 13 of 14

Page 14