Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 76–150

984 questions total · 14pages · All types, answers revealed

Page 1

Page 2 of 14

Page 3
76
MCQhard

Refer to the exhibit. A company has an S3 bucket policy that allows GetObject access from two IP ranges (10.0.0.0/16 and 192.168.0.0/16). The policy also denies all S3 actions on the 'confidential/' prefix unless the request comes from the 10.0.0.0/16 range. Which of the following statements is true?

A.Users from 192.168.0.0/16 can access objects in the confidential/ prefix.
B.Users from 10.0.0.0/16 can access objects in the confidential/ prefix, but users from 192.168.0.0/16 cannot.
C.Users from 10.0.0.0/16 cannot access objects in the confidential/ prefix.
D.The policy has no effect because the Allow and Deny statements cancel each other.
AnswerB

The bucket policy's explicit Deny on the confidential/ prefix applies only to requests outside 10.0.0.0/16, so 192.168.0.0/16 users are blocked there despite their Allow. The 10.0.0.0/16 range satisfies the Deny's condition, so its GetObject requests on that prefix succeed.

Why this answer

The S3 bucket policy includes an explicit Deny statement that blocks all S3 actions on the 'confidential/' prefix unless the request originates from the 10.0.0.0/16 IP range. Since explicit Deny statements override any Allow statements in AWS IAM policy evaluation, users from 192.168.0.0/16 are denied access to the 'confidential/' prefix even though the GetObject Allow statement includes that range. Only users from 10.0.0.0/16 satisfy the condition in the Deny statement and can therefore access objects in the 'confidential/' prefix.

Exam trap

The trap here is that candidates often assume an Allow statement for a broader set of IPs will grant access to all prefixes, overlooking that an explicit Deny with a condition can carve out exceptions, and that AWS evaluates Deny statements before Allow statements.

How to eliminate wrong answers

Option A is wrong because the explicit Deny statement on the 'confidential/' prefix blocks all requests not coming from 10.0.0.0/16, so users from 192.168.0.0/16 are denied access. Option B is correct as explained. Option C is wrong because the Deny statement specifically allows requests from 10.0.0.0/16, so users from that range can access the 'confidential/' prefix.

Option D is wrong because the Allow and Deny statements do not cancel each other; AWS IAM policy evaluation uses an explicit Deny override, so the Deny statement takes precedence over the Allow statement for requests from 192.168.0.0/16, while the Allow statement still applies to other objects.

77
MCQeasy

A company is modernizing a monolithic application into microservices on Amazon ECS. They want to decouple services and improve resilience. Which AWS service should they use for asynchronous communication between microservices?

A.Amazon SQS
B.Amazon Kinesis Data Streams
C.Amazon API Gateway
D.Amazon SNS
AnswerA

Amazon SQS provides fully managed, durable queues that decouple producers from consumers, letting microservices communicate asynchronously without waiting on each other. This directly satisfies the resilience requirement: if a consumer fails or scales slowly, messages persist in the queue rather than being lost, absorbing traffic spikes.

Why this answer

Amazon SQS provides a fully managed message queue for asynchronous communication, decoupling services. Option B (Amazon Kinesis Data Streams) is for streaming data. Option C (Amazon API Gateway) is for synchronous REST APIs.

Option D (Amazon SNS) is pub/sub, not point-to-point queue.

78
MCQeasy

A company uses AWS CloudFormation to manage infrastructure. They want to detect drift from the intended template configuration. Which service should they use?

A.AWS Config
B.AWS Service Catalog
C.AWS CloudTrail
D.CloudFormation Drift Detection
AnswerD

Drift detection compares each stack's actual resource configurations against the expected template values, reporting per-resource differences. This directly satisfies the requirement to detect deviation from the intended template configuration, without rebuilding or redeploying the stack.

Why this answer

CloudFormation Drift Detection compares the actual configuration of stack resources against the expected template configuration and reports resources that have been modified outside of CloudFormation. It is the native feature designed specifically to detect drift for CloudFormation-managed resources. AWS Config can detect configuration changes but is not tied to the template's intended state in the same way.

Exam trap

SAP-C02 often tests the confusion between AWS Config (compliance/configuration history) and CloudFormation Drift Detection (template-vs-actual comparison) — candidates must pick the service purpose-built for template drift.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and evaluates compliance against Config rules, but it does not compare against the CloudFormation template's declared state — it lacks template-aware drift semantics. Option B is wrong because AWS Service Catalog is for governing and provisioning approved products, not for detecting drift. Option C is wrong because AWS CloudTrail logs API activity (who did what), not the current configuration state versus template.

79
MCQhard

A company is designing a new application that must be highly available across multiple AWS Regions. The application will run on EC2 instances behind an Application Load Balancer. The company needs a DNS-based routing policy that routes users to the nearest healthy endpoint based on latency. Which Amazon Route 53 routing policy should be used?

A.Latency routing policy
B.Failover routing policy
C.Weighted routing policy
D.Simple routing policy
AnswerA

Latency routing returns the record for the region with the lowest measured latency between the resolver and the endpoint, and health checks remove unhealthy endpoints. This directly satisfies the nearest healthy endpoint by latency requirement across Regions.

Why this answer

Latency routing policy is correct because it directs traffic to the AWS Region that provides the lowest latency for the end user, based on historical latency data between the user's DNS resolver and the AWS endpoints. This meets the requirement for a DNS-based routing policy that routes users to the nearest healthy endpoint based on latency, while also supporting health checks to ensure traffic is only sent to healthy targets.

Exam trap

The trap here is that candidates often confuse 'latency-based routing' with 'geolocation routing' or 'geoproximity routing,' but the question explicitly asks for routing based on latency, not geographic location or proximity.

How to eliminate wrong answers

Option B (Failover routing policy) is wrong because it is designed for active-passive failover between two endpoints, not for routing based on latency or proximity. Option C (Weighted routing policy) is wrong because it distributes traffic based on assigned weights, not on the user's latency or geographic location. Option D (Simple routing policy) is wrong because it routes all traffic to a single endpoint (or multiple endpoints in a round-robin fashion if multiple records are returned) and does not consider latency, health, or proximity.

80
MCQmedium

A company is migrating a batch processing workload to AWS. The workload runs on a schedule and processes large files stored on a network file system. The company wants to use a serverless architecture to reduce costs. Which combination of AWS services should the company use?

A.AWS Step Functions, Amazon EMR, and Amazon EFS.
B.Amazon CloudWatch Events, AWS Lambda, and Amazon Kinesis Data Firehose.
C.AWS Step Functions, AWS Lambda, and Amazon S3.
D.Amazon CloudWatch Events, Amazon EC2, and Amazon EBS.
AnswerC

Step Functions orchestrates the scheduled workflow, Lambda runs the processing logic serverlessly, and Amazon S3 stores the large input and output files. This combination removes server management and scales automatically, meeting the serverless and cost-reduction constraints.

Why this answer

AWS Step Functions can orchestrate the workflow, AWS Lambda can process files in a serverless manner, and Amazon S3 can store the large files. Option A is wrong because Amazon EMR is not a serverless service and EFS is a network file system, not ideal for serverless batch processing. Option B is wrong because Amazon Kinesis Data Firehose is designed for streaming data, not batch processing of large files.

Option D is wrong because Amazon EC2 and EBS are not serverless.

81
MCQhard

A company is designing a global application that requires a highly available and low-latency API. The API will be consumed by clients across the world. The backend consists of an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances in a single AWS Region. The company wants to improve performance for global users. Which solution meets these requirements with minimal operational overhead?

A.Deploy the application in multiple Regions and use Amazon Route 53 latency-based routing with active-passive failover.
B.Create an Amazon CloudFront distribution with Lambda@Edge to proxy requests to the ALB.
C.Create an AWS Global Accelerator accelerator with the ALB as an endpoint.
D.Create an Amazon CloudFront distribution with the ALB as the origin.
AnswerC

AWS Global Accelerator routes client traffic over the AWS global network to the nearest edge location, then to the ALB endpoint, reducing latency for worldwide users. It requires no application changes and minimal operational overhead compared with multi-Region replication.

Why this answer

AWS Global Accelerator uses the AWS global network to route user traffic to the optimal endpoint, reducing latency and improving availability. By using the ALB as an endpoint, it provides static anycast IP addresses and automatically reroutes traffic if the ALB becomes unhealthy, all with minimal operational overhead since it requires no changes to the application or additional infrastructure.

Exam trap

The trap here is that candidates often confuse CloudFront (a CDN optimized for cacheable content) with Global Accelerator (a network layer service for improving performance of non-cacheable, dynamic traffic), leading them to choose Option D without realizing that CloudFront adds latency for uncacheable API requests.

How to eliminate wrong answers

Option A is wrong because deploying in multiple Regions and using Route 53 latency-based routing with active-passive failover introduces significant operational overhead for managing multi-Region infrastructure, and Route 53 DNS-based routing can be affected by client-side DNS caching, which may not provide the lowest latency for all users. Option B is wrong because Lambda@Edge is designed for lightweight compute at edge locations, not for proxying requests to an ALB; it would add unnecessary complexity, latency, and cost, and it is not a recommended pattern for simply routing traffic to an ALB. Option D is wrong because a CloudFront distribution with the ALB as the origin does not inherently optimize the network path from the client to the ALB; CloudFront caches content at edge locations, but for dynamic API traffic that cannot be cached, it adds an extra hop and does not improve the latency of the connection to the origin ALB.

82
MCQmedium

A company wants to migrate its on-premises Active Directory to AWS Managed Microsoft AD to support Windows-based workloads on AWS. The company has a complex Active Directory structure with multiple domains, group policies, and trusts with external directories. Which migration approach should the company use?

A.Replace Active Directory with AWS Identity and Access Management (IAM) for all authentication
B.Establish a forest trust between the on-premises AD and AWS Managed Microsoft AD, then gradually move resources to AWS
C.Rebuild the entire Active Directory structure from scratch in AWS Managed Microsoft AD
D.Use AD Connector to proxy authentication requests from AWS to the on-premises AD
AnswerB

Correct. A trust allows seamless coexistence and incremental migration.

Why this answer

Setting up a trust between the on-premises AD and AWS Managed Microsoft AD allows gradual migration of resources. This maintains existing authentication and group policies during the transition. Replacing AD with IAM is not suitable for Windows workloads.

Replicating the entire AD structure via AD Connector is not possible. A full rebuild is complex and risky.

83
MCQhard

A healthcare company operates a multi-account AWS environment with a shared services VPC in a central account. Workload accounts need to access a centralized Amazon RDS for MySQL database in the shared services VPC. The security team requires that all database traffic be encrypted in transit and that no workload account can access the database directly from the internet. They also want to minimize administrative overhead. Which solution meets these requirements?

A.Use AWS PrivateLink to create an interface VPC endpoint for RDS in each workload VPC, and enforce SSL/TLS on the RDS instance.
B.Deploy an Application Load Balancer in the shared services VPC, register the RDS instance as a target, and have workload accounts connect through the ALB using SSL/TLS.
C.Create a VPC peering connection between each workload VPC and the shared services VPC, and configure the RDS instance to require SSL/TLS connections.
D.Set up an AWS Transit Gateway with a central attachment in the shared services VPC, attach all workload VPCs, and configure the RDS security group to allow traffic only from the workload CIDR ranges over SSL/TLS.
AnswerD

AWS Transit Gateway provides a hub-and-spoke model that scales to many VPCs and accounts, centralizing connectivity and reducing administrative overhead. By attaching workload VPCs to the transit gateway and routing to the shared services VPC, traffic stays private. Enforcing SSL/TLS on the RDS instance and restricting the security group to workload CIDRs ensures encryption in transit and no internet exposure.

Why this answer

AWS Transit Gateway provides a scalable, centralized hub for connecting many VPCs across accounts, which minimizes administrative overhead compared to a mesh of VPC peering connections. By routing traffic through the transit gateway to the shared services VPC, workload accounts can access the RDS instance privately. Enforcing SSL/TLS on the RDS instance and restricting the security group to workload CIDRs ensures encryption in transit and prevents internet access.

Exam trap

The trap here is assuming that AWS PrivateLink can be used for Amazon RDS, but RDS is not a supported endpoint service for interface VPC endpoints.

84
MCQmedium

A company is designing a new serverless application that processes files uploaded to Amazon S3. The processing involves multiple steps, each implemented as a separate AWS Lambda function. The company needs to coordinate these steps, handle retries, and maintain a visual workflow. The solution must be highly available and scalable. Which service should be used to orchestrate the workflow?

A.Amazon Simple Notification Service (SNS) with Lambda subscriptions
B.AWS Step Functions
C.AWS Lambda with recursive invocations and dead-letter queues
D.Amazon EventBridge with rules to trigger Lambda functions
AnswerB

AWS Step Functions is a serverless orchestration service that allows you to coordinate multiple Lambda functions into a state machine. It provides built-in retry and error handling, and a visual console to monitor workflows. It scales automatically and is highly available, making it ideal for this multi-step serverless application.

Why this answer

AWS Step Functions is designed for orchestrating multi-step serverless workflows. It provides state management, built-in retries, error handling, and a visual interface, all while scaling automatically. Other options are messaging or event services that lack orchestration features, or manual approaches that are not robust.

Exam trap

The trap here is confusing event routing with workflow orchestration; EventBridge and SNS can trigger functions but do not maintain state or sequence.

85
MCQhard

A company has a multi-account AWS environment. The security team wants to centrally manage VPC flow logs for all accounts. They already have a centralized logging account. What is the MOST scalable solution?

A.Deploy a third-party log collector agent on each EC2 instance.
B.Configure AWS Transit Gateway to aggregate flow logs.
C.Use a CloudFormation StackSet to deploy VPC Flow Logs to an S3 bucket in the central account using bucket policies.
D.Enable VPC Flow Logs in each account and publish to a CloudWatch Logs group in the central account.
AnswerC

StackSets deploy the flow-log configuration across every account and region from one template, while the central bucket policy authorises each account's log-delivery principal. This satisfies the scalability constraint by avoiding per-account manual setup as the organisation grows.

Why this answer

Using a CloudFormation StackSet allows you to deploy VPC Flow Logs consistently across multiple accounts and regions, publishing them to a centralized S3 bucket in the logging account. Bucket policies grant cross-account write access, making this approach highly scalable without per-account agent management or CloudWatch Logs cross-account limitations.

Exam trap

The trap here is that candidates may think CloudWatch Logs can natively publish to a cross-account log group, but it cannot; S3 with bucket policies is the correct scalable approach for multi-account VPC Flow Logs.

How to eliminate wrong answers

Option A is wrong because deploying a third-party log collector agent on each EC2 instance is not scalable, introduces agent management overhead, and does not capture VPC-level network traffic (only instance-level). Option B is wrong because AWS Transit Gateway does not aggregate or generate flow logs; it is a network transit hub, not a logging service. Option D is wrong because CloudWatch Logs does not support publishing directly to a cross-account log group; you would need to use a subscription filter or a separate solution, and this approach does not scale as well as S3-based centralized storage.

86
MCQhard

A company is migrating a data warehouse from on-premises to Amazon Redshift. The current workload runs complex queries that join large tables. The company wants to optimize query performance after migration. Which design should the company implement?

A.Use distribution style AUTO and let Redshift decide
B.Use distribution style EVEN on all tables
C.Use distribution style ALL on all large tables
D.Use distribution style KEY on the join columns of large tables
AnswerD

KEY distribution co-locates matching join-column values on the same slice, so large-table joins execute locally without network redistribution. This directly targets the stem's complex joins across large tables, the dominant cost in Redshift query performance.

Why this answer

Distribution style KEY on join columns ensures data is co-located, minimizing data movement. Option A (AUTO) may not use the optimal distribution strategy. Option B (EVEN) distributes rows evenly, which can cause significant data movement across nodes.

Option C (ALL) is not suitable for large tables because it duplicates the entire table on every node, leading to high storage and performance issues.

87
MCQmedium

A company runs a batch processing application on AWS. The application reads input files from an S3 bucket, processes them on EC2 instances, and writes results to another S3 bucket. The processing job runs once a day and takes approximately 3 hours. The company wants to reduce costs and operational overhead. The Solutions Architect suggests using AWS Lambda for processing, but the processing time per file can exceed the Lambda maximum execution time of 15 minutes. The architect also considers using AWS Batch. The company wants to minimize the need for infrastructure management. Which solution should the Solutions Architect recommend?

A.Provision a fleet of EC2 instances and use Auto Scaling to manage the processing.
B.Use AWS Lambda with a larger memory allocation to increase CPU and reduce processing time.
C.Use AWS Batch with a managed compute environment that uses Spot Instances and a job queue.
D.Use Amazon ECS with Fargate launch type and run the processing as a task.
AnswerC

AWS Batch with a managed compute environment removes server infrastructure management, satisfying the minimal-overhead constraint, while Spot Instances cut cost for the 3-hour daily batch. It also lifts the 15-minute Lambda execution ceiling that blocked per-file processing.

Why this answer

AWS Batch with a managed compute environment using Spot Instances and a job queue is the best fit: it handles job scheduling, provisioning, and scaling automatically, eliminating infrastructure management, while Spot Instances reduce cost for the daily 3-hour batch job. It supports long-running jobs that exceed Lambda's 15-minute limit and is purpose-built for batch workloads. This satisfies both the cost-reduction and operational-overhead-minimization requirements.

Exam trap

SAP-C02 often tests the Lambda 15-minute limit versus long-running batch workloads, and candidates may pick Lambda with more memory or ECS/Fargate without recognizing that AWS Batch is the managed service designed for queue-based, long-running, cost-optimized batch processing.

How to eliminate wrong answers

Option A is wrong because provisioning and auto-scaling a fleet of EC2 instances requires significant infrastructure management and does not provide batch job scheduling or Spot integration out of the box. Option B is wrong because increasing Lambda memory does not overcome the hard 15-minute execution limit, so files that take longer will still fail. Option D is wrong because ECS with Fargate runs containers but lacks native batch job queuing, dependency management, and Spot Instance cost optimization that AWS Batch provides for batch workloads.

88
MCQmedium

A company has 200 AWS accounts in AWS Organizations. The compliance team needs to prove that all Amazon S3 buckets across every account have server-side encryption enabled and block public access, and they want a single dashboard showing compliance status. Which solution should they implement?

A.Enable AWS Config in each account with an aggregator in the compliance account and deploy managed rules for S3 encryption and public access using AWS CloudFormation StackSets.
B.Use Amazon Macie in the compliance account to inventory all S3 buckets across the organization and report encryption status.
C.Create an AWS Lambda function in each account that calls the S3 API and writes results to a central Amazon DynamoDB table.
D.Enable AWS Trusted Advisor in the management account and review the S3 bucket permissions checks for all accounts.
AnswerA

AWS Config aggregators collect configuration and compliance data from multiple accounts and Regions into one view. Deploying the managed rules with StackSets ensures consistent evaluation across all 200 accounts, giving the compliance team a centralized dashboard that reflects each bucket's encryption and public access state.

Why this answer

AWS Config aggregators consolidate configuration and compliance data from all accounts and Regions into an administrator account, and managed rules can evaluate S3 encryption and public access settings. Using CloudFormation StackSets to deploy the rules ensures uniform coverage across 200 accounts, and the aggregator supplies the single compliance dashboard the team needs.

Exam trap

The trap here is substituting a data-classification service such as Amazon Macie, or a custom Lambda pipeline, for the configuration compliance capability that AWS Config aggregators provide.

89
MCQmedium

A company has a multi-account AWS environment with AWS Organizations. They use AWS IAM Identity Center (successor to AWS Single Sign-On) for workforce access. The security team wants to ensure that all federated users from the corporate identity provider (IdP) are automatically assigned to the appropriate permission sets based on their group membership in the IdP. The company uses SAML 2.0 federation with IAM Identity Center. Which configuration should the solutions architect implement to achieve automatic group-based permission set assignments?

A.Configure IAM Identity Center to use an external identity provider only for authentication, and use AWS Lambda functions triggered by IdP events to call the IAM Identity Center API to assign permission sets.
B.Configure SCIM synchronization between the IdP and IAM Identity Center, and map IdP groups to IAM Identity Center groups. Then assign permission sets to those groups.
C.Use SAML attribute mappings in IAM Identity Center to pass group names as session tags, and create IAM roles with trust policies that conditionally allow access based on those tags.
D.Manually create IAM Identity Center groups that match the IdP group names, and assign permission sets to those groups. Update memberships manually when IdP groups change.
AnswerB

SCIM (System for Cross-domain Identity Management) automatically synchronizes users and groups from the IdP to IAM Identity Center. Once groups are synchronized, you can assign permission sets to those groups, and users inherit access based on group membership. This provides automatic provisioning and deprovisioning, meeting the requirement with minimal manual effort.

Why this answer

SCIM synchronization automatically provisions users and groups from the corporate IdP into IAM Identity Center. By mapping IdP groups to IAM Identity Center groups and assigning permission sets to those groups, users receive the correct permissions based on their group membership without manual intervention.

Exam trap

The trap here is assuming that SAML attribute mappings alone can drive permission set assignments, when in fact SCIM is required for automatic group synchronization and assignment.

90
MCQeasy

A company uses AWS CodePipeline to deploy a web application. They want to automatically roll back the deployment if the new version fails CloudWatch alarm-based health checks. Which feature should they use?

A.AWS Lambda function invoked by CloudWatch Events.
B.Amazon Route 53 health checks with failover routing.
C.AWS CodeBuild with post-build actions.
D.CodeDeploy automatic rollback configuration with CloudWatch alarm.
AnswerD

CodeDeploy automatic rollback redeploys the last known-good revision when a specified CloudWatch alarm enters ALARM state during deployment. This directly satisfies the requirement to roll back automatically on failed alarm-based health checks, without manual intervention or custom pipeline logic.

Why this answer

AWS CodeDeploy natively supports automatic rollback triggered by CloudWatch alarms. When a deployment causes a CloudWatch alarm to enter an ALARM state, CodeDeploy can automatically revert to the previous working version. This is the most straightforward and integrated solution for the requirement.

Option A (Lambda + CloudWatch Events) is possible but not the primary recommended feature. Option B (Route 53 health checks) is for DNS-level failover, not deployment rollback. Option C (CodeBuild post-build actions) is for build phase, not post-deployment monitoring.

91
MCQeasy

A company is designing a new web application that will serve static content (HTML, CSS, JS, images) to users globally. The application must have low latency and high availability. Content changes infrequently, but when updated, the changes must be reflected immediately. Which solution should the architect recommend?

A.Store content in an S3 bucket and use Amazon CloudFront with S3 as origin
B.Store content on an EC2 instance behind an Application Load Balancer and use CloudFront
C.Store content in Amazon ElastiCache for Redis and use CloudFront
D.Store content in an S3 bucket and use S3 Transfer Acceleration
AnswerA

CloudFront caches static assets at edge locations, delivering the low global latency the stem requires, while S3 provides durable, highly available origin storage. Invalidating or versioning objects on update ensures changes appear immediately, satisfying the freshness constraint.

Why this answer

Amazon CloudFront, with an S3 bucket as the origin, provides a global content delivery network (CDN) that caches static content at edge locations, significantly reducing latency for users worldwide. S3 offers durable, highly available storage, and CloudFront’s cache invalidation or versioned object updates allow changes to be reflected immediately when content is updated. This combination meets the requirements for low latency, high availability, and immediate content refresh.

Exam trap

The trap here is that candidates may over-engineer the solution by choosing EC2 or ElastiCache, mistakenly thinking they need compute or caching layers for static content, when S3 + CloudFront is the simplest, most cost-effective, and fully managed solution for global static content delivery.

How to eliminate wrong answers

Option B is wrong because storing static content on an EC2 instance behind an Application Load Balancer introduces unnecessary compute overhead, management complexity, and higher cost without any benefit for static content; EC2 is designed for dynamic processing, not serving static assets efficiently at global scale. Option C is wrong because Amazon ElastiCache for Redis is an in-memory cache designed for transient, high-speed data (e.g., session state, database query results), not for durable, long-term storage of static content; it lacks the persistence and origin-pull capabilities needed for a CDN origin. Option D is wrong because S3 Transfer Acceleration only speeds up uploads to an S3 bucket over long distances using AWS edge locations, but it does not cache content at edge locations for low-latency downloads; it does not provide global content distribution or high availability for serving static content to users.

92
Multi-Selectmedium

A company wants to implement AWS Organizations with multiple OUs to isolate development, testing, and production workloads. The company needs to ensure that production workloads are not impacted by changes in other OUs. Which TWO practices should the company follow? (Choose two.)

Select 2 answers
A.Allow all users to assume cross-account roles for easier management.
B.Share the same VPC across all OUs to simplify networking.
C.Use separate AWS accounts for each environment to provide strong isolation.
D.Use resource tagging to isolate environments instead of accounts.
E.Apply separate SCPs to each OU to enforce different security policies.
AnswersC, E

Separate AWS accounts create hard security and blast-radius boundaries: IAM, quotas, and service limits are per-account, so a misconfiguration or quota exhaustion in development cannot affect production. This satisfies the stem's requirement that production workloads remain unaffected by changes in other OUs.

Why this answer

Option C is correct because using separate AWS accounts for each environment (development, testing, production) provides the strongest isolation boundary in AWS Organizations, since accounts are the primary security and billing boundary and prevent changes in one environment from affecting another. Option E is correct because Service Control Policies (SCPs) applied at the OU level let the company enforce distinct permission guardrails per OU, ensuring that actions allowed in development or testing OUs cannot be applied to production accounts. Options A and B are incorrect because sharing cross-account role assumptions broadly or sharing a single VPC across all OUs weakens isolation and increases the blast radius of misconfigurations.

Option D is incorrect because resource tagging is only a labeling and governance mechanism, not a security boundary, so it cannot provide the strong isolation that separate accounts and SCPs deliver.

Exam trap

The trap here is that candidates often confuse logical isolation (like tagging or VPC sharing) with the strong, account-level isolation required for production workloads, and may overlook that SCPs are the correct mechanism to enforce different security policies per OU.

93
Multi-Selecthard

A healthcare company is migrating a legacy patient-records application to AWS. The application runs on two on-premises servers behind a hardware load balancer and uses a shared file system for documents. The company needs a migration plan that provides high availability across two Availability Zones, minimizes changes to the application, and keeps the document store accessible from both servers with POSIX permissions. (Choose two.)

Select 2 answers
A.Attach an Amazon EBS Multi-Attach io2 volume to both EC2 instances and format it with a clustered file system that the application already supports.
B.Replace the shared file system with an Amazon S3 bucket and rewrite the application to use the AWS SDK for Java to read and write documents.
C.Deploy the application servers on Amazon EC2 instances in two Availability Zones behind an Application Load Balancer, and use an Auto Scaling group to maintain capacity.
D.Use AWS Storage Gateway file gateway to expose an SMB share to the EC2 instances in both Availability Zones.
E.Mount an Amazon EFS file system to both EC2 instances, and configure the mount targets in each Availability Zone used by the application.
AnswersC, E

Running EC2 instances across two Availability Zones behind an Application Load Balancer removes the single hardware load balancer and provides high availability. An Auto Scaling group replaces failed instances automatically, which minimizes operational changes while satisfying the multi-AZ requirement for the compute tier.

Why this answer

High availability for the compute tier is achieved by placing EC2 instances in two Availability Zones behind an Application Load Balancer with an Auto Scaling group. For the shared document store, Amazon EFS provides POSIX-compliant shared access across Availability Zones through mount targets, so the application keeps its existing file-based access pattern with minimal changes.

Exam trap

The trap here is treating Amazon EBS Multi-Attach as a multi-AZ shared storage solution, when it is limited to a single Availability Zone and requires cluster-aware file systems.

94
Multi-Selectmedium

A company is building a serverless data processing pipeline using AWS Lambda, Amazon DynamoDB, and Amazon S3. The pipeline processes JSON files uploaded to an S3 bucket, transforms the data, and writes results to DynamoDB. The company wants to ensure the pipeline can handle bursts of traffic without data loss. Which TWO design decisions should the solutions architect make?

Select 2 answers
A.Configure DynamoDB with on-demand capacity mode.
B.Use an Amazon SQS queue to buffer events from S3 before processing by Lambda.
C.Increase the Lambda function timeout to 15 minutes.
D.Use DynamoDB Streams to capture changes and process in batches.
E.Enable S3 Transfer Acceleration on the bucket.
AnswersA, B

On-demand capacity mode absorbs unpredictable bursts by instantly scaling to workload demand, so DynamoDB throttling cannot drop writes during traffic spikes. This directly satisfies the stem's requirement to handle bursts without data loss, unlike provisioned mode, which needs pre-set capacity and auto scaling that reacts too slowly.

Why this answer

Option A is correct because DynamoDB on-demand capacity mode automatically scales read/write throughput to absorb unpredictable bursts of traffic without provisioning or throttling, which directly prevents data loss when the Lambda pipeline writes results at variable rates. Option B is correct because inserting an Amazon SQS queue between S3 event notifications and Lambda decouples ingestion from processing, buffering burst events durably (up to 14 days) so Lambda can poll and scale consumers without dropping events. Option C is not appropriate because raising the Lambda timeout to 15 minutes only extends execution time and does nothing to buffer bursts or prevent data loss.

Option D is not appropriate because DynamoDB Streams captures item-level changes after they occur and is used for downstream reactions, not for buffering incoming S3 events. Option E is not appropriate because S3 Transfer Acceleration only speeds up uploads to S3 via edge locations and does not address burst handling or data durability in the processing pipeline.

Exam trap

The trap here is that candidates may confuse DynamoDB Streams with a buffering mechanism for incoming writes, when in fact streams only capture post-write changes and do not prevent data loss from S3 event delivery failures.

95
MCQhard

A company is migrating a legacy on-premises application to AWS. The application runs on a physical server and uses a locally attached tape library for nightly backups. The company wants to eliminate tape management and store backups in Amazon S3. The backup software supports the iSCSI protocol. Which solution should a solutions architect recommend?

A.Use AWS DataSync to replicate the backup server's local disk to Amazon S3.
B.Deploy an AWS Storage Gateway tape gateway and configure the backup software to use the virtual tape library.
C.Deploy an AWS Storage Gateway file gateway and mount it as an NFS share on the backup server.
D.Deploy an AWS Storage Gateway volume gateway in stored mode and present it as an iSCSI target to the backup server.
AnswerB

Tape gateway presents a virtual tape library (VTL) over iSCSI to existing backup software. It stores virtual tapes in Amazon S3 and can archive them to Amazon S3 Glacier or Deep Archive. This eliminates physical tape management while preserving the backup workflow, matching the requirement exactly.

Why this answer

AWS Storage Gateway tape gateway provides a virtual tape library that integrates with existing backup software over iSCSI. Virtual tapes are stored in Amazon S3 and can be archived to Amazon S3 Glacier or Deep Archive, eliminating physical tape handling while preserving the backup application's workflow. Other gateway types or DataSync do not provide a tape interface.

Exam trap

The trap here is assuming that any Storage Gateway mode can replace tape, when only tape gateway presents a virtual tape library to backup software.

96
MCQmedium

A retail company is migrating its on-premises data center to AWS. They have many applications with complex interdependencies. The company wants to group servers into migration waves based on network dependencies to minimize disruption. Which AWS tool should they use to discover these dependencies?

A.AWS Application Discovery Service
B.AWS Trusted Advisor
C.AWS Migration Hub
D.AWS Systems Manager
AnswerA

AWS Application Discovery Service collects data about on-premises servers, including network dependencies and process connections. It provides a dependency map that helps group servers into migration waves. This directly addresses the need to understand interdependencies and plan waves, making it the correct tool for this scenario.

Why this answer

AWS Application Discovery Service is the tool designed to discover on-premises servers and their network dependencies. It collects data that can be used to group servers into migration waves, ensuring that interdependent applications are migrated together. This minimizes disruption and aligns with the company's goal.

Exam trap

The trap here is confusing AWS Migration Hub with Application Discovery Service; Migration Hub tracks migrations, but Discovery Service does the actual discovery of dependencies.

97
MCQmedium

A company is designing a new web application that will run on Amazon EC2 instances behind an Application Load Balancer. The application must handle millions of requests per day. To reduce latency and offload traffic from the EC2 instances, which AWS service should be placed in front of the load balancer?

A.Amazon CloudFront
B.AWS Global Accelerator
C.AWS Shield Advanced
D.AWS WAF
AnswerA

CloudFront caches content at edge locations worldwide, so repeated requests are served closer to users rather than reaching the load balancer. This reduces latency and offloads origin traffic from the EC2 instances, satisfying the requirement to place a service in front of the ALB.

Why this answer

Amazon CloudFront is a CDN that caches content at edge locations worldwide, reducing latency for end users and offloading a large portion of requests from the origin EC2 instances behind the ALB. Placing CloudFront in front of the ALB is the standard AWS pattern for high-volume web applications needing low latency and origin offload.

Exam trap

SAP-C02 often tests the confusion between CloudFront (caching CDN that offloads origin) and Global Accelerator (network path optimization without caching) — candidates must match 'offload traffic' to CloudFront.

How to eliminate wrong answers

Option B is wrong because AWS Global Accelerator improves latency by routing traffic over the AWS global network to the optimal endpoint, but it does not cache content, so it does not offload traffic from EC2 instances. Option C is wrong because AWS Shield Advanced is a DDoS protection service, not a caching or traffic-offloading layer. Option D is wrong because AWS WAF filters malicious web traffic but does not cache or reduce origin load for legitimate requests.

98
MCQeasy

An organization is modernizing a legacy application by breaking it into microservices on AWS. The application processes customer orders and sends notifications. The team wants to decouple the order processing from the notification service to improve scalability. Which AWS service should they use to asynchronously pass messages between the services?

A.Amazon Kinesis Data Streams
B.Amazon EventBridge
C.Amazon Simple Notification Service (Amazon SNS)
D.Amazon Simple Queue Service (Amazon SQS)
AnswerD

Amazon SQS provides a fully managed queue that decouples producers from consumers, letting the order service enqueue messages while the notification service polls and processes them independently. This asynchronous, pull-based model satisfies the requirement to decouple the services and improve scalability.

Why this answer

Amazon SQS is a fully managed message queue service that enables decoupling of application components. SNS is pub/sub; EventBridge is event bus; Kinesis is for real-time streaming. For simple point-to-point async messaging, SQS is the best fit.

99
MCQhard

A company runs a multi-account AWS environment managed with AWS Organizations. Each account sends VPC Flow Logs, AWS CloudTrail logs, and application logs to a central Amazon S3 bucket in the logging account. The security team needs to query up to 5 years of logs with ad-hoc SQL, correlate events across accounts, and minimize ongoing storage cost for logs older than 90 days. The logs must remain immediately queryable without restoration. Which solution meets these requirements MOST cost-effectively?

A.Deliver all logs to Amazon S3 and query them with Amazon CloudWatch Logs Insights after exporting each account's logs to CloudWatch Logs. Set a 5-year retention policy on the log groups.
B.Deliver all logs to Amazon S3, crawl them with AWS Glue crawlers, and query with Amazon Athena. Transition objects older than 90 days to S3 Glacier Deep Archive.
C.Deliver all logs to Amazon S3, load them nightly into Amazon Redshift Spectrum external tables, and query with Amazon Redshift. Compress older data with columnar storage.
D.Deliver all logs to Amazon S3, register the bucket with AWS Glue Data Catalog, and query with Amazon Athena. Transition objects older than 90 days to S3 Glacier Instant Retrieval using an S3 Lifecycle rule.
AnswerD

Athena queries S3 data in place using the Glue Data Catalog, so no loading or cluster management is needed, and it supports ad-hoc SQL across accounts. S3 Glacier Instant Retrieval keeps archived objects millisecond-retrievable, satisfying the immediate query requirement while cutting storage cost for logs older than 90 days. This combination is the most cost-effective fit for the stated query pattern and retention.

Why this answer

Athena with the AWS Glue Data Catalog queries S3 logs in place using standard SQL, providing ad-hoc, cross-account analysis without managing servers. Moving older objects to S3 Glacier Instant Retrieval reduces storage cost while preserving millisecond retrieval, so historical logs stay immediately queryable. Together these services satisfy the query, retention, and cost requirements more effectively than cluster-based or Deep Archive alternatives.

Exam trap

The trap here is assuming the cheapest archival storage class (Glacier Deep Archive) is always best, overlooking that its multi-hour retrieval latency breaks the immediate-query requirement.

100
MCQmedium

A company is using AWS Organizations and wants to centralize the management of Amazon EC2 instance security groups. The security team needs to enforce that certain ports are not open to the internet across all accounts. The company currently uses AWS Firewall Manager. Which approach should the security team use to enforce this policy?

A.Use AWS Config rules to detect non-compliant security groups and trigger a Lambda function to remediate.
B.Use AWS Firewall Manager to create a security group policy that defines rules, and apply it across all accounts. Firewall Manager will automatically create and manage security groups.
C.Use AWS Firewall Manager to audit security groups against a baseline policy and generate reports.
D.Use an SCP to deny ec2:AuthorizeSecurityGroupIngress for ports that should not be open.
AnswerB

Firewall Manager security group policies define the permitted rules once and enforce them across all accounts in the organisation, automatically creating and remediating security groups. This centrally blocks the specified internet-facing ports, meeting the cross-account enforcement requirement without per-account scripting.

Why this answer

AWS Firewall Manager can centrally create, apply, and manage security group policies across all accounts in an AWS Organization. By defining a security group policy with rules that block specific ports from 0.0.0.0/0, Firewall Manager automatically creates the required security groups and attaches them to the designated resources, ensuring compliance without manual intervention. This approach directly enforces the policy rather than just detecting or reporting violations.

Exam trap

The trap here is that candidates often confuse AWS Firewall Manager's audit-only mode (which generates reports) with its enforcement mode (which automatically creates and manages security groups), leading them to choose the reporting option instead of the correct enforcement option.

How to eliminate wrong answers

Option A is wrong because AWS Config rules with Lambda remediation are reactive—they detect non-compliant resources after creation and then attempt to fix them, which is not a preventive enforcement mechanism and can introduce latency or race conditions. Option C is wrong because auditing and generating reports only provides visibility into non-compliance but does not actively enforce the policy or prevent insecure security groups from being used. Option D is wrong because SCPs cannot deny specific API actions like ec2:AuthorizeSecurityGroupIngress based on port numbers or IP ranges; SCPs operate at the API action level and cannot inspect the parameters of the request, so they cannot block opening a specific port to the internet.

101
MCQhard

A financial services firm is designing a new trade-processing platform on AWS. The platform uses AWS Lambda functions that must access an Amazon RDS for MySQL database in a private subnet. Security policy forbids storing database credentials in environment variables or code. The firm also requires that credentials be automatically rotated every 30 days, and that the rotation be auditable. Which solution meets these requirements with the LEAST operational overhead?

A.Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter. Create a custom Lambda function that rotates the password every 30 days and updates the parameter.
B.Store the database credentials in AWS Secrets Manager. Grant the Lambda execution role secretsmanager:GetSecretValue on the specific secret ARN, and configure automatic rotation with a 30-day schedule using the provided RDS MySQL rotation Lambda function.
C.Store the database credentials in an encrypted Amazon S3 object. Have the Lambda function retrieve and decrypt the object at each invocation using an AWS KMS key, and use an S3 Lifecycle rule to delete and recreate the object every 30 days.
D.Store the database credentials in AWS Secrets Manager. Attach the AWS managed policy SecretsManagerReadWrite to the Lambda execution role, and enable automatic rotation with a 30-day schedule using the provided RDS MySQL rotation Lambda function.
AnswerB

Secrets Manager is purpose-built for storing and rotating database credentials. Automatic rotation with the provided RDS MySQL rotation function updates both the secret and the database password every 30 days. Scoping the execution role to GetSecretValue on the specific secret ARN follows least privilege and keeps the solution auditable via AWS CloudTrail.

Why this answer

AWS Secrets Manager integrates directly with Amazon RDS to rotate database credentials automatically using a managed rotation Lambda function. Configuring a 30-day rotation schedule satisfies the policy, and granting the Lambda execution role only secretsmanager:GetSecretValue on the specific secret ARN follows least privilege. Rotation events are logged in AWS CloudTrail, providing the required auditability.

Exam trap

The trap here is choosing a solution that stores secrets securely but lacks native rotation, such as Parameter Store SecureString, or granting overly broad permissions when using Secrets Manager.

102
Multi-Selectmedium

A company is designing a new application that will use Amazon S3 to store sensitive customer data. The data must be encrypted at rest and in transit. The company also needs to ensure that only authorized users can access the data. Which three steps should the company take? (Choose THREE.)

Select 3 answers
A.Enable S3 default encryption with SSE-KMS.
B.Use client-side encryption with a customer key.
C.Use bucket policies to restrict access based on IAM roles.
D.Configure the bucket policy to deny requests that do not use HTTPS.
E.Make the bucket publicly accessible for ease of access.
AnswersA, C, D

SSE-KMS encrypts objects at rest with customer-managed keys, satisfying the encryption-at-rest requirement while enabling key rotation, audit trails and granular access control through key policies — a stronger posture than SSE-S3 for sensitive customer data.

Why this answer

Option A is correct because enabling S3 default encryption with SSE-KMS ensures all objects are encrypted at rest using AWS KMS-managed keys, satisfying the encryption-at-rest requirement for sensitive customer data. Option C is correct because bucket policies that restrict access based on IAM roles enforce least-privilege authorization, ensuring only authorized users can access the data. Option D is correct because a bucket policy denying requests that do not use HTTPS (aws:SecureTransport false) enforces encryption in transit by rejecting unencrypted HTTP access.

Option B is not required because SSE-KMS already meets the encryption-at-rest requirement, and client-side encryption is an alternative rather than a necessary step. Option E is incorrect because making the bucket publicly accessible would expose sensitive data and violate the requirement that only authorized users can access it.

Exam trap

The trap here is that candidates may confuse client-side encryption (which is not an S3-managed encryption option) with server-side encryption, or they may overlook that public access is never acceptable for sensitive data, even if other controls are in place.

103
MCQmedium

A company has a serverless application that uses AWS Lambda functions. The functions are invoked by Amazon API Gateway and write to an Amazon DynamoDB table. The company wants to improve the existing solution to reduce latency for read-heavy workloads and reduce DynamoDB costs. The application reads the same items repeatedly. Which solution meets these requirements with the LEAST development effort?

A.Enable DynamoDB Accelerator (DAX) for the table and modify the Lambda functions to use the DAX client.
B.Increase the read capacity units (RCUs) of the DynamoDB table to handle the read load.
C.Implement an Amazon ElastiCache for Redis cluster and modify the Lambda functions to cache reads from DynamoDB.
D.Use Amazon DynamoDB global tables to replicate the table to multiple Regions and direct reads to the nearest Region.
AnswerA

DAX is a fully managed, in-memory cache for DynamoDB that provides microsecond latency for read-heavy workloads. By using the DAX client in the Lambda functions, reads are served from the cache, reducing latency and lowering DynamoDB read capacity costs. The development effort is minimal because it only requires changing the DynamoDB client to the DAX client, and DAX is compatible with the existing DynamoDB API. This meets the requirements effectively.

Why this answer

DAX is an in-memory cache specifically designed for DynamoDB, providing microsecond read latency and reducing the need to provision high read capacity. Integrating DAX requires only changing the DynamoDB client in the Lambda functions to the DAX client, which is a minimal code change. This directly addresses the read-heavy workload by caching frequently accessed items, lowering both latency and DynamoDB read costs.

Other options either increase costs, require more development effort, or do not solve the latency and cost issues.

Exam trap

The trap here is assuming that increasing read capacity units reduces latency for repeated reads.

104
MCQmedium

A company has a multi-account AWS environment with a central shared services account. The company wants to provide a self-service portal for developers to request temporary AWS credentials for specific roles in various accounts. The credentials must be generated without creating IAM users and must be auditable. Which solution meets these requirements?

A.Create IAM users in each account and use AWS STS AssumeRole to obtain temporary credentials.
B.Use AWS IAM Identity Center (successor to AWS Single Sign-On) to assign users to permission sets that map to IAM roles in target accounts.
C.Use AWS Cognito user pools to authenticate developers and issue temporary AWS credentials via Cognito identity pools.
D.Deploy a custom portal that uses AWS Lambda to call sts:AssumeRole and returns credentials to the developer.
AnswerB

IAM Identity Center allows centralized management of user access and generates temporary credentials for IAM roles in target accounts without creating IAM users. It provides an audit trail through AWS CloudTrail and integrates with external identity providers, meeting the self-service and auditable requirements.

Why this answer

AWS IAM Identity Center is designed to centrally manage access to multiple AWS accounts and provides temporary credentials for IAM roles without IAM users. It supports self-service via the AWS access portal and logs all access in CloudTrail, meeting the auditable requirement with minimal operational overhead.

Exam trap

The trap here is assuming that Cognito identity pools are suitable for developer access to AWS accounts, when they are primarily for customer-facing applications.

105
MCQeasy

A company is migrating a monolithic application to AWS and wants to adopt a microservices architecture. The application currently runs on a single server and uses a shared MySQL database. Which AWS service can help the company decouple the microservices and enable asynchronous communication?

A.Amazon API Gateway
B.AWS Step Functions
C.Elastic Load Balancing
D.Amazon Simple Queue Service (SQS)
AnswerD

Amazon SQS provides fully managed message queues that decouple microservices by buffering messages, so producers and consumers operate independently without waiting on each other. This directly satisfies the asynchronous communication requirement, unlike synchronous request-response services. It also removes the shared-database coupling by letting services exchange events through durable queues rather than direct calls.

Why this answer

Amazon SQS is a fully managed message queuing service that enables asynchronous communication and decoupling between microservices. By using SQS, the monolithic application can be broken into independent services that communicate via queues, improving scalability and resilience. SQS is specifically designed for decoupling and asynchronous messaging, making it the correct choice.

Exam trap

The trap is selecting API Gateway or Step Functions because they are also used in microservices architectures, but the question specifically asks for asynchronous communication and decoupling, which is the core purpose of SQS.

How to eliminate wrong answers

Option A is wrong because Amazon API Gateway is used for creating, publishing, and managing APIs, providing synchronous request/response communication, not asynchronous decoupling. Option B is wrong because AWS Step Functions is a serverless orchestration service for coordinating multiple AWS services into workflows, but it is not primarily a message queue for decoupling microservices; it is more for stateful workflows. Option C is wrong because Elastic Load Balancing distributes incoming traffic across multiple targets, providing synchronous load balancing, not asynchronous messaging.

106
MCQmedium

A media company stores millions of video files in an Amazon S3 bucket and serves them to viewers worldwide through Amazon CloudFront. The company recently enabled S3 Block Public Access and now viewers receive access-denied errors. The security team insists the bucket must remain private and no long-term credentials may be embedded in the application. Which solution meets these requirements with the LEAST administrative effort?

A.Generate an IAM user with programmatic access and store the access keys in the CloudFront origin configuration
B.Replicate the bucket to a second Region and point the CloudFront origin at the replica bucket with public read access
C.Disable S3 Block Public Access on the bucket and attach a bucket policy granting s3:GetObject to everyone
D.Create an origin access control (OAC) on the distribution and update the bucket policy to allow the CloudFront service principal to read objects
AnswerD

Origin access control lets CloudFront sign requests to S3 using SigV4, so the bucket stays private while only the distribution can retrieve objects. Updating the bucket policy to grant the CloudFront service principal access is the supported, low-effort configuration, and no credentials are stored in the application, satisfying both the security and effort requirements.

Why this answer

Origin access control is the current mechanism for letting a CloudFront distribution read from a private S3 bucket. CloudFront signs origin requests with SigV4, and a bucket policy grants access to the CloudFront service principal, so Block Public Access can remain enabled and no static credentials exist anywhere in the application.

Exam trap

The trap here is assuming that granting public read access or embedding IAM keys is the quick fix for CloudFront origin failures, when the supported private pattern is origin access control with a scoped bucket policy.

107
MCQhard

A company has a monolithic application running on a single EC2 instance. The application experiences performance issues during peak hours. The company decides to migrate to a microservices architecture using AWS Lambda and Amazon API Gateway. The migration must be done incrementally without downtime. What strategy should the company use?

A.Deploy all microservices in a new VPC and cut over DNS after testing.
B.Create a new version of the monolith that calls Lambda functions as backend.
C.Use AWS CodeDeploy to perform a blue/green deployment of the monolith to Lambda.
D.Use the strangler fig pattern: implement API Gateway to route traffic to new Lambda functions for specific endpoints while keeping the monolith for others.
AnswerD

The strangler fig pattern incrementally routes selected endpoints through API Gateway to Lambda while the monolith still serves the rest, allowing gradual migration with no downtime. Traffic shifts endpoint by endpoint until the monolith is fully replaced.

Why this answer

The strangler fig pattern allows incremental migration by routing specific API requests to new Lambda functions via API Gateway while keeping the monolithic application for the rest. This approach avoids downtime. Option A is incorrect because deploying all microservices in a new VPC and cutting over DNS risks downtime and is not incremental.

Option B is incorrect because creating a new version of the monolith that calls Lambda functions still leaves the monolith in place and does not fully utilize API Gateway for routing. Option C is incorrect because CodeDeploy blue/green deployment is for deploying to EC2 or Lambda, but it does not provide a pattern for incremental migration of a monolith to microservices; the strangler fig pattern is more appropriate.

108
MCQmedium

A logistics company is designing a new application that processes shipping manifests. The application runs on Amazon EC2 instances in an Auto Scaling group and must store session state so that users remain logged in if an instance is terminated. The company wants a highly available, low-latency solution with minimal operational overhead. Which solution meets these requirements?

A.Enable sticky sessions on the Application Load Balancer so that each user is always routed to the same EC2 instance, and store session state locally on that instance.
B.Store session state in an Amazon ElastiCache for Redis cluster with Multi-AZ enabled, and configure the application to read and write session data to the cluster.
C.Store session state in an Amazon RDS for MySQL Multi-AZ database, and have the application query the database for each request.
D.Store session state in an Amazon S3 bucket and have the application read and write the session file for each request.
AnswerB

ElastiCache for Redis with Multi-AZ provides automatic failover and high availability. It offers sub-millisecond latency for session reads and writes, and the application can store session state externally so that any EC2 instance can serve the user. This minimizes operational overhead because AWS manages the cluster.

Why this answer

ElastiCache for Redis with Multi-AZ is purpose-built for low-latency data access and provides automatic failover. By externalizing session state, any EC2 instance in the Auto Scaling group can handle requests, so instance termination does not log users out. AWS manages the cluster, keeping operational overhead low while meeting the high-availability and performance requirements.

Exam trap

The trap here is relying on sticky sessions or local instance storage, which fails when an instance is terminated and does not meet the high-availability requirement.

109
MCQmedium

A company wants to centralize access control for multiple AWS accounts using AWS Organizations. They need to allow developers in a specific account to launch EC2 instances only in certain regions. What is the most scalable solution?

A.Create an IAM role in each account with a policy to deny non-compliant regions.
B.Use AWS Config rules to detect and terminate instances in non-compliant regions.
C.Use an SCP attached to the organizational unit to deny EC2 actions in non-compliant regions.
D.Create an IAM policy in each account to deny non-compliant regions.
AnswerC

SCPs set the maximum permissions for every principal in an organisational unit, so one deny on EC2 actions outside approved regions applies automatically to all current and future accounts in that OU. This satisfies the centralised, scalable control requirement without per-account IAM edits.

Why this answer

Service control policies (SCPs) in AWS Organizations allow you to centrally define the maximum permissions for all accounts in an organizational unit (OU). By attaching an SCP that denies EC2 actions in non-compliant regions, you enforce the restriction across multiple accounts without needing to manage individual IAM policies or roles, making it the most scalable solution.

Exam trap

The trap here is that candidates often choose detective solutions like AWS Config (Option B) or per-account IAM policies (Options A and D) because they are familiar, but they miss that SCPs provide a centralized, preventive, and scalable control that applies to all principals, including the root user.

How to eliminate wrong answers

Option A is wrong because creating an IAM role in each account still requires per-account management and does not prevent the root user or other principals from launching instances in non-compliant regions; SCPs apply to all principals including the root user. Option B is wrong because AWS Config rules are detective, not preventive; they can detect and terminate instances after launch, but this is reactive and does not prevent the initial launch, leading to potential cost and security exposure. Option D is wrong because creating an IAM policy in each account requires manual per-account configuration and does not scale; it also cannot restrict the root user, whereas SCPs apply to all principals in the account.

110
MCQhard

A company operates a microservices platform on Amazon EKS. During incidents, engineers manually inspect CloudWatch metrics, logs, and traces to find the root cause, which takes hours. The company wants to reduce mean time to resolution by automating anomaly detection and correlating metrics, logs, and traces across services. Which approach should a solutions architect recommend?

A.Configure AWS Config rules on the EKS cluster and use AWS CloudTrail to record API calls, then query the data with Amazon Athena during incidents.
B.Deploy the AWS Distro for OpenTelemetry to collect metrics and traces, send them to Amazon CloudWatch with embedded metric format, and enable CloudWatch anomaly detection and ServiceLens for correlated analysis.
C.Enable Amazon GuardDuty for EKS and configure findings to trigger AWS Lambda functions that restart unhealthy pods automatically.
D.Install the CloudWatch agent on each node to collect system metrics, and create static CloudWatch alarms with fixed thresholds for CPU and memory on every service.
AnswerB

AWS Distro for OpenTelemetry collects metrics and traces from EKS workloads and forwards them, while CloudWatch embedded metric format ingests high-cardinality metrics cost-effectively. CloudWatch anomaly detection models normal behavior and flags deviations, and ServiceLens correlates metrics, logs, and traces through a service map. Together they automate detection and cross-signal correlation, directly cutting time to resolution.

Why this answer

Reducing time to resolution requires automated anomaly detection plus correlation across metrics, logs, and traces. AWS Distro for OpenTelemetry feeds EKS telemetry into CloudWatch, where embedded metric format keeps high-cardinality data affordable, anomaly detection learns normal baselines, and ServiceLens ties signals together through a service map. Security, audit, or static-threshold tools do not provide this correlated observability.

Exam trap

The trap here is confusing security and audit services such as GuardDuty, AWS Config, and CloudTrail with observability tooling, when only metrics, logs, and traces correlation addresses runtime troubleshooting.

111
MCQmedium

A company is designing a highly available application on AWS that uses an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application requires that the client's IP address be preserved in the application logs. The company also needs to perform SSL termination at the load balancer. How should the company configure the ALB to meet these requirements?

A.Use TCP listener on port 443 and forward to instances on port 80. Enable proxy protocol v2.
B.Use TCP listener on port 443 and forward to instances on port 443. Install SSL certificate on instances.
C.Use HTTPS listener on port 443, provide the SSL certificate, and forward to instances on port 443. Disable proxy protocol.
D.Use HTTPS listener on port 443, provide the SSL certificate, and forward to instances on port 80. Enable X-Forwarded-For header.
AnswerD

An HTTPS listener on port 443 terminates SSL at the ALB using the supplied certificate, while forwarding to port 80 reaches the instances. Enabling the X-Forwarded-For header preserves the original client IP for application logging, satisfying both requirements simultaneously.

Why this answer

Using an HTTPS listener on port 443 with SSL termination at the ALB allows the load balancer to decrypt traffic and forward it as HTTP on port 80. The X-Forwarded-For header is automatically added by the ALB to preserve the original client IP address in the application logs, meeting both requirements without additional configuration.

Exam trap

The trap here is that candidates often confuse TCP listeners with proxy protocol v2 as the only way to preserve client IP, overlooking that HTTPS listeners automatically provide the X-Forwarded-For header for client IP preservation when SSL termination is performed at the load balancer.

How to eliminate wrong answers

Option A is wrong because a TCP listener does not support SSL termination at the load balancer; it forwards encrypted traffic as-is, and proxy protocol v2 is used with TCP listeners to preserve client IP, but this does not meet the SSL termination requirement. Option B is wrong because using a TCP listener on port 443 and forwarding to instances on port 443 with SSL certificates on instances means SSL termination occurs on the instances, not at the load balancer, and client IP is not preserved without proxy protocol. Option C is wrong because forwarding HTTPS traffic on port 443 to instances on port 443 with SSL certificates on instances means SSL termination is performed on the instances, not at the load balancer, and disabling proxy protocol does not preserve the client IP via X-Forwarded-For.

112
Multi-Selecteasy

A company is designing a new database solution for a global e-commerce application. The database must support high read and write throughput with single-digit millisecond latency. The company expects traffic spikes during peak hours. Which TWO AWS services should the company consider?

Select 2 answers
A.Amazon DocumentDB (with MongoDB compatibility)
B.Amazon ElastiCache
C.Amazon DynamoDB
D.Amazon Aurora
E.Amazon RDS for MySQL
AnswersB, C

ElastiCache provides an in-memory caching layer delivering sub-millisecond read latency, absorbing the read-heavy load and peak-hour spikes so the primary database is not overwhelmed. It satisfies the single-digit millisecond latency and burst throughput constraints, though it is not a durable write store.

Why this answer

Amazon DynamoDB (C) is correct because it is a fully managed NoSQL key-value and document database designed for single-digit millisecond latency at any scale, and it handles high read/write throughput with automatic scaling to absorb peak-hour traffic spikes. Amazon ElastiCache (B) is correct because it provides in-memory caching with sub-millisecond latency using Redis or Memcached, offloading read traffic from the primary database and smoothing bursts during peak hours. Together they fit a global e-commerce workload needing fast, elastic throughput.

Amazon DocumentDB (A) is a MongoDB-compatible document database that does not deliver the same single-digit millisecond latency guarantees at scale for this use case. Amazon Aurora (D) and Amazon RDS for MySQL (E) are relational databases that can be fast but are not purpose-built for the extreme, spiky throughput and in-memory caching needs described here.

Exam trap

The trap here is that candidates often choose Amazon Aurora or RDS for MySQL because they are familiar with SQL databases, but they overlook the requirement for single-digit millisecond latency and high throughput under spikes, which in-memory caching and NoSQL solutions like ElastiCache and DynamoDB are specifically designed to meet.

113
MCQeasy

A company is migrating a legacy monolithic application to AWS. The application currently runs on a single Windows Server with IIS and SQL Server. The company wants to adopt a microservices architecture on AWS using containers. The development team has containerized the application into several Docker containers. The company needs a solution that minimizes operational overhead for managing the container orchestration and scaling, and also integrates with AWS services like IAM, CloudWatch, and VPC. Which AWS service should the company use to run the containers?

A.Amazon ECS with the Fargate launch type.
B.Amazon EKS with managed node groups.
C.AWS Elastic Beanstalk with a Docker platform.
D.Amazon EC2 instances with Docker installed, managed by an Auto Scaling group.
AnswerA

Fargate's serverless compute model removes EC2 instance patching and cluster capacity management, satisfying the minimal-operational-overhead constraint. It runs containers inside the VPC with native IAM task roles and CloudWatch logging, integrating directly with the AWS services the stem requires.

Why this answer

Amazon ECS with the Fargate launch type is a serverless compute engine for containers that eliminates the need to provision or manage EC2 instances, directly minimizing operational overhead. It natively integrates with IAM task roles, CloudWatch Logs/metrics, and VPC networking (awsvpc mode), matching all stated requirements. This makes it the best fit for a team that wants to run Docker containers without managing orchestration infrastructure.

Exam trap

SAP-C02 often tests the misconception that EKS is always the right answer for containers, when the requirement to minimize operational overhead points to Fargate.

How to eliminate wrong answers

Option B is wrong because EKS with managed node groups still requires managing worker nodes (patching, scaling, AMI updates), adding operational overhead compared to Fargate. Option C is wrong because Elastic Beanstalk with Docker is designed for single-container or simple multi-container deployments and does not provide the microservices orchestration, service discovery, and task-level IAM integration expected for a containerized microservices architecture. Option D is wrong because running Docker on EC2 with an Auto Scaling group requires the company to manage the instances, Docker daemon, scheduling, and scaling logic themselves, which maximizes operational overhead rather than minimizing it.

114
Multi-Selecthard

A company is modernizing an on-premises Java application by moving it to containers on Amazon EKS. The application reads configuration from environment-specific property files and stores user-uploaded documents on a locally mounted NFS share. The company wants the containerized application to be portable across clusters and environments, and it must not require rebuilding the container image per environment. Which two changes should a solutions architect make to meet these requirements? (Choose two.)

Select 2 answers
A.Move the uploaded documents into the container image and write new uploads to the pod's ephemeral writable layer
B.Bake the environment-specific property files into the container image during the CI build for each environment
C.Store the environment-specific configuration in AWS Systems Manager Parameter Store or AWS Secrets Manager and inject the values into the pods as environment variables or mounted files at runtime
D.Replace the NFS share with an Amazon EBS volume attached to each node and expose it to the pods with a hostPath volume
E.Replace the locally mounted NFS share with Amazon EFS and mount it into the pods using the Amazon EFS CSI driver with access points
AnswersC, E

Externalizing configuration into Parameter Store or Secrets Manager removes environment-specific values from the image, so the same image runs in every environment. Values can be injected as environment variables or mounted as files using the AWS Secrets and Configuration Provider for the Secrets Store CSI driver. This satisfies the requirement that the image must not be rebuilt per environment.

Why this answer

Portability across clusters and environments requires that environment-specific values and shared state live outside the image. Externalizing configuration into Parameter Store or Secrets Manager and injecting it at runtime keeps a single image valid everywhere, while Amazon EFS with the EFS CSI driver reproduces the shared NFS semantics the application expects. Baking configuration into images or using node-local storage both break portability and shared access.

Exam trap

The trap here is assuming that because the application already uses NFS, any node-local or image-embedded storage will behave the same way once containerized.

115
MCQmedium

A company is migrating a critical application to AWS and needs to ensure that the migration has minimal downtime. The application uses a SQL Server database. The company wants to use AWS Database Migration Service (DMS) for the migration. What should the company do to minimize downtime during the database migration?

A.Use DMS with validation enabled and then truncate the target before cutover.
B.Use DMS with ongoing replication (change data capture) to keep the target database synchronized, then perform a brief cutover.
C.Use DMS with full load only and schedule the migration during a maintenance window.
D.Perform a full load migration using DMS and then manually copy any remaining data.
AnswerB

DMS change data capture continuously replicates ongoing changes from SQL Server to the target after the initial full load, keeping both synchronised. The cutover then needs only a brief application pause, satisfying the minimal-downtime requirement.

Why this answer

Using change data capture (CDC) with AWS DMS enables ongoing replication of changes from the source SQL Server database to the target. This keeps the target nearly synchronized, so during cutover only a brief pause is needed to apply any final changes, minimizing downtime. Option A is incorrect because enabling validation does not reduce downtime; it only verifies data integrity after migration, and truncating the target before cutover would remove all data, causing potential data loss and additional downtime.

Option C is incorrect because a full load only captures a snapshot of the database at a point in time; any changes after that require a separate sync, leading to longer downtime. Option D is incorrect because manually copying remaining data after a full load migration defeats the purpose of using DMS and introduces significant downtime and risk of inconsistency.

116
MCQhard

A company is migrating a large-scale .NET application to AWS. The application uses Windows authentication and requires Active Directory integration. The company wants to reduce operational overhead. Which migration approach should they use?

A.Rehost on EC2 with on-premises AD via VPN
B.Rehost on EC2 with AWS Managed Microsoft AD
C.Replatform to use Amazon Cognito for authentication
D.Replatform to AWS Elastic Beanstalk with Amazon Lightsail
AnswerB

AWS Managed Microsoft AD provides the domain services and Kerberos-based Windows authentication the .NET application requires, while AWS handles patching, replication and domain controller availability. Rehosting on EC2 preserves the existing application without code changes, and the managed directory removes the operational overhead of self-managed AD.

Why this answer

(Rehost on EC2 with AWS Managed Microsoft AD) is correct because it provides Active Directory integration without the need to manage domain controllers, reducing operational overhead. Option A (Rehost on EC2 with on-premises AD via VPN) still requires managing on-premises resources and doesn't fully reduce overhead. Option C (Replatform to use Amazon Cognito) is aimed at web identity federation, not traditional Windows AD authentication.

Option D (Replatform to AWS Elastic Beanstalk with Amazon Lightsail) does not support Windows authentication or AD integration effectively.

117
Multi-Selectmedium

A company is migrating a legacy three-tier web application to AWS. The application consists of a web tier, an application tier, and a database tier. The company wants to minimize downtime and ensure data consistency during the migration. The database is a Microsoft SQL Server 2016 running on-premises. The company plans to use AWS Database Migration Service (DMS) for the database migration. Which two actions should be taken to meet these requirements? (Choose two.)

Select 2 answers
A.Create an AWS DMS task with a full load only, and then manually apply any changes made during the migration.
B.Configure AWS DMS with a full load plus ongoing replication (CDC) task to keep the target database in sync until cutover.
C.Perform a test migration to a staging environment to validate data consistency and application functionality before the production cutover.
D.Enable multi-AZ deployment on the target Amazon RDS for SQL Server instance to ensure high availability during migration.
E.Use AWS Schema Conversion Tool (SCT) to convert the SQL Server schema to Amazon Aurora MySQL before migration.
AnswersB, C

Using full load plus ongoing replication (CDC) allows DMS to perform an initial data load and then continuously replicate changes from the source to the target. This minimizes downtime because the target remains synchronized until the cutover, at which point the application can be switched to the target with minimal interruption. It ensures data consistency by capturing all changes.

Why this answer

Configuring DMS with full load plus ongoing replication keeps the target synchronized and minimizes downtime during cutover. Performing a test migration validates the process and ensures data consistency and application compatibility. Together, these actions address the requirements for minimal downtime and data consistency.

Exam trap

The trap here is overlooking the need for ongoing replication (CDC) and assuming a one-time full load is sufficient, which would cause data loss for changes made during migration.

118
MCQhard

A company is migrating a legacy .NET application to AWS. The application uses Windows authentication and connects to an on-premises SQL Server database. The company wants to minimize code changes. Which migration strategy is most appropriate?

A.Replatform the application to use Amazon Aurora PostgreSQL with AWS DMS.
B.Refactor the application into microservices using AWS Lambda and Amazon DynamoDB.
C.Rehost the application on EC2 Windows instances and use Amazon RDS for SQL Server.
D.Re-platform the application to run on Amazon Linux and use Amazon RDS for MySQL.
AnswerC

Rehosting on EC2 Windows preserves the existing Windows authentication mechanism without code changes, satisfying the minimise-changes constraint. Amazon RDS for SQL Server supports Windows authentication through AWS Managed Microsoft AD, allowing the application to connect using integrated security rather than SQL logins, so connection strings and authentication code remain largely unchanged.

Why this answer

Rehosting the application on EC2 Windows instances and using Amazon RDS for SQL Server preserves Windows authentication and the existing SQL Server engine, minimizing code changes. This is the classic 'lift and shift' approach that keeps the application's dependencies intact.

Exam trap

SAP-C02 often tests migration strategy selection, and the trap is choosing replatform/refactor options that sound modern but violate the 'minimize code changes' constraint.

How to eliminate wrong answers

Option A is wrong because replatforming to Aurora PostgreSQL with AWS DMS requires schema and code changes to move off SQL Server and Windows authentication. Option B is wrong because refactoring into Lambda and DynamoDB is a major rewrite that abandons Windows authentication and the relational model. Option D is wrong because moving to Amazon Linux and RDS for MySQL changes the OS and database engine, breaking Windows authentication and requiring code changes.

119
Multi-Selecthard

A company is migrating a legacy three-tier application from its on-premises data center to AWS. The application consists of a web tier, an application tier, and a database tier. The company wants to improve scalability and reduce operational overhead. The database tier uses Microsoft SQL Server and cannot be modified. The company wants to migrate with minimal changes. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Migrate the database tier to Amazon RDS for SQL Server with a Multi-AZ deployment.
B.Migrate the web and application tiers to Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer.
C.Migrate the web and application tiers to AWS Lambda functions with Amazon API Gateway.
D.Migrate the database tier to Amazon RDS for SQL Server with a read replica in a single Availability Zone.
E.Migrate the database tier to Amazon DynamoDB with on-demand capacity mode.
AnswersA, B

Amazon RDS for SQL Server is a managed service that supports Multi-AZ deployments for high availability and automatic failover. It reduces operational overhead by handling backups, patching, and replication. Since the database cannot be modified, using RDS for SQL Server with Multi-AZ provides a compatible, scalable, and resilient database tier with minimal changes.

Why this answer

Migrating the web and application tiers to EC2 Auto Scaling groups behind an Application Load Balancer improves scalability and reduces operational overhead. Migrating the database to Amazon RDS for SQL Server with Multi-AZ provides a managed, highly available database service that supports the existing SQL Server schema with minimal changes. Together, these actions meet the requirements without re-architecting the application.

Exam trap

The trap here is assuming that any managed database service can replace SQL Server, but NoSQL services like DynamoDB require a complete data model redesign, which is not feasible when the database cannot be modified.

120
MCQeasy

A company is using Amazon DynamoDB as the primary database for a web application. The application experiences occasional throttling on writes. The company wants to implement a solution that automatically increases write capacity during traffic spikes. Which solution should they use?

A.Switch to DynamoDB On-Demand capacity mode.
B.Implement DynamoDB Accelerator (DAX) for caching.
C.Use DynamoDB Global Tables to distribute writes.
D.Enable DynamoDB Auto Scaling for write capacity.
AnswerD

DynamoDB Auto Scaling adjusts provisioned write capacity in response to CloudWatch-consumed capacity metrics, scaling up during spikes and down afterwards. This automatically raises write throughput when traffic surges, directly addressing the occasional write throttling described in the stem.

Why this answer

DynamoDB Auto Scaling adjusts provisioned write (and read) capacity automatically in response to actual utilization, using CloudWatch alarms and Application Auto Scaling to raise capacity during spikes and lower it when traffic subsides. This directly addresses occasional write throttling while keeping the table in provisioned mode. It is the intended mechanism for elastic capacity on provisioned tables.

Exam trap

SAP-C02 often tests the confusion between read-side tools (DAX) and write-side scaling — candidates must recognize that DAX caches reads and that Global Tables address multi-region, not single-region write capacity.

How to eliminate wrong answers

Option A is wrong because switching to on-demand mode is a capacity-mode change, not an auto-scaling solution, and it can be more expensive for steady workloads; the question asks for a solution that automatically increases write capacity, which Auto Scaling does within provisioned mode. Option B is wrong because DAX caches reads, not writes — it reduces read latency and read capacity consumption but does nothing for write throttling. Option C is wrong because Global Tables replicate writes across regions for multi-region active-active access; they do not increase write capacity in a single region and can actually add replication write costs.

121
Multi-Selectmedium

A company is deploying a new three-tier application on AWS. The application consists of a web tier, an application tier, and a database tier. The company wants to ensure that the application can withstand the failure of a single Availability Zone and that the database tier can fail over automatically. The company also wants to minimize operational overhead. Which two solutions should a solutions architect recommend? (Choose two.)

Select 2 answers
A.Deploy the web and application tiers in a single Availability Zone with a larger instance size to reduce the chance of failure.
B.Use Amazon Route 53 with a latency-based routing policy to distribute traffic across multiple Regions.
C.Deploy the database tier on Amazon RDS with a Multi-AZ configuration.
D.Deploy the database tier on Amazon EC2 instances with a primary and standby replica, and use a third-party clustering solution for automatic failover.
E.Deploy the web and application tiers across multiple Availability Zones using an Auto Scaling group and an Application Load Balancer.
AnswersC, E

Amazon RDS Multi-AZ maintains a synchronous standby replica in a different Availability Zone and automatically fails over to it if the primary fails. This meets the requirement for automatic database failover and AZ resilience. It requires minimal operational effort because AWS manages replication and failover. It is the standard solution for high availability of relational databases on AWS.

Why this answer

Deploying the web and application tiers across multiple Availability Zones with an Auto Scaling group and Application Load Balancer provides AZ resilience and automatic recovery. Using Amazon RDS Multi-AZ ensures automatic database failover with synchronous replication. Together, these solutions meet the high availability and low operational overhead requirements.

Self-managed databases on EC2 increase overhead, single-AZ deployments are not fault-tolerant, and multi-Region routing is unnecessary for AZ-level resilience.

Exam trap

The trap here is assuming that a larger instance in a single Availability Zone or multi-Region routing is needed for AZ resilience, when in fact multi-AZ deployments within a Region are sufficient and simpler.

122
Multi-Selectmedium

An e-commerce company runs its application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses an Amazon Aurora MySQL DB cluster with one writer and two reader instances. During a sales event, the database CPU utilization is high, and read replicas show high replica lag. The company needs to improve the read scalability and reduce replica lag. Which THREE actions should the company take? (Choose THREE.)

Select 3 answers
A.Add more reader instances to the cluster to distribute the read traffic.
B.Enable Multi-AZ for the cluster to improve read availability.
C.Increase the instance size of the writer instance to improve write throughput.
D.Increase the instance size of the reader instances to larger instance types.
E.Enable Aurora Auto Scaling for the reader instances.
AnswersA, D, E

Adding reader instances spreads read connections across more Aurora replicas, lowering per-node CPU and query load. This directly improves read scalability, though it does not by itself address replica lag, which stems from write volume on the writer.

Why this answer

Adding more reader instances (Option A) distributes the read workload across additional nodes, reducing the load on each reader and helping to lower replica lag. Aurora Auto Scaling (Option E) automatically adjusts the number of reader instances based on metrics like CPU utilization or replica lag, providing dynamic scaling during traffic spikes. Increasing the instance size of reader instances (Option D) provides more CPU and memory resources to each reader, enabling them to process more read queries and apply changes from the writer faster, which directly reduces replica lag.

Exam trap

The trap here is that candidates may confuse Multi-AZ with read scaling, but Multi-AZ in Aurora is for high availability only and does not distribute read traffic, while the real solutions involve adding more readers, scaling readers up, or using Auto Scaling to handle variable load.

123
MCQhard

A media company is migrating a large on-premises video rendering workload to AWS. The workload runs on 100 physical servers and is highly parallelizable. The company wants to minimize infrastructure management and only pay for the compute capacity used. They also need to handle sudden spikes in demand. Which AWS service should they use?

A.AWS Lambda
B.AWS Batch
C.Amazon ECS with Fargate
D.Amazon EC2 with Spot Instances
AnswerB

AWS Batch is a fully managed batch computing service that dynamically provisions compute resources based on job volume and requirements. It handles job scheduling, dependency management, and scaling, allowing the company to focus on rendering jobs. It integrates with Spot Instances for cost savings and can scale to handle spikes. This minimizes infrastructure management and aligns with pay-for-use pricing.

Why this answer

AWS Batch is designed for batch computing workloads, providing managed job scheduling and dynamic scaling. It supports both EC2 and Fargate compute environments and can leverage Spot Instances for cost savings. This allows the media company to run parallel rendering jobs without managing infrastructure, while paying only for the resources used, and it scales automatically to handle spikes in demand.

Exam trap

The trap here is assuming that any serverless compute service like Lambda or Fargate is suitable for batch workloads; AWS Batch is purpose-built for batch processing with job queues and dependencies.

124
MCQhard

A company is migrating a high-traffic web application to AWS. The application currently runs on physical servers in a colocation facility and uses a custom session state mechanism stored in a local Redis instance on each server. The company wants to modernize the application to be highly available and scalable on AWS with minimal code changes. Which solution meets these requirements?

A.Deploy the application on Amazon ECS with Fargate, and use Amazon EFS to store session files that are shared across all tasks.
B.Deploy the application on Amazon EC2 instances in an Auto Scaling group, and use an Application Load Balancer with sticky sessions enabled to keep users on the same instance.
C.Deploy the application on Amazon EC2 instances behind an Application Load Balancer, and migrate session state to Amazon ElastiCache for Redis with cluster mode enabled.
D.Migrate the application to AWS Lambda with Amazon API Gateway, and store session data in Amazon DynamoDB using a new session management library.
AnswerC

Amazon ElastiCache for Redis provides a fully managed, highly available Redis service that can be configured with cluster mode for scalability. By moving session state from local instances to ElastiCache, the application becomes stateless and can scale horizontally behind an Application Load Balancer. This requires minimal code changes because the application already uses Redis APIs, just pointing to a new endpoint.

Why this answer

Migrating session state to Amazon ElastiCache for Redis preserves the existing Redis API usage, requiring only a configuration change to point to the new endpoint. ElastiCache provides high availability with automatic failover and scalability through cluster mode. Combined with an Application Load Balancer and EC2 Auto Scaling, the application becomes stateless, highly available, and scalable with minimal code modifications.

Exam trap

The trap here is assuming that sticky sessions alone can provide high availability and scalability, but they actually tie users to specific instances, preventing seamless failover and even load distribution.

125
MCQhard

A company is deploying a serverless application using AWS Lambda. The application processes high-resolution images and stores them in Amazon S3. The processing time for each image is variable, but some images require more than 15 minutes to process. Lambda has a maximum execution time of 15 minutes. How can the company process these long-running image transformations?

A.Use AWS Step Functions to chain multiple Lambda functions, each processing a part of the image.
B.Use AWS Batch to run the image processing as a job on EC2 or Fargate.
C.Use Amazon SQS to queue the images and have Lambda poll the queue; the Lambda function can process one image per invocation.
D.Increase the Lambda timeout to 20 minutes.
AnswerB

AWS Batch has no 15-minute invocation limit, so it can run image transformations as jobs on EC2 or Fargate for as long as needed. This directly satisfies the stem's constraint that some images exceed Lambda's maximum execution time.

Why this answer

AWS Lambda has a hard limit of 15 minutes per invocation, so images requiring more than 15 minutes cannot be processed within a single Lambda function. AWS Batch is designed for long-running, batch-oriented compute jobs and can run on EC2 or Fargate without any time limit, making it the correct choice for processing high-resolution images that exceed Lambda's timeout.

Exam trap

The trap here is that candidates assume Step Functions can extend Lambda's execution time by chaining functions, but each Lambda invocation still has a hard 15-minute limit, and Step Functions does not override that service quota.

How to eliminate wrong answers

Option A is wrong because chaining multiple Lambda functions via Step Functions does not extend the per-invocation timeout; each individual Lambda function still has a 15-minute limit, and splitting an image into parts would require custom orchestration and state management, not a native solution for long-running tasks. Option C is wrong because using SQS to queue images does not change Lambda's maximum execution time; each Lambda invocation still cannot exceed 15 minutes, so images requiring longer processing would time out. Option D is wrong because Lambda's maximum timeout is fixed at 15 minutes (900 seconds) and cannot be increased; this is a hard AWS service limit, not a configurable parameter.

126
MCQeasy

A company is migrating a legacy on-premises application to AWS. The application currently runs on a Windows Server with a SQL Server database. The company wants to minimize changes to the application code. Which migration strategy should the company use?

A.Rehost (lift-and-shift)
B.Refactor / re-architect
C.Replatform (lift-and-resize)
D.Rebuild
AnswerA

Rehost moves the Windows Server and SQL Server workloads to Amazon EC2 essentially unchanged, satisfying the requirement to minimise application code changes. Unlike replatforming or refactoring, no engine swap or rewrite occurs, so the legacy application continues running on the same OS and database platform.

Why this answer

Rehosting (lift-and-shift) involves moving the application as-is to AWS, minimizing code changes. Replatforming (lift-and-resize) may involve some changes, but rehosting requires the least modification. Refactoring and rebuilding involve significant changes.

127
Multi-Selectmedium

A company is building a serverless application using AWS Lambda and Amazon API Gateway. They need to authenticate users. Which TWO services can be used for authentication?

Select 2 answers
A.AWS Security Token Service
B.AWS IAM
C.Amazon SQS
D.Amazon Cognito
E.Amazon CloudFront
AnswersB, D

AWS IAM authenticates API Gateway requests via Signature Version 4 signed credentials, using IAM roles, users, or Cognito identity pools. This satisfies the stem's requirement for a Lambda and API Gateway authentication mechanism, since API Gateway natively supports IAM authorisation for REST and HTTP APIs without additional identity infrastructure.

Why this answer

Amazon Cognito (D) is correct because it provides user pools that handle sign-up, sign-in, and token issuance (ID, access, and refresh tokens) for API Gateway, and it also supports identity pools for federated identities, making it the standard managed authentication service for serverless applications. AWS IAM (B) is correct because API Gateway can use IAM authorization (SigV4-signed requests) to authenticate and authorize callers, and Lambda execution roles and resource policies rely on IAM for identity and access control. AWS Security Token Service (A) is not a standalone authentication service; it issues temporary credentials after authentication has already occurred, so it is not the answer here.

Amazon SQS (C) is a message queuing service and Amazon CloudFront (E) is a content delivery network, neither of which authenticates users.

Exam trap

The trap here is that candidates often confuse AWS STS (which issues temporary credentials) with an authentication service, or think SQS or CloudFront can handle authentication, when in fact only IAM and Cognito directly support user authentication for API Gateway in this context.

128
MCQmedium

A solutions architect deployed the above CloudFormation template. However, the Lambda function is not triggered when objects are uploaded to the S3 bucket. What is the most likely cause?

A.The BucketNotification resource depends on MyLambdaFunction, but the notification configuration is incorrect.
B.The Lambda function lacks a resource-based policy that allows S3 to invoke it.
C.The Lambda execution role does not have permission to access S3.
D.The Lambda function code does not read the S3 object content.
AnswerB

S3 invokes Lambda asynchronously, which requires a resource-based policy granting s3.amazonaws.com permission to call InvokeFunction. Without this policy, uploads succeed silently but no invocation occurs, so the function never triggers despite any execution role permissions.

Why this answer

For S3 to invoke a Lambda function, the function must have a resource-based policy (permission) that grants the s3.amazonaws.com service principal permission to call lambda:InvokeFunction. Without this permission, S3's notification configuration is accepted but invocation fails silently. This is the most common cause of 'Lambda not triggered' in CloudFormation deployments.

Exam trap

SAP-C02 often tests the confusion between the Lambda execution role (what the function can access) and the Lambda resource-based policy (who can invoke the function) — candidates pick the execution role fix when the real issue is the missing invoke permission.

How to eliminate wrong answers

Option A is wrong because the BucketNotification resource dependency is not the issue — even with correct dependency ordering, the invocation fails without the Lambda permission. Option C is wrong because the Lambda execution role governs what the function can do (e.g., read S3), not whether S3 can invoke it; the execution role is irrelevant to the trigger. Option D is wrong because the function code reading the object is a runtime concern after invocation — the question states the function is not triggered at all.

129
MCQmedium

A company uses Amazon S3 to store critical data. They need to ensure that data is automatically replicated to another AWS Region for disaster recovery. Which configuration meets this requirement with minimal operational overhead?

A.Enable S3 Versioning on the source bucket.
B.Use S3 Transfer Acceleration to upload objects to both Regions.
C.Configure an S3 Lifecycle policy to transition objects to S3 Glacier.
D.Enable S3 Cross-Region Replication (CRR) on the source bucket.
AnswerD

S3 Cross-Region Replication asynchronously copies objects to a bucket in another Region, satisfying the disaster-recovery constraint. Once configured on the source bucket with versioning and an IAM role, AWS handles ongoing replication, requiring minimal operational overhead.

Why this answer

S3 Cross-Region Replication (CRR) is the native S3 feature that asynchronously replicates objects from a source bucket in one Region to a destination bucket in another Region. Once configured with a replication rule and the required IAM role, new objects are copied automatically with no ongoing operational effort. This satisfies the disaster-recovery requirement with minimal overhead.

Exam trap

SAP-C02 often tests whether candidates confuse Versioning (same-Region durability) with CRR (cross-Region DR), so picking Versioning when the question explicitly says 'another AWS Region' is the classic wrong-answer trap.

How to eliminate wrong answers

Option A is wrong because S3 Versioning only preserves multiple versions of objects in the same bucket/Region; it does not replicate data across Regions. Option B is wrong because S3 Transfer Acceleration speeds up uploads to a single bucket using edge locations; it does not replicate objects to a second Region. Option C is wrong because a Lifecycle policy transitions objects to Glacier storage classes for cost optimization, not cross-Region replication.

130
MCQhard

A company is migrating a large-scale Hadoop cluster to Amazon EMR. The migration plan includes moving data from HDFS to Amazon S3. The company wants to minimize costs and ensure data durability. Which approach should the company use?

A.Set up a VPN connection and use rsync to copy data to S3.
B.Use Apache DistCp to copy data from HDFS to S3.
C.Use AWS Snowball Edge to physically transfer data from the cluster.
D.Use AWS Database Migration Service (DMS) to migrate the data to S3.
AnswerB

Apache DistCp is purpose-built for parallel, distributed copying between HDFS and Amazon S3, preserving data integrity across the large-scale Hadoop dataset. S3 provides eleven nines of durability with lower storage cost than HDFS on persistent EMR clusters, satisfying both the cost and durability constraints.

Why this answer

B is correct because DistCp is designed for efficient HDFS-to-S3 transfers, and S3's 99.999999999% durability meets requirements. A is wrong because VPN and rsync are not optimized for large-scale data transfer to S3. C is wrong because Snowball Edge adds latency and is not necessary for data already in the cluster.

D is wrong because AWS DMS is for databases, not file systems.

131
MCQhard

A company has a multi-account AWS organization with hundreds of accounts. The security team wants to ensure that all accounts have AWS Config enabled with a specific set of rules. They also want to automatically remediate non-compliant resources. Which solution is MOST scalable and operationally efficient?

A.Use AWS CloudFormation StackSets to deploy Config rules to all accounts.
B.Use AWS Config rules in each account with AWS Lambda functions for remediation.
C.Use AWS Config conformance packs deployed via AWS Organizations with automatic remediation using Systems Manager Automation.
D.Use an AWS Config aggregator in the management account to view compliance across accounts.
AnswerC

Conformance packs bundle Config rules and remediation actions into a single deployable entity, and AWS Organizations pushes them to every account automatically. This satisfies the hundreds-of-accounts scalability constraint without per-account scripting, while Systems Manager Automation executes the automatic remediation the security team requires.

Why this answer

AWS Config conformance packs can be deployed at the organization level using AWS Organizations, enabling centralized management of rules across hundreds of accounts. Automatic remediation is achieved by associating Systems Manager Automation documents with non-compliant resources. Option A is incorrect because CloudFormation StackSets require per-account deployment and management, which does not scale as efficiently as conformance packs.

Option B is incorrect because Config rules in each account with Lambda functions lack centralized deployment and management. Option D is incorrect because an AWS Config aggregator only provides a cross-account compliance view, not enforcement or remediation.

132
MCQeasy

A company is designing a new application that will store and retrieve large files (up to 5 TB). The files must be accessible via HTTPS and must be durable. Which AWS storage service should be used?

A.Amazon S3
B.Amazon EFS
C.AWS Storage Gateway
D.Amazon EBS
AnswerA

Amazon S3 stores objects up to 5 TB each, delivers them over HTTPS via REST endpoints, and provides eleven nines of durability through automatic replication across multiple Availability Zones. This satisfies the large-file, HTTPS-access and durability constraints without provisioning or managing any servers.

Why this answer

Amazon S3 is the correct choice because it supports objects up to 5 TB in size, provides HTTPS access via RESTful API endpoints, and offers 99.999999999% (11 nines) durability by automatically replicating data across multiple Availability Zones. S3 is purpose-built for storing and retrieving large files over the internet with high durability and scalability.

Exam trap

The trap here is that candidates may confuse file storage (EFS) or block storage (EBS) with object storage (S3), overlooking that only S3 provides native HTTPS access and 11 nines durability for large objects without requiring an EC2 instance or additional infrastructure.

How to eliminate wrong answers

Option B (Amazon EFS) is wrong because it is a file-level storage service for Linux workloads, not designed for single objects up to 5 TB (its maximum file size is 52 TB, but it lacks native HTTPS object access and is optimized for shared file systems, not direct HTTP retrieval). Option C (AWS Storage Gateway) is wrong because it is a hybrid storage service that provides on-premises access to AWS storage, not a primary storage service for direct HTTPS access to large files; it adds latency and complexity for a purely cloud-native application. Option D (Amazon EBS) is wrong because it is block-level storage attached to a single EC2 instance, cannot be accessed directly via HTTPS, and has a maximum volume size of 16 TB but requires an EC2 instance to serve files, making it unsuitable for direct object retrieval over the internet.

133
MCQeasy

A company wants to migrate an on-premises Oracle database to Amazon Aurora PostgreSQL. The migration must have minimal downtime. Which AWS service should be used for the migration?

A.AWS Server Migration Service (SMS)
B.AWS DataSync
C.AWS Database Migration Service (DMS)
D.AWS Snowball
AnswerC

AWS Database Migration Service performs continuous change data capture from the on-premises Oracle source, replicating ongoing transactions to Aurora PostgreSQL while the initial full load runs. This keeps the source live, so cutover requires only a brief application pause, satisfying the minimal-downtime constraint. Schema conversion is handled separately by the AWS Schema Conversion Tool.

Why this answer

AWS DMS supports ongoing replication to minimize downtime during migration.

134
MCQeasy

A company has an AWS Organizations setup with a management account and several member accounts. The finance team needs to receive a consolidated bill for all accounts and wants to apply volume discounts across the organization. The company also wants to prevent member accounts from leaving the organization without approval. Which action should the company take?

A.Enable all features in AWS Organizations and configure a service control policy that denies organizations:LeaveOrganization in member accounts.
B.Create an organization trail in AWS CloudTrail and configure an Amazon EventBridge rule to notify the finance team when an account leaves.
C.Use AWS Resource Access Manager to share the billing account with member accounts and restrict the organizations:LeaveOrganization action with an IAM policy in each member account.
D.Enable consolidated billing only, and use AWS Budgets to alert the finance team when a member account attempts to leave.
AnswerA

Enabling all features allows consolidated billing and volume discounts across the organization, and it also enables service control policies. A service control policy denying organizations:LeaveOrganization in member accounts prevents them from leaving without approval. This combination meets both the billing and the membership control requirements.

Why this answer

Enabling all features in AWS Organizations provides consolidated billing and volume discounts, and it is a prerequisite for service control policies. A service control policy that denies organizations:LeaveOrganization in member accounts prevents them from leaving without approval. This is the only option that both delivers the billing benefits and enforces the membership restriction.

Exam trap

The trap here is relying on monitoring tools like AWS Budgets or CloudTrail to prevent an action, when only a service control policy can actually block a member account from leaving the organization.

135
MCQmedium

A company runs a stateless web application on EC2 instances in an Auto Scaling group. The application is deployed across multiple Availability Zones. The team notices that during a recent traffic spike, some instances were terminated and replaced, causing a temporary drop in performance. How can the team improve the resilience of the application?

A.Purchase Reserved Instances to ensure capacity.
B.Use lifecycle hooks to wait for instance termination.
C.Increase the instance size to handle more traffic.
D.Configure a warm pool for the Auto Scaling group.
AnswerD

A warm pool maintains pre-initialised instances in a stopped or running state, ready to enter service immediately. This directly addresses the performance drop caused by cold-start bootstrapping during scale-out, since replacement instances bypass lengthy application initialisation. It satisfies the resilience constraint by reducing the time the Auto Scaling group operates below desired capacity during traffic spikes.

Why this answer

A warm pool pre-initializes instances, reducing the time needed for new instances to become ready during scale-out events. Option A is wrong because Reserved Instances guarantee capacity but do not reduce the initialization delay. Option B is wrong because lifecycle hooks can delay termination but do not accelerate instance readiness.

Option C is wrong because larger instance size does not prevent the temporary drop in performance caused by instance replacement delays.

136
MCQeasy

A company is designing a new application that will be deployed on AWS. The application requires a relational database with automatic failover and high availability within a single AWS region. Which database deployment option meets these requirements?

A.Amazon RDS Single-AZ deployment
B.Amazon RDS with Read Replicas
C.Amazon RDS Multi-AZ deployment
D.Amazon RDS cross-region replication
AnswerC

RDS Multi-AZ maintains a synchronous standby replica in a second Availability Zone within the same region, with automatic DNS failover during an outage. This delivers the required high availability and automatic failover for a relational database without cross-region complexity.

Why this answer

RDS Multi-AZ provides automatic failover and high availability within a region. Option A is wrong because Single-AZ does not provide failover. Option B is wrong because Read Replicas are for read scaling, not failover.

Option D is wrong because cross-region replication is for disaster recovery, not primary failover.

137
MCQhard

A company has 200 AWS accounts in AWS Organizations and a shared services VPC in a central networking account. Each workload account needs to reach an on-premises data center over a single AWS Direct Connect connection that terminates in the networking account. The company wants to minimize cost and avoid managing individual VPC peering connections. Which solution should a solutions architect recommend?

A.Deploy an AWS Site-to-Site VPN over the Direct Connect connection in each workload account and configure BGP to advertise the on-premises routes.
B.Create a VPC peering connection between the shared services VPC and each workload VPC, and propagate the Direct Connect routes through a static route in each workload VPC route table.
C.Create a transit gateway in the networking account, attach the Direct Connect gateway and all workload VPCs to it, and share the transit gateway using AWS Resource Access Manager.
D.Use AWS PrivateLink to create interface VPC endpoints in each workload VPC that point to the on-premises services in the networking account.
AnswerC

A transit gateway in the networking account can attach the Direct Connect gateway and all workload VPCs, and AWS Resource Access Manager lets other accounts in the organization attach their VPCs to the shared transit gateway. This centralizes connectivity, avoids a full mesh of peering connections, and scales to hundreds of accounts at lower operational cost.

Why this answer

A transit gateway in the networking account acts as a regional hub that connects the Direct Connect gateway and all workload VPCs. AWS Resource Access Manager shares the transit gateway with other accounts in the organization, so workload accounts attach their VPCs without creating peering meshes or per-account VPNs. This scales cleanly and reduces cost and operational overhead.

Exam trap

The trap here is assuming VPC peering is transitive or that PrivateLink provides general on-premises routing, when only a transit gateway shared through AWS Resource Access Manager centralizes connectivity at scale.

138
Multi-Selectmedium

A company is designing a real-time analytics platform that ingests data from thousands of IoT devices. The platform must process and store high-velocity data with low latency. Which TWO AWS services should be used together to meet these requirements? (Choose TWO.)

Select 2 answers
A.AWS Lambda
B.Amazon Kinesis Data Streams
C.Amazon Kinesis Data Analytics
D.Amazon S3
E.Amazon SQS
AnswersB, C

Kinesis Data Streams ingests high-velocity device telemetry durably and with low latency, sharding throughput across many producers and retaining records for replay. It satisfies the ingestion half of the requirement, feeding downstream consumers such as Kinesis Data Analytics or Lambda for real-time processing.

Why this answer

Amazon Kinesis Data Streams (B) is correct because it is purpose-built to ingest high-velocity, real-time streaming data from thousands of producers such as IoT devices, providing low-latency, durable, and scalable stream capture with shards and configurable retention. Amazon Kinesis Data Analytics (C) is correct because it runs continuous SQL or Apache Flink queries directly on streaming data from Kinesis Data Streams, enabling real-time processing and analytics with sub-second latency without managing servers. Together, Kinesis Data Streams handles ingestion and Kinesis Data Analytics handles real-time processing, which matches the platform's low-latency, high-velocity requirements.

AWS Lambda (A) is compute for event-driven functions but is not a streaming ingestion or stream-processing engine by itself, so it does not fulfill the ingestion-plus-real-time-analytics pairing. Amazon S3 (D) is object storage designed for durable batch storage, not low-latency stream ingestion or real-time processing. Amazon SQS (E) is a message queue for decoupling applications, not a high-throughput streaming data platform for real-time analytics.

Exam trap

The trap here is that candidates often confuse Amazon Kinesis Data Streams with Amazon SQS or Amazon S3 for streaming ingestion, but SQS lacks ordered, replayable streams and S3 introduces latency, while Kinesis Data Streams is purpose-built for high-velocity, low-latency data ingestion and analytics.

139
MCQhard

A company is migrating a legacy on-premises application to AWS. The application uses a proprietary database that runs on a single Windows server. The company wants to minimize downtime and avoid re-architecting the database. Which migration strategy should the solutions architect recommend?

A.Retire the application and replace it with a SaaS solution
B.Rehost using AWS Application Migration Service (CloudEndure)
C.Re-architect the application to use Amazon DynamoDB
D.Replatform by migrating the database to Amazon RDS for SQL Server
AnswerB

AWS Application Migration Service replicates the Windows server block-level to AWS, preserving the proprietary database unchanged, so no re-architecting occurs. Continuous replication keeps cutover downtime to minutes, satisfying both the minimise-downtime and avoid-re-architecting constraints. Replatforming or refactoring would alter the database engine, which the stem forbids.

Why this answer

Rehosting (lift-and-shift) with AWS Application Migration Service (formerly CloudEndure) moves the Windows server and its proprietary database to EC2 with minimal changes and minimal downtime, preserving the existing database engine. This aligns with the goal of avoiding re-architecture while meeting the migration timeline.

Exam trap

The trap is confusing 'rehost' with 'replatform' — candidates may pick RDS because it sounds like a managed improvement, but the question emphasizes minimizing downtime and avoiding re-architecture, which points to a lift-and-shift rehost.

How to eliminate wrong answers

Option A is wrong because retiring and replacing with SaaS requires re-architecting and data migration, which contradicts the requirement to avoid re-architecting and minimize downtime. Option C is wrong because re-architecting to DynamoDB is a major redesign that changes the database engine and application code, which is explicitly not desired. Option D is wrong because replatforming to Amazon RDS for SQL Server changes the database platform and may not support the proprietary database, and it requires schema/data migration, adding downtime and risk.

140
MCQmedium

A company runs a critical application on Amazon EC2 instances in an Auto Scaling group. The application writes logs to ephemeral instance storage. The operations team needs to retain these logs for 90 days for compliance and wants to search them using a central service. The logs are currently lost when instances are terminated. Which solution meets these requirements with the LEAST operational overhead?

A.Modify the application to write logs directly to an Amazon EFS file system mounted on each instance.
B.Install and configure a third-party log shipper to send logs to an Amazon S3 bucket with a lifecycle policy for 90-day retention.
C.Configure the CloudWatch agent to stream logs to Amazon CloudWatch Logs with a 90-day retention period.
D.Create a cron job on each instance that copies logs to an Amazon S3 bucket every hour.
AnswerC

The CloudWatch agent can collect logs from instance storage and send them to CloudWatch Logs, where you can set a retention policy of 90 days and use CloudWatch Logs Insights to search. This requires minimal operational overhead because it is a managed service and the agent can be installed via user data or AWS Systems Manager.

Why this answer

The CloudWatch agent provides a managed, low-overhead way to collect logs from EC2 instances and send them to CloudWatch Logs. Setting a 90-day retention period satisfies compliance, and CloudWatch Logs Insights allows searching. Other options involve custom scripts, third-party tools, or additional services that increase operational burden.

Exam trap

The trap here is overlooking that CloudWatch Logs can enforce retention and provide search, assuming that S3 is always the go-to for log retention, which adds search complexity.

141
MCQmedium

A company runs a microservices application on Amazon ECS with the Fargate launch type. The services communicate over HTTP and are deployed across multiple Availability Zones. The company wants to improve the application's resilience by implementing automatic retries and circuit breaking for inter-service communication. The services are registered in AWS Cloud Map. Which solution should a solutions architect recommend to meet these requirements with the LEAST operational overhead?

A.Use an Application Load Balancer with health checks and configure the ECS services to use it for service-to-service communication.
B.Deploy an AWS App Mesh service mesh and configure retry policies and circuit breakers for the virtual services.
C.Configure Amazon Route 53 with latency-based routing and health checks for each service, and rely on DNS failover for resilience.
D.Implement retry logic and circuit breakers in each microservice using an AWS SDK and the Cloud Map API for service discovery.
AnswerB

AWS App Mesh provides a service mesh that can automatically handle retries and circuit breaking without requiring changes to application code. It integrates with ECS and Cloud Map, allowing you to define virtual services and routes. By configuring retry policies and outlier detection, you can improve resilience with minimal operational overhead. App Mesh also provides observability, making it easier to monitor inter-service communication.

Why this answer

AWS App Mesh is a managed service mesh that provides retry policies, circuit breaking, and traffic routing without application code changes. It integrates with ECS and Cloud Map, reducing operational overhead. Other options require custom development or do not provide the required resilience features.

Exam trap

The trap here is assuming that a load balancer or DNS failover can provide application-level retries and circuit breaking, which they cannot.

142
MCQmedium

A company is designing a new microservices architecture using Amazon ECS with Fargate. The services need to communicate with each other using REST APIs. The company wants to implement a service mesh to handle traffic routing, observability, and security. Which AWS service should the company use?

A.Elastic Load Balancing for internal network load balancers.
B.AWS App Mesh.
C.AWS Cloud Map for service discovery.
D.Amazon API Gateway with VPC linking.
AnswerB

AWS App Mesh provides a managed Envoy-based service mesh that works with ECS on Fargate, delivering the traffic routing, observability and mutual TLS security the stem requires. It integrates natively with ECS service discovery, unlike ALB or Cloud Map alone, satisfying the REST API service-to-service communication constraint.

Why this answer

AWS App Mesh is a service mesh that provides application-level networking, enabling traffic routing, observability (metrics, logs, traces), and security (mTLS, authorization policies) for microservices. It integrates natively with Amazon ECS on Fargate, allowing sidecar Envoy proxies to handle inter-service communication without modifying application code.

Exam trap

The trap here is that candidates often confuse service discovery (Cloud Map) with a full service mesh, or assume that a load balancer (ELB) or API gateway can provide the same level of traffic routing, observability, and security for internal microservices communication.

How to eliminate wrong answers

Option A is wrong because Elastic Load Balancing for internal NLB operates at Layer 4 and does not provide service mesh capabilities like traffic routing based on HTTP headers, observability with distributed tracing, or mTLS security between services. Option C is wrong because AWS Cloud Map is a service discovery tool that registers service instances and provides DNS-based or API-based resolution, but it does not handle traffic routing, observability, or security policies required for a service mesh. Option D is wrong because Amazon API Gateway with VPC linking is designed for external API management and routing to backend services, not for internal service-to-service communication within a microservices mesh, and it lacks the sidecar proxy model and fine-grained traffic control of a service mesh.

143
MCQmedium

A company is migrating a legacy on-premises application to AWS. The application uses a shared file system that must be accessible from multiple Amazon EC2 instances across two Availability Zones. The file system must provide high throughput and support POSIX permissions. Which AWS service should the company use?

A.Amazon Elastic File System (Amazon EFS)
B.Amazon Elastic Block Store (Amazon EBS) Multi-Attach
C.Amazon FSx for Windows File Server
D.Amazon S3 with mounted file system using s3fs
AnswerA

Amazon EFS is a fully managed, scalable, elastic file system for Linux-based workloads. It supports POSIX permissions and can be mounted on multiple EC2 instances across multiple Availability Zones within a VPC. It provides high throughput and is designed for shared access, making it ideal for this scenario.

Why this answer

Amazon EFS is a shared, POSIX-compliant file system that can be mounted across multiple EC2 instances in multiple Availability Zones. It provides high throughput and is fully managed. FSx for Windows is for Windows workloads, S3 is object storage, and EBS Multi-Attach is limited to a single Availability Zone and is block storage.

Exam trap

The trap here is assuming that EBS Multi-Attach can provide shared file storage across Availability Zones, when it is limited to a single Availability Zone and does not offer a file system interface.

144
MCQhard

A company is migrating a mission-critical application to AWS. The application requires a fixed IP address for whitelisting by external partners. The company plans to use an Application Load Balancer (ALB) to distribute traffic. However, ALB does not support static IP addresses. How can the company meet the requirement for static IP addresses while using the ALB?

A.Replace the ALB with a Network Load Balancer (NLB) that has Elastic IP addresses
B.Use AWS Global Accelerator with the ALB as an endpoint
C.Use Amazon Route 53 with a failover routing policy
D.Assign Elastic IP addresses to the ALB
AnswerB

AWS Global Accelerator provisions two static anycast IPv4 addresses that external partners can whitelist, then forwards traffic to the ALB endpoint without exposing its dynamic node IPs. This satisfies the fixed-IP constraint while retaining ALB's layer 7 routing, and unlike CloudFront it preserves the client's source IP for partner-side filtering.

Why this answer

Using AWS Global Accelerator provides static anycast IP addresses and directs traffic to the ALB, meeting the requirement for fixed IP whitelisting. Option A (replacing with NLB) would avoid the ALB entirely and may not be suitable for application-level traffic. Option C (Route 53 failover) does not provide static IP addresses for whitelisting.

Option D (assigning Elastic IP to ALB) is not supported.

145
MCQeasy

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application stores user-uploaded files in an Amazon S3 bucket. The company wants to improve the security of the application by ensuring that the EC2 instances can access the S3 bucket without embedding long-term AWS credentials in the application code or on the instances. Which solution meets these requirements with the LEAST operational overhead?

A.Generate a pre-signed URL for each file upload using AWS credentials stored in the application, and have the application provide the URL to users.
B.Create an IAM user with programmatic access and an access key, store the credentials in AWS Secrets Manager, and have the application retrieve them at startup.
C.Create an IAM role with the necessary S3 permissions and attach it to the EC2 instances via an instance profile. The application uses the instance metadata service to obtain temporary credentials.
D.Store the S3 bucket credentials in an encrypted Amazon EBS volume attached to each EC2 instance, and have the application read them from the volume.
AnswerC

Attaching an IAM role to EC2 instances via an instance profile provides temporary credentials automatically rotated by AWS. The application can use the AWS SDK to retrieve credentials from the instance metadata service without embedding secrets. This is the least operational overhead because it requires no credential management and follows AWS best practices for secure access.

Why this answer

Attaching an IAM role to EC2 instances via an instance profile allows the application to obtain temporary credentials from the instance metadata service automatically. This eliminates the need to embed or manage long-term credentials, reduces operational overhead, and follows AWS security best practices. The other options either use long-term credentials, require secret management, or do not eliminate credential handling.

Exam trap

The trap here is assuming that storing credentials in Secrets Manager or on an encrypted volume is secure enough, when the best practice is to avoid long-term credentials entirely by using IAM roles.

146
MCQmedium

A company runs a web application on EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application experiences sudden traffic spikes. What is the most effective way to ensure the application can handle the spikes without manual intervention?

A.Use a target tracking scaling policy based on average CPU utilization.
B.Increase the instance size to handle more load per instance.
C.Manually increase the desired capacity when traffic spikes.
D.Use scheduled scaling to add instances at expected peak times.
AnswerA

Target tracking scales automatically as average CPU utilisation rises, adding EC2 capacity during sudden spikes without manual intervention. It satisfies the requirement for hands-off elasticity, unlike scheduled or step policies that need predefined thresholds or timings.

Why this answer

A target tracking scaling policy based on average CPU utilization is the most effective approach because it automatically adjusts the Auto Scaling group's desired capacity in real-time to maintain a target CPU metric (e.g., 50%). This dynamic scaling method responds directly to sudden traffic spikes without any manual intervention, ensuring the application can handle increased load while optimizing cost.

Exam trap

The trap here is that candidates often confuse scheduled scaling (which works only for predictable patterns) with dynamic scaling (which reacts to real-time metrics), leading them to choose D instead of A for handling sudden, unplanned traffic spikes.

How to eliminate wrong answers

Option B is wrong because increasing the instance size (vertical scaling) is a manual, one-time change that does not automatically handle sudden traffic spikes; it also introduces a single point of failure and does not leverage the elasticity of Auto Scaling. Option C is wrong because manually increasing the desired capacity when traffic spikes requires human intervention and real-time monitoring, which defeats the purpose of automated scaling and can lead to delays or errors during spikes. Option D is wrong because scheduled scaling is designed for predictable traffic patterns (e.g., time-of-day peaks) and cannot react to sudden, unplanned traffic spikes; it would either over-provision or under-provision during unexpected events.

147
MCQeasy

A company uses AWS Organizations with consolidated billing. The finance team wants to track costs by department. Each department has its own AWS account. Which feature should be used to map costs to departments?

A.Use cost allocation tags to tag resources with a department tag.
B.Use Amazon CloudWatch custom metrics to record department IDs.
C.Use service control policies (SCPs) to restrict costs per account.
D.Use AWS Budgets to create budgets per department.
AnswerA

Cost allocation tags attach department metadata to resources, and once activated in the billing console they appear as a dimension in Cost Explorer and Cost and Usage Reports, letting finance group spend by department across the linked accounts under consolidated billing.

Why this answer

Cost allocation tags allow you to tag AWS resources with metadata (e.g., department name) and then activate those tags in the AWS Billing and Cost Management console. Once activated, AWS generates cost reports that break down spending by those tags, enabling the finance team to map costs to each department's account. This is the native, recommended approach for cost attribution across accounts in AWS Organizations.

Exam trap

The trap here is that candidates confuse cost allocation tags with AWS Budgets or SCPs, mistakenly thinking that SCPs can limit costs or that Budgets can map costs, when in fact only tags provide the granular, reportable metadata needed for cost attribution.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch custom metrics are designed for monitoring operational performance (e.g., CPU utilization), not for tracking or attributing costs; they cannot be used to generate cost allocation reports. Option C is wrong because service control policies (SCPs) are used to centrally control permissions and enforce guardrails across accounts, not to restrict or track costs; they do not provide cost mapping or reporting capabilities. Option D is wrong because AWS Budgets allow you to set cost thresholds and receive alerts, but they do not provide a mechanism to map historical or granular costs to specific departments; they are a monitoring tool, not a cost attribution feature.

148
MCQhard

A company is modernizing a monolithic Java application by decomposing it into microservices. The application currently uses a single relational database. The company wants to migrate to a microservices architecture on AWS with minimal operational overhead. The microservices must be independently deployable and scalable, and each service should own its data. Which approach should a solutions architect recommend?

A.Use AWS App2Container to containerize the monolith, deploy it on Amazon ECS, and keep the monolithic database.
B.Decompose the application into microservices using AWS Fargate, and give each microservice its own Amazon DynamoDB table.
C.Refactor the application into AWS Lambda functions, and use a single Amazon Aurora database shared by all functions.
D.Migrate the application to AWS Elastic Beanstalk, and use Amazon RDS with read replicas for scaling.
AnswerB

AWS Fargate provides serverless compute for containers, reducing operational overhead. Decomposing the application into microservices aligns with independent deployability and scalability. Giving each microservice its own DynamoDB table follows the database-per-service pattern, enabling each service to own its data. This combination meets all requirements with minimal management.

Why this answer

Decomposing the monolith into microservices on AWS Fargate reduces operational overhead because Fargate manages the underlying compute. Each microservice having its own DynamoDB table implements the database-per-service pattern, ensuring independent data ownership and scalability. This architecture supports independent deployment and scaling, aligning with microservices best practices.

Exam trap

The trap here is assuming that containerizing a monolith or using serverless functions with a shared database constitutes a microservices architecture, when true microservices require independent data stores and deployment lifecycles.

149
MCQeasy

A company uses Amazon S3 to store sensitive data. The security team requires that all objects be encrypted at rest. The company currently uses server-side encryption with S3-managed keys (SSE-S3). The security team wants to ensure that only authorized users can access the decryption keys. What should the company do?

A.Configure an S3 bucket policy to allow only specific IAM roles to put objects.
B.Continue using SSE-S3 and enable S3 Block Public Access.
C.Use client-side encryption with an AWS KMS key.
D.Change the default encryption to server-side encryption with AWS KMS (SSE-KMS) and apply IAM policies to control key usage.
AnswerD

SSE-KMS encrypts objects with AWS KMS keys, and IAM policies on those keys restrict which principals may decrypt. This replaces S3-managed keys, where key access cannot be scoped to authorised users, meeting the stated requirement.

Why this answer

SSE-KMS encrypts objects with keys managed in AWS KMS, and access to those keys is governed by IAM policies and KMS key policies. This satisfies the requirement that only authorized users can access decryption keys, because KMS enforces key-level permissions separately from S3 bucket access. SSE-S3 uses AWS-managed keys that customers cannot control or restrict per-user.

Exam trap

SAP-C02 often tests the misconception that bucket policies or Block Public Access control encryption key access — they control object access, not KMS key usage, which requires IAM/KMS key policies.

How to eliminate wrong answers

Option A is wrong because a bucket policy controlling who can PutObject does not restrict access to the encryption keys — SSE-S3 keys are fully AWS-managed and not subject to customer IAM control. Option B is wrong because SSE-S3 with Block Public Access still leaves keys entirely under AWS control with no way to restrict decryption to specific users. Option C is wrong because client-side encryption with a KMS key is not the standard server-side approach the question asks for, and it shifts encryption responsibility to the application rather than configuring S3 default encryption.

150
MCQhard

A company has a multi-account AWS environment with a central network account that hosts a shared AWS Transit Gateway. The company wants to implement a hub-and-spoke network topology where all inter-VPC traffic between workload VPCs must be inspected by a central security VPC before reaching its destination. The security VPC contains an AWS Network Firewall. The company needs to ensure that traffic between any two workload VPCs is routed through the security VPC. Which configuration should a solutions architect implement?

A.Create a single Transit Gateway route table, associate all workload VPC attachments and the security VPC attachment with it, and propagate all attachments. Configure the security VPC attachment as the default route for all traffic.
B.Use AWS Resource Access Manager to share the Transit Gateway with all workload accounts. Configure each workload VPC to have a route to the security VPC's CIDR through a peering connection, and use the Transit Gateway for all other traffic.
C.Create two Transit Gateway route tables: one for workload VPCs and one for the security VPC. Associate each workload VPC attachment with the workload route table and propagate the security VPC attachment into it. Associate the security VPC attachment with the security route table and propagate all workload VPC attachments into it. Configure the workload route table to have a default route to the security VPC attachment.
D.Create a separate Transit Gateway route table for each workload VPC, associate the VPC attachment with its own route table, and propagate all other workload VPC attachments into that route table. Configure the security VPC attachment to be the next hop for all traffic.
AnswerC

This configuration isolates workload VPCs from each other by placing them in a route table that only has routes to the security VPC (via propagation of the security attachment) and a default route to the security VPC. The security VPC route table has routes to all workload VPCs, allowing return traffic. This forces all inter-VPC traffic through the security VPC for inspection.

Why this answer

To force all inter-VPC traffic through a central security VPC, you must prevent direct routing between workload VPCs on the Transit Gateway. Using separate route tables for workload and security attachments, with the workload route table having only a default route to the security VPC, ensures that all traffic from a workload VPC goes to the security VPC first. The security VPC route table then routes to the destination workload VPC.

Exam trap

The trap here is assuming that a single Transit Gateway route table with a default route to the security VPC will force all traffic through it, when propagated routes create more specific paths that bypass the default.

Page 1

Page 2 of 14

Page 3