Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 151–225

984 questions total · 14pages · All types, answers revealed

Page 2

Page 3 of 14

Page 4
151
MCQmedium

A social media startup uses AWS Lambda functions to process user-uploaded images. The Lambda function resizes images and stores them in Amazon S3. The function uses the S3 SDK to put objects. Recently, the team noticed that the function sometimes fails with 'Timeout' errors for large images. The Lambda function has a timeout of 5 seconds and 256 MB of memory. The team wants to improve the solution to handle larger images reliably and cost-effectively. Which solution should the team implement?

A.Migrate the image processing to a dedicated Amazon EC2 instance with an EBS volume.
B.Increase the Lambda function's timeout to 15 minutes and allocate more memory (e.g., 1024 MB).
C.Use Amazon API Gateway with a larger payload limit to offload the image processing.
D.Use AWS Elastic Transcoder to resize images instead of Lambda.
AnswerB

More memory and timeout allow processing larger images within Lambda limits.

Why this answer

(increase memory and timeout) directly addresses the issue: increasing memory also increases CPU and network throughput, which helps process large images faster; increasing timeout gives more time. Option A (EC2 with EBS) is overkill and not serverless, losing the benefits of Lambda. Option C (API Gateway with larger payload) does not help with Lambda's internal processing limits.

Option D (Elastic Transcoder) is for video transcoding, not image resizing.

152
MCQmedium

A company runs a two-tier web application on Amazon EC2 instances behind an Application Load Balancer. The database tier is Amazon RDS for MySQL with a single Availability Zone deployment. The company requires a recovery point objective (RPO) of 5 minutes and a recovery time objective (RTO) of 2 hours. The database is 500 GB. Which solution should a solutions architect recommend to meet these requirements MOST cost-effectively?

A.Configure a Multi-AZ deployment for the RDS instance, which maintains a synchronous standby in another Availability Zone.
B.Create a read replica in a second Availability Zone and promote it manually if the primary fails.
C.Use AWS Database Migration Service (DMS) with change data capture to continuously replicate to an EC2-based MySQL instance, and fail over by repointing the application.
D.Enable automated backups with a 5-minute backup window and restore from the latest snapshot during a failover.
AnswerA

Multi-AZ for RDS maintains a synchronous standby replica in a different Availability Zone. Failover typically completes in 60–120 seconds, well within the 2-hour RTO, and because replication is synchronous, RPO is effectively zero. It also provides high availability without the cost and operational overhead of read replicas or custom replication. This is the most cost-effective solution that meets both RPO and RTO.

Why this answer

A Multi-AZ deployment maintains a synchronous standby that is automatically promoted on failure, providing near-zero RPO and failover in minutes, which satisfies both the 5-minute RPO and 2-hour RTO. Automated backups alone cannot meet the RTO because restore times are lengthy. Read replicas are asynchronous and require manual promotion, risking RPO and RTO.

DMS adds unnecessary complexity and cost.

Exam trap

The trap here is assuming that automated backups with frequent transaction logs provide fast recovery, when in fact restoring a snapshot can take hours and does not meet a tight RTO.

153
MCQhard

A company is migrating a legacy application to AWS using the rehost (lift-and-shift) strategy. The application uses a proprietary database that is not supported by Amazon RDS. The company wants to automate the migration of multiple servers and minimize downtime. Which AWS service should be used to automate the server migration?

A.AWS CloudFormation to recreate the server configuration.
B.AWS Application Migration Service (AWS MGN).
C.AWS Server Migration Service (SMS).
D.AWS Database Migration Service (AWS DMS) for the database and manual server migration.
AnswerB

AWS Application Migration Service performs block-level replication of source servers into AWS, automating lift-and-shift for multiple machines with continuous replication that minimises cutover downtime. This satisfies both the rehost strategy and the unsupported proprietary database constraint, since the database travels with the server rather than needing RDS compatibility.

Why this answer

AWS Application Migration Service (MGN) automates lift-and-shift with minimal downtime. Option A is wrong because AWS CloudFormation is for infrastructure provisioning, not migration. Option C is wrong because AWS Server Migration Service (SMS) is older and less automated compared to MGN.

Option D is wrong because AWS Database Migration Service (DMS) is for databases, not servers.

154
Multi-Selectmedium

A company is using Amazon S3 to store sensitive data. The security team wants to ensure that all objects uploaded to specific S3 buckets are encrypted at rest. Which TWO actions should they take? (Choose 2)

Select 2 answers
A.Use a bucket policy that denies PutObject without the x-amz-server-side-encryption header.
B.Configure default encryption on the S3 buckets to use SSE-S3 or SSE-KMS.
C.Enable S3 Cross-Region Replication.
D.Enable S3 Versioning on the buckets.
E.Enable S3 Server Access Logs.
AnswersA, B

A bucket policy denying PutObject requests that lack the x-amz-server-side-encryption header enforces encryption at upload time, satisfying the requirement that all objects in the specified buckets be encrypted at rest. This blocks unencrypted PUTs before any object is written, rather than merely detecting them afterwards.

Why this answer

Option A is correct because a bucket policy with a Deny effect on s3:PutObject conditioned on the absence of the s3:x-amz-server-side-encryption header (or Null condition on that key) forces every uploader to explicitly request server-side encryption, preventing unencrypted PUT requests. Option B is correct because configuring default bucket encryption with SSE-S3 (AES-256) or SSE-KMS automatically encrypts objects at rest even when the request does not include an encryption header, providing a baseline guarantee for all uploaded data. Option C is not relevant because Cross-Region Replication only copies objects to another bucket and does not enforce encryption at rest on the source bucket.

Option D is not relevant because Versioning preserves multiple object versions but does not itself encrypt data. Option E is not relevant because Server Access Logs record request activity for auditing, not encryption enforcement.

155
MCQeasy

A company is migrating a legacy on-premises application to AWS. The application uses a monolithic architecture and a self-managed MySQL database. The company wants to reduce operational overhead and improve scalability with minimal application changes. A solutions architect needs to recommend a migration path for the database. Which AWS service should the solutions architect use?

A.Amazon Aurora MySQL-Compatible Edition
B.Amazon RDS for MySQL
C.Amazon DynamoDB
D.Amazon Redshift
AnswerB

Amazon RDS for MySQL is a managed relational database service that is compatible with MySQL. It handles provisioning, patching, backups, and Multi-AZ replication, reducing operational overhead. Because the application already uses MySQL, migrating to RDS for MySQL requires minimal application changes; often only the connection string needs updating. This aligns with the goal of reducing operational overhead while preserving compatibility and improving scalability.

Why this answer

Amazon RDS for MySQL provides a managed MySQL-compatible database that minimizes operational tasks such as patching, backups, and replication. Because the application already uses MySQL, the migration can be as simple as using AWS Database Migration Service to replicate the data and then updating the application's connection string. This meets the goals of reducing operational overhead and improving scalability without requiring application rewrites.

Other services either use different data models or are optimized for analytics rather than transactions.

Exam trap

The trap here is over-engineering by choosing Amazon Aurora when a simpler managed MySQL service like Amazon RDS for MySQL is sufficient, or mistakenly selecting a NoSQL or data warehouse service.

156
MCQeasy

A company is designing a new application that will process sensitive financial transactions. The application must be deployed in a VPC with no public internet access. The application needs to send logs to Amazon CloudWatch Logs and store files in Amazon S3. Which set of actions should be taken to meet these requirements without allowing internet access?

A.Create a Gateway VPC endpoint for S3 and an Interface VPC endpoint for CloudWatch Logs
B.Place the application behind a public Application Load Balancer
C.Set up a NAT gateway in a public subnet and route traffic through it
D.Use AWS PrivateLink to connect to CloudWatch Logs and S3
AnswerA

Gateway VPC endpoints route S3 traffic privately over the AWS network, while Interface VPC endpoints (powered by AWS PrivateLink) provide private connectivity to CloudWatch Logs. Together they satisfy the no-public-internet constraint for both logging and object storage.

Why this answer

A Gateway VPC endpoint for S3 allows private connectivity to S3 without traversing the internet, using route table entries. An Interface VPC endpoint for CloudWatch Logs, powered by AWS PrivateLink, enables private HTTPS connections to the CloudWatch Logs API without requiring a NAT gateway or internet gateway. Together, these endpoints satisfy the requirement for a VPC with no public internet access.

Exam trap

The trap here is that candidates often assume AWS PrivateLink can be used for both S3 and CloudWatch Logs uniformly, but S3 primarily uses Gateway VPC endpoints (not Interface endpoints) for private access, and PrivateLink is the mechanism for Interface endpoints only.

How to eliminate wrong answers

Option B is wrong because placing the application behind a public Application Load Balancer requires the ALB to have public internet access, which violates the 'no public internet access' requirement. Option C is wrong because a NAT gateway in a public subnet still requires an internet gateway for outbound traffic, and the application would need a route to the NAT gateway, which ultimately uses the internet; this does not meet the 'no internet access' condition. Option D is wrong because AWS PrivateLink is the underlying technology for Interface VPC endpoints, but it cannot be used directly for S3; S3 requires a Gateway VPC endpoint (or an Interface endpoint with a different configuration), and PrivateLink alone does not provide the correct connectivity for S3 without additional setup.

157
MCQhard

A company is migrating its on-premises data center to AWS. The company has over 200 applications, each with varying dependencies. The migration team wants to use AWS Migration Hub to track the migration progress. Which approach should the team take to ensure successful tracking and minimize manual effort?

A.Use Amazon CloudWatch dashboards to monitor the health of on-premises servers.
B.Use AWS Systems Manager to automate the migration of each application.
C.Use AWS Application Discovery Service to discover dependencies and then use AWS Migration Hub to track the migration of each application.
D.Manually create a spreadsheet of all applications and their dependencies, and update it weekly.
AnswerC

Application Discovery Service agentless and agent-based collection maps server dependencies automatically, feeding that inventory into Migration Hub. This satisfies the minimise-manual-effort constraint across 200 applications, since Migration Hub can then track each application's migration status without hand-built dependency records.

Why this answer

AWS Application Discovery Service automatically discovers on-premises servers and their dependencies, and its data feeds directly into AWS Migration Hub, which tracks migration status across applications. This combination minimizes manual effort and gives accurate dependency mapping for 200+ applications.

Exam trap

SAP-C02 often tests whether candidates choose manual tracking or generic monitoring tools instead of the Application Discovery Service plus Migration Hub pairing that automates dependency discovery and progress tracking.

How to eliminate wrong answers

Option A is wrong because CloudWatch dashboards monitor AWS resources, not on-premises server health or migration progress, and don't feed Migration Hub. Option B is wrong because Systems Manager automates management tasks on AWS/on-premises nodes but does not discover dependencies or track migration status in Migration Hub. Option D is wrong because manually maintaining a spreadsheet is exactly the high-effort, error-prone approach the team wants to avoid and does not integrate with Migration Hub.

158
MCQmedium

A company is migrating a critical application to AWS. The application requires a relational database with high availability and automated failover. The company wants to use a fully managed database service. Which AWS service should the architect choose?

A.Amazon RDS Multi-AZ
B.Amazon ElastiCache
C.Amazon DynamoDB
D.Amazon RDS Single-AZ
AnswerA

Amazon RDS Multi-AZ maintains a synchronous standby replica in a second Availability Zone and automatically promotes it during failure, giving the required high availability and automated failover. RDS is fully managed, handling patching, backups and instance replacement.

Why this answer

Amazon RDS Multi-AZ provides a fully managed relational database with synchronous replication to a standby instance in a different Availability Zone and automatic failover, meeting the high availability and automated failover requirements. It is the correct choice for a relational workload needing managed HA.

Exam trap

SAP-C02 often tests whether candidates confuse Multi-AZ (HA/failover) with read replicas (read scaling) — Multi-AZ is for availability, not performance, and Single-AZ is never the answer when automated failover is required.

How to eliminate wrong answers

Option B is wrong because Amazon ElastiCache is an in-memory caching service (Redis or Memcached), not a relational database, and does not provide durable relational storage. Option C is wrong because Amazon DynamoDB is a NoSQL key-value/document database, not relational, and does not support SQL or relational schemas. Option D is wrong because RDS Single-AZ has no standby and no automated failover — if the AZ fails, the database is unavailable until manual recovery, so it fails the HA requirement.

159
MCQeasy

A startup is building a serverless application using AWS Lambda. They need to securely store and retrieve database credentials without hardcoding them in the function code. Which AWS service should they use?

A.Amazon DynamoDB
B.AWS Secrets Manager
C.AWS Identity and Access Management (IAM)
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager stores credentials outside the function code and retrieves them at runtime via IAM-scoped API calls, with built-in rotation. This satisfies the no-hardcoding constraint by removing static credentials from Lambda deployment packages and environment variables.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, rotating, and retrieving database credentials and other secrets throughout their lifecycle. It integrates natively with Lambda via the AWS SDK, allowing retrieval of credentials at runtime without hardcoding, and supports automatic rotation of secrets for supported databases like Amazon RDS.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks native automatic rotation and is not designed as a full lifecycle secrets management service, making Secrets Manager the correct answer for database credential rotation requirements.

How to eliminate wrong answers

Option A is wrong because Amazon DynamoDB is a NoSQL database service designed for storing application data, not for securely managing secrets; storing credentials in DynamoDB would require you to manage encryption and access control manually, and it lacks built-in secret rotation. Option C is wrong because AWS Identity and Access Management (IAM) is used for managing permissions and access to AWS resources, not for storing secrets; while IAM roles can grant Lambda permissions to access Secrets Manager, IAM itself cannot store or retrieve credential values. Option D is wrong because AWS Systems Manager Parameter Store can store secrets as SecureString parameters, but it does not natively support automatic rotation of database credentials, which is a key requirement for securely managing credentials over time.

160
MCQmedium

A company is migrating a legacy application that uses a third-party identity provider (IdP) for authentication. The application currently uses SAML 2.0. The company wants to use AWS IAM Identity Center for centralized access management. What is the best approach to integrate the IdP with AWS?

A.Use AWS Directory Service for Microsoft Active Directory to synchronize with the IdP
B.Create IAM users for each employee and assign groups and permissions
C.Configure IAM Identity Center to use the existing IdP as the identity source via SAML 2.0 federation
D.Use Amazon Cognito user pools with the IdP as a SAML identity provider
AnswerC

IAM Identity Center can consume the existing IdP as its identity source through SAML 2.0 federation, so users authenticate against the third-party IdP while Identity Center handles centralised AWS access assignment. This preserves the current SAML 2.0 investment.

Why this answer

AWS IAM Identity Center supports SAML 2.0 federation with external identity providers (IdPs). This allows centralized access management without duplicating identities. Option A is incorrect because AWS Directory Service for Microsoft AD is for Active Directory synchronization, not generic SAML federation.

Option B is incorrect because creating IAM users for every employee would duplicate identities and increase administrative overhead. Option D is incorrect because Amazon Cognito user pools are designed for customer-facing applications, not for enterprise SSO with existing IdPs.

161
MCQeasy

A company is using Amazon ECS with Fargate launch type for a microservices application. The application experiences intermittent latency spikes. CloudWatch metrics show high CPU utilization but no obvious pattern. What should the company do to identify the cause?

A.Increase the CPU and memory for all ECS tasks.
B.Enable AWS X-Ray tracing on the ECS tasks to trace requests across microservices.
C.Set up CloudWatch Synthetics canaries to monitor the endpoints.
D.Use CloudWatch Logs Insights to analyze application logs for errors.
AnswerB

AWS X-Ray traces individual requests across microservices, exposing where latency accumulates within the call path rather than just aggregate CPU metrics. Since CloudWatch shows high CPU utilisation without an obvious pattern, X-Ray's per-request service map and segment timings pinpoint the specific downstream call or task causing intermittent spikes.

Why this answer

AWS X-Ray provides distributed tracing to pinpoint performance bottlenecks. Option A is wrong because increasing task size is a reactive fix that does not identify the cause. Option C is wrong because CloudWatch Synthetics monitors endpoint availability, not internal trace data.

Option D is wrong because CloudWatch Logs Insights is for querying logs, not for tracing requests across microservices.

162
MCQmedium

A company is migrating a high-traffic web application from on-premises to AWS. The application uses a MySQL database and stores session state on the web servers. The company wants to ensure that the application can scale horizontally and that users are not logged out when new web servers are added. Which migration strategy should be used for the session state?

A.Use sticky sessions on the Application Load Balancer to ensure that each user is directed to the same web server.
B.Migrate the session state to Amazon ElastiCache for Redis and configure the application to use it as a session store.
C.Store session state in an Amazon RDS for MySQL database with a multi-AZ deployment.
D.Use Amazon S3 to store session state as objects and have the application retrieve them on each request.
AnswerB

Amazon ElastiCache for Redis provides a highly available, in-memory data store that can be used to externalize session state. By storing sessions in ElastiCache, any web server can access the session data, enabling horizontal scaling without losing user sessions. This is a common pattern for modernizing applications to be stateless and scalable.

Why this answer

Migrating session state to Amazon ElastiCache for Redis is the best strategy because it externalizes session data, allowing any web server to handle requests for any user. This enables horizontal scaling and ensures that user sessions are not lost when new servers are added. Other options either do not scale well or introduce latency and complexity.

Exam trap

The trap here is thinking that sticky sessions solve the scaling issue, but they actually hinder horizontal scaling and do not prevent session loss if a server fails.

163
MCQmedium

A company is migrating a large-scale e-commerce platform from on-premises to AWS. The migration plan includes rehosting the application servers and replatforming the database to Amazon Aurora. The company needs to ensure minimal downtime during the cutover. Which strategy should the company use for the database migration?

A.Use AWS DMS with a full load and ongoing replication to keep the target synchronized
B.Use AWS DMS with a full load only, then cut over
C.Use an application-level dual-write to both databases during the cutover
D.Take a snapshot of the on-premises database and restore it to Amazon Aurora
AnswerA

AWS DMS full load plus ongoing change data capture replicates ongoing transactions continuously, so the Aurora target stays synchronised until cutover. This directly satisfies the minimal-downtime requirement, since the switch happens only after replication lag reaches near zero.

Why this answer

AWS DMS with a full load and ongoing replication (change data capture) keeps the target Aurora database synchronized with the source during the migration. This allows minimal downtime because the cutover only requires stopping writes to the source and letting DMS apply the final changes, then redirecting the application to Aurora. This is the standard strategy for minimal-downtime database migrations.

Exam trap

SAP-C02 often tests the misconception that a full load alone is sufficient for minimal downtime, ignoring the need for ongoing replication to capture changes during the migration.

How to eliminate wrong answers

Option B is wrong because a full load only does not capture changes made during the load, so any writes after the load start would be lost, causing data inconsistency and requiring downtime. Option C is wrong because application-level dual-write is complex, error-prone, and not a recommended AWS migration strategy; it also requires application changes. Option D is wrong because a snapshot and restore causes significant downtime as the snapshot must be taken, transferred, and restored, and any changes after the snapshot are lost.

164
MCQhard

A company has an IAM policy attached to a user as shown in the exhibit. The user is trying to stop an EC2 instance in the us-west-2 region. What will happen?

A.The user cannot stop the instance because the condition checks the request region.
B.The user cannot stop the instance because the second statement denies all actions in regions other than us-east-1.
C.The user can stop the instance because the first statement allows it.
D.The user can stop the instance because the condition applies only to the Deny statement, but the Allow statement is unconditional.
AnswerB

The second statement's explicit Deny overrides the first statement's Allow, since an explicit deny always wins in IAM policy evaluation. Because the condition restricts permitted actions to us-east-1, the stop request in us-west-2 falls outside that scope and is blocked by the deny.

Why this answer

IAM policy evaluation follows an explicit deny model: any explicit deny overrides any allow. The second statement uses a `Deny` effect with a `StringNotEquals` condition on `aws:RequestedRegion`, which denies all actions (including ec2:StopInstances) when the request region is NOT us-east-1. Since the user is attempting to stop an EC2 instance in us-west-2, the condition evaluates to true, and the deny applies, blocking the action regardless of the first statement's allow.

Exam trap

The trap here is that candidates often assume an unconditional Allow always wins, but they forget that an explicit Deny with a condition that matches the request will override that Allow, leading them to incorrectly choose Option D.

How to eliminate wrong answers

Option A is wrong because the condition does not check the request region in a vacuum; it is part of a Deny statement that explicitly blocks actions when the region is not us-east-1, so the user cannot stop the instance due to the deny, not because of a generic region check. Option C is wrong because while the first statement allows ec2:StopInstances, the second statement's explicit deny overrides that allow, making the action impossible. Option D is wrong because the condition applies to the Deny statement, and the Allow statement is unconditional, but in IAM, an explicit deny always overrides an allow, so the unconditional allow does not help when a deny is triggered.

165
MCQmedium

A company is designing a new microservices architecture on AWS. They need a solution for service discovery that allows services to register themselves and discover other services dynamically. The solution must be highly available and integrated with AWS-native services. Which AWS service should they use?

A.Amazon ECS Service Discovery
B.Application Load Balancer (ALB)
C.AWS Cloud Map
D.Amazon Route 53 private hosted zones
AnswerC

AWS Cloud Map provides service discovery where instances register themselves via API and consumers resolve them dynamically through DNS or HTTP. It is fully AWS-native, highly available across Regions, and integrates with ECS, EKS and Lambda, meeting the dynamic registration requirement.

Why this answer

AWS Cloud Map is the correct choice because it is a fully managed service discovery service that allows microservices to register themselves dynamically and discover other services via DNS or HTTP API calls. It integrates natively with AWS services like Amazon ECS, Amazon EKS, and AWS Lambda, and provides high availability through automatic health checking and resource synchronization across AWS Regions.

Exam trap

The trap here is that candidates often confuse Amazon ECS Service Discovery (Option A) as a separate service, when it is actually a feature of AWS Cloud Map, leading them to overlook Cloud Map as the correct, standalone service for dynamic service discovery.

How to eliminate wrong answers

Option A is wrong because Amazon ECS Service Discovery is not a standalone service; it is a feature of AWS Cloud Map that is exposed through Amazon ECS, and it lacks the broader API-based discovery and health-check integration that Cloud Map provides. Option B is wrong because an Application Load Balancer (ALB) is a Layer 7 load balancer that distributes traffic to targets, not a service registry for dynamic service-to-service discovery; it does not support service registration or DNS-based discovery for internal microservices. Option D is wrong because Amazon Route 53 private hosted zones provide DNS resolution within a VPC but do not support dynamic service registration, health checking, or API-based discovery; they are a static DNS solution, not a service discovery registry.

166
MCQmedium

A company is migrating a legacy on-premises .NET application to AWS. The application uses Windows Authentication and relies on Active Directory. The company wants to minimize code changes. Which solution should the architect recommend?

A.Use AWS Systems Manager to store credentials and inject them at runtime.
B.Migrate the application to Amazon WorkDocs and configure single sign-on.
C.Use Amazon Cognito user pools for authentication.
D.Deploy the application on Amazon EC2 instances joined to an AWS Managed Microsoft AD directory.
AnswerD

Joining EC2 instances to AWS Managed Microsoft AD lets the .NET application continue using Windows Authentication and Kerberos against a managed domain, so no code changes are needed. This satisfies the minimise-code-changes constraint while retaining Active Directory integration.

Why this answer

AWS Managed Microsoft AD is a fully managed Active Directory service in AWS that supports domain join for EC2 instances. By joining the EC2 instances to the directory, the legacy .NET application can continue using Windows Authentication (Kerberos/NTLM) without code changes. This preserves the existing authentication mechanism and minimizes migration effort.

Exam trap

SAP-C02 often tests the misconception that AWS identity services like Cognito or IAM can replace Active Directory for Windows Authentication, but they cannot; the key is recognizing that legacy Windows Authentication requires an actual AD domain, and AWS Managed Microsoft AD is the managed solution for that.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store or Secrets Manager is for storing and retrieving secrets, not for providing Windows Authentication or Active Directory integration; injecting credentials at runtime would require code changes and does not replicate AD-based authentication. Option B is wrong because Amazon WorkDocs is a document collaboration service, not an application hosting platform, and configuring SSO does not provide Windows Authentication for a .NET application. Option C is wrong because Amazon Cognito user pools are for customer identity and access management (CIAM) for web and mobile apps, not for Windows Authentication or Active Directory domain authentication; using Cognito would require significant code changes to integrate with the .NET application.

167
MCQhard

A company is designing a new application that will use Amazon DynamoDB. The application requires strongly consistent reads and must handle a sudden spike in read traffic that could exceed the provisioned read capacity. The company wants to ensure that the application continues to perform well without manual intervention. The table is currently provisioned with 100 read capacity units (RCUs). The workload is unpredictable but expected to grow. What should a solutions architect recommend to meet these requirements?

A.Enable DynamoDB Accelerator (DAX) for the table and use strongly consistent reads.
B.Increase the provisioned read capacity to a high fixed value, such as 10,000 RCUs, and enable auto scaling.
C.Create a global secondary index (GSI) with eventually consistent reads and direct read traffic to the GSI.
D.Switch the table to on-demand capacity mode.
AnswerD

On-demand capacity mode automatically scales to handle sudden spikes in traffic without manual intervention. It supports strongly consistent reads, and you pay per request. This meets the requirements for unpredictable workloads and eliminates the need to manage capacity, ensuring performance during spikes.

Why this answer

DynamoDB on-demand capacity mode is designed for unpredictable workloads and automatically scales read and write capacity to handle traffic spikes without manual intervention. It supports strongly consistent reads, so it meets the consistency requirement. This mode eliminates the need to provision or manage capacity, providing seamless performance during sudden spikes.

Exam trap

The trap here is assuming that DAX can be used with strongly consistent reads, when in fact DAX only supports eventually consistent reads, making it unsuitable for this scenario.

168
MCQmedium

A media company is designing a new video processing pipeline. The pipeline must ingest large video files uploaded to Amazon S3, process them using AWS Lambda, and store the output in another S3 bucket. The processing time can vary from a few seconds to over 15 minutes. The company wants a fully serverless, cost-effective solution that can handle sudden spikes in uploads. Which solution should a solutions architect recommend?

A.Configure S3 event notifications to invoke an AWS Lambda function that starts an Amazon ECS task on AWS Fargate to process the video.
B.Configure an S3 event notification to trigger a Lambda function directly for each uploaded video file.
C.Use an S3 event notification to send a message to an Amazon SQS queue, then have a Lambda function poll the queue and start an AWS Step Functions state machine to process the video.
D.Use an S3 event notification to trigger an AWS Glue job that processes the video and writes the output to S3.
AnswerC

This decouples ingestion from processing, allowing the Lambda function to quickly enqueue jobs. Step Functions can orchestrate long-running tasks, including those exceeding 15 minutes, by using activities or Lambda functions with retries. It handles spikes via SQS buffering and is fully serverless, providing cost-effective scaling.

Why this answer

The pipeline requires handling variable processing times, including jobs exceeding 15 minutes, and sudden spikes. Using S3 event notifications to enqueue messages in SQS decouples ingestion from processing, and a Lambda function can poll the queue and start a Step Functions state machine. Step Functions can orchestrate long-running workflows and is fully serverless, scaling automatically with demand.

Exam trap

The trap here is assuming Lambda can handle any processing duration; Lambda has a hard 15-minute timeout, so long-running video processing must be offloaded to a service like Step Functions or ECS.

169
MCQmedium

A migration engineer is using AWS Application Migration Service (MGN) to migrate a Windows server from on-premises. The engineer runs the command above and sees the source server is in the "READY_FOR_TEST" state. What should the engineer do next?

A.Launch a test instance to validate the migration
B.Perform the cutover to the AWS environment
C.Modify the source server's recommended instance type to a smaller size
D.Resume data replication from the source server
AnswerA

From READY_FOR_TEST, MGN has completed initial replication and the staging area holds a bootable snapshot, so the next step is launching a test instance to validate the migrated Windows server before cutover. Testing confirms boot, drivers and applications without affecting the source, satisfying the stem's validation requirement prior to final launch.

Why this answer

When a source server is in the READY_FOR_TEST state in AWS Application Migration Service (MGN), it means the initial replication has completed and the server is ready for a test launch. The next step is to launch a test instance to validate that the migrated server functions correctly in AWS before performing the actual cutover. This test launch does not affect the source server or the cutover process.

Exam trap

SAP-C02 often tests the misconception that READY_FOR_TEST means you should immediately cut over, when the correct next step is to launch a test instance for validation.

How to eliminate wrong answers

Option B is wrong because performing the cutover should only happen after a successful test launch and validation; cutting over without testing risks production issues. Option C is wrong because modifying the recommended instance type is not the immediate next step and should be done based on test performance, not before testing. Option D is wrong because data replication is already complete and ongoing; resuming replication is not applicable when the server is ready for test.

170
MCQmedium

A company is designing a new application on AWS that requires a relational database with read replicas across multiple AWS Regions. The database must have automated failover and a recovery point objective (RPO) of less than 5 seconds. Which database solution should the company choose?

A.Amazon Aurora Global Database
B.Amazon RDS for MySQL with Multi-AZ and cross-Region read replicas
C.Amazon RDS for PostgreSQL with cross-Region read replicas and Multi-AZ
D.Amazon DynamoDB Global Tables
AnswerA

Aurora Global Database replicates at the storage layer with a typical cross-Region lag under one second, comfortably meeting the sub-5-second RPO. It also provides managed failover, promoting a secondary Region to primary in under a minute, satisfying the automated failover and multi-Region read replica requirements.

Why this answer

Amazon Aurora Global Database is the correct choice because it is designed for cross-Region replication with a typical RPO of less than 1 second and automated failover from the primary Region to a secondary Region in under 1 minute. This meets the requirement for a relational database with read replicas across multiple Regions and an RPO of less than 5 seconds, as Aurora Global Database uses a dedicated, fast replication channel that minimizes lag.

Exam trap

The trap here is that candidates often confuse Multi-AZ failover (which is Region-bound) with cross-Region failover, or they assume that RDS cross-Region read replicas can achieve the same low RPO as Aurora Global Database, but RDS cross-Region replication is asynchronous and cannot guarantee sub-5-second RPO.

How to eliminate wrong answers

Option B is wrong because Amazon RDS for MySQL with Multi-AZ and cross-Region read replicas uses asynchronous replication for cross-Region replicas, which can introduce replication lag exceeding 5 seconds, and Multi-AZ only provides automated failover within a single Region, not across Regions. Option C is wrong because Amazon RDS for PostgreSQL with cross-Region read replicas and Multi-AZ also relies on asynchronous replication for cross-Region copies, which cannot guarantee an RPO of less than 5 seconds, and Multi-AZ failover is limited to the same Region. Option D is wrong because Amazon DynamoDB Global Tables is a NoSQL database, not a relational database, and the question explicitly requires a relational database solution.

171
MCQmedium

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in a self-managed Redis cluster on a single EC2 instance. During a recent load test, the Redis instance became a bottleneck, causing session timeouts and degraded performance. The company wants to improve the scalability and availability of the session store while minimizing application changes. Which solution meets these requirements?

A.Deploy a second Redis instance on another EC2 instance and configure the application to use both instances with client-side sharding.
B.Replace the Redis cluster with an Amazon RDS for MySQL Multi-AZ database and store sessions in a table.
C.Enable sticky sessions on the Application Load Balancer and continue using the single Redis instance.
D.Migrate the session store to Amazon ElastiCache for Redis with cluster mode enabled and multiple shards.
AnswerD

ElastiCache for Redis with cluster mode enabled provides horizontal scaling and high availability across multiple shards, eliminating the single-instance bottleneck. The application can use the Redis cluster endpoint with minimal changes, as the Redis protocol remains the same. This directly addresses scalability and availability requirements.

Why this answer

ElastiCache for Redis with cluster mode enabled offers a managed, scalable, and highly available session store that integrates with existing Redis clients. It removes the single-instance bottleneck by distributing data across shards and provides automatic failover. Other options either require extensive application changes or do not address scalability and availability.

Exam trap

The trap here is assuming that sticky sessions or a second Redis instance can solve the scalability and availability issues without application changes.

172
MCQmedium

An ALB is configured with a target group for HTTP:80. The health check returns a 302 redirect. What is the most likely cause of the unhealthy instances?

A.The application is returning a 500 Internal Server Error.
B.The application is taking too long to respond.
C.The security group is blocking health check traffic.
D.The application is redirecting health checks to another URL.
AnswerD

The ALB health check expects a 200 response; a 302 indicates the application redirects the health check path elsewhere, so the target never returns success and is marked unhealthy. The redirect, not the target itself, causes the failure.

Why this answer

The ALB health check expects a 200 OK response from the target. A 302 redirect indicates the application is responding with a redirect (e.g., HTTP to HTTPS or to a login page) instead of a success status. This causes the health check to fail because the ALB does not follow redirects for health checks; it only accepts the configured success codes (default 200).

Exam trap

The trap here is that candidates may assume a redirect is harmless or that the ALB will follow it, but the ALB strictly evaluates the first response status code against the configured success codes, and a 302 is not a success by default.

How to eliminate wrong answers

Option A is wrong because a 500 Internal Server Error would produce a 5xx status, not a 302 redirect. Option B is wrong because a timeout would result in a 504 Gateway Timeout or no response, not a 302 redirect. Option C is wrong because if the security group were blocking health check traffic, the ALB would receive no response (connection timeout or refused), not a 302 redirect.

173
MCQhard

Refer to the exhibit. A solutions architect has attached this IAM policy to an IAM role used by an application. The application is trying to upload an object to the S3 bucket example-bucket with server-side encryption using AWS KMS (SSE-KMS). What will happen?

A.The upload succeeds because the policy allows s3:PutObject for the bucket.
B.The upload fails because the policy requires SSE-S3.
C.The upload fails because the bucket policy does not allow SSE-KMS.
D.The upload succeeds because the condition only applies to encryption at rest.
AnswerB

The policy's `s3:PutObject` statement carries a condition demanding `AES256`, which is SSE-S3, not SSE-KMS. Because the application requests `aws:kms` encryption, the condition evaluates false and the request is denied, so the upload fails. The policy therefore blocks the SSE-KMS upload the stem describes.

Why this answer

The IAM policy explicitly requires the `s3:x-amz-server-side-encryption` header to be set to `AES256` (SSE-S3) via the `StringEquals` condition. Since the application is attempting to use SSE-KMS, the encryption header will be `aws:kms`, which does not match the required value. Therefore, the condition fails, and the `s3:PutObject` action is denied, causing the upload to fail.

Exam trap

The trap here is that candidates assume the `s3:PutObject` action alone grants permission, overlooking the restrictive condition that requires a specific encryption header value, which is a common IAM policy nuance tested on the SAP-C02 exam.

How to eliminate wrong answers

Option A is wrong because the policy includes a condition that restricts the `s3:PutObject` action to only requests with SSE-S3 encryption, so simply allowing the action for the bucket is insufficient. Option B is correct as explained. Option C is wrong because the question does not mention any bucket policy; the failure is due to the IAM policy's condition, not a bucket policy.

Option D is wrong because the condition explicitly applies to the encryption header in the request, which is part of the encryption at rest configuration, and the condition is enforced.

174
MCQmedium

A company is migrating a monolithic e-commerce application to AWS. The application currently runs on a single on-premises server running Windows Server and SQL Server. The company wants to minimize re-architecting effort and time to migrate. Which migration strategy should the company use?

A.Retire the application and replace it with a SaaS solution
B.Refactor the application to use microservices on Amazon ECS
C.Rehost the application on Amazon EC2 Windows instances with SQL Server
D.Replatform the application to use Amazon RDS for SQL Server
AnswerC

Rehosting lifts the Windows Server and SQL Server workload onto Amazon EC2 unchanged, preserving the existing monolith. This requires no code modification or database refactoring, directly satisfying the stated goals of minimal re-architecting effort and fastest migration timeline.

Why this answer

Rehost (lift-and-shift) involves moving the application as-is to AWS, minimizing changes and time. Option A (Retire) is not appropriate because the application is still needed. Option B (Refactor) requires significant re-architecting.

Option D (Replatform) involves some optimization but still requires changes.

175
MCQeasy

A company is migrating an e-commerce website to AWS. The website has a MySQL database. The company wants to automate the migration of the database schema and data. Which AWS service should they use?

A.AWS Glue
B.AWS Database Migration Service (DMS)
C.AWS Data Pipeline
D.AWS Schema Conversion Tool (SCT)
AnswerB

AWS Database Migration Service performs homogeneous MySQL-to-MySQL migrations, automating both schema conversion and ongoing data replication. It satisfies the requirement to automate schema and data movement without manual scripting, using a replication instance that reads from the source and writes to the target while the database stays operational.

Why this answer

(AWS Database Migration Service) is correct because it automates data migration and can convert schema using SCT. Option A (AWS Glue) is for ETL, not database migration. Option C (AWS Data Pipeline) is for data processing.

Option D (AWS Schema Conversion Tool) converts schema but does not migrate data.

176
MCQeasy

A company uses AWS Organizations and wants to allow a development account to assume a role in the production account for deployment purposes. Which component is necessary for this cross-account access?

A.A VPC peering connection between the accounts
B.An IAM role in the production account with a trust policy allowing the development account
C.A service control policy (SCP) that permits AssumeRole
D.An AWS Config rule to validate the role
AnswerB

The trust policy on the production role names the development account as principal, which is what permits the cross-account sts:AssumeRole call. Without that trust relationship, the development account's identity cannot obtain temporary credentials, so the deployment access fails.

Why this answer

Cross-account IAM access requires a role in the target (production) account with a trust policy that explicitly lists the source (development) account as a trusted principal. The development account then uses the STS AssumeRole API to obtain temporary credentials for that role. Without this trust policy, the role cannot be assumed from another account.

Exam trap

The trap here is confusing network connectivity (VPC peering) with IAM authorization, or assuming that an SCP alone can enable cross-account access when SCPs only act as a permission guardrail within an organization.

How to eliminate wrong answers

Option A is wrong because VPC peering connects networks at Layer 3 and does not provide any IAM-based authentication or authorization for cross-account role assumption. Option C is wrong because SCPs can only deny or allow permissions for principals within the same organization; they cannot grant cross-account access or replace the need for a trust policy on the target role. Option D is wrong because AWS Config rules evaluate resource compliance after the fact and do not enable or control the ability to assume a role across accounts.

177
MCQmedium

A company is using the 7 Rs strategy to migrate a monolithic application to AWS. They want to move the application to the cloud without modifying the code but plan to later refactor parts of it. Which migration strategy should they choose initially?

A.Relocate
B.Refactor
C.Replatform
D.Rehost
AnswerD

Rehosting lifts the application onto AWS infrastructure unchanged, satisfying the no-code-modification constraint. Unlike replatforming, which alters components, or refactoring, which rewrites code, rehosting preserves the monolith as-is. This lets the company migrate quickly, then refactor selected parts later once running in the cloud.

Why this answer

Rehost (lift-and-shift) is the correct initial strategy because it moves the application to AWS without modifying any code, aligning with the company's goal to first migrate without changes and later refactor. Relocate (A) involves moving the hypervisor, not the application itself. Refactor (B) involves rewriting or re-architecting the application, which is not desired initially.

Replatform (C) involves making some cloud optimizations that could require minor code changes.

178
MCQmedium

A company is migrating an on-premises Oracle database to Amazon RDS for Oracle. The database is 2 TB in size and the company has a 1 Gbps AWS Direct Connect connection. They need to minimize downtime. Which approach should the solutions architect recommend?

A.Export the database using Oracle Data Pump and import into RDS
B.Use AWS Snowball Edge to transfer the database files and then restore to RDS
C.Use AWS Schema Conversion Tool to convert the schema and AWS DMS for data migration without CDC
D.Use AWS DMS with full load followed by ongoing replication using change data capture (CDC)
AnswerD

AWS DMS performs the 2 TB full load over the Direct Connect link, then applies change data capture to replicate ongoing changes. Because CDC keeps the target synchronised, the final cutover requires only a brief application outage, minimising downtime.

Why this answer

AWS Database Migration Service (DMS) with change data capture (CDC) allows continuous replication and minimal downtime. Export/import would cause downtime. AWS Schema Conversion Tool (SCT) is for schema conversion, not data migration.

Snowball is for offline data transfer and would delay the process.

179
Multi-Selectmedium

A company is running a web application on EC2 instances in an Auto Scaling group behind an ALB. The application uses an Amazon RDS for MySQL database. Recently, the application has become slow, and the operations team identifies that the database is the bottleneck due to a high number of read queries. Which TWO actions should a solutions architect take to improve read performance? (Choose two.)

Select 2 answers
A.Enable Multi-AZ for the RDS instance.
B.Implement DynamoDB Accelerator (DAX) in front of the database.
C.Scale up the RDS instance to a larger instance type.
D.Add an Amazon RDS Read Replica in the same AWS Region.
E.Implement an Amazon ElastiCache for Redis cluster to cache frequent queries.
AnswersD, E

Read Replicas offload read-only traffic from the primary RDS for MySQL instance via asynchronous replication, directly relieving the read-query bottleneck. The application can route SELECT queries to the replica endpoint, reducing contention on the primary and improving overall read throughput.

Why this answer

Option D is correct because an Amazon RDS Read Replica offloads read-only traffic from the primary MySQL instance via asynchronous replication, directly reducing the read bottleneck and improving read throughput. Option E is correct because Amazon ElastiCache for Redis caches frequent query results in memory, so repeated read queries are served from the cache instead of hitting RDS, which reduces database load and improves response times. Option A is not correct because Multi-AZ provides high availability through a synchronous standby, not additional read capacity.

Option B is not correct because DynamoDB Accelerator (DAX) is a caching layer for DynamoDB, not for Amazon RDS for MySQL. Option C is not correct because scaling up the instance increases overall capacity but does not specifically address read scaling as effectively as read replicas or caching, and it may not resolve a high-read-query bottleneck.

Exam trap

The trap here is that candidates often confuse Multi-AZ with read replicas, assuming the standby instance can serve reads, when in fact Multi-AZ only provides failover and the standby is not accessible for read operations.

180
MCQeasy

A company runs a static website on Amazon S3 with a custom domain using Amazon Route 53. The website content is updated frequently by multiple developers. The company wants to implement a workflow where updates are automatically tested and deployed. They have existing CI/CD tools that integrate with AWS CodeCommit. The Solutions Architect needs to design a deployment pipeline that rebuilds the website only when changes are pushed to the main branch, and then invalidates the Amazon CloudFront cache if a CloudFront distribution is used. Which solution meets these requirements with the least operational overhead?

A.Use AWS CloudFormation with a custom resource that triggers a build on CodeCommit push.
B.Configure an S3 event notification to invoke an AWS Lambda function that builds and deploys the website.
C.Use AWS CodePipeline with a source stage tied to CodeCommit, a build stage using AWS CodeBuild, and a deploy stage that syncs the S3 bucket and invalidates CloudFront.
D.Use AWS Lambda@Edge to generate the website on the fly and cache at CloudFront.
AnswerC

CodePipeline orchestrates CodeCommit source, CodeBuild, and a deploy stage that syncs S3 and invalidates CloudFront, giving automatic rebuilds on main-branch pushes with minimal operational overhead. It satisfies the branch-triggered rebuild and cache invalidation requirements natively.

Why this answer

AWS CodePipeline natively integrates with CodeCommit as a source, CodeBuild as a build stage, and can deploy to S3 with a CloudFront invalidation step — all with minimal operational overhead. It supports branch-based triggers (e.g., main branch) and can be defined entirely in code, meeting the CI/CD and cache invalidation requirements.

Exam trap

The trap is over-engineering with Lambda@Edge or custom CloudFormation resources when the question explicitly states existing CI/CD tools integrate with CodeCommit — the exam rewards the managed, least-overhead pipeline service.

How to eliminate wrong answers

Option A is wrong because a CloudFormation custom resource that triggers builds on CodeCommit push is a custom, high-maintenance solution that reinvents what CodePipeline already provides. Option B is wrong because S3 event notifications trigger on object changes, not on CodeCommit pushes, and a Lambda function would need custom build logic — more operational overhead and not aligned with the existing CI/CD tooling. Option D is wrong because Lambda@Edge is for request/response manipulation at CloudFront edge locations, not for building and deploying a static site from source control.

181
MCQhard

A company is migrating a legacy monolithic application to AWS. The application has tightly coupled components and high latency between them. The company wants to modernize the application into a microservices architecture. Which migration strategy should the company use?

A.Repurchase
B.Rehost
C.Refactor / Re-architect
D.Replatform
AnswerC

Refactoring re-architects the monolith into independently deployable microservices, replacing in-process calls with lightweight APIs or asynchronous messaging. This directly resolves the stem's tightly coupled components and high inter-component latency, which lift-and-shift or replatform cannot address since they preserve the existing monolithic structure and coupling.

Why this answer

The refactor/re-architect strategy involves re-architecting the application into microservices. Option A is wrong because repurchase involves buying a new product, not re-architecting. Option B is wrong because rehost (lift-and-shift) does not modernize.

Option D is wrong because replatform (lift-tinker-and-shift) makes minor optimizations but does not change architecture.

182
MCQhard

A company is migrating an on-premises Oracle database to Amazon Aurora PostgreSQL. The database is 5 TB and must be migrated with minimal downtime. The company requires continuous replication of changes during the migration and the ability to cut over within a 1-hour maintenance window. Which combination of AWS services should be used to achieve this?

A.Native Oracle Data Guard with AWS Direct Connect
B.AWS Schema Conversion Tool (AWS SCT) with continuous replication
C.AWS Database Migration Service (AWS DMS) with full load only
D.AWS Database Migration Service (AWS DMS) with ongoing replication and AWS Schema Conversion Tool (AWS SCT)
AnswerD

AWS DMS can perform full load plus ongoing replication (change data capture) from Oracle to Aurora PostgreSQL, minimizing downtime. AWS SCT converts the Oracle schema to PostgreSQL-compatible DDL. This combination allows continuous replication until cutover, meeting the 1-hour window. DMS handles data migration, and SCT handles schema conversion, which is essential for heterogeneous migrations.

Why this answer

For heterogeneous migrations with minimal downtime, AWS DMS with ongoing replication and AWS SCT is the correct combination. DMS handles data migration and change data capture, while SCT converts the schema. Other options either lack ongoing replication, are not designed for data migration, or are incompatible with the target database engine.

Exam trap

The trap here is assuming that AWS SCT alone can handle both schema conversion and data replication, but SCT only converts schemas and does not replicate data.

183
MCQeasy

A company has an S3 bucket that stores sensitive data. The company wants to ensure that all objects uploaded to the bucket are encrypted at rest. Which solution should the solutions architect recommend?

A.Use a bucket policy to deny uploads that do not include the x-amz-server-side-encryption header.
B.Create an AWS Lambda function that encrypts objects after they are uploaded.
C.Configure an S3 Access Point with a policy that requires encryption.
D.Enable default encryption on the S3 bucket using SSE-S3 or SSE-KMS.
AnswerD

Correct. Default encryption on the S3 bucket automatically encrypts all objects at rest using SSE-S3 or SSE-KMS, regardless of the upload request. It is the simplest and most effective solution to ensure encryption at rest.

Why this answer

Enabling default encryption on the S3 bucket using SSE-S3 or SSE-KMS ensures that all objects are automatically encrypted at rest, regardless of whether the upload request specifies encryption. This is the simplest and most effective approach. Option A is technically viable but unnecessarily complex; a bucket policy that denies uploads without the x-amz-server-side-encryption header can enforce encryption, but it requires careful policy configuration and does not encrypt objects automatically if the header is missing—instead it rejects the upload.

Option B is inefficient and costly; using a Lambda function to encrypt objects after upload introduces latency and extra expense, whereas default encryption achieves the same result seamlessly. Option C is incorrect because S3 Access Points are designed for managing access to shared datasets, not for enforcing encryption; adding a policy there would complicate access management without providing the automatic encryption that default encryption offers.

184
MCQeasy

A company is using AWS CloudFormation to manage infrastructure. They want to ensure that any changes to a production stack are reviewed and approved before being applied. What is the BEST way to achieve this?

A.Enable termination protection on the stack.
B.Use AWS CodePipeline to automatically deploy changes.
C.Use Change Sets and require manual approval to execute them.
D.Use stack policies to prevent updates.
AnswerC

Change Sets compute the proposed modifications and surface them for inspection before any resource is altered, so a reviewer can approve or reject the diff. Requiring manual execution satisfies the stem's constraint that production changes be reviewed and approved prior to being applied.

Why this answer

AWS CloudFormation Change Sets allow you to preview how proposed changes will affect your running resources before executing them. By using Change Sets in conjunction with a manual approval process (e.g., via AWS CodePipeline or a separate review step), you can ensure changes are reviewed and approved before being applied. Option A (termination protection) only prevents stack deletion, not updates.

Option B (auto-deployment with CodePipeline) can include approval gates, but the question asks for the "BEST way" in the context of CloudFormation itself; Change Sets are the native mechanism for review. Option D (stack policies) control which resources can be updated, but do not enforce a review process.

185
MCQmedium

A company runs a batch processing workload on Amazon EC2 Spot Instances managed by an Auto Scaling group. The workload checkpoints progress to Amazon S3 every 10 minutes. Spot Instances are frequently interrupted, causing the workload to restart from the last checkpoint. The team wants to reduce the impact of interruptions and improve job completion time. Which solution should a solutions architect recommend?

A.Purchase a 1-year Reserved Instance for the batch workload and use it instead of Spot Instances.
B.Increase the checkpoint frequency to every 1 minute and continue using a single Spot capacity pool.
C.Configure the Auto Scaling group to use a mixed instances policy with multiple instance types and Availability Zones, and enable capacity rebalancing.
D.Use On-Demand Instances for the entire batch workload and enable EC2 Auto Scaling predictive scaling.
AnswerC

A mixed instances policy diversifies across instance types and Availability Zones, reducing the chance that a single Spot capacity pool interruption affects all instances. Capacity rebalancing proactively replaces instances when a Spot interruption notice is received, allowing the workload to checkpoint and migrate before termination. This directly reduces interruption impact and improves job completion time.

Why this answer

Diversifying across instance types and Availability Zones with a mixed instances policy spreads the workload over multiple Spot capacity pools, reducing correlated interruptions. Capacity rebalancing uses the two-minute Spot interruption notice to launch replacement instances and drain existing ones, so the workload can checkpoint and continue. Together they improve resilience and job completion time while retaining Spot cost savings.

Exam trap

The trap here is thinking that more frequent checkpoints or switching to On-Demand solves Spot interruptions, when the real fix is diversifying capacity pools and using capacity rebalancing to react to interruption notices.

186
MCQeasy

A company wants to design a serverless event-driven architecture where multiple downstream services need to process events from a single source. Events must be reliably delivered and each downstream service must process every event independently. Which AWS service should be used as the event router?

A.AWS Step Functions
B.Amazon Kinesis Data Streams
C.Amazon Simple Queue Service (SQS)
D.Amazon EventBridge
AnswerD

Amazon EventBridge routes each event to multiple targets, with rules matching an event bus and fanning out to every subscribed downstream service independently. This satisfies the requirement that each service processes every event, since EventBridge delivers to all matching targets rather than competing consumers pulling from a shared queue.

Why this answer

Amazon EventBridge is the correct choice because it provides a fully managed event bus that can receive events from a single source and fan out to multiple downstream targets (e.g., Lambda, SQS, Step Functions) with built-in filtering, transformation, and reliable delivery. Each downstream service subscribes independently via rules, ensuring every event is processed by all subscribers without the need for a polling mechanism or manual orchestration.

Exam trap

The trap here is that candidates often confuse Amazon SQS or Kinesis as a fan-out solution, but SQS is point-to-point and Kinesis requires custom consumer logic, whereas EventBridge natively supports independent, reliable event routing to multiple targets without additional infrastructure.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a workflow orchestration service, not an event router; it would require custom logic to fan out events and does not natively support independent, reliable delivery to multiple downstream services. Option B is wrong because Amazon Kinesis Data Streams is designed for real-time streaming data ingestion and processing with shard-level ordering, but it does not natively fan out events to multiple independent consumers—each consumer must share the same stream and manage its own checkpointing, which can lead to contention and does not guarantee independent processing of every event. Option C is wrong because Amazon SQS is a message queue that delivers each message to a single consumer; to fan out to multiple downstream services, you would need multiple queues and a publisher to send copies, which adds complexity and does not provide built-in event filtering or transformation.

187
Multi-Selecteasy

Which TWO AWS services can be used to automate the enforcement of compliance policies across multiple AWS accounts? (Choose TWO.)

Select 2 answers
A.AWS CloudTrail
B.AWS Organizations SCPs
C.AWS CloudFormation StackSets
D.Amazon VPC Flow Logs
E.AWS Config rules
AnswersB, E

AWS Organizations service control policies centrally restrict the maximum available permissions across every member account, satisfying the multi-account enforcement constraint. Attaching an SCP to an organisational unit or the root immediately denies non-compliant actions organisation-wide, regardless of each account's own IAM policies, giving automated, preventive governance rather than detective-only monitoring.

Why this answer

AWS Organizations Service Control Policies (SCPs) are correct because they attach at the OU or account level and set the maximum available permissions for member accounts, thereby automatically enforcing compliance guardrails (e.g., denying use of unapproved regions or services) across many accounts at once. AWS Config rules are correct because they continuously evaluate resource configurations against desired compliance policies and can trigger automatic remediation (via SSM Automation documents) across accounts when aggregated with a Config aggregator, enabling automated enforcement. AWS CloudTrail only records API activity for auditing and does not enforce policy, so it is not correct.

AWS CloudFormation StackSets deploys resources across accounts but does not itself enforce compliance policies, so it is not correct. Amazon VPC Flow Logs capture IP traffic metadata for monitoring and troubleshooting, not policy enforcement, so it is not correct.

Exam trap

The trap here is that candidates often confuse monitoring services (CloudTrail, VPC Flow Logs) with enforcement services, or assume that infrastructure deployment tools (CloudFormation StackSets) inherently enforce compliance, when in fact they only provision resources without policy enforcement.

188
MCQeasy

A company is using AWS CloudFormation to manage infrastructure. The stack creation fails with the error 'Resource handler returned message: 'User: arn:aws:sts::123456789012:assumed-role/Admin/MySession is not authorized to perform: ec2:RunInstances'. What is the MOST likely cause?

A.The IAM role used by CloudFormation does not have ec2:RunInstances permission.
B.The region specified in the template is disabled.
C.The CloudFormation template has a syntax error.
D.The AWS account is not subscribed to EC2 service.
AnswerA

CloudFormation assumes an IAM role to make API calls; if that role's policy lacks ec2:RunInstances, the stack's instance creation is denied. The error names the assumed role, confirming the missing permission is the cause of the stack creation failure.

Why this answer

The error message explicitly names the assumed role and the denied action `ec2:RunInstances`, which is the signature of an IAM permissions problem. CloudFormation uses either the user's credentials or a service role to create resources; if that principal lacks `ec2:RunInstances`, the stack fails with exactly this 'not authorized to perform' message.

Exam trap

SAP-C02 often tests whether candidates can parse the exact IAM error string and distinguish authorization failures from template syntax or region errors — the phrase 'not authorized to perform' is the giveaway.

How to eliminate wrong answers

Option B is wrong because a disabled region produces errors like 'InvalidRegion' or 'region not opted-in', not an IAM authorization failure. Option C is wrong because a template syntax error fails during validation with 'Template format error' before any resource handler runs. Option D is wrong because AWS accounts are not 'subscribed' to EC2 — EC2 is available by default in all commercial regions, and lack of subscription is not an AWS concept.

189
MCQmedium

A company is building a data lake on Amazon S3 using Parquet files. The data will be queried by multiple teams using Amazon Athena. The security team requires that access to sensitive columns (e.g., PII) be restricted based on the user's role. Which solution provides column-level access control with the LEAST administrative overhead?

A.Use AWS Lake Formation to define column-level permissions in the Data Catalog.
B.Create separate S3 buckets for sensitive and non-sensitive data and apply bucket policies to restrict access.
C.Load the data into Amazon Redshift and use Redshift Spectrum to query S3, then apply column-level security through Redshift.
D.Use IAM policies with condition keys to restrict access based on the Athena workgroup.
AnswerA

AWS Lake Formation enforces column-level and row-level permissions centrally through the Data Catalog, and Athena honours these grants automatically. Defining permissions once in Lake Formation satisfies the role-based PII restriction with the least administrative overhead compared with per-query workarounds.

Why this answer

AWS Lake Formation provides native column-level filtering in the Data Catalog, allowing you to define granular permissions on specific columns of a table without moving or duplicating data. When Athena queries a table registered with Lake Formation, the service automatically applies column-level access controls based on the IAM role or user, enforcing the restriction at query runtime with minimal administrative overhead.

Exam trap

The trap here is that candidates often assume S3 bucket policies or IAM conditions can achieve column-level access, but these operate at the object or API level and cannot filter columns within a single file, which is a key distinction tested in the SAP-C02 exam.

How to eliminate wrong answers

Option B is wrong because S3 bucket policies operate at the object or prefix level, not at the column level, so they cannot restrict access to specific columns within a Parquet file. Option C is wrong because it introduces unnecessary complexity and administrative overhead by requiring a separate Redshift cluster and Redshift Spectrum setup, whereas Lake Formation directly integrates with Athena and the Glue Data Catalog. Option D is wrong because IAM condition keys for Athena workgroups can limit which workgroup a user can use, but they cannot enforce column-level restrictions on the query results.

190
MCQeasy

A company is designing a new application that requires secure storage of secrets such as database passwords and API keys. The application runs on Amazon EC2 instances. The company wants to centralize secret management and automatically rotate secrets. Which AWS service should be used?

A.AWS Key Management Service (KMS)
B.AWS CloudHSM
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager stores secrets centrally and natively rotates them on a schedule using Lambda rotation functions, so database passwords and API keys are updated automatically. EC2 instances retrieve secrets at runtime via the API, eliminating hard-coded credentials.

Why this answer

AWS Secrets Manager is purpose-built for secure secret storage with built-in automatic rotation for RDS, Redshift, and DocumentDB credentials, plus custom Lambda-based rotation for other secrets. It centralizes secret management and integrates natively with EC2 via the AWS SDK or Secrets Manager Agent. KMS is for encryption keys, not secret lifecycle management, and Parameter Store lacks native rotation.

Exam trap

SAP-C02 often tests the distinction between KMS (encryption keys), Parameter Store (configuration and basic secrets), and Secrets Manager (managed rotation), so candidates must recognize that automatic rotation is the key differentiator.

How to eliminate wrong answers

Option A is wrong because AWS KMS manages encryption keys and does not store or rotate application secrets like database passwords or API keys. Option B is wrong because CloudHSM provides dedicated hardware security modules for key operations, not a managed secret store with rotation. Option C is wrong because Systems Manager Parameter Store can store secrets (as SecureString) but does not provide automatic rotation natively; rotation requires custom automation.

191
MCQmedium

A company has a centralized security account and wants to enable AWS Config in all accounts. They want to centrally manage Config rules and view compliance. What should they do?

A.Apply an SCP to enable AWS Config in all accounts.
B.Use CloudFormation StackSets to deploy Config rules, then view in each account.
C.Enable AWS Config in the security account only and use cross-account roles.
D.Enable AWS Config in each account and use an aggregator in the security account.
AnswerD

An aggregator in the security account collects configuration and compliance data from every source account, satisfying the centralised visibility requirement. AWS Config must still be enabled per account and Region, since the aggregator only gathers existing data rather than activating recording. This delivers central rule management and compliance viewing across the organisation.

Why this answer

AWS Config must be enabled in each individual account to record resource configurations and evaluate rules. An aggregator in the security account can then collect compliance data from all accounts, enabling centralized viewing and management of Config rules without needing to log into each account separately.

Exam trap

The trap here is that candidates assume a single Config instance in a central account can monitor all other accounts via cross-account roles, but AWS Config is account-scoped and must be enabled in each account to record its own resources.

How to eliminate wrong answers

Option A is wrong because SCPs (Service Control Policies) can only restrict or deny permissions; they cannot enable a service like AWS Config in accounts. Option B is wrong because CloudFormation StackSets can deploy Config rules across accounts, but without Config being enabled in each account first, the rules have no configuration recorder to evaluate against, and compliance cannot be viewed centrally without an aggregator. Option C is wrong because enabling AWS Config only in the security account would only record resources in that account; cross-account roles allow access but do not enable Config recording or rule evaluation in other accounts.

192
MCQmedium

A company has a CI/CD pipeline that builds and deploys a containerized application to Amazon ECS Fargate. The pipeline uses AWS CodeBuild to run tests and build Docker images. Recently, the pipeline has been failing intermittently with the error 'CannotPullContainerError: Error response from daemon: manifest for <image> not found'. The image is stored in Amazon ECR. The team suspects the issue is related to image tag inconsistency. The pipeline tags images with the commit hash. Which change will prevent this error?

A.Store the Docker image in Amazon S3 instead of ECR.
B.Ensure the pipeline builds and pushes the image with a unique tag, such as the commit hash, and uses that tag in the ECS task definition.
C.Use the 'latest' tag for all images.
D.Retry the failed pipeline step after a delay.
AnswerB

ECS resolves the image by the exact tag in the task definition. Pushing with the commit hash and referencing that same tag guarantees the manifest exists in Amazon ECR, eliminating the intermittent CannotPullContainerError caused by tag mismatch.

Why this answer

Ensuring that the image tag is unique and not reused prevents stale image references. Using the commit hash ensures uniqueness.

193
MCQeasy

A company wants to centrally manage backups for Amazon EBS volumes across multiple AWS accounts. They need a solution that can automatically back up volumes based on tags, retain backups according to a policy, and send notifications on failures. Which AWS service should they use?

A.AWS CloudFormation StackSets
B.Amazon RDS automated backups
C.AWS Backup
D.Amazon S3 lifecycle policies
AnswerC

AWS Backup satisfies the cross-account, tag-driven requirement through backup policies applied at the organisation level, with lifecycle rules governing retention and Amazon EventBridge delivering failure notifications. Unlike EBS snapshots managed per-account, it centralises governance across accounts, meeting the centralised management constraint in the stem.

Why this answer

AWS Backup is the correct service because it provides a centralized, policy-based backup solution for Amazon EBS volumes across multiple AWS accounts. It supports tag-based backup policies, retention rules, and integrates with Amazon CloudWatch Events and Amazon SNS to send notifications on failures, meeting all the stated requirements.

Exam trap

The trap here is that candidates might confuse AWS Backup with native snapshot management or assume that a service like CloudFormation StackSets can handle backup automation, but only AWS Backup provides the centralized, policy-driven, cross-account backup management with notification capabilities required by the scenario.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation StackSets is used to deploy infrastructure as code across multiple accounts and regions, not for managing backups or retention policies. Option B is wrong because Amazon RDS automated backups are specific to RDS databases and cannot back up EBS volumes or operate across multiple accounts. Option D is wrong because Amazon S3 lifecycle policies manage the transition and expiration of objects within S3 buckets, not the backup of EBS volumes.

194
MCQeasy

A company is designing a new static website hosted on Amazon S3. The website must be served over HTTPS with a custom domain name. Which AWS service should be used to achieve this?

A.Amazon Route 53 with alias record
B.Amazon CloudFront with SSL certificate
C.Amazon S3 static website hosting with bucket policy
D.Elastic Load Balancer with SSL termination
AnswerB

CloudFront terminates HTTPS at edge locations using an ACM certificate for the custom domain, then fetches content from the S3 origin. S3 static website endpoints alone cannot serve HTTPS with a custom domain, so CloudFront satisfies both requirements.

Why this answer

Amazon CloudFront can be configured to serve content from an S3 bucket as the origin, and it supports custom SSL certificates via AWS Certificate Manager (ACM) or IAM, enabling HTTPS for a custom domain. This is the recommended architecture for static websites requiring HTTPS because CloudFront provides edge caching, DDoS protection, and seamless SSL termination.

Exam trap

The trap here is that candidates often assume S3 static website hosting can directly serve HTTPS with a custom domain, but S3's built-in website endpoint does not support custom SSL certificates, making CloudFront the required service for HTTPS termination with a custom domain.

How to eliminate wrong answers

Option A is wrong because Amazon Route 53 with an alias record only provides DNS resolution, not HTTPS termination; it cannot serve content over HTTPS directly. Option C is wrong because Amazon S3 static website hosting does not support custom SSL certificates or HTTPS for custom domains; it only provides HTTPS via the S3 website endpoint (which uses a domain like s3-website-<region>.amazonaws.com) and cannot bind a custom SSL certificate. Option D is wrong because an Elastic Load Balancer with SSL termination is designed for dynamic content behind EC2 or containers, not for static S3-hosted websites, and it adds unnecessary complexity and cost without leveraging S3's native static hosting benefits.

195
MCQmedium

A company runs a critical application on EC2 instances behind an Application Load Balancer. The security team requires that all traffic to the application be encrypted in transit and that the load balancer use a certificate from AWS Certificate Manager (ACM). The application currently uses HTTP. What should the company do to meet the security requirement?

A.Replace the ALB with a Network Load Balancer and associate an ACM certificate with it.
B.Change the ALB listener to TCP and use a self-signed certificate on the EC2 instances.
C.Place a CloudFront distribution in front of the ALB and configure HTTPS between viewers and CloudFront.
D.Add an HTTPS listener to the ALB using an ACM certificate, and configure the HTTP listener to redirect to HTTPS.
AnswerD

This provides encryption and uses ACM for certificate management.

Why this answer

Adding an HTTPS listener to the ALB with an ACM certificate and configuring the HTTP listener to redirect to HTTPS ensures all traffic is encrypted in transit. This meets the security requirement directly without additional components. Option A is incorrect because Network Load Balancers do not support ACM certificates for TLS termination; they require TLS termination on the backend instances.

Option B is incorrect because TCP listeners cannot terminate TLS, and self-signed certificates on EC2 instances would not provide trusted encryption for clients. Option C is incorrect because while CloudFront can provide HTTPS, it adds unnecessary complexity and cost; the requirement can be met natively with the ALB.

196
MCQmedium

A company is migrating a legacy .NET Framework application to AWS. The application uses Windows authentication and relies on Active Directory for user authentication. The company wants to minimize code changes and maintain the same authentication mechanism. The application will run on Amazon EC2 instances in a VPC. Which solution should a solutions architect recommend?

A.Deploy the application on EC2 instances and configure a site-to-site VPN to the on-premises Active Directory, and join the instances to the on-premises domain.
B.Deploy the application on EC2 instances joined to an AWS Managed Microsoft AD directory, and configure the application to use Windows authentication against the directory.
C.Deploy the application on EC2 instances and use AWS IAM Identity Center (successor to AWS Single Sign-On) for authentication, modifying the application to use SAML.
D.Deploy the application on EC2 instances and use Amazon Cognito user pools for authentication, updating the application to use OpenID Connect.
AnswerB

AWS Managed Microsoft AD is a managed Active Directory service in AWS. EC2 instances can be domain-joined to this directory, allowing the application to use Windows authentication without code changes. This maintains the same authentication mechanism and minimizes migration effort, as the application continues to use Active Directory.

Why this answer

AWS Managed Microsoft AD provides a managed Active Directory in AWS, enabling EC2 instances to be domain-joined and use Windows authentication. This requires no application code changes and maintains the existing authentication mechanism. It also reduces operational overhead compared to extending an on-premises domain.

Exam trap

The trap here is assuming that AWS IAM Identity Center or Amazon Cognito can provide Windows authentication, when they are designed for different authentication protocols and would require application modifications.

197
MCQhard

A company runs a containerized application on Amazon ECS with Fargate launch type. The application is deployed across multiple Availability Zones. Recently, deployments have been failing because new tasks cannot register with the Application Load Balancer (ALB) target group. The health checks are failing. What is the MOST likely cause?

A.The security group for the tasks does not allow inbound traffic from the ALB on the health check port.
B.The ECS service is configured with a desired count of zero.
C.The task definition specifies an invalid container image.
D.The ECS cluster has insufficient capacity.
AnswerA

Fargate tasks and the ALB communicate over the network, so the task security group must permit inbound traffic from the ALB security group on the health check port. Without that rule, health checks fail and tasks never register.

Why this answer

If the security group for the tasks does not allow inbound traffic from the ALB on the health check port, health checks fail and tasks cannot register. Option B is incorrect because a desired count of zero would prevent new tasks from running, but the scenario describes deployments failing due to health check failures on new tasks. Option C is incorrect: an invalid container image would cause the task to fail to start, not cause health check failures after the task is running.

Option D is incorrect because Fargate manages capacity; insufficient capacity would cause a different error (e.g., unable to provision tasks), not health check failures.

198
MCQeasy

A company is building a new web application that will be accessed by users globally. They want to minimize latency and protect against DDoS attacks. Which AWS service should they use as the entry point?

A.Elastic Load Balancing
B.AWS Global Accelerator
C.Amazon CloudFront
D.Amazon Route 53
AnswerC

Amazon CloudFront terminates TLS at edge locations and caches content close to global users, directly reducing latency. Its integration with AWS Shield Standard provides automatic DDoS protection at no extra cost, satisfying both the latency and DDoS constraints named in the stem.

Why this answer

Amazon CloudFront is correct because it is a global content delivery network (CDN) that caches content at edge locations close to users, reducing latency for static and dynamic content. It also provides built-in DDoS protection through AWS Shield Standard and can integrate with AWS WAF for additional layer 7 filtering, making it the ideal entry point for a globally accessed web application requiring both low latency and DDoS mitigation.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with CloudFront because both improve latency globally, but Global Accelerator does not cache content or provide application-layer DDoS protection, making it unsuitable as the primary entry point for a web application requiring both features.

How to eliminate wrong answers

Option A is wrong because Elastic Load Balancing distributes traffic only within a single AWS Region and does not provide global edge caching or native DDoS protection at the application layer; it relies on other services for global latency reduction. Option B is wrong because AWS Global Accelerator improves latency by routing traffic over the AWS global network to the optimal regional endpoint, but it does not cache content or provide application-layer DDoS protection; it focuses on TCP/UDP traffic optimization and uses static anycast IPs. Option D is wrong because Amazon Route 53 is a DNS service that resolves domain names to IP addresses and can perform health checks and routing policies, but it does not cache content or provide DDoS mitigation beyond basic DNS-level protection; it is not an entry point for application traffic.

199
MCQhard

A company is migrating a legacy Oracle database to Amazon Aurora PostgreSQL. The migration must be completed with minimal downtime and minimal manual effort. Which AWS service should be used?

A.AWS DataSync
B.AWS DMS with ongoing replication
C.AWS Snowball Edge
D.AWS Schema Conversion Tool (SCT)
AnswerB

AWS DMS with ongoing replication performs the initial full load and then continuously applies change data capture from Oracle to Aurora PostgreSQL. Cutover happens once replication lag is negligible, satisfying minimal downtime with minimal manual intervention.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication enables continuous data replication from the source Oracle database to the target Aurora PostgreSQL with minimal downtime. It supports heterogeneous migrations when combined with the AWS Schema Conversion Tool (SCT) for schema conversion. DMS handles the data migration and keeps the target in sync until cutover, minimizing manual effort and downtime.

Exam trap

SAP-C02 often tests the difference between schema conversion (SCT) and data migration (DMS), so candidates may choose SCT alone thinking it covers the entire migration, or pick DataSync for database migration when it is meant for file storage.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is designed for moving files and object data, not for database migration with ongoing replication. Option C is wrong because AWS Snowball Edge is a physical device for transferring large amounts of data offline, which is not suitable for minimal-downtime database migration and does not support ongoing replication. Option D is wrong because AWS SCT only converts database schemas and code; it does not migrate data or provide ongoing replication, so it alone cannot meet the minimal downtime requirement.

200
MCQeasy

A startup runs its application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer to distribute traffic. During a recent marketing campaign, the application experienced high latency and some requests returned 503 errors. The team suspects that the tasks are hitting resource limits. The team wants to automatically scale the tasks based on CPU utilization. Which solution should the team implement?

A.Configure Application Auto Scaling for the ECS service with a target tracking scaling policy based on average CPU utilization.
B.Create a CloudWatch alarm that triggers a Lambda function to stop idle tasks.
C.Create an Auto Scaling group for the ECS cluster and configure it to scale based on CPU utilization.
D.Use AWS Lambda to periodically check CPU utilization and update the desired count of the ECS service.
AnswerA

Application Auto Scaling target tracking adjusts the ECS service's desired task count to hold average CPU utilisation at a target, directly addressing the resource-limit saturation causing 503s and latency. It works with Fargate because scaling operates on task count, not cluster capacity.

Why this answer

Application Auto Scaling with a target tracking policy on average CPU utilization is the native, recommended way to scale ECS service tasks. It automatically adjusts the desired count of tasks to keep CPU near the target value, responding to load changes without custom code. This directly addresses the high latency and 503 errors caused by tasks hitting resource limits.

Exam trap

SAP-C02 often tests the misconception that ECS clusters are scaled with EC2 Auto Scaling groups; for Fargate, scaling is done at the service level with Application Auto Scaling, not at the cluster level.

How to eliminate wrong answers

Option B is wrong because a CloudWatch alarm that stops idle tasks only reduces capacity — it does not add tasks when CPU is high, so it cannot solve the scaling problem and may worsen 503 errors. Option C is wrong because ECS with Fargate does not use EC2 Auto Scaling groups; the cluster capacity is managed by Fargate, and scaling must target the ECS service, not an Auto Scaling group. Option D is wrong because a custom Lambda polling loop is an anti-pattern: it adds latency, requires custom code, and is less reliable than the built-in Application Auto Scaling target tracking policy.

201
MCQhard

A global company uses AWS Organizations with hundreds of accounts. The networking team needs to allow VPCs in different accounts to communicate privately using AWS Transit Gateway. The company wants to centralize management while allowing individual account owners to create and attach VPCs. Which solution meets these requirements?

A.Create a VPN connection from each VPC to a central network appliance.
B.Use AWS PrivateLink to connect each VPC to a central VPC endpoint service.
C.Create a Transit Gateway in the networking account and share it with other accounts using AWS Resource Access Manager.
D.Create VPC peering connections between each VPC and a central VPC.
AnswerC

AWS Resource Access Manager shares the Transit Gateway from the networking account to other accounts or the organisation, letting individual owners create and attach their own VPC attachments while the networking team retains central ownership and management.

Why this answer

AWS Transit Gateway allows you to centralize network connectivity across multiple VPCs and accounts. By creating the Transit Gateway in the networking account and sharing it via AWS Resource Access Manager (RAM), you enable individual account owners to attach their VPCs to the shared Transit Gateway, achieving private communication while maintaining centralized management.

Exam trap

The trap here is that candidates often confuse AWS PrivateLink (which is for service exposure, not general routing) with Transit Gateway, or assume VPC peering can be scaled via a central VPC, failing to recognize that peering is non-transitive and requires a full mesh for multi-VPC connectivity.

How to eliminate wrong answers

Option A is wrong because VPN connections from each VPC to a central network appliance introduce significant complexity, bandwidth limitations, and operational overhead; they do not leverage native AWS transit capabilities and are not designed for scalable inter-VPC communication across hundreds of accounts. Option B is wrong because AWS PrivateLink is used to expose services privately from a VPC to other VPCs, not to enable general VPC-to-VPC routing; it requires creating endpoint services and does not provide a hub-and-spoke transit architecture for arbitrary VPC connectivity. Option D is wrong because VPC peering connections are one-to-one and do not scale to hundreds of accounts; they require full mesh or star topology with manual peering for each pair, and they do not support transitive routing, making centralized management impractical.

202
MCQhard

A company is migrating a stateful firewall appliance to AWS. The appliance currently inspects traffic between multiple on-premises segments. In AWS, the company wants to deploy the appliance in a VPC to inspect traffic between subnets. Which architecture should the company use to ensure that the appliance can inspect all traffic?

A.Deploy the appliance behind an Application Load Balancer and configure the VPC route tables.
B.Deploy the appliance behind a Gateway Load Balancer in an inspection VPC and use a Transit Gateway to route traffic through it.
C.Deploy the appliance behind a Network Load Balancer and configure the VPC route tables to send traffic to the NLB.
D.Use VPC Gateway Endpoints to route traffic through the appliance.
AnswerB

Gateway Load Balancer uses GENEVE encapsulation to transparently redirect traffic to third-party appliances, while Transit Gateway routes inter-subnet and inter-VPC traffic through the inspection VPC. This combination satisfies the requirement to inspect all traffic between subnets without altering routing on each workload.

Why this answer

A Gateway Load Balancer (GWLB) can be deployed in an inspection VPC and used with a Transit Gateway to route traffic from subnets through the appliance for inspection. Option A is wrong because an Application Load Balancer cannot inspect traffic and is designed for HTTP/HTTPS. Option C is wrong because a Network Load Balancer does not inspect traffic; it forwards traffic without inspection.

Option D is wrong because VPC Gateway Endpoints are used to access AWS services privately, not for traffic inspection.

203
MCQeasy

A company wants to migrate its on-premises virtualized workloads to AWS using the VMware Cloud on AWS service. The company currently uses VMware vSphere for virtualization. What is the primary benefit of using VMware Cloud on AWS for this migration?

A.It allows the company to continue using existing VMware management tools and processes
B.It provides better application performance compared to running on AWS native compute
C.It reduces the total cost of ownership by eliminating the need for any hardware maintenance
D.It eliminates the need to refactor applications for the cloud
AnswerA

VMware Cloud on AWS runs the native vSphere stack on dedicated bare-metal hosts, so existing vCenter, vSphere Client, and management workflows continue unchanged. This directly satisfies the stem's constraint of migrating vSphere workloads without retraining staff or re-platforming to native AWS services.

Why this answer

VMware Cloud on AWS allows organizations to use the same VMware tools and processes, minimizing the learning curve and operational changes. It does not automatically reduce costs, nor does it provide better performance or eliminate the need to refactor applications.

204
Multi-Selectmedium

A company is migrating a web application to AWS and wants to use a multi-tier architecture with an Auto Scaling group of EC2 instances behind an Application Load Balancer. The company needs to store session state for the application. Which TWO approaches should the company use to store session state in a scalable and highly available manner? (Choose TWO.)

Select 2 answers
A.Use Amazon DynamoDB with on-demand capacity.
B.Use an EC2 instance store for each instance.
C.Use Amazon EBS snapshots shared across instances.
D.Use Amazon ElastiCache for Redis with replication.
E.Use Amazon RDS for MySQL with Multi-AZ.
AnswersA, D

DynamoDB with on-demand capacity stores session state externally, so any EC2 instance in the Auto Scaling group can retrieve it. On-demand mode scales automatically with request volume, removing capacity planning and satisfying the scalable, highly available requirement without sticky sessions.

Why this answer

Option A is correct because Amazon DynamoDB with on-demand capacity provides a fully managed, serverless, highly available key-value store that scales automatically with traffic, making it ideal for persisting session state across an Auto Scaling group of EC2 instances behind an ALB. Option D is correct because Amazon ElastiCache for Redis with replication offers an in-memory, low-latency, highly available session store with a primary node and read replicas, and it supports Multi-AZ failover so sessions survive node failures. Option B is incorrect because an EC2 instance store is ephemeral, tied to a single instance, and loses data on stop/termination, so it cannot provide shared or durable session state.

Option C is incorrect because EBS snapshots are point-in-time backups, not a live shared session store, and cannot be concurrently attached across multiple instances for session access. Option E is incorrect because Amazon RDS for MySQL with Multi-AZ provides a relational database with failover, but it is not the optimal scalable session store and lacks the low-latency, purpose-built session handling of DynamoDB or ElastiCache.

205
Multi-Selectmedium

A company is migrating a legacy application to AWS. The application currently runs on a single on-premises server with a local MySQL database. The company wants to minimize changes and reduce operational overhead. Which TWO strategies should the solutions architect recommend? (Select TWO.)

Select 2 answers
A.Refactor the application to use microservices
B.Retire the application
C.Replatform the database to Amazon RDS for MySQL
D.Rehost the application on Amazon EC2
E.Repurchase a SaaS alternative
AnswersC, D

Amazon RDS for MySQL runs the same MySQL engine, so the application's queries and drivers work unchanged, satisfying the minimal-changes constraint. RDS also removes database patching, backup and server management tasks, directly reducing operational overhead.

Why this answer

Option C is correct because replatforming the local MySQL database to Amazon RDS for MySQL preserves the MySQL engine and schema while offloading patching, backups, and high availability to AWS, which reduces operational overhead with minimal application changes. Option D is correct because rehosting (lift-and-shift) the application onto Amazon EC2 moves the existing server workload to the cloud with little or no code modification, directly satisfying the goal of minimizing changes. Option A is not appropriate because refactoring into microservices requires significant redesign and development effort, contradicting the minimize-changes requirement.

Option B is wrong because retiring the application eliminates the workload rather than migrating it. Option E is wrong because repurchasing a SaaS alternative replaces the application entirely, which is a larger change than the company wants.

Exam trap

SAP-C02 often tests the trade-off between minimizing changes and reducing operational overhead, where candidates might over-optimize by choosing refactoring or repurchasing, ignoring the explicit requirement to minimize changes.

206
MCQmedium

A CloudFormation stack is created using the template above. The stack creation fails with the error: 'The following resource(s) failed to create: [EC2Instance]'. Logs show: 'AMI 'ami-0abcdef1234567890' does not exist.' What is the most likely cause?

A.The AMI ID is not available in the region where the stack is being deployed.
B.The SQS queue name 'my-queue' is already in use.
C.The AMI ID is invalid because it contains letters.
D.The instance type t2.micro is not supported in the region.
AnswerA

AMI IDs are region-specific, so an identifier valid in one region does not resolve in another. The stem's deployment targets a region lacking that image, producing the "does not exist" failure during EC2Instance creation. Copying the AMI to the target region, or referencing a region-appropriate ID, resolves the constraint.

Why this answer

The error 'AMI ami-0abcdef1234567890 does not exist' indicates that the specified AMI ID is not available in the AWS region where the CloudFormation stack is being deployed. AMI IDs are region-specific; an AMI that exists in us-east-1 will not exist in eu-west-1 unless it was explicitly copied or is a public AMI available in that region. The most likely cause is a region mismatch between the AMI ID and the stack's deployment region.

Exam trap

SAP-C02 often tests the regional nature of AMIs, so candidates who overlook that AMI IDs are region-specific may blame the instance type or queue name instead of the region mismatch.

How to eliminate wrong answers

Option B is wrong because an SQS queue name conflict would produce an error about the queue, not about the AMI; the error explicitly references the AMI ID. Option C is wrong because AMI IDs legitimately contain hexadecimal characters including letters (a-f), so the presence of letters does not make the ID invalid. Option D is wrong because if the instance type were unsupported, the error would mention the instance type, not the AMI; t2.micro is widely supported, and the error is specifically about the AMI.

207
MCQhard

A company has a data pipeline that uses AWS Glue to process large datasets in Amazon S3. The pipeline runs daily and takes over 12 hours to complete. The company wants to reduce the processing time. Which approach would be MOST effective?

A.Increase the Glue job timeout setting to 24 hours.
B.Enable S3 Transfer Acceleration on the source bucket.
C.Increase the number of DPUs allocated to the Glue job.
D.Convert the input data from CSV to Parquet format.
AnswerC

Glue scales horizontally by adding DPUs, each providing processing capacity and memory. Increasing DPUs for this long-running job parallelises the work across more executors, cutting the 12-hour runtime, whereas other changes do not raise raw compute throughput.

Why this answer

Increasing the number of DPUs (data processing units) allocated to the Glue job allows for greater parallelism, which directly reduces processing time for CPU-bound or memory-bound workloads. Option A is incorrect because increasing the timeout does not improve performance; it only prevents the job from failing due to time limits. Option B is incorrect because S3 Transfer Acceleration speeds up data transfer to S3, not the processing within Glue.

Option D is incorrect because while converting to Parquet can improve read performance and reduce data volume, it does not address the core processing bottleneck if the job is compute-intensive; the most effective immediate step is to increase DPUs.

208
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. The operations team reports that stack updates often fail because of resource conflicts. The team wants to improve the reliability of updates without manual intervention. Which solution provides the MOST automated recovery from update failures?

A.Use CloudFormation change sets to review and approve all changes before update.
B.Write a custom AWS Lambda function that reverts changes when a stack update fails.
C.Apply a stack policy to prevent updates to critical resources.
D.Use the default CloudFormation rollback behavior that automatically reverts changes on failure.
AnswerD

CloudFormation's default rollback automatically reverts stack resources to their last known stable state when an update fails, restoring service without operator involvement. This built-in behaviour delivers the hands-off recovery the team requires, unlike manual rollback or custom remediation tooling.

Why this answer

CloudFormation's built-in rollback behavior automatically reverts all changes made during a failed stack update, restoring the stack to its last known stable state without requiring any custom code or manual intervention. This provides the most automated recovery mechanism as it is natively integrated into the CloudFormation service and requires no additional infrastructure or scripting.

Exam trap

The trap here is that candidates may overthink the solution and choose a custom Lambda function (Option B) thinking it provides more control, when in fact CloudFormation's native rollback is the most automated and reliable approach, and custom solutions often introduce additional failure points.

How to eliminate wrong answers

Option A is wrong because change sets are a review and approval mechanism that helps prevent errors before an update is executed, but they do not provide any automated recovery after a failure occurs. Option B is wrong because writing a custom Lambda function to revert changes introduces unnecessary complexity, potential for errors, and is not as reliable or automated as CloudFormation's native rollback, which handles state management and resource dependencies correctly. Option C is wrong because stack policies only prevent updates to specific critical resources during a stack update, but they do not provide any recovery mechanism if the update fails due to conflicts elsewhere.

209
MCQhard

A solutions architect is optimizing a data processing workload that runs on AWS Lambda. The function processes large JSON files stored in Amazon S3, performs CPU-intensive transformations, and writes results to Amazon DynamoDB. The function currently has 512 MB of memory and takes about 10 minutes to process each file, occasionally timing out. The architect needs to reduce processing time and avoid timeouts. Which action is MOST effective?

A.Enable Lambda provisioned concurrency to ensure the function is always warm.
B.Increase the Lambda function's memory to 3008 MB and adjust the timeout to 15 minutes.
C.Move the function to a VPC and increase the ephemeral storage to 10 GB.
D.Configure the function to use AWS X-Ray tracing and enable AWS Lambda Insights.
AnswerB

Increasing memory also proportionally increases CPU and network bandwidth for Lambda. For CPU-intensive workloads, this can significantly reduce processing time. Raising the timeout to the maximum 15 minutes provides headroom to avoid timeouts while the function completes. This is the most direct way to improve performance for this scenario.

Why this answer

For CPU-intensive Lambda functions, memory allocation directly controls CPU share. Doubling or quadrupling memory can cut execution time substantially. Raising the timeout to 15 minutes provides a safety margin.

Provisioned concurrency, VPC placement, and monitoring tools do not increase compute resources during execution, so they fail to address the core performance and timeout problem.

Exam trap

The trap here is focusing on cold starts or observability when the real bottleneck is insufficient CPU, which is tied to the memory setting in Lambda.

210
MCQhard

A company is migrating a legacy on-premises application to AWS. The application uses a monolithic architecture and a MySQL database. The company wants to refactor the application into microservices and use a NoSQL database for better scalability. The new application will be deployed on Amazon EKS. The database must be highly available and support automatic scaling. Which database service should the company use?

A.Amazon Aurora Serverless
B.Amazon DynamoDB
C.Amazon DocumentDB (with MongoDB compatibility)
D.Amazon RDS for MySQL with Multi-AZ deployment
AnswerB

DynamoDB is a fully managed NoSQL key-value and document store that scales horizontally without provisioning, delivering single-digit-millisecond performance and multi-AZ durability by default. It satisfies the NoSQL, high-availability, and automatic-scaling requirements for the refactored microservices on Amazon EKS.

Why this answer

Amazon DynamoDB is a fully managed, serverless NoSQL key-value and document database that scales horizontally with automatic scaling, provides single-digit millisecond latency, and offers Multi-AZ high availability by default. It aligns with the requirement to move from a monolithic MySQL database to a NoSQL store for better scalability on EKS microservices.

Exam trap

The trap is picking DocumentDB because it is NoSQL and MongoDB-compatible, but the question does not require document semantics — DynamoDB is the default answer when 'NoSQL, highly available, automatic scaling, least operational overhead' are the criteria.

How to eliminate wrong answers

Option A is wrong because Aurora Serverless is a relational (MySQL/PostgreSQL-compatible) database, not NoSQL, and while it scales automatically, it does not meet the explicit NoSQL requirement. Option C is wrong because DocumentDB is MongoDB-compatible and would be a valid NoSQL choice, but the question does not specify a document model requirement, and DynamoDB is the more general-purpose, fully serverless, auto-scaling NoSQL option with the least operational overhead. Option D is wrong because RDS for MySQL with Multi-AZ is relational, not NoSQL, and does not provide the horizontal auto-scaling the scenario demands.

211
MCQmedium

A company uses AWS Organizations with a management account and 40 member accounts. The security team needs to centrally manage IAM roles that grant cross-account access to a shared services account. They want to deploy the roles to all member accounts and ensure new accounts automatically receive the roles. Which solution meets these requirements with the LEAST operational overhead?

A.Create an AWS CloudFormation StackSet with service-managed permissions in the management account, and configure automatic deployment to all accounts in the organization.
B.Use AWS Systems Manager Automation to run a script in each member account that creates the required IAM roles.
C.Enable AWS Control Tower and use its Account Factory to provision new accounts with a custom blueprint that includes the IAM roles.
D.Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share it with all member accounts.
AnswerA

CloudFormation StackSets with service-managed permissions integrate directly with AWS Organizations, allowing automatic deployment of IAM roles to all existing and future accounts. This eliminates manual per-account deployment and ensures new accounts receive the roles automatically, meeting the least operational overhead requirement.

Why this answer

CloudFormation StackSets with service-managed permissions is the native AWS Organizations-integrated solution for deploying a common stack to many accounts. It automatically targets existing accounts and new accounts as they join the organization, and it can be configured to deploy to specific OUs. This provides centralized management with minimal ongoing effort, unlike manual or script-based approaches.

Exam trap

The trap here is assuming that AWS RAM can share IAM roles across accounts, when RAM only supports specific resource types like subnets, transit gateways, and license configurations.

212
MCQeasy

A company is migrating a legacy application to AWS. The application uses a proprietary binary protocol that is not HTTP-based. The application currently runs on a single server and communicates with clients over TCP port 4444. The company wants to use AWS Elastic Load Balancing to distribute traffic across multiple EC2 instances for high availability. Which load balancer type should the company use?

A.AWS Global Accelerator
B.Classic Load Balancer (CLB)
C.Network Load Balancer (NLB)
D.Application Load Balancer (ALB)
AnswerC

Network Load Balancer operates at layer 4, forwarding TCP traffic on port 4444 without interpreting the proprietary binary protocol. This satisfies the requirement to distribute a non-HTTP protocol across multiple EC2 instances, which Application Load Balancer cannot handle.

Why this answer

A Network Load Balancer (NLB) operates at Layer 4 (TCP/UDP/TLS) and can forward arbitrary TCP traffic, including proprietary binary protocols on non-HTTP ports like 4444, while preserving source IP and supporting millions of requests per second with ultra-low latency. Because the application protocol is not HTTP-based, only a Layer 4 load balancer will work.

Exam trap

SAP-C02 often tests the Layer 4 vs Layer 7 distinction, baiting candidates into choosing ALB for any 'load balancing' scenario even when the protocol is non-HTTP.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator is not a load balancer — it is a networking service that routes traffic over the AWS global backbone to endpoints, and it still requires an ALB, NLB, or EC2 endpoint behind it. Option B is wrong because Classic Load Balancer is legacy and supports only basic Layer 4/7 features with limited protocol support and is not recommended for new designs. Option D is wrong because ALB is a Layer 7 load balancer that only understands HTTP/HTTPS (and gRPC/WebSocket), so it cannot forward a proprietary binary protocol on TCP 4444.

213
Multi-Selectmedium

A company is designing a new application that will run on Amazon EC2 instances. The application needs to access an Amazon S3 bucket to read and write objects. The company wants to ensure that the EC2 instances can access the S3 bucket without storing AWS credentials on the instances. Which TWO steps should the company take?

Select 2 answers
A.Attach the IAM role to the EC2 instance profile.
B.Store the AWS access key and secret access key in a configuration file on the instance.
C.Create an S3 bucket policy that allows access from the EC2 instance's IP address.
D.Configure the EC2 security group to allow outbound traffic to S3.
E.Create an IAM role with a policy that grants the required S3 permissions.
AnswersA, E

Attaching an IAM role to the EC2 instance profile lets the instance obtain temporary credentials from the instance metadata service automatically. The application then calls S3 using those rotating credentials, eliminating the need to store long-term AWS access keys on the instance.

Why this answer

Option A is correct because attaching an IAM role to the EC2 instance profile is the mechanism that delivers temporary, automatically rotated credentials to the instance via the instance metadata service (IMDS), so no long-term AWS credentials need to be stored on the instance. Option E is correct because the IAM role must first be created with a policy granting the specific S3 permissions (for example, s3:GetObject and s3:PutObject on the target bucket/prefix); without this role and policy, the instance profile would have nothing to assume. Option B is wrong because storing access keys in a configuration file on the instance is exactly the practice the company wants to avoid, and long-term keys are a security risk.

Option C is wrong because an S3 bucket policy based on the EC2 instance's IP address is brittle and does not eliminate credentials; it also fails for instances behind NAT or with changing IPs. Option D is wrong because security groups control network reachability only and do not grant S3 authorization; outbound HTTPS to S3 is necessary but not sufficient, and it does not address credential-free access.

Exam trap

The trap here is that candidates often confuse network-level controls (security group outbound rules) with authentication/authorization mechanisms, thinking that allowing outbound traffic to S3 is sufficient to grant access, when in fact the instance still needs valid IAM credentials to authenticate requests to S3.

214
MCQmedium

A media company is designing a video transcoding pipeline. They receive raw video files in Amazon S3, which need to be transcoded into multiple formats. The pipeline must handle sporadic bursts of uploads and complete processing within 30 minutes for each video. The cost should be minimized. Which design should they use?

A.Use AWS Lambda with layers containing FFmpeg to transcode videos.
B.Use Amazon S3 event notifications to trigger an AWS Elemental MediaConvert job.
C.Provision a cluster of EC2 instances running FFmpeg, with Auto Scaling based on SQS queue depth.
D.Use Amazon Elastic Transcoder, which is fully managed and triggers from S3 events.
AnswerB

S3 event notifications invoke MediaConvert directly, giving a fully managed, serverless transcoding service that scales per job without idle compute. This satisfies the sporadic-burst requirement and the 30-minute completion window, while consumption-based pricing minimises cost compared with continuously running EC2 transcoding fleets.

Why this answer

AWS Elemental MediaConvert is a fully managed, serverless video transcoding service designed for high-volume, bursty workloads. It integrates directly with S3 event notifications, scales automatically to handle sporadic uploads, and completes each job within the required 30-minute window. Its pay-per-use pricing minimizes cost by eliminating idle infrastructure, unlike provisioned EC2 clusters or Lambda's 15-minute execution limit.

Exam trap

The trap here is that candidates often assume Lambda can handle any short-lived compute task, but they overlook the 15-minute timeout and lack of GPU support for video encoding, making it unsuitable for transcoding jobs that require longer processing times or specialized hardware acceleration.

How to eliminate wrong answers

Option A is wrong because AWS Lambda has a maximum execution timeout of 15 minutes, which cannot accommodate transcoding jobs that may exceed this limit, especially for high-resolution or long-duration videos. Option C is wrong because provisioning a cluster of EC2 instances with Auto Scaling based on SQS queue depth incurs significant idle costs during low-activity periods and requires ongoing operational overhead for patching and scaling, making it less cost-effective than a fully managed service. Option D is wrong because Amazon Elastic Transcoder is a legacy service that is being phased out in favor of Elemental MediaConvert; it lacks advanced features like per-title encoding, Dolby Vision, and HDR10+ support, and its pricing model is generally less flexible for sporadic workloads.

215
MCQhard

A multinational company has a multi-account AWS environment with a central network account. They use AWS Transit Gateway to connect all VPCs. The company wants to implement centralized inspection of all traffic between VPCs using a third-party firewall appliance running on EC2 instances in a dedicated inspection VPC. Traffic must be inspected without modifying workload VPC route tables when new VPCs are added. What should the solutions architect recommend?

A.Deploy the firewall instances in the central network account and use AWS Resource Access Manager to share them with all workload accounts, then update each workload VPC's route tables to point to the firewall ENIs.
B.Use AWS PrivateLink to connect each workload VPC to the inspection VPC, and configure endpoint policies to redirect traffic.
C.Use AWS Transit Gateway with a separate route table for the inspection VPC, and configure the firewall instances as appliances in the inspection VPC. Use Transit Gateway route table associations and propagations to direct traffic through the inspection VPC.
D.Create a VPC peering connection between each workload VPC and the inspection VPC, and update each workload VPC's route tables to point to the inspection VPC for inter-VPC traffic.
AnswerC

Transit Gateway route tables can be used to isolate and direct traffic. By associating workload VPC attachments with a route table that points to the inspection VPC attachment, and associating the inspection VPC attachment with a route table that points to workload VPCs, you can force traffic through the firewall without modifying workload VPC route tables. New VPCs can be associated with the appropriate route table centrally.

Why this answer

Transit Gateway route tables allow centralized traffic steering. By associating workload VPC attachments with a route table that routes to the inspection VPC, and the inspection VPC attachment with a route table that routes back, traffic is forced through the firewall. New VPCs only need to be associated with the correct route table, avoiding workload VPC route table changes.

Exam trap

The trap here is thinking that VPC peering or PrivateLink can provide centralized inspection without modifying workload VPC route tables, when they actually require per-VPC route changes or do not support arbitrary traffic inspection.

216
MCQmedium

A company is designing a new microservices application using Amazon ECS with Fargate. The services need to communicate securely within the VPC. Which approach should be used for service discovery?

A.Amazon Route 53 private hosted zones with health checks
B.AWS Cloud Map
C.VPC peering connections between services
D.Application Load Balancer with path-based routing
AnswerB

AWS Cloud Map provides service discovery with health-checked registration of ECS tasks, returning IP addresses and ports through DNS or API calls. This suits Fargate tasks, whose addresses change, and keeps service-to-service traffic inside the VPC.

Why this answer

AWS Cloud Map is the correct choice because it provides a fully managed service discovery solution that integrates natively with Amazon ECS and Fargate. It allows microservices to register themselves with DNS-based or API-based service endpoints, enabling dynamic, secure communication within the VPC without requiring manual IP management or external DNS configuration.

Exam trap

The trap here is that candidates often confuse DNS-based resolution (Route 53 private hosted zones) with dynamic service discovery (AWS Cloud Map), assuming that static DNS records with health checks are sufficient for microservices that scale and change IPs frequently.

How to eliminate wrong answers

Option A is wrong because Route 53 private hosted zones with health checks are designed for DNS resolution and health monitoring of static resources, not for dynamic service discovery where service endpoints change frequently due to scaling or restarts. Option C is wrong because VPC peering connects entire VPCs, not individual services, and does not provide service discovery; it is a network connectivity mechanism, not a discovery mechanism. Option D is wrong because an Application Load Balancer with path-based routing is used for traffic distribution and routing to backend targets, not for service discovery; it does not provide a registry or DNS-based resolution for individual service instances.

217
MCQeasy

A startup is building a web application on AWS that requires a relational database. They expect unpredictable traffic patterns and want to minimize costs while ensuring high availability. Which database solution should they choose?

A.Amazon Redshift with concurrency scaling
B.Amazon Aurora Serverless (MySQL-compatible)
C.Amazon RDS for MySQL with Single-AZ deployment
D.Amazon DynamoDB with on-demand capacity
AnswerB

Aurora Serverless automatically scales compute capacity up and down with unpredictable traffic and pauses when idle, so the startup pays only for capacity used. It also provides Multi-AZ high availability with automatic failover, satisfying both the cost-minimisation and availability requirements.

Why this answer

Amazon Aurora Serverless (MySQL-compatible) is the correct choice because it automatically scales compute capacity based on actual application demand, making it ideal for unpredictable traffic patterns. It provides high availability through multi-AZ storage and automated failover, while minimizing costs by only charging for consumed capacity during active periods.

Exam trap

The trap here is that candidates often confuse 'relational database' with 'NoSQL' (DynamoDB) or choose a cheaper but non-HA option (Single-AZ RDS), overlooking that Aurora Serverless uniquely combines relational capabilities, automatic scaling, and built-in high availability at a cost-effective pay-per-request model.

How to eliminate wrong answers

Option A is wrong because Amazon Redshift is a data warehouse optimized for analytical queries on large datasets, not a transactional relational database for a web application, and concurrency scaling adds cost without addressing unpredictable traffic for OLTP workloads. Option C is wrong because Amazon RDS for MySQL with Single-AZ deployment lacks high availability—it does not provide automatic failover to a standby instance in another Availability Zone, which is required for the stated goal. Option D is wrong because Amazon DynamoDB is a NoSQL key-value and document database, not a relational database, and while on-demand capacity handles unpredictable traffic, it does not support SQL queries or relational data models needed for a web application with a relational database requirement.

218
MCQhard

A company is designing a new global application that requires a relational database with low-latency reads in multiple AWS Regions. The database must support automatic failover to a secondary Region in case of a disaster. The company wants to minimize operational overhead and ensure data consistency across Regions. Which solution should a solutions architect recommend?

A.Use Amazon RDS for PostgreSQL with Multi-AZ deployment and a cross-Region replica for disaster recovery.
B.Use Amazon RDS for MySQL with a cross-Region read replica and promote the replica during a failover.
C.Use Amazon Aurora Global Database with a primary Region and secondary Regions, enabling managed planned failover.
D.Use Amazon DynamoDB global tables with automatic multi-Region replication.
AnswerC

Amazon Aurora Global Database is designed for global applications, providing low-latency reads in secondary Regions with typical replication lag under one second. It supports managed planned failover, which promotes a secondary Region to primary with minimal data loss and automatic DNS updates. This minimizes operational overhead and ensures data consistency across Regions.

Why this answer

Amazon Aurora Global Database provides a relational database with low-latency reads in multiple Regions and supports managed planned failover. It replicates data with minimal lag, ensuring consistency, and the failover process is automated, reducing operational overhead. This meets the requirements for a global application with automatic disaster recovery.

Exam trap

The trap here is assuming that a cross-Region read replica provides automatic failover, when in fact it requires manual promotion and may lose data.

219
MCQeasy

A company is migrating to AWS and wants to use AWS CloudFormation to manage infrastructure as code. The DevOps team needs to ensure that stack updates are reviewed and approved before execution. Which feature should they use?

A.AWS CloudFormation Drift Detection
B.AWS CloudFormation StackSets
C.AWS CloudFormation Change Sets
D.AWS CloudFormation Nested Stacks
AnswerC

CloudFormation change sets generate a preview of proposed resource modifications before execution, letting reviewers inspect additions, deletions and replacements. This directly satisfies the stem's requirement that stack updates be reviewed and approved prior to execution, since the change set must be explicitly executed after inspection.

Why this answer

AWS CloudFormation Change Sets allow you to preview how proposed changes to a stack will impact your running resources before you apply them. This enables the DevOps team to review and approve stack updates by generating a summary of the changes (additions, modifications, deletions) without executing them immediately, meeting the requirement for a review-and-approval workflow.

Exam trap

The trap here is that candidates may confuse Drift Detection (which detects post-deployment configuration drift) with Change Sets (which preview intended changes before deployment), leading them to select Option A incorrectly.

How to eliminate wrong answers

Option A is wrong because Drift Detection is used to detect whether a stack's actual resources have deviated from the expected template configuration, not to review or approve updates before execution. Option B is wrong because StackSets enable you to deploy stacks across multiple accounts and regions from a single template, but they do not provide a mechanism to preview or approve changes before applying them. Option D is wrong because Nested Stacks allow you to compose stacks from other stacks for modularity, but they do not offer a change review or approval process for updates.

220
MCQmedium

A company uses AWS CloudTrail to log all API calls. The security team wants to be alerted when an IAM user creates a new access key. What is the MOST efficient way to achieve this?

A.Enable CloudTrail Insights to detect unusual key creation patterns.
B.Create a CloudWatch Events rule that matches the CreateAccessKey API call and sends an SNS notification.
C.Use CloudTrail to publish logs to CloudWatch Logs and create a metric filter to trigger an alarm.
D.Configure Amazon Athena to query CloudTrail logs and set up a scheduled query to notify.
AnswerB

CloudWatch Events (now EventBridge) pattern-matches the CreateAccessKey API call directly from CloudTrail's management event stream, triggering SNS without polling or log parsing. This satisfies the efficiency constraint: no Lambda, no CloudWatch Logs metric filters, and near-real-time alerting on the exact IAM action specified.

Why this answer

The most efficient way to alert when an IAM user creates a new access key is to use CloudWatch Events (now Amazon EventBridge) to match the CreateAccessKey API call from CloudTrail and trigger an SNS notification. Option A is incorrect because CloudTrail Insights is for detecting unusual activity patterns, not for real-time event-driven alerts. Option C is less efficient because it requires additional steps of publishing logs to CloudWatch Logs and creating a metric filter, adding complexity.

Option D is inefficient because querying CloudTrail logs with Athena is not real-time and requires custom scheduling.

221
MCQhard

A company uses AWS CloudFormation to manage infrastructure. The stack fails to update with the error: 'Resource handler returned message: The subnet 'subnet-xxx' is in use by a network interface.' The subnet is associated with a Lambda function in a VPC. The CloudFormation template is trying to delete the subnet. What should the company do to resolve this?

A.Update the Lambda function configuration to remove the VPC settings, then delete the subnet.
B.Modify the CloudFormation template to ignore the deletion failure using a DeletionPolicy attribute.
C.Use the AWS CLI to force delete the subnet.
D.Manually delete the Elastic Network Interface (ENI) from the AWS Management Console.
AnswerA

The Lambda function's elastic network interface holds the subnet, blocking deletion. Detaching the VPC configuration releases that interface, allowing CloudFormation to delete the subnet cleanly. This directly resolves the 'in use by a network interface' error the stack reports.

Why this answer

The error indicates that the subnet cannot be deleted because it is in use by a network interface, which is likely the Lambda function's elastic network interface (ENI). To resolve this, the Lambda function's VPC configuration must be removed so that the ENI is released, allowing the subnet to be deleted. This is the correct approach because CloudFormation cannot delete a subnet that still has dependencies.

Exam trap

SAP-C02 often tests the misconception that DeletionPolicy can force deletion of resources with dependencies, but it only controls retention; the real solution is to remove the dependency first.

How to eliminate wrong answers

Option B is wrong because a DeletionPolicy attribute only controls what happens to a resource when it is removed from the stack; it does not bypass the dependency check that prevents deletion of a subnet in use. Option C is wrong because AWS does not provide a force delete for subnets; the subnet must be free of dependencies. Option D is wrong because manually deleting the ENI may not be possible if it is managed by Lambda, and even if it were, it would not be a sustainable solution; the Lambda function would recreate the ENI.

222
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. The operations team wants to implement a change management process where all stack updates must be reviewed and approved before execution. The team currently uses AWS CodePipeline for CI/CD. Which solution meets these requirements with the LEAST operational overhead?

A.Use CloudFormation Change Sets and require a senior engineer to execute them.
B.Write an AWS Lambda function that triggers on stack update events and requires approval via Amazon SNS.
C.Use AWS Service Catalog to govern CloudFormation templates and require approval for provisioning.
D.Store CloudFormation templates in AWS CodeCommit and use AWS CLI to execute updates after peer review.
E.Create a CodePipeline pipeline with an approval stage before the CloudFormation deployment action.
AnswerE

A manual approval stage in CodePipeline halts the pipeline until a nominated reviewer approves, then triggers the CloudFormation deploy action. This satisfies the mandated review-and-approval gate before execution while reusing the existing CI/CD tooling, so no custom change-management system is built, keeping operational overhead minimal.

Why this answer

AWS CodePipeline natively supports approval actions, allowing a manual approval stage to be inserted before the CloudFormation deployment action. This integrates directly with the existing CI/CD pipeline, requires minimal custom code, and enforces review/approval before stack updates. It is the lowest-operational-overhead solution that meets the change management requirement.

Exam trap

SAP-C02 often tests the 'least operational overhead' constraint — candidates may over-engineer with Lambda/SNS or Service Catalog when the native CodePipeline approval action is the simplest fit.

How to eliminate wrong answers

Option A is wrong because relying on a senior engineer to manually execute change sets is error-prone and does not integrate with the CI/CD pipeline, adding operational overhead. Option B is wrong because writing a Lambda function and SNS approval workflow is custom code that must be built and maintained, increasing overhead. Option C is wrong because Service Catalog governs provisioning of approved products, not approval of stack updates within a CI/CD pipeline.

Option D is wrong because storing templates in CodeCommit and using CLI after peer review is a manual process that bypasses pipeline automation and adds overhead.

223
MCQmedium

A company is migrating its on-premises Active Directory to AWS Managed Microsoft AD. The company has multiple VPCs across different accounts that need to authenticate against the same directory. What is the MOST scalable and secure way to provide this access?

A.Set up a VPN connection from each VPC to the on-premises AD.
B.Deploy AWS Managed Microsoft AD in a central account and share it with other accounts using AWS Resource Access Manager.
C.Clone the directory and deploy it in each account.
D.Deploy an AD Connector in each VPC pointing to the on-premises AD.
AnswerB

AWS Resource Access Manager shares a single AWS Managed Microsoft AD directory across accounts and VPCs, avoiding duplicate directories. This centralises authentication, satisfies the multi-VPC requirement, and scales without per-account directory deployments or exposed credentials.

Why this answer

AWS Resource Access Manager (RAM) allows you to share AWS Managed Microsoft AD directories across accounts without duplicating the directory or managing multiple trust relationships. This provides a single, centrally managed directory that multiple VPCs in different accounts can authenticate against, ensuring scalability and security by avoiding cross-account credential replication or complex VPN meshes.

Exam trap

The trap here is that candidates often assume each VPC needs its own directory or AD Connector, but AWS RAM enables secure, scalable sharing of a single Managed AD across accounts without additional infrastructure.

How to eliminate wrong answers

Option A is wrong because setting up a VPN from each VPC to on-premises AD does not leverage AWS Managed Microsoft AD and introduces latency, single points of failure, and management overhead for multiple VPN tunnels; it also fails to migrate the directory to AWS as required. Option C is wrong because cloning the directory and deploying it in each account creates multiple independent directories that require complex cross-forest trusts or replication, breaking the requirement for a single shared directory and increasing administrative burden. Option D is wrong because deploying an AD Connector in each VPC points back to the on-premises AD, which does not migrate the directory to AWS Managed Microsoft AD and still relies on on-premises infrastructure, defeating the purpose of the migration.

224
MCQhard

A company is migrating a legacy Oracle database to Amazon Aurora PostgreSQL. The migration must minimize downtime and support ongoing replication. Which AWS service should the company use?

A.AWS DataSync
B.AWS Database Migration Service (DMS) with change data capture (CDC)
C.AWS Direct Connect
D.AWS Schema Conversion Tool (SCT)
AnswerB

DMS handles both the initial full load and ongoing replication via change data capture, reading the Oracle redo logs to apply continuous changes to Aurora PostgreSQL. This satisfies the minimal-downtime and ongoing-replication constraints, unlike snapshot-only tools that require an outage window.

Why this answer

B is correct because AWS DMS with ongoing replication (CDC) can migrate data with minimal downtime. A is wrong because AWS DataSync is designed for file-based data transfers, not database replication. C is wrong because AWS Direct Connect provides a dedicated network connection but does not handle database migration or replication.

D is wrong because the AWS Schema Conversion Tool (SCT) only converts schema and code, not the actual data.

225
MCQhard

A company is designing a new data lake on AWS. The data lake must support SQL queries using Amazon Athena and also allow Amazon SageMaker to access training data. The solution must minimize storage costs for infrequently accessed data while providing immediate access when needed. Which storage tier should be used for the data lake?

A.Amazon S3 Glacier Deep Archive
B.Amazon S3 Intelligent-Tiering
C.Amazon S3 Standard
D.Amazon S3 One Zone-Infrequent Access
AnswerB

S3 Intelligent-Tiering automatically moves objects between frequent and infrequent access tiers based on changing access patterns, with no retrieval fees. It serves Athena queries and SageMaker training reads immediately while cutting storage cost for cold data.

Why this answer

Amazon S3 Intelligent-Tiering is the correct choice because it automatically moves data between access tiers (frequent, infrequent, and archive instant access) based on changing access patterns, optimizing storage costs without compromising performance. This meets the requirement for infrequently accessed data to be cost-effective while still providing immediate access for Athena queries and SageMaker training, as data in the archive instant access tier can be retrieved within milliseconds.

Exam trap

The trap here is that candidates might choose S3 Standard for its immediate access or S3 Glacier Deep Archive for lowest cost, overlooking that S3 Intelligent-Tiering provides both cost optimization for infrequent access and immediate retrieval via the Archive Instant Access tier.

How to eliminate wrong answers

Option A is wrong because Amazon S3 Glacier Deep Archive has retrieval times of 12-48 hours, which fails the requirement for immediate access when needed for Athena and SageMaker. Option C is wrong because Amazon S3 Standard is designed for frequently accessed data and would be more expensive for infrequently accessed data, not minimizing storage costs. Option D is wrong because Amazon S3 One Zone-Infrequent Access stores data in a single Availability Zone, which risks data loss if that AZ fails, and it lacks automatic cost optimization for varying access patterns.

Page 2

Page 3 of 14

Page 4