Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 226–300

984 questions total · 14pages · All types, answers revealed

Page 3

Page 4 of 14

Page 5
226
MCQeasy

A company is migrating a large Oracle database to Amazon Aurora PostgreSQL. The migration must have minimal downtime and support ongoing replication. Which AWS service should the company use?

A.AWS Application Discovery Service
B.AWS Server Migration Service
C.AWS Database Migration Service
D.AWS Schema Conversion Tool
AnswerC

AWS Database Migration Service performs heterogeneous Oracle-to-Aurora PostgreSQL conversion and supports ongoing change data capture replication, keeping the source and target synchronised. This satisfies the minimal-downtime constraint, since cutover happens only after replication has caught up.

Why this answer

AWS Database Migration Service (DMS), is the correct answer because it is specifically designed for migrating databases to AWS with minimal downtime, and it supports ongoing replication from Oracle to Aurora PostgreSQL using change data capture (CDC). Option A is incorrect because AWS Application Discovery Service is used for discovering on-premises servers and applications, not for database migration. Option B is incorrect because AWS Server Migration Service (now part of SMS) is for migrating virtual machines, not databases.

Option D is incorrect because AWS Schema Conversion Tool (SCT) is used to convert the database schema from one engine to another, not for ongoing replication; it is often used alongside DMS.

227
Multi-Selectmedium

A company is designing a new application that will process sensitive financial data. They need to ensure encryption at rest and in transit. Which of the following should they use? (Select TWO.)

Select 2 answers
A.TLS for all data in transit
B.AWS Certificate Manager (ACM) for all encryption
C.SSL certificates for all connections
D.AWS Key Management Service (KMS) for encryption at rest
E.AWS Identity and Access Management (IAM) for data encryption
AnswersA, D

TLS encrypts data in transit between clients and services, directly satisfying the in-transit encryption requirement for sensitive financial data. It protects against interception on the network, complementing at-rest encryption. Selecting TLS alongside a KMS-based at-rest control fulfils both stated constraints.

Why this answer

Option A (TLS for all data in transit) is correct because Transport Layer Security encrypts data moving between clients and servers, protecting sensitive financial data from interception or tampering over the network. Option D (AWS Key Management Service (KMS) for encryption at rest) is correct because KMS lets the company create and manage customer master keys used to encrypt stored data, such as EBS volumes, S3 objects, and RDS databases, satisfying the encryption-at-rest requirement. Option B is not correct because AWS Certificate Manager only provisions, manages, and deploys TLS/SSL certificates; it does not itself perform encryption of data at rest or in transit.

Option C is not correct because SSL is a deprecated predecessor to TLS, and simply having certificates does not guarantee encryption is enforced on all connections. Option E is not correct because IAM controls authentication and authorization to AWS resources; it does not encrypt data.

Exam trap

The trap here is that candidates confuse SSL/TLS certificates (which are just cryptographic containers) with the actual encryption protocol (TLS), and they mistakenly think ACM or IAM directly perform encryption instead of managing certificates or access.

228
MCQmedium

A company is designing a new multi-tenant SaaS application on AWS. Each tenant must have its own AWS KMS customer managed key (CMK) for encrypting data at rest in Amazon S3. The security team requires that the encryption keys are automatically rotated every year and that key usage is logged for auditing. The application will use AWS Lambda functions to encrypt and decrypt data on behalf of tenants. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS Certificate Manager (ACM) to generate and manage per-tenant encryption keys. Configure Lambda functions to use the ACM-provided keys for S3 encryption.
B.Create a single AWS KMS CMK for all tenants and use encryption context to differentiate tenants. Enable automatic rotation on the CMK and grant Lambda functions permission to use the key.
C.Use AWS Secrets Manager to store a unique encryption key per tenant. Configure Lambda functions to retrieve the key and perform client-side encryption before storing data in Amazon S3.
D.Create a separate AWS KMS CMK per tenant with automatic key rotation enabled. Configure the Lambda execution role with kms:Encrypt and kms:Decrypt permissions scoped to each tenant's key using IAM policy conditions.
AnswerD

This solution uses AWS KMS CMKs with automatic rotation, satisfying the yearly rotation requirement. IAM policies scoped to each tenant's key enforce least privilege, and KMS integrates with AWS CloudTrail to log all key usage. Lambda functions can assume a role with the necessary permissions, and no custom key management overhead is required.

Why this answer

The requirement for per-tenant encryption keys with automatic yearly rotation and audit logging is best met by AWS KMS customer managed keys. KMS provides automatic key rotation, integrates with AWS CloudTrail for auditing, and allows fine-grained IAM policies to scope access per key. Lambda functions can securely use these keys via their execution role, minimizing operational overhead.

Exam trap

The trap here is assuming that a single KMS key with encryption context can provide sufficient tenant isolation, but the requirement explicitly demands separate keys per tenant.

229
Multi-Selectmedium

A company is migrating a web application to AWS. The application currently runs on a single server and uses a MySQL database. The company wants to ensure high availability and scalability. The web application is stateless. Which TWO actions should the company take to achieve these goals? (Choose TWO.)

Select 2 answers
A.Deploy the web application on Amazon EC2 instances in an Auto Scaling group across multiple Availability Zones, with an Application Load Balancer
B.Use a single Amazon RDS for MySQL DB instance
C.Use Multi-AZ Amazon RDS for MySQL
D.Use Amazon ElastiCache to cache database queries
E.Use a large EC2 instance for the web application with Elastic IP
AnswersA, C

An Application Load Balancer distributing traffic across an Auto Scaling group spanning multiple Availability Zones delivers both elasticity and fault tolerance. Because the application is stateless, any instance can serve any request, so horizontal scaling and zone redundancy directly satisfy the high availability and scalability goals.

Why this answer

To achieve high availability and scalability for the web application, the company should deploy the web tier across multiple Availability Zones using an Auto Scaling group with an Application Load Balancer (Option A), which distributes traffic and automatically scales instances. For the MySQL database, using Multi-AZ Amazon RDS (Option C) provides automatic failover and high availability. Option B (single RDS instance) is a single point of failure.

Option D (ElastiCache) is for caching, not for high availability or scaling. Option E (large EC2 instance with Elastic IP) does not provide scalability or availability.

230
MCQmedium

A company is deploying a new web application that uses Amazon S3 to store static content and Amazon CloudFront for content delivery. The application also uses an API Gateway with Lambda for backend logic. The company wants to protect the API from common web exploits like SQL injection and cross-site scripting. Which AWS service should be added to the architecture?

A.Amazon GuardDuty
B.Amazon Inspector
C.AWS Shield Advanced
D.AWS WAF
AnswerD

AWS WAF attaches to API Gateway and inspects HTTP requests against managed rule groups that block SQL injection and cross-site scripting patterns. CloudFront and S3 serve static content, so WAF on the API layer satisfies the requirement to protect backend logic from common web exploits.

Why this answer

AWS WAF integrates with API Gateway and CloudFront to protect against web exploits like SQL injection and cross-site scripting. Option A: Amazon GuardDuty is for threat detection, not inline protection. Option B: Amazon Inspector is for vulnerability assessment.

Option C: AWS Shield Advanced provides DDoS protection, not application-layer filtering.

231
MCQmedium

Refer to the exhibit. $ aws ec2 describe-instances --region us-east-1 --filters Name=tag:Name,Values=WebServer --query 'Reservations[].Instances[].{ID:InstanceId,State:State.Name,Type:InstanceType,LaunchTime:LaunchTime}' --output table A DevOps engineer runs the above command. The Auto Scaling group for WebServer instances has a desired count of 3, but the engineer notices that there are 5 instances with the same tag. What is the MOST likely cause?

A.The Auto Scaling group has a cooldown period that prevents immediate termination.
B.The command is filtering by the wrong tag key.
C.The other two instances are in a 'terminating' state and are not returned by the command.
D.The instances were launched with a different launch template that does not have the tag.
AnswerB

Correct. The tag key in the filter (Name) may not match the actual tag key on some instances. If the tag key is different (e.g., 'name' or 'web'), those instances would not be returned, but the engineer sees 5 instances, indicating the filter is matching instances from outside the ASG.

Why this answer

The `describe-instances` command filters by the `Name` tag with value `WebServer`, returning every instance that has that exact tag, regardless of whether it belongs to the Auto Scaling group. Seeing 5 instances while the ASG desired count is 3 indicates the filter is not specific to the ASG. The engineer is likely filtering by the wrong tag key; they should use an ASG-specific tag such as `tag:aws:autoscaling:groupName`.

Option C is incorrect because `describe-instances` returns terminating instances. Option A is less likely because cooldown periods do not affect tag-based instance queries. Option D is incorrect because instances launched without the `Name` tag would not appear in the output.

Exam trap

A common trap is to assume that instances in 'terminating' state are not returned by describe-instances, but they are. The filter's tag key must exactly match the instance tags; minor differences can lead to missing or extra results.

232
MCQmedium

A company is migrating a legacy application that uses Windows Authentication for SQL Server. The company wants to use AWS Managed Microsoft AD. Which migration strategy should be used for the database to maintain compatibility?

A.Use AWS DMS to migrate to Amazon DynamoDB
B.Replatform to Amazon RDS for MySQL
C.Replatform to Amazon RDS for SQL Server with Windows Authentication
D.Replatform to Amazon Aurora PostgreSQL
AnswerC

Amazon RDS for SQL Server joined to AWS Managed Microsoft AD supports Windows Authentication, so the legacy application's existing authentication mechanism continues to work without code changes. Replatforming preserves compatibility while removing database administration overhead.

Why this answer

AWS Managed Microsoft AD is a managed Active Directory service that supports Windows Authentication (Kerberos/NTLM) natively. Amazon RDS for SQL Server can be domain-joined to AWS Managed Microsoft AD, allowing the database to continue using Windows Authentication without code changes. This preserves the legacy application's authentication model during migration.

Exam trap

SAP-C02 often tests the misconception that any managed database service can replace SQL Server, ignoring that Windows Authentication requires Active Directory integration only available with RDS for SQL Server joined to AWS Managed Microsoft AD.

How to eliminate wrong answers

Option A is wrong because DynamoDB is a NoSQL key-value store that does not support Windows Authentication or SQL Server's authentication model, requiring a full application rewrite. Option B is wrong because RDS for MySQL uses MySQL-native authentication, not Windows Authentication, so the legacy app's integrated security would break. Option D is wrong because Aurora PostgreSQL uses PostgreSQL authentication mechanisms and does not support Windows Authentication via Active Directory.

233
Multi-Selectmedium

A company is designing a multi-tier web application that must be fault-tolerant and scalable. The application uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in an Auto Scaling group. The instances run a web server and a backend application. Which TWO steps should be taken to ensure the application can scale without data loss?

Select 2 answers
A.Use instance store volumes for temporary data.
B.Store session state in an external data store such as ElastiCache.
C.Implement lifecycle hooks to gracefully handle instance termination.
D.Use a custom CloudWatch metric to scale based on CPU utilization.
E.Use a fixed number of EC2 instances instead of Auto Scaling.
AnswersB, C

Storing session state externally makes instances stateless, preventing data loss on scale-in.

Why this answer

Storing session state in an external data store like ElastiCache decouples session data from individual EC2 instances. This ensures that if an instance is terminated or replaced during scaling events, the session data persists and can be served by any other instance in the Auto Scaling group, preventing data loss and maintaining user experience.

Exam trap

The trap here is that candidates often confuse instance store with EBS or assume that lifecycle hooks alone (Option C) prevent data loss, but lifecycle hooks only delay termination for cleanup—they do not preserve session data if the instance is ultimately terminated, making an external data store essential.

234
MCQmedium

A company is designing a CI/CD pipeline for a containerized application using AWS CodePipeline. The application is deployed to Amazon ECS with Fargate. The pipeline must automatically build and test code changes before deploying to production. Which service should be used to build and test the Docker images?

A.AWS CodeDeploy
B.AWS CodeBuild
C.Amazon ECR
D.AWS CodeCommit
AnswerB

CodeBuild is the managed build service that natively integrates with CodePipeline, compiling code and running tests inside Docker containers. It produces the tested image artefact the pipeline then deploys to ECS Fargate, satisfying the requirement to build and test before production release.

Why this answer

AWS CodeBuild is the correct service because it is a fully managed continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy. In this scenario, CodeBuild can build the Docker image from a Dockerfile, run unit or integration tests inside the build environment, and then push the image to Amazon ECR, all within the CI/CD pipeline defined in AWS CodePipeline.

Exam trap

The trap here is that candidates may confuse AWS CodeDeploy's role in ECS deployments with the build and test phase, assuming CodeDeploy handles the entire CI/CD process, when in fact it only handles the deployment step after the image is built and tested by CodeBuild.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a deployment service that automates code deployments to compute services like ECS, EC2, or Lambda, but it does not build or test Docker images. Option C is wrong because Amazon ECR is a container image registry for storing, managing, and deploying Docker images; it does not perform build or test operations. Option D is wrong because AWS CodeCommit is a source control service for hosting Git repositories; it does not build or test code.

235
MCQmedium

A company is designing a serverless application using AWS Lambda that needs to access a private Amazon RDS for MySQL database. The Lambda function is deployed in a VPC with the appropriate security groups. The database is in a private subnet. The company wants to avoid storing database credentials in the Lambda function code. What should the company do to securely access the database?

A.Create an IAM role that allows Lambda to access the RDS instance using IAM database authentication.
B.Pass the database credentials as environment variables to the Lambda function.
C.Store the database credentials in AWS Secrets Manager and retrieve them using the Secrets Manager API in the Lambda function.
D.Store the database credentials in AWS Systems Manager Parameter Store and retrieve them in the Lambda function.
AnswerC

AWS Secrets Manager provides a secure, auditable service for storing and automatically rotating database credentials. The Lambda function can retrieve the credentials at runtime via the Secrets Manager API, avoiding hard-coded secrets.

Why this answer

Option C is the best answer. AWS Secrets Manager securely stores database credentials and supports automatic rotation, and Lambda can retrieve them at runtime through the Secrets Manager API without hardcoding credentials. Option A (IAM database authentication) is valid only if the RDS MySQL instance is explicitly configured for IAM authentication and is not the general best practice for avoiding stored credentials.

Option B exposes credentials in environment variables, and Option D (Parameter Store) lacks native automatic rotation for RDS credentials.

Exam trap

The trap here is that candidates may confuse AWS Systems Manager Parameter Store (Option D) with Secrets Manager, but Parameter Store lacks native automatic rotation and is not the best practice for database credentials requiring rotation, making Secrets Manager the correct choice for this scenario.

How to eliminate wrong answers

Option A is wrong because IAM database authentication for RDS MySQL requires the user to authenticate with an authentication token generated using the IAM credentials, but it does not eliminate the need to store the master password or other credentials; it only replaces password-based authentication for specific database users, and the Lambda function still needs to securely obtain the token, which Secrets Manager can provide. Option B is wrong because passing database credentials as environment variables to the Lambda function is insecure; environment variables can be exposed in logs, CloudTrail, or the Lambda console, and they do not support automatic rotation or fine-grained access control. Option D is wrong because AWS Systems Manager Parameter Store is a viable option for storing secrets, but it lacks native automatic rotation capabilities and is not the recommended service for database credentials requiring rotation; Secrets Manager is the preferred service for this use case.

236
MCQeasy

A company is using AWS Organizations with multiple organizational units (OUs). The security team needs to enforce that all newly created S3 buckets in the production OU have versioning enabled and are encrypted with AWS KMS. Which solution meets these requirements with minimal operational overhead?

A.Apply a service control policy (SCP) at the production OU level that denies s3:CreateBucket unless versioning and KMS encryption are specified in the request.
B.Use AWS CloudTrail to monitor bucket creation and send alerts to the security team.
C.Create an IAM policy that requires versioning and KMS encryption when creating buckets, and attach it to all users.
D.Use AWS Config rules to detect noncompliant buckets and auto-remediate with Lambda.
AnswerD

Correct. AWS Config evaluates bucket configurations and uses custom Lambda functions to auto-remediate, enabling versioning and KMS encryption for any noncompliant bucket. This provides automated enforcement with acceptable operational overhead.

Why this answer

It uses AWS Config rules to detect noncompliant S3 buckets (e.g., missing versioning or KMS encryption) and triggers an automated Lambda remediation to enable versioning and encryption. This ensures compliance with minimal manual intervention, though it does incur some operational overhead for Lambda maintenance. Option A is incorrect because SCPs cannot enforce versioning at bucket creation—versioning is enabled after creation via PutBucketVersioning, and the headers mentioned in the explanation do not exist.

Option B only alerts and does not enforce. Option C is not scalable for OU-level enforcement and can be bypassed.

Exam trap

The trap is that candidates assume SCPs can enforce versioning at bucket creation because they are familiar with SCPs for preventive controls. However, versioning cannot be specified in the CreateBucket request; it must be enabled separately. Thus, the only viable option is AWS Config with auto-remediation (Option D), which is reactive but enforceable.

How to eliminate wrong answers

Option B is wrong because CloudTrail monitoring only alerts after the bucket is created, not preventing noncompliant buckets, and requires manual or automated follow-up, adding operational overhead. Option C is wrong because an IAM policy attached to users does not prevent creation by roles, services (e.g., CloudFormation), or cross-account access, and it cannot enforce compliance across all principals in the OU. Option D is wrong because AWS Config rules detect noncompliant buckets after creation and auto-remediate with Lambda, which is reactive and incurs overhead for remediation logic and potential race conditions, whereas SCPs prevent the violation proactively.

237
MCQhard

A media company is designing a new video transcoding pipeline. Source files are uploaded to an Amazon S3 bucket, and a Lambda function must start an AWS Elemental MediaConvert job for each upload. Transcoding jobs take 20-40 minutes, and the company wants automatic retries with a dead-letter queue for failed job submissions, while avoiding duplicate jobs if the same object is processed twice. Which design meets these requirements?

A.Configure S3 Event Notifications to invoke the Lambda function synchronously through an Application Load Balancer, and rely on the Lambda function's built-in idempotency token to prevent duplicate MediaConvert jobs.
B.Use an S3 Event Notification to send messages to an Amazon SQS FIFO queue, have Lambda poll the queue, and rely on the FIFO message deduplication ID to ensure each S3 object produces exactly one MediaConvert job.
C.Enable S3 Event Notifications to invoke a Step Functions state machine that calls Lambda, and configure the state machine with a Retry policy and a Catch block to route failures to an SQS dead-letter queue, using the S3 ETag as the idempotency key.
D.Configure S3 Event Notifications to invoke the Lambda function asynchronously, set MaximumRetryAttempts to 2 and a dead-letter queue on the function, and use the S3 object versionId plus sequencer in the event to deduplicate job submissions in DynamoDB.
AnswerD

S3 event notifications invoke Lambda asynchronously, so asynchronous invocation retry settings and an on-failure destination or DLQ apply. MediaConvert job submission returns quickly, so the 15-minute Lambda limit is not a concern. Using the object versionId and sequencer from the event to conditionally write a deduplication record in DynamoDB prevents duplicate jobs when the same object triggers multiple events.

Why this answer

S3 event notifications invoke Lambda asynchronously, which is the only invocation mode where MaximumRetryAttempts and on-failure destinations such as a dead-letter queue apply. Because MediaConvert job submission is a short API call, the function finishes well within the Lambda timeout. Deduplication should use immutable S3 event metadata, namely the object versionId and sequencer, to conditionally record each event in DynamoDB so that repeated notifications for the same object version do not start a second transcoding job.

Exam trap

The trap here is assuming that S3 can invoke Lambda synchronously or that Lambda has built-in idempotency, when asynchronous invocation with retry settings and explicit deduplication logic is required.

238
MCQhard

A company has a serverless application using AWS Lambda, API Gateway, and DynamoDB. During a traffic spike, some API requests fail with 5xx errors. The CloudWatch logs show 'ProvisionedThroughputExceededException' for DynamoDB. The team wants to handle this gracefully without losing requests. What should they do?

A.Enable auto scaling for DynamoDB and implement retry logic with exponential backoff in the Lambda function.
B.Increase the provisioned read/write capacity of the DynamoDB table to a high fixed value.
C.Use an SQS queue between API Gateway and Lambda to buffer requests.
D.Configure API Gateway to automatically retry failed requests.
AnswerA

DynamoDB's ProvisionedThroughputExceededException arises when read/write capacity units are exhausted, so on-demand or auto scaling absorbs the spike. Retries with exponential backoff and jitter let Lambda reattempt throttled calls, satisfying the requirement to handle failures gracefully without losing requests. Together they address capacity exhaustion and transient throttling.

Why this answer

The ProvisionedThroughputExceededException indicates that DynamoDB is throttling requests because the table's provisioned capacity is insufficient for the traffic spike. Enabling DynamoDB auto scaling allows the table to automatically adjust its read/write capacity based on utilization, while implementing retry logic with exponential backoff in the Lambda function ensures that throttled requests are retried after progressively longer intervals, preventing request loss and handling temporary spikes gracefully. This combination directly addresses the root cause and provides resilience.

Exam trap

SAP-C02 often tests the misconception that simply increasing provisioned capacity or adding a queue solves throttling, but the key is combining auto scaling with retry logic to handle spikes without losing requests.

How to eliminate wrong answers

Option B is wrong because setting a high fixed capacity does not handle dynamic traffic spikes efficiently and can be cost-prohibitive; it also doesn't address the need for retries when throttling still occurs. Option C is wrong because adding an SQS queue between API Gateway and Lambda changes the architecture to asynchronous processing, which may not be suitable for synchronous API requests expecting immediate responses, and it doesn't directly solve DynamoDB throttling. Option D is wrong because API Gateway does not automatically retry failed requests; retries must be implemented in the client or backend, and API Gateway's default behavior is to return the error to the caller.

239
MCQmedium

A company is designing a new microservices application on AWS. Each microservice needs to store and retrieve stateful data with low latency (single-digit milliseconds). The data must be durable and highly available across multiple Availability Zones. Which AWS service should be used for the primary data store for each microservice?

A.Amazon DynamoDB
B.Amazon S3
C.Amazon RDS with Multi-AZ
D.Amazon ElastiCache for Redis
AnswerA

DynamoDB delivers consistent single-digit-millisecond latency at any scale and replicates data across three Availability Zones by default, meeting the durability and multi-AZ availability requirements without managing servers. Its partition-based architecture sustains low latency as each microservice's dataset grows.

Why this answer

Amazon DynamoDB is a fully managed NoSQL key-value and document database that delivers single-digit millisecond latency at any scale. It is designed for high availability and durability by automatically replicating data across three Availability Zones in an AWS Region, meeting the requirements for stateful microservices data storage.

Exam trap

The SAP-C02 exam often tests the distinction between a durable primary data store and a cache or object store, where candidates mistakenly choose ElastiCache for its low latency without considering durability, or S3 for its high availability without recognizing its higher latency profile.

How to eliminate wrong answers

Option B is wrong because Amazon S3 is an object storage service designed for high throughput and large data volumes, not for low-latency single-digit millisecond access typical of microservices stateful data; its read/write latency is higher and it lacks native support for fine-grained updates. Option C is wrong because Amazon RDS with Multi-AZ provides high availability through synchronous replication to a standby instance, but it is a relational database that introduces overhead from SQL parsing and connection management, making it less suitable for the sub-10ms latency requirements of microservices compared to DynamoDB. Option D is wrong because Amazon ElastiCache for Redis is an in-memory cache, not a durable primary data store; while it offers low latency, its data is not durable by default (unless using Redis AOF with persistence, which still risks data loss on failure) and it is not designed for long-term stateful storage with the same durability guarantees as DynamoDB.

240
MCQhard

A company is migrating a large-scale Oracle data warehouse to Amazon Redshift. The migration must minimize downtime. The source database is 10 TB and runs on a single on-premises server with 1 Gbps network. Which approach should be used for the initial data load?

A.Use AWS DMS to migrate data directly to Redshift over the network.
B.Use AWS Snowball Edge to transfer data to S3, then copy to Redshift.
C.Use AWS DMS with ongoing replication after initial load via network.
D.Use S3 Transfer Acceleration to upload data to S3, then COPY to Redshift.
AnswerB

Offline transfer bypasses bandwidth constraints.

Why this answer

Using AWS Snowball Edge devices for offline transfer avoids network bandwidth limitations and provides fast, secure transfer of large data volumes. Option A is wrong because 1 Gbps network would take over 22 hours and may cause congestion. Option B is wrong because DMS works for ongoing replication but initial load over network is slow.

Option D is wrong because S3 Transfer Acceleration only speeds up S3 uploads, not the full pipeline.

241
MCQhard

A company uses AWS Organizations with 100 accounts. The security team wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. They create an SCP that denies all actions if MFA is not present. However, some users report that they cannot access the console even with MFA. What is the most likely reason?

A.The SCP does not include an explicit allow for the sts:GetSessionToken action.
B.The IAM policy attached to the users does not allow any actions.
C.The SCP does not apply to users who have administrative privileges.
D.The SCP also denies access to the root user of each account.
AnswerA

Without allowing STS:GetSessionToken, the MFA challenge cannot be completed.

Why this answer

When users authenticate with MFA, the AWS Management Console calls the STS GetSessionToken API to obtain temporary credentials that include the MFA session. If the SCP denies all actions, including sts:GetSessionToken, then even with valid MFA the user cannot obtain the necessary temporary credentials, resulting in access denial. The SCP must explicitly allow the sts:GetSessionToken action for users who authenticate with MFA.

Option B is incorrect because the issue is not about the users' IAM policies but about the SCP. Option C is incorrect because SCPs apply to all principals in the account, including administrators. Option D is incorrect because the SCP does not inherently affect the root user differently; root user is not affected by SCPs in the management account.

242
Multi-Selecthard

A company is modernizing a monolithic Java application to run on Amazon ECS with Fargate. The application uses a proprietary configuration management system. Which TWO AWS services can replace the configuration management system to store and retrieve configuration at runtime?

Select 2 answers
A.Amazon S3 with versioning enabled.
B.AWS Secrets Manager.
C.Amazon DynamoDB with application-side caching.
D.AWS AppConfig, a feature of AWS Systems Manager.
E.AWS Systems Manager Parameter Store.
AnswersD, E

AWS AppConfig stores configuration externally and delivers it to ECS tasks at runtime through the AppConfig agent or API, with validation and controlled rollout. This replaces the proprietary configuration management system, satisfying the requirement to store and retrieve configuration dynamically without redeploying the Java containers.

Why this answer

AWS AppConfig (option D) is a feature of AWS Systems Manager designed specifically for application configuration management, allowing you to store, validate, and deploy configuration data with runtime retrieval via the AppConfig API or Lambda extension, making it a direct replacement for a proprietary configuration management system. AWS Systems Manager Parameter Store (option E) provides hierarchical, versioned storage for configuration data and secrets, with runtime retrieval through the SSM API, and is a standard AWS-native configuration store for ECS/Fargate workloads. Option A (Amazon S3 with versioning) is object storage, not a configuration management service, and lacks native runtime configuration retrieval semantics.

Option B (AWS Secrets Manager) is purpose-built for secrets such as credentials and API keys, not general application configuration. Option C (Amazon DynamoDB with application-side caching) is a database, not a configuration management service, and would require custom application logic to serve as a configuration store.

Exam trap

SAP-C02 often tests the distinction between configuration management (AppConfig/Parameter Store) and secret management (Secrets Manager) — candidates incorrectly pick Secrets Manager for all runtime configuration needs.

243
MCQeasy

A company is migrating its on-premises virtual machines (VMs) to AWS. The company has 50 VMs running various operating systems and applications. The architect wants to use a service that automates the replication and conversion of the VMs to Amazon EC2 instances. Which AWS service should the architect use?

A.AWS Application Migration Service (AWS MGN)
B.AWS DataSync
C.AWS Server Migration Service (AWS SMS)
D.AWS CloudEndure Migration
AnswerA

AWS Application Migration Service replicates source servers block-by-block into staging areas and automatically converts them to bootable Amazon EC2 instances, satisfying the automated replication-and-conversion requirement. It supports heterogeneous operating systems and applications across all 50 VMs without manual rebuilds.

Why this answer

AWS Application Migration Service (MGN) is the AWS-recommended service for lift-and-shift migration of on-premises VMs to EC2. It performs continuous block-level replication, automatically converts the source server to run on AWS, and supports a wide range of operating systems and applications with minimal downtime. It replaces the deprecated Server Migration Service.

Exam trap

SAP-C02 often tests whether candidates know SMS is deprecated and CloudEndure was rebranded into MGN — the trap is picking a legacy name that sounds correct but is no longer the current service.

How to eliminate wrong answers

Option B is wrong because AWS DataSync transfers file and object data between storage systems; it does not replicate or convert VMs to EC2 instances. Option C is wrong because AWS Server Migration Service (SMS) is deprecated and no longer the recommended service for VM migration — MGN supersedes it. Option D is wrong because CloudEndure Migration was the predecessor product that was rebranded and folded into AWS MGN; it is not a separate current service to select.

244
MCQeasy

A company needs to design a new solution for storing and retrieving user-uploaded images. The images are accessed frequently for the first 30 days and then rarely accessed after that. The company wants to minimize storage costs while maintaining low-latency access for frequently accessed images. Which storage strategy should be used?

A.Store images in Amazon EBS volumes attached to a web server.
B.Store images in Amazon S3 Standard and use lifecycle policies to transition to S3 Standard-IA after 30 days.
C.Store all images in Amazon S3 Glacier Flexible Retrieval.
D.Store all images in Amazon S3 Standard.
AnswerB

S3 Standard serves the first 30 days at low latency, then a lifecycle rule transitions objects to S3 Standard-IA, whose lower storage price suits rarely accessed data while retaining millisecond access. This minimises cost without sacrificing performance for frequent reads.

Why this answer

Amazon S3 Standard provides low-latency access for frequently accessed images, and S3 lifecycle policies allow automatic transition to S3 Standard-Infrequent Access (Standard-IA) after 30 days, reducing storage costs while maintaining rapid access for the initial period. This strategy directly meets the requirement of minimizing costs without sacrificing performance for the first 30 days.

Exam trap

The trap here is that candidates may choose Option D (all S3 Standard) because it guarantees low-latency access, overlooking the cost savings of transitioning to Standard-IA for data that becomes rarely accessed after 30 days.

How to eliminate wrong answers

Option A is wrong because Amazon EBS volumes are block-level storage attached to a single EC2 instance, not designed for storing and retrieving user-uploaded images at scale, and they incur costs even when not accessed, lacking lifecycle management for infrequent access. Option C is wrong because Amazon S3 Glacier Flexible Retrieval has retrieval times of minutes to hours, which does not provide low-latency access for frequently accessed images during the first 30 days. Option D is wrong because storing all images in Amazon S3 Standard incurs higher storage costs for data that becomes rarely accessed after 30 days, failing to minimize storage costs as required.

245
MCQeasy

A startup is building a serverless application using AWS Lambda for business logic and Amazon DynamoDB for data storage. The application must process a high volume of writes to a single DynamoDB table. The development team is concerned about throttling due to hot partitions. Which design should the team implement to avoid throttling?

A.Enable DynamoDB Accelerator (DAX) to cache write operations.
B.Use a composite primary key with a partition key that has high cardinality, such as a user ID.
C.Use a global secondary index (GSI) as the primary index for writes.
D.Add a local secondary index (LSI) to the table.
AnswerB

A high-cardinality partition key such as user ID spreads writes across many physical partitions, preventing any single partition from becoming a hot spot. This directly addresses the throttling constraint caused by uneven write distribution in the single DynamoDB table.

Why this answer

Using a partition key with high cardinality, such as a user ID, ensures that write requests are evenly distributed across all partitions in the DynamoDB table. This prevents any single partition from becoming a hot partition, which would otherwise lead to throttling when the partition's throughput capacity is exceeded. DynamoDB scales by splitting partitions based on the partition key's hash, so high cardinality is essential for avoiding throttling under high write volumes.

Exam trap

The trap here is that candidates often confuse caching (DAX) as a solution for write performance, not realizing DAX only accelerates reads, or they mistakenly believe that secondary indexes (GSI/LSI) can redistribute write load, when in fact they share the base table's partition key and do not solve hot partition issues.

How to eliminate wrong answers

Option A is wrong because DynamoDB Accelerator (DAX) is an in-memory cache for read operations only; it does not cache or accelerate write operations, so it cannot prevent write throttling. Option C is wrong because a global secondary index (GSI) is a secondary index that supports read and write operations, but it does not replace the primary index for writes; writes are still directed to the base table's partition key, and using a GSI as the primary index is not a valid design—GSIs have their own throughput and can also experience throttling if not properly provisioned. Option D is wrong because a local secondary index (LSI) shares the same partition key as the base table and does not improve write distribution; it only provides an alternative sort key for querying within a partition, so it does not address hot partition issues.

246
MCQmedium

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local instance storage. The operations team wants to centralize log analysis and enable real-time alerting on specific error patterns. The solution must be highly available and require minimal changes to the application. Which approach should a solutions architect recommend?

A.Modify the application to write logs directly to Amazon Kinesis Data Firehose, which delivers them to Amazon S3 for analysis.
B.Set up an AWS Lambda function that periodically connects to each instance via SSH to retrieve logs and publish them to Amazon SNS.
C.Configure the instances to mount a shared Amazon EFS file system and write logs there, then use a third-party tool to analyze the logs.
D.Install and configure the Amazon CloudWatch agent on each instance to send logs to Amazon CloudWatch Logs, then use metric filters and alarms for alerting.
AnswerD

The CloudWatch agent can collect logs from local files and send them to CloudWatch Logs without application changes. Metric filters can extract patterns and trigger alarms. This solution is highly available because CloudWatch Logs is a regional service, and it provides real-time alerting with minimal operational overhead.

Why this answer

The CloudWatch agent provides a managed way to collect logs from EC2 instances and send them to CloudWatch Logs. Metric filters can monitor for specific patterns and trigger alarms in near real-time. This requires no application changes and is highly available, making it the most efficient solution.

Exam trap

The trap here is assuming that application code changes or custom scripts are needed for log centralization, when the CloudWatch agent can handle it without modifications.

247
MCQeasy

A company uses AWS Organizations with a management account and several member accounts. The security team needs to centrally manage IAM users and roles across all accounts. Which AWS service should the company use?

A.AWS Directory Service for Microsoft Active Directory.
B.AWS Identity and Access Management (IAM) in the management account.
C.AWS IAM Identity Center (AWS SSO).
D.Amazon Cognito user pools.
AnswerC

IAM Identity Center provides centralised management of users, groups and permission sets, then federates access into member accounts via IAM roles. This satisfies the requirement to manage identities centrally across all accounts without creating separate IAM users in each.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized place to manage user identities and permissions across multiple AWS accounts within an AWS Organization. It allows the security team to create or connect users and groups, and assign them fine-grained permissions to accounts, roles, and applications from a single pane of glass, eliminating the need to create IAM users in each account.

Exam trap

The trap here is that candidates often confuse IAM Identity Center with simply using IAM in the management account, failing to realize that IAM is account-scoped and cannot centrally manage identities across multiple accounts without additional federation or automation.

How to eliminate wrong answers

Option A is wrong because AWS Directory Service for Microsoft Active Directory is a managed Microsoft AD service used for identity federation and directory-aware workloads, not for centrally managing IAM users and roles across AWS accounts. Option B is wrong because IAM in the management account can only manage users and roles within that single account; it cannot natively manage identities across member accounts without complex cross-account role assumptions and manual duplication. Option D is wrong because Amazon Cognito user pools are designed for customer-facing identity and access management for web and mobile applications, not for managing workforce identities or AWS account access.

248
MCQmedium

A company is migrating a legacy on-premises .NET application to AWS. The application uses a SQL Server database and requires full control over the operating system for compliance. Which migration strategy should the solutions architect recommend to minimize rework while meeting compliance requirements?

A.Rehost the application on EC2 instances and use RDS Custom for SQL Server.
B.Replace the database with Amazon DynamoDB and refactor the application.
C.Replatform the application to use RDS for SQL Server and deploy the application on EC2 instances.
D.Refactor the application to run on Amazon ECS using Docker containers.
AnswerA

Rehosting on EC2 preserves the application with minimal rework, while RDS Custom for SQL Server grants operating system and database-level access needed for compliance. Standard RDS withholds OS access, and replatforming or refactoring would demand significant rework.

Why this answer

Rehosting (lift-and-shift) with EC2 and RDS Custom for SQL Server allows the company to move the application and database with minimal changes while retaining OS-level control for compliance. RDS Custom provides OS access (SSH, patching) unlike standard RDS, meeting the compliance requirement. Option B (DynamoDB) would require significant application refactoring.

Option C (RDS for SQL Server without Custom) lacks OS access. Option D (ECS with containers) adds containerization rework and does not inherently provide OS-level control.

249
Multi-Selecteasy

A company is designing a new static website hosted on Amazon S3. They want to use Amazon CloudFront as a content delivery network (CDN) to serve the website globally with low latency. The website content must be encrypted in transit. Which configurations should they use? (Choose TWO.)

Select 2 answers
A.Enable default encryption on the S3 bucket using AES-256.
B.Enable S3 Transfer Acceleration on the bucket.
C.Configure the S3 bucket policy to deny requests that do not use HTTPS.
D.Configure CloudFront to require HTTPS for viewer requests.
E.Use CloudFront signed URLs to restrict access.
AnswersC, D

A bucket policy denying requests where aws:SecureTransport is false rejects any plaintext HTTP access to S3 objects. This satisfies the encrypted-in-transit requirement by ensuring content cannot be fetched from the origin over an unencrypted connection.

Why this answer

Option C is correct because enforcing an S3 bucket policy with a Deny effect on aws:SecureTransport false ensures that any request reaching the S3 origin (including from CloudFront or direct callers) must use HTTPS/TLS, satisfying encryption in transit at the origin. Option D is correct because setting the CloudFront distribution's viewer protocol policy to redirect HTTP to HTTPS (or HTTPS only) guarantees that all client-to-edge traffic is encrypted with TLS, which is the primary in-transit path for a global static website. Option A is incorrect because AES-256 default encryption is server-side encryption at rest, not in transit.

Option B is incorrect because S3 Transfer Acceleration speeds up uploads/downloads using AWS edge locations but does not enforce or provide encryption in transit. Option E is incorrect because CloudFront signed URLs control access/authorization to content, not transport encryption.

Exam trap

The trap here is that candidates often confuse encryption at rest (S3 default encryption) with encryption in transit, or they assume that CloudFront's default HTTPS support automatically secures the S3 origin connection without needing a bucket policy to enforce it.

250
MCQmedium

A company is migrating a large on-premises Oracle database to Amazon RDS for Oracle. The database is 2 TB in size and has a 24/7 uptime requirement. The company plans to use AWS Database Migration Service (AWS DMS) for continuous replication with minimal downtime. The source database is Oracle 11g running on Linux. During the full load phase, AWS DMS reports high latency and the replication slows down significantly. The source database CPU utilization is at 100% during the migration. The company needs to minimize the impact on production workload. What should the company do to improve the migration performance and reduce impact on the source database?

A.Use AWS DMS change data capture (CDC) only, without full load, to reduce the load
B.Increase the size of the DMS replication instance to handle more load
C.Reduce the number of parallel load threads in the DMS task to decrease source CPU usage
D.Set up an Oracle read replica and use it as the source for AWS DMS
AnswerD

Setting up an Oracle read replica and using it as the source for AWS DMS offloads the replication overhead from the primary database, eliminating the CPU bottleneck and allowing the migration to proceed with minimal impact on the production workload.

Why this answer

The source Oracle 11g database is at 100% CPU during the full load, meaning the DMS full-load threads are competing with production workload on the same host. Offloading the DMS read workload to an Oracle read replica (via Oracle Active Data Guard or a manually maintained standby) isolates the migration reads from the primary, preserving production performance while still allowing DMS to perform full load plus CDC against the replica. This is the standard AWS-recommended pattern for minimizing source impact on large Oracle migrations.

Exam trap

SAP-C02 often tests the misconception that scaling the DMS replication instance or tuning DMS task parallelism fixes source-side bottlenecks, when the real fix is offloading reads to a replica or standby.

How to eliminate wrong answers

Option A is wrong because skipping full load and using CDC only would leave the target without the existing 2 TB of data — CDC replicates changes, not the initial dataset, so the migration would be incomplete. Option B is wrong because increasing the DMS replication instance size scales the target-side/task-side capacity but does nothing to relieve the 100% CPU on the source Oracle host, which is the actual bottleneck. Option C is wrong because reducing parallel load threads lowers throughput and lengthens the migration window; it may reduce source load slightly but does not address the root cause and directly contradicts the goal of improving migration performance.

251
MCQhard

A company is migrating a large-scale batch processing workload from on-premises to AWS. The workload runs on a schedule and processes data files from an FTP server. The company wants to use AWS services that are serverless and event-driven to reduce operational overhead. The data files will be uploaded to an Amazon S3 bucket. Which solution meets these requirements?

A.Use Amazon S3 Event Notifications to invoke an AWS Batch job that processes the file
B.Use Amazon S3 Event Notifications to invoke an AWS Lambda function that processes the file
C.Use AWS Glue to crawl the S3 bucket and run an ETL job on a schedule
D.Use Amazon S3 Event Notifications to start an AWS Step Functions workflow that runs processing on Amazon EC2
AnswerB

S3 Event Notifications trigger AWS Lambda directly on each uploaded object, giving the event-driven, serverless processing the workload requires. This removes polling and server management, satisfying the reduced operational overhead constraint, while Lambda scales automatically with the scheduled batch arrivals.

Why this answer

AWS Lambda is a serverless compute service that can be triggered by S3 event notifications, allowing immediate processing of uploaded files without managing servers. This meets the requirements for a serverless, event-driven solution with minimal operational overhead.

Exam trap

SAP-C02 often tests the distinction between serverless and non-serverless services; candidates may incorrectly assume AWS Batch or EC2 are serverless.

How to eliminate wrong answers

Option A is wrong because AWS Batch is not serverless; it requires provisioning compute environments and is not event-driven natively. Option C is wrong because AWS Glue is serverless but runs on a schedule, not event-driven, and is more for ETL than batch processing. Option D is wrong because Amazon EC2 is not serverless; it requires managing instances, and Step Functions orchestrates but doesn't eliminate server management.

252
Multi-Selecthard

A company is running a critical microservices application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer (ALB) to distribute traffic. Recently, the team noticed that the ALB's 5xx error rate has increased. The error is HTTP 503. The team suspects the target group is unhealthy. Which THREE steps should the team take to diagnose and resolve the issue?

Select 3 answers
A.Verify the ECS service's desired count and compare with the number of healthy tasks in the target group.
B.Replace the ALB with a Network Load Balancer (NLB) to bypass health checks.
C.Check the ECS service events and task status to ensure tasks are running and passing health checks.
D.Verify that sticky sessions (session affinity) are enabled on the target group.
E.Check the ALB access logs and health check settings for the target group.
AnswersA, C, E

Comparing the ECS service's desired count against healthy targets in the target group exposes capacity shortfalls: if tasks fail ALB health checks, they are deregistered, leaving too few healthy targets and triggering HTTP 503 responses. This directly addresses the suspected unhealthy target group constraint in the stem.

Why this answer

Option A is correct because an HTTP 503 from an ALB typically means the target group has no healthy targets; comparing the ECS service's desired count against the number of healthy targets registered in the target group immediately reveals whether tasks are failing to register or failing health checks. Option C is correct because ECS service events and task status (via the ECS console, describe-services, or describe-tasks) show why tasks are stopping, restarting, or failing to reach a steady state, which is the root cause of unhealthy targets. Option E is correct because ALB access logs record the 503 responses and target health, while the target group health check settings (path, port, protocol, interval, timeout, healthy/unhealthy thresholds, and success codes) determine whether tasks are marked healthy; misconfigured health checks are a common cause of 503s.

Option B is not appropriate because replacing the ALB with an NLB does not bypass the underlying problem and NLB health checks would still mark targets unhealthy, plus it changes the architecture unnecessarily. Option D is not relevant because sticky sessions (session affinity) affect request routing to already-healthy targets and do not cause or resolve 503 errors from an unhealthy target group.

253
MCQhard

Refer to the exhibit. A CloudFormation stack was successfully created. The stack's template includes an S3 bucket and a Lambda function. A developer runs the CLI command shown but receives an error that the stack does not exist. What is the MOST likely cause?

A.The AWS CLI is configured to use a different region than where the stack was deployed.
B.The stack was deleted after creation.
C.The stack name is case-sensitive and should be 'MyApp'.
D.The '--query' parameter is incorrectly formatted.
AnswerA

Stack names are unique per region; querying the wrong region returns 'stack does not exist'.

Why this answer

The CLI command is querying the wrong region. The stack was created in us-east-1 but the CLI default region might be different. Option B is wrong because the stack was created successfully.

Option C is wrong because outputs are returned correctly. Option D is wrong because the stack name is exactly as used.

254
MCQmedium

A company runs a containerized application on Amazon ECS with Fargate. The application needs to access an Amazon S3 bucket that contains sensitive data. The security team requires that all traffic between the ECS tasks and S3 remain within the AWS network and not traverse the internet. What is the MOST secure way to meet this requirement?

A.Use an internet gateway and route traffic through a NAT gateway.
B.Enable S3 Transfer Acceleration on the bucket.
C.Create a VPC endpoint for S3 and attach it to the VPC.
D.Use a NAT gateway and update the route table to direct S3 traffic to the NAT.
AnswerC

VPC endpoint enables private connectivity to S3 without internet.

Why this answer

Using a VPC endpoint for S3 (Gateway or Interface) ensures traffic stays within the AWS network. Option A is wrong because internet traffic goes over the public internet. Option B is wrong because a NAT gateway is for outbound internet, not private access to S3.

Option D is wrong because S3 Transfer Acceleration uses the internet.

255
MCQmedium

A company is designing a new microservices architecture on AWS. The company wants to use a service mesh to manage service-to-service communication, observability, and security. Which AWS service should the company use?

A.Amazon API Gateway
B.AWS App Mesh
C.AWS Transit Gateway
D.AWS Cloud Map
AnswerB

AWS App Mesh provides a managed service mesh that handles service-to-service communication, observability and traffic control across microservices. It satisfies the stem's requirement for a dedicated mesh layer by injecting Envoy proxies alongside tasks, delivering consistent routing, retries and mutual TLS without application code changes.

Why this answer

AWS App Mesh is a service mesh that provides application-level networking to manage service-to-service communication, observability (via metrics, logs, and traces), and security (via mTLS and fine-grained access policies) for microservices. It uses the Envoy proxy as a sidecar to intercept traffic, enabling features like traffic splitting, retries, and circuit breaking without modifying application code.

Exam trap

The trap here is that candidates often confuse a service mesh (App Mesh) with an API gateway (API Gateway), but API Gateway is designed for external-facing API management, not for internal service-to-service traffic control and observability within a microservices mesh.

How to eliminate wrong answers

Option A is wrong because Amazon API Gateway is a fully managed API gateway for creating, publishing, and securing REST/HTTP/WebSocket APIs at the edge, not a service mesh for internal service-to-service communication within a microservices architecture. Option C is wrong because AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks via a central router, operating at Layer 3, not at the application layer required for service mesh capabilities like traffic splitting and observability. Option D is wrong because AWS Cloud Map is a cloud resource discovery service that allows services to register and discover instances via DNS or API calls, but it does not provide traffic management, observability, or security features inherent to a service mesh.

256
Drag & Dropmedium

Drag and drop the steps to restore an Amazon RDS DB instance from a snapshot in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First navigate to snapshots, restore, configure settings, wait for completion, then update application endpoint.

257
MCQmedium

A company deployed the above CloudFormation template. An EC2 instance launched in the PrivateSubnet needs to access the internet for software updates. Which action is required?

A.Create a VPC Peering connection to a public VPC
B.Add a NAT Gateway in the PublicSubnet and update the PrivateSubnet's route table to point to the NAT Gateway
C.Add an Internet Gateway to the VPC and route the private subnet's route table to it
D.Modify the PrivateSubnet to assign public IP addresses on launch
AnswerB

A private subnet has no route to an internet gateway. Deploying a NAT Gateway in the public subnet and adding a 0.0.0.0/0 route in the private subnet's route table lets instances initiate outbound updates while remaining unreachable inbound.

Why this answer

A NAT Gateway placed in a public subnet with an Internet Gateway attached allows instances in private subnets to initiate outbound traffic to the internet (e.g., for software updates) while preventing inbound connections from the internet. The private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway. This is the standard AWS pattern for outbound-only internet access from private subnets.

Exam trap

The trap here is that candidates often confuse a NAT Gateway with an Internet Gateway, thinking that routing a private subnet directly to an Internet Gateway is sufficient, but this would expose instances to inbound traffic and require public IPs, defeating the purpose of a private subnet.

How to eliminate wrong answers

Option A is wrong because VPC Peering does not provide internet access; it only connects two VPCs privately, and neither VPC inherently has internet access without an Internet Gateway. Option C is wrong because routing a private subnet directly to an Internet Gateway would allow inbound internet traffic, violating the security model of a private subnet; Internet Gateways require public IP addresses and are used with public subnets. Option D is wrong because assigning public IP addresses to instances in a private subnet does not grant internet access; the subnet still lacks a route to an Internet Gateway, and public IPs alone cannot reach the internet without a gateway.

258
MCQhard

A company is migrating a critical application to AWS. The migration plan includes a pilot light strategy. The company has set up a small replica of the environment in AWS. During a disaster, the company wants to quickly provision the full production environment. Which AWS service is best suited for this purpose?

A.AWS OpsWorks
B.AWS Elastic Beanstalk
C.AWS CloudFormation
D.AWS CodeDeploy
AnswerC

AWS CloudFormation templates codify the full production environment, so during disaster recovery the stack can be provisioned rapidly and repeatably from the pilot light baseline, satisfying the requirement to quickly stand up complete production capacity.

Why this answer

AWS CloudFormation is the best service for this scenario because it allows you to define the entire infrastructure as code in templates, which can be stored and then quickly executed to provision the full production environment during a disaster. This aligns with the pilot light strategy, where a small replica is already running and CloudFormation can rapidly scale it up. Option A (OpsWorks) is wrong because it is configuration management service for Chef/Puppet, not for quickly provisioning full environments.

Option B (Elastic Beanstalk) is wrong because it is designed for deploying web applications, not for provisioning custom infrastructure. Option D (CodeDeploy) is wrong because it handles application deployments, not infrastructure provisioning.

259
MCQeasy

A company is designing a new web application on AWS. The application must be highly available and scale automatically based on traffic. The architecture includes an Application Load Balancer (ALB) and an Auto Scaling group of EC2 instances. The application stores session state. What is the BEST way to handle session state to ensure high availability?

A.Store session state in Amazon DynamoDB
B.Store session state on the local instance store of each EC2 instance
C.Store session state in Amazon S3
D.Store session state in Amazon ElastiCache for Redis
AnswerD

ElastiCache for Redis externalises session state into a replicated, Multi-AZ in-memory store, so any Auto Scaling EC2 instance behind the ALB can serve any user; instance loss or scale-in no longer drops sessions, preserving high availability.

Why this answer

Amazon ElastiCache for Redis is the best choice for handling session state in a highly available, auto-scaling web application because it provides a centralized, in-memory data store that is external to the EC2 instances. This ensures that session data persists independently of instance lifecycle events (e.g., scaling in/out or failures), and Redis offers sub-millisecond latency, replication, and automatic failover, which are critical for maintaining session continuity across the fleet.

Exam trap

The trap here is that candidates often choose DynamoDB (Option A) because it is a managed, highly available database, but they overlook the latency and cost implications for session state, which is a classic in-memory caching use case where ElastiCache for Redis is the optimal AWS service.

How to eliminate wrong answers

Option A is wrong because Amazon DynamoDB, while highly available and scalable, is a NoSQL database designed for document and key-value storage with higher latency compared to in-memory caches; it is not optimized for the low-latency, high-throughput session state access patterns required by web applications, and its cost per operation is typically higher than ElastiCache for this use case. Option B is wrong because storing session state on the local instance store of each EC2 instance ties session data to a specific instance; if the instance is terminated, replaced, or scaled in, all session data is lost, breaking high availability and user experience. Option C is wrong because Amazon S3 is an object storage service with significantly higher latency (typically tens to hundreds of milliseconds) compared to in-memory stores, and it is not designed for frequent, low-latency read/write operations required for session management; additionally, S3 lacks native session expiration and atomic operations needed for session handling.

260
MCQeasy

A company is designing a new application that will store sensitive customer data in Amazon S3. The company must ensure that the data is encrypted at rest and that the encryption keys are rotated automatically every year. The company also wants to audit key usage. Which solution will meet these requirements?

A.Use server-side encryption with customer-provided keys (SSE-C).
B.Use server-side encryption with AWS KMS customer managed keys (SSE-KMS) and enable automatic key rotation.
C.Use server-side encryption with Amazon S3 managed keys (SSE-S3).
D.Use client-side encryption with an AWS KMS customer managed key and store the encrypted data in Amazon S3.
AnswerB

SSE-KMS with customer managed keys allows the company to control the KMS key, enable automatic annual rotation, and audit key usage through AWS CloudTrail. This meets all requirements: encryption at rest, automatic key rotation, and auditing. Customer managed keys also provide granular access control and the ability to disable or revoke the key if needed.

Why this answer

Using SSE-KMS with AWS KMS customer managed keys enables automatic annual key rotation and provides audit trails of key usage via AWS CloudTrail. This meets the requirements for encryption at rest, automatic rotation, and auditing. Customer managed keys also allow the company to control access and lifecycle, which is important for sensitive data.

Other encryption options either lack auditing, require manual key management, or add unnecessary complexity.

Exam trap

The trap here is assuming that SSE-S3 automatically rotates keys and provides auditing, when in fact auditing key usage requires AWS KMS and customer managed keys.

261
MCQmedium

A company runs a critical application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application experiences intermittent high latency due to CPU spikes on some instances. The company wants to automatically replace unhealthy instances and optimize costs. What should a solutions architect do?

A.Configure a target tracking scaling policy based on average CPU utilization.
B.Use a lifecycle hook to perform a health check and terminate unhealthy instances.
C.Use an AWS Lambda function to terminate instances with high CPU.
D.Implement a scheduled scaling policy to increase instances during peak hours.
AnswerA

Target tracking adjusts desired capacity automatically to hold average CPU at a defined target, adding instances when spikes occur and removing them when demand falls. This addresses the CPU-driven latency while optimising cost, and unhealthy instances are replaced by the Auto Scaling group's health checks.

Why this answer

A target tracking scaling policy dynamically adjusts the number of instances based on average CPU utilization, which addresses intermittent CPU spikes. The Auto Scaling group also automatically replaces instances that fail ALB health checks, ensuring unhealthy instances are replaced. This optimizes costs by scaling down during low usage.

Option B is incorrect: lifecycle hooks are for custom actions during instance launch or termination, not for replacing unhealthy instances. Option C is incorrect: terminating instances with high CPU via Lambda does not integrate with Auto Scaling and could cause instability. Option D is incorrect: scheduled scaling is for predictable traffic patterns, not intermittent spikes.

Exam trap

Candidates may think that lifecycle hooks are needed to replace unhealthy instances, but ALB health checks integrated with Auto Scaling already handle this automatically.

262
Multi-Selectmedium

A company is designing a multi-account strategy using AWS Organizations. The security team requires that all API calls to create or modify IAM roles are logged and alerted. Which TWO steps should be taken to meet this requirement?

Select 2 answers
A.Use AWS Config to record IAM role changes and stream to CloudWatch Logs.
B.Create a CloudWatch Logs metric filter and alarm to detect IAM role creation/modification events.
C.Create an SCP that denies IAM role creation and modification.
D.Enable CloudTrail management events with CloudWatch Logs integration in all accounts.
E.Enable IAM Access Analyzer to monitor IAM role usage.
AnswersB, D

CloudTrail delivers IAM role creation and modification events to CloudWatch Logs, where a metric filter matches the specific API calls (CreateRole, UpdateAssumeRolePolicy, AttachRolePolicy). The alarm then alerts the security team, satisfying the requirement to both log and alert on these events across the organisation's accounts.

Why this answer

Option D is correct because CloudTrail management events capture IAM API calls such as CreateRole, UpdateRole, and PutRolePolicy, and integrating CloudTrail with CloudWatch Logs in every account (or via an organization trail) delivers those events to a central place for monitoring. Option B is correct because a CloudWatch Logs metric filter matches patterns for IAM role creation/modification events in the delivered CloudTrail logs, and an associated CloudWatch alarm triggers the required alerting. Together, D provides the logging pipeline and B provides detection and alerting.

Option A is not appropriate because AWS Config records resource configuration changes and compliance, not the API call events needed for real-time alerting on IAM role creation/modification. Option C is wrong because an SCP that denies IAM role creation/modification would block the activity rather than log and alert on it. Option E is wrong because IAM Access Analyzer identifies resource access and permissions issues, not API call logging or alerting.

Exam trap

The trap here is that candidates often confuse AWS Config (which records configuration changes) with CloudTrail (which records API calls), leading them to select Option A instead of the correct combination of CloudTrail and CloudWatch Logs metric filters.

263
MCQeasy

A company runs a static website on Amazon S3 behind Amazon CloudFront. The website uses a custom domain and SSL certificate from AWS Certificate Manager (ACM). Users report that they sometimes see an older version of the website after updates. What should the company do to ensure users always see the latest content?

A.Disable and re-enable the CloudFront distribution after each update.
B.Enable S3 bucket versioning and use version IDs in URLs.
C.Reduce the CloudFront TTL to 0 seconds for all objects.
D.Create a CloudFront invalidation for the updated files.
AnswerD

CloudFront caches objects at edge locations until the TTL expires, so updated S3 objects can still serve stale copies. An invalidation forces edge locations to fetch the current object from the origin, satisfying the requirement that users always see the latest content.

Why this answer

CloudFront caches objects at edge locations based on TTL and only re-fetches from the S3 origin when the cache expires or is explicitly invalidated. When a static site is updated, existing cached copies at edge locations continue to be served until they expire, which is why users sometimes see stale content. Creating a CloudFront invalidation for the updated files (or a wildcard path like /*) forces the edge locations to discard the cached objects and retrieve the latest versions from S3 on the next request.

Exam trap

SAP-C02 often tests the misconception that changing origin-side settings (versioning, TTLs, or toggling the distribution) refreshes edge caches, when only an explicit CloudFront invalidation purges cached objects.

How to eliminate wrong answers

Option A is wrong because disabling and re-enabling a distribution does not purge cached objects at edge locations and causes unnecessary downtime while the distribution redeploys. Option B is wrong because S3 bucket versioning only retains multiple versions of objects in the origin bucket; CloudFront still serves whatever version is cached at the edge, and version IDs in URLs would change the cache key rather than solve the staleness problem. Option C is wrong because setting TTL to 0 seconds disables caching benefits, dramatically increases origin load and latency, and is not the intended mechanism for pushing updates — invalidation is the correct, targeted tool.

264
MCQmedium

A company is migrating a high-traffic web application to AWS. The application currently runs on physical servers in a data center and uses a shared file system for user-uploaded content. The company wants to minimize changes to the application and ensure the file system is highly available across multiple Availability Zones. Which AWS service should be used to replace the shared file system?

A.Amazon FSx for Windows File Server with a Multi-AZ deployment
B.Amazon Elastic File System (Amazon EFS) with mount targets in multiple Availability Zones
C.Amazon S3 with a bucket for each Availability Zone
D.Amazon Elastic Block Store (Amazon EBS) volumes replicated across Availability Zones
AnswerB

Amazon EFS is a fully managed, elastic NFS file system that can be mounted on EC2 instances across multiple Availability Zones. It provides shared storage with high availability and durability, requiring no application changes. This matches the requirement to replace the shared file system with minimal changes and multi-AZ availability.

Why this answer

Amazon EFS provides a managed NFS file system that can be mounted on multiple EC2 instances across multiple Availability Zones, offering high availability and durability. It requires no application changes, making it ideal for replacing an on-premises shared file system. Other options either require application modifications or do not provide a shared, multi-AZ file system.

Exam trap

The trap here is assuming that Amazon S3 can serve as a drop-in replacement for a shared file system without application changes.

265
Multi-Selecteasy

A company uses AWS Organizations to manage multiple accounts. The central team wants to deploy a CloudFormation template that creates an S3 bucket with default encryption in every member account. Which THREE steps are required to accomplish this?

Select 3 answers
A.Create an IAM role in each member account that allows CloudFormation to create resources.
B.Create an SCP that allows CloudFormation to create S3 buckets.
C.Write a CloudFormation template that includes an S3 bucket resource with default encryption enabled.
D.Create a CloudFormation StackSet in the management account.
E.Configure the StackSet with the target accounts and regions, and specify an IAM role for execution.
AnswersC, D, E

The template must define the S3 bucket resource with default encryption configured, since StackSets deploy whatever the template declares. Without this resource and its encryption property, no bucket with default encryption would be created in member accounts, so this step is essential.

Why this answer

Option C is correct because the template itself must define the AWS::S3::Bucket resource with encryption enabled (for example, BucketEncryption with SSE-S3 or SSE-KMS) so that every deployed bucket has default encryption. Option D is correct because CloudFormation StackSets are the AWS Organizations-integrated mechanism for deploying a single template across many accounts from the management account. Option E is correct because a StackSet requires you to specify the target accounts (or organizational units) and regions, and to supply an IAM execution role that CloudFormation assumes in each target account to create the resources.

Option A is not required as a separate step because StackSets use a single execution role (often created automatically or supplied via the StackSet configuration) rather than manually creating a role in each member account. Option B is not required because an SCP is a permissions guardrail, not a deployment mechanism; CloudFormation StackSets handle the cross-account deployment, and no SCP specifically allowing S3 bucket creation is needed.

Exam trap

The trap here is that candidates confuse SCPs with IAM policies, assuming SCPs can grant permissions to CloudFormation, when in fact SCPs only restrict permissions and the actual execution relies on an IAM role assumed by StackSets.

266
MCQmedium

A company is migrating a containerized application to Amazon ECS. The application requires persistent storage that can be shared across multiple containers running on different EC2 instances. Which storage solution should they use?

A.Amazon FSx for Lustre
B.Amazon EBS
C.Amazon EFS
D.Amazon S3
AnswerC

Amazon EFS provides a shared, elastic NFS file system that mounts concurrently on EC2 instances in multiple Availability Zones, so containers on different hosts read and write the same data. EBS volumes attach to a single instance and cannot satisfy the shared-storage requirement.

Why this answer

Amazon EFS provides a fully managed, elastic NFS file system that can be mounted simultaneously by multiple EC2 instances across Availability Zones, making it the correct choice for shared persistent storage across containers on different hosts. ECS tasks on EC2 launch type can mount EFS volumes using the EFS mount helper, enabling concurrent read/write access. This satisfies the requirement for shared persistent storage that survives container restarts and is accessible from multiple nodes.

Exam trap

The trap is assuming any AWS storage service can be shared across instances; candidates often pick EBS or S3 without recognizing that only EFS (and FSx variants) provide POSIX-compliant shared file storage mountable by multiple EC2 instances simultaneously.

How to eliminate wrong answers

Option A is wrong because FSx for Lustre is a high-performance parallel file system designed for HPC and machine learning workloads, not general-purpose shared container storage, and it is more complex and costly for this use case. Option B is wrong because EBS volumes are block storage attached to a single EC2 instance (or in multi-attach, a limited set in the same AZ) and cannot be shared across containers on different EC2 instances in the way required. Option D is wrong because S3 is object storage accessed via APIs, not a POSIX file system, so it cannot be directly mounted as a shared persistent volume for containers without additional layers like Mountpoint for S3.

267
Multi-Selectmedium

A company is using AWS Organizations with multiple accounts. The security team wants to enforce that all newly created Amazon S3 buckets are encrypted with AWS KMS keys managed by the security account, and that any attempts to create unencrypted buckets are denied. The company also wants to ensure that existing buckets are remediated. Which two actions should the security team take to meet these requirements? (Choose two.)

Select 2 answers
A.Use AWS CloudFormation StackSets to deploy a custom resource that scans all buckets and enables encryption, and use an SCP to deny s3:CreateBucket without encryption.
B.Attach a service control policy to the root of the organization that denies s3:CreateBucket unless the request includes the s3:x-amz-server-side-encryption condition key with value aws:kms and the s3:x-amz-server-side-encryption-aws-kms-key-id condition key with the security account's KMS key ARN.
C.Use AWS Config with a conformance pack that includes the s3-bucket-server-side-encryption-enabled rule and an automatic remediation action that enables default encryption with a KMS key from the security account.
D.Attach a service control policy to the root of the organization that denies s3:CreateBucket unless the request includes the s3:x-amz-server-side-encryption header with value aws:kms.
E.Use an SCP that denies s3:PutBucketEncryption if the request does not specify a KMS key ARN from the security account, and use AWS Config to remediate existing buckets.
AnswersB, C

This SCP enforces that any s3:CreateBucket request must include both the encryption header and the specific KMS key ARN from the security account. This prevents the creation of unencrypted buckets and ensures the use of the security account's KMS key, meeting the requirement for centralized key management.

Why this answer

The SCP with conditions on s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id ensures that new buckets are created with the correct encryption and key. AWS Config conformance packs with automatic remediation detect and fix existing unencrypted buckets, providing ongoing compliance. Together, these actions enforce encryption at creation and remediate existing buckets.

Exam trap

The trap here is assuming that SCPs alone can remediate existing resources, when in fact SCPs only affect new API calls and do not change existing configurations.

268
MCQeasy

A company has a decentralized IT structure where each business unit manages its own AWS account. The central security team needs visibility into all IAM user activities across accounts. What is the MOST scalable solution to aggregate CloudTrail logs?

A.Enable CloudTrail Insights in each account and review separately.
B.Use AWS Config aggregator to collect IAM user activity.
C.Set up Amazon Kinesis Data Streams in each account and stream to a central Kinesis Data Firehose.
D.Configure CloudTrail in each account to deliver logs to a single S3 bucket in the security account.
AnswerD

CloudTrail delivers logs to a central S3 bucket via a bucket policy granting each account's trail write access, satisfying the multi-account aggregation requirement without per-account tooling. This scales to any number of business units, unlike manual consolidation, and preserves a single queryable log repository for the central security team.

Why this answer

CloudTrail can be configured in each account to deliver log files to a centralized S3 bucket in the security account. This approach aggregates all IAM user activities into a single location without requiring additional streaming infrastructure, and it scales automatically as new accounts are added. The central security team can then use Amazon Athena or AWS Lake Formation to query the logs across all accounts efficiently.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Kinesis (Option C) because they assume streaming is required for scalability, but CloudTrail's native S3 delivery is the most scalable and cost-effective aggregation method for IAM user activity logs.

How to eliminate wrong answers

Option A is wrong because reviewing CloudTrail Insights separately in each account does not aggregate logs; it requires manual per-account access and lacks a centralized view, making it unscalable for decentralized IT structures. Option B is wrong because AWS Config aggregator is designed to collect resource configuration changes and compliance history, not IAM user activity logs; CloudTrail is the service that records API activity, not AWS Config. Option C is wrong because setting up Kinesis Data Streams in each account and streaming to a central Kinesis Data Firehose introduces unnecessary complexity, cost, and operational overhead compared to the simpler S3 bucket delivery method; CloudTrail can directly deliver to S3 without needing Kinesis.

269
Multi-Selecthard

Which THREE of the following are common challenges when migrating a monolithic application to a microservices architecture on AWS? (Choose three.)

Select 3 answers
A.Managing distributed transactions across multiple services
B.Single database bottleneck when all services share the same database
C.Increased network latency due to inter-service communication
D.Ensuring data consistency between services that own their own databases
E.Difficulty in scaling individual services independently
AnswersA, C, D

With data split across services, a business operation spanning several of them cannot rely on a single local transaction. Coordinating commits across service boundaries needs compensating actions or saga orchestration, making distributed transaction management a core migration challenge.

Why this answer

Option A is correct because decomposing a monolith into microservices means a single business operation often spans multiple services, each with its own datastore, so maintaining atomicity requires patterns like Saga, two-phase commit, or compensating transactions instead of a single ACID transaction. Option C is correct because calls that were once in-process method invocations become remote network calls over HTTP/gRPC or via queues, adding serialization, connection, and round-trip latency plus retry and timeout overhead. Option D is correct because when each service owns its own database, you lose the monolith's single ACID transaction and must handle eventual consistency, idempotency, and reconciliation across services.

Option B is not a challenge specific to microservices migration — a shared single database is actually a characteristic of the monolith being left behind, and the migration goal is typically to decompose that database. Option E is not a challenge but a benefit: microservices are designed so each service can be scaled independently, which is easier than scaling a monolith as a whole.

Exam trap

SAP-C02 often tests the confusion between challenges of microservices and benefits, such as mistaking independent scaling as a challenge rather than an advantage.

270
MCQhard

A company is migrating a critical database server to Amazon EC2. The root volume (EBS) is configured with DeleteOnTermination=false. After migration, the company needs to ensure that if the EC2 instance fails, a new instance can be quickly launched using the same data. The company takes regular snapshots of the volume. Which statement is correct regarding the root volume's behavior?

A.The root volume cannot be used as a boot volume for a new instance.
B.The root volume will be automatically deleted when the instance is terminated.
C.The root volume will persist after instance termination and can be attached to another instance.
D.Snapshots of the volume will be automatically deleted when the instance is terminated.
AnswerC

With DeleteOnTermination set to false, the EBS root volume survives instance termination, satisfying the requirement that data remains available for a replacement instance. The volume detaches and can be reattached to a new EC2 instance in the same Availability Zone, enabling rapid recovery without restoring from snapshots.

Why this answer

When DeleteOnTermination is set to false, the root volume persists after the EC2 instance is terminated. This allows the volume to be attached to another instance, enabling quick recovery. Option A is incorrect because the root volume can be used as a boot volume for a new instance when attached.

Option B is incorrect because the volume is not automatically deleted; deletion only occurs when DeleteOnTermination is true. Option D is incorrect because snapshots are independent of the DeleteOnTermination setting and are not automatically deleted upon instance termination.

271
MCQeasy

A company has an AWS Organization with multiple accounts. The central IT team wants to deploy a common set of AWS Config rules across all accounts in the production OU. Which approach is the MOST scalable and maintainable?

A.Use an AWS Config aggregator to deploy rules across accounts.
B.Use AWS CloudFormation StackSets to deploy an AWS Config rule template to each account.
C.Use AWS Config conformance packs and deploy them using AWS CloudFormation StackSets.
D.Use AWS Config to create a custom rule in each account manually.
AnswerC

Conformance packs bundle Config rules as a single deployable entity, and StackSets pushes that pack into every account in the production OU automatically, including new accounts. This satisfies the scalability and maintainability requirement without per-account manual rule creation.

Why this answer

AWS Config conformance packs provide a collection of AWS Config rules and remediation actions that can be deployed consistently across accounts and Regions. Using AWS CloudFormation StackSets to deploy conformance packs is the most scalable and maintainable approach because StackSets automates the deployment to multiple accounts in an AWS Organization, and conformance packs allow centralized management of rule sets, including parameterization and remediation, without requiring per-account manual effort.

Exam trap

The trap here is that candidates confuse the purpose of an AWS Config aggregator (which only aggregates compliance data) with the ability to deploy rules, leading them to select Option A, while Option B seems plausible but misses that conformance packs are the purpose-built, more maintainable solution for deploying a common set of rules at scale.

How to eliminate wrong answers

Option A is wrong because an AWS Config aggregator is used to aggregate compliance data from multiple accounts and Regions into a single view; it does not deploy or manage Config rules across accounts. Option B is wrong because while CloudFormation StackSets can deploy individual Config rules, conformance packs are the recommended service for deploying a common set of rules with built-in support for organization-wide management, parameterization, and remediation actions, making them more maintainable than deploying individual rules. Option D is wrong because manually creating custom rules in each account is not scalable, introduces human error, and violates the principle of infrastructure as code and centralized management.

272
MCQeasy

A company uses Amazon RDS for MySQL for its database. The operations team notices that read queries are slow during peak hours. The application is read-heavy and can tolerate eventual consistency. Which solution would improve read performance with minimal application changes?

A.Increase the DB instance class to a larger size.
B.Enable Multi-AZ deployment for failover support.
C.Enable RDS Proxy to pool database connections.
D.Create an RDS read replica and direct read traffic to it.
AnswerD

An RDS read replica offloads read queries to a separate MySQL instance via asynchronous replication, directly relieving the primary during peak hours. Because the application tolerates eventual consistency, replication lag is acceptable, and directing reads to the replica endpoint requires minimal application change.

Why this answer

Creating an RDS read replica and directing read traffic to it offloads read queries from the primary instance, improving read performance for a read-heavy application that tolerates eventual consistency. This requires minimal application changes—typically just updating the connection string for read operations to point to the replica endpoint. Read replicas use asynchronous replication, so they are suitable for eventually consistent reads.

Exam trap

SAP-C02 often tests the misconception that Multi-AZ improves read performance (it does not; the standby is not readable) or that RDS Proxy increases read throughput (it pools connections, not reads).

How to eliminate wrong answers

Option A is wrong because increasing the DB instance class scales both reads and writes vertically, which is more expensive and does not specifically address read-heavy load; it also requires a reboot and may not be cost-effective. Option B is wrong because Multi-AZ is for high availability and failover, not read scaling; the standby does not serve read traffic. Option C is wrong because RDS Proxy pools and shares database connections to improve scalability and resilience, but it does not increase read throughput or offload read queries from the primary.

273
MCQmedium

A company wants to implement a multi-account strategy using AWS Organizations. The security team requires that all new accounts added to the organization automatically inherit a baseline set of security controls, such as AWS CloudTrail and AWS Config rules. Which approach should the company use?

A.Use AWS Organizations Service Control Policies (SCPs) to enforce the baseline controls.
B.Use AWS Systems Manager Automation to apply the baseline to new accounts.
C.Use AWS CloudFormation StackSets to deploy the baseline stack to new accounts automatically.
D.Use AWS Config aggregators to apply the baseline controls to new accounts.
AnswerC

CloudFormation StackSets with service-managed permissions deploy stacks automatically to accounts as AWS Organizations adds them, satisfying the requirement that new accounts inherit baseline controls without manual intervention. Unlike account-creation triggers or Control Tower, StackSets directly targets the organisational unit, ensuring CloudTrail and Config rules land immediately on joining.

Why this answer

AWS CloudFormation StackSets can automatically deploy a common baseline stack (containing CloudTrail, AWS Config rules, and other security controls) to all accounts in an AWS Organization, including new accounts as they are added. This approach ensures consistent, automated deployment of infrastructure-as-code across the entire organization without manual intervention.

Exam trap

The trap here is confusing SCPs (which only restrict permissions) with actual resource deployment mechanisms, leading candidates to incorrectly choose Option A because they think SCPs can 'enforce' the presence of services like CloudTrail.

How to eliminate wrong answers

Option A is wrong because Service Control Policies (SCPs) are used to define permission boundaries and restrict actions, not to deploy or enable services like CloudTrail or AWS Config rules; SCPs cannot create resources or enable services. Option B is wrong because AWS Systems Manager Automation is designed for operational tasks on existing instances or accounts, not for automatically provisioning baseline resources across new accounts as they join an organization. Option D is wrong because AWS Config aggregators only collect and aggregate compliance data from multiple accounts and regions; they do not deploy or enable Config rules or other security controls.

274
MCQhard

A company runs a critical application on Amazon EC2 instances in a single AWS Region. The application uses an Amazon RDS for MySQL database with a read replica in another Availability Zone. The company wants to improve the disaster recovery posture to meet an RPO of 5 minutes and an RTO of 15 minutes in case of a regional failure. The application must be able to fail over to a secondary Region with minimal data loss. Which solution meets these requirements?

A.Configure an Amazon RDS for MySQL cross-Region read replica in the secondary Region. Promote the read replica to a standalone database in the event of a regional failure.
B.Enable multi-AZ deployment for the RDS database and use a second standby in the secondary Region with synchronous replication.
C.Use AWS Database Migration Service (AWS DMS) with change data capture (CDC) to continuously replicate data to an Amazon RDS for MySQL instance in the secondary Region.
D.Enable automated backups for the RDS database and copy the backups to the secondary Region. In the event of a failure, restore the database from the latest backup in the secondary Region.
AnswerA

A cross-Region read replica uses asynchronous replication to keep a copy of the database in another Region. The replication lag is typically under a minute, satisfying the 5-minute RPO. Promotion of a read replica to a standalone instance takes only a few minutes, well within the 15-minute RTO. This is a cost-effective and reliable DR solution for RDS for MySQL, and it meets both the RPO and RTO requirements for this scenario.

Why this answer

A cross-Region read replica provides asynchronous replication to a secondary Region, typically with sub-minute latency, which satisfies the 5-minute RPO. In a disaster, promoting the read replica to a standalone database takes only a few minutes, meeting the 15-minute RTO. This is a native RDS feature that requires minimal operational overhead and is a recommended DR pattern for RDS for MySQL.

Other options either do not meet the RTO or rely on unsupported or overly complex mechanisms.

Exam trap

The trap here is assuming that automated backups with cross-Region copy can meet a 15-minute RTO.

275
MCQmedium

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application uses a self-signed SSL certificate on the instances, and an Application Load Balancer (ALB) terminates SSL. Users report intermittent SSL certificate errors. The security team requires that the certificate be managed and rotated automatically. Which solution should a solutions architect implement to meet these requirements?

A.Request a public certificate from AWS Certificate Manager (ACM) for the application's domain and attach it to the ALB. Remove the self-signed certificate from the instances.
B.Request a public certificate from AWS Certificate Manager (ACM) for the application's domain, attach it to the ALB, and configure the instances to use it.
C.Import the self-signed certificate into AWS Certificate Manager (ACM) and use it on the ALB. Configure ACM to rotate the certificate annually.
D.Use AWS Secrets Manager to store the self-signed certificate and configure the instances to retrieve and install it on a schedule using a Lambda function.
AnswerA

ACM provides public certificates that are automatically renewed and deployed. Attaching the ACM certificate to the ALB ensures that SSL termination uses a trusted certificate, eliminating intermittent errors caused by the self-signed certificate. Since the ALB handles SSL termination, the instances do not need certificates. This meets the requirements for managed and automatically rotated certificates.

Why this answer

The intermittent SSL errors are likely due to the self-signed certificate not being trusted by clients. Using a public ACM certificate on the ALB provides a trusted certificate that is automatically managed and renewed. Since the ALB terminates SSL, the instances do not need any certificate.

This solution meets the security team's requirement for automatic management and rotation.

Exam trap

The trap here is assuming that ACM can automatically rotate imported self-signed certificates or that instances need the certificate when an ALB terminates SSL.

276
Multi-Selectmedium

A company is designing a solution to process real-time streaming data from IoT devices. The data must be ingested, processed with sub-second latency, and stored for analytics. Which services should the company use? (Choose TWO.)

Select 2 answers
A.AWS Lambda
B.Amazon Kinesis Data Streams
C.Amazon SQS
D.Amazon Kinesis Data Analytics
E.Amazon Kinesis Data Firehose
AnswersA, B

Can process records from Kinesis streams in near real-time.

Why this answer

AWS Lambda is correct because it can process streaming data from Amazon Kinesis Data Streams with sub-second latency by subscribing to the stream as an event source. Lambda functions are invoked synchronously with each record, enabling real-time transformations or lightweight analytics before the data is stored.

Exam trap

The trap here is that candidates often confuse Amazon Kinesis Data Firehose (which has a 60-second minimum buffer) with Kinesis Data Streams for sub-second latency, or they mistakenly think SQS is suitable for streaming ingestion when it is designed for message queuing, not ordered, replayable stream processing.

277
MCQhard

A company uses AWS CloudFormation to manage infrastructure. A recent stack update failed because a resource exceeded a service quota. The team wants to be notified proactively when service limits are approaching. Which solution meets this requirement?

A.Use AWS CloudTrail to monitor API calls that indicate quota exhaustion.
B.Use AWS Config rules to check if resources are within limits.
C.Use AWS Trusted Advisor to check service limits regularly.
D.Use Amazon CloudWatch to monitor service quota usage metrics and set CloudWatch alarms.
AnswerD

CloudWatch publishes Service Quotas usage metrics, so alarms can fire before a limit is breached, satisfying the proactive notification requirement. Unlike Trusted Advisor's periodic checks, these metrics update continuously, letting the team act before a CloudFormation update fails again.

Why this answer

AWS Service Quotas publishes CloudWatch metrics (e.g., AWS/Usage namespace with Resource and Service dimensions) that track current usage against quotas. Creating CloudWatch alarms on these metrics allows proactive notification before a quota is exhausted, directly addressing the requirement. This is the AWS-recommended approach for quota monitoring at scale.

Exam trap

SAP-C02 often tests whether candidates know that Trusted Advisor is not real-time and requires paid support, while CloudWatch alarms on Service Quotas metrics provide the proactive, automated notification the question demands.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs API activity after the fact — it can show a quota-exceeded error occurred, but it is reactive, not proactive, and does not emit metrics you can alarm on. Option B is wrong because AWS Config rules evaluate resource configuration compliance (e.g., 'is this bucket encrypted?'), not service quota consumption, and there are no native Config rules that track quota utilization. Option C is wrong because Trusted Advisor's service limits check is only available on Business/Enterprise Support plans, runs periodically (not real-time), and does not integrate with CloudWatch alarms for automated notification.

278
MCQhard

A company runs a microservices application on Amazon EKS. The application consists of multiple services that communicate over HTTP. The operations team wants to implement a service mesh to gain observability, traffic management, and security features without modifying application code. They also want to minimize operational overhead. Which solution should a solutions architect recommend?

A.Deploy AWS App Mesh with Envoy sidecar proxies injected into each pod.
B.Configure an Application Load Balancer (ALB) with AWS WAF to manage traffic between services.
C.Use AWS Cloud Map for service discovery and implement custom retry logic in each microservice.
D.Install and configure Istio on the EKS cluster using Helm charts.
AnswerA

AWS App Mesh is a managed service mesh that uses Envoy proxies to provide observability, traffic routing, and security without application code changes. It integrates with EKS and handles control plane management, reducing operational overhead. It supports features like circuit breaking, retries, and mutual TLS. This is the native AWS solution for service mesh on EKS, meeting all requirements.

Why this answer

AWS App Mesh is a managed service mesh that provides consistent observability, traffic control, and security for microservices on EKS. It uses Envoy sidecar proxies injected into pods, requiring no application code changes. As a managed service, it reduces operational overhead compared to self-managed options like Istio.

It supports features such as traffic routing, retries, and mutual TLS, directly addressing the requirements.

Exam trap

The trap here is assuming that any service mesh requires significant operational effort, but AWS App Mesh is managed and minimizes overhead while providing the needed features.

279
MCQmedium

A company is migrating a containerized application from on-premises Kubernetes to Amazon EKS. The application uses persistent volumes for shared configuration files that must be accessible by multiple pods across different Availability Zones. The company wants a fully managed storage solution that supports ReadWriteMany (RWX) access. Which storage option should be used?

A.Amazon S3 mounted using the Mountpoint for Amazon S3 CSI driver.
B.Amazon FSx for Windows File Server with the FSx CSI driver.
C.Amazon EFS with the EFS CSI driver.
D.Amazon EBS with the EBS CSI driver.
AnswerC

Amazon EFS is a fully managed, elastic file system that supports the ReadWriteMany access mode and can be mounted by multiple pods across different Availability Zones. The EFS CSI driver integrates with Amazon EKS, allowing dynamic provisioning of persistent volumes. This meets the requirements for shared storage across AZs.

Why this answer

Amazon EFS with the EFS CSI driver is the correct choice because it is a fully managed, scalable file system that supports ReadWriteMany access and can be mounted by multiple pods across Availability Zones. It integrates natively with Amazon EKS, enabling dynamic provisioning and shared storage. The other options either do not support RWX, are not designed for Linux containers, or lack POSIX compliance.

Exam trap

The trap here is assuming that Amazon EBS can be used for shared storage across pods, but EBS volumes are single-AZ and cannot be attached to multiple instances simultaneously in read-write mode.

280
MCQeasy

Refer to the exhibit. An IAM policy allows ec2:Describe* actions on all resources. A developer wants to also allow describing RDS instances. Which action must be added to the policy?

A.rds:List*
B.rds:Get*
C.rds:Describe*
D.ec2:DescribeRdsInstances
AnswerC

Adding `rds:Describe*` grants the specific RDS read permissions the developer needs, satisfying the requirement to describe RDS instances. IAM evaluates actions per service namespace, so EC2's `ec2:Describe*` wildcard never covers RDS API calls; a separate RDS statement is mandatory.

Why this answer

AWS IAM policies use the `rds:Describe*` action to grant permission to describe RDS instances, DB snapshots, DB parameter groups, and other RDS resources. The `ec2:Describe*` action only covers EC2 resources, not RDS resources, so a separate RDS-specific action is required. The wildcard `*` after `Describe` matches all RDS describe operations, including `rds:DescribeDBInstances`.

Exam trap

The trap here is that candidates assume `ec2:Describe*` covers all AWS describe operations across services, but IAM actions are scoped per service namespace (e.g., `ec2:`, `rds:`), and each service has its own set of actions.

How to eliminate wrong answers

Option A is wrong because `rds:List*` is not a valid IAM action prefix for RDS; RDS uses `Describe` actions for read operations, not `List`. Option B is wrong because `rds:Get*` is not a valid IAM action for RDS; AWS RDS API uses `Describe` actions (e.g., `DescribeDBInstances`) rather than `Get` actions. Option D is wrong because `ec2:DescribeRdsInstances` does not exist; EC2 and RDS are separate services with distinct action namespaces, and RDS actions must use the `rds:` prefix.

281
MCQhard

A company is migrating a large-scale on-premises Apache Kafka cluster to AWS. The cluster handles real-time streaming data from thousands of IoT devices. The company wants to reduce operational overhead and ensure high availability. Which AWS service should be used?

A.Amazon Managed Streaming for Apache Kafka (MSK)
B.Amazon Simple Notification Service (SNS)
C.Amazon Simple Queue Service (SQS)
D.Amazon Kinesis Data Streams
AnswerA

Amazon MSK runs the Kafka control plane, broker patching and Multi-AZ replication, removing the operational burden the stem demands while preserving native Kafka APIs for the IoT stream. Self-managed brokers on EC2 would retain that overhead and weaken availability guarantees.

Why this answer

Amazon MSK is the correct choice because it is a fully managed service for Apache Kafka that runs the same open-source Kafka APIs, so existing producers, consumers, and tooling migrate without code changes. MSK handles broker provisioning, patching, replication across AZs, and automatic recovery, directly reducing operational overhead while providing high availability. It also integrates with VPC, IAM, KMS, and CloudWatch for security and monitoring.

Exam trap

SAP-C02 often tests whether candidates confuse Kafka-compatible managed services (MSK) with AWS-native streaming alternatives (Kinesis) or messaging services (SNS/SQS), so the trap is picking Kinesis for a 'migrate Kafka' scenario.

How to eliminate wrong answers

Option B is wrong because Amazon SNS is a pub/sub notification service for fan-out messaging, not a Kafka-compatible streaming platform, so it cannot host Kafka topics or preserve Kafka consumer semantics. Option C is wrong because Amazon SQS is a managed queue for decoupled point-to-point messaging and lacks Kafka's partitioned log, consumer groups, and replay capabilities. Option D is wrong because Kinesis Data Streams is a proprietary AWS streaming service; it requires rewriting Kafka producers/consumers and does not support the Kafka API, so it does not meet the 'migrate Kafka with minimal change' requirement.

282
Multi-Selectmedium

A company is migrating a legacy application that uses a proprietary binary protocol for communication. The application communicates over TCP/IP. The company wants to modernize the communication layer to use a RESTful API. Which TWO approaches should the company consider?

Select 2 answers
A.Replace the binary protocol with Amazon MQ.
B.Use Amazon API Gateway and AWS Lambda to create a REST API that translates requests to the legacy protocol.
C.Use AWS App Mesh to convert the binary protocol to HTTP.
D.Refactor the application to communicate over HTTP and use Amazon API Gateway.
E.Use Amazon CloudFront to cache the RESTful endpoints.
AnswersB, D

API Gateway fronts a RESTful HTTPS endpoint, while Lambda functions translate each request into the legacy proprietary binary protocol over TCP/IP and return JSON responses. This preserves the existing backend, so only the communication layer is modernised.

Why this answer

Option B is correct because Amazon API Gateway can expose a RESTful API endpoint while AWS Lambda functions act as the integration layer that translates incoming HTTP/JSON requests into the legacy proprietary binary protocol, allowing the legacy application to remain unchanged behind the modernization facade. Option D is correct because refactoring the application itself to natively speak HTTP lets it be fronted directly by Amazon API Gateway as a REST API, eliminating the need for protocol translation and providing a fully RESTful communication layer. Option A is not appropriate because Amazon MQ is a managed message broker for protocols such as JMS, AMQP, MQTT, OpenWire, and STOMP, not a REST API or binary-to-HTTP translator.

Option C is incorrect because AWS App Mesh is a service mesh for managing and observing service-to-service traffic (typically HTTP/gRPC/TCP), not a protocol conversion tool that turns a proprietary binary protocol into HTTP. Option E is incorrect because Amazon CloudFront is a CDN that caches and accelerates content delivery; it does not modernize or translate a proprietary binary protocol into REST.

283
MCQmedium

A company has a centralized logging account that receives VPC flow logs from all accounts. The logs are stored in an S3 bucket. The security team needs to analyze these logs to detect anomalous traffic patterns. Which solution provides the most cost-effective and scalable analysis?

A.Use Amazon QuickSight to create dashboards from the flow logs.
B.Use Amazon Athena to run SQL queries directly on the S3 bucket containing the flow logs.
C.Set up Amazon Kinesis Data Analytics to process the flow logs in real time.
D.Load the flow logs into Amazon Redshift and run SQL queries.
AnswerB

Athena is serverless and queries data in place in Amazon S3, so there is no cluster to provision or data to load. Cost scales with bytes scanned, making it both scalable and cost-effective for analysing accumulated VPC flow logs.

Why this answer

Amazon Athena is the most cost-effective and scalable solution because it allows querying VPC flow logs directly in S3 using standard SQL without requiring data loading or infrastructure management. Athena's serverless, pay-per-query model eliminates idle costs and scales automatically to handle any volume of log data, making it ideal for ad-hoc security analysis of historical logs.

Exam trap

The trap here is that candidates may choose Redshift or Kinesis because they associate 'analysis' with traditional data warehouses or real-time processing, overlooking that Athena's serverless, pay-per-query model is the most cost-effective and scalable for ad-hoc SQL analysis of data already in S3.

How to eliminate wrong answers

Option A is wrong because Amazon QuickSight is a visualization tool that requires a data source; it cannot directly analyze raw VPC flow logs in S3 without an intermediate query engine like Athena, and it incurs per-session costs that are not optimal for ad-hoc analysis. Option C is wrong because Amazon Kinesis Data Analytics processes streaming data in real time, which is unnecessary and more expensive for analyzing historical VPC flow logs already stored in S3; the requirement is for batch analysis of stored logs, not real-time processing. Option D is wrong because loading VPC flow logs into Amazon Redshift involves data ingestion, storage, and compute costs even when not querying, and it requires cluster management, making it less cost-effective and more complex than Athena's serverless approach for this use case.

284
MCQeasy

A company wants to migrate its on-premises file server to AWS. The file server contains 10 TB of data that changes infrequently. The company has a limited bandwidth internet connection and needs to complete the migration within one week. Which AWS service should the company use for the initial data transfer?

A.Amazon S3 Transfer Acceleration
B.AWS Snowball Edge
C.AWS Database Migration Service (DMS)
D.AWS DataSync
AnswerB

AWS Snowball Edge suits the 10 TB dataset because it ships a physical appliance, bypassing the limited internet bandwidth that would make a one-week transfer infeasible. Data is copied locally to the device, returned to AWS, and ingested into S3, meeting the one-week deadline without saturating the existing connection.

Why this answer

AWS Snowball Edge. This is the best option for migrating 10 TB of data over a limited bandwidth connection within a week, as it physically transfers the data via a portable storage device, bypassing the need for network bandwidth. Option A (Amazon S3 Transfer Acceleration) is incorrect because it still relies on internet bandwidth, which is insufficient for the given timeline.

Option C (AWS DMS) is for database migrations, not file servers. Option D (AWS DataSync) also requires network connectivity and bandwidth, making it unsuitable for the large initial transfer over a slow connection.

285
Multi-Selecthard

A company is designing a new application that will use Amazon DynamoDB as its database. The application will have a heavy read workload with occasional write spikes. The company wants to minimize costs while ensuring that reads are eventually consistent and writes are not throttled. Which three options should the architect consider? (Choose THREE.)

Select 3 answers
A.Use DynamoDB Streams to asynchronously replicate data to a second table for reads
B.Use Auto Scaling for write capacity
C.Use eventually consistent reads for most queries
D.Use DynamoDB Accelerator (DAX) to cache read results
E.Use strongly consistent reads for all queries
AnswersB, C, D

Auto Scaling adjusts write capacity to handle spikes without throttling.

Why this answer

DynamoDB Auto Scaling adjusts the provisioned write capacity based on actual traffic, preventing throttling during write spikes while reducing capacity and cost during low-traffic periods. This meets the requirement to minimize costs and avoid write throttling without manual intervention.

Exam trap

The trap here is that candidates may confuse DynamoDB Streams with a caching solution, or incorrectly assume strongly consistent reads are always required, ignoring the cost implications of RCU consumption for read-heavy workloads.

286
MCQmedium

A company uses AWS Lambda functions behind an Amazon API Gateway REST API. The Lambda functions query an Amazon RDS for PostgreSQL database. Recently, the company has noticed increased latency and occasional timeouts during peak hours. A solutions architect needs to improve the performance and scalability of the database layer. Which solution will meet these requirements with the LEAST operational overhead?

A.Enable Amazon DynamoDB Accelerator (DAX) on the RDS instance.
B.Add a Multi-AZ RDS Read Replica and modify Lambda to use the Read Replica for queries.
C.Increase the instance size of the RDS database to handle more concurrent connections.
D.Implement Amazon RDS Proxy to manage connection pooling between Lambda and the RDS instance.
AnswerD

Lambda opens a new database connection per invocation, exhausting PostgreSQL's connection limit during peak load. RDS Proxy pools and reuses connections, absorbing bursts without application changes. This reduces latency and timeouts with minimal operational overhead, since AWS manages the proxy infrastructure.

Why this answer

AWS Lambda functions can overwhelm an RDS database with too many concurrent connections, causing latency and timeouts. RDS Proxy pools and shares database connections, reducing the connection overhead and improving scalability without code changes. It requires minimal operational overhead because it is a managed service that integrates with IAM and Secrets Manager.

Exam trap

SAP-C02 often tests the misconception that read replicas or larger instances solve Lambda-to-RDS connection issues, when the core problem is connection pooling and the answer is RDS Proxy.

How to eliminate wrong answers

Option A is wrong because DAX is a caching service for DynamoDB, not RDS; it cannot be enabled on an RDS instance. Option B is wrong because a Multi-AZ read replica is for disaster recovery, not for offloading read queries; a read replica can offload reads but requires application changes and does not solve connection pooling, and Multi-AZ is synchronous standby. Option C is wrong because increasing instance size may handle more connections but does not address the fundamental connection management issue and can be costly and still limited by max_connections.

287
MCQmedium

A company is designing a new application that will be deployed on AWS. The application consists of a web tier running on Amazon EC2 instances and a database tier using Amazon Aurora. The company expects unpredictable traffic patterns and wants to optimize costs while maintaining high availability. The web tier must automatically scale based on demand, and the database must be able to handle read-heavy workloads. What should a solutions architect recommend?

A.Use AWS Lambda for the web tier with provisioned concurrency, and use Aurora Serverless for the database.
B.Use an Auto Scaling group with a scheduled scaling policy for the web tier, and use a single Aurora instance with a larger instance size for the database.
C.Use an Auto Scaling group for the web tier with a target tracking scaling policy, and add Aurora Replicas to the Aurora cluster for read scaling.
D.Use an Auto Scaling group with a simple scaling policy for the web tier, and enable Aurora Auto Scaling for the database.
AnswerC

An Auto Scaling group with target tracking can automatically adjust the number of EC2 instances based on metrics like CPU utilization, optimizing costs during low demand. Aurora Replicas offload read traffic from the primary instance, improving read scalability and performance. This combination provides high availability and cost efficiency for unpredictable traffic.

Why this answer

The recommended solution is to use an Auto Scaling group with a target tracking scaling policy for the web tier, which dynamically adjusts capacity based on demand, and to add Aurora Replicas to the Aurora cluster to handle read-heavy workloads. This provides high availability, cost optimization, and read scalability. Other options either use less responsive scaling policies or change the architecture unnecessarily.

Exam trap

The trap here is assuming that scheduled scaling can handle unpredictable traffic, but it is designed for predictable patterns and may not react to sudden spikes.

288
MCQeasy

A company uses Amazon CloudFront to deliver static content from an S3 bucket. They want to restrict access so that only CloudFront can access the S3 bucket. What configuration should they use?

A.Set the S3 bucket policy to allow access only from CloudFront's public IP ranges.
B.Create an origin access identity (OAI) and grant it read access to the S3 bucket.
C.Attach an IAM role to CloudFront distribution.
D.Configure CloudFront signed URLs.
AnswerB

An origin access identity (OAI) is a special CloudFront user that the distribution attaches to origin requests, letting the S3 bucket policy grant read access solely to that identity. This satisfies the requirement that only CloudFront reach the bucket, blocking direct public S3 access. Note that Microsoft Entra ID is unrelated here.

Why this answer

Create an origin access identity (OAI) and grant it read access to the S3 bucket. An OAI is a special CloudFront user that allows CloudFront to access private S3 bucket content securely. Option A is incorrect because CloudFront does not have static public IP ranges; it uses a large dynamic range.

Option C is incorrect because IAM roles are not used directly for CloudFront to S3 access; OAI is the standard method. Option D is incorrect because signed URLs control end-user access, not origin access.

289
MCQmedium

A company is designing a new application that will process sensitive financial data. The application must encrypt data at rest and in transit. The company wants to use AWS managed keys for encryption. Which AWS service should the company use to create and manage the encryption keys?

A.AWS CloudHSM
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.AWS Certificate Manager (ACM)
AnswerC

AWS Key Management Service creates and manages the AWS managed keys that encrypt the financial data at rest, and integrates with services for in-transit protection. It directly meets the requirement to use AWS managed keys for key creation and management.

Why this answer

AWS Key Management Service (KMS) is the correct choice because it is a managed service that enables you to create, store, and control encryption keys used to encrypt data at rest and in transit. KMS integrates with other AWS services (e.g., S3, EBS, RDS) and supports envelope encryption, where a customer master key (CMK) encrypts data keys that perform the actual encryption. It also provides automatic key rotation and fine-grained access control via IAM policies and key policies, meeting the requirement for AWS-managed keys.

Exam trap

The trap here is that candidates often confuse AWS CloudHSM (which provides dedicated, customer-managed HSMs) with KMS (which provides fully managed, AWS-controlled keys), leading them to choose CloudHSM when the question explicitly requires 'AWS managed keys'.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules (HSMs) that you manage yourself, not AWS-managed keys; it requires you to handle key lifecycle and scaling, and does not offer the same level of integration with AWS services as KMS. Option B is wrong because AWS Secrets Manager is designed to securely store and rotate secrets (e.g., database credentials, API keys), not to create or manage encryption keys; it can use KMS to encrypt those secrets, but it is not a key management service itself. Option D is wrong because AWS Certificate Manager (ACM) is used to provision, manage, and deploy public and private SSL/TLS certificates for securing network traffic (in transit), but it does not create or manage encryption keys for data at rest; it relies on KMS for private key protection in some cases, but its primary function is certificate lifecycle management.

290
MCQeasy

A company is migrating an on-premises application to AWS. The application requires low-latency access to a file system that can be mounted by multiple EC2 instances simultaneously. Which AWS storage service should they use?

A.Amazon EFS
B.Amazon S3
C.Amazon FSx for Windows File Server
D.Amazon EBS
AnswerA

Amazon EFS provides a shared, elastic NFS file system mountable concurrently by many EC2 instances across Availability Zones, with low latency. This satisfies the stem's requirement for simultaneous multi-instance access to a shared file system.

Why this answer

Amazon EFS is a fully managed, elastic NFS file system that can be mounted concurrently by thousands of EC2 instances across multiple Availability Zones, providing the shared low-latency POSIX access the application needs. It scales automatically and is the canonical AWS answer for multi-attach Linux file storage.

Exam trap

The trap is treating S3 as a general-purpose file system because it's the most familiar AWS storage service — but S3 is object storage and cannot be mounted as a shared POSIX filesystem without third-party gateways.

How to eliminate wrong answers

Option B is wrong because Amazon S3 is object storage accessed via HTTP APIs, not a mountable POSIX file system, so it cannot satisfy a legacy application expecting a mounted share. Option C is wrong because FSx for Windows File Server speaks SMB and targets Windows workloads, not the typical Linux multi-mount scenario described. Option D is wrong because EBS volumes attach to a single EC2 instance at a time (except niche Multi-Attach io1/io2 in one AZ), so they cannot be shared simultaneously.

291
MCQhard

Refer to the exhibit. An IAM policy is attached to an IAM user. The user tries to upload an object to `s3://my-bucket/secret/data.txt` from an IP address in the 10.0.0.0/8 range. What will happen?

A.The upload succeeds because the Allow statement grants s3:PutObject.
B.The upload succeeds because the Deny statement only applies to GetObject, not PutObject.
C.The upload fails because the Deny statement denies all s3 actions unconditionally.
D.The upload fails because the Deny statement explicitly denies s3:PutObject for the prefix secret/ from the specified IP range.
AnswerD

An explicit Deny in IAM always overrides any Allow, regardless of other policies. The Deny statement targets s3:PutObject on the secret/ prefix and matches the request's source IP within 10.0.0.0/8, so the upload is blocked.

Why this answer

In IAM policy evaluation, an explicit Deny always overrides any Allow. The Deny statement in the policy explicitly denies s3:PutObject for objects under the secret/ prefix when the request originates from the 10.0.0.0/8 range. Since the user is uploading to s3://my-bucket/secret/data.txt from an IP in that range, the Deny matches and the upload fails regardless of the Allow statement.

Exam trap

The trap is assuming Allow wins because it appears first or because the user 'has permission' — candidates forget that in AWS IAM, an explicit Deny always overrides any Allow, and they must check the Deny's conditions (prefix + IP range) against the request.

How to eliminate wrong answers

Option A is wrong because it ignores the explicit Deny — in AWS IAM, an explicit Deny always wins over an Allow, so the presence of a granting statement does not guarantee success. Option B is wrong because it misreads the Deny statement's scope; the Deny is not limited to GetObject — it denies s3:PutObject (and likely other actions) for the secret/ prefix from the specified IP range, so the claim that it 'only applies to GetObject' is factually incorrect. Option C is wrong because it overstates the Deny — the Deny is conditional (scoped to a specific prefix and IP range), not unconditional across all s3 actions, so saying it 'denies all s3 actions unconditionally' mischaracterizes the policy.

292
MCQhard

A company is migrating a stateful application to AWS. The application uses sticky sessions (session affinity) on the current on-premises load balancer. The company wants to use an Application Load Balancer (ALB) in AWS. Which feature should be enabled?

A.Connection draining (deregistration delay).
B.Sticky sessions (session affinity) using a cookie generated by the load balancer.
C.Health checks to ensure only healthy instances receive traffic.
D.Cross-zone load balancing.
AnswerB

An Application Load Balancer supports sticky sessions by issuing its own cookie, AWSALB, which pins each client to the same target for the session's duration. This preserves the session affinity the on-premises load balancer provided for the stateful application.

Why this answer

ALB supports sticky sessions via a load balancer-generated cookie (AWSALB) that binds a client to a specific target for the duration of the stickiness policy. Enabling stickiness on the target group preserves session state for stateful applications migrated from on-premises load balancers that used session affinity. This is the direct ALB feature that replicates the on-premises behavior.

Exam trap

SAP-C02 often tests whether candidates conflate session affinity (stickiness) with availability features like health checks, cross-zone balancing, or connection draining, all of which appear in the same ALB feature list.

How to eliminate wrong answers

Option A is wrong because connection draining (deregistration delay) only controls how long the ALB waits for in-flight requests to complete before deregistering a target; it does not maintain client-to-target affinity. Option C is wrong because health checks determine target availability and remove unhealthy targets from rotation; they do not preserve session state. Option D is wrong because cross-zone load balancing distributes traffic evenly across AZs for high availability; it does not provide session affinity and can actually break stickiness if misconfigured.

293
MCQmedium

A company is deploying a containerized application on Amazon ECS. The application must be highly available and scale automatically based on CPU utilization. The application also needs to be accessible from the internet via a single endpoint. Which combination of services should the solutions architect use?

A.Amazon ECS with an Application Load Balancer and ECS Service Auto Scaling with a target tracking policy based on average CPU utilization.
B.Amazon ECS with a Network Load Balancer and step scaling policies.
C.Amazon ECS with an Application Load Balancer and step scaling policies based on CPU utilization.
D.Amazon ECS with an Application Load Balancer and manual scaling.
AnswerA

An Application Load Balancer provides the single internet-facing endpoint and distributes traffic across ECS tasks in multiple Availability Zones, while target tracking on average CPU utilisation adjusts desired task count automatically. This combination directly satisfies the high availability, automatic scaling, and single endpoint constraints.

Why this answer

An Application Load Balancer (ALB) provides a single internet-facing endpoint and supports HTTP/HTTPS traffic, which is typical for containerized applications. ECS Service Auto Scaling with a target tracking policy based on average CPU utilization allows the service to automatically adjust the desired count of tasks to maintain a specified CPU utilization target, ensuring high availability and elasticity.

Exam trap

The trap here is that candidates often confuse step scaling with target tracking, assuming step scaling is required for CPU-based scaling, but target tracking is the simpler and more AWS-recommended approach for maintaining a specific utilization target.

How to eliminate wrong answers

Option B is wrong because a Network Load Balancer (NLB) operates at Layer 4 and does not support HTTP/HTTPS path-based routing or host-based routing, which are often needed for containerized applications; also, step scaling policies are less precise than target tracking for maintaining a specific CPU utilization metric. Option C is wrong because while it uses an ALB, step scaling policies are not the recommended approach for scaling based on CPU utilization—target tracking policies are simpler and more effective as they automatically adjust to maintain a target metric value. Option D is wrong because manual scaling does not provide automatic scaling based on CPU utilization, which is a requirement for the application to scale automatically.

294
MCQhard

A multinational corporation uses AWS Organizations to manage multiple accounts across different geographic regions. The company needs to ensure that all data residing in AWS accounts for a specific country remains within that country's boundaries. Which combination of AWS services and features should the company use to enforce this data residency requirement?

A.Use AWS PrivateLink and VPC endpoints to keep traffic within the country's region.
B.Use service control policies (SCPs) to deny actions in non-approved regions and AWS Config rules to audit compliance.
C.Use resource-based policies on all AWS resources to deny access from other regions.
D.Use AWS WAF and AWS Shield to protect data and enforce geographic restrictions.
AnswerB

SCPs deny API actions in non-approved regions, preventing data from being created or stored outside the country's boundary. AWS Config rules continuously audit resource placement for compliance. This combination enforces residency preventively and detectively, satisfying the geographic restriction requirement.

Why this answer

Service control policies (SCPs) in AWS Organizations allow you to centrally control the maximum available permissions for all accounts in the organization. By creating an SCP that explicitly denies all actions in non-approved regions, you can enforce that no resources can be created or modified outside the allowed region. AWS Config rules then provide ongoing compliance auditing by detecting and reporting any resources that violate the data residency policy, ensuring continuous enforcement and visibility.

Exam trap

The trap here is that candidates often confuse network-level controls (like PrivateLink or VPC endpoints) with governance-level controls (like SCPs), mistakenly believing that restricting network traffic is sufficient to enforce data residency, when in fact only SCPs can prevent resource creation in disallowed regions at the API level.

How to eliminate wrong answers

Option A is wrong because AWS PrivateLink and VPC endpoints keep network traffic within the AWS network and can restrict traffic to a specific region, but they do not prevent users or services from creating resources in other regions; they only control data plane traffic, not the control plane actions that create resources. Option C is wrong because resource-based policies (e.g., S3 bucket policies, IAM role trust policies) can restrict access based on source IP or VPC endpoint, but they cannot deny the creation of resources in other regions; they only control access to existing resources, not the provisioning of new ones. Option D is wrong because AWS WAF and AWS Shield are security services focused on protecting web applications from common exploits and DDoS attacks; they do not provide any mechanism to enforce geographic data residency or restrict resource creation to specific regions.

295
MCQmedium

A company is migrating a stateful application to AWS. The application runs on a single on-premises server and uses local storage for persistent data. The company wants to achieve high availability and scalability. Which migration approach should the company use?

A.Use multiple EC2 instances behind an Application Load Balancer with sticky sessions.
B.Lift and shift to a single Amazon EC2 instance with an EBS volume.
C.Refactor the application to store state in Amazon ElastiCache or Amazon DynamoDB.
D.Use an EC2 Auto Scaling group with lifecycle hooks to persist state to EBS snapshots.
AnswerC

Externalising session and persistent state into ElastiCache or DynamoDB removes the single-server dependency, letting the application tier scale horizontally behind a load balancer. This satisfies both the high-availability and scalability constraints that local storage on one server prevents.

Why this answer

The application is stateful and needs high availability and scalability. Refactoring to store state in managed services like Amazon ElastiCache or DynamoDB decouples state from compute, allowing compute to scale and be replaced without data loss. Option A is wrong: while an ALB with sticky sessions distributes traffic, it ties sessions to specific instances, making scaling and failover complex and not fully HA.

Option B is wrong: a single EC2 instance is a single point of failure and cannot scale. Option D is wrong: EBS snapshots are for backup/disaster recovery, not real-time HA or state persistence during scaling. Only option C properly addresses state management for HA and scalability.

296
MCQmedium

A company has a centralized network account that hosts a transit gateway with attachments to multiple VPCs in different accounts. The security team needs to ensure that all traffic between VPCs is inspected by a centralized NGFW appliance in the network account. What is the MOST efficient solution?

A.Use AWS PrivateLink to route traffic through the NGFW.
B.Create a transit gateway with a route table that includes a blackhole route for inter-VPC traffic, and attach an inspection VPC with the NGFW.
C.Establish VPC peering connections between all VPCs and route traffic through the inspection VPC.
D.Set up AWS Direct Connect between all VPCs and the inspection VPC.
AnswerB

This forces all inter-VPC traffic to go through the inspection VPC.

Why this answer

It uses a transit gateway with a centralized inspection VPC, which allows all inter-VPC traffic to be routed through the NGFW appliance. By attaching the inspection VPC to the transit gateway and configuring route tables with blackhole routes for direct inter-VPC traffic, traffic is forced to traverse the NGFW for inspection. This is the most efficient and scalable solution for centralized traffic inspection across multiple VPCs in different accounts.

Exam trap

The trap here is that candidates often assume VPC peering (Option C) can be used for transitive routing, but VPC peering does not support transitive routing, making it impossible to route traffic through an inspection VPC to other VPCs.

How to eliminate wrong answers

Option A is wrong because AWS PrivateLink is designed for private connectivity to services via Network Load Balancers, not for routing inter-VPC traffic through a centralized NGFW; it does not support transitive routing or traffic inspection between VPCs. Option C is wrong because VPC peering does not support transitive routing, so you cannot route traffic from one peered VPC through another VPC to reach a third VPC; this would require a full mesh of peering connections and complex route tables, which is inefficient and not scalable. Option D is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not a solution for routing traffic between VPCs; it does not provide inter-VPC routing capabilities and would add unnecessary cost and complexity.

297
Multi-Selecthard

A company runs a web application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer. The operations team notices that the ALB returns 503 errors during peak traffic. Which TWO actions should the solutions architect take to resolve this issue?

Select 2 answers
A.Increase the idle timeout on the ALB.
B.Enable ECS service Auto Scaling to automatically adjust the number of tasks.
C.Increase the deregistration delay on the target group.
D.Review the ECS service events for task failures or health check issues.
E.Increase the task memory allocation in the task definition.
AnswersB, D

ECS service Auto Scaling adds tasks when demand rises, so more targets register behind the ALB and absorb peak load. This directly addresses the 503s, which stem from insufficient healthy targets to serve requests, rather than from listener or health-check misconfiguration. Scaling task count restores capacity and keeps the target group populated.

Why this answer

Option B is correct because 503 errors from an ALB during peak traffic commonly indicate that the ECS service has insufficient healthy tasks to handle the load; enabling ECS service Auto Scaling (via Application Auto Scaling with target tracking on metrics like ALBRequestCountPerTarget or ECSServiceAverageCPUUtilization) allows the service to add tasks automatically to absorb the spike. Option D is correct because 503 responses can also stem from tasks failing to start, crashing, or failing ALB target group health checks; reviewing ECS service events surfaces messages such as 'service unable to place a task' or failed health checks, which is the essential diagnostic step to identify the root cause before remediation. Option A is not appropriate because the ALB idle timeout governs how long an idle connection is kept open, and increasing it does not address capacity shortages or unhealthy targets that produce 503s.

Option C is incorrect because the deregistration delay only controls how long the target group waits before completing deregistration of a draining target, which affects connection draining during scale-in or deployment, not peak-load 503 errors. Option E is incorrect because increasing task memory only helps if tasks are being killed due to out-of-memory conditions, and it does not scale capacity or diagnose the actual cause of the 503s.

Exam trap

The trap is choosing ALB-level timeout or deregistration settings for a 503 error, when 503s from an ALB almost always indicate a target health/capacity problem on the ECS side, not a load balancer configuration issue.

298
MCQeasy

A company is designing a highly available web application on AWS. The application consists of an Application Load Balancer (ALB) that distributes traffic to EC2 instances in an Auto Scaling group across multiple Availability Zones. The application state is stored in an Amazon ElastiCache for Redis cluster. The company wants to minimize downtime during patching of the Redis cluster. What should the company do?

A.Increase the Redis node type to handle the load and rely on the ElastiCache maintenance window.
B.Use a blue/green deployment strategy by creating a new Redis cluster and switching the application endpoint.
C.Deploy the Redis cluster with Multi-AZ and automatic failover enabled across two Availability Zones.
D.Deploy the Redis cluster as a single node in one Availability Zone and take regular snapshots.
AnswerC

Multi-AZ with automatic failover maintains a synchronous standby replica in a second Availability Zone, so Redis promotes the replica automatically when the primary is patched. This satisfies the requirement to minimise downtime during patching without manual intervention or data loss.

Why this answer

Deploying ElastiCache for Redis with Multi-AZ and automatic failover enabled ensures that if the primary node fails or requires patching, a read replica in a different Availability Zone is automatically promoted to primary, minimizing downtime. This aligns with the requirement for high availability during patching, as ElastiCache handles failover transparently without manual intervention.

Exam trap

The trap here is that candidates may confuse scaling (Option A) or manual migration strategies (Option B) with the native high-availability feature of ElastiCache Multi-AZ, which is specifically designed to handle patching and failures with minimal downtime.

How to eliminate wrong answers

Option A is wrong because increasing the node type only improves capacity and performance, not availability; it does not address downtime during patching, as the single node still experiences an outage during maintenance. Option B is wrong because a blue/green deployment for Redis would require manual endpoint switching and data synchronization, which is complex and introduces potential data loss or inconsistency; ElastiCache's built-in Multi-AZ failover is simpler and more reliable for patching. Option D is wrong because a single-node cluster in one Availability Zone has no redundancy; patching or any failure causes complete downtime, and snapshots only aid recovery, not high availability.

299
MCQeasy

A company has three EC2 instances as shown in the exhibit. The company wants to use an Application Load Balancer to distribute traffic across these instances with cross-zone load balancing enabled. How will the traffic be distributed?

A.Traffic is distributed evenly across the two availability zones.
B.Instances in us-east-1a receive 67% of traffic, us-east-1b receives 33%.
C.Each instance receives an equal share of traffic.
D.Traffic is sent to the instance with the least outstanding requests.
AnswerC

With cross-zone load balancing enabled, the load balancer node in each Availability Zone distributes requests evenly to all registered targets in every enabled AZ, so each of the three instances receives an equal one-third share of traffic.

Why this answer

With cross-zone load balancing enabled on an Application Load Balancer, traffic is distributed evenly across all registered targets regardless of the availability zone they reside in. Since there are three EC2 instances, each instance receives an equal share (33.3%) of the incoming traffic, ensuring balanced load across all instances.

Exam trap

The trap here is that candidates often confuse cross-zone load balancing with zone-level distribution, mistakenly thinking traffic is split by availability zone count rather than by individual instance count, or they incorrectly attribute the least outstanding requests algorithm to the Application Load Balancer.

How to eliminate wrong answers

Option A is wrong because cross-zone load balancing distributes traffic evenly across instances, not across availability zones; the ALB does not balance by zone when cross-zone is enabled. Option B is wrong because it incorrectly assumes a zone-based distribution proportional to instance count (2 instances in us-east-1a, 1 in us-east-1b), but cross-zone load balancing overrides zone-level weighting to give each instance an equal share. Option D is wrong because the Application Load Balancer uses a round-robin algorithm by default, not least outstanding requests; the least outstanding requests routing algorithm is used by the Network Load Balancer, not the ALB.

300
MCQhard

A security engineer created the S3 bucket policy shown in the exhibit. The policy is intended to allow the role MyAppRole to get objects only if they are encrypted with SSE-S3. However, the role is getting access denied errors when trying to get objects that are encrypted with SSE-S3. What is the most likely cause?

A.The Principal is incorrect; it should be the role name, not ARN.
B.The Resource ARN is incorrect; it should be 'arn:aws:s3:::my-bucket'.
C.The condition key is misspelled.
D.The condition key 's3:x-amz-server-side-encryption' checks the request header, not the object's encryption state.
AnswerD

The condition evaluates the request header, which may not be set when getting an already encrypted object.

Why this answer

The condition key `s3:x-amz-server-side-encryption` evaluates the `x-amz-server-side-encryption` request header sent by the client during the GET request, not the encryption state of the object stored in S3. Since the role is making GET requests without this header (or with a different value), the condition fails even though the object is encrypted with SSE-S3. To enforce that only objects encrypted with SSE-S3 can be retrieved, you must use a different approach, such as a bucket policy with `s3:ExistingObjectTag` or a pre-signed URL that includes the required header.

Exam trap

The trap here is that candidates assume `s3:x-amz-server-side-encryption` evaluates the object's stored encryption state, when in fact it only evaluates the request header, leading to a false sense of security and access denied errors when the header is missing.

How to eliminate wrong answers

Option A is wrong because the Principal field in an S3 bucket policy can accept an IAM role ARN (e.g., `arn:aws:iam::123456789012:role/MyAppRole`) and is syntactically correct; using the role name alone would be invalid. Option B is wrong because the Resource ARN `arn:aws:s3:::my-bucket/*` correctly specifies all objects within the bucket, and changing it to `arn:aws:s3:::my-bucket` would apply to the bucket itself, not its objects, which would not match the `s3:GetObject` action. Option C is wrong because the condition key `s3:x-amz-server-side-encryption` is spelled correctly; the issue is not a typo but a fundamental misunderstanding of what the key evaluates.

Page 3

Page 4 of 14

Page 5