Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 301–375

984 questions total · 14pages · All types, answers revealed

Page 4

Page 5 of 14

Page 6
301
Multi-Selecteasy

A company is designing a new web application that will be deployed on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be highly available and fault-tolerant across multiple Availability Zones. Which THREE actions should the company take to meet these requirements? (Choose three.)

Select 3 answers
A.Launch EC2 instances in an Auto Scaling group across multiple Availability Zones.
B.Use a larger EC2 instance type to handle failures.
C.Configure health checks on the ALB target group to automatically replace unhealthy instances.
D.Configure the ALB to route traffic to instances in multiple Availability Zones.
E.Use a single Availability Zone to reduce latency.
AnswersA, C, D

Launching EC2 instances in an Auto Scaling group across multiple Availability Zones satisfies the fault-tolerance requirement by distributing capacity so that an AZ failure does not take down the application. The Auto Scaling group also replaces unhealthy instances automatically, maintaining the desired capacity behind the ALB.

Why this answer

Option A is correct because an Auto Scaling group spanning multiple Availability Zones maintains capacity and automatically launches replacement instances when an AZ or instance fails, which is the foundation of high availability and fault tolerance. Option C is correct because ALB target group health checks continuously probe registered targets and, combined with the Auto Scaling group, cause unhealthy instances to be detected and replaced, restoring healthy capacity. Option D is correct because an Application Load Balancer is a regional, multi-AZ service that must have targets registered in multiple Availability Zones so it can route traffic away from a failed AZ and continue serving requests.

Option B is not correct because a larger instance type only increases the capacity of a single instance and does nothing to provide redundancy across Availability Zones or to recover from failures. Option E is not correct because confining the deployment to a single Availability Zone creates a single point of failure and directly violates the multi-AZ high availability and fault tolerance requirement.

Exam trap

The trap here is that candidates often confuse vertical scaling (larger instances) with horizontal scaling and fault tolerance, or mistakenly think that using a single Availability Zone can be compensated by other means, ignoring the fundamental requirement for multi-AZ deployment.

302
Multi-Selecthard

A company is designing a multi-account strategy for its development teams. Each team needs to have its own isolated environment with VPCs, subnets, and security groups. The company wants to centralize network administration and ensure that all VPCs use a common set of security rules. Which THREE steps should the company take? (Choose THREE.)

Select 3 answers
A.Allow each team to create their own VPCs and use VPC Peering to connect them.
B.Deploy a centralized inspection VPC with AWS Network Firewall and use Transit Gateway to route traffic.
C.Create a dedicated network account and use AWS Resource Access Manager to share subnets with other accounts.
D.Use AWS CloudFormation StackSets to deploy identical VPCs to each account.
E.Use AWS Firewall Manager to apply common security group rules across all accounts.
AnswersB, C, E

A centralised inspection VPC with AWS Network Firewall enforces one common rule set across every team's VPC, satisfying the requirement for shared security rules. Transit Gateway hubs the isolated VPCs together, letting traffic route through that inspection point while network administration stays centralised.

Why this answer

Option B is correct because a centralized inspection VPC with AWS Network Firewall, combined with AWS Transit Gateway for routing, provides centralized traffic inspection and a hub-and-spoke topology that enforces common security policy across all team VPCs. Option C is correct because a dedicated network account using AWS Resource Access Manager (RAM) to share subnets lets teams consume centrally managed VPC networking while keeping network administration centralized. Option E is correct because AWS Firewall Manager applies common security group rules (and other policies) across all accounts in AWS Organizations, ensuring uniform security rules.

Option A is not correct because VPC Peering is a point-to-point connection that does not scale for centralized administration or common security enforcement across many accounts. Option D is not correct because CloudFormation StackSets deploys identical VPCs per account, which duplicates network administration rather than centralizing it and does not enforce common security rules.

Exam trap

The trap here is that candidates may confuse AWS CloudFormation StackSets (which only automates resource deployment) with centralized security enforcement, overlooking the need for a hub-and-spoke architecture with a centralized inspection point like AWS Network Firewall and Transit Gateway.

303
MCQeasy

A company is migrating workloads to AWS using AWS Application Migration Service (AWS MGN). The source servers are running on VMware vSphere. After installing the AWS Replication Agent on the source servers, the migration waves are set up. However, during a test cutover, the test instance fails to launch with an error 'Insufficient IP address space in the target VPC'. What is the most likely cause?

A.The replication settings specify a subnet with an incorrect CIDR block
B.The IAM role for AWS MGN does not have permissions to create network interfaces
C.The target VPC subnet does not have enough available IP addresses
D.The AWS MGN service is not enabled in the target AWS Region
AnswerC

AWS MGN launches test and cutover instances into the target subnet, each consuming a free private IP address. The launch error explicitly reports insufficient IP address space, meaning the subnet's available address pool is exhausted rather than any agent or replication fault.

Why this answer

The error 'Insufficient IP address space in the target VPC' indicates that the subnet used for test instances does not have enough available IP addresses to launch the instance. AWS MGN allocates IP addresses from the specified subnet during instance launch. Option A is incorrect because a CIDR mismatch would cause a different error, typically related to subnet configuration.

Option B is incorrect because IAM permission issues would result in an access denied error, not an IP space error. Option D is incorrect because the service not being enabled would produce a different error (e.g., service not available). Therefore, the most likely cause is insufficient available IP addresses in the target VPC subnet.

304
MCQmedium

A company runs a steady-state HTTP API on a fleet of Amazon EC2 instances behind an Application Load Balancer. The operations team needs to reduce cost without degrading performance or availability. They observe that CPU utilization is consistently 8–12% and memory utilization is around 40%. The workload is stateless and can tolerate a brief instance restart during deployment. Which change should a solutions architect recommend to meet the cost-reduction goal?

A.Enable detailed CloudWatch monitoring at one-minute resolution and add a dashboard for CPU and memory metrics.
B.Migrate the workload to a smaller instance type and adjust the Auto Scaling group's desired capacity to match observed peak demand.
C.Purchase a 3-year All Upfront Compute Savings Plan covering the existing instance family and run the fleet unchanged.
D.Replace the Application Load Balancer with a Network Load Balancer and route traffic directly to the instances.
AnswerB

The workload is stateless and consistently underutilized, so right-sizing to a smaller instance type and calibrating desired capacity to actual peak demand removes idle compute. Because the fleet sits behind a load balancer and tolerates brief restarts, the resize can be performed with a launch template update and an instance refresh, preserving availability while lowering the hourly run rate.

Why this answer

The fleet is stateless, load balanced, and running far below capacity, which makes right-sizing the instance type and re-calibrating desired capacity the most direct lever for cost reduction. A launch template update combined with an instance refresh can roll the change out without downtime. Savings Plans and monitoring changes reduce or report cost but never eliminate the waste from consistently idle compute.

Exam trap

The trap here is assuming that a Savings Plan or Reserved Instance discount is the fastest path to lower cost, when it only discounts capacity the workload does not actually need.

305
MCQhard

A company is migrating a legacy PHP application running on a single on-premises server to AWS. The application stores session data locally on the server's filesystem. The company wants to achieve high availability and elasticity for the application on AWS. What should the company do to handle session state in the new architecture?

A.Configure an Application Load Balancer with sticky sessions enabled
B.Store session data in Amazon ElastiCache for Redis
C.Use Amazon EFS to share the session files across multiple EC2 instances
D.Refactor the application to use Amazon Cognito for session management
AnswerB

ElastiCache for Redis externalises session state from the instance filesystem into a shared, replicated in-memory store, so any Auto Scaling instance can serve any user's session. This satisfies the elasticity and high availability constraints that local filesystem storage cannot meet.

Why this answer

Using ElastiCache for session storage decouples session state from individual servers, allowing the application to scale horizontally. Sticky sessions with an ALB ties a user to a specific instance, which reduces availability if that instance fails. Storing sessions on EFS is possible but slower than ElastiCache.

Re-architecting to use Cognito is unnecessary for session state.

306
MCQeasy

A company runs a critical application on EC2 instances in an Auto Scaling group. They want to be notified immediately if any instance fails a status check. What is the simplest solution?

A.Configure an ELB health check and monitor the unhealthy host count.
B.Use AWS Systems Manager Automation to check instance status periodically.
C.Create a CloudWatch alarm on the StatusCheckFailed metric with an SNS action.
D.Enable AWS CloudTrail and create a metric filter for EC2 instance failures.
AnswerC

CloudWatch's StatusCheckFailed metric directly reports EC2 instance health, and an alarm on it triggers an SNS notification the moment a check fails. This satisfies the immediate-notification requirement with minimal configuration, avoiding custom scripts or Lambda polling. Auto Scaling group events alone would not surface individual instance status-check failures promptly.

Why this answer

CloudWatch can monitor the EC2 StatusCheckFailed metric and trigger an SNS notification when an instance fails a status check. This is the simplest solution because it uses built-in metrics and requires no custom scripting. Option A uses ELB health checks which monitor load balancer target health, not instance status checks.

Option B uses Systems Manager Automation which is not real-time. Option D uses CloudTrail which logs API calls, not status checks.

307
MCQmedium

A company runs a stateful web application on a single Amazon EC2 instance. The application writes data to a locally attached instance store volume. The company wants to improve the durability of the data without modifying the application. The data must survive an instance stop/start and be available if the instance is terminated and relaunched. What should a solutions architect recommend?

A.Enable termination protection on the EC2 instance.
B.Move the data to an Amazon EBS volume with the DeleteOnTermination flag set to false.
C.Create an Amazon Machine Image (AMI) of the instance after each data change.
D.Use an Auto Scaling group with a launch template that includes the instance store volume.
AnswerB

EBS volumes provide persistent block storage that is replicated within an Availability Zone. By setting DeleteOnTermination to false, the volume persists even if the instance is terminated. The volume can be reattached to a new instance. This ensures data durability across instance stop/start and termination, without application changes.

Why this answer

Amazon EBS volumes are durable, persistent block storage that can be detached from one instance and attached to another. Setting DeleteOnTermination to false ensures the volume remains after instance termination. The application can continue to write to the same mount point, so no code changes are needed.

This provides the required data durability across instance stop/start and termination.

Exam trap

The trap here is assuming that instance store data persists after a stop/start, when in fact instance store is ephemeral and data is lost on stop or termination.

308
MCQmedium

A company runs a production AWS Lambda function that processes orders. Recently, the function has been timing out occasionally. The function uses a VPC with a single private subnet and has a timeout of 30 seconds. What is the MOST likely cause of the timeout?

A.The function is experiencing cold starts due to high concurrency.
B.The function is hitting the maximum concurrent execution limit.
C.The function needs to be attached to a public subnet.
D.The function does not have a NAT gateway or VPC endpoints to access external resources.
AnswerD

A Lambda function in a private subnet has no route to the internet without a NAT gateway, and no path to AWS services without VPC endpoints. Calls to external order-processing resources therefore hang until the 30-second timeout expires, producing the intermittent failures described.

Why this answer

A Lambda function attached to a VPC with only a private subnet has no route to the internet unless a NAT gateway (for outbound internet) or VPC endpoints (for AWS services) are configured. If the function calls external resources or AWS APIs without these, the calls hang until the 30-second timeout. This is the most likely cause of intermittent timeouts in this scenario.

Exam trap

SAP-C02 often tests the misconception that Lambda functions in a VPC automatically have internet access — candidates forget that VPC attachment removes default internet connectivity and that NAT or VPC endpoints are required.

How to eliminate wrong answers

Option A is wrong because cold starts add latency but typically only a few hundred milliseconds to a few seconds, not 30-second timeouts, and they would not cause consistent timeouts. Option B is wrong because hitting the concurrency limit results in throttling errors (429) or invocation failures, not timeouts of the function's own execution. Option C is wrong because Lambda functions in a VPC do not need to be in a public subnet; they need a NAT gateway or VPC endpoints for outbound access, and placing them in a public subnet does not by itself grant internet access without an internet gateway route and public IP.

309
MCQmedium

A company runs a critical web application on a fleet of Amazon EC2 instances behind an Application Load Balancer (ALB). The operations team notices that during peak traffic, the ALB reports a high number of HTTP 5xx errors, and CloudWatch metrics show that the target group's HealthyHostCount drops significantly. The application logs indicate that the instances are running out of memory and becoming unresponsive. The company wants to improve the reliability of the application with minimal operational overhead. Which solution should a solutions architect recommend?

A.Increase the instance size of the EC2 instances in the Auto Scaling group to a larger memory-optimized instance type.
B.Create a scheduled scaling policy that increases the desired capacity of the Auto Scaling group during known peak hours.
C.Configure an Auto Scaling group with a target tracking scaling policy based on memory utilization, using the CloudWatch agent to publish memory metrics.
D.Enable ELB health checks and set a shorter health check interval so that unhealthy instances are replaced faster.
AnswerC

Publishing memory metrics via the CloudWatch agent and using a target tracking policy on memory utilization allows the Auto Scaling group to add instances when memory pressure rises, directly addressing the root cause of unresponsiveness. This approach is fully managed, requires no custom logic, and scales automatically, meeting the minimal operational overhead requirement.

Why this answer

The application becomes unresponsive due to memory exhaustion under peak load. A target tracking scaling policy based on memory utilization, fed by CloudWatch agent metrics, automatically adjusts capacity to maintain a target memory level. This directly addresses the root cause and is fully managed, requiring minimal operational effort.

Other options either do not scale dynamically or do not react to memory pressure.

Exam trap

The trap here is assuming that a larger instance type or scheduled scaling solves the problem, when the core issue is the lack of dynamic scaling based on the actual resource bottleneck.

310
MCQhard

A company is deploying a web application on AWS Elastic Beanstalk. The application must be accessible over HTTPS only and must automatically redirect HTTP requests to HTTPS. The SSL/TLS certificate is provided by AWS Certificate Manager (ACM). How should this be configured?

A.Use a NAT instance to perform SSL termination and redirect.
B.Install the certificate on each EC2 instance and configure the web server to redirect HTTP to HTTPS.
C.Configure the environment’s load balancer to listen on port 443 with the ACM certificate and port 80 with a redirect rule.
D.Deploy a CloudFront distribution with the ACM certificate and redirect HTTP to HTTPS at the distribution level.
AnswerC

An Application Load Balancer listener on port 443 with the ACM certificate terminates TLS, while a port 80 listener with a redirect rule sends HTTP clients to HTTPS. This satisfies the HTTPS-only requirement without modifying the application itself.

Why this answer

Elastic Beanstalk environments using a load balancer (ALB or CLB) can be configured to listen on port 443 with the ACM certificate for HTTPS termination, and simultaneously define a listener on port 80 with a redirect action that sends HTTP traffic to HTTPS. This is the simplest and most scalable approach, as it offloads SSL termination and redirection to the load balancer, eliminating the need to manage certificates or redirection logic on individual instances.

Exam trap

The trap here is that candidates often assume SSL termination must happen on the EC2 instances (Option B) or that a separate service like CloudFront (Option D) is required, when in fact the Elastic Beanstalk load balancer can natively handle both HTTPS termination and HTTP-to-HTTPS redirection with minimal configuration.

How to eliminate wrong answers

Option A is wrong because a NAT instance is used for outbound traffic from private subnets, not for SSL termination or HTTP-to-HTTPS redirection; it does not support load balancing or certificate management. Option B is wrong because installing the certificate on each EC2 instance and configuring the web server to redirect HTTP to HTTPS is inefficient, requires manual certificate renewal, and does not leverage Elastic Beanstalk's managed load balancer for centralized SSL termination. Option D is wrong because while CloudFront can redirect HTTP to HTTPS, it adds unnecessary complexity and cost for a simple single-region web app; the question specifically asks about configuring the Elastic Beanstalk environment, not an external CDN.

311
MCQeasy

A company is modernizing a legacy application by breaking it into microservices. The application has a complex set of dependencies and requires gradual migration. Which design pattern should the company use?

A.Blue/Green deployment pattern
B.Saga pattern
C.Strangler Fig pattern
D.Circuit Breaker pattern
AnswerC

The Strangler Fig pattern incrementally replaces legacy functionality by routing specific requests to new microservices while the monolith continues serving the remainder. This directly satisfies the stem's gradual migration requirement, letting the company peel off dependencies piecemeal rather than rewriting everything at once, and it accommodates the complex dependency web without a risky big-bang cutover.

Why this answer

(Strangler Fig pattern) because it allows incremental replacement of legacy system functionality with microservices, enabling gradual migration despite complex dependencies. Option A (Blue/Green deployment) is a deployment strategy, not a migration pattern. Option B (Saga pattern) is for managing distributed transactions, not incremental replacement.

Option D (Circuit Breaker) is a fault-tolerance pattern.

312
MCQhard

A company runs a critical database on an RDS for MySQL Multi-AZ DB instance. The database is experiencing high read latency. The application is read-heavy and uses many complex joins. The company needs to improve read performance with minimal application changes. Which solution is MOST appropriate?

A.Migrate the database to Amazon DynamoDB Global Tables.
B.Create one or more RDS read replicas and direct read queries to the replica endpoint.
C.Implement Amazon ElastiCache in front of the database to cache query results.
D.Increase the DB instance class to a larger size with more vCPUs.
AnswerB

Read replicas offload read traffic from the primary via MySQL's asynchronous replication, and the application only needs its read connection string repointed to the replica endpoint. This satisfies the minimal-application-change constraint while relieving the primary of complex join reads.

Why this answer

RDS read replicas offload read traffic from the primary instance by asynchronously replicating data, and the application only needs to change its read connection string to point at the replica endpoint — a minimal-change solution. This directly addresses read-heavy workloads with complex joins because the replica runs the same MySQL engine and can execute the same queries. It also preserves the existing Multi-AZ failover posture for the primary.

Exam trap

SAP-C02 often tests whether candidates over-engineer with caching or NoSQL when a simpler managed feature (read replicas) solves the problem — the trap is picking ElastiCache or DynamoDB because they sound more 'scalable' despite requiring significant application changes.

How to eliminate wrong answers

Option A is wrong because DynamoDB is a NoSQL key-value/document store that does not support complex SQL joins, and migrating would require a full application rewrite — the opposite of 'minimal application changes.' Option C is wrong because ElastiCache caches query results but does not help with complex joins that vary by parameters, and it introduces cache invalidation complexity plus application code changes. Option D is wrong because scaling up the primary instance increases both read and write capacity but does not isolate read traffic — it is more expensive and does not scale reads horizontally, and it still leaves the primary handling all read load.

313
MCQeasy

A company is migrating a critical application to AWS and needs to ensure business continuity during the migration. The application must remain available with minimal downtime. Which AWS service should be used to replicate data continuously?

A.AWS Direct Connect
B.AWS Database Migration Service (DMS) with ongoing replication
C.Amazon S3 Transfer Acceleration
D.AWS Snowball Edge
AnswerB

AWS DMS with ongoing replication continuously captures changes from the source database and applies them to the target, keeping both in sync until cutover. This satisfies the minimal-downtime constraint, as the application stays live on the source while replication runs, allowing a short, controlled switchover rather than a lengthy outage.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication (Option B) provides continuous, near-real-time data replication from source to target, enabling minimal-downtime cutover during a migration. It supports homogeneous and heterogeneous migrations and keeps the target in sync until the application is switched over, which is exactly what business continuity during migration requires.

Exam trap

The trap is confusing network-acceleration or bulk-transfer services (Direct Connect, Transfer Acceleration, Snowball) with a true continuous data replication service (DMS with ongoing replication) that supports minimal-downtime cutover.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection between on-premises and AWS; it improves bandwidth and latency but does not replicate data continuously by itself. Option C is wrong because S3 Transfer Acceleration speeds up uploads to S3 using edge locations; it is not a continuous replication service for databases or applications. Option D is wrong because Snowball Edge is a physical data-transfer appliance for bulk offline migration; it is not continuous replication and introduces shipping delays, which conflicts with minimal downtime.

314
MCQeasy

A company is designing a new internal web application for its employees. The application must be accessible only from the corporate network, which connects to AWS via an AWS Site-to-Site VPN. The company wants to use an Application Load Balancer (ALB) to distribute traffic to EC2 instances. The solution must ensure that the ALB is not accessible from the internet. Which configuration should be used?

A.Create an internet-facing ALB in a private subnet and attach a network ACL that denies all traffic except the corporate CIDR.
B.Create an internal ALB in a private subnet and attach a security group that allows traffic from the corporate network CIDR.
C.Create an internet-facing ALB in a public subnet and attach a security group that allows only the corporate network CIDR.
D.Create an internal ALB in a public subnet and attach a security group that allows only the corporate network CIDR.
AnswerB

An internal ALB has only private IP addresses and its DNS name resolves to private IPs, so it is not reachable from the internet. Placing it in a private subnet and allowing the corporate CIDR via security group ensures that only traffic from the VPN can reach the load balancer, meeting the requirement for internal-only access.

Why this answer

The requirement is for an ALB that is not accessible from the internet but is reachable from the corporate network over VPN. An internal ALB provides a private DNS name and private IP addresses, ensuring no internet exposure. Placing it in a private subnet and using a security group to allow only the corporate CIDR restricts access to the intended source.

This combination satisfies the security and accessibility requirements.

Exam trap

The trap here is assuming that security groups alone can make an internet-facing ALB private, when the ALB's scheme itself determines internet reachability.

315
MCQhard

A company is designing a new multi-region application that requires a global database with low-latency reads and writes. The application must be able to survive a regional outage. Which database solution should they choose?

A.Amazon RDS Multi-AZ
B.Amazon ElastiCache for Redis global datastore
C.Amazon DynamoDB global tables
D.Amazon Aurora Global Database
AnswerC

Amazon DynamoDB global tables provide active-active replication across chosen Regions, delivering single-digit-millisecond reads and writes locally while surviving a full regional outage. This satisfies the stem's dual constraints: low-latency access in every Region and continued operation when one Region fails, without manual failover intervention.

Why this answer

Amazon DynamoDB global tables provide a fully managed, multi-region, multi-primary database that delivers low-latency reads and writes globally. The service replicates data across multiple AWS Regions automatically, allowing writes to be performed in any region with conflict resolution. In the event of a regional outage, traffic can be directed to another region, ensuring high availability.

In contrast, Amazon Aurora Global Database has a single primary region for writes, so writes are not low-latency across regions.

Exam trap

Candidates often choose Aurora Global Database because it supports global reads and regional failover, but they overlook that the requirement for low-latency writes globally is better met by DynamoDB global tables' active-active model.

How to eliminate wrong answers

Option A is wrong because Amazon RDS Multi-AZ provides high availability within a single region by synchronously replicating to a standby in a different Availability Zone, but it does not support cross-region failover or global low-latency writes. Option B is wrong because Amazon ElastiCache for Redis global datastore is a caching layer, not a durable database; it provides cross-region replication for cached data but does not offer persistent storage or transactional write guarantees required for a primary database. Option C is wrong because Amazon DynamoDB global tables replicate data across regions for low-latency reads and writes, but they are eventually consistent for writes (last-writer-wins) and do not support the strong consistency and cross-region failover semantics that Aurora Global Database provides for relational workloads; the question does not specify a NoSQL requirement, and DynamoDB global tables are not the best fit for a relational database pattern.

316
Multi-Selecteasy

A company is migrating its on-premises file server to AWS. The file server contains 5 TB of data and is accessed by hundreds of users. The company wants a fully managed file storage solution that supports SMB protocol. Which AWS service should the architect consider?

Select 1 answer
A.Amazon FSx for Windows File Server
B.Amazon FSx for Lustre
C.AWS Storage Gateway File Gateway
D.Amazon S3
E.Amazon Elastic File System (Amazon EFS)
AnswersA

Amazon FSx for Windows File Server natively supports the SMB protocol and is fully managed, satisfying both constraints in the stem. It integrates with Microsoft Entra ID for access control and provides Windows ACLs, making it the appropriate fit for migrating a 5 TB on-premises file server accessed by hundreds of users.

Why this answer

Amazon FSx for Windows File Server is a fully managed file storage service that supports the SMB protocol and is designed for Windows workloads. It integrates with Active Directory and provides features like DFS, shadow copies, and Windows ACLs, making it the correct choice for migrating an on-premises Windows file server.

Exam trap

SAP-C02 often tests the distinction between SMB and NFS support across AWS storage services, causing candidates to select EFS (NFS) or S3 (object) for a Windows SMB requirement.

317
Multi-Selecthard

A company is migrating a legacy Java application to AWS. The application currently runs on a single on-premises server and uses a MySQL database. The company wants to modernize the application by decoupling components and improving scalability. Which THREE steps should the architect include in the migration plan?

Select 3 answers
A.Rewrite the application to use a NoSQL database in a single migration step
B.Place an Application Load Balancer in front of the application
C.Refactor the application into microservices and deploy on Amazon ECS with Fargate
D.Deploy the application on a single larger EC2 instance
E.Migrate the database to Amazon RDS for MySQL
AnswersB, C, E

An Application Load Balancer distributes HTTP/HTTPS traffic across multiple targets, directly satisfying the decoupling and scalability goals. It enables horizontal scaling by routing to an Auto Scaling group, removing the single-server bottleneck, and performs health checks to route around failed instances, which the legacy on-premises deployment could not achieve.

Why this answer

Option B is correct because placing an Application Load Balancer (ALB) in front of the application enables horizontal scaling, health checks, and distribution of traffic across multiple targets, which directly supports the goal of improving scalability and decoupling the entry point from the compute layer. Option C is correct because refactoring the monolith into microservices deployed on Amazon ECS with Fargate decouples components, allows independent scaling per service, and removes server management overhead, aligning with the modernization objective. Option E is correct because migrating the MySQL database to Amazon RDS for MySQL preserves compatibility with the existing relational schema while offloading patching, backups, and Multi-AZ high availability to AWS, improving scalability and resilience.

Option A does not belong because rewriting to a NoSQL database in a single migration step is risky, unnecessary for a MySQL-based app, and contradicts an incremental modernization approach. Option D does not belong because deploying on a single larger EC2 instance is vertical scaling that keeps the application monolithic and does not decouple components or improve scalability.

Exam trap

SAP-C02 often tests whether candidates recognize that modernization should be incremental and decoupled — options that propose a single big-bang rewrite or vertical scaling are almost always distractors.

318
MCQeasy

A company uses AWS CloudFormation to deploy infrastructure. A Solutions Architect needs to update a stack that includes an RDS DB instance. The update requires modifying the DB instance's storage type from gp2 to io1. What change should be made to the CloudFormation template to minimize downtime?

A.Modify the StorageType property in the CloudFormation template and perform a stack update.
B.Add an UpdateReplacePolicy attribute to the RDS resource.
C.Create a new stack with the updated storage type and migrate data.
D.Set the DeletionPolicy to Retain for the RDS resource.
AnswerA

Changing StorageType from gp2 to io1 is a supported modification that can be done without replacement, minimizing downtime.

Why this answer

Modifying the StorageType property of an RDS DB instance (e.g., from gp2 to io1) can be done without replacing the resource. When the CloudFormation stack is updated with this change, AWS performs an in-place modification that typically causes only a brief downtime (a few minutes). This is the standard approach to minimize downtime.

Option B is incorrect because UpdateReplacePolicy is not a valid CloudFormation attribute; the correct attribute is UpdatePolicy, but it does not apply to RDS storage type changes. Option C is incorrect because creating a new stack and migrating data would cause significantly more downtime and effort. Option D is incorrect because DeletionPolicy controls what happens when a resource is deleted from the stack, not during an update.

319
Multi-Selecthard

A company is designing a new disaster recovery solution for a critical application running on Amazon EC2. They need to replicate data across AWS Regions with a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. Which THREE actions should they take to meet these objectives?

Select 3 answers
A.Manually create and copy AMIs to the secondary region weekly
B.Create a CloudFormation template to provision the infrastructure in the secondary region
C.Use AWS Backup to automate cross-region EBS snapshot copies
D.Enable cross-region replication on the Amazon S3 buckets containing application data
E.Configure the EC2 instances in a Multi-AZ Auto Scaling group
AnswersB, C, D

CloudFormation allows rapid deployment of infrastructure in the DR region.

Why this answer

AWS CloudFormation templates enable infrastructure-as-code, allowing rapid and consistent provisioning of the secondary region environment. This automation is essential to meet the 1-hour RTO, as it eliminates manual setup and reduces recovery time to minutes by deploying pre-defined stacks.

Exam trap

The trap here is that candidates often confuse Multi-AZ (which provides high availability within a single Region) with cross-region disaster recovery, leading them to incorrectly select Option E despite it not addressing regional isolation.

320
MCQmedium

A company manages multiple AWS accounts using AWS Organizations. The security team needs to enforce that all newly created accounts automatically have a specific set of security controls, including AWS Config rules and an AWS CloudTrail trail. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS Config conformance packs to deploy rules across accounts.
B.Use AWS Lambda functions triggered by AWS CloudTrail events to create a new stack in each new account.
C.Use AWS Organizations with AWS CloudFormation StackSets to automatically deploy the security stack to new accounts.
D.Use AWS Service Catalog to create a portfolio that includes the security stack and grant access to new accounts.
AnswerC

StackSets with service-managed permissions automatically deploys the CloudFormation template containing Config rules and the CloudTrail trail to each new account as it joins the organisation. This satisfies the automatic enforcement requirement with minimal ongoing manual effort.

Why this answer

AWS Organizations integrates directly with AWS CloudFormation StackSets to automatically deploy stacks across accounts in an organization. By configuring StackSets with automatic deployment enabled, any new account added to the organization will automatically receive the specified security stack (including AWS Config rules and CloudTrail trail) without any manual intervention or additional orchestration. This approach minimizes operational overhead by leveraging native AWS automation.

Exam trap

The trap here is that candidates often confuse AWS Config conformance packs (which only handle Config rules) with the broader infrastructure deployment capability of CloudFormation StackSets, leading them to choose Option A even though it cannot deploy CloudTrail trails.

How to eliminate wrong answers

Option A is wrong because AWS Config conformance packs only deploy AWS Config rules and remediation actions, but they cannot deploy an AWS CloudTrail trail, which is a separate service requiring a stack or custom resource. Option B is wrong because using Lambda functions triggered by CloudTrail events to create stacks introduces additional complexity, latency, and potential failure points compared to the native StackSets automatic deployment feature; it also requires managing Lambda code, IAM roles, and event rules. Option D is wrong because AWS Service Catalog portfolios require users to manually launch products from the portfolio; they do not automatically deploy stacks to new accounts, so this would not meet the requirement for automatic enforcement.

321
MCQeasy

A startup runs a stateless REST API on a fleet of Amazon EC2 instances in an Auto Scaling group. The API stores session tokens in a local in-memory cache on each instance. During a scaling event, users are randomly logged out because their session token is not present on the new instance that serves their request. The team wants sessions to survive instance replacement and scale-out without changing the API code significantly. Which change should the solutions architect recommend?

A.Increase the Auto Scaling group's minimum capacity so instances are not replaced during traffic spikes.
B.Move session state to an Amazon ElastiCache for Redis cluster and have the API read and write tokens there.
C.Store session tokens in an Amazon S3 bucket and have each instance read the token on every request.
D.Enable sticky sessions on the Application Load Balancer target group so each user is always routed to the same instance.
AnswerB

ElastiCache for Redis provides a shared, highly available session store that all instances can access, so sessions survive instance replacement and scale-out. The API change is limited to replacing the local cache client with a Redis client. This directly removes the dependency on instance-local memory and supports horizontal scaling.

Why this answer

Session state stored in instance memory cannot survive scale-out or instance replacement. Moving tokens to ElastiCache for Redis gives all instances a shared, low-latency store, so any instance can validate a session. The API change is minimal because only the cache client is swapped, and the fleet becomes truly stateless.

Exam trap

The trap here is relying on load balancer stickiness to preserve sessions, when stickiness only pins a user to an instance and does not survive that instance being replaced.

322
MCQhard

A financial services company is designing a new multi-account landing zone. A central security team must be able to audit all API activity across every account, and each business unit must be prevented from disabling the audit trail. The company uses AWS Organizations with all features enabled. The solutions architect needs a solution that captures management events from all accounts in one place and enforces immutability of the logs. Which combination of actions should the architect take?

A.Create an individual trail in each account and configure each trail to deliver to a shared S3 bucket; use AWS Config rules to detect deletion of the trails.
B.Use AWS Control Tower to create a landing zone and enable the AWS CloudTrail configuration in the security OU; rely on the default CloudTrail trail created by Control Tower for audit.
C.Create an organization trail in AWS CloudTrail that applies to all accounts, deliver logs to a central S3 bucket, and apply an S3 bucket policy with a Deny for s3:DeleteObject and s3:PutBucketPolicy to all principals except the security account.
D.Enable AWS CloudTrail Lake in the management account and configure event data stores for each member account; use IAM policies to restrict access to the event data stores.
AnswerC

An organization trail automatically applies to every account in AWS Organizations, including new accounts, and delivers events to a central bucket. Combining it with a bucket policy that denies deletion and policy changes to non-security principals enforces immutability. This directly meets the audit and tamper-prevention requirements with minimal per-account configuration.

Why this answer

An organization trail in CloudTrail applies automatically to all accounts in AWS Organizations and delivers management events to a central S3 bucket. Adding a bucket policy that denies deletion and policy modification to all principals except the security account prevents business units from tampering with the audit logs, satisfying both centralization and immutability requirements.

Exam trap

The trap here is assuming that AWS Config or Control Tower alone prevents trail tampering, when preventive enforcement requires an explicit S3 bucket policy deny.

323
MCQmedium

A company manages multiple AWS accounts and wants to centralize billing and cost tracking. They have enabled AWS Organizations and consolidated billing. Which additional step should they take to gain granular visibility into costs per department?

A.Enable AWS Cost Explorer and use default groupings
B.Create AWS Budgets for each department
C.Implement cost allocation tags for resources and use AWS Cost Explorer to filter by tags
D.Use the consolidated billing feature to view costs per account
AnswerC

Cost allocation tags attach department metadata to resources, letting AWS Cost Explorer group and filter spend by that dimension. This satisfies the granular per-department visibility requirement, which consolidated billing alone cannot provide, since it aggregates charges at the account level rather than by organisational unit.

Why this answer

Cost allocation tags allow you to tag AWS resources with department-specific metadata (e.g., 'Department: Engineering'). Once enabled and activated in the Billing and Cost Management console, AWS Cost Explorer can filter and group costs by these tags, providing granular visibility into per-department spending across multiple accounts in an AWS Organization. This approach directly addresses the need for department-level cost tracking beyond the account-level view provided by consolidated billing.

Exam trap

The trap here is that candidates often confuse the account-level aggregation of consolidated billing (Option D) with the resource-level granularity needed for department tracking, or they assume AWS Budgets (Option B) provide visibility rather than just alerts.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer's default groupings (e.g., by service or linked account) do not provide department-level granularity unless custom tags or cost categories are used; relying on default groupings alone cannot break down costs by department. Option B is wrong because AWS Budgets are used to set spending thresholds and send alerts, not to provide granular visibility into historical or current cost breakdowns by department; they are a cost control mechanism, not a reporting or analysis tool. Option D is wrong because the consolidated billing feature aggregates costs at the account level, not at the department level; it cannot distinguish costs for resources within a single account that belong to different departments.

324
MCQmedium

A company runs a high-traffic web application on physical servers in its own data center. The servers use a proprietary TCP-based protocol on port 9000 that cannot be changed, and the application stores session data in local memory. The company wants to migrate the application to AWS with minimal code changes while enabling horizontal scaling and high availability. Which combination of AWS services should a solutions architect recommend to meet these requirements?

A.Use an Application Load Balancer with sticky sessions enabled, and store session data in Amazon ElastiCache for Redis.
B.Use a Network Load Balancer with a UDP listener on port 9000, and store session data in Amazon ElastiCache for Memcached.
C.Use an Application Load Balancer with a TCP listener on port 9000, and store session data in Amazon DynamoDB.
D.Use a Network Load Balancer with a TCP listener on port 9000, and store session data in Amazon ElastiCache for Redis.
AnswerD

A Network Load Balancer operates at Layer 4 and can forward TCP traffic on any port, including the proprietary protocol on port 9000, without requiring code changes. Storing session data in ElastiCache for Redis externalizes session state, enabling horizontal scaling and high availability. This combination meets all requirements with minimal application modification.

Why this answer

The proprietary TCP protocol on port 9000 requires a Layer 4 load balancer. A Network Load Balancer supports TCP listeners on any port, preserving the protocol without code changes. Externalizing session state to ElastiCache for Redis removes the dependency on local memory, enabling horizontal scaling.

This combination provides high availability and minimal modification.

Exam trap

The trap here is assuming that an Application Load Balancer can handle any TCP port, when it only supports HTTP/HTTPS/gRPC and would fail to forward the custom protocol.

325
MCQhard

A healthcare company has 200 AWS accounts in AWS Organizations. The security team wants to prevent any principal in member accounts from disabling AWS CloudTrail or deleting the organization trail, even if they have administrator permissions in their own account. The solution must be centrally managed and apply to all existing and future accounts. Which approach should a solutions architect recommend?

A.Create an IAM permission boundary in each member account that denies CloudTrail management actions for all IAM principals.
B.Use AWS CloudTrail Lake in the management account and grant member accounts read-only access to the event data store.
C.Create an organization trail in the management account and attach a service control policy that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail to all member accounts.
D.Enable CloudTrail in each member account and use AWS Config rules to detect and remediate trails that are stopped or deleted.
AnswerC

An organization trail applies to all accounts in the organization and cannot be modified by member accounts. Pairing it with an SCP that denies the destructive CloudTrail actions ensures that even account administrators cannot stop or delete logging. This combination provides centralized, tamper-resistant logging across current and future accounts.

Why this answer

The most reliable way to prevent CloudTrail tampering across an organization is to use an organization trail, which member accounts cannot alter, combined with an SCP that denies the specific destructive CloudTrail API actions. This is preventive and applies uniformly to all accounts. Detective Config rules, CloudTrail Lake analytics, and per-account permission boundaries do not provide the same centralized prevention.

Exam trap

The trap here is choosing a detective control such as AWS Config remediation when the requirement explicitly asks to prevent administrators from disabling logging, which demands a preventive control like an SCP plus an organization trail.

326
MCQmedium

A multinational corporation is migrating its on-premises Active Directory (AD) to AWS Managed Microsoft AD. The company has a hub-and-spoke VPC topology with a central transit gateway. The AD domain controllers must be deployed in two different AWS Regions for disaster recovery. The corporate security policy requires that all AD traffic between Regions must traverse the transit gateway and be inspected by a third-party firewall appliance deployed in the inspection VPC. Which architecture meets these requirements?

A.Deploy AD in two Regions and use a VPN connection between the VPCs to replicate data.
B.Deploy a single AD domain in one Region and use AD replication over a VPC peering connection to a second Region.
C.Deploy AD in two Regions, attach both VPCs to the transit gateway, and enable cross-Region transit gateway peering. Use route tables to direct AD traffic through the inspection VPC.
D.Deploy AD in two Regions, attach both VPCs to a transit gateway in the primary Region, and use a transit gateway inter-Region peering attachment. Configure route tables to force traffic through the inspection VPC in the primary Region.
AnswerC

Cross-Region transit gateway peering carries AD replication traffic between the two Regional directories, while transit gateway route tables in each Region force that traffic through the inspection VPC attachment, satisfying the security policy's inspection mandate. AWS Managed Microsoft AD domain controllers stay Regional, so DR is met without exposing replication to the public internet.

Why this answer

It uses cross-Region transit gateway peering, which allows VPCs in different Regions to communicate through their respective transit gateways. By attaching both VPCs to their local transit gateways and peering those gateways, you can configure route tables to force AD traffic through the inspection VPC in one Region, satisfying the firewall inspection requirement. Option D is incorrect because you cannot attach a VPC in a secondary Region to a transit gateway in the primary Region; transit gateway attachments are regional.

Exam trap

The trap is that candidates may think you can attach VPCs from different Regions to a single transit gateway, but in reality, transit gateway attachments are regional. Cross-Region connectivity requires transit gateway peering.

How to eliminate wrong answers

Option A is wrong because a VPN connection between VPCs does not provide the required transit gateway routing or inspection VPC integration; it also introduces additional latency and complexity without meeting the inspection requirement. Option B is wrong because a single AD domain with VPC peering does not support cross-Region AD replication natively (AD replication requires direct connectivity or VPN, and VPC peering alone cannot enforce inspection by a third-party firewall in a separate inspection VPC). Option C is wrong because attaching both VPCs to the transit gateway and enabling cross-Region transit gateway peering does not force AD traffic through the inspection VPC; route tables must be explicitly configured to direct traffic through the inspection VPC, and the description in C lacks the necessary detail about routing through the inspection VPC in the primary Region.

327
Multi-Selectmedium

A company uses AWS Organizations and wants to centrally manage Amazon GuardDuty across all accounts. Which TWO steps are required to enable GuardDuty in all accounts from a single management account?

Select 2 answers
A.Use AWS CloudFormation StackSets to deploy GuardDuty in each account
B.Enable GuardDuty manually in each member account by logging into each account
C.Create a service control policy to force GuardDuty to be enabled
D.Use the GuardDuty delegated administrator account to enable GuardDuty for all accounts in the organization
E.Designate a member account as the GuardDuty delegated administrator
AnswersD, E

Designating a delegated administrator in GuardDuty lets that account enable and manage the service across every member account via AWS Organizations integration, satisfying the centralised single-account management constraint. The management account itself cannot serve as the GuardDuty delegated administrator, so a member account must be registered first.

Why this answer

The correct answers are E and D. First, you must designate a member account as the GuardDuty delegated administrator (option E) using the Organizations management account, which grants that account administrative authority over GuardDuty for the entire organization. Then, from that delegated administrator account, you enable GuardDuty for all accounts in the organization (option D), which automatically enables GuardDuty in every existing and newly added member account.

Option A is incorrect because CloudFormation StackSets is not the mechanism GuardDuty uses for organization-wide enablement. Option B is incorrect because manual per-account enablement defeats the purpose of centralized management. Option C is incorrect because service control policies restrict permissions and cannot force a service like GuardDuty to be enabled.

Exam trap

The trap here is that candidates often confuse service control policies (SCPs) with proactive enforcement, but SCPs only restrict permissions and cannot automatically enable a service; they also overlook that CloudFormation StackSets cannot enable a service like GuardDuty, which requires a specific API action rather than resource deployment.

328
MCQeasy

A company has a multi-account AWS environment managed with AWS Organizations. The finance team wants to consolidate billing and receive a single bill for all accounts, while still allowing each account to have its own service usage and cost allocation tags. The company also wants to apply volume discounts across accounts. Which AWS Organizations feature should the solutions architect enable?

A.Enable consolidated billing for the organization so that all accounts are billed through the management account and share volume pricing benefits.
B.Create a separate AWS account for each business unit and use AWS Cost Explorer to manually combine the bills each month.
C.Enable AWS Budgets in each account and configure budget alerts to be sent to the finance team for a unified view.
D.Use AWS Cost and Usage Reports delivered to a central S3 bucket to generate a single invoice for all accounts.
AnswerA

Consolidated billing is an AWS Organizations feature that rolls all member account charges into a single bill paid by the management account. It also aggregates usage for volume discounts and Reserved Instance and Savings Plans sharing. This directly meets the requirements for a single bill, per-account usage tracking, and shared discounts.

Why this answer

Consolidated billing in AWS Organizations aggregates all member account charges into one bill paid by the management account. It also shares volume pricing, Reserved Instance, and Savings Plans benefits across accounts. This satisfies the requirements for a single bill, per-account usage visibility, and cross-account discounts with minimal effort.

Exam trap

The trap here is confusing cost visibility tools such as AWS Cost Explorer, AWS Budgets, or Cost and Usage Reports with consolidated billing, which is the Organizations feature that actually produces one bill and shares discounts.

329
Multi-Selectmedium

A company is managing multiple AWS accounts using AWS Organizations. They want to centralize the management of EC2 instances and enforce tagging standards across all accounts. Which TWO approaches should they use?

Select 2 answers
A.Use AWS CloudFormation StackSets to deploy AWS Config rules across all accounts to check for required tags.
B.Use AWS Service Catalog to enforce tagging on EC2 products.
C.Use AWS Resource Access Manager to share a tagging policy across accounts.
D.Apply a service control policy (SCP) that denies ec2:RunInstances if the required tags are not specified.
E.Use EC2 Auto Scaling lifecycle hooks to add tags automatically.
AnswersA, D

AWS Config rules deployed via CloudFormation StackSets provide continuous, account-wide tag compliance evaluation, satisfying the requirement to enforce tagging standards centrally. StackSets handle cross-account deployment through AWS Organizations, while Config detects non-compliant EC2 instances and can trigger remediation, giving the governance mechanism the scenario demands.

Why this answer

Option A is correct because CloudFormation StackSets can deploy AWS Config rules (e.g., required-tags) across all accounts in an AWS Organization from a single administrator account, providing centralized, continuous detection of non-compliant EC2 instances and their tags. Option D is correct because an SCP attached to the organization's root or OUs can enforce tagging standards preventively by denying ec2:RunInstances when the required tag keys/values are absent (using conditions such as aws:RequestTag and aws:TagKeys), blocking non-compliant launches across all member accounts. Option B is not correct because Service Catalog constraints (e.g., TagOptions) only apply to products launched through the catalog, not to all EC2 instances across accounts.

Option C is not correct because AWS Resource Access Manager shares resources such as subnets, Transit Gateways, and Route 53 Resolver rules, not tagging policies. Option E is not correct because Auto Scaling lifecycle hooks pause instances during launch/termination for custom actions and do not enforce or automatically add tags to meet organization-wide tagging standards.

Exam trap

The trap here is that candidates often confuse AWS Service Catalog's tagging enforcement as a global solution, not realizing it only applies to products launched through the catalog, not to direct EC2 API calls across accounts.

330
MCQmedium

A company is designing a new microservices architecture on AWS. Each service needs to store and retrieve small amounts of configuration data (under 10 KB per item) with low latency. The data is accessed frequently and must be highly available across multiple Availability Zones. Which AWS service should be used?

A.Amazon S3
B.Amazon ElastiCache for Memcached
C.Amazon RDS for MySQL
D.Amazon DynamoDB
AnswerD

DynamoDB stores items up to 400 KB, so sub-10 KB configuration data fits comfortably, and its multi-AZ replication delivers the required high availability. Provisioned throughput with single-digit millisecond latency suits frequent access, while key-value lookups avoid the overhead of relational joins or filesystem semantics.

Why this answer

Amazon DynamoDB is the correct choice because it is a fully managed NoSQL key-value and document database that delivers single-digit millisecond latency at any scale, making it ideal for frequently accessed configuration data under 10 KB. It provides built-in high availability and durability by automatically replicating data across three Availability Zones in an AWS Region, meeting the requirement for multi-AZ resilience without manual setup.

Exam trap

The trap here is that candidates often choose Amazon S3 for any 'storage' need without considering latency requirements, or they pick ElastiCache thinking it provides durable storage, when in fact DynamoDB is the only option that combines low latency, high availability across AZs, and native persistence for small configuration items.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service designed for larger objects (minimum 0 bytes, but optimal for >128 KB) and while it can store small items, its latency is higher (typically tens to hundreds of milliseconds) and it is not optimized for frequent, low-latency reads of sub-10 KB configuration data. Option B is wrong because Amazon ElastiCache for Memcached is an in-memory cache that does not provide native persistence or high availability across multiple Availability Zones without additional configuration (e.g., using a cluster with replication, which Memcached does not support natively); it is intended for caching, not as a durable data store for configuration. Option C is wrong because Amazon RDS for MySQL is a relational database that introduces overhead from SQL parsing, connection management, and schema design, and while it can be made multi-AZ, it is overkill for simple key-value configuration data and does not offer the single-digit millisecond latency of DynamoDB for this use case.

331
MCQmedium

A company uses AWS CloudTrail to log API activity. The compliance team requires that logs be stored for 7 years and be immediately accessible for the first 90 days, after which access can take up to 12 hours. Which storage solution meets these requirements cost-effectively?

A.Store logs in Amazon S3 Standard for 90 days, then transition to Amazon S3 Glacier for the remainder.
B.Store logs in Amazon S3 One Zone-Infrequent Access for 90 days, then delete.
C.Store logs in Amazon S3 Standard for 90 days, then transition to Amazon S3 Glacier Deep Archive.
D.Store logs in Amazon S3 Standard-Infrequent Access for 90 days, then transition to Amazon S3 Standard.
AnswerC

S3 Lifecycle transitions objects from S3 Standard to Glacier Deep Archive after 90 days, satisfying the immediate-access requirement for the first 90 days and the 12-hour retrieval tolerance thereafter. Deep Archive is the cheapest S3 class for 7-year retention, meeting the cost-effectiveness constraint.

Why this answer

S3 Standard provides immediate access for the first 90 days, and then transitioning to S3 Glacier Deep Archive (retrieval time up to 12 hours) meets the 7-year retention requirement at the lowest cost. Option A is wrong: while S3 Glacier can also provide retrieval within 12 hours (via its Bulk retrieval option), S3 Glacier Deep Archive is more cost-effective for long-term archival with comparable retrieval times. Option B is wrong: S3 One Zone-Infrequent Access is not durable enough for compliance (single Availability Zone) and deleting after 90 days does not satisfy the 7-year retention requirement.

Option D is wrong: S3 Standard-Infrequent Access is for infrequent access but transitioning to S3 Standard is more expensive, and the lifecycle policy does not achieve the 7-year retention.

Exam trap

The key trap is confusing the cost and retrieval time trade-offs between S3 Glacier and S3 Glacier Deep Archive. While both can achieve up to 12 hours retrieval (Glacier via Bulk, Deep Archive via Standard retrieval), Deep Archive is significantly cheaper for long-term storage, making it the most cost-effective choice when such retrieval times are acceptable.

332
MCQeasy

A company is migrating its on-premises VMware virtual machines to AWS. The company wants to use a lift-and-shift approach and minimize changes to the applications. Which AWS service should be used to automate the migration of these virtual machines?

A.AWS Migration Hub
B.AWS DataSync
C.AWS Application Migration Service (AWS MGN)
D.AWS Database Migration Service (AWS DMS)
AnswerC

AWS Application Migration Service (MGN) is designed for lift-and-shift migrations of physical, virtual, and cloud servers to AWS. It supports VMware vSphere environments and automates the replication and conversion of servers to run natively on AWS. It minimizes downtime and requires no changes to applications, making it the ideal choice for this scenario.

Why this answer

AWS Application Migration Service (MGN) is the correct choice because it automates the lift-and-shift migration of VMware virtual machines to AWS. It replicates servers continuously and launches them as EC2 instances, minimizing downtime and application changes. Other services like DMS, DataSync, and Migration Hub serve different purposes and do not handle server migration.

Exam trap

The trap here is confusing AWS Migration Hub, which only tracks migrations, with AWS Application Migration Service, which actually performs the migration.

333
Multi-Selectmedium

A media company is building a new video transcoding pipeline. Source files arrive in an Amazon S3 bucket, and a workflow must fan out to several processing steps, retry failed steps with backoff, and pause for manual approval before publishing. A solutions architect is evaluating AWS Step Functions. Which two statements are correct about using Step Functions for this design? (Choose two.)

Select 2 answers
A.Retries and backoff must be coded inside each Lambda function because Step Functions cannot define retry behavior at the state level.
B.Step Functions can invoke AWS Lambda functions but cannot call other AWS services directly, so every transcoding step must be wrapped in a Lambda function.
C.A Standard workflow can run for up to one year and supports exactly-once execution semantics, which suits long-running transcoding jobs and audit requirements.
D.An Express workflow can run for up to five minutes and provides at-least-once execution, making it suitable for high-volume, short-lived event processing.
E.Manual approval steps are implemented by polling a DynamoDB table in a loop until a reviewer updates a record, because Step Functions has no built-in callback mechanism.
AnswersC, D

Standard workflows are designed for durable, long-running processes and can execute for up to one year, with execution history retained so each state transition is recorded. They provide exactly-once semantics for state transitions, which is important for auditable approval steps and for jobs whose duration exceeds the five-minute limit of the other workflow type.

Why this answer

Standard workflows provide durable, exactly-once, up-to-one-year executions with recorded history, while Express workflows provide at-least-once, up-to-five-minute executions for high-volume short tasks. Choosing between them depends on job duration and the need for exactly-once semantics, and both types support state-level retry configuration and service integrations without Lambda wrappers.

Exam trap

The trap here is treating the two workflow types as interchangeable, when the duration limit and execution semantics differ in ways that decide the design.

334
MCQhard

A company is migrating a legacy monolithic application to AWS. The application stores session state locally on each server. The company wants to refactor the application to be stateless and deploy it across multiple Availability Zones for high availability. The application must handle sudden traffic spikes and maintain session persistence. Which solution should a solutions architect recommend?

A.Use Application Load Balancer with sticky sessions (session affinity) and store session state on each EC2 instance's local disk.
B.Store session state in an Amazon S3 bucket and have the application read and write session data for each request.
C.Store session state in an Amazon ElastiCache for Redis cluster with Multi-AZ enabled, and configure the application to use it.
D.Use Amazon DynamoDB with a global secondary index to store session state, and configure the application to use it.
AnswerC

ElastiCache for Redis with Multi-AZ provides a highly available, in-memory session store that is external to the application servers. This makes the application stateless and allows it to scale horizontally across AZs. Redis supports persistence and automatic failover, ensuring session data survives node failures. It is ideal for handling sudden traffic spikes due to its low latency and high throughput.

Why this answer

ElastiCache for Redis with Multi-AZ is the best choice because it provides a highly available, low-latency, in-memory session store that externalizes session state, making the application stateless. It scales to handle traffic spikes and ensures session persistence across AZs with automatic failover. Other options either keep the application stateful, introduce latency, or are not optimized for session management.

Exam trap

The trap here is thinking that sticky sessions solve the session state problem, but they actually prevent the application from becoming stateless and reduce availability.

335
MCQmedium

A company has multiple AWS accounts and wants to centrally manage VPC flow logs for all accounts. The flow logs should be sent to a central S3 bucket in the logging account. The solution must be automated for new accounts added to the organization. What should the team do?

A.Use AWS Config rules to detect missing flow logs and send alerts to the security team.
B.Use AWS CloudFormation StackSets to deploy a VPC flow log configuration to all accounts and regions, and configure the S3 bucket policy to allow cross-account delivery from all accounts.
C.Use an SCP to require that VPC flow logs be enabled.
D.Manually enable VPC flow logs in each account and region, and specify the central S3 bucket as the destination.
AnswerB

StackSets deploys the flow log configuration across every account and Region from one administration account, and automatically targets accounts newly added to the organisation. The central S3 bucket policy grants cross-account delivery, meeting the automation requirement without per-account manual setup.

Why this answer

AWS CloudFormation StackSets can deploy a VPC flow log configuration across multiple accounts and regions in an AWS Organization, and the central S3 bucket policy must allow cross-account delivery from all accounts. This approach automates the deployment for new accounts as they are added to the organization, meeting the requirement for centralized management and automation.

Exam trap

The trap here is that candidates may think SCPs can enforce resource configurations like enabling flow logs, but SCPs only control permissions and cannot create or configure resources; they must be combined with automation tools like StackSets or AWS Config rules with auto-remediation.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can detect missing flow logs and send alerts, but they do not automatically enable flow logs or deliver them to a central S3 bucket; they only provide compliance monitoring and notifications. Option C is wrong because Service Control Policies (SCPs) can restrict actions but cannot directly enable VPC flow logs or configure their delivery to a central S3 bucket; SCPs are for permission boundaries, not resource configuration. Option D is wrong because manually enabling flow logs in each account and region is not automated and does not scale for new accounts added to the organization, violating the automation requirement.

336
MCQmedium

A company uses Amazon CloudFront with an S3 origin to serve static content. They recently updated the content in S3, but users still see the old files. What is the MOST likely reason?

A.The CloudFront distribution's cache TTL is too long
B.S3 versioning is enabled and the objects are not updated
C.CloudFront is not configured to forward the Cache-Control header
D.S3 Transfer Acceleration is disabled
AnswerA

CloudFront serves objects from edge locations until the cached object's TTL expires, so an excessively long TTL means updated S3 content is not fetched. This satisfies the stem's scenario: users still receive stale files despite the origin being refreshed.

Why this answer

CloudFront caches objects at edge locations based on the cache TTL. If the TTL is set to a long duration, CloudFront continues to serve the cached old version even after the S3 origin is updated. The most likely reason users see old files is that the cached objects have not expired.

To resolve, you can invalidate the objects or use versioned filenames.

Exam trap

SAP-C02 often tests whether candidates incorrectly blame S3 versioning or missing header forwarding for stale CloudFront content, when the root cause is usually the cache TTL or lack of invalidation.

How to eliminate wrong answers

Option B is wrong because S3 versioning does not prevent CloudFront from serving the latest version; CloudFront fetches the current object version unless a specific version ID is requested. Option C is wrong because CloudFront does not need to forward the Cache-Control header to respect it; it reads the header from the origin response and caches accordingly. Option D is wrong because S3 Transfer Acceleration speeds up uploads to S3, not CloudFront cache updates, and has no effect on stale content.

337
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores user session data in a self-managed Redis cluster on a single EC2 instance. Users report being logged out intermittently, especially during peak traffic. The company wants to improve the reliability and scalability of session management with minimal application changes. Which solution should a solutions architect recommend?

A.Migrate the session store to Amazon ElastiCache for Redis with cluster mode enabled and Multi-AZ.
B.Configure the application to store session data in Amazon S3 and use S3 Transfer Acceleration.
C.Enable sticky sessions on the ALB and continue using the single Redis instance.
D.Replace the Redis session store with an Amazon DynamoDB table and use DAX for caching.
AnswerA

ElastiCache for Redis with cluster mode and Multi-AZ provides a highly available, scalable session store that can handle peak traffic and automatic failover. It is compatible with Redis, so minimal application changes are needed. This directly addresses the intermittent logouts caused by the single-instance Redis and improves reliability and scalability.

Why this answer

The single Redis instance is a bottleneck and single point of failure, causing intermittent logouts. Migrating to ElastiCache for Redis with cluster mode and Multi-AZ provides a scalable, highly available session store that is compatible with Redis, requiring minimal application changes. Sticky sessions or alternative stores either don't fix the root cause or demand significant rework.

Exam trap

The trap here is thinking that sticky sessions or a different database will solve session reliability, but the core issue is the single Redis instance's lack of high availability and scalability.

338
Multi-Selectmedium

A company is designing a centralized logging solution for multiple AWS accounts. The solution must meet compliance requirements that logs be immutable and stored for 7 years. Which THREE services should be combined to achieve this?

Select 3 answers
A.AWS Glue
B.S3 Object Lock
C.AWS CloudTrail
D.Amazon S3
E.Amazon Kinesis Data Streams
AnswersB, C, D

S3 Object Lock in compliance mode prevents any user, including the root account, from deleting or overwriting objects for a defined retention period. This directly satisfies the immutability requirement, and combined with lifecycle policies it enforces the seven-year retention window.

Why this answer

Amazon S3 (D) is the correct storage foundation because it provides durable, highly available object storage where the aggregated logs from all accounts can reside for the 7-year retention period. S3 Object Lock (B) is correct because it enforces WORM (write once, read many) immutability, using retention modes such as Compliance mode to prevent deletion or modification of log objects for the required duration. AWS CloudTrail (C) is correct because it captures API activity and account events across multiple AWS accounts, and with an organization trail it can deliver those logs centrally to the S3 bucket for compliance auditing.

AWS Glue (A) is a serverless ETL/catalog service used for data preparation and transformation, not for immutable log retention, so it does not satisfy the requirement. Amazon Kinesis Data Streams (E) is a real-time streaming ingestion service and does not itself provide immutable, 7-year storage, so it is not part of the required combination.

Exam trap

The trap here is that candidates may confuse Kinesis Data Streams as a storage service for logs, but it is a streaming ingestion layer with no built-in immutability or long-term retention, while Glue is mistakenly chosen for its data cataloging capabilities rather than for log storage.

339
MCQeasy

A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to prevent member accounts from disabling AWS CloudTrail or modifying its configuration. They also want to ensure that all CloudTrail logs are stored in a central S3 bucket in the management account. Which combination of actions should be taken?

A.Create an IAM policy in each member account that denies CloudTrail modification actions to all users, and enable CloudTrail in each account with a trail that delivers to a central S3 bucket.
B.Use AWS Config rules in each member account to detect and remediate any changes to CloudTrail configuration. Store logs in a central S3 bucket by configuring each account's trail to deliver to the bucket.
C.Enable AWS CloudTrail in the management account with organization trail, and use AWS Organizations to apply a tag policy that prevents member accounts from modifying CloudTrail.
D.Apply a service control policy (SCP) to all member accounts that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail. Configure CloudTrail in the management account to log all accounts and deliver to a central S3 bucket.
AnswerD

SCPs can deny specific CloudTrail actions in member accounts, preventing them from stopping or modifying trails. By configuring an organization trail in the management account, CloudTrail logs from all accounts are automatically delivered to a central S3 bucket. This meets the requirements for centralized logging and protection against tampering, with minimal operational overhead.

Why this answer

Service control policies (SCPs) in AWS Organizations can deny CloudTrail modification actions across member accounts, providing a preventive control. An organization trail created in the management account automatically logs activity in all accounts and delivers to a central S3 bucket. This combination ensures centralized, tamper-resistant logging without per-account configuration.

Exam trap

The trap here is assuming that AWS Config rules or IAM policies can prevent CloudTrail modifications, but only SCPs provide centralized, preventive control that member accounts cannot override.

340
Multi-Selectmedium

Which TWO actions should a company take to implement a least-privilege access model across multiple AWS accounts? (Choose TWO.)

Select 2 answers
A.Use IAM roles in each account with cross-account trust from a central identity provider, granting only required permissions.
B.Apply SCPs to deny high-risk actions across all accounts.
C.Generate long-term access keys for each user in the central account.
D.Share the root user credentials of each account with the central team.
E.Create IAM users in each account with full administrator access for all users.
AnswersA, B

Cross-account IAM roles with trust policies let identities federate from a central provider and assume only scoped permissions in each account, eliminating long-lived credentials. This directly enforces least privilege across accounts by granting the minimum required permissions per role.

Why this answer

Option A is correct because IAM roles with cross-account trust let users assume temporary credentials from a central identity provider (e.g., AWS IAM Identity Center or an external IdP via STS AssumeRole), so each account grants only the specific permissions the role needs, which is the essence of least privilege. Option B is correct because AWS Organizations service control policies (SCPs) set a permissions guardrail that denies high-risk actions (such as disabling CloudTrail or leaving the organization) across all member accounts, preventing privilege escalation even if an identity policy would otherwise allow it. Option C is wrong because generating long-term access keys for every user violates least privilege and key-rotation best practices; temporary credentials via roles are preferred.

Option D is wrong because sharing root user credentials is a severe security anti-pattern—root has unrestricted access and should be protected with MFA and never shared. Option E is wrong because creating IAM users with full administrator access in every account grants excessive permissions and directly contradicts a least-privilege model.

Exam trap

The trap here is that candidates often confuse SCPs with IAM permissions policies, thinking SCPs grant access rather than acting as a deny-only guardrail, or they mistakenly believe long-term access keys or shared root credentials are acceptable for cross-account access when they are explicitly anti-patterns for least-privilege.

341
MCQmedium

Refer to the exhibit. A CloudFormation stack has been deployed with the VPCId and SubnetIds outputs. A developer wants to use these outputs as parameters in another CloudFormation stack. Which AWS service can be used to pass these values to the new stack?

A.Amazon Simple Notification Service (SNS)
B.AWS Secrets Manager
C.AWS Systems Manager Parameter Store
D.CloudFormation cross-stack references using Export and ImportValue
AnswerD

Exporting stack outputs and importing them via Fn::ImportValue creates a cross-stack reference, passing VPCId and SubnetIds directly into the second stack. This satisfies the requirement without hardcoding values or duplicating parameters, and CloudFormation enforces the dependency between stacks.

Why this answer

CloudFormation cross-stack references using the `Export` output attribute and the `Fn::ImportValue` intrinsic function allow you to pass output values from one stack as parameters to another stack within the same AWS account and region. This is the native, recommended mechanism for sharing stack outputs without introducing external services or additional complexity.

Exam trap

The trap here is that candidates may confuse Parameter Store (a general-purpose parameter store) with CloudFormation's native cross-stack reference feature, overlooking that the question explicitly asks for passing outputs between CloudFormation stacks, which is directly solved by `Export` and `ImportValue`.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub messaging service used for notifications and event-driven workflows, not for storing or passing CloudFormation stack outputs as parameters. Option B is wrong because AWS Secrets Manager is designed to securely store and rotate secrets (e.g., database credentials, API keys), not to pass CloudFormation outputs between stacks. Option C is wrong because AWS Systems Manager Parameter Store can store configuration data and secrets, but it is not the native CloudFormation mechanism for cross-stack references; using it would require custom logic to write outputs to Parameter Store and then read them in the other stack, adding unnecessary overhead and violating the principle of using built-in CloudFormation features.

342
MCQeasy

A company is deploying a new stateless web application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The company wants to ensure that the application can scale automatically based on demand and that the EC2 instances are spread across multiple Availability Zones for high availability. The company also wants to minimize costs when demand is low. Which solution should a solutions architect recommend?

A.Use AWS Elastic Beanstalk with a single instance environment and enable automatic scaling.
B.Launch EC2 instances in a single Availability Zone and use a Network Load Balancer (NLB) to distribute traffic.
C.Create an Auto Scaling group that spans multiple Availability Zones, with a target tracking scaling policy based on average CPU utilization, and attach it to the ALB target group.
D.Deploy the application on Amazon ECS with Fargate and use a target tracking scaling policy based on memory utilization.
AnswerC

An Auto Scaling group across multiple AZs provides high availability and enables automatic scaling. A target tracking policy based on CPU utilization adjusts capacity to maintain a target value, scaling in during low demand to reduce costs. Attaching to the ALB target group integrates load balancing.

Why this answer

An Auto Scaling group spanning multiple AZs ensures high availability and allows horizontal scaling. Target tracking scaling policies automatically adjust the number of instances to maintain a specified metric, such as average CPU utilization, which helps handle demand fluctuations and reduces costs during low usage. Integrating with an ALB target group ensures traffic is distributed to healthy instances.

Exam trap

The trap here is assuming that a Network Load Balancer or a single-instance Elastic Beanstalk environment can provide high availability, when they either operate at the wrong layer or lack multi-AZ redundancy.

343
MCQhard

A startup runs a containerized microservices application on Amazon ECS with Fargate. They use an Application Load Balancer to distribute traffic. The application consists of 10 services, each with its own ECS service. Recently, the startup launched a marketing campaign and traffic increased 10x. The application started returning HTTP 503 errors. The ECS service metrics show that the number of running tasks is at the maximum desired count for each service. The ALB target group health checks are failing intermittently. The startup needs to handle the increased traffic and prevent 503 errors. What should they do?

A.Increase the desired count and maximum number of tasks for each ECS service.
B.Increase the CPU and memory limits for each task definition.
C.Decrease the health check interval to detect failures faster.
D.Add additional Application Load Balancers and split traffic across them.
AnswerA

Running tasks sit at the maximum desired count, so ECS cannot scale further; raising both desired count and maximum task limit lets the service launch additional Fargate tasks behind the ALB, absorbing the 10x traffic and clearing the 503 errors.

Why this answer

The ECS services are already at their maximum desired count, so the Auto Scaling group cannot add more tasks even though demand has increased 10x. Raising both the desired count and the maximum number of tasks per service allows ECS to scale out further, relieving the overload that causes intermittent health check failures and 503s. This directly addresses the capacity ceiling.

Exam trap

SAP-C02 often tests the misconception that increasing task resources (CPU/memory) or adding load balancers solves a capacity problem, when the real ceiling is the ECS service's maximum desired task count.

How to eliminate wrong answers

Option B is wrong because increasing CPU/memory limits per task does not add capacity if the task count is capped at maximum; it may even reduce the number of tasks that fit on available Fargate capacity. Option C is wrong because shortening health check intervals only detects failures faster and can increase false positives; it does not add capacity to handle the traffic. Option D is wrong because adding more ALBs does not help when the backend ECS services are already maxed out; the bottleneck is task capacity, not load balancer throughput.

344
MCQeasy

A company has a single AWS account and wants to implement a multi-account strategy using AWS Organizations. They need to centrally manage billing and apply policies to restrict which AWS services can be used in each account. The company also wants to ensure that new accounts automatically inherit these restrictions. Which step should they take first to set up AWS Organizations with these capabilities?

A.Create an organization from the management account, then create organizational units (OUs) and service control policies (SCPs) that define the allowed services, and attach the SCPs to the OUs.
B.Enable AWS Control Tower in the management account, which automatically creates OUs and SCPs. Then, customize the SCPs to restrict services.
C.Use AWS Resource Access Manager to share resources between accounts, and use AWS Config rules to enforce service restrictions.
D.Create a new AWS account for each business unit, then use AWS IAM policies in each account to restrict services. Link the accounts for consolidated billing.
AnswerA

Creating an organization from the management account is the foundational step. Then, organizing accounts into OUs and attaching SCPs to those OUs allows centralized policy enforcement. New accounts placed in an OU automatically inherit the SCPs, meeting the requirement for automatic restriction.

Why this answer

To set up AWS Organizations with centralized policy enforcement, the first step is to create the organization from the management account. Then, define OUs and SCPs to restrict services, and attach SCPs to OUs so that accounts inherit them automatically. This provides the required billing consolidation and policy control.

Exam trap

The trap here is thinking that AWS Control Tower must be used to create an organization, when in fact AWS Organizations can be created directly and SCPs applied without Control Tower.

345
Multi-Selectmedium

A company wants to reduce costs for a batch processing workload that runs nightly on Amazon EMR. The workload is fault-tolerant and can handle interruptions. Which TWO strategies should they implement? (Choose TWO.)

Select 2 answers
A.Use On-Demand Instances for all nodes.
B.Right-size the cluster by analyzing resource utilization metrics.
C.Purchase Reserved Instances for the cluster.
D.Use Dedicated Instances to improve performance.
E.Use Spot Instances for task nodes.
AnswersB, E

Right-sizing analyses CloudWatch metrics such as CPU, memory and HDFS utilisation to select appropriate instance types and task-node counts, eliminating over-provisioned capacity. Since the workload is fault-tolerant, smaller correctly sized clusters cut nightly EMR costs without affecting completion.

Why this answer

Option B is correct because right-sizing the cluster based on CloudWatch resource utilization metrics (such as CPU, memory, and disk I/O) eliminates over-provisioned nodes, directly lowering EMR costs for a nightly batch workload. Option E is correct because Spot Instances can be used for task nodes in EMR, and since the workload is fault-tolerant and interruption-tolerant, the steep Spot discounts (up to ~90% off On-Demand) reduce costs substantially without risking data loss on core/HDFS nodes. Option A is wrong because On-Demand Instances for all nodes is the most expensive purchasing model and ignores the workload's tolerance for interruption.

Option C is wrong because Reserved Instances require a 1- or 3-year commitment and are better suited to steady-state, predictable usage rather than a nightly batch job that may not run continuously. Option D is wrong because Dedicated Instances address tenancy/compliance requirements and typically cost more; they do not improve performance or reduce cost for this scenario.

Exam trap

SAP-C02 often tests the misconception that Reserved Instances are always cost-saving, but for intermittent workloads like nightly batch, Spot Instances and right-sizing are more effective; candidates may overlook that task nodes are fault-tolerant.

346
MCQmedium

A company has a multi-tier application running on AWS. The web tier uses an Application Load Balancer (ALB) with an Auto Scaling group of EC2 instances. The application tier runs on a separate Auto Scaling group of EC2 instances. The database tier uses Amazon RDS for MySQL. During a recent load test, the application became unresponsive. Monitoring showed that the database's CPU utilization was at 100% and the number of database connections was at the maximum limit. The application tier instances were healthy, but the web tier instances were returning 503 errors. The Solutions Architect determined that the application tier was making too many database connections because each request opened a new connection and did not close it properly. The team wants to fix the issue with minimal changes to the application code. Which solution should the Solutions Architect recommend?

A.Migrate the database from RDS MySQL to Amazon Aurora MySQL with read replicas.
B.Increase the max_connections parameter in the RDS parameter group to allow more connections.
C.Scale the application tier horizontally by increasing the desired capacity of the Auto Scaling group.
D.Configure Amazon RDS Proxy to pool database connections from the application tier.
AnswerD

RDS Proxy maintains a pool of established connections to the MySQL database and multiplexes application requests across them, capping total connections below the instance limit. This resolves the connection exhaustion causing 100% CPU and 503 errors, requiring only an endpoint change rather than code rewrites.

Why this answer

Amazon RDS Proxy provides connection pooling, allowing the application to reuse existing connections rather than opening new ones. This reduces the number of simultaneous connections to the database, alleviating CPU and connection limit pressure. It requires minimal code changes.

Option A is incorrect because migrating to Aurora does not address the connection management problem; it may still require RDS Proxy. Option B is incorrect because increasing max_connections does not fix the root cause of unclosed connections and can lead to resource contention. Option C is incorrect because scaling the application tier horizontally would increase the number of connections, worsening the issue.

347
MCQhard

A company attaches the IAM policy shown in the exhibit to an IAM user. The user tries to upload an object to my-bucket using the AWS CLI without the --ssl flag (i.e., using HTTP). What will happen?

A.The upload fails with an implicit denial because the Allow condition is not met.
B.The upload succeeds because the Allow statement grants s3:PutObject.
C.The upload fails with an explicit deny because of the Deny statement.
D.The upload succeeds because there is no explicit Deny for s3:PutObject.
AnswerC

The policy's Deny statement matches requests where aws:SecureTransport is false, which HTTP satisfies. Because an explicit deny always overrides any Allow, the CLI upload is rejected outright rather than merely unauthenticated, so the user receives an access-denied error.

Why this answer

The policy contains an explicit Deny statement that triggers when the request is made over HTTP (aws:SecureTransport is false). In AWS IAM, an explicit Deny always overrides any Allow, regardless of other statements or conditions. Because the CLI upload without --ssl uses HTTP, the Deny condition matches and the request is rejected with an explicit deny — not an implicit one.

Exam trap

SAP-C02 often tests the IAM evaluation logic where an explicit Deny overrides any Allow, and candidates confuse 'implicit deny from unmet condition' with 'explicit deny from a matching Deny statement' — the exam expects you to recognize the Deny fires here.

How to eliminate wrong answers

Option A is wrong because the failure is not an implicit denial from an unmet Allow condition — the Deny statement actively matches the HTTP request, producing an explicit deny, which is a materially different evaluation outcome. Option B is wrong because the Allow statement's condition (aws:SecureTransport: true) is not satisfied when HTTP is used, so the Allow does not grant s3:PutObject in this scenario. Option D is wrong because there is an explicit Deny for s3:PutObject when SecureTransport is false — the premise that no explicit Deny exists is factually incorrect.

348
MCQhard

A company has a multi-account AWS environment with a central security account. The security team needs to audit all API activity across all accounts and retain the logs for 7 years in a tamper-evident manner. They also need to ensure that no account administrator can disable or modify the logging configuration. Which solution meets these requirements?

A.Use AWS CloudTrail Lake to aggregate all events, set a retention period of 7 years, and use AWS KMS to encrypt the event data store.
B.Enable AWS Config in all accounts to record API activity, deliver snapshots to a central S3 bucket, and use AWS Config rules to monitor changes.
C.Create individual trails in each account, deliver logs to a central S3 bucket, enable versioning and MFA delete on the bucket, and use IAM policies to restrict access to the bucket.
D.Create an organization trail in AWS CloudTrail that applies to all accounts, deliver logs to a central S3 bucket in the security account, enable S3 Object Lock in compliance mode, and use SCPs to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail.
AnswerD

An organization trail automatically applies to all accounts in the organization and delivers logs to a central S3 bucket. S3 Object Lock in compliance mode prevents deletion or modification of log objects for the retention period. SCPs deny actions that could disable logging. This combination provides centralized, tamper-evident logging with long-term retention and protection against administrative interference.

Why this answer

An organization trail in CloudTrail centralizes logging across all accounts, delivering to a central S3 bucket. S3 Object Lock in compliance mode ensures logs cannot be deleted or altered for the retention period, meeting tamper-evident requirements. SCPs prevent member accounts from stopping or deleting the trail.

This solution provides the necessary audit coverage, retention, and protection against administrative tampering.

Exam trap

The trap here is assuming that CloudTrail Lake or AWS Config can replace a properly configured organization trail with S3 Object Lock for tamper-evident auditing.

349
MCQeasy

Refer to the exhibit. A company is using AWS Migration Hub to track migrations. The above IAM policy is attached to an IAM role used by the migration tool. The migration tool reports that it cannot register the migration task with Migration Hub. Which action should the company add to the policy to fix the issue?

A.mgh:ImportMigrationTask
B.mgh:AssociateDiscoveredResource
C.mgh:CreateHomeRegion
D.mgh:GetHomeRegion
AnswerA

Registering a migration task with Migration Hub requires the mgh:ImportMigrationTask permission, which the existing policy omits. Adding this action to the IAM role lets the migration tool create the task record, resolving the reported registration failure.

Why this answer

The IAM policy shown in the exhibit likely grants permissions for various Migration Hub actions but is missing the specific permission required to register a migration task. The AWS Migration Hub API action `mgh:ImportMigrationTask` is used to register a migration task with Migration Hub, which is exactly what the migration tool is attempting to do. Without this permission, the tool cannot associate the task with Migration Hub, resulting in the reported error.

Therefore, adding `mgh:ImportMigrationTask` to the policy resolves the issue.

Exam trap

SAP-C02 often tests the distinction between Migration Hub actions that register tasks versus those that associate resources or manage home region settings, causing candidates to confuse the specific permission needed for task registration.

How to eliminate wrong answers

Option B is wrong because `mgh:AssociateDiscoveredResource` is used to associate a discovered resource with a migration task, not to register the migration task itself. Option C is wrong because `mgh:CreateHomeRegion` is used to set the home region for Migration Hub, which is a one-time setup action and not required for registering a migration task. Option D is wrong because `mgh:GetHomeRegion` is a read-only action to retrieve the home region, which does not grant permission to register a migration task.

350
MCQmedium

A company is deploying a containerized microservices architecture on Amazon ECS with Fargate. They need to securely store and rotate database credentials. Which AWS service should they use?

A.AWS CloudHSM
B.AWS Identity and Access Management (IAM) roles
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager natively rotates database credentials via Lambda rotation functions, satisfying the stem's rotation requirement without custom code. Unlike Systems Manager Parameter Store, it provides built-in rotation scheduling and native RDS integration. Credentials are retrieved at runtime through IAM policies, keeping secrets out of task definitions and images.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, automatically rotating, and managing the lifecycle of database credentials. It integrates natively with Amazon ECS and Fargate via task role permissions, allowing containers to retrieve secrets at runtime without hardcoding them. Secrets Manager also supports automatic rotation of credentials for Amazon RDS, Aurora, and other databases, which directly addresses the requirement for credential rotation.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets) with AWS Secrets Manager, but Parameter Store lacks native automatic rotation and is not designed for managing database credential lifecycles, making Secrets Manager the correct choice for this specific requirement.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides hardware-based cryptographic key storage and cryptographic operations, not a service for storing or rotating database credentials; it lacks built-in automatic rotation and secret management features. Option B is wrong because IAM roles provide temporary credentials for AWS API access but cannot store or rotate database credentials; they are used for authorization, not secret storage. Option C is wrong because AWS Systems Manager Parameter Store can store secrets but does not natively support automatic rotation of database credentials; it requires custom solutions (e.g., Lambda functions) to implement rotation, whereas Secrets Manager provides built-in rotation.

351
MCQhard

A company is using AWS Organizations with a set of member accounts that need to access a shared Amazon S3 bucket in the master account. The bucket policy allows access only from the member accounts' root user. However, developers in member accounts are unable to access the bucket even when they assume an IAM role. What is the most likely cause?

A.The bucket is encrypted with an AWS KMS key that the role does not have permissions to use.
B.The bucket policy requires an explicit Deny for all principals except the root user.
C.A service control policy (SCP) is denying access to the S3 bucket.
D.The bucket policy grants access to the member account root user ARN, but the role session has a different ARN.
AnswerD

Resource-based policies match the exact principal ARN. Granting access to the account root ARN does not cover an assumed role session, whose ARN is arn:aws:sts::account:assumed-role/role/session. The policy must name the role or account principal explicitly.

Why this answer

The bucket policy explicitly grants access to the member account's root user ARN (e.g., `arn:aws:iam::123456789012:root`). When a developer assumes an IAM role in the member account, the resulting session has a different ARN (e.g., `arn:aws:sts::123456789012:assumed-role/DevRole/session`). Because the bucket policy's Principal is restricted to the root user ARN, the role session is not recognized as a matching principal, and access is denied.

This is a common misconfiguration when mixing root user grants with assumed-role access.

Exam trap

The trap here is that candidates often assume that granting access to a member account's root user automatically grants access to all IAM users and roles in that account, but in reality, root user ARN is a specific principal that does not cover assumed-role sessions or IAM users unless explicitly included.

How to eliminate wrong answers

Option A is wrong because the question states the bucket policy allows access only from the member accounts' root user, and there is no mention of KMS encryption or a KMS key permission issue; the problem is purely about principal matching in the bucket policy. Option B is wrong because an explicit Deny for all principals except the root user would still not allow the role session to access the bucket, but the question describes a bucket policy that 'allows access only from the member accounts' root user' — this is an Allow with a specific principal, not an explicit Deny, and the core issue is the principal mismatch, not an explicit Deny statement. Option C is wrong because while an SCP could deny access, the question asks for the 'most likely cause' given the specific bucket policy configuration; the direct and most common cause is the principal mismatch between the root user ARN in the policy and the assumed-role ARN used by the developers.

352
MCQmedium

A media company is migrating its on-premises rendering farm to AWS. The rendering application uses a shared file system that must be accessible by hundreds of EC2 instances simultaneously. The file system must provide high throughput and low latency, and support POSIX permissions. The company wants to minimize changes to the application. Which AWS storage service should they use?

A.Amazon FSx for Windows File Server
B.Amazon S3 with AWS Transfer Family
C.Amazon Elastic File System (EFS) Standard
D.Amazon FSx for Lustre
AnswerD

Amazon FSx for Lustre is a high-performance file system optimized for compute-intensive workloads like rendering. It provides sub-millisecond latencies, millions of IOPS, and hundreds of GB/s throughput. It supports POSIX permissions and can be accessed by many EC2 instances concurrently. It integrates with S3, allowing data to be processed and stored. This meets the requirements for a rendering farm.

Why this answer

Amazon FSx for Lustre is purpose-built for high-performance computing workloads such as rendering, providing the low latency, high throughput, and POSIX compliance needed. It can be accessed by many EC2 instances simultaneously and integrates with S3. Other file systems either lack the performance or are not POSIX-compliant for Linux workloads.

Exam trap

The trap here is assuming that Amazon EFS, being a shared file system, can handle the performance requirements of a rendering farm, but it is not optimized for such high-throughput, low-latency workloads.

353
MCQmedium

A company is designing a real-time analytics pipeline for IoT data. They need to ingest millions of messages per second, process them with low latency, and store results in Amazon S3. Which combination of services should they use?

A.Amazon Kinesis Data Streams, Amazon Kinesis Data Analytics, Amazon Kinesis Data Firehose
B.Amazon SQS, AWS Lambda, Amazon S3
C.Amazon Kinesis Data Streams, Amazon Redshift, Amazon S3
D.Amazon IoT Core, AWS Lambda, Amazon DynamoDB
AnswerA

Kinesis Data Streams ingests millions of records per second with sub-second latency, satisfying the high-throughput ingestion constraint. Kinesis Data Analytics then processes that stream in real time, and Kinesis Data Firehose delivers the results to Amazon S3 without custom consumer code. Together they meet the low-latency, S3-storage requirements.

Why this answer

Amazon Kinesis Data Streams ingests millions of messages per second with low latency, Kinesis Data Analytics processes the stream in real time using SQL or Apache Flink, and Kinesis Data Firehose reliably delivers the processed data to Amazon S3. This combination is purpose-built for real-time IoT analytics pipelines and meets the throughput, latency, and storage requirements.

Exam trap

SAP-C02 often tests the distinction between streaming (Kinesis) and queuing (SQS) services, and between real-time processing (Kinesis Analytics) and batch analytics (Redshift), causing candidates to pick SQS or Redshift for low-latency streaming use cases.

How to eliminate wrong answers

Option B is wrong because Amazon SQS is a message queue, not a real-time streaming service; it lacks the high-throughput, ordered, replayable stream semantics needed for millions of messages per second, and Lambda polling introduces latency. Option C is wrong because Amazon Redshift is a data warehouse for batch analytics, not a real-time stream processor; it cannot process streaming data with low latency. Option D is wrong because AWS Lambda is not designed for continuous stream processing at millions of events per second, and DynamoDB is a NoSQL database, not an S3 storage solution.

354
MCQmedium

A company is using AWS CodePipeline to automate deployments. They want to add a manual approval step before deploying to production. How should they configure this?

A.Add a manual approval action in the pipeline stage with an SNS topic for notification.
B.Use Amazon CloudWatch Events to trigger an SNS topic for approval.
C.Create a custom action using AWS CodeDeploy.
D.Add a Lambda function that sends an email and pauses the pipeline until a token is provided.
AnswerA

A manual approval action pauses the pipeline stage until a nominated person approves, and attaching an SNS topic notifies approvers when action is required. This satisfies the stem's need to gate production deployment behind human authorisation within CodePipeline.

Why this answer

AWS CodePipeline provides a built-in manual approval action that can be added to a pipeline stage, which sends an SNS notification to approvers. Option B is incorrect because CloudWatch Events is used for event-driven automation, not for manual approvals. Option C is incorrect because AWS CodeDeploy is a deployment service, not for approval steps.

Option D is incorrect because while a Lambda function could be used, CodePipeline has a native approval action that is simpler and more appropriate.

355
MCQmedium

A company is migrating a critical application to AWS using a lift-and-shift approach. The application runs on two on-premises servers: a web server and a database server running SQL Server. The company has deployed the web server on an EC2 instance behind an Application Load Balancer, and the database on an RDS for SQL Server Multi-AZ instance. After migration, users report that the application is noticeably slower compared to on-premises. The application uses a large number of database transactions, and latency between the web server and database has increased. The web server is in us-east-1a, and the RDS primary instance is in us-east-1b. The solutions architect verifies that the application is using the RDS endpoint, not the IP address. What should the architect do to reduce latency?

A.Enable Multi-AZ on the web server EC2 instance.
B.Move the web server EC2 instance to the same Availability Zone as the RDS primary instance.
C.Upgrade the web server EC2 instance to a larger instance type with enhanced networking.
D.Deploy Amazon CloudFront in front of the web server to cache responses.
AnswerB

Placing the EC2 instance in the same Availability Zone as the RDS primary eliminates cross-AZ network hops, cutting the round-trip latency that the transaction-heavy workload amplifies. This satisfies the requirement to reduce latency without altering the application or database configuration.

Why this answer

Cross-AZ traffic between the web server in us-east-1a and the RDS primary in us-east-1b adds roughly 1–2 ms of latency per round trip, which compounds dramatically for chatty applications issuing many small database transactions. Moving the EC2 web server into the same AZ as the RDS primary eliminates that cross-AZ hop, restoring on-premises-like latency. The application already uses the RDS endpoint, so no DNS or connection-string change is needed.

Exam trap

SAP-C02 often tests whether candidates understand that cross-AZ latency is the culprit in lift-and-shift slowdowns, and distractors like 'bigger instance' or 'CloudFront' sound like performance fixes but don't address the actual network hop.

How to eliminate wrong answers

Option A is wrong because Multi-AZ on an EC2 instance is not a feature — Multi-AZ applies to RDS, ELB, and similar managed services, not standalone EC2 instances, so this option is technically nonsensical. Option C is wrong because a larger instance type with enhanced networking improves throughput and packet-per-second performance but does not reduce the physical network latency of crossing AZ boundaries. Option D is wrong because CloudFront caches static content at edge locations and does nothing for dynamic database transactions between the web tier and RDS — it addresses client-side latency, not server-to-database latency.

356
MCQmedium

A multinational company is adopting AWS Organizations to manage multiple accounts across business units. The security team requires that specific IAM roles be automatically deployed to all existing and future member accounts. Which solution should the company use?

A.Use AWS Config rules to enforce the role creation in each account.
B.Use AWS CloudFormation StackSets with automatic deployment enabled in the organization.
C.Use AWS Service Catalog to create a portfolio with the IAM role product and share it with all accounts.
D.Use AWS Lambda functions triggered by AWS CloudTrail events to create the role in each account.
AnswerB

CloudFormation StackSets with automatic deployment targets an organisation or OU, so the required IAM roles are provisioned into every existing account and any account added later. This satisfies the automatic deployment requirement for both current and future member accounts.

Why this answer

AWS CloudFormation StackSets with automatic deployment enabled allows you to deploy IAM roles across all accounts in an AWS Organization, including future accounts, by specifying the organization root or OUs as targets. This ensures consistent role creation without manual intervention, as StackSets automatically provisions stacks in new accounts as they join the organization.

Exam trap

The trap here is that candidates often confuse AWS Config's remediation actions with direct resource creation, or they assume Service Catalog's sharing mechanism automatically deploys resources, when in fact only CloudFormation StackSets with automatic deployment provides native, organization-wide, and future-proof resource deployment.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are for evaluating resource compliance, not for creating or deploying resources; they can trigger remediation actions via Lambda or Systems Manager, but they do not directly create IAM roles across accounts. Option C is wrong because AWS Service Catalog allows users to provision products from a portfolio, but it does not automatically deploy roles to all accounts; it requires users to manually launch the product in each account. Option D is wrong because while Lambda functions triggered by CloudTrail events could create roles, this approach is event-driven and reactive, requiring custom code and handling for future accounts, and lacks the native, automated, and scalable deployment mechanism that StackSets provides for organizations.

357
MCQhard

A company runs a production application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer (ALB) to distribute traffic to tasks. The company has configured an Auto Scaling target tracking policy based on average CPU utilization. During a marketing campaign, traffic spikes cause the ALB to return 503 errors. The ECS service dashboard shows that the number of tasks scaled out to the maximum allowed but the CPU utilization remained high. What is the MOST likely cause of the 503 errors?

A.The ECS service scaled out to the maximum number of tasks, but the new tasks are not yet registered as healthy with the ALB, or the existing tasks are overwhelmed.
B.The target tracking scaling policy takes too long to trigger, and the service cannot scale quickly enough.
C.The Fargate tasks have exhausted their elastic network interface (ENI) limits.
D.The ALB connection limit has been exceeded due to the traffic spike.
AnswerA

Scaling out does not instantly add capacity: new Fargate tasks need time to pass ALB health checks and register, so the ALB returns 503 while existing tasks stay saturated. CPU remained high because demand exceeded the maximum task count.

Why this answer

The most likely cause is that the ECS service scaled out to the maximum number of tasks, but the new tasks are not yet registered as healthy with the ALB, or the existing tasks are overwhelmed. During a traffic spike, even if tasks scale out, there is a delay before they become healthy and can serve traffic. Meanwhile, the existing tasks may be overloaded, leading to 503 errors from the ALB.

Exam trap

SAP-C02 often tests the misconception that scaling out immediately resolves traffic spikes; candidates might overlook the delay in task registration and health checks, leading to 503 errors.

How to eliminate wrong answers

Option B is wrong because although scaling policies can have delays, the scenario states that tasks scaled out to the maximum, so the issue is not the scaling trigger but the readiness of new tasks or capacity of existing ones. Option C is wrong because Fargate tasks do not have ENI limits that would cause 503 errors; ENI limits are per task and are not typically exhausted in this manner. Option D is wrong because ALB connection limits are high and not the likely cause; 503 errors from ALB usually indicate no healthy targets.

358
Matchingmedium

Match each AWS service to its primary use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Centrally manage multiple AWS accounts

Connect VPCs and on-premises networks

Dedicated private network connection to AWS

Secure connection over the internet to AWS

Privately access services across VPCs

Why these pairings

Correct matches: AWS Organizations for account management, AWS Direct Connect for dedicated private connection, AWS VPN for encrypted internet connection, AWS Transit Gateway for hub-and-spoke network interconnection. Common confusions include swapping Direct Connect and VPN, or misattributing account management to networking services.

359
MCQmedium

A company is designing a new microservices architecture on AWS. They need to ensure that services can communicate asynchronously without tight coupling. Which AWS service should they use for message brokering?

A.Amazon Simple Queue Service (SQS)
B.Amazon Simple Notification Service (SNS)
C.Amazon Kinesis Data Streams
D.AWS Step Functions
AnswerA

SQS provides fully managed queues where producers send messages and consumers poll independently, decoupling services so neither waits on the other. This asynchronous, pull-based brokering satisfies the no-tight-coupling requirement, with standard queues offering at-least-once delivery and near-unlimited throughput.

Why this answer

Amazon SQS is a fully managed message queuing service that enables asynchronous, decoupled communication between microservices. Producers send messages to a queue, and consumers poll and process them independently, so services don't need to know about each other or wait for responses. This directly satisfies the requirement for asynchronous communication without tight coupling.

Exam trap

SAP-C02 often tests the distinction between SQS (pull-based queuing for decoupling) and SNS (push-based pub/sub for fanout), so candidates must recognize that asynchronous, decoupled microservice communication typically requires a queue, not a notification service.

How to eliminate wrong answers

Option B is wrong because Amazon SNS is a pub/sub service that pushes messages to subscribers immediately; while it decouples publishers from subscribers, it is not a message broker with durable queuing and does not support asynchronous pull-based consumption. Option C is wrong because Kinesis Data Streams is designed for real-time streaming of large data volumes with ordered shards, not for general-purpose microservice message brokering; it requires consumers to manage shard iterators and checkpoints. Option D is wrong because AWS Step Functions is a serverless orchestration service for coordinating workflows, not a message broker; it tightly couples steps in a state machine and is not intended for asynchronous, decoupled messaging between independent services.

360
MCQmedium

A company is deploying a multi-account AWS environment using AWS Organizations. The security team requires that all Amazon S3 buckets in member accounts are encrypted with AWS KMS customer managed keys, and that the keys are created and managed centrally in a security account. Which solution should a solutions architect recommend?

A.Create KMS keys in each member account and use AWS CloudFormation StackSets to deploy bucket policies that enforce their use.
B.Use AWS Secrets Manager to store KMS key material centrally and grant member accounts access to the secret.
C.Enable default encryption on all S3 buckets using SSE-S3 and use AWS Config to monitor compliance.
D.Create KMS keys in the security account and grant member accounts permission to use them via key policies and IAM policies. Use an S3 bucket policy in each member account to enforce encryption with the central key.
AnswerD

Centralizing KMS keys in the security account with cross-account key policies allows member accounts to use the keys for S3 encryption while keeping key management centralized. S3 bucket policies in member accounts can enforce that all PUT requests use the specified KMS key, satisfying the encryption requirement.

Why this answer

Creating KMS keys in a central security account and sharing them with member accounts via key policies and IAM policies keeps key management centralized. Enforcing encryption with those keys through S3 bucket policies in each member account ensures all buckets use the approved keys, meeting both the central management and encryption requirements.

Exam trap

The trap here is confusing SSE-S3 with SSE-KMS, or assuming that default encryption alone enforces the use of a specific customer managed key.

361
MCQmedium

A company has multiple AWS accounts managed via AWS Organizations. The security team requires that all S3 buckets across all accounts must block public access. How can this be enforced centrally with minimal operational overhead?

A.Enable AWS Config in each account and create a rule to mark public buckets as non-compliant.
B.Create an IAM role in each account with a policy that denies public access modifications and assign it to all users.
C.Use a bucket policy on each existing bucket to deny public access and rely on AWS Config to detect new buckets.
D.Create a service control policy (SCP) to deny s3:PutBucketPublicAccessBlock actions with conditions that require public access block settings.
AnswerD

SCPs can centrally enforce restrictions across all accounts in the organization.

Why this answer

An SCP applied at the AWS Organizations root or OU level can centrally deny the `s3:PutBucketPublicAccessBlock` action unless the request includes specific public access block settings. This enforces the security requirement across all accounts without per-account configuration, minimizing operational overhead. SCPs are the only mechanism that can prevent actions at the account level before they occur, making them ideal for mandatory security baselines.

Exam trap

The trap here is that candidates often choose AWS Config (option A) because it is a common detective control, but they overlook that SCPs are the only preventive control that works centrally across all accounts with zero per-account setup.

How to eliminate wrong answers

Option A is wrong because AWS Config rules only detect and report non-compliant resources after they exist; they do not prevent the creation of public buckets, so operational overhead remains for remediation. Option B is wrong because IAM roles assigned to users cannot prevent actions performed by services (e.g., AWS Lambda, CloudFormation) or root users, and managing roles across many accounts adds significant overhead. Option C is wrong because applying bucket policies to existing buckets is a reactive, per-bucket manual process that does not prevent new public buckets from being created, and AWS Config detection still requires remediation effort.

362
MCQhard

A multinational company is implementing a multi-account strategy using AWS Organizations. The security team needs to ensure that all newly created accounts automatically have a specific baseline CloudTrail trail and a set of AWS Config rules applied. The company also wants to enforce that no account can disable these controls. Which solution should be used?

A.Create an SCP that denies actions to disable CloudTrail and AWS Config, and use AWS CloudFormation StackSets to deploy the baseline resources to all accounts in the organization.
B.Use IAM roles with a trust policy that allows the management account to deploy CloudTrail and AWS Config, and use AWS Lambda to monitor for changes.
C.Use AWS Control Tower to set up the baseline and enforce it via preventive guardrails.
D.Use AWS Organizations to create an SCP that deploys AWS Config rules and CloudTrail via AWS CloudFormation StackSets.
AnswerA

SCPs in AWS Organizations deny the `cloudtrail:StopLogging` and `config:DeleteConfigurationRecorder` actions at the organisation root, so member accounts cannot disable the controls regardless of their own IAM permissions. StackSets then deploys the CloudTrail trail and Config rules automatically to every account, including newly created ones.

Why this answer

It combines an SCP that denies actions to disable CloudTrail and AWS Config (e.g., `cloudtrail:StopLogging`, `config:DeleteConfigRule`) with AWS CloudFormation StackSets to deploy the baseline resources across all accounts in the organization. The SCP enforces that no account (including root users) can disable the controls, while StackSets automatically deploy the CloudTrail trail and Config rules to new accounts as they join the organization. This meets both the automatic deployment and enforcement requirements.

Exam trap

The trap here is that candidates confuse SCPs with deployment mechanisms—SCPs only deny or allow actions, they cannot create resources, so StackSets (or similar) are required for deployment, and Control Tower guardrails are often mistaken for being able to deploy custom resources when they only enforce pre-defined policies.

How to eliminate wrong answers

Option B is wrong because IAM roles with a trust policy from the management account can deploy resources, but they do not prevent accounts from disabling CloudTrail or Config; they only allow the management account to deploy, not enforce. Option C is wrong because AWS Control Tower guardrails can enforce preventive controls (e.g., disallow disabling CloudTrail), but Control Tower does not automatically deploy custom CloudTrail trails or custom Config rules; it only provides pre-defined guardrails and cannot deploy arbitrary baseline resources. Option D is wrong because an SCP cannot deploy resources; SCPs only define permission boundaries and cannot create CloudTrail trails or Config rules—StackSets must be used separately, and the option incorrectly states that the SCP itself deploys the resources.

363
Multi-Selectmedium

A company is designing a serverless application that uses Amazon API Gateway and AWS Lambda. The API must be secured using AWS WAF. Which TWO actions should the company take to integrate WAF with API Gateway? (Choose TWO.)

Select 2 answers
A.Create an AWS WAF web ACL and attach it to the Lambda function
B.Configure API Gateway to require an API key and associate WAF with the usage plan
C.Associate an AWS WAF web ACL with the API Gateway HTTP API
D.Associate an AWS WAF web ACL with the API Gateway REST API stage
E.Place AWS WAF in front of Amazon CloudFront and use CloudFront as the API Gateway endpoint
AnswersC, D

AWS WAF web ACLs can be associated directly with API Gateway HTTP APIs, filtering requests at the API endpoint before they reach the backend. This satisfies the requirement to secure the API with WAF, though the association is configured on the HTTP API rather than a REST stage.

Why this answer

Options C and D are correct because AWS WAF web ACLs can be directly associated with API Gateway REST API stages and with API Gateway HTTP APIs, which is the supported way to protect these endpoints with WAF rules. For a REST API, the web ACL is attached at the stage level (for example, via the API Gateway console, AWS CLI, or CloudFormation), and for an HTTP API, the web ACL is associated with the API itself. Option A is incorrect because AWS WAF cannot be attached directly to a Lambda function; Lambda is protected only indirectly through the fronting service.

Option B is incorrect because API keys and usage plans handle throttling and identification, not WAF rule enforcement, and WAF is not associated with usage plans. Option E is incorrect because placing WAF in front of CloudFront and using CloudFront as the API Gateway endpoint is not the required or direct integration method for securing API Gateway with WAF.

Exam trap

The trap here is that candidates may think WAF must be attached to a CloudFront distribution or a Lambda function, but AWS WAF directly supports association with both API Gateway REST API stages and HTTP APIs without requiring CloudFront.

364
MCQeasy

A company wants to implement a serverless architecture where an AWS Lambda function is triggered whenever a new object is uploaded to an S3 bucket. Which S3 feature should they use?

A.S3 Object Lock
B.S3 Transfer Acceleration
C.S3 Event Notifications
D.S3 Inventory
AnswerC

S3 Event Notifications publish s3:ObjectCreated events to Lambda via a bucket notification configuration, invoking the function per uploaded object. This native push mechanism satisfies the serverless trigger requirement without polling, and supports prefix/suffix filtering to scope which uploads fire.

Why this answer

S3 Event Notifications allow you to configure S3 to publish events (e.g., s3:ObjectCreated:Put) to AWS Lambda, SQS, or SNS whenever an object is uploaded. This is the native serverless integration that triggers a Lambda function directly from S3 without polling or custom code.

Exam trap

The trap here is that candidates may confuse S3 Event Notifications with S3 Inventory or S3 Object Lock, thinking any S3 feature that 'tracks' or 'protects' objects can trigger code, but only Event Notifications provide real-time, push-based triggers to Lambda.

How to eliminate wrong answers

Option A is wrong because S3 Object Lock is a write-once-read-many (WORM) feature that prevents objects from being deleted or overwritten for a fixed retention period; it does not trigger Lambda functions. Option B is wrong because S3 Transfer Acceleration uses AWS edge locations to speed up uploads over long distances via optimized network paths; it has no event triggering capability. Option D is wrong because S3 Inventory provides scheduled CSV/Parquet reports listing objects and their metadata for auditing or lifecycle management; it does not generate real-time events to invoke Lambda.

365
MCQmedium

A company operates a web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in a self-managed Redis cluster on EC2. During a recent marketing campaign, the Redis cluster became a bottleneck, causing session timeouts and poor user experience. The company wants to improve the solution's scalability and resilience with minimal operational overhead. Which solution should a solutions architect recommend?

A.Replace the self-managed Redis cluster with an Amazon DynamoDB table using on-demand capacity mode and DAX.
B.Migrate the session store to Amazon ElastiCache for Redis with cluster mode enabled and automatic failover.
C.Configure the EC2 instances to store session state in Amazon S3 with Transfer Acceleration enabled.
D.Enable sticky sessions on the Application Load Balancer and store session state in instance memory.
AnswerB

ElastiCache for Redis with cluster mode enabled provides horizontal scaling, automatic sharding, and failover, directly addressing the bottleneck and resilience needs. It is a fully managed service, reducing operational overhead compared to self-managed Redis on EC2. The application can continue using the Redis protocol with minimal code changes, and the solution scales read/write capacity as demand grows.

Why this answer

Migrating to Amazon ElastiCache for Redis with cluster mode enabled provides a managed, scalable, and highly available session store. It eliminates the operational burden of self-managed Redis while offering automatic sharding and failover. This directly resolves the bottleneck and improves resilience.

Other options either require significant application changes, introduce latency, or do not address scalability.

Exam trap

The trap here is assuming that any managed database service will automatically reduce operational overhead without considering application compatibility and specific workload characteristics.

366
MCQeasy

A company is migrating a legacy Windows application to AWS. The application requires a shared file system accessible from multiple EC2 instances. Which AWS storage solution should the company use?

A.Amazon Elastic File System (EFS)
B.Amazon FSx for Windows File Server
C.Amazon Elastic Block Store (EBS) with multi-attach enabled
D.Amazon Simple Storage Service (S3)
AnswerB

Amazon FSx for Windows File Server provides fully managed SMB shares backed by Windows file servers, supporting NTFS permissions and Active Directory integration. Multiple EC2 instances can mount the same share concurrently, meeting the legacy Windows application's shared-file-system requirement.

Why this answer

Amazon FSx for Windows File Server provides a fully managed native Windows file system that supports the SMB protocol, which is required for legacy Windows applications to access shared file systems. Amazon EFS uses NFS, which is not natively supported by Windows. EBS with multi-attach is limited to a small number of instances and not ideal for file sharing.

S3 is object storage and does not provide a traditional file system interface.

367
MCQeasy

A company is designing a new application that will process streaming data from IoT devices. The data must be processed in real time and then stored in Amazon S3 for long-term analytics. Which combination of AWS services should be used?

A.Amazon Kinesis Data Firehose, Amazon Redshift
B.Amazon SQS, AWS Lambda, Amazon RDS
C.AWS IoT Core, Amazon DynamoDB
D.Amazon Kinesis Data Streams, AWS Lambda, Amazon S3
AnswerD

Kinesis Data Streams ingests the IoT telemetry with low latency, Lambda processes each record in real time as it arrives, and S3 stores the results durably for later analytics. This satisfies both the real-time processing and long-term storage requirements.

Why this answer

Amazon Kinesis Data Streams ingests and buffers streaming IoT data in real time, AWS Lambda processes each record as it arrives, and the processed data is written directly to Amazon S3 for durable long-term analytics. This combination provides the low-latency, serverless pipeline required for real-time processing and S3-based storage.

Exam trap

The trap here is that candidates often confuse Kinesis Data Firehose (which delivers near-real-time batches) with Kinesis Data Streams (which enables per-record real-time processing), leading them to pick Option A despite its lack of a real-time processing component.

How to eliminate wrong answers

Option A is wrong because Amazon Redshift is a data warehouse for analytics, not a real-time processing engine, and Kinesis Data Firehose delivers data in batches, not per-record processing. Option B is wrong because Amazon SQS is a message queue for decoupling components, not designed for real-time streaming ingestion, and Amazon RDS is a relational database, not suitable for high-throughput streaming data storage. Option C is wrong because AWS IoT Core ingests IoT messages but DynamoDB is a NoSQL database for low-latency queries, not a long-term analytics store like S3, and this combination lacks a real-time processing step.

368
MCQmedium

A company has a multi-account AWS environment and wants to centralize the management of IAM roles. The security team needs to ensure that all IAM roles across all accounts trust the same identity provider (IdP) for federated access. The company uses AWS IAM Identity Center (successor to AWS SSO) for user management. Which solution should be implemented?

A.Use AWS IAM Identity Center to create permission sets that grant access to accounts. IAM Identity Center automatically creates and manages the necessary IAM roles with the IdP trust.
B.Use an SCP to require that all IAM roles trust the corporate IdP.
C.Create IAM roles in each account with a trust policy that allows the corporate IdP.
D.Use AWS CloudFormation StackSets to deploy IAM roles with the IdP trust policy to all accounts.
AnswerA

IAM Identity Center permission sets are provisioned into each account as IAM roles whose trust policy references the Identity Center instance, so every account trusts the same IdP automatically. This centralises role management and satisfies the requirement for uniform federated trust across all accounts.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is designed to centralize user access across multiple AWS accounts. When you create permission sets in IAM Identity Center, it automatically provisions the necessary IAM roles in each target account with a trust policy that trusts the IAM Identity Center's own identity provider. This eliminates the need to manually create or manage IAM roles and their trust policies, ensuring all accounts use the same IdP for federated access.

Exam trap

The trap here is that candidates often confuse SCPs as a mechanism to enforce trust policies, but SCPs cannot modify IAM role trust relationships; they only control the maximum permissions for IAM users and roles within an account.

How to eliminate wrong answers

Option B is wrong because Service Control Policies (SCPs) can restrict permissions but cannot enforce trust policy conditions on IAM roles; SCPs operate at the account level to control which AWS services and actions are allowed, not to modify or mandate the content of IAM role trust policies. Option C is wrong because manually creating IAM roles in each account with a trust policy for the corporate IdP is operationally complex, error-prone, and does not leverage the centralized management capabilities of IAM Identity Center; it also does not automatically synchronize role creation across accounts. Option D is wrong because while AWS CloudFormation StackSets can deploy IAM roles with a specific trust policy to multiple accounts, this approach still requires manual definition and maintenance of the trust policy and does not integrate with IAM Identity Center's automatic role provisioning and lifecycle management.

369
MCQmedium

A company is migrating an on-premises Microsoft SQL Server database to Amazon RDS for SQL Server. They need to minimize downtime and ensure data consistency. Which AWS service should they use for the migration?

A.AWS DataSync
B.AWS Schema Conversion Tool (SCT)
C.AWS Database Migration Service (DMS)
D.AWS Glue
AnswerC

AWS Database Migration Service (DMS) supports heterogeneous migrations with minimal downtime using continuous replication.

Why this answer

(AWS DMS) is correct because it supports homogeneous migrations with minimal downtime using continuous replication. Option A (DataSync) is for file-based data. Option B (SCT) only provides schema conversion.

Option D (Glue) is for ETL jobs.

370
MCQmedium

A company is designing a new application that requires a global content delivery network with low latency and DDoS protection. Which combination of AWS services should be used?

A.Amazon CloudFront and AWS Shield
B.AWS Global Accelerator and Amazon CloudFront
C.Amazon Route 53 and AWS Shield
D.AWS WAF and Amazon CloudFront
AnswerA

Amazon CloudFront caches content at edge locations worldwide, cutting latency for global users, while AWS Shield provides managed DDoS protection at layers 3, 4 and 7. Together they satisfy the stem's dual requirement: a global content delivery network with low latency and integrated DDoS mitigation.

Why this answer

Amazon CloudFront provides a global content delivery network (CDN) with low latency by caching content at edge locations worldwide. AWS Shield, specifically Shield Advanced, offers managed DDoS protection against large-scale attacks, including layer 3/4 and layer 7 threats. Together, they meet the requirement for both low-latency content delivery and DDoS mitigation.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with a CDN, but Global Accelerator does not cache content—it only optimizes network routing, making it unsuitable for content delivery without CloudFront.

How to eliminate wrong answers

Option B is wrong because AWS Global Accelerator improves latency by directing traffic over the AWS global network to the optimal endpoint, but it does not provide content caching or DDoS protection at the edge; it is not a CDN. Option C is wrong because Amazon Route 53 is a DNS service that routes traffic but does not cache content or provide low-latency content delivery; AWS Shield alone does not offer CDN capabilities. Option D is wrong because AWS WAF is a web application firewall that filters HTTP/S requests but does not provide low-latency content caching or global edge distribution; it must be combined with CloudFront for CDN functionality, but the option omits Shield for DDoS protection.

371
MCQhard

A large enterprise is migrating to AWS and wants to implement a multi-account strategy with centralized network connectivity. The company has multiple VPCs in various accounts that need to communicate with each other and with on-premises resources. The solution must be scalable and minimize operational overhead. Which design should be used?

A.Use AWS PrivateLink to connect VPCs via interface endpoints.
B.Create a VPC peering connection between each pair of VPCs that need to communicate.
C.Set up a VPN connection from each VPC to the on-premises network and use routing to enable inter-VPC communication.
D.Use an AWS Transit Gateway in a central network account and attach all VPCs from the various accounts.
AnswerD

A central Transit Gateway in a network account lets VPCs from many accounts attach as spokes, providing scalable transitive routing to each other and to on-premises via VPN or Direct Connect, with far less operational overhead than per-VPC peering meshes.

Why this answer

AWS Transit Gateway acts as a central hub for interconnecting VPCs and on-premises networks, enabling scalable, low-operational-overhead connectivity across multiple accounts. By placing the Transit Gateway in a central network account and using AWS Resource Access Manager to share it with other accounts, the enterprise can avoid the complexity of managing many individual connections while supporting transitive routing and centralized control.

Exam trap

The trap here is that candidates often confuse AWS PrivateLink (which is for service-to-service communication) with a hub-and-spoke solution, or assume VPC peering can scale linearly, ignoring the lack of transitive routing and the operational burden of managing a full mesh.

How to eliminate wrong answers

Option A is wrong because AWS PrivateLink is designed for private access to specific services or endpoints, not for transitive routing between multiple VPCs or connecting to on-premises networks; it does not replace a hub-and-spoke architecture. Option B is wrong because VPC peering does not support transitive routing, requiring a full mesh of connections (O(n²)) that becomes unscalable and operationally heavy as the number of VPCs grows. Option C is wrong because establishing individual VPN connections from each VPC to on-premises does not enable inter-VPC communication without additional routing complexity and fails to provide a centralized, scalable hub for multi-account connectivity.

372
MCQhard

A company is designing a new global web application that will be deployed in multiple AWS Regions. The application must provide low-latency access to users worldwide, and the company wants to minimize operational complexity. The application uses a stateless web tier and a DynamoDB backend. The company needs to ensure that writes in one Region are eventually visible in other Regions. Which solution should a solutions architect recommend?

A.Deploy the web tier in each Region and use Amazon RDS for MySQL with cross-Region read replicas for the backend.
B.Deploy the web tier in each Region and use DynamoDB Accelerator (DAX) in each Region to replicate data across Regions.
C.Deploy the web tier in one Region and use Amazon CloudFront with Lambda@Edge to serve users globally, while using a single DynamoDB table in that Region.
D.Deploy the web tier in each Region behind an Application Load Balancer, and use DynamoDB global tables for the backend.
AnswerD

DynamoDB global tables provide multi-Region, active-active replication with eventual consistency, meeting the requirement for writes to be visible in other Regions. Deploying the stateless web tier in each Region behind an ALB provides low-latency access. This solution minimizes operational complexity because DynamoDB handles replication automatically.

Why this answer

DynamoDB global tables automatically replicate data across Regions, providing an active-active multi-Region database with eventual consistency. This allows writes in one Region to be visible in other Regions. Deploying the stateless web tier in each Region behind an ALB ensures low-latency access for users.

The combination minimizes operational complexity because replication and failover are managed by AWS.

Exam trap

The trap here is confusing DAX with global tables; DAX is a read cache and does not replicate data across Regions, while global tables provide multi-Region replication.

373
MCQmedium

A company is migrating a monolithic application to AWS. The application consists of a web server, an application server, and a MySQL database. The web server and application server run on the same EC2 instance. The company wants to minimize changes during migration. Which migration strategy should the architect recommend?

A.Refactor the application into microservices on Amazon ECS
B.Replatform by migrating the database to Amazon RDS
C.Rehost using AWS Application Migration Service (AWS MGN)
D.Retire the application and replace it with a SaaS solution
AnswerC

Rehosting with AWS Application Migration Service lifts the servers as-is onto EC2, replicating the existing web, application, and MySQL tiers without code changes. This directly satisfies the requirement to minimise changes during migration, since no refactoring, replatforming, or re-architecting is needed.

Why this answer

Rehosting using AWS Application Migration Service (AWS MGN) is the correct strategy because it minimizes changes by lifting and shifting the existing servers to EC2. The application remains monolithic, and the database can stay on the same instance or be moved as-is. This aligns with the requirement to minimize changes during migration.

Exam trap

SAP-C02 often tests the distinction between rehost and replatform, where candidates might think moving the database to RDS is minimal change, but it actually requires application modifications.

How to eliminate wrong answers

Option A is wrong because refactoring into microservices requires significant changes to the application architecture, which contradicts the goal of minimizing changes. Option B is wrong because replatforming by migrating the database to Amazon RDS involves changes to the database layer and possibly application connection strings, which is more than minimal. Option D is wrong because retiring and replacing with SaaS is not a migration of the existing application and would require re-implementation.

374
MCQhard

A company is migrating a legacy monolithic application to a microservices architecture on AWS. The application has strict latency requirements and must be deployed across multiple Availability Zones. Which design strategy BEST meets these requirements while minimizing operational overhead?

A.Use Amazon ECS with Fargate launch type, defining services across multiple AZs.
B.Use AWS Lambda functions for each microservice, triggered by API Gateway.
C.Deploy each microservice on Amazon EC2 instances in an Auto Scaling group across AZs.
D.Use Amazon EKS with worker nodes on EC2, and deploy microservices as Kubernetes pods.
AnswerA

Amazon ECS with Fargate removes EC2 instance management, satisfying the minimal operational overhead constraint. Defining services across multiple Availability Zones provides the required resilience, while Fargate's task placement and awsvpc networking keep inter-service latency low without patching or capacity planning.

Why this answer

Amazon ECS with Fargate is the best choice because it provides serverless container orchestration, automatically managing infrastructure and scaling. By deploying services across multiple Availability Zones, it ensures high availability and low-latency communication without the operational overhead of managing EC2 instances or Kubernetes control planes. AWS Lambda introduces cold start latency and a 15-minute execution limit, making it unsuitable for strict latency requirements and long-running microservices.

EC2 instances and EKS require more operational overhead for patching and scaling. Fargate minimizes that overhead while meeting latency and multi-AZ requirements.

Exam trap

The trap here is that candidates often choose Lambda for its serverless simplicity, but fail to consider the cold start latency and 15-minute execution limit that make it unsuitable for strict latency requirements and long-running microservices.

How to eliminate wrong answers

Option B is wrong because AWS Lambda functions have a maximum execution timeout of 15 minutes and are not designed for long-running or stateful microservices; they also introduce cold start latency that can violate strict latency requirements. Option C is wrong because managing EC2 instances in an Auto Scaling group requires significant operational overhead for patching, scaling, and capacity planning, which does not minimize operational overhead. Option D is wrong because Amazon EKS with worker nodes on EC2 requires managing the Kubernetes control plane and worker node lifecycle, adding operational complexity that contradicts the requirement to minimize operational overhead.

375
MCQhard

A company is designing a new cloud-native application that will be deployed across multiple AWS Regions for high availability. The application uses Amazon Aurora Global Database for its primary data store. The company needs to ensure that in the event of a regional failure, the secondary region can be promoted to primary with minimal data loss. Which configuration should be used?

A.Use Aurora Serverless v2 with data replication across regions using Database Migration Service (DMS).
B.Deploy Aurora Multi-AZ in the primary region and use a secondary region as a warm standby.
C.Use Aurora Global Database with one primary region and one secondary region. Enable managed failover with a Recovery Point Objective (RPO) of 1 second.
D.Configure Aurora Cross-Region Read Replicas and use Amazon Route 53 for DNS failover.
AnswerC

Aurora Global Database replicates storage-level changes to secondary Regions with typical lag under one second, so managed failover promoting the secondary meets the 1-second RPO constraint. This is the only configuration that keeps cross-Region replication continuously active without application-level write forwarding.

Why this answer

Amazon Aurora Global Database is specifically designed for cross-region disaster recovery with a typical RPO of 1 second and RTO of less than 1 minute when managed failover is enabled. It uses a storage-based replication layer that replicates data from the primary to secondary regions with minimal latency, ensuring that in a regional failure, the secondary region can be promoted to primary with very little data loss.

Exam trap

The trap here is that candidates often confuse cross-region read replicas (which have higher replication lag and require manual promotion) with Aurora Global Database's managed failover (which provides sub-second RPO and automated promotion), leading them to choose option D instead of C.

How to eliminate wrong answers

Option A is wrong because Aurora Serverless v2 does not support cross-region replication natively, and AWS Database Migration Service (DMS) is a migration tool, not a real-time replication solution for high availability; it introduces significant latency and potential data loss. Option B is wrong because Aurora Multi-AZ provides high availability within a single region, not across regions, and using a secondary region as a warm standby without global database replication would require manual backup restore or other mechanisms, resulting in higher RPO and RTO. Option D is wrong because Aurora Cross-Region Read Replicas use asynchronous replication with a typical RPO of seconds to minutes, and while Route 53 can handle DNS failover, the replication lag is not guaranteed to be as low as 1 second, and promoting a read replica to primary is a manual process that can take several minutes, leading to higher data loss.

Page 4

Page 5 of 14

Page 6