Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 376–450

984 questions total · 14pages · All types, answers revealed

Page 5

Page 6 of 14

Page 7
376
Multi-Selectmedium

A company is deploying a web application that uses an Application Load Balancer and an Auto Scaling group of EC2 instances. The application must be able to handle sudden spikes in traffic. Which TWO actions should the Solutions Architect take to improve scalability and reduce latency? (Choose two.)

Select 2 answers
A.Enable HTTP/2 on the Application Load Balancer.
B.Increase the default cooldown period for the Auto Scaling group.
C.Use larger EC2 instance types for the Auto Scaling group.
D.Configure the Auto Scaling group to use a predictive scaling policy.
E.Increase the health check interval on the Application Load Balancer.
AnswersA, D

HTTP/2 multiplexes many requests over a single TCP connection, cutting head-of-line blocking and connection overhead during sudden traffic spikes. This directly reduces latency for the web application behind the Application Load Balancer, satisfying the stem's requirement to handle bursts efficiently without adding capacity.

Why this answer

Option A is correct because enabling HTTP/2 on the Application Load Balancer allows multiplexed, concurrent requests over a single TCP connection and header compression, which reduces latency and improves throughput during traffic spikes. Option D is correct because a predictive scaling policy in the Auto Scaling group uses machine learning to forecast demand and pre-provision capacity ahead of anticipated spikes, improving responsiveness and reducing latency compared to reactive scaling alone. Option B is incorrect because increasing the default cooldown period delays subsequent scaling actions, making the group slower to react to sudden traffic increases.

Option C is incorrect because simply using larger instance types does not improve elasticity or latency during spikes and can reduce the granularity of scaling. Option E is incorrect because increasing the health check interval slows detection of unhealthy targets and does not improve scalability or latency.

377
MCQmedium

A company is designing a new application that will process real-time streaming data from thousands of IoT devices. The data must be ingested, processed with low latency, and stored in Amazon S3 for analytics. Which combination of AWS services should the company use to meet these requirements?

A.Amazon SQS, AWS Lambda, Amazon S3
B.Amazon Kinesis Data Firehose, Amazon Redshift, Amazon S3
C.Amazon MQ, AWS Lambda, Amazon RDS
D.Amazon Kinesis Data Streams, AWS Lambda, Amazon S3
AnswerD

Kinesis Data Streams ingests thousands of device events with low latency and durable ordering, Lambda consumes and processes records in real time, and Lambda's native S3 integration stores the results for analytics. This combination directly satisfies the ingestion, low-latency processing, and S3 storage requirements.

Why this answer

Amazon Kinesis Data Streams ingests real-time streaming data from thousands of IoT devices with low latency, and AWS Lambda can process each record as it arrives via event source mapping. The processed data is then stored in Amazon S3 for analytics, meeting all requirements for ingestion, low-latency processing, and durable storage.

Exam trap

The trap here is that candidates confuse Amazon SQS with Kinesis Data Streams for real-time streaming, but SQS is a pull-based queue with no ordered replay or shard-level parallelism, making it unsuitable for high-throughput IoT data ingestion.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue for decoupled communication, not designed for real-time streaming ingestion from thousands of IoT devices; it lacks the shard-based parallelism and ordered replay capabilities needed for streaming data. Option B is wrong because Amazon Redshift is a data warehouse for analytics, not a low-latency processing target; using Kinesis Data Firehose with Redshift adds unnecessary latency and cost for real-time processing, and the requirement specifies storing in S3, not Redshift. Option C is wrong because Amazon MQ is a managed message broker for JMS-compatible applications, not optimized for high-throughput streaming from IoT devices; Amazon RDS is a relational database, not suitable for storing streaming data for analytics in S3.

378
MCQmedium

A company is migrating a monolithic e-commerce application to AWS. The application consists of a web tier, an application tier, and a database tier. The company wants to decouple the tiers to improve scalability and resilience. Which AWS service should the company use to send messages from the web tier to the application tier asynchronously?

A.Amazon SNS
B.Amazon Kinesis Data Streams
C.AWS Step Functions
D.Amazon SQS
AnswerD

Amazon SQS lets the web tier enqueue messages that the application tier polls and processes independently, breaking the synchronous coupling between tiers. This satisfies the asynchronous messaging requirement, so a slow or failed application tier no longer blocks the web tier.

Why this answer

Amazon SQS is the correct choice because it provides a fully managed message queuing service that enables asynchronous communication between decoupled application tiers. The web tier can send messages to an SQS queue, and the application tier can poll and process those messages independently, which improves scalability and resilience by allowing each tier to scale and fail independently.

Exam trap

The trap here is that candidates often confuse SNS (pub/sub push model) with SQS (queue pull model) for decoupling tiers, but SNS does not provide the buffering and independent consumption needed for asynchronous decoupling between a web tier and an application tier.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub messaging service that pushes messages to subscribers, not a queue for point-to-point asynchronous decoupling; it does not provide the buffering and independent consumption that SQS offers. Option B is wrong because Amazon Kinesis Data Streams is designed for real-time streaming of large data volumes, not for simple message queuing between application tiers, and it introduces unnecessary complexity and cost for this use case. Option C is wrong because AWS Step Functions is a serverless orchestration service for coordinating multiple AWS services into workflows, not a message queue for decoupling tiers; it is used for state machines, not for basic asynchronous message passing.

379
MCQmedium

A company is running a containerized application on Amazon ECS with Fargate launch type. The application needs to store persistent data that must be shared across multiple containers in the same task. Which storage option should the company use?

A.Amazon S3 bucket mounted using s3fs
B.Amazon FSx for Lustre
C.Amazon EBS volume
D.Amazon EFS file system
AnswerD

EFS is the only shared, elastic file system mountable concurrently by multiple Fargate containers within a task, satisfying the cross-container persistence constraint. Fargate task ephemeral storage is per-task and not shareable, while EBS volumes cannot attach to Fargate tasks.

Why this answer

Amazon EFS provides a shared, persistent, and scalable NFS file system that can be mounted concurrently by multiple containers within the same ECS task using Fargate. EFS supports the NFSv4.1 protocol, enabling simultaneous read/write access from multiple containers, which meets the requirement for shared persistent storage across containers in the same task.

Exam trap

The trap here is that candidates often confuse Amazon EBS with a shared storage solution, but EBS volumes are zonal and single-instance attachable, making them incompatible with multi-container sharing in Fargate, whereas EFS is the only AWS-native, shared, persistent file system that works seamlessly with Fargate.

How to eliminate wrong answers

Option A is wrong because Amazon S3 mounted via s3fs is an object storage solution that does not provide true POSIX file system semantics, and s3fs is a third-party FUSE implementation that can introduce performance and consistency issues, making it unsuitable for shared persistent storage across containers in a Fargate task. Option B is wrong because Amazon FSx for Lustre is designed for high-performance computing workloads with low-latency access to data, but it is not natively integrated with ECS Fargate and requires a managed Lustre client, which is not supported in the Fargate environment. Option C is wrong because Amazon EBS volumes are block-level storage that can only be attached to a single EC2 instance at a time; they cannot be shared across multiple containers in the same ECS task, and Fargate does not support direct EBS volume attachments.

380
MCQeasy

A company wants to centralize AWS CloudTrail logs from all accounts in AWS Organizations into a single S3 bucket. Which configuration is required?

A.Configure each account's CloudTrail to send logs to a central CloudWatch Logs group
B.Create a CloudTrail trail in each account and deliver logs to the same S3 bucket
C.Create an organization trail in the management account that is enabled for all accounts
D.Use S3 replication to copy logs from individual account buckets to a central bucket
AnswerC

An organization trail created in the management account automatically applies to every account in AWS Organizations, delivering events to one central S3 bucket. This satisfies the requirement to centralise CloudTrail logs across all accounts without configuring individual trails per account, and it captures management events organisation-wide by default.

Why this answer

AWS Organizations supports creating an organization trail in the management account that automatically applies to all accounts in the organization. This centralizes CloudTrail logs from every account into a single S3 bucket without requiring per-account configuration, ensuring consistent logging and simplifying management.

Exam trap

The trap here is that candidates may think individual trails per account (Option B) are necessary or simpler, but AWS Organizations provides a native, centralized mechanism that automatically includes all accounts without per-account configuration.

How to eliminate wrong answers

Option A is wrong because CloudTrail cannot send logs directly to a CloudWatch Logs group; it can send events to CloudWatch Logs, but the question specifies centralizing logs into a single S3 bucket, not a CloudWatch Logs group. Option B is wrong because creating individual trails in each account and delivering to the same S3 bucket would require manual setup per account, does not leverage AWS Organizations integration, and may cause permission issues or log duplication without centralized management. Option D is wrong because S3 replication copies objects after they are written, but it does not address the initial delivery of CloudTrail logs from multiple accounts; each account would still need its own trail and bucket, adding complexity and cost.

381
MCQeasy

A company uses a single AWS account for development and production workloads. To improve security and cost allocation, the company decides to separate environments into multiple accounts. What is the PRIMARY benefit of using multiple accounts?

A.Reducing overall compute costs by sharing reserved instances across environments.
B.Simplifying backup and disaster recovery procedures.
C.Decreasing network latency between development and production environments.
D.Enabling centralized security controls and consolidated billing.
AnswerD

Multiple accounts let AWS Organizations apply service control policies centrally, enforcing security guardrails across every member account, while consolidated billing aggregates usage for volume discounts and cost allocation. This directly satisfies the stem's goals of improved security and cost allocation when separating development and production workloads.

Why this answer

Separating environments into multiple AWS accounts provides a strong security boundary (via AWS Organizations SCPs) and enables consolidated billing with cost allocation tags. This allows centralized security controls (e.g., guardrails, IAM policies) across accounts while aggregating usage for volume discounts, which is the primary benefit for improving security and cost allocation.

Exam trap

The trap here is that candidates confuse the secondary benefit of cost savings (shared RIs) with the primary benefit of security isolation and centralized governance, which is the core reason for multi-account strategies in the SAP-C02 exam.

How to eliminate wrong answers

Option A is wrong because sharing Reserved Instances across accounts is possible with consolidated billing, but this is a cost-saving benefit, not the primary security and cost allocation benefit of multi-account separation. Option B is wrong because backup and disaster recovery procedures are not inherently simplified by multiple accounts; they often require cross-account replication and additional orchestration. Option C is wrong because network latency between environments is not decreased by separate accounts; in fact, inter-account traffic typically adds latency compared to intra-VPC communication within a single account.

382
Multi-Selecteasy

A company wants to centrally manage IAM users across multiple AWS accounts using AWS IAM Identity Center (successor to AWS Single Sign-On). Which of the following are true? (Choose TWO.)

Select 2 answers
A.Users can be granted access to multiple accounts from a central location.
B.Users must be IAM users in each account.
C.Identity Center requires an on-premises Active Directory.
D.Permission sets are assigned to IAM roles in the management account.
E.Users can be created in the Identity Center directory.
AnswersA, E

AWS IAM Identity Center assigns users and groups to permission sets across every account in an AWS Organization from one administrative view, satisfying the centralised multi-account management requirement. This removes the need to create duplicate IAM users in each account, since identities exist once and are federated outward.

Why this answer

Option A is correct because IAM Identity Center is designed for centralized multi-account access: from the management account you create permission sets and assign users/groups to multiple AWS accounts, and users then access those accounts through the AWS access portal without per-account IAM users. Option E is correct because Identity Center includes a built-in Identity Center directory where you can create and manage users and groups directly, in addition to connecting external identity sources such as Active Directory or SAML/OIDC providers. Option B is incorrect because Identity Center federates users into accounts via IAM roles, so users do not need to exist as IAM users in each account.

Option C is incorrect because an on-premises Active Directory is optional, not required; the Identity Center directory or another external IdP can be used. Option D is incorrect because permission sets are not assigned to IAM roles in the management account; they are AWS-managed entities assigned to users/groups for target accounts, where Identity Center provisions corresponding IAM roles in those accounts.

Exam trap

The trap here is that candidates often confuse permission sets with IAM roles in the management account, but permission sets are actually applied to roles created in the member accounts, not the management account.

383
Multi-Selecthard

A company is designing a new application on AWS that requires a highly available and fault-tolerant architecture. Which TWO design principles should they follow?

Select 2 answers
A.Use Auto Scaling groups to automatically replace unhealthy instances.
B.Deploy application across multiple Availability Zones.
C.Manually create EBS snapshots every day.
D.Store data in a single Amazon S3 bucket in one Region.
E.Use a single large EC2 instance to simplify management.
AnswersA, B

Auto Scaling groups continuously health-check instances and terminate then replace failures across Availability Zones, directly satisfying the fault-tolerance constraint. Combined with multi-AZ placement, this removes single points of failure without manual intervention, ensuring the application self-heals and maintains capacity during instance or zone impairment.

Why this answer

Option A is correct because Auto Scaling groups continuously perform health checks and automatically terminate and replace unhealthy EC2 instances, which maintains capacity and self-heals the fleet without manual intervention, directly supporting fault tolerance. Option B is correct because deploying the application across multiple Availability Zones isolates it from a single-AZ failure; each AZ has independent power, cooling, and networking, so the workload remains available if one AZ goes down. Option C is not a high-availability design principle: manual daily EBS snapshots are a backup/recovery mechanism with a recovery point objective of up to 24 hours, not automatic failover.

Option D does not belong because a single S3 bucket in one Region concentrates data in one geographic location and does not by itself provide cross-Region fault tolerance (though S3 is internally redundant within a Region). Option E is wrong because a single large EC2 instance is a single point of failure and cannot deliver high availability or fault tolerance.

Exam trap

The trap here is that candidates often confuse data backup strategies (like EBS snapshots) with high availability design, or they mistakenly believe that a single large instance or a single-region storage approach is sufficient for fault tolerance, ignoring the need for redundancy and automated recovery.

384
MCQmedium

A company is designing a new solution to host a static website with global audience. The website content includes HTML, CSS, JavaScript, and images. The company wants to minimize latency for users worldwide and reduce the load on the origin server. The origin server is an Amazon S3 bucket configured for static website hosting. Which solution should be used to achieve these goals?

A.Use AWS Global Accelerator to route traffic to the S3 bucket.
B.Use AWS Lambda@Edge to serve content from edge locations.
C.Use Amazon CloudFront as a content delivery network (CDN) in front of the S3 bucket.
D.Enable S3 Transfer Acceleration on the bucket.
AnswerC

CloudFront caches the S3-hosted HTML, CSS, JavaScript and images at global edge locations, so users are served from the nearest point of presence rather than the origin. This directly satisfies both stated constraints: minimising worldwide latency and reducing load on the S3 origin, since repeat requests no longer reach the bucket.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches static content (HTML, CSS, JavaScript, images) at edge locations worldwide, significantly reducing latency for a global audience. By placing CloudFront in front of an S3 bucket configured for static website hosting, it offloads requests from the origin server, reducing load and improving performance. CloudFront also supports features like custom SSL, geo-restriction, and origin shield to further optimize delivery.

Exam trap

The trap here is confusing content delivery (CloudFront) with network acceleration (Global Accelerator) or upload acceleration (S3 Transfer Acceleration), leading candidates to pick options that improve network routing but do not cache or serve static content at edge locations.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator improves performance by routing traffic over the AWS global network to the optimal regional endpoint, but it does not cache content at edge locations; it is designed for TCP/UDP traffic and dynamic content, not for reducing load on an S3 static website origin. Option B is wrong because AWS Lambda@Edge runs custom code at CloudFront edge locations to modify requests/responses, but it is not a content delivery service itself; it requires CloudFront to be in place and cannot serve static content directly from edge locations without a CDN. Option D is wrong because S3 Transfer Acceleration speeds up uploads to S3 over long distances using AWS edge locations, but it does not cache or serve content to end users; it is designed for uploads, not for reducing latency for a global audience downloading static website content.

385
MCQhard

A company is deploying a new three-tier web application on AWS. The web tier runs on Amazon EC2 instances behind an Application Load Balancer. The application tier runs on Amazon ECS with the Fargate launch type. The database tier uses Amazon Aurora MySQL. The security team requires that all data in transit between tiers be encrypted and that the application tier be able to access the database without hardcoding credentials. The company wants to minimize operational overhead. Which solution meets these requirements?

A.Use an Application Load Balancer with an HTTP listener and rely on security groups to restrict traffic. Store database credentials in environment variables within the ECS task definition.
B.Configure the Application Load Balancer with an HTTPS listener using an ACM certificate, enable TLS on the ECS service, and store database credentials in AWS Systems Manager Parameter Store as a SecureString parameter without rotation.
C.Use AWS Certificate Manager Private Certificate Authority to issue certificates for the ALB and ECS tasks, and store database credentials in an Amazon S3 bucket encrypted with SSE-S3. Grant the ECS task role access to the bucket.
D.Configure the Application Load Balancer with an HTTPS listener using an ACM certificate, enable TLS on the ECS service, and store database credentials in AWS Secrets Manager with automatic rotation. Grant the ECS task role permission to read the secret.
AnswerD

This solution encrypts data in transit at every tier: the ALB uses an ACM certificate for client-to-web encryption, TLS on the ECS service encrypts application-to-database traffic, and Aurora MySQL supports TLS connections. AWS Secrets Manager stores credentials securely and rotates them automatically. The ECS task role grants least-privilege access to the secret, eliminating hardcoded credentials and reducing operational overhead.

Why this answer

The correct solution encrypts data in transit at all tiers and centralizes credential management with automatic rotation. An HTTPS listener on the Application Load Balancer with an ACM certificate secures client traffic, TLS on the ECS service secures application traffic, and Aurora MySQL supports TLS for database connections. AWS Secrets Manager with automatic rotation and an ECS task role eliminates hardcoded credentials while minimizing operational overhead.

Exam trap

The trap here is assuming that storing credentials in AWS Systems Manager Parameter Store as a SecureString provides the same automatic rotation capabilities as AWS Secrets Manager for database credentials.

386
Multi-Selecteasy

A company is planning to migrate a large .NET application to AWS. The application uses IIS and SQL Server. Which TWO AWS services can be used to rehost the application with minimal changes?

Select 2 answers
A.Amazon Aurora
B.Amazon EC2 with Windows Server
C.AWS Elastic Beanstalk
D.Amazon RDS for SQL Server
E.AWS Lambda
AnswersB, D

Amazon EC2 with Windows Server satisfies the rehost requirement by running the unmodified .NET application on IIS and SQL Server, since the customer manages the guest OS and full software stack. Unlike managed platform services that demand code or configuration changes, lift-and-shift onto EC2 instances preserves the existing architecture with minimal modification.

Why this answer

Amazon EC2 with Windows Server (B) is correct because it lets the company rehost the existing .NET/IIS application on a Windows Server instance with minimal changes, since IIS and the .NET runtime run natively on the VM just as they did on-premises. Amazon RDS for SQL Server (D) is correct because it provides a managed SQL Server engine that is compatible with the application's existing database, so the database can be migrated with little or no code change. AWS Elastic Beanstalk (C) is not the best fit here because it is a PaaS that abstracts the infrastructure and typically requires application packaging/deployment changes rather than a straight rehost of an IIS/SQL Server stack.

Amazon Aurora (A) is a MySQL/PostgreSQL-compatible engine and does not support SQL Server, so it would require database conversion. AWS Lambda (E) is a serverless compute service that cannot run a full IIS/.NET application with SQL Server dependencies without significant re-architecture.

387
MCQeasy

A company is migrating a critical application to AWS and wants to ensure business continuity during the cutover. The migration plan includes a pilot light strategy. Which of the following BEST describes the pilot light pattern?

A.Take regular backups and restore them in AWS during cutover.
B.Run a scaled-down but fully functional version of the environment in AWS at all times.
C.Replicate data to AWS and run a minimal version of the application that can be scaled up during cutover.
D.Run the application simultaneously in both environments and route traffic to both.
AnswerC

Replicating data continuously and running only a minimal core of the application satisfies the pilot light requirement: a small always-on footprint that can be scaled up rapidly during cutover. This differs from warm standby, which runs a fully functional but scaled-down copy, and from backup-and-restore, which provisions nothing until disaster.

Why this answer

The pilot light pattern is a disaster recovery strategy where core data is continuously replicated to AWS, and a minimal version of the application (e.g., a small EC2 instance running the application stack) is kept running. During cutover, this minimal environment is rapidly scaled up to full production capacity. This matches option C, as it describes replicating data and running a minimal version that can be scaled up.

Exam trap

The trap here is confusing the pilot light pattern with the warm standby pattern, as both involve a running environment in AWS, but pilot light uses a minimal stack that is not fully functional until scaled up, whereas warm standby runs a fully functional scaled-down version.

How to eliminate wrong answers

Option A is wrong because taking regular backups and restoring them is a backup-and-restore strategy, not a pilot light pattern; it has a higher recovery time objective (RTO) and does not maintain a running environment. Option B is wrong because running a scaled-down but fully functional version at all times describes the warm standby pattern, not the pilot light; pilot light keeps only the core data and a minimal application stack, not a fully functional environment. Option D is wrong because running the application simultaneously in both environments and routing traffic to both describes a multi-site active-active pattern, which is not the pilot light pattern.

388
Matchingmedium

Match each AWS migration service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Track migration progress across multiple tools

Automate migration of on-premises servers to AWS

Migrate databases to AWS with minimal downtime

Rehost applications from physical or virtual servers

Simplify, automate, and accelerate moving data to AWS

Why these pairings

AWS Migration Hub centralizes tracking, SMS automates server replication, DMS handles database migration, and Application Discovery Service discovers on-premises assets.

389
MCQmedium

A company uses AWS Organizations and wants to centrally manage AWS Config rules across all member accounts. They have enabled AWS Config in the management account and used AWS Config aggregator to view compliance status across accounts. However, they want to enforce a specific Config rule in all accounts automatically. Which solution should they use?

A.Use AWS Config conformance packs with AWS Organizations to deploy the rule across all accounts.
B.Use the AWS Config aggregator to manually enable the rule in each account.
C.Use AWS CloudFormation StackSets to deploy a Config rule template to each account.
D.Create an SCP that requires all accounts to enable AWS Config.
AnswerA

Conformance packs bundle Config rules and remediation actions as a single deployable entity, and AWS Organizations integration pushes them to every member account automatically, satisfying the requirement to enforce the rule centrally without per-account manual deployment.

Why this answer

AWS Config conformance packs can be deployed across all accounts in an AWS Organization using the AWS Organizations integration. Conformance packs allow you to deploy a collection of AWS Config rules and remediation actions consistently. Option B is incorrect because the AWS Config aggregator only provides a central view of compliance status; it does not automatically enable rules in member accounts.

Option C is incorrect: while CloudFormation StackSets can deploy Config rules, conformance packs are the recommended and more straightforward method for deploying Config rules across an organization. Option D is incorrect because SCPs (Service Control Policies) are used to manage permissions and cannot directly enforce AWS Config rules.

390
Multi-Selectmedium

A company is migrating a multi-tier application to AWS and wants to modernize by using containers and serverless technologies. The application consists of a Node.js frontend, a Java backend, and a PostgreSQL database. The company wants to reduce operational overhead and improve scalability. Which TWO strategies should the company use? (Choose two.)

Select 2 answers
A.Refactor the Node.js frontend to run on AWS Lambda with Amazon API Gateway
B.Migrate the database to Amazon RDS for PostgreSQL
C.Migrate the database to Amazon DynamoDB
D.Deploy the Java backend on Amazon ECS with AWS Fargate
E.Deploy the Java backend on Amazon EC2 with Auto Scaling
AnswersB, D

RDS reduces operational overhead compared to managing PostgreSQL on EC2.

Why this answer

Amazon RDS for PostgreSQL reduces operational overhead by managing backups, patching, and replication, while providing scalability through read replicas and storage auto-scaling. This aligns with the goal of modernizing the database layer without changing the database engine, avoiding the need to refactor the application to use a NoSQL database like DynamoDB.

Exam trap

The trap here is that candidates often assume that any use of containers or serverless must involve Lambda, but for stateful or long-running Java backends, ECS with Fargate is more appropriate than Lambda, and DynamoDB is not a drop-in replacement for PostgreSQL without significant application changes.

391
MCQhard

A company is designing a new application that will be deployed on AWS. The application requires a relational database that must be highly available, automatically scalable, and support read-heavy workloads. The company wants to minimize operational overhead and ensure that the database can fail over to another Availability Zone automatically. Which solution meets these requirements?

A.Amazon Aurora with a Multi-AZ deployment and Auto Scaling for read replicas
B.Amazon DynamoDB with global tables and on-demand capacity
C.Amazon Redshift with concurrency scaling and Multi-AZ
D.Amazon RDS for MySQL with Multi-AZ and a read replica in a different region
AnswerA

Amazon Aurora is a MySQL- and PostgreSQL-compatible relational database that provides high availability with a Multi-AZ deployment. It automatically fails over to a read replica in another AZ if the primary fails. Aurora Auto Scaling can automatically add or remove read replicas based on load, making it ideal for read-heavy workloads with minimal operational overhead.

Why this answer

Amazon Aurora with Multi-AZ and Auto Scaling for read replicas provides a highly available, relational database that automatically scales read capacity. It minimizes operational overhead by handling failover and scaling automatically. Other options either lack automatic scaling, are not relational, or are not designed for transactional workloads.

Exam trap

The trap here is assuming that RDS Multi-AZ includes automatic read replica scaling; it does not, and read replicas must be managed manually.

392
MCQeasy

A company is designing a new application that requires a fully managed NoSQL database with single-digit millisecond latency. The application needs to handle sudden spikes in read traffic without manual intervention. Which AWS service should the company choose?

A.Amazon RDS for MySQL
B.Amazon ElastiCache
C.Amazon Aurora
D.Amazon DynamoDB
AnswerD

Amazon DynamoDB is a fully managed NoSQL database delivering consistent single-digit millisecond latency at any scale. Its on-demand capacity mode absorbs sudden read-traffic spikes automatically, with no manual provisioning, satisfying both the latency and the no-intervention scaling constraints stated in the scenario.

Why this answer

Amazon DynamoDB is a fully managed NoSQL key-value and document database that delivers single-digit millisecond latency at any scale. It supports auto-scaling of read/write capacity based on traffic patterns, enabling the application to handle sudden spikes in read traffic without manual intervention.

Exam trap

The trap here is that candidates may confuse Amazon ElastiCache (a caching layer) with a primary NoSQL database, or assume that Amazon Aurora's MySQL compatibility makes it a NoSQL option, when in fact DynamoDB is the only fully managed NoSQL service among the choices that meets the latency and auto-scaling requirements.

How to eliminate wrong answers

Option A is wrong because Amazon RDS for MySQL is a relational database, not a NoSQL database, and it requires manual scaling or configuration of read replicas to handle traffic spikes. Option B is wrong because Amazon ElastiCache is an in-memory caching service, not a primary database; it is used to accelerate access to data stored elsewhere, not as a fully managed NoSQL database with its own persistence. Option C is wrong because Amazon Aurora is a relational database engine compatible with MySQL and PostgreSQL, not a NoSQL database, and while it offers auto-scaling storage, it does not natively auto-scale read capacity for sudden spikes without manual provisioning of Aurora Replicas.

393
MCQhard

A company is modernizing a legacy application by refactoring it into microservices. The application uses a monolithic database. The company wants to adopt a microservices architecture with independent data stores. What pattern should the company use?

A.Data lake with Amazon S3
B.Centralized database with an API layer
C.Database per Service
D.Shared database with read replicas
AnswerC

Database per Service gives each microservice its own private data store, removing the shared monolithic schema and allowing independent deployment and scaling. Services then integrate through APIs or events rather than direct cross-service database access.

Why this answer

The Database per Service pattern ensures that each microservice owns its own data, promoting loose coupling and allowing independent scaling and technology choices. Option A is incorrect because a data lake with Amazon S3 is designed for analytics and large-scale storage, not for transactional microservices data stores. Option B is incorrect because a centralized database with an API layer still creates a single point of coupling and does not give each service its own data store.

Option D is incorrect because a shared database with read replicas still uses a single database schema, which tightly couples the services.

394
MCQmedium

A company is migrating a Windows-based .NET application to AWS. The application uses SQL Server for its database and stores documents on a Windows file share. The company wants to adopt a hybrid model initially, where the application runs on AWS but still connects to on-premises resources for legacy integration. The migration must use a phased approach: first move the compute to AWS, then the database, and finally the file storage. The company has high latency to the internet and wants to optimize data transfer. You have set up a Direct Connect connection. During the first phase, you migrate the web and application servers to Amazon EC2 Windows instances. You need to ensure that the EC2 instances can access the on-premises SQL Server and file share securely. Which combination of actions should be taken?

A.Place the EC2 instances in a private subnet. Create a VPN connection or use Direct Connect virtual interface to connect to on-premises. Configure security groups to allow traffic to on-premises SQL Server and file share.
B.Place the EC2 instances in a private subnet with a NAT gateway. Use VPC peering to on-premises.
C.Place the EC2 instances in a public subnet. Use an internet gateway and configure security groups to allow inbound traffic from on-premises IPs.
D.Use Amazon EC2-Classic and link the instances to on-premises via ClassicLink.
AnswerA

Private subnets plus a Direct Connect virtual interface or VPN give the EC2 instances private, encrypted connectivity to on-premises SQL Server and file share, avoiding internet exposure. Security groups then restrict traffic to only those on-premises endpoints, meeting the secure hybrid-access requirement.

Why this answer

Placing EC2 instances in a private subnet keeps them off the public internet while still allowing outbound access through the VPC route table. A Direct Connect virtual interface (private VIF) or a VPN connection provides private, low-latency connectivity to on-premises SQL Server and file share, and security groups can be scoped to allow only the required SQL (1433) and SMB (445) traffic. This matches the hybrid, phased migration model where compute moves first but still depends on on-premises data.

Exam trap

SAP-C02 often tests whether candidates understand that NAT gateways and VPC peering do not provide on-premises connectivity — only Direct Connect or VPN can bridge AWS to a corporate data center.

How to eliminate wrong answers

Option B is wrong because a NAT gateway only provides outbound internet access — it cannot route traffic to on-premises networks, and VPC peering does not extend to on-premises environments (that requires Direct Connect or VPN). Option C is wrong because placing instances in a public subnet exposes them to the internet and uses an internet gateway, which contradicts the requirement for secure private access to on-premises resources over Direct Connect. Option D is wrong because EC2-Classic was retired by AWS in 2022 and ClassicLink is no longer available; it also does not provide the required private connectivity to on-premises.

395
Multi-Selectmedium

A company is planning to migrate a three-tier web application to AWS. The application consists of a web server, an application server, and a MySQL database. The company wants to minimize operational overhead and improve scalability. Which THREE AWS services should the company use to modernize the architecture? (Choose THREE.)

Select 3 answers
A.AWS Lambda
B.Elastic Load Balancing (ELB)
C.Amazon EC2 instances
D.Amazon ECS with Fargate
E.Amazon RDS for MySQL
AnswersB, D, E

Elastic Load Balancing distributes incoming traffic across targets in multiple Availability Zones, providing the high availability and horizontal scalability the web tier requires. It is fully managed, so it satisfies the minimise-operational-overhead constraint without needing self-managed load-balancing instances.

Why this answer

Elastic Load Balancing (ELB) [CORRECT] is right because it distributes incoming traffic across multiple targets in the web tier, enabling horizontal scaling and high availability without managing load-balancing servers. Amazon ECS with Fargate [CORRECT] is right because it runs the application tier as containers with serverless compute, eliminating EC2 instance provisioning and patching, which directly reduces operational overhead while supporting automatic scaling. Amazon RDS for MySQL [CORRECT] is right because it provides a managed MySQL-compatible database with automated backups, patching, Multi-AZ failover, and read replicas, replacing self-managed MySQL and improving scalability.

AWS Lambda is not selected because the scenario calls for a three-tier architecture with a dedicated application server tier, which ECS with Fargate addresses more directly. Amazon EC2 instances are not selected because managing them increases operational overhead, contrary to the goal of minimizing it.

396
MCQmedium

Refer to the exhibit. A company has created a CloudTrail trail named 'my-trail' in the management account of AWS Organizations. The trail is configured to deliver logs to a central S3 bucket. The security team wants to capture all management events from all accounts in the organization. Based on the exhibit, what is the most likely issue?

A.The trail is not a multi-region trail
B.The trail does not include global service events
C.The trail has log file validation enabled, which prevents cross-account delivery
D.The trail is not an organization trail
AnswerD

An organization trail is required to capture management events from every account in AWS Organizations automatically. A standard trail logs only the management account's events, so member accounts' activity never reaches the central S3 bucket, leaving the security team's organisation-wide visibility incomplete.

Why this answer

The exhibit shows that the CloudTrail trail 'my-trail' is not configured as an organization trail. In AWS Organizations, a trail must be explicitly created as an organization trail to automatically log management events from all member accounts. Without this setting, the trail only captures events from the management account, not the entire organization.

Exam trap

The trap here is that candidates may assume a trail created in the management account automatically covers all organization accounts, but CloudTrail requires explicit organization trail configuration to enable cross-account logging.

How to eliminate wrong answers

Option A is wrong because the exhibit does not indicate whether the trail is multi-region; even if it were single-region, that would not prevent cross-account delivery—it would only limit regional coverage. Option B is wrong because the question specifically asks about capturing management events from all accounts, and global service events (like IAM) are a subset of management events; excluding them would not prevent delivery from other accounts. Option C is wrong because log file validation is a security feature that ensures log integrity and does not block cross-account delivery; it is unrelated to organization trail configuration.

397
Multi-Selecteasy

A company is using an AWS Lambda function to process records from an Amazon Kinesis stream. The function stores results in an Amazon DynamoDB table. The team notices that the Lambda function sometimes fails due to throttling from DynamoDB. Which TWO actions should the team take to improve the continuous processing of records? (Choose TWO.)

Select 2 answers
A.Increase the number of shards in the Kinesis stream to reduce data per Lambda invocation.
B.Configure reserved concurrency for the Lambda function to limit its maximum concurrency.
C.Increase the concurrency limit for the Lambda function to allow more parallel executions.
D.Switch the DynamoDB table to on-demand capacity mode.
E.Enable DynamoDB auto scaling for the table to adjust read/write capacity automatically.
AnswersD, E

On-demand mode eliminates throttling by scaling automatically.

Why this answer

Switching the DynamoDB table to on-demand capacity mode eliminates the need to provision read/write capacity, allowing the table to automatically scale to handle any throttling caused by sudden spikes in Lambda writes. This directly addresses the throttling issue without requiring manual capacity management.

Exam trap

The trap here is that candidates often choose to increase Lambda concurrency or shards, thinking more parallelism will improve processing, but they fail to recognize that the bottleneck is DynamoDB capacity, and increasing Lambda concurrency only worsens the throttling.

398
MCQmedium

A company runs a critical application on Amazon RDS for PostgreSQL. The database performance has degraded over time. The Solutions Architect notices that read queries are slow and the DB instance's ReadIOPS metric is consistently high. Which action would improve read performance with minimal operational overhead?

A.Increase the allocated storage of the DB instance.
B.Enable Multi-AZ deployment for the DB instance.
C.Migrate the database to Amazon Aurora with PostgreSQL compatibility.
D.Create an RDS read replica and redirect read queries to it.
AnswerD

A read replica offloads read queries to a separate DB instance, relieving the primary's consistently high ReadIOPS. RDS replicates asynchronously with no application rewrite, satisfying the minimal-operational-overhead constraint while directly improving read performance for PostgreSQL.

Why this answer

Creating an RDS read replica (Option D) offloads read traffic from the primary instance, reducing ReadIOPS and improving read query performance. This requires minimal operational overhead because Amazon RDS manages the replica. Option A is incorrect: increasing storage can help with IOPS limits but does not directly reduce read load.

Option B is incorrect: Multi-AZ provides high availability, not read scalability. Option C is incorrect: migrating to Aurora involves more effort and is not the simplest solution.

399
Multi-Selecteasy

A company is designing a cost-effective architecture for a batch processing job that runs nightly. The job can tolerate interruptions and requires significant compute power for a few hours. The company wants to minimize costs. Which TWO strategies should the company use?

Select 2 answers
A.Use Spot Instances for compute.
B.Purchase Reserved Instances (RI) for a 1-year term.
C.Configure Auto Scaling to scale out during the job and scale in after.
D.Use On-Demand Instances to ensure availability.
E.Use Dedicated Hosts for compliance.
AnswersA, C

Spot Instances deliver up to 90% discounts versus On-Demand by using spare EC2 capacity, and the job's tolerance of interruptions matches Spot's two-minute termination notice. This satisfies the minimise-cost constraint for a fault-tolerant nightly batch workload.

Why this answer

Option A is correct because Spot Instances offer up to a 90% discount compared to On-Demand prices and are ideal for fault-tolerant, interruptible batch workloads that can be terminated and resumed without impacting the business. Option C is correct because Auto Scaling dynamically adds capacity only during the few hours the nightly job runs and removes it afterward, so the company pays only for the compute actually needed rather than provisioning for peak capacity 24/7. Together, Spot Instances plus Auto Scaling deliver the lowest cost for a short, interruption-tolerant batch job.

Option B is not appropriate because a 1-year Reserved Instance commitment is wasteful for a workload that runs only a few hours per night. Option D is not appropriate because On-Demand pricing is the most expensive per-hour option and provides no cost optimization for interruptible work. Option E is not appropriate because Dedicated Hosts are a premium, compliance-driven offering and are far more costly than needed here.

Exam trap

The trap here is that candidates often choose Reserved Instances (Option B) thinking they are always cheaper for recurring workloads, but they fail to recognize that the low utilization (a few hours per night) makes On-Demand or Spot more cost-effective than a 1-year commitment.

400
Multi-Selectmedium

A company runs a production AWS environment with Amazon EC2 instances managed by Auto Scaling groups. The operations team notices that after a recent deployment, the application is returning higher error rates. Which TWO steps should the team take to enable a quick rollback and improve future deployments?

Select 2 answers
A.Configure Auto Scaling lifecycle hooks to automatically terminate new instances if health checks fail.
B.Implement canary deployments using AWS CodeDeploy to shift traffic gradually and monitor error rates.
C.Use AWS CloudFormation change sets to automatically roll back failed deployments.
D.Use AWS Elastic Beanstalk to perform a blue/green deployment, swapping the environment URL after testing.
E.Enable AWS CloudTrail to track deployment API calls and automatically revert if errors exceed a threshold.
AnswersB, D

CodeDeploy canary shifts a small percentage of traffic to the new revision first, then promotes it only if error rates stay acceptable. This directly satisfies the gradual-shift and monitoring requirement, and rollback is a redeployment of the last known-good revision.

Why this answer

Option B is correct because AWS CodeDeploy canary deployments shift a small percentage of traffic to the new version first, letting the team monitor error rates and abort or roll back the deployment before all instances are affected. Option D is correct because Elastic Beanstalk blue/green deployments create a separate environment with the new version, and the environment URL (CNAME swap) is only switched after testing, so a failed deployment can be reverted by swapping back to the original environment. Option A is not correct because lifecycle hooks only pause instance launch/termination for custom actions and do not provide application-level rollback of a bad deployment.

Option C is not correct because CloudFormation change sets preview infrastructure changes and do not automatically roll back application deployments based on error rates. Option E is not correct because CloudTrail only records API activity for auditing; it does not automatically revert deployments when error thresholds are exceeded.

Exam trap

SAP-C02 often tests whether candidates can distinguish deployment strategies (canary, blue/green) from monitoring/auditing services (CloudTrail) and infrastructure tools (CloudFormation change sets), which do not provide automatic application rollback.

401
MCQhard

A company has a large AWS Organizations environment with 200 accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that the roles are deployed to all existing and future accounts, and that any changes to the roles are automatically propagated. Which solution should they use?

A.Write a script using AWS CLI that iterates over all accounts and creates the IAM roles, and schedule it to run periodically to update roles.
B.Use AWS Resource Access Manager (RAM) to share the IAM roles from the central security account to all member accounts.
C.Use AWS CloudFormation StackSets with service-managed permissions to deploy the IAM roles to all accounts in the organization, and enable automatic deployment.
D.Create an IAM role in the management account and use AWS Single Sign-On (SSO) to grant access to the central security account.
AnswerC

CloudFormation StackSets with service-managed permissions integrates with AWS Organizations to deploy stacks to all accounts. Enabling automatic deployment ensures that new accounts automatically receive the IAM roles, and updates to the stack are propagated to all accounts, meeting the requirements with minimal effort.

Why this answer

CloudFormation StackSets with service-managed permissions is the AWS-native way to deploy IAM roles across an organization. It automatically targets accounts in specified OUs and can be configured to deploy to new accounts as they are added. StackSet updates are rolled out to all stack instances, ensuring consistency.

This approach centralizes management and reduces operational overhead compared to manual or scripted methods.

Exam trap

The trap here is thinking that AWS RAM can share IAM roles, but RAM only supports a specific set of resource types and does not include IAM roles.

402
MCQhard

Refer to the exhibit. A CloudFormation template is used to create an S3 bucket with versioning enabled and a DeletionPolicy of Retain. The stack is deleted. What happens to the bucket and its objects?

A.The bucket and all its objects are deleted
B.The bucket and its objects are retained
C.The bucket is deleted only if it is empty
D.The bucket is deleted, but versioning information is retained
AnswerB

DeletionPolicy: Retain overrides CloudFormation's default delete behaviour, so the S3 bucket survives stack deletion along with every versioned object inside it. Versioning is irrelevant here; the retention guarantee comes solely from the DeletionPolicy attribute, satisfying the stem's requirement that both bucket and objects persist.

Why this answer

When a CloudFormation stack is deleted, the resource with DeletionPolicy set to Retain is preserved. Since the S3 bucket has DeletionPolicy: Retain, the bucket and all its objects (including versioned objects) are retained. Option A is incorrect because the bucket is not deleted.

Option C is incorrect because DeletionPolicy overrides stack deletion behavior regardless of contents. Option D is incorrect because versioning information is also retained along with the bucket.

403
MCQeasy

A company is using AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a member account. Which step is required?

A.Enable IAM Identity Center in the management account and then register the member account as a delegated administrator.
B.Create a service control policy that allows the member account to manage IAM Identity Center.
C.Use AWS CloudFormation StackSets to deploy IAM Identity Center configurations to the member account.
D.Set up AWS Config rules to enforce IAM Identity Center settings in the member account.
AnswerA

Delegated administration requires the management account to enable IAM Identity Center first, since only that account can register a member account as delegated administrator. This satisfies the stem's constraint: administration is delegated to a member account, not the management account, while AWS Organizations integration remains intact.

Why this answer

To delegate administration of IAM Identity Center to a member account, you must first enable IAM Identity Center in the management account. Then, you can register the member account as a delegated administrator using the IAM Identity Center console or the RegisterDelegatedAdministrator API. This allows the member account to manage IAM Identity Center settings, users, and groups without requiring management account credentials.

Exam trap

The trap here is that candidates often confuse service control policies (SCPs) with delegation mechanisms, assuming an SCP can grant administrative rights, when in fact SCPs only deny or allow existing permissions and cannot delegate IAM Identity Center administration.

How to eliminate wrong answers

Option B is wrong because service control policies (SCPs) can only deny or allow actions at the account level, but they cannot delegate administrative permissions for IAM Identity Center; delegation requires explicit registration via the management account. Option C is wrong because AWS CloudFormation StackSets can deploy resources across accounts but cannot register a delegated administrator for IAM Identity Center, which is a management-plane operation. Option D is wrong because AWS Config rules can only evaluate and enforce compliance of resource configurations, not grant administrative delegation or manage IAM Identity Center settings.

404
MCQeasy

A company is using Amazon CloudFront to deliver static content from an S3 bucket. The company wants to ensure that users can only access content through CloudFront and not directly from the S3 bucket. What should the company do?

A.Use CloudFront Origin Access Control (OAC) and update the bucket policy to only allow access from the CloudFront distribution.
B.Set S3 Object Ownership to BucketOwnerPreferred.
C.Configure the S3 bucket policy to allow public read access.
D.Generate CloudFront key pairs and require signed URLs for all content.
AnswerA

Origin Access Control signs CloudFront requests to S3 and pairs with a bucket policy permitting only that distribution, blocking direct S3 URLs. This satisfies the requirement that content be reachable solely through CloudFront, replacing the older, less secure origin access identity approach.

Why this answer

CloudFront Origin Access Control (OAC) is the current AWS-recommended mechanism to restrict S3 bucket access to a specific CloudFront distribution. By creating an OAC, associating it with the distribution's origin, and updating the S3 bucket policy to allow only that OAC's service principal, direct access to the S3 bucket is blocked while CloudFront can still fetch objects.

Exam trap

SAP-C02 often tests whether candidates confuse signed URLs (which control end-user access to CloudFront) with OAC (which controls CloudFront's access to S3) — the requirement to block direct S3 access specifically demands OAC plus a restrictive bucket policy.

How to eliminate wrong answers

Option B is wrong because S3 Object Ownership (BucketOwnerPreferred) only affects ownership of objects uploaded by other accounts; it has no bearing on restricting access to CloudFront. Option C is wrong because allowing public read access on the S3 bucket does the opposite of the requirement — it would let users bypass CloudFront and access objects directly. Option D is wrong because CloudFront signed URLs control who can access content through CloudFront, but they do not prevent direct access to the S3 bucket if the bucket itself is publicly accessible or has permissive policies.

405
MCQmedium

A company is migrating a legacy Java application from an on-premises VMware environment to AWS. The application runs on a single server with 16 vCPUs and 32 GB RAM, and uses an NFS share for shared files. The company wants to minimize changes and reduce operational overhead. Which migration strategy best meets these requirements?

A.Rehost the application to Amazon EC2 by using AWS Application Migration Service, and replace the NFS share with Amazon EFS.
B.Refactor the application into microservices running on Amazon ECS with AWS Fargate, and use Amazon S3 for shared file storage.
C.Retain the application on-premises and extend the network to AWS using AWS Direct Connect.
D.Replatform the application to AWS Elastic Beanstalk, and use Amazon RDS for shared file storage.
AnswerA

Rehosting with AWS Application Migration Service lifts and shifts the server to EC2 with minimal changes, and replacing the NFS share with Amazon EFS provides a managed, scalable file system that integrates with EC2. This reduces operational overhead while preserving the application architecture.

Why this answer

Rehosting with AWS Application Migration Service allows the server to be migrated to EC2 with minimal modifications, aligning with the lift-and-shift approach. Amazon EFS offers a managed NFS-compatible file system that can replace the on-premises NFS share without application changes, reducing operational overhead. Other strategies involve refactoring or replatforming, which introduce unnecessary changes.

Exam trap

The trap here is assuming that any AWS storage service can replace an NFS share, but only Amazon EFS provides the required NFS protocol compatibility for a lift-and-shift migration.

406
MCQmedium

A company runs a high-traffic web application on an EC2 Auto Scaling group behind an Application Load Balancer. The operations team notices that during sudden traffic spikes, new instances take several minutes to become healthy and serve traffic, causing elevated latency. The team wants to reduce the time from instance launch to serving traffic. Which change should a solutions architect recommend?

A.Increase the size of the Auto Scaling group's maximum capacity so more instances can launch simultaneously.
B.Attach an additional target group to the load balancer and register the same instances in both target groups.
C.Create a launch template that specifies a pre-baked Amazon Machine Image (AMI) with the application fully installed and configured, and use it in the Auto Scaling group.
D.Change the Auto Scaling group health check type from EC2 to ELB and reduce the health check grace period to zero.
AnswerC

A pre-baked AMI eliminates the need to install and configure the application at boot, so new instances reach a healthy state much faster. This directly addresses the slow scale-out during traffic spikes and is a standard pattern for reducing launch-to-serve time in Auto Scaling groups.

Why this answer

Using a pre-baked AMI removes the time-consuming installation and configuration steps that occur at instance launch. The application is already present and configured, so the instance can pass health checks and serve traffic much sooner. Other options do not address the underlying bootstrapping delay and may even introduce new problems.

Exam trap

The trap here is assuming that scaling out more aggressively or adjusting health check settings will fix slow instance initialization, when the real issue is the time spent installing and configuring the application at boot.

407
MCQeasy

A company is migrating a web application to AWS and wants to use a containerized architecture. The application consists of multiple microservices that communicate via REST APIs. The company needs a solution that minimizes operational overhead for managing containers and orchestrating microservices. Which AWS service should the company use?

A.Amazon EKS with managed node groups.
B.AWS Lambda functions for each microservice.
C.Amazon EC2 with Docker installed on each instance.
D.Amazon ECS with AWS Fargate launch type.
AnswerD

Fargate removes the need to provision or patch EC2 instances, so AWS manages the container host layer entirely. ECS still orchestrates the microservices and their REST connectivity, satisfying the requirement to minimise operational overhead for container management and orchestration.

Why this answer

Amazon ECS with the Fargate launch type is the correct choice because it allows you to run containers without managing the underlying servers or cluster, thus minimizing operational overhead. Fargate is a serverless compute engine for containers, perfectly suited for microservices requiring minimal management. Option A (EKS with managed node groups) still requires management of worker nodes and is more complex.

Option B (Lambda) is for functions, not containerized microservices. Option C (EC2 with Docker) involves significant operational overhead for managing instances and Docker.

408
MCQhard

A company is migrating a legacy monolithic application to AWS. The application uses a proprietary binary protocol over TCP. The company wants to modernize the architecture using microservices while minimizing changes to the client. Which approach should the company use?

A.Use a Network Load Balancer with TCP listener and route traffic based on destination port to different target groups.
B.Use AWS Global Accelerator with a TCP listener and endpoint groups for microservices.
C.Use an Application Load Balancer with path-based routing to direct traffic to separate microservices.
D.Use Amazon API Gateway with a custom authorizer to route requests to AWS Lambda functions.
AnswerA

A Network Load Balancer preserves the proprietary binary TCP protocol end to end, since it operates at layer 4 without parsing payloads. Port-based listener rules let a single NLB endpoint fan traffic out to separate microservice target groups, so existing clients keep their connection details unchanged.

Why this answer

A Network Load Balancer (NLB) with a TCP listener can forward traffic based on destination port to different target groups, allowing the legacy client using a proprietary binary protocol over TCP to reach distinct microservices without any client-side changes. This preserves the existing TCP connection semantics and binary protocol, which an Application Load Balancer (HTTP/HTTPS only) or API Gateway (HTTP/REST) cannot handle.

Exam trap

The trap here is that candidates often assume an Application Load Balancer or API Gateway can handle any protocol because of their advanced routing features, but they forget that ALB and API Gateway are strictly Layer 7 (HTTP/HTTPS) and cannot process raw TCP or proprietary binary protocols.

How to eliminate wrong answers

Option B is wrong because AWS Global Accelerator uses endpoint groups for routing traffic to regional endpoints, but it does not support port-based routing to different target groups within a single listener; it relies on the underlying NLB or ALB for that granularity, adding unnecessary complexity without solving the port-based routing need. Option C is wrong because an Application Load Balancer operates at Layer 7 (HTTP/HTTPS) and cannot handle proprietary binary protocols over TCP; it requires HTTP-based routing, which would force changes to the client. Option D is wrong because Amazon API Gateway only supports HTTP/REST and WebSocket APIs, not raw TCP or proprietary binary protocols, and would require the client to send HTTP requests, breaking the existing protocol.

409
Multi-Selectmedium

A company uses AWS Organizations and wants to establish a central logging solution. They need to collect CloudTrail logs from all accounts and store them in a central S3 bucket in the management account. Which TWO steps are required to achieve this?

Select 2 answers
A.Create an AWS Config rule to monitor CloudTrail configuration.
B.Apply a service control policy (SCP) to enforce CloudTrail logging.
C.Create a new CloudTrail trail in the management account with organization trail enabled.
D.Configure the trail to deliver logs to a central S3 bucket in the management account.
E.Enable CloudTrail in each member account individually.
AnswersC, D

An organisation trail created in the management account automatically applies to every account in AWS Organizations, delivering their CloudTrail events to the central S3 bucket. This single trail satisfies the requirement to aggregate logs from all member accounts without per-account configuration.

Why this answer

Option C is correct because creating a CloudTrail trail in the management account with the organization trail feature enabled automatically applies the trail to all accounts in the AWS Organization, capturing events across every member account without configuring each one separately. Option D is correct because the trail must be configured to deliver its log files to a central S3 bucket located in the management account, which fulfills the requirement of a single centralized logging destination. Option A is incorrect because an AWS Config rule only evaluates and reports on configuration compliance; it does not collect or centralize CloudTrail logs.

Option B is incorrect because an SCP governs the maximum available permissions for accounts but does not itself create trails or deliver logs to S3. Option E is incorrect because enabling CloudTrail individually in each member account is unnecessary and contrary to the centralized organization trail approach.

Exam trap

The trap is thinking that individual CloudTrail enablement in each member account is necessary. In reality, creating an organization trail in the management account automatically enables CloudTrail in all accounts.

410
MCQeasy

A company needs to provide temporary, limited-privilege credentials to mobile app users to access AWS resources. Which AWS service should the architect recommend?

A.Create IAM users for each mobile user and distribute access keys.
B.Use AWS Security Token Service (STS) directly from the mobile app.
C.Create an IAM role and have the mobile app assume it directly.
D.Use Amazon Cognito with an identity pool to issue temporary credentials.
AnswerD

Cognito identity pools exchange authenticated or guest identities for temporary, scoped AWS credentials via STS, satisfying the limited-privilege and temporary requirements for mobile users. IAM roles attached to the pool constrain exactly which resources each user may reach.

Why this answer

Amazon Cognito identity pools are designed to provide temporary, limited-privilege AWS credentials to mobile app users. The service authenticates users through a public identity provider (e.g., Amazon, Facebook, Google, or a custom OIDC provider) and then exchanges the resulting identity token for temporary AWS credentials via the AWS Security Token Service (STS). This approach avoids embedding long-term credentials in the mobile app and enforces least-privilege access through IAM roles associated with the identity pool.

Exam trap

The trap here is that candidates confuse the ability to call STS directly with the need for pre-existing credentials; STS cannot issue temporary credentials without first authenticating the caller, so a mobile app without embedded credentials must use a service like Cognito to broker the token exchange.

How to eliminate wrong answers

Option A is wrong because creating IAM users for each mobile user and distributing access keys is not scalable, introduces long-term static credentials that are insecure when stored on mobile devices, and violates the principle of least privilege for temporary access. Option B is wrong because using AWS Security Token Service (STS) directly from the mobile app would require the app to have long-term AWS credentials (access key and secret key) to call STS, which defeats the purpose of temporary credentials and creates a security risk. Option C is wrong because having the mobile app assume an IAM role directly is not possible without first obtaining temporary credentials; the AssumeRole API call itself requires valid AWS credentials (either long-term or temporary) to invoke, so a mobile app without pre-provisioned credentials cannot assume a role directly.

411
Multi-Selecthard

A company has a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application experiences occasional timeouts during peak hours. After reviewing AWS X-Ray traces, the team finds that DynamoDB queries are slow. Which THREE actions should the team take to improve performance and continuously optimize the solution?

Select 3 answers
A.Optimize DynamoDB queries by using global secondary indexes and reducing the number of separate queries.
B.Configure DynamoDB auto scaling to adjust read and write capacity based on demand.
C.Use Amazon ElastiCache for Redis to cache DynamoDB query results.
D.Implement Lambda function warmers to keep containers initialized and reduce cold starts.
E.Enable Amazon DynamoDB Accelerator (DAX) for read-heavy workloads.
AnswersA, B, E

Optimize DynamoDB queries by using global secondary indexes and reducing the number of separate queries. This reduces query latency and the number of round trips.

Why this answer

Option A is correct because DynamoDB slowness is often caused by inefficient access patterns such as Scan operations or multiple sequential queries; using global secondary indexes (GSIs) allows efficient Query operations against alternate partition/sort keys, and consolidating separate queries reduces cumulative latency and consumed read capacity. Option B is correct because DynamoDB auto scaling adjusts provisioned read/write capacity automatically in response to traffic patterns, preventing throttling and ProvisionedThroughputExceededException during peak hours, which directly addresses the timeout symptom. Option E is correct because DynamoDB Accelerator (DAX) is an in-memory write-through cache purpose-built for DynamoDB that delivers microsecond read latency for read-heavy workloads, offloading repeated reads from the table and reducing query response times.

Option C is not the best fit because ElastiCache for Redis requires custom cache-invalidation logic and adds architectural complexity, whereas DAX is the native DynamoDB caching solution. Option D does not belong because Lambda cold starts affect function initialization latency, not DynamoDB query execution time identified in the X-Ray traces.

Exam trap

SAP-C02 often tests whether candidates confuse Lambda cold-start mitigation with DynamoDB read latency, or pick ElastiCache over DAX when the workload is specifically DynamoDB read-heavy.

412
MCQmedium

A company has a central IT team that manages AWS Organizations. The development team needs to create and manage their own AWS accounts for new projects. What is the BEST way to automate account creation while maintaining governance?

A.Create an AWS Service Catalog product that uses AWS Organizations APIs to create a new account, applies a baseline CloudFormation template, and moves the account to the correct OU.
B.Use AWS CloudFormation StackSets to create accounts in bulk.
C.Use the AWS Organizations console to manually create accounts and assign them to the appropriate OU.
D.Give the development team the credentials to the management account and let them create accounts directly.
AnswerA

An AWS Service Catalog product wrapping AWS Organizations APIs creates accounts programmatically, applies a baseline CloudFormation template, and places each account in the correct OU. This gives the development team self-service while the central team retains governance through the portfolio.

Why this answer

It uses AWS Service Catalog to provide a self-service portal for the development team, while the central IT team retains governance by embedding AWS Organizations API calls to create accounts, apply a baseline CloudFormation template for security and compliance, and automatically move the account to the correct Organizational Unit (OU). This approach enforces guardrails without granting direct management account access.

Exam trap

The trap here is that candidates often confuse CloudFormation StackSets with account creation, but StackSets only operate on existing accounts, not create new ones.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation StackSets deploy resources across existing accounts and regions; they cannot create new AWS accounts. Option C is wrong because manual creation via the AWS Organizations console is not automated and does not scale for new projects, violating the requirement for automation. Option D is wrong because giving development team credentials to the management account violates the principle of least privilege and central governance, exposing the organization to security risks and accidental changes.

413
MCQmedium

A company is migrating a 40 TB on-premises Oracle database to Amazon Aurora PostgreSQL. The database must remain fully operational during the migration, and the cutover must complete within a 30-minute maintenance window. The company requires continuous data replication until the final switchover. Which migration approach should a solutions architect recommend?

A.Use AWS Database Migration Service (AWS DMS) with ongoing replication, then perform a cutover after the replication lag is near zero.
B.Use AWS Schema Conversion Tool (AWS SCT) to convert the schema, then use native Oracle tools to replicate ongoing changes to Aurora PostgreSQL.
C.Take a full export of the Oracle database using Oracle Data Pump, transfer it to Amazon S3, and import it into Aurora PostgreSQL.
D.Configure Oracle Active Data Guard to replicate to an Amazon RDS for Oracle read replica, then promote the replica and migrate to Aurora PostgreSQL.
AnswerA

AWS DMS with ongoing replication continuously captures changes from the source Oracle database and applies them to Aurora PostgreSQL. This keeps the target synchronized while the source remains fully operational, enabling a short cutover once replication lag is minimal. It directly satisfies the requirement for continuous replication and a 30-minute switchover window.

Why this answer

AWS DMS with ongoing replication is purpose-built for heterogeneous migrations that require minimal downtime. It reads ongoing changes from Oracle and applies them to Aurora PostgreSQL, keeping the target nearly current. When replication lag is low, the application can be switched over quickly, satisfying the 30-minute cutover requirement while the source remains fully available throughout the migration.

Exam trap

The trap here is assuming that a one-time dump-and-load or an Oracle-native replication tool can provide continuous replication into Aurora PostgreSQL without a dedicated heterogeneous replication service.

414
MCQmedium

A company is building a new microservices architecture on AWS using Amazon ECS with Fargate. The services need to communicate with each other using RESTful APIs. The company wants to implement an API gateway to handle authentication, rate limiting, and request routing. Which AWS service should be used as the API gateway?

A.Network Load Balancer
B.Application Load Balancer
C.Amazon API Gateway
D.Amazon CloudFront
AnswerC

Amazon API Gateway provides native RESTful API management, satisfying the authentication, rate limiting and request routing requirements. It integrates with Microsoft Entra ID via JWT authorisers or Lambda authorisers for token validation, and supports usage plans with throttling limits per API key. This offloads cross-cutting concerns from Fargate tasks, which otherwise need custom middleware.

Why this answer

Amazon API Gateway is the AWS-managed service purpose-built for creating, publishing, and managing RESTful APIs, with native support for authentication (IAM, Cognito, Lambda authorizers), rate limiting (usage plans and throttling), and request routing. It integrates directly with ECS/Fargate services via HTTP integrations or VPC Link, making it the correct choice for the described requirements.

Exam trap

SAP-C02 often tests the distinction between load balancers and API gateways — candidates pick ALB because it does Layer 7 routing, but ALB lacks the authentication, usage plans, and rate-limiting features that define an API gateway.

How to eliminate wrong answers

Option A is wrong because a Network Load Balancer operates at Layer 4 and does not provide API-level authentication, rate limiting, or request routing based on HTTP paths and methods. Option B is wrong because an Application Load Balancer does Layer 7 routing but lacks built-in API authentication, usage plans, and rate limiting — it is a load balancer, not an API gateway. Option D is wrong because CloudFront is a CDN for caching and content delivery, not an API gateway with authentication and rate-limiting features.

415
MCQhard

A company is designing a multi-region active-active application using Amazon Route 53 latency-based routing. The application runs on Amazon EC2 instances behind Application Load Balancers (ALBs) in two AWS Regions. The company needs to ensure that if one region becomes unavailable, traffic is automatically routed to the healthy region with minimal disruption. Which configuration meets these requirements?

A.Use Route 53 failover routing instead of latency-based routing.
B.Configure Route 53 latency-based routing without health checks.
C.Use Route 53 weighted routing with weights set to 50 for each region.
D.Configure Route 53 latency-based routing with health checks attached to each ALB endpoint.
AnswerD

Attaching Route 53 health checks to each ALB endpoint lets the DNS resolver withdraw an unhealthy region's records from latency-based answers, so clients resolve only the healthy region's ALB. This satisfies the automatic failover and minimal-disruption constraints, since failover occurs at DNS resolution without manual intervention or client reconfiguration.

Why this answer

Route 53 latency-based routing with health checks ensures that traffic is directed to the region with the lowest latency, and if an ALB endpoint fails its health check, Route 53 automatically removes it from DNS responses, routing traffic to the healthy region. This provides the required active-active multi-region failover with minimal disruption.

Exam trap

The trap here is that candidates often assume failover routing is the only way to handle regional failures, but for active-active architectures, latency-based routing with health checks provides automatic failover while maintaining low-latency routing to both regions.

How to eliminate wrong answers

Option A is wrong because failover routing is designed for active-passive setups, not active-active; it would route all traffic to a primary region and only fail over to a secondary region when the primary fails, which does not meet the requirement for both regions to be active simultaneously. Option B is wrong because latency-based routing without health checks cannot detect regional failures; if an ALB becomes unavailable, Route 53 would continue to return its IP, causing connection failures for clients. Option C is wrong because weighted routing with equal weights distributes traffic based on weight ratios, not latency, and without health checks it cannot automatically fail over if a region becomes unavailable.

416
MCQeasy

A company is deploying a web application on AWS that requires a relational database. The application is read-heavy and expects sudden spikes in traffic. The database must be highly available and perform well under load. Which database configuration meets these requirements?

A.Use Amazon ElastiCache for Memcached as the primary database.
B.Deploy Amazon RDS in a Multi-AZ configuration without read replicas.
C.Deploy Amazon RDS in a single Availability Zone with a large instance size.
D.Deploy Amazon RDS in a Multi-AZ configuration and use read replicas to offload read traffic.
AnswerD

Multi-AZ provides synchronous standby failover for high availability, while read replicas serve read-heavy traffic on separate instances, absorbing sudden spikes without loading the primary. This satisfies both the availability and read-performance constraints, unlike Multi-AZ alone, which does not offload reads.

Why this answer

It combines Multi-AZ deployment for high availability with read replicas to offload read traffic, addressing both the read-heavy workload and sudden traffic spikes. Multi-AZ ensures automatic failover to a standby instance in a different Availability Zone if the primary fails, while read replicas distribute read queries across multiple copies, reducing load on the primary database and improving performance under spike conditions.

Exam trap

The trap here is that candidates often confuse Multi-AZ with read replicas, assuming Multi-AZ alone provides read scaling, but Multi-AZ only provides failover redundancy—the standby instance cannot serve reads, so read replicas are required to offload read traffic.

How to eliminate wrong answers

Option A is wrong because Amazon ElastiCache for Memcached is an in-memory caching layer, not a relational database; it cannot serve as the primary database for a web application requiring persistent, relational storage with ACID transactions. Option B is wrong because Multi-AZ without read replicas provides high availability but does not offload read traffic, so the single primary instance becomes a bottleneck under sudden read spikes, leading to performance degradation. Option C is wrong because deploying in a single Availability Zone with a large instance size lacks high availability—if the AZ fails, the database becomes unavailable—and scaling vertically with a larger instance does not efficiently handle sudden read spikes compared to horizontal scaling with read replicas.

417
MCQmedium

A company is designing a new multi-tier application on AWS. The web tier runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The database tier uses Amazon RDS for MySQL with a single Availability Zone deployment. The company requires that the application survive an Availability Zone failure with minimal downtime and no data loss. The database must automatically fail over to a standby instance in another Availability Zone. What should a solutions architect recommend to meet these requirements?

A.Deploy the database on an EC2 instance with a RAID 1 configuration across two Availability Zones using Amazon EBS snapshots.
B.Create a read replica in another Availability Zone and promote it manually if the primary fails.
C.Configure the RDS DB instance as a Multi-AZ deployment with a standby replica in a different Availability Zone.
D.Enable automated backups with a retention period of 35 days and restore from the latest snapshot if a failure occurs.
AnswerC

Multi-AZ deployment creates a synchronous standby replica in a different Availability Zone. In the event of a failure, Amazon RDS automatically fails over to the standby, typically within 60–120 seconds, with no data loss because replication is synchronous. This meets the requirements for high availability and durability without application changes.

Why this answer

Amazon RDS Multi-AZ deployments provide synchronous replication to a standby in another Availability Zone and automatic failover, ensuring high availability and durability. The other options either involve manual intervention, asynchronous replication, or are not designed for automatic failover with no data loss. Multi-AZ is the recommended approach for production databases requiring AZ resilience.

Exam trap

The trap here is assuming that a read replica in another Availability Zone provides the same high availability as a Multi-AZ standby, but read replicas are asynchronous and require manual promotion.

418
Multi-Selectmedium

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local instance storage. The operations team wants to centralize log analysis and enable near-real-time monitoring for errors. They also want to archive logs for long-term compliance. The logs are generated continuously and can be large in volume. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Use AWS CloudTrail to capture log data from the instances and store it in an S3 bucket.
B.Enable detailed monitoring on the EC2 instances to capture application logs and store them in CloudWatch Logs.
C.Configure the CloudWatch agent to also send logs to Amazon S3 for long-term archival.
D.Create a CloudWatch Logs subscription filter to stream logs to Amazon Kinesis Data Firehose, which delivers them to Amazon S3 for archival.
E.Install and configure the Amazon CloudWatch agent on each instance to send logs to CloudWatch Logs.
AnswersD, E

CloudWatch Logs subscription filters can stream log events to Kinesis Data Firehose, which can then deliver them to Amazon S3 for durable, long-term storage. This provides a scalable and reliable archival solution. It complements the near-real-time monitoring in CloudWatch Logs and meets the compliance requirement for log retention in S3.

Why this answer

To centralize and monitor logs in near-real-time, the CloudWatch agent should be installed to send logs to CloudWatch Logs. For long-term archival, a subscription filter can stream logs to Kinesis Data Firehose, which delivers to S3. CloudTrail and detailed monitoring do not capture application logs, and the CloudWatch agent does not send logs directly to S3.

Exam trap

The trap here is assuming that CloudTrail or detailed monitoring can capture application logs, or that the CloudWatch agent can send logs directly to S3, when in fact CloudWatch Logs is the central service for log ingestion and S3 archival requires an additional streaming mechanism.

419
MCQhard

A company runs a stateful web application on a single Amazon EC2 instance with an attached Amazon EBS volume. The application stores session data locally on the instance's root volume. The company wants to make the application highly available across multiple Availability Zones with minimal application changes. The application must continue to function if an Availability Zone fails. Which solution should a solutions architect recommend?

A.Create an Auto Scaling group that spans multiple Availability Zones, and configure the application to replicate session data across instances using a peer-to-peer protocol.
B.Create an Auto Scaling group that spans multiple Availability Zones, and configure the application to store session data in an Amazon ElastiCache for Redis cluster with Multi-AZ enabled.
C.Create an Auto Scaling group that spans multiple Availability Zones, and store session data on an Amazon EFS file system mounted to all instances.
D.Create an Auto Scaling group that spans multiple Availability Zones, and configure the application to use sticky sessions on the Application Load Balancer.
AnswerB

Moving session state to ElastiCache for Redis with Multi-AZ provides a highly available, shared session store that survives AZ failures. The Auto Scaling group can then launch instances across multiple AZs, and any instance can handle requests because session data is externalized. This requires minimal application changes—only the session store configuration needs updating—and achieves high availability.

Why this answer

To achieve high availability across AZs with minimal changes, session state must be externalized to a highly available store. ElastiCache for Redis with Multi-AZ automatically replicates data and provides failover, so sessions survive AZ failures. The Auto Scaling group can then distribute instances across AZs.

Other options either do not externalize state, add complexity, or use unsuitable storage for session data.

Exam trap

The trap here is assuming that sticky sessions or shared file storage can provide high availability without modifying the application, when they either lose state on failure or introduce performance and complexity issues.

420
MCQeasy

A startup wants to deploy a web application on AWS with a serverless architecture. The application includes static content (HTML, CSS, JS) and a REST API backend using Lambda and DynamoDB. The company wants low latency and high availability globally. Which combination of services should they use?

A.Amazon CloudFront for static content, Application Load Balancer for API, and Lambda for compute.
B.AWS Lambda@Edge for both static content and API.
C.Amazon CloudFront for static content, Amazon API Gateway for the REST API, and AWS Lambda for compute.
D.Amazon S3 for static content with Transfer Acceleration, and AWS Lambda for API.
AnswerC

CloudFront caches static assets at edge locations worldwide, cutting latency, while API Gateway fronts Lambda for a fully managed REST API. This serverless combination delivers the global low latency and high availability the startup requires without managing servers.

Why this answer

It combines Amazon CloudFront for global low-latency delivery of static content, Amazon API Gateway to create and manage the REST API with built-in caching and throttling, and AWS Lambda for serverless compute. This architecture provides high availability, automatic scaling, and global edge caching, meeting the startup's requirements without managing servers.

Exam trap

The trap here is that candidates may confuse Lambda@Edge as a full compute solution for APIs, overlooking its severe execution limits, or assume that an ALB provides global low latency when it is inherently regional and requires additional services like Global Accelerator for global performance.

How to eliminate wrong answers

Option A is wrong because using an Application Load Balancer (ALB) for the API introduces a regional, not global, endpoint and requires managing EC2 instances or Lambda targets behind it, adding complexity and latency compared to API Gateway's global edge-optimized endpoints. Option B is wrong because Lambda@Edge is designed for lightweight, short-duration operations (e.g., header manipulation, URL rewrites) at CloudFront edge locations, not for running full REST API backends with DynamoDB interactions; it has a 5-second execution timeout and limited memory, making it unsuitable for typical API workloads. Option D is wrong because S3 Transfer Acceleration only speeds up uploads to S3 via optimized network paths, but does not provide a REST API gateway, authentication, or request throttling, and it lacks the global edge caching and API management features needed for a low-latency, globally available API.

421
MCQmedium

A company runs a production web application on EC2 instances in an Auto Scaling group behind an ALB. The application logs are stored on an EBS volume attached to each instance. The operations team notices that the logs are not being sent to a central location. What is the MOST efficient way to centralize log collection with minimal code changes?

A.Modify the application to use the AWS SDK to send logs to CloudWatch Logs via PutLogEvents API.
B.Use Amazon Kinesis Agent to send logs to Kinesis Data Firehose and then to S3.
C.Set up an S3 bucket with a lifecycle policy to transition logs to Glacier.
D.Install the CloudWatch Logs agent on each EC2 instance and configure it to stream the log files to CloudWatch Logs.
AnswerD

The CloudWatch Logs agent runs on each instance and tails the existing log files on the EBS volume, streaming them to CloudWatch Logs. This centralises collection without application code changes, unlike custom logging or instance-store approaches.

Why this answer

The CloudWatch Logs agent can be installed on each EC2 instance and configured to stream log files from the EBS volume to CloudWatch Logs without modifying application code. This centralizes logs efficiently and is the standard AWS approach for EC2 log collection. It requires only agent installation and configuration, meeting the minimal-code-change requirement.

Exam trap

SAP-C02 often tests 'minimal code changes' vs 'centralized logging': candidates pick SDK modification or Kinesis pipelines, overlooking that the CloudWatch Logs agent is the lowest-effort, agent-based solution for EC2 log centralization.

How to eliminate wrong answers

Option A is wrong because modifying the application to use the AWS SDK requires code changes and redeployment, which is not minimal effort. Option B is wrong because Kinesis Agent to Firehose to S3 adds complexity and is better suited for streaming data pipelines, not simple log centralization. Option C is wrong because an S3 bucket with lifecycle policies does not collect logs from EC2 instances; it only manages objects already in S3.

422
MCQmedium

A company runs a monolithic application on a single EC2 instance. The application is critical and must be highly available. The company wants to migrate to a containerized architecture on Amazon ECS with minimal downtime. Which approach should the company take?

A.Launch a new ECS cluster with the containerized application and use Route 53 weighted routing to shift traffic.
B.Deploy the monolith as a single task in ECS and update the task definition with new container versions.
C.Use AWS CodeStar to automatically deploy the application to ECS with blue/green deployments.
D.Use an Application Load Balancer with blue/green deployment using AWS CodeDeploy and ECS.
AnswerD

An Application Load Balancer with blue/green deployment via CodeDeploy shifts traffic between two ECS task sets, satisfying the minimal-downtime constraint. New tasks reach healthy status before the ALB reroutes production traffic, and instant rollback is possible if verification fails. This avoids the outage inherent in stopping the monolith before starting containers.

Why this answer

Option D is correct because using an Application Load Balancer (ALB) with blue/green deployment via AWS CodeDeploy and ECS allows you to shift traffic gradually from the old (blue) environment to the new (green) environment with minimal downtime. CodeDeploy orchestrates the deployment, and the ALB routes traffic to the appropriate target group. This approach provides high availability and rollback capability.

Exam trap

SAP-C02 often tests the misconception that Route 53 weighted routing or simple task definition updates provide blue/green deployments; candidates must recognize that CodeDeploy with ALB and ECS is the AWS-recommended approach for minimal-downtime container deployments.

How to eliminate wrong answers

Option A is wrong because Route 53 weighted routing can shift traffic, but it operates at the DNS level and does not provide the fine-grained control or health checks needed for containerized blue/green deployments; it also may not achieve minimal downtime due to DNS caching. Option B is wrong because deploying the monolith as a single task in ECS and updating the task definition does not provide a blue/green deployment; it would cause downtime during the update unless you have multiple tasks and a load balancer, but the option does not mention that. Option C is wrong because AWS CodeStar is a development service that provides templates and CI/CD pipelines, but it does not inherently provide blue/green deployments for ECS; you would still need CodeDeploy and an ALB.

423
MCQmedium

A company is designing a new microservices architecture on AWS. Each microservice is deployed as a containerized application and must be able to scale independently. The company wants to minimize operational overhead for managing the containers and the underlying infrastructure. Which solution should the architect recommend?

A.Amazon EKS with managed node groups
B.Amazon ECS with Fargate launch type
C.Amazon ECS with EC2 launch type and Auto Scaling groups
D.Amazon Lightsail containers
AnswerB

Fargate removes EC2 instance provisioning and patching, letting each containerised microservice scale independently via ECS service autoscaling. This satisfies the minimal operational overhead constraint, unlike EC2 launch types where you manage the underlying cluster capacity yourself.

Why this answer

Amazon ECS with the Fargate launch type is the correct choice because it is a serverless compute engine for containers that eliminates the need to provision, configure, or manage the underlying EC2 instances. This directly meets the requirement to minimize operational overhead while allowing each microservice to scale independently, as Fargate automatically handles the infrastructure and scaling based on the task definitions.

Exam trap

The trap here is that candidates often confuse 'managed node groups' (EKS) with 'serverless' (Fargate), assuming that managed node groups eliminate all operational overhead, when in fact they still require you to manage the EC2 instances, just with some automation for provisioning and updates.

How to eliminate wrong answers

Option A is wrong because Amazon EKS with managed node groups still requires you to manage and pay for the underlying EC2 instances (the node groups), and you are responsible for patching, scaling, and maintaining the worker nodes, which adds operational overhead. Option C is wrong because Amazon ECS with the EC2 launch type and Auto Scaling groups requires you to manage the EC2 instances, including capacity planning, patching, and cluster optimization, which contradicts the goal of minimizing operational overhead. Option D is wrong because Amazon Lightsail containers are designed for simpler, less complex workloads and do not offer the same level of granular scaling, integration with AWS services (e.g., VPC, IAM, CloudWatch), or the ability to handle production-grade microservices architectures with independent scaling requirements.

424
MCQeasy

A company uses AWS Organizations and has a requirement that all Amazon S3 buckets must have versioning enabled. The company wants to automatically enable versioning on any bucket that is created without it. Which solution should be implemented?

A.Use AWS Config with a managed rule s3-bucket-versioning-enabled and configure auto-remediation using an AWS Systems Manager Automation document to enable versioning.
B.Use an SCP to deny s3:CreateBucket unless versioning is enabled.
C.Use AWS Config to detect buckets without versioning and send an SNS notification.
D.Use AWS CloudFormation StackSets to deploy a bucket with versioning enabled in each account.
AnswerA

AWS Config's s3-bucket-versioning-enabled managed rule detects buckets lacking versioning, then auto-remediation triggers a Systems Manager Automation document that calls PutBucketVersioning. This satisfies the automatic enablement requirement for any non-compliant bucket, whether created directly or via CloudFormation.

Why this answer

AWS Config can detect S3 buckets without versioning using the managed rule `s3-bucket-versioning-enabled`, and then automatically remediate the noncompliant resource by invoking an AWS Systems Manager Automation document that enables versioning on the bucket. This provides a fully automated, event-driven solution that meets the requirement without manual intervention or blocking bucket creation.

Exam trap

The trap here is that candidates often choose Option B (SCP) because they assume SCPs can enforce API-level conditions like versioning, but SCPs cannot evaluate request parameters that are not supported as condition keys in the IAM policy context.

How to eliminate wrong answers

Option B is wrong because SCPs cannot conditionally deny `s3:CreateBucket` based on whether versioning is enabled at creation time; the `s3:CreateBucket` API call does not support a condition key for versioning, so the SCP would either block all bucket creation or be ineffective. Option C is wrong because sending an SNS notification only alerts administrators but does not automatically enable versioning, failing the requirement to 'automatically enable versioning'. Option D is wrong because AWS CloudFormation StackSets can only deploy resources in accounts where they are explicitly applied; they cannot retroactively fix buckets created outside the StackSet or in accounts not included in the stack instance, leaving gaps in coverage.

425
Multi-Selecthard

A company is migrating a legacy application to AWS. The application uses a custom authentication mechanism that relies on LDAP. The company wants to minimize changes to the application. Which THREE services should the company consider for integrating LDAP authentication? (Choose THREE.)

Select 3 answers
A.AWS Directory Service Simple AD
B.AWS Directory Service AD Connector
C.AWS Directory Service for Microsoft Active Directory
D.Amazon Cognito user pools
E.AWS Identity and Access Management (IAM)
AnswersA, B, C

Simple AD is an Samba-based managed directory that exposes standard LDAP and Kerberos endpoints in AWS, so the legacy application's existing LDAP calls work unmodified. This satisfies the minimise-changes constraint, though it lacks trusts and advanced Microsoft AD features.

Why this answer

Options A, B, and C are correct because all three are AWS Directory Service offerings that expose LDAP endpoints the legacy application can bind to with minimal code changes. Simple AD (A) is a Samba 4-based, Microsoft AD-compatible directory that supports LDAP and Kerberos, so an app using LDAP authentication can point at it directly. AD Connector (B) is a proxy that forwards LDAP (and Kerberos) authentication requests to an existing on-premises Active Directory, letting the app keep using LDAP while credentials stay on-premises.

AWS Directory Service for Microsoft Active Directory (C), i.e., AWS Managed Microsoft AD, runs actual Windows AD domain controllers that serve LDAP/LDAPS, so it natively satisfies LDAP-dependent authentication. Option D (Amazon Cognito user pools) is wrong because it is an OIDC/OAuth 2.0 identity provider for web/mobile apps, not an LDAP directory, and would require rewriting the app's authentication logic. Option E (IAM) is wrong because IAM handles AWS API authorization via SigV4 and federation (SAML/OIDC), not LDAP bind authentication for an application.

Exam trap

SAP-C02 often tests whether candidates recognize that Cognito user pools and IAM are not LDAP-compatible, and that only the three AWS Directory Service options provide LDAP endpoints for legacy applications.

426
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The operations team notices that stack updates frequently fail because of updates to resources that are not supported for updates. What is the BEST way to handle this?

A.Use AWS Config rules to prevent updates.
B.Delete the stack and create a new one for each update.
C.Use AWS Service Catalog to enforce version control.
D.Use a change set to review the proposed changes before executing the update.
AnswerD

Change sets preview exactly which resources CloudFormation will replace, modify or leave untouched, exposing unsupported-update resources before execution. Reviewing this plan lets the operations team detect and correct problematic resource definitions ahead of the update, directly preventing the frequent stack-update failures described in the stem.

Why this answer

The best practice is to use a change set to preview changes and identify unsupported updates before executing the update.

427
MCQmedium

A company is using AWS Organizations with multiple accounts. The central IT team wants to enforce that all EC2 instances are launched with specific tags (e.g., CostCenter and Environment). The solution should prevent any untagged instances from being created. Which approach should be taken?

A.Use AWS Service Catalog to provision EC2 instances only from pre-configured products that include required tags.
B.Use an AWS Config rule to detect untagged instances and trigger a Lambda function to terminate them.
C.Create an SCP that denies the ec2:RunInstances action if the required tags are not specified in the request.
D.Create an IAM policy for each account that requires tags on instance creation.
AnswerC

SCPs set the maximum permissions for member accounts and are evaluated before IAM, so a deny on ec2:RunInstances with a Null condition on aws:RequestTag keys blocks untagged launches organisation-wide, satisfying the requirement to prevent creation rather than merely detect it afterwards.

Why this answer

AWS Organizations SCPs can centrally enforce tag requirements by denying the ec2:RunInstances action when required tags are not specified in the request. While IAM policies can also use condition keys like aws:RequestTag to enforce tags, managing individual IAM policies across many accounts is less efficient and harder to maintain. SCPs provide a preventive control that applies to all principals in an account, ensuring consistent enforcement without relying on detection and remediation.

Exam trap

The trap here is that candidates often choose a detective solution (like AWS Config with Lambda) because it seems automated, but the question explicitly requires a preventive control that blocks creation, which only SCPs can achieve at the organizational level.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog can enforce tags on provisioned products, but it does not prevent users from launching EC2 instances directly via the console, CLI, or SDK outside of Service Catalog, leaving a gap in enforcement. Option B is wrong because AWS Config rules are detective, not preventive; they can detect untagged instances and trigger a Lambda function to terminate them, but this allows a window of time where the untagged instance exists and may incur cost or security risk, and it does not block the creation in the first place. Option D is wrong because IAM policies must be applied individually to each account or user, and they can be overridden or bypassed by users with sufficient permissions (e.g., administrators), whereas SCPs provide a centralized, unmodifiable guardrail across all accounts in the organization.

428
MCQmedium

A company is deploying a containerized application on Amazon EKS. The application needs to access an Amazon RDS database. The security team requires that database credentials be rotated automatically and never stored in plaintext. Which solution should the architect use?

A.Use AWS Secrets Manager to store and rotate credentials, and grant the EKS pod access via an IAM role
B.Use IAM database authentication for RDS and assign an IAM role to the pod
C.Hardcode the credentials in the container image and rotate the image regularly
D.Store credentials in AWS Systems Manager Parameter Store and grant the EKS pod access via an IAM role
AnswerA

Secrets Manager natively rotates RDS credentials on a schedule, and an IAM role bound to the pod's service account supplies temporary credentials, so no plaintext secret is stored. This satisfies the stem's automatic rotation and no-plaintext requirements.

Why this answer

AWS Secrets Manager is the correct choice because it natively supports automatic rotation of RDS database credentials via a built-in Lambda rotation function, and it integrates with IAM roles to grant EKS pods secure access without storing secrets in plaintext. By using an IAM role for the pod (via IRSA), the application can retrieve credentials at runtime from Secrets Manager, ensuring compliance with the security team's requirements.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager, assuming Parameter Store supports automatic rotation, but Parameter Store lacks native rotation capabilities for RDS credentials, making Secrets Manager the only correct choice for automated rotation.

How to eliminate wrong answers

Option B is wrong because IAM database authentication for RDS does not support automatic credential rotation; it relies on IAM roles and tokens, but the security team specifically requires rotating database credentials, not just authentication. Option C is wrong because hardcoding credentials in a container image violates the requirement to never store credentials in plaintext and does not provide automated rotation. Option D is wrong because AWS Systems Manager Parameter Store does not natively support automatic rotation of RDS credentials; it can store secrets but lacks the built-in rotation capability that Secrets Manager provides.

429
MCQhard

A healthcare company operates a multi-account AWS environment with AWS Organizations. A central Security account runs Amazon GuardDuty and AWS Security Hub, and all member accounts are delegated administrators for those services. The company now wants to centrally manage Amazon Inspector findings across all accounts and ensure that new accounts are automatically covered. Which solution meets these requirements with the LEAST operational effort?

A.Designate the Security account as the delegated administrator for Amazon Inspector in AWS Organizations, then enable Inspector with organization-wide configuration so that all existing and future member accounts are automatically enrolled.
B.Enable Amazon Inspector in each member account individually, then configure each account to forward findings to the Security account using Amazon EventBridge rules and AWS Lambda.
C.Enable Amazon Inspector only in the Security account and use cross-account IAM roles to scan resources in member accounts from the Security account.
D.Use AWS CloudFormation StackSets to deploy Inspector enablement templates to all accounts and rely on AWS Config rules to detect accounts that are not enabled.
AnswerA

Amazon Inspector supports a delegated administrator model through AWS Organizations. Once the Security account is the delegated administrator, enabling Inspector at the organization level automatically enrolls existing accounts and any accounts added later. Findings aggregate in the delegated administrator account, eliminating per-account setup and meeting the automatic coverage requirement with minimal effort.

Why this answer

Amazon Inspector integrates with AWS Organizations through a delegated administrator. The Security account becomes the delegated administrator, and organization-wide enablement covers all current and future accounts automatically. Findings are aggregated centrally, which directly satisfies both the central management and automatic new-account coverage requirements without custom forwarding pipelines.

Exam trap

The trap here is assuming that Amazon Inspector findings must be forwarded manually across accounts, when the service already supports a delegated administrator model with organization-wide auto-enrollment.

430
MCQhard

A CloudFormation stack output is as above. The company wants to use the SQS queue URL in another stack. Which intrinsic function should be used to reference the queue URL in the second stack?

A.Fn::ImportValue
B.Fn::GetAtt
C.Fn::Sub
D.Fn::Ref
AnswerA

Fn::ImportValue retrieves a value exported by another stack via the Export output field, satisfying the cross-stack reference requirement. The queue URL must first be exported in the source stack's Outputs section; the second stack then imports it by name, avoiding hardcoded values and enabling stack independence.

Why this answer

A is correct because Fn::ImportValue is the only intrinsic function that can reference a cross-stack output value exported via the Export field in a CloudFormation stack. Since the SQS queue URL is an output from one stack and needs to be used in another stack, Fn::ImportValue is required to import the exported value by name.

Exam trap

The trap here is that candidates often confuse Fn::GetAtt or Fn::Ref with cross-stack references, but those functions only work within the same stack, while Fn::ImportValue is specifically designed for cross-stack value sharing.

How to eliminate wrong answers

Option B (Fn::GetAtt) is wrong because it retrieves an attribute from a resource within the same stack, not from another stack's output. Option C (Fn::Sub) is wrong because it substitutes variables in a string template, but cannot reference cross-stack exports directly. Option D (Fn::Ref) is wrong because it returns the value of a parameter or resource within the same stack, not an exported output from another stack.

431
MCQmedium

A company uses Amazon RDS for MySQL with Multi-AZ deployment. The database experiences occasional read replica lag of up to 5 seconds. The application requires read-after-write consistency. Which action should the company take to improve the solution?

A.Modify the application to always read from the primary instance.
B.Increase the number of read replicas to distribute the load.
C.Implement Amazon ElastiCache to cache read results.
D.Use Amazon RDS Proxy to route read queries to the read replica.
AnswerA

Read replicas are asynchronously updated, so lag of up to 5 seconds can return stale data. Directing all reads to the primary instance guarantees read-after-write consistency, because the primary always reflects the committed write, eliminating replica lag exposure.

Why this answer

Reading from the primary instance ensures read-after-write consistency. Since the application requires strong consistency, all reads must be directed to the primary, as read replicas may have lag. Option B is incorrect because increasing the number of read replicas does not reduce replication lag.

Option C is incorrect because Amazon ElastiCache is a caching layer, not a solution for consistency. Option D is incorrect because Amazon RDS Proxy helps manage connections but does not eliminate read replica lag.

432
MCQmedium

A company has an existing web application that stores user-uploaded images in an Amazon S3 bucket. The bucket has S3 Standard storage and versioning enabled. Over time, storage costs have increased because many old object versions are never accessed after 30 days, but they must be retained for 1 year for compliance. The security team requires that no object version be permanently deleted before 365 days. Which solution is the MOST cost-effective while meeting the compliance requirement?

A.Enable S3 Intelligent-Tiering on the bucket and rely on it to move noncurrent versions to the archive access tier.
B.Disable versioning on the bucket and use S3 Standard-Infrequent Access for all objects after 30 days.
C.Create an S3 Lifecycle policy that transitions noncurrent versions to S3 Glacier Deep Archive after 30 days and expires them after 365 days.
D.Configure a bucket policy that denies s3:DeleteObjectVersion unless the object is older than 365 days, and manually delete older versions.
AnswerC

Noncurrent version transition to Glacier Deep Archive after 30 days moves rarely accessed old versions to the lowest-cost storage class, and expiration at 365 days satisfies the retention requirement. S3 Lifecycle policies operate automatically without application changes, reducing storage cost while ensuring compliance. This is the most cost-effective option for long-term retention of noncurrent versions.

Why this answer

A lifecycle rule that transitions noncurrent versions to Glacier Deep Archive after 30 days and expires them at 365 days automatically lowers storage costs while guaranteeing retention for the compliance period. Intelligent-Tiering, bucket policies with manual deletion, and disabling versioning do not achieve the same automated, compliant cost reduction.

Exam trap

The trap here is assuming that S3 Intelligent-Tiering automatically manages noncurrent versions and enforces retention, when it only optimizes access-based tiers for current objects.

433
Multi-Selectmedium

A company is implementing a multi-account strategy using AWS Organizations. They want to centralize CloudTrail logs from all accounts into a single S3 bucket in the management account. Which TWO steps are required to achieve this? (Choose two.)

Select 2 answers
A.Use S3 replication to copy logs from member account buckets to the central bucket.
B.Create an IAM role in each member account that allows CloudTrail to write to the central bucket.
C.Enable AWS Config in each member account to forward logs to the central bucket.
D.Create a CloudTrail trail in the management account with the 'Enable for all accounts in my organization' option.
E.Configure the S3 bucket policy to grant the CloudTrail service principal write access from all accounts.
AnswersD, E

Creating an organisation trail with 'Enable for all accounts in my organization' automatically applies the trail to every account, delivering their events to the central S3 bucket. This satisfies the centralisation requirement without configuring each account individually.

Why this answer

Option D is correct because creating an organization trail from the management account with 'Enable for all accounts in my organization' is the mechanism that makes CloudTrail log events from every member account into the specified S3 bucket, satisfying the centralized logging requirement. Option E is correct because the central S3 bucket must have a bucket policy granting the CloudTrail service principal (cloudtrail.amazonaws.com) permission to write objects, and it must account for the source accounts (via aws:SourceArn or organization conditions) so logs from all accounts can be delivered. Option A is not required because S3 replication copies objects between buckets and is unrelated to CloudTrail's native organization trail delivery.

Option B is not required because CloudTrail uses the service principal and bucket policy, not an IAM role in each member account, to deliver logs. Option C is not required because AWS Config records resource configuration changes and does not forward CloudTrail logs to S3.

Exam trap

The trap here is that candidates often assume cross-account access requires IAM roles (Option B) or replication (Option A), but CloudTrail's organization trail uses S3 bucket policies with the CloudTrail service principal, not IAM roles, to enable direct log delivery from all member accounts.

434
MCQmedium

A company is using AWS Organizations to manage multiple accounts. The security team requires that all newly created member accounts automatically have an AWS Config rule enabled that checks whether S3 buckets have default encryption enabled. Which solution should be used?

A.Use an SCP in the root to require encryption on S3 buckets.
B.Use AWS CloudFormation StackSets with automatic deployment to deploy the AWS Config rule across all accounts in the organization.
C.Create an AWS Config rule in the management account and delegate an admin account to apply it to all member accounts.
D.Configure AWS CloudTrail to automatically enable the AWS Config rule in new accounts.
AnswerB

StackSets with automatic deployment targets the organisation or OU, so the Config rule template is instantiated in each existing and newly created member account without manual intervention, satisfying the automatic enablement requirement for new accounts.

Why this answer

AWS CloudFormation StackSets with automatic deployment can deploy the AWS Config rule across all accounts in an AWS Organization, including newly created member accounts, by targeting the root organizational unit (OU). This ensures that the Config rule is automatically enabled in new accounts as they are created, meeting the security team's requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse SCPs (which only deny or allow actions) with actual configuration enforcement, or they assume CloudTrail can perform configuration actions, when in reality only automated deployment tools like CloudFormation StackSets can proactively enable Config rules in new accounts.

How to eliminate wrong answers

Option A is wrong because a Service Control Policy (SCP) can deny actions that disable encryption but cannot directly enable an AWS Config rule or enforce default encryption on existing S3 buckets; SCPs are permission boundaries, not configuration enforcement tools. Option C is wrong because while you can delegate an admin account for AWS Config, the management account cannot directly apply a Config rule to all member accounts automatically for new accounts; Config rules must be deployed via StackSets or similar automation to target new accounts. Option D is wrong because AWS CloudTrail does not have the capability to enable AWS Config rules; CloudTrail is for logging API activity, not for deploying or managing Config rules.

435
MCQeasy

A small business wants to host a simple static website on AWS. The website consists of HTML, CSS, JavaScript, and images. The company expects low traffic and wants to minimize costs. The website must be highly available and load quickly for users globally. Which solution should a Solutions Architect recommend?

A.Store the website files in an S3 bucket configured for static website hosting, and use Amazon CloudFront as a CDN.
B.Host the website on Amazon Lightsail with a load balancer and two instances.
C.Host the website on a single EC2 instance running Apache web server, with an Elastic IP address.
D.Deploy the website on AWS Elastic Beanstalk with a single EC2 instance.
AnswerA

S3 static website hosting serves the HTML, CSS, JavaScript and images without servers, and CloudFront caches content at edge locations for fast global delivery and high availability. This meets the low-traffic, minimal-cost, globally performant requirements.

Why this answer

S3 static website hosting with CloudFront provides low cost, high availability, and global low latency. Option B is wrong because Lightsail with a load balancer and two instances is more expensive and overkill for a simple static site. Option C is wrong because a single EC2 instance is not highly available and costs more than S3.

Option D is wrong because Elastic Beanstalk is designed for dynamic web apps, not static sites, and a single EC2 instance lacks high availability.

436
MCQmedium

A company is migrating 400 on-premises VMware virtual machines to AWS. The migration team wants to use the AWS Application Migration Service (AWS MGN) to replicate servers continuously to a staging area and then launch test and cutover instances. The company's security policy requires that all replicated data remain encrypted with customer-managed keys and that the replication traffic never traverse the public internet. The on-premises network is already connected to a VPC through an AWS Site-to-Site VPN. Which combination of actions should the migration team take to meet these requirements?

A.Deploy AWS MGN replication agents and configure them to replicate to an Amazon S3 bucket using AWS Snowball Edge devices for the initial seed, then rely on S3 default encryption with Amazon S3 managed keys.
B.Deploy AWS MGN replication agents and use AWS DataSync to copy VM disk images to Amazon FSx for Windows File Server in the target VPC, then launch cutover instances from the file share.
C.Deploy AWS MGN replication agents and configure the replication settings to use the public AWS MGN service endpoints; enable EBS encryption with the default AWS managed key to reduce operational overhead.
D.Deploy AWS MGN replication agents, create a staging Area subnet in the target VPC, and configure the replication settings to use the Site-to-Site VPN for data replication; specify a customer-managed AWS KMS key for EBS encryption.
AnswerD

AWS MGN replication agents stream block-level data over TCP port 1500 to replication servers in the staging Area subnet. Because the VPC is reachable over the Site-to-Site VPN, replication traffic stays off the public internet, and the staging Area subnet plus the EBS encryption key selected in the replication settings satisfy the customer-managed key requirement.

Why this answer

AWS MGN replicates source servers continuously to a staging Area subnet using replication agents and lightweight replication servers, and the launch settings determine EBS encryption. Placing the staging Area subnet in the VPC reachable over the existing Site-to-Site VPN keeps replication traffic private, and selecting a customer-managed AWS KMS key in the replication template satisfies both encryption and key-ownership requirements without introducing unrelated services.

Exam trap

The trap here is assuming AWS MGN replicates through Amazon S3 or public endpoints by default, when it actually streams block data to replication servers in a staging Area subnet over TCP port 1500.

437
MCQmedium

A company is designing a new solution to securely store and manage secrets for applications running on AWS. The secrets include database credentials, API keys, and OAuth tokens. The solution must automatically rotate secrets and integrate with AWS services like Amazon RDS. Which AWS service should be used?

A.Store secrets in AWS Systems Manager Parameter Store with a SecureString parameter type.
B.Use AWS CloudHSM to store secrets as keys.
C.Use AWS Key Management Service (KMS) to store secrets as encrypted data keys.
D.Use AWS Secrets Manager to store secrets and configure automatic rotation.
AnswerD

AWS Secrets Manager natively performs scheduled rotation of database credentials, API keys and OAuth tokens via Lambda rotation functions, and integrates directly with Amazon RDS by updating both the secret and the database user's password. This satisfies the stem's mandatory automatic rotation and RDS integration requirements, which Systems Manager Parameter Store cannot provide.

Why this answer

AWS Secrets Manager is purpose-built for securely storing, managing, and automatically rotating secrets such as database credentials, API keys, and OAuth tokens. It provides native integration with Amazon RDS, enabling automatic rotation of RDS credentials without custom code, which directly meets the requirements for automatic rotation and AWS service integration.

Exam trap

The trap here is that candidates confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with AWS Secrets Manager (which is designed specifically for automatic secret rotation and deep AWS service integration), leading them to choose Parameter Store for its lower cost and familiarity.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store with SecureString does not support automatic rotation of secrets; it requires custom AWS Lambda functions or external processes to rotate secrets. Option B is wrong because AWS CloudHSM is a hardware security module for generating and storing cryptographic keys, not for managing application secrets like database credentials or API keys, and it lacks native rotation and RDS integration. Option C is wrong because AWS KMS is a key management service for creating and controlling encryption keys, not for storing secrets; it can encrypt data keys but does not provide secret storage, rotation, or direct RDS integration.

438
MCQhard

A company is designing a data lake on Amazon S3. The data is ingested from multiple sources and must be encrypted at rest using customer-managed keys. The company also needs to audit all access to the data lake. Which combination of services should be used?

A.Enable S3 bucket encryption with SSE-S3. Enable S3 server access logs.
B.Configure S3 bucket encryption with SSE-KMS using a customer-managed CMK. Enable AWS CloudTrail with data events for S3 and KMS.
C.Enable S3 default encryption with SSE-S3. Enable Amazon CloudWatch Logs for S3 access logging.
D.Use client-side encryption with a customer-managed key. Enable Amazon CloudWatch Logs for S3 access logs.
AnswerB

SSE-KMS with a customer-managed CMK satisfies the customer-managed key requirement, while CloudTrail data events capture object-level S3 access and KMS key usage. Together they provide encryption at rest plus the audit trail of all data lake access.

Why this answer

It uses SSE-KMS with a customer-managed CMK to meet the encryption-at-rest requirement with customer-controlled keys, and enables AWS CloudTrail with data events for both S3 and KMS to audit all access to the data lake. This combination provides granular auditing of every S3 object-level operation (e.g., GetObject, PutObject) and every KMS key usage (e.g., Decrypt, GenerateDataKey), which is essential for compliance and security monitoring.

Exam trap

The trap here is that candidates often confuse S3 server access logs (which are log files delivered to an S3 bucket) with CloudTrail data events, or assume SSE-S3 meets the 'customer-managed keys' requirement because it is a form of server-side encryption, but SSE-S3 uses AWS-owned keys, not customer-managed ones.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses AWS-managed keys, not customer-managed keys, and S3 server access logs are best-effort (delivered asynchronously) and do not capture KMS key usage, failing both the encryption and audit requirements. Option C is wrong because SSE-S3 again uses AWS-managed keys, and Amazon CloudWatch Logs for S3 access logging is not a native S3 feature; S3 access logs are delivered to S3, not directly to CloudWatch Logs, and they lack KMS audit trails. Option D is wrong because client-side encryption requires the customer to manage encryption/decryption in their application, which adds complexity and does not leverage S3's native encryption at rest; also, CloudWatch Logs for S3 access logs is not a standard S3 audit mechanism and does not capture KMS data events.

439
MCQmedium

A company is migrating a multi-tier web application to AWS. The application uses sticky sessions (session affinity). The company wants to use an Application Load Balancer (ALB). How should the architect configure the ALB to support sticky sessions?

A.Configure the ALB listener to use a custom header for session affinity.
B.Enable stickiness on the target group and set a cookie expiration duration.
C.Use a Network Load Balancer (NLB) and enable proxy protocol.
D.Place an Amazon ElastiCache cluster in front of the ALB to store session data.
AnswerB

Enabling stickiness at the target group level makes the ALB generate a duration-based cookie (AWSALB), binding each client to a single target for the configured period. This satisfies the session affinity constraint, since ALB stickiness is configured on the target group, not the listener, and the expiration duration controls how long that binding persists.

Why this answer

For an Application Load Balancer (ALB) to support sticky sessions, you enable stickiness at the target group level and configure a cookie expiration duration. ALB uses a load balancer-generated cookie (AWSALB) to track session affinity, and the duration determines how long the cookie remains valid. This is the standard, supported method for session affinity on ALB.

Exam trap

SAP-C02 often tests whether candidates know that ALB stickiness is configured on the target group (not the listener) and that NLB does not support cookie-based stickiness — a common misconception is that NLB can do it with proxy protocol.

How to eliminate wrong answers

Option A is wrong because ALB does not support custom headers for session affinity — stickiness is cookie-based, and you cannot configure a custom header for this purpose. Option C is wrong because NLB does not support sticky sessions natively (it operates at Layer 4 and does not inspect HTTP cookies); proxy protocol is for preserving client IP, not session affinity. Option D is wrong because placing ElastiCache in front of the ALB is not how you achieve sticky sessions — externalizing session state is a valid architectural pattern, but it does not configure the ALB for stickiness, and it adds unnecessary complexity.

440
MCQhard

A company has a multi-account AWS environment with a central shared services VPC and multiple workload VPCs connected via AWS Transit Gateway. The security team wants to inspect all traffic between workload VPCs using a centralized firewall appliance in the shared services VPC. They need to ensure that traffic is inspected without modifying the workload VPC route tables. What should they do?

A.Create a VPC peering connection between each workload VPC and the shared services VPC, and update the route tables in each workload VPC to point to the shared services VPC for inter-VPC traffic.
B.Configure AWS Transit Gateway route tables to send all inter-VPC traffic to the shared services VPC, and enable appliance mode on the Transit Gateway attachment for the shared services VPC.
C.Use AWS PrivateLink to create endpoint services in the shared services VPC for each workload VPC, and configure the workload VPCs to use these endpoints for inter-VPC communication.
D.Configure AWS Transit Gateway route tables to send all inter-VPC traffic to the shared services VPC, and disable appliance mode on the Transit Gateway attachment for the shared services VPC.
AnswerB

By configuring Transit Gateway route tables to direct traffic to the shared services VPC and enabling appliance mode on that attachment, traffic between workload VPCs will be routed through the firewall appliance. Appliance mode ensures that flow symmetry is maintained for stateful inspection, and workload VPC route tables do not need to be modified.

Why this answer

To inspect traffic between workload VPCs without modifying their route tables, you can use AWS Transit Gateway route tables to direct traffic to a central shared services VPC. Enabling appliance mode on the Transit Gateway attachment for the shared services VPC ensures that flow symmetry is maintained for stateful inspection. This solution is scalable and does not require changes to workload VPC route tables.

Exam trap

The trap here is overlooking the need for appliance mode on the Transit Gateway attachment to maintain flow symmetry for stateful inspection.

441
MCQhard

A company runs a critical workload on a fleet of Amazon EC2 instances behind an Application Load Balancer. The workload is latency-sensitive and the operations team wants to continuously improve performance without changing the application code. They have enabled detailed monitoring and AWS X-Ray tracing. Which solution will provide the MOST actionable, near-real-time insight into which downstream dependencies are causing increased response times?

A.Enable VPC Flow Logs on the instances' subnets and query the logs with Amazon Athena to find the slowest network flows.
B.Configure Amazon CloudWatch detailed monitoring for the EC2 instances and create dashboards for CPU and memory utilization.
C.Use AWS X-Ray service maps and trace analytics to identify latency contributions from downstream services and analyze response time distributions.
D.Enable AWS CloudTrail data events on the load balancer and analyze the logs with Amazon CloudWatch Logs Insights.
AnswerC

X-Ray service maps visualize each downstream call and segment latency, letting the team pinpoint which dependency adds the most time. Trace analytics aggregates response time distributions and error rates, so improvements can be prioritized without code changes. This directly satisfies near-real-time insight into downstream dependencies and is the intended use of X-Ray tracing already enabled.

Why this answer

X-Ray tracing already enabled in the environment produces service maps and trace analytics that attribute latency to specific downstream calls. This lets the team continuously identify and improve the slowest dependencies without modifying application code. Host-level metrics, flow logs, and API audit trails do not provide the needed request-level timing detail.

Exam trap

The trap here is assuming that infrastructure metrics or network flow logs can substitute for request-level tracing when the goal is to identify slow downstream dependencies.

442
MCQhard

A company is designing a multi-region active-active application using Amazon Route 53, Application Load Balancers, and Auto Scaling groups. They need to route users to the closest region with the lowest latency. Which routing policy should they use?

A.Latency routing
B.Weighted routing
C.Failover routing
D.Geolocation routing
AnswerA

Latency routing uses latency measurements between users and AWS Regions to direct each request to the Region with the lowest latency, matching the closest-region requirement. Weighted, failover and geolocation policies do not optimise for measured network latency.

Why this answer

(Latency routing) is correct because it routes users to the AWS region that provides the lowest latency, based on real-time latency measurements. This is ideal for multi-region active-active applications where users should be directed to the closest region. Option B (Weighted routing) distributes traffic based on assigned weights, not latency.

Option C (Failover routing) is used for active-passive disaster recovery. Option D (Geolocation routing) routes based on the geographic location of the user, not on actual network latency.

443
MCQmedium

A media company runs a video processing pipeline on AWS. Videos are uploaded to an S3 bucket, which triggers an AWS Lambda function that transcodes the video into multiple formats using FFmpeg. The transcoding job runs on the Lambda function with a 15-minute timeout. Recently, the company started receiving 4K videos that take more than 15 minutes to transcode. The Lambda function times out, and the video is not processed. The company wants to process these large videos without increasing the Lambda timeout and without rewriting the entire pipeline. What should the solutions architect do?

A.Replace the Lambda function with AWS Elemental MediaConvert job triggered by S3 events.
B.Increase the Lambda function memory to the maximum to improve performance and reduce processing time.
C.Use AWS Step Functions to call multiple Lambda functions in parallel to process chunks of the video.
D.Use a Lambda function with a larger ephemeral storage to handle the video file.
AnswerA

MediaConvert is a managed transcoding service handling large 4K files without Lambda's 15-minute limit. Triggering jobs from existing S3 events preserves the pipeline's entry point, so only the compute layer changes, satisfying the requirement to avoid rewriting the pipeline.

Why this answer

AWS Elemental MediaConvert is a managed, file-based video transcoding service designed for large-scale, long-running jobs that far exceed Lambda's 15-minute execution limit. It natively integrates with S3 (input/output buckets) and can be triggered by S3 event notifications via EventBridge or Lambda, so the existing upload-to-S3 pipeline is preserved with minimal changes. This directly solves the 4K transcoding timeout without increasing Lambda timeout or rewriting the pipeline.

Exam trap

SAP-C02 often tests whether candidates recognize that Lambda's 15-minute timeout is a hard, non-negotiable limit — tempting them to 'just add memory' or 'add storage' when the real fix is moving long-running work to a purpose-built service like MediaConvert, Fargate, or Batch.

How to eliminate wrong answers

Option B is wrong because increasing Lambda memory only scales CPU proportionally and cannot extend the hard 15-minute invocation timeout — a 4K job exceeding 15 minutes will still be killed. Option C is wrong because splitting a video into chunks and transcoding in parallel requires rewriting the pipeline logic, reassembling segments, and managing state — exactly what the question says to avoid, and Step Functions still invokes Lambda functions bounded by the 15-minute limit. Option D is wrong because ephemeral storage (/tmp, up to 10 GB) addresses disk space, not execution duration; the timeout remains 15 minutes regardless of storage size.

444
MCQeasy

A company uses AWS CloudFormation to deploy resources. The operations team notices that some stack updates fail due to resource conflicts. What is the BEST practice to minimize such failures?

A.Enable termination protection on the stack.
B.Use AWS CloudFormation change sets before updating the stack.
C.Use AWS CloudFormation nested stacks.
D.Use stack policies to protect critical resources.
AnswerB

Change sets generate a preview of proposed resource modifications by comparing the updated template against the deployed stack, exposing replacement or conflict-causing changes before execution. This satisfies the requirement to minimise failed updates, since the operations team can review and correct problematic resource alterations prior to committing the stack update.

Why this answer

Change sets let you preview exactly what CloudFormation will add, modify, or delete before executing the update, so you can catch resource conflicts, replacement issues, or unintended changes before they cause a failed stack update. This is the AWS-recommended best practice for minimizing update failures and understanding impact.

Exam trap

SAP-C02 often tests whether candidates confuse preventive controls (stack policies, termination protection) with diagnostic tools (change sets) — change sets are the right answer when the goal is to preview and avoid update conflicts, not to block changes.

How to eliminate wrong answers

Option A is wrong because termination protection only prevents accidental stack deletion — it has no effect on update failures caused by resource conflicts. Option C is wrong because nested stacks improve modularity and reuse but don't inherently prevent update conflicts; they can even complicate troubleshooting. Option D is wrong because stack policies protect specific resources from being updated or replaced, which can actually cause update failures rather than prevent them — they're a guardrail, not a conflict-avoidance tool.

445
Multi-Selecteasy

Which TWO AWS services can be used to monitor and troubleshoot network connectivity issues between EC2 instances? (Choose two.)

Select 2 answers
A.Amazon Inspector.
B.AWS CloudTrail.
C.AWS Config.
D.VPC Reachability Analyzer.
E.VPC Flow Logs.
AnswersD, E

VPC Reachability Analyzer performs static configuration analysis across ENIs, security groups, NACLs, route tables and gateways, tracing the exact hop where connectivity breaks without sending traffic. This satisfies the stem's troubleshooting requirement by pinpointing misconfigured components between EC2 instances, rather than merely reporting packet loss or flow logs.

Why this answer

VPC Reachability Analyzer (D) is correct because it performs static analysis of the VPC configuration and traces the path between a source and destination (such as two EC2 instances) to determine whether packets can reach the target, identifying blocking components like security groups, NACLs, route tables, and gateways. VPC Flow Logs (E) is correct because it captures IP traffic metadata (source/destination IP, ports, protocol, ACCEPT/REJECT) for ENIs, subnets, or VPCs, which is used to diagnose connectivity and traffic-filtering issues between EC2 instances. Amazon Inspector (A) is wrong because it is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not a connectivity troubleshooting tool.

AWS CloudTrail (B) is wrong because it records API activity and account actions for auditing, not packet-level or path-level network reachability. AWS Config (C) is wrong because it evaluates resource configuration compliance and changes over time, not live network connectivity between instances.

446
MCQhard

A financial services firm runs a latency-sensitive trading application across three AWS Regions. The application writes to an Amazon DynamoDB table in the primary Region and must be able to read and write locally in the other two Regions with single-digit-millisecond latency, while tolerating a full Region failure. The firm accepts eventual consistency across Regions but requires that no acknowledged write is ever lost. Which solution should a solutions architect recommend?

A.Replicate the table to each Region using AWS Database Migration Service with change data capture, and have the application write to the nearest Regional table.
B.Use Amazon Aurora Global Database with a writer in the primary Region and read replicas in the other Regions, and route writes to the primary writer endpoint.
C.Create a DynamoDB global table with multi-Region replication and configure the application to read and write to the local Regional replica.
D.Deploy the DynamoDB table in the primary Region and use DynamoDB Accelerator (DAX) clusters in each Region to serve local reads and writes.
AnswerC

DynamoDB global tables provide multi-Region, multi-active replication with local read and write latency in each Region, and last-writer-wins conflict resolution. Writes acknowledged in any Region are durable and replicated, and the table remains writable if one Region fails, satisfying the local-latency and Region-failure tolerance requirements while accepting eventual consistency.

Why this answer

Multi-active writes with local single-digit-millisecond latency in three Regions, tolerance of a Region outage, and no acknowledged-write loss point to DynamoDB global tables. Each Region holds a full replica that accepts reads and writes locally, and replication propagates changes asynchronously, so a failed Region does not stop the others from serving traffic.

Exam trap

The trap here is treating a read-accelerating cache such as DAX, or a single-writer relational engine, as if it could accept low-latency writes in every Region.

447
MCQhard

A financial services company is migrating a mainframe COBOL application to AWS. The application writes files to a VSAM dataset and is invoked by a CICS transaction manager. The company wants to preserve business logic with minimal rewrite while moving to a managed runtime. Which migration strategy and AWS service combination best meets these requirements?

A.Repurchase a SaaS core banking product and re-implement the COBOL business logic through the vendor's configuration tools
B.Rehost the application with AWS Application Migration Service (AWS MGN) to Amazon EC2 and keep the mainframe emulator on the instance
C.Replatform the COBOL application to AWS Lambda using a custom runtime that emulates CICS transaction semantics
D.Replatform the COBOL application with AWS Mainframe Modernization using the Blu Age automated refactoring pattern, deploying to a managed runtime environment
AnswerD

AWS Mainframe Modernization provides two patterns: automated refactoring with Blu Age, which transforms COBOL and related artifacts into modern Java-based applications, and replatforming with Micro Focus. The Blu Age pattern preserves business logic while producing code that runs on a managed AWS runtime, and it handles CICS and VSAM constructs as part of the transformation. This directly matches the goal of minimal rewrite with a managed runtime.

Why this answer

AWS Mainframe Modernization is purpose-built for moving mainframe workloads, offering automated refactoring with Blu Age and replatforming with Micro Focus. The Blu Age pattern transforms COBOL, CICS, and VSAM artifacts into modern code that runs on a managed runtime, which preserves business logic and minimizes rewrite. The other approaches either cannot replicate CICS transaction semantics, cannot replicate a mainframe LPAR, or abandon the existing logic entirely.

Exam trap

The trap here is treating AWS Lambda custom runtimes as a drop-in replacement for a CICS transaction manager, when they cannot emulate pseudo-conversational state or VSAM semantics.

448
Multi-Selecteasy

A company runs a web application on EC2 instances behind an ALB. They want to improve the security posture by implementing defense in depth. Which TWO measures should they implement? (Choose TWO.)

Select 2 answers
A.Store static assets in a public S3 bucket.
B.Place EC2 instances in public subnets for easier management.
C.Allow direct internet access to the EC2 instances.
D.Configure security groups to restrict traffic to only necessary ports.
E.Use AWS WAF to filter common web exploits.
AnswersD, E

Security groups act as stateful virtual firewalls at the instance level, permitting only required ports and protocols. Restricting inbound rules to necessary ports removes unnecessary exposure, forming one layer of defence in depth alongside load balancer and network controls.

Why this answer

Option D is correct because security groups act as stateful virtual firewalls at the instance/ENI level, and restricting inbound rules to only the ports and protocols the application actually needs (for example, 443 from the ALB's security group rather than 0.0.0.0/0) enforces least privilege and shrinks the attack surface as part of a defense-in-depth strategy. Option E is correct because AWS WAF integrates with the Application Load Balancer to inspect HTTP/HTTPS requests and block common web exploits such as SQL injection and cross-site scripting using managed rule groups, adding a layer of protection that security groups cannot provide since they only filter at L3/L4. Option A is not appropriate because a public S3 bucket exposes static assets to unauthenticated access and weakens, rather than strengthens, the security posture; static content should be served via CloudFront with an origin access control or kept private.

Option B is not appropriate because placing EC2 instances in public subnets gives them routable public IPs and needlessly exposes them to the internet; they should sit in private subnets behind the ALB. Option C is not appropriate because allowing direct internet access to the instances bypasses the ALB and WAF protections, contradicting the defense-in-depth goal.

Exam trap

SAP-C02 often tests the confusion between network-layer controls (security groups, NACLs) and application-layer controls (WAF), tempting candidates to pick redundant or exposure-increasing options instead of complementary layers.

449
MCQmedium

A company uses AWS Organizations and wants to allow certain accounts to use AWS Service Catalog for self-service provisioning. The IT team needs to control which products are available. Where should the product portfolio be shared?

A.Share the portfolio with the target accounts from the Service Catalog console
B.Use AWS CloudFormation StackSets to deploy products to each account
C.Use SCPs to allow specific accounts to use Service Catalog
D.Create IAM roles in the central account that developers can assume
AnswerA

Sharing the portfolio from the Service Catalog console uses AWS RAM to grant target accounts access to the exact products selected. This satisfies the IT team's need to control which products each account can self-provision.

Why this answer

AWS Service Catalog allows you to share a product portfolio directly with individual AWS accounts or organizational units (OUs) within AWS Organizations. By sharing the portfolio from the Service Catalog console, the IT team can control which products are available to specific accounts, enabling self-service provisioning while maintaining governance. This approach leverages Service Catalog's native portfolio sharing mechanism, which does not require additional infrastructure or cross-account IAM roles.

Exam trap

The trap here is that candidates often confuse AWS Service Catalog portfolio sharing with other cross-account mechanisms like CloudFormation StackSets or IAM roles, failing to recognize that Service Catalog's native sharing via RAM is the correct way to control product availability for self-service provisioning.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation StackSets are used to deploy infrastructure across multiple accounts and regions, but they do not provide a self-service catalog for end users to provision products on demand; they are an automation tool, not a governance mechanism for product availability. Option C is wrong because Service Control Policies (SCPs) are used to restrict permissions at the AWS Organizations level, but they cannot control which specific Service Catalog products are available to an account; SCPs only allow or deny actions on the Service Catalog API, not portfolio-level sharing. Option D is wrong because creating IAM roles in the central account for developers to assume does not directly control which Service Catalog products are available in target accounts; it only grants cross-account access, but the portfolio must still be shared with the target account for the products to appear in that account's Service Catalog.

450
MCQhard

A company runs a critical e-commerce platform on AWS. The application is deployed across multiple Availability Zones in a single region (us-east-1). The architecture includes an Application Load Balancer (ALB), an EC2 Auto Scaling group, and an Amazon RDS for MySQL Multi-AZ database. The application experiences periodic spikes in traffic, and the Auto Scaling group scales out successfully. However, during a recent traffic spike, the database CPU utilization reached 90%, causing increased latency and some database connection timeouts. The company needs to improve the database performance to handle the spikes without over-provisioning. The solutions architect must design a solution that reduces the load on the primary database instance and improves read scalability. The application is read-heavy, with a read-to-write ratio of 80:20. Which solution should the architect implement?

A.Implement an Amazon ElastiCache Redis cluster to cache frequent database queries.
B.Increase the DB instance class to a larger size and enable Multi-AZ with synchronous replication.
C.Migrate the database to Amazon DynamoDB and use DynamoDB Accelerator (DAX) for read performance.
D.Create one or more Amazon RDS Read Replicas in the same region and configure the application to route read queries to the read replica endpoint.
AnswerD

Read Replicas offload read traffic from the primary via asynchronous MySQL replication, directly addressing the 80:20 read-heavy ratio and the 90% primary CPU saturation. The application routes SELECT queries to the replica endpoint, restoring primary capacity for writes without over-provisioning.

Why this answer

Amazon RDS Read Replicas can offload read traffic from the primary instance, reducing CPU utilization. For a read-heavy workload (80:20), creating Read Replicas in the same region and routing read queries to them is the most effective solution to improve read scalability without over-provisioning the primary. Option D is correct.

Option A (ElastiCache) is more suited for caching but does not offload database reads directly; it requires significant application changes and may not handle all query patterns. Option B (scaling up instance class) has scaling limits and is less cost-effective; Multi-AZ is for high availability, not read scaling. Option C (DynamoDB) is a different database; migrating would be complex and unnecessary.

Page 5

Page 6 of 14

Page 7