Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 451–525

984 questions total · 14pages · All types, answers revealed

Page 6

Page 7 of 14

Page 8
451
MCQhard

A company has a multi-account AWS environment with a central network account and multiple workload accounts. They want to use AWS Transit Gateway to connect VPCs across accounts. The network team has created a Transit Gateway in the network account and shared it using AWS Resource Access Manager (RAM) with the workload accounts. The workload accounts have created VPC attachments to the Transit Gateway. However, traffic is not flowing between the VPCs. The route tables in the workload VPCs have routes pointing to the Transit Gateway. What is the most likely cause?

A.The Transit Gateway is in a different AWS account, so route propagation is not automatic.
B.The Transit Gateway route tables do not have routes for the attached VPCs.
C.The security groups in the workload VPCs are blocking traffic.
D.VPC flow logs are not enabled.
AnswerB

Attachment alone does not enable routing. The Transit Gateway's route table must contain routes associating each VPC attachment, otherwise packets arriving from one VPC have no path to the other attachments, even though the workload VPC route tables correctly target the gateway.

Why this answer

For traffic to flow between VPCs attached to a Transit Gateway, the Transit Gateway route tables must have routes for the attached VPC CIDRs. When a VPC is attached, a route to the VPC is not automatically added to the Transit Gateway route table unless route propagation is enabled or a static route is created. The most likely cause is that the Transit Gateway route tables lack routes for the attached VPCs, preventing traffic from being forwarded between them.

Exam trap

SAP-C02 often tests the shared responsibility of Transit Gateway routing, and candidates may assume that attaching a VPC automatically adds routes to the Transit Gateway route table, when in fact propagation or static routes are required.

How to eliminate wrong answers

Option A is wrong because route propagation in Transit Gateway route tables is not automatic regardless of account ownership; it must be enabled on the attachment, and cross-account sharing via RAM does not change that. Option C is wrong because security groups could block traffic, but the question states that route tables in the workload VPCs have routes pointing to the Transit Gateway, and the most fundamental issue is the missing Transit Gateway route table routes; security groups are a secondary check. Option D is wrong because VPC flow logs are for logging, not for enabling traffic flow; they have no impact on connectivity.

452
MCQmedium

A company has a microservices application running on Amazon ECS with the EC2 launch type. Each service runs as an ECS service with a desired count of 4 tasks across two Availability Zones. The operations team wants to reduce cost during predictable low-traffic nights while maintaining availability. They also want to ensure that a sudden traffic spike during the day does not cause outages. Which solution should a solutions architect recommend?

A.Configure ECS Service Auto Scaling with target tracking on CPU utilization, and schedule scaling actions to reduce the minimum capacity at night.
B.Deploy the services on AWS Fargate and use scheduled scaling to set the desired count to 2 at night and 8 during the day.
C.Create a second ECS cluster for night-time traffic and use Amazon Route 53 weighted routing to shift traffic between clusters.
D.Use AWS Auto Scaling to scale the EC2 container instances in the cluster based on CPU, and set the ECS service desired count to a fixed value of 4.
AnswerA

ECS Service Auto Scaling supports target tracking on metrics like CPU utilization and scheduled scaling actions. A scheduled action can lower the minimum task count at night, while target tracking scales out quickly during a daytime spike. This combination reduces cost during predictable low traffic and maintains availability during demand surges, meeting both requirements.

Why this answer

ECS Service Auto Scaling with target tracking plus scheduled scaling actions directly adjusts task count based on demand and predictable schedules. This reduces cost at night and scales out during spikes. Scaling only the EC2 instances, migrating to Fargate, or using multiple clusters do not provide the required responsive task-level scaling.

Exam trap

The trap here is confusing EC2 Auto Scaling of container instances with ECS Service Auto Scaling, assuming that adding instances automatically adjusts the number of running tasks.

453
Multi-Selecthard

A company is expanding its AWS Organizations environment to include several new business units. The security team must ensure that all new accounts automatically have a baseline security configuration, including a VPC with specific flow logs enabled, an AWS Config recorder, and a set of IAM roles for cross-account access. They want to minimize manual effort and ensure consistency. Which two solutions should they use to achieve these goals? (Choose two.)

Select 2 answers
A.Use AWS Systems Manager Automation to run a runbook that configures each new account after creation.
B.Use AWS Control Tower to set up a landing zone and apply mandatory guardrails to new accounts.
C.Use AWS CloudFormation StackSets to deploy a baseline template to all accounts in the organization.
D.Use AWS Service Catalog to create a portfolio of baseline products and share it with all accounts.
E.Use AWS Config conformance packs to deploy baseline configurations across all accounts.
AnswersB, C

AWS Control Tower provides a landing zone with preconfigured blueprints, including VPCs with flow logs, AWS Config recorders, and IAM roles for cross-account access. It automates account provisioning and applies guardrails to ensure compliance. This reduces manual effort and ensures consistency across new accounts, directly meeting the baseline security requirements.

Why this answer

AWS Control Tower automates the setup of a secure landing zone with preconfigured baselines and guardrails, while CloudFormation StackSets deploy resource templates across accounts and automatically target new accounts. Together, they provide automated, consistent baseline security configurations with minimal manual effort, meeting the requirements for VPC flow logs, Config recorders, and IAM roles.

Exam trap

The trap here is confusing services that assess compliance (Config conformance packs) or require manual provisioning (Service Catalog) with those that automatically deploy and enforce baseline configurations.

454
MCQeasy

A company wants to centralize management of AWS resources across multiple accounts using AWS Control Tower. What is a prerequisite for setting up Control Tower?

A.A pre-configured landing zone.
B.An AWS Organizations management account.
C.At least three organizational units (OUs).
D.Existing AWS Config rules in all accounts.
AnswerB

Control Tower is built on AWS Organizations and provisions its landing zone from the organisation's management account, which must exist and have all features enabled. Without that management account, Control Tower cannot create organisational units, accounts or guardrails.

Why this answer

AWS Control Tower requires an AWS Organizations management account because Control Tower uses Organizations to create and manage accounts, apply service control policies (SCPs), and enforce guardrails across the organization. The management account serves as the central point for all administrative actions, and without it, Control Tower cannot establish the necessary multi-account structure or landing zone.

Exam trap

The trap here is that candidates often confuse the prerequisite of an existing AWS Organizations management account with the need for a pre-configured landing zone, mistakenly thinking Control Tower requires an already-built environment rather than building it itself.

How to eliminate wrong answers

Option A is wrong because a pre-configured landing zone is not a prerequisite; Control Tower itself sets up the landing zone as part of its initial configuration. Option C is wrong because Control Tower does not require at least three organizational units (OUs); it creates a default OU structure (e.g., Security, Sandbox) but the minimum is one OU, and you can add more later. Option D is wrong because existing AWS Config rules in all accounts are not a prerequisite; Control Tower deploys and manages Config rules as part of its guardrails, and pre-existing rules could conflict with Control Tower's managed rules.

455
MCQmedium

A company is using Amazon RDS for MySQL and notices that read replicas are falling behind the primary. The primary instance is experiencing high write traffic. What is the best solution to reduce replica lag?

A.Increase the instance class of the read replica.
B.Enable Multi-AZ on the primary instance.
C.Disable binary logging on the primary.
D.Move the read replica to the same AWS Region as the primary.
AnswerA

Replica lag under high write traffic often stems from the replica's insufficient compute to apply the primary's binary log changes. Increasing the read replica's instance class gives it more CPU and memory to replay writes faster, reducing lag.

Why this answer

Read replica lag under high write traffic on the primary is most often caused by the replica's inability to apply the relay log fast enough — i.e., insufficient CPU/IOPS on the replica itself. Increasing the replica instance class gives it more vCPU, memory, and baseline EBS throughput, allowing the SQL thread to apply binlog events faster and close the gap. This directly addresses the bottleneck (replica apply capacity) without touching the primary's write path.

Exam trap

SAP-C02 often tests the misconception that Multi-AZ or Region placement affects read replica performance, when in fact replica lag is a function of the replica's own compute/IO capacity and the primary's write volume.

How to eliminate wrong answers

Option B is wrong because Multi-AZ creates a synchronous standby in a different AZ for failover only — the standby does not serve reads and has zero effect on read replica lag. Option C is wrong because disabling binary logging on the primary breaks replication entirely (replicas rely on the binlog stream) and would also break point-in-time recovery; it is never a valid lag fix. Option D is wrong because cross-Region replicas are not inherently slower than same-Region ones for apply throughput — the lag is driven by replica resources and write volume, not geography, and moving the replica does not add CPU or IOPS.

456
MCQhard

A company is migrating a critical application from on-premises to AWS. The application uses a Microsoft SQL Server database with Always On Availability Groups for high availability. The company wants to use Amazon RDS for SQL Server to reduce management overhead. The database size is 500 GB. The migration must have minimal downtime and support transactional consistency. The company has a VPN connection to AWS. Which migration strategy should the company use?

A.Use AWS DMS with a full-load migration and ongoing replication from the on-premises SQL Server to RDS for SQL Server.
B.Take a full backup of the database, restore it to RDS, and then schedule a final backup and restore after cutting over.
C.Use the SQL Server Import/Export Wizard to copy data from on-premises to RDS over the VPN.
D.Use AWS SCT to convert the database schema and then use AWS DMS for data migration.
AnswerA

AWS DMS full-load plus ongoing replication reads the transaction log of the on-premises SQL Server and applies changes continuously to RDS, so the cutover window stays short. This satisfies the minimal-downtime and transactional-consistency constraints for the 500 GB Always On database, with change data capture handled over the existing VPN.

Why this answer

AWS DMS with full-load plus ongoing replication (CDC) is the standard approach for migrating SQL Server to RDS with minimal downtime and transactional consistency. DMS performs an initial bulk load and then continuously replicates ongoing changes from the source to the target, allowing cutover with minimal downtime. It supports SQL Server Always On Availability Groups as a source by connecting to the listener, and it maintains transactional consistency.

Exam trap

The trap is underestimating downtime for backup/restore or overestimating the need for schema conversion; candidates must recognize that homogeneous migrations (SQL Server to SQL Server) do not require SCT and that minimal downtime demands CDC.

How to eliminate wrong answers

Option B is wrong because backup and restore requires downtime during the final backup/restore window and does not provide continuous replication, so it cannot meet the minimal downtime requirement. Option C is wrong because the Import/Export Wizard is a manual, offline process that does not support ongoing replication and would cause significant downtime. Option D is wrong because AWS SCT is for schema conversion between different database engines (e.g., Oracle to PostgreSQL); since both source and target are SQL Server, no schema conversion is needed, and SCT alone does not handle data replication.

457
MCQmedium

A company is using Amazon CloudFront with an S3 origin. They notice that users are receiving outdated content. What configuration change should be made to ensure users always get the latest content?

A.Use signed URLs to serve content.
B.Create an invalidation for the objects.
C.Enable compression on the S3 bucket.
D.Reduce the TTL to 0 in the CloudFront distribution.
AnswerB

An invalidation removes cached objects from CloudFront edge locations before their TTL expires, forcing subsequent requests to fetch the current version from the S3 origin. This satisfies the stem's requirement that users always receive the latest content.

Why this answer

CloudFront caches objects at edge locations based on the origin's cache headers and the distribution's TTL settings. When content at the S3 origin is updated but the cached object has not yet expired, users continue to receive the stale version. Creating an invalidation explicitly removes the specified objects from all edge caches, forcing CloudFront to fetch the fresh version from S3 on the next request.

This is the standard, immediate remediation for serving outdated content.

Exam trap

The trap here is confusing access control mechanisms (signed URLs) or performance tuning (compression, TTL) with cache invalidation, when the actual problem is stale cached content at the edge.

How to eliminate wrong answers

Option A is wrong because signed URLs only control access/authorization to content; they do not affect cache freshness or force CloudFront to re-fetch updated objects. Option C is wrong because compression reduces payload size for transfer efficiency and has no bearing on cache staleness or object versioning. Option D is wrong because setting TTL to 0 disables caching benefits entirely and is a blunt, performance-degrading workaround rather than a targeted fix; it also does not guarantee immediate refresh of already-cached objects the way an invalidation does.

458
MCQhard

A company is migrating a monolithic application to microservices on AWS. The application uses a shared MySQL database. The team wants to decouple the database per microservice. Which strategy should the team use to minimize downtime during migration?

A.Rehost the application on EC2 and use a single RDS MySQL instance for all microservices.
B.Use the strangler fig pattern to gradually migrate functionality to microservices, each with its own database.
C.Use AWS Database Migration Service (DMS) to replicate the shared database to multiple target databases in real time.
D.Rewrite the entire application as microservices in a single release, using a shared database initially.
AnswerB

The strangler fig pattern incrementally routes functionality from the monolith to microservices, each owning its own database, so the shared MySQL schema is decomposed gradually rather than in one cutover. This satisfies the minimal-downtime constraint, since the monolith keeps serving traffic throughout and can be retired once migration completes.

Why this answer

The strangler fig pattern allows incremental migration of functionality from a monolith to microservices, each with its own database, while the monolith continues to operate. This minimizes downtime because changes are gradual and can be rolled back. By decoupling databases per microservice over time, the team avoids a big-bang rewrite and can manage data migration carefully.

Exam trap

The trap is equating database replication with decoupling; candidates may choose DMS because it sounds like a migration tool, but it does not achieve the architectural goal of per-service databases with minimal downtime.

How to eliminate wrong answers

Option A is wrong because rehosting on EC2 with a single RDS instance does not decouple the database per microservice; it maintains the shared database, which is the opposite of the goal. Option C is wrong because using DMS to replicate the shared database to multiple targets in real time does not address the architectural decoupling; it may create data consistency issues and does not minimize downtime during the migration of functionality. Option D is wrong because rewriting the entire application in a single release is risky and likely to cause significant downtime, and using a shared database initially does not achieve decoupling.

459
MCQhard

A company is running a production web application on AWS using an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application uses a MySQL database hosted on Amazon RDS with Multi-AZ enabled. Recently, during a traffic spike, some users experienced increased latency and occasional 503 errors. The operations team noticed that the database CPU utilization reached 100% and the number of database connections peaked at the maximum limit. The application team confirmed that the application uses connection pooling on the EC2 instances but the pool size is fixed. Which solution should the solutions architect recommend to prevent recurrence?

A.Add read replicas to offload read queries.
B.Increase the DB instance class to a larger size.
C.Implement Amazon RDS Proxy to manage database connections.
D.Increase the maximum number of EC2 instances in the Auto Scaling group.
AnswerC

Amazon RDS Proxy pools and shares database connections, absorbing traffic spikes so the fixed application-side pools no longer exhaust the RDS connection limit. This relieves the 100% CPU and connection ceiling causing latency and 503 errors.

Why this answer

The issue stems from database connections hitting the maximum limit, causing CPU saturation and 503 errors. Amazon RDS Proxy sits between the application and the database, efficiently managing and pooling connections from the EC2 instances, reducing the number of open connections to the RDS instance and preventing connection exhaustion. This allows the existing connection pooling on the EC2 side to scale without overwhelming the database, directly addressing the root cause.

Exam trap

The trap here is that candidates often confuse connection exhaustion with CPU or memory bottlenecks and choose vertical scaling (Option B) or read replicas (Option A), missing that the core issue is the fixed connection pool size and the database's max connections limit, which RDS Proxy directly addresses by pooling and reusing connections.

How to eliminate wrong answers

Option A is wrong because adding read replicas offloads read queries but does not reduce the number of database connections hitting the primary instance; the connection limit and CPU spike from connection overhead remain. Option B is wrong because increasing the DB instance class provides more CPU and memory but does not solve the connection limit issue; the application will still exhaust the max connections, and scaling vertically is a temporary fix that increases cost without addressing the architectural bottleneck. Option D is wrong because increasing the maximum number of EC2 instances in the Auto Scaling group would increase the number of application servers, each with a fixed connection pool, potentially worsening the connection exhaustion and CPU spike on the database.

460
Multi-Selecteasy

A company is designing a new web application that will run on Amazon EC2 instances behind an Application Load Balancer. The application must be highly available across multiple Availability Zones. Which TWO actions should the architect take? (Choose TWO.)

Select 2 answers
A.Launch all EC2 instances in a single Availability Zone.
B.Configure the ALB as internet-facing and attach it to multiple Availability Zones.
C.Launch EC2 instances in at least two Availability Zones.
D.Use a Network Load Balancer instead of an Application Load Balancer.
E.Assign Elastic IP addresses to each EC2 instance.
AnswersB, C

An internet-facing ALB distributes client traffic and, when attached to multiple Availability Zones, its nodes reside in each of those zones. This removes the load balancer as a single point of failure, satisfying the multi-AZ high availability requirement for the web tier.

Why this answer

Option B is correct because an internet-facing Application Load Balancer must be attached to subnets in multiple Availability Zones so it can distribute incoming traffic across those zones and remain resilient if one AZ fails. Option C is correct because the EC2 instances themselves must be launched in at least two Availability Zones; an ALB can only route to targets in the AZs it is enabled for, so placing instances in multiple AZs is what actually makes the application highly available. Option A is wrong because confining all instances to a single AZ creates a single point of failure and defeats the multi-AZ requirement.

Option D is wrong because the scenario specifies an Application Load Balancer for a web application, and swapping to an NLB is neither required nor appropriate for HTTP/HTTPS layer-7 routing. Option E is wrong because Elastic IP addresses are not needed for instances behind an ALB; the ALB's nodes handle public addressing, and EIPs do not provide multi-AZ high availability.

Exam trap

The trap here is that candidates may think launching instances in a single AZ is sufficient if the ALB is configured across multiple AZs, but the ALB requires healthy targets in each enabled AZ to maintain high availability; without instances in at least two AZs, the ALB cannot route traffic if the sole AZ fails.

461
MCQmedium

A developer notices that CloudWatch Logs for a Lambda function show no logs after a recent deployment. The function is invoked successfully. What is the most likely cause?

A.The Lambda function is exceeding the CloudWatch Logs API rate limits.
B.The Lambda execution role does not have permissions to write to CloudWatch Logs.
C.The log group retention policy is set to 7 days, which expired old logs.
D.The log group was deleted and not recreated.
AnswerB

Lambda writes logs to CloudWatch Logs using its execution role's permissions. If that role lacks logs:CreateLogStream and logs:PutLogEvents, invocations succeed but emit nothing. This directly explains the stem's constraint: successful invocations with no log output after deployment.

Why this answer

Lambda writes logs to CloudWatch Logs using the function's execution role. If that role lacks logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents permissions, invocations succeed but no log events appear. This is the most common cause of silent logging after a deployment that changed IAM roles.

Exam trap

The trap is assuming that a successful invocation implies logging works; candidates forget that logging is a separate IAM-authorized API call that can fail independently of the function's business logic.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs API rate limits would produce throttling errors in the function's response or in CloudWatch metrics, not a complete absence of logs. Option C is wrong because a 7-day retention policy only deletes logs older than 7 days; it does not prevent new logs from being written. Option D is wrong because if the log group were deleted, Lambda would recreate it automatically on the next invocation (assuming the role has CreateLogGroup permission), so logs would still appear.

462
MCQeasy

A company uses AWS Organizations with a single OU for all accounts. The security team wants to prevent any account from leaving the organization without approval. What should they do?

A.Configure IAM policies on the root user of each account to deny leave actions.
B.Create an AWS Config rule to detect leave attempts.
C.Enable AWS CloudTrail to monitor leave events and send alerts.
D.Apply an SCP that denies the organizations:LeaveOrganization action.
AnswerD

Service control policies set the maximum available permissions for member accounts, and applying one that denies organizations:LeaveOrganization blocks the API call from every principal in the OU, including the account's own root user, satisfying the requirement that no account can depart without approval.

Why this answer

A Service Control Policy (SCP) applied at the root or OU level in AWS Organizations can explicitly deny the `organizations:LeaveOrganization` action for all member accounts. SCPs are the only mechanism that can centrally restrict what actions accounts can perform, including leaving the organization, regardless of the permissions granted by IAM policies within those accounts.

Exam trap

The trap here is that candidates often confuse IAM policies with SCPs, thinking IAM can restrict root user actions, or they choose detective controls (Config or CloudTrail) instead of the preventive SCP that actually blocks the action.

How to eliminate wrong answers

Option A is wrong because IAM policies attached to the root user of each account cannot prevent the account from leaving the organization; the root user has full administrative access that overrides IAM policies, and the LeaveOrganization action is controlled by Organizations, not IAM. Option B is wrong because an AWS Config rule can only detect noncompliant resources or actions after they occur, but it cannot prevent the leave action from succeeding; by the time the rule triggers, the account may have already left. Option C is wrong because AWS CloudTrail logs events after they happen, so it can only provide visibility into a leave event after it has occurred, not block it proactively.

463
MCQmedium

A company is migrating a legacy on-premises application to AWS. The application uses a shared file system that must be accessible from multiple Linux-based Amazon EC2 instances simultaneously. The application requires a POSIX-compliant file system with high throughput and low latency. The company wants a fully managed, scalable solution that can grow to petabytes. What should a solutions architect recommend?

A.Amazon FSx for Lustre
B.Amazon S3 with s3fs-fuse mounted on each EC2 instance
C.Amazon FSx for Windows File Server
D.Amazon Elastic File System (Amazon EFS)
AnswerD

Amazon EFS is a fully managed, scalable, POSIX-compliant file system for Linux workloads. It supports concurrent access from multiple EC2 instances and scales automatically to petabytes. It provides high throughput and low latency with the appropriate performance mode. This meets all the requirements without managing infrastructure.

Why this answer

Amazon EFS is a fully managed, elastic file system that supports the POSIX interface and can be mounted on multiple Linux EC2 instances concurrently. It scales automatically to petabytes and offers high throughput and low latency. It requires no infrastructure management, making it the ideal choice for a shared file system for Linux workloads.

Exam trap

The trap here is assuming that Amazon S3 mounted via s3fs is a suitable replacement for a POSIX file system, when it is not POSIX-compliant and has performance drawbacks.

464
MCQeasy

A startup is deploying a web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in an Amazon DynamoDB table. To improve performance, the team wants to reduce latency for read-heavy workloads. Which design change would be MOST effective?

A.Add an Amazon ElastiCache Redis cluster in front of DynamoDB to cache session data.
B.Use an Auto Scaling group to add more EC2 instances during peak hours.
C.Enable DynamoDB Accelerator (DAX) for the session table.
D.Increase the size of the EC2 instances to handle more concurrent users.
AnswerC

DAX provides an in-memory write-through cache for DynamoDB, serving repeated session reads in microseconds and cutting latency for read-heavy workloads. It satisfies the performance constraint directly, unlike increasing capacity or adding read replicas, which address throughput rather than microsecond read latency.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache specifically designed for Amazon DynamoDB. It reduces read latency from single-digit milliseconds to microseconds by caching frequently accessed items, making it ideal for read-heavy session state workloads without requiring application-level cache management.

Exam trap

The trap here is that candidates often choose ElastiCache Redis (Option A) because it is a general-purpose cache, but they overlook that DAX is purpose-built for DynamoDB and eliminates the need for custom cache invalidation logic, making it the most effective and operationally simpler choice for this specific use case.

How to eliminate wrong answers

Option A is wrong because adding an ElastiCache Redis cluster in front of DynamoDB introduces operational complexity and potential data inconsistency between the cache and the database, whereas DAX provides a native, write-through cache that automatically synchronizes with DynamoDB. Option B is wrong because scaling EC2 instances with Auto Scaling addresses compute capacity, not the latency of reading session data from DynamoDB; the bottleneck is database read performance, not application server throughput. Option D is wrong because increasing EC2 instance size improves compute and memory capacity but does not reduce the latency of DynamoDB read operations; the session state is stored externally, so larger instances do not accelerate database access.

465
MCQmedium

A company is designing a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application experiences sudden spikes in traffic. Which AWS service should be used to handle the traffic spikes without losing any requests?

A.Amazon SNS
B.AWS Step Functions
C.Amazon SQS
D.Amazon Kinesis Data Streams
AnswerC

Amazon SQS decouples API Gateway from Lambda, buffering burst traffic in a durable queue so no requests are lost during spikes. Lambda's concurrency limits would otherwise throttle or drop invocations; SQS absorbs the surge and enables downstream retry processing.

Why this answer

Amazon SQS is a fully managed message queuing service that decouples application components and buffers requests during traffic spikes. By placing an SQS queue between API Gateway and Lambda (or between Lambda and DynamoDB), the system can absorb sudden bursts of traffic without losing requests, as messages are durably stored until processed. This is the standard pattern for handling spiky serverless workloads.

Exam trap

SAP-C02 often tests the confusion between SNS (push, no buffering) and SQS (pull, buffering), causing candidates to pick SNS when the requirement is to avoid losing requests during spikes.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub notification service that pushes messages to subscribers; it does not buffer or retain messages for later processing, so requests can be lost if subscribers cannot keep up. Option B is wrong because AWS Step Functions orchestrates workflows but does not provide a durable buffer for high-volume request spikes; it is designed for coordinating stateful workflows, not for queuing. Option D is wrong because Amazon Kinesis Data Streams is designed for real-time streaming analytics with ordered records and retention, but it requires provisioned shards and is not the simplest or most appropriate buffer for decoupling a serverless application; SQS is the canonical choice for request buffering.

466
MCQmedium

A company runs a nightly batch job on a single Amazon EC2 instance that reads 2 TB of data from Amazon S3, transforms it, and writes results back to S3. The job currently takes 9 hours and must finish within a 4-hour maintenance window. The instance is a compute-optimized type with 10 Gbps network bandwidth, and CloudWatch shows the CPU is never above 35%. Which change should a solutions architect make to shorten the runtime?

A.Move the job to an AWS Lambda function with 10 GB of memory and a 15-minute timeout.
B.Change the instance type to a larger compute-optimized size with 25 Gbps network bandwidth and keep the single-instance design.
C.Redesign the job to process data in parallel across multiple EC2 instances using S3 multipart uploads and range-based GET requests.
D.Enable S3 Transfer Acceleration on the bucket and rerun the job unchanged on the same instance.
AnswerC

The instance is CPU-idle and network-bound, so the bottleneck is throughput to and from S3 rather than compute. Partitioning the dataset and processing shards concurrently across several instances multiplies aggregate bandwidth, and range-based GETs plus multipart uploads make full use of each instance's network path. This directly attacks the real constraint and can bring a 9-hour job within the 4-hour window.

Why this answer

Low CPU utilization with high data volume points to a network and concurrency bottleneck rather than insufficient compute. Sharding the dataset and processing shards concurrently across multiple instances multiplies aggregate S3 bandwidth, and range-based GETs with multipart uploads let each worker fully use its network path. Vertical scaling and Transfer Acceleration leave the sequential processing model intact.

Exam trap

The trap here is reading 10 Gbps network bandwidth and assuming the instance is already network-saturated, when a single sequential reader rarely achieves that ceiling without concurrent requests.

467
Multi-Selecthard

A company is migrating a legacy application to AWS. The application requires static IP addresses for whitelisting by third-party APIs. The company plans to use an Application Load Balancer with EC2 instances. Which two steps should the company take to ensure the ALB has a consistent set of IP addresses? (Choose TWO.)

Select 2 answers
A.Use a NAT Gateway with Elastic IPs for outbound traffic.
B.Place a Network Load Balancer with Elastic IP addresses in front of the ALB.
C.Use Amazon Route 53 with an A record pointing to the ALB.
D.Place the ALB behind an AWS Global Accelerator.
E.Associate an AWS WAF web ACL with the ALB.
AnswersB, D

A Network Load Balancer supports Elastic IP addresses, giving static public IPs for third-party whitelisting. Placing it in front of the Application Load Balancer preserves the ALB's layer 7 routing while presenting fixed addresses, satisfying the static IP constraint.

Why this answer

Option B is correct because an Application Load Balancer does not support static IP addresses, but a Network Load Balancer can be assigned Elastic IP addresses per subnet; placing the NLB in front of the ALB gives third-party APIs a fixed set of IPs to whitelist while the NLB forwards traffic to the ALB. Option D is correct because AWS Global Accelerator provides two static anycast IP addresses that front the ALB, so third parties can whitelist those fixed IPs and traffic is routed to the ALB without the ALB itself needing static addresses. Option A is not correct because a NAT Gateway with Elastic IPs only affects outbound traffic from private subnets and does not provide static inbound IPs for an ALB.

Option C is not correct because a Route 53 A record resolves to the ALB's DNS name and its dynamic IP addresses, so it does not create a consistent static IP set. Option E is not correct because AWS WAF is a layer 7 filtering service and has no effect on the IP addresses used by the ALB.

Exam trap

The trap here is that candidates may think AWS WAF provides static IP addresses, but it does not. Additionally, they might overlook the NLB+Elastic IP approach as a valid method, or confuse NAT Gateway's outbound Elastic IPs with inbound static IPs.

468
Multi-Selecthard

A company uses Amazon DynamoDB for a gaming application. The table has a partition key of user_id and a sort key of timestamp. During a new game launch, the table experiences throttling on a few partitions. The company wants to improve the partition distribution. Which action should the company take?

Select 1 answer
A.Add a random suffix to the partition key to distribute writes more evenly.
B.Use DAX (DynamoDB Accelerator) to cache read-heavy workloads.
C.Increase the read capacity units for the table.
D.Implement write sharding by using a composite partition key.
E.Switch the table to on-demand capacity mode.
AnswersD

Write sharding spreads writes across multiple partition key values by appending a calculated suffix to the partition key, distributing load that a single hot partition would otherwise absorb. This directly improves partition distribution when many writes target the same user_id.

Why this answer

The root cause is a hot partition caused by low partition key cardinality: many writes land on the same user_id value. The correct fix is write sharding, which increases the number of distinct partition key values so writes spread across more physical partitions. Option D describes this correctly by using a composite partition key (e.g., user_id#shard).

Option A is not correct: appending a random suffix to the existing partition key changes the key schema and destroys the ability to query by user_id, and it is the same sharding concept as D rather than a separate remediation. B is incorrect because DAX only accelerates reads and does not relieve write-side hot partitions. C is incorrect because increasing RCUs adds read throughput and cannot fix write throttling on a hot partition.

E is incorrect because on-demand capacity mode changes billing/capacity management but does not change partition key distribution or eliminate hot partitions.

Exam trap

The trap is reaching for capacity or caching solutions (DAX, more RCUs, on-demand mode) when the real issue is partition key cardinality and distribution. The exam tests whether you diagnose the root cause (hot partition from low-cardinality key) rather than the symptom (throttling), and whether you recognize that write sharding and adding a random suffix to the partition key are the same technique rather than two independent actions.

469
MCQhard

A global company uses a multi-account AWS Organizations structure with hundreds of accounts. The network team wants to centrally manage VPC flow logs for all accounts and send them to a centralized S3 bucket in the security account. Which solution is MOST scalable and operationally efficient?

A.Use AWS Config to detect VPCs without flow logs and trigger a Lambda function to enable them.
B.Use CloudFormation StackSets to deploy a stack that enables VPC flow logs in every account and region, sending logs to a centralized S3 bucket with appropriate bucket policies.
C.Write a script that uses the AWS API to enable VPC flow logs in each account and region, triggered by AWS Config rules.
D.Set up a VPN connection from each account to the security account and configure flow logs to use a S3 endpoint in the security account.
AnswerB

StackSets deploys the flow-log stack across every account and region from a single administration, using service-managed permissions so new accounts inherit it automatically. This satisfies the hundreds-of-accounts scale constraint, unlike per-account scripting, and centralises delivery to the security account's S3 bucket.

Why this answer

CloudFormation StackSets allow you to deploy a single CloudFormation template across multiple accounts and regions in an AWS Organization, making it the most scalable and operationally efficient solution for centrally enabling VPC Flow Logs. By including the appropriate S3 bucket policy in the security account, you can ensure logs from all accounts are delivered to a centralized bucket without manual intervention.

Exam trap

The trap here is that candidates often overcomplicate the solution by considering VPNs or custom scripts, when the most scalable and operationally efficient approach is to use CloudFormation StackSets with a service-managed permission model to deploy a standardized stack across the entire organization.

How to eliminate wrong answers

Option A is wrong because AWS Config can detect non-compliant VPCs, but relying on a Lambda function to enable flow logs introduces a single point of failure and is less scalable than a declarative, infrastructure-as-code approach like StackSets. Option C is wrong because writing a custom script that uses the AWS API to enable flow logs in each account and region is error-prone, requires ongoing maintenance, and does not provide the same level of consistency and rollback capabilities as StackSets. Option D is wrong because setting up a VPN connection from each account to the security account is unnecessary and adds significant complexity and cost; VPC Flow Logs can be delivered directly to a centralized S3 bucket using a bucket policy that grants cross-account access, without requiring network connectivity.

470
MCQhard

An IAM policy attached to a user allows s3:GetObject and s3:PutObject on my-bucket, but denies all actions on the confidential/ prefix. The user reports that they can still upload objects to the confidential/ folder. Why?

A.The Allow statement appears before the Deny statement in the policy.
B.The Deny statement is not explicit enough to override the Allow.
C.The Deny statement is in a separate policy that is not attached to the user.
D.The Deny statement's resource ARN does not match the confidential folder objects.
AnswerC

An explicit Deny only takes effect when the policy containing it is attached to the principal. Because that policy is unattached, the Allow in the attached policy governs, so s3:PutObject on the confidential/ prefix succeeds despite the intended restriction.

Why this answer

In AWS IAM, an explicit Deny only takes effect if the policy containing it is actually attached to the principal (user, group, or role). If the Deny statement lives in a separate policy that was never attached to the user, IAM evaluates only the attached policies — the Allow for s3:PutObject on my-bucket therefore grants access to the confidential/ prefix. The fix is to attach the policy containing the Deny to the user (or a group the user belongs to).

Exam trap

SAP-C02 often tests the misconception that an explicit Deny anywhere in the account automatically applies, when in fact the Deny must be in a policy that is actually attached to the principal to be evaluated.

How to eliminate wrong answers

Option A is wrong because IAM does not evaluate statements by order of appearance — all statements in all attached policies are evaluated together with explicit Deny always winning regardless of position. Option B is wrong because an explicit Deny does override an Allow in IAM; the issue is not the strength of the Deny but whether it is attached at all. Option D is wrong because the question states the Deny targets the confidential/ prefix, and even if the ARN were slightly off, the primary reported symptom (uploads still succeeding) is explained by the policy not being attached, not by ARN mismatch.

471
MCQmedium

A company uses Amazon S3 to store backups. The backup process uploads objects with a prefix 'backups/' and sets the storage class to STANDARD_IA. The company wants to automatically move objects older than 30 days to GLACIER. What is the most efficient way to achieve this?

A.Use an AWS Lambda function triggered by S3 events to change the storage class.
B.Use S3 Batch Operations to copy objects to a new bucket with GLACIER storage class.
C.Create an S3 Lifecycle rule that transitions objects with prefix 'backups/' to GLACIER after 30 days.
D.Enable S3 Intelligent-Tiering on the bucket.
AnswerC

S3 Lifecycle rules natively transition objects between storage classes based on age, so a rule scoped to the 'backups/' prefix moves them to GLACIER after 30 days without custom code or manual intervention. This is the most efficient mechanism for the stated transition.

Why this answer

S3 Lifecycle rules are designed to automatically transition objects between storage classes based on age and prefix. Creating a rule that targets the 'backups/' prefix and transitions objects to GLACIER after 30 days is the most efficient, server-side, and cost-effective method. It requires no custom code or manual intervention.

Exam trap

SAP-C02 often tests the difference between lifecycle policies and Intelligent-Tiering, and candidates may choose Intelligent-Tiering thinking it moves data to GLACIER, but it only moves between frequent and infrequent access tiers.

How to eliminate wrong answers

Option A is wrong because using Lambda to change storage class is inefficient, requires custom code, and incurs Lambda execution costs; lifecycle rules are native and simpler. Option B is wrong because S3 Batch Operations is for one-time bulk actions, not automated ongoing transitions. Option D is wrong because Intelligent-Tiering automatically moves data between access tiers but does not transition to GLACIER; it is for unknown or changing access patterns, not a fixed 30-day rule.

472
MCQeasy

Refer to the exhibit. A CloudFormation stack creation failed. The architect needs to identify the reason for the failure. Which CLI command should be used to get detailed error messages?

A.aws cloudformation describe-stacks --stack-name my-stack
B.aws cloudformation describe-stack-events --stack-name my-stack
C.aws cloudformation get-template --stack-name my-stack
D.aws cloudformation list-stack-resources --stack-name my-stack
AnswerB

`describe-stack-events` returns the chronological event stream for the stack, including each resource's status reason. When creation fails, the `CREATE_FAILED` event carries the precise error message naming the offending resource and cause, satisfying the requirement for detailed failure diagnostics rather than just stack-level status.

Why this answer

The 'describe-stack-events' command provides detailed events including error messages, which can be used to identify reasons for stack creation failure. Option A is incorrect because 'describe-stacks' only shows the stack status and output, not detailed error messages. Option C is incorrect because 'get-template' retrieves the template body, not events.

Option D is incorrect because 'list-stack-resources' lists resources, not events or errors.

473
Multi-Selectmedium

A company is implementing a hybrid network architecture with multiple VPCs in different AWS accounts. They need to ensure private connectivity between the VPCs and their on-premises data center. Which TWO services should they use together to meet this requirement?

Select 2 answers
A.AWS Direct Connect
B.Amazon Route 53 Resolver
C.VPC peering
D.AWS Transit Gateway
E.AWS Client VPN
AnswersA, D

AWS Direct Connect provides a dedicated private network link from the on-premises data centre into AWS, bypassing the public internet. It supplies the private hybrid connectivity the scenario demands, terminating at a VPC or transit gateway.

Why this answer

AWS Direct Connect (A) is correct because it provides a dedicated private network connection from the on-premises data center to AWS, bypassing the public internet for consistent, low-latency private connectivity. AWS Transit Gateway (D) is correct because it acts as a central hub that connects multiple VPCs across different AWS accounts and attaches to the Direct Connect gateway, enabling transitive routing between all VPCs and on-premises. Together, Direct Connect provides the private on-premises link while Transit Gateway provides scalable many-to-many VPC interconnection across accounts.

Amazon Route 53 Resolver (B) only handles DNS resolution between on-premises and VPCs and does not provide the private network transport itself. VPC peering (C) connects only two VPCs at a time and does not scale to a hub-and-spoke multi-account topology or integrate natively with on-premises routing. AWS Client VPN (E) is a remote-user VPN solution for individual clients, not for site-to-site private connectivity between VPCs and a data center.

Exam trap

The trap here is that candidates often choose VPC peering (Option C) thinking it can connect multiple VPCs to on-premises directly, but VPC peering lacks transitive routing and cannot terminate a Direct Connect connection, making Transit Gateway the required central aggregation point.

474
MCQmedium

A company is designing a multi-tier web application on AWS. The web tier must automatically scale based on CPU utilization, and the application tier must process messages from an SQS queue. The application tier instances are frequently terminated and replaced due to scaling events. Where should the application logs be stored to ensure they are retained regardless of instance lifecycle?

A.Configure the CloudWatch Logs agent on each instance to stream logs to CloudWatch Logs.
B.Store logs on an EBS volume and take regular snapshots.
C.Write logs to the instance store volume of each EC2 instance.
D.Write logs to an Amazon S3 bucket mounted on each instance using NFS.
AnswerA

Streaming via the CloudWatch Logs agent decouples log storage from the instance lifecycle, satisfying the requirement that logs survive frequent termination and replacement. Logs persist in CloudWatch Logs independently of any EC2 instance, unlike instance-store or ephemeral volumes.

Why this answer

The CloudWatch Logs agent streams log data to Amazon CloudWatch Logs in real-time, decoupling log retention from the EC2 instance lifecycle. When instances are terminated, the logs are already persisted in CloudWatch Logs, ensuring they are retained regardless of scaling events.

Exam trap

The trap here is that candidates may confuse instance store (ephemeral) with EBS (persistent) storage, or assume that mounting S3 via NFS is a straightforward AWS feature, when in fact CloudWatch Logs is the only fully managed, instance-lifecycle-independent solution for log retention in this scenario.

How to eliminate wrong answers

Option B is wrong because EBS snapshots are point-in-time backups and do not provide continuous log streaming; logs written to an EBS volume are lost if the instance is terminated and the volume is deleted, unless snapshots are taken frequently, which adds complexity and potential data loss between snapshots. Option C is wrong because instance store volumes are ephemeral and data is lost when the instance is stopped, terminated, or fails; they are not suitable for persistent log storage. Option D is wrong because mounting an S3 bucket via NFS is not a native AWS feature; it requires third-party tools or FUSE-based solutions, introduces latency and complexity, and does not guarantee real-time log streaming or seamless integration with instance scaling.

475
MCQmedium

A company is migrating an on-premises Oracle database to Amazon Aurora PostgreSQL. The database is 10 TB and supports a critical application with a maximum allowable downtime of 30 minutes. The company wants to use AWS Database Migration Service (AWS DMS) with change data capture (CDC) to minimize downtime. After the initial full load, CDC is replicating ongoing changes. The company needs to perform the final cutover. Which sequence of steps should the company take to achieve the least downtime?

A.Stop the application, stop the DMS task, and then redirect the application to Aurora.
B.Stop the application, wait for CDC to catch up, stop the DMS task, and then redirect the application to Aurora.
C.Stop the DMS task, stop the application, and then redirect the application to Aurora.
D.Keep the application running, stop the DMS task, and then redirect the application to Aurora.
AnswerB

This sequence ensures that all changes are replicated before switching. Stopping the application prevents new writes, allowing CDC to catch up and replicate the final changes. Stopping the DMS task after catch-up ensures no data loss. Then redirecting the application to Aurora completes the cutover. This minimizes downtime to the time needed for CDC to catch up and the application switch.

Why this answer

The correct cutover process with AWS DMS and CDC involves stopping the application to prevent new writes, allowing CDC to replicate the remaining changes to Aurora, and then stopping the DMS task. This ensures data consistency. After that, the application can be redirected to Aurora.

This sequence minimizes downtime while guaranteeing no data loss.

Exam trap

The trap here is stopping the DMS task too early, before CDC has fully caught up, which leads to missing data in the target.

476
MCQmedium

A company runs a critical application on an Amazon RDS for PostgreSQL DB instance. The database experiences periodic slowdowns. The team notices that the DB instance has a large number of connections in an idle state. What is the BEST way to address this issue?

A.Migrate the database to Amazon Aurora.
B.Configure AWS Lambda to manage database connections.
C.Use an RDS Proxy to pool database connections.
D.Increase the max_connections parameter in the DB parameter group.
AnswerC

RDS Proxy pools and reuses established connections, so idle sessions no longer consume backend resources on the DB instance. This directly resolves the connection exhaustion causing periodic slowdowns, since the proxy multiplexes many client connections onto fewer database connections without application changes.

Why this answer

Amazon RDS Proxy pools and reuses database connections, reducing the number of idle connections held by the application and smoothing connection churn. This directly addresses the slowdown caused by many idle connections, improving database performance without application changes. It also handles failover and credentials via Secrets Manager.

Exam trap

The trap is thinking 'more connections' solves connection-related slowdowns; candidates pick increasing max_connections when the real issue is idle connection waste, which pooling addresses.

How to eliminate wrong answers

Option A is wrong because migrating to Aurora is a major architectural change and does not inherently solve idle connection buildup. Option B is wrong because Lambda managing connections adds complexity and does not pool connections for the existing application. Option D is wrong because increasing max_connections allows more connections but does not reduce idle ones — it can worsen resource contention.

477
MCQhard

A company has a VPC with a CIDR block of 10.0.0.0/16. They need to connect this VPC to an on-premises network that uses the CIDR block 10.0.0.0/8. The company wants to use AWS Site-to-Site VPN for the connection. They must avoid IP address conflicts. What is the MOST appropriate solution?

A.Use AWS Transit Gateway with a Site-to-Site VPN attachment and enable route propagation.
B.Configure the Site-to-Site VPN with static routes and use AWS PrivateLink to access on-premises services.
C.Use AWS Site-to-Site VPN with a virtual private gateway and implement NAT on the on-premises side to translate the VPC CIDR to a non-overlapping range.
D.Re-create the VPC with a non-overlapping CIDR block, such as 192.168.0.0/16, and then establish the Site-to-Site VPN.
AnswerD

The most straightforward way to avoid IP address conflicts is to ensure that the VPC CIDR does not overlap with the on-premises network. Re-creating the VPC with a non-overlapping CIDR like 192.168.0.0/16 eliminates the conflict entirely. While this may require migration effort, it is the most reliable and recommended solution for overlapping CIDRs.

Why this answer

IP address conflicts between a VPC and on-premises networks can cause routing failures and unpredictable behavior. The most appropriate solution is to use non-overlapping CIDR blocks. Re-creating the VPC with a CIDR that does not overlap with the on-premises 10.0.0.0/8 network ensures clean routing and avoids the need for complex NAT or translation.

While migration may be required, it is the most reliable long-term fix.

Exam trap

The trap here is assuming that AWS Transit Gateway or VPN configurations can automatically resolve overlapping CIDR blocks, but they cannot; the only true fix is to use non-overlapping IP ranges.

478
MCQmedium

A company is migrating an on-premises data warehouse to Amazon Redshift. The data warehouse contains 50 TB of data and is used for complex analytical queries. The company wants to minimize the migration time and ensure the data is available for querying as soon as possible. Which approach should the company use?

A.Use AWS Snowball Edge to transfer the data to Amazon S3, then use the COPY command to load it into Amazon Redshift.
B.Use AWS DataSync to transfer the data to Amazon EFS, then use AWS Glue to load it into Amazon Redshift.
C.Use AWS Database Migration Service (AWS DMS) to replicate the data directly from the on-premises data warehouse to Amazon Redshift.
D.Use Amazon Kinesis Data Firehose to stream the data from on-premises to Amazon Redshift.
AnswerA

AWS Snowball Edge is ideal for large data transfers, and loading into Redshift from S3 using the COPY command is the most efficient method. It parallelizes the load and minimizes migration time. This approach is cost-effective and scalable for 50 TB.

Why this answer

For large-scale data transfers, AWS Snowball Edge is the most efficient method to move data to AWS. Once the data is in Amazon S3, the COPY command in Amazon Redshift can load it in parallel, significantly reducing migration time. This approach is cost-effective and ensures the data is available for querying quickly.

Exam trap

The trap here is assuming that AWS DMS is always the best tool for database migration, but for large one-time bulk transfers, physical devices like Snowball Edge are faster and more reliable.

479
Multi-Selecteasy

A company has an AWS Lambda function that processes messages from an SQS queue. The function is experiencing timeouts. Which TWO changes could help resolve the timeout issue? (Choose 2)

Select 2 answers
A.Increase the batch size in the SQS event source mapping.
B.Enable SQS queue encryption.
C.Increase the Lambda function timeout.
D.Increase the Lambda function memory allocation.
E.Decrease the SQS visibility timeout.
AnswersC, D

Raising the function's configured timeout directly addresses the stem's timeout constraint: Lambda terminates execution once the limit is reached, so a longer duration lets genuinely slow processing finish. This suits the SQS-triggered workload, though it only helps when the function's actual runtime exceeds the current limit rather than being stuck.

Why this answer

Option C is correct because the Lambda function timeout setting defines the maximum execution time before Lambda terminates the invocation; if the function legitimately needs more time to process messages, raising the timeout (up to 15 minutes) directly prevents timeout errors. Option D is correct because Lambda allocates CPU and network bandwidth proportionally to memory, so increasing the memory allocation gives the function more compute power and can significantly reduce processing time, resolving timeouts caused by slow execution. Option A is not appropriate because increasing the SQS batch size means each invocation processes more messages, which typically increases execution duration and worsens timeouts.

Option B is not relevant because SQS queue encryption (SSE) protects data at rest and does not affect Lambda execution time. Option E is not appropriate because decreasing the visibility timeout makes messages reappear sooner for reprocessing, which can cause duplicate processing and does not fix the underlying Lambda timeout.

480
MCQhard

A financial services company uses AWS Organizations with all features enabled. A security account runs AWS CloudFormation StackSets with service-managed permissions to deploy guardrail resources into every account. Compliance requires that no member account administrator can disable AWS CloudTrail or delete the organization trail, even in accounts where they hold full administrative rights, and that new accounts automatically receive the guardrail. Which combination should the solutions architect recommend?

A.Create a trail in each member account with AWS CloudFormation StackSets and enable log file validation so tampering with delivered logs is detectable.
B.Deploy an organization trail from the management account and attach a service control policy that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail to all member accounts except the management account.
C.Enable AWS CloudTrail Lake in the security account and configure an event data store that ingests management events from all accounts through AWS Organizations.
D.Deploy a CloudFormation StackSet that creates a trail and an IAM policy denying cloudtrail:StopLogging, and attach the policy to every IAM role in each account.
AnswerB

An organization trail created in the management account applies to every account in the organization, and member accounts cannot alter or delete it. A service control policy that denies the stop and delete actions removes those permissions from every principal in member accounts, including administrators, because SCPs define the maximum available permissions. New accounts inherit both automatically, satisfying the guardrail requirement.

Why this answer

An organization trail owned by the management account extends logging to all accounts and cannot be modified or deleted by member accounts. Pairing it with a service control policy that denies the stop and delete actions on CloudTrail removes those capabilities from member-account administrators, because SCPs bound the permissions available to every principal in the account. Accounts created later automatically fall under the same trail and policy.

Exam trap

The trap here is assuming an IAM policy or log file validation can restrain an account administrator, when only a service control policy plus a management-account-owned organization trail removes the ability to disable logging.

481
MCQmedium

A company has a critical application running on AWS Lambda that processes messages from an Amazon SQS queue. The queue occasionally receives a large backlog of messages, causing Lambda to scale up significantly and incur high costs. The company wants to optimize costs while ensuring that all messages are processed in a timely manner. Which solution should a solutions architect recommend?

A.Configure the SQS queue as an event source for Lambda with a batch size of 10 and a maximum batching window of 0 seconds.
B.Configure the SQS queue as an event source for Lambda with a larger batch size and a longer maximum batching window.
C.Set the Lambda function's reserved concurrency to a low value to limit scaling.
D.Increase the Lambda function's memory allocation to reduce execution time.
AnswerB

Increasing the batch size and batching window allows Lambda to process more messages per invocation and wait longer to accumulate messages, reducing the number of invocations and thus cost. During a backlog, Lambda can process larger batches, improving efficiency. This optimizes cost while still processing all messages in a timely manner, as the window is bounded.

Why this answer

By increasing the batch size and maximum batching window, Lambda can retrieve more messages per invocation and wait to accumulate a full batch, reducing the number of invocations and associated costs. This is especially effective during backlogs because Lambda can process messages in larger chunks. It maintains timely processing because the batching window is limited.

Other options either do not reduce invocations or may throttle processing.

Exam trap

The trap here is thinking that limiting concurrency or increasing memory is the primary way to reduce Lambda costs, when actually batching is a more effective cost optimization for queue processing.

482
MCQeasy

A company is migrating a legacy on-premises application to AWS. The application runs on a physical server with 16 vCPUs and 64 GB RAM, and it stores data on a local SSD. The company wants to minimize changes to the application and reduce operational overhead. They plan to use a lift-and-shift approach. Which AWS service should a solutions architect recommend to migrate the server?

A.AWS Database Migration Service (AWS DMS)
B.AWS Server Migration Service (AWS SMS)
C.AWS Application Migration Service (AWS MGN)
D.AWS DataSync
AnswerC

AWS Application Migration Service (MGN) is designed for lift-and-shift migrations of physical or virtual servers to AWS. It replicates the entire server, including the operating system, applications, and data, to AWS. This minimizes changes and reduces operational overhead because the migration is automated and the application runs as-is on Amazon EC2.

Why this answer

AWS Application Migration Service (MGN) is the primary service for lift-and-shift migrations of physical or virtual servers. It replicates the entire server to AWS, allowing the application to run unchanged on EC2. This minimizes changes and operational overhead, making it ideal for the scenario.

Exam trap

The trap here is confusing AWS DataSync with a server migration service, when DataSync is only for file and object data transfer and cannot replicate an entire server.

483
MCQhard

A company is modernizing a legacy Java application to run on AWS. The application currently uses a monolithic architecture with a shared MySQL database. The company wants to adopt a microservices architecture using containers and wants to decouple the database. The solutions architect proposes using Amazon ECS with Fargate for compute and Amazon RDS for MySQL for the database. However, during the transition, the performance team notices that the database CPU utilization is consistently above 80% during peak hours. The application logs show many slow queries. The team suspects that the database is the bottleneck. The company wants to improve performance without rewriting the application. Which action should the solutions architect take first?

A.Enable Amazon RDS Performance Insights to identify the most resource-intensive queries.
B.Add an RDS read replica and direct read traffic to it.
C.Scale up the RDS instance to a larger instance type.
D.Migrate the database to Amazon DynamoDB to eliminate relational bottlenecks.
AnswerA

Performance Insights captures database load segmented by SQL statement, wait event and host, exposing which queries consume the most CPU during peaks. This identifies the bottleneck without rewriting the application, satisfying the constraint of improving performance while the monolith remains unchanged.

Why this answer

The first step to address the database bottleneck is to identify the root cause of the slow queries. Enabling Amazon RDS Performance Insights provides detailed visibility into query performance, allowing the team to pinpoint the most resource-intensive queries and their execution plans. This diagnostic information guides further optimization efforts (e.g., indexing, query rewriting, or schema changes) without requiring application code changes.

Options B and C are premature without understanding which queries are problematic; a read replica would not help if the bottleneck is write-heavy or if reads are already well-distributed, and scaling up may only mask the issue. Option D would require significant application rewriting, which contradicts the requirement to improve performance without rewriting the application.

484
Multi-Selecthard

A financial services company is migrating a legacy on-premises Java application to AWS. The application uses an Oracle database and is deployed on WebLogic Server. The company wants to modernize the application by moving to a microservices architecture on AWS. The migration must minimize downtime and ensure data consistency during the transition. Which two strategies should be used to achieve these goals? (Choose two.)

Select 2 answers
A.Implement a strangler fig pattern by gradually replacing components of the monolith with microservices, using Amazon API Gateway to route traffic between old and new components.
B.Decompose the monolith into microservices using AWS App2Container to containerize the WebLogic application, then deploy to Amazon ECS with AWS Fargate.
C.Migrate the application to AWS Elastic Beanstalk with a Tomcat platform and use AWS CodeDeploy for blue/green deployments to achieve zero downtime.
D.Use AWS Migration Hub to orchestrate the migration and AWS Server Migration Service (SMS) to replicate the WebLogic servers to Amazon EC2, then refactor in place.
E.Use AWS Database Migration Service (AWS DMS) with ongoing replication to migrate the Oracle database to Amazon Aurora PostgreSQL, and cut over when replication lag is minimal.
AnswersA, E

The strangler fig pattern allows incremental modernization by routing traffic to new microservices while the legacy monolith continues to operate. Amazon API Gateway can direct requests based on routes, enabling a gradual transition with minimal downtime and reduced risk. This supports data consistency by allowing the monolith and microservices to coexist during migration.

Why this answer

The strangler fig pattern enables incremental decomposition of the monolith into microservices, while API Gateway routes traffic, allowing coexistence and minimal downtime. AWS DMS with ongoing replication ensures the database is continuously synchronized during migration, enabling a cutover with minimal lag. Together, these strategies achieve modernization with data consistency and low downtime.

Exam trap

The trap here is assuming that containerizing the entire application with App2Container automatically modernizes it to microservices, when in fact it only packages the existing monolith into a container.

485
MCQmedium

A company runs a critical application on a single Amazon EC2 instance in a development environment. The application writes data to an instance store volume. After a planned stop and start of the instance, the data on the instance store is lost. The company wants to prevent data loss in the future for this instance. What should a solutions architect recommend?

A.Enable termination protection on the instance.
B.Attach an additional EBS volume and move the application data to it.
C.Enable detailed monitoring on the instance to detect data loss.
D.Create a snapshot of the instance store volume regularly.
AnswerB

EBS volumes provide persistent, replicated storage that survives instance stop/start and can be reattached. Moving the application data from instance store to an EBS volume ensures durability and availability. This directly solves the data loss issue because EBS volumes are independent of the instance lifecycle.

Why this answer

Instance store volumes are ephemeral and lose data when the instance is stopped or terminated. To prevent data loss, the application must use persistent storage such as Amazon EBS. Attaching an EBS volume and moving data to it ensures durability across instance lifecycle events.

Other options either provide no persistence or are technically infeasible.

Exam trap

The trap here is assuming that instance store data can be preserved through snapshots or termination protection, when in fact instance store is inherently non-persistent and cannot be snapshotted.

486
MCQmedium

A company is migrating its on-premises PostgreSQL database to Amazon Aurora PostgreSQL. The database is 2 TB in size and has a 24-hour maintenance window on weekends. The company needs to minimize downtime and ensure data consistency. Which strategy should the solutions architect recommend?

A.Create an Aurora read replica from the on-premises database using a VPN connection.
B.Use AWS DMS with ongoing replication from the on-premises database to Aurora, then perform a cutover during the maintenance window.
C.Use AWS Schema Conversion Tool (AWS SCT) to convert the schema and then use AWS Database Migration Service (AWS DMS) with full load only.
D.Perform a full pg_dump of the on-premises database and restore it to Aurora using pg_restore.
AnswerB

AWS DMS continuous replication keeps the target in sync while the source stays live, so only a brief cutover is needed. This satisfies the minimal-downtime requirement, and the weekend maintenance window provides the safe switchover point while preserving data consistency.

Why this answer

AWS DMS with ongoing replication (change data capture, CDC) allows the on-premises PostgreSQL database to be continuously synchronized with the target Aurora PostgreSQL cluster, minimizing downtime. When the cutover is performed during the 24-hour maintenance window, data consistency is ensured because all changes up to that point have been replicated. This approach avoids the need for a lengthy full database dump and restore, which would cause extended downtime.

Exam trap

The trap here is that candidates often assume a full dump and restore (pg_dump/pg_restore) is the simplest approach, but they overlook the massive downtime it requires for a 2 TB database, whereas DMS with CDC is designed specifically to minimize downtime for large-scale migrations.

How to eliminate wrong answers

Option A is wrong because Aurora read replicas can only be created from an existing Aurora DB cluster, not from an on-premises database; a VPN connection alone does not enable this replication. Option C is wrong because AWS SCT is used for schema conversion (not needed here since both are PostgreSQL), and a full-load-only DMS task would not capture ongoing changes, leading to data inconsistency and longer downtime. Option D is wrong because performing a full pg_dump and pg_restore would require the on-premises database to be offline for the duration of the dump and restore, causing significant downtime that exceeds the maintenance window.

487
MCQmedium

A company is migrating a legacy monolithic application to AWS. The application currently uses a shared file system for storing user uploads. The solution architect needs to design a highly available and scalable storage solution that supports concurrent read/write operations from multiple EC2 instances. Which AWS service should be used?

A.Amazon FSx for Windows File Server
B.Amazon S3 with S3 File Gateway
C.Amazon EFS
D.Amazon EBS with Multi-Attach enabled
AnswerC

Amazon EFS provides a shared, elastic NFS file system that many EC2 instances across Availability Zones can mount concurrently with read/write access. This satisfies the concurrent access and high availability constraints that a single-instance or block-based store cannot.

Why this answer

Amazon EFS provides a fully managed, elastic NFS file system that supports concurrent read/write access from thousands of EC2 instances across multiple Availability Zones. It is designed for high availability and scalability, automatically growing and shrinking as files are added or removed, making it ideal for a shared file system for user uploads in a migrated monolithic application.

Exam trap

The trap here is that candidates often confuse Amazon EBS Multi-Attach with a true shared file system, overlooking its single-AZ limitation and the need for a cluster-aware file system, or they mistakenly choose S3 File Gateway thinking it provides native file system semantics, when in fact it adds latency and complexity for concurrent write workloads.

How to eliminate wrong answers

Option A is wrong because Amazon FSx for Windows File Server is optimized for Windows-based workloads requiring SMB protocol support and Active Directory integration, not for general-purpose Linux-based concurrent access from multiple EC2 instances. Option B is wrong because Amazon S3 with S3 File Gateway presents an NFS or SMB mount point backed by S3, but it introduces latency and caching complexity, and S3 itself is an object store, not a POSIX-compliant file system suitable for concurrent read/write locking. Option D is wrong because Amazon EBS with Multi-Attach enabled supports only up to 16 Nitro-based EC2 instances in a single Availability Zone, lacks cross-AZ high availability, and does not provide a shared file system interface (it is a block-level device requiring a cluster-aware file system).

488
Multi-Selecthard

A company is modernizing a legacy monolithic application by decomposing it into microservices. The application currently uses a single relational database. The company wants to migrate to a microservices architecture on AWS and needs to choose appropriate data storage strategies. The company requires that each microservice has its own database to ensure loose coupling and independent scaling. Which two strategies should the company use to achieve this? (Choose two.)

Select 2 answers
A.Use Amazon Aurora Serverless v2 for each microservice that requires a relational database, with separate clusters per service.
B.Use Amazon S3 for all microservices to store structured data as JSON objects.
C.Use Amazon DynamoDB for each microservice that requires a key-value store, with separate tables per service.
D.Use a single Amazon RDS for PostgreSQL instance with separate schemas for each microservice.
E.Use Amazon ElastiCache for Redis as the primary database for all microservices.
AnswersA, C

Amazon Aurora Serverless v2 automatically scales capacity based on demand and supports relational workloads. Deploying a separate Aurora cluster for each microservice provides database isolation and independent scaling. This aligns with the microservices pattern and allows each service to evolve its schema independently. Aurora Serverless v2 is cost-effective for variable workloads and supports PostgreSQL and MySQL compatibility.

Why this answer

To achieve a database per microservice, each service should have its own dedicated database that matches its data model. Amazon DynamoDB is suitable for key-value and document workloads, while Amazon Aurora Serverless v2 works for relational workloads. Both allow independent scaling and isolation.

Using a shared database or non-database services like S3 or ElastiCache does not meet the requirement for loose coupling and independent scaling.

Exam trap

The trap here is assuming that separate schemas on a shared database instance provide sufficient isolation; they do not, as the instance remains a shared resource.

489
MCQmedium

A company is designing a new microservices architecture using AWS Lambda. Each microservice has its own database. The company wants to securely store database credentials and rotate them automatically. Which AWS service should be used?

A.AWS Key Management Service (KMS)
B.AWS Systems Manager Parameter Store
C.AWS Identity and Access Management (IAM)
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager natively stores database credentials and provides built-in automatic rotation via Lambda, satisfying the rotation requirement without custom code. Unlike SSM Parameter Store, rotation is a first-class managed feature, so credentials are regularly replaced and securely retrieved by each microservice at runtime.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials for services like Amazon RDS, Redshift, and DocumentDB. It supports built-in rotation with AWS Lambda, ensuring credentials are rotated on a schedule without manual intervention, which directly meets the requirement for automatic rotation in a microservices architecture.

Exam trap

The trap here is that candidates often confuse Parameter Store's secure string parameter with Secrets Manager, but Parameter Store lacks native automatic rotation, which is the critical requirement in this question.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encryption keys, not for storing or rotating secrets like database credentials; it can encrypt secrets but does not manage rotation. Option B is wrong because AWS Systems Manager Parameter Store can store secrets but lacks native automatic rotation capabilities—it requires custom solutions or integration with Secrets Manager for rotation. Option C is wrong because IAM is used for access control and permissions, not for storing secrets or rotating credentials; it cannot store database passwords or manage their lifecycle.

490
MCQhard

A company is designing a multi-region active-active application that uses Amazon DynamoDB global tables. The application must be able to handle write conflicts that may occur when the same item is updated in two different regions at the same time. The company needs to ensure that the application uses the most recently written data. What should the architect recommend?

A.Use the default last writer wins conflict resolution
B.Use optimistic locking with a version number
C.Use DynamoDB Streams to capture changes and reconcile conflicts
D.Use conditional writes to prevent overwrites
AnswerA

DynamoDB global tables resolve concurrent writes using last writer wins, comparing timestamps to keep the most recent update. This satisfies the requirement that the application uses the most recently written data when the same item is updated simultaneously in two regions.

Why this answer

Amazon DynamoDB global tables use a last writer wins (LWW) conflict resolution mechanism based on the timestamp of the update. When concurrent updates to the same item occur in different regions, DynamoDB automatically compares the update timestamps and retains the most recently written data. This satisfies the requirement to use the most recently written data without requiring custom reconciliation logic.

Exam trap

The trap here is that candidates often overthink conflict resolution and choose complex options like streams or optimistic locking, not realizing that DynamoDB global tables already handle this automatically with LWW, which is the simplest and most appropriate solution for ensuring the most recently written data is used.

How to eliminate wrong answers

Option B is wrong because optimistic locking with a version number prevents overwrites by rejecting stale updates, but it does not resolve conflicts by keeping the most recent write; it would cause writes to fail instead of automatically selecting the latest data. Option C is wrong because DynamoDB Streams can capture changes but do not provide built-in conflict resolution; using streams to reconcile conflicts would require custom application logic and would not automatically ensure the most recently written data is used. Option D is wrong because conditional writes prevent overwrites when a condition is not met, which would cause write failures rather than resolving conflicts by keeping the latest write.

491
MCQmedium

A media company is designing a new application that ingests large video files uploaded by users. The files must be stored durably and then processed by a compute fleet that runs for several hours per file. The company wants to minimize compute costs and ensure that processing can resume if interrupted. Which architectural approach should a solutions architect recommend?

A.Store files in Amazon S3 and use Amazon ECS with Fargate tasks that run for up to 24 hours.
B.Store files in Amazon S3 and use AWS Lambda with a 15-minute timeout to process each file.
C.Store files in Amazon S3 and use AWS Batch with managed compute environments to run processing jobs.
D.Store files in Amazon EBS and use a single large EC2 instance to process files sequentially.
AnswerC

AWS Batch is designed for batch computing workloads and can run jobs for hours or days. It manages compute resources dynamically, which can reduce costs by using Spot Instances and scaling down when not needed. AWS Batch also supports job queues and retries, allowing processing to resume if interrupted, and integrates with S3 for input and output.

Why this answer

AWS Batch is purpose-built for batch computing, supporting long-running jobs and managed compute environments that can use Spot Instances to reduce costs. It provides job queues, retries, and dependency management, enabling processing to resume after interruptions. Storing files in Amazon S3 ensures durability and accessibility for the compute fleet.

This combination meets the requirements for cost minimization and resiliency.

Exam trap

The trap here is assuming that AWS Lambda or Fargate can handle multi-hour processing without considering their timeout limits or the lack of built-in batch orchestration.

492
MCQhard

A company is migrating a critical application to AWS and needs to ensure it meets a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 5 minutes. The application runs on EC2 with an EBS volume. Which configuration should the company use?

A.Multi-AZ deployment with synchronous replication between two instances.
B.Single EC2 instance with EBS snapshots every 5 minutes.
C.Two EC2 instances in an Auto Scaling group with a warm standby.
D.EC2 instance with Elastic Disaster Recovery service.
AnswerD

AWS Elastic Disaster Recovery continuously replicates block-level data to a staging area, achieving RPOs of seconds and typical RTOs under 15 minutes. This satisfies both constraints directly: the 5-minute RPO via continuous replication and the 15-minute RTO through automated launch of recovery instances with attached EBS volumes.

Why this answer

AWS Elastic Disaster Recovery (DRS) continuously replicates source servers (including EC2 and on-premises) to a staging area in AWS with sub-second RPO, and can launch recovery instances in minutes, meeting both the 5-minute RPO and 15-minute RTO. It supports point-in-time recovery and automated drills, making it the purpose-built DR service for these targets.

Exam trap

SAP-C02 often tests the distinction between HA (Multi-AZ, Auto Scaling) and DR (Elastic Disaster Recovery, pilot light, warm standby) — candidates pick Multi-AZ or warm standby because they sound resilient, but only DRS meets the specific 5-minute RPO with continuous replication.

How to eliminate wrong answers

Option A is wrong because Multi-AZ with synchronous replication is a high-availability pattern, not a DR pattern — it protects against AZ failure but not regional disasters, and it doesn't address RPO/RTO for the described scenario. Option B is wrong because EBS snapshots every 5 minutes are not guaranteed to complete within 5 minutes (snapshots are incremental and can take longer), and restoring from a snapshot to a running instance typically exceeds 15 minutes RTO. Option C is wrong because a warm standby in an Auto Scaling group provides HA/scaling but not continuous replication with a 5-minute RPO; data on the standby would be stale or absent without replication.

493
MCQmedium

A company is designing a new real-time bidding platform that must handle sudden bursts of traffic up to 100,000 requests per second. The application runs on Amazon EC2 instances behind an Application Load Balancer and stores bid data in Amazon DynamoDB. The company wants to minimize latency and cost while ensuring the database can scale automatically. Which solution meets these requirements?

A.Use Amazon RDS for MySQL with Multi-AZ and read replicas, and implement a caching layer using Amazon ElastiCache.
B.Use DynamoDB with provisioned capacity mode and set up Auto Scaling with a target utilization of 70%.
C.Use DynamoDB with on-demand capacity mode and enable DynamoDB Accelerator (DAX) for read-heavy workloads.
D.Use Amazon Aurora Serverless v2 with auto-scaling and enable Aurora Global Database for low-latency reads.
AnswerC

On-demand capacity mode automatically scales to handle sudden bursts without capacity planning, and DAX provides microsecond read latency for read-heavy workloads like real-time bidding. This combination minimizes latency and cost because you pay only for what you use, with no need to over-provision. It directly addresses the unpredictable traffic and low-latency requirements.

Why this answer

The correct solution uses DynamoDB on-demand mode to handle unpredictable bursts without capacity planning, and DAX to provide microsecond read latency for read-heavy operations. This combination ensures automatic scaling, low latency, and cost efficiency for a real-time bidding platform. Other options either require manual scaling, introduce bottlenecks, or are not optimized for the required throughput and latency.

Exam trap

The trap here is assuming that provisioned capacity with Auto Scaling can react quickly enough to sudden bursts, but it cannot match the instant scalability of on-demand mode.

494
MCQhard

Refer to the exhibit. An architect is troubleshooting an EC2 instance that is not responding to health checks from an Application Load Balancer. The instance is in the 'running' state. Which of the following is the most likely cause?

A.The security group is blocking the health check traffic.
B.The instance is in a stopped state.
C.The instance is impaired due to an AWS issue.
D.The instance has exhausted its CPU credits.
AnswerA

A security group that omits the load balancer's health check port or source blocks the probe packets, so the target never receives them and is marked unhealthy despite the instance running. Allowing the health check port from the ALB security group or subnet CIDR resolves it.

Why this answer

The most likely cause is that the instance's security group is not allowing inbound traffic from the ALB's security group on the health check port. ALB health checks originate from the load balancer's ENIs, so the target's security group must explicitly permit that traffic; otherwise the instance appears healthy at the OS level but fails ALB checks.

Exam trap

SAP-C02 often tests the misconception that a running instance with a healthy OS is automatically reachable by the ALB, when security group and NACL rules on the health check path are the usual culprits.

How to eliminate wrong answers

Option B is wrong because the question states the instance is in the 'running' state, so a stopped state is contradicted by the scenario. Option C is wrong because an AWS-side impairment would typically affect many resources and is not the first thing to check; it is a rare cause compared to misconfigured security groups. Option D is wrong because CPU credit exhaustion on a T-family instance degrades performance but does not by itself cause health check failures unless the instance becomes completely unresponsive, which is far less likely than a security group misconfiguration.

495
MCQeasy

A startup has 25 AWS accounts in a single organization. A new compliance officer wants a single, read-only view of all resources and their configuration across every account, and wants to be alerted when an S3 bucket becomes publicly accessible. The team has no existing aggregation tooling. Which approach requires the least operational effort?

A.Enable AWS CloudTrail organization trails and use CloudTrail Lake queries to list all resources and detect public S3 buckets.
B.Use AWS Trusted Advisor in the management account with the organization view enabled and rely on the S3 bucket permissions check to detect public buckets.
C.Deploy a custom script on an EC2 instance in each account that calls the S3 and IAM APIs nightly and writes results to a central S3 bucket, then query the results with Amazon Athena.
D.Enable AWS Config in each account with a delegated administrator in a security account, deploy the s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited managed rules, and use the aggregator to view all accounts.
AnswerD

AWS Config supports a delegated administrator so one account can centrally manage recorders and rules for the whole organization, and the aggregator consolidates resource and compliance data across accounts and Regions. The two managed rules directly detect publicly accessible buckets and surface noncompliance.

Why this answer

AWS Config with a delegated administrator and a cross-account aggregator gives a single read-only view of resource configuration and compliance across all accounts, which is exactly what the compliance officer asked for. The managed S3 public-access rules provide continuous, change-driven detection of publicly accessible buckets.

Exam trap

The trap here is treating CloudTrail as a configuration inventory tool, when it records API calls and cannot report current resource state such as whether a bucket is public.

496
MCQmedium

A company is migrating 200 on-premises virtual machines running a mix of Windows and Linux workloads to AWS. The migration must complete within a tight cutover window, and the company wants to minimize manual configuration and scripting. A solutions architect needs to choose a migration approach that supports automated conversion of the source servers into Amazon EC2 instances with minimal changes. Which AWS service should the solutions architect use?

A.AWS DataSync
B.AWS Application Migration Service (AWS MGN)
C.AWS Database Migration Service (AWS DMS)
D.AWS Server Migration Service (AWS SMS)
AnswerB

AWS Application Migration Service (AWS MGN) is the primary lift-and-shift service for block-level replication and automated conversion of source servers to EC2 instances. It supports both Windows and Linux, uses a lightweight replication agent, and requires minimal manual effort because it automatically provisions staging and cutover instances. The tight cutover window is addressed by continuous replication and automated launch of test or cutover instances, which matches the requirements exactly.

Why this answer

AWS Application Migration Service is purpose-built for rehosting physical, virtual, or cloud servers to AWS. It continuously replicates source servers at the block level, then automatically launches them as EC2 instances for test or cutover. This removes the need to rebuild operating systems or applications manually, supports both Windows and Linux, and enables short cutover windows because the replication is ongoing.

The other services address data transfer or database migration, not whole-server conversion.

Exam trap

The trap here is assuming that AWS Server Migration Service is still the recommended tool for lift-and-shift server migrations, when AWS Application Migration Service is now the primary service for that use case.

497
MCQmedium

A company is migrating a legacy three-tier Java application from its on-premises data center to AWS. The application uses a proprietary in-memory session store that cannot be modified. The company wants to use AWS Application Migration Service (AWS MGN) for the migration and minimize downtime. After the initial replication, the company needs to perform a final cutover with less than 5 minutes of downtime. Which approach should the company take?

A.Use AWS MGN to replicate the servers continuously, then perform a final cutover by stopping the source servers, allowing MGN to replicate the last changes, and launching test instances.
B.Use AWS MGN to replicate the servers continuously, then perform a final cutover by stopping the source servers, letting MGN replicate the last changes, and launching cutover instances.
C.Use AWS Database Migration Service (AWS DMS) to replicate the application servers, then perform a cutover by redirecting traffic to new Amazon EC2 instances.
D.Use AWS Server Migration Service (AWS SMS) to replicate the servers, then perform a cutover by launching Amazon EC2 instances from the latest AMI.
AnswerB

AWS MGN continuously replicates source servers to a staging area. For final cutover, you stop the source servers, allow MGN to replicate the final changes, and then launch cutover instances. This minimizes downtime to the time needed for the last replication and instance launch, which can be under 5 minutes with proper preparation.

Why this answer

AWS Application Migration Service (AWS MGN) provides continuous block-level replication and enables a final cutover with minimal downtime. The correct process involves stopping the source servers, allowing MGN to replicate the last changes, and then launching cutover instances. This ensures that the migrated servers are up-to-date and ready to serve production traffic, achieving the low-downtime objective.

Exam trap

The trap here is confusing test instances with cutover instances; test instances are for validation only and do not serve production traffic.

498
MCQmedium

A company is running a stateful web application on EC2 instances in an Auto Scaling group. Users report that their sessions are lost when instances are terminated during scale-in. What should a solutions architect do to preserve session state?

A.Use lifecycle hooks to save session data to Amazon S3 before instance termination.
B.Enable sticky sessions (session affinity) on the Application Load Balancer.
C.Store session state in Amazon ElastiCache.
D.Increase the Auto Scaling group's cooldown period to prevent rapid scaling.
AnswerC

ElastiCache externalises session data from instance memory into a shared Redis or Memcached tier, so any instance in the Auto Scaling group can serve subsequent requests. Scale-in termination no longer discards sessions, satisfying the requirement to preserve state.

Why this answer

ElastiCache provides a centralized, fast session store that persists across instance terminations, ensuring session state is retained even when instances are scaled in. Option A is wrong because using lifecycle hooks to save session data to Amazon S3 is unreliable due to the high latency and the risk that the termination process may not complete the save in time. Option B is wrong because sticky sessions (session affinity) on the Application Load Balancer can cause uneven load distribution and still result in session loss if all instances in a target group are replaced or if the specific instance with the session is terminated.

Option D is wrong because increasing the Auto Scaling group's cooldown period only delays the next scaling activity but does not preserve session state when instances are eventually terminated.

499
MCQmedium

A healthcare company is designing a new multi-tenant SaaS application on AWS. Each tenant requires a separate encryption key, and the company must be able to audit key usage per tenant and automatically rotate keys annually. The keys must be stored in a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS Secrets Manager to store encryption keys per tenant, enable automatic rotation every year, and use AWS CloudTrail to audit access.
B.Use AWS Certificate Manager (ACM) to issue a separate certificate per tenant, store the private keys in ACM, and enable automatic renewal.
C.Use AWS Key Management Service (KMS) with a customer managed key per tenant, enable automatic annual rotation, and use AWS CloudTrail to audit key usage.
D.Deploy AWS CloudHSM clusters in each AWS Region, create a separate key for each tenant, and configure automatic rotation using a custom Lambda function.
AnswerC

AWS KMS provides FIPS 140-2 Level 3 validated HSMs, supports customer managed keys with automatic annual rotation, and logs all key usage to CloudTrail for auditing. Creating one customer managed key per tenant isolates encryption and enables per-tenant audit trails. This approach requires minimal operational effort because AWS manages the HSM infrastructure and rotation.

Why this answer

AWS KMS customer managed keys provide tenant-specific encryption with FIPS 140-2 Level 3 validated HSMs, and automatic key rotation can be enabled with a single setting. CloudTrail captures all API calls related to the keys, enabling per-tenant auditing. This solution offloads HSM management and rotation to AWS, minimizing operational overhead while meeting security and compliance requirements.

Exam trap

The trap here is assuming that AWS CloudHSM is necessary for FIPS 140-2 Level 3 compliance, when AWS KMS already meets that standard and requires far less management effort.

500
MCQhard

A company is designing a disaster recovery solution for a critical application that runs on Amazon EC2 instances in a single AWS Region. The application uses an Amazon RDS for MySQL database. The company wants to achieve a recovery point objective (RPO) of 5 seconds and a recovery time objective (RTO) of 15 minutes. Which solution should the company use?

A.Configure an RDS Multi-AZ DB cluster with a standby instance in another Region.
B.Use EC2 Auto Scaling to launch new instances in another Region and use an Application Load Balancer.
C.Take automated snapshots of the RDS instance every 5 seconds and copy them to another Region.
D.Deploy RDS Read Replicas in another Region and promote them during a disaster.
AnswerD

Correct. Cross-Region Read Replicas use asynchronous replication, typically achieving an RPO of seconds, and can be promoted to primary within minutes, meeting both RPO and RTO requirements.

Why this answer

Cross-Region Read Replicas for Amazon RDS MySQL use asynchronous replication, so they do not guarantee a 5-second RPO; replication lag can vary from seconds to minutes. However, among the options provided, D is the closest fit because the read replica can be promoted to a standalone primary database, and the other options fail to meet the RPO/RTO or are invalid. A strict 5-second RPO would be better served by Amazon Aurora Global Database, but D is the best available choice.

Option A is invalid because RDS Multi-AZ DB clusters do not support a standby instance in another Region for MySQL. Options B and C do not meet the RPO/RTO requirements.

Exam trap

The trap is that candidates assume Multi-AZ DB clusters support cross-Region standby instances, but Multi-AZ is limited to a single Region. They may also overlook that cross-Region Read Replicas use asynchronous replication and therefore cannot guarantee a 5-second RPO.

How to eliminate wrong answers

Option B is wrong because EC2 Auto Scaling and an Application Load Balancer address compute recovery but do not replicate the RDS database, failing to meet the RPO of 5 seconds and RTO of 15 minutes for the database tier. Option C is wrong because automated snapshots cannot be taken every 5 seconds (minimum interval is 5 minutes for automated snapshots, and manual snapshots are limited to once per 5 minutes per API), and copying snapshots to another Region introduces latency that exceeds the 5-second RPO. Option D is wrong because RDS Read Replicas in another Region use asynchronous replication, which can have a replication lag of several seconds to minutes, failing to guarantee a 5-second RPO; promotion is also not automatic, potentially exceeding the 15-minute RTO.

501
MCQeasy

A company wants to store application logs in Amazon S3 with a lifecycle policy that moves objects to S3 Glacier Instant Retrieval after 30 days and deletes them after 1 year. The logs are accessed frequently in the first 30 days but rarely after. Which storage class should the company use for the first 30 days?

A.S3 Standard
B.S3 Standard-IA
C.S3 One Zone-IA
D.S3 Glacier Flexible Retrieval
AnswerA

S3 Standard is appropriate for frequently accessed data. It has no retrieval fees, making it cost-effective for logs accessed multiple times in the first 30 days. The lifecycle transition to Glacier Instant Retrieval after 30 days is seamless.

Why this answer

S3 Standard is the correct choice because the logs are accessed frequently during the first 30 days. Standard provides low-latency access with no retrieval fees, and the lifecycle policy can transition objects to S3 Glacier Instant Retrieval after 30 days. For data that is accessed multiple times within a short retention period, Standard is more cost-effective than Standard-IA, which incurs retrieval fees and a 30-day minimum storage charge.

Exam trap

The common trap is selecting S3 Standard-IA (Option B) due to its lower storage cost, but failing to account for retrieval fees and the 30-day minimum charge. For frequently accessed data with short retention, S3 Standard is more cost-effective.

How to eliminate wrong answers

Option A (S3 Standard) is wrong because it is designed for frequently accessed data with no cost savings for infrequent access patterns; using it for the first 30 days would incur higher storage costs than necessary since the logs are not accessed constantly. Option C (S3 One Zone-IA) is wrong because it stores data in a single Availability Zone, which does not provide the durability and availability required for application logs that may need to be recovered after a zone failure; the question does not indicate tolerance for such risk. Option D (S3 Glacier Flexible Retrieval) is wrong because it is intended for long-term archival with retrieval times ranging from minutes to hours, not for data that is accessed frequently within the first 30 days; it would introduce unacceptable latency for the initial frequent access pattern.

502
MCQmedium

A company has multiple AWS accounts and wants to use AWS CloudFormation StackSets to deploy a common set of resources across all accounts. The StackSet should be managed from the management account. What permissions are required?

A.Create IAM users in target accounts with AdministratorAccess.
B.Create an IAM role in each target account with a trust policy allowing the management account to assume it.
C.Use a CloudFormation service role in the management account.
D.Apply an SCP to allow CloudFormation actions across accounts.
AnswerB

StackSets needs a trust relationship in every target account so the management account can assume a role and deploy stacks. Creating an IAM role in each target account, with a trust policy naming the management account, satisfies the cross-account assumption requirement.

Why this answer

AWS CloudFormation StackSets require the management account to assume an IAM role in each target account to deploy resources. This role must have a trust policy that allows the management account's StackSets service-linked role (or a custom role) to assume it, granting the necessary permissions to create, update, or delete stack instances across accounts. Without this cross-account trust relationship, StackSets cannot perform operations in target accounts.

Exam trap

The trap here is that candidates often confuse a CloudFormation service role (used for stack operations within a single account) with the cross-account IAM roles required by StackSets, leading them to select Option C.

How to eliminate wrong answers

Option A is wrong because creating IAM users with AdministratorAccess in target accounts is not required and violates security best practices; StackSets use IAM roles, not users, for cross-account access. Option C is wrong because a CloudFormation service role in the management account only governs permissions within that account, not across target accounts; StackSets need roles in each target account. Option D is wrong because SCPs (Service Control Policies) are used to restrict permissions at the organizational unit or account level, but they do not grant the necessary cross-account trust or permissions for StackSets to assume roles; SCPs can only deny or allow actions, not establish trust relationships.

503
MCQhard

A company uses AWS Config to evaluate resource compliance across multiple accounts. The security team wants to automatically remediate non-compliant resources using AWS Systems Manager Automation documents. Which solution is MOST scalable and secure?

A.Create a Lambda function in each account that periodically checks Config rules and triggers remediation
B.Set up Amazon CloudWatch Events rules in each account to detect Config compliance changes and invoke remediation Lambda functions
C.Enable AWS Config rules with automatic remediation using SSM Automation documents in each account, and use an AWS Config aggregator to monitor compliance across all accounts
D.Use AWS Organizations service control policies to automatically remediate non-compliant resources
AnswerC

Automatic remediation must run locally in each account so SSM Automation can act on that account's resources without cross-account role sprawl; the aggregator then gives central visibility. This satisfies the scalability and security constraints by keeping remediation scoped per account while consolidating compliance monitoring.

Why this answer

It leverages AWS Config's native automatic remediation feature, which directly associates SSM Automation documents with Config rules to remediate non-compliant resources as soon as they are detected. This approach is scalable as it operates within each account without requiring custom Lambda functions or external triggers, and it is secure because remediation actions are defined and controlled by the SSM Automation documents, which can be centrally managed. The use of an AWS Config aggregator provides a single-pane-of-glass view across all accounts for monitoring compliance, meeting the security team's requirements efficiently.

Exam trap

The trap here is that candidates often confuse AWS Config's automatic remediation with custom event-driven approaches (like Lambda or CloudWatch Events) or mistakenly think SCPs can remediate resources, when in fact SCPs only prevent non-compliant actions from being taken, not fix existing non-compliant resources.

How to eliminate wrong answers

Option A is wrong because periodically checking Config rules with a Lambda function introduces latency and inefficiency, as it relies on polling rather than event-driven detection, and it requires managing Lambda functions in every account, which is less scalable and secure than using native Config remediation. Option B is wrong because while CloudWatch Events (now Amazon EventBridge) can detect compliance changes, invoking a Lambda function for remediation adds unnecessary complexity and custom code, whereas AWS Config's built-in automatic remediation is more direct and secure, eliminating the need for additional event processing. Option D is wrong because AWS Organizations service control policies (SCPs) are used to restrict permissions and enforce guardrails, not to automatically remediate non-compliant resources; SCPs cannot trigger remediation actions on existing resources.

504
MCQeasy

A company is using AWS Application Migration Service (MGN) to migrate hundreds of on-premises servers to AWS. After the migration, some servers fail a health check. What is the most efficient way to remediate the failed servers?

A.Launch test instances from MGN, diagnose the issues, then update the source servers and perform a final cutover.
B.Rerun the MGN replication and perform a new cutover.
C.Restore the servers from the latest AMI and re-run the health check.
D.Use AWS CloudEndure Migration to re-migrate the servers.
AnswerA

MGN test instances let you validate each server in AWS before cutover, so boot and health-check failures are diagnosed and fixed on the source servers first. This avoids repeated cutover attempts, making remediation efficient across hundreds of servers.

Why this answer

It follows the recommended MGN workflow for remediation: launch test instances to identify issues, fix them on the source server, and then perform a final cutover. Option B is inefficient as it restarts the entire replication and cutover process without testing. Option C is incorrect because restoring from a backup AMI is not part of the MGN migration process and does not allow iterative fixes.

Option D is wrong because CloudEndure Migration is the former name of MGN and is not a separate service for re-migration.

505
MCQhard

A company is building a high-performance computing (HPC) cluster on AWS for genomics research. The compute nodes require low-latency inter-node communication. Which networking solution should be used?

A.Elastic Fabric Adapter (EFA)
B.Enhanced Networking (ENA)
C.VPC Peering
D.AWS Direct Connect
AnswerA

Elastic Fabric Adapter provides kernel-bypass and OS-bypass capabilities, enabling tightly coupled HPC applications to communicate with far lower latency than standard TCP/IP over Elastic Network Adapter. It satisfies the stem's low-latency inter-node requirement, supporting MPI and NCCL collective operations essential for genomics workloads distributed across many compute nodes.

Why this answer

Elastic Fabric Adapter (EFA) is a network interface that enables HPC and machine learning applications to achieve low-latency inter-node communication by bypassing the operating system kernel and providing OS-bypass capabilities via the Libfabric library. This is essential for tightly coupled HPC workloads like genomics research, where MPI (Message Passing Interface) jobs require microsecond-level latency and high throughput between compute nodes.

Exam trap

The trap here is that candidates confuse Enhanced Networking (ENA) with Elastic Fabric Adapter (EFA), assuming both provide similar low-latency benefits, but only EFA offers OS-bypass for HPC inter-node communication, while ENA still relies on kernel processing.

How to eliminate wrong answers

Option B (Enhanced Networking with ENA) is wrong because while it provides higher bandwidth and lower jitter than standard networking, it still operates through the kernel network stack and does not support OS-bypass, so it cannot achieve the ultra-low latency required for tightly coupled HPC inter-node communication. Option C (VPC Peering) is wrong because it is a logical connection between VPCs used for routing traffic, not a physical network adapter or interface; it does not reduce latency or provide OS-bypass for compute nodes within the same cluster. Option D (AWS Direct Connect) is wrong because it establishes a dedicated network connection from on-premises to AWS, not between compute nodes within a VPC; it is irrelevant to inter-node communication latency inside an HPC cluster.

506
MCQmedium

A company is designing a new application that will run on EC2 instances behind an Application Load Balancer. The application must handle sudden spikes in traffic without manual intervention. Which scaling strategy should be used?

A.Manual scaling by operations team
B.Simple scaling with a cooldown period
C.Scheduled scaling based on historical data
D.Target tracking scaling policy
AnswerD

Target tracking scaling adjusts capacity automatically to hold a chosen metric, such as average CPU utilisation or request count per target, at a target value. It responds to sudden traffic spikes without manual intervention, unlike scheduled or simple step policies that need predefined thresholds.

Why this answer

Target tracking scaling policy is the correct choice because it automatically adjusts the number of EC2 instances to maintain a specified target metric (e.g., average CPU utilization or request count per target) without manual intervention. This policy uses a built-in metric and dynamically calculates the required capacity to handle sudden traffic spikes, aligning with the requirement for automatic scaling under unpredictable load.

Exam trap

The trap here is that candidates often confuse 'scheduled scaling' (which works for predictable patterns) with 'dynamic scaling' (which handles unpredictable spikes), and may overlook that target tracking is the only fully automated policy that continuously adjusts capacity based on a real-time metric without manual cooldown tuning.

How to eliminate wrong answers

Option A is wrong because manual scaling requires human intervention to add or remove instances, which cannot respond to sudden spikes in real time. Option B is wrong because simple scaling with a cooldown period uses a single step adjustment and then locks scaling actions during the cooldown, which can delay response to rapid traffic changes and cause under- or over-provisioning. Option C is wrong because scheduled scaling relies on predictable patterns from historical data and cannot react to unexpected spikes that deviate from the schedule.

507
MCQeasy

A company has a centralized logging solution using Amazon S3 and AWS CloudTrail. They want to ensure that logs are immutable and cannot be deleted or modified by any user, including the root user. Which S3 feature should be enabled?

A.S3 Object Lock in compliance mode.
B.S3 Versioning with a lifecycle policy.
C.S3 bucket policy denying s3:DeleteObject.
D.S3 MFA Delete.
AnswerA

S3 Object Lock in compliance mode prevents any principal, including the account root user, from overwriting or deleting protected object versions for the retention period. This satisfies the immutability constraint that standard bucket policies or versioning alone cannot guarantee.

Why this answer

S3 Object Lock in compliance mode ensures that objects are write-once-read-many (WORM) and cannot be deleted or overwritten by any user, including the root user. Compliance mode locks the retention period and prevents any user, even the AWS account root user, from shortening or removing the retention settings, making logs truly immutable.

Exam trap

The trap here is that candidates often choose a bucket policy denying s3:DeleteObject, not realizing that the root user can bypass bucket policies by modifying them, whereas S3 Object Lock in compliance mode provides a true immutability guarantee that even the root user cannot override.

How to eliminate wrong answers

Option B is wrong because S3 Versioning alone does not prevent deletion; it only preserves previous versions of objects, and a user with sufficient permissions can still delete the current version or the entire object. Option C is wrong because a bucket policy denying s3:DeleteObject can be overridden by a user with administrative privileges (including the root user) who can modify or remove the policy itself. Option D is wrong because MFA Delete only adds an extra authentication factor for delete operations but does not prevent deletion by the root user if they have the MFA device; it also does not prevent overwrites or modifications.

508
Multi-Selecthard

A company is migrating a containerized application from an on-premises Kubernetes cluster to Amazon Elastic Kubernetes Service (Amazon EKS). The application consists of multiple microservices that communicate with each other and with an on-premises database. The company wants to minimize changes to the application and ensure secure, low-latency connectivity between the EKS cluster and the on-premises database during and after the migration. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Use AWS App Mesh to manage service-to-service communication within the EKS cluster.
B.Expose the on-premises database to the internet and configure the EKS pods to connect using its public IP address.
C.Deploy the application to an Amazon EKS cluster and use AWS Direct Connect or AWS Site-to-Site VPN to connect the VPC to the on-premises network.
D.Migrate the on-premises database to Amazon RDS and update the application to use the new endpoint.
E.Configure an AWS Transit Gateway with a VPN attachment to route traffic between the VPC and the on-premises network.
AnswersC, E

Using AWS Direct Connect or AWS Site-to-Site VPN provides a private, low-latency connection between the EKS cluster's VPC and the on-premises network. This allows the containerized microservices to continue communicating with the on-premises database without exposing it to the public internet. Direct Connect offers dedicated bandwidth and consistent latency, while Site-to-Site VPN is a quicker, encrypted option. This action preserves the application's connectivity model with minimal changes.

Why this answer

The two correct actions are to establish private connectivity between the EKS VPC and the on-premises network using AWS Direct Connect or Site-to-Site VPN, and to use AWS Transit Gateway to centralize and route that traffic. These provide secure, low-latency communication to the on-premises database without exposing it to the internet or requiring application changes. The other options either address intra-cluster concerns, involve unnecessary database migration, or introduce insecure public access.

Exam trap

The trap here is focusing on service mesh or database migration instead of the hybrid network connectivity that is actually required to reach an on-premises database from Amazon EKS.

509
MCQeasy

A company is designing a multi-account strategy for its development, testing, and production environments. The security team requires that all accounts share a centralized logging solution. Which approach meets this requirement with the LEAST administrative overhead?

A.Configure each account to write logs to its own S3 bucket and use AWS Glue to copy them to a central bucket.
B.Use AWS CloudTrail to deliver logs to a central S3 bucket in the logging account.
C.Use Amazon CloudWatch Logs in each account and view logs from a central account via cross-account access.
D.Use Amazon Kinesis Data Firehose in each account to stream logs to a central Amazon OpenSearch Service.
AnswerB

CloudTrail can deliver events from every account in an organisation to one central S3 bucket using an organisation trail, requiring only a bucket policy and no per-account configuration, which minimises administrative overhead across development, testing and production.

Why this answer

AWS CloudTrail can be configured to deliver logs from multiple accounts to a single central S3 bucket in a logging account by setting up a CloudTrail trail in each account that points to the same bucket. This approach requires minimal administrative overhead as it leverages native AWS cross-account logging capabilities without additional data movement or transformation services.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing options that involve additional services (Glue, Kinesis, OpenSearch) or partial centralization (CloudWatch cross-account access), missing the simplicity and native support of CloudTrail's direct cross-account S3 delivery.

How to eliminate wrong answers

Option A is wrong because it introduces unnecessary complexity and administrative overhead by requiring each account to write logs to its own S3 bucket and then using AWS Glue to copy them to a central bucket; Glue is a serverless ETL service not designed for simple log replication, and this adds cost and management burden. Option C is wrong because while cross-account CloudWatch Logs access is possible, it requires setting up IAM roles and resource policies for each account and log group, and viewing logs from a central account does not centralize the logs themselves—logs remain in source accounts, increasing management overhead and potential access issues. Option D is wrong because using Kinesis Data Firehose in each account to stream logs to a central OpenSearch Service adds significant complexity, cost, and administrative overhead compared to a simple S3 bucket delivery, and OpenSearch Service is not a centralized logging solution by default—it requires additional configuration for log indexing and retention.

510
MCQeasy

A company is designing a new application that will process streaming data from IoT devices. The data must be ingested in real-time and stored in Amazon S3 for long-term analytics. Which AWS service should be used to ingest the streaming data?

A.Amazon Simple Notification Service (SNS)
B.Amazon Simple Queue Service (SQS)
C.AWS Database Migration Service (DMS)
D.Amazon Kinesis Data Streams
AnswerD

Kinesis Data Streams ingests records in real time with low latency and durable, ordered shards, then supports delivery into Amazon S3 via Firehose or consumers. This satisfies the stem's real-time ingestion and long-term S3 storage requirements.

Why this answer

Amazon Kinesis Data Streams is designed for real-time data ingestion and can stream data directly to Amazon S3. Option A is wrong because SNS is a pub/sub messaging service, not intended for real-time data ingestion. Option B is wrong because SQS is a message queue service, not optimized for streaming ingestion.

Option C is wrong because AWS DMS is used for database migration, not for ingesting streaming data.

511
MCQeasy

A company wants to provide temporary, limited-privilege credentials to its application running on an EC2 instance so that the application can access an S3 bucket. What is the BEST practice for achieving this?

A.Use an S3 bucket policy to allow access from the EC2 instance's public IP
B.Create an IAM user and store the credentials in the EC2 instance user data
C.Store AWS access keys in the application code
D.Create an IAM role with the necessary permissions and attach it to the EC2 instance
AnswerD

An IAM role attached to the instance delivers temporary credentials through the instance metadata service, which the AWS SDK and CLI retrieve and rotate automatically. This satisfies the limited-privilege, temporary-credential requirement without embedding long-lived access keys on the instance.

Why this answer

The best practice is to use an IAM role, which provides temporary security credentials via the EC2 instance metadata service (IMDS). The application automatically retrieves these credentials without hardcoding secrets, and the credentials are rotated automatically by AWS. This approach follows the principle of least privilege and eliminates the security risks of long-term access keys.

Exam trap

The trap here is that candidates may think storing credentials in user data or code is acceptable for automation, but AWS explicitly prohibits this in favor of IAM roles for EC2 to avoid long-term credential exposure.

How to eliminate wrong answers

Option A is wrong because restricting access by EC2 instance public IP is not secure (IPs can change, and other AWS services or instances could share the same IP) and does not provide temporary credentials. Option B is wrong because storing IAM user credentials in EC2 user data exposes long-term access keys, which can be compromised and require manual rotation. Option C is wrong because hardcoding AWS access keys in application code is a severe security risk, as the keys are static, can be exposed in version control, and violate the principle of least privilege.

512
MCQmedium

A company is implementing a multi-account strategy using AWS Organizations. They need to centralize logging of all API calls across accounts. Which solution meets this requirement with the least operational overhead?

A.Enable CloudWatch Logs in each account and stream to a central log group.
B.Create a CloudTrail trail in each account and aggregate logs to a central S3 bucket.
C.Create an organization trail in the management account with CloudTrail.
D.Enable S3 server access logs on all accounts and send to a central bucket.
AnswerC

An organisation trail created in the management account automatically applies to every member account, including future ones, capturing all API activity into a single S3 bucket. This satisfies the centralised logging requirement with minimal operational overhead, since no per-account configuration or maintenance is needed.

Why this answer

AWS Organizations supports creating an organization trail in the management account that automatically logs API calls for all member accounts without requiring per-account configuration. This centralizes logging with minimal operational overhead, as CloudTrail handles the aggregation across the organization.

Exam trap

The trap here is that candidates often think they need to configure CloudTrail in each account individually (Option B) or use CloudWatch Logs streaming (Option A), missing the organization trail feature that automatically centralizes logging with zero per-account effort.

How to eliminate wrong answers

Option A is wrong because streaming CloudWatch Logs from each account to a central log group requires per-account setup and additional log delivery infrastructure, increasing operational overhead. Option B is wrong because creating individual CloudTrail trails per account and aggregating to a central S3 bucket still requires manual configuration in each account and does not leverage the automatic organization-wide trail feature. Option D is wrong because S3 server access logs capture only S3-specific requests, not all API calls across services, and they require per-bucket configuration, failing to meet the requirement of centralizing all API calls.

513
MCQeasy

A company uses AWS Organizations with multiple accounts. The central IT team wants to restrict the use of specific EC2 instance types across all accounts to control costs. Which approach should the team use?

A.Use AWS Budgets to send alerts when costs exceed a threshold.
B.Configure Amazon CloudWatch Events to detect launches and terminate instances.
C.Attach an IAM policy to each account's root user to deny the ec2:RunInstances action for certain instance types.
D.Create a service control policy (SCP) that denies the ec2:RunInstances action for prohibited instance types and apply it to the organization.
AnswerD

An SCP applied at the organisation root enforces the instance-type restriction across every member account, satisfying the requirement to govern all accounts centrally. The ec2:RunInstances deny with a condition on instance type blocks launches regardless of each account's IAM permissions, since SCPs define the maximum available permissions.

Why this answer

Service control policies (SCPs) are the correct mechanism to centrally restrict permissions across all accounts in an AWS Organization. By creating an SCP that denies the ec2:RunInstances action for specific instance types and applying it to the organization (or relevant OUs), the central IT team can enforce this restriction globally, preventing any IAM principal in any account from launching prohibited instance types, regardless of their IAM permissions.

Exam trap

The trap here is that candidates often confuse IAM policies with SCPs, thinking that attaching a deny policy to the root user or individual IAM users is sufficient, but SCPs are the only mechanism that can enforce restrictions across all principals in an AWS Organization account, including the root user.

How to eliminate wrong answers

Option A is wrong because AWS Budgets only sends cost alerts and does not enforce restrictions on resource creation; it cannot prevent the launch of specific instance types. Option B is wrong because Amazon CloudWatch Events can detect instance launches and trigger a Lambda function to terminate them, but this is a reactive, non-deterministic approach that incurs cost and latency, and instances may run briefly before termination. Option C is wrong because attaching an IAM policy to each account's root user does not prevent other IAM users or roles in the account from launching instances, and it is not scalable across many accounts; SCPs are the only way to apply a deny across all principals in an account.

514
MCQeasy

A company is migrating an on-premises application to AWS. The application requires dedicated hardware for licensing compliance. Which AWS service should the company use to meet this requirement?

A.Amazon EC2 Dedicated Hosts
B.AWS Elastic Beanstalk
C.Amazon EC2 Reserved Instances
D.Amazon Virtual Private Cloud (VPC)
AnswerA

Amazon EC2 Dedicated Hosts provide a physical server fully dedicated to your use, giving visibility and control over socket and core allocation. This satisfies the licensing compliance constraint, since bring-your-own-licence terms tied to physical cores or sockets require dedicated hardware rather than shared tenancy.

Why this answer

Amazon EC2 Dedicated Hosts provide a physical server dedicated to a single customer, which is required for licensing compliance with certain software (e.g., Windows Server, SQL Server) that is licensed per-socket or per-core. This meets the requirement for dedicated hardware.

Exam trap

The trap is confusing Dedicated Hosts with Dedicated Instances or Reserved Instances; candidates may think that Reserved Instances provide dedicated hardware, but they only provide a billing discount, not physical isolation.

How to eliminate wrong answers

Option B is wrong because AWS Elastic Beanstalk is a PaaS service for deploying applications, not for providing dedicated hardware. Option C is wrong because EC2 Reserved Instances are a billing discount, not a dedicated hardware offering; they do not provide physical isolation. Option D is wrong because Amazon VPC is a virtual network, not a dedicated hardware service.

515
MCQeasy

A company is migrating a legacy application that uses an Oracle database to AWS. The application is critical and requires high availability with automatic failover. The company wants to use Amazon RDS for Oracle. The database size is 200 GB. The company needs a solution that provides automatic failover to a standby instance in a different Availability Zone with minimal downtime. Which RDS deployment option should the company use?

A.Multi-Region deployment with Read Replicas
B.Single-AZ deployment with Oracle Data Guard
C.Single-AZ deployment with automatic backups
D.Multi-AZ deployment
AnswerD

Multi-AZ maintains a synchronous standby replica in a second Availability Zone, so RDS performs automatic failover to it on failure, typically within one to two minutes. This satisfies the stem's demand for automatic failover with minimal downtime for the 200 GB Oracle database.

Why this answer

Amazon RDS Multi-AZ deployment maintains a synchronous standby replica in a different Availability Zone and automatically fails over to it in the event of a primary failure, with minimal downtime (typically 60-120 seconds). It requires no application changes and uses a DNS CNAME that is updated on failover. This directly meets the requirement for automatic failover to a standby in a different AZ.

Exam trap

SAP-C02 often tests the confusion between Multi-AZ (automatic failover, synchronous, same region) and Read Replicas (read scaling, asynchronous, manual promotion) — candidates pick Read Replicas for HA when Multi-AZ is required.

How to eliminate wrong answers

Option A is wrong because Multi-Region with Read Replicas is for cross-region disaster recovery and read scaling, not automatic in-region failover; Read Replicas are asynchronous and require manual promotion. Option B is wrong because Single-AZ with Oracle Data Guard is not an RDS-managed feature — RDS Multi-AZ uses its own replication, and Data Guard is for self-managed Oracle on EC2. Option C is wrong because Single-AZ with automatic backups provides point-in-time recovery but no standby instance and no automatic failover — recovery requires restoring a snapshot, causing significant downtime.

516
MCQhard

A company is migrating a monolithic application to a serverless architecture using AWS Lambda. The application reads and writes to an Amazon RDS for PostgreSQL database. The database connection pool is exhausted during peak traffic. Which design change should a solutions architect recommend to avoid connection exhaustion?

A.Use Amazon SQS to buffer write requests to the database.
B.Use DynamoDB Accelerator (DAX) as a caching layer.
C.Use Amazon RDS Proxy to pool and share database connections.
D.Increase the max_connections parameter in the RDS parameter group.
AnswerC

Lambda's per-invocation concurrency opens many direct PostgreSQL connections, exhausting the pool. RDS Proxy maintains a shared pool and multiplexes Lambda connections onto it, so the constraint of connection exhaustion at peak traffic is removed without changing application logic.

Why this answer

Amazon RDS Proxy sits between the Lambda function and the RDS database, managing a pool of database connections and reusing them across multiple invocations. This prevents the Lambda function from exhausting the database connection pool during traffic spikes, as each Lambda instance does not need to open its own connection. RDS Proxy also handles connection multiplexing and reduces the overhead of establishing new connections.

Exam trap

The trap here is that candidates often think increasing max_connections or using a queue (SQS) is sufficient, but they overlook that Lambda's concurrent execution model requires connection pooling at the database layer, which RDS Proxy uniquely provides.

How to eliminate wrong answers

Option A is wrong because Amazon SQS buffers write requests but does not address the root cause of connection exhaustion; it only decouples the write path, leaving read operations and other direct database interactions still vulnerable to connection pool exhaustion. Option B is wrong because DynamoDB Accelerator (DAX) is an in-memory cache for DynamoDB, not for Amazon RDS for PostgreSQL, and it cannot pool or manage database connections. Option D is wrong because increasing the max_connections parameter only raises the limit, but does not prevent Lambda from opening too many connections; it can lead to resource contention and still exhaust database resources under high concurrency.

517
MCQhard

A financial services company uses AWS Organizations with 300 member accounts. The security team wants to ensure that all AWS API activity in every account is logged to a central Amazon S3 bucket owned by the management account. The logs must be immutable for 7 years and protected from deletion by any member account administrator. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

A.Enable AWS Config in all accounts with a conformance pack that checks for CloudTrail logging, and configure an AWS Lambda function to copy trail logs to a central S3 bucket with a lifecycle policy.
B.Create an individual trail in each member account that delivers to a central S3 bucket, and use a bucket policy that denies s3:DeleteObject to all principals except the management account.
C.Create an organization trail in the management account that applies to all accounts, configure the trail to deliver to a central S3 bucket, and enable S3 Object Lock in compliance mode with a 7-year retention period on the bucket.
D.Use AWS CloudTrail Lake in the management account to ingest events from all member accounts, and configure a 7-year retention period on the event data store.
AnswerC

An organization trail created in the management account automatically applies to all existing and future accounts in the organization, eliminating per-account configuration. Delivering to a central S3 bucket with S3 Object Lock in compliance mode enforces immutability for the retention period, and member account administrators cannot override or delete the objects, satisfying both centralization and protection requirements.

Why this answer

An organization trail in the management account automatically applies to all current and future accounts, providing centralized logging with minimal effort. Delivering to a central S3 bucket with S3 Object Lock in compliance mode ensures that logs cannot be deleted or altered by any user, including the root user, for the specified retention period. This meets the immutability and centralization requirements with the least operational overhead.

Exam trap

The trap here is assuming that a bucket policy denying delete operations provides the same immutability as S3 Object Lock, but bucket policies can be modified by administrators with sufficient permissions.

518
MCQmedium

A company is using AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a specific member account. What must be done?

A.Create an IAM role in the member account with permissions to manage Identity Center
B.Use the AWS Organizations console to register the member account as a delegated administrator for IAM Identity Center
C.Attach an SCP to the member account allowing Identity Center actions
D.Create a new user in the management account with admin privileges
AnswerB

Registering the member account as a delegated administrator for IAM Identity Center, through the AWS Organizations console or `register-delegated-administrator`, grants that account permission to manage Identity Center centrally. This satisfies the stem's requirement to delegate administration while retaining management from the organisation's management account.

Why this answer

To delegate administration of IAM Identity Center to a specific member account in AWS Organizations, you must register that account as a delegated administrator using the AWS Organizations console or API. This grants the member account the necessary permissions to manage Identity Center settings, users, and groups without requiring the management account to perform all tasks. Option B is correct because it follows the official AWS mechanism for delegating administrative control of Identity Center to a member account.

Exam trap

The trap here is that candidates often confuse delegating administration with simply granting IAM permissions via roles or SCPs, not realizing that AWS requires a specific registration process through Organizations to enable delegated administration for Identity Center.

How to eliminate wrong answers

Option A is wrong because creating an IAM role in the member account with permissions to manage Identity Center does not establish the required delegation relationship; Identity Center delegation must be registered at the Organizations level, not via a local IAM role. Option C is wrong because attaching a service control policy (SCP) to the member account only restricts or allows actions at the account level but does not delegate administrative authority for Identity Center; SCPs are for permission boundaries, not delegation. Option D is wrong because creating a new user in the management account with admin privileges does not delegate administration to a member account; it keeps all control in the management account and does not enable the member account to manage Identity Center independently.

519
MCQmedium

A company is using Amazon CloudFront to serve content from an S3 origin. The content is updated infrequently. Users in some regions report seeing stale content. The company wants to ensure that users always see the latest version without waiting for TTL expiration. What is the MOST cost-effective solution?

A.Use file versioning in the URL (e.g., appending a query string or using a unique object key).
B.Set a very short TTL (e.g., 0 seconds) for the CloudFront distribution.
C.Use an origin shield to reduce the number of requests to S3.
D.Create a CloudFront invalidation request for the changed files after each update.
AnswerA

Appending a version identifier to the URL creates a distinct cache key, so CloudFront fetches the new object immediately rather than serving the stale cached copy until TTL expiry. This satisfies the freshness requirement at minimal cost, avoiding invalidation charges.

Why this answer

File versioning (changing the URL or appending a query string) is the most cost-effective solution because it guarantees that users always fetch the latest version from the origin without waiting for TTL expiration. This approach avoids the costs associated with CloudFront invalidations (Option D) and does not increase load on the origin as a very short TTL would (Option B). Option C (origin shield) helps reduce requests to the origin but does not force existing cached content to be refreshed.

Therefore, file versioning is the best practice for infrequently updated content.

520
MCQhard

A company is migrating a large-scale Apache Kafka cluster to Amazon MSK. The cluster has 100 topics with high throughput. The team wants to minimize operational overhead and ensure high availability. Which configuration should be used?

A.Use Amazon Kinesis Data Streams with enhanced fan-out.
B.Use Amazon SQS FIFO queues with message deduplication.
C.Deploy Apache Kafka on Amazon EC2 with Spot Instances and EBS volumes.
D.Provision an Amazon MSK cluster with 3 brokers per AZ across 3 AZs.
AnswerD

Spreading three brokers per Availability Zone across three AZs gives replication factor tolerance and automatic broker failover, meeting the high-availability requirement. Distributing partitions across nine brokers also absorbs the high throughput of 100 topics while MSK manages patching and recovery, minimising operational overhead.

Why this answer

Amazon MSK is the managed Kafka service that minimizes operational overhead while providing high availability when brokers are spread across multiple Availability Zones. Provisioning 3 brokers per AZ across 3 AZs gives replication factor and rack-awareness that survive an AZ failure, and MSK handles patching, broker replacement, and monitoring. This directly matches the requirement to migrate a large Kafka cluster with minimal ops overhead and HA.

Exam trap

SAP-C02 often tests the misconception that any streaming service is interchangeable with Kafka — candidates pick Kinesis or SQS for a 'Kafka migration,' missing that only MSK preserves Kafka APIs and semantics while providing managed HA across AZs.

How to eliminate wrong answers

Option A is wrong because Kinesis Data Streams is a different service with different APIs and semantics — it is not Kafka-compatible, so migrating an existing Kafka cluster would require rewriting producers/consumers and losing Kafka features like consumer groups, topics, and partitions. Option B is wrong because SQS FIFO is a queue, not a streaming log — it lacks Kafka's topic/partition model, replay, and ordering guarantees across partitions, and FIFO throughput is limited compared to Kafka. Option C is wrong because self-managing Kafka on EC2 with Spot Instances introduces significant operational overhead and Spot interruptions risk availability — the opposite of 'minimize operational overhead and ensure high availability.'

521
Multi-Selectmedium

A company is migrating a legacy application to AWS. The application runs on a single EC2 instance and uses an attached EBS volume for data storage. The company wants to improve high availability. Which THREE actions should the company take? (Choose three.)

Select 3 answers
A.Migrate the database to Amazon RDS with Multi-AZ deployment.
B.Use an EBS volume with higher IOPS to improve performance.
C.Store data on the instance store instead of EBS to reduce latency.
D.Place the EC2 instance in an Auto Scaling group that spans multiple Availability Zones.
E.Place the EC2 instances behind an Application Load Balancer.
AnswersA, D, E

Migrating to Amazon RDS with Multi-AZ satisfies the high-availability constraint by replacing a single-instance database with a synchronously replicated standby in a second Availability Zone. Automatic failover redirects the endpoint during an AZ outage, eliminating the EBS volume's single point of failure without application connection-string changes.

Why this answer

Option A is correct because migrating the database to Amazon RDS with a Multi-AZ deployment provides automatic failover to a standby replica in a different Availability Zone, eliminating the single point of failure for data storage and improving availability. Option D is correct because placing the EC2 instance in an Auto Scaling group spanning multiple Availability Zones allows the application to be launched in more than one AZ and automatically replaced if an instance or AZ fails. Option E is correct because placing the EC2 instances behind an Application Load Balancer distributes incoming traffic across healthy targets in multiple AZs and routes around failed instances, which is essential for high availability.

Option B is incorrect because increasing EBS IOPS only improves performance, not availability, and does not address single-instance or single-AZ failure. Option C is incorrect because instance store is ephemeral and tied to a single host, so it reduces durability and availability rather than improving it.

Exam trap

SAP-C02 often tests the confusion between performance improvements (higher IOPS, instance store) and availability improvements (Multi-AZ, ASG across AZs, ALB), so candidates must map each option to the correct pillar.

522
MCQeasy

A company needs to provide a global content delivery solution with low latency. Which AWS service should they use?

A.Amazon S3
B.Amazon EC2
C.Amazon Route 53
D.Amazon CloudFront
AnswerD

Amazon CloudFront caches content at edge locations worldwide, delivering objects from the point of presence nearest each user. This directly satisfies the low-latency requirement by shortening the network path, rather than serving every request from a single regional origin. It also integrates with AWS Shield and AWS WAF for protection at the edge.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches content at edge locations worldwide, reducing latency by serving data from the nearest edge to the user. It integrates with origins like S3, EC2, or on-premises servers and supports both static and dynamic content acceleration, making it the correct choice for low-latency global delivery.

Exam trap

The trap here is that candidates often confuse Amazon S3's static website hosting or Route 53's latency-based routing with actual content delivery, but neither provides the edge caching and global distribution that CloudFront offers for low-latency delivery.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service, not a content delivery network; it stores data in a single region and does not provide global edge caching or low-latency distribution on its own. Option B is wrong because Amazon EC2 is a compute service that runs virtual servers in specific regions; it lacks built-in global edge caching and would require manual scaling and additional services to achieve low-latency delivery worldwide. Option C is wrong because Amazon Route 53 is a DNS and traffic management service; it resolves domain names to IP addresses but does not cache or deliver content, so it cannot reduce latency for content delivery.

523
Multi-Selecthard

A company is designing a new multi-tier application on AWS. The application will use an Application Load Balancer (ALB) to distribute traffic to Amazon EC2 instances in an Auto Scaling group. The company requires that the application be highly available across multiple Availability Zones and that it can scale automatically based on demand. The company also wants to ensure that the application can handle sudden spikes in traffic without manual intervention. Which two actions should a solutions architect recommend to meet these requirements? (Choose two.)

Select 2 answers
A.Enable cross-zone load balancing on the ALB and configure the Auto Scaling group to use a single Availability Zone.
B.Use a Network Load Balancer (NLB) instead of an Application Load Balancer (ALB) to improve performance.
C.Create a target tracking scaling policy based on average CPU utilization to automatically adjust the number of instances.
D.Configure the Auto Scaling group to use multiple Availability Zones and set the minimum capacity to at least two instances.
E.Configure a scheduled scaling policy to add instances at predicted peak times.
AnswersC, D

A target tracking scaling policy automatically scales the Auto Scaling group to maintain a target metric, such as average CPU utilization. This handles sudden spikes in traffic by adding instances as needed, and scales in during low demand, providing automatic scaling without manual intervention.

Why this answer

To achieve high availability, the Auto Scaling group must span multiple Availability Zones with a minimum capacity of at least two instances. To handle sudden spikes automatically, a target tracking scaling policy based on a metric like CPU utilization dynamically adjusts capacity. Together, these actions provide both resilience and elasticity without manual intervention.

Exam trap

The trap here is assuming that a Network Load Balancer or cross-zone load balancing alone can provide high availability, when in fact the Auto Scaling group must be configured across multiple AZs with sufficient minimum capacity.

524
MCQmedium

A company is migrating a legacy three-tier application to AWS. The application consists of a Java-based web tier, a business logic tier running on Windows Server 2012, and a Microsoft SQL Server database. The company wants to minimize changes to the application and reduce operational overhead. The business logic tier uses Windows authentication and accesses the database via integrated security. The company requires a highly available architecture across multiple Availability Zones. Which migration strategy should a solutions architect recommend?

A.Repurchase a SaaS solution that provides similar functionality, and retire the legacy application.
B.Refactor the application into microservices running on Amazon ECS, and use Amazon DynamoDB for data storage.
C.Replatform the web tier to AWS Elastic Beanstalk, rehost the business logic tier on EC2, and migrate the database to Amazon Aurora MySQL.
D.Rehost the web tier and business logic tier on Amazon EC2 instances, and migrate the database to Amazon RDS for SQL Server with Multi-AZ.
AnswerD

Rehosting the application tiers on EC2 preserves the existing Java and Windows Server 2012 environment with minimal modifications. Migrating the database to Amazon RDS for SQL Server with Multi-AZ supports Windows authentication and integrated security, and provides high availability across Availability Zones. This approach aligns with the goal of minimizing changes and reducing operational overhead by offloading database management to AWS.

Why this answer

Rehosting the application tiers on EC2 and migrating the database to RDS for SQL Server with Multi-AZ is the most suitable strategy. It preserves the existing application code and authentication mechanisms, while providing high availability and reducing operational overhead by leveraging a managed database service. This approach aligns with the rehost migration pattern and meets the requirements.

Exam trap

The trap here is assuming that replatforming to a managed service like Elastic Beanstalk or Aurora always reduces operational overhead, but it often requires code changes and may not support Windows authentication.

525
MCQmedium

A company plans to migrate a legacy on-premises web application to AWS using the 7 Rs (Rehost, Replatform, etc.). The application has tightly coupled components and unpredictable traffic. The team wants to minimize migration risk and time. Which migration strategy should they use?

A.Replatform
B.Rehost (lift-and-shift)
C.Repurchase
D.Retire
AnswerB

Rehosting moves the tightly coupled application onto Amazon EC2 unchanged, avoiding refactoring risk and delivering the fastest migration timeline. The unpredictable traffic pattern is absorbed by EC2 Auto Scaling, which adds or removes instances on demand without altering the application's internal architecture.

Why this answer

Rehost (lift-and-shift) moves the application to AWS with minimal changes, preserving the tightly coupled architecture and avoiding refactoring risk. Because the components are tightly coupled and traffic is unpredictable, re-architecting or replatforming would add time and risk. Rehost is the fastest, lowest-risk path when the goal is to minimize migration risk and time.

Exam trap

SAP-C02 often tests the trade-off between speed/risk and cloud optimization, baiting candidates toward Replatform when the question emphasizes minimal risk and time.

How to eliminate wrong answers

Option A is wrong because Replatform requires modifying the application or its dependencies (e.g., swapping a self-managed database for RDS), which adds effort and risk for a tightly coupled app. Option C is wrong because Repurchase means replacing the application with a SaaS product, which is a functional change, not a low-risk migration. Option D is wrong because Retire means decommissioning the application — the company wants to migrate it, not remove it.

Page 6

Page 7 of 14

Page 8