Courseiva

AWS Certified Solutions Architect Professional SAP-C02 (SAP-C02) — Questions 526–600

984 questions total · 14pages · All types, answers revealed

Page 7

Page 8 of 14

Page 9
526
Multi-Selectmedium

A company is migrating a critical application to AWS using a rehost (lift-and-shift) approach. The application consists of a web tier and a database tier. The company wants to ensure high availability and disaster recovery. Which TWO actions should the company take? (Choose TWO.)

Select 2 answers
A.Configure Amazon EC2 Auto Scaling to launch instances across multiple AWS Regions.
B.Deploy the web tier across multiple Availability Zones.
C.Use Amazon RDS Multi-AZ for the database tier.
D.Use Amazon RDS read replicas to offload read traffic.
E.Use a single Availability Zone for the database to reduce latency.
AnswersB, C

Spreading the web tier across multiple Availability Zones places instances behind an Application Load Balancer, so an AZ failure does not take the application offline. This satisfies the high availability and disaster recovery requirement without altering the rehosted application's architecture or code.

Why this answer

Option B is correct because deploying the web tier across multiple Availability Zones ensures that if one AZ fails, the application remains available through instances in another AZ, which is a fundamental high-availability design for a rehosted web tier on EC2. Option C is correct because Amazon RDS Multi-AZ maintains a synchronous standby replica in a different AZ and automatically fails over the database endpoint during an AZ outage or primary failure, providing high availability for the database tier. Option A is not appropriate because EC2 Auto Scaling operates within a single Region across AZs; it cannot launch instances across multiple AWS Regions, and cross-Region scaling is not a standard Auto Scaling capability.

Option D is not the best fit because read replicas are primarily for scaling read-heavy workloads and are asynchronous, so they do not provide automatic failover for high availability. Option E is incorrect because confining the database to a single AZ creates a single point of failure and undermines the disaster recovery and high availability goals.

Exam trap

SAP-C02 often tests the confusion between Multi-AZ (synchronous HA, automatic failover) and read replicas (asynchronous, read scaling/DR) — candidates pick read replicas for HA when Multi-AZ is the correct answer.

527
MCQeasy

A company stores sensitive data in an S3 bucket encrypted with SSE-KMS. They need to audit all access requests to the bucket. Which AWS service should they use?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.AWS Config
D.AWS CloudTrail
AnswerD

CloudTrail records S3 data events, capturing every object-level access request including the caller identity, time, and API action. Enabling data event logging on the bucket provides the complete audit trail of access requests that SSE-KMS encryption alone cannot supply.

Why this answer

AWS CloudTrail logs all API calls made to S3, including requests to decrypt KMS keys. This enables auditing of all access requests to the bucket. AWS Config (C) records resource configuration changes, not access requests.

VPC Flow Logs (A) capture network traffic, not API calls. CloudWatch Logs (B) can store and monitor logs but does not generate logs from S3 access by itself.

528
Matchingmedium

Match each AWS cost management tool to its use.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Visualize and explore cost and usage data

Set custom cost and usage budgets with alerts

Recommendations for cost optimization, performance, security

Flexible pricing model for compute savings

Recommend optimal compute resources based on usage

Why these pairings

Correct matches: Cost Explorer visualizes costs, Budgets set alerts, Trusted Advisor recommends optimizations, and CUR provides detailed data. Common confusions involve mixing tool capabilities.

529
Multi-Selecthard

A company is migrating a high-volume transactional database from on-premises to Amazon Aurora PostgreSQL. The database uses sequences, triggers, and stored procedures. The company needs to minimize downtime during cutover and ensure data consistency. Which two actions should be taken to meet these requirements? (Choose two.)

Select 2 answers
A.Take a full database backup and restore it to Aurora PostgreSQL using native tools.
B.Use the AWS Schema Conversion Tool (AWS SCT) to convert the database schema and stored procedures.
C.Use AWS Snowball Edge to transfer the database files to Amazon S3 and then load them into Aurora.
D.Use AWS Database Migration Service (AWS DMS) with change data capture (CDC) for ongoing replication.
E.Configure Aurora PostgreSQL as a read replica of the on-premises database.
AnswersB, D

AWS SCT converts the source schema, including sequences, triggers, and stored procedures, to a format compatible with Aurora PostgreSQL. This addresses the code-level incompatibilities that would otherwise require manual rewriting. It is essential for heterogeneous migrations to ensure the target database functions correctly after cutover.

Why this answer

AWS DMS with CDC provides ongoing replication to keep the target in sync with minimal downtime, while AWS SCT converts the schema and procedural code to Aurora PostgreSQL. Together, they address both data consistency and code compatibility for a heterogeneous migration. The other options either cause downtime, are technically infeasible, or do not handle schema conversion.

Exam trap

The trap here is thinking that a native backup and restore can suffice for a heterogeneous migration, ignoring the need for schema conversion and ongoing replication.

530
Multi-Selecthard

A company is migrating a legacy application to AWS. The application consists of several components that communicate via TCP. The solutions architect must design a solution that minimizes operational overhead and provides high availability. Which TWO strategies should be used?

Select 2 answers
A.Use instance store volumes for data persistence.
B.Use managed services like Amazon RDS and Amazon ElastiCache to reduce operational overhead.
C.Use Spot Instances for all compute resources.
D.Use VPC Peering to connect components.
E.Use an Application Load Balancer to distribute traffic across multiple EC2 instances.
AnswersB, E

Managed services reduce overhead and provide HA out-of-the-box.

Why this answer

Using managed services like Amazon RDS and Amazon ElastiCache offloads administrative tasks such as patching, backups, and replication setup, significantly reducing operational overhead. Option E is correct because an Application Load Balancer (ALB) distributes incoming TCP traffic across multiple EC2 instances in different Availability Zones, providing high availability and fault tolerance for the application components.

Exam trap

The trap here is that candidates may confuse high availability with data persistence, incorrectly choosing instance store volumes (Option A) for persistence, or assume that Spot Instances (Option C) can be used for all compute resources despite their interruption risk, overlooking the need for reliable TCP communication in a production migration.

531
MCQhard

A company runs a high-traffic web application on Amazon EC2 instances behind an Application Load Balancer. The application experiences intermittent latency spikes during peak hours. Analysis shows that the latency spikes correlate with high CPU utilization on the EC2 instances. The company wants to reduce latency without over-provisioning. Which solution is MOST cost-effective and scalable?

A.Add Amazon ElastiCache to cache database queries.
B.Use Spot Instances to reduce costs and scale horizontally.
C.Increase the EC2 instance size to handle peak loads.
D.Configure an Auto Scaling group with a target tracking scaling policy based on average CPU utilization.
AnswerD

Target tracking adjusts desired capacity dynamically against average CPU utilisation, matching the observed correlation between CPU load and latency. It scales out only when demand rises, satisfying the no-over-provisioning constraint while remaining elastic and cost-effective during peak hours.

Why this answer

A target tracking scaling policy based on average CPU utilization automatically adjusts the number of EC2 instances in the Auto Scaling group to maintain a target CPU utilization level. This directly addresses the latency spikes caused by high CPU utilization during peak hours by scaling out horizontally, while scaling in during low traffic to avoid over-provisioning, making it both cost-effective and scalable.

Exam trap

The trap here is that candidates may confuse addressing the symptom (high CPU) with vertical scaling (Option C) or cost-saving measures (Option B), rather than recognizing that horizontal auto-scaling with a target tracking policy is the most cost-effective and scalable solution for handling intermittent latency spikes caused by CPU utilization.

How to eliminate wrong answers

Option A is wrong because caching database queries with ElastiCache reduces database load and query latency, but does not directly address high CPU utilization on the EC2 instances themselves, which is the root cause of the latency spikes. Option B is wrong because Spot Instances are cost-effective but can be interrupted with a two-minute warning, making them unsuitable for a high-traffic web application that requires consistent availability and low latency during peak hours. Option C is wrong because increasing the EC2 instance size (vertical scaling) is less cost-effective and scalable than horizontal scaling, as it leads to over-provisioning during off-peak hours and has a hard limit on instance size, failing to handle unpredictable traffic spikes efficiently.

532
MCQmedium

A company runs a production application on Amazon EC2 instances behind an Application Load Balancer. Recently, error rates increased due to a misconfiguration. The operations team wants to automatically roll back to the previous working configuration if errors exceed a threshold. Which solution provides the fastest rollback?

A.Manually restore AMI snapshots of the previous deployment.
B.Use AWS Elastic Beanstalk with rolling updates and health checks.
C.Use AWS CloudFormation with a stack policy to prevent updates.
D.Implement AWS CodeDeploy with automatic rollback triggered by CloudWatch alarms.
AnswerD

CodeDeploy deployment groups can bind CloudWatch alarms; when the alarm threshold breaches, CodeDeploy automatically reverts to the last known-good revision. This restores the previous configuration within minutes, far faster than manual redeployment, satisfying the fastest-rollback constraint.

Why this answer

AWS CodeDeploy with automatic rollback triggered by CloudWatch alarms provides the fastest rollback because it continuously monitors application health via CloudWatch metrics and automatically reverts to the last known good revision when an alarm threshold is breached. This automation minimizes manual intervention and downtime, enabling rapid recovery from misconfigurations.

Exam trap

SAP-C02 often tests the difference between automated rollback mechanisms and manual or preventive measures, causing candidates to choose options that either lack automation or do not directly trigger rollback based on error thresholds.

How to eliminate wrong answers

Option A is wrong because manually restoring AMI snapshots is slow, error-prone, and does not provide automated rollback based on error thresholds. Option B is wrong because Elastic Beanstalk rolling updates with health checks can roll back, but it is not as fast or as tightly integrated with CloudWatch alarms for automatic rollback as CodeDeploy. Option C is wrong because a CloudFormation stack policy prevents updates but does not automatically roll back to a previous working configuration upon error detection.

533
Multi-Selecthard

A company is deploying a new financial application on AWS that requires strict compliance with PCI DSS. The application will store sensitive cardholder data in an Amazon S3 bucket. The security team needs to ensure that data is encrypted at rest and that access is audited. They also need to be able to prove that encryption keys are rotated annually. Which two actions should be taken to meet these requirements? (Choose two.)

Select 2 answers
A.Enable default encryption on the S3 bucket using SSE-KMS with a customer managed key.
B.Enable versioning on the S3 bucket to protect against accidental deletion.
C.Enable default encryption on the S3 bucket using SSE-S3.
D.Configure AWS CloudTrail to log S3 data events for the bucket.
E.Enable S3 server access logging to a separate bucket.
AnswersA, D

SSE-KMS with a customer managed key allows you to control the key policy, enable automatic annual rotation, and audit key usage with AWS CloudTrail. This meets the requirements for encryption at rest, key rotation, and auditing. You can also use KMS grants to control access.

Why this answer

To meet encryption at rest with provable key rotation, use SSE-KMS with a customer managed key, which allows you to enable automatic annual rotation and audit key usage. To audit access to the data, enable CloudTrail data events for the S3 bucket, which logs object-level operations and KMS key usage. Together, these provide the necessary encryption and auditing controls.

Exam trap

The trap here is assuming that SSE-S3 provides sufficient key management control to prove annual rotation, when in fact only customer managed KMS keys allow you to demonstrate rotation to auditors.

534
MCQeasy

A company wants to allow developers to assume a role in a production account from their development account using AWS IAM. What is needed for this cross-account access?

A.A role in the dev account with permissions to access production resources.
B.An IAM user in the production account with permissions to switch roles.
C.A role in the production account with a trust policy allowing the dev account, and an IAM policy in the dev account allowing sts:AssumeRole.
D.An SCP that allows sts:AssumeRole from the dev account.
AnswerC

Cross-account role assumption needs two grants: the production role's trust policy must name the development account as principal, and the development identity needs an IAM policy permitting sts:AssumeRole on that role's ARN. Both halves are required for the call to succeed.

Why this answer

Cross-account IAM role access requires a role in the target (production) account with a trust policy that explicitly lists the source (development) account as a trusted principal, and an IAM policy in the source account that grants the sts:AssumeRole action for that role's ARN. This two-part configuration establishes a secure delegation path where the dev account's users or roles can request temporary credentials from the production account via the AWS Security Token Service (STS).

Exam trap

The trap here is that candidates often confuse the direction of the trust relationship, mistakenly thinking the role must be in the source account (dev) rather than the target account (production), or they overlook that both a trust policy and an IAM permissions policy are required for cross-account access.

How to eliminate wrong answers

Option A is wrong because a role in the dev account cannot directly access production resources; cross-account access requires the role to be in the production account, not the dev account. Option B is wrong because an IAM user in the production account with permissions to switch roles would only allow that user to assume roles within the same account, not from an external dev account; cross-account access requires a trust policy on the production role that authorizes the dev account. Option D is wrong because an SCP (Service Control Policy) is an organization-level policy that can restrict actions but cannot grant permissions; it can only deny or allow actions at the account level, and it does not establish the trust relationship needed for cross-account role assumption.

535
MCQmedium

A company is designing a serverless application using AWS Lambda. The function needs to access a VPC resource. What is the correct way to configure this?

A.Attach an Internet Gateway to the VPC
B.Assign the Lambda function to the VPC and configure a security group
C.Set up a VPC peering connection
D.Configure a NAT Gateway in the public subnet
AnswerB

Attaching the function to the VPC places its elastic network interfaces in specified subnets, and the security group controls outbound and inbound traffic to the VPC resource. This satisfies the requirement to reach a private VPC resource.

Why this answer

Lambda functions must be attached to a VPC and assigned a security group to access resources within the VPC, such as an RDS database or an Elasticache cluster. This configuration creates an elastic network interface (ENI) in the VPC, allowing the function to communicate with VPC resources via private IP addresses. The security group acts as a virtual firewall to control inbound and outbound traffic for the Lambda function.

Exam trap

The trap here is that candidates often confuse external connectivity (Internet Gateway, NAT Gateway) with internal VPC access, mistakenly thinking those components are required for a Lambda function to reach resources within the same VPC.

How to eliminate wrong answers

Option A is wrong because an Internet Gateway enables communication between a VPC and the internet, not direct access to VPC resources from a Lambda function; Lambda already uses a VPC-attached ENI for private connectivity. Option C is wrong because VPC peering connects two separate VPCs, but the Lambda function needs to be directly attached to the target VPC, not rely on a peering connection. Option D is wrong because a NAT Gateway allows outbound internet access from private subnets, but it does not enable a Lambda function to access VPC resources; the function must be attached to the VPC with appropriate security group rules.

536
MCQeasy

A developer is deploying a serverless application using AWS SAM. The deployment fails with a 'ResourceNotReady' error. What is the most likely cause?

A.The SAM template has invalid YAML syntax.
B.The application has too many tags.
C.A resource that the application depends on is not yet created.
D.The Lambda function code has a runtime error.
AnswerC

SAM and CloudFormation create resources in dependency order; a ResourceNotReady error occurs when a dependent resource, such as a nested stack or custom resource, has not finished provisioning before a downstream resource references it. The dependency is not yet created when required.

Why this answer

'ResourceNotReady' in AWS SAM indicates that a resource the application depends on is not yet created or still in progress. This often happens when a nested stack or a resource with dependencies (e.g., a DynamoDB table) is not fully provisioned before the dependent resource tries to use it. Option A is incorrect: invalid YAML syntax would cause a template validation error, not a 'ResourceNotReady' error.

Option B is incorrect: too many tags would not cause this error; tags are metadata and do not affect resource readiness. Option D is incorrect: a Lambda runtime error would occur during function invocation, not during deployment.

537
MCQmedium

A company has an AWS Lambda function that processes messages from an Amazon SQS queue. The function is invoked with a batch size of 10. Some messages are failing repeatedly, causing the function to retry them up to the maximum retry count and then they are sent to a dead-letter queue (DLQ). The company wants to improve the resilience of the application by handling partial batch failures more efficiently. What should a solutions architect do?

A.Move the messages to a DLQ immediately after the first failure.
B.Implement reportBatchItemFailures in the Lambda function and enable partial batch response for the SQS event source mapping.
C.Decrease the batch size to 1 so that each invocation processes a single message.
D.Increase the batch size to 100 to process more messages per invocation.
AnswerB

ReportBatchItemFailures lets the function return only the identifiers of failed messages, so Lambda deletes successful ones and retries just the failures. This avoids reprocessing the entire batch of ten, directly satisfying the requirement to handle partial batch failures efficiently and reduce duplicate DLQ entries.

Why this answer

Implementing reportBatchItemFailures in the Lambda function and enabling partial batch response for the SQS event source mapping allows the function to signal which specific messages within a batch failed. This prevents the entire batch from being retried or sent to the DLQ, and only the failed messages are retried individually, improving resilience and efficiency.

Exam trap

The trap here is that candidates often think decreasing batch size to 1 is the simplest fix, but that ignores the throughput impact and the fact that AWS provides a native partial batch failure mechanism that is more efficient and scalable.

How to eliminate wrong answers

Option A is wrong because moving messages to a DLQ immediately after the first failure defeats the purpose of retries and would cause unnecessary data loss for transient failures. Option C is wrong because decreasing the batch size to 1 reduces throughput and does not address partial batch failures; it simply avoids the problem by processing one message at a time, which is less efficient. Option D is wrong because increasing the batch size to 100 would amplify the impact of partial failures, as the entire batch would be retried or sent to the DLQ if any message fails, making the problem worse.

538
MCQmedium

A company has an application that runs on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local disk. The company wants to centralize log storage and enable near-real-time analysis of the logs. The company also wants to retain the logs for 7 years for compliance. The logs are currently stored in a file on each instance. The company wants a solution that requires minimal changes to the application and is cost-effective. Which solution meets these requirements?

A.Configure the application to write logs directly to Amazon S3 and use Amazon Athena for analysis.
B.Install and configure the Amazon CloudWatch agent on each instance to send logs to CloudWatch Logs. Configure a subscription filter to stream logs to Amazon Kinesis Data Firehose, which delivers to Amazon S3. Use Amazon Athena for analysis.
C.Install and configure the Amazon CloudWatch agent on each instance to send logs to CloudWatch Logs. Set the retention period to 7 years and use CloudWatch Logs Insights for analysis.
D.Use AWS Systems Manager to run a script on each instance that periodically uploads log files to Amazon S3. Use Amazon QuickSight for analysis.
AnswerB

The CloudWatch agent centralizes logs with minimal application changes. A subscription filter can stream logs in near-real-time to Kinesis Data Firehose, which reliably delivers them to Amazon S3 for long-term, cost-effective storage. Athena can then query the logs directly from S3. This solution meets all requirements: centralized logging, near-real-time analysis, 7-year retention, minimal changes, and cost-effectiveness.

Why this answer

The combination of the CloudWatch agent, subscription filters, Kinesis Data Firehose, and Amazon S3 provides a managed, near-real-time log pipeline with minimal application changes. Logs are centralized in CloudWatch Logs, streamed to S3 for cost-effective long-term retention, and can be analyzed with Athena. This meets the compliance, analysis, and cost requirements without modifying the application.

Exam trap

The trap here is assuming that CloudWatch Logs alone is cost-effective for 7-year retention, when S3 is far cheaper for long-term archival.

539
MCQeasy

A company is migrating a legacy .NET application from on-premises Windows servers to AWS. The application uses Windows authentication and requires a shared file storage that supports SMB protocol. The company wants to minimize code changes and use a managed AWS service for file storage. Which AWS service should a solutions architect recommend?

A.Amazon Elastic File System (Amazon EFS)
B.Amazon S3 with S3 File Gateway
C.Amazon FSx for Windows File Server
D.Amazon FSx for Lustre
AnswerC

Amazon FSx for Windows File Server is a fully managed native Microsoft Windows file system that supports SMB protocol and integrates with Microsoft Active Directory for Windows authentication. It allows the application to continue using Windows authentication and SMB without code changes, meeting the requirements for a managed service and minimal modifications.

Why this answer

Amazon FSx for Windows File Server is the only managed AWS file storage service that natively supports SMB protocol and Microsoft Active Directory integration for Windows authentication. It enables the legacy .NET application to migrate to AWS with minimal code changes, as it can continue to use its existing authentication and file access methods.

Exam trap

The trap here is assuming that any managed file storage service can replace a Windows file server, overlooking the need for SMB protocol and Windows authentication compatibility.

540
MCQhard

A company is migrating a legacy database to Amazon RDS. The database currently runs on a single server with a 2 TB volume. The migration must have less than 30 minutes of downtime. Which approach should be used for the initial data load?

A.Use a native database dump and restore during a maintenance window
B.Use AWS Database Migration Service (DMS) with ongoing replication
C.Export the database to Amazon S3 and import into RDS using native tools
D.Create a read replica from the source database to RDS
AnswerB

DMS performs a full load then continuously replicates ongoing changes, so the cutover window stays within the 30-minute downtime limit. The 2 TB volume size is irrelevant because replication is incremental rather than a one-off copy.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication is the best approach because it allows for continuous data replication from the source to RDS, minimizing downtime to a brief cutover. The initial load can be done while the source remains active, and ongoing replication keeps the target in sync until cutover. This meets the less than 30 minutes downtime requirement.

Exam trap

The trap is underestimating the downtime of native dump/restore for large databases; candidates may pick it because it's familiar, but DMS with CDC is designed for minimal downtime.

How to eliminate wrong answers

Option A is wrong because a native dump and restore during a maintenance window would require significant downtime, likely exceeding 30 minutes for a 2 TB database. Option C is wrong because exporting to S3 and importing still requires downtime and is not a continuous replication method. Option D is wrong because creating a read replica from an on-premises database to RDS is not directly supported; DMS is the tool for this.

541
MCQhard

A financial services company is designing a new application that will store sensitive customer data in Amazon S3. The company must encrypt the data at rest and ensure that the encryption keys are rotated annually. The security team requires that the company retains full control over the key rotation and can audit key usage. The solutions architect needs to recommend an encryption solution that meets these requirements with minimal operational effort. Which solution should the architect recommend?

A.Use client-side encryption with a custom encryption library and store the keys in AWS Secrets Manager.
B.Use SSE-S3 with default encryption and enable S3 bucket key.
C.Use SSE-KMS with a customer managed key (CMK) and enable automatic key rotation.
D.Use SSE-KMS with an AWS managed key and enable automatic key rotation.
AnswerC

SSE-KMS with a customer managed key allows the company to control key rotation, audit key usage via AWS CloudTrail, and define key policies. Enabling automatic key rotation rotates the key annually, meeting the requirement with minimal operational effort. This solution provides the necessary control and auditability while being fully managed.

Why this answer

SSE-KMS with a customer managed key provides the company with full control over the encryption keys, including the ability to enable automatic annual rotation. It also integrates with AWS CloudTrail for auditing key usage. This solution is fully managed, requiring minimal operational effort.

Other options either do not provide the required control or require more management overhead.

Exam trap

The trap here is confusing AWS managed keys with customer managed keys, and assuming that AWS managed keys support automatic rotation and auditing.

542
MCQmedium

A company is using AWS Organizations with consolidated billing. The company has a production account and a development account. The security team needs to ensure that developers cannot create IAM users in the development account. Which option is the MOST effective?

A.Apply an SCP to the development account that denies iam:CreateUser.
B.Create an IAM group for developers with a policy that denies iam:CreateUser.
C.Enable AWS CloudTrail to monitor iam:CreateUser calls.
D.Attach an IAM policy to each developer user that denies iam:CreateUser.
AnswerA

SCPs are effective even for users with full administrative permissions.

Why this answer

Service Control Policies (SCPs) are the most effective way to enforce permissions boundaries across entire accounts in AWS Organizations. An SCP applied to the development account will deny the `iam:CreateUser` action for all principals (including the root user) in that account, regardless of any IAM policies attached to users or roles. This ensures developers cannot create IAM users, even if they have full administrative access within the account.

Exam trap

The trap here is that candidates often confuse IAM policies (which are account-specific and can be overridden) with SCPs (which are organization-wide and cannot be bypassed by account administrators), leading them to choose an IAM-based solution that is less effective for cross-account control.

How to eliminate wrong answers

Option B is wrong because an IAM group policy only applies to users who are members of that group; developers could be added to other groups or have inline policies that grant `iam:CreateUser`, bypassing the restriction. Option C is wrong because AWS CloudTrail only logs API calls for auditing purposes and does not prevent the `iam:CreateUser` action from being executed. Option D is wrong because an IAM policy attached to each developer user is not scalable and can be overridden by other policies (e.g., a full-admin policy) that grant the same action; it also does not prevent a developer from creating a new user with a different set of permissions.

543
MCQmedium

A company is designing a new application that processes sensitive healthcare data. The application runs on Amazon ECS with Fargate and uses an Application Load Balancer. The company must ensure that all data in transit is encrypted. Which step should be taken?

A.Configure the target group to use HTTP protocol.
B.Configure the security group to only allow inbound traffic from approved IPs.
C.Use HTTP on port 80 and rely on VPC network ACLs.
D.Configure the ALB listener to use HTTPS (port 443) with an SSL certificate.
AnswerD

Terminating TLS at the ALB listener encrypts traffic between clients and the load balancer, satisfying the in-transit encryption requirement. An SSL certificate on port 443 ensures HTTPS from the internet to the ALB, covering the external leg of the data path.

Why this answer

To encrypt data in transit between clients and the Application Load Balancer (ALB), you must configure the ALB listener to use HTTPS (port 443) with an SSL/TLS certificate. This ensures that all traffic between the client and the load balancer is encrypted using TLS, meeting the requirement for encrypted data in transit for sensitive healthcare data.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups, NACLs) with encryption, or assume that using HTTP on the backend is sufficient, forgetting that the client-to-ALB leg must also be encrypted to satisfy 'data in transit' requirements.

How to eliminate wrong answers

Option A is wrong because configuring the target group to use HTTP protocol does not encrypt traffic between the client and the ALB; it only affects the backend connection, and the client-to-ALB leg remains unencrypted if the listener is HTTP. Option B is wrong because restricting inbound traffic to approved IPs controls network access but does not encrypt the data in transit; encryption requires TLS/SSL, not IP filtering. Option C is wrong because using HTTP on port 80 and relying on VPC network ACLs provides no encryption; network ACLs are stateless packet filters and do not provide any cryptographic protection for data in transit.

544
MCQmedium

A financial services company has an AWS Organizations structure with a management account, a dedicated network account, and 40 workload accounts. Each workload account has its own VPC, and all VPCs must be able to reach a shared services VPC in the network account. The security team requires that all inter-VPC traffic be inspected by a central firewall appliance before reaching the shared services. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS PrivateLink to expose the shared services as endpoint services, and have each workload VPC create an interface VPC endpoint to access them.
B.Deploy a VPN connection from each workload VPC to the shared services VPC using AWS Site-to-Site VPN, and route traffic through the VPN tunnels.
C.Create a VPC peering connection between each workload VPC and the shared services VPC, and route traffic through the shared services VPC where a firewall appliance is deployed.
D.Attach all workload VPCs to a central AWS Transit Gateway in the network account, use a separate route table for the shared services VPC, and associate a firewall appliance VPC with a dedicated inspection route table.
AnswerD

AWS Transit Gateway provides transitive routing and centralized management. By using separate route tables and associating the firewall VPC with an inspection route table, traffic from workload VPCs can be forced through the firewall before reaching the shared services VPC. This is the standard hub-and-spoke inspection pattern and scales to many accounts with minimal per-VPC configuration.

Why this answer

A central AWS Transit Gateway with separate route tables allows all workload VPCs to route traffic through a firewall VPC in the network account before reaching shared services. This hub-and-spoke inspection model is scalable, requires minimal per-account configuration, and meets the security requirement for central inspection. Other options either lack transitivity, do not enforce inspection, or are not designed for inter-VPC routing at scale.

Exam trap

The trap here is assuming that VPC peering or PrivateLink can provide centralized traffic inspection, when they are either non-transitive or service-specific and cannot force all traffic through a firewall.

545
MCQhard

A company is migrating a legacy on-premises application that uses a custom TCP protocol. The application needs to be accessible from the internet while maintaining security. Which AWS service should they use to expose the application without modifying the code?

A.Amazon CloudFront
B.Network Load Balancer (NLB)
C.Amazon API Gateway
D.Application Load Balancer (ALB)
AnswerB

Network Load Balancer operates at layer 4, forwarding arbitrary TCP traffic to targets while preserving source IP, so the custom protocol works unmodified. It satisfies the no-code-change constraint and supports internet-facing exposure with TLS termination.

Why this answer

Network Load Balancer (NLB) because it operates at Layer 4 (TCP) and can handle custom TCP protocols without requiring application modifications. Option A (CloudFront) is a content delivery network that only supports HTTP/HTTPS. Option C (API Gateway) is designed for HTTP/HTTPS APIs and does not handle raw TCP traffic.

Option D (Application Load Balancer, ALB) operates at Layer 7 (HTTP/HTTPS) and cannot process custom TCP protocols.

546
Multi-Selecthard

A company is running a stateful web application on a single Amazon EC2 instance. The application stores session data on an instance store volume. The company wants to improve the availability and durability of the application by moving to a multi-AZ architecture. The application must remain accessible if an Availability Zone fails. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Configure the application to use sticky sessions on the Application Load Balancer and store session data on each instance's EBS volume.
B.Use Amazon S3 to store session data and have the application read/write sessions directly to S3.
C.Deploy the application on EC2 instances in an Auto Scaling group spanning multiple Availability Zones, behind an Application Load Balancer.
D.Attach an additional instance store volume to each EC2 instance to replicate session data across volumes.
E.Move session data to Amazon ElastiCache for Redis with Multi-AZ enabled.
AnswersC, E

An Auto Scaling group across multiple AZs with an ALB ensures that the application remains accessible if one AZ fails. The ALB distributes traffic to healthy instances, and Auto Scaling maintains capacity. This provides high availability for the application tier, which is essential for a multi-AZ architecture.

Why this answer

To achieve a multi-AZ architecture, the application tier must be distributed across AZs with an ALB, and session state must be externalized to a highly available store like ElastiCache for Redis Multi-AZ. These two actions together ensure the application remains accessible and session data is durable even if an AZ fails.

Exam trap

The trap here is assuming that instance store or EBS volumes with sticky sessions can provide cross-AZ availability, when they are tied to a single AZ.

547
MCQmedium

A company has a multi-account AWS environment with a centralized security account. The security team needs to have read-only access to all Amazon S3 buckets across all accounts for auditing purposes. Which solution is the MOST secure and scalable?

A.Create an IAM role in each account with read-only S3 permissions and a trust policy that allows the security account to assume the role.
B.Attach a bucket policy to each S3 bucket that grants read-only access to the security team's IAM user in the security account.
C.Use the root user of each account to access the buckets.
D.Create an IAM user in each account with read-only S3 permissions and share the credentials with the security team.
AnswerA

A cross-account IAM role with a trust policy scoped to the security account lets auditors assume read-only S3 permissions without distributing long-term credentials. This satisfies the security and scalability constraints by centralising access through role assumption across every account.

Why this answer

It uses IAM roles with cross-account trust policies, which is the most secure and scalable approach for granting read-only S3 access across multiple accounts. The security account assumes the role in each target account, avoiding long-term credentials and allowing centralized control via AWS Organizations or manual role creation.

Exam trap

The trap here is that candidates may choose Option B thinking bucket policies are simpler, but they overlook the scalability and maintenance burden of managing individual bucket policies across hundreds or thousands of buckets, and the fact that bucket policies do not support cross-account access without explicitly listing the principal ARN, which is less flexible than IAM roles.

How to eliminate wrong answers

Option B is wrong because attaching bucket policies to each S3 bucket individually is not scalable for large environments and requires managing policies per bucket, which can lead to policy size limits and complexity. Option C is wrong because using root users violates the principle of least privilege, is not auditable, and is insecure due to shared static credentials. Option D is wrong because creating IAM users in each account with shared credentials introduces long-term access keys that must be rotated and managed, increasing security risk and operational overhead compared to role-based access.

548
Multi-Selectmedium

Which TWO actions improve the security of an S3 bucket that stores sensitive data?

Select 2 answers
A.Enable default encryption with SSE-S3 or SSE-KMS.
B.Block all public access using the S3 Block Public Access feature.
C.Enable S3 Transfer Acceleration.
D.Configure a lifecycle policy to transition objects to Glacier.
E.Enable S3 Select to filter data.
AnswersA, B

SSE-S3 or SSE-KMS encrypts objects at rest, so data written to the bucket is unreadable without the corresponding key. This directly satisfies the sensitive-data protection requirement, mitigating exposure if storage media or snapshots are compromised.

Why this answer

Option A is correct because enabling default encryption with SSE-S3 or SSE-KMS ensures that all objects written to the bucket are encrypted at rest automatically, protecting sensitive data even if individual PUT requests omit encryption headers. Option B is correct because the S3 Block Public Access feature overrides bucket policies and ACLs to prevent any public exposure of the bucket or its objects, which is a critical safeguard for sensitive data. Option C is not a security control; S3 Transfer Acceleration only speeds up uploads and downloads via AWS edge locations.

Option D addresses cost and storage-class optimization, not security, since Glacier transition does not itself restrict access. Option E is a query capability for filtering object data with SQL, not a security mechanism.

Exam trap

The trap here is that candidates may confuse performance or cost features (Transfer Acceleration, Glacier lifecycle, S3 Select) with security controls, leading them to select options that do not actually protect data confidentiality or integrity.

549
Multi-Selectmedium

A company is migrating a multi-tier web application to AWS. The application consists of a web server, application server, and Oracle database. Which TWO AWS services should be used to modernize the application while reducing operational overhead?

Select 2 answers
A.Amazon RDS for Oracle
B.Amazon Lightsail
C.AWS Elastic Beanstalk
D.Amazon EC2
E.Amazon DynamoDB
AnswersA, C

Amazon RDS for Oracle is a managed service handling provisioning, patching, backups and Multi-AZ failover, removing database administration overhead. It preserves Oracle compatibility, satisfying the modernisation goal while reducing the operational burden the stem requires.

Why this answer

Amazon RDS for Oracle (A) is correct because it is a managed relational database service that supports Oracle engines, automating tasks such as provisioning, patching, backups, and Multi-AZ replication, which reduces the operational overhead of running the Oracle database tier. AWS Elastic Beanstalk (C) is correct because it provides a managed platform for deploying and scaling web and application server tiers, handling capacity provisioning, load balancing, and application health monitoring so the company can modernize without managing underlying infrastructure. Amazon Lightsail (B) is not appropriate because it is a simplified VPS offering aimed at small, simple workloads and does not provide the managed multi-tier or Oracle capabilities needed here.

Amazon EC2 (D) is not the best choice because it requires the company to manage the operating system, patching, scaling, and database operations itself, increasing operational overhead. Amazon DynamoDB (E) is incorrect because it is a NoSQL key-value/document database and cannot replace the existing Oracle relational database workload.

Exam trap

SAP-C02 often tests the misconception that EC2 or Lightsail reduce operational overhead, when in fact managed services like RDS and Elastic Beanstalk are required to offload patching, scaling, and backups.

550
MCQhard

A company has a critical application that uses an Amazon Aurora MySQL database cluster. The application experiences occasional slow queries during peak hours, impacting user experience. A solutions architect needs to identify the root cause and improve performance with minimal changes. The architect has enabled Performance Insights and sees high wait times on the database. Which action should the architect take FIRST to resolve the issue?

A.Analyze Performance Insights to identify the top SQL statements and wait events causing the bottleneck.
B.Scale up the Aurora cluster by changing the instance class to a larger size.
C.Modify the application to use Aurora's reader endpoint for all read queries.
D.Add additional read replicas to the Aurora cluster to distribute the read load.
AnswerA

Performance Insights provides detailed metrics on database load, including top SQL statements and wait events. By analyzing this data, the architect can identify whether the issue is due to inefficient queries, locking, or resource contention. This targeted approach allows for specific optimizations, such as query tuning or index creation, which are more effective than broad scaling actions. It aligns with the requirement to identify the root cause first.

Why this answer

Performance Insights offers granular visibility into database load and wait events. Analyzing it first allows the architect to identify the specific cause of slow queries, enabling targeted fixes like query optimization or index changes. This is more efficient than blindly scaling, which may not resolve the issue and adds cost.

Exam trap

The trap here is jumping to scaling actions without first diagnosing the root cause, which can lead to unnecessary costs and unresolved performance issues.

551
MCQmedium

A company uses AWS Organizations with multiple accounts. The finance team needs to track costs by department, where each department uses resources across several accounts. What is the BEST way to allocate costs accurately?

A.Use AWS Cost Explorer to view costs by linked account.
B.Define cost allocation tags for each department and enable them in the Billing and Cost Management console.
C.Set up AWS Budgets for each department with alerts.
D.Create AWS Resource Groups for each department and use AWS Config to track costs.
AnswerB

Cost allocation tags must be activated in the Billing and Cost Management console before they appear in Cost Explorer and billing reports. Defining department tags and enabling them lets finance attribute spend across accounts to each department, meeting the cross-account tracking requirement.

Why this answer

Cost allocation tags allow you to tag AWS resources with department-specific metadata (e.g., 'Department: Finance') and then activate those tags in the Billing and Cost Management console. Once enabled, AWS Cost Explorer and cost reports can filter and group costs by these tags, providing accurate per-department cost tracking across multiple accounts in AWS Organizations. This is the most precise method because it directly associates resource usage with the department responsible, regardless of which account hosts the resource.

Exam trap

The trap here is that candidates often confuse account-level grouping (Option A) with tag-based allocation, assuming that each department has its own AWS account, but the question explicitly states departments use resources across several accounts, making tag-based allocation the only accurate method.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer viewing costs by linked account only shows costs per AWS account, not per department; a single department may span multiple accounts, and a single account may host resources for multiple departments, so account-level grouping cannot accurately allocate costs to departments. Option C is wrong because AWS Budgets are used for setting cost thresholds and sending alerts, not for allocating or tracking historical costs by department; they do not provide a mechanism to assign costs to departments. Option D is wrong because AWS Resource Groups are logical groupings of resources based on tags or other criteria, and AWS Config tracks resource configuration changes and compliance, not cost allocation; neither service provides cost tracking or allocation capabilities.

552
MCQeasy

A company uses AWS Organizations and wants to centrally manage backups of EC2 instances across multiple accounts. Which service should they use?

A.AWS CloudEndure Disaster Recovery
B.Amazon S3 Glacier
C.AWS Storage Gateway
D.AWS Backup
AnswerD

AWS Backup provides a central backup policy that spans accounts in AWS Organizations, letting you define and monitor backup plans for EC2 instances across the entire organisation from one place, which satisfies the centralised multi-account management requirement.

Why this answer

AWS Backup is the correct service because it provides a fully managed, policy-based backup solution that integrates with AWS Organizations to centrally manage backups across multiple accounts. It allows you to define backup policies that automatically apply to EC2 instances and other supported resources across all member accounts, ensuring compliance and centralized monitoring without requiring per-account manual configuration.

Exam trap

The trap here is that candidates may confuse AWS Backup with disaster recovery services like CloudEndure, not realizing that AWS Backup is purpose-built for centralized, policy-driven backup management across multiple accounts, while CloudEndure focuses on continuous replication for failover, not scheduled backups.

How to eliminate wrong answers

Option A is wrong because AWS CloudEndure Disaster Recovery is designed for continuous replication and rapid failover for disaster recovery scenarios, not for scheduled, policy-based backup management across multiple accounts. Option B is wrong because Amazon S3 Glacier is a storage class for long-term archival of objects, not a service for orchestrating or managing backups of EC2 instances across accounts. Option C is wrong because AWS Storage Gateway provides hybrid cloud storage access (e.g., file, volume, tape gateways) for on-premises environments, not centralized backup management of EC2 instances within AWS Organizations.

553
MCQhard

A global e-commerce company is designing a new order-processing system that must survive the failure of an entire AWS Region. The system uses an Amazon Aurora MySQL database and must provide a recovery point objective (RPO) of 1 minute and a recovery time objective (RTO) of 5 minutes. The company wants to minimize operational overhead and avoid managing replication instances. Which solution should the solutions architect recommend?

A.Configure Aurora MySQL with a cross-Region read replica using binary log replication, and promote the replica on failure.
B.Create an Aurora global database with the primary cluster in one Region and a secondary cluster in another Region; configure the application to fail over using the secondary cluster's endpoint.
C.Take automated snapshots of the Aurora cluster and copy them to another Region; restore from the copied snapshot on failure.
D.Deploy Aurora MySQL with a Multi-AZ configuration across three Availability Zones in a single Region; rely on automatic failover for disaster recovery.
AnswerB

Aurora global database replicates at the storage layer with typical lag under one second, meeting the 1-minute RPO, and allows promotion of a secondary cluster in under a minute, meeting the 5-minute RTO. It is fully managed, so no replication instances are needed, minimizing operational overhead. This directly satisfies all requirements.

Why this answer

Aurora global database replicates data across Regions with sub-second typical latency, enabling an RPO well within one minute, and allows a secondary cluster to be promoted in under a minute, meeting the five-minute RTO. Because it is a managed feature with no replication instances to operate, it also minimizes operational overhead.

Exam trap

The trap here is treating Aurora Multi-AZ or cross-Region read replicas as equivalent to an Aurora global database for Region-wide disaster recovery with strict RPO and RTO.

554
MCQeasy

A company wants to share a large dataset stored in Amazon S3 with a partner who has their own AWS account. The partner needs to access the data using their own account credentials. Which approach should the company use?

A.Use S3 cross-region replication.
B.Grant the partner's AWS account access via a bucket policy.
C.Create a pre-signed URL for the partner.
D.Provide the partner with an IAM user in the company's account.
AnswerB

A bucket policy grants cross-account access directly to the partner's AWS account principal, letting them use their own credentials without sharing keys. This satisfies the requirement for account-to-account sharing of a large S3 dataset, unlike IAM users or presigned URLs, which are tied to the source account or expire.

Why this answer

A bucket policy can grant cross-account access to the partner's AWS account by specifying the partner's AWS account ID as the principal. This allows the partner's IAM users or roles to access the S3 bucket directly using their own credentials, without needing to share access keys or create users in the company's account. The bucket policy must explicitly allow the necessary actions (e.g., s3:GetObject) and the partner must also have an IAM policy that permits the same actions.

Exam trap

The SAP-C02 exam often tests the misconception that pre-signed URLs are the only way to grant temporary access, but the question explicitly requires the partner to use their own account credentials, which only a bucket policy (or an S3 access point with a policy) can achieve.

How to eliminate wrong answers

Option A is wrong because S3 cross-region replication is used to automatically replicate objects to a different AWS region for data redundancy or compliance, not to grant cross-account access to a partner. Option C is wrong because a pre-signed URL grants temporary access to a specific object using a URL that embeds credentials, but it does not allow the partner to use their own AWS account credentials; it also expires and is not suitable for ongoing or large-scale access. Option D is wrong because providing an IAM user in the company's account would require the partner to use that user's credentials (access key and secret key) instead of their own account credentials, violating the requirement that the partner uses their own account credentials.

555
MCQhard

A company wants to migrate a legacy Oracle database to AWS with minimal downtime. The database is 2 TB in size and runs on a single on-premises server. The company requires the ability to cut over quickly and roll back if needed. Which AWS service should be used?

A.Use S3 Transfer Acceleration to upload the database dump directly to an EC2 instance.
B.AWS Database Migration Service (DMS) with ongoing replication from the source to an Amazon RDS for Oracle target.
C.AWS Schema Conversion Tool (SCT) to convert the schema and then export the data to flat files for import.
D.AWS Snowball Edge to copy the database files and then restore on Amazon RDS.
AnswerB

DMS with ongoing replication keeps the RDS for Oracle target continuously synchronised, so cutover needs only a brief application switch, and the source remains intact for rollback. This satisfies the minimal-downtime and quick-rollback constraints for the 2 TB database.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication enables continuous data replication from the on-premises Oracle database to Amazon RDS for Oracle, allowing minimal downtime during cutover. It also supports rollback by stopping replication and reverting to the source. Option A is incorrect because S3 Transfer Acceleration is for fast uploads to S3, not for database migration with replication.

Option C is incorrect because AWS Schema Conversion Tool (SCT) handles schema conversion, not ongoing data replication. Option D is incorrect because AWS Snowball Edge is an offline data transfer device, which does not meet the minimal downtime requirement.

Exam trap

Candidates may think Snowball Edge is suitable for very large databases, but for minimal downtime requirements, an online replication service like DMS is necessary.

556
MCQeasy

A company uses AWS Control Tower to manage a multi-account environment. The security team needs to ensure that all accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket. What is the BEST way to achieve this?

A.Use an AWS Lambda function that runs periodically to enable CloudTrail in accounts where it is disabled.
B.Create an AWS Config rule in each account to enable CloudTrail if it is disabled.
C.Use an SCP to require CloudTrail to be enabled in each account.
D.Use the AWS CloudTrail setup provided by Control Tower, which automatically enables a trail for all accounts in the organization.
AnswerD

Control Tower's built-in CloudTrail configuration creates an organisation-wide trail delivering logs to the central S3 bucket it provisions, covering every account including future ones. This satisfies the requirement for CloudTrail across all accounts with centralised log delivery without custom automation.

Why this answer

AWS Control Tower provides an integrated CloudTrail setup that automatically creates and manages a central trail for all accounts in the organization. This trail is deployed using AWS CloudFormation StackSets and delivers logs to a centralized S3 bucket, ensuring compliance without manual intervention or custom automation. This is the best approach because it is native, fully managed, and aligns with Control Tower's governance model.

Exam trap

The trap here is that candidates often assume SCPs can enforce service enablement (like enabling CloudTrail), but SCPs only control permissions—they cannot enable services or resources; they can only prevent disabling of existing configurations.

How to eliminate wrong answers

Option A is wrong because using a periodic Lambda function is reactive, introduces latency, and does not prevent accounts from disabling CloudTrail between runs; it also adds operational overhead and potential single points of failure. Option B is wrong because an AWS Config rule can only detect non-compliance and trigger remediation (e.g., via auto-remediation), but it cannot enforce the setting across all accounts proactively; it also requires Config to be enabled in each account first. Option C is wrong because SCPs can only deny or allow API actions, not enable services; an SCP cannot force CloudTrail to be enabled—it can only prevent disabling of an already-enabled trail or block certain CloudTrail API calls.

557
Multi-Selecthard

A company is using AWS Organizations with hundreds of accounts. The central IT team needs to deploy a common set of AWS resources (e.g., VPCs, subnets, security groups) to all accounts in a specific organizational unit (OU). The solution must be automated and ensure that new accounts added to the OU automatically receive the resources. Which three steps should the team take? (Choose three.)

Select 3 answers
A.Create a StackSet with the template and target the OU, enabling automatic deployment.
B.Create an AWS CloudFormation template that defines the common resources.
C.Use AWS Config rules to detect missing resources and deploy them via Lambda.
D.Enable AWS CloudFormation StackSets trusted access with AWS Organizations.
E.Create an SCP that requires the creation of those resources.
AnswersA, B, D

StackSets deploy a CloudFormation template across many accounts in one operation, and targeting the OU with automatic deployment enabled means any account later added to that OU inherits the resources without manual intervention, satisfying the automation constraint.

Why this answer

Option B is correct because the common resources (VPCs, subnets, security groups) must first be codified in an AWS CloudFormation template, which serves as the reusable artifact for automated, consistent deployment across accounts. Option D is correct because CloudFormation StackSets must be granted trusted access with AWS Organizations so the management account can deploy stack instances into member accounts and target OUs directly. Option A is correct because creating a StackSet from that template and targeting the specific OU with automatic deployment enabled ensures existing accounts receive the resources and any new account added to the OU is provisioned automatically.

Option C is incorrect because AWS Config rules only detect and evaluate resource compliance; they do not natively deploy resources, and using Lambda for remediation is a custom, reactive approach rather than the automated StackSet mechanism required. Option E is incorrect because an SCP only sets permission guardrails (allowing or denying actions); it cannot create or require the actual provisioning of VPCs, subnets, or security groups.

Exam trap

The trap here is confusing AWS Config (a detective control) with a provisioning tool, and assuming SCPs can create resources when they only enforce permission boundaries.

558
MCQeasy

A company has a production AWS account and a development AWS account. The development team needs to assume an IAM role in the production account to deploy resources. What is the correct way to set up this cross-account access?

A.Create an IAM role in the production account with a trust policy that specifies the development account as a trusted entity
B.Apply a service control policy to allow cross-account access
C.Create an IAM user in the production account and share the credentials with the development team
D.Configure security group rules to allow access from the development account
AnswerA

A trust policy in the production account naming the development account as principal establishes the cross-account relationship, satisfying the requirement that the development team assume a role in production. The development team then attaches a policy allowing sts:AssumeRole for that role's ARN, completing the two-sided configuration.

Why this answer

Cross-account IAM role access requires creating an IAM role in the production (trusting) account with a trust policy that explicitly lists the development (trusted) account as a principal. The development team then assumes that role using the AWS STS AssumeRole API, which returns temporary security credentials. This follows the AWS recommended pattern for delegating access without sharing long-term credentials.

Exam trap

The trap here is that candidates confuse network-level controls (security groups) or organizational policies (SCPs) with IAM-based cross-account trust, or mistakenly think sharing IAM user credentials is acceptable for cross-account access.

How to eliminate wrong answers

Option B is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an AWS Organization; they do not grant cross-account access themselves and cannot be used to allow role assumption between accounts. Option C is wrong because sharing IAM user credentials violates the principle of least privilege and security best practices; it exposes long-term access keys that are not scoped or temporary, increasing risk. Option D is wrong because security group rules control network traffic at the instance level, not IAM-based access; they cannot grant API-level permissions to assume roles or deploy resources.

559
MCQeasy

A company has 30 AWS accounts in AWS Organizations. The finance team wants to receive a single consolidated bill for all accounts and apply volume discounts across the organization. Which action should a solutions architect take?

A.Create an AWS Cost and Usage Report in each account and use AWS Cost Explorer to merge the reports into a single view.
B.Enable consolidated billing by inviting all accounts to join the organization, and designate one account as the management account.
C.Use AWS Resource Access Manager to share a billing resource across all accounts and enable cost allocation tags.
D.Configure AWS Budgets in the management account to aggregate spend from all member accounts and send a single invoice.
AnswerB

Consolidated billing is a feature of AWS Organizations where the management account pays for all member accounts and receives a single bill. It also aggregates usage for volume pricing tiers and Reserved Instance and Savings Plans sharing, which meets the finance team's requirement for one bill and volume discounts.

Why this answer

Consolidated billing in AWS Organizations makes the management account responsible for paying all charges and produces one bill for the organization. It also combines usage across accounts for volume pricing and allows sharing of Reserved Instances and Savings Plans, which is exactly what the finance team needs.

Exam trap

The trap here is confusing cost visibility tools such as AWS Cost Explorer or AWS Budgets with the billing consolidation that AWS Organizations consolidated billing actually provides.

560
MCQmedium

A company is designing a new application that will use Amazon API Gateway and AWS Lambda. The application must authenticate users using an existing OpenID Connect (OIDC) identity provider. The company wants to minimize the amount of custom code required and ensure that only authenticated users can invoke the API. Which authentication method should be used?

A.Use AWS Lambda authorizer with a custom authorizer function that validates JWT tokens.
B.Use API Gateway resource policies to restrict access based on IP range.
C.Use API Gateway native OpenID Connect authorization with a JWT authorizer.
D.Use Amazon Cognito user pools with an OIDC identity provider.
AnswerC

API Gateway supports native OpenID Connect authorization with a JWT authorizer. You can configure it to validate tokens from your OIDC provider without writing any custom code. It automatically validates the token signature, issuer, and audience. This minimizes custom code and ensures only authenticated users can invoke the API.

Why this answer

API Gateway native OpenID Connect authorization with a JWT authorizer allows you to validate tokens from an OIDC provider without writing custom code. It automatically validates the token's signature, issuer, and audience, and only allows authenticated users to invoke the API. This meets the requirements with minimal custom code.

Exam trap

The trap here is assuming that a Lambda authorizer is required to validate JWT tokens, when API Gateway now supports native JWT authorizers for OIDC.

561
MCQeasy

A company plans to migrate its on-premises VMware VMs to AWS. The company wants to automate the migration of VM images and minimize manual effort. Which AWS service should the company use?

A.AWS VM Import/Export
B.AWS DataSync
C.AWS Application Migration Service (MGN)
D.AWS Database Migration Service (DMS)
AnswerC

AWS Application Migration Service replicates source servers block-by-block into AWS, then launches test or cutover instances automatically. This agent-based continuous replication removes manual image conversion, satisfying the requirement to automate VMware VM migration and minimise manual effort.

Why this answer

AWS Application Migration Service (MGN) is the correct choice because it automates the migration of on-premises server volumes (including VMware VMs) to AWS with minimal manual effort. It provides continuous, block-level replication and simplifies large-scale migrations. MGN is the modern successor to AWS Server Migration Service (SMS).

AWS VM Import/Export (Option A) is a one-time import tool requiring manual steps. AWS DataSync (Option B) is for file and object transfers, not VM images. AWS DMS (Option D) is for databases.

Therefore, MGN (Option C) is the service that best meets the requirement.

Exam trap

A common pitfall is choosing AWS VM Import/Export because it is a familiar VM import tool, but it lacks automation. The correct service for automated server migration is now AWS Application Migration Service (MGN), which has replaced SMS.

562
Multi-Selecthard

Which THREE factors should be considered when designing a disaster recovery plan for a multi-tier application using AWS? (Choose three.)

Select 3 answers
A.Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
B.Data replication strategy (e.g., synchronous vs. asynchronous).
C.DNS failover using Amazon Route 53.
D.Deploying the application across multiple Availability Zones.
E.Using larger instance sizes for better performance.
AnswersA, B, C

RTO defines the maximum tolerable downtime and RPO the maximum tolerable data loss; together they drive every subsequent DR decision, including standby strategy, replication frequency and budget. They are the primary business requirements against which any multi-tier AWS DR design is validated.

Why this answer

Option A is correct because RTO (maximum tolerable downtime) and RPO (maximum tolerable data loss) are the foundational business requirements that drive every DR design decision, such as whether to use pilot light, warm standby, or multi-site active-active. Option B is correct because the data replication strategy determines actual data loss and recovery behavior: synchronous replication (e.g., Aurora Global Database or Multi-AZ) gives near-zero RPO but adds latency, while asynchronous replication (e.g., S3 Cross-Region Replication, RDS read replicas) lowers latency but risks losing recent writes. Option C is correct because Amazon Route 53 failover routing with health checks is the mechanism that redirects client traffic to the standby Region during a disaster, making it essential for reducing RTO in a multi-tier application.

Option D is not one of the three because deploying across multiple Availability Zones addresses high availability within a single Region, not disaster recovery across Regions, which is the scope of a DR plan. Option E is not one of the three because instance sizing affects performance and cost, not recovery time, recovery point, or failover capability, so it is irrelevant to DR design.

563
MCQmedium

A company runs a web application on EC2 instances in an Auto Scaling group. The application receives a variable workload. The company wants to scale based on a custom metric that tracks the number of active users. What is the MOST efficient way to achieve this?

A.Use a scheduled scaling policy to add or remove instances based on historical usage patterns.
B.Use AWS Lambda to periodically evaluate the custom metric and adjust the desired capacity via API calls.
C.Create a step scaling policy that uses CloudWatch alarms based on the custom metric.
D.Create a target tracking scaling policy using the custom metric as the target.
AnswerD

Target tracking adjusts capacity automatically to hold the custom metric at a specified target, so active-user load is matched without manual threshold tuning. This satisfies the variable workload and efficiency requirements, unlike step or simple scaling policies that need hand-tuned alarms.

Why this answer

Target tracking scaling is the most efficient because it automatically adjusts capacity to keep a chosen metric at a target value, using CloudWatch alarms under the hood. It supports custom metrics and eliminates the need to define step boundaries or thresholds manually, which is exactly what a variable workload with a custom metric requires.

Exam trap

SAP-C02 often tests whether candidates over-engineer scaling with Lambda or step policies when the native target tracking policy already supports custom metrics.

How to eliminate wrong answers

Option A is wrong because scheduled scaling is time-based, not metric-driven, so it cannot react to variable active-user counts. Option B is wrong because a Lambda polling loop is custom orchestration that adds latency, cost, and operational overhead versus native target tracking. Option C is wrong because step scaling requires manually defining alarm thresholds and step adjustments, which is less efficient than target tracking for a single target metric.

564
MCQhard

A company has a complex AWS environment with multiple accounts and VPCs. The company wants to ensure that all outbound traffic from VPCs goes through a centralized inspection VPC for security monitoring. The company uses AWS Transit Gateway. Which solution should be implemented?

A.Deploy AWS Network Firewall in each VPC and configure routing to send outbound traffic through the firewall.
B.Use VPC peering to connect all VPCs to the inspection VPC and configure routes.
C.Use Route 53 Resolver to forward all outbound DNS queries to the inspection VPC.
D.Create a Transit Gateway with route tables. Attach the inspection VPC as a central hub. Configure the route tables of the transit gateway to point the default route (0.0.0.0/0) to the inspection VPC attachment. Then attach all other VPCs and configure their route tables to send traffic to the Transit Gateway.
AnswerD

Transit Gateway route tables let you steer the default route (0.0.0.0/0) to the inspection VPC attachment, forcing all spoke VPC egress through the central hub for inspection. Attaching every VPC to the same Transit Gateway satisfies the centralised inspection constraint without complex peering.

Why this answer

It uses AWS Transit Gateway with centralized route tables to force all outbound traffic from attached VPCs through the inspection VPC. By configuring the Transit Gateway route table with a default route (0.0.0.0/0) pointing to the inspection VPC attachment, all outbound traffic from other VPCs is routed to the inspection VPC for security monitoring before leaving the network. This design meets the requirement of a single, centralized inspection point without requiring VPC peering or per-VPC firewall deployments.

Exam trap

The trap here is that candidates often confuse VPC peering with Transit Gateway, assuming peering can achieve transitive routing, but AWS VPC peering explicitly does not support transitive routing, making Option B invalid for centralized inspection.

How to eliminate wrong answers

Option A is wrong because deploying AWS Network Firewall in each VPC creates a decentralized inspection model, not a centralized one, and does not leverage Transit Gateway for traffic flow. Option B is wrong because VPC peering does not support transitive routing; each peering connection is a one-to-one relationship, so traffic cannot be centrally routed through a single inspection VPC without complex full-mesh peering. Option C is wrong because Route 53 Resolver only handles DNS queries, not general outbound traffic (e.g., HTTP, HTTPS, or other IP protocols), and thus cannot enforce security monitoring on all outbound traffic.

565
MCQhard

A company is migrating a critical application to AWS using the 7 Rs migration strategy. The application is tightly coupled with legacy infrastructure and has compliance requirements that prevent any code changes. The migration must be completed in 3 months. Which strategy is most appropriate?

A.Retain the application on-premises and use AWS Storage Gateway for backup.
B.Rehost using AWS Application Migration Service (MGN) and Amazon EC2.
C.Replatform to use Amazon RDS for MySQL.
D.Refactor into microservices on Amazon ECS.
AnswerB

Rehosting with AWS Application Migration Service lifts and shifts servers to Amazon EC2 without modifying code, satisfying the no-code-change compliance constraint. Block-level replication keeps the source running during cutover, enabling completion within the three-month window despite tight legacy coupling.

Why this answer

Rehosting (lift-and-shift) using AWS Application Migration Service (MGN) and EC2 meets the no-code-change requirement and can be completed within 3 months. Option A is wrong because retaining the application on-premises does not migrate it to AWS, failing the migration goal. Option C is wrong because replatforming to Amazon RDS would likely require code changes (e.g., database drivers, queries), violating the no-code-change constraint.

Option D is wrong because refactoring into microservices requires significant code changes and is too time-consuming for the 3-month timeline.

566
MCQmedium

A company has a production AWS account and a development AWS account under AWS Organizations. The development team wants to deploy a CloudFormation stack that creates an S3 bucket with a bucket policy that grants access to the production account's IAM roles. The development account has an SCP that denies all s3:PutBucketPolicy actions. The development team has full administrator access in their account. When they try to create the stack, it fails. What is the most likely reason and how should they proceed?

A.The development team does not have IAM permissions to create buckets. They need to attach an IAM policy that allows s3:PutBucketPolicy.
B.The SCP denies s3:PutBucketPolicy and overrides the administrator permissions. They need to request an exception to the SCP from the security team.
C.CloudFormation service role is missing. They need to create a service role with appropriate permissions.
D.The production account's IAM roles are not trusted. They need to update the trust policy.
AnswerB

SCPs set the maximum available permissions for accounts in an organisation, so they override even administrator access. The deny on s3:PutBucketPolicy blocks the stack's bucket policy creation; only the security team can grant an SCP exception.

Why this answer

SCPs apply to all principals in the account, including administrators, and deny actions even if IAM policies allow them. Since the SCP denies s3:PutBucketPolicy, the development team cannot create the bucket policy despite having full admin access. Option A is incorrect because the team does have IAM permissions (admin), but the SCP overrides them.

Option C is incorrect because CloudFormation's service role is not the issue; the SCP restriction affects all principals, including CloudFormation. Option D is incorrect because the trust policy of the production account's IAM roles is unrelated to the SCP in the development account.

567
MCQmedium

A healthcare company has a multi-account AWS environment with a central audit account. The security team needs to ensure that all API activity across all accounts is logged and that logs are stored immutably for 7 years. They also need to be able to search logs across all accounts quickly. Which solution meets these requirements with the LEAST operational overhead?

A.Enable AWS CloudTrail in each account individually, deliver logs to a central S3 bucket with a bucket policy that denies deletion, and use Amazon CloudWatch Logs Insights to search logs.
B.Use AWS Config to record API activity across all accounts and deliver snapshots to a central S3 bucket with S3 Object Lock in governance mode, and use Amazon QuickSight for search.
C.Create an organization trail in AWS CloudTrail that logs to a central S3 bucket with S3 Object Lock in compliance mode, and use Amazon Athena to query the logs.
D.Create an organization trail that logs to a central S3 bucket with versioning and MFA delete enabled, and use AWS Glue to catalog logs for search.
AnswerC

An organization trail automatically logs API activity for all accounts in the organization to a central S3 bucket. S3 Object Lock in compliance mode prevents deletion or modification for the retention period, meeting immutability. Athena can query logs directly from S3 without loading them into a separate system, providing fast search with minimal operational overhead.

Why this answer

An organization trail simplifies logging across all accounts, including future accounts. S3 Object Lock in compliance mode ensures logs cannot be deleted or altered for the retention period, even by the root user. Amazon Athena allows direct SQL queries on S3 data, providing fast search without additional infrastructure.

This solution minimizes operational overhead while meeting immutability and search requirements.

Exam trap

The trap here is underestimating the strength of S3 Object Lock compliance mode versus governance mode or bucket policies, and assuming that AWS Config records API activity.

568
MCQhard

A company is migrating a legacy .NET Framework 4.7 application to AWS. The application uses Windows authentication and COM+ components. Which migration approach is most suitable?

A.Replatform to .NET Core on AWS Elastic Beanstalk (Linux)
B.Use Windows containers on Amazon ECS with Amazon ECS-optimized Windows Server AMI
C.Refactor to run on AWS Lambda with .NET Core 3.1
D.Containerize with Linux containers on Amazon ECS
AnswerB

Windows containers on Amazon ECS with the ECS-optimised Windows Server AMI preserve .NET Framework 4.7, Windows authentication and COM+ registration, which Linux containers cannot host. This satisfies the constraint of running COM+ components without rewriting the application.

Why this answer

Windows containers on Amazon ECS with the ECS-optimized Windows Server AMI support .NET Framework applications and COM+ components, making them the most suitable migration approach. Option A is incorrect because replatforming to .NET Core on Linux would require significant code changes and does not support COM+. Option C is incorrect because AWS Lambda does not support full .NET Framework or COM+.

Option D is incorrect because Linux containers cannot run Windows-based .NET Framework applications.

569
Multi-Selectmedium

A company is migrating a monolithic application to a microservices architecture on AWS. They want to improve deployment frequency and reduce risk. Which TWO strategies should they adopt?

Select 2 answers
A.Deploy all microservices from a single codebase.
B.Implement blue/green deployments.
C.Use CI/CD pipelines with automated testing.
D.Require manual approval for each production deployment.
E.Use feature branches with manual merge approvals.
AnswersB, C

Blue/green deployments run the new microservice version alongside the old one, shifting traffic only after verification. This satisfies the reduced-risk constraint by enabling instant rollback to the previous environment, while supporting frequent releases without downtime.

Why this answer

Correct answers are B and C. Blue/green deployments (B) reduce risk by allowing instant rollback and minimizing downtime during production releases. CI/CD pipelines with automated testing (C) increase deployment frequency by automating build, test, and deployment steps, enabling rapid and reliable releases.

Option A is incorrect because deploying all microservices from a single codebase increases coupling and blast radius. Option D is incorrect because manual approval gates slow down frequency. Option E is incorrect because feature branches with manual merge approvals introduce delays and integration complexity.

570
MCQhard

A company has a microservices architecture running on Amazon ECS with Fargate. Each service writes logs to CloudWatch Logs. The operations team needs to search across all logs for a specific error pattern. Currently, they manually query each log group, which is time-consuming. What is the MOST efficient way to enable centralized log search?

A.Export logs to Amazon S3 and use Amazon Athena to query them.
B.Use CloudWatch Contributor Insights to identify the top error sources.
C.Create a subscription filter for each log group that sends logs to a Kinesis Data Firehose delivery stream.
D.Use CloudWatch Logs Insights to query all log groups from a single query.
AnswerD

CloudWatch Logs Insights queries multiple log groups in one statement, aggregating results centrally. This removes the manual per-group querying that made cross-service error searches slow, directly meeting the centralised search requirement across all Fargate services.

Why this answer

CloudWatch Logs Insights enables querying multiple log groups in a single query using a query language, allowing centralized search across all services. Option A is wrong because exporting to S3 and using Athena is for analyzing historical data, not real-time search. Option B is wrong because CloudWatch Contributor Insights identifies top contributors and is not for arbitrary pattern search.

Option C is wrong because subscription filters to Kinesis Data Firehose can centralize logs but require additional infrastructure and do not provide a built-in query interface like Logs Insights.

Exam trap

Candidates may think that sending logs to a central storage like S3 or Kinesis is necessary, but CloudWatch Logs Insights already provides cross-log-group querying.

571
MCQmedium

A company is designing a new solution to process and analyze large volumes of log data. The data is generated continuously by thousands of IoT devices and must be ingested in near real-time. The company needs to perform simple transformations and aggregations on the data before storing it in Amazon S3 for long-term analysis. The solution must be highly available, scalable, and require minimal operational overhead. Which AWS service should the solutions architect use to ingest and transform the data?

A.Amazon Managed Streaming for Apache Kafka (Amazon MSK) with a Kafka Connect S3 sink connector.
B.Amazon Kinesis Data Firehose with an AWS Lambda function for transformation.
C.Amazon Kinesis Data Streams with an AWS Lambda function for transformation and an Amazon S3 destination.
D.AWS Glue with a scheduled job to process data from an Amazon S3 bucket.
AnswerB

Amazon Kinesis Data Firehose is a fully managed service that can ingest streaming data, transform it using AWS Lambda, and deliver it to Amazon S3. It automatically scales to handle varying throughput and requires no ongoing administration. It provides near real-time delivery and can buffer data before delivering to S3, making it ideal for this scenario.

Why this answer

Amazon Kinesis Data Firehose is a fully managed service that ingests streaming data, applies transformations via AWS Lambda, and delivers to Amazon S3. It scales automatically and requires no server management, providing near real-time processing with minimal operational overhead. This meets the requirements for continuous ingestion, transformation, and storage.

Exam trap

The trap here is assuming that Kinesis Data Streams with Lambda is equivalent to Firehose, but Data Streams requires managing shards and custom consumers, increasing operational overhead.

572
Multi-Selectmedium

A company has a multi-account AWS environment and wants to implement a secure, scalable cross-account network architecture using AWS Transit Gateway. Which TWO steps should be taken?

Select 2 answers
A.Deploy VPC endpoints in each account for communication
B.Create a Transit Gateway in a central networking account and share it with other accounts using AWS Resource Access Manager
C.Create VPC attachments in each account to connect to the shared Transit Gateway
D.Establish VPC peering connections between each account and the central networking account
E.Set up AWS Direct Connect between all accounts
AnswersB, C

RAM allows sharing the Transit Gateway with other accounts.

Why this answer

AWS Transit Gateway must be created in a central networking account and then shared with other accounts using AWS Resource Access Manager (RAM) to enable cross-account connectivity without VPC peering. This centralizes routing and simplifies network management across multiple VPCs and accounts.

Exam trap

The trap here is that candidates confuse VPC endpoints (used for service access) with Transit Gateway (used for VPC-to-VPC routing), or assume VPC peering is sufficient for multi-account scalability despite its non-transitive nature and management overhead.

573
MCQhard

A company runs a production database on Amazon RDS for PostgreSQL. The database experiences high write latency during peak hours. The company wants to improve write performance with minimal cost. Which action should a solutions architect take?

A.Enable Multi-AZ deployment for automatic failover.
B.Add multiple read replicas in different Availability Zones.
C.Use RDS for PostgreSQL with multiple write replicas and configure application-level sharding.
D.Increase the allocated storage and provisioned IOPS.
AnswerD

Provisioned IOPS storage on RDS for PostgreSQL decouples disk throughput from capacity, directly relieving the write-latency bottleneck during peak hours. Increasing allocated storage alone raises baseline IOPS only marginally, so pairing it with provisioned IOPS delivers the sustained write performance the stem demands at minimal cost.

Why this answer

High write latency on RDS for PostgreSQL is typically caused by insufficient storage IOPS or throughput. Increasing allocated storage and provisioned IOPS (on gp3/io1/io2) directly addresses the storage bottleneck that limits write performance, and it is the lowest-cost targeted fix compared to architectural changes. Read replicas and Multi-AZ do not improve write throughput on the primary.

Exam trap

The trap is assuming read replicas or Multi-AZ improve write performance — candidates must remember that only the primary handles writes, and HA/read scaling are orthogonal to write throughput.

How to eliminate wrong answers

Option A is wrong because Multi-AZ provides high availability via synchronous standby replication, not write performance — the standby does not serve writes, and the synchronous commit can even add slight latency. Option B is wrong because read replicas offload read traffic only; they do not increase write capacity on the primary and add cost. Option C is wrong because RDS for PostgreSQL does not support multiple write replicas natively (that is Aurora), and application-level sharding is a major architectural change with high cost and complexity.

Option D is correct because scaling storage/IOPS directly removes the I/O bottleneck causing write latency.

574
MCQmedium

A company has a multi-account AWS environment using AWS Organizations with 50 accounts. The accounts are organized into OUs based on environment: Production, Staging, and Development. The central IT team uses AWS CloudFormation StackSets to deploy a baseline network configuration (VPC, subnets, security groups) to all accounts. Recently, the network team updated the stack set to add a new subnet to the VPC. After the update, they noticed that the stack set operation failed for 10 accounts. The error message indicates that the stack set cannot update because a resource already exists. What is the MOST LIKELY cause of this failure?

A.The accounts are in different OUs and the stack set is not configured to deploy to all OUs.
B.Some accounts have manually created resources that conflict with the stack set template's resources.
C.The network team does not have sufficient IAM permissions to update stacks in those accounts.
D.The stack set was previously drift-detected and the drift is preventing updates.
AnswerB

StackSets fail when a resource declared in the template already exists outside CloudFormation's control. Manually created subnets or VPCs in those ten accounts cause the update to abort with an already-exists error, since CloudFormation cannot adopt unmanaged resources.

Why this answer

StackSets deploy a common template across accounts. If a resource defined in the template (e.g., a subnet with a specific CIDR) already exists in an account due to manual creation or prior configuration, the update fails with a 'resource already exists' error. Option A is incorrect because OU configuration affects initial deployment, not updates, and the error is about resource conflict, not OU coverage.

Option C is incorrect because IAM permissions would cause an 'access denied' error, not a resource conflict. Option D is incorrect because drift detection does not prevent updates; it only reports differences.

575
MCQhard

A company is designing a new application that requires low-latency access to a shared dataset across multiple EC2 instances in the same AWS Region. The dataset is updated frequently. Which storage solution should the company use?

A.Amazon S3
B.Amazon EBS with Provisioned IOPS
C.Amazon S3 Glacier
D.Amazon EFS
AnswerD

Amazon EFS provides a shared, elastic NFS file system mountable concurrently by many EC2 instances in one Region, with low-latency access to frequently updated data. This satisfies the shared-dataset constraint that instance-attached EBS volumes cannot meet.

Why this answer

Amazon EFS provides a fully managed, NFS-based shared file system that can be mounted concurrently by multiple EC2 instances across different Availability Zones within the same AWS Region. It offers low-latency access and supports frequent updates through its standard storage class, making it ideal for shared datasets that require consistent, low-latency performance.

Exam trap

The trap here is that candidates often confuse block storage (EBS) with shared file storage, assuming EBS can be attached to multiple instances simultaneously, or they overlook the latency and protocol differences between object storage (S3) and file storage (EFS) for shared, low-latency workloads.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service accessed via HTTP/S APIs, not a file system; it introduces higher latency and does not support low-latency file-level locking or concurrent NFS-style access required by multiple EC2 instances. Option B is wrong because Amazon EBS volumes are block-level storage that can only be attached to a single EC2 instance at a time (except for multi-attach EBS, which is limited to specific instance types and is not designed for shared, frequently updated datasets across many instances). Option C is wrong because Amazon S3 Glacier is designed for archival and long-term backup with retrieval times ranging from minutes to hours, making it completely unsuitable for low-latency, frequently updated access.

576
Multi-Selecthard

A company is designing a new solution to host a static website with global low latency. The website content is stored in an S3 bucket and must be secured with HTTPS. Which three services or features should be used together to meet these requirements?

Select 3 answers
A.Application Load Balancer
B.S3 bucket configured as an origin with Origin Access Control (OAC)
C.Amazon Route 53
D.AWS Certificate Manager (ACM) to provision a custom SSL certificate
E.Amazon CloudFront
AnswersB, D, E

Restricts direct access to S3, ensuring content is served only through CloudFront.

Why this answer

Origin Access Control (OAC) allows CloudFront to securely access the S3 bucket without making the bucket public, enforcing that all requests come through CloudFront. This is the modern replacement for Origin Access Identity (OAI) and supports HTTPS between CloudFront and S3.

Exam trap

The trap here is that candidates often think an Application Load Balancer is needed for HTTPS termination, but CloudFront handles HTTPS natively with ACM, and ALB is unnecessary for static S3 content.

577
MCQmedium

A company is migrating a web application from on-premises to AWS. The application consists of a stateless web tier and a stateful application tier that stores session data in a local file system. The company wants to use AWS Elastic Beanstalk for both tiers. During a test migration, the development team notices that users are being logged out intermittently. The application tier is configured with two EC2 instances behind an internal load balancer. What should the development team do to resolve the issue?

A.Enable sticky sessions (session affinity) on the application tier's load balancer.
B.Move session storage to Amazon ElastiCache for Redis and configure the application to use it.
C.Increase the number of instances in the web tier to reduce the load on the application tier.
D.Store session data in Amazon DynamoDB.
AnswerB

ElastiCache for Redis externalises session state, so both EC2 instances behind the load balancer read the same session data. This eliminates the intermittent logouts caused by the load balancer routing users to an instance lacking their locally stored session.

Why this answer

The issue is that session data is stored locally on each application instance. When traffic is distributed by the internal load balancer, subsequent requests from the same user may go to a different instance, losing the session data. The best practice is to use a centralized session store like Amazon ElastiCache for Redis.

This ensures session data persists across all instances. Option A (sticky sessions) would cause load imbalance and is not recommended for high availability. Option C does not address session storage.

Option D (DynamoDB) is possible but not as performant for session storage and requires more custom code; Redis is the recommended service for session management.

578
MCQhard

A company is migrating from a monolithic application to microservices on AWS. They need to reduce the blast radius of failures. Which architecture pattern should they implement?

A.Implement Auto Scaling groups for each microservice without separating data stores.
B.Use a cell-based architecture where each microservice runs in isolated cells with independent data stores.
C.Route all traffic through a single Application Load Balancer to simplify management.
D.Deploy all microservices in a single Availability Zone with a shared database.
AnswerB

Cell-based architecture partitions workloads into independent, self-contained cells, each with its own compute and data stores. A failure inside one cell cannot cascade to others, directly shrinking the blast radius, which is the isolation outcome the migration to microservices requires.

Why this answer

A cell-based architecture isolates each microservice (or group) into independent cells with their own data stores, so a failure in one cell cannot cascade to others — this directly reduces blast radius. Independent data stores prevent a shared database from becoming a single point of failure and coupling failure domains. This pattern is the AWS-recommended approach for fault isolation in microservices.

Exam trap

The trap is assuming Auto Scaling alone reduces blast radius — scaling improves capacity but does not isolate failure domains if the data store or load balancer is shared.

How to eliminate wrong answers

Option A is wrong because Auto Scaling without separating data stores leaves a shared database as a single failure domain — a DB outage or lock contention takes down every microservice, defeating blast-radius reduction. Option C is wrong because a single ALB is a shared control-plane/data-plane chokepoint; if it fails or is misconfigured, all traffic to all microservices is affected, and it does not isolate backend failures. Option D is wrong because deploying everything in one AZ with a shared database concentrates both compute and data in a single failure domain, maximizing blast radius rather than reducing it.

579
MCQmedium

A company is migrating a legacy .NET application from on-premises Windows Server to AWS. The application uses Windows authentication and requires a shared file share for configuration files. The company wants to minimize code changes. Which combination of AWS services should be used?

A.Amazon WorkSpaces for application hosting, and Amazon FSx for Lustre for configuration files.
B.Amazon ECS with Windows containers, and Amazon EFS for configuration files.
C.Amazon EC2 Windows instances joined to AWS Managed Microsoft AD, and Amazon FSx for Windows File Server.
D.AWS Lambda with .NET Core, and Amazon S3 for configuration files.
AnswerC

Amazon EC2 Windows instances can be domain-joined to AWS Managed Microsoft AD, enabling Windows authentication. Amazon FSx for Windows File Server provides a fully managed Windows file share that supports SMB protocol and integrates with Active Directory, meeting the shared file share requirement with minimal changes.

Why this answer

To minimize code changes, the application should run on EC2 Windows instances that are domain-joined to AWS Managed Microsoft AD, which provides Windows authentication. Amazon FSx for Windows File Server offers a managed SMB file share that integrates with Active Directory, replacing the on-premises file share without application modifications. This combination preserves the existing authentication and file access mechanisms.

Exam trap

The trap here is assuming that any file storage service can replace a Windows file share, but only Amazon FSx for Windows File Server supports SMB and Active Directory integration required for Windows authentication.

580
MCQhard

A company is designing a new hybrid cloud solution that requires low-latency access to on-premises data from AWS. The connection must be highly available and encrypted. The company has multiple VPCs and on-premises locations. Which combination of services meets these requirements?

A.AWS Site-to-Site VPN and VPC Endpoints
B.AWS Transit Gateway and AWS Direct Connect with VPN backup
C.VPC Peering and AWS Site-to-Site VPN
D.AWS Client VPN and VPC Peering
AnswerB

Transit Gateway provides a hub-and-spoke model for multiple VPCs and on-premises networks. Direct Connect offers dedicated low-latency connections with encryption, and VPN provides a backup.

Why this answer

AWS Transit Gateway acts as a central hub to interconnect multiple VPCs and on-premises networks, simplifying the hybrid architecture. AWS Direct Connect provides a private, low-latency, and consistent network path, while a Site-to-Site VPN over the Direct Connect link (or as a separate backup) adds encryption and high availability. This combination meets all requirements: low latency (Direct Connect), encryption (VPN), high availability (dual connections or failover), and support for multiple VPCs and on-premises locations (Transit Gateway).

Exam trap

The trap here is that candidates often assume a single VPN or Direct Connect alone is sufficient, but the question requires both low latency (Direct Connect) and encryption (VPN) across multiple VPCs and on-premises sites, which only Transit Gateway with Direct Connect and VPN backup fully satisfies.

How to eliminate wrong answers

Option A is wrong because VPC Endpoints are used for private access to AWS services (e.g., S3, DynamoDB) and do not provide connectivity to on-premises data centers; they also do not offer encryption or high availability for hybrid connectivity. Option C is wrong because VPC Peering does not support transitive routing (it is a one-to-one connection) and cannot connect multiple VPCs to multiple on-premises locations without a hub; additionally, it does not inherently provide encryption or low-latency guarantees for hybrid links. Option D is wrong because AWS Client VPN is a remote access VPN for individual clients (not site-to-site) and VPC Peering again lacks transitive routing and cannot aggregate multiple on-premises connections.

581
MCQeasy

A company uses Amazon CloudWatch Logs to collect application logs. The operations team wants to be notified when a specific error message appears in the logs. What is the SIMPLEST way to achieve this?

A.Configure S3 event notifications on the log file destination to send an alert.
B.Subscribe a Lambda function to the log group and have it check for the error message.
C.Create a metric filter on the log group for the error message and set up a CloudWatch alarm on the metric.
D.Use CloudWatch Logs Insights to run a query periodically and send results via email.
AnswerC

A metric filter scans incoming log events for the error pattern and increments a custom CloudWatch metric, which an alarm then evaluates against a threshold. This satisfies the stem's notification requirement natively within CloudWatch Logs, avoiding custom Lambda parsing or third-party tooling.

Why this answer

A CloudWatch metric filter scans a log group for a specified pattern (such as an error string) and increments a custom metric each time the pattern matches; attaching a CloudWatch alarm to that metric then triggers notifications via SNS when the threshold is breached. This is the native, lowest-effort mechanism for alerting on log content and requires no custom code. It directly satisfies the 'simplest way' requirement.

Exam trap

SAP-C02 often tests whether candidates choose the simplest native AWS service rather than a custom Lambda or manual query approach, so candidates who over-engineer the solution pick Lambda or Logs Insights instead of metric filters plus alarms.

How to eliminate wrong answers

Option A is wrong because S3 event notifications fire on object creation events, not on log content, and CloudWatch Logs does not necessarily deliver logs to S3 in a way that supports per-message alerting. Option B is wrong because subscribing a Lambda function to a log group requires writing and maintaining custom code, which is more complex than a metric filter and alarm. Option D is wrong because Logs Insights queries are ad hoc and must be run manually or scheduled via additional tooling; they do not natively push email alerts and are not the simplest solution.

582
MCQmedium

A company is migrating a containerized application to AWS. The application consists of multiple microservices that communicate over HTTP. The company wants to minimize operational overhead and automatically scale the services based on demand. Which AWS service should be used?

A.Amazon EKS with self-managed worker nodes
B.Amazon EC2 instances with Docker installed and an Auto Scaling group
C.AWS Lambda functions for each microservice
D.Amazon ECS with Fargate launch type
AnswerD

Amazon ECS with Fargate allows you to run containers without managing servers, reducing operational overhead. It supports service auto scaling based on metrics like CPU utilization or request count. It integrates with Application Load Balancers for HTTP traffic, making it ideal for microservices communication.

Why this answer

Amazon ECS with Fargate provides a serverless compute engine for containers, eliminating the need to manage servers. It supports auto scaling and integrates with load balancers for HTTP communication. This aligns with the goals of minimizing operational overhead and scaling based on demand.

Exam trap

The trap here is assuming that AWS Lambda is a suitable replacement for containerized microservices without considering the need for long-running processes and container dependencies.

583
MCQmedium

A company is migrating a legacy monolithic application to AWS. The application has a stateful session layer that uses local disk storage. The migration plan involves rehosting the application on Amazon EC2 instances. What architecture change should the company implement to ensure high availability and stateless application tiers?

A.Store session data in Amazon S3 with Transfer Acceleration.
B.Use Amazon RDS with Multi-AZ to store session data.
C.Use Amazon ElastiCache for session state management.
D.Attach Amazon EBS volumes to each EC2 instance for session persistence.
AnswerC

Storing session state in Amazon ElastiCache (Redis or Memcached) externalises it from instance local disk, so any EC2 instance in the Auto Scaling group can serve any request. This removes the stateful constraint, letting the tier scale horizontally and survive instance failure behind a load balancer.

Why this answer

Moving session state to Amazon ElastiCache (Redis or Memcached) externalizes the stateful layer so EC2 instances become stateless and can be placed behind an ELB/ALB with Auto Scaling. This enables any instance to serve any request, supports horizontal scaling, and survives instance failure without losing sessions. ElastiCache provides the low-latency, in-memory access pattern that session lookups require.

Exam trap

SAP-C02 often tests whether candidates confuse 'externalizing state' with 'making the tier stateless' — RDS externalizes state but is the wrong performance fit, and EBS keeps state local, so only ElastiCache satisfies both statelessness and low-latency session access.

How to eliminate wrong answers

Option A is wrong because S3 is object storage with high latency (tens to hundreds of milliseconds) and is not designed for the high-frequency, low-latency read/write pattern of session state; Transfer Acceleration speeds uploads, not session lookups. Option B is wrong because RDS Multi-AZ provides database high availability, not a session store — using a relational DB for session state adds latency, connection overhead, and does not make the app tier stateless in the intended sense (though it does externalize state, it is the wrong tool for the performance requirement). Option D is wrong because attaching EBS volumes to each instance keeps session data tied to a specific instance, so if that instance fails or is replaced by Auto Scaling, the session is lost — this preserves statefulness and defeats high availability.

584
MCQeasy

A company runs a serverless application using AWS Lambda functions that process messages from an Amazon SQS queue. The company wants to improve the reliability of message processing by ensuring that failed messages are not lost and can be reprocessed later. Which solution should a solutions architect recommend?

A.Increase the visibility timeout of the SQS queue to allow more time for Lambda to process messages.
B.Enable long polling on the SQS queue to reduce the number of empty responses.
C.Configure a dead-letter queue (DLQ) for the source SQS queue and set a maximum receive count.
D.Use an Amazon SNS topic to fan out messages to multiple SQS queues for redundancy.
AnswerC

A dead-letter queue captures messages that fail processing after a specified number of receives, preventing them from being lost. The messages can be analyzed and reprocessed later. This is a standard SQS feature that improves reliability without application changes.

Why this answer

Configuring a dead-letter queue on the source SQS queue ensures that messages that repeatedly fail processing are moved to a separate queue for later analysis and reprocessing. This prevents message loss and is a built-in reliability feature of SQS.

Exam trap

The trap here is confusing visibility timeout or long polling with failure handling, when only a dead-letter queue can capture and retain failed messages.

585
MCQhard

A company is modernizing a legacy application by refactoring it into microservices. The application uses a monolithic Oracle database. The team wants to use Amazon RDS for Oracle as the migration target. Which migration approach minimizes risk and downtime?

A.Create a new RDS instance and use AWS SCT to convert the schema, then cutover after testing.
B.Use the strangler fig pattern to incrementally migrate functionality to new microservices, each with its own database.
C.Migrate the entire database at once using AWS DMS with ongoing replication.
D.Rewrite the application as microservices on AWS and then migrate the database.
AnswerB

The strangler fig pattern routes traffic incrementally from the monolith to new microservices, each owning its own database, so the Oracle monolith keeps running until features are fully migrated. This satisfies the minimise-risk-and-downtime constraint by avoiding a single cutover event.

Why this answer

The strangler fig pattern allows incremental migration of functionality from a monolith to microservices, reducing risk and downtime because each service can be migrated and tested independently while the monolith continues to operate. This approach aligns with modernizing a legacy application by refactoring into microservices, each with its own database, which avoids a big-bang cutover. It minimizes risk by allowing rollback and gradual validation, and minimizes downtime because the legacy system remains available during the transition.

Exam trap

The trap is equating 'minimizes risk and downtime' with a single migration tool like AWS DMS or SCT; candidates may overlook that incremental refactoring via the strangler fig pattern is the lowest-risk approach for modernizing a monolith.

How to eliminate wrong answers

Option A is wrong because using AWS SCT to convert the schema and then cutting over after testing is a lift-and-shift approach that does not refactor into microservices; it also risks downtime during cutover and does not address the architectural modernization goal. Option C is wrong because migrating the entire database at once with AWS DMS, even with ongoing replication, is a big-bang migration that does not refactor the application into microservices and can introduce significant risk. Option D is wrong because rewriting the application as microservices and then migrating the database is essentially a big-bang rewrite, which is high-risk and does not minimize downtime or risk incrementally.

586
MCQmedium

A media company uses AWS Organizations with a central shared services account that hosts a Transit Gateway. Workload accounts in two OUs must be able to route traffic through the Transit Gateway to on-premises networks via AWS Site-to-Site VPN, but must not be able to route traffic to each other. A solutions architect needs to enforce this segmentation centrally. What should the architect do?

A.Apply a service control policy to each OU that denies ec2:CreateRoute for routes pointing to the other OU's CIDR ranges.
B.Enable Transit Gateway Inter-Region Peering between the two OUs and configure static routes to block traffic between them.
C.Create separate Transit Gateway route tables for each OU, associate the workload VPC attachments with their respective route tables, and only propagate the VPN attachment into both route tables.
D.Configure VPC peering between each workload VPC and the shared services VPC, and use security groups to deny traffic between the OUs.
AnswerC

Transit Gateway route tables control which attachments can reach which destinations. By associating each OU's VPC attachments with a separate route table and propagating only the VPN attachment, traffic can flow to on-premises but not between the OUs. This provides centralized, network-layer segmentation without relying on account-level controls.

Why this answer

Transit Gateway route tables are the correct mechanism for centralized network segmentation. By giving each OU its own route table that propagates only the VPN attachment, workload VPCs can reach on-premises but cannot reach each other. SCPs, Inter-Region peering, and VPC peering with security groups do not provide the required centralized, route-level isolation.

Exam trap

The trap here is reaching for service control policies to enforce network segmentation, when SCPs control API permissions and cannot filter or block data-plane traffic between attached VPCs.

587
MCQhard

A company has a monolithic application running on a single Amazon EC2 instance. The application consists of a web server and a backend worker process. The company wants to migrate to a microservices architecture using containers on Amazon ECS with Fargate. The solutions architect needs to design a solution that minimizes downtime during the migration. Which approach should the solutions architect recommend?

A.Create a Docker image of the entire monolithic application and run it on ECS with Fargate.
B.Use a strangler fig pattern: gradually replace parts of the monolith with microservices, routing traffic via an Application Load Balancer.
C.Run the monolithic application on the same EC2 instance as the new microservices, using different ports.
D.Refactor the entire application into microservices, then deploy all microservices at once on ECS.
AnswerB

The strangler fig pattern incrementally extracts functionality from the monolith into ECS Fargate microservices, with an Application Load Balancer routing requests between old and new components. This satisfies the minimise-downtime constraint, since both run concurrently and traffic shifts progressively, avoiding a disruptive big-bang cutover.

Why this answer

The strangler fig pattern incrementally replaces monolith functionality with microservices while keeping the monolith running, routing traffic between old and new components via a load balancer. This allows gradual cutover, rollback capability, and near-zero downtime — exactly what the question asks for. It is the industry-standard approach for low-risk monolith-to-microservices migration.

Exam trap

SAP-C02 often tests whether candidates recognize that 'minimize downtime' and 'microservices' together rule out big-bang refactors and lift-and-shift containerization — the trap is picking the option that sounds fastest (containerize everything at once) rather than the one that is safest and incremental.

How to eliminate wrong answers

Option A is wrong because containerizing the entire monolith as-is does not achieve a microservices architecture — it just lifts and shifts the same monolithic design, failing the stated goal. Option C is wrong because running the monolith and microservices on the same EC2 instance couples their fate (shared failure domain, resource contention) and does not provide a clean migration path or high availability. Option D is wrong because a big-bang refactor and simultaneous deployment of all microservices maximizes risk, requires extensive upfront work, and typically causes significant downtime if anything fails.

588
MCQhard

A company is migrating a monolithic application to AWS and wants to modernize it into microservices. The application currently uses a single relational database. Which migration strategy is most appropriate to minimize risk while starting the modernization process?

A.Incremental migration using the Strangler Fig pattern
B.Big bang migration of the entire application to containers
C.Replatform to Amazon RDS for MySQL
D.Rehost the application using AWS VM Import/Export
AnswerA

The Strangler Fig pattern incrementally extracts functionality from the monolith behind a facade, routing traffic to new microservices while the legacy application keeps running. This limits blast radius and lets the team modernise gradually without a risky big-bang rewrite.

Why this answer

The Strangler Fig pattern (Option A) is the most appropriate strategy because it allows incremental replacement of monolithic components with microservices, reducing the risk associated with a full rewrite or big bang migration. Option B (big bang migration to containers) is risky as it requires simultaneous migration of all components. Option C (replatform to Amazon RDS) only changes the database platform without addressing application architecture.

Option D (rehost using VM Import/Export) simply lifts and shifts the monolith without modernization.

589
MCQeasy

A company is using AWS CloudTrail to log all API activity. The security team wants to be alerted when an IAM user creates a new access key. What is the simplest way to achieve this?

A.Configure an S3 event notification on the CloudTrail log bucket to trigger a Lambda function.
B.Set up a CloudTrail trail with log file validation enabled.
C.Use AWS Config to create a rule that checks for access keys.
D.Create an Amazon EventBridge rule that matches the 'CreateAccessKey' API call and sends an SNS notification.
AnswerD

EventBridge natively ingests CloudTrail management events and pattern-matches on the `CreateAccessKey` API call, triggering an SNS notification without custom code or log parsing. This satisfies the stem's requirement for the simplest alerting mechanism, since CloudTrail already delivers the event stream EventBridge consumes.

Why this answer

Amazon EventBridge natively integrates with CloudTrail to receive API call events in near real-time. By creating an EventBridge rule that matches the 'CreateAccessKey' event source and detail-type, you can route the event directly to an SNS topic for alerting. This is the simplest, most direct, and serverless approach, requiring no custom code or additional services beyond the rule and SNS topic.

Exam trap

SAP-C02 often tests the distinction between real-time event-driven alerting (EventBridge) and batch/log-based processing (S3 notifications, Config rules), so candidates may incorrectly choose S3 event notifications or AWS Config due to familiarity with those services.

How to eliminate wrong answers

Option A is wrong because S3 event notifications trigger on object-level operations (e.g., PutObject) and would require a custom Lambda function to parse CloudTrail log files, adding unnecessary complexity and latency. Option B is wrong because log file validation only ensures log integrity (detecting tampering) and does not provide any alerting or event-driven capability. Option C is wrong because AWS Config rules evaluate resource configurations for compliance and are not designed for real-time API call alerting; they also typically require a custom rule or Lambda, making it less simple.

590
MCQmedium

A company runs a critical web application on EC2 instances behind an ALB. The application stores session data in an ElastiCache Redis cluster. During a recent outage, the Redis cluster failed and all active sessions were lost, causing users to be logged out. Which solution would provide the HIGHEST availability for session data?

A.Enable Cluster Mode and deploy Redis in Multi-AZ with replicas.
B.Deploy a single-node Redis cluster with automatic backups.
C.Disable Redis persistence to improve performance.
D.Use a larger Redis instance type to handle more connections.
AnswerA

Multi-AZ with replicas provides automatic failover and high availability.

Why this answer

Enabling ElastiCache Redis Cluster Mode with Multi-AZ and replicas provides the highest availability because data is sharded across multiple nodes, each with one or more replicas in different AZs. If a primary node or AZ fails, ElastiCache automatically promotes a replica, preserving session data and minimizing downtime. This eliminates the single point of failure that caused the outage.

Exam trap

SAP-C02 often tests the difference between high availability (Multi-AZ with automatic failover) and durability (backups/persistence), so candidates who pick 'automatic backups' as an HA solution confuse backup/restore with failover.

How to eliminate wrong answers

Option B is wrong because a single-node Redis cluster, even with backups, has no automatic failover — a node failure causes downtime and data loss until a manual restore, which is not high availability. Option C is wrong because disabling persistence reduces durability and does not improve availability; it actually increases the risk of data loss on failure. Option D is wrong because a larger instance type only increases capacity and does not address redundancy or failover, so a failure still causes an outage.

591
MCQhard

A company is migrating a monolithic application to microservices on Amazon ECS. The application uses a legacy database that does not support distributed transactions. The team wants to ensure data consistency across services. Which solution is BEST for achieving eventual consistency with minimal code changes?

A.Use Amazon DynamoDB transactions across all services.
B.Modify the legacy database to support two-phase commit.
C.Use Amazon SQS to queue all database writes and process them sequentially.
D.Implement the Saga pattern using AWS Step Functions.
AnswerD

Step Functions can orchestrate a saga, handling failures and compensating transactions.

Why this answer

The Saga pattern coordinates a sequence of local transactions across microservices, with compensating transactions to roll back on failure, achieving eventual consistency without distributed transactions. AWS Step Functions is the managed orchestration service that implements Saga with minimal custom code — you define the state machine in Amazon States Language and Step Functions handles retries, compensation, and state tracking. This is the AWS-recommended approach for eventual consistency in microservices.

Exam trap

The trap is reaching for a database-level solution (DynamoDB transactions, two-phase commit) when the problem explicitly involves a legacy database that cannot participate — candidates must recognize that Saga is the only pattern that works across heterogeneous data stores with minimal code changes.

How to eliminate wrong answers

Option A is wrong because DynamoDB transactions only work within DynamoDB tables (up to 100 items across tables in the same account/region) and cannot wrap the legacy database, so they cannot provide consistency across services that write to the legacy DB. Option B is wrong because modifying a legacy database to support two-phase commit is a massive, risky change that contradicts the 'minimal code changes' requirement and is often impossible with commercial off-the-shelf legacy systems. Option C is wrong because queuing all writes to a single SQS queue and processing them sequentially creates a bottleneck, does not provide compensating transactions for partial failures, and does not address consistency across services that each own their own data store.

592
MCQmedium

A company is migrating a critical application to AWS and needs to ensure high availability across two Availability Zones. The application runs on EC2 instances behind an Application Load Balancer (ALB). The database is an on-premises SQL Server that will be migrated later. Which architecture provides high availability for the application tier during the migration?

A.Deploy EC2 instances in two AZs behind an ALB with cross-zone load balancing enabled.
B.Deploy EC2 instances in a single AZ with an Auto Scaling group.
C.Deploy EC2 instances in two AZs behind a Network Load Balancer (NLB).
D.Use Amazon Route 53 weighted routing to distribute traffic to instances in two AZs.
AnswerA

Instances in two Availability Zones behind an ALB survive an AZ failure, and cross-zone load balancing distributes requests evenly to healthy targets in the remaining zone. This delivers application-tier high availability during the migration, independent of the on-premises SQL Server still in place.

Why this answer

Deploying EC2 instances in two Availability Zones behind an Application Load Balancer with cross-zone load balancing enabled provides high availability for the application tier. The ALB distributes traffic across healthy instances in both AZs, and cross-zone load balancing ensures even distribution even if one AZ has more instances. This architecture survives an AZ failure because the ALB routes traffic to the remaining AZ, and the application remains available.

Exam trap

The trap is confusing high availability with auto scaling or DNS-based routing; candidates may pick a single-AZ Auto Scaling group or Route 53 weighted routing, but true high availability across AZs requires a load balancer with cross-zone enabled.

How to eliminate wrong answers

Option B is wrong because deploying instances in a single AZ with an Auto Scaling group does not provide high availability across AZs; an AZ failure would take down all instances. Option C is wrong because a Network Load Balancer (NLB) operates at Layer 4 and does not provide the same HTTP/HTTPS-aware routing as an ALB; while it can be used, the question specifies an ALB is already in use, and NLB is not the best fit for application-tier high availability with HTTP. Option D is wrong because Route 53 weighted routing distributes traffic at the DNS level but does not provide health checks and failover as robustly as an ALB; it also does not ensure high availability within the application tier itself.

593
MCQmedium

A company is migrating a legacy application to AWS using the 7 Rs migration strategy. The application is a monolithic Java application running on a single on-premises server with a MySQL database. The company wants to reduce operational overhead and improve scalability. The development team has already containerized the application and tested it locally. The company wants to run the containerized application on AWS without managing the underlying infrastructure. Which AWS service should the company use to deploy the containerized application?

A.Amazon ECS with AWS Fargate launch type
B.Amazon EKS with managed node groups
C.Amazon EC2 with Docker installed
D.Amazon Lightsail containers
AnswerA

Amazon ECS with the Fargate launch type runs containers serverlessly, so no EC2 instances need provisioning, patching or scaling. This directly satisfies the stem's requirement to avoid managing underlying infrastructure while improving scalability, and it suits the already-containerised Java application without code changes.

Why this answer

Amazon ECS with AWS Fargate launch type is a serverless compute engine for containers, eliminating infrastructure management. Option B (EKS with managed node groups) still requires managing the node groups at the EC2 level. Option C (EC2 with Docker) requires managing EC2 instances.

Option D (Lightsail containers) is not as scalable or integrated with AWS services as ECS with Fargate.

594
MCQeasy

A company wants to design a cost-effective solution to store infrequently accessed log files for 7 years. The logs are generated daily and must be available for retrieval within 24 hours. Which Amazon S3 storage class should be used?

A.S3 One Zone-Infrequent Access
B.S3 Intelligent-Tiering
C.S3 Glacier Deep Archive
D.S3 Standard
AnswerC

S3 Glacier Deep Archive offers the lowest storage cost for long-term retention and supports standard retrieval within 12 hours, satisfying the 24-hour availability constraint across the 7-year period. It is designed precisely for rarely accessed compliance archives.

Why this answer

Amazon S3 Glacier Deep Archive is the most cost-effective storage class for infrequently accessed data that must be retained for 7 years, with retrieval times of up to 12 hours (within the 24-hour requirement). It offers the lowest storage cost among S3 classes, making it ideal for long-term archival of log files that are rarely accessed.

Exam trap

The trap here is that candidates often confuse retrieval time requirements with access frequency, assuming that any 'Infrequent Access' class (like S3 One Zone-IA or S3 Standard-IA) is the best choice for archival, when in fact S3 Glacier Deep Archive is designed specifically for long-term, cost-effective archival with retrieval times that still meet the 24-hour window.

How to eliminate wrong answers

Option A is wrong because S3 One Zone-Infrequent Access is designed for data that is accessed infrequently but requires rapid retrieval (milliseconds), and it stores data in a single Availability Zone, which does not provide the durability needed for a 7-year retention period; its cost is higher than Glacier Deep Archive for long-term archival. Option B is wrong because S3 Intelligent-Tiering automatically moves data between access tiers based on usage patterns, but it is not optimized for purely archival data that will almost never be accessed; it incurs monitoring and automation fees that make it less cost-effective than Glacier Deep Archive for data that will be stored for 7 years with infrequent access. Option D is wrong because S3 Standard is designed for frequently accessed data with millisecond retrieval and is the most expensive storage class, making it unsuitable for cost-effective long-term archival of infrequently accessed logs.

595
MCQmedium

A media company is deploying a new video transcoding pipeline on AWS. The pipeline will process thousands of small input files stored in Amazon S3, and each file must be transcoded independently. The transcoding jobs are short (under 5 minutes) and stateless. The company wants a solution that scales automatically, minimizes operational overhead, and provides near-real-time processing. Which design should a solutions architect recommend?

A.Use AWS Lambda functions triggered by S3 event notifications to process each file as it is uploaded.
B.Use AWS Step Functions to orchestrate a fleet of Amazon EC2 instances that poll an Amazon SQS queue for new files.
C.Use AWS Batch with a managed compute environment to run transcoding jobs on Amazon EC2 Spot Instances.
D.Use Amazon Kinesis Data Firehose to stream the video files to Amazon Elastic Transcoder for processing.
AnswerA

AWS Lambda is ideal for short, stateless, event-driven tasks. S3 event notifications can invoke a Lambda function synchronously when an object is created, enabling near-real-time processing. Lambda automatically scales with the number of events, and there is no infrastructure to manage. This matches the requirements for low operational overhead and automatic scaling for small, independent transcoding jobs.

Why this answer

The requirement for near-real-time processing of small, independent files with minimal operational overhead points to a serverless, event-driven architecture. AWS Lambda integrates natively with S3 event notifications, allowing each uploaded file to trigger a function immediately. Lambda scales automatically and eliminates server management.

Other options introduce polling, orchestration overhead, or unsuitable services, failing to meet the low-latency and low-ops goals.

Exam trap

The trap here is assuming that any scalable compute service (like AWS Batch or Step Functions with EC2) is equally suitable, overlooking the need for event-driven, near-real-time processing and minimal operational overhead.

596
MCQeasy

A company is migrating a legacy on-premises application to AWS. The application requires a shared file system that can be mounted on multiple Amazon EC2 instances across multiple Availability Zones. The file system must be highly available, durable, and support POSIX permissions. The company wants a fully managed solution. Which AWS service should a solutions architect recommend?

A.Amazon S3 with a file gateway deployed on each EC2 instance.
B.Amazon Elastic Block Store (Amazon EBS) with Multi-Attach enabled.
C.Amazon Elastic File System (Amazon EFS).
D.Amazon FSx for Windows File Server.
AnswerC

Amazon EFS is a fully managed, elastic NFS file system that can be mounted on multiple EC2 instances across multiple Availability Zones. It provides high availability and durability by storing data redundantly across Availability Zones. It supports POSIX permissions and is designed for shared access, making it the ideal solution for this legacy application requiring a shared file system.

Why this answer

Amazon Elastic File System (Amazon EFS) is a fully managed, scalable, and elastic NFS file system for Linux-based workloads. It can be mounted on multiple EC2 instances across multiple Availability Zones simultaneously, providing high availability and durability. It supports POSIX permissions and is designed for shared access, making it the correct choice for a legacy application requiring a shared file system.

Exam trap

The trap here is confusing Amazon EBS Multi-Attach with a shared file system; Multi-Attach is limited to a single Availability Zone and does not support POSIX-compliant shared access.

597
MCQeasy

A company is designing a solution to capture changes from an Amazon RDS database and stream them to a data lake. Which AWS service should be used to capture database changes in real time?

A.AWS Glue with streaming ETL
B.AWS Lambda with database polling
C.Amazon Kinesis Data Streams with a custom producer
D.AWS Database Migration Service (DMS) with change data capture (CDC)
AnswerD

AWS DMS with change data capture reads the database's transaction logs (or redo logs) and streams row-level inserts, updates and deletions continuously, satisfying the real-time capture requirement. Unlike batch exports, CDC propagates changes as they commit, feeding the data lake with minimal latency.

Why this answer

AWS DMS with change data capture (CDC) is the correct service because it is specifically designed to capture ongoing changes from source databases (including Amazon RDS) in near real time and replicate them to targets like Amazon S3 (data lake). DMS reads the database transaction logs (e.g., MySQL binlog, PostgreSQL WAL) to capture inserts, updates, and deletes without requiring application-level polling or custom code, making it the most appropriate managed solution for streaming database changes to a data lake.

Exam trap

The trap here is that candidates often confuse AWS DMS with other streaming services like Kinesis or Glue, not realizing that DMS is the only AWS service that natively captures database transaction log changes without requiring custom code or polling.

How to eliminate wrong answers

Option A is wrong because AWS Glue with streaming ETL is designed for processing streaming data from sources like Amazon Kinesis or Kafka, not for capturing changes directly from an RDS database; it lacks native CDC capabilities to read database transaction logs. Option B is wrong because AWS Lambda with database polling requires custom code to repeatedly query the database for changes, which introduces latency, increased load on the database, and is not a real-time streaming solution; it also does not capture deletes or changes efficiently without additional logic. Option C is wrong because Amazon Kinesis Data Streams with a custom producer requires you to build and manage your own application to poll the RDS database and push changes to Kinesis, adding operational overhead and complexity; it does not provide native CDC integration with database transaction logs.

598
MCQmedium

A company has a web application that uses an Amazon RDS for PostgreSQL database. The database is experiencing high read traffic, and the application is seeing increased latency. The database is currently a Single-AZ deployment with a db.r5.2xlarge instance. The company wants to improve read performance and also increase availability with minimal application changes. Which solution should a solutions architect recommend?

A.Enable Amazon RDS Performance Insights to identify and optimize slow queries.
B.Migrate the database to Amazon Aurora PostgreSQL with a reader endpoint and update the application to use the reader endpoint for read queries.
C.Create a read replica of the RDS instance and modify the application to direct read queries to the read replica endpoint.
D.Convert the RDS instance to a Multi-AZ deployment and create a read replica in a different Availability Zone.
AnswerC

Creating a read replica offloads read traffic from the primary database, improving read performance. Modifying the application to use the read replica endpoint for read queries is a standard pattern and requires minimal changes if the application uses a separate connection for reads. This also improves availability because the read replica can be promoted if the primary fails.

Why this answer

Adding a read replica to the existing RDS instance and directing read queries to it offloads read traffic and improves performance. This requires minimal application changes—just pointing read queries to the replica endpoint. It also enhances availability because the replica can be promoted.

Other options either do not serve reads, require more changes, or involve migration.

Exam trap

The trap here is confusing Multi-AZ with read scaling; Multi-AZ provides failover, not read capacity, and Performance Insights only monitors.

599
MCQeasy

A company is designing a new solution to store and analyze large amounts of log data from multiple sources. The logs must be retained for 90 days for recent analysis, and then archived to a more cost-effective storage class for an additional 5 years. The solution must support SQL-based queries. Which combination of AWS services should the company use?

A.Amazon Redshift with data sharing to retain logs for 5 years.
B.Amazon S3 with lifecycle policies to transition objects to S3 Glacier Deep Archive after 90 days, and Amazon Athena for SQL queries.
C.Amazon OpenSearch Service with UltraWarm storage to archive logs after 90 days.
D.Amazon RDS for PostgreSQL with automated backups to retain logs for 5 years.
AnswerB

S3 lifecycle policies automatically transition objects to Glacier Deep Archive after 90 days, meeting the 5-year archival cost constraint. Athena queries S3 directly using standard SQL, so no separate database or ETL pipeline is needed for the recent-analysis requirement.

Why this answer

Amazon S3 with lifecycle policies can automatically transition log objects from S3 Standard to S3 Glacier Deep Archive after 90 days, meeting the 90-day retention for recent analysis and the 5-year archival requirement at the lowest cost. Amazon Athena allows SQL-based queries directly on the log data stored in S3, without needing to load data into a separate database, making it a serverless and cost-effective solution for ad-hoc analysis.

Exam trap

The trap here is that candidates often confuse Amazon OpenSearch Service's UltraWarm storage as a long-term archival solution, but it is actually a warm tier for less-frequently accessed data within the same cluster, not a cost-effective cold archive like S3 Glacier Deep Archive, and it does not support SQL queries natively.

How to eliminate wrong answers

Option A is wrong because Amazon Redshift is a data warehouse optimized for structured, frequently queried data, not for storing large volumes of raw log data over long periods; using data sharing does not provide a cost-effective archival tier like S3 Glacier Deep Archive, and retaining logs for 5 years in Redshift would be prohibitively expensive. Option C is wrong because Amazon OpenSearch Service with UltraWarm storage is designed for near-real-time search and analytics on log data, but it does not support SQL-based queries natively (it uses its own query DSL) and UltraWarm is not a long-term archival tier; it also lacks the cost efficiency of S3 Glacier Deep Archive for 5-year retention. Option D is wrong because Amazon RDS for PostgreSQL is a relational database service intended for transactional workloads, not for storing and analyzing large volumes of log data; automated backups are for point-in-time recovery, not for long-term archival, and storing logs for 5 years in RDS would incur high storage costs and performance issues.

600
MCQeasy

A company has a single AWS account with multiple VPCs. They want to connect all VPCs to a central VPC for shared services, such as Active Directory and DNS, without using a complex mesh of VPC peering connections. They also want to minimize costs. Which solution should they use?

A.Use AWS PrivateLink to connect each VPC to the shared services VPC.
B.Create a full mesh of VPC peering connections between all VPCs.
C.Use AWS Transit Gateway to connect all VPCs and the shared services VPC.
D.Create a VPN connection between each VPC and the shared services VPC.
AnswerC

AWS Transit Gateway acts as a central hub to connect multiple VPCs and on-premises networks. It simplifies network architecture by eliminating complex peering meshes. With Transit Gateway, you can connect all VPCs to a single gateway, and the shared services VPC can be accessed by all. This is scalable and cost-effective compared to multiple peering connections.

Why this answer

AWS Transit Gateway provides a central hub to connect multiple VPCs and shared services. It simplifies network architecture, reduces management overhead, and is cost-effective compared to a full mesh of VPC peering connections. It allows all VPCs to access the shared services VPC without complex peering arrangements.

Exam trap

The trap here is assuming that VPC peering is always the cheapest option, but for multiple VPCs, Transit Gateway can be more cost-effective and manageable.

Page 7

Page 8 of 14

Page 9