Courseiva

CCNA Accelerate Workload Migration and Modernization Questions

75 of 235 questions · Page 1/4 · Accelerate Workload Migration and Modernization · Answers revealed

1
MCQmedium

A company is migrating a monolithic e-commerce application to a microservices architecture on AWS. The migration must minimize downtime and allow rollback. Which migration strategy should the company use?

A.Refactor
B.Big bang migration
C.Strangler fig pattern
D.Rehost (lift and shift)
AnswerC

The strangler fig pattern incrementally routes specific functions from the monolith to new microservices behind a facade, so each slice can be released and rolled back independently. This satisfies both the minimal-downtime and rollback constraints, unlike a single big-bang cutover.

Why this answer

The strangler fig pattern incrementally replaces pieces of a monolith with microservices by routing traffic through a facade, allowing new services to be introduced alongside the legacy system. This minimizes downtime because the monolith keeps serving unaffected functionality while migrated components go live, and it enables rollback by simply routing traffic back to the old path. It is the standard AWS-recommended approach for low-risk monolith decomposition.

Exam trap

SAP-C02 often tests whether candidates conflate the general act of refactoring with a specific incremental migration pattern, so pick the option that explicitly describes gradual replacement with rollback capability.

How to eliminate wrong answers

Option A is wrong because refactoring is the broader activity of rewriting code, not a migration strategy that by itself guarantees minimal downtime or rollback — it describes what you do, not how you cut over safely. Option B is wrong because a big bang migration replaces everything at once, maximizing downtime and offering no practical rollback path if the new system fails. Option D is wrong because rehost (lift and shift) moves the monolith to EC2 as-is and does not decompose it into microservices, so it fails the architectural goal.

2
MCQmedium

A company is migrating a monolithic application to AWS. They want to minimize refactoring effort while gaining some benefits of the cloud. Which migration strategy is most appropriate?

A.Refactor / Re-architect
B.Repurchase
C.Rehost (lift-and-shift)
D.Replatform (lift-tinker-and-shift)
AnswerC

Rehosting moves the application to AWS without altering its architecture, satisfying the minimal-refactoring constraint. The monolith runs on EC2 instances, gaining cloud benefits such as elasticity and pay-as-you-go pricing while avoiding code changes. This differs from replatforming, which requires modifying components, and refactoring, which demands architectural redesign.

Why this answer

Rehost (lift-and-shift) involves moving the application as-is to AWS with minimal changes, aligning with the goal of minimizing refactoring effort. Option A is wrong because Refactor/Re-architect requires significant code changes. Option B is wrong because Repurchase involves switching to a different product, often a SaaS solution.

Option D is wrong because Replatform (lift-tinker-and-shift) involves some modifications to the application to take advantage of cloud capabilities, which requires more effort than pure rehost.

3
MCQmedium

A company is planning to migrate its on-premises data warehouse to AWS. The data warehouse runs on a large Oracle RAC cluster with complex stored procedures and ETL jobs. The company wants to minimize migration effort while gaining cloud benefits. Which AWS service should be used as the target?

A.Amazon DynamoDB
B.Amazon RDS for Oracle
C.Amazon Redshift
D.Amazon Aurora PostgreSQL
AnswerC

Amazon Redshift is a petabyte-scale columnar data warehouse supporting SQL, stored procedures and ETL tooling, letting the company migrate with minimal refactoring while gaining managed cloud elasticity. It avoids the re-architecture effort required by serverless alternatives such as Athena.

Why this answer

Amazon Redshift is a petabyte-scale data warehouse service that is optimized for analytical workloads and supports complex SQL queries, stored procedures, and ETL jobs. It is designed to handle large data volumes and can minimize migration effort by providing compatibility with existing SQL and ETL tools. DynamoDB is a NoSQL database not suitable for complex stored procedures, RDS for Oracle is not a data warehouse and may not scale as needed, and Aurora PostgreSQL is an OLTP database, not a data warehouse.

Exam trap

SAP-C02 often tests the misconception that RDS for Oracle is a suitable data warehouse target, but it lacks the analytical scalability of Redshift.

How to eliminate wrong answers

Option A is wrong because DynamoDB is a NoSQL key-value store, not a relational data warehouse; it cannot run complex stored procedures or ETL jobs natively. Option B is wrong because Amazon RDS for Oracle is an OLTP database service, not a data warehouse; it may not provide the performance and scalability required for large analytical workloads. Option D is wrong because Amazon Aurora PostgreSQL is an OLTP database, not a data warehouse; while it can handle some analytical queries, it is not optimized for large-scale data warehousing.

4
MCQeasy

A company is migrating a stateful application to AWS. The application maintains session state in memory on the application server. Which AWS service should be used to store session state for high availability?

A.Amazon RDS
B.Amazon S3
C.Amazon ElastiCache
D.Amazon EBS
AnswerC

ElastiCache stores session state in a managed Redis or Memcached cluster external to the application servers, so any instance can serve any user and sessions survive instance failure. This satisfies the stem's high availability requirement for a stateful application.

Why this answer

Amazon ElastiCache is an in-memory caching service that supports Redis or Memcached, making it ideal for storing session state with low latency and high availability. It provides sub-millisecond response times and can be configured with Multi-AZ and automatic failover to ensure session data persists even if a node fails. This is the standard AWS solution for externalizing session state in stateless application architectures.

Exam trap

SAP-C02 often tests the misconception that any database can store session state; the trap is that candidates may choose RDS for its durability, but session state requires low-latency, high-throughput access, making ElastiCache the correct choice.

How to eliminate wrong answers

Option A is wrong because Amazon RDS is a disk-based relational database that introduces higher latency and is not optimized for high-frequency session read/write operations; it is better suited for persistent, structured data. Option B is wrong because Amazon S3 is object storage with higher latency and is not designed for frequent, small writes typical of session state, nor does it provide the low-latency access required. Option D is wrong because Amazon EBS is block storage attached to a single EC2 instance and does not provide a shared, highly available store for session state across multiple instances.

5
MCQhard

A company is migrating a legacy .NET application to AWS. The application uses Windows authentication and COM+ components. The company wants to move to a modern architecture with minimal changes to the application code. The application must run on AWS and integrate with Active Directory for authentication. Which solution should the company use?

A.Migrate the application to AWS Lambda with a custom runtime that emulates COM+ components, and use Amazon Cognito for authentication.
B.Migrate the application to Amazon EC2 for Windows Server instances joined to an AWS Managed Microsoft AD domain, and use COM+ components on the instances.
C.Refactor the application to use .NET Core and run it on Amazon ECS with Windows containers, using AWS IAM for authentication.
D.Migrate the application to Amazon RDS for SQL Server and use AWS Directory Service for authentication, keeping the application on-premises.
AnswerB

Amazon EC2 for Windows Server supports Windows authentication and COM+ components natively. By joining the instances to AWS Managed Microsoft AD, the application can use Active Directory for authentication without code changes. This approach provides a familiar environment for the legacy application and minimizes migration effort, aligning with a rehost strategy.

Why this answer

For a legacy .NET application using Windows authentication and COM+ components, the most straightforward migration path is to rehost it on Amazon EC2 for Windows Server instances. Joining these instances to AWS Managed Microsoft AD provides seamless Active Directory integration. This approach requires minimal code changes and preserves the existing architecture, making it the best fit for the company's requirements.

Exam trap

The trap here is assuming that modern services like Lambda or ECS can easily support legacy COM+ and Windows authentication without significant refactoring.

6
MCQhard

A company is migrating a legacy application that uses TCP on port 8080 to AWS. The application must be accessible from the internet. The company wants to use an Application Load Balancer. What must the company do to ensure the load balancer can accept traffic on port 8080?

A.Configure the security group to allow inbound traffic on port 80 and 443 only.
B.Change the ALB's default port to 8080.
C.Assign an Elastic IP address to the ALB.
D.Create a listener for port 8080 on the ALB.
AnswerD

An ALB listener defines the port and protocol on which it accepts inbound connections, so creating one on port 8080 satisfies the requirement to accept TCP traffic there. The listener then evaluates rules and forwards to a target group. Without a matching listener, the ALB silently drops traffic, regardless of security group configuration.

Why this answer

An ALB requires a listener for each port it accepts traffic on; to accept TCP on port 8080, you must create a listener on port 8080 with rules forwarding to the target group. The security group must also allow 8080, but the listener is the ALB configuration step that enables the port.

Exam trap

The trap is assuming the ALB has a configurable default port or that an Elastic IP is needed — ALBs use listeners, and only NLBs support Elastic IPs.

How to eliminate wrong answers

Option A is wrong because restricting the security group to 80/443 would block 8080 traffic entirely, not enable it. Option B is wrong because ALBs do not have a 'default port' to change; listeners define ports. Option C is wrong because ALBs do not support Elastic IP addresses (only NLBs do), and an EIP would not enable port 8080.

7
MCQhard

A company is migrating an on-premises .NET application to AWS. The application uses a SQL Server database with a large number of stored procedures and triggers. The company wants to reduce licensing costs by moving to an open-source database. Which AWS service should the solutions architect use to automate the database conversion?

A.AWS Database Migration Service (DMS)
B.AWS App2Container
C.AWS Schema Conversion Tool (SCT)
D.AWS Application Migration Service (CloudEndure)
AnswerC

AWS SCT analyses the SQL Server schema and automatically converts stored procedures, triggers and other proprietary objects into the target open-source engine's equivalent syntax. This satisfies the requirement to automate conversion, reducing the manual rewrite effort before data migration.

Why this answer

AWS Schema Conversion Tool (SCT) automates the conversion of database schema and code to a target database like PostgreSQL or MySQL. DMS handles data migration, not schema conversion. App2Container is for containerizing applications.

CloudEndure is for server migration.

8
MCQeasy

A retail company is migrating its e-commerce platform from a monolith running on a single on-premises server to AWS. The current application consists of a Java-based web server, a MySQL database, and a caching layer using Redis. The company wants to modernize the architecture by adopting microservices, using serverless where possible, and minimizing operational overhead. The migration must be completed within six months with minimal disruption to ongoing operations. The solutions architect proposes the following initial steps: containerize the Java application and run it on Amazon ECS with Fargate, migrate the MySQL database to Amazon Aurora Serverless v2, and replace Redis with Amazon ElastiCache for Redis Serverless. However, the team is concerned about the complexity of the migration and the potential for downtime. Which recommendation should the solutions architect make to address these concerns?

A.Rewrite the entire application as microservices from scratch and deploy them in a new AWS environment. Cut over all traffic at once after testing.
B.Use AWS Blue/Green deployment for the monolith to reduce downtime, then migrate to microservices after the deployment is stable.
C.Use the Strangler Fig pattern to incrementally replace monolith functionality with microservices, routing traffic to new services as they are built.
D.Perform a lift-and-shift migration of the monolith to EC2 instances, then gradually refactor into microservices over the next year.
AnswerC

The Strangler Fig pattern incrementally replaces monolith functionality with microservices, routing traffic gradually to new services. This limits migration risk and avoids downtime, satisfying the six-month deadline with minimal disruption while enabling the serverless modernisation the company wants.

Why this answer

The Strangler Fig pattern allows the team to incrementally replace specific functionalities of the monolithic e-commerce platform with microservices, routing traffic to the new services as they are built. This minimizes disruption and downtime by avoiding a big-bang cutover, and it aligns with the goal of modernizing to microservices and serverless within the six-month timeline. The pattern leverages an existing ingress controller (e.g., an Application Load Balancer with path-based routing) to gradually shift requests from the monolith to new services running on Amazon ECS with Fargate, while the database and caching layers are migrated separately with minimal impact.

Exam trap

The trap here is that candidates often confuse Blue/Green deployments (which reduce downtime for a single application version) with the Strangler Fig pattern (which is specifically designed for incremental migration from a monolith to microservices), leading them to choose Option B as a safe but incomplete solution.

How to eliminate wrong answers

Option A is wrong because rewriting the entire application from scratch as microservices and performing a single cutover introduces high complexity, significant risk of downtime, and likely exceeds the six-month timeline, contradicting the requirement for minimal disruption. Option B is wrong because Blue/Green deployment for the monolith reduces downtime during deployment but does not address the migration to microservices; it keeps the monolith intact and defers the modernization, failing to meet the goal of adopting microservices and serverless. Option D is wrong because a lift-and-shift to EC2 instances postpones refactoring for over a year, which violates the six-month migration deadline and does not minimize operational overhead, as it retains the monolithic architecture and requires managing EC2 instances.

9
MCQeasy

A company is migrating a legacy application that uses a proprietary binary protocol over TCP. The application must be migrated with minimal changes and requires high throughput. Which AWS service should the architect recommend for load balancing?

A.Network Load Balancer (NLB)
B.AWS Global Accelerator
C.Application Load Balancer (ALB)
D.Classic Load Balancer (CLB)
AnswerA

Network Load Balancer operates at Layer 4, forwarding TCP connections without inspecting or terminating them, so the proprietary binary protocol passes through unchanged. It satisfies the minimal-changes constraint and handles millions of requests per second, meeting the high-throughput requirement that an Application Load Balancer could not.

Why this answer

Network Load Balancer (NLB) is designed for TCP traffic at high throughput with minimal latency, making it ideal for migrating legacy applications using proprietary binary protocols over TCP. Option B (AWS Global Accelerator) improves application performance by directing traffic over the AWS global network but is not a load balancer. Option C (Application Load Balancer) operates at Layer 7 and is best for HTTP/HTTPS traffic, not TCP.

Option D (Classic Load Balancer) is a legacy option that lacks the performance and features of NLB.

10
MCQhard

A company is modernizing a legacy monolithic application by moving it to a microservices architecture on AWS. The application currently uses a relational database with complex joins and stored procedures. The company wants to decouple the database and improve scalability. They plan to use Amazon Aurora and need to minimize the risk of data inconsistencies during the transition. Which strategy should they use to gradually migrate the database while ensuring data consistency?

A.Use AWS Schema Conversion Tool (SCT) to split the monolithic database into microservice databases.
B.Use Amazon Aurora Global Database to replicate data across microservice databases.
C.Use AWS Glue to extract, transform, and load data from the monolithic database into microservice databases.
D.Use the strangler fig pattern with AWS Database Migration Service (DMS) to replicate data between the monolithic database and new microservice databases.
AnswerD

The strangler fig pattern involves gradually replacing parts of the monolith with microservices. AWS DMS can replicate data from the monolithic database to new microservice-specific databases, ensuring consistency during the transition. This allows incremental migration, reducing risk. DMS supports ongoing replication, so both systems can operate in parallel until the monolith is fully replaced.

Why this answer

The strangler fig pattern, combined with AWS DMS for continuous replication, allows gradual migration from a monolith to microservices. DMS replicates data changes in near real-time, ensuring consistency between the old and new databases. This approach minimizes risk and allows rollback if needed.

Other options either do not support continuous replication or are not designed for database decomposition.

Exam trap

The trap here is assuming that AWS SCT can split a monolithic database into microservices, but it only converts schemas between engines, not decomposes databases.

11
Multi-Selecthard

A company is migrating a large number of on-premises VMs to AWS. They need to assess the current environment and track migration progress. Which THREE AWS services should be used together?

Select 3 answers
A.AWS Server Migration Service (SMS)
B.AWS Application Migration Service (MGN)
C.AWS Migration Hub
D.AWS Database Migration Service (DMS)
E.AWS Application Discovery Service
AnswersB, C, E

AWS Application Migration Service replicates source servers block-level into AWS and launches them as EC2 instances, satisfying the migration-execution requirement. It also feeds replication status into Migration Hub, letting the company track progress across the VM fleet.

Why this answer

AWS Application Discovery Service (E) is correct because it performs the assessment phase by collecting on-premises server inventory, configuration, and utilization data (via the Discovery Agent or agentless VMware collector) to build the baseline needed for migration planning. AWS Application Migration Service (B) is correct because it is the recommended lift-and-shift service that replicates on-premises VMs (block-level replication using the AWS Replication Agent) and launches them on AWS as EC2 instances, handling the actual migration of the large VM fleet. AWS Migration Hub (C) is correct because it provides a single console to track migration status and progress across services such as MGN and DMS, giving the centralized progress-tracking capability the company requires.

AWS Server Migration Service (A) is not appropriate because it is a legacy service being deprecated in favor of MGN for VM migrations. AWS Database Migration Service (D) is not appropriate because it targets database migrations specifically, not the general VM migration and assessment scenario described.

12
MCQhard

During an on-premises to AWS migration using AWS MGN (Application Migration Service), the replication is stuck at 99% for the last few GB. The source server is a Linux database server with a large InnoDB redo log. What is the most likely cause?

A.High disk I/O on the source server
B.The source server needs reboot after MGN agent installation
C.Insufficient network bandwidth between source and AWS
D.Continuous writes to the database redo logs preventing final sync
AnswerD

Continuous InnoDB redo log writes mean the source volume never reaches a quiescent state, so MGN's final sync cannot converge — each pass replicates new blocks faster than they drain. The 99% stall reflects this ongoing delta, not a network or staging-area fault. Quiescing the database or stopping writes lets the final cutover complete.

Why this answer

AWS MGN uses changed block tracking (CBT) to replicate changed blocks. Large InnoDB redo logs are continuously written, causing constant changes and preventing final sync. Option A (High disk I/O) can slow replication but would not cause a stall at exactly 99%.

Option B (source server reboot) is not required after agent installation and would reset replication, not stall at 99%. Option C (insufficient network bandwidth) would affect all stages, not just final sync. Therefore, continuous writes to the redo logs (Option D) is the most likely cause.

13
MCQmedium

A company is moving a legacy application that uses a shared file system to AWS. The application requires POSIX-compliant file storage that can be accessed by multiple EC2 instances simultaneously. Which AWS storage service should they use?

A.Amazon FSx for Windows File Server
B.Amazon EFS
C.Amazon EBS with Multi-Attach
D.Amazon S3
AnswerB

Amazon EFS provides a POSIX-compliant, shared NFSv4 file system that multiple EC2 instances can mount concurrently across Availability Zones, satisfying the simultaneous multi-instance access requirement. Unlike EBS, which attaches to a single instance, EFS is purpose-built for shared file workloads, making it the appropriate fit for this legacy application.

Why this answer

(Amazon EFS) is correct because it provides a scalable, POSIX-compliant NFS file system that can be accessed by multiple EC2 instances simultaneously. Option A (Amazon FSx for Windows File Server) uses SMB protocol and is not POSIX-compliant. Option C (Amazon EBS with Multi-Attach) only supports a limited number of instances and has specific constraints, and it is not a fully managed shared file system.

Option D (Amazon S3) is object storage and does not provide POSIX compliance.

14
MCQeasy

A company is planning to migrate its on-premises Oracle database to Amazon RDS for Oracle. The database is 2 TB in size and the company has a high-speed network connection to AWS. Which AWS service should the company use to migrate the database with minimal downtime?

A.Amazon S3 Transfer Acceleration
B.AWS Database Migration Service (DMS)
C.AWS Snowball Edge
D.AWS Schema Conversion Tool (SCT)
AnswerB

DMS performs continuous replication from the source Oracle database to RDS for Oracle, keeping the target synchronised until cutover. This satisfies the minimal-downtime constraint, since only a brief final switchover is needed rather than a full offline export and import of the 2 TB dataset.

Why this answer

AWS DMS supports Oracle to RDS for Oracle migration with ongoing replication for minimal downtime. Option A is incorrect because S3 Transfer Acceleration is used for accelerating uploads to S3, not for database migration. Option C is incorrect because Snowball Edge is for offline data transfer and not suitable for databases with minimal downtime.

Option D is incorrect because AWS Schema Conversion Tool (SCT) is used for schema conversion, not data migration.

15
MCQeasy

A company is modernizing a monolithic application into microservices on Amazon ECS. They want to decouple services and improve resilience. Which AWS service should they use for asynchronous communication between microservices?

A.Amazon SQS
B.Amazon Kinesis Data Streams
C.Amazon API Gateway
D.Amazon SNS
AnswerA

Amazon SQS provides fully managed, durable queues that decouple producers from consumers, letting microservices communicate asynchronously without waiting on each other. This directly satisfies the resilience requirement: if a consumer fails or scales slowly, messages persist in the queue rather than being lost, absorbing traffic spikes.

Why this answer

Amazon SQS provides a fully managed message queue for asynchronous communication, decoupling services. Option B (Amazon Kinesis Data Streams) is for streaming data. Option C (Amazon API Gateway) is for synchronous REST APIs.

Option D (Amazon SNS) is pub/sub, not point-to-point queue.

16
MCQmedium

A company is migrating a batch processing workload to AWS. The workload runs on a schedule and processes large files stored on a network file system. The company wants to use a serverless architecture to reduce costs. Which combination of AWS services should the company use?

A.AWS Step Functions, Amazon EMR, and Amazon EFS.
B.Amazon CloudWatch Events, AWS Lambda, and Amazon Kinesis Data Firehose.
C.AWS Step Functions, AWS Lambda, and Amazon S3.
D.Amazon CloudWatch Events, Amazon EC2, and Amazon EBS.
AnswerC

Step Functions orchestrates the scheduled workflow, Lambda runs the processing logic serverlessly, and Amazon S3 stores the large input and output files. This combination removes server management and scales automatically, meeting the serverless and cost-reduction constraints.

Why this answer

AWS Step Functions can orchestrate the workflow, AWS Lambda can process files in a serverless manner, and Amazon S3 can store the large files. Option A is wrong because Amazon EMR is not a serverless service and EFS is a network file system, not ideal for serverless batch processing. Option B is wrong because Amazon Kinesis Data Firehose is designed for streaming data, not batch processing of large files.

Option D is wrong because Amazon EC2 and EBS are not serverless.

17
MCQmedium

A company wants to migrate its on-premises Active Directory to AWS Managed Microsoft AD to support Windows-based workloads on AWS. The company has a complex Active Directory structure with multiple domains, group policies, and trusts with external directories. Which migration approach should the company use?

A.Replace Active Directory with AWS Identity and Access Management (IAM) for all authentication
B.Establish a forest trust between the on-premises AD and AWS Managed Microsoft AD, then gradually move resources to AWS
C.Rebuild the entire Active Directory structure from scratch in AWS Managed Microsoft AD
D.Use AD Connector to proxy authentication requests from AWS to the on-premises AD
AnswerB

Correct. A trust allows seamless coexistence and incremental migration.

Why this answer

Setting up a trust between the on-premises AD and AWS Managed Microsoft AD allows gradual migration of resources. This maintains existing authentication and group policies during the transition. Replacing AD with IAM is not suitable for Windows workloads.

Replicating the entire AD structure via AD Connector is not possible. A full rebuild is complex and risky.

18
MCQhard

A company is migrating a data warehouse from on-premises to Amazon Redshift. The current workload runs complex queries that join large tables. The company wants to optimize query performance after migration. Which design should the company implement?

A.Use distribution style AUTO and let Redshift decide
B.Use distribution style EVEN on all tables
C.Use distribution style ALL on all large tables
D.Use distribution style KEY on the join columns of large tables
AnswerD

KEY distribution co-locates matching join-column values on the same slice, so large-table joins execute locally without network redistribution. This directly targets the stem's complex joins across large tables, the dominant cost in Redshift query performance.

Why this answer

Distribution style KEY on join columns ensures data is co-located, minimizing data movement. Option A (AUTO) may not use the optimal distribution strategy. Option B (EVEN) distributes rows evenly, which can cause significant data movement across nodes.

Option C (ALL) is not suitable for large tables because it duplicates the entire table on every node, leading to high storage and performance issues.

19
Multi-Selecthard

A healthcare company is migrating a legacy patient-records application to AWS. The application runs on two on-premises servers behind a hardware load balancer and uses a shared file system for documents. The company needs a migration plan that provides high availability across two Availability Zones, minimizes changes to the application, and keeps the document store accessible from both servers with POSIX permissions. (Choose two.)

Select 2 answers
A.Attach an Amazon EBS Multi-Attach io2 volume to both EC2 instances and format it with a clustered file system that the application already supports.
B.Replace the shared file system with an Amazon S3 bucket and rewrite the application to use the AWS SDK for Java to read and write documents.
C.Deploy the application servers on Amazon EC2 instances in two Availability Zones behind an Application Load Balancer, and use an Auto Scaling group to maintain capacity.
D.Use AWS Storage Gateway file gateway to expose an SMB share to the EC2 instances in both Availability Zones.
E.Mount an Amazon EFS file system to both EC2 instances, and configure the mount targets in each Availability Zone used by the application.
AnswersC, E

Running EC2 instances across two Availability Zones behind an Application Load Balancer removes the single hardware load balancer and provides high availability. An Auto Scaling group replaces failed instances automatically, which minimizes operational changes while satisfying the multi-AZ requirement for the compute tier.

Why this answer

High availability for the compute tier is achieved by placing EC2 instances in two Availability Zones behind an Application Load Balancer with an Auto Scaling group. For the shared document store, Amazon EFS provides POSIX-compliant shared access across Availability Zones through mount targets, so the application keeps its existing file-based access pattern with minimal changes.

Exam trap

The trap here is treating Amazon EBS Multi-Attach as a multi-AZ shared storage solution, when it is limited to a single Availability Zone and requires cluster-aware file systems.

20
MCQhard

A company is migrating a legacy on-premises application to AWS. The application runs on a physical server and uses a locally attached tape library for nightly backups. The company wants to eliminate tape management and store backups in Amazon S3. The backup software supports the iSCSI protocol. Which solution should a solutions architect recommend?

A.Use AWS DataSync to replicate the backup server's local disk to Amazon S3.
B.Deploy an AWS Storage Gateway tape gateway and configure the backup software to use the virtual tape library.
C.Deploy an AWS Storage Gateway file gateway and mount it as an NFS share on the backup server.
D.Deploy an AWS Storage Gateway volume gateway in stored mode and present it as an iSCSI target to the backup server.
AnswerB

Tape gateway presents a virtual tape library (VTL) over iSCSI to existing backup software. It stores virtual tapes in Amazon S3 and can archive them to Amazon S3 Glacier or Deep Archive. This eliminates physical tape management while preserving the backup workflow, matching the requirement exactly.

Why this answer

AWS Storage Gateway tape gateway provides a virtual tape library that integrates with existing backup software over iSCSI. Virtual tapes are stored in Amazon S3 and can be archived to Amazon S3 Glacier or Deep Archive, eliminating physical tape handling while preserving the backup application's workflow. Other gateway types or DataSync do not provide a tape interface.

Exam trap

The trap here is assuming that any Storage Gateway mode can replace tape, when only tape gateway presents a virtual tape library to backup software.

21
MCQmedium

A retail company is migrating its on-premises data center to AWS. They have many applications with complex interdependencies. The company wants to group servers into migration waves based on network dependencies to minimize disruption. Which AWS tool should they use to discover these dependencies?

A.AWS Application Discovery Service
B.AWS Trusted Advisor
C.AWS Migration Hub
D.AWS Systems Manager
AnswerA

AWS Application Discovery Service collects data about on-premises servers, including network dependencies and process connections. It provides a dependency map that helps group servers into migration waves. This directly addresses the need to understand interdependencies and plan waves, making it the correct tool for this scenario.

Why this answer

AWS Application Discovery Service is the tool designed to discover on-premises servers and their network dependencies. It collects data that can be used to group servers into migration waves, ensuring that interdependent applications are migrated together. This minimizes disruption and aligns with the company's goal.

Exam trap

The trap here is confusing AWS Migration Hub with Application Discovery Service; Migration Hub tracks migrations, but Discovery Service does the actual discovery of dependencies.

22
MCQeasy

An organization is modernizing a legacy application by breaking it into microservices on AWS. The application processes customer orders and sends notifications. The team wants to decouple the order processing from the notification service to improve scalability. Which AWS service should they use to asynchronously pass messages between the services?

A.Amazon Kinesis Data Streams
B.Amazon EventBridge
C.Amazon Simple Notification Service (Amazon SNS)
D.Amazon Simple Queue Service (Amazon SQS)
AnswerD

Amazon SQS provides a fully managed queue that decouples producers from consumers, letting the order service enqueue messages while the notification service polls and processes them independently. This asynchronous, pull-based model satisfies the requirement to decouple the services and improve scalability.

Why this answer

Amazon SQS is a fully managed message queue service that enables decoupling of application components. SNS is pub/sub; EventBridge is event bus; Kinesis is for real-time streaming. For simple point-to-point async messaging, SQS is the best fit.

23
MCQeasy

A company is migrating a monolithic application to AWS and wants to adopt a microservices architecture. The application currently runs on a single server and uses a shared MySQL database. Which AWS service can help the company decouple the microservices and enable asynchronous communication?

A.Amazon API Gateway
B.AWS Step Functions
C.Elastic Load Balancing
D.Amazon Simple Queue Service (SQS)
AnswerD

Amazon SQS provides fully managed message queues that decouple microservices by buffering messages, so producers and consumers operate independently without waiting on each other. This directly satisfies the asynchronous communication requirement, unlike synchronous request-response services. It also removes the shared-database coupling by letting services exchange events through durable queues rather than direct calls.

Why this answer

Amazon SQS is a fully managed message queuing service that enables asynchronous communication and decoupling between microservices. By using SQS, the monolithic application can be broken into independent services that communicate via queues, improving scalability and resilience. SQS is specifically designed for decoupling and asynchronous messaging, making it the correct choice.

Exam trap

The trap is selecting API Gateway or Step Functions because they are also used in microservices architectures, but the question specifically asks for asynchronous communication and decoupling, which is the core purpose of SQS.

How to eliminate wrong answers

Option A is wrong because Amazon API Gateway is used for creating, publishing, and managing APIs, providing synchronous request/response communication, not asynchronous decoupling. Option B is wrong because AWS Step Functions is a serverless orchestration service for coordinating multiple AWS services into workflows, but it is not primarily a message queue for decoupling microservices; it is more for stateful workflows. Option C is wrong because Elastic Load Balancing distributes incoming traffic across multiple targets, providing synchronous load balancing, not asynchronous messaging.

24
MCQeasy

A company is migrating a legacy monolithic application to AWS. The application currently runs on a single Windows Server with IIS and SQL Server. The company wants to adopt a microservices architecture on AWS using containers. The development team has containerized the application into several Docker containers. The company needs a solution that minimizes operational overhead for managing the container orchestration and scaling, and also integrates with AWS services like IAM, CloudWatch, and VPC. Which AWS service should the company use to run the containers?

A.Amazon ECS with the Fargate launch type.
B.Amazon EKS with managed node groups.
C.AWS Elastic Beanstalk with a Docker platform.
D.Amazon EC2 instances with Docker installed, managed by an Auto Scaling group.
AnswerA

Fargate's serverless compute model removes EC2 instance patching and cluster capacity management, satisfying the minimal-operational-overhead constraint. It runs containers inside the VPC with native IAM task roles and CloudWatch logging, integrating directly with the AWS services the stem requires.

Why this answer

Amazon ECS with the Fargate launch type is a serverless compute engine for containers that eliminates the need to provision or manage EC2 instances, directly minimizing operational overhead. It natively integrates with IAM task roles, CloudWatch Logs/metrics, and VPC networking (awsvpc mode), matching all stated requirements. This makes it the best fit for a team that wants to run Docker containers without managing orchestration infrastructure.

Exam trap

SAP-C02 often tests the misconception that EKS is always the right answer for containers, when the requirement to minimize operational overhead points to Fargate.

How to eliminate wrong answers

Option B is wrong because EKS with managed node groups still requires managing worker nodes (patching, scaling, AMI updates), adding operational overhead compared to Fargate. Option C is wrong because Elastic Beanstalk with Docker is designed for single-container or simple multi-container deployments and does not provide the microservices orchestration, service discovery, and task-level IAM integration expected for a containerized microservices architecture. Option D is wrong because running Docker on EC2 with an Auto Scaling group requires the company to manage the instances, Docker daemon, scheduling, and scaling logic themselves, which maximizes operational overhead rather than minimizing it.

25
Multi-Selecthard

A company is modernizing an on-premises Java application by moving it to containers on Amazon EKS. The application reads configuration from environment-specific property files and stores user-uploaded documents on a locally mounted NFS share. The company wants the containerized application to be portable across clusters and environments, and it must not require rebuilding the container image per environment. Which two changes should a solutions architect make to meet these requirements? (Choose two.)

Select 2 answers
A.Move the uploaded documents into the container image and write new uploads to the pod's ephemeral writable layer
B.Bake the environment-specific property files into the container image during the CI build for each environment
C.Store the environment-specific configuration in AWS Systems Manager Parameter Store or AWS Secrets Manager and inject the values into the pods as environment variables or mounted files at runtime
D.Replace the NFS share with an Amazon EBS volume attached to each node and expose it to the pods with a hostPath volume
E.Replace the locally mounted NFS share with Amazon EFS and mount it into the pods using the Amazon EFS CSI driver with access points
AnswersC, E

Externalizing configuration into Parameter Store or Secrets Manager removes environment-specific values from the image, so the same image runs in every environment. Values can be injected as environment variables or mounted as files using the AWS Secrets and Configuration Provider for the Secrets Store CSI driver. This satisfies the requirement that the image must not be rebuilt per environment.

Why this answer

Portability across clusters and environments requires that environment-specific values and shared state live outside the image. Externalizing configuration into Parameter Store or Secrets Manager and injecting it at runtime keeps a single image valid everywhere, while Amazon EFS with the EFS CSI driver reproduces the shared NFS semantics the application expects. Baking configuration into images or using node-local storage both break portability and shared access.

Exam trap

The trap here is assuming that because the application already uses NFS, any node-local or image-embedded storage will behave the same way once containerized.

26
MCQmedium

A company is migrating a critical application to AWS and needs to ensure that the migration has minimal downtime. The application uses a SQL Server database. The company wants to use AWS Database Migration Service (DMS) for the migration. What should the company do to minimize downtime during the database migration?

A.Use DMS with validation enabled and then truncate the target before cutover.
B.Use DMS with ongoing replication (change data capture) to keep the target database synchronized, then perform a brief cutover.
C.Use DMS with full load only and schedule the migration during a maintenance window.
D.Perform a full load migration using DMS and then manually copy any remaining data.
AnswerB

DMS change data capture continuously replicates ongoing changes from SQL Server to the target after the initial full load, keeping both synchronised. The cutover then needs only a brief application pause, satisfying the minimal-downtime requirement.

Why this answer

Using change data capture (CDC) with AWS DMS enables ongoing replication of changes from the source SQL Server database to the target. This keeps the target nearly synchronized, so during cutover only a brief pause is needed to apply any final changes, minimizing downtime. Option A is incorrect because enabling validation does not reduce downtime; it only verifies data integrity after migration, and truncating the target before cutover would remove all data, causing potential data loss and additional downtime.

Option C is incorrect because a full load only captures a snapshot of the database at a point in time; any changes after that require a separate sync, leading to longer downtime. Option D is incorrect because manually copying remaining data after a full load migration defeats the purpose of using DMS and introduces significant downtime and risk of inconsistency.

27
MCQhard

A company is migrating a large-scale .NET application to AWS. The application uses Windows authentication and requires Active Directory integration. The company wants to reduce operational overhead. Which migration approach should they use?

A.Rehost on EC2 with on-premises AD via VPN
B.Rehost on EC2 with AWS Managed Microsoft AD
C.Replatform to use Amazon Cognito for authentication
D.Replatform to AWS Elastic Beanstalk with Amazon Lightsail
AnswerB

AWS Managed Microsoft AD provides the domain services and Kerberos-based Windows authentication the .NET application requires, while AWS handles patching, replication and domain controller availability. Rehosting on EC2 preserves the existing application without code changes, and the managed directory removes the operational overhead of self-managed AD.

Why this answer

(Rehost on EC2 with AWS Managed Microsoft AD) is correct because it provides Active Directory integration without the need to manage domain controllers, reducing operational overhead. Option A (Rehost on EC2 with on-premises AD via VPN) still requires managing on-premises resources and doesn't fully reduce overhead. Option C (Replatform to use Amazon Cognito) is aimed at web identity federation, not traditional Windows AD authentication.

Option D (Replatform to AWS Elastic Beanstalk with Amazon Lightsail) does not support Windows authentication or AD integration effectively.

28
Multi-Selectmedium

A company is migrating a legacy three-tier web application to AWS. The application consists of a web tier, an application tier, and a database tier. The company wants to minimize downtime and ensure data consistency during the migration. The database is a Microsoft SQL Server 2016 running on-premises. The company plans to use AWS Database Migration Service (DMS) for the database migration. Which two actions should be taken to meet these requirements? (Choose two.)

Select 2 answers
A.Create an AWS DMS task with a full load only, and then manually apply any changes made during the migration.
B.Configure AWS DMS with a full load plus ongoing replication (CDC) task to keep the target database in sync until cutover.
C.Perform a test migration to a staging environment to validate data consistency and application functionality before the production cutover.
D.Enable multi-AZ deployment on the target Amazon RDS for SQL Server instance to ensure high availability during migration.
E.Use AWS Schema Conversion Tool (SCT) to convert the SQL Server schema to Amazon Aurora MySQL before migration.
AnswersB, C

Using full load plus ongoing replication (CDC) allows DMS to perform an initial data load and then continuously replicate changes from the source to the target. This minimizes downtime because the target remains synchronized until the cutover, at which point the application can be switched to the target with minimal interruption. It ensures data consistency by capturing all changes.

Why this answer

Configuring DMS with full load plus ongoing replication keeps the target synchronized and minimizes downtime during cutover. Performing a test migration validates the process and ensures data consistency and application compatibility. Together, these actions address the requirements for minimal downtime and data consistency.

Exam trap

The trap here is overlooking the need for ongoing replication (CDC) and assuming a one-time full load is sufficient, which would cause data loss for changes made during migration.

29
MCQhard

A company is migrating a legacy .NET application to AWS. The application uses Windows authentication and connects to an on-premises SQL Server database. The company wants to minimize code changes. Which migration strategy is most appropriate?

A.Replatform the application to use Amazon Aurora PostgreSQL with AWS DMS.
B.Refactor the application into microservices using AWS Lambda and Amazon DynamoDB.
C.Rehost the application on EC2 Windows instances and use Amazon RDS for SQL Server.
D.Re-platform the application to run on Amazon Linux and use Amazon RDS for MySQL.
AnswerC

Rehosting on EC2 Windows preserves the existing Windows authentication mechanism without code changes, satisfying the minimise-changes constraint. Amazon RDS for SQL Server supports Windows authentication through AWS Managed Microsoft AD, allowing the application to connect using integrated security rather than SQL logins, so connection strings and authentication code remain largely unchanged.

Why this answer

Rehosting the application on EC2 Windows instances and using Amazon RDS for SQL Server preserves Windows authentication and the existing SQL Server engine, minimizing code changes. This is the classic 'lift and shift' approach that keeps the application's dependencies intact.

Exam trap

SAP-C02 often tests migration strategy selection, and the trap is choosing replatform/refactor options that sound modern but violate the 'minimize code changes' constraint.

How to eliminate wrong answers

Option A is wrong because replatforming to Aurora PostgreSQL with AWS DMS requires schema and code changes to move off SQL Server and Windows authentication. Option B is wrong because refactoring into Lambda and DynamoDB is a major rewrite that abandons Windows authentication and the relational model. Option D is wrong because moving to Amazon Linux and RDS for MySQL changes the OS and database engine, breaking Windows authentication and requiring code changes.

30
Multi-Selecthard

A company is migrating a legacy three-tier application from its on-premises data center to AWS. The application consists of a web tier, an application tier, and a database tier. The company wants to improve scalability and reduce operational overhead. The database tier uses Microsoft SQL Server and cannot be modified. The company wants to migrate with minimal changes. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Migrate the database tier to Amazon RDS for SQL Server with a Multi-AZ deployment.
B.Migrate the web and application tiers to Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer.
C.Migrate the web and application tiers to AWS Lambda functions with Amazon API Gateway.
D.Migrate the database tier to Amazon RDS for SQL Server with a read replica in a single Availability Zone.
E.Migrate the database tier to Amazon DynamoDB with on-demand capacity mode.
AnswersA, B

Amazon RDS for SQL Server is a managed service that supports Multi-AZ deployments for high availability and automatic failover. It reduces operational overhead by handling backups, patching, and replication. Since the database cannot be modified, using RDS for SQL Server with Multi-AZ provides a compatible, scalable, and resilient database tier with minimal changes.

Why this answer

Migrating the web and application tiers to EC2 Auto Scaling groups behind an Application Load Balancer improves scalability and reduces operational overhead. Migrating the database to Amazon RDS for SQL Server with Multi-AZ provides a managed, highly available database service that supports the existing SQL Server schema with minimal changes. Together, these actions meet the requirements without re-architecting the application.

Exam trap

The trap here is assuming that any managed database service can replace SQL Server, but NoSQL services like DynamoDB require a complete data model redesign, which is not feasible when the database cannot be modified.

31
MCQhard

A media company is migrating a large on-premises video rendering workload to AWS. The workload runs on 100 physical servers and is highly parallelizable. The company wants to minimize infrastructure management and only pay for the compute capacity used. They also need to handle sudden spikes in demand. Which AWS service should they use?

A.AWS Lambda
B.AWS Batch
C.Amazon ECS with Fargate
D.Amazon EC2 with Spot Instances
AnswerB

AWS Batch is a fully managed batch computing service that dynamically provisions compute resources based on job volume and requirements. It handles job scheduling, dependency management, and scaling, allowing the company to focus on rendering jobs. It integrates with Spot Instances for cost savings and can scale to handle spikes. This minimizes infrastructure management and aligns with pay-for-use pricing.

Why this answer

AWS Batch is designed for batch computing workloads, providing managed job scheduling and dynamic scaling. It supports both EC2 and Fargate compute environments and can leverage Spot Instances for cost savings. This allows the media company to run parallel rendering jobs without managing infrastructure, while paying only for the resources used, and it scales automatically to handle spikes in demand.

Exam trap

The trap here is assuming that any serverless compute service like Lambda or Fargate is suitable for batch workloads; AWS Batch is purpose-built for batch processing with job queues and dependencies.

32
MCQhard

A company is migrating a high-traffic web application to AWS. The application currently runs on physical servers in a colocation facility and uses a custom session state mechanism stored in a local Redis instance on each server. The company wants to modernize the application to be highly available and scalable on AWS with minimal code changes. Which solution meets these requirements?

A.Deploy the application on Amazon ECS with Fargate, and use Amazon EFS to store session files that are shared across all tasks.
B.Deploy the application on Amazon EC2 instances in an Auto Scaling group, and use an Application Load Balancer with sticky sessions enabled to keep users on the same instance.
C.Deploy the application on Amazon EC2 instances behind an Application Load Balancer, and migrate session state to Amazon ElastiCache for Redis with cluster mode enabled.
D.Migrate the application to AWS Lambda with Amazon API Gateway, and store session data in Amazon DynamoDB using a new session management library.
AnswerC

Amazon ElastiCache for Redis provides a fully managed, highly available Redis service that can be configured with cluster mode for scalability. By moving session state from local instances to ElastiCache, the application becomes stateless and can scale horizontally behind an Application Load Balancer. This requires minimal code changes because the application already uses Redis APIs, just pointing to a new endpoint.

Why this answer

Migrating session state to Amazon ElastiCache for Redis preserves the existing Redis API usage, requiring only a configuration change to point to the new endpoint. ElastiCache provides high availability with automatic failover and scalability through cluster mode. Combined with an Application Load Balancer and EC2 Auto Scaling, the application becomes stateless, highly available, and scalable with minimal code modifications.

Exam trap

The trap here is assuming that sticky sessions alone can provide high availability and scalability, but they actually tie users to specific instances, preventing seamless failover and even load distribution.

33
MCQeasy

A company is migrating a legacy on-premises application to AWS. The application currently runs on a Windows Server with a SQL Server database. The company wants to minimize changes to the application code. Which migration strategy should the company use?

A.Rehost (lift-and-shift)
B.Refactor / re-architect
C.Replatform (lift-and-resize)
D.Rebuild
AnswerA

Rehost moves the Windows Server and SQL Server workloads to Amazon EC2 essentially unchanged, satisfying the requirement to minimise application code changes. Unlike replatforming or refactoring, no engine swap or rewrite occurs, so the legacy application continues running on the same OS and database platform.

Why this answer

Rehosting (lift-and-shift) involves moving the application as-is to AWS, minimizing code changes. Replatforming (lift-and-resize) may involve some changes, but rehosting requires the least modification. Refactoring and rebuilding involve significant changes.

34
MCQhard

A company is migrating a large-scale Hadoop cluster to Amazon EMR. The migration plan includes moving data from HDFS to Amazon S3. The company wants to minimize costs and ensure data durability. Which approach should the company use?

A.Set up a VPN connection and use rsync to copy data to S3.
B.Use Apache DistCp to copy data from HDFS to S3.
C.Use AWS Snowball Edge to physically transfer data from the cluster.
D.Use AWS Database Migration Service (DMS) to migrate the data to S3.
AnswerB

Apache DistCp is purpose-built for parallel, distributed copying between HDFS and Amazon S3, preserving data integrity across the large-scale Hadoop dataset. S3 provides eleven nines of durability with lower storage cost than HDFS on persistent EMR clusters, satisfying both the cost and durability constraints.

Why this answer

B is correct because DistCp is designed for efficient HDFS-to-S3 transfers, and S3's 99.999999999% durability meets requirements. A is wrong because VPN and rsync are not optimized for large-scale data transfer to S3. C is wrong because Snowball Edge adds latency and is not necessary for data already in the cluster.

D is wrong because AWS DMS is for databases, not file systems.

35
MCQhard

A company is migrating a legacy on-premises application to AWS. The application uses a proprietary database that runs on a single Windows server. The company wants to minimize downtime and avoid re-architecting the database. Which migration strategy should the solutions architect recommend?

A.Retire the application and replace it with a SaaS solution
B.Rehost using AWS Application Migration Service (CloudEndure)
C.Re-architect the application to use Amazon DynamoDB
D.Replatform by migrating the database to Amazon RDS for SQL Server
AnswerB

AWS Application Migration Service replicates the Windows server block-level to AWS, preserving the proprietary database unchanged, so no re-architecting occurs. Continuous replication keeps cutover downtime to minutes, satisfying both the minimise-downtime and avoid-re-architecting constraints. Replatforming or refactoring would alter the database engine, which the stem forbids.

Why this answer

Rehosting (lift-and-shift) with AWS Application Migration Service (formerly CloudEndure) moves the Windows server and its proprietary database to EC2 with minimal changes and minimal downtime, preserving the existing database engine. This aligns with the goal of avoiding re-architecture while meeting the migration timeline.

Exam trap

The trap is confusing 'rehost' with 'replatform' — candidates may pick RDS because it sounds like a managed improvement, but the question emphasizes minimizing downtime and avoiding re-architecture, which points to a lift-and-shift rehost.

How to eliminate wrong answers

Option A is wrong because retiring and replacing with SaaS requires re-architecting and data migration, which contradicts the requirement to avoid re-architecting and minimize downtime. Option C is wrong because re-architecting to DynamoDB is a major redesign that changes the database engine and application code, which is explicitly not desired. Option D is wrong because replatforming to Amazon RDS for SQL Server changes the database platform and may not support the proprietary database, and it requires schema/data migration, adding downtime and risk.

36
MCQmedium

A company is migrating a legacy on-premises application to AWS. The application uses a shared file system that must be accessible from multiple Amazon EC2 instances across two Availability Zones. The file system must provide high throughput and support POSIX permissions. Which AWS service should the company use?

A.Amazon Elastic File System (Amazon EFS)
B.Amazon Elastic Block Store (Amazon EBS) Multi-Attach
C.Amazon FSx for Windows File Server
D.Amazon S3 with mounted file system using s3fs
AnswerA

Amazon EFS is a fully managed, scalable, elastic file system for Linux-based workloads. It supports POSIX permissions and can be mounted on multiple EC2 instances across multiple Availability Zones within a VPC. It provides high throughput and is designed for shared access, making it ideal for this scenario.

Why this answer

Amazon EFS is a shared, POSIX-compliant file system that can be mounted across multiple EC2 instances in multiple Availability Zones. It provides high throughput and is fully managed. FSx for Windows is for Windows workloads, S3 is object storage, and EBS Multi-Attach is limited to a single Availability Zone and is block storage.

Exam trap

The trap here is assuming that EBS Multi-Attach can provide shared file storage across Availability Zones, when it is limited to a single Availability Zone and does not offer a file system interface.

37
MCQhard

A company is migrating a mission-critical application to AWS. The application requires a fixed IP address for whitelisting by external partners. The company plans to use an Application Load Balancer (ALB) to distribute traffic. However, ALB does not support static IP addresses. How can the company meet the requirement for static IP addresses while using the ALB?

A.Replace the ALB with a Network Load Balancer (NLB) that has Elastic IP addresses
B.Use AWS Global Accelerator with the ALB as an endpoint
C.Use Amazon Route 53 with a failover routing policy
D.Assign Elastic IP addresses to the ALB
AnswerB

AWS Global Accelerator provisions two static anycast IPv4 addresses that external partners can whitelist, then forwards traffic to the ALB endpoint without exposing its dynamic node IPs. This satisfies the fixed-IP constraint while retaining ALB's layer 7 routing, and unlike CloudFront it preserves the client's source IP for partner-side filtering.

Why this answer

Using AWS Global Accelerator provides static anycast IP addresses and directs traffic to the ALB, meeting the requirement for fixed IP whitelisting. Option A (replacing with NLB) would avoid the ALB entirely and may not be suitable for application-level traffic. Option C (Route 53 failover) does not provide static IP addresses for whitelisting.

Option D (assigning Elastic IP to ALB) is not supported.

38
MCQhard

A company is modernizing a monolithic Java application by decomposing it into microservices. The application currently uses a single relational database. The company wants to migrate to a microservices architecture on AWS with minimal operational overhead. The microservices must be independently deployable and scalable, and each service should own its data. Which approach should a solutions architect recommend?

A.Use AWS App2Container to containerize the monolith, deploy it on Amazon ECS, and keep the monolithic database.
B.Decompose the application into microservices using AWS Fargate, and give each microservice its own Amazon DynamoDB table.
C.Refactor the application into AWS Lambda functions, and use a single Amazon Aurora database shared by all functions.
D.Migrate the application to AWS Elastic Beanstalk, and use Amazon RDS with read replicas for scaling.
AnswerB

AWS Fargate provides serverless compute for containers, reducing operational overhead. Decomposing the application into microservices aligns with independent deployability and scalability. Giving each microservice its own DynamoDB table follows the database-per-service pattern, enabling each service to own its data. This combination meets all requirements with minimal management.

Why this answer

Decomposing the monolith into microservices on AWS Fargate reduces operational overhead because Fargate manages the underlying compute. Each microservice having its own DynamoDB table implements the database-per-service pattern, ensuring independent data ownership and scalability. This architecture supports independent deployment and scaling, aligning with microservices best practices.

Exam trap

The trap here is assuming that containerizing a monolith or using serverless functions with a shared database constitutes a microservices architecture, when true microservices require independent data stores and deployment lifecycles.

39
MCQhard

A company is migrating a legacy application to AWS using the rehost (lift-and-shift) strategy. The application uses a proprietary database that is not supported by Amazon RDS. The company wants to automate the migration of multiple servers and minimize downtime. Which AWS service should be used to automate the server migration?

A.AWS CloudFormation to recreate the server configuration.
B.AWS Application Migration Service (AWS MGN).
C.AWS Server Migration Service (SMS).
D.AWS Database Migration Service (AWS DMS) for the database and manual server migration.
AnswerB

AWS Application Migration Service performs block-level replication of source servers into AWS, automating lift-and-shift for multiple machines with continuous replication that minimises cutover downtime. This satisfies both the rehost strategy and the unsupported proprietary database constraint, since the database travels with the server rather than needing RDS compatibility.

Why this answer

AWS Application Migration Service (MGN) automates lift-and-shift with minimal downtime. Option A is wrong because AWS CloudFormation is for infrastructure provisioning, not migration. Option C is wrong because AWS Server Migration Service (SMS) is older and less automated compared to MGN.

Option D is wrong because AWS Database Migration Service (DMS) is for databases, not servers.

40
MCQeasy

A company is migrating a legacy on-premises application to AWS. The application uses a monolithic architecture and a self-managed MySQL database. The company wants to reduce operational overhead and improve scalability with minimal application changes. A solutions architect needs to recommend a migration path for the database. Which AWS service should the solutions architect use?

A.Amazon Aurora MySQL-Compatible Edition
B.Amazon RDS for MySQL
C.Amazon DynamoDB
D.Amazon Redshift
AnswerB

Amazon RDS for MySQL is a managed relational database service that is compatible with MySQL. It handles provisioning, patching, backups, and Multi-AZ replication, reducing operational overhead. Because the application already uses MySQL, migrating to RDS for MySQL requires minimal application changes; often only the connection string needs updating. This aligns with the goal of reducing operational overhead while preserving compatibility and improving scalability.

Why this answer

Amazon RDS for MySQL provides a managed MySQL-compatible database that minimizes operational tasks such as patching, backups, and replication. Because the application already uses MySQL, the migration can be as simple as using AWS Database Migration Service to replicate the data and then updating the application's connection string. This meets the goals of reducing operational overhead and improving scalability without requiring application rewrites.

Other services either use different data models or are optimized for analytics rather than transactions.

Exam trap

The trap here is over-engineering by choosing Amazon Aurora when a simpler managed MySQL service like Amazon RDS for MySQL is sufficient, or mistakenly selecting a NoSQL or data warehouse service.

41
MCQhard

A company is migrating its on-premises data center to AWS. The company has over 200 applications, each with varying dependencies. The migration team wants to use AWS Migration Hub to track the migration progress. Which approach should the team take to ensure successful tracking and minimize manual effort?

A.Use Amazon CloudWatch dashboards to monitor the health of on-premises servers.
B.Use AWS Systems Manager to automate the migration of each application.
C.Use AWS Application Discovery Service to discover dependencies and then use AWS Migration Hub to track the migration of each application.
D.Manually create a spreadsheet of all applications and their dependencies, and update it weekly.
AnswerC

Application Discovery Service agentless and agent-based collection maps server dependencies automatically, feeding that inventory into Migration Hub. This satisfies the minimise-manual-effort constraint across 200 applications, since Migration Hub can then track each application's migration status without hand-built dependency records.

Why this answer

AWS Application Discovery Service automatically discovers on-premises servers and their dependencies, and its data feeds directly into AWS Migration Hub, which tracks migration status across applications. This combination minimizes manual effort and gives accurate dependency mapping for 200+ applications.

Exam trap

SAP-C02 often tests whether candidates choose manual tracking or generic monitoring tools instead of the Application Discovery Service plus Migration Hub pairing that automates dependency discovery and progress tracking.

How to eliminate wrong answers

Option A is wrong because CloudWatch dashboards monitor AWS resources, not on-premises server health or migration progress, and don't feed Migration Hub. Option B is wrong because Systems Manager automates management tasks on AWS/on-premises nodes but does not discover dependencies or track migration status in Migration Hub. Option D is wrong because manually maintaining a spreadsheet is exactly the high-effort, error-prone approach the team wants to avoid and does not integrate with Migration Hub.

42
MCQmedium

A company is migrating a critical application to AWS. The application requires a relational database with high availability and automated failover. The company wants to use a fully managed database service. Which AWS service should the architect choose?

A.Amazon RDS Multi-AZ
B.Amazon ElastiCache
C.Amazon DynamoDB
D.Amazon RDS Single-AZ
AnswerA

Amazon RDS Multi-AZ maintains a synchronous standby replica in a second Availability Zone and automatically promotes it during failure, giving the required high availability and automated failover. RDS is fully managed, handling patching, backups and instance replacement.

Why this answer

Amazon RDS Multi-AZ provides a fully managed relational database with synchronous replication to a standby instance in a different Availability Zone and automatic failover, meeting the high availability and automated failover requirements. It is the correct choice for a relational workload needing managed HA.

Exam trap

SAP-C02 often tests whether candidates confuse Multi-AZ (HA/failover) with read replicas (read scaling) — Multi-AZ is for availability, not performance, and Single-AZ is never the answer when automated failover is required.

How to eliminate wrong answers

Option B is wrong because Amazon ElastiCache is an in-memory caching service (Redis or Memcached), not a relational database, and does not provide durable relational storage. Option C is wrong because Amazon DynamoDB is a NoSQL key-value/document database, not relational, and does not support SQL or relational schemas. Option D is wrong because RDS Single-AZ has no standby and no automated failover — if the AZ fails, the database is unavailable until manual recovery, so it fails the HA requirement.

43
MCQmedium

A company is migrating a legacy application that uses a third-party identity provider (IdP) for authentication. The application currently uses SAML 2.0. The company wants to use AWS IAM Identity Center for centralized access management. What is the best approach to integrate the IdP with AWS?

A.Use AWS Directory Service for Microsoft Active Directory to synchronize with the IdP
B.Create IAM users for each employee and assign groups and permissions
C.Configure IAM Identity Center to use the existing IdP as the identity source via SAML 2.0 federation
D.Use Amazon Cognito user pools with the IdP as a SAML identity provider
AnswerC

IAM Identity Center can consume the existing IdP as its identity source through SAML 2.0 federation, so users authenticate against the third-party IdP while Identity Center handles centralised AWS access assignment. This preserves the current SAML 2.0 investment.

Why this answer

AWS IAM Identity Center supports SAML 2.0 federation with external identity providers (IdPs). This allows centralized access management without duplicating identities. Option A is incorrect because AWS Directory Service for Microsoft AD is for Active Directory synchronization, not generic SAML federation.

Option B is incorrect because creating IAM users for every employee would duplicate identities and increase administrative overhead. Option D is incorrect because Amazon Cognito user pools are designed for customer-facing applications, not for enterprise SSO with existing IdPs.

44
MCQmedium

A company is migrating a high-traffic web application from on-premises to AWS. The application uses a MySQL database and stores session state on the web servers. The company wants to ensure that the application can scale horizontally and that users are not logged out when new web servers are added. Which migration strategy should be used for the session state?

A.Use sticky sessions on the Application Load Balancer to ensure that each user is directed to the same web server.
B.Migrate the session state to Amazon ElastiCache for Redis and configure the application to use it as a session store.
C.Store session state in an Amazon RDS for MySQL database with a multi-AZ deployment.
D.Use Amazon S3 to store session state as objects and have the application retrieve them on each request.
AnswerB

Amazon ElastiCache for Redis provides a highly available, in-memory data store that can be used to externalize session state. By storing sessions in ElastiCache, any web server can access the session data, enabling horizontal scaling without losing user sessions. This is a common pattern for modernizing applications to be stateless and scalable.

Why this answer

Migrating session state to Amazon ElastiCache for Redis is the best strategy because it externalizes session data, allowing any web server to handle requests for any user. This enables horizontal scaling and ensures that user sessions are not lost when new servers are added. Other options either do not scale well or introduce latency and complexity.

Exam trap

The trap here is thinking that sticky sessions solve the scaling issue, but they actually hinder horizontal scaling and do not prevent session loss if a server fails.

45
MCQmedium

A company is migrating a large-scale e-commerce platform from on-premises to AWS. The migration plan includes rehosting the application servers and replatforming the database to Amazon Aurora. The company needs to ensure minimal downtime during the cutover. Which strategy should the company use for the database migration?

A.Use AWS DMS with a full load and ongoing replication to keep the target synchronized
B.Use AWS DMS with a full load only, then cut over
C.Use an application-level dual-write to both databases during the cutover
D.Take a snapshot of the on-premises database and restore it to Amazon Aurora
AnswerA

AWS DMS full load plus ongoing change data capture replicates ongoing transactions continuously, so the Aurora target stays synchronised until cutover. This directly satisfies the minimal-downtime requirement, since the switch happens only after replication lag reaches near zero.

Why this answer

AWS DMS with a full load and ongoing replication (change data capture) keeps the target Aurora database synchronized with the source during the migration. This allows minimal downtime because the cutover only requires stopping writes to the source and letting DMS apply the final changes, then redirecting the application to Aurora. This is the standard strategy for minimal-downtime database migrations.

Exam trap

SAP-C02 often tests the misconception that a full load alone is sufficient for minimal downtime, ignoring the need for ongoing replication to capture changes during the migration.

How to eliminate wrong answers

Option B is wrong because a full load only does not capture changes made during the load, so any writes after the load start would be lost, causing data inconsistency and requiring downtime. Option C is wrong because application-level dual-write is complex, error-prone, and not a recommended AWS migration strategy; it also requires application changes. Option D is wrong because a snapshot and restore causes significant downtime as the snapshot must be taken, transferred, and restored, and any changes after the snapshot are lost.

46
MCQmedium

A company is migrating a legacy on-premises .NET application to AWS. The application uses Windows Authentication and relies on Active Directory. The company wants to minimize code changes. Which solution should the architect recommend?

A.Use AWS Systems Manager to store credentials and inject them at runtime.
B.Migrate the application to Amazon WorkDocs and configure single sign-on.
C.Use Amazon Cognito user pools for authentication.
D.Deploy the application on Amazon EC2 instances joined to an AWS Managed Microsoft AD directory.
AnswerD

Joining EC2 instances to AWS Managed Microsoft AD lets the .NET application continue using Windows Authentication and Kerberos against a managed domain, so no code changes are needed. This satisfies the minimise-code-changes constraint while retaining Active Directory integration.

Why this answer

AWS Managed Microsoft AD is a fully managed Active Directory service in AWS that supports domain join for EC2 instances. By joining the EC2 instances to the directory, the legacy .NET application can continue using Windows Authentication (Kerberos/NTLM) without code changes. This preserves the existing authentication mechanism and minimizes migration effort.

Exam trap

SAP-C02 often tests the misconception that AWS identity services like Cognito or IAM can replace Active Directory for Windows Authentication, but they cannot; the key is recognizing that legacy Windows Authentication requires an actual AD domain, and AWS Managed Microsoft AD is the managed solution for that.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store or Secrets Manager is for storing and retrieving secrets, not for providing Windows Authentication or Active Directory integration; injecting credentials at runtime would require code changes and does not replicate AD-based authentication. Option B is wrong because Amazon WorkDocs is a document collaboration service, not an application hosting platform, and configuring SSO does not provide Windows Authentication for a .NET application. Option C is wrong because Amazon Cognito user pools are for customer identity and access management (CIAM) for web and mobile apps, not for Windows Authentication or Active Directory domain authentication; using Cognito would require significant code changes to integrate with the .NET application.

47
MCQmedium

A migration engineer is using AWS Application Migration Service (MGN) to migrate a Windows server from on-premises. The engineer runs the command above and sees the source server is in the "READY_FOR_TEST" state. What should the engineer do next?

A.Launch a test instance to validate the migration
B.Perform the cutover to the AWS environment
C.Modify the source server's recommended instance type to a smaller size
D.Resume data replication from the source server
AnswerA

From READY_FOR_TEST, MGN has completed initial replication and the staging area holds a bootable snapshot, so the next step is launching a test instance to validate the migrated Windows server before cutover. Testing confirms boot, drivers and applications without affecting the source, satisfying the stem's validation requirement prior to final launch.

Why this answer

When a source server is in the READY_FOR_TEST state in AWS Application Migration Service (MGN), it means the initial replication has completed and the server is ready for a test launch. The next step is to launch a test instance to validate that the migrated server functions correctly in AWS before performing the actual cutover. This test launch does not affect the source server or the cutover process.

Exam trap

SAP-C02 often tests the misconception that READY_FOR_TEST means you should immediately cut over, when the correct next step is to launch a test instance for validation.

How to eliminate wrong answers

Option B is wrong because performing the cutover should only happen after a successful test launch and validation; cutting over without testing risks production issues. Option C is wrong because modifying the recommended instance type is not the immediate next step and should be done based on test performance, not before testing. Option D is wrong because data replication is already complete and ongoing; resuming replication is not applicable when the server is ready for test.

48
MCQmedium

A company is migrating a monolithic e-commerce application to AWS. The application currently runs on a single on-premises server running Windows Server and SQL Server. The company wants to minimize re-architecting effort and time to migrate. Which migration strategy should the company use?

A.Retire the application and replace it with a SaaS solution
B.Refactor the application to use microservices on Amazon ECS
C.Rehost the application on Amazon EC2 Windows instances with SQL Server
D.Replatform the application to use Amazon RDS for SQL Server
AnswerC

Rehosting lifts the Windows Server and SQL Server workload onto Amazon EC2 unchanged, preserving the existing monolith. This requires no code modification or database refactoring, directly satisfying the stated goals of minimal re-architecting effort and fastest migration timeline.

Why this answer

Rehost (lift-and-shift) involves moving the application as-is to AWS, minimizing changes and time. Option A (Retire) is not appropriate because the application is still needed. Option B (Refactor) requires significant re-architecting.

Option D (Replatform) involves some optimization but still requires changes.

49
MCQeasy

A company is migrating an e-commerce website to AWS. The website has a MySQL database. The company wants to automate the migration of the database schema and data. Which AWS service should they use?

A.AWS Glue
B.AWS Database Migration Service (DMS)
C.AWS Data Pipeline
D.AWS Schema Conversion Tool (SCT)
AnswerB

AWS Database Migration Service performs homogeneous MySQL-to-MySQL migrations, automating both schema conversion and ongoing data replication. It satisfies the requirement to automate schema and data movement without manual scripting, using a replication instance that reads from the source and writes to the target while the database stays operational.

Why this answer

(AWS Database Migration Service) is correct because it automates data migration and can convert schema using SCT. Option A (AWS Glue) is for ETL, not database migration. Option C (AWS Data Pipeline) is for data processing.

Option D (AWS Schema Conversion Tool) converts schema but does not migrate data.

50
MCQmedium

A company is using the 7 Rs strategy to migrate a monolithic application to AWS. They want to move the application to the cloud without modifying the code but plan to later refactor parts of it. Which migration strategy should they choose initially?

A.Relocate
B.Refactor
C.Replatform
D.Rehost
AnswerD

Rehosting lifts the application onto AWS infrastructure unchanged, satisfying the no-code-modification constraint. Unlike replatforming, which alters components, or refactoring, which rewrites code, rehosting preserves the monolith as-is. This lets the company migrate quickly, then refactor selected parts later once running in the cloud.

Why this answer

Rehost (lift-and-shift) is the correct initial strategy because it moves the application to AWS without modifying any code, aligning with the company's goal to first migrate without changes and later refactor. Relocate (A) involves moving the hypervisor, not the application itself. Refactor (B) involves rewriting or re-architecting the application, which is not desired initially.

Replatform (C) involves making some cloud optimizations that could require minor code changes.

51
MCQmedium

A company is migrating an on-premises Oracle database to Amazon RDS for Oracle. The database is 2 TB in size and the company has a 1 Gbps AWS Direct Connect connection. They need to minimize downtime. Which approach should the solutions architect recommend?

A.Export the database using Oracle Data Pump and import into RDS
B.Use AWS Snowball Edge to transfer the database files and then restore to RDS
C.Use AWS Schema Conversion Tool to convert the schema and AWS DMS for data migration without CDC
D.Use AWS DMS with full load followed by ongoing replication using change data capture (CDC)
AnswerD

AWS DMS performs the 2 TB full load over the Direct Connect link, then applies change data capture to replicate ongoing changes. Because CDC keeps the target synchronised, the final cutover requires only a brief application outage, minimising downtime.

Why this answer

AWS Database Migration Service (DMS) with change data capture (CDC) allows continuous replication and minimal downtime. Export/import would cause downtime. AWS Schema Conversion Tool (SCT) is for schema conversion, not data migration.

Snowball is for offline data transfer and would delay the process.

52
MCQhard

A company is migrating a legacy monolithic application to AWS. The application has tightly coupled components and high latency between them. The company wants to modernize the application into a microservices architecture. Which migration strategy should the company use?

A.Repurchase
B.Rehost
C.Refactor / Re-architect
D.Replatform
AnswerC

Refactoring re-architects the monolith into independently deployable microservices, replacing in-process calls with lightweight APIs or asynchronous messaging. This directly resolves the stem's tightly coupled components and high inter-component latency, which lift-and-shift or replatform cannot address since they preserve the existing monolithic structure and coupling.

Why this answer

The refactor/re-architect strategy involves re-architecting the application into microservices. Option A is wrong because repurchase involves buying a new product, not re-architecting. Option B is wrong because rehost (lift-and-shift) does not modernize.

Option D is wrong because replatform (lift-tinker-and-shift) makes minor optimizations but does not change architecture.

53
MCQhard

A company is migrating an on-premises Oracle database to Amazon Aurora PostgreSQL. The database is 5 TB and must be migrated with minimal downtime. The company requires continuous replication of changes during the migration and the ability to cut over within a 1-hour maintenance window. Which combination of AWS services should be used to achieve this?

A.Native Oracle Data Guard with AWS Direct Connect
B.AWS Schema Conversion Tool (AWS SCT) with continuous replication
C.AWS Database Migration Service (AWS DMS) with full load only
D.AWS Database Migration Service (AWS DMS) with ongoing replication and AWS Schema Conversion Tool (AWS SCT)
AnswerD

AWS DMS can perform full load plus ongoing replication (change data capture) from Oracle to Aurora PostgreSQL, minimizing downtime. AWS SCT converts the Oracle schema to PostgreSQL-compatible DDL. This combination allows continuous replication until cutover, meeting the 1-hour window. DMS handles data migration, and SCT handles schema conversion, which is essential for heterogeneous migrations.

Why this answer

For heterogeneous migrations with minimal downtime, AWS DMS with ongoing replication and AWS SCT is the correct combination. DMS handles data migration and change data capture, while SCT converts the schema. Other options either lack ongoing replication, are not designed for data migration, or are incompatible with the target database engine.

Exam trap

The trap here is assuming that AWS SCT alone can handle both schema conversion and data replication, but SCT only converts schemas and does not replicate data.

54
MCQmedium

A company is migrating a legacy .NET Framework application to AWS. The application uses Windows authentication and relies on Active Directory for user authentication. The company wants to minimize code changes and maintain the same authentication mechanism. The application will run on Amazon EC2 instances in a VPC. Which solution should a solutions architect recommend?

A.Deploy the application on EC2 instances and configure a site-to-site VPN to the on-premises Active Directory, and join the instances to the on-premises domain.
B.Deploy the application on EC2 instances joined to an AWS Managed Microsoft AD directory, and configure the application to use Windows authentication against the directory.
C.Deploy the application on EC2 instances and use AWS IAM Identity Center (successor to AWS Single Sign-On) for authentication, modifying the application to use SAML.
D.Deploy the application on EC2 instances and use Amazon Cognito user pools for authentication, updating the application to use OpenID Connect.
AnswerB

AWS Managed Microsoft AD is a managed Active Directory service in AWS. EC2 instances can be domain-joined to this directory, allowing the application to use Windows authentication without code changes. This maintains the same authentication mechanism and minimizes migration effort, as the application continues to use Active Directory.

Why this answer

AWS Managed Microsoft AD provides a managed Active Directory in AWS, enabling EC2 instances to be domain-joined and use Windows authentication. This requires no application code changes and maintains the existing authentication mechanism. It also reduces operational overhead compared to extending an on-premises domain.

Exam trap

The trap here is assuming that AWS IAM Identity Center or Amazon Cognito can provide Windows authentication, when they are designed for different authentication protocols and would require application modifications.

55
MCQhard

A company is migrating a legacy Oracle database to Amazon Aurora PostgreSQL. The migration must be completed with minimal downtime and minimal manual effort. Which AWS service should be used?

A.AWS DataSync
B.AWS DMS with ongoing replication
C.AWS Snowball Edge
D.AWS Schema Conversion Tool (SCT)
AnswerB

AWS DMS with ongoing replication performs the initial full load and then continuously applies change data capture from Oracle to Aurora PostgreSQL. Cutover happens once replication lag is negligible, satisfying minimal downtime with minimal manual intervention.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication enables continuous data replication from the source Oracle database to the target Aurora PostgreSQL with minimal downtime. It supports heterogeneous migrations when combined with the AWS Schema Conversion Tool (SCT) for schema conversion. DMS handles the data migration and keeps the target in sync until cutover, minimizing manual effort and downtime.

Exam trap

SAP-C02 often tests the difference between schema conversion (SCT) and data migration (DMS), so candidates may choose SCT alone thinking it covers the entire migration, or pick DataSync for database migration when it is meant for file storage.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is designed for moving files and object data, not for database migration with ongoing replication. Option C is wrong because AWS Snowball Edge is a physical device for transferring large amounts of data offline, which is not suitable for minimal-downtime database migration and does not support ongoing replication. Option D is wrong because AWS SCT only converts database schemas and code; it does not migrate data or provide ongoing replication, so it alone cannot meet the minimal downtime requirement.

56
MCQhard

A company is migrating a stateful firewall appliance to AWS. The appliance currently inspects traffic between multiple on-premises segments. In AWS, the company wants to deploy the appliance in a VPC to inspect traffic between subnets. Which architecture should the company use to ensure that the appliance can inspect all traffic?

A.Deploy the appliance behind an Application Load Balancer and configure the VPC route tables.
B.Deploy the appliance behind a Gateway Load Balancer in an inspection VPC and use a Transit Gateway to route traffic through it.
C.Deploy the appliance behind a Network Load Balancer and configure the VPC route tables to send traffic to the NLB.
D.Use VPC Gateway Endpoints to route traffic through the appliance.
AnswerB

Gateway Load Balancer uses GENEVE encapsulation to transparently redirect traffic to third-party appliances, while Transit Gateway routes inter-subnet and inter-VPC traffic through the inspection VPC. This combination satisfies the requirement to inspect all traffic between subnets without altering routing on each workload.

Why this answer

A Gateway Load Balancer (GWLB) can be deployed in an inspection VPC and used with a Transit Gateway to route traffic from subnets through the appliance for inspection. Option A is wrong because an Application Load Balancer cannot inspect traffic and is designed for HTTP/HTTPS. Option C is wrong because a Network Load Balancer does not inspect traffic; it forwards traffic without inspection.

Option D is wrong because VPC Gateway Endpoints are used to access AWS services privately, not for traffic inspection.

57
MCQeasy

A company wants to migrate its on-premises virtualized workloads to AWS using the VMware Cloud on AWS service. The company currently uses VMware vSphere for virtualization. What is the primary benefit of using VMware Cloud on AWS for this migration?

A.It allows the company to continue using existing VMware management tools and processes
B.It provides better application performance compared to running on AWS native compute
C.It reduces the total cost of ownership by eliminating the need for any hardware maintenance
D.It eliminates the need to refactor applications for the cloud
AnswerA

VMware Cloud on AWS runs the native vSphere stack on dedicated bare-metal hosts, so existing vCenter, vSphere Client, and management workflows continue unchanged. This directly satisfies the stem's constraint of migrating vSphere workloads without retraining staff or re-platforming to native AWS services.

Why this answer

VMware Cloud on AWS allows organizations to use the same VMware tools and processes, minimizing the learning curve and operational changes. It does not automatically reduce costs, nor does it provide better performance or eliminate the need to refactor applications.

58
Multi-Selectmedium

A company is migrating a web application to AWS and wants to use a multi-tier architecture with an Auto Scaling group of EC2 instances behind an Application Load Balancer. The company needs to store session state for the application. Which TWO approaches should the company use to store session state in a scalable and highly available manner? (Choose TWO.)

Select 2 answers
A.Use Amazon DynamoDB with on-demand capacity.
B.Use an EC2 instance store for each instance.
C.Use Amazon EBS snapshots shared across instances.
D.Use Amazon ElastiCache for Redis with replication.
E.Use Amazon RDS for MySQL with Multi-AZ.
AnswersA, D

DynamoDB with on-demand capacity stores session state externally, so any EC2 instance in the Auto Scaling group can retrieve it. On-demand mode scales automatically with request volume, removing capacity planning and satisfying the scalable, highly available requirement without sticky sessions.

Why this answer

Option A is correct because Amazon DynamoDB with on-demand capacity provides a fully managed, serverless, highly available key-value store that scales automatically with traffic, making it ideal for persisting session state across an Auto Scaling group of EC2 instances behind an ALB. Option D is correct because Amazon ElastiCache for Redis with replication offers an in-memory, low-latency, highly available session store with a primary node and read replicas, and it supports Multi-AZ failover so sessions survive node failures. Option B is incorrect because an EC2 instance store is ephemeral, tied to a single instance, and loses data on stop/termination, so it cannot provide shared or durable session state.

Option C is incorrect because EBS snapshots are point-in-time backups, not a live shared session store, and cannot be concurrently attached across multiple instances for session access. Option E is incorrect because Amazon RDS for MySQL with Multi-AZ provides a relational database with failover, but it is not the optimal scalable session store and lacks the low-latency, purpose-built session handling of DynamoDB or ElastiCache.

59
Multi-Selectmedium

A company is migrating a legacy application to AWS. The application currently runs on a single on-premises server with a local MySQL database. The company wants to minimize changes and reduce operational overhead. Which TWO strategies should the solutions architect recommend? (Select TWO.)

Select 2 answers
A.Refactor the application to use microservices
B.Retire the application
C.Replatform the database to Amazon RDS for MySQL
D.Rehost the application on Amazon EC2
E.Repurchase a SaaS alternative
AnswersC, D

Amazon RDS for MySQL runs the same MySQL engine, so the application's queries and drivers work unchanged, satisfying the minimal-changes constraint. RDS also removes database patching, backup and server management tasks, directly reducing operational overhead.

Why this answer

Option C is correct because replatforming the local MySQL database to Amazon RDS for MySQL preserves the MySQL engine and schema while offloading patching, backups, and high availability to AWS, which reduces operational overhead with minimal application changes. Option D is correct because rehosting (lift-and-shift) the application onto Amazon EC2 moves the existing server workload to the cloud with little or no code modification, directly satisfying the goal of minimizing changes. Option A is not appropriate because refactoring into microservices requires significant redesign and development effort, contradicting the minimize-changes requirement.

Option B is wrong because retiring the application eliminates the workload rather than migrating it. Option E is wrong because repurchasing a SaaS alternative replaces the application entirely, which is a larger change than the company wants.

Exam trap

SAP-C02 often tests the trade-off between minimizing changes and reducing operational overhead, where candidates might over-optimize by choosing refactoring or repurchasing, ignoring the explicit requirement to minimize changes.

60
MCQeasy

A company is migrating a legacy application to AWS. The application uses a proprietary binary protocol that is not HTTP-based. The application currently runs on a single server and communicates with clients over TCP port 4444. The company wants to use AWS Elastic Load Balancing to distribute traffic across multiple EC2 instances for high availability. Which load balancer type should the company use?

A.AWS Global Accelerator
B.Classic Load Balancer (CLB)
C.Network Load Balancer (NLB)
D.Application Load Balancer (ALB)
AnswerC

Network Load Balancer operates at layer 4, forwarding TCP traffic on port 4444 without interpreting the proprietary binary protocol. This satisfies the requirement to distribute a non-HTTP protocol across multiple EC2 instances, which Application Load Balancer cannot handle.

Why this answer

A Network Load Balancer (NLB) operates at Layer 4 (TCP/UDP/TLS) and can forward arbitrary TCP traffic, including proprietary binary protocols on non-HTTP ports like 4444, while preserving source IP and supporting millions of requests per second with ultra-low latency. Because the application protocol is not HTTP-based, only a Layer 4 load balancer will work.

Exam trap

SAP-C02 often tests the Layer 4 vs Layer 7 distinction, baiting candidates into choosing ALB for any 'load balancing' scenario even when the protocol is non-HTTP.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator is not a load balancer — it is a networking service that routes traffic over the AWS global backbone to endpoints, and it still requires an ALB, NLB, or EC2 endpoint behind it. Option B is wrong because Classic Load Balancer is legacy and supports only basic Layer 4/7 features with limited protocol support and is not recommended for new designs. Option D is wrong because ALB is a Layer 7 load balancer that only understands HTTP/HTTPS (and gRPC/WebSocket), so it cannot forward a proprietary binary protocol on TCP 4444.

61
MCQhard

A company is migrating a legacy Oracle database to Amazon Aurora PostgreSQL. The migration must minimize downtime and support ongoing replication. Which AWS service should the company use?

A.AWS DataSync
B.AWS Database Migration Service (DMS) with change data capture (CDC)
C.AWS Direct Connect
D.AWS Schema Conversion Tool (SCT)
AnswerB

DMS handles both the initial full load and ongoing replication via change data capture, reading the Oracle redo logs to apply continuous changes to Aurora PostgreSQL. This satisfies the minimal-downtime and ongoing-replication constraints, unlike snapshot-only tools that require an outage window.

Why this answer

B is correct because AWS DMS with ongoing replication (CDC) can migrate data with minimal downtime. A is wrong because AWS DataSync is designed for file-based data transfers, not database replication. C is wrong because AWS Direct Connect provides a dedicated network connection but does not handle database migration or replication.

D is wrong because the AWS Schema Conversion Tool (SCT) only converts schema and code, not the actual data.

62
MCQeasy

A company is migrating a large Oracle database to Amazon Aurora PostgreSQL. The migration must have minimal downtime and support ongoing replication. Which AWS service should the company use?

A.AWS Application Discovery Service
B.AWS Server Migration Service
C.AWS Database Migration Service
D.AWS Schema Conversion Tool
AnswerC

AWS Database Migration Service performs heterogeneous Oracle-to-Aurora PostgreSQL conversion and supports ongoing change data capture replication, keeping the source and target synchronised. This satisfies the minimal-downtime constraint, since cutover happens only after replication has caught up.

Why this answer

AWS Database Migration Service (DMS), is the correct answer because it is specifically designed for migrating databases to AWS with minimal downtime, and it supports ongoing replication from Oracle to Aurora PostgreSQL using change data capture (CDC). Option A is incorrect because AWS Application Discovery Service is used for discovering on-premises servers and applications, not for database migration. Option B is incorrect because AWS Server Migration Service (now part of SMS) is for migrating virtual machines, not databases.

Option D is incorrect because AWS Schema Conversion Tool (SCT) is used to convert the database schema from one engine to another, not for ongoing replication; it is often used alongside DMS.

63
Multi-Selectmedium

A company is migrating a web application to AWS. The application currently runs on a single server and uses a MySQL database. The company wants to ensure high availability and scalability. The web application is stateless. Which TWO actions should the company take to achieve these goals? (Choose TWO.)

Select 2 answers
A.Deploy the web application on Amazon EC2 instances in an Auto Scaling group across multiple Availability Zones, with an Application Load Balancer
B.Use a single Amazon RDS for MySQL DB instance
C.Use Multi-AZ Amazon RDS for MySQL
D.Use Amazon ElastiCache to cache database queries
E.Use a large EC2 instance for the web application with Elastic IP
AnswersA, C

An Application Load Balancer distributing traffic across an Auto Scaling group spanning multiple Availability Zones delivers both elasticity and fault tolerance. Because the application is stateless, any instance can serve any request, so horizontal scaling and zone redundancy directly satisfy the high availability and scalability goals.

Why this answer

To achieve high availability and scalability for the web application, the company should deploy the web tier across multiple Availability Zones using an Auto Scaling group with an Application Load Balancer (Option A), which distributes traffic and automatically scales instances. For the MySQL database, using Multi-AZ Amazon RDS (Option C) provides automatic failover and high availability. Option B (single RDS instance) is a single point of failure.

Option D (ElastiCache) is for caching, not for high availability or scaling. Option E (large EC2 instance with Elastic IP) does not provide scalability or availability.

64
MCQmedium

A company is migrating a legacy application that uses Windows Authentication for SQL Server. The company wants to use AWS Managed Microsoft AD. Which migration strategy should be used for the database to maintain compatibility?

A.Use AWS DMS to migrate to Amazon DynamoDB
B.Replatform to Amazon RDS for MySQL
C.Replatform to Amazon RDS for SQL Server with Windows Authentication
D.Replatform to Amazon Aurora PostgreSQL
AnswerC

Amazon RDS for SQL Server joined to AWS Managed Microsoft AD supports Windows Authentication, so the legacy application's existing authentication mechanism continues to work without code changes. Replatforming preserves compatibility while removing database administration overhead.

Why this answer

AWS Managed Microsoft AD is a managed Active Directory service that supports Windows Authentication (Kerberos/NTLM) natively. Amazon RDS for SQL Server can be domain-joined to AWS Managed Microsoft AD, allowing the database to continue using Windows Authentication without code changes. This preserves the legacy application's authentication model during migration.

Exam trap

SAP-C02 often tests the misconception that any managed database service can replace SQL Server, ignoring that Windows Authentication requires Active Directory integration only available with RDS for SQL Server joined to AWS Managed Microsoft AD.

How to eliminate wrong answers

Option A is wrong because DynamoDB is a NoSQL key-value store that does not support Windows Authentication or SQL Server's authentication model, requiring a full application rewrite. Option B is wrong because RDS for MySQL uses MySQL-native authentication, not Windows Authentication, so the legacy app's integrated security would break. Option D is wrong because Aurora PostgreSQL uses PostgreSQL authentication mechanisms and does not support Windows Authentication via Active Directory.

65
MCQhard

A company is migrating a large-scale Oracle data warehouse to Amazon Redshift. The migration must minimize downtime. The source database is 10 TB and runs on a single on-premises server with 1 Gbps network. Which approach should be used for the initial data load?

A.Use AWS DMS to migrate data directly to Redshift over the network.
B.Use AWS Snowball Edge to transfer data to S3, then copy to Redshift.
C.Use AWS DMS with ongoing replication after initial load via network.
D.Use S3 Transfer Acceleration to upload data to S3, then COPY to Redshift.
AnswerB

Offline transfer bypasses bandwidth constraints.

Why this answer

Using AWS Snowball Edge devices for offline transfer avoids network bandwidth limitations and provides fast, secure transfer of large data volumes. Option A is wrong because 1 Gbps network would take over 22 hours and may cause congestion. Option B is wrong because DMS works for ongoing replication but initial load over network is slow.

Option D is wrong because S3 Transfer Acceleration only speeds up S3 uploads, not the full pipeline.

66
Multi-Selecthard

A company is modernizing a monolithic Java application to run on Amazon ECS with Fargate. The application uses a proprietary configuration management system. Which TWO AWS services can replace the configuration management system to store and retrieve configuration at runtime?

Select 2 answers
A.Amazon S3 with versioning enabled.
B.AWS Secrets Manager.
C.Amazon DynamoDB with application-side caching.
D.AWS AppConfig, a feature of AWS Systems Manager.
E.AWS Systems Manager Parameter Store.
AnswersD, E

AWS AppConfig stores configuration externally and delivers it to ECS tasks at runtime through the AppConfig agent or API, with validation and controlled rollout. This replaces the proprietary configuration management system, satisfying the requirement to store and retrieve configuration dynamically without redeploying the Java containers.

Why this answer

AWS AppConfig (option D) is a feature of AWS Systems Manager designed specifically for application configuration management, allowing you to store, validate, and deploy configuration data with runtime retrieval via the AppConfig API or Lambda extension, making it a direct replacement for a proprietary configuration management system. AWS Systems Manager Parameter Store (option E) provides hierarchical, versioned storage for configuration data and secrets, with runtime retrieval through the SSM API, and is a standard AWS-native configuration store for ECS/Fargate workloads. Option A (Amazon S3 with versioning) is object storage, not a configuration management service, and lacks native runtime configuration retrieval semantics.

Option B (AWS Secrets Manager) is purpose-built for secrets such as credentials and API keys, not general application configuration. Option C (Amazon DynamoDB with application-side caching) is a database, not a configuration management service, and would require custom application logic to serve as a configuration store.

Exam trap

SAP-C02 often tests the distinction between configuration management (AppConfig/Parameter Store) and secret management (Secrets Manager) — candidates incorrectly pick Secrets Manager for all runtime configuration needs.

67
MCQeasy

A company is migrating its on-premises virtual machines (VMs) to AWS. The company has 50 VMs running various operating systems and applications. The architect wants to use a service that automates the replication and conversion of the VMs to Amazon EC2 instances. Which AWS service should the architect use?

A.AWS Application Migration Service (AWS MGN)
B.AWS DataSync
C.AWS Server Migration Service (AWS SMS)
D.AWS CloudEndure Migration
AnswerA

AWS Application Migration Service replicates source servers block-by-block into staging areas and automatically converts them to bootable Amazon EC2 instances, satisfying the automated replication-and-conversion requirement. It supports heterogeneous operating systems and applications across all 50 VMs without manual rebuilds.

Why this answer

AWS Application Migration Service (MGN) is the AWS-recommended service for lift-and-shift migration of on-premises VMs to EC2. It performs continuous block-level replication, automatically converts the source server to run on AWS, and supports a wide range of operating systems and applications with minimal downtime. It replaces the deprecated Server Migration Service.

Exam trap

SAP-C02 often tests whether candidates know SMS is deprecated and CloudEndure was rebranded into MGN — the trap is picking a legacy name that sounds correct but is no longer the current service.

How to eliminate wrong answers

Option B is wrong because AWS DataSync transfers file and object data between storage systems; it does not replicate or convert VMs to EC2 instances. Option C is wrong because AWS Server Migration Service (SMS) is deprecated and no longer the recommended service for VM migration — MGN supersedes it. Option D is wrong because CloudEndure Migration was the predecessor product that was rebranded and folded into AWS MGN; it is not a separate current service to select.

68
MCQmedium

A company is migrating a legacy on-premises .NET application to AWS. The application uses a SQL Server database and requires full control over the operating system for compliance. Which migration strategy should the solutions architect recommend to minimize rework while meeting compliance requirements?

A.Rehost the application on EC2 instances and use RDS Custom for SQL Server.
B.Replace the database with Amazon DynamoDB and refactor the application.
C.Replatform the application to use RDS for SQL Server and deploy the application on EC2 instances.
D.Refactor the application to run on Amazon ECS using Docker containers.
AnswerA

Rehosting on EC2 preserves the application with minimal rework, while RDS Custom for SQL Server grants operating system and database-level access needed for compliance. Standard RDS withholds OS access, and replatforming or refactoring would demand significant rework.

Why this answer

Rehosting (lift-and-shift) with EC2 and RDS Custom for SQL Server allows the company to move the application and database with minimal changes while retaining OS-level control for compliance. RDS Custom provides OS access (SSH, patching) unlike standard RDS, meeting the compliance requirement. Option B (DynamoDB) would require significant application refactoring.

Option C (RDS for SQL Server without Custom) lacks OS access. Option D (ECS with containers) adds containerization rework and does not inherently provide OS-level control.

69
MCQmedium

A company is migrating a large on-premises Oracle database to Amazon RDS for Oracle. The database is 2 TB in size and has a 24/7 uptime requirement. The company plans to use AWS Database Migration Service (AWS DMS) for continuous replication with minimal downtime. The source database is Oracle 11g running on Linux. During the full load phase, AWS DMS reports high latency and the replication slows down significantly. The source database CPU utilization is at 100% during the migration. The company needs to minimize the impact on production workload. What should the company do to improve the migration performance and reduce impact on the source database?

A.Use AWS DMS change data capture (CDC) only, without full load, to reduce the load
B.Increase the size of the DMS replication instance to handle more load
C.Reduce the number of parallel load threads in the DMS task to decrease source CPU usage
D.Set up an Oracle read replica and use it as the source for AWS DMS
AnswerD

Setting up an Oracle read replica and using it as the source for AWS DMS offloads the replication overhead from the primary database, eliminating the CPU bottleneck and allowing the migration to proceed with minimal impact on the production workload.

Why this answer

The source Oracle 11g database is at 100% CPU during the full load, meaning the DMS full-load threads are competing with production workload on the same host. Offloading the DMS read workload to an Oracle read replica (via Oracle Active Data Guard or a manually maintained standby) isolates the migration reads from the primary, preserving production performance while still allowing DMS to perform full load plus CDC against the replica. This is the standard AWS-recommended pattern for minimizing source impact on large Oracle migrations.

Exam trap

SAP-C02 often tests the misconception that scaling the DMS replication instance or tuning DMS task parallelism fixes source-side bottlenecks, when the real fix is offloading reads to a replica or standby.

How to eliminate wrong answers

Option A is wrong because skipping full load and using CDC only would leave the target without the existing 2 TB of data — CDC replicates changes, not the initial dataset, so the migration would be incomplete. Option B is wrong because increasing the DMS replication instance size scales the target-side/task-side capacity but does nothing to relieve the 100% CPU on the source Oracle host, which is the actual bottleneck. Option C is wrong because reducing parallel load threads lowers throughput and lengthens the migration window; it may reduce source load slightly but does not address the root cause and directly contradicts the goal of improving migration performance.

70
MCQhard

A company is migrating a large-scale batch processing workload from on-premises to AWS. The workload runs on a schedule and processes data files from an FTP server. The company wants to use AWS services that are serverless and event-driven to reduce operational overhead. The data files will be uploaded to an Amazon S3 bucket. Which solution meets these requirements?

A.Use Amazon S3 Event Notifications to invoke an AWS Batch job that processes the file
B.Use Amazon S3 Event Notifications to invoke an AWS Lambda function that processes the file
C.Use AWS Glue to crawl the S3 bucket and run an ETL job on a schedule
D.Use Amazon S3 Event Notifications to start an AWS Step Functions workflow that runs processing on Amazon EC2
AnswerB

S3 Event Notifications trigger AWS Lambda directly on each uploaded object, giving the event-driven, serverless processing the workload requires. This removes polling and server management, satisfying the reduced operational overhead constraint, while Lambda scales automatically with the scheduled batch arrivals.

Why this answer

AWS Lambda is a serverless compute service that can be triggered by S3 event notifications, allowing immediate processing of uploaded files without managing servers. This meets the requirements for a serverless, event-driven solution with minimal operational overhead.

Exam trap

SAP-C02 often tests the distinction between serverless and non-serverless services; candidates may incorrectly assume AWS Batch or EC2 are serverless.

How to eliminate wrong answers

Option A is wrong because AWS Batch is not serverless; it requires provisioning compute environments and is not event-driven natively. Option C is wrong because AWS Glue is serverless but runs on a schedule, not event-driven, and is more for ETL than batch processing. Option D is wrong because Amazon EC2 is not serverless; it requires managing instances, and Step Functions orchestrates but doesn't eliminate server management.

71
MCQhard

A company is migrating a critical application to AWS. The migration plan includes a pilot light strategy. The company has set up a small replica of the environment in AWS. During a disaster, the company wants to quickly provision the full production environment. Which AWS service is best suited for this purpose?

A.AWS OpsWorks
B.AWS Elastic Beanstalk
C.AWS CloudFormation
D.AWS CodeDeploy
AnswerC

AWS CloudFormation templates codify the full production environment, so during disaster recovery the stack can be provisioned rapidly and repeatably from the pilot light baseline, satisfying the requirement to quickly stand up complete production capacity.

Why this answer

AWS CloudFormation is the best service for this scenario because it allows you to define the entire infrastructure as code in templates, which can be stored and then quickly executed to provision the full production environment during a disaster. This aligns with the pilot light strategy, where a small replica is already running and CloudFormation can rapidly scale it up. Option A (OpsWorks) is wrong because it is configuration management service for Chef/Puppet, not for quickly provisioning full environments.

Option B (Elastic Beanstalk) is wrong because it is designed for deploying web applications, not for provisioning custom infrastructure. Option D (CodeDeploy) is wrong because it handles application deployments, not infrastructure provisioning.

72
MCQmedium

A company is migrating a high-traffic web application to AWS. The application currently runs on physical servers in a data center and uses a shared file system for user-uploaded content. The company wants to minimize changes to the application and ensure the file system is highly available across multiple Availability Zones. Which AWS service should be used to replace the shared file system?

A.Amazon FSx for Windows File Server with a Multi-AZ deployment
B.Amazon Elastic File System (Amazon EFS) with mount targets in multiple Availability Zones
C.Amazon S3 with a bucket for each Availability Zone
D.Amazon Elastic Block Store (Amazon EBS) volumes replicated across Availability Zones
AnswerB

Amazon EFS is a fully managed, elastic NFS file system that can be mounted on EC2 instances across multiple Availability Zones. It provides shared storage with high availability and durability, requiring no application changes. This matches the requirement to replace the shared file system with minimal changes and multi-AZ availability.

Why this answer

Amazon EFS provides a managed NFS file system that can be mounted on multiple EC2 instances across multiple Availability Zones, offering high availability and durability. It requires no application changes, making it ideal for replacing an on-premises shared file system. Other options either require application modifications or do not provide a shared, multi-AZ file system.

Exam trap

The trap here is assuming that Amazon S3 can serve as a drop-in replacement for a shared file system without application changes.

73
MCQmedium

A company is migrating a containerized application to Amazon ECS. The application requires persistent storage that can be shared across multiple containers running on different EC2 instances. Which storage solution should they use?

A.Amazon FSx for Lustre
B.Amazon EBS
C.Amazon EFS
D.Amazon S3
AnswerC

Amazon EFS provides a shared, elastic NFS file system that mounts concurrently on EC2 instances in multiple Availability Zones, so containers on different hosts read and write the same data. EBS volumes attach to a single instance and cannot satisfy the shared-storage requirement.

Why this answer

Amazon EFS provides a fully managed, elastic NFS file system that can be mounted simultaneously by multiple EC2 instances across Availability Zones, making it the correct choice for shared persistent storage across containers on different hosts. ECS tasks on EC2 launch type can mount EFS volumes using the EFS mount helper, enabling concurrent read/write access. This satisfies the requirement for shared persistent storage that survives container restarts and is accessible from multiple nodes.

Exam trap

The trap is assuming any AWS storage service can be shared across instances; candidates often pick EBS or S3 without recognizing that only EFS (and FSx variants) provide POSIX-compliant shared file storage mountable by multiple EC2 instances simultaneously.

How to eliminate wrong answers

Option A is wrong because FSx for Lustre is a high-performance parallel file system designed for HPC and machine learning workloads, not general-purpose shared container storage, and it is more complex and costly for this use case. Option B is wrong because EBS volumes are block storage attached to a single EC2 instance (or in multi-attach, a limited set in the same AZ) and cannot be shared across containers on different EC2 instances in the way required. Option D is wrong because S3 is object storage accessed via APIs, not a POSIX file system, so it cannot be directly mounted as a shared persistent volume for containers without additional layers like Mountpoint for S3.

74
Multi-Selecthard

Which THREE of the following are common challenges when migrating a monolithic application to a microservices architecture on AWS? (Choose three.)

Select 3 answers
A.Managing distributed transactions across multiple services
B.Single database bottleneck when all services share the same database
C.Increased network latency due to inter-service communication
D.Ensuring data consistency between services that own their own databases
E.Difficulty in scaling individual services independently
AnswersA, C, D

With data split across services, a business operation spanning several of them cannot rely on a single local transaction. Coordinating commits across service boundaries needs compensating actions or saga orchestration, making distributed transaction management a core migration challenge.

Why this answer

Option A is correct because decomposing a monolith into microservices means a single business operation often spans multiple services, each with its own datastore, so maintaining atomicity requires patterns like Saga, two-phase commit, or compensating transactions instead of a single ACID transaction. Option C is correct because calls that were once in-process method invocations become remote network calls over HTTP/gRPC or via queues, adding serialization, connection, and round-trip latency plus retry and timeout overhead. Option D is correct because when each service owns its own database, you lose the monolith's single ACID transaction and must handle eventual consistency, idempotency, and reconciliation across services.

Option B is not a challenge specific to microservices migration — a shared single database is actually a characteristic of the monolith being left behind, and the migration goal is typically to decompose that database. Option E is not a challenge but a benefit: microservices are designed so each service can be scaled independently, which is easier than scaling a monolith as a whole.

Exam trap

SAP-C02 often tests the confusion between challenges of microservices and benefits, such as mistaking independent scaling as a challenge rather than an advantage.

75
MCQhard

A company is migrating a critical database server to Amazon EC2. The root volume (EBS) is configured with DeleteOnTermination=false. After migration, the company needs to ensure that if the EC2 instance fails, a new instance can be quickly launched using the same data. The company takes regular snapshots of the volume. Which statement is correct regarding the root volume's behavior?

A.The root volume cannot be used as a boot volume for a new instance.
B.The root volume will be automatically deleted when the instance is terminated.
C.The root volume will persist after instance termination and can be attached to another instance.
D.Snapshots of the volume will be automatically deleted when the instance is terminated.
AnswerC

With DeleteOnTermination set to false, the EBS root volume survives instance termination, satisfying the requirement that data remains available for a replacement instance. The volume detaches and can be reattached to a new EC2 instance in the same Availability Zone, enabling rapid recovery without restoring from snapshots.

Why this answer

When DeleteOnTermination is set to false, the root volume persists after the EC2 instance is terminated. This allows the volume to be attached to another instance, enabling quick recovery. Option A is incorrect because the root volume can be used as a boot volume for a new instance when attached.

Option B is incorrect because the volume is not automatically deleted; deletion only occurs when DeleteOnTermination is true. Option D is incorrect because snapshots are independent of the DeleteOnTermination setting and are not automatically deleted upon instance termination.

Page 1 of 4 · 235 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Accelerate Workload Migration and Modernization questions.