Courseiva

CCNA Accelerate Workload Migration and Modernization Questions

75 of 235 questions · Page 2/4 · Accelerate Workload Migration and Modernization · Answers revealed

76
MCQmedium

A company is migrating a containerized application from on-premises Kubernetes to Amazon EKS. The application uses persistent volumes for shared configuration files that must be accessible by multiple pods across different Availability Zones. The company wants a fully managed storage solution that supports ReadWriteMany (RWX) access. Which storage option should be used?

A.Amazon S3 mounted using the Mountpoint for Amazon S3 CSI driver.
B.Amazon FSx for Windows File Server with the FSx CSI driver.
C.Amazon EFS with the EFS CSI driver.
D.Amazon EBS with the EBS CSI driver.
AnswerC

Amazon EFS is a fully managed, elastic file system that supports the ReadWriteMany access mode and can be mounted by multiple pods across different Availability Zones. The EFS CSI driver integrates with Amazon EKS, allowing dynamic provisioning of persistent volumes. This meets the requirements for shared storage across AZs.

Why this answer

Amazon EFS with the EFS CSI driver is the correct choice because it is a fully managed, scalable file system that supports ReadWriteMany access and can be mounted by multiple pods across Availability Zones. It integrates natively with Amazon EKS, enabling dynamic provisioning and shared storage. The other options either do not support RWX, are not designed for Linux containers, or lack POSIX compliance.

Exam trap

The trap here is assuming that Amazon EBS can be used for shared storage across pods, but EBS volumes are single-AZ and cannot be attached to multiple instances simultaneously in read-write mode.

77
MCQhard

A company is migrating a large-scale on-premises Apache Kafka cluster to AWS. The cluster handles real-time streaming data from thousands of IoT devices. The company wants to reduce operational overhead and ensure high availability. Which AWS service should be used?

A.Amazon Managed Streaming for Apache Kafka (MSK)
B.Amazon Simple Notification Service (SNS)
C.Amazon Simple Queue Service (SQS)
D.Amazon Kinesis Data Streams
AnswerA

Amazon MSK runs the Kafka control plane, broker patching and Multi-AZ replication, removing the operational burden the stem demands while preserving native Kafka APIs for the IoT stream. Self-managed brokers on EC2 would retain that overhead and weaken availability guarantees.

Why this answer

Amazon MSK is the correct choice because it is a fully managed service for Apache Kafka that runs the same open-source Kafka APIs, so existing producers, consumers, and tooling migrate without code changes. MSK handles broker provisioning, patching, replication across AZs, and automatic recovery, directly reducing operational overhead while providing high availability. It also integrates with VPC, IAM, KMS, and CloudWatch for security and monitoring.

Exam trap

SAP-C02 often tests whether candidates confuse Kafka-compatible managed services (MSK) with AWS-native streaming alternatives (Kinesis) or messaging services (SNS/SQS), so the trap is picking Kinesis for a 'migrate Kafka' scenario.

How to eliminate wrong answers

Option B is wrong because Amazon SNS is a pub/sub notification service for fan-out messaging, not a Kafka-compatible streaming platform, so it cannot host Kafka topics or preserve Kafka consumer semantics. Option C is wrong because Amazon SQS is a managed queue for decoupled point-to-point messaging and lacks Kafka's partitioned log, consumer groups, and replay capabilities. Option D is wrong because Kinesis Data Streams is a proprietary AWS streaming service; it requires rewriting Kafka producers/consumers and does not support the Kafka API, so it does not meet the 'migrate Kafka with minimal change' requirement.

78
Multi-Selectmedium

A company is migrating a legacy application that uses a proprietary binary protocol for communication. The application communicates over TCP/IP. The company wants to modernize the communication layer to use a RESTful API. Which TWO approaches should the company consider?

Select 2 answers
A.Replace the binary protocol with Amazon MQ.
B.Use Amazon API Gateway and AWS Lambda to create a REST API that translates requests to the legacy protocol.
C.Use AWS App Mesh to convert the binary protocol to HTTP.
D.Refactor the application to communicate over HTTP and use Amazon API Gateway.
E.Use Amazon CloudFront to cache the RESTful endpoints.
AnswersB, D

API Gateway fronts a RESTful HTTPS endpoint, while Lambda functions translate each request into the legacy proprietary binary protocol over TCP/IP and return JSON responses. This preserves the existing backend, so only the communication layer is modernised.

Why this answer

Option B is correct because Amazon API Gateway can expose a RESTful API endpoint while AWS Lambda functions act as the integration layer that translates incoming HTTP/JSON requests into the legacy proprietary binary protocol, allowing the legacy application to remain unchanged behind the modernization facade. Option D is correct because refactoring the application itself to natively speak HTTP lets it be fronted directly by Amazon API Gateway as a REST API, eliminating the need for protocol translation and providing a fully RESTful communication layer. Option A is not appropriate because Amazon MQ is a managed message broker for protocols such as JMS, AMQP, MQTT, OpenWire, and STOMP, not a REST API or binary-to-HTTP translator.

Option C is incorrect because AWS App Mesh is a service mesh for managing and observing service-to-service traffic (typically HTTP/gRPC/TCP), not a protocol conversion tool that turns a proprietary binary protocol into HTTP. Option E is incorrect because Amazon CloudFront is a CDN that caches and accelerates content delivery; it does not modernize or translate a proprietary binary protocol into REST.

79
MCQeasy

A company wants to migrate its on-premises file server to AWS. The file server contains 10 TB of data that changes infrequently. The company has a limited bandwidth internet connection and needs to complete the migration within one week. Which AWS service should the company use for the initial data transfer?

A.Amazon S3 Transfer Acceleration
B.AWS Snowball Edge
C.AWS Database Migration Service (DMS)
D.AWS DataSync
AnswerB

AWS Snowball Edge suits the 10 TB dataset because it ships a physical appliance, bypassing the limited internet bandwidth that would make a one-week transfer infeasible. Data is copied locally to the device, returned to AWS, and ingested into S3, meeting the one-week deadline without saturating the existing connection.

Why this answer

AWS Snowball Edge. This is the best option for migrating 10 TB of data over a limited bandwidth connection within a week, as it physically transfers the data via a portable storage device, bypassing the need for network bandwidth. Option A (Amazon S3 Transfer Acceleration) is incorrect because it still relies on internet bandwidth, which is insufficient for the given timeline.

Option C (AWS DMS) is for database migrations, not file servers. Option D (AWS DataSync) also requires network connectivity and bandwidth, making it unsuitable for the large initial transfer over a slow connection.

80
MCQeasy

A company is migrating an on-premises application to AWS. The application requires low-latency access to a file system that can be mounted by multiple EC2 instances simultaneously. Which AWS storage service should they use?

A.Amazon EFS
B.Amazon S3
C.Amazon FSx for Windows File Server
D.Amazon EBS
AnswerA

Amazon EFS provides a shared, elastic NFS file system mountable concurrently by many EC2 instances across Availability Zones, with low latency. This satisfies the stem's requirement for simultaneous multi-instance access to a shared file system.

Why this answer

Amazon EFS is a fully managed, elastic NFS file system that can be mounted concurrently by thousands of EC2 instances across multiple Availability Zones, providing the shared low-latency POSIX access the application needs. It scales automatically and is the canonical AWS answer for multi-attach Linux file storage.

Exam trap

The trap is treating S3 as a general-purpose file system because it's the most familiar AWS storage service — but S3 is object storage and cannot be mounted as a shared POSIX filesystem without third-party gateways.

How to eliminate wrong answers

Option B is wrong because Amazon S3 is object storage accessed via HTTP APIs, not a mountable POSIX file system, so it cannot satisfy a legacy application expecting a mounted share. Option C is wrong because FSx for Windows File Server speaks SMB and targets Windows workloads, not the typical Linux multi-mount scenario described. Option D is wrong because EBS volumes attach to a single EC2 instance at a time (except niche Multi-Attach io1/io2 in one AZ), so they cannot be shared simultaneously.

81
MCQhard

Refer to the exhibit. An IAM policy is attached to an IAM user. The user tries to upload an object to `s3://my-bucket/secret/data.txt` from an IP address in the 10.0.0.0/8 range. What will happen?

A.The upload succeeds because the Allow statement grants s3:PutObject.
B.The upload succeeds because the Deny statement only applies to GetObject, not PutObject.
C.The upload fails because the Deny statement denies all s3 actions unconditionally.
D.The upload fails because the Deny statement explicitly denies s3:PutObject for the prefix secret/ from the specified IP range.
AnswerD

An explicit Deny in IAM always overrides any Allow, regardless of other policies. The Deny statement targets s3:PutObject on the secret/ prefix and matches the request's source IP within 10.0.0.0/8, so the upload is blocked.

Why this answer

In IAM policy evaluation, an explicit Deny always overrides any Allow. The Deny statement in the policy explicitly denies s3:PutObject for objects under the secret/ prefix when the request originates from the 10.0.0.0/8 range. Since the user is uploading to s3://my-bucket/secret/data.txt from an IP in that range, the Deny matches and the upload fails regardless of the Allow statement.

Exam trap

The trap is assuming Allow wins because it appears first or because the user 'has permission' — candidates forget that in AWS IAM, an explicit Deny always overrides any Allow, and they must check the Deny's conditions (prefix + IP range) against the request.

How to eliminate wrong answers

Option A is wrong because it ignores the explicit Deny — in AWS IAM, an explicit Deny always wins over an Allow, so the presence of a granting statement does not guarantee success. Option B is wrong because it misreads the Deny statement's scope; the Deny is not limited to GetObject — it denies s3:PutObject (and likely other actions) for the secret/ prefix from the specified IP range, so the claim that it 'only applies to GetObject' is factually incorrect. Option C is wrong because it overstates the Deny — the Deny is conditional (scoped to a specific prefix and IP range), not unconditional across all s3 actions, so saying it 'denies all s3 actions unconditionally' mischaracterizes the policy.

82
MCQhard

A company is migrating a stateful application to AWS. The application uses sticky sessions (session affinity) on the current on-premises load balancer. The company wants to use an Application Load Balancer (ALB) in AWS. Which feature should be enabled?

A.Connection draining (deregistration delay).
B.Sticky sessions (session affinity) using a cookie generated by the load balancer.
C.Health checks to ensure only healthy instances receive traffic.
D.Cross-zone load balancing.
AnswerB

An Application Load Balancer supports sticky sessions by issuing its own cookie, AWSALB, which pins each client to the same target for the session's duration. This preserves the session affinity the on-premises load balancer provided for the stateful application.

Why this answer

ALB supports sticky sessions via a load balancer-generated cookie (AWSALB) that binds a client to a specific target for the duration of the stickiness policy. Enabling stickiness on the target group preserves session state for stateful applications migrated from on-premises load balancers that used session affinity. This is the direct ALB feature that replicates the on-premises behavior.

Exam trap

SAP-C02 often tests whether candidates conflate session affinity (stickiness) with availability features like health checks, cross-zone balancing, or connection draining, all of which appear in the same ALB feature list.

How to eliminate wrong answers

Option A is wrong because connection draining (deregistration delay) only controls how long the ALB waits for in-flight requests to complete before deregistering a target; it does not maintain client-to-target affinity. Option C is wrong because health checks determine target availability and remove unhealthy targets from rotation; they do not preserve session state. Option D is wrong because cross-zone load balancing distributes traffic evenly across AZs for high availability; it does not provide session affinity and can actually break stickiness if misconfigured.

83
MCQmedium

A company is migrating a stateful application to AWS. The application runs on a single on-premises server and uses local storage for persistent data. The company wants to achieve high availability and scalability. Which migration approach should the company use?

A.Use multiple EC2 instances behind an Application Load Balancer with sticky sessions.
B.Lift and shift to a single Amazon EC2 instance with an EBS volume.
C.Refactor the application to store state in Amazon ElastiCache or Amazon DynamoDB.
D.Use an EC2 Auto Scaling group with lifecycle hooks to persist state to EBS snapshots.
AnswerC

Externalising session and persistent state into ElastiCache or DynamoDB removes the single-server dependency, letting the application tier scale horizontally behind a load balancer. This satisfies both the high-availability and scalability constraints that local storage on one server prevents.

Why this answer

The application is stateful and needs high availability and scalability. Refactoring to store state in managed services like Amazon ElastiCache or DynamoDB decouples state from compute, allowing compute to scale and be replaced without data loss. Option A is wrong: while an ALB with sticky sessions distributes traffic, it ties sessions to specific instances, making scaling and failover complex and not fully HA.

Option B is wrong: a single EC2 instance is a single point of failure and cannot scale. Option D is wrong: EBS snapshots are for backup/disaster recovery, not real-time HA or state persistence during scaling. Only option C properly addresses state management for HA and scalability.

84
MCQeasy

A company is migrating workloads to AWS using AWS Application Migration Service (AWS MGN). The source servers are running on VMware vSphere. After installing the AWS Replication Agent on the source servers, the migration waves are set up. However, during a test cutover, the test instance fails to launch with an error 'Insufficient IP address space in the target VPC'. What is the most likely cause?

A.The replication settings specify a subnet with an incorrect CIDR block
B.The IAM role for AWS MGN does not have permissions to create network interfaces
C.The target VPC subnet does not have enough available IP addresses
D.The AWS MGN service is not enabled in the target AWS Region
AnswerC

AWS MGN launches test and cutover instances into the target subnet, each consuming a free private IP address. The launch error explicitly reports insufficient IP address space, meaning the subnet's available address pool is exhausted rather than any agent or replication fault.

Why this answer

The error 'Insufficient IP address space in the target VPC' indicates that the subnet used for test instances does not have enough available IP addresses to launch the instance. AWS MGN allocates IP addresses from the specified subnet during instance launch. Option A is incorrect because a CIDR mismatch would cause a different error, typically related to subnet configuration.

Option B is incorrect because IAM permission issues would result in an access denied error, not an IP space error. Option D is incorrect because the service not being enabled would produce a different error (e.g., service not available). Therefore, the most likely cause is insufficient available IP addresses in the target VPC subnet.

85
MCQhard

A company is migrating a legacy PHP application running on a single on-premises server to AWS. The application stores session data locally on the server's filesystem. The company wants to achieve high availability and elasticity for the application on AWS. What should the company do to handle session state in the new architecture?

A.Configure an Application Load Balancer with sticky sessions enabled
B.Store session data in Amazon ElastiCache for Redis
C.Use Amazon EFS to share the session files across multiple EC2 instances
D.Refactor the application to use Amazon Cognito for session management
AnswerB

ElastiCache for Redis externalises session state from the instance filesystem into a shared, replicated in-memory store, so any Auto Scaling instance can serve any user's session. This satisfies the elasticity and high availability constraints that local filesystem storage cannot meet.

Why this answer

Using ElastiCache for session storage decouples session state from individual servers, allowing the application to scale horizontally. Sticky sessions with an ALB ties a user to a specific instance, which reduces availability if that instance fails. Storing sessions on EFS is possible but slower than ElastiCache.

Re-architecting to use Cognito is unnecessary for session state.

86
MCQeasy

A company is modernizing a legacy application by breaking it into microservices. The application has a complex set of dependencies and requires gradual migration. Which design pattern should the company use?

A.Blue/Green deployment pattern
B.Saga pattern
C.Strangler Fig pattern
D.Circuit Breaker pattern
AnswerC

The Strangler Fig pattern incrementally replaces legacy functionality by routing specific requests to new microservices while the monolith continues serving the remainder. This directly satisfies the stem's gradual migration requirement, letting the company peel off dependencies piecemeal rather than rewriting everything at once, and it accommodates the complex dependency web without a risky big-bang cutover.

Why this answer

(Strangler Fig pattern) because it allows incremental replacement of legacy system functionality with microservices, enabling gradual migration despite complex dependencies. Option A (Blue/Green deployment) is a deployment strategy, not a migration pattern. Option B (Saga pattern) is for managing distributed transactions, not incremental replacement.

Option D (Circuit Breaker) is a fault-tolerance pattern.

87
MCQeasy

A company is migrating a critical application to AWS and needs to ensure business continuity during the migration. The application must remain available with minimal downtime. Which AWS service should be used to replicate data continuously?

A.AWS Direct Connect
B.AWS Database Migration Service (DMS) with ongoing replication
C.Amazon S3 Transfer Acceleration
D.AWS Snowball Edge
AnswerB

AWS DMS with ongoing replication continuously captures changes from the source database and applies them to the target, keeping both in sync until cutover. This satisfies the minimal-downtime constraint, as the application stays live on the source while replication runs, allowing a short, controlled switchover rather than a lengthy outage.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication (Option B) provides continuous, near-real-time data replication from source to target, enabling minimal-downtime cutover during a migration. It supports homogeneous and heterogeneous migrations and keeps the target in sync until the application is switched over, which is exactly what business continuity during migration requires.

Exam trap

The trap is confusing network-acceleration or bulk-transfer services (Direct Connect, Transfer Acceleration, Snowball) with a true continuous data replication service (DMS with ongoing replication) that supports minimal-downtime cutover.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection between on-premises and AWS; it improves bandwidth and latency but does not replicate data continuously by itself. Option C is wrong because S3 Transfer Acceleration speeds up uploads to S3 using edge locations; it is not a continuous replication service for databases or applications. Option D is wrong because Snowball Edge is a physical data-transfer appliance for bulk offline migration; it is not continuous replication and introduces shipping delays, which conflicts with minimal downtime.

88
Multi-Selecteasy

A company is migrating its on-premises file server to AWS. The file server contains 5 TB of data and is accessed by hundreds of users. The company wants a fully managed file storage solution that supports SMB protocol. Which AWS service should the architect consider?

Select 1 answer
A.Amazon FSx for Windows File Server
B.Amazon FSx for Lustre
C.AWS Storage Gateway File Gateway
D.Amazon S3
E.Amazon Elastic File System (Amazon EFS)
AnswersA

Amazon FSx for Windows File Server natively supports the SMB protocol and is fully managed, satisfying both constraints in the stem. It integrates with Microsoft Entra ID for access control and provides Windows ACLs, making it the appropriate fit for migrating a 5 TB on-premises file server accessed by hundreds of users.

Why this answer

Amazon FSx for Windows File Server is a fully managed file storage service that supports the SMB protocol and is designed for Windows workloads. It integrates with Active Directory and provides features like DFS, shadow copies, and Windows ACLs, making it the correct choice for migrating an on-premises Windows file server.

Exam trap

SAP-C02 often tests the distinction between SMB and NFS support across AWS storage services, causing candidates to select EFS (NFS) or S3 (object) for a Windows SMB requirement.

89
Multi-Selecthard

A company is migrating a legacy Java application to AWS. The application currently runs on a single on-premises server and uses a MySQL database. The company wants to modernize the application by decoupling components and improving scalability. Which THREE steps should the architect include in the migration plan?

Select 3 answers
A.Rewrite the application to use a NoSQL database in a single migration step
B.Place an Application Load Balancer in front of the application
C.Refactor the application into microservices and deploy on Amazon ECS with Fargate
D.Deploy the application on a single larger EC2 instance
E.Migrate the database to Amazon RDS for MySQL
AnswersB, C, E

An Application Load Balancer distributes HTTP/HTTPS traffic across multiple targets, directly satisfying the decoupling and scalability goals. It enables horizontal scaling by routing to an Auto Scaling group, removing the single-server bottleneck, and performs health checks to route around failed instances, which the legacy on-premises deployment could not achieve.

Why this answer

Option B is correct because placing an Application Load Balancer (ALB) in front of the application enables horizontal scaling, health checks, and distribution of traffic across multiple targets, which directly supports the goal of improving scalability and decoupling the entry point from the compute layer. Option C is correct because refactoring the monolith into microservices deployed on Amazon ECS with Fargate decouples components, allows independent scaling per service, and removes server management overhead, aligning with the modernization objective. Option E is correct because migrating the MySQL database to Amazon RDS for MySQL preserves compatibility with the existing relational schema while offloading patching, backups, and Multi-AZ high availability to AWS, improving scalability and resilience.

Option A does not belong because rewriting to a NoSQL database in a single migration step is risky, unnecessary for a MySQL-based app, and contradicts an incremental modernization approach. Option D does not belong because deploying on a single larger EC2 instance is vertical scaling that keeps the application monolithic and does not decouple components or improve scalability.

Exam trap

SAP-C02 often tests whether candidates recognize that modernization should be incremental and decoupled — options that propose a single big-bang rewrite or vertical scaling are almost always distractors.

90
MCQmedium

A company runs a high-traffic web application on physical servers in its own data center. The servers use a proprietary TCP-based protocol on port 9000 that cannot be changed, and the application stores session data in local memory. The company wants to migrate the application to AWS with minimal code changes while enabling horizontal scaling and high availability. Which combination of AWS services should a solutions architect recommend to meet these requirements?

A.Use an Application Load Balancer with sticky sessions enabled, and store session data in Amazon ElastiCache for Redis.
B.Use a Network Load Balancer with a UDP listener on port 9000, and store session data in Amazon ElastiCache for Memcached.
C.Use an Application Load Balancer with a TCP listener on port 9000, and store session data in Amazon DynamoDB.
D.Use a Network Load Balancer with a TCP listener on port 9000, and store session data in Amazon ElastiCache for Redis.
AnswerD

A Network Load Balancer operates at Layer 4 and can forward TCP traffic on any port, including the proprietary protocol on port 9000, without requiring code changes. Storing session data in ElastiCache for Redis externalizes session state, enabling horizontal scaling and high availability. This combination meets all requirements with minimal application modification.

Why this answer

The proprietary TCP protocol on port 9000 requires a Layer 4 load balancer. A Network Load Balancer supports TCP listeners on any port, preserving the protocol without code changes. Externalizing session state to ElastiCache for Redis removes the dependency on local memory, enabling horizontal scaling.

This combination provides high availability and minimal modification.

Exam trap

The trap here is assuming that an Application Load Balancer can handle any TCP port, when it only supports HTTP/HTTPS/gRPC and would fail to forward the custom protocol.

91
MCQeasy

A company is migrating its on-premises VMware virtual machines to AWS. The company wants to use a lift-and-shift approach and minimize changes to the applications. Which AWS service should be used to automate the migration of these virtual machines?

A.AWS Migration Hub
B.AWS DataSync
C.AWS Application Migration Service (AWS MGN)
D.AWS Database Migration Service (AWS DMS)
AnswerC

AWS Application Migration Service (MGN) is designed for lift-and-shift migrations of physical, virtual, and cloud servers to AWS. It supports VMware vSphere environments and automates the replication and conversion of servers to run natively on AWS. It minimizes downtime and requires no changes to applications, making it the ideal choice for this scenario.

Why this answer

AWS Application Migration Service (MGN) is the correct choice because it automates the lift-and-shift migration of VMware virtual machines to AWS. It replicates servers continuously and launches them as EC2 instances, minimizing downtime and application changes. Other services like DMS, DataSync, and Migration Hub serve different purposes and do not handle server migration.

Exam trap

The trap here is confusing AWS Migration Hub, which only tracks migrations, with AWS Application Migration Service, which actually performs the migration.

92
MCQhard

A company attaches the IAM policy shown in the exhibit to an IAM user. The user tries to upload an object to my-bucket using the AWS CLI without the --ssl flag (i.e., using HTTP). What will happen?

A.The upload fails with an implicit denial because the Allow condition is not met.
B.The upload succeeds because the Allow statement grants s3:PutObject.
C.The upload fails with an explicit deny because of the Deny statement.
D.The upload succeeds because there is no explicit Deny for s3:PutObject.
AnswerC

The policy's Deny statement matches requests where aws:SecureTransport is false, which HTTP satisfies. Because an explicit deny always overrides any Allow, the CLI upload is rejected outright rather than merely unauthenticated, so the user receives an access-denied error.

Why this answer

The policy contains an explicit Deny statement that triggers when the request is made over HTTP (aws:SecureTransport is false). In AWS IAM, an explicit Deny always overrides any Allow, regardless of other statements or conditions. Because the CLI upload without --ssl uses HTTP, the Deny condition matches and the request is rejected with an explicit deny — not an implicit one.

Exam trap

SAP-C02 often tests the IAM evaluation logic where an explicit Deny overrides any Allow, and candidates confuse 'implicit deny from unmet condition' with 'explicit deny from a matching Deny statement' — the exam expects you to recognize the Deny fires here.

How to eliminate wrong answers

Option A is wrong because the failure is not an implicit denial from an unmet Allow condition — the Deny statement actively matches the HTTP request, producing an explicit deny, which is a materially different evaluation outcome. Option B is wrong because the Allow statement's condition (aws:SecureTransport: true) is not satisfied when HTTP is used, so the Allow does not grant s3:PutObject in this scenario. Option D is wrong because there is an explicit Deny for s3:PutObject when SecureTransport is false — the premise that no explicit Deny exists is factually incorrect.

93
MCQeasy

Refer to the exhibit. A company is using AWS Migration Hub to track migrations. The above IAM policy is attached to an IAM role used by the migration tool. The migration tool reports that it cannot register the migration task with Migration Hub. Which action should the company add to the policy to fix the issue?

A.mgh:ImportMigrationTask
B.mgh:AssociateDiscoveredResource
C.mgh:CreateHomeRegion
D.mgh:GetHomeRegion
AnswerA

Registering a migration task with Migration Hub requires the mgh:ImportMigrationTask permission, which the existing policy omits. Adding this action to the IAM role lets the migration tool create the task record, resolving the reported registration failure.

Why this answer

The IAM policy shown in the exhibit likely grants permissions for various Migration Hub actions but is missing the specific permission required to register a migration task. The AWS Migration Hub API action `mgh:ImportMigrationTask` is used to register a migration task with Migration Hub, which is exactly what the migration tool is attempting to do. Without this permission, the tool cannot associate the task with Migration Hub, resulting in the reported error.

Therefore, adding `mgh:ImportMigrationTask` to the policy resolves the issue.

Exam trap

SAP-C02 often tests the distinction between Migration Hub actions that register tasks versus those that associate resources or manage home region settings, causing candidates to confuse the specific permission needed for task registration.

How to eliminate wrong answers

Option B is wrong because `mgh:AssociateDiscoveredResource` is used to associate a discovered resource with a migration task, not to register the migration task itself. Option C is wrong because `mgh:CreateHomeRegion` is used to set the home region for Migration Hub, which is a one-time setup action and not required for registering a migration task. Option D is wrong because `mgh:GetHomeRegion` is a read-only action to retrieve the home region, which does not grant permission to register a migration task.

94
MCQmedium

A media company is migrating its on-premises rendering farm to AWS. The rendering application uses a shared file system that must be accessible by hundreds of EC2 instances simultaneously. The file system must provide high throughput and low latency, and support POSIX permissions. The company wants to minimize changes to the application. Which AWS storage service should they use?

A.Amazon FSx for Windows File Server
B.Amazon S3 with AWS Transfer Family
C.Amazon Elastic File System (EFS) Standard
D.Amazon FSx for Lustre
AnswerD

Amazon FSx for Lustre is a high-performance file system optimized for compute-intensive workloads like rendering. It provides sub-millisecond latencies, millions of IOPS, and hundreds of GB/s throughput. It supports POSIX permissions and can be accessed by many EC2 instances concurrently. It integrates with S3, allowing data to be processed and stored. This meets the requirements for a rendering farm.

Why this answer

Amazon FSx for Lustre is purpose-built for high-performance computing workloads such as rendering, providing the low latency, high throughput, and POSIX compliance needed. It can be accessed by many EC2 instances simultaneously and integrates with S3. Other file systems either lack the performance or are not POSIX-compliant for Linux workloads.

Exam trap

The trap here is assuming that Amazon EFS, being a shared file system, can handle the performance requirements of a rendering farm, but it is not optimized for such high-throughput, low-latency workloads.

95
MCQmedium

A company is migrating a critical application to AWS using a lift-and-shift approach. The application runs on two on-premises servers: a web server and a database server running SQL Server. The company has deployed the web server on an EC2 instance behind an Application Load Balancer, and the database on an RDS for SQL Server Multi-AZ instance. After migration, users report that the application is noticeably slower compared to on-premises. The application uses a large number of database transactions, and latency between the web server and database has increased. The web server is in us-east-1a, and the RDS primary instance is in us-east-1b. The solutions architect verifies that the application is using the RDS endpoint, not the IP address. What should the architect do to reduce latency?

A.Enable Multi-AZ on the web server EC2 instance.
B.Move the web server EC2 instance to the same Availability Zone as the RDS primary instance.
C.Upgrade the web server EC2 instance to a larger instance type with enhanced networking.
D.Deploy Amazon CloudFront in front of the web server to cache responses.
AnswerB

Placing the EC2 instance in the same Availability Zone as the RDS primary eliminates cross-AZ network hops, cutting the round-trip latency that the transaction-heavy workload amplifies. This satisfies the requirement to reduce latency without altering the application or database configuration.

Why this answer

Cross-AZ traffic between the web server in us-east-1a and the RDS primary in us-east-1b adds roughly 1–2 ms of latency per round trip, which compounds dramatically for chatty applications issuing many small database transactions. Moving the EC2 web server into the same AZ as the RDS primary eliminates that cross-AZ hop, restoring on-premises-like latency. The application already uses the RDS endpoint, so no DNS or connection-string change is needed.

Exam trap

SAP-C02 often tests whether candidates understand that cross-AZ latency is the culprit in lift-and-shift slowdowns, and distractors like 'bigger instance' or 'CloudFront' sound like performance fixes but don't address the actual network hop.

How to eliminate wrong answers

Option A is wrong because Multi-AZ on an EC2 instance is not a feature — Multi-AZ applies to RDS, ELB, and similar managed services, not standalone EC2 instances, so this option is technically nonsensical. Option C is wrong because a larger instance type with enhanced networking improves throughput and packet-per-second performance but does not reduce the physical network latency of crossing AZ boundaries. Option D is wrong because CloudFront caches static content at edge locations and does nothing for dynamic database transactions between the web tier and RDS — it addresses client-side latency, not server-to-database latency.

96
MCQeasy

A company is migrating a legacy Windows application to AWS. The application requires a shared file system accessible from multiple EC2 instances. Which AWS storage solution should the company use?

A.Amazon Elastic File System (EFS)
B.Amazon FSx for Windows File Server
C.Amazon Elastic Block Store (EBS) with multi-attach enabled
D.Amazon Simple Storage Service (S3)
AnswerB

Amazon FSx for Windows File Server provides fully managed SMB shares backed by Windows file servers, supporting NTFS permissions and Active Directory integration. Multiple EC2 instances can mount the same share concurrently, meeting the legacy Windows application's shared-file-system requirement.

Why this answer

Amazon FSx for Windows File Server provides a fully managed native Windows file system that supports the SMB protocol, which is required for legacy Windows applications to access shared file systems. Amazon EFS uses NFS, which is not natively supported by Windows. EBS with multi-attach is limited to a small number of instances and not ideal for file sharing.

S3 is object storage and does not provide a traditional file system interface.

97
MCQmedium

A company is migrating an on-premises Microsoft SQL Server database to Amazon RDS for SQL Server. They need to minimize downtime and ensure data consistency. Which AWS service should they use for the migration?

A.AWS DataSync
B.AWS Schema Conversion Tool (SCT)
C.AWS Database Migration Service (DMS)
D.AWS Glue
AnswerC

AWS Database Migration Service (DMS) supports heterogeneous migrations with minimal downtime using continuous replication.

Why this answer

(AWS DMS) is correct because it supports homogeneous migrations with minimal downtime using continuous replication. Option A (DataSync) is for file-based data. Option B (SCT) only provides schema conversion.

Option D (Glue) is for ETL jobs.

98
MCQmedium

A company is migrating a monolithic application to AWS. The application consists of a web server, an application server, and a MySQL database. The web server and application server run on the same EC2 instance. The company wants to minimize changes during migration. Which migration strategy should the architect recommend?

A.Refactor the application into microservices on Amazon ECS
B.Replatform by migrating the database to Amazon RDS
C.Rehost using AWS Application Migration Service (AWS MGN)
D.Retire the application and replace it with a SaaS solution
AnswerC

Rehosting with AWS Application Migration Service lifts the servers as-is onto EC2, replicating the existing web, application, and MySQL tiers without code changes. This directly satisfies the requirement to minimise changes during migration, since no refactoring, replatforming, or re-architecting is needed.

Why this answer

Rehosting using AWS Application Migration Service (AWS MGN) is the correct strategy because it minimizes changes by lifting and shifting the existing servers to EC2. The application remains monolithic, and the database can stay on the same instance or be moved as-is. This aligns with the requirement to minimize changes during migration.

Exam trap

SAP-C02 often tests the distinction between rehost and replatform, where candidates might think moving the database to RDS is minimal change, but it actually requires application modifications.

How to eliminate wrong answers

Option A is wrong because refactoring into microservices requires significant changes to the application architecture, which contradicts the goal of minimizing changes. Option B is wrong because replatforming by migrating the database to Amazon RDS involves changes to the database layer and possibly application connection strings, which is more than minimal. Option D is wrong because retiring and replacing with SaaS is not a migration of the existing application and would require re-implementation.

99
Multi-Selecteasy

A company is planning to migrate a large .NET application to AWS. The application uses IIS and SQL Server. Which TWO AWS services can be used to rehost the application with minimal changes?

Select 2 answers
A.Amazon Aurora
B.Amazon EC2 with Windows Server
C.AWS Elastic Beanstalk
D.Amazon RDS for SQL Server
E.AWS Lambda
AnswersB, D

Amazon EC2 with Windows Server satisfies the rehost requirement by running the unmodified .NET application on IIS and SQL Server, since the customer manages the guest OS and full software stack. Unlike managed platform services that demand code or configuration changes, lift-and-shift onto EC2 instances preserves the existing architecture with minimal modification.

Why this answer

Amazon EC2 with Windows Server (B) is correct because it lets the company rehost the existing .NET/IIS application on a Windows Server instance with minimal changes, since IIS and the .NET runtime run natively on the VM just as they did on-premises. Amazon RDS for SQL Server (D) is correct because it provides a managed SQL Server engine that is compatible with the application's existing database, so the database can be migrated with little or no code change. AWS Elastic Beanstalk (C) is not the best fit here because it is a PaaS that abstracts the infrastructure and typically requires application packaging/deployment changes rather than a straight rehost of an IIS/SQL Server stack.

Amazon Aurora (A) is a MySQL/PostgreSQL-compatible engine and does not support SQL Server, so it would require database conversion. AWS Lambda (E) is a serverless compute service that cannot run a full IIS/.NET application with SQL Server dependencies without significant re-architecture.

100
MCQeasy

A company is migrating a critical application to AWS and wants to ensure business continuity during the cutover. The migration plan includes a pilot light strategy. Which of the following BEST describes the pilot light pattern?

A.Take regular backups and restore them in AWS during cutover.
B.Run a scaled-down but fully functional version of the environment in AWS at all times.
C.Replicate data to AWS and run a minimal version of the application that can be scaled up during cutover.
D.Run the application simultaneously in both environments and route traffic to both.
AnswerC

Replicating data continuously and running only a minimal core of the application satisfies the pilot light requirement: a small always-on footprint that can be scaled up rapidly during cutover. This differs from warm standby, which runs a fully functional but scaled-down copy, and from backup-and-restore, which provisions nothing until disaster.

Why this answer

The pilot light pattern is a disaster recovery strategy where core data is continuously replicated to AWS, and a minimal version of the application (e.g., a small EC2 instance running the application stack) is kept running. During cutover, this minimal environment is rapidly scaled up to full production capacity. This matches option C, as it describes replicating data and running a minimal version that can be scaled up.

Exam trap

The trap here is confusing the pilot light pattern with the warm standby pattern, as both involve a running environment in AWS, but pilot light uses a minimal stack that is not fully functional until scaled up, whereas warm standby runs a fully functional scaled-down version.

How to eliminate wrong answers

Option A is wrong because taking regular backups and restoring them is a backup-and-restore strategy, not a pilot light pattern; it has a higher recovery time objective (RTO) and does not maintain a running environment. Option B is wrong because running a scaled-down but fully functional version at all times describes the warm standby pattern, not the pilot light; pilot light keeps only the core data and a minimal application stack, not a fully functional environment. Option D is wrong because running the application simultaneously in both environments and routing traffic to both describes a multi-site active-active pattern, which is not the pilot light pattern.

101
Multi-Selectmedium

A company is migrating a multi-tier application to AWS and wants to modernize by using containers and serverless technologies. The application consists of a Node.js frontend, a Java backend, and a PostgreSQL database. The company wants to reduce operational overhead and improve scalability. Which TWO strategies should the company use? (Choose two.)

Select 2 answers
A.Refactor the Node.js frontend to run on AWS Lambda with Amazon API Gateway
B.Migrate the database to Amazon RDS for PostgreSQL
C.Migrate the database to Amazon DynamoDB
D.Deploy the Java backend on Amazon ECS with AWS Fargate
E.Deploy the Java backend on Amazon EC2 with Auto Scaling
AnswersB, D

RDS reduces operational overhead compared to managing PostgreSQL on EC2.

Why this answer

Amazon RDS for PostgreSQL reduces operational overhead by managing backups, patching, and replication, while providing scalability through read replicas and storage auto-scaling. This aligns with the goal of modernizing the database layer without changing the database engine, avoiding the need to refactor the application to use a NoSQL database like DynamoDB.

Exam trap

The trap here is that candidates often assume that any use of containers or serverless must involve Lambda, but for stateful or long-running Java backends, ECS with Fargate is more appropriate than Lambda, and DynamoDB is not a drop-in replacement for PostgreSQL without significant application changes.

102
MCQhard

A company is modernizing a legacy application by refactoring it into microservices. The application uses a monolithic database. The company wants to adopt a microservices architecture with independent data stores. What pattern should the company use?

A.Data lake with Amazon S3
B.Centralized database with an API layer
C.Database per Service
D.Shared database with read replicas
AnswerC

Database per Service gives each microservice its own private data store, removing the shared monolithic schema and allowing independent deployment and scaling. Services then integrate through APIs or events rather than direct cross-service database access.

Why this answer

The Database per Service pattern ensures that each microservice owns its own data, promoting loose coupling and allowing independent scaling and technology choices. Option A is incorrect because a data lake with Amazon S3 is designed for analytics and large-scale storage, not for transactional microservices data stores. Option B is incorrect because a centralized database with an API layer still creates a single point of coupling and does not give each service its own data store.

Option D is incorrect because a shared database with read replicas still uses a single database schema, which tightly couples the services.

103
MCQmedium

A company is migrating a Windows-based .NET application to AWS. The application uses SQL Server for its database and stores documents on a Windows file share. The company wants to adopt a hybrid model initially, where the application runs on AWS but still connects to on-premises resources for legacy integration. The migration must use a phased approach: first move the compute to AWS, then the database, and finally the file storage. The company has high latency to the internet and wants to optimize data transfer. You have set up a Direct Connect connection. During the first phase, you migrate the web and application servers to Amazon EC2 Windows instances. You need to ensure that the EC2 instances can access the on-premises SQL Server and file share securely. Which combination of actions should be taken?

A.Place the EC2 instances in a private subnet. Create a VPN connection or use Direct Connect virtual interface to connect to on-premises. Configure security groups to allow traffic to on-premises SQL Server and file share.
B.Place the EC2 instances in a private subnet with a NAT gateway. Use VPC peering to on-premises.
C.Place the EC2 instances in a public subnet. Use an internet gateway and configure security groups to allow inbound traffic from on-premises IPs.
D.Use Amazon EC2-Classic and link the instances to on-premises via ClassicLink.
AnswerA

Private subnets plus a Direct Connect virtual interface or VPN give the EC2 instances private, encrypted connectivity to on-premises SQL Server and file share, avoiding internet exposure. Security groups then restrict traffic to only those on-premises endpoints, meeting the secure hybrid-access requirement.

Why this answer

Placing EC2 instances in a private subnet keeps them off the public internet while still allowing outbound access through the VPC route table. A Direct Connect virtual interface (private VIF) or a VPN connection provides private, low-latency connectivity to on-premises SQL Server and file share, and security groups can be scoped to allow only the required SQL (1433) and SMB (445) traffic. This matches the hybrid, phased migration model where compute moves first but still depends on on-premises data.

Exam trap

SAP-C02 often tests whether candidates understand that NAT gateways and VPC peering do not provide on-premises connectivity — only Direct Connect or VPN can bridge AWS to a corporate data center.

How to eliminate wrong answers

Option B is wrong because a NAT gateway only provides outbound internet access — it cannot route traffic to on-premises networks, and VPC peering does not extend to on-premises environments (that requires Direct Connect or VPN). Option C is wrong because placing instances in a public subnet exposes them to the internet and uses an internet gateway, which contradicts the requirement for secure private access to on-premises resources over Direct Connect. Option D is wrong because EC2-Classic was retired by AWS in 2022 and ClassicLink is no longer available; it also does not provide the required private connectivity to on-premises.

104
Multi-Selectmedium

A company is planning to migrate a three-tier web application to AWS. The application consists of a web server, an application server, and a MySQL database. The company wants to minimize operational overhead and improve scalability. Which THREE AWS services should the company use to modernize the architecture? (Choose THREE.)

Select 3 answers
A.AWS Lambda
B.Elastic Load Balancing (ELB)
C.Amazon EC2 instances
D.Amazon ECS with Fargate
E.Amazon RDS for MySQL
AnswersB, D, E

Elastic Load Balancing distributes incoming traffic across targets in multiple Availability Zones, providing the high availability and horizontal scalability the web tier requires. It is fully managed, so it satisfies the minimise-operational-overhead constraint without needing self-managed load-balancing instances.

Why this answer

Elastic Load Balancing (ELB) [CORRECT] is right because it distributes incoming traffic across multiple targets in the web tier, enabling horizontal scaling and high availability without managing load-balancing servers. Amazon ECS with Fargate [CORRECT] is right because it runs the application tier as containers with serverless compute, eliminating EC2 instance provisioning and patching, which directly reduces operational overhead while supporting automatic scaling. Amazon RDS for MySQL [CORRECT] is right because it provides a managed MySQL-compatible database with automated backups, patching, Multi-AZ failover, and read replicas, replacing self-managed MySQL and improving scalability.

AWS Lambda is not selected because the scenario calls for a three-tier architecture with a dedicated application server tier, which ECS with Fargate addresses more directly. Amazon EC2 instances are not selected because managing them increases operational overhead, contrary to the goal of minimizing it.

105
MCQmedium

A company is migrating a legacy Java application from an on-premises VMware environment to AWS. The application runs on a single server with 16 vCPUs and 32 GB RAM, and uses an NFS share for shared files. The company wants to minimize changes and reduce operational overhead. Which migration strategy best meets these requirements?

A.Rehost the application to Amazon EC2 by using AWS Application Migration Service, and replace the NFS share with Amazon EFS.
B.Refactor the application into microservices running on Amazon ECS with AWS Fargate, and use Amazon S3 for shared file storage.
C.Retain the application on-premises and extend the network to AWS using AWS Direct Connect.
D.Replatform the application to AWS Elastic Beanstalk, and use Amazon RDS for shared file storage.
AnswerA

Rehosting with AWS Application Migration Service lifts and shifts the server to EC2 with minimal changes, and replacing the NFS share with Amazon EFS provides a managed, scalable file system that integrates with EC2. This reduces operational overhead while preserving the application architecture.

Why this answer

Rehosting with AWS Application Migration Service allows the server to be migrated to EC2 with minimal modifications, aligning with the lift-and-shift approach. Amazon EFS offers a managed NFS-compatible file system that can replace the on-premises NFS share without application changes, reducing operational overhead. Other strategies involve refactoring or replatforming, which introduce unnecessary changes.

Exam trap

The trap here is assuming that any AWS storage service can replace an NFS share, but only Amazon EFS provides the required NFS protocol compatibility for a lift-and-shift migration.

106
MCQeasy

A company is migrating a web application to AWS and wants to use a containerized architecture. The application consists of multiple microservices that communicate via REST APIs. The company needs a solution that minimizes operational overhead for managing containers and orchestrating microservices. Which AWS service should the company use?

A.Amazon EKS with managed node groups.
B.AWS Lambda functions for each microservice.
C.Amazon EC2 with Docker installed on each instance.
D.Amazon ECS with AWS Fargate launch type.
AnswerD

Fargate removes the need to provision or patch EC2 instances, so AWS manages the container host layer entirely. ECS still orchestrates the microservices and their REST connectivity, satisfying the requirement to minimise operational overhead for container management and orchestration.

Why this answer

Amazon ECS with the Fargate launch type is the correct choice because it allows you to run containers without managing the underlying servers or cluster, thus minimizing operational overhead. Fargate is a serverless compute engine for containers, perfectly suited for microservices requiring minimal management. Option A (EKS with managed node groups) still requires management of worker nodes and is more complex.

Option B (Lambda) is for functions, not containerized microservices. Option C (EC2 with Docker) involves significant operational overhead for managing instances and Docker.

107
MCQmedium

A company is migrating a 40 TB on-premises Oracle database to Amazon Aurora PostgreSQL. The database must remain fully operational during the migration, and the cutover must complete within a 30-minute maintenance window. The company requires continuous data replication until the final switchover. Which migration approach should a solutions architect recommend?

A.Use AWS Database Migration Service (AWS DMS) with ongoing replication, then perform a cutover after the replication lag is near zero.
B.Use AWS Schema Conversion Tool (AWS SCT) to convert the schema, then use native Oracle tools to replicate ongoing changes to Aurora PostgreSQL.
C.Take a full export of the Oracle database using Oracle Data Pump, transfer it to Amazon S3, and import it into Aurora PostgreSQL.
D.Configure Oracle Active Data Guard to replicate to an Amazon RDS for Oracle read replica, then promote the replica and migrate to Aurora PostgreSQL.
AnswerA

AWS DMS with ongoing replication continuously captures changes from the source Oracle database and applies them to Aurora PostgreSQL. This keeps the target synchronized while the source remains fully operational, enabling a short cutover once replication lag is minimal. It directly satisfies the requirement for continuous replication and a 30-minute switchover window.

Why this answer

AWS DMS with ongoing replication is purpose-built for heterogeneous migrations that require minimal downtime. It reads ongoing changes from Oracle and applies them to Aurora PostgreSQL, keeping the target nearly current. When replication lag is low, the application can be switched over quickly, satisfying the 30-minute cutover requirement while the source remains fully available throughout the migration.

Exam trap

The trap here is assuming that a one-time dump-and-load or an Oracle-native replication tool can provide continuous replication into Aurora PostgreSQL without a dedicated heterogeneous replication service.

108
Multi-Selecthard

A company is migrating a legacy application to AWS. The application uses a custom authentication mechanism that relies on LDAP. The company wants to minimize changes to the application. Which THREE services should the company consider for integrating LDAP authentication? (Choose THREE.)

Select 3 answers
A.AWS Directory Service Simple AD
B.AWS Directory Service AD Connector
C.AWS Directory Service for Microsoft Active Directory
D.Amazon Cognito user pools
E.AWS Identity and Access Management (IAM)
AnswersA, B, C

Simple AD is an Samba-based managed directory that exposes standard LDAP and Kerberos endpoints in AWS, so the legacy application's existing LDAP calls work unmodified. This satisfies the minimise-changes constraint, though it lacks trusts and advanced Microsoft AD features.

Why this answer

Options A, B, and C are correct because all three are AWS Directory Service offerings that expose LDAP endpoints the legacy application can bind to with minimal code changes. Simple AD (A) is a Samba 4-based, Microsoft AD-compatible directory that supports LDAP and Kerberos, so an app using LDAP authentication can point at it directly. AD Connector (B) is a proxy that forwards LDAP (and Kerberos) authentication requests to an existing on-premises Active Directory, letting the app keep using LDAP while credentials stay on-premises.

AWS Directory Service for Microsoft Active Directory (C), i.e., AWS Managed Microsoft AD, runs actual Windows AD domain controllers that serve LDAP/LDAPS, so it natively satisfies LDAP-dependent authentication. Option D (Amazon Cognito user pools) is wrong because it is an OIDC/OAuth 2.0 identity provider for web/mobile apps, not an LDAP directory, and would require rewriting the app's authentication logic. Option E (IAM) is wrong because IAM handles AWS API authorization via SigV4 and federation (SAML/OIDC), not LDAP bind authentication for an application.

Exam trap

SAP-C02 often tests whether candidates recognize that Cognito user pools and IAM are not LDAP-compatible, and that only the three AWS Directory Service options provide LDAP endpoints for legacy applications.

109
MCQmedium

A company is migrating 400 on-premises VMware virtual machines to AWS. The migration team wants to use the AWS Application Migration Service (AWS MGN) to replicate servers continuously to a staging area and then launch test and cutover instances. The company's security policy requires that all replicated data remain encrypted with customer-managed keys and that the replication traffic never traverse the public internet. The on-premises network is already connected to a VPC through an AWS Site-to-Site VPN. Which combination of actions should the migration team take to meet these requirements?

A.Deploy AWS MGN replication agents and configure them to replicate to an Amazon S3 bucket using AWS Snowball Edge devices for the initial seed, then rely on S3 default encryption with Amazon S3 managed keys.
B.Deploy AWS MGN replication agents and use AWS DataSync to copy VM disk images to Amazon FSx for Windows File Server in the target VPC, then launch cutover instances from the file share.
C.Deploy AWS MGN replication agents and configure the replication settings to use the public AWS MGN service endpoints; enable EBS encryption with the default AWS managed key to reduce operational overhead.
D.Deploy AWS MGN replication agents, create a staging Area subnet in the target VPC, and configure the replication settings to use the Site-to-Site VPN for data replication; specify a customer-managed AWS KMS key for EBS encryption.
AnswerD

AWS MGN replication agents stream block-level data over TCP port 1500 to replication servers in the staging Area subnet. Because the VPC is reachable over the Site-to-Site VPN, replication traffic stays off the public internet, and the staging Area subnet plus the EBS encryption key selected in the replication settings satisfy the customer-managed key requirement.

Why this answer

AWS MGN replicates source servers continuously to a staging Area subnet using replication agents and lightweight replication servers, and the launch settings determine EBS encryption. Placing the staging Area subnet in the VPC reachable over the existing Site-to-Site VPN keeps replication traffic private, and selecting a customer-managed AWS KMS key in the replication template satisfies both encryption and key-ownership requirements without introducing unrelated services.

Exam trap

The trap here is assuming AWS MGN replicates through Amazon S3 or public endpoints by default, when it actually streams block data to replication servers in a staging Area subnet over TCP port 1500.

110
MCQmedium

A company is migrating a multi-tier web application to AWS. The application uses sticky sessions (session affinity). The company wants to use an Application Load Balancer (ALB). How should the architect configure the ALB to support sticky sessions?

A.Configure the ALB listener to use a custom header for session affinity.
B.Enable stickiness on the target group and set a cookie expiration duration.
C.Use a Network Load Balancer (NLB) and enable proxy protocol.
D.Place an Amazon ElastiCache cluster in front of the ALB to store session data.
AnswerB

Enabling stickiness at the target group level makes the ALB generate a duration-based cookie (AWSALB), binding each client to a single target for the configured period. This satisfies the session affinity constraint, since ALB stickiness is configured on the target group, not the listener, and the expiration duration controls how long that binding persists.

Why this answer

For an Application Load Balancer (ALB) to support sticky sessions, you enable stickiness at the target group level and configure a cookie expiration duration. ALB uses a load balancer-generated cookie (AWSALB) to track session affinity, and the duration determines how long the cookie remains valid. This is the standard, supported method for session affinity on ALB.

Exam trap

SAP-C02 often tests whether candidates know that ALB stickiness is configured on the target group (not the listener) and that NLB does not support cookie-based stickiness — a common misconception is that NLB can do it with proxy protocol.

How to eliminate wrong answers

Option A is wrong because ALB does not support custom headers for session affinity — stickiness is cookie-based, and you cannot configure a custom header for this purpose. Option C is wrong because NLB does not support sticky sessions natively (it operates at Layer 4 and does not inspect HTTP cookies); proxy protocol is for preserving client IP, not session affinity. Option D is wrong because placing ElastiCache in front of the ALB is not how you achieve sticky sessions — externalizing session state is a valid architectural pattern, but it does not configure the ALB for stickiness, and it adds unnecessary complexity.

111
MCQhard

A financial services company is migrating a mainframe COBOL application to AWS. The application writes files to a VSAM dataset and is invoked by a CICS transaction manager. The company wants to preserve business logic with minimal rewrite while moving to a managed runtime. Which migration strategy and AWS service combination best meets these requirements?

A.Repurchase a SaaS core banking product and re-implement the COBOL business logic through the vendor's configuration tools
B.Rehost the application with AWS Application Migration Service (AWS MGN) to Amazon EC2 and keep the mainframe emulator on the instance
C.Replatform the COBOL application to AWS Lambda using a custom runtime that emulates CICS transaction semantics
D.Replatform the COBOL application with AWS Mainframe Modernization using the Blu Age automated refactoring pattern, deploying to a managed runtime environment
AnswerD

AWS Mainframe Modernization provides two patterns: automated refactoring with Blu Age, which transforms COBOL and related artifacts into modern Java-based applications, and replatforming with Micro Focus. The Blu Age pattern preserves business logic while producing code that runs on a managed AWS runtime, and it handles CICS and VSAM constructs as part of the transformation. This directly matches the goal of minimal rewrite with a managed runtime.

Why this answer

AWS Mainframe Modernization is purpose-built for moving mainframe workloads, offering automated refactoring with Blu Age and replatforming with Micro Focus. The Blu Age pattern transforms COBOL, CICS, and VSAM artifacts into modern code that runs on a managed runtime, which preserves business logic and minimizes rewrite. The other approaches either cannot replicate CICS transaction semantics, cannot replicate a mainframe LPAR, or abandon the existing logic entirely.

Exam trap

The trap here is treating AWS Lambda custom runtimes as a drop-in replacement for a CICS transaction manager, when they cannot emulate pseudo-conversational state or VSAM semantics.

112
MCQhard

A company is migrating a critical application from on-premises to AWS. The application uses a Microsoft SQL Server database with Always On Availability Groups for high availability. The company wants to use Amazon RDS for SQL Server to reduce management overhead. The database size is 500 GB. The migration must have minimal downtime and support transactional consistency. The company has a VPN connection to AWS. Which migration strategy should the company use?

A.Use AWS DMS with a full-load migration and ongoing replication from the on-premises SQL Server to RDS for SQL Server.
B.Take a full backup of the database, restore it to RDS, and then schedule a final backup and restore after cutting over.
C.Use the SQL Server Import/Export Wizard to copy data from on-premises to RDS over the VPN.
D.Use AWS SCT to convert the database schema and then use AWS DMS for data migration.
AnswerA

AWS DMS full-load plus ongoing replication reads the transaction log of the on-premises SQL Server and applies changes continuously to RDS, so the cutover window stays short. This satisfies the minimal-downtime and transactional-consistency constraints for the 500 GB Always On database, with change data capture handled over the existing VPN.

Why this answer

AWS DMS with full-load plus ongoing replication (CDC) is the standard approach for migrating SQL Server to RDS with minimal downtime and transactional consistency. DMS performs an initial bulk load and then continuously replicates ongoing changes from the source to the target, allowing cutover with minimal downtime. It supports SQL Server Always On Availability Groups as a source by connecting to the listener, and it maintains transactional consistency.

Exam trap

The trap is underestimating downtime for backup/restore or overestimating the need for schema conversion; candidates must recognize that homogeneous migrations (SQL Server to SQL Server) do not require SCT and that minimal downtime demands CDC.

How to eliminate wrong answers

Option B is wrong because backup and restore requires downtime during the final backup/restore window and does not provide continuous replication, so it cannot meet the minimal downtime requirement. Option C is wrong because the Import/Export Wizard is a manual, offline process that does not support ongoing replication and would cause significant downtime. Option D is wrong because AWS SCT is for schema conversion between different database engines (e.g., Oracle to PostgreSQL); since both source and target are SQL Server, no schema conversion is needed, and SCT alone does not handle data replication.

113
MCQhard

A company is migrating a monolithic application to microservices on AWS. The application uses a shared MySQL database. The team wants to decouple the database per microservice. Which strategy should the team use to minimize downtime during migration?

A.Rehost the application on EC2 and use a single RDS MySQL instance for all microservices.
B.Use the strangler fig pattern to gradually migrate functionality to microservices, each with its own database.
C.Use AWS Database Migration Service (DMS) to replicate the shared database to multiple target databases in real time.
D.Rewrite the entire application as microservices in a single release, using a shared database initially.
AnswerB

The strangler fig pattern incrementally routes functionality from the monolith to microservices, each owning its own database, so the shared MySQL schema is decomposed gradually rather than in one cutover. This satisfies the minimal-downtime constraint, since the monolith keeps serving traffic throughout and can be retired once migration completes.

Why this answer

The strangler fig pattern allows incremental migration of functionality from a monolith to microservices, each with its own database, while the monolith continues to operate. This minimizes downtime because changes are gradual and can be rolled back. By decoupling databases per microservice over time, the team avoids a big-bang rewrite and can manage data migration carefully.

Exam trap

The trap is equating database replication with decoupling; candidates may choose DMS because it sounds like a migration tool, but it does not achieve the architectural goal of per-service databases with minimal downtime.

How to eliminate wrong answers

Option A is wrong because rehosting on EC2 with a single RDS instance does not decouple the database per microservice; it maintains the shared database, which is the opposite of the goal. Option C is wrong because using DMS to replicate the shared database to multiple targets in real time does not address the architectural decoupling; it may create data consistency issues and does not minimize downtime during the migration of functionality. Option D is wrong because rewriting the entire application in a single release is risky and likely to cause significant downtime, and using a shared database initially does not achieve decoupling.

114
MCQmedium

A company is migrating an on-premises Oracle database to Amazon Aurora PostgreSQL. The database is 10 TB and supports a critical application with a maximum allowable downtime of 30 minutes. The company wants to use AWS Database Migration Service (AWS DMS) with change data capture (CDC) to minimize downtime. After the initial full load, CDC is replicating ongoing changes. The company needs to perform the final cutover. Which sequence of steps should the company take to achieve the least downtime?

A.Stop the application, stop the DMS task, and then redirect the application to Aurora.
B.Stop the application, wait for CDC to catch up, stop the DMS task, and then redirect the application to Aurora.
C.Stop the DMS task, stop the application, and then redirect the application to Aurora.
D.Keep the application running, stop the DMS task, and then redirect the application to Aurora.
AnswerB

This sequence ensures that all changes are replicated before switching. Stopping the application prevents new writes, allowing CDC to catch up and replicate the final changes. Stopping the DMS task after catch-up ensures no data loss. Then redirecting the application to Aurora completes the cutover. This minimizes downtime to the time needed for CDC to catch up and the application switch.

Why this answer

The correct cutover process with AWS DMS and CDC involves stopping the application to prevent new writes, allowing CDC to replicate the remaining changes to Aurora, and then stopping the DMS task. This ensures data consistency. After that, the application can be redirected to Aurora.

This sequence minimizes downtime while guaranteeing no data loss.

Exam trap

The trap here is stopping the DMS task too early, before CDC has fully caught up, which leads to missing data in the target.

115
MCQmedium

A company is migrating an on-premises data warehouse to Amazon Redshift. The data warehouse contains 50 TB of data and is used for complex analytical queries. The company wants to minimize the migration time and ensure the data is available for querying as soon as possible. Which approach should the company use?

A.Use AWS Snowball Edge to transfer the data to Amazon S3, then use the COPY command to load it into Amazon Redshift.
B.Use AWS DataSync to transfer the data to Amazon EFS, then use AWS Glue to load it into Amazon Redshift.
C.Use AWS Database Migration Service (AWS DMS) to replicate the data directly from the on-premises data warehouse to Amazon Redshift.
D.Use Amazon Kinesis Data Firehose to stream the data from on-premises to Amazon Redshift.
AnswerA

AWS Snowball Edge is ideal for large data transfers, and loading into Redshift from S3 using the COPY command is the most efficient method. It parallelizes the load and minimizes migration time. This approach is cost-effective and scalable for 50 TB.

Why this answer

For large-scale data transfers, AWS Snowball Edge is the most efficient method to move data to AWS. Once the data is in Amazon S3, the COPY command in Amazon Redshift can load it in parallel, significantly reducing migration time. This approach is cost-effective and ensures the data is available for querying quickly.

Exam trap

The trap here is assuming that AWS DMS is always the best tool for database migration, but for large one-time bulk transfers, physical devices like Snowball Edge are faster and more reliable.

116
MCQeasy

A company is migrating a legacy on-premises application to AWS. The application runs on a physical server with 16 vCPUs and 64 GB RAM, and it stores data on a local SSD. The company wants to minimize changes to the application and reduce operational overhead. They plan to use a lift-and-shift approach. Which AWS service should a solutions architect recommend to migrate the server?

A.AWS Database Migration Service (AWS DMS)
B.AWS Server Migration Service (AWS SMS)
C.AWS Application Migration Service (AWS MGN)
D.AWS DataSync
AnswerC

AWS Application Migration Service (MGN) is designed for lift-and-shift migrations of physical or virtual servers to AWS. It replicates the entire server, including the operating system, applications, and data, to AWS. This minimizes changes and reduces operational overhead because the migration is automated and the application runs as-is on Amazon EC2.

Why this answer

AWS Application Migration Service (MGN) is the primary service for lift-and-shift migrations of physical or virtual servers. It replicates the entire server to AWS, allowing the application to run unchanged on EC2. This minimizes changes and operational overhead, making it ideal for the scenario.

Exam trap

The trap here is confusing AWS DataSync with a server migration service, when DataSync is only for file and object data transfer and cannot replicate an entire server.

117
MCQhard

A company is modernizing a legacy Java application to run on AWS. The application currently uses a monolithic architecture with a shared MySQL database. The company wants to adopt a microservices architecture using containers and wants to decouple the database. The solutions architect proposes using Amazon ECS with Fargate for compute and Amazon RDS for MySQL for the database. However, during the transition, the performance team notices that the database CPU utilization is consistently above 80% during peak hours. The application logs show many slow queries. The team suspects that the database is the bottleneck. The company wants to improve performance without rewriting the application. Which action should the solutions architect take first?

A.Enable Amazon RDS Performance Insights to identify the most resource-intensive queries.
B.Add an RDS read replica and direct read traffic to it.
C.Scale up the RDS instance to a larger instance type.
D.Migrate the database to Amazon DynamoDB to eliminate relational bottlenecks.
AnswerA

Performance Insights captures database load segmented by SQL statement, wait event and host, exposing which queries consume the most CPU during peaks. This identifies the bottleneck without rewriting the application, satisfying the constraint of improving performance while the monolith remains unchanged.

Why this answer

The first step to address the database bottleneck is to identify the root cause of the slow queries. Enabling Amazon RDS Performance Insights provides detailed visibility into query performance, allowing the team to pinpoint the most resource-intensive queries and their execution plans. This diagnostic information guides further optimization efforts (e.g., indexing, query rewriting, or schema changes) without requiring application code changes.

Options B and C are premature without understanding which queries are problematic; a read replica would not help if the bottleneck is write-heavy or if reads are already well-distributed, and scaling up may only mask the issue. Option D would require significant application rewriting, which contradicts the requirement to improve performance without rewriting the application.

118
Multi-Selecthard

A financial services company is migrating a legacy on-premises Java application to AWS. The application uses an Oracle database and is deployed on WebLogic Server. The company wants to modernize the application by moving to a microservices architecture on AWS. The migration must minimize downtime and ensure data consistency during the transition. Which two strategies should be used to achieve these goals? (Choose two.)

Select 2 answers
A.Implement a strangler fig pattern by gradually replacing components of the monolith with microservices, using Amazon API Gateway to route traffic between old and new components.
B.Decompose the monolith into microservices using AWS App2Container to containerize the WebLogic application, then deploy to Amazon ECS with AWS Fargate.
C.Migrate the application to AWS Elastic Beanstalk with a Tomcat platform and use AWS CodeDeploy for blue/green deployments to achieve zero downtime.
D.Use AWS Migration Hub to orchestrate the migration and AWS Server Migration Service (SMS) to replicate the WebLogic servers to Amazon EC2, then refactor in place.
E.Use AWS Database Migration Service (AWS DMS) with ongoing replication to migrate the Oracle database to Amazon Aurora PostgreSQL, and cut over when replication lag is minimal.
AnswersA, E

The strangler fig pattern allows incremental modernization by routing traffic to new microservices while the legacy monolith continues to operate. Amazon API Gateway can direct requests based on routes, enabling a gradual transition with minimal downtime and reduced risk. This supports data consistency by allowing the monolith and microservices to coexist during migration.

Why this answer

The strangler fig pattern enables incremental decomposition of the monolith into microservices, while API Gateway routes traffic, allowing coexistence and minimal downtime. AWS DMS with ongoing replication ensures the database is continuously synchronized during migration, enabling a cutover with minimal lag. Together, these strategies achieve modernization with data consistency and low downtime.

Exam trap

The trap here is assuming that containerizing the entire application with App2Container automatically modernizes it to microservices, when in fact it only packages the existing monolith into a container.

119
MCQmedium

A company is migrating its on-premises PostgreSQL database to Amazon Aurora PostgreSQL. The database is 2 TB in size and has a 24-hour maintenance window on weekends. The company needs to minimize downtime and ensure data consistency. Which strategy should the solutions architect recommend?

A.Create an Aurora read replica from the on-premises database using a VPN connection.
B.Use AWS DMS with ongoing replication from the on-premises database to Aurora, then perform a cutover during the maintenance window.
C.Use AWS Schema Conversion Tool (AWS SCT) to convert the schema and then use AWS Database Migration Service (AWS DMS) with full load only.
D.Perform a full pg_dump of the on-premises database and restore it to Aurora using pg_restore.
AnswerB

AWS DMS continuous replication keeps the target in sync while the source stays live, so only a brief cutover is needed. This satisfies the minimal-downtime requirement, and the weekend maintenance window provides the safe switchover point while preserving data consistency.

Why this answer

AWS DMS with ongoing replication (change data capture, CDC) allows the on-premises PostgreSQL database to be continuously synchronized with the target Aurora PostgreSQL cluster, minimizing downtime. When the cutover is performed during the 24-hour maintenance window, data consistency is ensured because all changes up to that point have been replicated. This approach avoids the need for a lengthy full database dump and restore, which would cause extended downtime.

Exam trap

The trap here is that candidates often assume a full dump and restore (pg_dump/pg_restore) is the simplest approach, but they overlook the massive downtime it requires for a 2 TB database, whereas DMS with CDC is designed specifically to minimize downtime for large-scale migrations.

How to eliminate wrong answers

Option A is wrong because Aurora read replicas can only be created from an existing Aurora DB cluster, not from an on-premises database; a VPN connection alone does not enable this replication. Option C is wrong because AWS SCT is used for schema conversion (not needed here since both are PostgreSQL), and a full-load-only DMS task would not capture ongoing changes, leading to data inconsistency and longer downtime. Option D is wrong because performing a full pg_dump and pg_restore would require the on-premises database to be offline for the duration of the dump and restore, causing significant downtime that exceeds the maintenance window.

120
Multi-Selecthard

A company is modernizing a legacy monolithic application by decomposing it into microservices. The application currently uses a single relational database. The company wants to migrate to a microservices architecture on AWS and needs to choose appropriate data storage strategies. The company requires that each microservice has its own database to ensure loose coupling and independent scaling. Which two strategies should the company use to achieve this? (Choose two.)

Select 2 answers
A.Use Amazon Aurora Serverless v2 for each microservice that requires a relational database, with separate clusters per service.
B.Use Amazon S3 for all microservices to store structured data as JSON objects.
C.Use Amazon DynamoDB for each microservice that requires a key-value store, with separate tables per service.
D.Use a single Amazon RDS for PostgreSQL instance with separate schemas for each microservice.
E.Use Amazon ElastiCache for Redis as the primary database for all microservices.
AnswersA, C

Amazon Aurora Serverless v2 automatically scales capacity based on demand and supports relational workloads. Deploying a separate Aurora cluster for each microservice provides database isolation and independent scaling. This aligns with the microservices pattern and allows each service to evolve its schema independently. Aurora Serverless v2 is cost-effective for variable workloads and supports PostgreSQL and MySQL compatibility.

Why this answer

To achieve a database per microservice, each service should have its own dedicated database that matches its data model. Amazon DynamoDB is suitable for key-value and document workloads, while Amazon Aurora Serverless v2 works for relational workloads. Both allow independent scaling and isolation.

Using a shared database or non-database services like S3 or ElastiCache does not meet the requirement for loose coupling and independent scaling.

Exam trap

The trap here is assuming that separate schemas on a shared database instance provide sufficient isolation; they do not, as the instance remains a shared resource.

121
MCQhard

A company is migrating a critical application to AWS and needs to ensure it meets a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 5 minutes. The application runs on EC2 with an EBS volume. Which configuration should the company use?

A.Multi-AZ deployment with synchronous replication between two instances.
B.Single EC2 instance with EBS snapshots every 5 minutes.
C.Two EC2 instances in an Auto Scaling group with a warm standby.
D.EC2 instance with Elastic Disaster Recovery service.
AnswerD

AWS Elastic Disaster Recovery continuously replicates block-level data to a staging area, achieving RPOs of seconds and typical RTOs under 15 minutes. This satisfies both constraints directly: the 5-minute RPO via continuous replication and the 15-minute RTO through automated launch of recovery instances with attached EBS volumes.

Why this answer

AWS Elastic Disaster Recovery (DRS) continuously replicates source servers (including EC2 and on-premises) to a staging area in AWS with sub-second RPO, and can launch recovery instances in minutes, meeting both the 5-minute RPO and 15-minute RTO. It supports point-in-time recovery and automated drills, making it the purpose-built DR service for these targets.

Exam trap

SAP-C02 often tests the distinction between HA (Multi-AZ, Auto Scaling) and DR (Elastic Disaster Recovery, pilot light, warm standby) — candidates pick Multi-AZ or warm standby because they sound resilient, but only DRS meets the specific 5-minute RPO with continuous replication.

How to eliminate wrong answers

Option A is wrong because Multi-AZ with synchronous replication is a high-availability pattern, not a DR pattern — it protects against AZ failure but not regional disasters, and it doesn't address RPO/RTO for the described scenario. Option B is wrong because EBS snapshots every 5 minutes are not guaranteed to complete within 5 minutes (snapshots are incremental and can take longer), and restoring from a snapshot to a running instance typically exceeds 15 minutes RTO. Option C is wrong because a warm standby in an Auto Scaling group provides HA/scaling but not continuous replication with a 5-minute RPO; data on the standby would be stale or absent without replication.

122
MCQmedium

A company is migrating 200 on-premises virtual machines running a mix of Windows and Linux workloads to AWS. The migration must complete within a tight cutover window, and the company wants to minimize manual configuration and scripting. A solutions architect needs to choose a migration approach that supports automated conversion of the source servers into Amazon EC2 instances with minimal changes. Which AWS service should the solutions architect use?

A.AWS DataSync
B.AWS Application Migration Service (AWS MGN)
C.AWS Database Migration Service (AWS DMS)
D.AWS Server Migration Service (AWS SMS)
AnswerB

AWS Application Migration Service (AWS MGN) is the primary lift-and-shift service for block-level replication and automated conversion of source servers to EC2 instances. It supports both Windows and Linux, uses a lightweight replication agent, and requires minimal manual effort because it automatically provisions staging and cutover instances. The tight cutover window is addressed by continuous replication and automated launch of test or cutover instances, which matches the requirements exactly.

Why this answer

AWS Application Migration Service is purpose-built for rehosting physical, virtual, or cloud servers to AWS. It continuously replicates source servers at the block level, then automatically launches them as EC2 instances for test or cutover. This removes the need to rebuild operating systems or applications manually, supports both Windows and Linux, and enables short cutover windows because the replication is ongoing.

The other services address data transfer or database migration, not whole-server conversion.

Exam trap

The trap here is assuming that AWS Server Migration Service is still the recommended tool for lift-and-shift server migrations, when AWS Application Migration Service is now the primary service for that use case.

123
MCQmedium

A company is migrating a legacy three-tier Java application from its on-premises data center to AWS. The application uses a proprietary in-memory session store that cannot be modified. The company wants to use AWS Application Migration Service (AWS MGN) for the migration and minimize downtime. After the initial replication, the company needs to perform a final cutover with less than 5 minutes of downtime. Which approach should the company take?

A.Use AWS MGN to replicate the servers continuously, then perform a final cutover by stopping the source servers, allowing MGN to replicate the last changes, and launching test instances.
B.Use AWS MGN to replicate the servers continuously, then perform a final cutover by stopping the source servers, letting MGN replicate the last changes, and launching cutover instances.
C.Use AWS Database Migration Service (AWS DMS) to replicate the application servers, then perform a cutover by redirecting traffic to new Amazon EC2 instances.
D.Use AWS Server Migration Service (AWS SMS) to replicate the servers, then perform a cutover by launching Amazon EC2 instances from the latest AMI.
AnswerB

AWS MGN continuously replicates source servers to a staging area. For final cutover, you stop the source servers, allow MGN to replicate the final changes, and then launch cutover instances. This minimizes downtime to the time needed for the last replication and instance launch, which can be under 5 minutes with proper preparation.

Why this answer

AWS Application Migration Service (AWS MGN) provides continuous block-level replication and enables a final cutover with minimal downtime. The correct process involves stopping the source servers, allowing MGN to replicate the last changes, and then launching cutover instances. This ensures that the migrated servers are up-to-date and ready to serve production traffic, achieving the low-downtime objective.

Exam trap

The trap here is confusing test instances with cutover instances; test instances are for validation only and do not serve production traffic.

124
MCQeasy

A company is using AWS Application Migration Service (MGN) to migrate hundreds of on-premises servers to AWS. After the migration, some servers fail a health check. What is the most efficient way to remediate the failed servers?

A.Launch test instances from MGN, diagnose the issues, then update the source servers and perform a final cutover.
B.Rerun the MGN replication and perform a new cutover.
C.Restore the servers from the latest AMI and re-run the health check.
D.Use AWS CloudEndure Migration to re-migrate the servers.
AnswerA

MGN test instances let you validate each server in AWS before cutover, so boot and health-check failures are diagnosed and fixed on the source servers first. This avoids repeated cutover attempts, making remediation efficient across hundreds of servers.

Why this answer

It follows the recommended MGN workflow for remediation: launch test instances to identify issues, fix them on the source server, and then perform a final cutover. Option B is inefficient as it restarts the entire replication and cutover process without testing. Option C is incorrect because restoring from a backup AMI is not part of the MGN migration process and does not allow iterative fixes.

Option D is wrong because CloudEndure Migration is the former name of MGN and is not a separate service for re-migration.

125
Multi-Selecthard

A company is migrating a containerized application from an on-premises Kubernetes cluster to Amazon Elastic Kubernetes Service (Amazon EKS). The application consists of multiple microservices that communicate with each other and with an on-premises database. The company wants to minimize changes to the application and ensure secure, low-latency connectivity between the EKS cluster and the on-premises database during and after the migration. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Use AWS App Mesh to manage service-to-service communication within the EKS cluster.
B.Expose the on-premises database to the internet and configure the EKS pods to connect using its public IP address.
C.Deploy the application to an Amazon EKS cluster and use AWS Direct Connect or AWS Site-to-Site VPN to connect the VPC to the on-premises network.
D.Migrate the on-premises database to Amazon RDS and update the application to use the new endpoint.
E.Configure an AWS Transit Gateway with a VPN attachment to route traffic between the VPC and the on-premises network.
AnswersC, E

Using AWS Direct Connect or AWS Site-to-Site VPN provides a private, low-latency connection between the EKS cluster's VPC and the on-premises network. This allows the containerized microservices to continue communicating with the on-premises database without exposing it to the public internet. Direct Connect offers dedicated bandwidth and consistent latency, while Site-to-Site VPN is a quicker, encrypted option. This action preserves the application's connectivity model with minimal changes.

Why this answer

The two correct actions are to establish private connectivity between the EKS VPC and the on-premises network using AWS Direct Connect or Site-to-Site VPN, and to use AWS Transit Gateway to centralize and route that traffic. These provide secure, low-latency communication to the on-premises database without exposing it to the internet or requiring application changes. The other options either address intra-cluster concerns, involve unnecessary database migration, or introduce insecure public access.

Exam trap

The trap here is focusing on service mesh or database migration instead of the hybrid network connectivity that is actually required to reach an on-premises database from Amazon EKS.

126
MCQeasy

A company is migrating an on-premises application to AWS. The application requires dedicated hardware for licensing compliance. Which AWS service should the company use to meet this requirement?

A.Amazon EC2 Dedicated Hosts
B.AWS Elastic Beanstalk
C.Amazon EC2 Reserved Instances
D.Amazon Virtual Private Cloud (VPC)
AnswerA

Amazon EC2 Dedicated Hosts provide a physical server fully dedicated to your use, giving visibility and control over socket and core allocation. This satisfies the licensing compliance constraint, since bring-your-own-licence terms tied to physical cores or sockets require dedicated hardware rather than shared tenancy.

Why this answer

Amazon EC2 Dedicated Hosts provide a physical server dedicated to a single customer, which is required for licensing compliance with certain software (e.g., Windows Server, SQL Server) that is licensed per-socket or per-core. This meets the requirement for dedicated hardware.

Exam trap

The trap is confusing Dedicated Hosts with Dedicated Instances or Reserved Instances; candidates may think that Reserved Instances provide dedicated hardware, but they only provide a billing discount, not physical isolation.

How to eliminate wrong answers

Option B is wrong because AWS Elastic Beanstalk is a PaaS service for deploying applications, not for providing dedicated hardware. Option C is wrong because EC2 Reserved Instances are a billing discount, not a dedicated hardware offering; they do not provide physical isolation. Option D is wrong because Amazon VPC is a virtual network, not a dedicated hardware service.

127
MCQeasy

A company is migrating a legacy application that uses an Oracle database to AWS. The application is critical and requires high availability with automatic failover. The company wants to use Amazon RDS for Oracle. The database size is 200 GB. The company needs a solution that provides automatic failover to a standby instance in a different Availability Zone with minimal downtime. Which RDS deployment option should the company use?

A.Multi-Region deployment with Read Replicas
B.Single-AZ deployment with Oracle Data Guard
C.Single-AZ deployment with automatic backups
D.Multi-AZ deployment
AnswerD

Multi-AZ maintains a synchronous standby replica in a second Availability Zone, so RDS performs automatic failover to it on failure, typically within one to two minutes. This satisfies the stem's demand for automatic failover with minimal downtime for the 200 GB Oracle database.

Why this answer

Amazon RDS Multi-AZ deployment maintains a synchronous standby replica in a different Availability Zone and automatically fails over to it in the event of a primary failure, with minimal downtime (typically 60-120 seconds). It requires no application changes and uses a DNS CNAME that is updated on failover. This directly meets the requirement for automatic failover to a standby in a different AZ.

Exam trap

SAP-C02 often tests the confusion between Multi-AZ (automatic failover, synchronous, same region) and Read Replicas (read scaling, asynchronous, manual promotion) — candidates pick Read Replicas for HA when Multi-AZ is required.

How to eliminate wrong answers

Option A is wrong because Multi-Region with Read Replicas is for cross-region disaster recovery and read scaling, not automatic in-region failover; Read Replicas are asynchronous and require manual promotion. Option B is wrong because Single-AZ with Oracle Data Guard is not an RDS-managed feature — RDS Multi-AZ uses its own replication, and Data Guard is for self-managed Oracle on EC2. Option C is wrong because Single-AZ with automatic backups provides point-in-time recovery but no standby instance and no automatic failover — recovery requires restoring a snapshot, causing significant downtime.

128
MCQhard

A company is migrating a large-scale Apache Kafka cluster to Amazon MSK. The cluster has 100 topics with high throughput. The team wants to minimize operational overhead and ensure high availability. Which configuration should be used?

A.Use Amazon Kinesis Data Streams with enhanced fan-out.
B.Use Amazon SQS FIFO queues with message deduplication.
C.Deploy Apache Kafka on Amazon EC2 with Spot Instances and EBS volumes.
D.Provision an Amazon MSK cluster with 3 brokers per AZ across 3 AZs.
AnswerD

Spreading three brokers per Availability Zone across three AZs gives replication factor tolerance and automatic broker failover, meeting the high-availability requirement. Distributing partitions across nine brokers also absorbs the high throughput of 100 topics while MSK manages patching and recovery, minimising operational overhead.

Why this answer

Amazon MSK is the managed Kafka service that minimizes operational overhead while providing high availability when brokers are spread across multiple Availability Zones. Provisioning 3 brokers per AZ across 3 AZs gives replication factor and rack-awareness that survive an AZ failure, and MSK handles patching, broker replacement, and monitoring. This directly matches the requirement to migrate a large Kafka cluster with minimal ops overhead and HA.

Exam trap

SAP-C02 often tests the misconception that any streaming service is interchangeable with Kafka — candidates pick Kinesis or SQS for a 'Kafka migration,' missing that only MSK preserves Kafka APIs and semantics while providing managed HA across AZs.

How to eliminate wrong answers

Option A is wrong because Kinesis Data Streams is a different service with different APIs and semantics — it is not Kafka-compatible, so migrating an existing Kafka cluster would require rewriting producers/consumers and losing Kafka features like consumer groups, topics, and partitions. Option B is wrong because SQS FIFO is a queue, not a streaming log — it lacks Kafka's topic/partition model, replay, and ordering guarantees across partitions, and FIFO throughput is limited compared to Kafka. Option C is wrong because self-managing Kafka on EC2 with Spot Instances introduces significant operational overhead and Spot interruptions risk availability — the opposite of 'minimize operational overhead and ensure high availability.'

129
MCQmedium

A company is migrating a legacy three-tier application to AWS. The application consists of a Java-based web tier, a business logic tier running on Windows Server 2012, and a Microsoft SQL Server database. The company wants to minimize changes to the application and reduce operational overhead. The business logic tier uses Windows authentication and accesses the database via integrated security. The company requires a highly available architecture across multiple Availability Zones. Which migration strategy should a solutions architect recommend?

A.Repurchase a SaaS solution that provides similar functionality, and retire the legacy application.
B.Refactor the application into microservices running on Amazon ECS, and use Amazon DynamoDB for data storage.
C.Replatform the web tier to AWS Elastic Beanstalk, rehost the business logic tier on EC2, and migrate the database to Amazon Aurora MySQL.
D.Rehost the web tier and business logic tier on Amazon EC2 instances, and migrate the database to Amazon RDS for SQL Server with Multi-AZ.
AnswerD

Rehosting the application tiers on EC2 preserves the existing Java and Windows Server 2012 environment with minimal modifications. Migrating the database to Amazon RDS for SQL Server with Multi-AZ supports Windows authentication and integrated security, and provides high availability across Availability Zones. This approach aligns with the goal of minimizing changes and reducing operational overhead by offloading database management to AWS.

Why this answer

Rehosting the application tiers on EC2 and migrating the database to RDS for SQL Server with Multi-AZ is the most suitable strategy. It preserves the existing application code and authentication mechanisms, while providing high availability and reducing operational overhead by leveraging a managed database service. This approach aligns with the rehost migration pattern and meets the requirements.

Exam trap

The trap here is assuming that replatforming to a managed service like Elastic Beanstalk or Aurora always reduces operational overhead, but it often requires code changes and may not support Windows authentication.

130
MCQmedium

A company plans to migrate a legacy on-premises web application to AWS using the 7 Rs (Rehost, Replatform, etc.). The application has tightly coupled components and unpredictable traffic. The team wants to minimize migration risk and time. Which migration strategy should they use?

A.Replatform
B.Rehost (lift-and-shift)
C.Repurchase
D.Retire
AnswerB

Rehosting moves the tightly coupled application onto Amazon EC2 unchanged, avoiding refactoring risk and delivering the fastest migration timeline. The unpredictable traffic pattern is absorbed by EC2 Auto Scaling, which adds or removes instances on demand without altering the application's internal architecture.

Why this answer

Rehost (lift-and-shift) moves the application to AWS with minimal changes, preserving the tightly coupled architecture and avoiding refactoring risk. Because the components are tightly coupled and traffic is unpredictable, re-architecting or replatforming would add time and risk. Rehost is the fastest, lowest-risk path when the goal is to minimize migration risk and time.

Exam trap

SAP-C02 often tests the trade-off between speed/risk and cloud optimization, baiting candidates toward Replatform when the question emphasizes minimal risk and time.

How to eliminate wrong answers

Option A is wrong because Replatform requires modifying the application or its dependencies (e.g., swapping a self-managed database for RDS), which adds effort and risk for a tightly coupled app. Option C is wrong because Repurchase means replacing the application with a SaaS product, which is a functional change, not a low-risk migration. Option D is wrong because Retire means decommissioning the application — the company wants to migrate it, not remove it.

131
Multi-Selectmedium

A company is migrating a critical application to AWS using a rehost (lift-and-shift) approach. The application consists of a web tier and a database tier. The company wants to ensure high availability and disaster recovery. Which TWO actions should the company take? (Choose TWO.)

Select 2 answers
A.Configure Amazon EC2 Auto Scaling to launch instances across multiple AWS Regions.
B.Deploy the web tier across multiple Availability Zones.
C.Use Amazon RDS Multi-AZ for the database tier.
D.Use Amazon RDS read replicas to offload read traffic.
E.Use a single Availability Zone for the database to reduce latency.
AnswersB, C

Spreading the web tier across multiple Availability Zones places instances behind an Application Load Balancer, so an AZ failure does not take the application offline. This satisfies the high availability and disaster recovery requirement without altering the rehosted application's architecture or code.

Why this answer

Option B is correct because deploying the web tier across multiple Availability Zones ensures that if one AZ fails, the application remains available through instances in another AZ, which is a fundamental high-availability design for a rehosted web tier on EC2. Option C is correct because Amazon RDS Multi-AZ maintains a synchronous standby replica in a different AZ and automatically fails over the database endpoint during an AZ outage or primary failure, providing high availability for the database tier. Option A is not appropriate because EC2 Auto Scaling operates within a single Region across AZs; it cannot launch instances across multiple AWS Regions, and cross-Region scaling is not a standard Auto Scaling capability.

Option D is not the best fit because read replicas are primarily for scaling read-heavy workloads and are asynchronous, so they do not provide automatic failover for high availability. Option E is incorrect because confining the database to a single AZ creates a single point of failure and undermines the disaster recovery and high availability goals.

Exam trap

SAP-C02 often tests the confusion between Multi-AZ (synchronous HA, automatic failover) and read replicas (asynchronous, read scaling/DR) — candidates pick read replicas for HA when Multi-AZ is the correct answer.

132
Multi-Selecthard

A company is migrating a high-volume transactional database from on-premises to Amazon Aurora PostgreSQL. The database uses sequences, triggers, and stored procedures. The company needs to minimize downtime during cutover and ensure data consistency. Which two actions should be taken to meet these requirements? (Choose two.)

Select 2 answers
A.Take a full database backup and restore it to Aurora PostgreSQL using native tools.
B.Use the AWS Schema Conversion Tool (AWS SCT) to convert the database schema and stored procedures.
C.Use AWS Snowball Edge to transfer the database files to Amazon S3 and then load them into Aurora.
D.Use AWS Database Migration Service (AWS DMS) with change data capture (CDC) for ongoing replication.
E.Configure Aurora PostgreSQL as a read replica of the on-premises database.
AnswersB, D

AWS SCT converts the source schema, including sequences, triggers, and stored procedures, to a format compatible with Aurora PostgreSQL. This addresses the code-level incompatibilities that would otherwise require manual rewriting. It is essential for heterogeneous migrations to ensure the target database functions correctly after cutover.

Why this answer

AWS DMS with CDC provides ongoing replication to keep the target in sync with minimal downtime, while AWS SCT converts the schema and procedural code to Aurora PostgreSQL. Together, they address both data consistency and code compatibility for a heterogeneous migration. The other options either cause downtime, are technically infeasible, or do not handle schema conversion.

Exam trap

The trap here is thinking that a native backup and restore can suffice for a heterogeneous migration, ignoring the need for schema conversion and ongoing replication.

133
MCQeasy

A company is migrating a legacy .NET application from on-premises Windows servers to AWS. The application uses Windows authentication and requires a shared file storage that supports SMB protocol. The company wants to minimize code changes and use a managed AWS service for file storage. Which AWS service should a solutions architect recommend?

A.Amazon Elastic File System (Amazon EFS)
B.Amazon S3 with S3 File Gateway
C.Amazon FSx for Windows File Server
D.Amazon FSx for Lustre
AnswerC

Amazon FSx for Windows File Server is a fully managed native Microsoft Windows file system that supports SMB protocol and integrates with Microsoft Active Directory for Windows authentication. It allows the application to continue using Windows authentication and SMB without code changes, meeting the requirements for a managed service and minimal modifications.

Why this answer

Amazon FSx for Windows File Server is the only managed AWS file storage service that natively supports SMB protocol and Microsoft Active Directory integration for Windows authentication. It enables the legacy .NET application to migrate to AWS with minimal code changes, as it can continue to use its existing authentication and file access methods.

Exam trap

The trap here is assuming that any managed file storage service can replace a Windows file server, overlooking the need for SMB protocol and Windows authentication compatibility.

134
MCQhard

A company is migrating a legacy database to Amazon RDS. The database currently runs on a single server with a 2 TB volume. The migration must have less than 30 minutes of downtime. Which approach should be used for the initial data load?

A.Use a native database dump and restore during a maintenance window
B.Use AWS Database Migration Service (DMS) with ongoing replication
C.Export the database to Amazon S3 and import into RDS using native tools
D.Create a read replica from the source database to RDS
AnswerB

DMS performs a full load then continuously replicates ongoing changes, so the cutover window stays within the 30-minute downtime limit. The 2 TB volume size is irrelevant because replication is incremental rather than a one-off copy.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication is the best approach because it allows for continuous data replication from the source to RDS, minimizing downtime to a brief cutover. The initial load can be done while the source remains active, and ongoing replication keeps the target in sync until cutover. This meets the less than 30 minutes downtime requirement.

Exam trap

The trap is underestimating the downtime of native dump/restore for large databases; candidates may pick it because it's familiar, but DMS with CDC is designed for minimal downtime.

How to eliminate wrong answers

Option A is wrong because a native dump and restore during a maintenance window would require significant downtime, likely exceeding 30 minutes for a 2 TB database. Option C is wrong because exporting to S3 and importing still requires downtime and is not a continuous replication method. Option D is wrong because creating a read replica from an on-premises database to RDS is not directly supported; DMS is the tool for this.

135
MCQhard

A company is migrating a legacy on-premises application that uses a custom TCP protocol. The application needs to be accessible from the internet while maintaining security. Which AWS service should they use to expose the application without modifying the code?

A.Amazon CloudFront
B.Network Load Balancer (NLB)
C.Amazon API Gateway
D.Application Load Balancer (ALB)
AnswerB

Network Load Balancer operates at layer 4, forwarding arbitrary TCP traffic to targets while preserving source IP, so the custom protocol works unmodified. It satisfies the no-code-change constraint and supports internet-facing exposure with TLS termination.

Why this answer

Network Load Balancer (NLB) because it operates at Layer 4 (TCP) and can handle custom TCP protocols without requiring application modifications. Option A (CloudFront) is a content delivery network that only supports HTTP/HTTPS. Option C (API Gateway) is designed for HTTP/HTTPS APIs and does not handle raw TCP traffic.

Option D (Application Load Balancer, ALB) operates at Layer 7 (HTTP/HTTPS) and cannot process custom TCP protocols.

136
Multi-Selectmedium

A company is migrating a multi-tier web application to AWS. The application consists of a web server, application server, and Oracle database. Which TWO AWS services should be used to modernize the application while reducing operational overhead?

Select 2 answers
A.Amazon RDS for Oracle
B.Amazon Lightsail
C.AWS Elastic Beanstalk
D.Amazon EC2
E.Amazon DynamoDB
AnswersA, C

Amazon RDS for Oracle is a managed service handling provisioning, patching, backups and Multi-AZ failover, removing database administration overhead. It preserves Oracle compatibility, satisfying the modernisation goal while reducing the operational burden the stem requires.

Why this answer

Amazon RDS for Oracle (A) is correct because it is a managed relational database service that supports Oracle engines, automating tasks such as provisioning, patching, backups, and Multi-AZ replication, which reduces the operational overhead of running the Oracle database tier. AWS Elastic Beanstalk (C) is correct because it provides a managed platform for deploying and scaling web and application server tiers, handling capacity provisioning, load balancing, and application health monitoring so the company can modernize without managing underlying infrastructure. Amazon Lightsail (B) is not appropriate because it is a simplified VPS offering aimed at small, simple workloads and does not provide the managed multi-tier or Oracle capabilities needed here.

Amazon EC2 (D) is not the best choice because it requires the company to manage the operating system, patching, scaling, and database operations itself, increasing operational overhead. Amazon DynamoDB (E) is incorrect because it is a NoSQL key-value/document database and cannot replace the existing Oracle relational database workload.

Exam trap

SAP-C02 often tests the misconception that EC2 or Lightsail reduce operational overhead, when in fact managed services like RDS and Elastic Beanstalk are required to offload patching, scaling, and backups.

137
MCQhard

A company wants to migrate a legacy Oracle database to AWS with minimal downtime. The database is 2 TB in size and runs on a single on-premises server. The company requires the ability to cut over quickly and roll back if needed. Which AWS service should be used?

A.Use S3 Transfer Acceleration to upload the database dump directly to an EC2 instance.
B.AWS Database Migration Service (DMS) with ongoing replication from the source to an Amazon RDS for Oracle target.
C.AWS Schema Conversion Tool (SCT) to convert the schema and then export the data to flat files for import.
D.AWS Snowball Edge to copy the database files and then restore on Amazon RDS.
AnswerB

DMS with ongoing replication keeps the RDS for Oracle target continuously synchronised, so cutover needs only a brief application switch, and the source remains intact for rollback. This satisfies the minimal-downtime and quick-rollback constraints for the 2 TB database.

Why this answer

AWS Database Migration Service (DMS) with ongoing replication enables continuous data replication from the on-premises Oracle database to Amazon RDS for Oracle, allowing minimal downtime during cutover. It also supports rollback by stopping replication and reverting to the source. Option A is incorrect because S3 Transfer Acceleration is for fast uploads to S3, not for database migration with replication.

Option C is incorrect because AWS Schema Conversion Tool (SCT) handles schema conversion, not ongoing data replication. Option D is incorrect because AWS Snowball Edge is an offline data transfer device, which does not meet the minimal downtime requirement.

Exam trap

Candidates may think Snowball Edge is suitable for very large databases, but for minimal downtime requirements, an online replication service like DMS is necessary.

138
MCQeasy

A company plans to migrate its on-premises VMware VMs to AWS. The company wants to automate the migration of VM images and minimize manual effort. Which AWS service should the company use?

A.AWS VM Import/Export
B.AWS DataSync
C.AWS Application Migration Service (MGN)
D.AWS Database Migration Service (DMS)
AnswerC

AWS Application Migration Service replicates source servers block-by-block into AWS, then launches test or cutover instances automatically. This agent-based continuous replication removes manual image conversion, satisfying the requirement to automate VMware VM migration and minimise manual effort.

Why this answer

AWS Application Migration Service (MGN) is the correct choice because it automates the migration of on-premises server volumes (including VMware VMs) to AWS with minimal manual effort. It provides continuous, block-level replication and simplifies large-scale migrations. MGN is the modern successor to AWS Server Migration Service (SMS).

AWS VM Import/Export (Option A) is a one-time import tool requiring manual steps. AWS DataSync (Option B) is for file and object transfers, not VM images. AWS DMS (Option D) is for databases.

Therefore, MGN (Option C) is the service that best meets the requirement.

Exam trap

A common pitfall is choosing AWS VM Import/Export because it is a familiar VM import tool, but it lacks automation. The correct service for automated server migration is now AWS Application Migration Service (MGN), which has replaced SMS.

139
MCQhard

A company is migrating a critical application to AWS using the 7 Rs migration strategy. The application is tightly coupled with legacy infrastructure and has compliance requirements that prevent any code changes. The migration must be completed in 3 months. Which strategy is most appropriate?

A.Retain the application on-premises and use AWS Storage Gateway for backup.
B.Rehost using AWS Application Migration Service (MGN) and Amazon EC2.
C.Replatform to use Amazon RDS for MySQL.
D.Refactor into microservices on Amazon ECS.
AnswerB

Rehosting with AWS Application Migration Service lifts and shifts servers to Amazon EC2 without modifying code, satisfying the no-code-change compliance constraint. Block-level replication keeps the source running during cutover, enabling completion within the three-month window despite tight legacy coupling.

Why this answer

Rehosting (lift-and-shift) using AWS Application Migration Service (MGN) and EC2 meets the no-code-change requirement and can be completed within 3 months. Option A is wrong because retaining the application on-premises does not migrate it to AWS, failing the migration goal. Option C is wrong because replatforming to Amazon RDS would likely require code changes (e.g., database drivers, queries), violating the no-code-change constraint.

Option D is wrong because refactoring into microservices requires significant code changes and is too time-consuming for the 3-month timeline.

140
MCQhard

A company is migrating a legacy .NET Framework 4.7 application to AWS. The application uses Windows authentication and COM+ components. Which migration approach is most suitable?

A.Replatform to .NET Core on AWS Elastic Beanstalk (Linux)
B.Use Windows containers on Amazon ECS with Amazon ECS-optimized Windows Server AMI
C.Refactor to run on AWS Lambda with .NET Core 3.1
D.Containerize with Linux containers on Amazon ECS
AnswerB

Windows containers on Amazon ECS with the ECS-optimised Windows Server AMI preserve .NET Framework 4.7, Windows authentication and COM+ registration, which Linux containers cannot host. This satisfies the constraint of running COM+ components without rewriting the application.

Why this answer

Windows containers on Amazon ECS with the ECS-optimized Windows Server AMI support .NET Framework applications and COM+ components, making them the most suitable migration approach. Option A is incorrect because replatforming to .NET Core on Linux would require significant code changes and does not support COM+. Option C is incorrect because AWS Lambda does not support full .NET Framework or COM+.

Option D is incorrect because Linux containers cannot run Windows-based .NET Framework applications.

141
MCQmedium

A company is migrating a web application from on-premises to AWS. The application consists of a stateless web tier and a stateful application tier that stores session data in a local file system. The company wants to use AWS Elastic Beanstalk for both tiers. During a test migration, the development team notices that users are being logged out intermittently. The application tier is configured with two EC2 instances behind an internal load balancer. What should the development team do to resolve the issue?

A.Enable sticky sessions (session affinity) on the application tier's load balancer.
B.Move session storage to Amazon ElastiCache for Redis and configure the application to use it.
C.Increase the number of instances in the web tier to reduce the load on the application tier.
D.Store session data in Amazon DynamoDB.
AnswerB

ElastiCache for Redis externalises session state, so both EC2 instances behind the load balancer read the same session data. This eliminates the intermittent logouts caused by the load balancer routing users to an instance lacking their locally stored session.

Why this answer

The issue is that session data is stored locally on each application instance. When traffic is distributed by the internal load balancer, subsequent requests from the same user may go to a different instance, losing the session data. The best practice is to use a centralized session store like Amazon ElastiCache for Redis.

This ensures session data persists across all instances. Option A (sticky sessions) would cause load imbalance and is not recommended for high availability. Option C does not address session storage.

Option D (DynamoDB) is possible but not as performant for session storage and requires more custom code; Redis is the recommended service for session management.

142
MCQmedium

A company is migrating a legacy .NET application from on-premises Windows Server to AWS. The application uses Windows authentication and requires a shared file share for configuration files. The company wants to minimize code changes. Which combination of AWS services should be used?

A.Amazon WorkSpaces for application hosting, and Amazon FSx for Lustre for configuration files.
B.Amazon ECS with Windows containers, and Amazon EFS for configuration files.
C.Amazon EC2 Windows instances joined to AWS Managed Microsoft AD, and Amazon FSx for Windows File Server.
D.AWS Lambda with .NET Core, and Amazon S3 for configuration files.
AnswerC

Amazon EC2 Windows instances can be domain-joined to AWS Managed Microsoft AD, enabling Windows authentication. Amazon FSx for Windows File Server provides a fully managed Windows file share that supports SMB protocol and integrates with Active Directory, meeting the shared file share requirement with minimal changes.

Why this answer

To minimize code changes, the application should run on EC2 Windows instances that are domain-joined to AWS Managed Microsoft AD, which provides Windows authentication. Amazon FSx for Windows File Server offers a managed SMB file share that integrates with Active Directory, replacing the on-premises file share without application modifications. This combination preserves the existing authentication and file access mechanisms.

Exam trap

The trap here is assuming that any file storage service can replace a Windows file share, but only Amazon FSx for Windows File Server supports SMB and Active Directory integration required for Windows authentication.

143
MCQmedium

A company is migrating a containerized application to AWS. The application consists of multiple microservices that communicate over HTTP. The company wants to minimize operational overhead and automatically scale the services based on demand. Which AWS service should be used?

A.Amazon EKS with self-managed worker nodes
B.Amazon EC2 instances with Docker installed and an Auto Scaling group
C.AWS Lambda functions for each microservice
D.Amazon ECS with Fargate launch type
AnswerD

Amazon ECS with Fargate allows you to run containers without managing servers, reducing operational overhead. It supports service auto scaling based on metrics like CPU utilization or request count. It integrates with Application Load Balancers for HTTP traffic, making it ideal for microservices communication.

Why this answer

Amazon ECS with Fargate provides a serverless compute engine for containers, eliminating the need to manage servers. It supports auto scaling and integrates with load balancers for HTTP communication. This aligns with the goals of minimizing operational overhead and scaling based on demand.

Exam trap

The trap here is assuming that AWS Lambda is a suitable replacement for containerized microservices without considering the need for long-running processes and container dependencies.

144
MCQmedium

A company is migrating a legacy monolithic application to AWS. The application has a stateful session layer that uses local disk storage. The migration plan involves rehosting the application on Amazon EC2 instances. What architecture change should the company implement to ensure high availability and stateless application tiers?

A.Store session data in Amazon S3 with Transfer Acceleration.
B.Use Amazon RDS with Multi-AZ to store session data.
C.Use Amazon ElastiCache for session state management.
D.Attach Amazon EBS volumes to each EC2 instance for session persistence.
AnswerC

Storing session state in Amazon ElastiCache (Redis or Memcached) externalises it from instance local disk, so any EC2 instance in the Auto Scaling group can serve any request. This removes the stateful constraint, letting the tier scale horizontally and survive instance failure behind a load balancer.

Why this answer

Moving session state to Amazon ElastiCache (Redis or Memcached) externalizes the stateful layer so EC2 instances become stateless and can be placed behind an ELB/ALB with Auto Scaling. This enables any instance to serve any request, supports horizontal scaling, and survives instance failure without losing sessions. ElastiCache provides the low-latency, in-memory access pattern that session lookups require.

Exam trap

SAP-C02 often tests whether candidates confuse 'externalizing state' with 'making the tier stateless' — RDS externalizes state but is the wrong performance fit, and EBS keeps state local, so only ElastiCache satisfies both statelessness and low-latency session access.

How to eliminate wrong answers

Option A is wrong because S3 is object storage with high latency (tens to hundreds of milliseconds) and is not designed for the high-frequency, low-latency read/write pattern of session state; Transfer Acceleration speeds uploads, not session lookups. Option B is wrong because RDS Multi-AZ provides database high availability, not a session store — using a relational DB for session state adds latency, connection overhead, and does not make the app tier stateless in the intended sense (though it does externalize state, it is the wrong tool for the performance requirement). Option D is wrong because attaching EBS volumes to each instance keeps session data tied to a specific instance, so if that instance fails or is replaced by Auto Scaling, the session is lost — this preserves statefulness and defeats high availability.

145
MCQhard

A company is modernizing a legacy application by refactoring it into microservices. The application uses a monolithic Oracle database. The team wants to use Amazon RDS for Oracle as the migration target. Which migration approach minimizes risk and downtime?

A.Create a new RDS instance and use AWS SCT to convert the schema, then cutover after testing.
B.Use the strangler fig pattern to incrementally migrate functionality to new microservices, each with its own database.
C.Migrate the entire database at once using AWS DMS with ongoing replication.
D.Rewrite the application as microservices on AWS and then migrate the database.
AnswerB

The strangler fig pattern routes traffic incrementally from the monolith to new microservices, each owning its own database, so the Oracle monolith keeps running until features are fully migrated. This satisfies the minimise-risk-and-downtime constraint by avoiding a single cutover event.

Why this answer

The strangler fig pattern allows incremental migration of functionality from a monolith to microservices, reducing risk and downtime because each service can be migrated and tested independently while the monolith continues to operate. This approach aligns with modernizing a legacy application by refactoring into microservices, each with its own database, which avoids a big-bang cutover. It minimizes risk by allowing rollback and gradual validation, and minimizes downtime because the legacy system remains available during the transition.

Exam trap

The trap is equating 'minimizes risk and downtime' with a single migration tool like AWS DMS or SCT; candidates may overlook that incremental refactoring via the strangler fig pattern is the lowest-risk approach for modernizing a monolith.

How to eliminate wrong answers

Option A is wrong because using AWS SCT to convert the schema and then cutting over after testing is a lift-and-shift approach that does not refactor into microservices; it also risks downtime during cutover and does not address the architectural modernization goal. Option C is wrong because migrating the entire database at once with AWS DMS, even with ongoing replication, is a big-bang migration that does not refactor the application into microservices and can introduce significant risk. Option D is wrong because rewriting the application as microservices and then migrating the database is essentially a big-bang rewrite, which is high-risk and does not minimize downtime or risk incrementally.

146
MCQhard

A company is migrating a monolithic application to AWS and wants to modernize it into microservices. The application currently uses a single relational database. Which migration strategy is most appropriate to minimize risk while starting the modernization process?

A.Incremental migration using the Strangler Fig pattern
B.Big bang migration of the entire application to containers
C.Replatform to Amazon RDS for MySQL
D.Rehost the application using AWS VM Import/Export
AnswerA

The Strangler Fig pattern incrementally extracts functionality from the monolith behind a facade, routing traffic to new microservices while the legacy application keeps running. This limits blast radius and lets the team modernise gradually without a risky big-bang rewrite.

Why this answer

The Strangler Fig pattern (Option A) is the most appropriate strategy because it allows incremental replacement of monolithic components with microservices, reducing the risk associated with a full rewrite or big bang migration. Option B (big bang migration to containers) is risky as it requires simultaneous migration of all components. Option C (replatform to Amazon RDS) only changes the database platform without addressing application architecture.

Option D (rehost using VM Import/Export) simply lifts and shifts the monolith without modernization.

147
MCQmedium

A company is migrating a critical application to AWS and needs to ensure high availability across two Availability Zones. The application runs on EC2 instances behind an Application Load Balancer (ALB). The database is an on-premises SQL Server that will be migrated later. Which architecture provides high availability for the application tier during the migration?

A.Deploy EC2 instances in two AZs behind an ALB with cross-zone load balancing enabled.
B.Deploy EC2 instances in a single AZ with an Auto Scaling group.
C.Deploy EC2 instances in two AZs behind a Network Load Balancer (NLB).
D.Use Amazon Route 53 weighted routing to distribute traffic to instances in two AZs.
AnswerA

Instances in two Availability Zones behind an ALB survive an AZ failure, and cross-zone load balancing distributes requests evenly to healthy targets in the remaining zone. This delivers application-tier high availability during the migration, independent of the on-premises SQL Server still in place.

Why this answer

Deploying EC2 instances in two Availability Zones behind an Application Load Balancer with cross-zone load balancing enabled provides high availability for the application tier. The ALB distributes traffic across healthy instances in both AZs, and cross-zone load balancing ensures even distribution even if one AZ has more instances. This architecture survives an AZ failure because the ALB routes traffic to the remaining AZ, and the application remains available.

Exam trap

The trap is confusing high availability with auto scaling or DNS-based routing; candidates may pick a single-AZ Auto Scaling group or Route 53 weighted routing, but true high availability across AZs requires a load balancer with cross-zone enabled.

How to eliminate wrong answers

Option B is wrong because deploying instances in a single AZ with an Auto Scaling group does not provide high availability across AZs; an AZ failure would take down all instances. Option C is wrong because a Network Load Balancer (NLB) operates at Layer 4 and does not provide the same HTTP/HTTPS-aware routing as an ALB; while it can be used, the question specifies an ALB is already in use, and NLB is not the best fit for application-tier high availability with HTTP. Option D is wrong because Route 53 weighted routing distributes traffic at the DNS level but does not provide health checks and failover as robustly as an ALB; it also does not ensure high availability within the application tier itself.

148
MCQmedium

A company is migrating a legacy application to AWS using the 7 Rs migration strategy. The application is a monolithic Java application running on a single on-premises server with a MySQL database. The company wants to reduce operational overhead and improve scalability. The development team has already containerized the application and tested it locally. The company wants to run the containerized application on AWS without managing the underlying infrastructure. Which AWS service should the company use to deploy the containerized application?

A.Amazon ECS with AWS Fargate launch type
B.Amazon EKS with managed node groups
C.Amazon EC2 with Docker installed
D.Amazon Lightsail containers
AnswerA

Amazon ECS with the Fargate launch type runs containers serverlessly, so no EC2 instances need provisioning, patching or scaling. This directly satisfies the stem's requirement to avoid managing underlying infrastructure while improving scalability, and it suits the already-containerised Java application without code changes.

Why this answer

Amazon ECS with AWS Fargate launch type is a serverless compute engine for containers, eliminating infrastructure management. Option B (EKS with managed node groups) still requires managing the node groups at the EC2 level. Option C (EC2 with Docker) requires managing EC2 instances.

Option D (Lightsail containers) is not as scalable or integrated with AWS services as ECS with Fargate.

149
MCQeasy

A company is planning to migrate a Microsoft SQL Server database to Amazon RDS for SQL Server. They want to automate the migration process and minimize manual effort. Which AWS service should they use?

A.AWS CloudEndure Migration
B.AWS DataSync
C.AWS Database Migration Service (DMS)
D.AWS Schema Conversion Tool (SCT)
AnswerC

DMS performs continuous, automated data replication between heterogeneous or homogeneous engines, including SQL Server to RDS for SQL Server, using change data capture to keep source and target synchronised. This directly satisfies the requirement to automate the migration and minimise manual effort, rather than scripting backups or native restore.

Why this answer

AWS DMS can migrate SQL Server to RDS with minimal downtime. Option A is wrong because CloudEndure Migration is for server migration. Option B is wrong because DataSync is for file data.

Option D is wrong because Schema Conversion Tool is for schema conversion.

150
MCQmedium

A company is migrating 50 on-premises VMware virtual machines to AWS. The migration must complete within a four-week maintenance window, and the company wants to minimize application changes. The VMs run a mix of Windows and Linux. Which AWS service should the company use to migrate these VMs to Amazon EC2?

A.AWS Database Migration Service (AWS DMS)
B.AWS Application Migration Service (AWS MGN)
C.AWS Server Migration Service (AWS SMS)
D.AWS DataSync
AnswerB

AWS Application Migration Service (AWS MGN) performs agent-based, block-level replication of source servers into a staging area in AWS, then launches test or cutover instances on EC2. It supports both Windows and Linux, requires no application changes, and is designed for large-scale lift-and-shift migrations within tight cutover windows, making it appropriate for this scenario.

Why this answer

AWS Application Migration Service (MGN) is purpose-built for lift-and-shift migrations of physical, virtual, or cloud servers to EC2. It supports Windows and Linux, uses block-level replication, and enables test launches and cutover with minimal downtime. The other services address data-only movement or legacy tooling, not full server migration.

Exam trap

The trap here is assuming that AWS Server Migration Service is still the recommended tool for VM migrations, when AWS now directs new migrations to AWS Application Migration Service.

← PreviousPage 2 of 4 · 235 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Accelerate Workload Migration and Modernization questions.