Courseiva

CCNA Design for New Solutions Questions

75 of 321 questions · Page 1/5 · Design for New Solutions · Answers revealed

1
MCQeasy

A company is designing a new microservices-based application on AWS. They need to decouple services and ensure asynchronous communication. Which AWS service should they use?

A.Amazon Kinesis
B.Amazon SQS
C.AWS Lambda
D.Amazon SNS
AnswerB

Amazon SQS provides fully managed queues that decouple producers from consumers, letting microservices communicate asynchronously without direct invocation. This satisfies the asynchronous communication requirement, since messages persist durably until a consumer polls and processes them, absorbing traffic spikes and service failures.

Why this answer

Amazon SQS (Simple Queue Service) is the correct choice because it provides a fully managed message queue that enables asynchronous communication between microservices. By decoupling the components, SQS allows one service to send messages to a queue, and another service to poll and process those messages independently, ensuring fault tolerance and scalability without requiring both services to be available simultaneously.

Exam trap

The trap here is that candidates often confuse Amazon SNS (pub/sub) with SQS (queue), thinking both provide decoupling, but SNS requires subscribers to be active or integrated with a queue, whereas SQS inherently buffers messages for asynchronous consumption.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis is designed for real-time streaming data ingestion and processing (e.g., log streams, clickstreams), not for decoupling point-to-point asynchronous messaging between microservices; it uses shards and records, not queues with individual message visibility. Option C is wrong because AWS Lambda is a compute service that runs code in response to events, not a messaging or decoupling service; it can be a consumer or producer but does not itself provide a queue for asynchronous communication. Option D is wrong because Amazon SNS is a pub/sub messaging service that pushes messages to multiple subscribers (fan-out), but it does not provide a queue for decoupling—subscribers must be available or use a queue integration; SNS alone does not offer the buffering and polling model needed for true asynchronous decoupling.

2
MCQeasy

A company is designing a new CI/CD pipeline for a web application that will be deployed on Amazon ECS. Which AWS service should the company use to build and test the application code?

A.AWS CodePipeline
B.AWS CodeDeploy
C.AWS CodeCommit
D.AWS CodeBuild
AnswerD

AWS CodeBuild is a fully managed build service that compiles source code, runs unit tests, and produces deployable artefacts, integrating natively with CodePipeline and ECS. This satisfies the requirement to build and test the application code within the CI/CD pipeline.

Why this answer

AWS CodeBuild is a fully managed continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy. For a CI/CD pipeline that requires building and testing application code before deployment to Amazon ECS, CodeBuild is the correct service to perform these build and test actions.

Exam trap

The trap here is that candidates often confuse AWS CodePipeline (the orchestration layer) with the actual build service, mistakenly thinking that CodePipeline itself performs the build and test steps, when in fact it only coordinates other services like CodeBuild.

How to eliminate wrong answers

Option A is wrong because AWS CodePipeline is a continuous delivery service that orchestrates the pipeline stages (source, build, test, deploy) but does not itself build or test code; it relies on other services like CodeBuild for those actions. Option B is wrong because AWS CodeDeploy is a deployment service that automates code deployments to compute services (including ECS) but does not perform build or test operations. Option C is wrong because AWS CodeCommit is a source control service that hosts Git repositories and does not have any capability to build or test application code.

3
MCQeasy

A company is migrating a monolithic application to a microservices architecture on AWS. They want to decouple the services and ensure that messages between services are processed asynchronously and durably. Which AWS service should they use for this purpose?

A.Amazon Kinesis Data Streams
B.Amazon Simple Queue Service (SQS)
C.Amazon Simple Notification Service (SNS)
D.AWS Step Functions
AnswerB

Amazon SQS provides durable, fully managed message queues that decouple microservice producers from consumers, satisfying the asynchronous processing requirement. Messages persist across multiple Availability Zones until successfully processed, and standard queues offer at-least-once delivery at scale. This directly meets the stem's need for durable, asynchronous inter-service communication without managing brokers.

Why this answer

Amazon SQS is a fully managed message queue service designed for asynchronous, durable message passing between decoupled components. It stores messages redundantly across multiple Availability Zones, supports at-least-once delivery, and allows producers and consumers to operate independently — exactly matching the requirement for durable asynchronous processing in a microservices architecture.

Exam trap

SAP-C02 often tests whether candidates confuse SNS (push-based pub/sub, no durable storage) with SQS (pull-based queue, durable storage), causing them to pick SNS when the requirement explicitly says messages must be processed durably and asynchronously.

How to eliminate wrong answers

Option A is wrong because Kinesis Data Streams is optimized for real-time streaming and analytics with ordered shards, not for general-purpose durable message decoupling between microservices; it requires more operational overhead and is not a simple queue. Option C is wrong because SNS is a pub/sub fan-out service that pushes notifications to subscribers but does not store messages durably for later retrieval — if a subscriber is unavailable, the message is lost (unless paired with SQS). Option D is wrong because Step Functions is a workflow orchestration service for coordinating stateful, multi-step processes, not a message queue for decoupling services.

4
MCQhard

A solutions architect is reviewing the above IAM policy attached to an S3 bucket. A user from IP address 10.0.1.5 makes a request over HTTP (not HTTPS). Will the user be able to download an object?

A.No, because the IP address is not in the allowed range.
B.Yes, because the IP address is allowed.
C.No, because the request is not using HTTPS.
D.Yes, because the Allow statement is evaluated first.
AnswerC

The policy's explicit Deny for `aws:SecureTransport: false` overrides any Allow, so the HTTP request from 10.0.1.5 is blocked regardless of source IP. AWS evaluates Deny first, making the insecure transport condition the decisive constraint that prevents the object download.

Why this answer

The IAM policy includes a condition that requires requests to use HTTPS (aws:SecureTransport = true). Since the user's request is over HTTP, the condition fails, and the Allow statement does not apply. Therefore, the request is denied by default, and the user cannot download the object.

Exam trap

SAP-C02 often tests the misconception that if an IP address is allowed, access is granted regardless of other conditions, but the trap is forgetting that all conditions in a statement must be satisfied for the Allow to take effect.

How to eliminate wrong answers

Option A is wrong because the IP address 10.0.1.5 is within the allowed range 10.0.0.0/16, so the IP condition is satisfied. Option B is wrong because although the IP is allowed, the HTTPS condition is not met, so the overall Allow statement does not apply. Option D is wrong because IAM policy evaluation does not simply evaluate Allow statements first; all conditions must be satisfied for an Allow to take effect, and explicit Deny statements override Allow.

5
MCQmedium

A company is migrating a monolithic application to microservices on Amazon ECS. The application needs to communicate with external partners via HTTPS. The company wants to use mTLS for mutual authentication. Which AWS service should be used to handle the mTLS termination?

A.Application Load Balancer (ALB) with mutual TLS
B.Amazon CloudFront with a custom origin
C.Network Load Balancer (NLB) with TLS termination
D.Amazon API Gateway HTTP API
AnswerA

ALB supports mutual TLS termination natively, validating client certificates against a trust store before forwarding traffic. This satisfies the mutual authentication requirement for partner HTTPS connections without running certificate handling on the ECS tasks themselves, simplifying the microservice architecture.

Why this answer

Application Load Balancer (ALB) supports mutual TLS (mTLS) natively by configuring a trust store on the listener that validates client certificates against a Certificate Authority (CA) bundle you upload. This allows the ALB to terminate the HTTPS connection and perform client certificate authentication before forwarding traffic to the ECS service, meeting the requirement for mTLS termination without custom proxy logic.

Exam trap

The trap here is confusing ALB mTLS with NLB TLS termination or assuming API Gateway HTTP API supports mTLS, when in fact only ALB and API Gateway REST API (not HTTP API) offer mutual TLS termination for incoming client connections.

How to eliminate wrong answers

Option B is wrong because Amazon CloudFront does not support mTLS; it can only present client certificates to origins (origin-facing mTLS) but cannot terminate incoming mTLS connections from clients. Option C is wrong because Network Load Balancer (NLB) with TLS termination only validates server certificates and does not support client certificate authentication (mTLS) at the listener level. Option D is wrong because Amazon API Gateway HTTP API does not support mTLS; only API Gateway REST API supports mTLS via mutual TLS authentication, but the HTTP API variant lacks this feature.

6
MCQmedium

A company runs a critical two-tier application on AWS. The web tier consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The database tier is a single Amazon RDS for MySQL instance. The company wants to improve the availability of the database tier so that it can survive an Availability Zone failure with minimal downtime and no data loss. The application uses the RDS endpoint in its configuration. What should a solutions architect recommend?

A.Create a read replica in another Availability Zone and update the application to use the read replica endpoint.
B.Enable a Multi-AZ deployment for the RDS instance.
C.Enable RDS automated backups with a longer retention period and restore from a snapshot in another Availability Zone if a failure occurs.
D.Migrate the database to an Amazon DynamoDB table with global tables enabled.
AnswerB

Multi-AZ creates a synchronous standby replica in a different Availability Zone. The primary endpoint automatically fails over to the standby during an AZ outage, with no data loss because replication is synchronous. The application continues to use the same endpoint, so no configuration change is required. This meets the requirements of minimal downtime and no data loss.

Why this answer

A Multi-AZ deployment maintains a synchronous standby in a separate Availability Zone. During an AZ failure, RDS automatically fails over to the standby, and the application continues to use the same endpoint. Because replication is synchronous, no committed data is lost.

This provides high availability with minimal downtime and zero data loss, satisfying the requirements without application changes.

Exam trap

The trap here is assuming that a read replica provides automatic failover and zero data loss, when in fact read replicas use asynchronous replication and require manual promotion.

7
Multi-Selecthard

A company is designing a new application that will process streaming data from thousands of IoT devices. The data must be ingested in real time and then processed using Apache Flink. Which services should be used? (Choose TWO.)

Select 2 answers
A.Amazon Kinesis Data Streams
B.AWS Lambda
C.Amazon Kinesis Data Analytics for Apache Flink
D.Amazon Kinesis Data Firehose
E.Amazon Simple Queue Service (SQS)
AnswersA, C

Amazon Kinesis Data Streams ingests thousands of IoT device events in real time with low latency and high throughput, satisfying the stem's real-time ingestion constraint. It integrates natively with Apache Flink through the Kinesis connector, letting Flink consume the stream directly for processing without intermediate storage or batch staging.

Why this answer

Amazon Kinesis Data Streams (A) is correct because it provides a highly scalable, real-time ingestion service that can capture data from thousands of IoT devices with low latency, making it ideal for streaming ingestion. Amazon Kinesis Data Analytics for Apache Flink (C) is correct because it is the managed service that runs Apache Flink applications to process and analyze streaming data in real time, directly integrating with Kinesis Data Streams as a source. AWS Lambda (B) is not designed for continuous stream processing with Apache Flink and is better suited for event-driven, short-lived functions.

Amazon Kinesis Data Firehose (D) is primarily for loading streaming data into destinations like S3, Redshift, or Elasticsearch, not for running Flink processing. Amazon SQS (E) is a message queue for decoupling components, not a real-time streaming ingestion or Flink processing service.

Exam trap

The trap here is that candidates often confuse Kinesis Data Firehose with Kinesis Data Streams, not realizing that Firehose is a delivery service that does not support Apache Flink's requirement for per-record replay and checkpointing, while Data Streams provides the necessary persistent, ordered stream.

8
MCQmedium

Refer to the exhibit. A company has an IAM policy that allows s3:GetObject on all objects in 'my-bucket' but denies access to objects in the 'confidential' folder. A user tries to access 's3://my-bucket/confidential/report.pdf'. What will happen?

A.Access is denied because the Deny statement explicitly matches the resource.
B.Access is allowed because the Deny statement is not evaluated.
C.Access is denied only if the user is not authorized by other policies.
D.Access is allowed because the Allow statement is broader.
AnswerA

The explicit Deny statement matches the resource `arn:aws:s3:::my-bucket/confidential/*`, and AWS evaluates explicit denies before allows, so the request is refused regardless of the broader s3:GetObject Allow. This satisfies the stem's constraint that the confidential folder must remain inaccessible to the user.

Why this answer

In AWS IAM, an explicit Deny always overrides any Allow. The policy denies access to objects in the 'confidential' folder, and the user's request matches that resource. Therefore, access is denied regardless of the Allow statement.

Exam trap

SAP-C02 often tests the IAM policy evaluation logic, and candidates may incorrectly assume that an Allow statement with broader permissions can override an explicit Deny, or that Deny statements are only evaluated if no Allow exists.

How to eliminate wrong answers

Option B is wrong because the Deny statement is evaluated and takes precedence. Option C is wrong because an explicit Deny in any policy overrides any Allow, even if other policies authorize the action. Option D is wrong because the Allow statement does not override an explicit Deny.

9
Multi-Selectmedium

A company is designing a microservices architecture using Amazon ECS with Fargate. The services need to communicate with each other. The company wants to implement service discovery and load balancing at the application layer. Which TWO services should the company use?

Select 2 answers
A.Amazon API Gateway
B.Network Load Balancer (NLB)
C.AWS Cloud Map
D.Application Load Balancer (ALB)
E.Amazon Route 53
AnswersC, D

AWS Cloud Map provides service discovery for ECS tasks, registering each task's IP address and health status in a namespace so callers resolve healthy endpoints directly. This satisfies the stem's service-discovery requirement for Fargate microservices, where tasks lack stable addresses and no load balancer is needed for discovery itself.

Why this answer

AWS Cloud Map (C) is correct because it provides service discovery for ECS services, allowing microservices to register and discover each other via DNS names or API calls, which is essential for dynamic Fargate tasks. Application Load Balancer (D) is correct because it operates at the application layer (Layer 7) and supports HTTP/HTTPS routing, making it suitable for load balancing microservices traffic. Network Load Balancer (B) is not correct because it works at Layer 4 (TCP/UDP) and does not provide application-layer load balancing.

Amazon API Gateway (A) is not correct because it is primarily for exposing APIs to external clients, not for internal service-to-service communication. Amazon Route 53 (E) is not correct because it is a DNS service, not a service discovery or application-layer load balancing solution for ECS tasks.

Exam trap

The trap here is that candidates often confuse Network Load Balancer (NLB) as an application-layer solution because it can handle TLS termination, but it operates at Layer 4 and lacks the HTTP-aware routing required for application-layer communication.

10
MCQmedium

A company is designing a new application that requires a relational database with automated backups and multi-AZ redundancy. The database workload is predictable with occasional read replicas for reporting. Which AWS service should be used?

A.Amazon RDS
B.Amazon Redshift
C.Amazon DynamoDB
D.Amazon ElastiCache
AnswerA

Amazon RDS provides automated backups and Multi-AZ standby replication with automatic failover, satisfying both redundancy requirements. Read replicas offload reporting queries from the primary, matching the predictable workload with occasional reporting reads described in the scenario.

Why this answer

Amazon RDS is the correct choice because it provides managed relational databases (e.g., MySQL, PostgreSQL, Oracle, SQL Server) with built-in automated backups and Multi-AZ redundancy for high availability. The workload is predictable and requires occasional read replicas for reporting, both of which are natively supported by RDS without the need for complex configuration.

Exam trap

The trap here is that candidates may confuse Amazon Redshift's columnar storage and read replica-like features (e.g., concurrency scaling) with a relational database, but Redshift is not designed for transactional workloads or automated Multi-AZ failover.

How to eliminate wrong answers

Option B (Amazon Redshift) is wrong because it is a petabyte-scale data warehouse optimized for analytical queries on large datasets, not a transactional relational database for predictable workloads with read replicas. Option C (Amazon DynamoDB) is wrong because it is a NoSQL key-value and document database that does not support relational features like joins or SQL queries, and its read replicas are not designed for occasional reporting in the same manner as RDS. Option D (Amazon ElastiCache) is wrong because it is an in-memory caching service (Redis/Memcached) that does not provide persistent relational storage, automated backups, or Multi-AZ redundancy for a database workload.

11
MCQeasy

A company runs a stateless REST API on six Amazon EC2 instances in a single Availability Zone behind a Network Load Balancer (NLB). The API writes uploaded files to a shared POSIX file system that must remain accessible from every instance. The company wants to make the architecture resilient to an Availability Zone failure with the least operational effort. Which solution should a solutions architect recommend?

A.Deploy an Amazon EFS file system with mount targets in at least two Availability Zones, and launch EC2 instances in an Auto Scaling group across those same Availability Zones.
B.Store the files in an Amazon S3 bucket in the same Region and use the AWS CLI to synchronize the bucket to local instance store volumes on each EC2 instance.
C.Create an Amazon FSx for Windows File Server file system in one Availability Zone and configure AWS DataSync to copy files to a second file system hourly.
D.Attach an Amazon EBS io2 Block Express volume to all six EC2 instances and enable EBS Multi-Attach so every instance reads and writes the same volume.
AnswerA

Amazon EFS is a fully managed, multi-AZ POSIX file system that mounts concurrently on Linux EC2 instances in every Availability Zone where a mount target exists. Spreading the Auto Scaling group across the same zones removes the single-AZ failure domain without requiring the company to build or replicate any file-system layer, which matches the least-operational-effort requirement.

Why this answer

A shared POSIX file system that survives an Availability Zone loss is delivered by Amazon EFS with mount targets in multiple zones, combined with an Auto Scaling group that spans those zones. This is fully managed, requires no replication logic, and keeps the existing Linux application unchanged, which satisfies the resilience goal with the least operational effort.

Exam trap

The trap here is assuming that EBS Multi-Attach provides a cross-Availability-Zone shared file system, when it is limited to a single zone and to block-level access.

12
MCQhard

A company is designing a new global application that will be deployed in multiple AWS Regions. The application uses an Amazon Aurora MySQL database in each Region. The company needs to ensure that the database in each Region can be used for read scaling and that a secondary Region can be promoted to primary within minutes in case of a regional failure. The company wants to minimize data loss. Which solution should a solutions architect recommend?

A.Configure Aurora Multi-Master clusters in each Region and use AWS Global Accelerator to route traffic.
B.Create Aurora read replicas in each Region and use Amazon Route 53 health checks to redirect traffic during a failure.
C.Configure Aurora Global Database with the primary cluster in one Region and secondary clusters in other Regions.
D.Use Amazon RDS for MySQL with cross-Region read replicas and promote the replica in the secondary Region during a failure.
AnswerC

Aurora Global Database uses a dedicated replication infrastructure to replicate data from the primary cluster to secondary clusters with typical latency under one second. Secondary clusters can serve read-only traffic, providing read scaling. In a regional failure, a secondary cluster can be promoted to primary in as little as one minute, with minimal data loss (typically less than one second of replication lag). This meets the requirements for read scaling, fast promotion, and minimal data loss.

Why this answer

Aurora Global Database is designed for global applications requiring low-latency reads and fast regional failover. It replicates data from a primary cluster to secondary clusters in other Regions with minimal lag, allowing secondary clusters to serve read traffic. In a regional failure, a secondary cluster can be promoted to primary in about a minute with minimal data loss, satisfying the requirements for read scaling, fast promotion, and low data loss.

Exam trap

The trap here is assuming that cross-Region read replicas provide the same fast promotion and minimal data loss as Aurora Global Database, when they actually require manual promotion and may have higher replication lag.

13
MCQmedium

A company is designing a new two-tier web application on AWS. The web tier runs on Amazon EC2 instances behind an Application Load Balancer (ALB), and the database tier uses Amazon RDS for MySQL. The company requires that the database credentials be automatically rotated every 30 days without application downtime. The application retrieves credentials from a centralized store at runtime. Which solution meets these requirements?

A.Use IAM database authentication for RDS and store the IAM role credentials in AWS Secrets Manager with automatic rotation.
B.Store the database credentials in an encrypted Amazon S3 object and use an AWS Lambda function to rotate the credentials in RDS and update the S3 object.
C.Store the database credentials in AWS Secrets Manager and enable automatic rotation with a Lambda rotation function.
D.Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter and configure automatic rotation using a Lambda function.
AnswerC

AWS Secrets Manager supports automatic rotation of database credentials using a Lambda rotation function. It can rotate RDS MySQL credentials every 30 days, and the application can retrieve the current credentials from Secrets Manager at runtime, ensuring no downtime. Secrets Manager integrates natively with RDS and provides a secure, centralized store.

Why this answer

The requirement is for automatic rotation of database credentials every 30 days with no application downtime and a centralized store. AWS Secrets Manager provides native support for rotating RDS MySQL credentials using a Lambda rotation function, and applications can retrieve the latest credentials at runtime. This meets all the requirements without custom development.

The other options either lack native rotation, are insecure, or use a different authentication mechanism that does not involve rotating credentials.

Exam trap

The trap here is confusing IAM database authentication with password-based authentication, or assuming Parameter Store provides automatic rotation when it does not.

14
MCQhard

A company is designing a new application that will use Amazon DynamoDB as its primary database. The application has two access patterns: one requires strongly consistent reads, and the other requires eventually consistent reads. The company wants to minimize costs while meeting the read consistency requirements. How should the company configure DynamoDB reads?

A.Use strongly consistent reads for all read requests to ensure data accuracy.
B.Use DynamoDB Accelerator (DAX) to cache reads and achieve strong consistency.
C.Use DynamoDB global tables with strongly consistent reads enabled.
D.Use strongly consistent reads for the pattern that requires it, and eventually consistent reads for the other pattern.
AnswerD

DynamoDB charges double read capacity units for strongly consistent reads, so applying them only to the pattern requiring them and eventually consistent reads elsewhere minimises cost while meeting both consistency requirements. Using strongly consistent reads for both patterns would needlessly double capacity consumption.

Why this answer

DynamoDB supports both strongly consistent reads and eventually consistent reads at the API level (via the `ConsistentRead` parameter). Strongly consistent reads return the most up-to-date data but consume twice the read capacity units (RCUs) compared to eventually consistent reads. By using strongly consistent reads only for the access pattern that requires it, and eventually consistent reads for the other pattern, the company minimizes RCU consumption and thus costs while meeting the specific consistency requirements of each pattern.

Exam trap

The trap here is that candidates may assume DAX can provide strong consistency (it cannot) or that global tables are a solution for local consistency requirements, when in fact the correct approach is to use the native DynamoDB `ConsistentRead` parameter selectively based on the access pattern.

How to eliminate wrong answers

Option A is wrong because using strongly consistent reads for all requests would double the RCU consumption for the pattern that only needs eventually consistent reads, unnecessarily increasing costs. Option B is wrong because DAX is an in-memory cache that provides eventually consistent reads by default; it does not support strongly consistent reads, so it cannot satisfy the pattern requiring strong consistency. Option C is wrong because DynamoDB global tables are designed for multi-region replication and provide eventually consistent reads across regions; they do not support strongly consistent reads globally, and enabling them does not help meet local consistency requirements.

15
MCQeasy

A company is designing a new microservices architecture on Amazon ECS with Fargate. Each microservice must be isolated and able to communicate with others only through defined APIs. Which solution provides the BEST isolation and security?

A.Use AWS App Mesh with Envoy sidecars to control traffic between services.
B.Place all microservices in the same security group and allow all traffic.
C.Use an Application Load Balancer per microservice with listener rules.
D.Use VPC peering between each microservice's VPC.
AnswerA

AWS App Mesh injects Envoy sidecar proxies into each Fargate task, giving per-service identity, mutual TLS, and explicit traffic routing so services communicate only through defined APIs. This satisfies the isolation and API-only communication requirements better than security groups alone.

Why this answer

AWS App Mesh with Envoy sidecars provides service-level traffic control, encryption, and observability without modifying application code. It enforces fine-grained routing and security policies (e.g., mTLS, retries, timeouts) between microservices, ensuring isolation and that communication only occurs through defined APIs. This aligns with the microservices principle of strict API boundaries and defense in depth.

Exam trap

The SAP-C02 exam often tests the misconception that network-level controls (security groups, VPC peering) are sufficient for microservice isolation, but the exam requires understanding that application-layer service mesh (like App Mesh) provides the necessary API-level security and observability.

How to eliminate wrong answers

Option B is wrong because placing all microservices in the same security group and allowing all traffic removes network segmentation, violating the isolation requirement and exposing services to unrestricted lateral movement. Option C is wrong because an Application Load Balancer per microservice adds unnecessary complexity, cost, and does not enforce service-to-service API-level security; ALBs operate at Layer 7 but cannot enforce mTLS or fine-grained routing between individual service instances. Option D is wrong because VPC peering between each microservice's VPC is operationally unscalable (n² peering connections), introduces latency, and does not provide application-layer API control or encryption between services.

16
Multi-Selecteasy

A company is designing a new VPC with public and private subnets. The company wants to ensure that instances in the private subnets can download updates from the internet, but cannot be directly accessed from the internet. Which THREE components are required to meet these requirements? (Choose THREE.)

Select 3 answers
A.A route table for private subnets with a default route pointing to the NAT Gateway.
B.An Internet Gateway attached to the VPC.
C.A Virtual Private Gateway (VGW).
D.A NAT Gateway in a public subnet.
E.A VPC endpoint for S3.
AnswersA, B, D

Private instances need outbound internet access without inbound reachability. A route table associated with the private subnets carrying a default route (0.0.0.0/0) to the NAT Gateway directs their egress traffic there, satisfying the download-updates requirement while keeping them unreachable from the internet.

Why this answer

Option A is correct because the private subnet's route table must contain a default route (0.0.0.0/0) targeting the NAT Gateway so that outbound internet-bound traffic from private instances is forwarded to the NAT device. Option B is correct because an Internet Gateway must be attached to the VPC to provide the public subnet (and thus the NAT Gateway) with connectivity to the internet; without it, no traffic can reach external update servers. Option D is correct because the NAT Gateway itself must reside in a public subnet, where it has a route to the Internet Gateway, and it performs source NAT so private instances can initiate outbound connections while remaining unreachable from the internet.

Option C is not needed here because a Virtual Private Gateway is used for Site-to-Site VPN or Direct Connect connectivity to on-premises networks, not for general internet access. Option E is not required because a VPC endpoint for S3 only provides private access to S3 (and similar services), not general internet downloads for OS or software updates.

Exam trap

The trap here is that candidates often confuse a Virtual Private Gateway (VGW) with a NAT Gateway, mistakenly thinking a VGW can provide internet access, or they assume a VPC endpoint for S3 is sufficient for general internet downloads, when it only covers S3 traffic.

17
MCQmedium

A media company is designing a new video transcoding pipeline on AWS. The pipeline receives large video files in an Amazon S3 bucket, and each file must be transcoded into multiple formats. The transcoding jobs take between 10 and 45 minutes, and the company wants to minimize compute cost while ensuring that jobs are not interrupted. The solution must automatically scale based on the number of pending jobs. Which compute option should the company use?

A.AWS Lambda functions with a 15-minute timeout, triggered by S3 event notifications, scaling automatically with concurrency.
B.AWS Fargate tasks on Amazon ECS, triggered by an Application Load Balancer, scaling based on CPU utilization of the tasks.
C.AWS Batch with a managed compute environment using On-Demand EC2 instances, scaling based on the number of jobs in the job queue.
D.Amazon EC2 Spot Instances in an Auto Scaling group, with a launch template that installs transcoding software, scaling based on the SQS queue depth.
AnswerC

AWS Batch is designed for batch computing workloads and can scale compute resources based on the number of runnable jobs in the queue. Using On-Demand instances ensures jobs are not interrupted, and the managed compute environment handles provisioning and scaling automatically, minimizing operational overhead.

Why this answer

AWS Batch with On-Demand instances provides a managed batch processing environment that scales based on job queue depth. It supports long-running jobs beyond the Lambda timeout and avoids the interruption risk of Spot Instances. The managed compute environment automatically provisions and terminates instances, reducing operational overhead while meeting the cost and reliability requirements.

Exam trap

The trap here is assuming that Spot Instances are always the cheapest and therefore best choice, ignoring the interruption risk that conflicts with the requirement that jobs not be interrupted.

18
MCQmedium

A company is designing a containerized microservices architecture on Amazon ECS. The services must be able to discover each other using DNS names. Which AWS service should the company use for service discovery?

A.AWS Cloud Map
B.Amazon Route 53 Resolver
C.Elastic Load Balancing (ELB)
D.Amazon Elastic Container Registry (ECR)
AnswerA

AWS Cloud Map provides service discovery with DNS names, letting ECS tasks register and resolve each other automatically. It integrates natively with ECS service discovery, satisfying the DNS-based lookup requirement without custom routing or load balancer workarounds.

Why this answer

AWS Cloud Map is the correct choice because it provides a fully managed service discovery solution that integrates natively with Amazon ECS. It allows microservices to register their DNS names and health checks, enabling other services to discover them via DNS queries or API calls. This directly supports the requirement for containerized services to find each other using DNS names within an ECS cluster.

Exam trap

The trap here is confusing a load balancer (ELB) with service discovery; candidates often think ELB provides DNS-based discovery, but it only routes traffic to a group of targets, not per-instance DNS names for dynamic microservice-to-microservice communication.

How to eliminate wrong answers

Option B (Amazon Route 53 Resolver) is wrong because it is a DNS resolution service for hybrid networks (on-premises to AWS), not a service discovery mechanism for ECS microservices; it does not register or manage service instances. Option C (Elastic Load Balancing) is wrong because it distributes traffic to targets but does not provide DNS-based service discovery for individual service instances; it is a load balancer, not a discovery registry. Option D (Amazon Elastic Container Registry) is wrong because it is a container image repository, not a service discovery tool; it stores Docker images but has no role in DNS resolution or instance registration.

19
MCQhard

A logistics company is designing a new shipment-tracking platform on AWS. The platform ingests telemetry from thousands of trucks, and downstream analytics must query the latest position of any truck within one second. The company also needs to retain six months of raw telemetry for audit at the lowest possible storage cost, and the data must be queryable with standard SQL for ad hoc reports. The company wants a fully managed solution with minimal operational overhead. Which design should the solutions architect recommend?

A.Write telemetry to Amazon S3 and use Amazon Athena with a view that selects the maximum timestamp per truck for latest-position queries
B.Write telemetry to Amazon OpenSearch Service and retain six months of indices for both latest-position lookups and ad hoc SQL reporting
C.Write telemetry to Amazon Kinesis Data Streams, use AWS Lambda to write the latest position to Amazon DynamoDB and the raw records to Amazon S3, and query S3 with Amazon Athena
D.Write telemetry directly to Amazon Redshift, use materialized views for latest positions, and keep all raw data in Redshift for six months
AnswerC

Kinesis Data Streams ingests high-volume telemetry durably, Lambda maintains a DynamoDB table keyed by truck ID for sub-second latest-position lookups, and the same function archives raw records to S3. Athena runs standard SQL directly against S3, and S3 lifecycle policies can move older telemetry to cheaper storage classes, meeting the six-month low-cost audit requirement with no servers to manage.

Why this answer

The design separates the low-latency serving path from the cheap long-term store. Kinesis Data Streams absorbs the telemetry firehose, a Lambda consumer maintains a DynamoDB table keyed by truck ID so the latest position is readable in milliseconds, and the same stream is archived to S3 for audit. Athena then provides standard SQL over the archived data at low cost, and S3 lifecycle rules keep six months of telemetry affordable.

Exam trap

The trap here is trying to satisfy both the sub-second operational lookup and the cheap SQL audit from a single engine instead of splitting the serving and archival paths.

20
MCQmedium

A company is designing a new global web application that will be deployed on AWS. The application must provide low-latency access to users worldwide and must be able to fail over between regions in case of an outage. The company wants to use a single global endpoint and minimize DNS propagation delays during failover. Which solution should a solutions architect recommend?

A.Use Amazon CloudFront with origin failover and multiple regional origins.
B.Use Amazon Route 53 with latency-based routing and health checks to fail over between regions.
C.Use an Application Load Balancer in each region and Route 53 weighted routing with health checks.
D.Use AWS Global Accelerator with endpoint groups in multiple regions and health checks.
AnswerD

AWS Global Accelerator provides a single global anycast IP address that routes traffic to the optimal endpoint based on health, geography, and latency. It uses the AWS global network to reduce latency and provides fast failover (within seconds) by automatically redirecting traffic to healthy endpoints. This meets the requirements for a single global endpoint and minimal failover delay.

Why this answer

AWS Global Accelerator offers a single global anycast IP address and routes traffic over the AWS global network, reducing latency. It performs health checks and automatically fails over to healthy endpoints within seconds, far faster than DNS-based failover. This meets the need for a single global endpoint and minimal failover delay.

Other options rely on DNS, which introduces propagation delays and does not provide a single IP.

Exam trap

The trap here is assuming that Route 53 latency-based routing with health checks provides the same fast failover and single global endpoint as AWS Global Accelerator, when DNS TTL and propagation can cause significant delays.

21
MCQhard

Refer to the exhibit. A CloudFormation template creates an S3 bucket with versioning and a public bucket policy. After deployment, users can access objects in the bucket via the internet. However, the security team requires that all access be logged. What is missing from this configuration?

A.The bucket is not encrypted.
B.The bucket policy does not restrict access to a specific IP range.
C.Bucket versioning is not enabled.
D.No logging configuration is specified.
AnswerD

Server access logging is a separate bucket-level property that CloudFormation does not enable implicitly; versioning and a public policy govern object retention and access, not request auditing. Because the template defines neither an AWS::S3::Bucket LoggingConfiguration nor a target bucket, no access records reach any destination, so the security team's logging requirement remains unmet.

Why this answer

The question states that the security team requires all access to be logged, but the CloudFormation template does not include any logging configuration (e.g., server access logs or AWS CloudTrail object-level logging). Without enabling S3 server access logging or delivering logs to a target bucket, no access records are generated, violating the logging requirement. The bucket policy and versioning are irrelevant to the logging gap.

Exam trap

The trap here is that candidates confuse security controls like encryption, IP restrictions, or versioning with logging, failing to recognize that the specific requirement for 'all access to be logged' can only be met by explicitly configuring a logging destination.

How to eliminate wrong answers

Option A is wrong because encryption (e.g., SSE-S3, SSE-KMS) protects data at rest but does not provide access logging; the security requirement is about logging, not encryption. Option B is wrong because restricting access to a specific IP range controls who can access the bucket but does not enable logging; the requirement is for all access to be logged, not restricted. Option C is wrong because bucket versioning is already enabled per the template description, and versioning preserves object versions but does not log access events.

22
MCQmedium

A company is designing a new CI/CD pipeline for a containerized application using AWS CodePipeline. The application source code is stored in an Amazon S3 bucket. The pipeline must automatically build a Docker image from the source code and push it to Amazon ECR. Which action should be used as the build provider?

A.AWS CodeDeploy
B.AWS CodeCommit
C.Amazon ECS
D.AWS CodeBuild
AnswerD

AWS CodeBuild natively builds Docker images and pushes them to Amazon ECR, satisfying the pipeline's build-and-push requirement. It integrates directly with CodePipeline as a build action, executing buildspec commands that run docker build and docker push against ECR within the pipeline's S3-sourced workflow, without needing external compute or custom orchestration.

Why this answer

AWS CodeBuild is the correct build provider because it is a fully managed continuous integration service that can compile source code, run tests, and produce Docker images. It integrates natively with CodePipeline and Amazon ECR, allowing you to define a buildspec.yml file that uses the 'aws ecr get-login-password' command and 'docker build/push' commands to build and push the image directly to ECR.

Exam trap

The trap here is that candidates often confuse Amazon ECS (a container runtime service) with a build service, or assume CodeDeploy can handle image building because it supports ECS deployments, but neither service can compile source code or push images to ECR.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a deployment service that automates application deployments to EC2, Lambda, or on-premises instances; it does not build Docker images or push them to ECR. Option B is wrong because AWS CodeCommit is a source control service for hosting Git repositories; it cannot perform build actions or push images to ECR. Option C is wrong because Amazon ECS is a container orchestration service that runs containers on a cluster; it does not build images or act as a build provider in CodePipeline.

23
Multi-Selectmedium

A company is designing a new application that will run on Amazon ECS with Fargate. They need to store configuration data and secrets securely. Which services should they use? (Choose TWO.)

Select 2 answers
A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon S3
D.AWS CloudFormation
E.AWS KMS
AnswersA, B

Designed for secrets management.

Why this answer

AWS Secrets Manager is correct because it is purpose-built for securely storing, rotating, and managing secrets such as database credentials and API keys throughout their lifecycle. It integrates natively with Amazon ECS to inject secrets into containers at runtime without exposing them in the task definition or environment variables, meeting the requirement for secure configuration data and secrets.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secure strings) with AWS Secrets Manager, but the exam expects you to know that Secrets Manager is the preferred service for secrets that require automatic rotation, while Parameter Store is better for configuration data that does not need rotation, and both are correct in this question because the requirement is to store both configuration data and secrets securely.

24
MCQmedium

A media company is designing a new video transcoding pipeline on AWS. Raw video files (up to 10 GB each) are uploaded by users to an S3 bucket. Each upload must be transcoded into multiple formats (MP4, WebM, HLS) and stored in another S3 bucket. The transcoding job can take up to 30 minutes per file. The company needs a solution that is cost-effective and can handle hundreds of concurrent uploads. The operations team wants to minimize maintenance. Which solution should a Solutions Architect recommend?

A.Use S3 event notifications to invoke an AWS Lambda function that performs transcoding and stores results.
B.Use S3 event notifications to invoke a Lambda function that submits a job to AWS Elemental MediaConvert for each file.
C.Use an Auto Scaling group of EC2 instances with transcoding software installed. Configure S3 events to send messages to an SQS queue, which the instances poll.
D.Use S3 event notifications to trigger an AWS Step Functions workflow that runs an ECS Fargate task for each file.
AnswerB

MediaConvert is a managed transcoding service handling large files and multiple output formats, so it satisfies the cost-effective, low-maintenance requirement. S3 event notifications trigger Lambda per upload, which submits the job, scaling automatically to hundreds of concurrent uploads without servers to manage.

Why this answer

AWS Elemental MediaConvert is a fully managed, serverless media transcoding service designed for high-volume, multi-format video processing. Using S3 event notifications to invoke a Lambda function that submits a job to MediaConvert offloads the transcoding complexity, scales automatically to handle hundreds of concurrent uploads, and requires no infrastructure maintenance, making it both cost-effective and operationally minimal.

Exam trap

The trap here is that candidates may choose Option A (Lambda) without considering the 15-minute timeout limit, or Option D (Step Functions + Fargate) because it sounds serverless, but they overlook that MediaConvert is the fully managed, cost-optimized service specifically designed for this use case.

How to eliminate wrong answers

Option A is wrong because AWS Lambda has a maximum execution timeout of 15 minutes, but the transcoding job can take up to 30 minutes per file, so the Lambda function would time out before completion. Option C is wrong because managing an Auto Scaling group of EC2 instances with transcoding software introduces significant maintenance overhead (patching, scaling policies, instance health) and is not cost-effective for sporadic or bursty workloads compared to a serverless service. Option D is wrong while technically possible, using ECS Fargate tasks orchestrated by Step Functions adds unnecessary complexity and cost compared to MediaConvert, which is purpose-built for video transcoding and natively integrates with S3; Fargate requires custom container images, task definitions, and more operational overhead.

25
MCQmedium

A company is migrating a monolithic application to microservices on AWS. They have identified that some services require high-throughput, low-latency data sharing. Which AWS service should they use for this purpose?

A.Amazon ElastiCache for Redis
B.Amazon RDS
C.Amazon S3
D.AWS Glue
AnswerA

ElastiCache for Redis is an in-memory store delivering sub-millisecond reads and writes at high throughput, which suits services needing fast shared data access. It removes database round trips for frequently accessed data, satisfying the low-latency, high-throughput requirement.

Why this answer

Amazon ElastiCache for Redis is an in-memory data store that provides microsecond latency and high throughput, making it ideal for data sharing between microservices. Option A is correct. Option B (Amazon RDS) is a relational database, not optimized for low-latency data sharing.

Option C (Amazon S3) is object storage with higher latency. Option D (AWS Glue) is an ETL service, not suitable for real-time data sharing.

26
Multi-Selectmedium

A company is designing a new serverless application using AWS Lambda. The application needs to access an Amazon RDS for PostgreSQL database. The database credentials must be rotated automatically every 30 days. Which THREE steps should the company take to securely manage the credentials? (Choose three.)

Select 3 answers
A.Store the database credentials in AWS Secrets Manager.
B.Configure automatic rotation for the secret in AWS Secrets Manager.
C.Grant the Lambda function's IAM role permission to access the RDS database directly.
D.Write custom rotation logic in the Lambda function to change the database password.
E.Grant the Lambda function's IAM role permission to retrieve the secret from Secrets Manager.
AnswersA, B, E

Secrets Manager is purpose-built for storing and retrieving database credentials securely, satisfying the 30-day rotation requirement natively. Unlike Lambda environment variables or Parameter Store, it integrates rotation scheduling and encryption, so credentials never reside in code or configuration files.

Why this answer

Option A is correct because AWS Secrets Manager is the managed service designed to store and protect database credentials, and it natively supports Amazon RDS for PostgreSQL as a rotation target. Option B is correct because Secrets Manager provides built-in automatic rotation, and configuring rotation with a 30-day schedule satisfies the requirement to rotate credentials every 30 days without custom code. Option E is correct because the Lambda function must have an IAM role policy granting secretsmanager:GetSecretValue (and typically DescribeSecret) on the specific secret so it can retrieve the current credentials at runtime.

Option C is not correct because granting the Lambda execution role direct access to RDS does not manage or rotate credentials, and database authentication still requires valid credentials. Option D is not correct because Secrets Manager already supplies rotation logic for RDS for PostgreSQL, so writing custom rotation logic in the application Lambda function is unnecessary and not a secure credential-management step.

Exam trap

The trap here is that candidates often confuse IAM roles for database access (which is only supported for Amazon RDS with IAM database authentication, not for standard PostgreSQL credentials) with the need to retrieve secrets via IAM permissions, leading them to select Option C instead of Option E.

27
MCQhard

Refer to the exhibit. A company has an S3 bucket policy that allows GetObject access from two IP ranges (10.0.0.0/16 and 192.168.0.0/16). The policy also denies all S3 actions on the 'confidential/' prefix unless the request comes from the 10.0.0.0/16 range. Which of the following statements is true?

A.Users from 192.168.0.0/16 can access objects in the confidential/ prefix.
B.Users from 10.0.0.0/16 can access objects in the confidential/ prefix, but users from 192.168.0.0/16 cannot.
C.Users from 10.0.0.0/16 cannot access objects in the confidential/ prefix.
D.The policy has no effect because the Allow and Deny statements cancel each other.
AnswerB

The bucket policy's explicit Deny on the confidential/ prefix applies only to requests outside 10.0.0.0/16, so 192.168.0.0/16 users are blocked there despite their Allow. The 10.0.0.0/16 range satisfies the Deny's condition, so its GetObject requests on that prefix succeed.

Why this answer

The S3 bucket policy includes an explicit Deny statement that blocks all S3 actions on the 'confidential/' prefix unless the request originates from the 10.0.0.0/16 IP range. Since explicit Deny statements override any Allow statements in AWS IAM policy evaluation, users from 192.168.0.0/16 are denied access to the 'confidential/' prefix even though the GetObject Allow statement includes that range. Only users from 10.0.0.0/16 satisfy the condition in the Deny statement and can therefore access objects in the 'confidential/' prefix.

Exam trap

The trap here is that candidates often assume an Allow statement for a broader set of IPs will grant access to all prefixes, overlooking that an explicit Deny with a condition can carve out exceptions, and that AWS evaluates Deny statements before Allow statements.

How to eliminate wrong answers

Option A is wrong because the explicit Deny statement on the 'confidential/' prefix blocks all requests not coming from 10.0.0.0/16, so users from 192.168.0.0/16 are denied access. Option B is correct as explained. Option C is wrong because the Deny statement specifically allows requests from 10.0.0.0/16, so users from that range can access the 'confidential/' prefix.

Option D is wrong because the Allow and Deny statements do not cancel each other; AWS IAM policy evaluation uses an explicit Deny override, so the Deny statement takes precedence over the Allow statement for requests from 192.168.0.0/16, while the Allow statement still applies to other objects.

28
MCQhard

A company is designing a new application that must be highly available across multiple AWS Regions. The application will run on EC2 instances behind an Application Load Balancer. The company needs a DNS-based routing policy that routes users to the nearest healthy endpoint based on latency. Which Amazon Route 53 routing policy should be used?

A.Latency routing policy
B.Failover routing policy
C.Weighted routing policy
D.Simple routing policy
AnswerA

Latency routing returns the record for the region with the lowest measured latency between the resolver and the endpoint, and health checks remove unhealthy endpoints. This directly satisfies the nearest healthy endpoint by latency requirement across Regions.

Why this answer

Latency routing policy is correct because it directs traffic to the AWS Region that provides the lowest latency for the end user, based on historical latency data between the user's DNS resolver and the AWS endpoints. This meets the requirement for a DNS-based routing policy that routes users to the nearest healthy endpoint based on latency, while also supporting health checks to ensure traffic is only sent to healthy targets.

Exam trap

The trap here is that candidates often confuse 'latency-based routing' with 'geolocation routing' or 'geoproximity routing,' but the question explicitly asks for routing based on latency, not geographic location or proximity.

How to eliminate wrong answers

Option B (Failover routing policy) is wrong because it is designed for active-passive failover between two endpoints, not for routing based on latency or proximity. Option C (Weighted routing policy) is wrong because it distributes traffic based on assigned weights, not on the user's latency or geographic location. Option D (Simple routing policy) is wrong because it routes all traffic to a single endpoint (or multiple endpoints in a round-robin fashion if multiple records are returned) and does not consider latency, health, or proximity.

29
MCQhard

A company is designing a global application that requires a highly available and low-latency API. The API will be consumed by clients across the world. The backend consists of an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances in a single AWS Region. The company wants to improve performance for global users. Which solution meets these requirements with minimal operational overhead?

A.Deploy the application in multiple Regions and use Amazon Route 53 latency-based routing with active-passive failover.
B.Create an Amazon CloudFront distribution with Lambda@Edge to proxy requests to the ALB.
C.Create an AWS Global Accelerator accelerator with the ALB as an endpoint.
D.Create an Amazon CloudFront distribution with the ALB as the origin.
AnswerC

AWS Global Accelerator routes client traffic over the AWS global network to the nearest edge location, then to the ALB endpoint, reducing latency for worldwide users. It requires no application changes and minimal operational overhead compared with multi-Region replication.

Why this answer

AWS Global Accelerator uses the AWS global network to route user traffic to the optimal endpoint, reducing latency and improving availability. By using the ALB as an endpoint, it provides static anycast IP addresses and automatically reroutes traffic if the ALB becomes unhealthy, all with minimal operational overhead since it requires no changes to the application or additional infrastructure.

Exam trap

The trap here is that candidates often confuse CloudFront (a CDN optimized for cacheable content) with Global Accelerator (a network layer service for improving performance of non-cacheable, dynamic traffic), leading them to choose Option D without realizing that CloudFront adds latency for uncacheable API requests.

How to eliminate wrong answers

Option A is wrong because deploying in multiple Regions and using Route 53 latency-based routing with active-passive failover introduces significant operational overhead for managing multi-Region infrastructure, and Route 53 DNS-based routing can be affected by client-side DNS caching, which may not provide the lowest latency for all users. Option B is wrong because Lambda@Edge is designed for lightweight compute at edge locations, not for proxying requests to an ALB; it would add unnecessary complexity, latency, and cost, and it is not a recommended pattern for simply routing traffic to an ALB. Option D is wrong because a CloudFront distribution with the ALB as the origin does not inherently optimize the network path from the client to the ALB; CloudFront caches content at edge locations, but for dynamic API traffic that cannot be cached, it adds an extra hop and does not improve the latency of the connection to the origin ALB.

30
MCQmedium

A company is designing a new serverless application that processes files uploaded to Amazon S3. The processing involves multiple steps, each implemented as a separate AWS Lambda function. The company needs to coordinate these steps, handle retries, and maintain a visual workflow. The solution must be highly available and scalable. Which service should be used to orchestrate the workflow?

A.Amazon Simple Notification Service (SNS) with Lambda subscriptions
B.AWS Step Functions
C.AWS Lambda with recursive invocations and dead-letter queues
D.Amazon EventBridge with rules to trigger Lambda functions
AnswerB

AWS Step Functions is a serverless orchestration service that allows you to coordinate multiple Lambda functions into a state machine. It provides built-in retry and error handling, and a visual console to monitor workflows. It scales automatically and is highly available, making it ideal for this multi-step serverless application.

Why this answer

AWS Step Functions is designed for orchestrating multi-step serverless workflows. It provides state management, built-in retries, error handling, and a visual interface, all while scaling automatically. Other options are messaging or event services that lack orchestration features, or manual approaches that are not robust.

Exam trap

The trap here is confusing event routing with workflow orchestration; EventBridge and SNS can trigger functions but do not maintain state or sequence.

31
MCQeasy

A company is designing a new web application that will serve static content (HTML, CSS, JS, images) to users globally. The application must have low latency and high availability. Content changes infrequently, but when updated, the changes must be reflected immediately. Which solution should the architect recommend?

A.Store content in an S3 bucket and use Amazon CloudFront with S3 as origin
B.Store content on an EC2 instance behind an Application Load Balancer and use CloudFront
C.Store content in Amazon ElastiCache for Redis and use CloudFront
D.Store content in an S3 bucket and use S3 Transfer Acceleration
AnswerA

CloudFront caches static assets at edge locations, delivering the low global latency the stem requires, while S3 provides durable, highly available origin storage. Invalidating or versioning objects on update ensures changes appear immediately, satisfying the freshness constraint.

Why this answer

Amazon CloudFront, with an S3 bucket as the origin, provides a global content delivery network (CDN) that caches static content at edge locations, significantly reducing latency for users worldwide. S3 offers durable, highly available storage, and CloudFront’s cache invalidation or versioned object updates allow changes to be reflected immediately when content is updated. This combination meets the requirements for low latency, high availability, and immediate content refresh.

Exam trap

The trap here is that candidates may over-engineer the solution by choosing EC2 or ElastiCache, mistakenly thinking they need compute or caching layers for static content, when S3 + CloudFront is the simplest, most cost-effective, and fully managed solution for global static content delivery.

How to eliminate wrong answers

Option B is wrong because storing static content on an EC2 instance behind an Application Load Balancer introduces unnecessary compute overhead, management complexity, and higher cost without any benefit for static content; EC2 is designed for dynamic processing, not serving static assets efficiently at global scale. Option C is wrong because Amazon ElastiCache for Redis is an in-memory cache designed for transient, high-speed data (e.g., session state, database query results), not for durable, long-term storage of static content; it lacks the persistence and origin-pull capabilities needed for a CDN origin. Option D is wrong because S3 Transfer Acceleration only speeds up uploads to an S3 bucket over long distances using AWS edge locations, but it does not cache content at edge locations for low-latency downloads; it does not provide global content distribution or high availability for serving static content to users.

32
Multi-Selectmedium

A company is building a serverless data processing pipeline using AWS Lambda, Amazon DynamoDB, and Amazon S3. The pipeline processes JSON files uploaded to an S3 bucket, transforms the data, and writes results to DynamoDB. The company wants to ensure the pipeline can handle bursts of traffic without data loss. Which TWO design decisions should the solutions architect make?

Select 2 answers
A.Configure DynamoDB with on-demand capacity mode.
B.Use an Amazon SQS queue to buffer events from S3 before processing by Lambda.
C.Increase the Lambda function timeout to 15 minutes.
D.Use DynamoDB Streams to capture changes and process in batches.
E.Enable S3 Transfer Acceleration on the bucket.
AnswersA, B

On-demand capacity mode absorbs unpredictable bursts by instantly scaling to workload demand, so DynamoDB throttling cannot drop writes during traffic spikes. This directly satisfies the stem's requirement to handle bursts without data loss, unlike provisioned mode, which needs pre-set capacity and auto scaling that reacts too slowly.

Why this answer

Option A is correct because DynamoDB on-demand capacity mode automatically scales read/write throughput to absorb unpredictable bursts of traffic without provisioning or throttling, which directly prevents data loss when the Lambda pipeline writes results at variable rates. Option B is correct because inserting an Amazon SQS queue between S3 event notifications and Lambda decouples ingestion from processing, buffering burst events durably (up to 14 days) so Lambda can poll and scale consumers without dropping events. Option C is not appropriate because raising the Lambda timeout to 15 minutes only extends execution time and does nothing to buffer bursts or prevent data loss.

Option D is not appropriate because DynamoDB Streams captures item-level changes after they occur and is used for downstream reactions, not for buffering incoming S3 events. Option E is not appropriate because S3 Transfer Acceleration only speeds up uploads to S3 via edge locations and does not address burst handling or data durability in the processing pipeline.

Exam trap

The trap here is that candidates may confuse DynamoDB Streams with a buffering mechanism for incoming writes, when in fact streams only capture post-write changes and do not prevent data loss from S3 event delivery failures.

33
MCQmedium

A company is designing a new web application that will run on Amazon EC2 instances behind an Application Load Balancer. The application must handle millions of requests per day. To reduce latency and offload traffic from the EC2 instances, which AWS service should be placed in front of the load balancer?

A.Amazon CloudFront
B.AWS Global Accelerator
C.AWS Shield Advanced
D.AWS WAF
AnswerA

CloudFront caches content at edge locations worldwide, so repeated requests are served closer to users rather than reaching the load balancer. This reduces latency and offloads origin traffic from the EC2 instances, satisfying the requirement to place a service in front of the ALB.

Why this answer

Amazon CloudFront is a CDN that caches content at edge locations worldwide, reducing latency for end users and offloading a large portion of requests from the origin EC2 instances behind the ALB. Placing CloudFront in front of the ALB is the standard AWS pattern for high-volume web applications needing low latency and origin offload.

Exam trap

SAP-C02 often tests the confusion between CloudFront (caching CDN that offloads origin) and Global Accelerator (network path optimization without caching) — candidates must match 'offload traffic' to CloudFront.

How to eliminate wrong answers

Option B is wrong because AWS Global Accelerator improves latency by routing traffic over the AWS global network to the optimal endpoint, but it does not cache content, so it does not offload traffic from EC2 instances. Option C is wrong because AWS Shield Advanced is a DDoS protection service, not a caching or traffic-offloading layer. Option D is wrong because AWS WAF filters malicious web traffic but does not cache or reduce origin load for legitimate requests.

34
MCQhard

A financial services firm is designing a new trade-processing platform on AWS. The platform uses AWS Lambda functions that must access an Amazon RDS for MySQL database in a private subnet. Security policy forbids storing database credentials in environment variables or code. The firm also requires that credentials be automatically rotated every 30 days, and that the rotation be auditable. Which solution meets these requirements with the LEAST operational overhead?

A.Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter. Create a custom Lambda function that rotates the password every 30 days and updates the parameter.
B.Store the database credentials in AWS Secrets Manager. Grant the Lambda execution role secretsmanager:GetSecretValue on the specific secret ARN, and configure automatic rotation with a 30-day schedule using the provided RDS MySQL rotation Lambda function.
C.Store the database credentials in an encrypted Amazon S3 object. Have the Lambda function retrieve and decrypt the object at each invocation using an AWS KMS key, and use an S3 Lifecycle rule to delete and recreate the object every 30 days.
D.Store the database credentials in AWS Secrets Manager. Attach the AWS managed policy SecretsManagerReadWrite to the Lambda execution role, and enable automatic rotation with a 30-day schedule using the provided RDS MySQL rotation Lambda function.
AnswerB

Secrets Manager is purpose-built for storing and rotating database credentials. Automatic rotation with the provided RDS MySQL rotation function updates both the secret and the database password every 30 days. Scoping the execution role to GetSecretValue on the specific secret ARN follows least privilege and keeps the solution auditable via AWS CloudTrail.

Why this answer

AWS Secrets Manager integrates directly with Amazon RDS to rotate database credentials automatically using a managed rotation Lambda function. Configuring a 30-day rotation schedule satisfies the policy, and granting the Lambda execution role only secretsmanager:GetSecretValue on the specific secret ARN follows least privilege. Rotation events are logged in AWS CloudTrail, providing the required auditability.

Exam trap

The trap here is choosing a solution that stores secrets securely but lacks native rotation, such as Parameter Store SecureString, or granting overly broad permissions when using Secrets Manager.

35
Multi-Selectmedium

A company is designing a new application that will use Amazon S3 to store sensitive customer data. The data must be encrypted at rest and in transit. The company also needs to ensure that only authorized users can access the data. Which three steps should the company take? (Choose THREE.)

Select 3 answers
A.Enable S3 default encryption with SSE-KMS.
B.Use client-side encryption with a customer key.
C.Use bucket policies to restrict access based on IAM roles.
D.Configure the bucket policy to deny requests that do not use HTTPS.
E.Make the bucket publicly accessible for ease of access.
AnswersA, C, D

SSE-KMS encrypts objects at rest with customer-managed keys, satisfying the encryption-at-rest requirement while enabling key rotation, audit trails and granular access control through key policies — a stronger posture than SSE-S3 for sensitive customer data.

Why this answer

Option A is correct because enabling S3 default encryption with SSE-KMS ensures all objects are encrypted at rest using AWS KMS-managed keys, satisfying the encryption-at-rest requirement for sensitive customer data. Option C is correct because bucket policies that restrict access based on IAM roles enforce least-privilege authorization, ensuring only authorized users can access the data. Option D is correct because a bucket policy denying requests that do not use HTTPS (aws:SecureTransport false) enforces encryption in transit by rejecting unencrypted HTTP access.

Option B is not required because SSE-KMS already meets the encryption-at-rest requirement, and client-side encryption is an alternative rather than a necessary step. Option E is incorrect because making the bucket publicly accessible would expose sensitive data and violate the requirement that only authorized users can access it.

Exam trap

The trap here is that candidates may confuse client-side encryption (which is not an S3-managed encryption option) with server-side encryption, or they may overlook that public access is never acceptable for sensitive data, even if other controls are in place.

36
MCQmedium

A media company stores millions of video files in an Amazon S3 bucket and serves them to viewers worldwide through Amazon CloudFront. The company recently enabled S3 Block Public Access and now viewers receive access-denied errors. The security team insists the bucket must remain private and no long-term credentials may be embedded in the application. Which solution meets these requirements with the LEAST administrative effort?

A.Generate an IAM user with programmatic access and store the access keys in the CloudFront origin configuration
B.Replicate the bucket to a second Region and point the CloudFront origin at the replica bucket with public read access
C.Disable S3 Block Public Access on the bucket and attach a bucket policy granting s3:GetObject to everyone
D.Create an origin access control (OAC) on the distribution and update the bucket policy to allow the CloudFront service principal to read objects
AnswerD

Origin access control lets CloudFront sign requests to S3 using SigV4, so the bucket stays private while only the distribution can retrieve objects. Updating the bucket policy to grant the CloudFront service principal access is the supported, low-effort configuration, and no credentials are stored in the application, satisfying both the security and effort requirements.

Why this answer

Origin access control is the current mechanism for letting a CloudFront distribution read from a private S3 bucket. CloudFront signs origin requests with SigV4, and a bucket policy grants access to the CloudFront service principal, so Block Public Access can remain enabled and no static credentials exist anywhere in the application.

Exam trap

The trap here is assuming that granting public read access or embedding IAM keys is the quick fix for CloudFront origin failures, when the supported private pattern is origin access control with a scoped bucket policy.

37
MCQmedium

A logistics company is designing a new application that processes shipping manifests. The application runs on Amazon EC2 instances in an Auto Scaling group and must store session state so that users remain logged in if an instance is terminated. The company wants a highly available, low-latency solution with minimal operational overhead. Which solution meets these requirements?

A.Enable sticky sessions on the Application Load Balancer so that each user is always routed to the same EC2 instance, and store session state locally on that instance.
B.Store session state in an Amazon ElastiCache for Redis cluster with Multi-AZ enabled, and configure the application to read and write session data to the cluster.
C.Store session state in an Amazon RDS for MySQL Multi-AZ database, and have the application query the database for each request.
D.Store session state in an Amazon S3 bucket and have the application read and write the session file for each request.
AnswerB

ElastiCache for Redis with Multi-AZ provides automatic failover and high availability. It offers sub-millisecond latency for session reads and writes, and the application can store session state externally so that any EC2 instance can serve the user. This minimizes operational overhead because AWS manages the cluster.

Why this answer

ElastiCache for Redis with Multi-AZ is purpose-built for low-latency data access and provides automatic failover. By externalizing session state, any EC2 instance in the Auto Scaling group can handle requests, so instance termination does not log users out. AWS manages the cluster, keeping operational overhead low while meeting the high-availability and performance requirements.

Exam trap

The trap here is relying on sticky sessions or local instance storage, which fails when an instance is terminated and does not meet the high-availability requirement.

38
MCQmedium

A company is designing a highly available application on AWS that uses an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application requires that the client's IP address be preserved in the application logs. The company also needs to perform SSL termination at the load balancer. How should the company configure the ALB to meet these requirements?

A.Use TCP listener on port 443 and forward to instances on port 80. Enable proxy protocol v2.
B.Use TCP listener on port 443 and forward to instances on port 443. Install SSL certificate on instances.
C.Use HTTPS listener on port 443, provide the SSL certificate, and forward to instances on port 443. Disable proxy protocol.
D.Use HTTPS listener on port 443, provide the SSL certificate, and forward to instances on port 80. Enable X-Forwarded-For header.
AnswerD

An HTTPS listener on port 443 terminates SSL at the ALB using the supplied certificate, while forwarding to port 80 reaches the instances. Enabling the X-Forwarded-For header preserves the original client IP for application logging, satisfying both requirements simultaneously.

Why this answer

Using an HTTPS listener on port 443 with SSL termination at the ALB allows the load balancer to decrypt traffic and forward it as HTTP on port 80. The X-Forwarded-For header is automatically added by the ALB to preserve the original client IP address in the application logs, meeting both requirements without additional configuration.

Exam trap

The trap here is that candidates often confuse TCP listeners with proxy protocol v2 as the only way to preserve client IP, overlooking that HTTPS listeners automatically provide the X-Forwarded-For header for client IP preservation when SSL termination is performed at the load balancer.

How to eliminate wrong answers

Option A is wrong because a TCP listener does not support SSL termination at the load balancer; it forwards encrypted traffic as-is, and proxy protocol v2 is used with TCP listeners to preserve client IP, but this does not meet the SSL termination requirement. Option B is wrong because using a TCP listener on port 443 and forwarding to instances on port 443 with SSL certificates on instances means SSL termination occurs on the instances, not at the load balancer, and client IP is not preserved without proxy protocol. Option C is wrong because forwarding HTTPS traffic on port 443 to instances on port 443 with SSL certificates on instances means SSL termination is performed on the instances, not at the load balancer, and disabling proxy protocol does not preserve the client IP via X-Forwarded-For.

39
Multi-Selecteasy

A company is designing a new database solution for a global e-commerce application. The database must support high read and write throughput with single-digit millisecond latency. The company expects traffic spikes during peak hours. Which TWO AWS services should the company consider?

Select 2 answers
A.Amazon DocumentDB (with MongoDB compatibility)
B.Amazon ElastiCache
C.Amazon DynamoDB
D.Amazon Aurora
E.Amazon RDS for MySQL
AnswersB, C

ElastiCache provides an in-memory caching layer delivering sub-millisecond read latency, absorbing the read-heavy load and peak-hour spikes so the primary database is not overwhelmed. It satisfies the single-digit millisecond latency and burst throughput constraints, though it is not a durable write store.

Why this answer

Amazon DynamoDB (C) is correct because it is a fully managed NoSQL key-value and document database designed for single-digit millisecond latency at any scale, and it handles high read/write throughput with automatic scaling to absorb peak-hour traffic spikes. Amazon ElastiCache (B) is correct because it provides in-memory caching with sub-millisecond latency using Redis or Memcached, offloading read traffic from the primary database and smoothing bursts during peak hours. Together they fit a global e-commerce workload needing fast, elastic throughput.

Amazon DocumentDB (A) is a MongoDB-compatible document database that does not deliver the same single-digit millisecond latency guarantees at scale for this use case. Amazon Aurora (D) and Amazon RDS for MySQL (E) are relational databases that can be fast but are not purpose-built for the extreme, spiky throughput and in-memory caching needs described here.

Exam trap

The trap here is that candidates often choose Amazon Aurora or RDS for MySQL because they are familiar with SQL databases, but they overlook the requirement for single-digit millisecond latency and high throughput under spikes, which in-memory caching and NoSQL solutions like ElastiCache and DynamoDB are specifically designed to meet.

40
MCQhard

A company is deploying a serverless application using AWS Lambda. The application processes high-resolution images and stores them in Amazon S3. The processing time for each image is variable, but some images require more than 15 minutes to process. Lambda has a maximum execution time of 15 minutes. How can the company process these long-running image transformations?

A.Use AWS Step Functions to chain multiple Lambda functions, each processing a part of the image.
B.Use AWS Batch to run the image processing as a job on EC2 or Fargate.
C.Use Amazon SQS to queue the images and have Lambda poll the queue; the Lambda function can process one image per invocation.
D.Increase the Lambda timeout to 20 minutes.
AnswerB

AWS Batch has no 15-minute invocation limit, so it can run image transformations as jobs on EC2 or Fargate for as long as needed. This directly satisfies the stem's constraint that some images exceed Lambda's maximum execution time.

Why this answer

AWS Lambda has a hard limit of 15 minutes per invocation, so images requiring more than 15 minutes cannot be processed within a single Lambda function. AWS Batch is designed for long-running, batch-oriented compute jobs and can run on EC2 or Fargate without any time limit, making it the correct choice for processing high-resolution images that exceed Lambda's timeout.

Exam trap

The trap here is that candidates assume Step Functions can extend Lambda's execution time by chaining functions, but each Lambda invocation still has a hard 15-minute limit, and Step Functions does not override that service quota.

How to eliminate wrong answers

Option A is wrong because chaining multiple Lambda functions via Step Functions does not extend the per-invocation timeout; each individual Lambda function still has a 15-minute limit, and splitting an image into parts would require custom orchestration and state management, not a native solution for long-running tasks. Option C is wrong because using SQS to queue images does not change Lambda's maximum execution time; each Lambda invocation still cannot exceed 15 minutes, so images requiring longer processing would time out. Option D is wrong because Lambda's maximum timeout is fixed at 15 minutes (900 seconds) and cannot be increased; this is a hard AWS service limit, not a configurable parameter.

41
Multi-Selectmedium

A company is building a serverless application using AWS Lambda and Amazon API Gateway. They need to authenticate users. Which TWO services can be used for authentication?

Select 2 answers
A.AWS Security Token Service
B.AWS IAM
C.Amazon SQS
D.Amazon Cognito
E.Amazon CloudFront
AnswersB, D

AWS IAM authenticates API Gateway requests via Signature Version 4 signed credentials, using IAM roles, users, or Cognito identity pools. This satisfies the stem's requirement for a Lambda and API Gateway authentication mechanism, since API Gateway natively supports IAM authorisation for REST and HTTP APIs without additional identity infrastructure.

Why this answer

Amazon Cognito (D) is correct because it provides user pools that handle sign-up, sign-in, and token issuance (ID, access, and refresh tokens) for API Gateway, and it also supports identity pools for federated identities, making it the standard managed authentication service for serverless applications. AWS IAM (B) is correct because API Gateway can use IAM authorization (SigV4-signed requests) to authenticate and authorize callers, and Lambda execution roles and resource policies rely on IAM for identity and access control. AWS Security Token Service (A) is not a standalone authentication service; it issues temporary credentials after authentication has already occurred, so it is not the answer here.

Amazon SQS (C) is a message queuing service and Amazon CloudFront (E) is a content delivery network, neither of which authenticates users.

Exam trap

The trap here is that candidates often confuse AWS STS (which issues temporary credentials) with an authentication service, or think SQS or CloudFront can handle authentication, when in fact only IAM and Cognito directly support user authentication for API Gateway in this context.

42
MCQeasy

A company is designing a new application that will store and retrieve large files (up to 5 TB). The files must be accessible via HTTPS and must be durable. Which AWS storage service should be used?

A.Amazon S3
B.Amazon EFS
C.AWS Storage Gateway
D.Amazon EBS
AnswerA

Amazon S3 stores objects up to 5 TB each, delivers them over HTTPS via REST endpoints, and provides eleven nines of durability through automatic replication across multiple Availability Zones. This satisfies the large-file, HTTPS-access and durability constraints without provisioning or managing any servers.

Why this answer

Amazon S3 is the correct choice because it supports objects up to 5 TB in size, provides HTTPS access via RESTful API endpoints, and offers 99.999999999% (11 nines) durability by automatically replicating data across multiple Availability Zones. S3 is purpose-built for storing and retrieving large files over the internet with high durability and scalability.

Exam trap

The trap here is that candidates may confuse file storage (EFS) or block storage (EBS) with object storage (S3), overlooking that only S3 provides native HTTPS access and 11 nines durability for large objects without requiring an EC2 instance or additional infrastructure.

How to eliminate wrong answers

Option B (Amazon EFS) is wrong because it is a file-level storage service for Linux workloads, not designed for single objects up to 5 TB (its maximum file size is 52 TB, but it lacks native HTTPS object access and is optimized for shared file systems, not direct HTTP retrieval). Option C (AWS Storage Gateway) is wrong because it is a hybrid storage service that provides on-premises access to AWS storage, not a primary storage service for direct HTTPS access to large files; it adds latency and complexity for a purely cloud-native application. Option D (Amazon EBS) is wrong because it is block-level storage attached to a single EC2 instance, cannot be accessed directly via HTTPS, and has a maximum volume size of 16 TB but requires an EC2 instance to serve files, making it unsuitable for direct object retrieval over the internet.

43
MCQeasy

A company wants to migrate an on-premises Oracle database to Amazon Aurora PostgreSQL. The migration must have minimal downtime. Which AWS service should be used for the migration?

A.AWS Server Migration Service (SMS)
B.AWS DataSync
C.AWS Database Migration Service (DMS)
D.AWS Snowball
AnswerC

AWS Database Migration Service performs continuous change data capture from the on-premises Oracle source, replicating ongoing transactions to Aurora PostgreSQL while the initial full load runs. This keeps the source live, so cutover requires only a brief application pause, satisfying the minimal-downtime constraint. Schema conversion is handled separately by the AWS Schema Conversion Tool.

Why this answer

AWS DMS supports ongoing replication to minimize downtime during migration.

44
MCQeasy

A company is designing a new application that will be deployed on AWS. The application requires a relational database with automatic failover and high availability within a single AWS region. Which database deployment option meets these requirements?

A.Amazon RDS Single-AZ deployment
B.Amazon RDS with Read Replicas
C.Amazon RDS Multi-AZ deployment
D.Amazon RDS cross-region replication
AnswerC

RDS Multi-AZ maintains a synchronous standby replica in a second Availability Zone within the same region, with automatic DNS failover during an outage. This delivers the required high availability and automatic failover for a relational database without cross-region complexity.

Why this answer

RDS Multi-AZ provides automatic failover and high availability within a region. Option A is wrong because Single-AZ does not provide failover. Option B is wrong because Read Replicas are for read scaling, not failover.

Option D is wrong because cross-region replication is for disaster recovery, not primary failover.

45
Multi-Selectmedium

A company is designing a real-time analytics platform that ingests data from thousands of IoT devices. The platform must process and store high-velocity data with low latency. Which TWO AWS services should be used together to meet these requirements? (Choose TWO.)

Select 2 answers
A.AWS Lambda
B.Amazon Kinesis Data Streams
C.Amazon Kinesis Data Analytics
D.Amazon S3
E.Amazon SQS
AnswersB, C

Kinesis Data Streams ingests high-velocity device telemetry durably and with low latency, sharding throughput across many producers and retaining records for replay. It satisfies the ingestion half of the requirement, feeding downstream consumers such as Kinesis Data Analytics or Lambda for real-time processing.

Why this answer

Amazon Kinesis Data Streams (B) is correct because it is purpose-built to ingest high-velocity, real-time streaming data from thousands of producers such as IoT devices, providing low-latency, durable, and scalable stream capture with shards and configurable retention. Amazon Kinesis Data Analytics (C) is correct because it runs continuous SQL or Apache Flink queries directly on streaming data from Kinesis Data Streams, enabling real-time processing and analytics with sub-second latency without managing servers. Together, Kinesis Data Streams handles ingestion and Kinesis Data Analytics handles real-time processing, which matches the platform's low-latency, high-velocity requirements.

AWS Lambda (A) is compute for event-driven functions but is not a streaming ingestion or stream-processing engine by itself, so it does not fulfill the ingestion-plus-real-time-analytics pairing. Amazon S3 (D) is object storage designed for durable batch storage, not low-latency stream ingestion or real-time processing. Amazon SQS (E) is a message queue for decoupling applications, not a high-throughput streaming data platform for real-time analytics.

Exam trap

The trap here is that candidates often confuse Amazon Kinesis Data Streams with Amazon SQS or Amazon S3 for streaming ingestion, but SQS lacks ordered, replayable streams and S3 introduces latency, while Kinesis Data Streams is purpose-built for high-velocity, low-latency data ingestion and analytics.

46
MCQmedium

A company is designing a new microservices architecture using Amazon ECS with Fargate. The services need to communicate with each other using REST APIs. The company wants to implement a service mesh to handle traffic routing, observability, and security. Which AWS service should the company use?

A.Elastic Load Balancing for internal network load balancers.
B.AWS App Mesh.
C.AWS Cloud Map for service discovery.
D.Amazon API Gateway with VPC linking.
AnswerB

AWS App Mesh provides a managed Envoy-based service mesh that works with ECS on Fargate, delivering the traffic routing, observability and mutual TLS security the stem requires. It integrates natively with ECS service discovery, unlike ALB or Cloud Map alone, satisfying the REST API service-to-service communication constraint.

Why this answer

AWS App Mesh is a service mesh that provides application-level networking, enabling traffic routing, observability (metrics, logs, traces), and security (mTLS, authorization policies) for microservices. It integrates natively with Amazon ECS on Fargate, allowing sidecar Envoy proxies to handle inter-service communication without modifying application code.

Exam trap

The trap here is that candidates often confuse service discovery (Cloud Map) with a full service mesh, or assume that a load balancer (ELB) or API gateway can provide the same level of traffic routing, observability, and security for internal microservices communication.

How to eliminate wrong answers

Option A is wrong because Elastic Load Balancing for internal NLB operates at Layer 4 and does not provide service mesh capabilities like traffic routing based on HTTP headers, observability with distributed tracing, or mTLS security between services. Option C is wrong because AWS Cloud Map is a service discovery tool that registers service instances and provides DNS-based or API-based resolution, but it does not handle traffic routing, observability, or security policies required for a service mesh. Option D is wrong because Amazon API Gateway with VPC linking is designed for external API management and routing to backend services, not for internal service-to-service communication within a microservices mesh, and it lacks the sidecar proxy model and fine-grained traffic control of a service mesh.

47
MCQmedium

A company runs a web application on EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application experiences sudden traffic spikes. What is the most effective way to ensure the application can handle the spikes without manual intervention?

A.Use a target tracking scaling policy based on average CPU utilization.
B.Increase the instance size to handle more load per instance.
C.Manually increase the desired capacity when traffic spikes.
D.Use scheduled scaling to add instances at expected peak times.
AnswerA

Target tracking scales automatically as average CPU utilisation rises, adding EC2 capacity during sudden spikes without manual intervention. It satisfies the requirement for hands-off elasticity, unlike scheduled or step policies that need predefined thresholds or timings.

Why this answer

A target tracking scaling policy based on average CPU utilization is the most effective approach because it automatically adjusts the Auto Scaling group's desired capacity in real-time to maintain a target CPU metric (e.g., 50%). This dynamic scaling method responds directly to sudden traffic spikes without any manual intervention, ensuring the application can handle increased load while optimizing cost.

Exam trap

The trap here is that candidates often confuse scheduled scaling (which works only for predictable patterns) with dynamic scaling (which reacts to real-time metrics), leading them to choose D instead of A for handling sudden, unplanned traffic spikes.

How to eliminate wrong answers

Option B is wrong because increasing the instance size (vertical scaling) is a manual, one-time change that does not automatically handle sudden traffic spikes; it also introduces a single point of failure and does not leverage the elasticity of Auto Scaling. Option C is wrong because manually increasing the desired capacity when traffic spikes requires human intervention and real-time monitoring, which defeats the purpose of automated scaling and can lead to delays or errors during spikes. Option D is wrong because scheduled scaling is designed for predictable traffic patterns (e.g., time-of-day peaks) and cannot react to sudden, unplanned traffic spikes; it would either over-provision or under-provision during unexpected events.

48
MCQeasy

A company is designing a new application that will process sensitive financial transactions. The application must be deployed in a VPC with no public internet access. The application needs to send logs to Amazon CloudWatch Logs and store files in Amazon S3. Which set of actions should be taken to meet these requirements without allowing internet access?

A.Create a Gateway VPC endpoint for S3 and an Interface VPC endpoint for CloudWatch Logs
B.Place the application behind a public Application Load Balancer
C.Set up a NAT gateway in a public subnet and route traffic through it
D.Use AWS PrivateLink to connect to CloudWatch Logs and S3
AnswerA

Gateway VPC endpoints route S3 traffic privately over the AWS network, while Interface VPC endpoints (powered by AWS PrivateLink) provide private connectivity to CloudWatch Logs. Together they satisfy the no-public-internet constraint for both logging and object storage.

Why this answer

A Gateway VPC endpoint for S3 allows private connectivity to S3 without traversing the internet, using route table entries. An Interface VPC endpoint for CloudWatch Logs, powered by AWS PrivateLink, enables private HTTPS connections to the CloudWatch Logs API without requiring a NAT gateway or internet gateway. Together, these endpoints satisfy the requirement for a VPC with no public internet access.

Exam trap

The trap here is that candidates often assume AWS PrivateLink can be used for both S3 and CloudWatch Logs uniformly, but S3 primarily uses Gateway VPC endpoints (not Interface endpoints) for private access, and PrivateLink is the mechanism for Interface endpoints only.

How to eliminate wrong answers

Option B is wrong because placing the application behind a public Application Load Balancer requires the ALB to have public internet access, which violates the 'no public internet access' requirement. Option C is wrong because a NAT gateway in a public subnet still requires an internet gateway for outbound traffic, and the application would need a route to the NAT gateway, which ultimately uses the internet; this does not meet the 'no internet access' condition. Option D is wrong because AWS PrivateLink is the underlying technology for Interface VPC endpoints, but it cannot be used directly for S3; S3 requires a Gateway VPC endpoint (or an Interface endpoint with a different configuration), and PrivateLink alone does not provide the correct connectivity for S3 without additional setup.

49
MCQeasy

A startup is building a serverless application using AWS Lambda. They need to securely store and retrieve database credentials without hardcoding them in the function code. Which AWS service should they use?

A.Amazon DynamoDB
B.AWS Secrets Manager
C.AWS Identity and Access Management (IAM)
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager stores credentials outside the function code and retrieves them at runtime via IAM-scoped API calls, with built-in rotation. This satisfies the no-hardcoding constraint by removing static credentials from Lambda deployment packages and environment variables.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, rotating, and retrieving database credentials and other secrets throughout their lifecycle. It integrates natively with Lambda via the AWS SDK, allowing retrieval of credentials at runtime without hardcoding, and supports automatic rotation of secrets for supported databases like Amazon RDS.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks native automatic rotation and is not designed as a full lifecycle secrets management service, making Secrets Manager the correct answer for database credential rotation requirements.

How to eliminate wrong answers

Option A is wrong because Amazon DynamoDB is a NoSQL database service designed for storing application data, not for securely managing secrets; storing credentials in DynamoDB would require you to manage encryption and access control manually, and it lacks built-in secret rotation. Option C is wrong because AWS Identity and Access Management (IAM) is used for managing permissions and access to AWS resources, not for storing secrets; while IAM roles can grant Lambda permissions to access Secrets Manager, IAM itself cannot store or retrieve credential values. Option D is wrong because AWS Systems Manager Parameter Store can store secrets as SecureString parameters, but it does not natively support automatic rotation of database credentials, which is a key requirement for securely managing credentials over time.

50
MCQhard

A company has an IAM policy attached to a user as shown in the exhibit. The user is trying to stop an EC2 instance in the us-west-2 region. What will happen?

A.The user cannot stop the instance because the condition checks the request region.
B.The user cannot stop the instance because the second statement denies all actions in regions other than us-east-1.
C.The user can stop the instance because the first statement allows it.
D.The user can stop the instance because the condition applies only to the Deny statement, but the Allow statement is unconditional.
AnswerB

The second statement's explicit Deny overrides the first statement's Allow, since an explicit deny always wins in IAM policy evaluation. Because the condition restricts permitted actions to us-east-1, the stop request in us-west-2 falls outside that scope and is blocked by the deny.

Why this answer

IAM policy evaluation follows an explicit deny model: any explicit deny overrides any allow. The second statement uses a `Deny` effect with a `StringNotEquals` condition on `aws:RequestedRegion`, which denies all actions (including ec2:StopInstances) when the request region is NOT us-east-1. Since the user is attempting to stop an EC2 instance in us-west-2, the condition evaluates to true, and the deny applies, blocking the action regardless of the first statement's allow.

Exam trap

The trap here is that candidates often assume an unconditional Allow always wins, but they forget that an explicit Deny with a condition that matches the request will override that Allow, leading them to incorrectly choose Option D.

How to eliminate wrong answers

Option A is wrong because the condition does not check the request region in a vacuum; it is part of a Deny statement that explicitly blocks actions when the region is not us-east-1, so the user cannot stop the instance due to the deny, not because of a generic region check. Option C is wrong because while the first statement allows ec2:StopInstances, the second statement's explicit deny overrides that allow, making the action impossible. Option D is wrong because the condition applies to the Deny statement, and the Allow statement is unconditional, but in IAM, an explicit deny always overrides an allow, so the unconditional allow does not help when a deny is triggered.

51
MCQmedium

A company is designing a new microservices architecture on AWS. They need a solution for service discovery that allows services to register themselves and discover other services dynamically. The solution must be highly available and integrated with AWS-native services. Which AWS service should they use?

A.Amazon ECS Service Discovery
B.Application Load Balancer (ALB)
C.AWS Cloud Map
D.Amazon Route 53 private hosted zones
AnswerC

AWS Cloud Map provides service discovery where instances register themselves via API and consumers resolve them dynamically through DNS or HTTP. It is fully AWS-native, highly available across Regions, and integrates with ECS, EKS and Lambda, meeting the dynamic registration requirement.

Why this answer

AWS Cloud Map is the correct choice because it is a fully managed service discovery service that allows microservices to register themselves dynamically and discover other services via DNS or HTTP API calls. It integrates natively with AWS services like Amazon ECS, Amazon EKS, and AWS Lambda, and provides high availability through automatic health checking and resource synchronization across AWS Regions.

Exam trap

The trap here is that candidates often confuse Amazon ECS Service Discovery (Option A) as a separate service, when it is actually a feature of AWS Cloud Map, leading them to overlook Cloud Map as the correct, standalone service for dynamic service discovery.

How to eliminate wrong answers

Option A is wrong because Amazon ECS Service Discovery is not a standalone service; it is a feature of AWS Cloud Map that is exposed through Amazon ECS, and it lacks the broader API-based discovery and health-check integration that Cloud Map provides. Option B is wrong because an Application Load Balancer (ALB) is a Layer 7 load balancer that distributes traffic to targets, not a service registry for dynamic service-to-service discovery; it does not support service registration or DNS-based discovery for internal microservices. Option D is wrong because Amazon Route 53 private hosted zones provide DNS resolution within a VPC but do not support dynamic service registration, health checking, or API-based discovery; they are a static DNS solution, not a service discovery registry.

52
MCQhard

A company is designing a new application that will use Amazon DynamoDB. The application requires strongly consistent reads and must handle a sudden spike in read traffic that could exceed the provisioned read capacity. The company wants to ensure that the application continues to perform well without manual intervention. The table is currently provisioned with 100 read capacity units (RCUs). The workload is unpredictable but expected to grow. What should a solutions architect recommend to meet these requirements?

A.Enable DynamoDB Accelerator (DAX) for the table and use strongly consistent reads.
B.Increase the provisioned read capacity to a high fixed value, such as 10,000 RCUs, and enable auto scaling.
C.Create a global secondary index (GSI) with eventually consistent reads and direct read traffic to the GSI.
D.Switch the table to on-demand capacity mode.
AnswerD

On-demand capacity mode automatically scales to handle sudden spikes in traffic without manual intervention. It supports strongly consistent reads, and you pay per request. This meets the requirements for unpredictable workloads and eliminates the need to manage capacity, ensuring performance during spikes.

Why this answer

DynamoDB on-demand capacity mode is designed for unpredictable workloads and automatically scales read and write capacity to handle traffic spikes without manual intervention. It supports strongly consistent reads, so it meets the consistency requirement. This mode eliminates the need to provision or manage capacity, providing seamless performance during sudden spikes.

Exam trap

The trap here is assuming that DAX can be used with strongly consistent reads, when in fact DAX only supports eventually consistent reads, making it unsuitable for this scenario.

53
MCQmedium

A media company is designing a new video processing pipeline. The pipeline must ingest large video files uploaded to Amazon S3, process them using AWS Lambda, and store the output in another S3 bucket. The processing time can vary from a few seconds to over 15 minutes. The company wants a fully serverless, cost-effective solution that can handle sudden spikes in uploads. Which solution should a solutions architect recommend?

A.Configure S3 event notifications to invoke an AWS Lambda function that starts an Amazon ECS task on AWS Fargate to process the video.
B.Configure an S3 event notification to trigger a Lambda function directly for each uploaded video file.
C.Use an S3 event notification to send a message to an Amazon SQS queue, then have a Lambda function poll the queue and start an AWS Step Functions state machine to process the video.
D.Use an S3 event notification to trigger an AWS Glue job that processes the video and writes the output to S3.
AnswerC

This decouples ingestion from processing, allowing the Lambda function to quickly enqueue jobs. Step Functions can orchestrate long-running tasks, including those exceeding 15 minutes, by using activities or Lambda functions with retries. It handles spikes via SQS buffering and is fully serverless, providing cost-effective scaling.

Why this answer

The pipeline requires handling variable processing times, including jobs exceeding 15 minutes, and sudden spikes. Using S3 event notifications to enqueue messages in SQS decouples ingestion from processing, and a Lambda function can poll the queue and start a Step Functions state machine. Step Functions can orchestrate long-running workflows and is fully serverless, scaling automatically with demand.

Exam trap

The trap here is assuming Lambda can handle any processing duration; Lambda has a hard 15-minute timeout, so long-running video processing must be offloaded to a service like Step Functions or ECS.

54
MCQmedium

A company is designing a new application on AWS that requires a relational database with read replicas across multiple AWS Regions. The database must have automated failover and a recovery point objective (RPO) of less than 5 seconds. Which database solution should the company choose?

A.Amazon Aurora Global Database
B.Amazon RDS for MySQL with Multi-AZ and cross-Region read replicas
C.Amazon RDS for PostgreSQL with cross-Region read replicas and Multi-AZ
D.Amazon DynamoDB Global Tables
AnswerA

Aurora Global Database replicates at the storage layer with a typical cross-Region lag under one second, comfortably meeting the sub-5-second RPO. It also provides managed failover, promoting a secondary Region to primary in under a minute, satisfying the automated failover and multi-Region read replica requirements.

Why this answer

Amazon Aurora Global Database is the correct choice because it is designed for cross-Region replication with a typical RPO of less than 1 second and automated failover from the primary Region to a secondary Region in under 1 minute. This meets the requirement for a relational database with read replicas across multiple Regions and an RPO of less than 5 seconds, as Aurora Global Database uses a dedicated, fast replication channel that minimizes lag.

Exam trap

The trap here is that candidates often confuse Multi-AZ failover (which is Region-bound) with cross-Region failover, or they assume that RDS cross-Region read replicas can achieve the same low RPO as Aurora Global Database, but RDS cross-Region replication is asynchronous and cannot guarantee sub-5-second RPO.

How to eliminate wrong answers

Option B is wrong because Amazon RDS for MySQL with Multi-AZ and cross-Region read replicas uses asynchronous replication for cross-Region replicas, which can introduce replication lag exceeding 5 seconds, and Multi-AZ only provides automated failover within a single Region, not across Regions. Option C is wrong because Amazon RDS for PostgreSQL with cross-Region read replicas and Multi-AZ also relies on asynchronous replication for cross-Region copies, which cannot guarantee an RPO of less than 5 seconds, and Multi-AZ failover is limited to the same Region. Option D is wrong because Amazon DynamoDB Global Tables is a NoSQL database, not a relational database, and the question explicitly requires a relational database solution.

55
MCQmedium

An ALB is configured with a target group for HTTP:80. The health check returns a 302 redirect. What is the most likely cause of the unhealthy instances?

A.The application is returning a 500 Internal Server Error.
B.The application is taking too long to respond.
C.The security group is blocking health check traffic.
D.The application is redirecting health checks to another URL.
AnswerD

The ALB health check expects a 200 response; a 302 indicates the application redirects the health check path elsewhere, so the target never returns success and is marked unhealthy. The redirect, not the target itself, causes the failure.

Why this answer

The ALB health check expects a 200 OK response from the target. A 302 redirect indicates the application is responding with a redirect (e.g., HTTP to HTTPS or to a login page) instead of a success status. This causes the health check to fail because the ALB does not follow redirects for health checks; it only accepts the configured success codes (default 200).

Exam trap

The trap here is that candidates may assume a redirect is harmless or that the ALB will follow it, but the ALB strictly evaluates the first response status code against the configured success codes, and a 302 is not a success by default.

How to eliminate wrong answers

Option A is wrong because a 500 Internal Server Error would produce a 5xx status, not a 302 redirect. Option B is wrong because a timeout would result in a 504 Gateway Timeout or no response, not a 302 redirect. Option C is wrong because if the security group were blocking health check traffic, the ALB would receive no response (connection timeout or refused), not a 302 redirect.

56
MCQhard

Refer to the exhibit. A solutions architect has attached this IAM policy to an IAM role used by an application. The application is trying to upload an object to the S3 bucket example-bucket with server-side encryption using AWS KMS (SSE-KMS). What will happen?

A.The upload succeeds because the policy allows s3:PutObject for the bucket.
B.The upload fails because the policy requires SSE-S3.
C.The upload fails because the bucket policy does not allow SSE-KMS.
D.The upload succeeds because the condition only applies to encryption at rest.
AnswerB

The policy's `s3:PutObject` statement carries a condition demanding `AES256`, which is SSE-S3, not SSE-KMS. Because the application requests `aws:kms` encryption, the condition evaluates false and the request is denied, so the upload fails. The policy therefore blocks the SSE-KMS upload the stem describes.

Why this answer

The IAM policy explicitly requires the `s3:x-amz-server-side-encryption` header to be set to `AES256` (SSE-S3) via the `StringEquals` condition. Since the application is attempting to use SSE-KMS, the encryption header will be `aws:kms`, which does not match the required value. Therefore, the condition fails, and the `s3:PutObject` action is denied, causing the upload to fail.

Exam trap

The trap here is that candidates assume the `s3:PutObject` action alone grants permission, overlooking the restrictive condition that requires a specific encryption header value, which is a common IAM policy nuance tested on the SAP-C02 exam.

How to eliminate wrong answers

Option A is wrong because the policy includes a condition that restricts the `s3:PutObject` action to only requests with SSE-S3 encryption, so simply allowing the action for the bucket is insufficient. Option B is correct as explained. Option C is wrong because the question does not mention any bucket policy; the failure is due to the IAM policy's condition, not a bucket policy.

Option D is wrong because the condition explicitly applies to the encryption header in the request, which is part of the encryption at rest configuration, and the condition is enforced.

57
MCQeasy

A company wants to design a serverless event-driven architecture where multiple downstream services need to process events from a single source. Events must be reliably delivered and each downstream service must process every event independently. Which AWS service should be used as the event router?

A.AWS Step Functions
B.Amazon Kinesis Data Streams
C.Amazon Simple Queue Service (SQS)
D.Amazon EventBridge
AnswerD

Amazon EventBridge routes each event to multiple targets, with rules matching an event bus and fanning out to every subscribed downstream service independently. This satisfies the requirement that each service processes every event, since EventBridge delivers to all matching targets rather than competing consumers pulling from a shared queue.

Why this answer

Amazon EventBridge is the correct choice because it provides a fully managed event bus that can receive events from a single source and fan out to multiple downstream targets (e.g., Lambda, SQS, Step Functions) with built-in filtering, transformation, and reliable delivery. Each downstream service subscribes independently via rules, ensuring every event is processed by all subscribers without the need for a polling mechanism or manual orchestration.

Exam trap

The trap here is that candidates often confuse Amazon SQS or Kinesis as a fan-out solution, but SQS is point-to-point and Kinesis requires custom consumer logic, whereas EventBridge natively supports independent, reliable event routing to multiple targets without additional infrastructure.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a workflow orchestration service, not an event router; it would require custom logic to fan out events and does not natively support independent, reliable delivery to multiple downstream services. Option B is wrong because Amazon Kinesis Data Streams is designed for real-time streaming data ingestion and processing with shard-level ordering, but it does not natively fan out events to multiple independent consumers—each consumer must share the same stream and manage its own checkpointing, which can lead to contention and does not guarantee independent processing of every event. Option C is wrong because Amazon SQS is a message queue that delivers each message to a single consumer; to fan out to multiple downstream services, you would need multiple queues and a publisher to send copies, which adds complexity and does not provide built-in event filtering or transformation.

58
MCQmedium

A company is building a data lake on Amazon S3 using Parquet files. The data will be queried by multiple teams using Amazon Athena. The security team requires that access to sensitive columns (e.g., PII) be restricted based on the user's role. Which solution provides column-level access control with the LEAST administrative overhead?

A.Use AWS Lake Formation to define column-level permissions in the Data Catalog.
B.Create separate S3 buckets for sensitive and non-sensitive data and apply bucket policies to restrict access.
C.Load the data into Amazon Redshift and use Redshift Spectrum to query S3, then apply column-level security through Redshift.
D.Use IAM policies with condition keys to restrict access based on the Athena workgroup.
AnswerA

AWS Lake Formation enforces column-level and row-level permissions centrally through the Data Catalog, and Athena honours these grants automatically. Defining permissions once in Lake Formation satisfies the role-based PII restriction with the least administrative overhead compared with per-query workarounds.

Why this answer

AWS Lake Formation provides native column-level filtering in the Data Catalog, allowing you to define granular permissions on specific columns of a table without moving or duplicating data. When Athena queries a table registered with Lake Formation, the service automatically applies column-level access controls based on the IAM role or user, enforcing the restriction at query runtime with minimal administrative overhead.

Exam trap

The trap here is that candidates often assume S3 bucket policies or IAM conditions can achieve column-level access, but these operate at the object or API level and cannot filter columns within a single file, which is a key distinction tested in the SAP-C02 exam.

How to eliminate wrong answers

Option B is wrong because S3 bucket policies operate at the object or prefix level, not at the column level, so they cannot restrict access to specific columns within a Parquet file. Option C is wrong because it introduces unnecessary complexity and administrative overhead by requiring a separate Redshift cluster and Redshift Spectrum setup, whereas Lake Formation directly integrates with Athena and the Glue Data Catalog. Option D is wrong because IAM condition keys for Athena workgroups can limit which workgroup a user can use, but they cannot enforce column-level restrictions on the query results.

59
MCQeasy

A company is designing a new application that requires secure storage of secrets such as database passwords and API keys. The application runs on Amazon EC2 instances. The company wants to centralize secret management and automatically rotate secrets. Which AWS service should be used?

A.AWS Key Management Service (KMS)
B.AWS CloudHSM
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager stores secrets centrally and natively rotates them on a schedule using Lambda rotation functions, so database passwords and API keys are updated automatically. EC2 instances retrieve secrets at runtime via the API, eliminating hard-coded credentials.

Why this answer

AWS Secrets Manager is purpose-built for secure secret storage with built-in automatic rotation for RDS, Redshift, and DocumentDB credentials, plus custom Lambda-based rotation for other secrets. It centralizes secret management and integrates natively with EC2 via the AWS SDK or Secrets Manager Agent. KMS is for encryption keys, not secret lifecycle management, and Parameter Store lacks native rotation.

Exam trap

SAP-C02 often tests the distinction between KMS (encryption keys), Parameter Store (configuration and basic secrets), and Secrets Manager (managed rotation), so candidates must recognize that automatic rotation is the key differentiator.

How to eliminate wrong answers

Option A is wrong because AWS KMS manages encryption keys and does not store or rotate application secrets like database passwords or API keys. Option B is wrong because CloudHSM provides dedicated hardware security modules for key operations, not a managed secret store with rotation. Option C is wrong because Systems Manager Parameter Store can store secrets (as SecureString) but does not provide automatic rotation natively; rotation requires custom automation.

60
MCQeasy

A company is designing a new static website hosted on Amazon S3. The website must be served over HTTPS with a custom domain name. Which AWS service should be used to achieve this?

A.Amazon Route 53 with alias record
B.Amazon CloudFront with SSL certificate
C.Amazon S3 static website hosting with bucket policy
D.Elastic Load Balancer with SSL termination
AnswerB

CloudFront terminates HTTPS at edge locations using an ACM certificate for the custom domain, then fetches content from the S3 origin. S3 static website endpoints alone cannot serve HTTPS with a custom domain, so CloudFront satisfies both requirements.

Why this answer

Amazon CloudFront can be configured to serve content from an S3 bucket as the origin, and it supports custom SSL certificates via AWS Certificate Manager (ACM) or IAM, enabling HTTPS for a custom domain. This is the recommended architecture for static websites requiring HTTPS because CloudFront provides edge caching, DDoS protection, and seamless SSL termination.

Exam trap

The trap here is that candidates often assume S3 static website hosting can directly serve HTTPS with a custom domain, but S3's built-in website endpoint does not support custom SSL certificates, making CloudFront the required service for HTTPS termination with a custom domain.

How to eliminate wrong answers

Option A is wrong because Amazon Route 53 with an alias record only provides DNS resolution, not HTTPS termination; it cannot serve content over HTTPS directly. Option C is wrong because Amazon S3 static website hosting does not support custom SSL certificates or HTTPS for custom domains; it only provides HTTPS via the S3 website endpoint (which uses a domain like s3-website-<region>.amazonaws.com) and cannot bind a custom SSL certificate. Option D is wrong because an Elastic Load Balancer with SSL termination is designed for dynamic content behind EC2 or containers, not for static S3-hosted websites, and it adds unnecessary complexity and cost without leveraging S3's native static hosting benefits.

61
MCQeasy

A company is building a new web application that will be accessed by users globally. They want to minimize latency and protect against DDoS attacks. Which AWS service should they use as the entry point?

A.Elastic Load Balancing
B.AWS Global Accelerator
C.Amazon CloudFront
D.Amazon Route 53
AnswerC

Amazon CloudFront terminates TLS at edge locations and caches content close to global users, directly reducing latency. Its integration with AWS Shield Standard provides automatic DDoS protection at no extra cost, satisfying both the latency and DDoS constraints named in the stem.

Why this answer

Amazon CloudFront is correct because it is a global content delivery network (CDN) that caches content at edge locations close to users, reducing latency for static and dynamic content. It also provides built-in DDoS protection through AWS Shield Standard and can integrate with AWS WAF for additional layer 7 filtering, making it the ideal entry point for a globally accessed web application requiring both low latency and DDoS mitigation.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with CloudFront because both improve latency globally, but Global Accelerator does not cache content or provide application-layer DDoS protection, making it unsuitable as the primary entry point for a web application requiring both features.

How to eliminate wrong answers

Option A is wrong because Elastic Load Balancing distributes traffic only within a single AWS Region and does not provide global edge caching or native DDoS protection at the application layer; it relies on other services for global latency reduction. Option B is wrong because AWS Global Accelerator improves latency by routing traffic over the AWS global network to the optimal regional endpoint, but it does not cache content or provide application-layer DDoS protection; it focuses on TCP/UDP traffic optimization and uses static anycast IPs. Option D is wrong because Amazon Route 53 is a DNS service that resolves domain names to IP addresses and can perform health checks and routing policies, but it does not cache content or provide DDoS mitigation beyond basic DNS-level protection; it is not an entry point for application traffic.

62
MCQhard

A company is migrating a legacy on-premises application to AWS. The application uses a monolithic architecture and a MySQL database. The company wants to refactor the application into microservices and use a NoSQL database for better scalability. The new application will be deployed on Amazon EKS. The database must be highly available and support automatic scaling. Which database service should the company use?

A.Amazon Aurora Serverless
B.Amazon DynamoDB
C.Amazon DocumentDB (with MongoDB compatibility)
D.Amazon RDS for MySQL with Multi-AZ deployment
AnswerB

DynamoDB is a fully managed NoSQL key-value and document store that scales horizontally without provisioning, delivering single-digit-millisecond performance and multi-AZ durability by default. It satisfies the NoSQL, high-availability, and automatic-scaling requirements for the refactored microservices on Amazon EKS.

Why this answer

Amazon DynamoDB is a fully managed, serverless NoSQL key-value and document database that scales horizontally with automatic scaling, provides single-digit millisecond latency, and offers Multi-AZ high availability by default. It aligns with the requirement to move from a monolithic MySQL database to a NoSQL store for better scalability on EKS microservices.

Exam trap

The trap is picking DocumentDB because it is NoSQL and MongoDB-compatible, but the question does not require document semantics — DynamoDB is the default answer when 'NoSQL, highly available, automatic scaling, least operational overhead' are the criteria.

How to eliminate wrong answers

Option A is wrong because Aurora Serverless is a relational (MySQL/PostgreSQL-compatible) database, not NoSQL, and while it scales automatically, it does not meet the explicit NoSQL requirement. Option C is wrong because DocumentDB is MongoDB-compatible and would be a valid NoSQL choice, but the question does not specify a document model requirement, and DynamoDB is the more general-purpose, fully serverless, auto-scaling NoSQL option with the least operational overhead. Option D is wrong because RDS for MySQL with Multi-AZ is relational, not NoSQL, and does not provide the horizontal auto-scaling the scenario demands.

63
Multi-Selectmedium

A company is designing a new application that will run on Amazon EC2 instances. The application needs to access an Amazon S3 bucket to read and write objects. The company wants to ensure that the EC2 instances can access the S3 bucket without storing AWS credentials on the instances. Which TWO steps should the company take?

Select 2 answers
A.Attach the IAM role to the EC2 instance profile.
B.Store the AWS access key and secret access key in a configuration file on the instance.
C.Create an S3 bucket policy that allows access from the EC2 instance's IP address.
D.Configure the EC2 security group to allow outbound traffic to S3.
E.Create an IAM role with a policy that grants the required S3 permissions.
AnswersA, E

Attaching an IAM role to the EC2 instance profile lets the instance obtain temporary credentials from the instance metadata service automatically. The application then calls S3 using those rotating credentials, eliminating the need to store long-term AWS access keys on the instance.

Why this answer

Option A is correct because attaching an IAM role to the EC2 instance profile is the mechanism that delivers temporary, automatically rotated credentials to the instance via the instance metadata service (IMDS), so no long-term AWS credentials need to be stored on the instance. Option E is correct because the IAM role must first be created with a policy granting the specific S3 permissions (for example, s3:GetObject and s3:PutObject on the target bucket/prefix); without this role and policy, the instance profile would have nothing to assume. Option B is wrong because storing access keys in a configuration file on the instance is exactly the practice the company wants to avoid, and long-term keys are a security risk.

Option C is wrong because an S3 bucket policy based on the EC2 instance's IP address is brittle and does not eliminate credentials; it also fails for instances behind NAT or with changing IPs. Option D is wrong because security groups control network reachability only and do not grant S3 authorization; outbound HTTPS to S3 is necessary but not sufficient, and it does not address credential-free access.

Exam trap

The trap here is that candidates often confuse network-level controls (security group outbound rules) with authentication/authorization mechanisms, thinking that allowing outbound traffic to S3 is sufficient to grant access, when in fact the instance still needs valid IAM credentials to authenticate requests to S3.

64
MCQmedium

A media company is designing a video transcoding pipeline. They receive raw video files in Amazon S3, which need to be transcoded into multiple formats. The pipeline must handle sporadic bursts of uploads and complete processing within 30 minutes for each video. The cost should be minimized. Which design should they use?

A.Use AWS Lambda with layers containing FFmpeg to transcode videos.
B.Use Amazon S3 event notifications to trigger an AWS Elemental MediaConvert job.
C.Provision a cluster of EC2 instances running FFmpeg, with Auto Scaling based on SQS queue depth.
D.Use Amazon Elastic Transcoder, which is fully managed and triggers from S3 events.
AnswerB

S3 event notifications invoke MediaConvert directly, giving a fully managed, serverless transcoding service that scales per job without idle compute. This satisfies the sporadic-burst requirement and the 30-minute completion window, while consumption-based pricing minimises cost compared with continuously running EC2 transcoding fleets.

Why this answer

AWS Elemental MediaConvert is a fully managed, serverless video transcoding service designed for high-volume, bursty workloads. It integrates directly with S3 event notifications, scales automatically to handle sporadic uploads, and completes each job within the required 30-minute window. Its pay-per-use pricing minimizes cost by eliminating idle infrastructure, unlike provisioned EC2 clusters or Lambda's 15-minute execution limit.

Exam trap

The trap here is that candidates often assume Lambda can handle any short-lived compute task, but they overlook the 15-minute timeout and lack of GPU support for video encoding, making it unsuitable for transcoding jobs that require longer processing times or specialized hardware acceleration.

How to eliminate wrong answers

Option A is wrong because AWS Lambda has a maximum execution timeout of 15 minutes, which cannot accommodate transcoding jobs that may exceed this limit, especially for high-resolution or long-duration videos. Option C is wrong because provisioning a cluster of EC2 instances with Auto Scaling based on SQS queue depth incurs significant idle costs during low-activity periods and requires ongoing operational overhead for patching and scaling, making it less cost-effective than a fully managed service. Option D is wrong because Amazon Elastic Transcoder is a legacy service that is being phased out in favor of Elemental MediaConvert; it lacks advanced features like per-title encoding, Dolby Vision, and HDR10+ support, and its pricing model is generally less flexible for sporadic workloads.

65
MCQmedium

A company is designing a new microservices application using Amazon ECS with Fargate. The services need to communicate securely within the VPC. Which approach should be used for service discovery?

A.Amazon Route 53 private hosted zones with health checks
B.AWS Cloud Map
C.VPC peering connections between services
D.Application Load Balancer with path-based routing
AnswerB

AWS Cloud Map provides service discovery with health-checked registration of ECS tasks, returning IP addresses and ports through DNS or API calls. This suits Fargate tasks, whose addresses change, and keeps service-to-service traffic inside the VPC.

Why this answer

AWS Cloud Map is the correct choice because it provides a fully managed service discovery solution that integrates natively with Amazon ECS and Fargate. It allows microservices to register themselves with DNS-based or API-based service endpoints, enabling dynamic, secure communication within the VPC without requiring manual IP management or external DNS configuration.

Exam trap

The trap here is that candidates often confuse DNS-based resolution (Route 53 private hosted zones) with dynamic service discovery (AWS Cloud Map), assuming that static DNS records with health checks are sufficient for microservices that scale and change IPs frequently.

How to eliminate wrong answers

Option A is wrong because Route 53 private hosted zones with health checks are designed for DNS resolution and health monitoring of static resources, not for dynamic service discovery where service endpoints change frequently due to scaling or restarts. Option C is wrong because VPC peering connects entire VPCs, not individual services, and does not provide service discovery; it is a network connectivity mechanism, not a discovery mechanism. Option D is wrong because an Application Load Balancer with path-based routing is used for traffic distribution and routing to backend targets, not for service discovery; it does not provide a registry or DNS-based resolution for individual service instances.

66
MCQeasy

A startup is building a web application on AWS that requires a relational database. They expect unpredictable traffic patterns and want to minimize costs while ensuring high availability. Which database solution should they choose?

A.Amazon Redshift with concurrency scaling
B.Amazon Aurora Serverless (MySQL-compatible)
C.Amazon RDS for MySQL with Single-AZ deployment
D.Amazon DynamoDB with on-demand capacity
AnswerB

Aurora Serverless automatically scales compute capacity up and down with unpredictable traffic and pauses when idle, so the startup pays only for capacity used. It also provides Multi-AZ high availability with automatic failover, satisfying both the cost-minimisation and availability requirements.

Why this answer

Amazon Aurora Serverless (MySQL-compatible) is the correct choice because it automatically scales compute capacity based on actual application demand, making it ideal for unpredictable traffic patterns. It provides high availability through multi-AZ storage and automated failover, while minimizing costs by only charging for consumed capacity during active periods.

Exam trap

The trap here is that candidates often confuse 'relational database' with 'NoSQL' (DynamoDB) or choose a cheaper but non-HA option (Single-AZ RDS), overlooking that Aurora Serverless uniquely combines relational capabilities, automatic scaling, and built-in high availability at a cost-effective pay-per-request model.

How to eliminate wrong answers

Option A is wrong because Amazon Redshift is a data warehouse optimized for analytical queries on large datasets, not a transactional relational database for a web application, and concurrency scaling adds cost without addressing unpredictable traffic for OLTP workloads. Option C is wrong because Amazon RDS for MySQL with Single-AZ deployment lacks high availability—it does not provide automatic failover to a standby instance in another Availability Zone, which is required for the stated goal. Option D is wrong because Amazon DynamoDB is a NoSQL key-value and document database, not a relational database, and while on-demand capacity handles unpredictable traffic, it does not support SQL queries or relational data models needed for a web application with a relational database requirement.

67
MCQhard

A company is designing a new global application that requires a relational database with low-latency reads in multiple AWS Regions. The database must support automatic failover to a secondary Region in case of a disaster. The company wants to minimize operational overhead and ensure data consistency across Regions. Which solution should a solutions architect recommend?

A.Use Amazon RDS for PostgreSQL with Multi-AZ deployment and a cross-Region replica for disaster recovery.
B.Use Amazon RDS for MySQL with a cross-Region read replica and promote the replica during a failover.
C.Use Amazon Aurora Global Database with a primary Region and secondary Regions, enabling managed planned failover.
D.Use Amazon DynamoDB global tables with automatic multi-Region replication.
AnswerC

Amazon Aurora Global Database is designed for global applications, providing low-latency reads in secondary Regions with typical replication lag under one second. It supports managed planned failover, which promotes a secondary Region to primary with minimal data loss and automatic DNS updates. This minimizes operational overhead and ensures data consistency across Regions.

Why this answer

Amazon Aurora Global Database provides a relational database with low-latency reads in multiple Regions and supports managed planned failover. It replicates data with minimal lag, ensuring consistency, and the failover process is automated, reducing operational overhead. This meets the requirements for a global application with automatic disaster recovery.

Exam trap

The trap here is assuming that a cross-Region read replica provides automatic failover, when in fact it requires manual promotion and may lose data.

68
MCQhard

A company is designing a new data lake on AWS. The data lake must support SQL queries using Amazon Athena and also allow Amazon SageMaker to access training data. The solution must minimize storage costs for infrequently accessed data while providing immediate access when needed. Which storage tier should be used for the data lake?

A.Amazon S3 Glacier Deep Archive
B.Amazon S3 Intelligent-Tiering
C.Amazon S3 Standard
D.Amazon S3 One Zone-Infrequent Access
AnswerB

S3 Intelligent-Tiering automatically moves objects between frequent and infrequent access tiers based on changing access patterns, with no retrieval fees. It serves Athena queries and SageMaker training reads immediately while cutting storage cost for cold data.

Why this answer

Amazon S3 Intelligent-Tiering is the correct choice because it automatically moves data between access tiers (frequent, infrequent, and archive instant access) based on changing access patterns, optimizing storage costs without compromising performance. This meets the requirement for infrequently accessed data to be cost-effective while still providing immediate access for Athena queries and SageMaker training, as data in the archive instant access tier can be retrieved within milliseconds.

Exam trap

The trap here is that candidates might choose S3 Standard for its immediate access or S3 Glacier Deep Archive for lowest cost, overlooking that S3 Intelligent-Tiering provides both cost optimization for infrequent access and immediate retrieval via the Archive Instant Access tier.

How to eliminate wrong answers

Option A is wrong because Amazon S3 Glacier Deep Archive has retrieval times of 12-48 hours, which fails the requirement for immediate access when needed for Athena and SageMaker. Option C is wrong because Amazon S3 Standard is designed for frequently accessed data and would be more expensive for infrequently accessed data, not minimizing storage costs. Option D is wrong because Amazon S3 One Zone-Infrequent Access stores data in a single Availability Zone, which risks data loss if that AZ fails, and it lacks automatic cost optimization for varying access patterns.

69
Multi-Selectmedium

A company is designing a new application that will process sensitive financial data. They need to ensure encryption at rest and in transit. Which of the following should they use? (Select TWO.)

Select 2 answers
A.TLS for all data in transit
B.AWS Certificate Manager (ACM) for all encryption
C.SSL certificates for all connections
D.AWS Key Management Service (KMS) for encryption at rest
E.AWS Identity and Access Management (IAM) for data encryption
AnswersA, D

TLS encrypts data in transit between clients and services, directly satisfying the in-transit encryption requirement for sensitive financial data. It protects against interception on the network, complementing at-rest encryption. Selecting TLS alongside a KMS-based at-rest control fulfils both stated constraints.

Why this answer

Option A (TLS for all data in transit) is correct because Transport Layer Security encrypts data moving between clients and servers, protecting sensitive financial data from interception or tampering over the network. Option D (AWS Key Management Service (KMS) for encryption at rest) is correct because KMS lets the company create and manage customer master keys used to encrypt stored data, such as EBS volumes, S3 objects, and RDS databases, satisfying the encryption-at-rest requirement. Option B is not correct because AWS Certificate Manager only provisions, manages, and deploys TLS/SSL certificates; it does not itself perform encryption of data at rest or in transit.

Option C is not correct because SSL is a deprecated predecessor to TLS, and simply having certificates does not guarantee encryption is enforced on all connections. Option E is not correct because IAM controls authentication and authorization to AWS resources; it does not encrypt data.

Exam trap

The trap here is that candidates confuse SSL/TLS certificates (which are just cryptographic containers) with the actual encryption protocol (TLS), and they mistakenly think ACM or IAM directly perform encryption instead of managing certificates or access.

70
MCQmedium

A company is designing a new multi-tenant SaaS application on AWS. Each tenant must have its own AWS KMS customer managed key (CMK) for encrypting data at rest in Amazon S3. The security team requires that the encryption keys are automatically rotated every year and that key usage is logged for auditing. The application will use AWS Lambda functions to encrypt and decrypt data on behalf of tenants. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS Certificate Manager (ACM) to generate and manage per-tenant encryption keys. Configure Lambda functions to use the ACM-provided keys for S3 encryption.
B.Create a single AWS KMS CMK for all tenants and use encryption context to differentiate tenants. Enable automatic rotation on the CMK and grant Lambda functions permission to use the key.
C.Use AWS Secrets Manager to store a unique encryption key per tenant. Configure Lambda functions to retrieve the key and perform client-side encryption before storing data in Amazon S3.
D.Create a separate AWS KMS CMK per tenant with automatic key rotation enabled. Configure the Lambda execution role with kms:Encrypt and kms:Decrypt permissions scoped to each tenant's key using IAM policy conditions.
AnswerD

This solution uses AWS KMS CMKs with automatic rotation, satisfying the yearly rotation requirement. IAM policies scoped to each tenant's key enforce least privilege, and KMS integrates with AWS CloudTrail to log all key usage. Lambda functions can assume a role with the necessary permissions, and no custom key management overhead is required.

Why this answer

The requirement for per-tenant encryption keys with automatic yearly rotation and audit logging is best met by AWS KMS customer managed keys. KMS provides automatic key rotation, integrates with AWS CloudTrail for auditing, and allows fine-grained IAM policies to scope access per key. Lambda functions can securely use these keys via their execution role, minimizing operational overhead.

Exam trap

The trap here is assuming that a single KMS key with encryption context can provide sufficient tenant isolation, but the requirement explicitly demands separate keys per tenant.

71
MCQmedium

A company is deploying a new web application that uses Amazon S3 to store static content and Amazon CloudFront for content delivery. The application also uses an API Gateway with Lambda for backend logic. The company wants to protect the API from common web exploits like SQL injection and cross-site scripting. Which AWS service should be added to the architecture?

A.Amazon GuardDuty
B.Amazon Inspector
C.AWS Shield Advanced
D.AWS WAF
AnswerD

AWS WAF attaches to API Gateway and inspects HTTP requests against managed rule groups that block SQL injection and cross-site scripting patterns. CloudFront and S3 serve static content, so WAF on the API layer satisfies the requirement to protect backend logic from common web exploits.

Why this answer

AWS WAF integrates with API Gateway and CloudFront to protect against web exploits like SQL injection and cross-site scripting. Option A: Amazon GuardDuty is for threat detection, not inline protection. Option B: Amazon Inspector is for vulnerability assessment.

Option C: AWS Shield Advanced provides DDoS protection, not application-layer filtering.

72
Multi-Selectmedium

A company is designing a multi-tier web application that must be fault-tolerant and scalable. The application uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in an Auto Scaling group. The instances run a web server and a backend application. Which TWO steps should be taken to ensure the application can scale without data loss?

Select 2 answers
A.Use instance store volumes for temporary data.
B.Store session state in an external data store such as ElastiCache.
C.Implement lifecycle hooks to gracefully handle instance termination.
D.Use a custom CloudWatch metric to scale based on CPU utilization.
E.Use a fixed number of EC2 instances instead of Auto Scaling.
AnswersB, C

Storing session state externally makes instances stateless, preventing data loss on scale-in.

Why this answer

Storing session state in an external data store like ElastiCache decouples session data from individual EC2 instances. This ensures that if an instance is terminated or replaced during scaling events, the session data persists and can be served by any other instance in the Auto Scaling group, preventing data loss and maintaining user experience.

Exam trap

The trap here is that candidates often confuse instance store with EBS or assume that lifecycle hooks alone (Option C) prevent data loss, but lifecycle hooks only delay termination for cleanup—they do not preserve session data if the instance is ultimately terminated, making an external data store essential.

73
MCQmedium

A company is designing a CI/CD pipeline for a containerized application using AWS CodePipeline. The application is deployed to Amazon ECS with Fargate. The pipeline must automatically build and test code changes before deploying to production. Which service should be used to build and test the Docker images?

A.AWS CodeDeploy
B.AWS CodeBuild
C.Amazon ECR
D.AWS CodeCommit
AnswerB

CodeBuild is the managed build service that natively integrates with CodePipeline, compiling code and running tests inside Docker containers. It produces the tested image artefact the pipeline then deploys to ECS Fargate, satisfying the requirement to build and test before production release.

Why this answer

AWS CodeBuild is the correct service because it is a fully managed continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy. In this scenario, CodeBuild can build the Docker image from a Dockerfile, run unit or integration tests inside the build environment, and then push the image to Amazon ECR, all within the CI/CD pipeline defined in AWS CodePipeline.

Exam trap

The trap here is that candidates may confuse AWS CodeDeploy's role in ECS deployments with the build and test phase, assuming CodeDeploy handles the entire CI/CD process, when in fact it only handles the deployment step after the image is built and tested by CodeBuild.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a deployment service that automates code deployments to compute services like ECS, EC2, or Lambda, but it does not build or test Docker images. Option C is wrong because Amazon ECR is a container image registry for storing, managing, and deploying Docker images; it does not perform build or test operations. Option D is wrong because AWS CodeCommit is a source control service for hosting Git repositories; it does not build or test code.

74
MCQmedium

A company is designing a serverless application using AWS Lambda that needs to access a private Amazon RDS for MySQL database. The Lambda function is deployed in a VPC with the appropriate security groups. The database is in a private subnet. The company wants to avoid storing database credentials in the Lambda function code. What should the company do to securely access the database?

A.Create an IAM role that allows Lambda to access the RDS instance using IAM database authentication.
B.Pass the database credentials as environment variables to the Lambda function.
C.Store the database credentials in AWS Secrets Manager and retrieve them using the Secrets Manager API in the Lambda function.
D.Store the database credentials in AWS Systems Manager Parameter Store and retrieve them in the Lambda function.
AnswerC

AWS Secrets Manager provides a secure, auditable service for storing and automatically rotating database credentials. The Lambda function can retrieve the credentials at runtime via the Secrets Manager API, avoiding hard-coded secrets.

Why this answer

Option C is the best answer. AWS Secrets Manager securely stores database credentials and supports automatic rotation, and Lambda can retrieve them at runtime through the Secrets Manager API without hardcoding credentials. Option A (IAM database authentication) is valid only if the RDS MySQL instance is explicitly configured for IAM authentication and is not the general best practice for avoiding stored credentials.

Option B exposes credentials in environment variables, and Option D (Parameter Store) lacks native automatic rotation for RDS credentials.

Exam trap

The trap here is that candidates may confuse AWS Systems Manager Parameter Store (Option D) with Secrets Manager, but Parameter Store lacks native automatic rotation and is not the best practice for database credentials requiring rotation, making Secrets Manager the correct choice for this scenario.

How to eliminate wrong answers

Option A is wrong because IAM database authentication for RDS MySQL requires the user to authenticate with an authentication token generated using the IAM credentials, but it does not eliminate the need to store the master password or other credentials; it only replaces password-based authentication for specific database users, and the Lambda function still needs to securely obtain the token, which Secrets Manager can provide. Option B is wrong because passing database credentials as environment variables to the Lambda function is insecure; environment variables can be exposed in logs, CloudTrail, or the Lambda console, and they do not support automatic rotation or fine-grained access control. Option D is wrong because AWS Systems Manager Parameter Store is a viable option for storing secrets, but it lacks native automatic rotation capabilities and is not the recommended service for database credentials requiring rotation; Secrets Manager is the preferred service for this use case.

75
MCQhard

A media company is designing a new video transcoding pipeline. Source files are uploaded to an Amazon S3 bucket, and a Lambda function must start an AWS Elemental MediaConvert job for each upload. Transcoding jobs take 20-40 minutes, and the company wants automatic retries with a dead-letter queue for failed job submissions, while avoiding duplicate jobs if the same object is processed twice. Which design meets these requirements?

A.Configure S3 Event Notifications to invoke the Lambda function synchronously through an Application Load Balancer, and rely on the Lambda function's built-in idempotency token to prevent duplicate MediaConvert jobs.
B.Use an S3 Event Notification to send messages to an Amazon SQS FIFO queue, have Lambda poll the queue, and rely on the FIFO message deduplication ID to ensure each S3 object produces exactly one MediaConvert job.
C.Enable S3 Event Notifications to invoke a Step Functions state machine that calls Lambda, and configure the state machine with a Retry policy and a Catch block to route failures to an SQS dead-letter queue, using the S3 ETag as the idempotency key.
D.Configure S3 Event Notifications to invoke the Lambda function asynchronously, set MaximumRetryAttempts to 2 and a dead-letter queue on the function, and use the S3 object versionId plus sequencer in the event to deduplicate job submissions in DynamoDB.
AnswerD

S3 event notifications invoke Lambda asynchronously, so asynchronous invocation retry settings and an on-failure destination or DLQ apply. MediaConvert job submission returns quickly, so the 15-minute Lambda limit is not a concern. Using the object versionId and sequencer from the event to conditionally write a deduplication record in DynamoDB prevents duplicate jobs when the same object triggers multiple events.

Why this answer

S3 event notifications invoke Lambda asynchronously, which is the only invocation mode where MaximumRetryAttempts and on-failure destinations such as a dead-letter queue apply. Because MediaConvert job submission is a short API call, the function finishes well within the Lambda timeout. Deduplication should use immutable S3 event metadata, namely the object versionId and sequencer, to conditionally record each event in DynamoDB so that repeated notifications for the same object version do not start a second transcoding job.

Exam trap

The trap here is assuming that S3 can invoke Lambda synchronously or that Lambda has built-in idempotency, when asynchronous invocation with retry settings and explicit deduplication logic is required.

Page 1 of 5 · 321 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design for New Solutions questions.