Courseiva

CCNA Design for New Solutions Questions

75 of 321 questions · Page 2/5 · Design for New Solutions · Answers revealed

76
MCQmedium

A company is designing a new microservices application on AWS. Each microservice needs to store and retrieve stateful data with low latency (single-digit milliseconds). The data must be durable and highly available across multiple Availability Zones. Which AWS service should be used for the primary data store for each microservice?

A.Amazon DynamoDB
B.Amazon S3
C.Amazon RDS with Multi-AZ
D.Amazon ElastiCache for Redis
AnswerA

DynamoDB delivers consistent single-digit-millisecond latency at any scale and replicates data across three Availability Zones by default, meeting the durability and multi-AZ availability requirements without managing servers. Its partition-based architecture sustains low latency as each microservice's dataset grows.

Why this answer

Amazon DynamoDB is a fully managed NoSQL key-value and document database that delivers single-digit millisecond latency at any scale. It is designed for high availability and durability by automatically replicating data across three Availability Zones in an AWS Region, meeting the requirements for stateful microservices data storage.

Exam trap

The SAP-C02 exam often tests the distinction between a durable primary data store and a cache or object store, where candidates mistakenly choose ElastiCache for its low latency without considering durability, or S3 for its high availability without recognizing its higher latency profile.

How to eliminate wrong answers

Option B is wrong because Amazon S3 is an object storage service designed for high throughput and large data volumes, not for low-latency single-digit millisecond access typical of microservices stateful data; its read/write latency is higher and it lacks native support for fine-grained updates. Option C is wrong because Amazon RDS with Multi-AZ provides high availability through synchronous replication to a standby instance, but it is a relational database that introduces overhead from SQL parsing and connection management, making it less suitable for the sub-10ms latency requirements of microservices compared to DynamoDB. Option D is wrong because Amazon ElastiCache for Redis is an in-memory cache, not a durable primary data store; while it offers low latency, its data is not durable by default (unless using Redis AOF with persistence, which still risks data loss on failure) and it is not designed for long-term stateful storage with the same durability guarantees as DynamoDB.

77
MCQeasy

A company needs to design a new solution for storing and retrieving user-uploaded images. The images are accessed frequently for the first 30 days and then rarely accessed after that. The company wants to minimize storage costs while maintaining low-latency access for frequently accessed images. Which storage strategy should be used?

A.Store images in Amazon EBS volumes attached to a web server.
B.Store images in Amazon S3 Standard and use lifecycle policies to transition to S3 Standard-IA after 30 days.
C.Store all images in Amazon S3 Glacier Flexible Retrieval.
D.Store all images in Amazon S3 Standard.
AnswerB

S3 Standard serves the first 30 days at low latency, then a lifecycle rule transitions objects to S3 Standard-IA, whose lower storage price suits rarely accessed data while retaining millisecond access. This minimises cost without sacrificing performance for frequent reads.

Why this answer

Amazon S3 Standard provides low-latency access for frequently accessed images, and S3 lifecycle policies allow automatic transition to S3 Standard-Infrequent Access (Standard-IA) after 30 days, reducing storage costs while maintaining rapid access for the initial period. This strategy directly meets the requirement of minimizing costs without sacrificing performance for the first 30 days.

Exam trap

The trap here is that candidates may choose Option D (all S3 Standard) because it guarantees low-latency access, overlooking the cost savings of transitioning to Standard-IA for data that becomes rarely accessed after 30 days.

How to eliminate wrong answers

Option A is wrong because Amazon EBS volumes are block-level storage attached to a single EC2 instance, not designed for storing and retrieving user-uploaded images at scale, and they incur costs even when not accessed, lacking lifecycle management for infrequent access. Option C is wrong because Amazon S3 Glacier Flexible Retrieval has retrieval times of minutes to hours, which does not provide low-latency access for frequently accessed images during the first 30 days. Option D is wrong because storing all images in Amazon S3 Standard incurs higher storage costs for data that becomes rarely accessed after 30 days, failing to minimize storage costs as required.

78
MCQeasy

A startup is building a serverless application using AWS Lambda for business logic and Amazon DynamoDB for data storage. The application must process a high volume of writes to a single DynamoDB table. The development team is concerned about throttling due to hot partitions. Which design should the team implement to avoid throttling?

A.Enable DynamoDB Accelerator (DAX) to cache write operations.
B.Use a composite primary key with a partition key that has high cardinality, such as a user ID.
C.Use a global secondary index (GSI) as the primary index for writes.
D.Add a local secondary index (LSI) to the table.
AnswerB

A high-cardinality partition key such as user ID spreads writes across many physical partitions, preventing any single partition from becoming a hot spot. This directly addresses the throttling constraint caused by uneven write distribution in the single DynamoDB table.

Why this answer

Using a partition key with high cardinality, such as a user ID, ensures that write requests are evenly distributed across all partitions in the DynamoDB table. This prevents any single partition from becoming a hot partition, which would otherwise lead to throttling when the partition's throughput capacity is exceeded. DynamoDB scales by splitting partitions based on the partition key's hash, so high cardinality is essential for avoiding throttling under high write volumes.

Exam trap

The trap here is that candidates often confuse caching (DAX) as a solution for write performance, not realizing DAX only accelerates reads, or they mistakenly believe that secondary indexes (GSI/LSI) can redistribute write load, when in fact they share the base table's partition key and do not solve hot partition issues.

How to eliminate wrong answers

Option A is wrong because DynamoDB Accelerator (DAX) is an in-memory cache for read operations only; it does not cache or accelerate write operations, so it cannot prevent write throttling. Option C is wrong because a global secondary index (GSI) is a secondary index that supports read and write operations, but it does not replace the primary index for writes; writes are still directed to the base table's partition key, and using a GSI as the primary index is not a valid design—GSIs have their own throughput and can also experience throttling if not properly provisioned. Option D is wrong because a local secondary index (LSI) shares the same partition key as the base table and does not improve write distribution; it only provides an alternative sort key for querying within a partition, so it does not address hot partition issues.

79
Multi-Selecteasy

A company is designing a new static website hosted on Amazon S3. They want to use Amazon CloudFront as a content delivery network (CDN) to serve the website globally with low latency. The website content must be encrypted in transit. Which configurations should they use? (Choose TWO.)

Select 2 answers
A.Enable default encryption on the S3 bucket using AES-256.
B.Enable S3 Transfer Acceleration on the bucket.
C.Configure the S3 bucket policy to deny requests that do not use HTTPS.
D.Configure CloudFront to require HTTPS for viewer requests.
E.Use CloudFront signed URLs to restrict access.
AnswersC, D

A bucket policy denying requests where aws:SecureTransport is false rejects any plaintext HTTP access to S3 objects. This satisfies the encrypted-in-transit requirement by ensuring content cannot be fetched from the origin over an unencrypted connection.

Why this answer

Option C is correct because enforcing an S3 bucket policy with a Deny effect on aws:SecureTransport false ensures that any request reaching the S3 origin (including from CloudFront or direct callers) must use HTTPS/TLS, satisfying encryption in transit at the origin. Option D is correct because setting the CloudFront distribution's viewer protocol policy to redirect HTTP to HTTPS (or HTTPS only) guarantees that all client-to-edge traffic is encrypted with TLS, which is the primary in-transit path for a global static website. Option A is incorrect because AES-256 default encryption is server-side encryption at rest, not in transit.

Option B is incorrect because S3 Transfer Acceleration speeds up uploads/downloads using AWS edge locations but does not enforce or provide encryption in transit. Option E is incorrect because CloudFront signed URLs control access/authorization to content, not transport encryption.

Exam trap

The trap here is that candidates often confuse encryption at rest (S3 default encryption) with encryption in transit, or they assume that CloudFront's default HTTPS support automatically secures the S3 origin connection without needing a bucket policy to enforce it.

80
MCQmedium

A company is designing a new microservices architecture on AWS. The company wants to use a service mesh to manage service-to-service communication, observability, and security. Which AWS service should the company use?

A.Amazon API Gateway
B.AWS App Mesh
C.AWS Transit Gateway
D.AWS Cloud Map
AnswerB

AWS App Mesh provides a managed service mesh that handles service-to-service communication, observability and traffic control across microservices. It satisfies the stem's requirement for a dedicated mesh layer by injecting Envoy proxies alongside tasks, delivering consistent routing, retries and mutual TLS without application code changes.

Why this answer

AWS App Mesh is a service mesh that provides application-level networking to manage service-to-service communication, observability (via metrics, logs, and traces), and security (via mTLS and fine-grained access policies) for microservices. It uses the Envoy proxy as a sidecar to intercept traffic, enabling features like traffic splitting, retries, and circuit breaking without modifying application code.

Exam trap

The trap here is that candidates often confuse a service mesh (App Mesh) with an API gateway (API Gateway), but API Gateway is designed for external-facing API management, not for internal service-to-service traffic control and observability within a microservices mesh.

How to eliminate wrong answers

Option A is wrong because Amazon API Gateway is a fully managed API gateway for creating, publishing, and securing REST/HTTP/WebSocket APIs at the edge, not a service mesh for internal service-to-service communication within a microservices architecture. Option C is wrong because AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks via a central router, operating at Layer 3, not at the application layer required for service mesh capabilities like traffic splitting and observability. Option D is wrong because AWS Cloud Map is a cloud resource discovery service that allows services to register and discover instances via DNS or API calls, but it does not provide traffic management, observability, or security features inherent to a service mesh.

81
MCQmedium

A company deployed the above CloudFormation template. An EC2 instance launched in the PrivateSubnet needs to access the internet for software updates. Which action is required?

A.Create a VPC Peering connection to a public VPC
B.Add a NAT Gateway in the PublicSubnet and update the PrivateSubnet's route table to point to the NAT Gateway
C.Add an Internet Gateway to the VPC and route the private subnet's route table to it
D.Modify the PrivateSubnet to assign public IP addresses on launch
AnswerB

A private subnet has no route to an internet gateway. Deploying a NAT Gateway in the public subnet and adding a 0.0.0.0/0 route in the private subnet's route table lets instances initiate outbound updates while remaining unreachable inbound.

Why this answer

A NAT Gateway placed in a public subnet with an Internet Gateway attached allows instances in private subnets to initiate outbound traffic to the internet (e.g., for software updates) while preventing inbound connections from the internet. The private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway. This is the standard AWS pattern for outbound-only internet access from private subnets.

Exam trap

The trap here is that candidates often confuse a NAT Gateway with an Internet Gateway, thinking that routing a private subnet directly to an Internet Gateway is sufficient, but this would expose instances to inbound traffic and require public IPs, defeating the purpose of a private subnet.

How to eliminate wrong answers

Option A is wrong because VPC Peering does not provide internet access; it only connects two VPCs privately, and neither VPC inherently has internet access without an Internet Gateway. Option C is wrong because routing a private subnet directly to an Internet Gateway would allow inbound internet traffic, violating the security model of a private subnet; Internet Gateways require public IP addresses and are used with public subnets. Option D is wrong because assigning public IP addresses to instances in a private subnet does not grant internet access; the subnet still lacks a route to an Internet Gateway, and public IPs alone cannot reach the internet without a gateway.

82
MCQeasy

A company is designing a new web application on AWS. The application must be highly available and scale automatically based on traffic. The architecture includes an Application Load Balancer (ALB) and an Auto Scaling group of EC2 instances. The application stores session state. What is the BEST way to handle session state to ensure high availability?

A.Store session state in Amazon DynamoDB
B.Store session state on the local instance store of each EC2 instance
C.Store session state in Amazon S3
D.Store session state in Amazon ElastiCache for Redis
AnswerD

ElastiCache for Redis externalises session state into a replicated, Multi-AZ in-memory store, so any Auto Scaling EC2 instance behind the ALB can serve any user; instance loss or scale-in no longer drops sessions, preserving high availability.

Why this answer

Amazon ElastiCache for Redis is the best choice for handling session state in a highly available, auto-scaling web application because it provides a centralized, in-memory data store that is external to the EC2 instances. This ensures that session data persists independently of instance lifecycle events (e.g., scaling in/out or failures), and Redis offers sub-millisecond latency, replication, and automatic failover, which are critical for maintaining session continuity across the fleet.

Exam trap

The trap here is that candidates often choose DynamoDB (Option A) because it is a managed, highly available database, but they overlook the latency and cost implications for session state, which is a classic in-memory caching use case where ElastiCache for Redis is the optimal AWS service.

How to eliminate wrong answers

Option A is wrong because Amazon DynamoDB, while highly available and scalable, is a NoSQL database designed for document and key-value storage with higher latency compared to in-memory caches; it is not optimized for the low-latency, high-throughput session state access patterns required by web applications, and its cost per operation is typically higher than ElastiCache for this use case. Option B is wrong because storing session state on the local instance store of each EC2 instance ties session data to a specific instance; if the instance is terminated, replaced, or scaled in, all session data is lost, breaking high availability and user experience. Option C is wrong because Amazon S3 is an object storage service with significantly higher latency (typically tens to hundreds of milliseconds) compared to in-memory stores, and it is not designed for frequent, low-latency read/write operations required for session management; additionally, S3 lacks native session expiration and atomic operations needed for session handling.

83
MCQeasy

A company is designing a new application that will store sensitive customer data in Amazon S3. The company must ensure that the data is encrypted at rest and that the encryption keys are rotated automatically every year. The company also wants to audit key usage. Which solution will meet these requirements?

A.Use server-side encryption with customer-provided keys (SSE-C).
B.Use server-side encryption with AWS KMS customer managed keys (SSE-KMS) and enable automatic key rotation.
C.Use server-side encryption with Amazon S3 managed keys (SSE-S3).
D.Use client-side encryption with an AWS KMS customer managed key and store the encrypted data in Amazon S3.
AnswerB

SSE-KMS with customer managed keys allows the company to control the KMS key, enable automatic annual rotation, and audit key usage through AWS CloudTrail. This meets all requirements: encryption at rest, automatic key rotation, and auditing. Customer managed keys also provide granular access control and the ability to disable or revoke the key if needed.

Why this answer

Using SSE-KMS with AWS KMS customer managed keys enables automatic annual key rotation and provides audit trails of key usage via AWS CloudTrail. This meets the requirements for encryption at rest, automatic rotation, and auditing. Customer managed keys also allow the company to control access and lifecycle, which is important for sensitive data.

Other encryption options either lack auditing, require manual key management, or add unnecessary complexity.

Exam trap

The trap here is assuming that SSE-S3 automatically rotates keys and provides auditing, when in fact auditing key usage requires AWS KMS and customer managed keys.

84
Multi-Selectmedium

A company is designing a solution to process real-time streaming data from IoT devices. The data must be ingested, processed with sub-second latency, and stored for analytics. Which services should the company use? (Choose TWO.)

Select 2 answers
A.AWS Lambda
B.Amazon Kinesis Data Streams
C.Amazon SQS
D.Amazon Kinesis Data Analytics
E.Amazon Kinesis Data Firehose
AnswersA, B

Can process records from Kinesis streams in near real-time.

Why this answer

AWS Lambda is correct because it can process streaming data from Amazon Kinesis Data Streams with sub-second latency by subscribing to the stream as an event source. Lambda functions are invoked synchronously with each record, enabling real-time transformations or lightweight analytics before the data is stored.

Exam trap

The trap here is that candidates often confuse Amazon Kinesis Data Firehose (which has a 60-second minimum buffer) with Kinesis Data Streams for sub-second latency, or they mistakenly think SQS is suitable for streaming ingestion when it is designed for message queuing, not ordered, replayable stream processing.

85
MCQeasy

Refer to the exhibit. An IAM policy allows ec2:Describe* actions on all resources. A developer wants to also allow describing RDS instances. Which action must be added to the policy?

A.rds:List*
B.rds:Get*
C.rds:Describe*
D.ec2:DescribeRdsInstances
AnswerC

Adding `rds:Describe*` grants the specific RDS read permissions the developer needs, satisfying the requirement to describe RDS instances. IAM evaluates actions per service namespace, so EC2's `ec2:Describe*` wildcard never covers RDS API calls; a separate RDS statement is mandatory.

Why this answer

AWS IAM policies use the `rds:Describe*` action to grant permission to describe RDS instances, DB snapshots, DB parameter groups, and other RDS resources. The `ec2:Describe*` action only covers EC2 resources, not RDS resources, so a separate RDS-specific action is required. The wildcard `*` after `Describe` matches all RDS describe operations, including `rds:DescribeDBInstances`.

Exam trap

The trap here is that candidates assume `ec2:Describe*` covers all AWS describe operations across services, but IAM actions are scoped per service namespace (e.g., `ec2:`, `rds:`), and each service has its own set of actions.

How to eliminate wrong answers

Option A is wrong because `rds:List*` is not a valid IAM action prefix for RDS; RDS uses `Describe` actions for read operations, not `List`. Option B is wrong because `rds:Get*` is not a valid IAM action for RDS; AWS RDS API uses `Describe` actions (e.g., `DescribeDBInstances`) rather than `Get` actions. Option D is wrong because `ec2:DescribeRdsInstances` does not exist; EC2 and RDS are separate services with distinct action namespaces, and RDS actions must use the `rds:` prefix.

86
Multi-Selecthard

A company is designing a new application that will use Amazon DynamoDB as its database. The application will have a heavy read workload with occasional write spikes. The company wants to minimize costs while ensuring that reads are eventually consistent and writes are not throttled. Which three options should the architect consider? (Choose THREE.)

Select 3 answers
A.Use DynamoDB Streams to asynchronously replicate data to a second table for reads
B.Use Auto Scaling for write capacity
C.Use eventually consistent reads for most queries
D.Use DynamoDB Accelerator (DAX) to cache read results
E.Use strongly consistent reads for all queries
AnswersB, C, D

Auto Scaling adjusts write capacity to handle spikes without throttling.

Why this answer

DynamoDB Auto Scaling adjusts the provisioned write capacity based on actual traffic, preventing throttling during write spikes while reducing capacity and cost during low-traffic periods. This meets the requirement to minimize costs and avoid write throttling without manual intervention.

Exam trap

The trap here is that candidates may confuse DynamoDB Streams with a caching solution, or incorrectly assume strongly consistent reads are always required, ignoring the cost implications of RCU consumption for read-heavy workloads.

87
MCQmedium

A company is designing a new application that will be deployed on AWS. The application consists of a web tier running on Amazon EC2 instances and a database tier using Amazon Aurora. The company expects unpredictable traffic patterns and wants to optimize costs while maintaining high availability. The web tier must automatically scale based on demand, and the database must be able to handle read-heavy workloads. What should a solutions architect recommend?

A.Use AWS Lambda for the web tier with provisioned concurrency, and use Aurora Serverless for the database.
B.Use an Auto Scaling group with a scheduled scaling policy for the web tier, and use a single Aurora instance with a larger instance size for the database.
C.Use an Auto Scaling group for the web tier with a target tracking scaling policy, and add Aurora Replicas to the Aurora cluster for read scaling.
D.Use an Auto Scaling group with a simple scaling policy for the web tier, and enable Aurora Auto Scaling for the database.
AnswerC

An Auto Scaling group with target tracking can automatically adjust the number of EC2 instances based on metrics like CPU utilization, optimizing costs during low demand. Aurora Replicas offload read traffic from the primary instance, improving read scalability and performance. This combination provides high availability and cost efficiency for unpredictable traffic.

Why this answer

The recommended solution is to use an Auto Scaling group with a target tracking scaling policy for the web tier, which dynamically adjusts capacity based on demand, and to add Aurora Replicas to the Aurora cluster to handle read-heavy workloads. This provides high availability, cost optimization, and read scalability. Other options either use less responsive scaling policies or change the architecture unnecessarily.

Exam trap

The trap here is assuming that scheduled scaling can handle unpredictable traffic, but it is designed for predictable patterns and may not react to sudden spikes.

88
MCQmedium

A company is designing a new application that will process sensitive financial data. The application must encrypt data at rest and in transit. The company wants to use AWS managed keys for encryption. Which AWS service should the company use to create and manage the encryption keys?

A.AWS CloudHSM
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.AWS Certificate Manager (ACM)
AnswerC

AWS Key Management Service creates and manages the AWS managed keys that encrypt the financial data at rest, and integrates with services for in-transit protection. It directly meets the requirement to use AWS managed keys for key creation and management.

Why this answer

AWS Key Management Service (KMS) is the correct choice because it is a managed service that enables you to create, store, and control encryption keys used to encrypt data at rest and in transit. KMS integrates with other AWS services (e.g., S3, EBS, RDS) and supports envelope encryption, where a customer master key (CMK) encrypts data keys that perform the actual encryption. It also provides automatic key rotation and fine-grained access control via IAM policies and key policies, meeting the requirement for AWS-managed keys.

Exam trap

The trap here is that candidates often confuse AWS CloudHSM (which provides dedicated, customer-managed HSMs) with KMS (which provides fully managed, AWS-controlled keys), leading them to choose CloudHSM when the question explicitly requires 'AWS managed keys'.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules (HSMs) that you manage yourself, not AWS-managed keys; it requires you to handle key lifecycle and scaling, and does not offer the same level of integration with AWS services as KMS. Option B is wrong because AWS Secrets Manager is designed to securely store and rotate secrets (e.g., database credentials, API keys), not to create or manage encryption keys; it can use KMS to encrypt those secrets, but it is not a key management service itself. Option D is wrong because AWS Certificate Manager (ACM) is used to provision, manage, and deploy public and private SSL/TLS certificates for securing network traffic (in transit), but it does not create or manage encryption keys for data at rest; it relies on KMS for private key protection in some cases, but its primary function is certificate lifecycle management.

89
MCQmedium

A company is deploying a containerized application on Amazon ECS. The application must be highly available and scale automatically based on CPU utilization. The application also needs to be accessible from the internet via a single endpoint. Which combination of services should the solutions architect use?

A.Amazon ECS with an Application Load Balancer and ECS Service Auto Scaling with a target tracking policy based on average CPU utilization.
B.Amazon ECS with a Network Load Balancer and step scaling policies.
C.Amazon ECS with an Application Load Balancer and step scaling policies based on CPU utilization.
D.Amazon ECS with an Application Load Balancer and manual scaling.
AnswerA

An Application Load Balancer provides the single internet-facing endpoint and distributes traffic across ECS tasks in multiple Availability Zones, while target tracking on average CPU utilisation adjusts desired task count automatically. This combination directly satisfies the high availability, automatic scaling, and single endpoint constraints.

Why this answer

An Application Load Balancer (ALB) provides a single internet-facing endpoint and supports HTTP/HTTPS traffic, which is typical for containerized applications. ECS Service Auto Scaling with a target tracking policy based on average CPU utilization allows the service to automatically adjust the desired count of tasks to maintain a specified CPU utilization target, ensuring high availability and elasticity.

Exam trap

The trap here is that candidates often confuse step scaling with target tracking, assuming step scaling is required for CPU-based scaling, but target tracking is the simpler and more AWS-recommended approach for maintaining a specific utilization target.

How to eliminate wrong answers

Option B is wrong because a Network Load Balancer (NLB) operates at Layer 4 and does not support HTTP/HTTPS path-based routing or host-based routing, which are often needed for containerized applications; also, step scaling policies are less precise than target tracking for maintaining a specific CPU utilization metric. Option C is wrong because while it uses an ALB, step scaling policies are not the recommended approach for scaling based on CPU utilization—target tracking policies are simpler and more effective as they automatically adjust to maintain a target metric value. Option D is wrong because manual scaling does not provide automatic scaling based on CPU utilization, which is a requirement for the application to scale automatically.

90
MCQeasy

A company is designing a highly available web application on AWS. The application consists of an Application Load Balancer (ALB) that distributes traffic to EC2 instances in an Auto Scaling group across multiple Availability Zones. The application state is stored in an Amazon ElastiCache for Redis cluster. The company wants to minimize downtime during patching of the Redis cluster. What should the company do?

A.Increase the Redis node type to handle the load and rely on the ElastiCache maintenance window.
B.Use a blue/green deployment strategy by creating a new Redis cluster and switching the application endpoint.
C.Deploy the Redis cluster with Multi-AZ and automatic failover enabled across two Availability Zones.
D.Deploy the Redis cluster as a single node in one Availability Zone and take regular snapshots.
AnswerC

Multi-AZ with automatic failover maintains a synchronous standby replica in a second Availability Zone, so Redis promotes the replica automatically when the primary is patched. This satisfies the requirement to minimise downtime during patching without manual intervention or data loss.

Why this answer

Deploying ElastiCache for Redis with Multi-AZ and automatic failover enabled ensures that if the primary node fails or requires patching, a read replica in a different Availability Zone is automatically promoted to primary, minimizing downtime. This aligns with the requirement for high availability during patching, as ElastiCache handles failover transparently without manual intervention.

Exam trap

The trap here is that candidates may confuse scaling (Option A) or manual migration strategies (Option B) with the native high-availability feature of ElastiCache Multi-AZ, which is specifically designed to handle patching and failures with minimal downtime.

How to eliminate wrong answers

Option A is wrong because increasing the node type only improves capacity and performance, not availability; it does not address downtime during patching, as the single node still experiences an outage during maintenance. Option B is wrong because a blue/green deployment for Redis would require manual endpoint switching and data synchronization, which is complex and introduces potential data loss or inconsistency; ElastiCache's built-in Multi-AZ failover is simpler and more reliable for patching. Option D is wrong because a single-node cluster in one Availability Zone has no redundancy; patching or any failure causes complete downtime, and snapshots only aid recovery, not high availability.

91
MCQeasy

A company has three EC2 instances as shown in the exhibit. The company wants to use an Application Load Balancer to distribute traffic across these instances with cross-zone load balancing enabled. How will the traffic be distributed?

A.Traffic is distributed evenly across the two availability zones.
B.Instances in us-east-1a receive 67% of traffic, us-east-1b receives 33%.
C.Each instance receives an equal share of traffic.
D.Traffic is sent to the instance with the least outstanding requests.
AnswerC

With cross-zone load balancing enabled, the load balancer node in each Availability Zone distributes requests evenly to all registered targets in every enabled AZ, so each of the three instances receives an equal one-third share of traffic.

Why this answer

With cross-zone load balancing enabled on an Application Load Balancer, traffic is distributed evenly across all registered targets regardless of the availability zone they reside in. Since there are three EC2 instances, each instance receives an equal share (33.3%) of the incoming traffic, ensuring balanced load across all instances.

Exam trap

The trap here is that candidates often confuse cross-zone load balancing with zone-level distribution, mistakenly thinking traffic is split by availability zone count rather than by individual instance count, or they incorrectly attribute the least outstanding requests algorithm to the Application Load Balancer.

How to eliminate wrong answers

Option A is wrong because cross-zone load balancing distributes traffic evenly across instances, not across availability zones; the ALB does not balance by zone when cross-zone is enabled. Option B is wrong because it incorrectly assumes a zone-based distribution proportional to instance count (2 instances in us-east-1a, 1 in us-east-1b), but cross-zone load balancing overrides zone-level weighting to give each instance an equal share. Option D is wrong because the Application Load Balancer uses a round-robin algorithm by default, not least outstanding requests; the least outstanding requests routing algorithm is used by the Network Load Balancer, not the ALB.

92
MCQhard

A security engineer created the S3 bucket policy shown in the exhibit. The policy is intended to allow the role MyAppRole to get objects only if they are encrypted with SSE-S3. However, the role is getting access denied errors when trying to get objects that are encrypted with SSE-S3. What is the most likely cause?

A.The Principal is incorrect; it should be the role name, not ARN.
B.The Resource ARN is incorrect; it should be 'arn:aws:s3:::my-bucket'.
C.The condition key is misspelled.
D.The condition key 's3:x-amz-server-side-encryption' checks the request header, not the object's encryption state.
AnswerD

The condition evaluates the request header, which may not be set when getting an already encrypted object.

Why this answer

The condition key `s3:x-amz-server-side-encryption` evaluates the `x-amz-server-side-encryption` request header sent by the client during the GET request, not the encryption state of the object stored in S3. Since the role is making GET requests without this header (or with a different value), the condition fails even though the object is encrypted with SSE-S3. To enforce that only objects encrypted with SSE-S3 can be retrieved, you must use a different approach, such as a bucket policy with `s3:ExistingObjectTag` or a pre-signed URL that includes the required header.

Exam trap

The trap here is that candidates assume `s3:x-amz-server-side-encryption` evaluates the object's stored encryption state, when in fact it only evaluates the request header, leading to a false sense of security and access denied errors when the header is missing.

How to eliminate wrong answers

Option A is wrong because the Principal field in an S3 bucket policy can accept an IAM role ARN (e.g., `arn:aws:iam::123456789012:role/MyAppRole`) and is syntactically correct; using the role name alone would be invalid. Option B is wrong because the Resource ARN `arn:aws:s3:::my-bucket/*` correctly specifies all objects within the bucket, and changing it to `arn:aws:s3:::my-bucket` would apply to the bucket itself, not its objects, which would not match the `s3:GetObject` action. Option C is wrong because the condition key `s3:x-amz-server-side-encryption` is spelled correctly; the issue is not a typo but a fundamental misunderstanding of what the key evaluates.

93
Multi-Selecteasy

A company is designing a new web application that will be deployed on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be highly available and fault-tolerant across multiple Availability Zones. Which THREE actions should the company take to meet these requirements? (Choose three.)

Select 3 answers
A.Launch EC2 instances in an Auto Scaling group across multiple Availability Zones.
B.Use a larger EC2 instance type to handle failures.
C.Configure health checks on the ALB target group to automatically replace unhealthy instances.
D.Configure the ALB to route traffic to instances in multiple Availability Zones.
E.Use a single Availability Zone to reduce latency.
AnswersA, C, D

Launching EC2 instances in an Auto Scaling group across multiple Availability Zones satisfies the fault-tolerance requirement by distributing capacity so that an AZ failure does not take down the application. The Auto Scaling group also replaces unhealthy instances automatically, maintaining the desired capacity behind the ALB.

Why this answer

Option A is correct because an Auto Scaling group spanning multiple Availability Zones maintains capacity and automatically launches replacement instances when an AZ or instance fails, which is the foundation of high availability and fault tolerance. Option C is correct because ALB target group health checks continuously probe registered targets and, combined with the Auto Scaling group, cause unhealthy instances to be detected and replaced, restoring healthy capacity. Option D is correct because an Application Load Balancer is a regional, multi-AZ service that must have targets registered in multiple Availability Zones so it can route traffic away from a failed AZ and continue serving requests.

Option B is not correct because a larger instance type only increases the capacity of a single instance and does nothing to provide redundancy across Availability Zones or to recover from failures. Option E is not correct because confining the deployment to a single Availability Zone creates a single point of failure and directly violates the multi-AZ high availability and fault tolerance requirement.

Exam trap

The trap here is that candidates often confuse vertical scaling (larger instances) with horizontal scaling and fault tolerance, or mistakenly think that using a single Availability Zone can be compensated by other means, ignoring the fundamental requirement for multi-AZ deployment.

94
MCQmedium

A company runs a stateful web application on a single Amazon EC2 instance. The application writes data to a locally attached instance store volume. The company wants to improve the durability of the data without modifying the application. The data must survive an instance stop/start and be available if the instance is terminated and relaunched. What should a solutions architect recommend?

A.Enable termination protection on the EC2 instance.
B.Move the data to an Amazon EBS volume with the DeleteOnTermination flag set to false.
C.Create an Amazon Machine Image (AMI) of the instance after each data change.
D.Use an Auto Scaling group with a launch template that includes the instance store volume.
AnswerB

EBS volumes provide persistent block storage that is replicated within an Availability Zone. By setting DeleteOnTermination to false, the volume persists even if the instance is terminated. The volume can be reattached to a new instance. This ensures data durability across instance stop/start and termination, without application changes.

Why this answer

Amazon EBS volumes are durable, persistent block storage that can be detached from one instance and attached to another. Setting DeleteOnTermination to false ensures the volume remains after instance termination. The application can continue to write to the same mount point, so no code changes are needed.

This provides the required data durability across instance stop/start and termination.

Exam trap

The trap here is assuming that instance store data persists after a stop/start, when in fact instance store is ephemeral and data is lost on stop or termination.

95
MCQhard

A company is deploying a web application on AWS Elastic Beanstalk. The application must be accessible over HTTPS only and must automatically redirect HTTP requests to HTTPS. The SSL/TLS certificate is provided by AWS Certificate Manager (ACM). How should this be configured?

A.Use a NAT instance to perform SSL termination and redirect.
B.Install the certificate on each EC2 instance and configure the web server to redirect HTTP to HTTPS.
C.Configure the environment’s load balancer to listen on port 443 with the ACM certificate and port 80 with a redirect rule.
D.Deploy a CloudFront distribution with the ACM certificate and redirect HTTP to HTTPS at the distribution level.
AnswerC

An Application Load Balancer listener on port 443 with the ACM certificate terminates TLS, while a port 80 listener with a redirect rule sends HTTP clients to HTTPS. This satisfies the HTTPS-only requirement without modifying the application itself.

Why this answer

Elastic Beanstalk environments using a load balancer (ALB or CLB) can be configured to listen on port 443 with the ACM certificate for HTTPS termination, and simultaneously define a listener on port 80 with a redirect action that sends HTTP traffic to HTTPS. This is the simplest and most scalable approach, as it offloads SSL termination and redirection to the load balancer, eliminating the need to manage certificates or redirection logic on individual instances.

Exam trap

The trap here is that candidates often assume SSL termination must happen on the EC2 instances (Option B) or that a separate service like CloudFront (Option D) is required, when in fact the Elastic Beanstalk load balancer can natively handle both HTTPS termination and HTTP-to-HTTPS redirection with minimal configuration.

How to eliminate wrong answers

Option A is wrong because a NAT instance is used for outbound traffic from private subnets, not for SSL termination or HTTP-to-HTTPS redirection; it does not support load balancing or certificate management. Option B is wrong because installing the certificate on each EC2 instance and configuring the web server to redirect HTTP to HTTPS is inefficient, requires manual certificate renewal, and does not leverage Elastic Beanstalk's managed load balancer for centralized SSL termination. Option D is wrong because while CloudFront can redirect HTTP to HTTPS, it adds unnecessary complexity and cost for a simple single-region web app; the question specifically asks about configuring the Elastic Beanstalk environment, not an external CDN.

96
MCQeasy

A company is designing a new internal web application for its employees. The application must be accessible only from the corporate network, which connects to AWS via an AWS Site-to-Site VPN. The company wants to use an Application Load Balancer (ALB) to distribute traffic to EC2 instances. The solution must ensure that the ALB is not accessible from the internet. Which configuration should be used?

A.Create an internet-facing ALB in a private subnet and attach a network ACL that denies all traffic except the corporate CIDR.
B.Create an internal ALB in a private subnet and attach a security group that allows traffic from the corporate network CIDR.
C.Create an internet-facing ALB in a public subnet and attach a security group that allows only the corporate network CIDR.
D.Create an internal ALB in a public subnet and attach a security group that allows only the corporate network CIDR.
AnswerB

An internal ALB has only private IP addresses and its DNS name resolves to private IPs, so it is not reachable from the internet. Placing it in a private subnet and allowing the corporate CIDR via security group ensures that only traffic from the VPN can reach the load balancer, meeting the requirement for internal-only access.

Why this answer

The requirement is for an ALB that is not accessible from the internet but is reachable from the corporate network over VPN. An internal ALB provides a private DNS name and private IP addresses, ensuring no internet exposure. Placing it in a private subnet and using a security group to allow only the corporate CIDR restricts access to the intended source.

This combination satisfies the security and accessibility requirements.

Exam trap

The trap here is assuming that security groups alone can make an internet-facing ALB private, when the ALB's scheme itself determines internet reachability.

97
MCQhard

A company is designing a new multi-region application that requires a global database with low-latency reads and writes. The application must be able to survive a regional outage. Which database solution should they choose?

A.Amazon RDS Multi-AZ
B.Amazon ElastiCache for Redis global datastore
C.Amazon DynamoDB global tables
D.Amazon Aurora Global Database
AnswerC

Amazon DynamoDB global tables provide active-active replication across chosen Regions, delivering single-digit-millisecond reads and writes locally while surviving a full regional outage. This satisfies the stem's dual constraints: low-latency access in every Region and continued operation when one Region fails, without manual failover intervention.

Why this answer

Amazon DynamoDB global tables provide a fully managed, multi-region, multi-primary database that delivers low-latency reads and writes globally. The service replicates data across multiple AWS Regions automatically, allowing writes to be performed in any region with conflict resolution. In the event of a regional outage, traffic can be directed to another region, ensuring high availability.

In contrast, Amazon Aurora Global Database has a single primary region for writes, so writes are not low-latency across regions.

Exam trap

Candidates often choose Aurora Global Database because it supports global reads and regional failover, but they overlook that the requirement for low-latency writes globally is better met by DynamoDB global tables' active-active model.

How to eliminate wrong answers

Option A is wrong because Amazon RDS Multi-AZ provides high availability within a single region by synchronously replicating to a standby in a different Availability Zone, but it does not support cross-region failover or global low-latency writes. Option B is wrong because Amazon ElastiCache for Redis global datastore is a caching layer, not a durable database; it provides cross-region replication for cached data but does not offer persistent storage or transactional write guarantees required for a primary database. Option C is wrong because Amazon DynamoDB global tables replicate data across regions for low-latency reads and writes, but they are eventually consistent for writes (last-writer-wins) and do not support the strong consistency and cross-region failover semantics that Aurora Global Database provides for relational workloads; the question does not specify a NoSQL requirement, and DynamoDB global tables are not the best fit for a relational database pattern.

98
Multi-Selecthard

A company is designing a new disaster recovery solution for a critical application running on Amazon EC2. They need to replicate data across AWS Regions with a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. Which THREE actions should they take to meet these objectives?

Select 3 answers
A.Manually create and copy AMIs to the secondary region weekly
B.Create a CloudFormation template to provision the infrastructure in the secondary region
C.Use AWS Backup to automate cross-region EBS snapshot copies
D.Enable cross-region replication on the Amazon S3 buckets containing application data
E.Configure the EC2 instances in a Multi-AZ Auto Scaling group
AnswersB, C, D

CloudFormation allows rapid deployment of infrastructure in the DR region.

Why this answer

AWS CloudFormation templates enable infrastructure-as-code, allowing rapid and consistent provisioning of the secondary region environment. This automation is essential to meet the 1-hour RTO, as it eliminates manual setup and reduces recovery time to minutes by deploying pre-defined stacks.

Exam trap

The trap here is that candidates often confuse Multi-AZ (which provides high availability within a single Region) with cross-region disaster recovery, leading them to incorrectly select Option E despite it not addressing regional isolation.

99
MCQhard

A financial services company is designing a new multi-account landing zone. A central security team must be able to audit all API activity across every account, and each business unit must be prevented from disabling the audit trail. The company uses AWS Organizations with all features enabled. The solutions architect needs a solution that captures management events from all accounts in one place and enforces immutability of the logs. Which combination of actions should the architect take?

A.Create an individual trail in each account and configure each trail to deliver to a shared S3 bucket; use AWS Config rules to detect deletion of the trails.
B.Use AWS Control Tower to create a landing zone and enable the AWS CloudTrail configuration in the security OU; rely on the default CloudTrail trail created by Control Tower for audit.
C.Create an organization trail in AWS CloudTrail that applies to all accounts, deliver logs to a central S3 bucket, and apply an S3 bucket policy with a Deny for s3:DeleteObject and s3:PutBucketPolicy to all principals except the security account.
D.Enable AWS CloudTrail Lake in the management account and configure event data stores for each member account; use IAM policies to restrict access to the event data stores.
AnswerC

An organization trail automatically applies to every account in AWS Organizations, including new accounts, and delivers events to a central bucket. Combining it with a bucket policy that denies deletion and policy changes to non-security principals enforces immutability. This directly meets the audit and tamper-prevention requirements with minimal per-account configuration.

Why this answer

An organization trail in CloudTrail applies automatically to all accounts in AWS Organizations and delivers management events to a central S3 bucket. Adding a bucket policy that denies deletion and policy modification to all principals except the security account prevents business units from tampering with the audit logs, satisfying both centralization and immutability requirements.

Exam trap

The trap here is assuming that AWS Config or Control Tower alone prevents trail tampering, when preventive enforcement requires an explicit S3 bucket policy deny.

100
MCQmedium

A company is designing a new microservices architecture on AWS. Each service needs to store and retrieve small amounts of configuration data (under 10 KB per item) with low latency. The data is accessed frequently and must be highly available across multiple Availability Zones. Which AWS service should be used?

A.Amazon S3
B.Amazon ElastiCache for Memcached
C.Amazon RDS for MySQL
D.Amazon DynamoDB
AnswerD

DynamoDB stores items up to 400 KB, so sub-10 KB configuration data fits comfortably, and its multi-AZ replication delivers the required high availability. Provisioned throughput with single-digit millisecond latency suits frequent access, while key-value lookups avoid the overhead of relational joins or filesystem semantics.

Why this answer

Amazon DynamoDB is the correct choice because it is a fully managed NoSQL key-value and document database that delivers single-digit millisecond latency at any scale, making it ideal for frequently accessed configuration data under 10 KB. It provides built-in high availability and durability by automatically replicating data across three Availability Zones in an AWS Region, meeting the requirement for multi-AZ resilience without manual setup.

Exam trap

The trap here is that candidates often choose Amazon S3 for any 'storage' need without considering latency requirements, or they pick ElastiCache thinking it provides durable storage, when in fact DynamoDB is the only option that combines low latency, high availability across AZs, and native persistence for small configuration items.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service designed for larger objects (minimum 0 bytes, but optimal for >128 KB) and while it can store small items, its latency is higher (typically tens to hundreds of milliseconds) and it is not optimized for frequent, low-latency reads of sub-10 KB configuration data. Option B is wrong because Amazon ElastiCache for Memcached is an in-memory cache that does not provide native persistence or high availability across multiple Availability Zones without additional configuration (e.g., using a cluster with replication, which Memcached does not support natively); it is intended for caching, not as a durable data store for configuration. Option C is wrong because Amazon RDS for MySQL is a relational database that introduces overhead from SQL parsing, connection management, and schema design, and while it can be made multi-AZ, it is overkill for simple key-value configuration data and does not offer the single-digit millisecond latency of DynamoDB for this use case.

101
Multi-Selectmedium

A media company is building a new video transcoding pipeline. Source files arrive in an Amazon S3 bucket, and a workflow must fan out to several processing steps, retry failed steps with backoff, and pause for manual approval before publishing. A solutions architect is evaluating AWS Step Functions. Which two statements are correct about using Step Functions for this design? (Choose two.)

Select 2 answers
A.Retries and backoff must be coded inside each Lambda function because Step Functions cannot define retry behavior at the state level.
B.Step Functions can invoke AWS Lambda functions but cannot call other AWS services directly, so every transcoding step must be wrapped in a Lambda function.
C.A Standard workflow can run for up to one year and supports exactly-once execution semantics, which suits long-running transcoding jobs and audit requirements.
D.An Express workflow can run for up to five minutes and provides at-least-once execution, making it suitable for high-volume, short-lived event processing.
E.Manual approval steps are implemented by polling a DynamoDB table in a loop until a reviewer updates a record, because Step Functions has no built-in callback mechanism.
AnswersC, D

Standard workflows are designed for durable, long-running processes and can execute for up to one year, with execution history retained so each state transition is recorded. They provide exactly-once semantics for state transitions, which is important for auditable approval steps and for jobs whose duration exceeds the five-minute limit of the other workflow type.

Why this answer

Standard workflows provide durable, exactly-once, up-to-one-year executions with recorded history, while Express workflows provide at-least-once, up-to-five-minute executions for high-volume short tasks. Choosing between them depends on job duration and the need for exactly-once semantics, and both types support state-level retry configuration and service integrations without Lambda wrappers.

Exam trap

The trap here is treating the two workflow types as interchangeable, when the duration limit and execution semantics differ in ways that decide the design.

102
MCQhard

A company is migrating a legacy monolithic application to AWS. The application stores session state locally on each server. The company wants to refactor the application to be stateless and deploy it across multiple Availability Zones for high availability. The application must handle sudden traffic spikes and maintain session persistence. Which solution should a solutions architect recommend?

A.Use Application Load Balancer with sticky sessions (session affinity) and store session state on each EC2 instance's local disk.
B.Store session state in an Amazon S3 bucket and have the application read and write session data for each request.
C.Store session state in an Amazon ElastiCache for Redis cluster with Multi-AZ enabled, and configure the application to use it.
D.Use Amazon DynamoDB with a global secondary index to store session state, and configure the application to use it.
AnswerC

ElastiCache for Redis with Multi-AZ provides a highly available, in-memory session store that is external to the application servers. This makes the application stateless and allows it to scale horizontally across AZs. Redis supports persistence and automatic failover, ensuring session data survives node failures. It is ideal for handling sudden traffic spikes due to its low latency and high throughput.

Why this answer

ElastiCache for Redis with Multi-AZ is the best choice because it provides a highly available, low-latency, in-memory session store that externalizes session state, making the application stateless. It scales to handle traffic spikes and ensures session persistence across AZs with automatic failover. Other options either keep the application stateful, introduce latency, or are not optimized for session management.

Exam trap

The trap here is thinking that sticky sessions solve the session state problem, but they actually prevent the application from becoming stateless and reduce availability.

103
MCQmedium

Refer to the exhibit. A CloudFormation stack has been deployed with the VPCId and SubnetIds outputs. A developer wants to use these outputs as parameters in another CloudFormation stack. Which AWS service can be used to pass these values to the new stack?

A.Amazon Simple Notification Service (SNS)
B.AWS Secrets Manager
C.AWS Systems Manager Parameter Store
D.CloudFormation cross-stack references using Export and ImportValue
AnswerD

Exporting stack outputs and importing them via Fn::ImportValue creates a cross-stack reference, passing VPCId and SubnetIds directly into the second stack. This satisfies the requirement without hardcoding values or duplicating parameters, and CloudFormation enforces the dependency between stacks.

Why this answer

CloudFormation cross-stack references using the `Export` output attribute and the `Fn::ImportValue` intrinsic function allow you to pass output values from one stack as parameters to another stack within the same AWS account and region. This is the native, recommended mechanism for sharing stack outputs without introducing external services or additional complexity.

Exam trap

The trap here is that candidates may confuse Parameter Store (a general-purpose parameter store) with CloudFormation's native cross-stack reference feature, overlooking that the question explicitly asks for passing outputs between CloudFormation stacks, which is directly solved by `Export` and `ImportValue`.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub messaging service used for notifications and event-driven workflows, not for storing or passing CloudFormation stack outputs as parameters. Option B is wrong because AWS Secrets Manager is designed to securely store and rotate secrets (e.g., database credentials, API keys), not to pass CloudFormation outputs between stacks. Option C is wrong because AWS Systems Manager Parameter Store can store configuration data and secrets, but it is not the native CloudFormation mechanism for cross-stack references; using it would require custom logic to write outputs to Parameter Store and then read them in the other stack, adding unnecessary overhead and violating the principle of using built-in CloudFormation features.

104
MCQeasy

A company is deploying a new stateless web application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The company wants to ensure that the application can scale automatically based on demand and that the EC2 instances are spread across multiple Availability Zones for high availability. The company also wants to minimize costs when demand is low. Which solution should a solutions architect recommend?

A.Use AWS Elastic Beanstalk with a single instance environment and enable automatic scaling.
B.Launch EC2 instances in a single Availability Zone and use a Network Load Balancer (NLB) to distribute traffic.
C.Create an Auto Scaling group that spans multiple Availability Zones, with a target tracking scaling policy based on average CPU utilization, and attach it to the ALB target group.
D.Deploy the application on Amazon ECS with Fargate and use a target tracking scaling policy based on memory utilization.
AnswerC

An Auto Scaling group across multiple AZs provides high availability and enables automatic scaling. A target tracking policy based on CPU utilization adjusts capacity to maintain a target value, scaling in during low demand to reduce costs. Attaching to the ALB target group integrates load balancing.

Why this answer

An Auto Scaling group spanning multiple AZs ensures high availability and allows horizontal scaling. Target tracking scaling policies automatically adjust the number of instances to maintain a specified metric, such as average CPU utilization, which helps handle demand fluctuations and reduces costs during low usage. Integrating with an ALB target group ensures traffic is distributed to healthy instances.

Exam trap

The trap here is assuming that a Network Load Balancer or a single-instance Elastic Beanstalk environment can provide high availability, when they either operate at the wrong layer or lack multi-AZ redundancy.

105
MCQmedium

A company is deploying a containerized microservices architecture on Amazon ECS with Fargate. They need to securely store and rotate database credentials. Which AWS service should they use?

A.AWS CloudHSM
B.AWS Identity and Access Management (IAM) roles
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager natively rotates database credentials via Lambda rotation functions, satisfying the stem's rotation requirement without custom code. Unlike Systems Manager Parameter Store, it provides built-in rotation scheduling and native RDS integration. Credentials are retrieved at runtime through IAM policies, keeping secrets out of task definitions and images.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, automatically rotating, and managing the lifecycle of database credentials. It integrates natively with Amazon ECS and Fargate via task role permissions, allowing containers to retrieve secrets at runtime without hardcoding them. Secrets Manager also supports automatic rotation of credentials for Amazon RDS, Aurora, and other databases, which directly addresses the requirement for credential rotation.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets) with AWS Secrets Manager, but Parameter Store lacks native automatic rotation and is not designed for managing database credential lifecycles, making Secrets Manager the correct choice for this specific requirement.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides hardware-based cryptographic key storage and cryptographic operations, not a service for storing or rotating database credentials; it lacks built-in automatic rotation and secret management features. Option B is wrong because IAM roles provide temporary credentials for AWS API access but cannot store or rotate database credentials; they are used for authorization, not secret storage. Option C is wrong because AWS Systems Manager Parameter Store can store secrets but does not natively support automatic rotation of database credentials; it requires custom solutions (e.g., Lambda functions) to implement rotation, whereas Secrets Manager provides built-in rotation.

106
MCQmedium

A company is designing a real-time analytics pipeline for IoT data. They need to ingest millions of messages per second, process them with low latency, and store results in Amazon S3. Which combination of services should they use?

A.Amazon Kinesis Data Streams, Amazon Kinesis Data Analytics, Amazon Kinesis Data Firehose
B.Amazon SQS, AWS Lambda, Amazon S3
C.Amazon Kinesis Data Streams, Amazon Redshift, Amazon S3
D.Amazon IoT Core, AWS Lambda, Amazon DynamoDB
AnswerA

Kinesis Data Streams ingests millions of records per second with sub-second latency, satisfying the high-throughput ingestion constraint. Kinesis Data Analytics then processes that stream in real time, and Kinesis Data Firehose delivers the results to Amazon S3 without custom consumer code. Together they meet the low-latency, S3-storage requirements.

Why this answer

Amazon Kinesis Data Streams ingests millions of messages per second with low latency, Kinesis Data Analytics processes the stream in real time using SQL or Apache Flink, and Kinesis Data Firehose reliably delivers the processed data to Amazon S3. This combination is purpose-built for real-time IoT analytics pipelines and meets the throughput, latency, and storage requirements.

Exam trap

SAP-C02 often tests the distinction between streaming (Kinesis) and queuing (SQS) services, and between real-time processing (Kinesis Analytics) and batch analytics (Redshift), causing candidates to pick SQS or Redshift for low-latency streaming use cases.

How to eliminate wrong answers

Option B is wrong because Amazon SQS is a message queue, not a real-time streaming service; it lacks the high-throughput, ordered, replayable stream semantics needed for millions of messages per second, and Lambda polling introduces latency. Option C is wrong because Amazon Redshift is a data warehouse for batch analytics, not a real-time stream processor; it cannot process streaming data with low latency. Option D is wrong because AWS Lambda is not designed for continuous stream processing at millions of events per second, and DynamoDB is a NoSQL database, not an S3 storage solution.

107
MCQmedium

A company is designing a new microservices architecture on AWS. They need to ensure that services can communicate asynchronously without tight coupling. Which AWS service should they use for message brokering?

A.Amazon Simple Queue Service (SQS)
B.Amazon Simple Notification Service (SNS)
C.Amazon Kinesis Data Streams
D.AWS Step Functions
AnswerA

SQS provides fully managed queues where producers send messages and consumers poll independently, decoupling services so neither waits on the other. This asynchronous, pull-based brokering satisfies the no-tight-coupling requirement, with standard queues offering at-least-once delivery and near-unlimited throughput.

Why this answer

Amazon SQS is a fully managed message queuing service that enables asynchronous, decoupled communication between microservices. Producers send messages to a queue, and consumers poll and process them independently, so services don't need to know about each other or wait for responses. This directly satisfies the requirement for asynchronous communication without tight coupling.

Exam trap

SAP-C02 often tests the distinction between SQS (pull-based queuing for decoupling) and SNS (push-based pub/sub for fanout), so candidates must recognize that asynchronous, decoupled microservice communication typically requires a queue, not a notification service.

How to eliminate wrong answers

Option B is wrong because Amazon SNS is a pub/sub service that pushes messages to subscribers immediately; while it decouples publishers from subscribers, it is not a message broker with durable queuing and does not support asynchronous pull-based consumption. Option C is wrong because Kinesis Data Streams is designed for real-time streaming of large data volumes with ordered shards, not for general-purpose microservice message brokering; it requires consumers to manage shard iterators and checkpoints. Option D is wrong because AWS Step Functions is a serverless orchestration service for coordinating workflows, not a message broker; it tightly couples steps in a state machine and is not intended for asynchronous, decoupled messaging between independent services.

108
Multi-Selectmedium

A company is designing a serverless application that uses Amazon API Gateway and AWS Lambda. The API must be secured using AWS WAF. Which TWO actions should the company take to integrate WAF with API Gateway? (Choose TWO.)

Select 2 answers
A.Create an AWS WAF web ACL and attach it to the Lambda function
B.Configure API Gateway to require an API key and associate WAF with the usage plan
C.Associate an AWS WAF web ACL with the API Gateway HTTP API
D.Associate an AWS WAF web ACL with the API Gateway REST API stage
E.Place AWS WAF in front of Amazon CloudFront and use CloudFront as the API Gateway endpoint
AnswersC, D

AWS WAF web ACLs can be associated directly with API Gateway HTTP APIs, filtering requests at the API endpoint before they reach the backend. This satisfies the requirement to secure the API with WAF, though the association is configured on the HTTP API rather than a REST stage.

Why this answer

Options C and D are correct because AWS WAF web ACLs can be directly associated with API Gateway REST API stages and with API Gateway HTTP APIs, which is the supported way to protect these endpoints with WAF rules. For a REST API, the web ACL is attached at the stage level (for example, via the API Gateway console, AWS CLI, or CloudFormation), and for an HTTP API, the web ACL is associated with the API itself. Option A is incorrect because AWS WAF cannot be attached directly to a Lambda function; Lambda is protected only indirectly through the fronting service.

Option B is incorrect because API keys and usage plans handle throttling and identification, not WAF rule enforcement, and WAF is not associated with usage plans. Option E is incorrect because placing WAF in front of CloudFront and using CloudFront as the API Gateway endpoint is not the required or direct integration method for securing API Gateway with WAF.

Exam trap

The trap here is that candidates may think WAF must be attached to a CloudFront distribution or a Lambda function, but AWS WAF directly supports association with both API Gateway REST API stages and HTTP APIs without requiring CloudFront.

109
MCQeasy

A company wants to implement a serverless architecture where an AWS Lambda function is triggered whenever a new object is uploaded to an S3 bucket. Which S3 feature should they use?

A.S3 Object Lock
B.S3 Transfer Acceleration
C.S3 Event Notifications
D.S3 Inventory
AnswerC

S3 Event Notifications publish s3:ObjectCreated events to Lambda via a bucket notification configuration, invoking the function per uploaded object. This native push mechanism satisfies the serverless trigger requirement without polling, and supports prefix/suffix filtering to scope which uploads fire.

Why this answer

S3 Event Notifications allow you to configure S3 to publish events (e.g., s3:ObjectCreated:Put) to AWS Lambda, SQS, or SNS whenever an object is uploaded. This is the native serverless integration that triggers a Lambda function directly from S3 without polling or custom code.

Exam trap

The trap here is that candidates may confuse S3 Event Notifications with S3 Inventory or S3 Object Lock, thinking any S3 feature that 'tracks' or 'protects' objects can trigger code, but only Event Notifications provide real-time, push-based triggers to Lambda.

How to eliminate wrong answers

Option A is wrong because S3 Object Lock is a write-once-read-many (WORM) feature that prevents objects from being deleted or overwritten for a fixed retention period; it does not trigger Lambda functions. Option B is wrong because S3 Transfer Acceleration uses AWS edge locations to speed up uploads over long distances via optimized network paths; it has no event triggering capability. Option D is wrong because S3 Inventory provides scheduled CSV/Parquet reports listing objects and their metadata for auditing or lifecycle management; it does not generate real-time events to invoke Lambda.

110
MCQeasy

A company is designing a new application that will process streaming data from IoT devices. The data must be processed in real time and then stored in Amazon S3 for long-term analytics. Which combination of AWS services should be used?

A.Amazon Kinesis Data Firehose, Amazon Redshift
B.Amazon SQS, AWS Lambda, Amazon RDS
C.AWS IoT Core, Amazon DynamoDB
D.Amazon Kinesis Data Streams, AWS Lambda, Amazon S3
AnswerD

Kinesis Data Streams ingests the IoT telemetry with low latency, Lambda processes each record in real time as it arrives, and S3 stores the results durably for later analytics. This satisfies both the real-time processing and long-term storage requirements.

Why this answer

Amazon Kinesis Data Streams ingests and buffers streaming IoT data in real time, AWS Lambda processes each record as it arrives, and the processed data is written directly to Amazon S3 for durable long-term analytics. This combination provides the low-latency, serverless pipeline required for real-time processing and S3-based storage.

Exam trap

The trap here is that candidates often confuse Kinesis Data Firehose (which delivers near-real-time batches) with Kinesis Data Streams (which enables per-record real-time processing), leading them to pick Option A despite its lack of a real-time processing component.

How to eliminate wrong answers

Option A is wrong because Amazon Redshift is a data warehouse for analytics, not a real-time processing engine, and Kinesis Data Firehose delivers data in batches, not per-record processing. Option B is wrong because Amazon SQS is a message queue for decoupling components, not designed for real-time streaming ingestion, and Amazon RDS is a relational database, not suitable for high-throughput streaming data storage. Option C is wrong because AWS IoT Core ingests IoT messages but DynamoDB is a NoSQL database for low-latency queries, not a long-term analytics store like S3, and this combination lacks a real-time processing step.

111
MCQmedium

A company is designing a new application that requires a global content delivery network with low latency and DDoS protection. Which combination of AWS services should be used?

A.Amazon CloudFront and AWS Shield
B.AWS Global Accelerator and Amazon CloudFront
C.Amazon Route 53 and AWS Shield
D.AWS WAF and Amazon CloudFront
AnswerA

Amazon CloudFront caches content at edge locations worldwide, cutting latency for global users, while AWS Shield provides managed DDoS protection at layers 3, 4 and 7. Together they satisfy the stem's dual requirement: a global content delivery network with low latency and integrated DDoS mitigation.

Why this answer

Amazon CloudFront provides a global content delivery network (CDN) with low latency by caching content at edge locations worldwide. AWS Shield, specifically Shield Advanced, offers managed DDoS protection against large-scale attacks, including layer 3/4 and layer 7 threats. Together, they meet the requirement for both low-latency content delivery and DDoS mitigation.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with a CDN, but Global Accelerator does not cache content—it only optimizes network routing, making it unsuitable for content delivery without CloudFront.

How to eliminate wrong answers

Option B is wrong because AWS Global Accelerator improves latency by directing traffic over the AWS global network to the optimal endpoint, but it does not provide content caching or DDoS protection at the edge; it is not a CDN. Option C is wrong because Amazon Route 53 is a DNS service that routes traffic but does not cache content or provide low-latency content delivery; AWS Shield alone does not offer CDN capabilities. Option D is wrong because AWS WAF is a web application firewall that filters HTTP/S requests but does not provide low-latency content caching or global edge distribution; it must be combined with CloudFront for CDN functionality, but the option omits Shield for DDoS protection.

112
MCQhard

A company is designing a new global web application that will be deployed in multiple AWS Regions. The application must provide low-latency access to users worldwide, and the company wants to minimize operational complexity. The application uses a stateless web tier and a DynamoDB backend. The company needs to ensure that writes in one Region are eventually visible in other Regions. Which solution should a solutions architect recommend?

A.Deploy the web tier in each Region and use Amazon RDS for MySQL with cross-Region read replicas for the backend.
B.Deploy the web tier in each Region and use DynamoDB Accelerator (DAX) in each Region to replicate data across Regions.
C.Deploy the web tier in one Region and use Amazon CloudFront with Lambda@Edge to serve users globally, while using a single DynamoDB table in that Region.
D.Deploy the web tier in each Region behind an Application Load Balancer, and use DynamoDB global tables for the backend.
AnswerD

DynamoDB global tables provide multi-Region, active-active replication with eventual consistency, meeting the requirement for writes to be visible in other Regions. Deploying the stateless web tier in each Region behind an ALB provides low-latency access. This solution minimizes operational complexity because DynamoDB handles replication automatically.

Why this answer

DynamoDB global tables automatically replicate data across Regions, providing an active-active multi-Region database with eventual consistency. This allows writes in one Region to be visible in other Regions. Deploying the stateless web tier in each Region behind an ALB ensures low-latency access for users.

The combination minimizes operational complexity because replication and failover are managed by AWS.

Exam trap

The trap here is confusing DAX with global tables; DAX is a read cache and does not replicate data across Regions, while global tables provide multi-Region replication.

113
MCQhard

A company is designing a new cloud-native application that will be deployed across multiple AWS Regions for high availability. The application uses Amazon Aurora Global Database for its primary data store. The company needs to ensure that in the event of a regional failure, the secondary region can be promoted to primary with minimal data loss. Which configuration should be used?

A.Use Aurora Serverless v2 with data replication across regions using Database Migration Service (DMS).
B.Deploy Aurora Multi-AZ in the primary region and use a secondary region as a warm standby.
C.Use Aurora Global Database with one primary region and one secondary region. Enable managed failover with a Recovery Point Objective (RPO) of 1 second.
D.Configure Aurora Cross-Region Read Replicas and use Amazon Route 53 for DNS failover.
AnswerC

Aurora Global Database replicates storage-level changes to secondary Regions with typical lag under one second, so managed failover promoting the secondary meets the 1-second RPO constraint. This is the only configuration that keeps cross-Region replication continuously active without application-level write forwarding.

Why this answer

Amazon Aurora Global Database is specifically designed for cross-region disaster recovery with a typical RPO of 1 second and RTO of less than 1 minute when managed failover is enabled. It uses a storage-based replication layer that replicates data from the primary to secondary regions with minimal latency, ensuring that in a regional failure, the secondary region can be promoted to primary with very little data loss.

Exam trap

The trap here is that candidates often confuse cross-region read replicas (which have higher replication lag and require manual promotion) with Aurora Global Database's managed failover (which provides sub-second RPO and automated promotion), leading them to choose option D instead of C.

How to eliminate wrong answers

Option A is wrong because Aurora Serverless v2 does not support cross-region replication natively, and AWS Database Migration Service (DMS) is a migration tool, not a real-time replication solution for high availability; it introduces significant latency and potential data loss. Option B is wrong because Aurora Multi-AZ provides high availability within a single region, not across regions, and using a secondary region as a warm standby without global database replication would require manual backup restore or other mechanisms, resulting in higher RPO and RTO. Option D is wrong because Aurora Cross-Region Read Replicas use asynchronous replication with a typical RPO of seconds to minutes, and while Route 53 can handle DNS failover, the replication lag is not guaranteed to be as low as 1 second, and promoting a read replica to primary is a manual process that can take several minutes, leading to higher data loss.

114
MCQmedium

A company is designing a new application that will process real-time streaming data from thousands of IoT devices. The data must be ingested, processed with low latency, and stored in Amazon S3 for analytics. Which combination of AWS services should the company use to meet these requirements?

A.Amazon SQS, AWS Lambda, Amazon S3
B.Amazon Kinesis Data Firehose, Amazon Redshift, Amazon S3
C.Amazon MQ, AWS Lambda, Amazon RDS
D.Amazon Kinesis Data Streams, AWS Lambda, Amazon S3
AnswerD

Kinesis Data Streams ingests thousands of device events with low latency and durable ordering, Lambda consumes and processes records in real time, and Lambda's native S3 integration stores the results for analytics. This combination directly satisfies the ingestion, low-latency processing, and S3 storage requirements.

Why this answer

Amazon Kinesis Data Streams ingests real-time streaming data from thousands of IoT devices with low latency, and AWS Lambda can process each record as it arrives via event source mapping. The processed data is then stored in Amazon S3 for analytics, meeting all requirements for ingestion, low-latency processing, and durable storage.

Exam trap

The trap here is that candidates confuse Amazon SQS with Kinesis Data Streams for real-time streaming, but SQS is a pull-based queue with no ordered replay or shard-level parallelism, making it unsuitable for high-throughput IoT data ingestion.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue for decoupled communication, not designed for real-time streaming ingestion from thousands of IoT devices; it lacks the shard-based parallelism and ordered replay capabilities needed for streaming data. Option B is wrong because Amazon Redshift is a data warehouse for analytics, not a low-latency processing target; using Kinesis Data Firehose with Redshift adds unnecessary latency and cost for real-time processing, and the requirement specifies storing in S3, not Redshift. Option C is wrong because Amazon MQ is a managed message broker for JMS-compatible applications, not optimized for high-throughput streaming from IoT devices; Amazon RDS is a relational database, not suitable for storing streaming data for analytics in S3.

115
MCQmedium

A company is migrating a monolithic e-commerce application to AWS. The application consists of a web tier, an application tier, and a database tier. The company wants to decouple the tiers to improve scalability and resilience. Which AWS service should the company use to send messages from the web tier to the application tier asynchronously?

A.Amazon SNS
B.Amazon Kinesis Data Streams
C.AWS Step Functions
D.Amazon SQS
AnswerD

Amazon SQS lets the web tier enqueue messages that the application tier polls and processes independently, breaking the synchronous coupling between tiers. This satisfies the asynchronous messaging requirement, so a slow or failed application tier no longer blocks the web tier.

Why this answer

Amazon SQS is the correct choice because it provides a fully managed message queuing service that enables asynchronous communication between decoupled application tiers. The web tier can send messages to an SQS queue, and the application tier can poll and process those messages independently, which improves scalability and resilience by allowing each tier to scale and fail independently.

Exam trap

The trap here is that candidates often confuse SNS (pub/sub push model) with SQS (queue pull model) for decoupling tiers, but SNS does not provide the buffering and independent consumption needed for asynchronous decoupling between a web tier and an application tier.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub messaging service that pushes messages to subscribers, not a queue for point-to-point asynchronous decoupling; it does not provide the buffering and independent consumption that SQS offers. Option B is wrong because Amazon Kinesis Data Streams is designed for real-time streaming of large data volumes, not for simple message queuing between application tiers, and it introduces unnecessary complexity and cost for this use case. Option C is wrong because AWS Step Functions is a serverless orchestration service for coordinating multiple AWS services into workflows, not a message queue for decoupling tiers; it is used for state machines, not for basic asynchronous message passing.

116
MCQmedium

A company is running a containerized application on Amazon ECS with Fargate launch type. The application needs to store persistent data that must be shared across multiple containers in the same task. Which storage option should the company use?

A.Amazon S3 bucket mounted using s3fs
B.Amazon FSx for Lustre
C.Amazon EBS volume
D.Amazon EFS file system
AnswerD

EFS is the only shared, elastic file system mountable concurrently by multiple Fargate containers within a task, satisfying the cross-container persistence constraint. Fargate task ephemeral storage is per-task and not shareable, while EBS volumes cannot attach to Fargate tasks.

Why this answer

Amazon EFS provides a shared, persistent, and scalable NFS file system that can be mounted concurrently by multiple containers within the same ECS task using Fargate. EFS supports the NFSv4.1 protocol, enabling simultaneous read/write access from multiple containers, which meets the requirement for shared persistent storage across containers in the same task.

Exam trap

The trap here is that candidates often confuse Amazon EBS with a shared storage solution, but EBS volumes are zonal and single-instance attachable, making them incompatible with multi-container sharing in Fargate, whereas EFS is the only AWS-native, shared, persistent file system that works seamlessly with Fargate.

How to eliminate wrong answers

Option A is wrong because Amazon S3 mounted via s3fs is an object storage solution that does not provide true POSIX file system semantics, and s3fs is a third-party FUSE implementation that can introduce performance and consistency issues, making it unsuitable for shared persistent storage across containers in a Fargate task. Option B is wrong because Amazon FSx for Lustre is designed for high-performance computing workloads with low-latency access to data, but it is not natively integrated with ECS Fargate and requires a managed Lustre client, which is not supported in the Fargate environment. Option C is wrong because Amazon EBS volumes are block-level storage that can only be attached to a single EC2 instance at a time; they cannot be shared across multiple containers in the same ECS task, and Fargate does not support direct EBS volume attachments.

117
Multi-Selecthard

A company is designing a new application on AWS that requires a highly available and fault-tolerant architecture. Which TWO design principles should they follow?

Select 2 answers
A.Use Auto Scaling groups to automatically replace unhealthy instances.
B.Deploy application across multiple Availability Zones.
C.Manually create EBS snapshots every day.
D.Store data in a single Amazon S3 bucket in one Region.
E.Use a single large EC2 instance to simplify management.
AnswersA, B

Auto Scaling groups continuously health-check instances and terminate then replace failures across Availability Zones, directly satisfying the fault-tolerance constraint. Combined with multi-AZ placement, this removes single points of failure without manual intervention, ensuring the application self-heals and maintains capacity during instance or zone impairment.

Why this answer

Option A is correct because Auto Scaling groups continuously perform health checks and automatically terminate and replace unhealthy EC2 instances, which maintains capacity and self-heals the fleet without manual intervention, directly supporting fault tolerance. Option B is correct because deploying the application across multiple Availability Zones isolates it from a single-AZ failure; each AZ has independent power, cooling, and networking, so the workload remains available if one AZ goes down. Option C is not a high-availability design principle: manual daily EBS snapshots are a backup/recovery mechanism with a recovery point objective of up to 24 hours, not automatic failover.

Option D does not belong because a single S3 bucket in one Region concentrates data in one geographic location and does not by itself provide cross-Region fault tolerance (though S3 is internally redundant within a Region). Option E is wrong because a single large EC2 instance is a single point of failure and cannot deliver high availability or fault tolerance.

Exam trap

The trap here is that candidates often confuse data backup strategies (like EBS snapshots) with high availability design, or they mistakenly believe that a single large instance or a single-region storage approach is sufficient for fault tolerance, ignoring the need for redundancy and automated recovery.

118
MCQmedium

A company is designing a new solution to host a static website with global audience. The website content includes HTML, CSS, JavaScript, and images. The company wants to minimize latency for users worldwide and reduce the load on the origin server. The origin server is an Amazon S3 bucket configured for static website hosting. Which solution should be used to achieve these goals?

A.Use AWS Global Accelerator to route traffic to the S3 bucket.
B.Use AWS Lambda@Edge to serve content from edge locations.
C.Use Amazon CloudFront as a content delivery network (CDN) in front of the S3 bucket.
D.Enable S3 Transfer Acceleration on the bucket.
AnswerC

CloudFront caches the S3-hosted HTML, CSS, JavaScript and images at global edge locations, so users are served from the nearest point of presence rather than the origin. This directly satisfies both stated constraints: minimising worldwide latency and reducing load on the S3 origin, since repeat requests no longer reach the bucket.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches static content (HTML, CSS, JavaScript, images) at edge locations worldwide, significantly reducing latency for a global audience. By placing CloudFront in front of an S3 bucket configured for static website hosting, it offloads requests from the origin server, reducing load and improving performance. CloudFront also supports features like custom SSL, geo-restriction, and origin shield to further optimize delivery.

Exam trap

The trap here is confusing content delivery (CloudFront) with network acceleration (Global Accelerator) or upload acceleration (S3 Transfer Acceleration), leading candidates to pick options that improve network routing but do not cache or serve static content at edge locations.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator improves performance by routing traffic over the AWS global network to the optimal regional endpoint, but it does not cache content at edge locations; it is designed for TCP/UDP traffic and dynamic content, not for reducing load on an S3 static website origin. Option B is wrong because AWS Lambda@Edge runs custom code at CloudFront edge locations to modify requests/responses, but it is not a content delivery service itself; it requires CloudFront to be in place and cannot serve static content directly from edge locations without a CDN. Option D is wrong because S3 Transfer Acceleration speeds up uploads to S3 over long distances using AWS edge locations, but it does not cache or serve content to end users; it is designed for uploads, not for reducing latency for a global audience downloading static website content.

119
MCQhard

A company is deploying a new three-tier web application on AWS. The web tier runs on Amazon EC2 instances behind an Application Load Balancer. The application tier runs on Amazon ECS with the Fargate launch type. The database tier uses Amazon Aurora MySQL. The security team requires that all data in transit between tiers be encrypted and that the application tier be able to access the database without hardcoding credentials. The company wants to minimize operational overhead. Which solution meets these requirements?

A.Use an Application Load Balancer with an HTTP listener and rely on security groups to restrict traffic. Store database credentials in environment variables within the ECS task definition.
B.Configure the Application Load Balancer with an HTTPS listener using an ACM certificate, enable TLS on the ECS service, and store database credentials in AWS Systems Manager Parameter Store as a SecureString parameter without rotation.
C.Use AWS Certificate Manager Private Certificate Authority to issue certificates for the ALB and ECS tasks, and store database credentials in an Amazon S3 bucket encrypted with SSE-S3. Grant the ECS task role access to the bucket.
D.Configure the Application Load Balancer with an HTTPS listener using an ACM certificate, enable TLS on the ECS service, and store database credentials in AWS Secrets Manager with automatic rotation. Grant the ECS task role permission to read the secret.
AnswerD

This solution encrypts data in transit at every tier: the ALB uses an ACM certificate for client-to-web encryption, TLS on the ECS service encrypts application-to-database traffic, and Aurora MySQL supports TLS connections. AWS Secrets Manager stores credentials securely and rotates them automatically. The ECS task role grants least-privilege access to the secret, eliminating hardcoded credentials and reducing operational overhead.

Why this answer

The correct solution encrypts data in transit at all tiers and centralizes credential management with automatic rotation. An HTTPS listener on the Application Load Balancer with an ACM certificate secures client traffic, TLS on the ECS service secures application traffic, and Aurora MySQL supports TLS for database connections. AWS Secrets Manager with automatic rotation and an ECS task role eliminates hardcoded credentials while minimizing operational overhead.

Exam trap

The trap here is assuming that storing credentials in AWS Systems Manager Parameter Store as a SecureString provides the same automatic rotation capabilities as AWS Secrets Manager for database credentials.

120
MCQhard

A company is designing a new application that will be deployed on AWS. The application requires a relational database that must be highly available, automatically scalable, and support read-heavy workloads. The company wants to minimize operational overhead and ensure that the database can fail over to another Availability Zone automatically. Which solution meets these requirements?

A.Amazon Aurora with a Multi-AZ deployment and Auto Scaling for read replicas
B.Amazon DynamoDB with global tables and on-demand capacity
C.Amazon Redshift with concurrency scaling and Multi-AZ
D.Amazon RDS for MySQL with Multi-AZ and a read replica in a different region
AnswerA

Amazon Aurora is a MySQL- and PostgreSQL-compatible relational database that provides high availability with a Multi-AZ deployment. It automatically fails over to a read replica in another AZ if the primary fails. Aurora Auto Scaling can automatically add or remove read replicas based on load, making it ideal for read-heavy workloads with minimal operational overhead.

Why this answer

Amazon Aurora with Multi-AZ and Auto Scaling for read replicas provides a highly available, relational database that automatically scales read capacity. It minimizes operational overhead by handling failover and scaling automatically. Other options either lack automatic scaling, are not relational, or are not designed for transactional workloads.

Exam trap

The trap here is assuming that RDS Multi-AZ includes automatic read replica scaling; it does not, and read replicas must be managed manually.

121
MCQeasy

A company is designing a new application that requires a fully managed NoSQL database with single-digit millisecond latency. The application needs to handle sudden spikes in read traffic without manual intervention. Which AWS service should the company choose?

A.Amazon RDS for MySQL
B.Amazon ElastiCache
C.Amazon Aurora
D.Amazon DynamoDB
AnswerD

Amazon DynamoDB is a fully managed NoSQL database delivering consistent single-digit millisecond latency at any scale. Its on-demand capacity mode absorbs sudden read-traffic spikes automatically, with no manual provisioning, satisfying both the latency and the no-intervention scaling constraints stated in the scenario.

Why this answer

Amazon DynamoDB is a fully managed NoSQL key-value and document database that delivers single-digit millisecond latency at any scale. It supports auto-scaling of read/write capacity based on traffic patterns, enabling the application to handle sudden spikes in read traffic without manual intervention.

Exam trap

The trap here is that candidates may confuse Amazon ElastiCache (a caching layer) with a primary NoSQL database, or assume that Amazon Aurora's MySQL compatibility makes it a NoSQL option, when in fact DynamoDB is the only fully managed NoSQL service among the choices that meets the latency and auto-scaling requirements.

How to eliminate wrong answers

Option A is wrong because Amazon RDS for MySQL is a relational database, not a NoSQL database, and it requires manual scaling or configuration of read replicas to handle traffic spikes. Option B is wrong because Amazon ElastiCache is an in-memory caching service, not a primary database; it is used to accelerate access to data stored elsewhere, not as a fully managed NoSQL database with its own persistence. Option C is wrong because Amazon Aurora is a relational database engine compatible with MySQL and PostgreSQL, not a NoSQL database, and while it offers auto-scaling storage, it does not natively auto-scale read capacity for sudden spikes without manual provisioning of Aurora Replicas.

122
Multi-Selecteasy

A company is designing a cost-effective architecture for a batch processing job that runs nightly. The job can tolerate interruptions and requires significant compute power for a few hours. The company wants to minimize costs. Which TWO strategies should the company use?

Select 2 answers
A.Use Spot Instances for compute.
B.Purchase Reserved Instances (RI) for a 1-year term.
C.Configure Auto Scaling to scale out during the job and scale in after.
D.Use On-Demand Instances to ensure availability.
E.Use Dedicated Hosts for compliance.
AnswersA, C

Spot Instances deliver up to 90% discounts versus On-Demand by using spare EC2 capacity, and the job's tolerance of interruptions matches Spot's two-minute termination notice. This satisfies the minimise-cost constraint for a fault-tolerant nightly batch workload.

Why this answer

Option A is correct because Spot Instances offer up to a 90% discount compared to On-Demand prices and are ideal for fault-tolerant, interruptible batch workloads that can be terminated and resumed without impacting the business. Option C is correct because Auto Scaling dynamically adds capacity only during the few hours the nightly job runs and removes it afterward, so the company pays only for the compute actually needed rather than provisioning for peak capacity 24/7. Together, Spot Instances plus Auto Scaling deliver the lowest cost for a short, interruption-tolerant batch job.

Option B is not appropriate because a 1-year Reserved Instance commitment is wasteful for a workload that runs only a few hours per night. Option D is not appropriate because On-Demand pricing is the most expensive per-hour option and provides no cost optimization for interruptible work. Option E is not appropriate because Dedicated Hosts are a premium, compliance-driven offering and are far more costly than needed here.

Exam trap

The trap here is that candidates often choose Reserved Instances (Option B) thinking they are always cheaper for recurring workloads, but they fail to recognize that the low utilization (a few hours per night) makes On-Demand or Spot more cost-effective than a 1-year commitment.

123
MCQhard

A company is migrating a legacy monolithic application to AWS. The application uses a proprietary binary protocol over TCP. The company wants to modernize the architecture using microservices while minimizing changes to the client. Which approach should the company use?

A.Use a Network Load Balancer with TCP listener and route traffic based on destination port to different target groups.
B.Use AWS Global Accelerator with a TCP listener and endpoint groups for microservices.
C.Use an Application Load Balancer with path-based routing to direct traffic to separate microservices.
D.Use Amazon API Gateway with a custom authorizer to route requests to AWS Lambda functions.
AnswerA

A Network Load Balancer preserves the proprietary binary TCP protocol end to end, since it operates at layer 4 without parsing payloads. Port-based listener rules let a single NLB endpoint fan traffic out to separate microservice target groups, so existing clients keep their connection details unchanged.

Why this answer

A Network Load Balancer (NLB) with a TCP listener can forward traffic based on destination port to different target groups, allowing the legacy client using a proprietary binary protocol over TCP to reach distinct microservices without any client-side changes. This preserves the existing TCP connection semantics and binary protocol, which an Application Load Balancer (HTTP/HTTPS only) or API Gateway (HTTP/REST) cannot handle.

Exam trap

The trap here is that candidates often assume an Application Load Balancer or API Gateway can handle any protocol because of their advanced routing features, but they forget that ALB and API Gateway are strictly Layer 7 (HTTP/HTTPS) and cannot process raw TCP or proprietary binary protocols.

How to eliminate wrong answers

Option B is wrong because AWS Global Accelerator uses endpoint groups for routing traffic to regional endpoints, but it does not support port-based routing to different target groups within a single listener; it relies on the underlying NLB or ALB for that granularity, adding unnecessary complexity without solving the port-based routing need. Option C is wrong because an Application Load Balancer operates at Layer 7 (HTTP/HTTPS) and cannot handle proprietary binary protocols over TCP; it requires HTTP-based routing, which would force changes to the client. Option D is wrong because Amazon API Gateway only supports HTTP/REST and WebSocket APIs, not raw TCP or proprietary binary protocols, and would require the client to send HTTP requests, breaking the existing protocol.

124
MCQeasy

A company needs to provide temporary, limited-privilege credentials to mobile app users to access AWS resources. Which AWS service should the architect recommend?

A.Create IAM users for each mobile user and distribute access keys.
B.Use AWS Security Token Service (STS) directly from the mobile app.
C.Create an IAM role and have the mobile app assume it directly.
D.Use Amazon Cognito with an identity pool to issue temporary credentials.
AnswerD

Cognito identity pools exchange authenticated or guest identities for temporary, scoped AWS credentials via STS, satisfying the limited-privilege and temporary requirements for mobile users. IAM roles attached to the pool constrain exactly which resources each user may reach.

Why this answer

Amazon Cognito identity pools are designed to provide temporary, limited-privilege AWS credentials to mobile app users. The service authenticates users through a public identity provider (e.g., Amazon, Facebook, Google, or a custom OIDC provider) and then exchanges the resulting identity token for temporary AWS credentials via the AWS Security Token Service (STS). This approach avoids embedding long-term credentials in the mobile app and enforces least-privilege access through IAM roles associated with the identity pool.

Exam trap

The trap here is that candidates confuse the ability to call STS directly with the need for pre-existing credentials; STS cannot issue temporary credentials without first authenticating the caller, so a mobile app without embedded credentials must use a service like Cognito to broker the token exchange.

How to eliminate wrong answers

Option A is wrong because creating IAM users for each mobile user and distributing access keys is not scalable, introduces long-term static credentials that are insecure when stored on mobile devices, and violates the principle of least privilege for temporary access. Option B is wrong because using AWS Security Token Service (STS) directly from the mobile app would require the app to have long-term AWS credentials (access key and secret key) to call STS, which defeats the purpose of temporary credentials and creates a security risk. Option C is wrong because having the mobile app assume an IAM role directly is not possible without first obtaining temporary credentials; the AssumeRole API call itself requires valid AWS credentials (either long-term or temporary) to invoke, so a mobile app without pre-provisioned credentials cannot assume a role directly.

125
MCQmedium

A company is building a new microservices architecture on AWS using Amazon ECS with Fargate. The services need to communicate with each other using RESTful APIs. The company wants to implement an API gateway to handle authentication, rate limiting, and request routing. Which AWS service should be used as the API gateway?

A.Network Load Balancer
B.Application Load Balancer
C.Amazon API Gateway
D.Amazon CloudFront
AnswerC

Amazon API Gateway provides native RESTful API management, satisfying the authentication, rate limiting and request routing requirements. It integrates with Microsoft Entra ID via JWT authorisers or Lambda authorisers for token validation, and supports usage plans with throttling limits per API key. This offloads cross-cutting concerns from Fargate tasks, which otherwise need custom middleware.

Why this answer

Amazon API Gateway is the AWS-managed service purpose-built for creating, publishing, and managing RESTful APIs, with native support for authentication (IAM, Cognito, Lambda authorizers), rate limiting (usage plans and throttling), and request routing. It integrates directly with ECS/Fargate services via HTTP integrations or VPC Link, making it the correct choice for the described requirements.

Exam trap

SAP-C02 often tests the distinction between load balancers and API gateways — candidates pick ALB because it does Layer 7 routing, but ALB lacks the authentication, usage plans, and rate-limiting features that define an API gateway.

How to eliminate wrong answers

Option A is wrong because a Network Load Balancer operates at Layer 4 and does not provide API-level authentication, rate limiting, or request routing based on HTTP paths and methods. Option B is wrong because an Application Load Balancer does Layer 7 routing but lacks built-in API authentication, usage plans, and rate limiting — it is a load balancer, not an API gateway. Option D is wrong because CloudFront is a CDN for caching and content delivery, not an API gateway with authentication and rate-limiting features.

126
MCQhard

A company is designing a multi-region active-active application using Amazon Route 53 latency-based routing. The application runs on Amazon EC2 instances behind Application Load Balancers (ALBs) in two AWS Regions. The company needs to ensure that if one region becomes unavailable, traffic is automatically routed to the healthy region with minimal disruption. Which configuration meets these requirements?

A.Use Route 53 failover routing instead of latency-based routing.
B.Configure Route 53 latency-based routing without health checks.
C.Use Route 53 weighted routing with weights set to 50 for each region.
D.Configure Route 53 latency-based routing with health checks attached to each ALB endpoint.
AnswerD

Attaching Route 53 health checks to each ALB endpoint lets the DNS resolver withdraw an unhealthy region's records from latency-based answers, so clients resolve only the healthy region's ALB. This satisfies the automatic failover and minimal-disruption constraints, since failover occurs at DNS resolution without manual intervention or client reconfiguration.

Why this answer

Route 53 latency-based routing with health checks ensures that traffic is directed to the region with the lowest latency, and if an ALB endpoint fails its health check, Route 53 automatically removes it from DNS responses, routing traffic to the healthy region. This provides the required active-active multi-region failover with minimal disruption.

Exam trap

The trap here is that candidates often assume failover routing is the only way to handle regional failures, but for active-active architectures, latency-based routing with health checks provides automatic failover while maintaining low-latency routing to both regions.

How to eliminate wrong answers

Option A is wrong because failover routing is designed for active-passive setups, not active-active; it would route all traffic to a primary region and only fail over to a secondary region when the primary fails, which does not meet the requirement for both regions to be active simultaneously. Option B is wrong because latency-based routing without health checks cannot detect regional failures; if an ALB becomes unavailable, Route 53 would continue to return its IP, causing connection failures for clients. Option C is wrong because weighted routing with equal weights distributes traffic based on weight ratios, not latency, and without health checks it cannot automatically fail over if a region becomes unavailable.

127
MCQeasy

A company is deploying a web application on AWS that requires a relational database. The application is read-heavy and expects sudden spikes in traffic. The database must be highly available and perform well under load. Which database configuration meets these requirements?

A.Use Amazon ElastiCache for Memcached as the primary database.
B.Deploy Amazon RDS in a Multi-AZ configuration without read replicas.
C.Deploy Amazon RDS in a single Availability Zone with a large instance size.
D.Deploy Amazon RDS in a Multi-AZ configuration and use read replicas to offload read traffic.
AnswerD

Multi-AZ provides synchronous standby failover for high availability, while read replicas serve read-heavy traffic on separate instances, absorbing sudden spikes without loading the primary. This satisfies both the availability and read-performance constraints, unlike Multi-AZ alone, which does not offload reads.

Why this answer

It combines Multi-AZ deployment for high availability with read replicas to offload read traffic, addressing both the read-heavy workload and sudden traffic spikes. Multi-AZ ensures automatic failover to a standby instance in a different Availability Zone if the primary fails, while read replicas distribute read queries across multiple copies, reducing load on the primary database and improving performance under spike conditions.

Exam trap

The trap here is that candidates often confuse Multi-AZ with read replicas, assuming Multi-AZ alone provides read scaling, but Multi-AZ only provides failover redundancy—the standby instance cannot serve reads, so read replicas are required to offload read traffic.

How to eliminate wrong answers

Option A is wrong because Amazon ElastiCache for Memcached is an in-memory caching layer, not a relational database; it cannot serve as the primary database for a web application requiring persistent, relational storage with ACID transactions. Option B is wrong because Multi-AZ without read replicas provides high availability but does not offload read traffic, so the single primary instance becomes a bottleneck under sudden read spikes, leading to performance degradation. Option C is wrong because deploying in a single Availability Zone with a large instance size lacks high availability—if the AZ fails, the database becomes unavailable—and scaling vertically with a larger instance does not efficiently handle sudden read spikes compared to horizontal scaling with read replicas.

128
MCQmedium

A company is designing a new multi-tier application on AWS. The web tier runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The database tier uses Amazon RDS for MySQL with a single Availability Zone deployment. The company requires that the application survive an Availability Zone failure with minimal downtime and no data loss. The database must automatically fail over to a standby instance in another Availability Zone. What should a solutions architect recommend to meet these requirements?

A.Deploy the database on an EC2 instance with a RAID 1 configuration across two Availability Zones using Amazon EBS snapshots.
B.Create a read replica in another Availability Zone and promote it manually if the primary fails.
C.Configure the RDS DB instance as a Multi-AZ deployment with a standby replica in a different Availability Zone.
D.Enable automated backups with a retention period of 35 days and restore from the latest snapshot if a failure occurs.
AnswerC

Multi-AZ deployment creates a synchronous standby replica in a different Availability Zone. In the event of a failure, Amazon RDS automatically fails over to the standby, typically within 60–120 seconds, with no data loss because replication is synchronous. This meets the requirements for high availability and durability without application changes.

Why this answer

Amazon RDS Multi-AZ deployments provide synchronous replication to a standby in another Availability Zone and automatic failover, ensuring high availability and durability. The other options either involve manual intervention, asynchronous replication, or are not designed for automatic failover with no data loss. Multi-AZ is the recommended approach for production databases requiring AZ resilience.

Exam trap

The trap here is assuming that a read replica in another Availability Zone provides the same high availability as a Multi-AZ standby, but read replicas are asynchronous and require manual promotion.

129
MCQeasy

A startup wants to deploy a web application on AWS with a serverless architecture. The application includes static content (HTML, CSS, JS) and a REST API backend using Lambda and DynamoDB. The company wants low latency and high availability globally. Which combination of services should they use?

A.Amazon CloudFront for static content, Application Load Balancer for API, and Lambda for compute.
B.AWS Lambda@Edge for both static content and API.
C.Amazon CloudFront for static content, Amazon API Gateway for the REST API, and AWS Lambda for compute.
D.Amazon S3 for static content with Transfer Acceleration, and AWS Lambda for API.
AnswerC

CloudFront caches static assets at edge locations worldwide, cutting latency, while API Gateway fronts Lambda for a fully managed REST API. This serverless combination delivers the global low latency and high availability the startup requires without managing servers.

Why this answer

It combines Amazon CloudFront for global low-latency delivery of static content, Amazon API Gateway to create and manage the REST API with built-in caching and throttling, and AWS Lambda for serverless compute. This architecture provides high availability, automatic scaling, and global edge caching, meeting the startup's requirements without managing servers.

Exam trap

The trap here is that candidates may confuse Lambda@Edge as a full compute solution for APIs, overlooking its severe execution limits, or assume that an ALB provides global low latency when it is inherently regional and requires additional services like Global Accelerator for global performance.

How to eliminate wrong answers

Option A is wrong because using an Application Load Balancer (ALB) for the API introduces a regional, not global, endpoint and requires managing EC2 instances or Lambda targets behind it, adding complexity and latency compared to API Gateway's global edge-optimized endpoints. Option B is wrong because Lambda@Edge is designed for lightweight, short-duration operations (e.g., header manipulation, URL rewrites) at CloudFront edge locations, not for running full REST API backends with DynamoDB interactions; it has a 5-second execution timeout and limited memory, making it unsuitable for typical API workloads. Option D is wrong because S3 Transfer Acceleration only speeds up uploads to S3 via optimized network paths, but does not provide a REST API gateway, authentication, or request throttling, and it lacks the global edge caching and API management features needed for a low-latency, globally available API.

130
MCQmedium

A company is designing a new microservices architecture on AWS. Each microservice is deployed as a containerized application and must be able to scale independently. The company wants to minimize operational overhead for managing the containers and the underlying infrastructure. Which solution should the architect recommend?

A.Amazon EKS with managed node groups
B.Amazon ECS with Fargate launch type
C.Amazon ECS with EC2 launch type and Auto Scaling groups
D.Amazon Lightsail containers
AnswerB

Fargate removes EC2 instance provisioning and patching, letting each containerised microservice scale independently via ECS service autoscaling. This satisfies the minimal operational overhead constraint, unlike EC2 launch types where you manage the underlying cluster capacity yourself.

Why this answer

Amazon ECS with the Fargate launch type is the correct choice because it is a serverless compute engine for containers that eliminates the need to provision, configure, or manage the underlying EC2 instances. This directly meets the requirement to minimize operational overhead while allowing each microservice to scale independently, as Fargate automatically handles the infrastructure and scaling based on the task definitions.

Exam trap

The trap here is that candidates often confuse 'managed node groups' (EKS) with 'serverless' (Fargate), assuming that managed node groups eliminate all operational overhead, when in fact they still require you to manage the EC2 instances, just with some automation for provisioning and updates.

How to eliminate wrong answers

Option A is wrong because Amazon EKS with managed node groups still requires you to manage and pay for the underlying EC2 instances (the node groups), and you are responsible for patching, scaling, and maintaining the worker nodes, which adds operational overhead. Option C is wrong because Amazon ECS with the EC2 launch type and Auto Scaling groups requires you to manage the EC2 instances, including capacity planning, patching, and cluster optimization, which contradicts the goal of minimizing operational overhead. Option D is wrong because Amazon Lightsail containers are designed for simpler, less complex workloads and do not offer the same level of granular scaling, integration with AWS services (e.g., VPC, IAM, CloudWatch), or the ability to handle production-grade microservices architectures with independent scaling requirements.

131
MCQmedium

A company is deploying a containerized application on Amazon EKS. The application needs to access an Amazon RDS database. The security team requires that database credentials be rotated automatically and never stored in plaintext. Which solution should the architect use?

A.Use AWS Secrets Manager to store and rotate credentials, and grant the EKS pod access via an IAM role
B.Use IAM database authentication for RDS and assign an IAM role to the pod
C.Hardcode the credentials in the container image and rotate the image regularly
D.Store credentials in AWS Systems Manager Parameter Store and grant the EKS pod access via an IAM role
AnswerA

Secrets Manager natively rotates RDS credentials on a schedule, and an IAM role bound to the pod's service account supplies temporary credentials, so no plaintext secret is stored. This satisfies the stem's automatic rotation and no-plaintext requirements.

Why this answer

AWS Secrets Manager is the correct choice because it natively supports automatic rotation of RDS database credentials via a built-in Lambda rotation function, and it integrates with IAM roles to grant EKS pods secure access without storing secrets in plaintext. By using an IAM role for the pod (via IRSA), the application can retrieve credentials at runtime from Secrets Manager, ensuring compliance with the security team's requirements.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager, assuming Parameter Store supports automatic rotation, but Parameter Store lacks native rotation capabilities for RDS credentials, making Secrets Manager the only correct choice for automated rotation.

How to eliminate wrong answers

Option B is wrong because IAM database authentication for RDS does not support automatic credential rotation; it relies on IAM roles and tokens, but the security team specifically requires rotating database credentials, not just authentication. Option C is wrong because hardcoding credentials in a container image violates the requirement to never store credentials in plaintext and does not provide automated rotation. Option D is wrong because AWS Systems Manager Parameter Store does not natively support automatic rotation of RDS credentials; it can store secrets but lacks the built-in rotation capability that Secrets Manager provides.

132
MCQhard

A CloudFormation stack output is as above. The company wants to use the SQS queue URL in another stack. Which intrinsic function should be used to reference the queue URL in the second stack?

A.Fn::ImportValue
B.Fn::GetAtt
C.Fn::Sub
D.Fn::Ref
AnswerA

Fn::ImportValue retrieves a value exported by another stack via the Export output field, satisfying the cross-stack reference requirement. The queue URL must first be exported in the source stack's Outputs section; the second stack then imports it by name, avoiding hardcoded values and enabling stack independence.

Why this answer

A is correct because Fn::ImportValue is the only intrinsic function that can reference a cross-stack output value exported via the Export field in a CloudFormation stack. Since the SQS queue URL is an output from one stack and needs to be used in another stack, Fn::ImportValue is required to import the exported value by name.

Exam trap

The trap here is that candidates often confuse Fn::GetAtt or Fn::Ref with cross-stack references, but those functions only work within the same stack, while Fn::ImportValue is specifically designed for cross-stack value sharing.

How to eliminate wrong answers

Option B (Fn::GetAtt) is wrong because it retrieves an attribute from a resource within the same stack, not from another stack's output. Option C (Fn::Sub) is wrong because it substitutes variables in a string template, but cannot reference cross-stack exports directly. Option D (Fn::Ref) is wrong because it returns the value of a parameter or resource within the same stack, not an exported output from another stack.

133
MCQeasy

A small business wants to host a simple static website on AWS. The website consists of HTML, CSS, JavaScript, and images. The company expects low traffic and wants to minimize costs. The website must be highly available and load quickly for users globally. Which solution should a Solutions Architect recommend?

A.Store the website files in an S3 bucket configured for static website hosting, and use Amazon CloudFront as a CDN.
B.Host the website on Amazon Lightsail with a load balancer and two instances.
C.Host the website on a single EC2 instance running Apache web server, with an Elastic IP address.
D.Deploy the website on AWS Elastic Beanstalk with a single EC2 instance.
AnswerA

S3 static website hosting serves the HTML, CSS, JavaScript and images without servers, and CloudFront caches content at edge locations for fast global delivery and high availability. This meets the low-traffic, minimal-cost, globally performant requirements.

Why this answer

S3 static website hosting with CloudFront provides low cost, high availability, and global low latency. Option B is wrong because Lightsail with a load balancer and two instances is more expensive and overkill for a simple static site. Option C is wrong because a single EC2 instance is not highly available and costs more than S3.

Option D is wrong because Elastic Beanstalk is designed for dynamic web apps, not static sites, and a single EC2 instance lacks high availability.

134
MCQmedium

A company is designing a new solution to securely store and manage secrets for applications running on AWS. The secrets include database credentials, API keys, and OAuth tokens. The solution must automatically rotate secrets and integrate with AWS services like Amazon RDS. Which AWS service should be used?

A.Store secrets in AWS Systems Manager Parameter Store with a SecureString parameter type.
B.Use AWS CloudHSM to store secrets as keys.
C.Use AWS Key Management Service (KMS) to store secrets as encrypted data keys.
D.Use AWS Secrets Manager to store secrets and configure automatic rotation.
AnswerD

AWS Secrets Manager natively performs scheduled rotation of database credentials, API keys and OAuth tokens via Lambda rotation functions, and integrates directly with Amazon RDS by updating both the secret and the database user's password. This satisfies the stem's mandatory automatic rotation and RDS integration requirements, which Systems Manager Parameter Store cannot provide.

Why this answer

AWS Secrets Manager is purpose-built for securely storing, managing, and automatically rotating secrets such as database credentials, API keys, and OAuth tokens. It provides native integration with Amazon RDS, enabling automatic rotation of RDS credentials without custom code, which directly meets the requirements for automatic rotation and AWS service integration.

Exam trap

The trap here is that candidates confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with AWS Secrets Manager (which is designed specifically for automatic secret rotation and deep AWS service integration), leading them to choose Parameter Store for its lower cost and familiarity.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store with SecureString does not support automatic rotation of secrets; it requires custom AWS Lambda functions or external processes to rotate secrets. Option B is wrong because AWS CloudHSM is a hardware security module for generating and storing cryptographic keys, not for managing application secrets like database credentials or API keys, and it lacks native rotation and RDS integration. Option C is wrong because AWS KMS is a key management service for creating and controlling encryption keys, not for storing secrets; it can encrypt data keys but does not provide secret storage, rotation, or direct RDS integration.

135
MCQhard

A company is designing a data lake on Amazon S3. The data is ingested from multiple sources and must be encrypted at rest using customer-managed keys. The company also needs to audit all access to the data lake. Which combination of services should be used?

A.Enable S3 bucket encryption with SSE-S3. Enable S3 server access logs.
B.Configure S3 bucket encryption with SSE-KMS using a customer-managed CMK. Enable AWS CloudTrail with data events for S3 and KMS.
C.Enable S3 default encryption with SSE-S3. Enable Amazon CloudWatch Logs for S3 access logging.
D.Use client-side encryption with a customer-managed key. Enable Amazon CloudWatch Logs for S3 access logs.
AnswerB

SSE-KMS with a customer-managed CMK satisfies the customer-managed key requirement, while CloudTrail data events capture object-level S3 access and KMS key usage. Together they provide encryption at rest plus the audit trail of all data lake access.

Why this answer

It uses SSE-KMS with a customer-managed CMK to meet the encryption-at-rest requirement with customer-controlled keys, and enables AWS CloudTrail with data events for both S3 and KMS to audit all access to the data lake. This combination provides granular auditing of every S3 object-level operation (e.g., GetObject, PutObject) and every KMS key usage (e.g., Decrypt, GenerateDataKey), which is essential for compliance and security monitoring.

Exam trap

The trap here is that candidates often confuse S3 server access logs (which are log files delivered to an S3 bucket) with CloudTrail data events, or assume SSE-S3 meets the 'customer-managed keys' requirement because it is a form of server-side encryption, but SSE-S3 uses AWS-owned keys, not customer-managed ones.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses AWS-managed keys, not customer-managed keys, and S3 server access logs are best-effort (delivered asynchronously) and do not capture KMS key usage, failing both the encryption and audit requirements. Option C is wrong because SSE-S3 again uses AWS-managed keys, and Amazon CloudWatch Logs for S3 access logging is not a native S3 feature; S3 access logs are delivered to S3, not directly to CloudWatch Logs, and they lack KMS audit trails. Option D is wrong because client-side encryption requires the customer to manage encryption/decryption in their application, which adds complexity and does not leverage S3's native encryption at rest; also, CloudWatch Logs for S3 access logs is not a standard S3 audit mechanism and does not capture KMS data events.

136
MCQhard

A company is designing a multi-region active-active application using Amazon Route 53, Application Load Balancers, and Auto Scaling groups. They need to route users to the closest region with the lowest latency. Which routing policy should they use?

A.Latency routing
B.Weighted routing
C.Failover routing
D.Geolocation routing
AnswerA

Latency routing uses latency measurements between users and AWS Regions to direct each request to the Region with the lowest latency, matching the closest-region requirement. Weighted, failover and geolocation policies do not optimise for measured network latency.

Why this answer

(Latency routing) is correct because it routes users to the AWS region that provides the lowest latency, based on real-time latency measurements. This is ideal for multi-region active-active applications where users should be directed to the closest region. Option B (Weighted routing) distributes traffic based on assigned weights, not latency.

Option C (Failover routing) is used for active-passive disaster recovery. Option D (Geolocation routing) routes based on the geographic location of the user, not on actual network latency.

137
MCQmedium

A media company runs a video processing pipeline on AWS. Videos are uploaded to an S3 bucket, which triggers an AWS Lambda function that transcodes the video into multiple formats using FFmpeg. The transcoding job runs on the Lambda function with a 15-minute timeout. Recently, the company started receiving 4K videos that take more than 15 minutes to transcode. The Lambda function times out, and the video is not processed. The company wants to process these large videos without increasing the Lambda timeout and without rewriting the entire pipeline. What should the solutions architect do?

A.Replace the Lambda function with AWS Elemental MediaConvert job triggered by S3 events.
B.Increase the Lambda function memory to the maximum to improve performance and reduce processing time.
C.Use AWS Step Functions to call multiple Lambda functions in parallel to process chunks of the video.
D.Use a Lambda function with a larger ephemeral storage to handle the video file.
AnswerA

MediaConvert is a managed transcoding service handling large 4K files without Lambda's 15-minute limit. Triggering jobs from existing S3 events preserves the pipeline's entry point, so only the compute layer changes, satisfying the requirement to avoid rewriting the pipeline.

Why this answer

AWS Elemental MediaConvert is a managed, file-based video transcoding service designed for large-scale, long-running jobs that far exceed Lambda's 15-minute execution limit. It natively integrates with S3 (input/output buckets) and can be triggered by S3 event notifications via EventBridge or Lambda, so the existing upload-to-S3 pipeline is preserved with minimal changes. This directly solves the 4K transcoding timeout without increasing Lambda timeout or rewriting the pipeline.

Exam trap

SAP-C02 often tests whether candidates recognize that Lambda's 15-minute timeout is a hard, non-negotiable limit — tempting them to 'just add memory' or 'add storage' when the real fix is moving long-running work to a purpose-built service like MediaConvert, Fargate, or Batch.

How to eliminate wrong answers

Option B is wrong because increasing Lambda memory only scales CPU proportionally and cannot extend the hard 15-minute invocation timeout — a 4K job exceeding 15 minutes will still be killed. Option C is wrong because splitting a video into chunks and transcoding in parallel requires rewriting the pipeline logic, reassembling segments, and managing state — exactly what the question says to avoid, and Step Functions still invokes Lambda functions bounded by the 15-minute limit. Option D is wrong because ephemeral storage (/tmp, up to 10 GB) addresses disk space, not execution duration; the timeout remains 15 minutes regardless of storage size.

138
MCQhard

A financial services firm runs a latency-sensitive trading application across three AWS Regions. The application writes to an Amazon DynamoDB table in the primary Region and must be able to read and write locally in the other two Regions with single-digit-millisecond latency, while tolerating a full Region failure. The firm accepts eventual consistency across Regions but requires that no acknowledged write is ever lost. Which solution should a solutions architect recommend?

A.Replicate the table to each Region using AWS Database Migration Service with change data capture, and have the application write to the nearest Regional table.
B.Use Amazon Aurora Global Database with a writer in the primary Region and read replicas in the other Regions, and route writes to the primary writer endpoint.
C.Create a DynamoDB global table with multi-Region replication and configure the application to read and write to the local Regional replica.
D.Deploy the DynamoDB table in the primary Region and use DynamoDB Accelerator (DAX) clusters in each Region to serve local reads and writes.
AnswerC

DynamoDB global tables provide multi-Region, multi-active replication with local read and write latency in each Region, and last-writer-wins conflict resolution. Writes acknowledged in any Region are durable and replicated, and the table remains writable if one Region fails, satisfying the local-latency and Region-failure tolerance requirements while accepting eventual consistency.

Why this answer

Multi-active writes with local single-digit-millisecond latency in three Regions, tolerance of a Region outage, and no acknowledged-write loss point to DynamoDB global tables. Each Region holds a full replica that accepts reads and writes locally, and replication propagates changes asynchronously, so a failed Region does not stop the others from serving traffic.

Exam trap

The trap here is treating a read-accelerating cache such as DAX, or a single-writer relational engine, as if it could accept low-latency writes in every Region.

139
MCQhard

A company runs a critical e-commerce platform on AWS. The application is deployed across multiple Availability Zones in a single region (us-east-1). The architecture includes an Application Load Balancer (ALB), an EC2 Auto Scaling group, and an Amazon RDS for MySQL Multi-AZ database. The application experiences periodic spikes in traffic, and the Auto Scaling group scales out successfully. However, during a recent traffic spike, the database CPU utilization reached 90%, causing increased latency and some database connection timeouts. The company needs to improve the database performance to handle the spikes without over-provisioning. The solutions architect must design a solution that reduces the load on the primary database instance and improves read scalability. The application is read-heavy, with a read-to-write ratio of 80:20. Which solution should the architect implement?

A.Implement an Amazon ElastiCache Redis cluster to cache frequent database queries.
B.Increase the DB instance class to a larger size and enable Multi-AZ with synchronous replication.
C.Migrate the database to Amazon DynamoDB and use DynamoDB Accelerator (DAX) for read performance.
D.Create one or more Amazon RDS Read Replicas in the same region and configure the application to route read queries to the read replica endpoint.
AnswerD

Read Replicas offload read traffic from the primary via asynchronous MySQL replication, directly addressing the 80:20 read-heavy ratio and the 90% primary CPU saturation. The application routes SELECT queries to the replica endpoint, restoring primary capacity for writes without over-provisioning.

Why this answer

Amazon RDS Read Replicas can offload read traffic from the primary instance, reducing CPU utilization. For a read-heavy workload (80:20), creating Read Replicas in the same region and routing read queries to them is the most effective solution to improve read scalability without over-provisioning the primary. Option D is correct.

Option A (ElastiCache) is more suited for caching but does not offload database reads directly; it requires significant application changes and may not handle all query patterns. Option B (scaling up instance class) has scaling limits and is less cost-effective; Multi-AZ is for high availability, not read scaling. Option C (DynamoDB) is a different database; migrating would be complex and unnecessary.

140
MCQhard

A company is running a production web application on AWS using an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application uses a MySQL database hosted on Amazon RDS with Multi-AZ enabled. Recently, during a traffic spike, some users experienced increased latency and occasional 503 errors. The operations team noticed that the database CPU utilization reached 100% and the number of database connections peaked at the maximum limit. The application team confirmed that the application uses connection pooling on the EC2 instances but the pool size is fixed. Which solution should the solutions architect recommend to prevent recurrence?

A.Add read replicas to offload read queries.
B.Increase the DB instance class to a larger size.
C.Implement Amazon RDS Proxy to manage database connections.
D.Increase the maximum number of EC2 instances in the Auto Scaling group.
AnswerC

Amazon RDS Proxy pools and shares database connections, absorbing traffic spikes so the fixed application-side pools no longer exhaust the RDS connection limit. This relieves the 100% CPU and connection ceiling causing latency and 503 errors.

Why this answer

The issue stems from database connections hitting the maximum limit, causing CPU saturation and 503 errors. Amazon RDS Proxy sits between the application and the database, efficiently managing and pooling connections from the EC2 instances, reducing the number of open connections to the RDS instance and preventing connection exhaustion. This allows the existing connection pooling on the EC2 side to scale without overwhelming the database, directly addressing the root cause.

Exam trap

The trap here is that candidates often confuse connection exhaustion with CPU or memory bottlenecks and choose vertical scaling (Option B) or read replicas (Option A), missing that the core issue is the fixed connection pool size and the database's max connections limit, which RDS Proxy directly addresses by pooling and reusing connections.

How to eliminate wrong answers

Option A is wrong because adding read replicas offloads read queries but does not reduce the number of database connections hitting the primary instance; the connection limit and CPU spike from connection overhead remain. Option B is wrong because increasing the DB instance class provides more CPU and memory but does not solve the connection limit issue; the application will still exhaust the max connections, and scaling vertically is a temporary fix that increases cost without addressing the architectural bottleneck. Option D is wrong because increasing the maximum number of EC2 instances in the Auto Scaling group would increase the number of application servers, each with a fixed connection pool, potentially worsening the connection exhaustion and CPU spike on the database.

141
Multi-Selecteasy

A company is designing a new web application that will run on Amazon EC2 instances behind an Application Load Balancer. The application must be highly available across multiple Availability Zones. Which TWO actions should the architect take? (Choose TWO.)

Select 2 answers
A.Launch all EC2 instances in a single Availability Zone.
B.Configure the ALB as internet-facing and attach it to multiple Availability Zones.
C.Launch EC2 instances in at least two Availability Zones.
D.Use a Network Load Balancer instead of an Application Load Balancer.
E.Assign Elastic IP addresses to each EC2 instance.
AnswersB, C

An internet-facing ALB distributes client traffic and, when attached to multiple Availability Zones, its nodes reside in each of those zones. This removes the load balancer as a single point of failure, satisfying the multi-AZ high availability requirement for the web tier.

Why this answer

Option B is correct because an internet-facing Application Load Balancer must be attached to subnets in multiple Availability Zones so it can distribute incoming traffic across those zones and remain resilient if one AZ fails. Option C is correct because the EC2 instances themselves must be launched in at least two Availability Zones; an ALB can only route to targets in the AZs it is enabled for, so placing instances in multiple AZs is what actually makes the application highly available. Option A is wrong because confining all instances to a single AZ creates a single point of failure and defeats the multi-AZ requirement.

Option D is wrong because the scenario specifies an Application Load Balancer for a web application, and swapping to an NLB is neither required nor appropriate for HTTP/HTTPS layer-7 routing. Option E is wrong because Elastic IP addresses are not needed for instances behind an ALB; the ALB's nodes handle public addressing, and EIPs do not provide multi-AZ high availability.

Exam trap

The trap here is that candidates may think launching instances in a single AZ is sufficient if the ALB is configured across multiple AZs, but the ALB requires healthy targets in each enabled AZ to maintain high availability; without instances in at least two AZs, the ALB cannot route traffic if the sole AZ fails.

142
MCQmedium

A company is migrating a legacy on-premises application to AWS. The application uses a shared file system that must be accessible from multiple Linux-based Amazon EC2 instances simultaneously. The application requires a POSIX-compliant file system with high throughput and low latency. The company wants a fully managed, scalable solution that can grow to petabytes. What should a solutions architect recommend?

A.Amazon FSx for Lustre
B.Amazon S3 with s3fs-fuse mounted on each EC2 instance
C.Amazon FSx for Windows File Server
D.Amazon Elastic File System (Amazon EFS)
AnswerD

Amazon EFS is a fully managed, scalable, POSIX-compliant file system for Linux workloads. It supports concurrent access from multiple EC2 instances and scales automatically to petabytes. It provides high throughput and low latency with the appropriate performance mode. This meets all the requirements without managing infrastructure.

Why this answer

Amazon EFS is a fully managed, elastic file system that supports the POSIX interface and can be mounted on multiple Linux EC2 instances concurrently. It scales automatically to petabytes and offers high throughput and low latency. It requires no infrastructure management, making it the ideal choice for a shared file system for Linux workloads.

Exam trap

The trap here is assuming that Amazon S3 mounted via s3fs is a suitable replacement for a POSIX file system, when it is not POSIX-compliant and has performance drawbacks.

143
MCQeasy

A startup is deploying a web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in an Amazon DynamoDB table. To improve performance, the team wants to reduce latency for read-heavy workloads. Which design change would be MOST effective?

A.Add an Amazon ElastiCache Redis cluster in front of DynamoDB to cache session data.
B.Use an Auto Scaling group to add more EC2 instances during peak hours.
C.Enable DynamoDB Accelerator (DAX) for the session table.
D.Increase the size of the EC2 instances to handle more concurrent users.
AnswerC

DAX provides an in-memory write-through cache for DynamoDB, serving repeated session reads in microseconds and cutting latency for read-heavy workloads. It satisfies the performance constraint directly, unlike increasing capacity or adding read replicas, which address throughput rather than microsecond read latency.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache specifically designed for Amazon DynamoDB. It reduces read latency from single-digit milliseconds to microseconds by caching frequently accessed items, making it ideal for read-heavy session state workloads without requiring application-level cache management.

Exam trap

The trap here is that candidates often choose ElastiCache Redis (Option A) because it is a general-purpose cache, but they overlook that DAX is purpose-built for DynamoDB and eliminates the need for custom cache invalidation logic, making it the most effective and operationally simpler choice for this specific use case.

How to eliminate wrong answers

Option A is wrong because adding an ElastiCache Redis cluster in front of DynamoDB introduces operational complexity and potential data inconsistency between the cache and the database, whereas DAX provides a native, write-through cache that automatically synchronizes with DynamoDB. Option B is wrong because scaling EC2 instances with Auto Scaling addresses compute capacity, not the latency of reading session data from DynamoDB; the bottleneck is database read performance, not application server throughput. Option D is wrong because increasing EC2 instance size improves compute and memory capacity but does not reduce the latency of DynamoDB read operations; the session state is stored externally, so larger instances do not accelerate database access.

144
MCQmedium

A company is designing a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application experiences sudden spikes in traffic. Which AWS service should be used to handle the traffic spikes without losing any requests?

A.Amazon SNS
B.AWS Step Functions
C.Amazon SQS
D.Amazon Kinesis Data Streams
AnswerC

Amazon SQS decouples API Gateway from Lambda, buffering burst traffic in a durable queue so no requests are lost during spikes. Lambda's concurrency limits would otherwise throttle or drop invocations; SQS absorbs the surge and enables downstream retry processing.

Why this answer

Amazon SQS is a fully managed message queuing service that decouples application components and buffers requests during traffic spikes. By placing an SQS queue between API Gateway and Lambda (or between Lambda and DynamoDB), the system can absorb sudden bursts of traffic without losing requests, as messages are durably stored until processed. This is the standard pattern for handling spiky serverless workloads.

Exam trap

SAP-C02 often tests the confusion between SNS (push, no buffering) and SQS (pull, buffering), causing candidates to pick SNS when the requirement is to avoid losing requests during spikes.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub notification service that pushes messages to subscribers; it does not buffer or retain messages for later processing, so requests can be lost if subscribers cannot keep up. Option B is wrong because AWS Step Functions orchestrates workflows but does not provide a durable buffer for high-volume request spikes; it is designed for coordinating stateful workflows, not for queuing. Option D is wrong because Amazon Kinesis Data Streams is designed for real-time streaming analytics with ordered records and retention, but it requires provisioned shards and is not the simplest or most appropriate buffer for decoupling a serverless application; SQS is the canonical choice for request buffering.

145
Multi-Selecthard

A company is migrating a legacy application to AWS. The application requires static IP addresses for whitelisting by third-party APIs. The company plans to use an Application Load Balancer with EC2 instances. Which two steps should the company take to ensure the ALB has a consistent set of IP addresses? (Choose TWO.)

Select 2 answers
A.Use a NAT Gateway with Elastic IPs for outbound traffic.
B.Place a Network Load Balancer with Elastic IP addresses in front of the ALB.
C.Use Amazon Route 53 with an A record pointing to the ALB.
D.Place the ALB behind an AWS Global Accelerator.
E.Associate an AWS WAF web ACL with the ALB.
AnswersB, D

A Network Load Balancer supports Elastic IP addresses, giving static public IPs for third-party whitelisting. Placing it in front of the Application Load Balancer preserves the ALB's layer 7 routing while presenting fixed addresses, satisfying the static IP constraint.

Why this answer

Option B is correct because an Application Load Balancer does not support static IP addresses, but a Network Load Balancer can be assigned Elastic IP addresses per subnet; placing the NLB in front of the ALB gives third-party APIs a fixed set of IPs to whitelist while the NLB forwards traffic to the ALB. Option D is correct because AWS Global Accelerator provides two static anycast IP addresses that front the ALB, so third parties can whitelist those fixed IPs and traffic is routed to the ALB without the ALB itself needing static addresses. Option A is not correct because a NAT Gateway with Elastic IPs only affects outbound traffic from private subnets and does not provide static inbound IPs for an ALB.

Option C is not correct because a Route 53 A record resolves to the ALB's DNS name and its dynamic IP addresses, so it does not create a consistent static IP set. Option E is not correct because AWS WAF is a layer 7 filtering service and has no effect on the IP addresses used by the ALB.

Exam trap

The trap here is that candidates may think AWS WAF provides static IP addresses, but it does not. Additionally, they might overlook the NLB+Elastic IP approach as a valid method, or confuse NAT Gateway's outbound Elastic IPs with inbound static IPs.

146
MCQeasy

Refer to the exhibit. A CloudFormation stack creation failed. The architect needs to identify the reason for the failure. Which CLI command should be used to get detailed error messages?

A.aws cloudformation describe-stacks --stack-name my-stack
B.aws cloudformation describe-stack-events --stack-name my-stack
C.aws cloudformation get-template --stack-name my-stack
D.aws cloudformation list-stack-resources --stack-name my-stack
AnswerB

`describe-stack-events` returns the chronological event stream for the stack, including each resource's status reason. When creation fails, the `CREATE_FAILED` event carries the precise error message naming the offending resource and cause, satisfying the requirement for detailed failure diagnostics rather than just stack-level status.

Why this answer

The 'describe-stack-events' command provides detailed events including error messages, which can be used to identify reasons for stack creation failure. Option A is incorrect because 'describe-stacks' only shows the stack status and output, not detailed error messages. Option C is incorrect because 'get-template' retrieves the template body, not events.

Option D is incorrect because 'list-stack-resources' lists resources, not events or errors.

147
MCQmedium

A company is designing a multi-tier web application on AWS. The web tier must automatically scale based on CPU utilization, and the application tier must process messages from an SQS queue. The application tier instances are frequently terminated and replaced due to scaling events. Where should the application logs be stored to ensure they are retained regardless of instance lifecycle?

A.Configure the CloudWatch Logs agent on each instance to stream logs to CloudWatch Logs.
B.Store logs on an EBS volume and take regular snapshots.
C.Write logs to the instance store volume of each EC2 instance.
D.Write logs to an Amazon S3 bucket mounted on each instance using NFS.
AnswerA

Streaming via the CloudWatch Logs agent decouples log storage from the instance lifecycle, satisfying the requirement that logs survive frequent termination and replacement. Logs persist in CloudWatch Logs independently of any EC2 instance, unlike instance-store or ephemeral volumes.

Why this answer

The CloudWatch Logs agent streams log data to Amazon CloudWatch Logs in real-time, decoupling log retention from the EC2 instance lifecycle. When instances are terminated, the logs are already persisted in CloudWatch Logs, ensuring they are retained regardless of scaling events.

Exam trap

The trap here is that candidates may confuse instance store (ephemeral) with EBS (persistent) storage, or assume that mounting S3 via NFS is a straightforward AWS feature, when in fact CloudWatch Logs is the only fully managed, instance-lifecycle-independent solution for log retention in this scenario.

How to eliminate wrong answers

Option B is wrong because EBS snapshots are point-in-time backups and do not provide continuous log streaming; logs written to an EBS volume are lost if the instance is terminated and the volume is deleted, unless snapshots are taken frequently, which adds complexity and potential data loss between snapshots. Option C is wrong because instance store volumes are ephemeral and data is lost when the instance is stopped, terminated, or fails; they are not suitable for persistent log storage. Option D is wrong because mounting an S3 bucket via NFS is not a native AWS feature; it requires third-party tools or FUSE-based solutions, introduces latency and complexity, and does not guarantee real-time log streaming or seamless integration with instance scaling.

148
MCQmedium

A company is migrating a legacy monolithic application to AWS. The application currently uses a shared file system for storing user uploads. The solution architect needs to design a highly available and scalable storage solution that supports concurrent read/write operations from multiple EC2 instances. Which AWS service should be used?

A.Amazon FSx for Windows File Server
B.Amazon S3 with S3 File Gateway
C.Amazon EFS
D.Amazon EBS with Multi-Attach enabled
AnswerC

Amazon EFS provides a shared, elastic NFS file system that many EC2 instances across Availability Zones can mount concurrently with read/write access. This satisfies the concurrent access and high availability constraints that a single-instance or block-based store cannot.

Why this answer

Amazon EFS provides a fully managed, elastic NFS file system that supports concurrent read/write access from thousands of EC2 instances across multiple Availability Zones. It is designed for high availability and scalability, automatically growing and shrinking as files are added or removed, making it ideal for a shared file system for user uploads in a migrated monolithic application.

Exam trap

The trap here is that candidates often confuse Amazon EBS Multi-Attach with a true shared file system, overlooking its single-AZ limitation and the need for a cluster-aware file system, or they mistakenly choose S3 File Gateway thinking it provides native file system semantics, when in fact it adds latency and complexity for concurrent write workloads.

How to eliminate wrong answers

Option A is wrong because Amazon FSx for Windows File Server is optimized for Windows-based workloads requiring SMB protocol support and Active Directory integration, not for general-purpose Linux-based concurrent access from multiple EC2 instances. Option B is wrong because Amazon S3 with S3 File Gateway presents an NFS or SMB mount point backed by S3, but it introduces latency and caching complexity, and S3 itself is an object store, not a POSIX-compliant file system suitable for concurrent read/write locking. Option D is wrong because Amazon EBS with Multi-Attach enabled supports only up to 16 Nitro-based EC2 instances in a single Availability Zone, lacks cross-AZ high availability, and does not provide a shared file system interface (it is a block-level device requiring a cluster-aware file system).

149
MCQmedium

A company is designing a new microservices architecture using AWS Lambda. Each microservice has its own database. The company wants to securely store database credentials and rotate them automatically. Which AWS service should be used?

A.AWS Key Management Service (KMS)
B.AWS Systems Manager Parameter Store
C.AWS Identity and Access Management (IAM)
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager natively stores database credentials and provides built-in automatic rotation via Lambda, satisfying the rotation requirement without custom code. Unlike SSM Parameter Store, rotation is a first-class managed feature, so credentials are regularly replaced and securely retrieved by each microservice at runtime.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials for services like Amazon RDS, Redshift, and DocumentDB. It supports built-in rotation with AWS Lambda, ensuring credentials are rotated on a schedule without manual intervention, which directly meets the requirement for automatic rotation in a microservices architecture.

Exam trap

The trap here is that candidates often confuse Parameter Store's secure string parameter with Secrets Manager, but Parameter Store lacks native automatic rotation, which is the critical requirement in this question.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encryption keys, not for storing or rotating secrets like database credentials; it can encrypt secrets but does not manage rotation. Option B is wrong because AWS Systems Manager Parameter Store can store secrets but lacks native automatic rotation capabilities—it requires custom solutions or integration with Secrets Manager for rotation. Option C is wrong because IAM is used for access control and permissions, not for storing secrets or rotating credentials; it cannot store database passwords or manage their lifecycle.

150
MCQhard

A company is designing a multi-region active-active application that uses Amazon DynamoDB global tables. The application must be able to handle write conflicts that may occur when the same item is updated in two different regions at the same time. The company needs to ensure that the application uses the most recently written data. What should the architect recommend?

A.Use the default last writer wins conflict resolution
B.Use optimistic locking with a version number
C.Use DynamoDB Streams to capture changes and reconcile conflicts
D.Use conditional writes to prevent overwrites
AnswerA

DynamoDB global tables resolve concurrent writes using last writer wins, comparing timestamps to keep the most recent update. This satisfies the requirement that the application uses the most recently written data when the same item is updated simultaneously in two regions.

Why this answer

Amazon DynamoDB global tables use a last writer wins (LWW) conflict resolution mechanism based on the timestamp of the update. When concurrent updates to the same item occur in different regions, DynamoDB automatically compares the update timestamps and retains the most recently written data. This satisfies the requirement to use the most recently written data without requiring custom reconciliation logic.

Exam trap

The trap here is that candidates often overthink conflict resolution and choose complex options like streams or optimistic locking, not realizing that DynamoDB global tables already handle this automatically with LWW, which is the simplest and most appropriate solution for ensuring the most recently written data is used.

How to eliminate wrong answers

Option B is wrong because optimistic locking with a version number prevents overwrites by rejecting stale updates, but it does not resolve conflicts by keeping the most recent write; it would cause writes to fail instead of automatically selecting the latest data. Option C is wrong because DynamoDB Streams can capture changes but do not provide built-in conflict resolution; using streams to reconcile conflicts would require custom application logic and would not automatically ensure the most recently written data is used. Option D is wrong because conditional writes prevent overwrites when a condition is not met, which would cause write failures rather than resolving conflicts by keeping the latest write.

← PreviousPage 2 of 5 · 321 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design for New Solutions questions.