Courseiva

SAP-C02 · topic practice

Continuous Improvement for Existing Solutions practice questions

Domain 4 of SAP-C02 covers reviewing deployed workloads and making them better: cost, performance, reliability, and operational excellence. Questions present an existing architecture with a symptom or goal, then ask which AWS service, configuration change, or redesign fixes it. Expect DynamoDB key redesign, Auto Scaling policies, network diagnostics, and DR strategy trade-offs.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Continuous Improvement for Existing Solutions

What the exam tests

What to know about Continuous Improvement for Existing Solutions

Given an existing workload, identify the bottleneck or risk, then pick the AWS service or configuration change that resolves it at acceptable cost. The single most important skill is mapping a stated symptom, such as throttling or slow failover, to the specific AWS feature that addresses it.

Diagnosing EC2 network paths with VPC Flow Logs and AWS Network Manager / Reachability Analyzer

Redesigning DynamoDB partition keys and using adaptive capacity or on-demand to fix hot partitions

Choosing Auto Scaling target tracking, step, or scheduled policies driven by custom CloudWatch metrics

Selecting DR strategies (backup/restore, pilot light, warm standby, multi-site) per RTO and RPO

Watch out for

Common Continuous Improvement for Existing Solutions exam traps

  • ▸Assuming DynamoDB hot partitions are fixed only by adding read/write capacity instead of changing the partition key design.
  • ▸Picking CloudWatch basic monitoring when detailed monitoring or custom metrics are required for fine-grained Auto Scaling.
  • ▸Treating multi-site active-active as always correct for DR, ignoring cost and the stated RTO/RPO requirements.

Practice set

Continuous Improvement for Existing Solutions questions

20 questions · select your answer, then reveal the explanation

A company is using AWS CloudFormation to deploy infrastructure. The security team requires that all Amazon S3 buckets created by CloudFormation must be encrypted at rest. What should a solutions architect do to enforce this requirement?

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all Amazon S3 buckets across the organization are encrypted at rest. Which TWO steps should the security team take to enforce this requirement?

A company is running a critical application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application needs to process a large batch job that runs once per month and takes 2 hours. The company wants to optimize costs while ensuring the batch job has sufficient capacity. Which THREE steps should a solutions architect recommend?

A company runs a critical application on EC2 instances behind an Application Load Balancer (ALB) in a production AWS account. Recently, the application has experienced intermittent timeouts. The operations team notices that the CPU utilization of the instances spikes to 100% for a few minutes during the timeouts. The Auto Scaling group is configured with a target tracking scaling policy based on average CPU utilization at 70%. What should a solutions architect do to improve the application's availability and reduce timeouts?

A company is running a containerized microservices application on Amazon ECS with Fargate launch type. The application experiences increased latency during peak hours. Upon investigation, the CPU utilization of the tasks reaches 90%. The ECS service is configured with a target tracking scaling policy based on average CPU at 70%. However, scaling is not keeping up with demand. What should a solutions architect do to improve the responsiveness of the scaling?

An IAM policy is attached to a group. A user in the group tries to terminate an EC2 instance in us-east-1 using the AWS CLI. What will happen?

Exhibit

Refer to the exhibit.

iam-policy.json:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "ec2:Describe*",
      "Resource": "*"
    },
    {
      "Effect": "Deny",
      "Action": "ec2:TerminateInstances",
      "Resource": "arn:aws:ec2:us-east-1:123456789012:instance/*"
    }
  ]
}

A solutions architect runs the command shown in the exhibit. Which statement is true about the output?

Network Topology
$ aws ec2 describe-instancesfilters Name=tag:Environmentquery 'Reservations[].Instances[?State.Name==`running`].[InstanceIdoutput table+Refer to the exhibit.Output:| DescribeInstances |

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses an Amazon RDS MySQL Multi-AZ DB instance. During a recent load test, the application became unresponsive for several minutes. The monitoring shows that the RDS instance CPU utilization spiked to 100% during the test. The application reads and writes to the same database. Which design change would provide the BEST improvement in database scalability and reduce CPU contention?

A company uses AWS CodePipeline to automate deployments of a microservices application to Amazon ECS. The pipeline builds a Docker image, pushes it to Amazon ECR, and updates the ECS service. Recently, deployments have failed because insufficient IAM permissions cause the pipeline to fail when updating the ECS service. The development team wants to implement least privilege permissions. Which IAM policy statement should be added to the CodePipeline service role to allow it to update the ECS service?

A company runs a critical web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application stores session state in an Amazon ElastiCache for Redis cluster. Recently, the operations team noticed that during traffic spikes, the ALB returns 5xx errors and the application becomes slow. CloudWatch metrics show that the Redis cluster's CPU utilization reaches 100% and memory usage is high. The Auto Scaling group scales out, but the new instances take several minutes to warm up and become healthy. The company needs to improve the application's ability to handle traffic spikes with minimal impact on performance. Which solution should the company implement?

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences intermittent latency spikes. The operations team has enabled detailed CloudWatch metrics and EC2 instance status checks. The team needs to identify the root cause of the latency. Which TWO actions should the team take to diagnose the issue? (Choose two.)

A company runs a containerized microservices application on Amazon ECS with Fargate launch type. The application consists of a frontend service and a backend service. The backend service is CPU-intensive and experiences high load during business hours. The operations team observes that the frontend service sometimes returns 503 errors during peak load. The team has already configured an ECS service auto scaling policy for the backend service based on average CPU utilization with a target value of 70%. The backend service is currently running 4 tasks, and the frontend is running 2 tasks. The errors seem to correlate with the backend scaling up. Which solution should the team implement to improve the application's performance and reduce errors?

Match each AWS monitoring and logging service to its capability.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Collect metrics, logs, and set alarms

Record API activity for auditing

Assess, audit, and evaluate resource configurations

Trace and analyze distributed application requests

Automated security assessment of workloads

A company uses AWS Lambda to process incoming messages from an SQS queue. The Lambda function is triggered by SQS and processes messages in batches of 10. Recently, the number of messages has increased significantly, and some messages are being processed multiple times. What should a solutions architect do to ensure exactly-once processing?

A company runs a web application on Amazon ECS with Fargate launch type behind an Application Load Balancer. The application stores session state in a local file system on the container. Users report that they are frequently logged out and lose session data. What is the most likely cause?

A company uses Amazon ElastiCache for Redis to cache frequently accessed data. The cache cluster is a single node (cache.r5.large). Over time, the cache hit ratio has decreased, and the CPU utilization is consistently above 80%. What should a solutions architect do to improve performance?

A company uses Amazon DynamoDB with provisioned capacity for a critical workload. They notice that write requests are being throttled during peak hours. The table has a partition key of 'user_id' and a sort key of 'timestamp'. The access pattern is evenly distributed. What should a solutions architect do to reduce throttling?

A company is using an AWS Lambda function to process files uploaded to an S3 bucket. The function is written in Python and uses the boto3 library to read the files. Recently, some files have been processed multiple times. Which TWO measures should a solutions architect implement to ensure idempotent processing?

A company is using Amazon RDS for PostgreSQL with Multi-AZ deployment. The database experiences high write latency during peak hours. The solutions architect suggests using an RDS read replica to offload read traffic. Which THREE steps are necessary to implement this solution?

A company uses cross-account S3 access. The above IAM policy is attached to an IAM user in Account A. The user tries to upload an object to a bucket in Account B, but the upload fails. What is the MOST likely reason?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "StringEquals": {
          "s3:x-amz-acl": "bucket-owner-full-control"
        }
      }
    }
  ]
}

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Continuous Improvement for Existing Solutions sessions

Start a Continuous Improvement for Existing Solutions only practice session

Every question in these sessions is drawn from the Continuous Improvement for Existing Solutions domain — nothing else.

Related practice questions

Related SAP-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SAP-C02 exam test about Continuous Improvement for Existing Solutions?
Given an existing workload, identify the bottleneck or risk, then pick the AWS service or configuration change that resolves it at acceptable cost. The single most important skill is mapping a stated symptom, such as throttling or slow failover, to the specific AWS feature that addresses it.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Continuous Improvement for Existing Solutions questions in a focused session?
Yes — the session launcher on this page draws every question from the Continuous Improvement for Existing Solutions domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SAP-C02 topics?
Use the topic links above to move to related areas, or go back to the SAP-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SAP-C02 exam covers. They are not copied from any real exam or dump site.