Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 526–600

1169 questions total · 16pages · All types, answers revealed

Page 7

Page 8 of 16

Page 9
526
MCQmedium

A company runs a global e-commerce application that uses Amazon DynamoDB as its primary database. The application requires single-digit millisecond read and write latency from any region and must continue to operate during a regional outage with minimal data loss. Which DynamoDB feature should the SysOps administrator enable to meet these requirements?

A.DynamoDB Accelerator (DAX)
B.DynamoDB global tables
C.DynamoDB Point-in-Time Recovery (PITR)
D.DynamoDB Auto Scaling
AnswerB

DynamoDB global tables automatically replicate each item write to all selected AWS Regions, creating active-active replica tables with multi-region read and write capability. This cross-region replication gives users low-latency access because they can be served by a nearby replica, and it provides business continuity by allowing another Region to continue serving traffic during a Regional outage without manual data restore. Because every replica holds a full copy of the data, a Region failure is effectively transparent at the table level, assuming your application can reroute traffic.

Why this answer

DynamoDB global tables provide multi-Region, multi-active replication, enabling single-digit millisecond reads and writes from any Region while offering automatic failover and recovery during a regional outage. This feature uses DynamoDB Streams to replicate data across Regions with eventual consistency, meeting the requirement for continued operation with minimal data loss.

Exam trap

The trap here is that candidates often confuse DynamoDB Accelerator (DAX) with global tables, assuming a caching layer can provide multi-Region availability, but DAX is Region-specific and does not replicate data across Regions.

How to eliminate wrong answers

Option A is wrong because DynamoDB Accelerator (DAX) is an in-memory cache that reduces read latency but does not provide multi-Region replication or write availability during a regional outage. Option C is wrong because Point-in-Time Recovery (PITR) enables backup restoration to any point within the last 35 days but does not provide real-time failover or cross-Region read/write capability. Option D is wrong because Auto Scaling adjusts provisioned throughput based on traffic but does not replicate data across Regions or ensure availability during a regional outage.

527
MCQmedium

An application writes error logs to Amazon CloudWatch Logs. The SysOps administrator needs to monitor for the occurrence of the string 'ERROR' in the logs and trigger an Amazon SNS notification if more than 10 errors occur within a 5-minute window. The administrator also wants to visualize the error count over time. Which approach should be used to meet these requirements with the least operational overhead?

A.Create a CloudWatch Logs metric filter to count 'ERROR' entries, then create a CloudWatch alarm on that metric with a period of 5 minutes and a threshold of 10.
B.Use CloudWatch Logs Insights to run a query every 5 minutes and send notifications via a scheduled AWS Lambda function.
C.Create an AWS Lambda function that processes log events in real-time and publishes to Amazon SNS when the error count exceeds 10 in 5 minutes.
D.Use Amazon EventBridge to match log events with the pattern 'ERROR' and send them to an SNS topic.
AnswerA

A CloudWatch Logs metric filter continuously scans incoming log events for the pattern 'ERROR' and increments a custom metric (e.g., ErrorCount) in near real time. The CloudWatch alarm evaluates that metric over a 5-minute period and triggers when the count crosses 10, providing fully managed, code-free alerting that also makes the metric available for dashboards and scaling decisions.

Why this answer

CloudWatch Logs metric filters can extract a count of 'ERROR' occurrences from incoming log events and emit a custom metric. A CloudWatch alarm on that metric with a period of 5 minutes and a threshold of 10 directly triggers an SNS notification when the error count exceeds 10 within the window, and the metric itself can be graphed in CloudWatch dashboards for visualization—all with minimal configuration and no custom code.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Lambda or EventBridge, not realizing that CloudWatch Logs metric filters combined with CloudWatch alarms are the native, serverless, and lowest-overhead way to count substring occurrences and trigger alerts on aggregated thresholds.

How to eliminate wrong answers

Option B is wrong because running a CloudWatch Logs Insights query every 5 minutes via a scheduled Lambda function introduces unnecessary complexity, latency, and operational overhead compared to a real-time metric filter and alarm. Option C is wrong because creating a Lambda function to process log events in real-time adds custom code, scaling concerns, and maintenance burden when CloudWatch Logs metric filters and alarms natively provide the same functionality with zero code. Option D is wrong because Amazon EventBridge does not natively parse or count occurrences of a string like 'ERROR' within log events; it matches event patterns at the event level, not substring counts within log messages, and cannot aggregate counts over a time window.

528
Multi-Selecteasy

A company wants to use Amazon CloudFront to distribute content globally with low latency. Which TWO features of CloudFront help achieve this?

Select 2 answers
A.Regional edge caches that provide additional caching layers
B.Edge locations that cache content near users
C.Use of S3 Transfer Acceleration
D.VPC peering to connect to origins
E.Integration with AWS Global Accelerator
AnswersA, B

Regional edge caches are a middle-tier layer between CloudFront edge locations and the origin server. They have larger storage capacity than edge locations and retain content longer, which improves cache hit ratios for content that is requested less frequently. When an edge location misses, it can fetch from the regional edge cache instead of hitting the origin directly, reducing origin load and latency. This is a native CloudFront architecture component, not a separate service.

Why this answer

Option B is correct because CloudFront's global network of edge locations caches content at sites physically close to end users, so requests are served from the nearest point of presence and round-trip latency is minimized. Option A is correct because regional edge caches sit between the edge locations and the origin, providing an additional, larger caching layer that keeps less-popular content cached longer and reduces the number of origin fetches, which further lowers latency and improves hit ratios. Option C is not correct because S3 Transfer Acceleration speeds up uploads to S3 buckets over the AWS backbone and is not a CloudFront content-delivery feature.

Option D is not correct because VPC peering connects VPCs privately and does not provide global edge caching or low-latency content distribution. Option E is not correct because AWS Global Accelerator is a separate service that routes traffic over the AWS global network using static anycast IPs; it is not a CloudFront feature used to achieve edge caching.

Exam trap

SOA-C02 often tests the distinction between CloudFront's built-in caching features (edge locations and regional edge caches) and other AWS services like S3 Transfer Acceleration or Global Accelerator that also aim to reduce latency but are not part of CloudFront.

529
MCQeasy

A SysOps administrator is troubleshooting an application that runs on an EC2 instance. The application is experiencing high latency, and the administrator suspects a memory leak. Which metrics should the administrator examine first?

A.Custom CloudWatch metrics published by the CloudWatch agent, such as mem_used_percent.
B.CloudWatch metrics from the Detailed Monitoring feature, such as DiskReadOps.
C.CloudWatch metrics for the instance's Elastic Network Interface.
D.CloudWatch default EC2 metrics, such as CPUUtilization and NetworkIn.
AnswerA

The CloudWatch agent runs inside the EC2 instance as an OS-level service, so it can read the guest operating system's /proc/meminfo and report memory utilization as a custom metric in the CWAgent namespace (e.g., mem_used_percent). It uses the PutMetricData API and requires an IAM role with CloudWatchAgentServerPolicy to publish metrics. Default hypervisor-level EC2 metrics never expose guest memory, which is why installing the agent is the standard way to get memory utilization in CloudWatch.

Why this answer

A memory leak causes the application to consume increasing amounts of memory over time, leading to high latency as the OS begins swapping or the kernel reclaims memory. The CloudWatch agent can publish custom metrics like `mem_used_percent`, which directly tracks memory usage percentage and is the most relevant metric to confirm a memory leak. Default EC2 metrics do not include memory utilization, so the administrator must rely on custom metrics from the CloudWatch agent.

Exam trap

The trap here is that candidates assume default EC2 metrics include memory utilization, but AWS does not provide guest OS memory metrics by default; you must install the CloudWatch agent to capture them.

How to eliminate wrong answers

Option B is wrong because DiskReadOps measures disk I/O operations, not memory usage; it would not help identify a memory leak. Option C is wrong because Elastic Network Interface metrics track network throughput and packet counts, which are unrelated to memory consumption. Option D is wrong because default EC2 metrics like CPUUtilization and NetworkIn do not include memory metrics; EC2 does not expose guest OS memory usage without the CloudWatch agent.

530
MCQhard

A SysOps administrator deploys the CloudFormation template shown in the exhibit. The stack creation fails with a security group error. What is the most likely cause?

A.The AMI ID is incorrect.
B.The security group ingress rule uses an invalid CIDR.
C.The template uses 'SecurityGroups' instead of 'SecurityGroupIds' for a VPC instance.
D.The security group ingress rule allows SSH from all IPs.
AnswerC

In CloudFormation's AWS::EC2::Instance resource, the SecurityGroups property accepts security group names and is only supported for EC2-Classic or a default VPC, but when launching an instance into a VPC subnet you must use SecurityGroupIds. Supplying SecurityGroups together with a SubnetId causes the EC2 RunInstances API to receive a group name in a context that requires a group ID, generating a parameter-combination or subnet-not-found error. Changing the template to reference the VPC security group's ID via SecurityGroupIds resolves the deployment failure.

Why this answer

When launching an EC2 instance into a VPC subnet, CloudFormation's AWS::EC2::Instance resource requires the SecurityGroupIds property (a list of security group IDs), not SecurityGroups (which is only valid for EC2-Classic). Using SecurityGroups with a VPC subnet causes the stack to fail with a security group error.

Exam trap

SOA-C02 often tests the EC2-Classic vs VPC property distinction — candidates see 'SecurityGroups' and assume it is valid because it sounds correct, missing that VPC instances require SecurityGroupIds.

How to eliminate wrong answers

Option A is wrong because an incorrect AMI ID produces an 'InvalidAMIID.NotFound' error, not a security group error. Option B is wrong because an invalid CIDR in an ingress rule would fail with an 'InvalidParameterValue' error referencing the CIDR, not a generic security group error. Option D is wrong because allowing SSH from 0.0.0.0/0 is a security best-practice violation but does not cause stack creation to fail — CloudFormation will happily create the rule.

531
MCQmedium

A company uses Amazon CloudFront to deliver its static website hosted on Amazon S3. The security team notices that users are able to access the S3 bucket directly via the S3 endpoint, bypassing CloudFront. What should be done to ensure that content is only accessible through CloudFront?

A.Create an origin access identity (OAI) and update the S3 bucket policy to grant access only to the OAI
B.Use AWS WAF to block requests that do not include the CloudFront distribution's domain name
C.Create an AWS Lambda@Edge function to validate headers
D.Use S3 Block Public Access to prevent all public access
AnswerA

An origin access identity (OAI) is a CloudFront user that serves as the only AWS principal allowed to read objects from your S3 bucket. After you associate the OAI with the CloudFront distribution, update the bucket policy so it grants the s3:GetObject action strictly to that OAI's principal ARN or canonical user ID. Any request that goes directly to the S3 bucket's HTTPS endpoint is then denied with AccessDenied, because the requester is not the OAI. This ensures the only way to fetch content is through CloudFront, which is exactly the intended behavior.

Why this answer

An Origin Access Identity (OAI) is a special CloudFront user that can be associated with a CloudFront distribution. By updating the S3 bucket policy to grant read access only to that OAI's canonical user ID, the bucket becomes inaccessible via direct S3 endpoints, while CloudFront can still fetch and serve the content. This enforces that all traffic must go through CloudFront.

Exam trap

The trap here is that candidates often confuse OAI with S3 Block Public Access, thinking that blocking all public access will still allow CloudFront access, but Block Public Access applies to all principals including CloudFront unless the bucket policy explicitly grants access to the OAI.

How to eliminate wrong answers

Option B is wrong because AWS WAF can inspect HTTP headers, but the CloudFront distribution's domain name is not a reliable header that can be enforced; users can spoof headers, and WAF cannot prevent direct S3 endpoint access since S3 does not integrate with WAF. Option C is wrong because a Lambda@Edge function can validate or modify headers, but it runs within CloudFront's processing, not on the S3 bucket itself; it cannot block direct S3 endpoint access. Option D is wrong because S3 Block Public Access prevents all public access to the bucket, which would also block CloudFront from accessing the bucket, breaking the intended architecture.

532
MCQmedium

A web application is deployed in us-east-1 (primary) and eu-west-1 (standby). Under normal conditions, all traffic should go to us-east-1. If the us-east-1 health check fails, traffic must automatically redirect to eu-west-1 within 30 to 60 seconds. What Route 53 configuration implements this?

A.Create failover routing records for the domain: a Primary record pointing to us-east-1 with a Route 53 health check, and a Secondary record pointing to eu-west-1 with no health check
B.Use weighted routing with 100 weight for us-east-1 and 0 weight for eu-west-1; update the weights via Lambda when a CloudWatch alarm fires
C.Enable Route 53 latency routing with records for both regions; Route 53 will automatically switch to eu-west-1 when us-east-1 becomes unavailable
D.Configure Route 53 geolocation routing to send all US traffic to us-east-1 and all European traffic to eu-west-1
AnswerA

When the health check on the Primary record fails for the configured number of consecutive intervals, Route 53 removes the Primary from DNS responses and serves the Secondary. DNS TTL on the records should be set low (60 seconds or less) to minimize client-side caching delay. The failover is automatic, with no manual intervention or Lambda functions required.

Why this answer

Route 53 failover routing records, combined with a health check on the primary record, automatically redirect traffic to the secondary (standby) record when the primary health check fails. The health check interval and failure threshold can be configured to detect failure within 30–60 seconds, meeting the requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse failover routing with latency or geolocation routing, assuming that Route 53 automatically considers health in those routing policies, but only failover routing explicitly supports active-passive failover with health checks.

How to eliminate wrong answers

Option B is wrong because weighted routing with 0 weight for eu-west-1 would never send traffic there, even if us-east-1 fails, unless the weights are updated externally; this approach cannot achieve automatic failover within 30–60 seconds without additional automation and introduces latency. Option C is wrong because latency routing selects the region with the lowest latency for each user, not based on health; if us-east-1 is unhealthy but still has low latency, traffic would continue to be sent there, failing the failover requirement. Option D is wrong because geolocation routing directs traffic based on the user's geographic location, not health; it would not redirect traffic from us-east-1 to eu-west-1 if us-east-1 fails, as users outside Europe would still be routed to the unhealthy primary region.

533
MCQeasy

A company has multiple on-premises branch offices, each with a site-to-site VPN connection to a single VPC in AWS. The SysOps administrator needs to enable communication between the branch offices using the AWS cloud as a hub. Which configuration should be implemented to achieve this with the least operational overhead?

A.Configure static routes in the VPC route table pointing to each VPN connection.
B.Use dynamic routing (BGP) on all VPN connections and enable route propagation on the virtual private gateway (VGW).
C.Create a separate Transit VPC with EC2-based VPN appliances to route traffic between branch offices.
D.Place all branch offices in the same IPsec tunnel by configuring identical pre-shared keys.
AnswerB

Configuring BGP on every Site-to-Site VPN connection and enabling route propagation on the VPC route table for the virtual private gateway (VGW) allows the VGW to automatically exchange route information between all attached VPN connections. Each branch's BGP session advertises its local CIDRs, and those routes are installed into the VPC route table via route propagation, so traffic from one branch to another is forwarded through the VGW without manual entries. This is the native AWS mechanism for a hub-and-spoke setup where the VPC is the hub and branch offices are spokes, enabling dynamic, self-updating inter-branch communication.

Why this answer

Enabling dynamic routing (BGP) on all VPN connections and propagating routes from the virtual private gateway (VGW) into the VPC route table allows each branch office to learn the CIDR blocks of all other branch offices automatically. This eliminates the need for manual static route entries and ensures that traffic between branch offices is routed through the VPC hub with minimal operational overhead, as BGP handles failover and route updates dynamically.

Exam trap

The trap here is that candidates often assume static routes are simpler and sufficient for hub-and-spoke communication, overlooking that BGP route propagation on the VGW provides automated, scalable route exchange with minimal ongoing management, which is the key to reducing operational overhead.

How to eliminate wrong answers

Option A is wrong because configuring static routes in the VPC route table pointing to each VPN connection would require manual updates whenever a branch office subnet changes or a VPN connection is added/removed, increasing operational overhead and not scaling well. Option C is wrong because creating a separate Transit VPC with EC2-based VPN appliances introduces significant complexity, cost, and maintenance overhead compared to using the native VGW with BGP route propagation. Option D is wrong because placing all branch offices in the same IPsec tunnel by configuring identical pre-shared keys is not a valid configuration; each site-to-site VPN connection must have unique tunnel settings, and this approach would cause routing conflicts and security issues, not enable inter-branch communication.

534
MCQeasy

Developers are allowed to create IAM roles for their Lambda functions. However, the security team is concerned that developers could create roles with Administrator access, granting Lambda functions more permissions than the developers themselves have. What IAM feature prevents privilege escalation in this scenario?

A.Attach a permission boundary to each developer IAM user that limits them to creating roles with only the permissions they are allowed to grant
B.Enable IAM Access Analyzer to detect when developers create overly permissive roles
C.Require MFA for all IAM API calls so developers must re-authenticate before creating roles
D.Enable CloudTrail logging for all IAM API calls and set up a CloudWatch alarm for iam:CreateRole events
AnswerA

The permission boundary on the developer prevents them from passing permissions they do not have (iam:PassRole with a role whose boundary exceeds their own). When combined with an IAM policy that requires any role they create to have the same boundary attached, privilege escalation is prevented systematically.

Why this answer

Permission boundaries are an IAM feature that allow you to set the maximum permissions that an identity-based policy can grant to a principal. By attaching a permission boundary to each developer IAM user that restricts them to creating roles with only the permissions they are allowed to grant, you prevent the developer from creating a Lambda execution role with AdministratorAccess or any other policy that exceeds the boundary. This directly addresses the privilege escalation concern because the boundary acts as a ceiling on the permissions the developer can delegate to the role.

Exam trap

The trap here is that candidates often confuse detective controls (like Access Analyzer, CloudTrail, or alarms) with preventive controls, thinking that monitoring or alerting can stop the action, when only a preventive mechanism like a permission boundary can block the creation of an overly permissive role at the time of the API call.

How to eliminate wrong answers

Option B is wrong because IAM Access Analyzer is a post-creation analysis tool that identifies resources shared with external principals; it does not prevent a developer from creating an overly permissive role in the first place. Option C is wrong because requiring MFA for IAM API calls adds an authentication step but does not restrict the permissions that can be assigned to a role; a developer with valid MFA could still create an AdministratorAccess role. Option D is wrong because CloudTrail logging and CloudWatch alarms are detective controls that only alert after the role has been created; they do not prevent the privilege escalation from occurring.

535
MCQeasy

A company wants to centrally manage access to AWS accounts for its employees. Which AWS service should be used to create and manage users and groups across multiple accounts?

A.AWS IAM
B.AWS Directory Service
C.AWS IAM Identity Center
D.AWS Organizations
AnswerC

AWS IAM Identity Center is the AWS-native service designed specifically to centralize user and group management across multiple AWS accounts and applications. It integrates with AWS Organizations so you can assign users or groups to accounts and apply permission sets that map to IAM roles, enabling single sign-on and consistent permission enforcement. With support for built-in identity stores or external identity providers, IAM Identity Center provides the exact capability needed to centrally manage access to AWS accounts.

Why this answer

AWS IAM Identity Center (successor to AWS SSO) allows you to centrally create and manage users and groups and assign them single sign-on access to multiple AWS accounts. Option C is correct. Option A (AWS IAM) is wrong because IAM is per-account and not designed for cross-account user management.

Option B (AWS Directory Service) is wrong because it provides managed Microsoft Active Directory, not multi-account user management. Option D (AWS Organizations) is wrong because it manages accounts and policies, not users and groups.

536
MCQhard

A company runs a production application on EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application uses an RDS for PostgreSQL database. The SysOps administrator has configured a read replica in a different AWS Region for disaster recovery. During a disaster, the primary region becomes unavailable. The administrator promotes the read replica to a standalone instance. After promoting, the application fails to connect to the new database because the endpoint changed. The administrator needs to minimize downtime. What should the administrator do to handle the endpoint change automatically?

A.Assign an Elastic IP address to the RDS instance.
B.Use Amazon Route 53 with a weighted alias record that points to the primary database endpoint, and configure a health check to fail over to the secondary endpoint.
C.Update the application configuration files to point to the new endpoint.
D.Use an RDS proxy and configure it to automatically failover to the promoted replica.
AnswerB

Route 53 weighted alias records can point to the RDS primary and secondary endpoints, allowing you to control traffic distribution. By associating a health check with the primary record, Route 53 automatically removes the primary from DNS resolution when the health check fails, causing traffic to be sent to the secondary endpoint. This achieves automated failover with minimal downtime, and the application continues using the same DNS name throughout.

Why this answer

By using Amazon Route 53 with a weighted alias record that points to the primary database endpoint and configuring a health check, the administrator can automate DNS failover. When the primary region becomes unavailable, the health check fails, and Route 53 automatically routes traffic to the secondary record that points to the promoted read replica's endpoint. This minimizes downtime.

Option A is wrong because Elastic IP addresses cannot be assigned to RDS instances; they are used for EC2 instances. Option C is wrong because manually updating application configuration files would increase downtime and is not automatic. Option D is wrong because an RDS proxy does not automatically update the endpoint after a disaster recovery promotion; it still requires the endpoint to be changed in the application configuration.

537
MCQmedium

An organization uses Amazon CloudFront to serve static content from an S3 bucket. The content is updated frequently, but users are seeing stale files. What is the most efficient way to invalidate the cache for updated objects?

A.Create a CloudFront invalidation for the updated files.
B.Use the S3 console to set a new cache-control header.
C.Change the origin path in the CloudFront distribution.
D.Delete and recreate the CloudFront distribution.
AnswerA

CloudFront invalidation is the designed mechanism to force edge locations to discard the cached copies of specified files immediately. When you submit an invalidation for the updated objects, CloudFront stops serving the stale versions and fetches the current ones from the S3 origin on the next request. This is a targeted, low-overhead operation that does not disrupt the distribution or require any configuration changes, making it the correct approach.

Why this answer

CloudFront caches objects at edge locations based on the cache key (path, headers, query strings). When origin content changes, the edge cache still serves the old object until TTL expires. Creating an invalidation explicitly purges the specified paths from all edge locations, forcing CloudFront to fetch fresh content from the S3 origin on the next request.

This is the fastest, most targeted way to serve updated files without waiting for TTL expiry.

Exam trap

SOA-C02 often tests the misconception that changing cache headers or S3 metadata retroactively purges already-cached objects — candidates must remember that only an explicit invalidation (or a new cache key) removes content already stored at edge locations.

How to eliminate wrong answers

Option B is wrong because setting a new Cache-Control header on the S3 object only affects future cache decisions after the object is re-fetched — it does not purge objects already cached at edge locations, so users still see stale content until TTL expires. Option C is wrong because changing the origin path alters where CloudFront fetches content from, which would break the distribution's mapping to the S3 bucket rather than invalidate cached objects. Option D is wrong because deleting and recreating the distribution is disruptive, changes the distribution's domain name, requires DNS updates, and takes significant time to redeploy — far less efficient than a simple invalidation.

538
MCQmedium

A SysOps administrator needs to monitor application logs stored in Amazon CloudWatch Logs for the term 'CRITICAL'. When more than 5 'CRITICAL' entries appear in a 5-minute window, the administrator wants to automatically restart the underlying Amazon EC2 instance. Which solution should the administrator implement?

A.Create a CloudWatch Logs metric filter, then a CloudWatch alarm that triggers an AWS Systems Manager Automation document to restart the instance.
B.Create a CloudWatch Logs metric filter, then a CloudWatch alarm that triggers an EC2 Reboot Instances action.
C.Create a CloudWatch Logs metric filter, then use Amazon CloudWatch Events (Amazon EventBridge) to trigger an AWS Lambda function that restarts the instance.
D.Use Amazon CloudWatch Synthetics canary to monitor the logs and automatically stop the instance.
AnswerB

A CloudWatch Logs metric filter parses each log event and publishes a custom metric whenever a 'CRITICAL' pattern is matched. A CloudWatch alarm then evaluates that metric over a specified period and, when it enters the ALARM state, can directly trigger the built-in 'Reboot Instances' EC2 action. This is the most direct and reliable solution because it uses a native CloudWatch alarm action to restart the instance, requiring no custom code, Lambda functions, or extra orchestration layers.

Why this answer

CloudWatch Logs metric filters can count occurrences of the term 'CRITICAL' in log data, and a CloudWatch alarm can be configured to trigger an EC2 Reboot Instances action directly when the metric exceeds a threshold of 5 in a 5-minute period. This provides a native, simple, and fully managed solution without requiring additional services like Lambda or Systems Manager.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Lambda or Systems Manager, not realizing that CloudWatch alarms have a built-in EC2 action for reboot, stop, terminate, or recover, which is the simplest and most cost-effective method for this use case.

How to eliminate wrong answers

Option A is wrong because while a CloudWatch alarm can trigger an AWS Systems Automation document, the EC2 Reboot Instances action is a direct alarm target and does not require Systems Manager Automation, which adds unnecessary complexity and potential latency. Option C is wrong because using CloudWatch Events (EventBridge) to invoke a Lambda function to restart the instance is an over-engineered approach; the EC2 Reboot Instances action is a built-in alarm target that eliminates the need for custom code. Option D is wrong because CloudWatch Synthetics canaries are designed for synthetic monitoring of endpoints and web applications, not for analyzing existing CloudWatch Logs for specific terms like 'CRITICAL'.

539
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM users in any member account can create access keys for themselves. What is the MOST efficient way to enforce this policy across all accounts?

A.Create an SCP that denies the iam:CreateAccessKey action and attach it to the root organizational unit.
B.Apply an IAM policy to the master account's root user that denies access key creation.
C.Enable AWS Trusted Advisor security checks and follow the recommendations.
D.Use AWS Config to detect access key creation and automatically delete the keys using a Lambda function.
AnswerA

An SCP is an organization-level policy that applies to all accounts (including the management account, though it can be excluded) when attached to the root OU. Denying iam:CreateAccessKey at the root OU is a preventive control that blocks the action organization-wide before it can be executed. This is the correct approach because it enforces the restriction in a centralized, scalable way that cannot be overridden by individual account IAM policies.

Why this answer

A service control policy (SCP) can be applied at the root or to specific OUs to deny IAM actions across all member accounts. Option A is correct because it centrally restricts the action. Option B is wrong because it only works for the master account.

Option C is wrong because it requires individual account configuration. Option D is wrong because while AWS Config and Lambda can detect and remediate access key creation, this is a reactive approach and not the most efficient preventive control. SCPs proactively deny the action before it occurs, making them more efficient for enforcing this policy across all accounts.

540
MCQmedium

An organization has a VPC peering connection between VPC A and VPC B. Instances in VPC A can reach instances in VPC B, but not vice versa. What is the most likely cause?

A.The route table in VPC B does not have a route to VPC A's CIDR.
B.DNS resolution is not enabled for the VPC peering connection.
C.Security groups in VPC B block inbound traffic from VPC A.
D.The VPC peering connection is in a 'pending-acceptance' state.
AnswerA

For a VPC peering connection to work, both VPCs must have explicit routes in their route tables that send traffic destined for the peer's CIDR to the peering connection ID. If VPC B's route table lacks such a route to VPC A's CIDR, any return traffic from VPC B to VPC A is dropped because there is no valid next hop, even though VPC A may have a route that permits outbound traffic. This is the classic cause of one-way connectivity failures after a peering connection is accepted.

Why this answer

For a VPC peering connection to allow bidirectional traffic, both VPCs must have routes in their route tables pointing to the other VPC's CIDR block. Since instances in VPC A can reach VPC B but not vice versa, the most likely cause is that VPC B's route table lacks a route to VPC A's CIDR. Without this route, VPC B's subnet does not know how to forward return traffic to VPC A, even though the peering connection itself is active.

Exam trap

The trap here is that candidates often assume a VPC peering connection automatically enables bidirectional traffic once accepted, overlooking the requirement to manually add routes in both VPCs' route tables.

How to eliminate wrong answers

Option B is wrong because DNS resolution (enabling 'DNS resolution' or 'DNS hostnames' for the peering connection) affects whether instances can resolve private DNS names across VPCs, but it does not control basic IP-level reachability; the issue here is unidirectional connectivity, not DNS resolution. Option C is wrong because security groups in VPC B blocking inbound traffic from VPC A would prevent all traffic from VPC A to VPC B, but the question states that instances in VPC A can reach VPC B, so security groups are not the cause of the reverse failure. Option D is wrong because if the VPC peering connection were in a 'pending-acceptance' state, no traffic would flow in either direction; the fact that VPC A can reach VPC B confirms the connection is active and accepted.

541
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB) in a VPC. Users report slow load times. The SysOps team notices that all traffic goes to a single availability zone. Which action should be taken to improve performance and reliability?

A.Configure the ALB to use subnets in at least two Availability Zones
B.Add more EC2 instances in the same Availability Zone
C.Replace the ALB with a Network Load Balancer (NLB)
D.Enable cross-zone load balancing on the ALB
AnswerA

To provide high availability, the Application Load Balancer (ALB) must be enabled in multiple Availability Zones by associating it with at least one subnet in each AZ. The ALB service creates a load balancer node in each enabled AZ, allowing it to route traffic to targets in those AZs and to continue serving requests if one AZ fails. Without multi-AZ subnet configuration, the ALB and its single node become a single point of failure, negating the resilience of having multiple EC2 instances across AZs. This is the foundational action required to meet fault-tolerance requirements.

Why this answer

The correct action is to configure the ALB to use subnets in at least two Availability Zones. An ALB is a regional service that requires subnets in multiple AZs to distribute incoming traffic across healthy targets in those zones. When all traffic goes to a single AZ, it indicates the ALB is only attached to one subnet, creating a single point of failure and limiting the pool of EC2 instances that can serve traffic, which directly causes slow load times and reduced reliability.

Exam trap

The trap here is that candidates often confuse cross-zone load balancing (which distributes traffic across instances within an AZ) with multi-AZ subnet configuration (which enables the ALB to route traffic to instances in different AZs), leading them to incorrectly select option D.

How to eliminate wrong answers

Option B is wrong because adding more EC2 instances in the same Availability Zone does not address the root cause—the ALB is only routing traffic to one AZ, so all new instances would still be in that same AZ, failing to distribute load or improve fault tolerance. Option C is wrong because replacing the ALB with a Network Load Balancer (NLB) does not solve the single-AZ issue; an NLB also requires subnets in multiple AZs for high availability, and the problem is about AZ configuration, not load balancer type. Option D is wrong because cross-zone load balancing on an ALB is enabled by default and controls distribution of traffic across instances within the same AZ, not across AZs; it does not fix the issue of the ALB only having subnets in one AZ.

542
MCQmedium

Refer to the exhibit. The command returns no events for RunInstances during the specified time period. The administrator knows that instances were launched during that time. What is the most likely cause?

A.CloudTrail logs are being delivered to an S3 bucket, not to CloudWatch Logs.
B.The command is run in the wrong AWS Region.
C.CloudTrail is not configured to log management events.
D.The IAM user does not have permission to view CloudTrail events.
AnswerC

CloudTrail's lookup-events API returns events from the event history that have been captured by an active trail with management-event logging enabled. RunInstances is a management event (EC2 instance creation), so if the trail is configured to log only data events (e.g., S3 object-level operations) or if management-event logging is disabled, the event history will not contain this API call. Consequently, the lookup command executes successfully but returns zero matches for RunInstances.

Why this answer

CloudTrail can be configured to log either management events, data events, or both. If only data events are logged, management events such as RunInstances will not appear in the CloudTrail event history. The command `aws cloudtrail lookup-events` queries the CloudTrail event history, which only contains events that CloudTrail is configured to record.

Since the administrator knows instances were launched but no events are returned, the most likely cause is that CloudTrail is not configured to log management events.

Exam trap

The trap here is that candidates assume CloudTrail always logs all API calls by default, but they overlook that CloudTrail can be configured to exclude management events, and the `lookup-events` command only returns events that CloudTrail is actually recording.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs are delivered to an S3 bucket for long-term storage, but the `lookup-events` command queries the CloudTrail event history, which is a separate, queryable view of the last 90 days of events regardless of whether they are also delivered to S3 or CloudWatch Logs. Option B is wrong because if the command were run in the wrong AWS Region, it would return events from that region, but the administrator knows instances were launched in the region where the command is run; the issue is that no events are returned at all, not that events from a different region appear. Option D is wrong because the IAM user needs permission to call `cloudtrail:LookupEvents`, but if the user lacked that permission, the command would return an access denied error, not an empty result set.

543
MCQmedium

A company stores critical data in an Amazon S3 bucket in the us-west-2 Region. The SysOps administrator needs to ensure that all objects are automatically replicated to another AWS Region for disaster recovery. The Recovery Point Objective (RPO) must be less than 15 minutes, and existing objects must also be replicated. Which S3 feature should the administrator use?

A.S3 Cross-Region Replication (CRR) with Replication Time Control (RTC)
B.S3 Same-Region Replication (SRR)
C.S3 Event Notifications with an AWS Lambda function to copy objects to another region
D.S3 Transfer Acceleration
AnswerA

S3 Cross-Region Replication (CRR) with Replication Time Control (RTC) is the correct choice because CRR asynchronously copies objects from the source bucket in the US to a destination bucket in another AWS Region, satisfying the geographic disaster recovery requirement. RTC adds a guaranteed 15-minute replication SLA for 99.99% of objects, meeting the stated RPO. Additionally, CRR can be configured to replicate existing objects using S3 Batch Replication, while RTC provides monitoring via CloudWatch metrics and events, ensuring timely, trackable replication.

Why this answer

S3 Cross-Region Replication (CRR) with Replication Time Control (RTC) is the correct choice because it provides automatic, asynchronous replication of objects to a different AWS Region, meeting the RPO of less than 15 minutes by guaranteeing replication within 15 minutes for most objects (99.99% of objects are replicated within 15 minutes). Additionally, CRR can replicate existing objects when configured with the appropriate replication rule and batch operations, satisfying the requirement to replicate all objects.

Exam trap

The trap here is that candidates may choose S3 Event Notifications with Lambda (Option C) because it seems like a flexible custom solution, but they overlook the lack of a guaranteed RPO, the inability to replicate existing objects without additional effort, and the operational overhead compared to the managed, SLA-backed CRR with RTC.

How to eliminate wrong answers

Option B (S3 Same-Region Replication) is wrong because it replicates objects within the same AWS Region, not across regions, so it does not meet the disaster recovery requirement for cross-region replication. Option C (S3 Event Notifications with Lambda) is wrong because it is a custom, event-driven approach that introduces latency, complexity, and potential failure points, and it cannot guarantee the 15-minute RPO or reliably replicate existing objects without additional scripting. Option D (S3 Transfer Acceleration) is wrong because it is designed to speed up uploads over long distances using edge locations, not to replicate objects between buckets or regions.

544
MCQeasy

A SysOps administrator needs to audit all API calls made in the AWS account, including actions performed by the root user. Which service should be enabled?

A.AWS Config
B.VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the definitive service for auditing API activity because it records a detailed history of every public AWS API call made on the account, including the identity of the caller, the API operation, parameters, source IP, and event time. It captures management events from all regions and by default retains the last 90 days in the event history, while a trail can deliver logs to S3 for long-term storage, enabling governance, security analysis, and tracking of root user actions. It is the correct service when you need to answer 'who did what, when, and how' across the entire AWS control plane.

Why this answer

AWS CloudTrail records all API calls made in an AWS account, including those made by the root user, IAM users, roles, and AWS services. It provides a detailed audit trail of actions taken, which is essential for security and compliance auditing. Enabling CloudTrail in all regions ensures comprehensive coverage.

Exam trap

SOA-C02 often tests the difference between CloudTrail (API auditing) and AWS Config (resource configuration history); candidates may confuse the two, especially when the question mentions 'audit' and 'API calls'.

How to eliminate wrong answers

Option A is wrong because AWS Config evaluates resource configurations against desired policies but does not record API calls or user actions. Option B is wrong because VPC Flow Logs capture IP traffic metadata for network interfaces, not API calls. Option D is wrong because Amazon CloudWatch Logs is a log storage and analysis service; it does not natively capture API activity unless CloudTrail logs are specifically sent to it.

545
MCQmedium

A SysOps administrator is asked to ensure that all objects in an S3 bucket are encrypted at rest using a customer-managed KMS key. The bucket currently has default encryption set to SSE-S3. What must be done to meet the requirement?

A.Update the bucket's default encryption to SSE-KMS using the customer-managed key, and re-upload existing objects.
B.Add a bucket policy that denies s3:PutObject without the x-amz-server-side-encryption header.
C.Apply a service control policy to enforce SSE-KMS across the organization.
D.Enable S3 Versioning and set the bucket's default encryption to SSE-KMS.
AnswerA

Default encryption is applied only when an object is first written to Amazon S3; changing the bucket's default from SSE-S3 or none to SSE-KMS with a customer-managed key does not retroactively alter objects that are already stored. To satisfy the requirement, the administrator must update the default encryption configuration and then copy each existing object back over itself (or re-upload it) using an operation that explicitly applies SSE-KMS, because the bucket's default will not touch the old objects. Only this combination ensures both current and future objects meet the SSE-KMS policy.

Why this answer

Default encryption on an S3 bucket only applies to newly uploaded objects; existing objects remain encrypted with the previous method (SSE-S3). To ensure all objects are encrypted at rest with a customer-managed KMS key, you must update the bucket's default encryption to SSE-KMS with the desired key and then re-upload (or copy) existing objects so they inherit the new encryption setting. Simply changing the default encryption does not retroactively re-encrypt objects already stored.

Exam trap

The trap here is that candidates assume changing the bucket's default encryption automatically re-encrypts all existing objects, but AWS S3 default encryption only applies to new uploads, not to objects already in the bucket.

How to eliminate wrong answers

Option B is wrong because adding a bucket policy that denies s3:PutObject without the x-amz-server-side-encryption header only enforces encryption on new uploads but does not address existing objects already encrypted with SSE-S3, nor does it require the use of a customer-managed KMS key. Option C is wrong because a service control policy (SCP) is an AWS Organizations feature that applies to all accounts in an organization, but it cannot retroactively re-encrypt existing objects in a specific bucket; it only governs future API calls. Option D is wrong because enabling S3 Versioning does not change the encryption of existing objects; it only creates new versions of objects on subsequent writes, and setting default encryption to SSE-KMS still only applies to new uploads, leaving the original versions encrypted with SSE-S3.

546
MCQeasy

A SysOps administrator notices that an EC2 instance's CPU utilization has been above 90% for the past hour. The instance is part of an Auto Scaling group with a CPU utilization-based scaling policy. However, no new instances have been launched. What is the most likely cause?

A.The Auto Scaling cooldown period is preventing additional scaling activities.
B.The EC2 instance is in a private subnet and cannot communicate with the Auto Scaling service.
C.The CloudWatch alarm is publishing to an S3 bucket that is full.
D.The scaling policy is based on memory utilization, not CPU.
AnswerA

The Auto Scaling cooldown period is a configurable duration that begins after the most recent scaling activity completes. During this cooldown, the Auto Scaling group intentionally ignores new CloudWatch alarm triggers to prevent flapping, so even sustained high CPU will not launch additional instances until the cooldown expires. This is a common and often overlooked reason why a CPU-based alarm appears to have no effect.

Why this answer

The most likely cause is that the Auto Scaling cooldown period is preventing additional scaling activities. When a scaling activity completes, a cooldown period (default 300 seconds) starts during which the Auto Scaling group ignores additional CloudWatch alarms to allow metrics to stabilize. If the instance has been above 90% CPU for an hour but no new instances launched, the cooldown period may have been triggered by a previous scaling event and is still active, blocking further scale-out actions despite sustained high utilization.

Exam trap

The trap here is that candidates often assume high CPU utilization always triggers immediate scaling, overlooking the cooldown period that can delay or block subsequent scaling activities even when alarms are in ALARM state.

How to eliminate wrong answers

Option B is wrong because EC2 instances in a private subnet can still communicate with the Auto Scaling service via a VPC endpoint or NAT gateway; the instance's subnet type does not prevent the Auto Scaling group from launching new instances. Option C is wrong because CloudWatch alarms publish to SNS topics, not S3 buckets; an S3 bucket being full has no impact on alarm delivery or scaling policy execution. Option D is wrong because the question explicitly states the scaling policy is CPU utilization-based, so a memory-based policy would not trigger on CPU metrics, but the policy is correctly configured for CPU.

547
MCQeasy

A company uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances. The security team wants to ensure that all traffic between the ALB and the instances is encrypted. Which configuration step is required?

A.Configure the ALB listener to use HTTPS with a security policy.
B.Configure the target group to use HTTPS protocol and install SSL/TLS certificates on the instances.
C.Place the instances in a private subnet and use a NAT gateway for outbound traffic.
D.Create a security group rule that allows only HTTPS traffic from the ALB to the instances.
AnswerB

The ALB-to-instance hop is encrypted only when the target group's protocol is HTTPS and the instances present valid certificates. Setting the target group to HTTPS satisfies the requirement, since the listener's own TLS termination covers only the client-to-ALB leg.

Why this answer

Configuring the target group to use the HTTPS protocol ensures that the ALB encrypts traffic to the instances using SSL/TLS. The instances must have valid certificates installed to terminate the HTTPS connection. Option A is incorrect because the ALB listener handles encryption between clients and the ALB, not between the ALB and instances.

Option C is incorrect because placing instances in a private subnet and using a NAT gateway affects outbound internet access, not encryption between the ALB and instances. Option D is incorrect because a security group rule can allow only HTTPS traffic, but it does not enforce encryption; the traffic protocol must also be HTTPS.

548
MCQhard

A SysOps administrator is investigating a failed CloudFormation stack creation. The describe-stack-events output shows that the stack creation failed with the reason 'Resource creation cancelled'. What is the most likely cause of this failure?

A.The stack template contains an invalid parameter value.
B.The IAM role used by CloudFormation does not have sufficient permissions to create the resources.
C.A WaitCondition resource did not receive the required signal within the specified timeout period.
D.A nested stack within the parent stack failed to create.
AnswerC

In the CloudFormation event history, a 'Resource creation cancelled' status for a stack resource is the result of a WaitCondition or WaitConditionHandle timing out. For a WaitCondition resource, CloudFormation pauses the stack creation until it receives a success signal (typically sent by cfn-signal) from the launched resources. If that signal is not delivered within the specified Timeout period, the resource is marked as cancelled and the entire stack creation is stopped and rolled back. This failure mode is distinct from error-driven rollbacks because the resource itself never finished creating — it was simply waiting on an external signal that never arrived.

Why this answer

The WaitCondition timed out before receiving the required signal, causing CloudFormation to cancel the stack creation. Option A is incorrect because a parameter validation error would appear as a different reason. Option B is incorrect because there is no indication of missing IAM permissions.

Option D is incorrect because the stack creation was cancelled due to the wait condition timeout, not a nested stack failure.

549
MCQhard

A SysOps administrator is investigating a security incident where an unauthorized key pair was created. The CloudTrail lookup command output is shown. The administrator wants to find the source IP address of the 'admin' user who created the key pair. Which field in the 'CloudTrailEvent' JSON should the administrator examine?

A.requestParameters
B.userIdentity
C.sourceIPAddress
D.eventTime
AnswerC

The sourceIPAddress field in an AWS CloudTrail event is the authoritative record of the IP address from which the request was made, whether over the internet or from within a VPC via a VPC endpoint. This field is the primary evidence for tracing the original network source of suspicious API calls, and it is the correct answer for the security incident in question. It may contain a public IPv4/IPv6 address or, in some scenarios, the private IP of a proxy, so it must be interpreted carefully.

Why this answer

The source IP address of the API call is recorded in the 'sourceIPAddress' field within the CloudTrail event JSON. Therefore, option C is correct. Option A (requestParameters) contains the parameters of the request, not the IP.

Option B (userIdentity) contains information about the user identity, not the IP. Option D (eventTime) is the timestamp.

550
MCQeasy

A SysOps administrator wants to deploy a new version of an application to an existing Auto Scaling group of Amazon EC2 instances. The deployment must minimize disruption by launching new instances, performing health checks, and shifting traffic to the new instances before terminating the old ones. Which AWS CodeDeploy deployment configuration should the administrator choose?

A.Blue/green
B.Rolling
C.AllAtOnce
D.Canary
AnswerA

Blue/green in CodeDeploy for EC2 Auto Scaling groups provisions a separate, temporary 'green' replacement fleet alongside the original 'blue' fleet. After the green instances pass the configured health checks and tests, the load balancer or target group shifts production traffic from blue to green, enabling an immediate, nearly zero-downtime release. Because the blue fleet remains untouched until deployment completion, rollback is trivial: just flip traffic back and terminate green. This is the only option that both eliminates downtime and provides a built-in instant rollback path.

Why this answer

The blue/green deployment configuration in AWS CodeDeploy is designed to minimize disruption by provisioning a new set of instances (green environment), performing health checks against them, and then shifting traffic from the old instances (blue environment) to the new ones before terminating the old instances. This matches the requirement of launching new instances, health-checking, and shifting traffic before termination, which is not possible with in-place deployment types like rolling or all-at-once.

Exam trap

The trap here is that candidates often confuse 'rolling' with 'blue/green' because both involve gradual updates, but rolling updates modify the existing Auto Scaling group in-place without creating a separate environment or shifting traffic before termination.

How to eliminate wrong answers

Option B (Rolling) is wrong because it performs an in-place update by gradually replacing instances within the existing Auto Scaling group without creating a separate environment, so traffic is not shifted before termination and health checks occur on the same instances. Option C (AllAtOnce) is wrong because it deploys to all instances simultaneously in-place, causing full downtime or disruption during the update. Option D (Canary) is wrong because it is a traffic-shifting pattern used in AWS CodeDeploy for Lambda or ECS deployments, not for EC2 Auto Scaling groups, and it does not launch new instances in a separate environment.

551
Multi-Selectmedium

A company is running a production web application on EC2 instances behind an Application Load Balancer. The company wants to optimize costs without sacrificing performance. Which TWO actions should the SysOps administrator take?

Select 2 answers
A.Purchase Reserved Instances for the baseline capacity.
B.Use Dedicated Hosts for all instances to control placement.
C.Implement Auto Scaling to match capacity with demand.
D.Enable T2/T3 unlimited to handle spikes without throttling.
E.Use multiple instance types in each Availability Zone.
AnswersA, C

Reserved Instances provide a significant hourly cost reduction over On-Demand pricing in exchange for a one- or three-year commitment, directly addressing the stem’s requirement to optimise costs. By purchasing Reserved Instances for the baseline capacity—the minimum number of instances always running—the company locks in lower rates for that steady-state workload while retaining On-Demand or Spot instances to handle any variable traffic spikes, thus preserving performance.

Why this answer

(Reserved Instances) provides a significant discount for steady-state workloads, and Option C (Auto Scaling) ensures capacity matches demand, preventing over-provisioning. Option B (Dedicated Hosts) is more expensive and unnecessary. Option D (T3 unlimited) could cause unexpected costs if credits exhausted.

Option E (Multiple instance types per AZ) is not a cost optimization.

552
MCQeasy

A company needs to resolve DNS names for on-premises servers from AWS. They have set up a DHCP options set with the on-premises DNS server IP. Which additional step is required?

A.Create a VPC peering connection and use the on-premises DNS IP as the DHCP option set.
B.Configure Route 53 Resolver outbound endpoint to forward queries to on-premises DNS.
C.Create a VPC peering connection to the on-premises network.
D.Configure Route 53 Resolver inbound endpoint to forward DNS queries from on-premises to AWS.
AnswerB

A Route 53 Resolver outbound endpoint is the correct answer because it allows DNS queries initiated from within the VPC to be forwarded to an on-premises DNS server via a forwarding rule. The endpoint consists of elastic network interfaces (ENIs) in your subnets that receive queries from instances, evaluate the forwarding rules (e.g., by domain name), and forward matching queries over your VPN or Direct Connect to the on-premises resolver. This enables AWS resources to resolve hostnames for on-premises servers, fulfilling the requirement directly.

Why this answer

The DHCP options set configures VPC resources to use the on-premises DNS server IP. However, to actually forward DNS queries from the VPC to the on-premises DNS server for resolution of on-premises hostnames, you need a Route 53 Resolver outbound endpoint. This endpoint provides a forwarding path from the VPC to the on-premises network (over VPN or Direct Connect).

Option D (inbound endpoint) is used for the reverse direction—allowing on-premises DNS to forward queries to AWS for resolving private hosted zones—and is not required here. Options A and C are incorrect because VPC peering does not enable DNS resolution to on-premises networks; dedicated connectivity and DNS forwarding via Route 53 Resolver are needed.

Exam trap

The trap is confusing the direction of DNS forwarding. Candidates often select the inbound endpoint (Option D) thinking it forwards queries from AWS to on-premises, but in reality, the inbound endpoint handles queries coming from on-premises into AWS. The correct direction for AWS-to-on-premises forwarding is the outbound endpoint (Option B).

How to eliminate wrong answers

Option A is wrong because a VPC peering connection does not inherently forward DNS queries; it only enables network connectivity between VPCs, and using the on-premises DNS IP as a DHCP option set is already done. Option B is wrong because a Route 53 Resolver outbound endpoint forwards queries from AWS to on-premises, which is the opposite direction needed; the requirement is to resolve on-premises DNS names from AWS, not the other way. Option C is wrong because a VPC peering connection cannot be established to an on-premises network; VPC peering is only between VPCs, not between a VPC and an on-premises data center.

553
MCQeasy

A production RDS MySQL database stores financial records. The team needs the ability to restore the database to any point within the last 7 days in case of accidental data deletion. Automated backups are currently disabled. What must be configured?

A.Enable automated backups and set the backup retention period to 7 days
B.Create a manual DB snapshot every night using the AWS CLI on a schedule
C.Enable Multi-AZ to maintain a synchronous standby replica in a second Availability Zone
D.Enable RDS read replicas and promote one if data deletion occurs
AnswerA

Automated backups with a 7-day retention period keep daily snapshots and transaction logs for 7 days. Any point within the retention window is recoverable. Transaction logs allow recovery to any 5-minute interval within that window. Setting the period to 0 disables automated backups and PITR entirely.

Why this answer

To restore an RDS MySQL database to any point within the last 7 days, you must enable automated backups and set the backup retention period to 7 days. Automated backups enable point-in-time recovery (PITR), which allows restoration to any second within the retention window using binary logs. Without automated backups, RDS cannot perform PITR, even if manual snapshots exist.

Exam trap

The trap here is that candidates often confuse manual snapshots with automated backups, not realizing that only automated backups enable point-in-time recovery, while manual snapshots are static and cannot be used for granular restoration.

How to eliminate wrong answers

Option B is wrong because manual DB snapshots capture only a single point in time and do not provide the continuous binary log data needed for point-in-time recovery to any arbitrary moment within 7 days. Option C is wrong because Multi-AZ provides high availability and automatic failover, but it does not create backups or enable point-in-time recovery; it only maintains a synchronous standby replica. Option D is wrong because RDS read replicas are designed for read scaling and, while they can be promoted to a standalone instance, they do not provide point-in-time recovery capabilities and rely on the same backup configuration as the source instance.

554
MCQeasy

A SysOps administrator needs to ensure that data in an S3 bucket is encrypted at rest. The bucket already has server-side encryption with S3 managed keys (SSE-S3) enabled. Which additional step is required to enforce encryption for all objects?

A.Add a bucket policy that denies PutObject without encryption.
B.Enable CloudTrail to log unencrypted uploads.
C.Enable default encryption on the bucket.
D.Enable versioning on the bucket.
AnswerA

This enforces encryption at upload time by explicitly rejecting any PutObject request that does not include server-side encryption headers (e.g., x-amz-server-side-encryption: AES256 or aws:kms). This is a preventive control that blocks unencrypted writes outright, unlike default encryption which merely applies encryption if the request lacks headers but can be overridden by explicit headers. The policy should include a condition like "Null": {"s3:x-amz-server-side-encryption": "true"} to deny requests without the encryption header.

Why this answer

A bucket policy can deny PutObject requests that do not include the x-amz-server-side-encryption header, thereby enforcing encryption for all uploads. Option B is incorrect because CloudTrail logs API calls but does not enforce encryption. Option C is incorrect because enabling default encryption on the bucket only encrypts objects that are uploaded without specifying encryption, but it does not prevent unencrypted uploads; a bucket policy is needed to enforce encryption.

Option D is incorrect because versioning allows multiple versions of objects but does not enforce encryption.

555
Multi-Selecthard

A company has a VPC with public and private subnets in two Availability Zones. The private subnets need outbound internet access for EC2 instances to download updates. Which THREE components are required to achieve this? (Choose three.)

Select 3 answers
A.Route table in the private subnets with a default route pointing to the NAT Gateway
B.Internet Gateway attached to the VPC
C.Egress-only Internet Gateway
D.NAT Gateway in a public subnet
E.AWS Site-to-Site VPN connection
AnswersA, B, D

The route table associated with the private subnets must contain a default route (0.0.0.0/0) pointing to the NAT Gateway's network interface. This ensures that any outbound IPv4 traffic from instances in those subnets is forwarded to the NAT Gateway for translation. Without this route, private instances would have no path to the internet, even though the NAT Gateway exists.

Why this answer

A route table associated with private subnets must have a default route (0.0.0.0/0) pointing to a NAT Gateway to direct outbound internet traffic from EC2 instances through the NAT device. This allows instances in private subnets to initiate outbound connections to the internet (e.g., for software updates) while preventing unsolicited inbound connections from the internet.

Exam trap

The trap here is that candidates often confuse the Egress-Only Internet Gateway (IPv6 only) with the NAT Gateway (IPv4) or think a VPN connection can provide internet access, when in fact a NAT Gateway in a public subnet plus an Internet Gateway are required for IPv4 outbound connectivity from private subnets.

556
Multi-Selectmedium

A SysOps administrator is deploying a critical application using AWS CloudFormation. The stack must be updated frequently. Which TWO strategies should the administrator use to minimize the risk of update failures? (Choose TWO.)

Select 2 answers
A.Use change sets to review the impact of changes before applying them.
B.Disable rollback on failure to avoid stack deletion.
C.Always use the AWS CLI to perform updates instead of the console.
D.Manually approve each resource update through the console.
E.Use a stack policy to protect critical resources from accidental updates.
AnswersA, E

Change sets in AWS CloudFormation provide a summary of proposed changes to resources, including creations, modifications, and deletions, and flag any replacements. By reviewing a change set before executing it, you can detect unintended resource replacements (e.g., an RDS instance being replaced due to an immutable parameter) and abort the update if needed, thereby minimizing risk of change-related downtime or data loss.

Why this answer

Option A is correct because CloudFormation change sets generate a preview of the proposed changes, showing which resources will be added, modified, or replaced, so the administrator can detect unintended replacements or deletions before executing the update and thereby reduce the risk of a failed or destructive stack update. Option E is correct because a stack policy is a JSON document that explicitly denies Update:Modify or Update:Replace actions on specified critical resources, preventing accidental updates to those resources during stack updates and thus lowering the chance of update failures or outages. Option B is not appropriate because disabling rollback on failure does not prevent update failures; it only leaves the stack in UPDATE_FAILED or UPDATE_ROLLBACK_FAILED state, which can complicate recovery rather than minimize risk.

Option C is incorrect because the AWS CLI and the console both invoke the same CloudFormation UpdateStack API, so the interface used has no bearing on update risk. Option D is incorrect because CloudFormation does not provide a per-resource manual approval mechanism during stack updates; change sets are the supported review mechanism.

Exam trap

The trap is assuming that disabling rollback or using the CLI improves safety — candidates confuse 'avoiding stack deletion' with 'reducing update risk,' but rollback is a safety net, not a hazard.

557
MCQmedium

A company runs a production Amazon RDS for MySQL DB instance in a single Availability Zone. The SysOps administrator needs to improve database availability to ensure automatic failover if the primary instance fails. Which configuration should the administrator enable?

A.Create a Read Replica in another Availability Zone and promote it on failure.
B.Enable Multi-AZ deployment on the DB instance.
C.Take hourly snapshots and automate restoration in another AZ.
D.Use Amazon RDS Proxy to manage connection failover.
AnswerB

Enabling Multi-AZ deployment creates a synchronous standby replica in a different Availability Zone with automatic failover, ensuring that if the primary instance fails, Amazon RDS automatically switches to the standby with minimal downtime. The synchronous replication means the standby is always up to date with the primary, so there is no data loss. This configuration provides high availability with a single database endpoint, so applications can maintain connectivity during failover.

Why this answer

Enabling Multi-AZ deployment on the DB instance automatically provisions and maintains a synchronous standby replica in a different Availability Zone. If the primary instance fails, Amazon RDS automatically fails over to the standby, providing high availability without manual intervention. This is the native AWS solution for automatic failover for RDS MySQL.

Exam trap

The trap here is that candidates often confuse Read Replicas (asynchronous, for read scaling) with Multi-AZ (synchronous, for high availability), assuming promoting a Read Replica provides the same automatic failover guarantee.

How to eliminate wrong answers

Option A is wrong because creating a Read Replica and promoting it on failure is a manual process that introduces downtime and does not provide automatic failover; Read Replicas are designed for read scaling, not synchronous high availability. Option C is wrong because taking hourly snapshots and automating restoration in another AZ would result in significant data loss (up to one hour) and long recovery times, not automatic failover. Option D is wrong because Amazon RDS Proxy manages database connections and connection pooling, but it does not provide automatic failover of the database instance itself; it can work with Multi-AZ but is not a substitute for it.

558
Multi-Selecthard

A SysOps administrator is designing a solution to manage secrets (e.g., database credentials) for a multi-tier application running on EC2 instances. The solution must rotate secrets automatically and provide fine-grained access control. Which TWO services should be used together? (Choose TWO.)

Select 2 answers
A.AWS KMS
B.AWS CloudHSM
C.AWS Secrets Manager
D.AWS Systems Manager Parameter Store
E.IAM roles for EC2
AnswersC, E

AWS Secrets Manager is purpose-built for securely storing and automatically rotating database credentials, API keys, and other secrets. It supports built-in rotation for Amazon RDS and Redshift, and custom rotation via AWS Lambda for other services. Secrets can be retrieved on demand through the AWS SDK or CLI, with IAM policies controlling access, and versioning ensures application rollback and staged rotation.

Why this answer

AWS Secrets Manager (C) is correct because it is the service purpose-built for storing and automatically rotating secrets such as database credentials, using built-in rotation via Lambda functions and native integration with services like RDS, Redshift, and DocumentDB. IAM roles for EC2 (E) is correct because attaching an IAM role to the EC2 instances provides temporary credentials through the instance metadata service (IMDS), enabling fine-grained, least-privilege access control via IAM policies that scope which secrets each instance can retrieve, eliminating hard-coded credentials. AWS KMS (A) is not selected because it is an encryption key management service used to encrypt data and secrets, but it does not itself store or rotate secrets.

AWS CloudHSM (B) is not selected because it provides dedicated hardware security modules for key operations and compliance use cases, not secret lifecycle management or rotation. AWS Systems Manager Parameter Store (D) is not selected because, although it can store parameters and SecureString values, it lacks native automatic secret rotation, which the scenario explicitly requires.

Exam trap

SOA-C02 often tests the misconception that Parameter Store and Secrets Manager are interchangeable, when only Secrets Manager provides native automatic rotation for RDS-style credentials.

559
Multi-Selecthard

Which TWO configurations can improve the performance of an Amazon RDS for PostgreSQL database that is experiencing high read latency? (Choose TWO.)

Select 2 answers
A.Upgrade to a larger instance size.
B.Enable provisioned IOPS on the DB instance.
C.Create a read replica in the same AWS Region.
D.Enable Multi-AZ deployment.
E.Enable storage auto-scaling.
AnswersB, C

Enabling provisioned IOPS on the DB instance creates an io1/io2 storage volume with a fixed, predictable IOPS level, decoupling performance from burst balances. This gives consistent low-latency I/O for transactional workloads and avoids the variability of general-purpose SSD when sustained throughput is required. It directly addresses storage I/O performance, making it a correct configuration choice.

Why this answer

Enabling Provisioned IOPS on an Amazon RDS for PostgreSQL database provides consistent and predictable I/O performance, which directly reduces read latency by ensuring sufficient IOPS for read-intensive workloads. Option C is correct because creating a read replica offloads read traffic from the primary DB instance to the replica, reducing contention and improving read latency for the primary instance.

Exam trap

The trap here is that candidates often confuse Multi-AZ deployment with read replicas, mistakenly thinking Multi-AZ improves read performance, when in fact the standby in Multi-AZ is not accessible for reads and only provides failover redundancy.

560
MCQhard

A company is using Amazon CloudFront with an S3 bucket as the origin. The S3 bucket contains sensitive data that should only be accessible via CloudFront. The SysOps administrator has configured an Origin Access Identity (OAI) and updated the bucket policy to allow access only to the OAI. However, users are still able to access the S3 bucket directly via the S3 URL. What is the most likely reason?

A.The bucket policy does not include a condition to require the OAI.
B.The bucket policy allows public read access in addition to the OAI access.
C.The OAI is not properly associated with the CloudFront distribution.
D.The S3 bucket is configured as a static website.
AnswerB

If the bucket policy includes an allow statement for s3:GetObject with Principal: "*", every internet user who knows the object's direct S3 URL can read it without using CloudFront. This is a common misconfiguration when administrators add the OAI allow rule but forget to remove the public read rule, leaving two paths to the content. The correct policy must only permit the OAI principal and, if needed, explicitly deny all other principals to prevent bypass.

Why this answer

The most likely reason users can still access the S3 bucket directly is that the bucket policy contains a statement granting public read access (e.g., 'Principal': '*') in addition to the OAI allow statement. Even with OAI configured, an explicit public allow overrides the restriction. The bucket policy must be reviewed to remove any public access grants.

Exam trap

SOA-C02 often tests the misconception that configuring OAI alone secures the bucket, when in fact an existing public bucket policy statement can still allow direct access, and candidates must identify that as the root cause.

How to eliminate wrong answers

Option A is wrong because the OAI condition is typically included in the bucket policy as a 'Condition' with 'aws:SourceArn' or 'aws:UserAgent', but the absence of a condition is not the primary reason for direct access if the policy already allows the OAI; the issue is an additional public allow. Option C is wrong because if the OAI were not properly associated, CloudFront would not be able to access the bucket, but users accessing directly would still be blocked if the bucket policy only allowed the OAI. Option D is wrong because configuring the bucket as a static website does not inherently make it public; public access depends on the bucket policy and ACLs, and static website hosting requires public read, but the question states the bucket policy was updated to allow only OAI, so the static website setting alone would not override that.

561
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all IAM users in member accounts must use MFA. They create an SCP that denies all actions if the IAM user does not have MFA. However, the SCP does not apply to the root user. The SysOps administrator finds that some IAM users in member accounts are still able to access the console without MFA. What is the most likely reason?

A.The SCP is applied to an OU that does not contain the affected accounts.
B.The IAM user has a resource-based policy that allows access.
C.The SCP only applies to the root user, not IAM users.
D.The SCP is not inherited by child OUs.
AnswerA

Service control policies take effect only on accounts that are directly in the OU or in child OUs underneath it. If the affected accounts are in a different OU—or in the organization root with no explicit SCP attachment—the deny statement won't apply. The fix is to attach the denying SCP to the exact branch of the organization hierarchy that contains those accounts, which requires verifying the OU structure in AWS Organizations.

Why this answer

SCPs are inherited down the OU tree, but they only apply to accounts within the OU they are attached to. If the SCP is attached to an OU that does not contain the affected member accounts, those accounts are unaffected and their IAM users can still sign in without MFA.

Exam trap

The trap is assuming SCPs are global once created, when in fact they only affect accounts within the OU they are attached to — attachment scope is the most common reason an SCP appears not to work.

How to eliminate wrong answers

Option B is wrong because resource-based policies cannot override an SCP — SCPs act as a permissions boundary at the account/OU level and take precedence in the authorization evaluation. Option C is wrong because SCPs apply to all principals in the account, including IAM users and roles, not just the root user; the question's note about root is a red herring. Option D is wrong because SCPs are inherited by child OUs by default — inheritance is a core feature, not a limitation.

562
MCQhard

A company uses AWS Global Accelerator to improve performance of a TCP application. Users in Asia report higher latency than users in Europe. The endpoints are all in us-east-1. What is the BEST solution?

A.Create a VPC peering connection between us-east-1 and an Asia region.
B.Add more endpoints in us-east-1 to distribute load.
C.Switch to Amazon CloudFront for the TCP application.
D.Deploy additional endpoints in an Asia region and configure Global Accelerator to route traffic to the closest endpoint.
AnswerD

Global Accelerator routes users to the nearest healthy endpoint, so adding endpoints in an Asia region places compute closer to those users, cutting round-trip latency. With endpoints only in us-east-1, Asian traffic must still cross the Pacific, which no accelerator tuning can remove.

Why this answer

VPC peering does not affect Global Accelerator routing; Global Accelerator uses Anycast IPs and routes to endpoints based on location, not VPC peering. Option B is incorrect because adding more endpoints in us-east-1 does not reduce latency for users in Asia; they still have to travel across the Atlantic and Pacific. Option C is incorrect because CloudFront is designed for HTTP/HTTPS (and WebSockets), not general TCP applications.

Global Accelerator supports TCP/UDP. Option D is correct because deploying endpoints in an Asia region and configuring Global Accelerator to route traffic to the closest endpoint reduces latency for Asian users.

563
MCQhard

A company uses AWS CloudFormation with nested stacks. The parent stack creates a child stack that launches an Auto Scaling group. The child stack fails to create, and the parent stack rolls back. The administrator wants to debug the child stack. What is the most efficient way to view the child stack's events?

A.Navigate to the child stack in the AWS CloudFormation console and view its events.
B.Rerun the parent stack with a different name to see the child stack creation.
C.Check the CloudWatch Logs for the parent stack.
D.View the parent stack's events in the AWS Management Console.
AnswerA

The child stack persists after rollback, because CloudFormation leaves it in a terminal state for inspection. Its Events tab lists every resource created or attempted within the child, including the exact failure reason (e.g., an EC2 instance's user-data script exit code, an IAM permission denial, or a resource creation timeout). This is the authoritative source of diagnostic information because the parent stack only sees the child as an atomic resource.

Why this answer

After a nested stack fails, it remains in a FAILED state and is visible in the AWS CloudFormation console. You can navigate directly to the child stack to view its events and identify the cause of failure. Option B is incorrect because rerunning the parent stack with a different name would create a new child stack, not help debug the original failed child stack.

Option C is incorrect because CloudWatch Logs are not automatically enabled for CloudFormation stacks; you would need to configure logging. Option D is incorrect because the parent stack's events only show aggregated status or a failure message for the child stack, not the detailed events inside the child stack.

564
MCQeasy

A company runs a web application on Amazon EC2 instances in a single Availability Zone. The SysOps administrator wants to increase the availability of the application so that it can survive an Availability Zone failure. Which action is the most effective?

A.Deploy an additional EC2 instance in the same Availability Zone.
B.Launch EC2 instances in two different Availability Zones and place them behind an Application Load Balancer.
C.Enable termination protection on all EC2 instances.
D.Use an Amazon RDS Multi-AZ deployment for the database tier.
AnswerB

Launching EC2 instances in two different Availability Zones and placing them behind an Application Load Balancer is the canonical web-tier high availability pattern. The ALB performs continuous health checks and distributes traffic to healthy targets across both AZs. If an entire AZ becomes unhealthy, the ALB automatically reroutes requests to instances in the remaining AZ, preserving the application's availability. This design eliminates the AZ as a single point of failure for the web tier.

Why this answer

Deploying EC2 instances across two different Availability Zones and placing them behind an Application Load Balancer (ALB) provides fault isolation. If one AZ fails, the ALB automatically routes traffic to the healthy instances in the other AZ, ensuring the application remains available. This architecture directly addresses the goal of surviving an AZ failure by eliminating the single point of failure at the AZ level.

Exam trap

The trap here is that candidates often confuse high availability with fault tolerance at a single component level, mistakenly thinking that adding more instances in the same AZ or enabling termination protection improves availability, when in fact only distributing resources across multiple isolated Availability Zones can survive an AZ failure.

How to eliminate wrong answers

Option A is wrong because adding more instances in the same Availability Zone does not protect against an AZ failure; all instances would still be affected if that single AZ goes down. Option C is wrong because termination protection only prevents accidental deletion of instances, it does not provide any redundancy or fault tolerance for an AZ outage. Option D is wrong because while an Amazon RDS Multi-AZ deployment improves database availability, it does not address the availability of the web application tier running on EC2; the question asks for the most effective action to increase application availability, which requires a multi-AZ architecture for the compute layer.

565
MCQeasy

A SysOps administrator is automating the deployment of an application across multiple AWS accounts using AWS CodePipeline. The pipeline must deploy to different environments (dev, test, prod) sequentially. Which deployment approach should be used?

A.Use AWS CodeCommit repositories in each account and trigger builds.
B.Use AWS CLI scripts with cross-region replication.
C.Use separate CodePipeline stages with cross-account actions using IAM roles.
D.Create a single pipeline with all deployment stages in the same account.
AnswerC

Separate CodePipeline stages with cross-account actions using IAM roles is the correct architecture because CodePipeline natively supports cross-account actions by assuming a role in the target account for each stage. The pipeline in the originating account uses a source stage, then invokes a deployment action that assumes an IAM role in the destination account, allowing you to deploy the same artifact to multiple accounts sequentially or in parallel. This design enforces least privilege, keeps the pipeline state centralized while distributing execution, and meets the requirement of deploying to multiple accounts without combining resources.

Why this answer

Cross-account deployment in CodePipeline is achieved by defining separate stages (or actions) that assume an IAM role in the target account, allowing the pipeline in the tooling account to deploy into dev, test, and prod accounts sequentially. This uses sts:AssumeRole with a trust policy on the target account's role, and the stages run in order with manual approval gates as needed.

Exam trap

SOA-C02 often tests the confusion between cross-region and cross-account deployment — candidates pick CLI scripting or single-account pipelines when the question explicitly requires multiple accounts with sequential stages.

How to eliminate wrong answers

Option A is wrong because separate CodeCommit repositories per account do not create a sequential cross-account deployment mechanism — they just fragment source control and still require a pipeline to orchestrate. Option B is wrong because AWS CLI scripts with cross-region replication address data movement, not multi-account pipeline orchestration, and they bypass CodePipeline's stage/approval model. Option D is wrong because a single pipeline with all stages in one account cannot deploy into other accounts without cross-account roles, and it violates the isolation the question requires.

566
Drag & Dropmedium

Drag and drop the steps to configure an Amazon Route 53 failover routing policy into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Create health checks first, then create primary and secondary records with failover types, then test.

567
MCQmedium

A company is deploying a web application on EC2 instances behind an Application Load Balancer (ALB). The application needs to maintain user session state. Which configuration ensures session stickiness with minimal performance impact?

A.Use Amazon CloudFront with origin stickiness enabled.
B.Use a Network Load Balancer (NLB) with target group stickiness.
C.Enable sticky sessions on the Application Load Balancer using a load balancer-generated cookie.
D.Store session state in Amazon DynamoDB and have each instance read from DynamoDB.
AnswerC

The Application Load Balancer supports sticky sessions by generating a durable cookie (AWSALB) that is stored in the client's browser and mapped to the specific EC2 instance that handled the initial request. On subsequent requests, the ALB reads this cookie and routes the client to the same instance for the duration of the cookie's lifetime or until the instance becomes unhealthy. This mechanism is purpose-built for session-stateful web applications, and it adds negligible overhead because the routing decision is made entirely on the ALB without requiring external database reads or application code changes.

Why this answer

Enabling sticky sessions on an Application Load Balancer (ALB) using a load balancer-generated cookie (AWSALB) binds a user's session to a specific target instance with minimal overhead. The ALB inserts the cookie in the response, and subsequent requests from the same client are routed to the same instance without requiring application-level session replication or external storage, thus preserving performance.

Exam trap

The trap here is that candidates often confuse session stickiness with session persistence via external storage (DynamoDB) or assume a Network Load Balancer can provide cookie-based stickiness, but the exam tests the specific AWS service capabilities: only ALB supports cookie-based sticky sessions at Layer 7 with minimal performance impact.

How to eliminate wrong answers

Option A is wrong because CloudFront origin stickiness is not a native feature; CloudFront can forward cookies but does not itself maintain session stickiness to EC2 instances behind an ALB, and adding CloudFront introduces unnecessary latency and complexity for this use case. Option B is wrong because a Network Load Balancer (NLB) operates at Layer 4 and does not support cookie-based stickiness; its target group stickiness uses source IP hashing, which can cause uneven load distribution and does not work well with clients behind NAT or proxies. Option D is wrong because storing session state in DynamoDB and having each instance read from it adds network latency and increases cost per request, degrading performance compared to the lightweight cookie-based stickiness provided by the ALB.

568
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer. The instances are in an Auto Scaling group across three Availability Zones. To improve reliability, the company wants to ensure that if an entire Availability Zone fails, the application remains available. Which configuration should be implemented?

A.Remove the load balancer and use Route 53 weighted routing to distribute traffic.
B.Launch all instances in a single Availability Zone to reduce latency.
C.Configure the Auto Scaling group to launch instances in three Availability Zones.
D.Use a Network Load Balancer instead of an Application Load Balancer.
AnswerC

Configuring the Auto Scaling group to launch instances in three Availability Zones is the correct approach because it distributes the web application across separate physical data centers within the Region. The Auto Scaling group manages instance health and automatically replaces unhealthy or failed instances in the remaining AZs, while the Application Load Balancer routes traffic only to healthy instances across all three zones. This design ensures that if an entire AZ experiences an outage, the load balancer shifts traffic to instances in the other AZs, keeping the application available and meeting the reliability requirement.

Why this answer

Configuring the Auto Scaling group to launch instances across three Availability Zones ensures that if one AZ fails, the remaining AZs continue to serve traffic. The Application Load Balancer automatically distributes incoming requests to healthy instances in the surviving AZs, maintaining application availability without manual intervention.

Exam trap

The trap here is that candidates may think changing the load balancer type (e.g., to NLB) is the solution, but the core requirement is ensuring the Auto Scaling group spans multiple Availability Zones, not the load balancer protocol or layer.

How to eliminate wrong answers

Option A is wrong because removing the load balancer and using Route 53 weighted routing would not provide automatic health checking and failover at the instance level; Route 53 weighted routing distributes traffic based on weights but does not monitor instance health or reroute traffic if an AZ fails, leading to potential downtime. Option B is wrong because launching all instances in a single Availability Zone creates a single point of failure; if that AZ fails, the entire application becomes unavailable, directly contradicting the goal of improving reliability. Option D is wrong because replacing the Application Load Balancer with a Network Load Balancer does not inherently improve AZ-level resilience; both ALB and NLB support cross-zone load balancing and can distribute traffic across multiple AZs, but the key requirement is that the Auto Scaling group spans multiple AZs, not the type of load balancer.

569
MCQhard

A SysOps administrator receives an alert that a VPN connection between a VPC and an on-premises network is down. The VPN uses static routing. After verifying the on-premises side is functioning, what should the administrator check in AWS?

A.Check the BGP session status.
B.Reboot the virtual private gateway.
C.Ensure the route table has a route to the virtual private gateway.
D.Verify that the customer gateway device is configured with the correct IP address.
AnswerD

The customer gateway device represents the on-premises endpoint of the VPN tunnel, and its public IP address is a required parameter. If the IP address configured in AWS for the customer gateway does not match the actual public IP of the on-premises device—for example if it changed or NATed—the IPsec negotiation cannot succeed. Verifying this critical endpoint configuration is the first step in troubleshooting a downed tunnel because it prevents the security associations from ever being established. This directly addresses the root cause of a failed VPN connection.

Why this answer

Since the VPN uses static routing, BGP is not in use, so checking BGP session status (Option A) is irrelevant. Rebooting the virtual private gateway (Option B) is a disruptive action that should not be a first step without identifying the root cause. Ensuring the route table has a route to the virtual private gateway (Option C) is important for traffic flow but does not address the VPN tunnel being down.

The correct first step is to verify that the customer gateway device is configured with the correct IP address (Option D), because a mismatch in the public IP address of the on-premises VPN endpoint will prevent the IPsec tunnel from establishing, even if the on-premises side is functioning internally.

Exam trap

The trap here is that candidates assume a VPN tunnel failure must be a routing or BGP issue, but with static routing, the most common cause is a mismatch in the customer gateway IP address, which is a simple configuration check that should be performed first.

How to eliminate wrong answers

Option A is wrong because static routing does not use BGP; BGP is only used with dynamic routing, so checking BGP session status would not apply. Option B is wrong because rebooting the virtual private gateway is a drastic, last-resort action that could cause unnecessary downtime and does not diagnose the specific cause of the tunnel failure. Option C is wrong because while a missing route to the virtual private gateway could affect traffic flow, the VPN tunnel itself can be up even without a route; the immediate issue is the tunnel being down, not routing.

570
Multi-Selecthard

A company uses AWS Organizations and wants to restrict the use of specific AWS services across all member accounts. Which TWO methods can be used to enforce these restrictions? (Choose TWO.)

Select 2 answers
A.Create IAM policies in each account that deny the service actions and attach them to all IAM users and roles.
B.Use AWS Config rules to automatically disable non-compliant services.
C.Use AWS Service Catalog to block the use of disallowed services.
D.Attach a service control policy to the root organizational unit that denies the service actions.
E.Configure VPC endpoints to block traffic to the disallowed services.
AnswersA, D

IAM policies can explicitly deny AWS service actions and, when attached to every IAM user and role in an account, prevent those principals from invoking the disallowed APIs. However, this approach is operationally heavy because you must attach the policy to all existing and future principals individually, and it does not restrict the account root user unless combined with an SCP or resource-based policy. It is a valid account-level enforcement method, but it requires diligent maintenance across all accounts.

Why this answer

IAM policies in each account can deny actions for specific services, and when attached to all IAM users and roles, they effectively restrict usage across the account, though this requires consistent application. Option D is correct because SCPs attached to the root organizational unit can deny access to specified services across all member accounts in the organization. Option B is incorrect because AWS Config rules can detect non-compliance but cannot enforce restrictions or disable services.

Option C is incorrect because AWS Service Catalog is used to create and manage a catalog of approved services, not to block disallowed services. Option E is incorrect because VPC endpoints control network traffic to services, not service-level restrictions.

571
Multi-Selectmedium

Which TWO actions can a SysOps administrator take to improve the availability of a web application using an Application Load Balancer (ALB) and EC2 instances? (Choose two.)

Select 2 answers
A.Place all instances in a single subnet to reduce latency
B.Configure health checks on the target group
C.Deploy EC2 instances in multiple Availability Zones
D.Use larger instance types to handle more traffic
E.Increase the deregistration delay (connection draining) timeout
AnswersB, C

Health checks are the mechanism an Application Load Balancer uses to continuously verify that an instance is able to receive traffic. Without them, the ALB keeps sending requests to instances that may be failing, causing connection errors and degraded user experience. Once a health check fails a configured number of times, the ALB automatically marks the instance as unhealthy and stops routing new traffic to it, while still allowing it to recover. This is a direct, operational improvement to availability because it proactively isolates failures at the instance level.

Why this answer

Health checks allow the ALB to automatically detect unhealthy EC2 instances and stop routing traffic to them, which prevents failed requests from reaching users. By configuring health checks on the target group, the ALB can mark instances as unhealthy based on criteria like HTTP response codes or timeout thresholds, and then route traffic only to healthy instances. This directly improves availability by ensuring that requests are not sent to failed or degraded instances.

Exam trap

The trap here is that candidates often confuse scaling (larger instances or more instances) with high availability, or they think that increasing timeouts like deregistration delay improves availability, when in fact only redundancy across AZs and proper health checking provide true fault tolerance.

572
Multi-Selecthard

An application writes logs to an S3 bucket. The logs are accessed frequently for the first 30 days, then rarely after that, but must be retained for 7 years. Which THREE steps should be taken to optimize cost? (Choose three.)

Select 3 answers
A.Use an S3 Lifecycle policy to transition objects to S3 Glacier Deep Archive after 90 days.
B.Use an S3 Lifecycle policy to transition objects to S3 Standard-IA after 30 days.
C.Delete logs older than 30 days.
D.Set an S3 Lifecycle policy to expire objects after 7 years.
E.Use S3 Intelligent-Tiering to automatically optimize costs.
AnswersA, B, D

Transitioning objects to S3 Glacier Deep Archive after 90 days is correct because it directly addresses the long-term retention requirement while minimizing storage costs. After 90 days, the logs are almost never accessed, so the multi-hour retrieval time of Deep Archive is an acceptable trade-off for its extremely low per-GB price. Lifecycle policies can automatically move objects between storage classes based on age, and Glacier Deep Archive is the cheapest option for data that must be kept for years. This approach preserves the logs for compliance while using the most cost-effective storage class available.

Why this answer

S3 Glacier Deep Archive is the lowest-cost storage class for long-term archival data, making it ideal for logs that are rarely accessed after 90 days. An S3 Lifecycle policy automates the transition from a higher-cost class (e.g., Standard-IA) to Glacier Deep Archive, reducing storage costs while retaining the data for the required 7-year period.

Exam trap

The trap here is that candidates may choose S3 Intelligent-Tiering (option E) thinking it automatically handles all cost optimization, but it does not support transitions to Glacier Deep Archive and incurs per-object monitoring fees, making it unsuitable for this long-term archival scenario.

573
MCQmedium

A SysOps administrator is troubleshooting an issue where an EC2 instance running a web server is unreachable. The instance passes status checks and is in a healthy state. Security groups and network ACLs are configured correctly. CloudWatch metrics show CPU utilization is 5%. The administrator can SSH into the instance but cannot connect to the web server on port 443. What is the most likely cause?

A.The security group inbound rule for HTTPS is misconfigured.
B.The instance has an incorrect route table entry.
C.The web server service is not running or crashed.
D.The instance has insufficient CPU credits.
AnswerC

The web server service is likely not running or has crashed after boot, which would leave port 443 closed while SSH (port 22) remains active because no guest OS process is listening on the HTTPS port. EC2 status checks only detect hardware, hypervisor, and network reachability issues; they do not monitor application processes or service states inside the instance. With CPU utilization at 5% and correct security group rules, the most consistent explanation is that the web server process (e.g., httpd, nginx, or IIS) is not started. Check the service status and application logs, then restart the service to restore connectivity.

Why this answer

The instance passes both status checks and is healthy, and the administrator can SSH into it, confirming that the operating system and network stack are functional. Since the web server is unreachable on port 443 despite correct security group and network ACL configurations, and CPU utilization is low (5%), the most likely cause is that the web server service (e.g., Apache, Nginx) has stopped or crashed. This would prevent the instance from listening on port 443, even though the underlying infrastructure is sound.

Exam trap

The trap here is that candidates often assume a reachability issue must be a network configuration problem (security group or route table), but the combination of successful SSH and failed HTTPS on a low-CPU, healthy instance points directly to the application service not running.

How to eliminate wrong answers

Option A is wrong because the security group inbound rule for HTTPS is explicitly stated to be configured correctly, and SSH (port 22) works, indicating no network-level filtering issue. Option B is wrong because an incorrect route table entry would affect all traffic to/from the instance, not just port 443, and SSH connectivity would also fail. Option D is wrong because CPU utilization is only 5%, which is well below the threshold for credit exhaustion, and the instance passes status checks, ruling out a performance-based bottleneck.

574
MCQeasy

A company wants to host a static website on AWS with high availability and low latency for global users. Which service should be used to serve the static content?

A.AWS Lambda with API Gateway.
B.Amazon Route 53 with a simple routing policy.
C.EC2 instances behind an Application Load Balancer.
D.Amazon S3 bucket configured for static website hosting, with Amazon CloudFront.
AnswerD

An S3 bucket configured for static website hosting provides durable, highly available object storage with built-in features like index and error documents, and it scales automatically to handle any traffic level. Adding Amazon CloudFront in front of S3 gives you a global CDN that caches content at edge locations, reducing latency for users worldwide and offloading repeated requests from the bucket. CloudFront also adds HTTPS for custom domains, DDoS protection via AWS Shield, and allows you to keep the S3 bucket private using Origin Access Control (OAC), making this pairing the recommended serverless, cost-effective architecture for a high-availability static website.

Why this answer

Amazon S3 static website hosting serves the HTML/CSS/JS objects directly from the bucket, and fronting it with Amazon CloudFront caches content at global edge locations, delivering low latency and high availability. This combination is the canonical AWS pattern for globally distributed static sites because it removes server management and scales automatically.

Exam trap

SOA-C02 often tests whether candidates recognize that 'high availability and low latency for global users' implies edge caching (CloudFront) plus object storage (S3), not compute or DNS-only solutions — the trap is picking Route 53 or EC2/ALB as if DNS or a regional load balancer could deliver global edge performance.

How to eliminate wrong answers

Option A is wrong because Lambda with API Gateway is a serverless compute/API pattern for dynamic request handling, not for serving static assets, and it adds unnecessary cost and cold-start latency. Option B is wrong because Route 53 with a simple routing policy only resolves DNS to a single endpoint — it provides no caching, no edge delivery, and no high-availability failover for global users. Option C is wrong because EC2 instances behind an ALB require managing servers, patching, and scaling, and an ALB is region-scoped, so it cannot deliver the global low-latency edge caching that static content demands.

575
MCQmedium

A company runs a production database on an Amazon RDS for PostgreSQL DB instance in a single Availability Zone. The SysOps administrator needs to improve the database's availability to meet an SLA of 99.99% and ensure automatic failover in case of a database failure. Which configuration change should be made?

A.Enable a Multi-AZ deployment
B.Create a read replica in a different AWS Region
C.Configure automated backups with cross-region copy
D.Enable deletion protection on the DB instance
AnswerA

Multi-AZ deployment provisions a standby replica in a different Availability Zone with synchronous replication. If the primary instance fails, AWS automatically fails over to the standby, typically within 60 seconds, preserving your DNS endpoint so applications continue without manual intervention. This is the only option that directly provides automatic high availability for the primary RDS instance.

Why this answer

Enabling a Multi-AZ deployment for an Amazon RDS PostgreSQL DB instance automatically provisions and maintains a synchronous standby replica in a different Availability Zone. In the event of a database failure or an Availability Zone outage, Amazon RDS automatically fails over to the standby replica, typically within 60-120 seconds, meeting the 99.99% SLA requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse read replicas (which are for read scaling and disaster recovery) with Multi-AZ deployments (which are for high availability and automatic failover), leading them to incorrectly select the cross-region read replica option.

How to eliminate wrong answers

Option B is wrong because creating a read replica in a different AWS Region provides read scalability and disaster recovery, but it does not support automatic failover for the primary DB instance; failover requires manual promotion of the read replica, which cannot meet a 99.99% SLA. Option C is wrong because configuring automated backups with cross-region copy protects against data loss by storing backups in another region, but it does not provide automatic failover or high availability for the database instance itself. Option D is wrong because enabling deletion protection on the DB instance only prevents accidental deletion of the database; it has no effect on availability, failover, or resilience against failures.

576
MCQeasy

A company wants to allow its employees to access internal applications using a custom domain name (app.example.com) that resolves to an internal ALB. Which AWS service should be used?

A.AWS Global Accelerator
B.Application Load Balancer
C.Amazon Route 53
D.Amazon CloudFront
AnswerC

Amazon Route 53 is a scalable and authoritative DNS service designed specifically to resolve custom domain names. It lets you create hosted zones, manage records (A, AAAA, CNAME, MX, etc.), and route traffic to AWS resources such as load balancers, CloudFront distributions, or IP addresses. Route 53 also supports alias records that integrate natively with other AWS services, making it the standard choice for mapping internal or external domains to application endpoints.

Why this answer

Amazon Route 53 is the correct choice because it is a DNS service that can resolve a custom domain name (app.example.com) to an internal Application Load Balancer's DNS name. By creating a private hosted zone associated with the company's VPC, Route 53 can provide internal DNS resolution without exposing the ALB to the internet, which meets the requirement for internal application access.

Exam trap

The trap here is that candidates often confuse DNS resolution with load balancing or content delivery, mistakenly choosing the ALB (which handles traffic distribution but not name resolution) or CloudFront (which is for public content delivery), instead of recognizing that Route 53 is the DNS service required to map a custom domain to an internal resource.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator is a network layer service that improves availability and performance by directing traffic to optimal endpoints over the AWS global network, but it does not provide DNS resolution for custom domain names. Option B is wrong because an Application Load Balancer is a load balancer that distributes incoming traffic to targets, but it does not resolve domain names; it requires a DNS service like Route 53 to map a custom domain to its DNS name. Option D is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations and is typically used for public-facing applications; it does not provide internal DNS resolution within a VPC and would require public exposure.

577
MCQeasy

Refer to the exhibit. A SysOps administrator creates a CloudFormation stack with the template shown. After 30 days, what happens to noncurrent versions of objects in the bucket?

A.They are permanently deleted.
B.They are moved to Amazon S3 Glacier.
C.They become the current version.
D.They are moved to Amazon S3 Standard-Infrequent Access.
AnswerA

An S3 Lifecycle expiration rule for noncurrent versions explicitly deletes those versions after the specified number of days, regardless of the storage class. Because the rule only includes an Expiration action and no Transition action, old versions are permanently removed from the bucket rather than being archived or moved. Once permanently deleted, these objects cannot be recovered, so it is critical to have a backup or a separate replication rule if you need to preserve them.

Why this answer

The CloudFormation template configures an S3 bucket with a lifecycle rule that sets 'NoncurrentVersionExpirationInDays' to 30. This rule permanently deletes noncurrent versions of objects after 30 days, as S3 lifecycle policies for noncurrent versions do not transition to other storage classes unless explicitly specified with a separate transition action. After 30 days, the noncurrent versions are removed from the bucket entirely.

Exam trap

The trap here is that candidates may assume noncurrent versions are automatically transitioned to cheaper storage classes like Glacier or S3 Standard-IA, but without explicit transition actions in the lifecycle rule, only expiration (deletion) occurs.

How to eliminate wrong answers

Option B is wrong because the lifecycle rule only specifies 'NoncurrentVersionExpirationInDays' with no 'Transitions' action for noncurrent versions, so objects are not moved to S3 Glacier. Option C is wrong because noncurrent versions cannot become the current version; S3 versioning maintains a distinct current version, and noncurrent versions are older versions that are immutable. Option D is wrong because there is no 'NoncurrentVersionTransition' action defined in the lifecycle rule to move objects to S3 Standard-Infrequent Access; the rule only sets expiration.

578
MCQhard

An organization uses AWS Systems Manager to manage a fleet of EC2 instances. The SysOps administrator needs to run a script on all instances that have a specific tag (Environment: Production). The script must be executed immediately and only once. Which approach should be used?

A.Use Patch Manager to apply the script as a patch baseline.
B.Create an Automation document and execute it.
C.Use Run Command with a target based on the tag.
D.Create a State Manager association with the script.
AnswerC

Run Command's SendCommand API accepts a target that can be a tag key-value pair, like tag:Environment=Production, and every SSM agent that matches will execute the AWS-RunShellScript or AWS-RunPowerShellScript document immediately in a one-time, unmanaged fashion. This satisfies the requirement of running a script once across the fleet, with output optionally streamed to S3 or CloudWatch Logs for auditing. Because no association, schedule, or patch baseline is involved, it is the simplest and most direct SSM primitive for this task.

Why this answer

Run Command enables you to run commands on EC2 instances immediately and only once, using tags to target specific instances. Option A is incorrect because Patch Manager is designed for applying patches, not running arbitrary scripts. Option B is incorrect because Automation documents are for multi-step workflow orchestration, not simple one-time script execution.

Option D is incorrect because State Manager is for recurring configurations or ensuring a desired state over time, not immediate one-time execution.

579
MCQhard

A company uses AWS CloudTrail to log API activity. The security team needs to be alerted when an IAM user creates a new access key. Which combination of services should the SysOps administrator use to meet this requirement?

A.CloudWatch Logs Insights query on CloudTrail logs with an alarm
B.An AWS Config rule that checks for new access keys and sends an SNS notification
C.A CloudWatch Events rule that matches the CreateAccessKey API call and sends an SNS notification
D.S3 event notifications to an SNS topic
AnswerC

Amazon EventBridge (formerly CloudWatch Events) can consume CloudTrail events as a built-in event source, so a rule with an event pattern tailored to `AWS API Call via CloudTrail` and `eventName` `CreateAccessKey` fires whenever that API is invoked. The rule can target an SNS topic as the action, delivering a near-real-time notification that includes the full event detail such as the IAM user, source IP, and user agent. This is the direct, native mechanism for alerting on specific API calls.

Why this answer

Amazon CloudWatch Events (now Amazon EventBridge) can match AWS API calls recorded by CloudTrail, such as CreateAccessKey, and route them to targets like SNS for alerting. The rule pattern matches the event source (iam.amazonaws.com) and event name (CreateAccessKey), then triggers an SNS notification to the security team. This is the standard serverless approach for real-time alerting on specific API activity.

Exam trap

The trap is confusing AWS Config rules with EventBridge rules; Config evaluates resource compliance, while EventBridge matches API events for real-time alerting.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights is a query tool for analyzing logs on demand; it does not natively trigger alarms based on specific API calls without additional metric filters and alarms, and it is not the most direct combination. Option B is wrong because AWS Config rules evaluate resource compliance periodically or on configuration changes, but they are not designed for immediate alerting on API calls like CreateAccessKey. Option D is wrong because S3 event notifications trigger on object-level events in S3 buckets, not on CloudTrail API activity.

580
MCQeasy

A company wants to distribute content with low latency to users globally. The content is static and stored in an S3 bucket. Which AWS service should be used?

A.Application Load Balancer
B.AWS Global Accelerator
C.Amazon CloudFront
D.S3 Transfer Acceleration
AnswerC

Amazon CloudFront is a content delivery network that caches static and dynamic content at edge locations worldwide, ensuring users receive data from the nearest edge to minimize latency. It works with origins like S3, EC2, or on-premises servers, and offloads repeated requests from the origin by serving cached copies. This directly satisfies the requirement to distribute content with low latency to users.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches static content at edge locations worldwide, reducing latency for users by serving data from the nearest edge. It integrates directly with S3 buckets as an origin, providing low-latency distribution of static content without requiring any changes to the S3 bucket configuration.

Exam trap

The trap here is confusing AWS Global Accelerator (which optimizes network path for dynamic traffic) with CloudFront (which caches static content at the edge), leading candidates to pick Global Accelerator for static content distribution.

How to eliminate wrong answers

Option A is wrong because an Application Load Balancer distributes traffic across targets within a single region and does not cache content or provide global edge distribution. Option B is wrong because AWS Global Accelerator improves performance for TCP/UDP traffic by routing users to the nearest edge via the AWS global network, but it does not cache static content; it is designed for dynamic traffic and non-HTTP protocols. Option D is wrong because S3 Transfer Acceleration speeds up uploads to S3 over long distances using AWS edge locations, but it is not designed for low-latency content distribution to end users; it accelerates uploads, not downloads.

581
MCQmedium

A company has multiple VPCs in the same account that need to communicate with each other. The VPCs are in the same region. Which solution provides the simplest and most scalable connectivity?

A.Set up AWS Direct Connect and route through a single VPC.
B.Use AWS PrivateLink to connect the VPCs.
C.Create a Transit Gateway and attach all VPCs.
D.Create VPC Peering connections between each pair of VPCs.
AnswerC

AWS Transit Gateway (TGW) is a regional hub-and-spoke router that centrally manages connectivity between multiple VPCs and on-premises networks via a single attachment per VPC. After attaching all VPCs to the transit gateway, you configure route tables and propagate routes so that traffic can flow transitively between any attached VPC, eliminating the need for a full mesh of peering connections. This approach scales to hundreds of VPCs, simplifies route management, and supports additional connections such as VPNs and Direct Connect, making it the correct choice.

Why this answer

AWS Transit Gateway acts as a central hub that allows you to attach multiple VPCs and manage inter-VPC routing through a single gateway, simplifying connectivity and scaling easily as you add more VPCs. It eliminates the need for complex mesh or star configurations and supports transitive routing, making it the simplest and most scalable solution for multi-VPC communication within the same region.

Exam trap

The trap here is that candidates often confuse VPC Peering as the simplest solution for a few VPCs, but the question emphasizes scalability, and Transit Gateway is the only option that provides transitive routing without a full mesh of connections.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not designed for inter-VPC connectivity, and routing through a single VPC creates a single point of failure and bandwidth bottleneck. Option B is wrong because AWS PrivateLink is used to expose services privately from one VPC to another, not for general inter-VPC routing; it requires service-specific configurations and does not provide transitive routing between all VPCs. Option D is wrong because VPC Peering requires creating and managing a full mesh of individual peering connections (n*(n-1)/2), which becomes complex and unscalable as the number of VPCs increases, and it does not support transitive routing.

582
MCQmedium

A SysOps administrator notices that an Amazon CloudWatch Logs log group is growing rapidly and suspects that an EC2 instance is sending sensitive data to the logs. What is the most effective way to detect and redact sensitive data in real-time?

A.Use CloudWatch Logs Insights to query and mask sensitive data.
B.Enable S3 event notifications to trigger a Lambda function for redaction.
C.Create a CloudWatch Logs subscription filter that invokes a Lambda function for redaction.
D.Send logs to Amazon Kinesis Data Firehose and use Lambda for redaction.
AnswerC

A CloudWatch Logs subscription filter with a Lambda destination is the native near-real-time mechanism for processing incoming log events. When new log events arrive, the subscription filter immediately invokes the Lambda function, which can decode the gzip-compressed payload, redact sensitive fields, and forward the sanitized data to its final storage destination. This direct integration avoids intermediate storage or additional pipeline services, making it the most efficient and purpose-built solution for real-time log redaction.

Why this answer

CloudWatch Logs subscription filters can invoke a Lambda function in real-time as log events are ingested. This allows the Lambda function to inspect, detect, and redact sensitive data (e.g., credit card numbers or passwords) before the logs are stored in the log group, meeting the requirement for real-time detection and redaction.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs Insights (a query tool) with a real-time processing capability, or they over-engineer the solution by involving S3 or Kinesis when a direct subscription filter is the simplest and most effective real-time redaction method.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights is a query tool for analyzing historical log data, not a real-time processing or redaction mechanism; it cannot modify or redact data in transit. Option B is wrong because S3 event notifications trigger on object-level events in an S3 bucket, but the logs are not yet in S3; this would require an additional export step and cannot provide real-time redaction at the point of ingestion. Option D is wrong because sending logs to Kinesis Data Firehose adds unnecessary latency and complexity; while Lambda can be used for redaction in that pipeline, the most direct and effective real-time method is a CloudWatch Logs subscription filter targeting Lambda, which operates at the log ingestion stage without requiring an intermediate streaming service.

583
MCQmedium

A company uses AWS CloudFormation to deploy a stack that includes an EC2 instance and an S3 bucket. The SysOps administrator needs to monitor the stack for any changes to the S3 bucket's bucket policy. Which AWS service should be used?

A.Amazon CloudWatch
B.AWS Config
C.AWS CloudTrail
D.AWS Trusted Advisor
AnswerB

AWS Config continuously records configuration items for supported resources, including S3 bucket policies, and can evaluate those configurations against managed or custom rules. When someone manually changes the bucket policy, AWS Config detects the change, generates a configuration item, and can trigger a compliance notification through a rule such as s3-bucket-policy-grantee-check or a custom Lambda-backed rule. This makes it the correct service for detecting post-deployment drift from the intended policy.

Why this answer

AWS Config is the correct service because it can track changes to S3 bucket policies, evaluate them against desired configurations, and trigger notifications or remediation. AWS CloudTrail logs API calls that modify bucket policies but does not monitor the policy state itself. Amazon CloudWatch is used for monitoring metrics and logs, not for tracking configuration changes.

AWS Trusted Advisor provides best practice recommendations and does not monitor bucket policies.

584
MCQmedium

A company has an Application Load Balancer (ALB) that routes traffic to Amazon EC2 instances in private subnets of a VPC. The SysOps administrator needs to ensure that the EC2 instances can download software updates from the internet, but they must not be directly accessible from the internet. The solution should minimize operational overhead. Which solution should the administrator implement?

A.Place the EC2 instances in a public subnet and configure security group inbound rules to block all traffic.
B.Attach a NAT Gateway to a public subnet and configure the private subnet route table to send 0.0.0.0/0 traffic to the NAT Gateway.
C.Launch a NAT instance in a public subnet with an Elastic IP address and configure route tables accordingly.
D.Attach an Internet Gateway to the VPC and add a route to the private subnet route table pointing 0.0.0.0/0 to the Internet Gateway.
AnswerB

A NAT Gateway deployed in a public subnet with an Elastic IP provides secure outbound-only internet connectivity for private-instance traffic. The private subnet route table's 0.0.0.0/0 entry points to the NAT gateway, which translates source IPs and discards unsolicited inbound connections. Because AWS fully manages the gateway, it auto-scales and requires no patching, minimizing operational overhead. This satisfies both security and administrative efficiency.

Why this answer

A NAT Gateway (option B) allows EC2 instances in private subnets to initiate outbound connections to the internet (e.g., for software updates) while preventing any unsolicited inbound connections from the internet. It is a fully managed AWS service that automatically scales and requires no patching, minimizing operational overhead compared to a NAT instance. The private subnet route table directs 0.0.0.0/0 traffic to the NAT Gateway, which is placed in a public subnet with an Elastic IP address to enable internet access.

Exam trap

The trap here is that candidates may confuse a NAT Gateway with a NAT instance, thinking the latter is acceptable, but the question explicitly requires minimizing operational overhead, which disqualifies the self-managed NAT instance in favor of the fully managed NAT Gateway.

How to eliminate wrong answers

Option A is wrong because placing EC2 instances in a public subnet with security group rules blocking all inbound traffic still leaves them with public IP addresses, making them theoretically reachable from the internet (security groups are stateful and can be misconfigured), and it violates the requirement that instances must not be directly accessible from the internet. Option C is wrong because launching a NAT instance requires manual management (patching, scaling, high availability setup), increasing operational overhead, which contradicts the 'minimize operational overhead' requirement. Option D is wrong because adding a route to the private subnet route table pointing 0.0.0.0/0 to an Internet Gateway would make the private subnet effectively public, allowing direct inbound internet access to the EC2 instances, which violates the requirement that they must not be directly accessible from the internet.

585
MCQmedium

A SysOps administrator needs to ensure that an S3 bucket can recover from accidental deletions by users. The bucket stores versioned objects. What additional configuration should be enabled to prevent permanent deletion?

A.Enable S3 Server-Side Encryption.
B.Enable S3 Lifecycle rules to expire objects.
C.Enable MFA Delete on the bucket.
D.Configure a bucket policy to deny s3:DeleteObject.
AnswerC

MFA Delete requires the principal making a destructive request to supply a valid one-time code from a hardware or virtual MFA device, in addition to normal AWS authentication. When applied to a versioned bucket, it protects against permanently deleting an object version and against changing the bucket's versioning state. This means an accidental delete creates a recoverable delete marker, and even compromised AWS credentials cannot irreversibly purge data without the MFA code.

Why this answer

Enabling MFA Delete on the S3 bucket adds an extra layer of protection by requiring multi-factor authentication for any DeleteObject or DeleteBucket operations. Even if a user has s3:DeleteObject permission, they cannot permanently delete versioned objects unless they present a valid MFA code. This prevents accidental or unauthorized permanent deletions while still allowing versioned objects to be recovered.

Exam trap

The trap here is that candidates assume a bucket policy denying s3:DeleteObject is sufficient, but it does not prevent accidental deletion by authorized users who have delete permissions and can simply remove the policy; MFA Delete is the only way to enforce an additional authentication factor for permanent deletions in versioned buckets.

How to eliminate wrong answers

Option A is wrong because S3 Server-Side Encryption protects data at rest from unauthorized access, not from accidental deletion. Option B is wrong because S3 Lifecycle rules to expire objects actually automate the deletion of objects, which increases the risk of permanent deletion rather than preventing it. Option D is wrong because a bucket policy denying s3:DeleteObject would block all delete operations, including the ability to delete non-current versions or markers, which is overly restrictive and does not leverage versioning recovery; it also does not prevent accidental deletion by authorized users who could simply remove the policy.

586
MCQmedium

A company uses AWS CloudFormation to deploy a multi-tier application. The stack includes an Application Load Balancer, Auto Scaling group, and RDS database. The SysOps administrator receives a notification that a stack update has failed. The administrator wants to investigate the failure and understand which resource caused the issue. The stack is in the UPDATE_ROLLBACK_IN_PROGRESS state. What should the administrator do to identify the failed resource?

A.Review the stack's template in the CloudFormation console to check for syntax errors.
B.Check the CloudWatch Logs for the EC2 instances in the Auto Scaling group.
C.Manually re-run the update with the same parameters to see if the error recurs.
D.View the stack events in the CloudFormation console to see which resource failed and the error message.
AnswerD

The CloudFormation console's stack events tab displays a chronological list of every resource operation with its status and a status reason field containing the exact AWS SDK error, such as 'Resource creation cancelled' or 'The requested configuration is currently not supported.' This provides the precise failing resource and the underlying API error, which is the definitive information needed to troubleshoot an update failure. You can also retrieve the same data programmatically with the DescribeStackEvents API.

Why this answer

When a CloudFormation stack update fails and enters UPDATE_ROLLBACK_IN_PROGRESS, the most direct way to identify the failed resource is to view the stack events in the CloudFormation console. Each event includes a status reason field that contains the specific error message and the logical resource ID of the resource that caused the failure, allowing the administrator to pinpoint the issue without additional investigation.

Exam trap

The trap here is that candidates may assume the failure is due to a template syntax error (Option A) or that application logs (Option B) would reveal the issue, when in fact CloudFormation events are the authoritative source for resource-level failure details during stack operations.

How to eliminate wrong answers

Option A is wrong because syntax errors in the template would typically cause the update to fail before it begins (e.g., during validation), not during the update process itself; the stack is already in UPDATE_ROLLBACK_IN_PROGRESS, meaning the template was valid enough to start the update. Option B is wrong because CloudWatch Logs for EC2 instances in the Auto Scaling group would only show application-level or OS-level logs, not CloudFormation resource provisioning failures; the failure is at the infrastructure layer, not within the instances. Option C is wrong because manually re-running the update with the same parameters is risky and inefficient; it could cause the same failure again or trigger additional rollbacks, and it does not leverage the existing event data that already contains the error details.

587
MCQmedium

An administrator attempts to deploy an application using AWS CodeDeploy. The deployment fails with 'Access Denied' when trying to download the revision from the S3 bucket 'example-bucket'. The IAM policy attached to the instance profile is shown in the exhibit. What is the cause of the failure?

A.The policy does not include s3:ListBucket
B.The policy is missing the s3:GetObjectVersion action for the bucket
C.The policy grants s3:ListBucket but not s3:GetObject
D.The policy is attached to the wrong IAM role
AnswerB

When you enable S3 Versioning, every object version has a unique versionId, and a GetObject request that specifies that version requires an explicit s3:GetObjectVersion permission in addition to s3:GetObject. The deployment workflow is calling GetObject with a versionId to fetch a unique revision, and the policy only grants the standard object-level actions. Without s3:GetObjectVersion, AWS rejects the request with AccessDenied, making this the exact root cause.

Why this answer

The deployment fails with 'Access Denied' when trying to download the revision from S3. The IAM policy attached to the instance profile must allow the s3:GetObject action to download objects. However, if the deployment uses a specific version of the revision (e.g., when using CodeDeploy with S3 versioning), the s3:GetObjectVersion action is also required.

The exhibit shows the policy includes s3:GetObject but not s3:GetObjectVersion, causing the failure. Option B is correct because the missing s3:GetObjectVersion action is the cause. Option A is incorrect because s3:ListBucket is present in the policy.

Option C is incorrect because the policy does include s3:GetObject. Option D is incorrect because the policy is attached to the correct instance profile.

588
MCQmedium

A SysOps administrator needs to ensure that all traffic between an on-premises data center and the AWS VPC is encrypted and goes over the internet. Which AWS service should be used?

A.AWS Site-to-Site VPN
B.VPC Peering
C.AWS Transit Gateway
D.AWS Direct Connect
AnswerA

AWS Site-to-Site VPN creates encrypted IPsec tunnels between the customer's on-premises network and AWS virtual private gateways or transit gateways. These tunnels, which leverage the public internet, provide secure and confidential transmission of data by encrypting traffic in transit. The service also automatically provisions two tunnels for high availability, ensuring redundant connectivity.

Why this answer

AWS Site-to-Site VPN creates an encrypted tunnel between an on-premises data center and an AWS VPC using IPsec (IKEv1/IKEv2) over the public internet. This meets the requirement for encryption and internet-based connectivity, as the VPN traffic traverses the internet but is secured by IPsec tunnels.

Exam trap

The trap here is that candidates often confuse AWS Site-to-Site VPN with AWS Direct Connect, assuming Direct Connect provides encryption by default, but Direct Connect is a private connection that does not include encryption unless a VPN is layered on top.

How to eliminate wrong answers

Option B (VPC Peering) is wrong because it connects VPCs within AWS using private AWS infrastructure, not over the internet, and does not support encryption by default. Option C (AWS Transit Gateway) is wrong because it is a network transit hub that connects VPCs and on-premises networks, but it does not itself provide encryption; it requires a Site-to-Site VPN or Direct Connect for on-premises connectivity. Option D (AWS Direct Connect) is wrong because it uses a dedicated private network connection, not the internet, and does not inherently encrypt traffic unless combined with a VPN.

589
MCQeasy

Refer to the exhibit. An application running on EC2 is using the AWS SDK to publish custom metrics to CloudWatch. The application fails to publish metrics. The IAM role attached to the EC2 instance has this policy. What is the issue?

A.The condition key 'cloudwatch:namespace' is misspelled.
B.The policy does not specify a specific resource ARN.
C.The application may be using a different namespace than 'MyApp'.
D.The action 'cloudwatch:PutMetricData' is not allowed for custom metrics.
AnswerC

This is the correct answer because the IAM policy uses a condition key `cloudwatch:namespace` with the `StringEquals` operator, which requires an exact match. If the application's code calls PutMetricData with any namespace other than \'MyApp\' — for example, a custom namespace like \'MyApplication\' or \'Company/Metrics\' — the condition fails, and the action is denied even though the policy statement otherwise allows it. CloudWatch namespaces are case-sensitive, so a mismatch in capitalization would also cause a denial, and the application may not be specifying the namespace as expected.

Why this answer

The IAM policy explicitly allows 'cloudwatch:PutMetricData' on the condition that the namespace is 'MyApp'. If the application's AWS SDK code publishes metrics under a different namespace (e.g., 'AWS/EC2' or a custom namespace like 'MyOtherApp'), the condition fails and the API call is denied. This is the most likely cause of the failure, as the policy is otherwise correctly configured for the specified namespace.

Exam trap

The trap here is that candidates often assume a policy with a condition key is always correct, overlooking that the application's actual namespace value must exactly match the condition value for the API call to succeed.

How to eliminate wrong answers

Option A is wrong because 'cloudwatch:namespace' is a valid condition key for CloudWatch PutMetricData; it is not misspelled. Option B is wrong because CloudWatch PutMetricData does not require a resource ARN in the policy; it uses a 'Resource': '*' by convention and the condition key provides the necessary restriction. Option D is wrong because the action 'cloudwatch:PutMetricData' is explicitly allowed for custom metrics when the namespace condition is met; the issue is not that the action is disallowed entirely.

590
MCQhard

A company uses Amazon Route 53 as its DNS service. They have a domain example.com with an alias record pointing to an Application Load Balancer (ALB). Recently, they updated the ALB's DNS name, but the Route 53 record was not updated. Users are still being directed to the old ALB, which has been decommissioned. The SysOps administrator updates the alias record to point to the new ALB DNS name. However, users still experience errors for several hours. What is the most likely reason?

A.Route 53 requires time to propagate changes globally
B.The alias record was not saved correctly
C.The TTL on the DNS record is set too high, causing client-side caching
D.The domain is using DNSSEC, which delays updates
AnswerC

DNS records include a Time-to-Live field that tells clients and recursive resolvers how long to cache the answer. Setting a high TTL, for example 86400 seconds, causes clients that resolved before the change to retain the old IP address for up to 24 hours, even though Route 53 already serves the new record. Lowering the TTL in advance or waiting for the old TTL to expire is the correct fix, making this the accurate explanation.

Why this answer

Alias records in Route 53 are not subject to TTL-based caching for the alias target resolution itself, but the DNS query response from the resolver to the client still includes a TTL value. When the TTL is set too high, clients and intermediate resolvers cache the old DNS response (pointing to the decommissioned ALB) for the duration of that TTL, causing continued errors even after the Route 53 record is updated. The alias record update propagates instantly within Route 53's authoritative infrastructure, but cached records at clients and recursive resolvers must expire before users reach the new ALB.

Exam trap

The trap here is that candidates assume alias records update instantly for all users, forgetting that the TTL in the DNS response controls client-side and resolver caching, which can cause delays even after the authoritative record is changed.

How to eliminate wrong answers

Option A is wrong because Route 53 alias records do not require global propagation time; updates to alias records are effective immediately within Route 53's authoritative DNS servers due to its anycast network and single authoritative source. Option B is wrong because the scenario states the SysOps administrator updated the alias record, and if it were not saved correctly, the record would not change at all, not cause a delay of several hours; the issue is client-side caching, not a save error. Option D is wrong because DNSSEC does not delay updates; it adds cryptographic signing but does not introduce additional propagation delays—DNSSEC validation happens at the resolver, not by introducing a waiting period for record changes.

591
MCQmedium

A company has a CloudFront distribution with an S3 bucket as the origin. The S3 bucket contains sensitive data that should only be accessible through CloudFront. Which configuration is required to ensure that direct access to the S3 bucket is blocked?

A.Attach an IAM role to CloudFront that allows S3 access
B.Set the S3 bucket policy to deny all access except from CloudFront's IP ranges
C.Create an Origin Access Identity (OAI) and add a bucket policy that grants access only to the OAI
D.Use signed URLs for all requests
AnswerC

An Origin Access Identity (OAI) is a special virtual identity that CloudFront uses to fetch objects from your S3 bucket. After creating an OAI and associating it with the distribution, you update the bucket policy to allow s3:GetObject for that OAI principal and deny all other direct S3 access. This ensures viewers can only access content through CloudFront, while the S3 bucket remains private. This is the AWS-recommended mechanism for securing S3 origins and avoids the pitfalls of IP-based or public-bucket policies.

Why this answer

The correct configuration is to create an Origin Access Identity (OAI) and grant it access via the S3 bucket policy. An OAI is a special CloudFront user that can be associated with a distribution. By updating the S3 bucket policy to allow only the OAI to perform s3:GetObject, you ensure that objects are only accessible through CloudFront.

This effectively blocks direct public access to the bucket while allowing CloudFront to serve the content.

Exam trap

SOA-C02 often tests the misconception that CloudFront IP ranges or IAM roles are sufficient to secure S3 origins, when in fact an OAI (or OAC) with a bucket policy is required to block direct access.

How to eliminate wrong answers

Option A is wrong because attaching an IAM role to CloudFront does not automatically restrict direct access to the S3 bucket; CloudFront would still need explicit permissions, and the bucket would remain publicly accessible unless its policy is changed. Option B is wrong because CloudFront's IP ranges are not static and can change, making IP-based restrictions unreliable and difficult to maintain; also, this does not prevent direct access from other AWS services or within the same region. Option D is wrong because signed URLs control access to CloudFront-distributed content but do not block direct access to the S3 bucket itself; users could still bypass CloudFront and access the S3 object URL directly if the bucket is public.

592
MCQeasy

A company runs a web application on EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application stores session data on local instance storage. Users report that they are unexpectedly logged out during peak traffic. Which action should the SysOps Administrator take to improve reliability?

A.Move the session storage to an instance store volume.
B.Enable sticky sessions on the Application Load Balancer.
C.Increase the size of the Auto Scaling group to handle peak traffic.
D.Configure an ElastiCache Redis cluster to store session state externally.
AnswerD

Configuring an ElastiCache Redis cluster to store session state externally solves the persistence problem by creating a centralized, in-memory data store that every EC2 instance can read from and write to. Because sessions live outside any single instance, any instance in the Auto Scaling group can service any request, making the application effectively stateless from the instance perspective. Redis offers sub-millisecond latency, supports replication and backup/restore for durability, and integrates cleanly with common session-management libraries, so instance terminations or scaling events no longer disrupt active user sessions.

Why this answer

Storing session data on local instance storage is ephemeral; if an instance is terminated or replaced during scaling events, session data is lost, causing users to be logged out. Moving session state to an external, highly available service like ElastiCache Redis ensures persistence across instance lifecycles and improves reliability under peak traffic.

Exam trap

The trap here is that candidates often confuse sticky sessions (session affinity) with session persistence, not realizing that sticky sessions only maintain routing to a specific instance but do not protect against data loss when that instance is terminated.

How to eliminate wrong answers

Option A is wrong because instance store volumes are ephemeral and data is lost on instance stop/termination, which would not solve the logout issue. Option B is wrong because sticky sessions (session affinity) only route a user to the same instance, but if that instance is terminated during scaling, the session data is still lost. Option C is wrong because increasing the Auto Scaling group size does not address the root cause—session data loss on instance replacement—and may even increase the frequency of scaling events.

593
MCQhard

A company is using AWS Elastic Beanstalk to deploy a web application. The application uses a custom Amazon Machine Image (AMI) that must be updated periodically. The SysOps administrator creates a new AMI and updates the Elastic Beanstalk environment's configuration. However, new instances are still launched with the old AMI. What is the most likely cause?

A.The environment is configured to use a launch template, and the AMI was not updated in the launch template.
B.The environment is using an immutable update policy.
C.The environment's platform version is pinned to an older version.
D.The old AMI was not deregistered.
AnswerA

When an Elastic Beanstalk environment uses a custom AMI through a launch template, the template holds the exact AMI ID. Updating the source AMI or rebuilding the environment does not change that ID. You must explicitly edit the launch template's ImageId (or use a new launch template version) and then rebuild, otherwise EC2 instances continue to launch with the original AMI. This is the direct cause of the environment still running the old configuration.

Why this answer

When an Elastic Beanstalk environment is configured to use a launch template, the AMI ID is specified in the launch template, not in the environment's configuration. Updating the environment configuration alone does not change the launch template, so new instances continue to use the old AMI. The administrator must update the launch template with the new AMI ID.

Exam trap

SOA-C02 often tests the misconception that updating the environment configuration automatically updates all underlying resources; candidates forget that launch templates are separate entities that must be explicitly updated.

How to eliminate wrong answers

Option B is wrong because an immutable update policy performs a rolling update with new instances and would actually pick up the new AMI if the configuration were correctly updated; it does not cause instances to launch with the old AMI. Option C is wrong because platform version pinning affects the runtime and infrastructure software versions, not the custom AMI ID used for instances. Option D is wrong because deregistering the old AMI is not required to launch new instances with a new AMI; in fact, leaving the old AMI registered does not force its use.

594
MCQeasy

A company uses AWS CodeDeploy to automate deployments to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment'. The logs on a failed instance show that the 'BeforeInstall' lifecycle event script exited with a non-zero exit code. What is the MOST likely cause?

A.The BeforeInstall script has a bug that causes it to exit with a non-zero exit code.
B.The instance does not have the required permissions to download the application revision.
C.The instance is not healthy according to the Elastic Load Balancer health checks.
D.The CodeDeploy agent is not running on the instance.
AnswerA

The BeforeInstall hook is a lifecycle event in a CodeDeploy deployment. If the script exits with any non-zero exit code, CodeDeploy treats that as an unrecoverable failure and immediately stops the deployment, marking the instance as failed. A bug such as a missing command, a syntax error, or a failed dependency check would produce exactly this behavior, and the agent log would show the script's error output.

Why this answer

The error message indicates that the deployment failed because too many instances failed, and the logs on a failed instance show that the 'BeforeInstall' lifecycle event script exited with a non-zero exit code. In AWS CodeDeploy, each lifecycle event script must exit with a zero exit code to indicate success; any non-zero exit code is treated as a failure, causing the deployment to fail on that instance. Since the logs explicitly point to the BeforeInstall script's non-zero exit, the most likely cause is a bug in that script.

Exam trap

The trap here is that candidates may confuse the cause of a deployment failure with external factors like permissions or health checks, but the logs explicitly point to the BeforeInstall script's non-zero exit code, making a script bug the direct and most likely cause.

How to eliminate wrong answers

Option B is wrong because if the instance lacked permissions to download the application revision, the error would typically occur during the 'DownloadBundle' lifecycle event, not during 'BeforeInstall', and the logs would show a permission-related error. Option C is wrong because Elastic Load Balancer health checks are used for traffic routing and instance health monitoring, but they do not directly cause a CodeDeploy lifecycle event script to exit with a non-zero code; a failed health check would result in the instance being deregistered, not a script exit code error. Option D is wrong because if the CodeDeploy agent were not running, the instance would not execute any lifecycle events at all, and the logs would not show a BeforeInstall script exit code; instead, the deployment would likely show a 'pending' or 'failed' status with an agent connectivity error.

595
MCQhard

A company uses AWS Organizations with SCPs to restrict member accounts. The security team wants to prevent all users in the 'Developers' OU from deleting S3 buckets, except for the root user of the management account. How should this be implemented?

A.Create an IAM policy that denies s3:DeleteBucket and attach it to all IAM users. The root user is not affected by IAM policies.
B.Attach an SCP that denies s3:DeleteBucket to the Developers OU. The management account root is not affected by SCPs.
C.Attach an SCP that denies s3:DeleteBucket except when called by root user.
D.Attach an SCP that denies s3:DeleteBucket to the Developers OU. The root user in member accounts is not affected.
AnswerB

Attaching an SCP that denies s3:DeleteBucket to the Developers OU effectively blocks all principals in every member account under that OU, including each member account's root user, because SCPs act as an upper permission boundary. The management account root is explicitly exempt from SCP restrictions, so this control does not affect the management account root. This is the correct way to implement a cross-account deletion guardrail.

Why this answer

SCPs applied to an OU restrict what member accounts can do, but they do not affect the management account. The management account root user is not constrained by SCPs, so attaching a deny s3:DeleteBucket SCP to the Developers OU prevents users in that OU from deleting buckets while leaving the management account root unaffected. This matches the requirement exactly.

Exam trap

The trap is thinking SCPs can be conditioned to exempt the root user or that member-account root users are exempt — SCPs do not apply to the management account at all, and they do apply to member account roots.

How to eliminate wrong answers

Option A is wrong because an IAM policy attached to users does not cover all principals (roles, federated users) and the root user of the management account is not affected by IAM policies, but the requirement is to exempt only the management account root — the IAM approach is incomplete and does not use the Organizations control plane. Option C is wrong because SCPs do not support 'except when called by root user' conditions in that form; SCP conditions cannot reliably identify the management account root in the way described, and SCPs do not apply to the management account anyway. Option D is wrong because the root user in member accounts IS affected by SCPs, so the statement is factually incorrect.

596
MCQeasy

A company wants to provide temporary security credentials to a mobile application so it can access an S3 bucket. Which AWS service should be used to issue these credentials?

A.Amazon Cognito
B.AWS Key Management Service (KMS)
C.AWS Security Token Service (STS)
D.AWS Identity and Access Management (IAM)
AnswerC

AWS Security Token Service (STS) is the authoritative AWS service that vends temporary security credentials, returning an access key, a secret key, a session token, and an expiration timestamp. It provides APIs such as AssumeRole, GetFederationToken, AssumeRoleWithSAML, and AssumeRoleWithWebIdentity to support cross-account access, role delegation, and identity federation. These credentials automatically expire and carry the permissions of the assumed role, which is exactly what the company needs for short-lived, limited-privilege access.

Why this answer

AWS Security Token Service (STS) is specifically designed to generate temporary security credentials for users and applications. Option A is incorrect: Amazon Cognito can issue temporary credentials via identity pools, but STS is the direct service for temporary credentials. Option B is incorrect: AWS KMS manages encryption keys, not credentials.

Option D is incorrect: IAM manages long-term user credentials, not temporary ones.

597
MCQmedium

A SysOps administrator needs to audit all IAM user activity in the AWS account for the last 90 days. Which AWS service should be used?

A.AWS Config
B.AWS Trusted Advisor
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerC

AWS CloudTrail is the correct service for auditing IAM user activity because it records every AWS API call as a CloudTrail event, including who made the request (IAM user or role), when it was made, from which source IP, and what action was performed. By enabling a trail that delivers events to an S3 bucket (and optionally CloudWatch Logs), you capture a complete, tamper-evident history of all IAM user activity for security analysis and operational troubleshooting. CloudTrail also supports logging both management events, such as CreateUser or AttachUserPolicy, and data events, giving you the audit coverage necessary to answer 'who did what' in your account.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made by IAM users, including console sign-in events, CLI commands, and SDK actions, and retains these logs for up to 90 days by default in the event history. This allows the SysOps administrator to audit all IAM user activity over the last 90 days without additional configuration.

Exam trap

The trap here is that candidates confuse AWS Config's configuration tracking with CloudTrail's API activity logging, or assume GuardDuty's threat detection includes a built-in audit trail for all user actions.

How to eliminate wrong answers

Option A is wrong because AWS Config is used for evaluating resource configurations against desired policies and tracking configuration changes, not for recording API-level user activity. Option B is wrong because AWS Trusted Advisor provides best-practice recommendations for cost, performance, security, and fault tolerance, but does not log or audit IAM user actions. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not provide a direct audit trail of all IAM user activity.

598
MCQmedium

A company uses AWS CloudFormation to deploy its infrastructure. The SysOps administrator needs to ensure that the application stack can be recreated in another AWS Region in the event of a disaster. The stack includes an RDS MySQL database and an EC2 instance running a web server. The administrator wants to automate the backup of the RDS database and the EC2 instance configuration. What is the MOST efficient way to achieve this?

A.Use S3 to store database dump files and instance configuration scripts.
B.Create manual snapshots of the RDS database and EC2 instance every day and copy them to the secondary region.
C.Store the CloudFormation template in S3 and use it to recreate the stack in the secondary region.
D.Use AWS Backup to create backup plans that include the RDS instance and EC2 instance, and copy backups to the secondary region.
AnswerD

AWS Backup provides a fully managed, policy-based backup solution that can target both RDS instances and EC2 instances (via Amazon Machine Images) within a single backup plan. You can schedule automated backups, apply retention and lifecycle policies, and configure cross-region replication to the secondary region, ensuring consistent disaster recovery without custom scripting or manual snapshots. This is the most efficient and reliable approach because it centralizes backup management and automates the entire DR copy process.

Why this answer

AWS Backup provides a centralized, automated way to create backup plans that include both RDS and EC2 instances, and it supports cross-region backup copies. This meets the requirement to automate backups and ensure they are available in a secondary region for disaster recovery. It is the most efficient because it eliminates manual scripting and snapshot management.

Exam trap

SOA-C02 often tests the difference between infrastructure-as-code recreation and data backup; candidates may choose CloudFormation template storage thinking it covers backups, but it does not protect data.

How to eliminate wrong answers

Option A is wrong because using S3 to store database dump files and configuration scripts requires manual or scripted processes, which is not automated and may not ensure consistency. Option B is wrong because creating manual snapshots daily is not automated and is error-prone; it also does not cover EC2 instance configuration in a unified way. Option C is wrong because storing the CloudFormation template in S3 only allows recreating the stack, but it does not automate backups of the RDS database or EC2 instance configuration; it addresses infrastructure recreation, not data backup.

599
MCQeasy

A company wants to use Amazon CloudFront to serve content from an Application Load Balancer (ALB) that is internet-facing. Which type of origin should be configured in CloudFront?

A.S3 origin with the ALB's DNS name as the bucket name.
B.Custom origin with Origin Access Identity (OAI) to restrict access.
C.Custom origin (HTTP/HTTPS) pointing to the ALB DNS name.
D.Custom origin pointing to the ALB's private IP address.
AnswerC

An Application Load Balancer is an HTTP/HTTPS endpoint, so the correct way to attach it to CloudFront is as a custom origin, entering the ALB's DNS name (e.g., my-alb-1234567890.us-east-1.elb.amazonaws.com) rather than a bucket name or IP address. CloudFront then sends requests to that public DNS name and can resolve it from edge locations, forwarding the original request or the configured cache behavior. This is the standard pattern for accelerating dynamic or mixed content served through an ALB, and it also works with any load balancer that exposes a public DNS endpoint.

Why this answer

CloudFront requires a custom origin (HTTP/HTTPS) when the origin is an Application Load Balancer (ALB) because ALBs are not S3 buckets and do not support S3 origin configurations. The custom origin type allows CloudFront to forward requests to the ALB's public DNS name, which resolves to the ALB's IP addresses, enabling proper load balancing and content delivery.

Exam trap

The trap here is that candidates may mistakenly think an ALB can be configured as an S3 origin or that OAI applies to non-S3 origins, but CloudFront strictly requires a custom origin for ALBs and OAI is only valid for S3 bucket origins.

How to eliminate wrong answers

Option A is wrong because an S3 origin expects an S3 bucket endpoint, not an ALB DNS name; using an ALB DNS name as a bucket name would cause a configuration error. Option B is wrong because Origin Access Identity (OAI) is used exclusively with S3 origins to restrict access to S3 content, not with ALB origins; for ALBs, you would use custom headers or AWS WAF to restrict access. Option D is wrong because CloudFront cannot use private IP addresses as origins; the ALB must be internet-facing with a public DNS name for CloudFront to reach it over the internet.

600
MCQmedium

A company has an Amazon DynamoDB table with on-demand capacity mode. The SysOps administrator needs to ensure that the table can survive a regional outage. The table is currently in us-east-1. Which feature should be configured to achieve regional resilience with minimal data loss?

A.DynamoDB Accelerator (DAX)
B.DynamoDB global tables
C.DynamoDB point-in-time recovery
D.DynamoDB auto scaling
AnswerB

DynamoDB global tables replicate your table automatically across multiple AWS Regions using DynamoDB Streams, creating a multi-active, fully managed solution. In the event of a regional outage, applications can read and write to the table in another Region with minimal downtime because each replica is independently accessible. Global tables use last-writer-wins conflict resolution to reconcile concurrent updates, providing eventual consistency and effectively meeting disaster recovery needs with a low RTO and RPO.

Why this answer

DynamoDB global tables provide multi-Region, fully replicated tables that automatically propagate writes to all configured Regions, enabling the table to survive a regional outage with minimal data loss. This feature uses DynamoDB Streams to replicate data asynchronously across Regions, offering recovery point objectives (RPO) of typically under one second. For the requirement of regional resilience, global tables are the correct choice because they maintain active copies in multiple AWS Regions.

Exam trap

The trap here is that candidates often confuse point-in-time recovery (PITR) with cross-Region disaster recovery, not realizing that PITR only protects against accidental deletes or corruption within a single Region, not a full regional outage.

How to eliminate wrong answers

Option A is wrong because DynamoDB Accelerator (DAX) is an in-memory cache that improves read performance but does not provide any cross-Region replication or regional resilience. Option C is wrong because point-in-time recovery (PITR) enables restoring a table to any point within the last 35 days within the same Region, but it does not protect against a regional outage since the backups are stored in the same Region. Option D is wrong because DynamoDB auto scaling adjusts read/write capacity based on traffic but does not replicate data across Regions or provide any disaster recovery capability.

Page 7

Page 8 of 16

Page 9