Courseiva
← Back to AWS Certified SysOps Administrator Associate SOA-C02 questions

Scenario-based practice

Hard Difficulty Questions

Practise AWS Certified SysOps Administrator Associate SOA-C02 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
SOA-C02
exam code
Amazon Web Services
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SOA-C02 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A SysOps administrator is managing a fleet of EC2 instances in an Auto Scaling group. The instances are behind an Application Load Balancer. The administrator notices that the 'SurgeQueueLength' metric for the ALB is frequently high. What does this indicate, and what is the BEST remediation action?

Question 2hardmulti select
Full question →

Which THREE measures help protect an S3 bucket from accidental data loss? (Choose 3)

Question 3hardmultiple choice
Full question →

A company runs a critical production workload on a fleet of EC2 instances managed by an Auto Scaling group. The instances are behind an Application Load Balancer (ALB). Recently, the company experienced a regional outage that caused all instances to become unhealthy. The SysOps administrator must design a solution to automatically recover from such an outage with minimal downtime. The solution must be cost-effective and not require manual intervention. The administrator considers four options. Which option meets the requirements?

Question 4hardmultiple choice
Full question →

A company runs a critical stateful web application on Amazon EC2 instances in a single AWS region. The application stores user session data in an Amazon ElastiCache for Redis cluster. The SysOps administrator must design a disaster recovery (DR) strategy that can survive a complete regional outage with a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. The application must be able to redirect users to the DR region with minimal manual effort. Which combination of actions meets these requirements?

Question 5hardmultiple choice
Full question →

A company runs a critical database workload on an Amazon RDS for MySQL DB instance with Multi-AZ deployment in the us-east-1 region. The SysOps administrator must design a disaster recovery strategy that can recover from a complete regional outage. The Recovery Time Objective (RTO) is 2 hours and the Recovery Point Objective (RPO) is 1 hour. Which solution meets these requirements at the lowest cost?

Question 6hardmultiple choice
Full question →

A company uses AWS Organizations to manage multiple AWS accounts. The security team wants to restrict access to a specific AWS service (Amazon EC2) in all accounts except for the 'production' account. The SysOps administrator needs to implement this restriction centrally. Which approach should the administrator use?

Question 7hardmultiple choice
Full question →

A CloudFormation stack manages an RDS database, an S3 bucket, and several Lambda functions. During a recent stack update, a property change caused CloudFormation to replace the RDS instance, deleting the database and re-creating it — resulting in data loss. The team wants to prevent any future stack update from replacing or deleting the RDS instance without an explicit override. What CloudFormation feature accomplishes this?

Question 8hardmultiple choice
Full question →

A SysOps administrator uses AWS CloudFormation to deploy infrastructure. The admin has a template that creates an EC2 instance with a custom software stack. The software stack must be installed and configured using PowerShell scripts. The admin wants to minimize operational overhead by automating the creation of an AMI that includes the software stack, and the AMI should be rebuilt on a weekly basis to include the latest security patches. Which combination of AWS services should be used?

Question 9hardmultiple choice
Full question →

A company uses AWS Organizations and has multiple accounts. The security team requires that all Amazon S3 buckets across all accounts must be encrypted at rest with AWS KMS (SSE-KMS). The SysOps administrator needs to automatically detect non-compliant buckets and remediate them by enabling SSE-KMS. The solution must work across all existing and future accounts. Which AWS service should be used?

Question 10hardmultiple choice
Full question →

A company runs a critical application on Amazon EC2 instances across multiple Availability Zones. The application stores state data on a shared Amazon EFS file system. The SysOps administrator needs to ensure that the file system remains available if an entire Availability Zone fails. The file system must also provide low-latency access from all instances. Which configuration meets these requirements?

Question 11hardmultiple choice
Full question →

A company uses Amazon CloudFront to deliver content to a global audience. The origin is an Application Load Balancer in us-east-1. The SysOps administrator wants to reduce costs by minimizing the number of requests that reach the origin server. Which action should the administrator take?

Question 12hardmultiple choice
Full question →

A company runs a critical application on a fleet of EC2 instances that process real-time financial transactions. The application requires consistent low latency. The SysOps administrator notices that the application's latency increases periodically due to noisy neighbors. The administrator wants to optimize performance predictability. Which instance type should the administrator choose?

Question 13hardmultiple choice
Open the full VLAN trunking answer →

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The data center has multiple VLANs that need to connect to separate VPCs in AWS. The company wants to maintain isolation between the VPCs while maximizing bandwidth utilization. Which solution should the SysOps administrator recommend?

Question 14hardmultiple choice
Full question →

A SysOps administrator examines the output of the describe-alarms command for the 'HighCPU' alarm. The alarm is in ALARM state. What action will be taken automatically?

Network Topology
$ aws cloudwatch describe-alarmsalarm-names "HighCPU"Refer to the exhibit."CompositeAlarms": [],"MetricAlarms": ["AlarmName": "HighCPU","AlarmArn": "arn:aws:cloudwatch:us-east-1:123456789012:alarm:HighCPU","AlarmConfigurationUpdatedTimestamp": "2023-01-15T10:30:00.000Z","StateValue": "ALARM","StateUpdatedTimestamp": "2023-01-15T10:35:00.000Z","MetricName": "CPUUtilization","Namespace": "AWS/EC2","Statistic": "Average","Period": 300,"EvaluationPeriods": 1,"Threshold": 90.0,"AlarmActions": ["arn:aws:automate:us-east-1:ec2:recover"],"OKActions": [],"InsufficientDataActions": []
Question 15hardmultiple choice
Full question →

A company is deploying a critical application using AWS CloudFormation. The deployment must be resilient to failures and ensure that resources are created in a specific order. The template defines a stack that includes an Amazon RDS database and an Auto Scaling group. The Auto Scaling group depends on the database being available. Which CloudFormation feature should the SysOps administrator use to ensure the database is fully created and available before the Auto Scaling group is created?

Question 16hardmultiple choice
Full question →

A company runs a web application on Amazon EC2 instances. The application's traffic pattern is unpredictable, often spiking to 3x normal load for short periods. The SysOps administrator needs to ensure that the application can handle spikes without performance degradation while minimizing costs. Which combination of purchasing options and scaling strategies should the administrator use?

Question 17hardmultiple choice
Read the full NAT/PAT explanation →

A SysOps Administrator manages a VPC with public and private subnets. The private subnets need to access the internet for software updates. The Administrator creates a NAT Gateway in a public subnet and updates the private subnet route table to point 0.0.0.0/0 to the NAT Gateway. However, instances in the private subnet still cannot reach the internet. What is the MOST likely reason?

Question 18hardmultiple choice
Full question →

An application runs on EC2 instances in an Auto Scaling group. The instances process messages from an SQS queue. To ensure high availability, the SysOps administrator has configured the Auto Scaling group to span three Availability Zones. However, during a recent failure of one AZ, the application experienced a temporary increase in processing latency. What is the MOST likely cause of this latency?

Question 19hardmulti select
Full question →

A company uses Amazon S3 to store backups and logs. The total data volume is 50 TB and grows by 2 TB per month. The company requires that data be retained for 7 years. Which THREE actions will optimize storage costs? (Choose THREE.)

Question 20hardmultiple choice
Full question →

A company is using AWS Elastic Beanstalk to deploy a web application. The application requires a custom Amazon Machine Image (AMI) that includes specific software. The administrator creates a custom AMI and configures the Elastic Beanstalk environment to use it. However, new instances launched during scaling use the default platform AMI instead. What is the MOST likely cause?

These SOA-C02 practice questions are part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style SOA-C02 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.