Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Amazon AWS Certified Solutions Architect - Professional Exam SAP-C02 Exam Questions

Page: 1 / 47 Total 691 questions

Want more questions? Get Premium Access.

Question 1

A company runs applications in hundreds of production AWS accounts. The company uses AWS Organizations with all features enabled and has a centralized backup

operation that uses AWS Backup.

The company is concerned about ransomware attacks. To address this concern, the company has created a new policy that all backups must be resilient to breaches of privileged-user credentials in any production account.

Which combination of steps will meet this new requirement? (Select THREE.)

Correct Answer: A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts.; B. Add an SCP that restricts the modification of AWS Backup vaults.; C. Implement AWS Backup Vault Lock in compliance mode.
Explanation:

To make backups resilient to compromised credentials in production accounts:

  • AWS Backup Vault Lock (Compliance Mode): Prevents anyone, even root users or administrators with compromised credentials, from deleting backups. Compliance mode cannot be overridden. This is the primary defense against ransomware attacks.
  • MFA Delete on backup storage S3 buckets: Requires multi-factor authentication to delete backup data, adding an additional layer of protection even if credentials are compromised. Prevents simple credential-based deletion.
  • Deny-based IAM policies: Create explicit deny statements in SCPs or IAM policies that deny backup deletion and modification actions to production account roles. This prevents privilege escalation attacks from modifying permissions to allow deletion.
  • Why these three together: Backup Vault Lock prevents deletion; MFA Delete adds verification requirement; IAM deny policies prevent permission changes. Layered defense ensures ransomware cannot destroy backups even with compromised privileged credentials.

This multi-layered approach addresses the specific threat of privileged credential compromise in production accounts.

Question 2

A company is modernizing a legacy.NET Frameworkapplication backed by SQL Server. Requirements:

Containerize into microservices.

Control OS patches and storage.

Add load balancing.

Ensure high availability.Which solution meets all of these with minimal refactoring?

Correct Answer: A. Use App2Container to deploy on ECS EC2 with ALB and RDS for SQL Server.
Explanation:

A is correct because:

App2Containersupports packaging .NET Framework apps into containers without porting to .NET Core.

ECS with EC2gives full control over the OS and patching.

ALBhandles microservice-level load balancing.

RDS for SQL Serverwith Multi-AZ ensures high availability.

Options B, C, and D involve Aurora MySQL (incompatible with SQL Server features) orrequire .NET Core, which involves more significant application changes.


App2Container Overview

ECS EC2 vs Fargate

Question 3

A startup company hosts a fleet of Amazon EC2 instances in private subnets using the latest Amazon Linux 2 AMI. The company's engineers rely heavily on SSH access to the instances for troubleshooting.

The company's existing architecture includes the following:

* A VPC with private and public subnets, and a NAT gateway

* Site-to-Site VPN for connectivity with the on-premises environment

* EC2 security groups with direct SSH access from the on-premises environment

The company needs to increase security controls around SSH access and provide auditing of commands executed by the engineers.

Which strategy should a solutions architect use?

Correct Answer: D. Create an IAM role with the AmazonSSMManagedInstanceCore managed policy attached. Attach the IAM role to all the EC2 instances. Remove all security group rules attached to the EC2 instances that allow inbound TCP on port 22. Have the engineers install the AWS Systems Manager Session Manager plugin for their devices and remotely access the instances by using the start-session API call from Systems Manager.
Explanation:

Allows client machines to be able to connect to Session Manager using the AWS CLI instead of going through the AWS EC2 or AWS Server Manager console. https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-working-with-install-plugin.htmlhttps://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-working-with-install-plugin.html#:~:text=aws%20ssm%20start%2Dsession%20%2D%2Dtarget%20instance%2Did


Question 4

A company is running a containerized application in the AWS Cloud. The application is running by using Amazon Elastic Container Service (Amazon ECS) on a set of Amazon EC2 instances. The EC2 instances run in an Auto Scaling group.

The company uses Amazon Elastic Container Registry (Amazon ECR) to store its container images. When a new image version is uploaded, the new image version receives a unique tag.

The company needs a solution that inspects new image versions for common vulnerabilities and exposures. The solution must automatically delete new image tags that have Critical or High severity findings. The solution also must notify the development team when such a deletion occurs.

Which solution meets these requirements?

Correct Answer: A. Configure scan on push on the repository Use Amazon EventBridge to invoke an AWS Step Functions state machine when a scan is complete for images that have Critical or High severity findings. Use the Step Functions state machine to delete the image tag for those images and to notify the development team through Amazon Simple Notification Service (Amazon SNS).
Explanation:

https://docs.aws.amazon.com/AmazonECR/latest/userguide/ecr-eventbridge.html 'Activating an AWS Step Functions state machine'https://docs.aws.amazon.com/step-functions/latest/dg/tutorial-creating-lambda-state-machine.html


Question 5

A company is storing sensitive data in an Amazon S3 bucket. The company must log all activities for objects in the S3 bucket and must keep the logs for 5 years. The company's security team also must receive an email notification every time there is an attempt to delete data in the S3 bucket.

Which combination of steps will meet these requirements MOST cost-effectively? (Select THREE.)

Correct Answer: A. Configure AWS CloudTrail to log S3 data events.; D. Configure Amazon S3 to send object deletion events to an Amazon EventBridge event bus that publishes to an Amazon Simple Notification Service (Amazon SNS) topic.; F. Configure a new S3 bucket to store the logs with an S3 Lifecycle policy.
Explanation:

Configuring AWS CloudTrail to log S3 data events will enable logging all activities for objects in the S3 bucket1. Data events are object-level API operations such as GetObject, DeleteObject, and PutObject1. Configuring Amazon S3 to send object deletion events to an Amazon EventBridge event bus that publishes to an Amazon Simple Notification Service (Amazon SNS) topic will enable sending email notifications every time there is an attempt to delete data in the S3 bucket2. EventBridge can route events from S3 to SNS, which can send emails to subscribers2. Configuring a new S3 bucket to store the logs with an S3 Lifecycle policy will enable keeping the logs for 5 years in a cost-effective way3. A lifecycle policy can transition the logs to a cheaper storage class such as Glacier or delete them after a specified period of time3.


Question 6

A company has loT sensors that monitor traffic patterns throughout a large city. The company wants to read and collect data from the sensors and perform aggregations on the data.

A solutions architect designs a solution in which the loT devices are streaming to Amazon Kinesis Data Streams. Several applications are reading from the stream. However, several consumers are experiencing throttling and are periodically and are periodically encountering a RealProvisioned Throughput Exceeded error.

Which actions should the solution architect take to resolve this issue? (Select THREE.)

Correct Answer: A. Reshard the stream to increase the number of shards s in the stream.; C. Use consumers with the enhanced fan-out feature.; E. Use an error retry and exponential backoff mechanism in the consumer logic.
Explanation:

https://repost.aws/knowledge-center/kinesis-readprovisionedthroughputexceeded

Follow Data Streams best practices

To mitigate ReadProvisionedThroughputExceeded exceptions, apply these best practices:

* Reshard your stream to increase the number of shards in the stream.

* Use consumers with enhanced fan-out. For more information about enhanced fan-out, see Developing custom consumers with dedicated throughput (enhanced fan-out).

* Use an error retry and exponential backoff mechanism in the consumer logic if ReadProvisionedThroughputExceeded exceptions are encountered. For consumer applications that use an AWS SDK, the requests are retried by default.


Question 7

A company has dozens of AWS accounts for different teams, applications, and environments. The company has defined a custom set of controls that all accounts must have. The company is concerned that potential misconfigurations in the accounts could lead to security issues or noncompliance. A solutions architect must design a solution that deploys the custom controls by using infrastructure as code (IaC) in a repeatable way. Which solution will meet these requirements with the LEAST operational overhead?

Correct Answer: C. Enable AWS Control Tower to set up and govern the multi-account environment. Use blueprints that enforce security best practices. Use Customizations for AWS Control Tower and CloudFormation templates to define the custom controls for each account. Use Amazon EventBridge to deploy Customizations for AWS Control Tower during account-provisioning lifecycle events.
Explanation:

Comprehensive and Detailed

Option C offers a scalable and low-overhead solution for managing custom controls across multiple AWS accounts:

AWS Control Tower provides a pre-configured environment to set up and govern a secure, multi-account AWS environment based on AWS best practices.

Customizations for AWS Control Tower (CfCT) allows for the deployment of custom configurations and resources, such as AWS Config rules and IAM policies, across accounts and organizational units using AWS CloudFormation templates.

Amazon EventBridge integrates with AWS Control Tower to automate the deployment of customizations during account provisioning events, ensuring that all new accounts adhere to the defined controls without manual intervention.

This approach ensures consistent enforcement of custom controls across all accounts with minimal operational overhead.


AWS Control Tower: Automates the setup of a baseline environment, or landing zone, that is a secure, well-architected multi-account AWS environment.

Customizations for AWS Control Tower: Enables you to customize your AWS Control Tower landing zone using AWS CloudFormation templates and service control policies (SCPs).

Amazon EventBridge: A serverless event bus that makes it easier to build event-driven applications at scale using events generated from your applications, integrated SaaS applications, and AWS services.

Question 8

A company is running a data-intensive application on AWS. The application runs on a cluster of hundreds of Amazon EC2 instances. A shared file system also runs on several EC2 instances that store 200 TB of data. The application reads and modifies the data on the shared file system and generates a report. The job runs once monthly, reads a subset of the files from the shared file system, and takes about 72 hours to complete. The compute instances scale in an Auto Scaling group, but the instances that host the shared file system run continuously. The compute and storage instances are all in the same AWS Region.

A solutions architect needs to reduce costs by replacing the shared file system instances. The file system must provide high performance access to the needed data for the duration of the 72-hour run.

Which solution will provide the LARGEST overall cost reduction while meeting these requirements?

Correct Answer: A. Migrate the data from the existing shared file system to an Amazon S3 bucket that uses the S3 Intelligent-Tiering storage class. Before the job runs each month, use Amazon FSx for Lustre to create a new file system with the data from Amazon S3 by using lazy loading. Use the new file system as the shared storage for the duration of the job. Delete the file system when the job is complete.
Explanation:

https://aws.amazon.com/blogs/storage/new-enhancements-for-moving-data-between-amazon-fsx-for-lustre-and-amazon-s3/


Question 9

A company wants to use Amazon Workspaces in combination with thin client devices to replace aging desktops. Employees use the desktops to access applications that work with clinical trial data. Corporate security policy states that access to the applications must be restricted to only company branch office locations. The company is considering adding an additional branch office in the next 6 months.

Which solution meets these requirements with the MOST operational efficiency?

Correct Answer: A. Create an IP access control group rule with the list of public addresses from the branch offices. Associate the IP access control group with the Workspaces directory.
Explanation:

Utilizing an IP access control group rule with the list of public addresses from branch offices and associating it with the Amazon WorkSpaces directory is the most operationally efficient solution. This method ensures that access to WorkSpaces is restricted to specified locations, aligning with the corporate security policy. This approach offers simplicity and flexibility, especially with the potential addition of a new branch office, as updating the IP access control group is straightforward.

AWS Documentation on Amazon WorkSpaces and IP Access Control Groups provides detailed instructions on how to implement access restrictions based on IP addresses. This solution aligns with best practices for securing virtual desktops while maintaining operational efficiency.


Question 10

A company creates an Amazon API Gateway API and shares the API with an external development team. The API uses AWS Lambda functions and is deployed to a stage that is named Production.

The external development team is the sole consumer of the API. The API experiences sudden increases of usage at specific times, leading to concerns about increased costs. The company needs to limit cost and usage without reworking the Lambda functions.

Which solution will meet these requirements MOST cost-effectivery?

Correct Answer: D. Create an API Gateway API key and usage plan. Define throttling limits and quotas in the usage plan. Associate the usage plan with the Production stage and the API key. Share the API key with the external development team.
Explanation:

API Gateway usage plans with API keys provide a cost-effective way to throttle requests and limit usage without modifying Lambda functions. Usage plans allow the company to set request rate limits and quotas per API key, which directly controls consumption and associated costs. This is the most straightforward solution that doesn't require reworking Lambda functions. Alternative approaches like Reserved Concurrency would still incur costs for unused capacity, making usage plans the most cost-effective choice for limiting both usage and costs.

Question 11

A company operates a fleet of servers on premises and operates a fleet of Amazon EC2 instances in its organization in AWS Organizations. The company's AWS accounts contain hundreds of VPCs. The company wants to connect its AWS accounts to its on-premises network. AWS Site-to-Site VPN connections are already established to a single AWS account. The company wants to control which VPCs can communicate with other VPCs.

Which combination of steps will achieve this level of control with the LEAST operational effort? (Choose three.)

Correct Answer: A. Create a transit gateway in an AWS account. Share the transit gateway across accounts by using AWS Resource Access Manager (AWS RAM).; B. Configure attachments to all VPCs and VPNs.; C. Set up transit gateway route tables. Associate the VPCs and VPNs with the route tables.
Explanation:

To connect on-premises network to hundreds of VPCs across multiple accounts with centralized control:

  • AWS Transit Gateway: Acts as a central hub for connecting VPCs and on-premises networks. Dramatically reduces operational complexity compared to managing individual VPN or peering connections
  • Transit Gateway attachments: Create attachments from Transit Gateway to each account's VPCs, allowing them to share the on-premises connectivity
  • Existing VPN integration: Connect the existing Site-to-Site VPN to Transit Gateway instead of a single VPC. Transit Gateway then distributes traffic to appropriate VPCs
  • Transit Gateway route tables: Use separate route tables to control which VPCs can communicate with other VPCs and on-premises networks. This provides the granular control requested while keeping operational effort minimal
  • Organization integration: Works with AWS Organizations for centralized management

This approach scales to hundreds of VPCs with minimal operational overhead compared to managing individual connections.

Question 12

A company has an asynchronous HTTP application that is hosted as an AWS Lambda function. A public Amazon API Gateway endpoint invokes the Lambda function. The Lambda function and the API Gateway endpoint reside in the us-east-1 Region. A solutions architect needs to redesign the application to support failover to another AWS Region.

Which solution will meet these requirements?

Correct Answer: B. Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure API Gateway to direct traffic to the SQS queue instead of to the Lambda function. Configure the Lambda function to pull messages from the queue for processing.
Explanation:

This solution allows for deploying the Lambda function and API Gateway endpoint to another region, providing a failover option in case of any issues in the primary region. Using Route 53's failover routing policy allows for automatic routing of traffic to the healthy endpoint, ensuring that the application is available even in case of issues in one region. This solution provides a cost-effective and simple way to implement failover while minimizing operational overhead.


Question 13

A solutions architect wants to cost-optimize and appropriately size Amazon EC2 instances in a single AWS account. The solutions architect wants to ensure that the instances are optimized based on CPU, memory, and network metrics.

Which combination of steps should the solutions architect take to meet these requirements? (Choose two.)

Correct Answer: B. Turn on AWS Trusted Advisor and review any ''Low Utilization Amazon EC2 Instances'' recommendations.; D. Configure AWS Compute Optimizer in the AWS account to receive findings and optimization recommendations.
Explanation:

AWS Trusted Advisor is a service that provides real-time guidance to help users provision their resources following AWS best practices1.One of the Trusted Advisor checks is ''Low Utilization Amazon EC2 Instances'', which identifies EC2 instances that appear to be underutilized based on CPU, network I/O, and disk I/O metrics1. This check can help users optimize the cost and size of their EC2 instances by recommending smaller or more appropriate instance types.

AWS Compute Optimizer is a service that analyzes the configuration and utilization metrics of AWS resources and generates optimization recommendations to reduce the costand improve the performance of workloads2.Compute Optimizer supports four types of AWS resources: EC2 instances, EBS volumes, ECS services on AWSFargate, and Lambdafunctions2.For EC2 instances, Compute Optimizer evaluates the vCPUs, memory, storage, and other specifications, as well as the CPU utilization, network in and out, disk read and write, and other utilization metrics of currently running instances3. It then recommends optimal instance types based on price-performance trade-offs.

Option A is incorrect because purchasing AWS Business Support or AWS Enterprise Support for the account will not directly help with cost-optimization and sizing of EC2 instances.However, these support plans do provide access to more Trusted Advisor checks than the basic support plan1.

Option C is incorrect because installing the Amazon CloudWatch agent and configuring memory metric collection on the EC2 instances will not provide any optimization recommendations by itself.However, memory metrics can be used by Compute Optimizer to enhance its recommendations if enabled3.

Option E is incorrect because creating an EC2 Instance Savings Plan for the AWS Regions, instance families, and operating systems of interest will not help with cost-optimization and sizing of EC2 instances.Savings Plans are a flexible pricing model that offer lower prices on Amazon EC2 usage in exchange for a commitment to a consistent amount of usage for a 1- or 3-year term4. Savings Plans do not affect the configuration or utilization of EC2 instances.


Question 14

A company use an organization in AWS Organizations to manage multiple AWS accounts. The company hosts some applications in a VPC in the company's snared services account. The company has attached a transit gateway to the VPC in the Shared services account.

The company is developing a new capability and has created a development environment that requires access to the applications that are in the snared services account. The company intends to delete and recreate resources frequently in the development account. The company also wants to give a development team the ability to recreate the team's connection to the shared services account as required.

Which solution will meet these requirements?

Correct Answer: B. Turn on automate acceptance for the transit gateway in the shared services account. Use AWS Resource Access Manager (AWS RAM) to share the transit gateway resource in the shared services account with the development account. Accept the resource in tie development account. Create a transit gateway attachment in the development account.
Explanation:

For a development environment that requires frequent resource recreation and connectivity to applications hosted in a shared services account, the most efficient solution involves using AWS Resource Access Manager (RAM) and the transit gateway in the shared services account. By turning on automatic acceptance for the transit gateway in the shared services account and sharing it with the development account through AWS RAM, the development team can easily recreate their connection as needed without manual intervention. This setup allows for scalable, flexible connectivity between accounts while minimizing operational overhead and ensuring consistent access to shared services.

AWS Documentation on AWS Resource Access Manager and Transit Gateway provides guidance on sharing network resources across AWS accounts and enabling automatic acceptance for transit gateway attachments. This approach is also supported by AWS best practices for multi-account strategies using AWS Organizations and network architecture.


Question 15

A company is implementing a CI/CD pipeline for containerized applications by using Amazon ECR. The company needs a solution that provides automated vulnerability scanning of all container images and the ability to prioritize remediation based on actual deployment status. The solution must scan repositories for operating system and programming language vulnerabilities. The solution must provide continuous monitoring as new Common Vulnerabilities and Exposures (CVEs) are discovered and integrate the findings into the company's existing event-driven workflow.

Which solution will meet these requirements with the LEAST operational overhead?

Correct Answer: D. Turn on Amazon ECR enhanced scanning. Integrate enhanced scanning with Amazon Inspector. Configure continuous scanning for repositories. Use Amazon Inspector to track the deployment status of container images. Configure Amazon EventBridge rules to capture Amazon Inspector findings and route the findings to the company's existing event-driven workflow.
Explanation:

The requirements are: (1) Automated vulnerability scanning of container images (OS and language package vulnerabilities), (2) Prioritization based on deployment status, (3) Continuous monitoring of new CVEs, (4) Integration into event-driven workflows, (5) Least operational overhead. The solution: (1) Enable Amazon ECR image scanning on all repositories—it scans images automatically when pushed for OS and language package vulnerabilities, (2) Use ECR's native deployment status feature to prioritize findings based on whether images are deployed in production, staging, or development, (3) Enable continuous monitoring in ECR so new CVE definitions automatically rescan existing images, (4) Configure Amazon EventBridge to trigger on ECR scan findings (via EventBridge rule for ECR vulnerability events), routing findings to SNS, Lambda, or SIEM integrations. This is entirely native to ECR with no additional scanning tools or custom orchestration needed, providing the least operational overhead.