DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free AWS SAP-C02 Practice Questions & Answers 2026 Part3

Are you preparing for the AWS SAP-C02 certification exam? SPOTO offers the AWS SAP-C02 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
A company is running an application in the AWS Cloud. The application collects and stores a large amount of unstructured data in an Amazon S3 bucket. The S3 bucket contains several terabytes of data and uses the S3 Standard storage class. The data increases in size by several gigabytes every day.The company needs to query and analyze the data. The company does not access data that is more than 1 year old. However, the company must retain all the data indefinitely for compliance reasons.Which solution will meet these requirements MOST cost-effectively?
A. Use S3 Select to query the data
B. Use Amazon Redshift Spectrum to query the data
C. Use an AWS Glue Data Catalog and Amazon Athena to query the data
D. Use Amazon Redshift Spectrum to query the data
View answer
Correct Answer: C

View The Updated SAP-C02 Exam Questions

SPOTO Provides 100% Real SAP-C02 Exam Questions for You to Pass Your SAP-C02 Exam!

Question #2
A company is running an application in the AWS Cloud. The application collects and stores a large amount of unstructured data in an Amazon S3 bucket. The S3 bucket contains several terabytes of data and uses the S3 Standard storage class. The data increases in size by several gigabytes every day.The company needs to query and analyze the data. The company does not access data that is more than 1 year old. However, the company must retain all the data indefinitely for compliance reasons.Which solution will meet these requirements MOST cost-effectively?
A. Use S3 Select to query the data
B. Use Amazon Redshift Spectrum to query the data
C. Use an AWS Glue Data Catalog and Amazon Athena to query the data
D. Use Amazon Redshift Spectrum to query the data
View answer
Correct Answer: C
Question #3
A video streaming company recently launched a mobile app for video sharing. The app uploads various files to an Amazon S3 bucket in the us-east-1 Region. The files range in size from 1 GB to 10 GB.Users who access the app from Australia have experienced uploads that take long periods of time. Sometimes the files fail to completely upload for these users. A solutions architect must improve the app’s performance for these uploads.Which solutions will meet these requirements? (Choose two.)
A. Enable S3 Transfer Acceleration on the S3 bucket
B. Configure an S3 bucket in each Region to receive the uploads
C. Set up Amazon Route 53 with latency-based routing to route the uploads to the nearest S3 bucket Region
D. Configure the app to break the video files into chunks
E. Modify the app to add random prefixes to the files before uploading
View answer
Correct Answer: AD
Question #4
A company with global offices has a single 1 Gbps AWS Direct Connect connection to a single AWS Region. The company’s on-premises network uses the connection to communicate with the company’s resources in the AWS Cloud. The connection has a single private virtual interface that connects to a single VPC.A solutions architect must implement a solution that adds a redundant Direct Connect connection in the same Region. The solution also must provide connectivity to other Regions through the same pair of Direct Connect connections as the company expands into other Regions.Which solution meets these requirements?
A. Provision a Direct Connect gateway
B. Keep the existing private virtual interface
C. Keep the existing private virtual interface
D. Provision a transit gateway
View answer
Correct Answer: A
Question #5
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #6
A company is refactoring its on-premises order-processing platform in the AWS Cloud. The platform includes a web front end that is hosted on a fleet of VMs, RabbitMQ to connect the front end to the backend, and a Kubernetes cluster to run a containerized backend system to process the orders. The company does not want to make any major changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AMI of the web server VM
B. Create a custom AWS Lambda runtime to mimic the web server environment
C. Create an AMI of the web server VM
D. Create an AMI of the web server VM
View answer
Correct Answer: A
Question #7
A company uses AWS Organizations with a single OU named Production to manage multiple accounts. All accounts are members of the Production OU. Administrators use deny list SCPs in the root of the organization to manage access to restricted services.The company recently acquired a new business unit and invited the new unit’s existing AWS account to the organization. Once onboarded, the administrators of the new business unit discovered that they are not able to update existing AWS Config rules to meet the company’s policies.Which option will allow administrators to make changes and continue to enforce the current policies without introducing additional long-term maintenance?
A. Remove the organization’s root SCPs that limit access to AWS Config
B. Create a temporary OU named Onboarding for the new account
C. Convert the organization’s root SCPs from deny list SCPs to allow list SCPs to allow the required services only
D. Create a temporary OU named Onboarding for the new account
View answer
Correct Answer: D
Question #8
A company has an organization in AWS Organizations that has a large number of AWS accounts. One of the AWS accounts is designated as a transit account and has a transit gateway that is shared with all of the other AWS accounts. AWS Site-to-Site VPN connections are configured between all of the company’s global offices and the transit account. The company has AWS Config enabled on all of its accounts.The company’s networking team needs to centrally manage a list of internal IP address ranges that belong to the global offices. Developers will reference this list to gain access to their applications securely.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Create a JSON file that is hosted in Amazon S3 and that lists all of the internal IP address ranges
B. Create a new AWS Config managed rule that contains all of the internal IP address ranges
C. In the transit account, create a VPC prefix list with all of the internal IP address ranges
D. In the transit account, create a security group with all of the internal IP address ranges
View answer
Correct Answer: C
Question #9
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #10
A company plans to refactor a monolithic application into a modern application design deployed on AWS. The CI/CD pipeline needs to be upgraded to support the modern design for the application with the following requirements:-It should allow changes to be released several times every hour.-It should be able to roll back the changes as quickly as possible.Which design will meet these requirements?
A. Deploy a CI/CD pipeline that incorporates AMIs to contain the application and their configurations
B. Specify AWS Elastic Beanstalk to stage in a secondary environment as the deployment target for the CI/CD pipeline of the application
C. Use AWS Systems Manager to re-provision the infrastructure for each deployment
D. Roll out the application updates as part of an Auto Scaling event using prebuilt AMIs
View answer
Correct Answer: B
Question #11
A company is running a traditional web application on Amazon EC2 instances. The company needs to refactor the application as microservices that run on containers. Separate versions of the application exist in two distinct environments: production and testing. Load for the application is variable, but the minimum load and the maximum load are known. A solutions architect needs to design the updated application with a serverless architecture that minimizes operational complexity. Which solution will meet these requirements MOST cost - effectively?
A. Upload the container images to AWS Lambda as functions
B. Upload the container images to Amazon Elastic Container Registry (Amazon ECR)
C. Upload the container images to Amazon Elastic Container Registry (Amazon ECR)
D. Upload the container images to AWS Elastic Beanstalk
View answer
Correct Answer: D
Question #12
A solutions architect needs to advise a company on how to migrate its on-premises data processing application to the AWS Cloud. Currently, users upload input files through a web portal. The web server then stores the uploaded files on NAS and messages the processing server over a message queue. Each media file can take up to 1 hour to process. The company has determined that the number of media files awaiting processing is significantly higher during business hours, with the number of files rapidly declining after business hours.What is the MOST cost-effective migration recommendation?
A. Create a queue using Amazon SQS
B. Create a queue using Amazon MQ
C. Create a queue using Amazon MQ
D. Create a queue using Amazon SQS
View answer
Correct Answer: D
Question #13
A company has migrated Its forms-processing application to AWS. When users interact with the application, they upload scanned forms as files through a web application. A database stores user metadata and references to files that are stored in Amazon S3. The web application runs on Amazon EC2 instances and an Amazon RDS for PostgreSQL database.When forms are uploaded, the application sends notifications to a team through Amazon Simple Notification Service (Amazon SNS). A team member then logs in and processes each form. The team member performs data validation on the form and extracts relevant data before entering the information into another system that uses an API.A solutions architect needs to automate the manual processing of the forms. The solution must provide accurate form extraction. minimize time to market, and minimize tong-term operational overhead.Which solution will meet these requirements?
A. Develop custom libraries to perform optical character recognition (OCR) on the forms
B. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
C. Host a new application tier on EC2 instances
D. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
View answer
Correct Answer: D
Question #14
A company runs a microservice as an AWS Lambda function. The microservice writes data to an on-premises SQL database that supports a limited number of concurrent connections. When the number of Lambda function invocations is too high, the database crashes and causes application downtime. The company has an AWS Direct Connect connection between the company's VPC and the on-premises data center. The company wants to protect the database from crashes.
A. Write the data to an Amazon Simple Queue Service (Amazon SQS) queue
B. Create a new Amazon Aurora Serverless DB cluster
C. Create an Amazon RDS Proxy DB instance
D. Write the data to an Amazon Simple Notification Service (Amazon SNS) topic
View answer
Correct Answer: A
Question #15
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #16
A company’s solutions architect is reviewing a web application that runs on AWS. The application references static assets in an Amazon S3 bucket in the us-east-1 Region. The company needs resiliency across multiple AWS Regions. The company already has created an S3 bucket in a second Region.Which solution will meet these requirements with the LEAST operational overhead?
A. Configure the application to write each object to both S3 buckets
B. Create an AWS Lambda function to copy objects from the S3 bucket in us-east-1 to the S3 bucket in the second Region
C. Configure replication on the S3 bucket in us-east-1 to replicate objects to the S3 bucket in the second Region
D. Configure replication on the S3 bucket in us-east-1 to replicate objects to the S3 bucket in the second Region
View answer
Correct Answer: C
Question #17
A company needs to architect a hybrid DNS solution. This solution will use an Amazon Route 53 private hosted zone for the domain cloud.example.com for the resources stored within VPCs.The company has the following DNS resolution requirements:On-premises systems should be able to resolve and connect to cloud.example.com.All VPCs should be able to resolve cloud.example.com.There is already an AWS Direct Connect connection between the on-premises corporate network and AWS Transit Gateway.Which architecture should the company use to meet these requirements with the HIGHEST performance?
A. ssociate the private hosted zone to all the VPCs
B. ssociate the private hosted zone to all the VPCs
C. ssociate the private hosted zone to the shared services VPCreate a Route 53 outbound resolver in the shared services VPAttach all VPCs to the transit gateway and create forwarding rules in the on-premises DNS server for cloud
D. ssociate the private hosted zone to the shared services VPC
View answer
Correct Answer: A
Question #18
A company is refactoring its on-premises order-processing platform in the AWS Cloud. The platform includes a web front end that is hosted on a fleet of VMs, RabbitMQ to connect the front end to the backend, and a Kubernetes cluster to run a containerized backend system to process the orders. The company does not want to make any major changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AMI of the web server VM
B. Create a custom AWS Lambda runtime to mimic the web server environment
C. Create an AMI of the web server VM
D. Create an AMI of the web server VM
View answer
Correct Answer: A
Question #19
A company has a serverless application comprised of Amazon CloudFront, Amazon API Gateway, and AWS Lambda functions. The current deployment process of the application code is to create a new version number of the Lambda function and run an AWS CLI script to update. If the new function version has errors, another CLI script reverts by deploying the previous working version of the function. The company would like to decrease the time to deploy new versions of the application logic provided by the Lambda functions, and also reduce the time to detect and revert when errors are identified.How can this be accomplished?
A. Create and deploy nested AWS CloudFormation stacks with the parent stack consisting of the AWS CloudFront distribution and API Gateway, and the child stack containing the Lambda function
B. Use AWS SAM and built-in AWS CodeDeploy to deploy the new Lambda version, gradually shift traffic to the new version, and use pre-traffic and post-traffic test functions to verify code
C. Refactor the AWS CLI scripts into a single script that deploys the new Lambda version
D. Create and deploy an AWS CloudFormation stack that consists of a new API Gateway endpoint that references the new Lambda version
View answer
Correct Answer: B
Question #20
A health insurance company stores personally identifiable information (PII) in an Amazon S3 bucket. The company uses server-side encryption with S3 managed encryption keys (SSE-S3) to encrypt the objects. According to a new requirement, all current and future objects in the S3 bucket must be encrypted by keys that the company’s security team manages. The S3 bucket does not have versioning enabled.Which solution will meet these requirements?
A. In the S3 bucket properties, change the default encryption to SSE-S3 with a customer managed key
B. In the S3 bucket properties, change the default encryption to server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
C. In the S3 bucket properties, change the default encryption to server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
D. In the S3 bucket properties, change the default encryption to AES-256 with a customer managed key
View answer
Correct Answer: B
Question #21
A company has many AWS accounts and uses AWS Organizations to manage all of them. A solutions architect must implement a solution that the company can use to share a common network across multiple accounts.The company’s infrastructure team has a dedicated infrastructure account that has a VPC. The infrastructure team must use this account to manage the network. Individual accounts cannot have the ability to manage their own networks. However, individual accounts must be able to create AWS resources within subnets.Which combination of actions should the solutions architect perform to meet these requirements? (Choose two.)
A. Create a transit gateway in the infrastructure account
B. Enable resource sharing from the AWS Organizations management account
C. Create VPCs in each AWS account within the organization in AWS Organizations
D. Create a resource share in AWS Resource Access Manager in the infrastructure account
E. Create a resource share in AWS Resource Access Manager in the infrastructure account
View answer
Correct Answer: BD
Question #22
A company has a legacy application that runs on multiple .NET Framework components. The components share the same Microsoft SQL Server database and communicate with each other asynchronously by using Microsoft Message Queueing (MSMQ).The company is starting a migration to containerized .NET Core components and wants to refactor the application to run on AWS. The .NET Core components require complex orchestration. The company must have full control over networking and host configuration. The application ' s database model is strongly relational.Which solution will meet these requirements?
A. ost the
B. ost the
C. ost the
D. ost the
View answer
Correct Answer: C
Question #23
An adventure company has launched a new feature on its mobile app. Users can use the feature to upload their hiking and rafting photos and videos anytime. The photos and videos are stored in Amazon S3 Standard storage in an S3 bucket and are served through Amazon CloudFront.The company needs to optimize the cost of the storage. A solutions architect discovers that most of the uploaded photos and videos are accessed infrequently after 30 days. However, some of the uploaded photos and videos are accessed frequently after 30 days. The solutions architect needs to implement a solution that maintains millisecond retrieval availability of the photos and videos at the lowest possible cost.Which solution will meet these requirements?
A. Configure S3 Intelligent-Tiering on the S3 bucket
B. Configure an S3 Lifecycle policy to transition image objects and video objects from S3 Standard to S3 Glacier Deep Archive after 30 days
C. Replace Amazon S3 with an Amazon Elastic File System (Amazon EFS) file system that is mounted on Amazon EC2 instances
D. Add a Cache-Control: max-age header to the S3 image objects and S3 video objects
View answer
Correct Answer: A
Question #24
A solutions architect needs to advise a company on how to migrate its on-premises data processing application to the AWS Cloud. Currently, users upload input files through a web portal. The web server then stores the uploaded files on NAS and messages the processing server over a message queue. Each media file can take up to 1 hour to process. The company has determined that the number of media files awaiting processing is significantly higher during business hours, with the number of files rapidly declining after business hours.What is the MOST cost-effective migration recommendation?
A. Create a queue using Amazon SQS
B. Create a queue using Amazon MQ
C. Create a queue using Amazon MQ
D. Create a queue using Amazon SQS
View answer
Correct Answer: D
Question #25
An application is using an Amazon RDS for MySQL Multi-AZ DB instance in the us-east-1 Region. After a failover test, the application lost the connections to the database and could not re-establish the connections. After a restart of the application, the application re-established the connections.A solutions architect must implement a solution so that the application can re-establish connections to the database without requiring a restart.Which solution will meet these requirements?
A. Create an Amazon Aurora MySQL Serverless v1 DB instance
B. Create an RDS proxy
C. Create a two-node Amazon Aurora MySQL DB cluster
D. Create an Amazon S3 bucket
View answer
Correct Answer: B
Question #26
A company runs a new application as a static website in Amazon S3. The company has deployed the application to a production AWS account and uses Amazon CloudFront to deliver the website. The website calls an Amazon API Gateway REST API. An AWS Lambda function backs each API method.The company wants to create a CSV report every 2 weeks to show each API Lambda function’s recommended configured memory, recommended cost, and the price difference between current configurations and the recommendations. The company will store the reports in an S3 bucket.Which solution will meet these requirements with the LEAST development time?
A. Create a Lambda function that extracts metrics data for each API Lambda function from Amazon CloudWatch Logs for the 2-week period
B. Opt in to AWS Compute Optimizer
C. Opt in to AWS Compute Optimizer
D. Purchase the AWS Business Support plan for the production account
View answer
Correct Answer: B
Question #27
A company is running an application in the AWS Cloud. The application collects and stores a large amount of unstructured data in an Amazon S3 bucket. The S3 bucket contains several terabytes of data and uses the S3 Standard storage class. The data increases in size by several gigabytes every day.The company needs to query and analyze the data. The company does not access data that is more than 1 year old. However, the company must retain all the data indefinitely for compliance reasons.Which solution will meet these requirements MOST cost-effectively?
A. Use S3 Select to query the data
B. Use Amazon Redshift Spectrum to query the data
C. Use an AWS Glue Data Catalog and Amazon Athena to query the data
D. Use Amazon Redshift Spectrum to query the data
View answer
Correct Answer: C
Question #28
A company has a multi-tier web application that runs on a fleet of Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group. The ALB and the Auto Scaling group are replicated in a backup AWS Region. The minimum value and the maximum value for the Auto Scaling group are set to zero. An Amazon RDS Multi-AZ DB instance stores the application’s data. The DB instance has a read replica in the backup Region. The application presents an endpoint to end users by using an Amazon Route 53 record.The company needs to reduce its RTO to less than 15 minutes by giving the application the ability to automatically fail over to the backup Region. The company does not have a large enough budget for an active-active strategy.What should a solutions architect recommend to meet these requirements?
A. Reconfigure the application’s Route 53 record with a latency-based routing policy that load balances traffic between the two ALBs
B. Create an AWS Lambda function in the backup Region to promote the read replica and modify the Auto Scaling group values
C. Configure the Auto Scaling group in the backup Region to have the same values as the Auto Scaling group in the primary Region
D. Configure an endpoint in AWS Global Accelerator with the two ALBs as equal weighted targets
View answer
Correct Answer: B
Question #29
A company wants to migrate its data analytics environment from on premises to AWS. The environment consists of two simple Node.js applications. One of the applications collects sensor data and loads it into a MySQL database. The other application aggregates the data into reports. When the aggregation jobs run, some of the load jobs fail to run correctly.The company must resolve the data loading issue. The company also needs the migration to occur without interruptions or changes for the company’s customers.What should a solutions architect do to meet these requirements?
A. Set up an Amazon Aurora MySQL database as a replication target for the on-premises database
B. Set up an Amazon Aurora MySQL database
C. Set up an Amazon Aurora MySQL database
D. Set up an Amazon Aurora MySQL database
View answer
Correct Answer: C
Question #30
A company is using multiple AWS accounts. The DNS records are stored in a private hosted zone for Amazon Route 53 in Account A. The company’s applications and databases are running in Account B.A solutions architect will deploy a two-tier application in a new VPC. To simplify the configuration, the db.example.com CNAME record set for the Amazon RDS endpoint was created in a private hosted zone for Amazon Route 53.During deployment, the application failed to start. Troubleshooting revealed that db.example.com is not resolvable on the Amazon EC2 instance. The solutions architect confirmed that the record set was created correctly in Route 53.Which combination of steps should the solutions architect take to resolve this issue? (Choose two.)
A. Deploy the database on a separate EC2 instance in the new VPC
B. Use SSH to connect to the application tier EC2 instance
C. Create an authorization to associate the private hosted zone in Account A with the new VPC in Account B
D. Create a private hosted zone for the example com domain in Account B
E. Associate a new VPC in Account B with a hosted zone in Account A
View answer
Correct Answer: CE
Question #31
A security engineer determined that an existing application retrieves credentials to an Amazon RDS for MySQL database from an encrypted file in Amazon S3. For the next version of the application, the security engineer wants to implement the following application design changes to improve security:-The database must use strong, randomly generated passwords stored in a secure AWS managed service.-The application resources must be deployed through AWS CloudFormation.-The application must rotate credentials for the database every 90 days.A solutions architect will generate a CloudFormation template to deploy the application.Which resources specified in the CloudFormation template will meet the security engineer’s requirements with the LEAST amount of operational overhead?
A. Generate the database password as a secret resource using AWS Secrets Manager
B. Generate the database password as a SecureString parameter type using AWS Systems Manager Parameter Store
C. Generate the database password as a secret resource using AWS Secrets Manager
D. Generate the database password as a SecureString parameter type using AWS Systems Manager Parameter Store
View answer
Correct Answer: A
Question #32
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #33
A company has a multi-tier web application that runs on a fleet of Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group. The ALB and the Auto Scaling group are replicated in a backup AWS Region. The minimum value and the maximum value for the Auto Scaling group are set to zero. An Amazon RDS Multi-AZ DB instance stores the application’s data. The DB instance has a read replica in the backup Region. The application presents an endpoint to end users by using an Amazon Route 53 record.The company needs to reduce its RTO to less than 15 minutes by giving the application the ability to automatically fail over to the backup Region. The company does not have a large enough budget for an active-active strategy.What should a solutions architect recommend to meet these requirements?
A. Reconfigure the application’s Route 53 record with a latency-based routing policy that load balances traffic between the two ALBs
B. Create an AWS Lambda function in the backup Region to promote the read replica and modify the Auto Scaling group values
C. Configure the Auto Scaling group in the backup Region to have the same values as the Auto Scaling group in the primary Region
D. Configure an endpoint in AWS Global Accelerator with the two ALBs as equal weighted targets
View answer
Correct Answer: B
Question #34
A company has an organization in AWS Organizations that has a large number of AWS accounts. One of the AWS accounts is designated as a transit account and has a transit gateway that is shared with all of the other AWS accounts. AWS Site-to-Site VPN connections are configured between all of the company’s global offices and the transit account. The company has AWS Config enabled on all of its accounts.The company’s networking team needs to centrally manage a list of internal IP address ranges that belong to the global offices. Developers will reference this list to gain access to their applications securely.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Create a JSON file that is hosted in Amazon S3 and that lists all of the internal IP address ranges
B. Create a new AWS Config managed rule that contains all of the internal IP address ranges
C. In the transit account, create a VPC prefix list with all of the internal IP address ranges
D. In the transit account, create a security group with all of the internal IP address ranges
View answer
Correct Answer: C
Question #35
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #36
A company is running a traditional web application on Amazon EC2 instances. The company needs to refactor the application as microservices that run on containers. Separate versions of the application exist in two distinct environments: production and testing. Load for the application is variable, but the minimum load and the maximum load are known. A solutions architect needs to design the updated application with a serverless architecture that minimizes operational complexity.Which solution will meet these requirements MOST cost-effectively?
A. Upload the container images to AWS Lambda as functions
B. Upload the container images to Amazon Elastic Container Registry (Amazon ECR)
C. Upload the container images to Amazon Elastic Container Registry (Amazon ECR)
D. Upload the container images to AWS Elastic Beanstalk
View answer
Correct Answer: B
Question #37
A company has applications in an AWS account that is named Source. The account is in an organization in AWS Organizations. One of the applications uses AWS Lambda functions and stores inventory data in an Amazon Aurora database. The application deploys the Lambda functions by using a deployment package. The company has configured automated backups for Aurora.The company wants to migrate the Lambda functions and the Aurora database to a new AWS account that is named Target. The application processes critical data, so the company must minimize downtime.Which solution will meet these requirements?
A. Download the Lambda function deployment package from the Source account
B. Download the Lambda function deployment package from the Source account
C. Use AWS Resource Access Manager (AWS RAM) to share the Lambda functions and the Aurora DB cluster with the Target account
D. Use AWS Resource Access Manager (AWS RAM) to share the Lambda functions with the Target account
View answer
Correct Answer: B
Question #38
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #39
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #40
A company that uses AWS Organizations allows developers to experiment on AWS. As part of the landing zone that the company has deployed, developers use their company email address to request an account. The company wants to ensure that developers are not launching costly services or running services unnecessarily. The company must give developers a fixed monthly budget to limit their AWS costs.Which combination of steps will meet these requirements? (Choose three.)
A. Create an SCP to set a fixed monthly account usage limit
B. Use AWS Budgets to create a fixed monthly budget for each developer’s account as part of the account creation process
C. Create an SCP to deny access to costly services and components
D. Create an IAM policy to deny access to costly services and components
E. Create an AWS Budgets alert action to terminate services when the budgeted amount is reached
F. Create an AWS Budgets alert action to send an Amazon Simple Notification Service (Amazon SNS) notification when the budgeted amount is reached
View answer
Correct Answer: BCF
Question #41
An AWS customer has a web application that runs on premises. The web application fetches data from a third-party API that is behind a firewall. The third party accepts only one public CIDR block in each client’s allow list.The customer wants to migrate their web application to the AWS Cloud. The application will be hosted on a set of Amazon EC2 instances behind an Application Load Balancer (ALB) in a VPC. The ALB is located in public subnets. The EC2 instances are located in private subnets. NAT gateways provide internet access to the private subnets.How should a solutions architect ensure that the web application can continue to call the third-party API after the migration?
A. Associate a block of customer-owned public IP addresses to the VPC
B. Register a block of customer-owned public IP addresses in the AWS account
C. Create Elastic IP addresses from the block of customer-owned IP addresses
D. Register a block of customer-owned public IP addresses in the AWS account
View answer
Correct Answer: B
Question #42
A company uses Amazon S3 to store files and images in a variety of storage classes. The company's S3 costs have increased substantially during the past year.A solutions architect needs to review data trends for the past 12 months and identity the appropriate storage class for the objects.Which solution will meet these requirements?
A. Download AWS Cost and Usage Reports for the last 12 months of S3 usage
B. Use S3 storage class analysis
C. Use Amazon S3 Storage Lens
D. Use Access Analyzer for S3
View answer
Correct Answer: C
Question #43
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #44
A company is storing data on premises on a Windows file server. The company produces 5 GB of new data daily.The company migrated part of its Windows-based workload to AWS and needs the data to be available on a file system in the cloud. The company already has established an AWS Direct Connect connection between the on-premises network and AWS.Which data migration strategy should the company use?
A. Use the file gateway option in AWS Storage Gateway to replace the existing Windows file server, and point the existing file share to the new file gateway
B. Use AWS DataSync to schedule a daily task to replicate data between the on-premises Windows file server and Amazon FSx
C. Use AWS Data Pipeline to schedule a daily task to replicate data between the on-premises Windows file server and Amazon Elastic File System (Amazon EFS)
D. Use AWS DataSync to schedule a daily task to replicate data between the on-premises Windows file server and Amazon Elastic File System (Amazon EFS)
View answer
Correct Answer: B
Question #45
A company uses AWS Organizations with a single OU named Production to manage multiple accounts. All accounts are members of the Production OU. Administrators use deny list SCPs in the root of the organization to manage access to restricted services.The company recently acquired a new business unit and invited the new unit’s existing AWS account to the organization. Once onboarded, the administrators of the new business unit discovered that they are not able to update existing AWS Config rules to meet the company’s policies.Which option will allow administrators to make changes and continue to enforce the current policies without introducing additional long-term maintenance?
A. Remove the organization’s root SCPs that limit access to AWS Config
B. Create a temporary OU named Onboarding for the new account
C. Convert the organization’s root SCPs from deny list SCPs to allow list SCPs to allow the required services only
D. Create a temporary OU named Onboarding for the new account
View answer
Correct Answer: D
Question #46
A telecommunications company is running an application on AWS. The company has set up an AWS Direct Connect connection between the company's on-premises data center and AWS. The company deployed the application on Amazon EC2 instances in multiple Availability Zones behind an internal Application Load Balancer (ALB). The company's clients connect from the on-premises network by using HTTPS. The TLS terminates in the ALB. The company has multiple target groups and uses path-based routing to forward requests based on the URL path.The company is planning to deploy an on-premises firewall appliance with an allow list that is based on IP address. A solutions architect must develop a solution to allow traffic flow to AWS from the on-premises network so that the clients can continue to access the application.Which solution will meet these requirements?
A. Configure the existing ALB to use static IP addresses
B. Create a Network Load Balancer (NLB)
C. Create a Network Load Balancer (NLB)
D. Create a Gateway Load Balancer (GWLB)
View answer
Correct Answer: B
Question #47
A company is using Amazon OpenSearch Service to analyze data. The company loads data into an OpenSearch Service cluster with 10 data nodes from an Amazon S3 bucket that uses S3 Standard storage. The data resides in the cluster for 1 month for read-only analysis. After 1 month, the company deletes the index that contains the data from the cluster. For compliance purposes, the company must retain a copy of all input data.The company is concerned about ongoing costs and asks a solutions architect to recommend a new solution. Which solution will meet these requirements MOST cost-effectively?
A. Replace all the data nodes with UltraWarm nodes to handle the expected capacity
B. Reduce the number of data nodes in the cluster to 2 Add UltraWarm nodes to handle the expected capacity
C. Reduce the number of data nodes in the cluster to 2
D. Reduce the number of data nodes in the cluster to 2
View answer
Correct Answer: B
Question #48
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #49
A company has migrated Its forms-processing application to AWS. When users interact with the application, they upload scanned forms as files through a web application. A database stores user metadata and references to files that are stored in Amazon S3. The web application runs on Amazon EC2 instances and an Amazon RDS for PostgreSQL database.When forms are uploaded, the application sends notifications to a team through Amazon Simple Notification Service (Amazon SNS). A team member then logs in and processes each form. The team member performs data validation on the form and extracts relevant data before entering the information into another system that uses an API.A solutions architect needs to automate the manual processing of the forms. The solution must provide accurate form extraction. minimize time to market, and minimize tong-term operational overhead.Which solution will meet these requirements?
A. Develop custom libraries to perform optical character recognition (OCR) on the forms
B. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
C. Host a new application tier on EC2 instances
D. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
View answer
Correct Answer: D
Question #50
A company recently deployed an application on AWS. The application uses Amazon DynamoDB. The company measured the application load and configured the RCUs and WCUs on the DynamoDB table to match the expected peak load. The peak load occurs once a week for a 4-hour period and is double the average load. The application load is close to the average load for the rest of the week. The access pattern includes many more writes to the table than reads of the table.A solutions architect needs to implement a solution to minimize the cost of the table.Which solution will meet these requirements?
A. se AWS Application Auto Scaling to increase capacity during the peak period
B. onfigure on-demand capacity mode for the table
C. onfigure DynamoDB Accelerator (DAX) in front of the table
D. onfigure DynamoDB Accelerator (DAX) in front of the table
View answer
Correct Answer: A
Question #51
A company is hosting a three-tier web application in an on-premises environment. Due to a recent surge in traffic that resulted in downtime and a significant financial impact, company management has ordered that the application be moved to AWS. The application is written in .NET and has a dependency on a MySQL database. A solutions architect must design a scalable and highly available solution to meet the demand of 200,000 daily users.Which steps should the solutions architect take to design an appropriate solution?
A. Use AWS Elastic Beanstalk to create a new application with a web server environment and an Amazon RDS MySQL Multi-AZ DB instance
B. Use AWS CloudFormation to launch a stack containing an Application Load Balancer (ALB) in front of an Amazon EC2 Auto Scaling group spanning three Availability Zones
C. Use AWS Elastic Beanstalk to create an automatically scaling web server environment that spans two separate Regions with an Application Load Balancer (ALB) in each Region
D. Use AWS CloudFormation to launch a stack containing an Application Load Balancer (ALB) in front of an Amazon ECS cluster of Spot instances spanning three Availability Zones
View answer
Correct Answer: B
Question #52
A company wants to migrate its workloads from on premises to AWS. The workloads run on Linux and Windows. The company has a large on-premises infrastructure that consists of physical machines and VMs that host numerous applications.The company must capture details about the system configuration, system performance, running processes, and network connections of its on-premises workloads. The company also must divide the on-premises applications into groups for AWS migrations. The company needs recommendations for Amazon EC2 instance types so that the company can run its workloads on AWS in the most cost-effective manner.Which combination of steps should a solutions architect take to meet these requirements? (Choose three.)
A. Assess the existing applications by installing AWS Application Discovery Agent on the physical machines and VMs
B. Assess the existing applications by installing AWS Systems Manager Agent on the physical machines and VMs
C. Group servers into applications for migration by using AWS Systems Manager Application Manager
D. Group servers into applications for migration by using AWS Migration Hub
E. Generate recommended instance types and associated costs by using AWS Migration Hub
F. Import data about server sizes into AWS Trusted Advisor
View answer
Correct Answer: ADE
Question #53
A company recently completed the migration from an on-premises data center to the AWS Cloud by using a replatforming strategy. One of the migrated servers is running a legacy Simple Mail Transfer Protocol (SMTP) service that a critical application relies upon. The application sends outbound email messages to the company’s customers. The legacy SMTP server does not support TLS encryption and uses TCP port 25. The application can use SMTP only.The company decides to use Amazon Simple Email Service (Amazon SES) and to decommission the legacy SMTP server. The company has created and validated the SES domain. The company has lifted the SES limits.What should the company do to modify the application to send email messages from Amazon SES?
A. Configure the application to connect to Amazon SES by using TLS Wrapper
B. Configure the application to connect to Amazon SES by using STARTTLS
C. Configure the application to use the SES API to send email messages
D. Configure the application to use AWS SDKs to send email messages
View answer
Correct Answer: B
Question #54
A company is refactoring its on-premises order-processing platform in the AWS Cloud. The platform includes a web front end that is hosted on a fleet of VMs, RabbitMQ to connect the front end to the backend, and a Kubernetes cluster to run a containerized backend system to process the orders. The company does not want to make any major changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AMI of the web server VM
B. Create a custom AWS Lambda runtime to mimic the web server environment
C. Create an AMI of the web server VM
D. Create an AMI of the web server VM
View answer
Correct Answer: A
Question #55
A company wants to migrate its workloads from on premises to AWS. The workloads run on Linux and Windows. The company has a large on-premises infrastructure that consists of physical machines and VMs that host numerous applications.The company must capture details about the system configuration, system performance, running processes, and network connections of its on-premises workloads. The company also must divide the on-premises applications into groups for AWS migrations. The company needs recommendations for Amazon EC2 instance types so that the company can run its workloads on AWS in the most cost-effective manner.Which combination of steps should a solutions architect take to meet these requirements? (Choose three.)
A. ssess the existing applications by installing AWS Application Discovery Agent on the physical machines and VMs
B. ssess the existing applications by installing AWS Systems Manager Agent on the physical machines and VMs
C. roup servers into applications for migration by using AWS Systems Manager Application Manager
D. roup servers into applications for migration by using AWS Migration Hub
E. enerate recommended instance types and associated costs by using AWS Migration Hub
F. mport data about server sizes into AWS Trusted Advisor
View answer
Correct Answer: ADE
Question #56
A company is running an application in the AWS Cloud. The application collects and stores a large amount of unstructured data in an Amazon S3 bucket. The S3 bucket contains several terabytes of data and uses the S3 Standard storage class. The data increases in size by several gigabytes every day.The company needs to query and analyze the data. The company does not access data that is more than 1 year old. However, the company must retain all the data indefinitely for compliance reasons.Which solution will meet these requirements MOST cost-effectively?
A. Use S3 Select to query the data
B. Use Amazon Redshift Spectrum to query the data
C. Use an AWS Glue Data Catalog and Amazon Athena to query the data
D. Use Amazon Redshift Spectrum to query the data
View answer
Correct Answer: C
Question #57
Example Corp. has an on-premises data center and a VPC named VPC A in the Example Corp. AWS account. The on-premises network connects to VPC A through an AWS Site-To-Site VPN. The on-premises servers can properly access VPC A. Example Corp. just acquired AnyCompany, which has a VPC named VPC B. There is no IP address overlap among these networks. Example Corp. has peered VPC A and VPC B.Example Corp. wants to connect from its on-premise servers to VPC B. Example Corp. has properly set up the network ACL and security groups.Which solution will meet this requirement with the LEAST operational effort?
A. Create a transit gateway
B. Create a transit gateway
C. Update the route tables for the Site-to-Site VPN and both VPCs for all three networks
D. Modify the Site-to-Site VPN’s virtual private gateway definition to include VPC A and VPC B
View answer
Correct Answer: A
Question #58
A global ecommerce company has many data centers around the world. With the growth of its stored data, the company needs to set up a solution to provide scalable storage for legacy on-premises file applications. The company must be able to take point-in-time copies of volumes by using AWS Backup and must retain low-latency access to frequently accessed data. The company also needs to have storage volumes that can be mounted as Internet Small Computer System Interface (iSCSI) devices from the company's on-premises application servers.Which solution will meet these requirements?
A. Provision an AWS Storage Gateway tape gateway
B. Provision an Amazon FSx File Gateway and an Amazon S3 File Gateway
C. Provision an AWS Storage Gateway volume gateway in cache mode
D. Provision an AWS Storage Gateway file gateway in cache mode
View answer
Correct Answer: C
Question #59
A solutions architect is designing the data storage and retrieval architecture for a new application that a company will be launching soon. The application is designed to ingest millions of small records per minute from devices all around the world. Each record is less than 4 KB in size and needs to be stored in a durable location where it can be retrieved with low latency. The data is ephemeral and the company is required to store the data for 120 days only, after which the data can be deleted.The solutions architect calculates that, during the course of a year, the storage requirements would be about 10-15 TB.Which storage strategy is the MOST cost-effective and meets the design requirements?
A. Design the application to store each incoming record as a single
B. Design the application to store each incoming record in an Amazon DynamoDB table properly configured for the scale
C. Design the application to store each incoming record in a single table in an Amazon RDS MySQL database
D. Design the application to batch incoming records before writing them to an Amazon S3 bucket
View answer
Correct Answer: B
Question #60
A company is building a serverless application that runs on an AWS Lambda function that is attached to a VPC. The company needs to integrate the application with a new service from an external provider. The external provider supports only requests that come from public IPv4 addresses that are in an allow list.The company must provide a single public IP address to the external provider before the application can start using the new service.Which solution will give the application the ability to access the new service?
A. Deploy a NAT gateway
B. Deploy an egress-only internet gateway
C. Deploy an internet gateway
D. Deploy an internet gateway
View answer
Correct Answer: A
Question #61
A company needs to implement a patching process for its servers. The on-premises servers and Amazon EC2 instances use a variety of tools to perform patching. Management requires a single report showing the patch status of all the servers and instances.Which set of actions should a solutions architect take to meet these requirements?
A. Use AWS Systems Manager to manage patches on the on-premises servers and EC2 instances
B. Use AWS OpsWorks to manage patches on the on-premises servers and EC2 instances
C. Use an Amazon EventBridge rule to apply patches by scheduling an AWS Systems Manager patch remediation job
D. Use AWS OpsWorks to manage patches on the on-premises servers and EC2 instances
View answer
Correct Answer: A
Question #62
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #63
A company has on-premises Linux, Windows, and Ubuntu servers that run many applications. The servers run on physical machines and VMs. The company plans to migrate the servers to Amazon EC2 instances.
A. Install AWS Systems Manager Agent (SSM Agent) on the physical machines and VMs to gather performance and usage information from servers
B. Install the Amazon Inspector agent on the physical machines and VMs to gather performance and usage information from servers
C. Install the AWS Application Discovery Agent on the physical machines and VMs to gather performance and usage information from servers
D. Install the unified Amazon CloudWatch agent on the physical machines and VMs to gather performance and usage information from servers
View answer
Correct Answer: C
Question #64
A company is running several workloads in a single AWS account. A new company policy states that engineers can provision only approved resources and that engineers must use AWS CloudFormation to provision these resources. A solutions architect needs to create a solution to enforce the new restriction on the IAM role that the engineers use for access.What should the solutions architect do to create the solution?
A. Upload AWS CloudFormation templates that contain approved resources to an Amazon S3 bucket
B. Update the IAM policy for the engineers’ IAM role with permissions to only allow provisioning of approved resources and AWS CloudFormation
C. Update the IAM policy for the engineers’ IAM role with permissions to only allow AWS CloudFormation actions
D. Provision resources in AWS CloudFormation stacks
View answer
Correct Answer: C
Question #65
A company has applications in an AWS account that is named Source. The account is in an organization in AWS Organizations. One of the applications uses AWS Lambda functions and stores inventory data in an Amazon Aurora database. The application deploys the Lambda functions by using a deployment package. The company has configured automated backups for Aurora.The company wants to migrate the Lambda functions and the Aurora database to a new AWS account that is named Target. The application processes critical data, so the company must minimize downtime.Which solution will meet these requirements?
A. Download the Lambda function deployment package from the Source account
B. Download the Lambda function deployment package from the Source account
C. Use AWS Resource Access Manager (AWS RAM) to share the Lambda functions and the Aurora DB cluster with the Target account
D. Use AWS Resource Access Manager (AWS RAM) to share the Lambda functions with the Target account
View answer
Correct Answer: B
Question #66
A company plans to refactor a monolithic application into a modern application design deployed on AWS. The CI/CD pipeline needs to be upgraded to support the modern design for the application with the following requirements:-It should allow changes to be released several times every hour.-It should be able to roll back the changes as quickly as possible.Which design will meet these requirements?
A. Deploy a CI/CD pipeline that incorporates AMIs to contain the application and their configurations
B. Specify AWS Elastic Beanstalk to stage in a secondary environment as the deployment target for the CI/CD pipeline of the application
C. Use AWS Systems Manager to re-provision the infrastructure for each deployment
D. Roll out the application updates as part of an Auto Scaling event using prebuilt AMIs
View answer
Correct Answer: B
Question #67
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #68
An application is using an Amazon RDS for MySQL Multi-AZ DB instance in the us-east-1 Region. After a failover test, the application lost the connections to the database and could not re-establish the connections. After a restart of the application, the application re-established the connections.A solutions architect must implement a solution so that the application can re-establish connections to the database without requiring a restart.Which solution will meet these requirements?
A. Create an Amazon Aurora MySQL Serverless v1 DB instance
B. Create an RDS proxy
C. Create a two-node Amazon Aurora MySQL DB cluster
D. Create an Amazon S3 bucket
View answer
Correct Answer: B
Question #69
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #70
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #71
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #72
A company wants to change its internal cloud billing strategy for each of its business units. Currently, the cloud governance team shares reports for overall cloud spending with the head of each business unit. The company uses AWS Organizations to manage the separate AWS accounts for each business unit. The existing tagging standard in Organizations includes the application, environment, and owner. The cloud governance team wants a centralized solution so each business unit receives monthly reports on its cloud spending. The solution should also send notifications for any cloud spending that exceeds a set threshold.Which solution is the MOST cost-effective way to meet these requirements?
A. Configure AWS Budgets in each account and configure budget alerts that are grouped by application, environment, and owner
B. Configure AWS Budgets in the organization's management account and configure budget alerts that are grouped by application, environment, and owner
C. Configure AWS Budgets in each account and configure budget alerts that are grouped by application, environment, and owner
D. Enable AWS Cost and Usage Reports in the organization's management account and configure reports grouped by application, environment
View answer
Correct Answer: B
Question #73
A finance company hosts a data lake in Amazon S3. The company receives financial data records over SFTP each night from several third parties. The company runs its own SFTP server on an Amazon EC2 instance in a public subnet of a VPC. After the files are uploaded, they are moved to the data lake by a cron job that runs on the same instance. The SFTP server is reachable on DNS sftp.example.com through the use of Amazon Route 53.What should a solutions architect do to improve the reliability and scalability of the SFTP solution?
A. Move the EC2 instance into an Auto Scaling group
B. Migrate the SFTP server to AWS Transfer for SFTP
C. Migrate the SFTP server to a file gateway in AWS Storage Gateway
D. Place the EC2 instance behind a Network Load Balancer (NLB)
View answer
Correct Answer: B
Question #74
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #75
A company has migrated Its forms-processing application to AWS. When users interact with the application, they upload scanned forms as files through a web application. A database stores user metadata and references to files that are stored in Amazon S3. The web application runs on Amazon EC2 instances and an Amazon RDS for PostgreSQL database.When forms are uploaded, the application sends notifications to a team through Amazon Simple Notification Service (Amazon SNS). A team member then logs in and processes each form. The team member performs data validation on the form and extracts relevant data before entering the information into another system that uses an API.A solutions architect needs to automate the manual processing of the forms. The solution must provide accurate form extraction. minimize time to market, and minimize tong-term operational overhead.Which solution will meet these requirements?
A. Develop custom libraries to perform optical character recognition (OCR) on the forms
B. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
C. Host a new application tier on EC2 instances
D. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
View answer
Correct Answer: D
Question #76
A company that has multiple AWS accounts is using AWS Organizations. The company’s AWS accounts host VPCs, Amazon EC2 instances, and containers.The company’s compliance team has deployed a security tool in each VPC where the company has deployments. The security tools run on EC2 instances and send information to the AWS account that is dedicated for the compliance team. The company has tagged all the compliance-related resources with a key of “costCenter” and a value or “compliance”.The company wants to identify the cost of the security tools that are running on the EC2 instances so that the company can charge the compliance team’s AWS account. The cost calculation must be as accurate as possible.What should a solutions architect do to meet these requirements?
A. In the management account of the organization, activate the costCenter user-defined tag
B. In the member accounts of the organization, activate the costCenter user-defined tag
C. In the member accounts of the organization activate the costCenter user-defined tag
D. Create a custom report in the organization view in AWS Trusted Advisor
View answer
Correct Answer: A
Question #77
A company is running several workloads in a single AWS account. A new company policy states that engineers can provision only approved resources and that engineers must use AWS CloudFormation to provision these resources. A solutions architect needs to create a solution to enforce the new restriction on the IAM role that the engineers use for access.What should the solutions architect do to create the solution?
A. Upload AWS CloudFormation templates that contain approved resources to an Amazon S3 bucket
B. Update the IAM policy for the engineers’ IAM role with permissions to only allow provisioning of approved resources and AWS CloudFormation
C. Update the IAM policy for the engineers’ IAM role with permissions to only allow AWS CloudFormation actions
D. Provision resources in AWS CloudFormation stacks
View answer
Correct Answer: C
Question #78
Example Corp. has an on-premises data center and a VPC named VPC A in the Example Corp. AWS account. The on-premises network connects to VPC A through an AWS Site-To-Site VPN. The on-premises servers can properly access VPC A. Example Corp. just acquired AnyCompany, which has a VPC named VPC B. There is no IP address overlap among these networks. Example Corp. has peered VPC A and VPC B.Example Corp. wants to connect from its on-premise servers to VPC B. Example Corp. has properly set up the network ACL and security groups.Which solution will meet this requirement with the LEAST operational effort?
A. Create a transit gateway
B. Create a transit gateway
C. Update the route tables for the Site-to-Site VPN and both VPCs for all three networks
D. Modify the Site-to-Site VPN’s virtual private gateway definition to include VPC A and VPC B
View answer
Correct Answer: A
Question #79
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #80
A solutions architect needs to copy data from an Amazon S3 bucket m an AWS account to a new S3 bucket in a new AWS account. The solutions architect must implement a solution that uses the AWS CLI. Which combination of steps will successfully copy the data? (Choose three.)
A. Create a bucket policy to allow the source bucket to list its contents and to put objects and set object ACLs in the destination bucket
B. Create a bucket policy to allow a user in the destination account to list the source bucket’s contents and read the source bucket’s objects
C. Create an IAM policy in the source account
D. Create an IAM policy in the destination account
E. Run the aws s3 sync command as a user in the source account
F. Run the aws s3 sync command as a user in the destination account
View answer
Correct Answer: BDF
Question #81
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #82
A startup company hosts a fleet of Amazon EC2 instances in private subnets using the latest Amazon Linux 2 AMI. The company’s engineers rely heavily on SSH access to the instances for troubleshooting.The company’s existing architecture includes the following:-A VPC with private and public subnets, and a NAT gateway.-Site-to-Site VPN for connectivity with the on-premises environment.-EC2 security groups with direct SSH access from the on-premises environment.The company needs to increase security controls around SSH access and provide auditing of commands run by the engineers.Which strategy should a solutions architect use?
A. Install and configure EC2 Instance Connect on the fleet of EC2 instances
B. Update the EC2 security groups to only allow inbound TCP on port 22 to the IP addresses of the engineer’s devices
C. Update the EC2 security groups to only allow inbound TCP on port 22 to the IP addresses of the engineer’s devices
D. Create an IAM role with the AmazonSSMManagedInstanceCore managed policy attached
View answer
Correct Answer: D
Question #83
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #84
A company recently deployed an application on AWS. The application uses Amazon DynamoDB. The company measured the application load and configured the RCUs and WCUs on the DynamoDB table to match the expected peak load. The peak load occurs once a week for a 4-hour period and is double the average load. The application load is close to the average load for the rest of the week. The access pattern includes many more writes to the table than reads of the table.A solutions architect needs to implement a solution to minimize the cost of the table.Which solution will meet these requirements?
A. Use AWS Application Auto Scaling to increase capacity during the peak period
B. Configure on-demand capacity mode for the table
C. Configure DynamoDB Accelerator (DAX) in front of the table
D. Configure DynamoDB Accelerator (DAX) in front of the table
View answer
Correct Answer: A
Question #85
A company is running an application in the AWS Cloud. The application collects and stores a large amount of unstructured data in an Amazon S3 bucket. The S3 bucket contains several terabytes of data and uses the S3 Standard storage class. The data increases in size by several gigabytes every day.The company needs to query and analyze the data. The company does not access data that is more than 1 year old. However, the company must retain all the data indefinitely for compliance reasons.Which solution will meet these requirements MOST cost-effectively?
A. Use S3 Select to query the data
B. Use Amazon Redshift Spectrum to query the data
C. Use an AWS Glue Data Catalog and Amazon Athena to query the data
D. Use Amazon Redshift Spectrum to query the data
View answer
Correct Answer: C
Question #86
A company is building a serverless application that runs on an AWS Lambda function that is attached to a VPC. The company needs to integrate the application with a new service from an external provider. The external provider supports only requests that come from public IPv4 addresses that are in an allow list.The company must provide a single public IP address to the external provider before the application can start using the new service.Which solution will give the application the ability to access the new service?
A. Deploy a NAT gateway
B. Deploy an egress-only internet gateway
C. Deploy an internet gateway
D. Deploy an internet gateway
View answer
Correct Answer: A
Question #87
A company is running a two-tier web-based application in an on-premises data center. The application layer consists of a single server running a stateful application. The application connects to a PostgreSQL database running on a separate server. The application’s user base is expected to grow significantly, so the company is migrating the application and database to AWS. The solution will use Amazon Aurora PostgreSQL, Amazon EC2 Auto Scaling, and Elastic Load Balancing.Which solution will provide a consistent user experience that will allow the application and database tiers to scale?
A. nable Aurora Auto Scaling for Aurora Replicas
B. nable Aurora Auto Scaling for Aurora writers
C. nable Aurora Auto Scaling for Aurora Replicas
D. nable Aurora Scaling for Aurora writers
View answer
Correct Answer: C
Question #88
A company wants to change its internal cloud billing strategy for each of its business units. Currently, the cloud governance team shares reports for overall cloud spending with the head of each business unit. The company uses AWS Organizations to manage the separate AWS accounts for each business unit. The existing tagging standard in Organizations includes the application, environment, and owner. The cloud governance team wants a centralized solution so each business unit receives monthly reports on its cloud spending. The solution should also send notifications for any cloud spending that exceeds a set threshold.Which solution is the MOST cost-effective way to meet these requirements?
A. Configure AWS Budgets in each account and configure budget alerts that are grouped by application, environment, and owner
B. Configure AWS Budgets in the organization's management account and configure budget alerts that are grouped by application, environment, and owner
C. Configure AWS Budgets in each account and configure budget alerts that are grouped by application, environment, and owner
D. Enable AWS Cost and Usage Reports in the organization's management account and configure reports grouped by application, environment
View answer
Correct Answer: B
Question #89
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #90
A company runs a new application as a static website in Amazon S3. The company has deployed the application to a production AWS account and uses Amazon CloudFront to deliver the website. The website calls an Amazon API Gateway REST API. An AWS Lambda function backs each API method.The company wants to create a CSV report every 2 weeks to show each API Lambda function’s recommended configured memory, recommended cost, and the price difference between current configurations and the recommendations. The company will store the reports in an S3 bucket.Which solution will meet these requirements with the LEAST development time?
A. Create a Lambda function that extracts metrics data for each API Lambda function from Amazon CloudWatch Logs for the 2-week period
B. Opt in to AWS Compute Optimizer
C. Opt in to AWS Compute Optimizer
D. Purchase the AWS Business Support plan for the production account
View answer
Correct Answer: B
Question #91
How should EC2 instances in AWS synchronize their clocks with an on-premisesatomic clock NTP server, with theleast administrative overhead?
A. Configure a DHCP options set with the on-prem NTP server
B. Use a custom AMI with Amazon Time Sync
C. Deploy a 3rd-party NTP server from Marketplace
D. Create an IPsec VPN tunnel to sync over Direct Connect
View answer
Correct Answer: A
Question #92
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #93
A company has migrated Its forms-processing application to AWS. When users interact with the application, they upload scanned forms as files through a web application. A database stores user metadata and references to files that are stored in Amazon S3. The web application runs on Amazon EC2 instances and an Amazon RDS for PostgreSQL database.When forms are uploaded, the application sends notifications to a team through Amazon Simple Notification Service (Amazon SNS). A team member then logs in and processes each form. The team member performs data validation on the form and extracts relevant data before entering the information into another system that uses an API.A solutions architect needs to automate the manual processing of the forms. The solution must provide accurate form extraction. minimize time to market, and minimize tong-term operational overhead.Which solution will meet these requirements?
A. Develop custom libraries to perform optical character recognition (OCR) on the forms
B. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
C. Host a new application tier on EC2 instances
D. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
View answer
Correct Answer: D
Question #94
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #95
A company is planning to store a large number of archived documents and make the documents available to employees through the corporate intranet. Employees will access the system by connecting through a client VPN service that is attached to a VPC. The data must not be accessible to the public.The documents that the company is storing are copies of data that is held on physical media elsewhere. The number of requests will be low. Availability and speed of retrieval are not concerns of the company.Which solution will meet these requirements at the LOWEST cost?
A. Create an Amazon S3 bucket
B. Launch an Amazon EC2 instance that runs a web server
C. Launch an Amazon EC2 instance that runs a web server Attach an Amazon Elastic Block Store (Amazon EBS) volume to store the archived data
D. Create an Amazon S3 bucket
View answer
Correct Answer: A
Question #96
A software company has deployed an application that consumes a REST API by using Amazon API Gateway, AWS Lambda functions, and an Amazon DynamoDB table. The application is showing an increase in the number of errors during PUT requests. Most of the PUT calls come from a small number of clients that are authenticated with specific API keys.A solutions architect has identified that a large number of the PUT requests originate from one client. The API is noncritical, and clients can tolerate retries of unsuccessful calls. However, the errors are displayed to customers and are causing damage to the API’s reputation.What should the solutions architect recommend to improve the customer experience?
A. Implement retry logic with exponential backoff and irregular variation in the client application
B. Implement API throttling through a usage plan at the API Gateway level
C. Turn on API caching to enhance responsiveness for the production stage
D. Implement reserved concurrency at the Lambda function level to provide the resources that are needed during sudden increases in traffic
View answer
Correct Answer: B
Question #97
A company has created an OU in AWS Organizations for each of its engineering teams. Each OU owns multiple AWS accounts. The organization has hundreds of AWS accounts.A solutions architect must design a solution so that each OU can view a breakdown of usage costs across its AWS accounts.Which solution meets these requirements?
A. Create an AWS Cost and Usage Report (CUR) for each OU by using AWS Resource Access Manager
B. Create an AWS Cost and Usage Report (CUR) from the AWS Organizations management account
C. Create an AWS Cost and Usage Report (CUR) in each AWS Organizations member account
D. Create an AWS Cost and Usage Report (CUR) by using AWS Systems Manager
View answer
Correct Answer: B
Question #98
A company recently completed the migration from an on-premises data center to the AWS Cloud by using a replatforming strategy. One of the migrated servers is running a legacy Simple Mail Transfer Protocol (SMTP) service that a critical application relies upon. The application sends outbound email messages to the company’s customers. The legacy SMTP server does not support TLS encryption and uses TCP port 25. The application can use SMTP only.The company decides to use Amazon Simple Email Service (Amazon SES) and to decommission the legacy SMTP server. The company has created and validated the SES domain. The company has lifted the SES limits.What should the company do to modify the application to send email messages from Amazon SES?
A. Configure the application to connect to Amazon SES by using TLS Wrapper
B. Configure the application to connect to Amazon SES by using STARTTLS
C. Configure the application to use the SES API to send email messages
D. Configure the application to use AWS SDKs to send email messages
View answer
Correct Answer: B
Question #99
A company has an organization in AWS Organizations. The company is using AWS Control Tower to deploy a landing zone for the organization. The company wants to implement governance and policy enforcement. The company must implement a policy that will detect Amazon RDS DB instances that are not encrypted at rest in the company’s production OU.Which solution will meet this requirement?
A. Turn on mandatory guardrails in AWS Control Tower
B. Enable the appropriate guardrail from the list of strongly recommended guardrails in AWS Control Tower
C. Use AWS Config to create a new mandatory guardrail
D. Create a custom SCP in AWS Control Tower
View answer
Correct Answer: B
Question #100
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #101
A company is using AWS Organizations to manage multiple AWS accounts. For security purposes, the company requires the creation of an Amazon Simple Notification Service (Amazon SNS) topic that enables integration with a third-party alerting system in all the Organizations member accounts.A solutions architect used an AWS CloudFormation template to create the SNS topic and stack sets to automate the deployment of CloudFormation stacks. Trusted access has been enabled in Organizations.What should the solutions architect do to deploy the CloudFormation StackSets in all AWS accounts?
A. Create a stack set in the Organizations member accounts
B. Create stacks in the Organizations member accounts
C. Create a stack set in the Organizations management account
D. Create stacks in the Organizations management account
View answer
Correct Answer: C
Question #102
A company is using AWS Organizations to manage multiple AWS accounts. For security purposes, the company requires the creation of an Amazon Simple Notification Service (Amazon SNS) topic that enables integration with a third-party alerting system in all the Organizations member accounts.A solutions architect used an AWS CloudFormation template to create the SNS topic and stack sets to automate the deployment of CloudFormation stacks. Trusted access has been enabled in Organizations.What should the solutions architect do to deploy the CloudFormation StackSets in all AWS accounts?
A. Create a stack set in the Organizations member accounts
B. Create stacks in the Organizations member accounts
C. Create a stack set in the Organizations management account
D. Create stacks in the Organizations management account
View answer
Correct Answer: C
Question #103
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #104
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #105
A company is in the process of implementing AWS Organizations to constrain its developers to use only Amazon EC2, Amazon S3, and Amazon DynamoDB. The developers account resides in a dedicated organizational unit (OU). The solutions architect has implemented the following SCP on the developers account:When this policy is deployed, IAM users in the developers account are still able to use AWS services that are not listed in the policy.What should the solutions architect do to eliminate the developers’ ability to use services outside the scope of this policy?
A. Create an explicit deny statement for each AWS service that should be constrained
B. Remove the FullAWSAccess SCP from the developers account’s OU
C. Modify the FullAWSAccess SCP to explicitly deny all services
D. Add an explicit deny statement using a wildcard to the end of the SCP
View answer
Correct Answer: B
Question #106
A company is running a data-intensive application on AWS. The application runs on a cluster of hundreds of Amazon EC2 instances. A shared file system also runs on several EC2 instances that store 200 TB of data. The application reads and modifies the data on the shared file system and generates a report. The job runs once monthly, reads a subset of the files from the shared file system, and takes about 72 hours to complete. The compute instances scale in an Auto Scaling group, but the instances that host the shared file system run continuously. The compute and storage instances are all in the same AWS Region.A solutions architect needs to reduce costs by replacing the shared file system instances. The file system must provide high performance access to the needed data for the duration of the 72-hour run.Which solution will provide the LARGEST overall cost reduction while meeting these requirements?
A. Migrate the data from the existing shared file system to an Amazon S3 bucket that uses the S3 Intelligent-Tiering storage class
B. Migrate the data from the existing shared file system to a large Amazon Elastic Block Store (Amazon EBS) volume with Multi-Attach enabled
C. Migrate the data from the existing shared file system to an Amazon S3 bucket that uses the S3 Standard storage class
D. Migrate the data from the existing shared file system to an Amazon S3 bucket
View answer
Correct Answer: A
Question #107
A company is building a solution in the AWS Cloud. Thousands or devices will connect to the solution and send data. Each device needs to be able to send and receive data in real time over the MQTT protocol. Each device must authenticate by using a unique X.509 certificate.Which solution will meet these requirements with the LEAST operational overhead?
A. Set up AWS IoT Core
B. Create a Network Load Balancer (NLB) and configure it with an AWS Lambda authorizer
C. Set up AWS IoT Core
D. Set up an Amazon API Gateway HTTP API and a Network Load Balancer (NLB)
View answer
Correct Answer: C
Question #108
A company has an organization in AWS Organizations. The company is using AWS Control Tower to deploy a landing zone for the organization. The company wants to implement governance and policy enforcement. The company must implement a policy that will detect Amazon RDS DB instances that are not encrypted at rest in the company’s production OU.Which solution will meet this requirement?
A. Turn on mandatory guardrails in AWS Control Tower
B. Enable the appropriate guardrail from the list of strongly recommended guardrails in AWS Control Tower
C. Use AWS Config to create a new mandatory guardrail
D. Create a custom SCP in AWS Control Tower
View answer
Correct Answer: B
Question #109
A company has many AWS accounts and uses AWS Organizations to manage all of them. A solutions architect must implement a solution that the company can use to share a common network across multiple accounts.The company’s infrastructure team has a dedicated infrastructure account that has a VPC. The infrastructure team must use this account to manage the network. Individual accounts cannot have the ability to manage their own networks. However, individual accounts must be able to create AWS resources within subnets.Which combination of actions should the solutions architect perform to meet these requirements? (Choose two.)
A. Create a transit gateway in the infrastructure account
B. Enable resource sharing from the AWS Organizations management account
C. Create VPCs in each AWS account within the organization in AWS Organizations
D. Create a resource share in AWS Resource Access Manager in the infrastructure account
E. Create a resource share in AWS Resource Access Manager in the infrastructure account
View answer
Correct Answer: BD
Question #110
Example Corp. has an on-premises data center and a VPC named VPC A in the Example Corp. AWS account. The on-premises network connects to VPC A through an AWS Site-To-Site VPN. The on-premises servers can properly access VPC A. Example Corp. just acquired AnyCompany, which has a VPC named VPC B. There is no IP address overlap among these networks. Example Corp. has peered VPC A and VPC B.Example Corp. wants to connect from its on-premise servers to VPC B. Example Corp. has properly set up the network ACL and security groups.Which solution will meet this requirement with the LEAST operational effort?
A. Create a transit gateway
B. Create a transit gateway
C. Update the route tables for the Site-to-Site VPN and both VPCs for all three networks
D. Modify the Site-to-Site VPN’s virtual private gateway definition to include VPC A and VPC B
View answer
Correct Answer: A
Question #111
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #112
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #113
A company wants to use a third-party software-as-a-service (SaaS) application. The third-party SaaS application is consumed through several API calls. The third-party SaaS application also runs on AWS inside a VPC.The company will consume the third-party SaaS application from inside a VPC. The company has internal security policies that mandate the use of private connectivity that does not traverse the internet. No resources that run in the company VPC are allowed to be accessed from outside the company’s VPC. All permissions must conform to the principles of least privilege.Which solution meets these requirements?
A. Create an AWS PrivateLink interface VPC endpoint
B. Create an AWS Site-to-Site VPN connection between the third-party SaaS application and the company VPC
C. Create a VPC peering connection between the third-party SaaS application and the company VP Update route tables by adding the needed routes for the peering connection
D. Create an AWS PrivateLink endpoint service
View answer
Correct Answer: A
Question #114
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #115
A company is using AWS CloudFormation to deploy its infrastructure. The company is concerned that, if a production CloudFormation stack is deleted, important data stored in Amazon RDS databases or Amazon EBS volumes might also be deleted.How can the company prevent users from accidentally deleting data in this way?
A. Modify the CloudFormation templates to add a DeletionPolicy attribute to RDS and EBS resources
B. Configure a stack policy that disallows the deletion of RDS and EBS resources
C. Modify IAM policies lo deny deleting RDS and EBS resources that are tagged with an "aws:cloudformation:stack-name" tag
D. Use AWS Config rules to prevent deleting RDS and EBS resources
View answer
Correct Answer: A
Question #116
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #117
A company that has multiple AWS accounts is using AWS Organizations. The company’s AWS accounts host VPCs, Amazon EC2 instances, and containers.The company’s compliance team has deployed a security tool in each VPC where the company has deployments. The security tools run on EC2 instances and send information to the AWS account that is dedicated for the compliance team. The company has tagged all the compliance-related resources with a key of “costCenter” and a value or “compliance”.The company wants to identify the cost of the security tools that are running on the EC2 instances so that the company can charge the compliance team’s AWS account. The cost calculation must be as accurate as possible.What should a solutions architect do to meet these requirements?
A. In the management account of the organization, activate the costCenter user-defined tag
B. In the member accounts of the organization, activate the costCenter user-defined tag
C. In the member accounts of the organization activate the costCenter user-defined tag
D. Create a custom report in the organization view in AWS Trusted Advisor
View answer
Correct Answer: A
Question #118
An enterprise company wants to allow its developers to purchase third-party software through AWS Marketplace. The company uses an AWS Organizations account structure with full features enabled, and has a shared services account in each organizational unit (OU) that will be used by procurement managers. The procurement team’s policy indicates that developers should be able to obtain third-party software from an approved list only and use Private Marketplace in AWS Marketplace to achieve this requirement. The procurement team wants administration of Private Marketplace to be restricted to a role named procurement-manager-role, which could be assumed by procurement managers. Other IAM users, groups, roles, and account administrators in the company should be denied Private Marketplace administrative access.What is the MOST efficient way to design an architecture to meet these requirements?
A. Create an IAM role named procurement-manager-role in all AWS accounts in the organization
B. Create an IAM role named procurement-manager-role in all AWS accounts in the organization
C. Create an IAM role named procurement-manager-role in all the shared services accounts in the organization
D. Create an IAM role named procurement-manager-role in all AWS accounts that will be used by developers
View answer
Correct Answer: C
Question #119
A company is running an application in the AWS Cloud. The application collects and stores a large amount of unstructured data in an Amazon S3 bucket. The S3 bucket contains several terabytes of data and uses the S3 Standard storage class. The data increases in size by several gigabytes every day.The company needs to query and analyze the data. The company does not access data that is more than 1 year old. However, the company must retain all the data indefinitely for compliance reasons.Which solution will meet these requirements MOST cost-effectively?
A. Use S3 Select to query the data
B. Use Amazon Redshift Spectrum to query the data
C. Use an AWS Glue Data Catalog and Amazon Athena to query the data
D. Use Amazon Redshift Spectrum to query the data
View answer
Correct Answer: C
Question #120
An AWS customer has a web application that runs on premises. The web application fetches data from a third-party API that is behind a firewall. The third party accepts only one public CIDR block in each client’s allow list.The customer wants to migrate their web application to the AWS Cloud. The application will be hosted on a set of Amazon EC2 instances behind an Application Load Balancer (ALB) in a VPC. The ALB is located in public subnets. The EC2 instances are located in private subnets. NAT gateways provide internet access to the private subnets.How should a solutions architect ensure that the web application can continue to call the third-party API after the migration?
A. Associate a block of customer-owned public IP addresses to the VPC
B. Register a block of customer-owned public IP addresses in the AWS account
C. Create Elastic IP addresses from the block of customer-owned IP addresses
D. Register a block of customer-owned public IP addresses in the AWS account
View answer
Correct Answer: B
Question #121
A company has migrated Its forms-processing application to AWS. When users interact with the application, they upload scanned forms as files through a web application. A database stores user metadata and references to files that are stored in Amazon S3. The web application runs on Amazon EC2 instances and an Amazon RDS for PostgreSQL database.When forms are uploaded, the application sends notifications to a team through Amazon Simple Notification Service (Amazon SNS). A team member then logs in and processes each form. The team member performs data validation on the form and extracts relevant data before entering the information into another system that uses an API.A solutions architect needs to automate the manual processing of the forms. The solution must provide accurate form extraction. minimize time to market, and minimize tong-term operational overhead.Which solution will meet these requirements?
A. Develop custom libraries to perform optical character recognition (OCR) on the forms
B. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
C. Host a new application tier on EC2 instances
D. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
View answer
Correct Answer: D
Question #122
A company has a web application that allows users to upload short videos. The videos are stored on Amazon EBS volumes and analyzed by custom recognition software for categorization.The website contains static content that has variable traffic with peaks in certain months. The architecture consists of Amazon EC2 instances running in an Auto Scaling group for the web application and EC2 instances running in an Auto Scaling group to process an Amazon SQS queue. The company wants to re-architect the application to reduce operational overhead using AWS managed services where possible and remove dependencies on third-party software.Which solution meets these requirements?
A. Use Amazon ECS containers for the web application and Spot instances for the Auto Scaling group that processes the SQS queue
B. Store the uploaded videos in Amazon EFS and mount the file system to the EC2 instances for the web application
C. Host the web application in Amazon S3
D. Use AWS Elastic Beanstalk to launch EC2 instances in an Auto Scaling group for the web application and launch a worker environment to process the SQS queue
View answer
Correct Answer: C
Question #123
A company is refactoring its on-premises order-processing platform in the AWS Cloud. The platform includes a web front end that is hosted on a fleet of VMs, RabbitMQ to connect the front end to the backend, and a Kubernetes cluster to run a containerized backend system to process the orders. The company does not want to make any major changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AMI of the web server VM
B. Create a custom AWS Lambda runtime to mimic the web server environment
C. Create an AMI of the web server VM
D. Create an AMI of the web server VM
View answer
Correct Answer: A
Question #124
A company is running an application on several Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The load on the application varies throughout the day, and EC2 instances are scaled in and out on a regular basis. Log files from the EC2 instances are copied to a central Amazon S3 bucket every 15 minutes. The security team discovers that log files are missing from some of the terminated EC2 instances.Which set of actions will ensure that log files are copied to the central S3 bucket from the terminated EC2 instances?
A. Create a script to copy log files to Amazon S3, and store the script in a file on the EC2 instance
B. Create an AWS Systems Manager document with a script to copy log files to Amazon S3
C. Change the log delivery rate to every 5 minutes
D. Create an AWS Systems Manager document with a script to copy log files to Amazon S3
View answer
Correct Answer: B
Question #125
A company is refactoring its on-premises order-processing platform in the AWS Cloud. The platform includes a web front end that is hosted on a fleet of VMs, RabbitMQ to connect the front end to the backend, and a Kubernetes cluster to run a containerized backend system to process the orders. The company does not want to make any major changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AMI of the web server VM
B. Create a custom AWS Lambda runtime to mimic the web server environment
C. Create an AMI of the web server VM
D. Create an AMI of the web server VM
View answer
Correct Answer: A
Question #126
A retail company is hosting an ecommerce website on AWS across multiple AWS Regions. The company wants the website to be operational at all times for online purchases. The website stores data in an Amazon RDS for MySQL DB instance.Which solution will provide the HIGHEST availability for the database?
A. Configure automated backups on Amazon RDS
B. Configure global tables and read replicas on Amazon RDS
C. Configure global tables and automated backups on Amazon RDS
D. Configure read replicas on Amazon RDS
View answer
Correct Answer: D
Question #127
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #128
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #129
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #130
A health insurance company stores personally identifiable information (PII) in an Amazon S3 bucket. The company uses server-side encryption with S3 managed encryption keys (SSE-S3) to encrypt the objects. According to a new requirement, all current and future objects in the S3 bucket must be encrypted by keys that the company’s security team manages. The S3 bucket does not have versioning enabled.Which solution will meet these requirements?
A. In the S3 bucket properties, change the default encryption to SSE-S3 with a customer managed key
B. In the S3 bucket properties, change the default encryption to server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
C. In the S3 bucket properties, change the default encryption to server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
D. In the S3 bucket properties, change the default encryption to AES-256 with a customer managed key
View answer
Correct Answer: B
Question #131
A company is storing data in several Amazon DynamoDB tables. A solutions architect must use a serverless architecture to make the data accessible publicly through a simple API over HTTPS. The solution must scale automatically in response to demand.Which solutions meet these requirements? (Choose two.)
A. Create an Amazon API Gateway REST API
B. Create an Amazon API Gateway HTTP API
C. Create an Amazon API Gateway HTTP API
D. Create an accelerator in AWS Global Accelerator
E. Create a Network Load Balancer
View answer
Correct Answer: AC
Question #132
A company is running an application in the AWS Cloud. The application collects and stores a large amount of unstructured data in an Amazon S3 bucket. The S3 bucket contains several terabytes of data and uses the S3 Standard storage class. The data increases in size by several gigabytes every day.The company needs to query and analyze the data. The company does not access data that is more than 1 year old. However, the company must retain all the data indefinitely for compliance reasons.Which solution will meet these requirements MOST cost-effectively?
A. Use S3 Select to query the data
B. Use Amazon Redshift Spectrum to query the data
C. Use an AWS Glue Data Catalog and Amazon Athena to query the data
D. Use Amazon Redshift Spectrum to query the data
View answer
Correct Answer: C
Question #133
A company is refactoring its on-premises order-processing platform in the AWS Cloud. The platform includes a web front end that is hosted on a fleet of VMs, RabbitMQ to connect the front end to the backend, and a Kubernetes cluster to run a containerized backend system to process the orders. The company does not want to make any major changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AMI of the web server VM
B. Create a custom AWS Lambda runtime to mimic the web server environment
C. Create an AMI of the web server VM
D. Create an AMI of the web server VM
View answer
Correct Answer: A
Question #134
A company has migrated Its forms-processing application to AWS. When users interact with the application, they upload scanned forms as files through a web application. A database stores user metadata and references to files that are stored in Amazon S3. The web application runs on Amazon EC2 instances and an Amazon RDS for PostgreSQL database.When forms are uploaded, the application sends notifications to a team through Amazon Simple Notification Service (Amazon SNS). A team member then logs in and processes each form. The team member performs data validation on the form and extracts relevant data before entering the information into another system that uses an API.A solutions architect needs to automate the manual processing of the forms. The solution must provide accurate form extraction. minimize time to market, and minimize tong-term operational overhead.Which solution will meet these requirements?
A. Develop custom libraries to perform optical character recognition (OCR) on the forms
B. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
C. Host a new application tier on EC2 instances
D. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
View answer
Correct Answer: D
Question #135
A company uses Amazon S3 to store files and images in a variety of storage classes. The company's S3 costs have increased substantially during the past year.A solutions architect needs to review data trends for the past 12 months and identity the appropriate storage class for the objects.Which solution will meet these requirements?
A. Download AWS Cost and Usage Reports for the last 12 months of S3 usage
B. Use S3 storage class analysis
C. Use Amazon S3 Storage Lens
D. Use Access Analyzer for S3
View answer
Correct Answer: C
Question #136
A company is refactoring its on-premises order-processing platform in the AWS Cloud. The platform includes a web front end that is hosted on a fleet of VMs, RabbitMQ to connect the front end to the backend, and a Kubernetes cluster to run a containerized backend system to process the orders. The company does not want to make any major changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AMI of the web server VM
B. Create a custom AWS Lambda runtime to mimic the web server environment
C. Create an AMI of the web server VM
D. Create an AMI of the web server VM
View answer
Correct Answer: A
Question #137
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #138
A company is refactoring its on-premises order-processing platform in the AWS Cloud. The platform includes a web front end that is hosted on a fleet of VMs, RabbitMQ to connect the front end to the backend, and a Kubernetes cluster to run a containerized backend system to process the orders. The company does not want to make any major changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AMI of the web server VM
B. Create a custom AWS Lambda runtime to mimic the web server environment
C. Create an AMI of the web server VM
D. Create an AMI of the web server VM
View answer
Correct Answer: A
Question #139
A company recently deployed an application on AWS. The application uses Amazon DynamoDB. The company measured the application load and configured the RCUs and WCUs on the DynamoDB table to match the expected peak load. The peak load occurs once a week for a 4-hour period and is double the average load. The application load is close to the average load for the rest of the week. The access pattern includes many more writes to the table than reads of the table.A solutions architect needs to implement a solution to minimize the cost of the table.Which solution will meet these requirements?
A. Use AWS Application Auto Scaling to increase capacity during the peak period
B. Configure on-demand capacity mode for the table
C. Configure DynamoDB Accelerator (DAX) in front of the table
D. Configure DynamoDB Accelerator (DAX) in front of the table
View answer
Correct Answer: A
Question #140
A financial services company in North America plans to release a new online web application to its customers on AWS. The company will launch the application in the us-east-1 Region on Amazon EC2 instances. The application must be highly available and must dynamically scale to meet user traffic. The company also wants to implement a disaster recovery environment for the application in the us-west-1 Region by using active-passive failover.Which solution will meet these requirements?
A. Create a VPC in us-east-1 and a VPC in us-west-1
B. Create a VPC in us-east-1 and a VPC in us-west-1
C. Create a VPC in us-east-1 and a VPC in us-west-1
D. Create a VPC in us-east-1 and a VPC in us-west-1
View answer
Correct Answer: C
Question #141
A solutions architect has developed a web application that uses an Amazon API Gateway Regional endpoint and an AWS Lambda function. The consumers of the web application are all close to the AWS Region where the application will be deployed. The Lambda function only queries an Amazon Aurora MySQL database. The solutions architect has configured the database to have three read replicas.During testing, the application does not meet performance requirements. Under high load, the application opens a large number of database connections. The solutions architect must improve the application’s performance.Which actions should the solutions architect take to meet these requirements? (Choose two.)
A. Use the cluster endpoint of the Aurora database
B. Use RDS Proxy to set up a connection pool to the reader endpoint of the Aurora database
C. Use the Lambda Provisioned Concurrency feature
D. Move the code for opening the database connection in the Lambda function outside of the event handler
E. Change the API Gateway endpoint to an edge-optimized endpoint
View answer
Correct Answer: BD
Question #142
A retail company is operating its ecommerce application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The company uses an Amazon RDS DB instance as the database backend. Amazon CloudFront is configured with one origin that points to the ALB. Static content is cached. Amazon Route 53 is used to host all public zones.After an update of the application, the ALB occasionally returns a 502 status code (Bad Gateway) error. The root cause is malformed HTTP headers that are returned to the ALB. The webpage returns successfully when a solutions architect reloads the webpage immediately after the error occurs.While the company is working on the problem, the solutions architect needs to provide a custom error page instead of the standard ALB error page to visitors.Which combination of steps will meet this requirement with the LEAST amount of operational overhead? (Choose two.)
A. Create an Amazon S3 bucket
B. Create an Amazon CloudWatch alarm to invoke an AWS Lambda function if the ALB health check response Target
C. Modify the existing Amazon Route 53 records by adding health checks
D. Create an Amazon CloudWatch alarm to invoke an AWS Lambda function if the ALB health check response Elb
E. Add a custom error response by configuring a CloudFront custom error page
View answer
Correct Answer: AE
Question #143
A company uses an on-premises data analytics platform. The system is highly available in a fully redundant configuration across 12 servers in the company’s data center.The system runs scheduled jobs, both hourly and daily, in addition to one-time requests from users. Scheduled jobs can take between 20 minutes and 2 hours to finish running and have tight SLAs. The scheduled jobs account for 65% of the system usage. User jobs typically finish running in less than 5 minutes and have no SLA. The user jobs account for 35% of system usage. During system failures, scheduled jobs must continue to meet SLAs. However, user jobs can be delayed.A solutions architect needs to move the system to Amazon EC2 instances and adopt a consumption-based model to reduce costs with no long-term commitments. The solution must maintain high availability and must not affect the SLAs.Which solution will meet these requirements MOST cost-effectively?
A. Split the 12 instances across two Availability Zones in the chosen AWS Region
B. Split the 12 instances across three Availability Zones in the chosen AWS Region
C. Split the 12 instances across three Availability Zones in the chosen AWS Region
D. Split the 12 instances across three Availability Zones in the chosen AWS Region
View answer
Correct Answer: D
Question #144
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #145
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #146
A company is running an application on several Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The load on the application varies throughout the day, and EC2 instances are scaled in and out on a regular basis. Log files from the EC2 instances are copied to a central Amazon S3 bucket every 15 minutes. The security team discovers that log files are missing from some of the terminated EC2 instances.Which set of actions will ensure that log files are copied to the central S3 bucket from the terminated EC2 instances?
A. Create a script to copy log files to Amazon S3, and store the script in a file on the EC2 instance
B. Create an AWS Systems Manager document with a script to copy log files to Amazon S3
C. Change the log delivery rate to every 5 minutes
D. Create an AWS Systems Manager document with a script to copy log files to Amazon S3
View answer
Correct Answer: B
Question #147
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #148
A company is developing a new service that will be accessed using TCP on a static port. A solutions architect must ensure that the service is highly available, has redundancy across Availability Zones, and is accessible using the DNS name my.service.com, which is publicly accessible. The service must use fixed address assignments so other companies can add the addresses to their allow lists.Assuming that resources are deployed in multiple Availability Zones in a single Region, which solution will meet these requirements?
A. Create Amazon EC2 instances with an Elastic IP address for each instance
B. Create an Amazon ECS cluster and a service definition for the application
C. Create Amazon EC2 instances for the service
D. Create an Amazon ECS cluster and a service definition for the application
View answer
Correct Answer: C
Question #149
A company with global offices has a single 1 Gbps AWS Direct Connect connection to a single AWS Region. The company’s on-premises network uses the connection to communicate with the company’s resources in the AWS Cloud. The connection has a single private virtual interface that connects to a single VPC.A solutions architect must implement a solution that adds a redundant Direct Connect connection in the same Region. The solution also must provide connectivity to other Regions through the same pair of Direct Connect connections as the company expands into other Regions.Which solution meets these requirements?
A. Provision a Direct Connect gateway
B. Keep the existing private virtual interface
C. Keep the existing private virtual interface
D. Provision a transit gateway
View answer
Correct Answer: A
Question #150
A video processing company has an application that downloads images from an Amazon S3 bucket, processes the images, stores a transformed image in a second S3 bucket, and updates metadata about the image in an Amazon DynamoDB table. The application is written in Node.js and runs by using an AWS Lambda function. The Lambda function is invoked when a new image is uploaded to Amazon S3.The application ran without incident for a while. However, the size of the images has grown significantly. The Lambda function is now failing frequently with timeout errors. The function timeout is set to its maximum value. A solutions architect needs to refactor the application’s architecture to prevent invocation failures. The company does not want to manage the underlying infrastructure.Which combination of steps should the solutions architect take to meet these requirements? (Choose two.)
A. Modify the application deployment by building a Docker image that contains the application code
B. Create a new Amazon Elastic Container Service (Amazon ECS) task definition with a compatibility type of AWS Fargate
C. Create an AWS Step Functions state machine with a Parallel state to invoke the Lambda function
D. Create a new Amazon Elastic Container Service (Amazon ECS) task definition with a compatibility type of Amazon EC2
E. Modify the application to store images on Amazon Elastic File System (Amazon EFS) and to store metadata on an Amazon RDS DB instance
View answer
Correct Answer: AB
Question #151
A company has a multi-tier web application that runs on a fleet of Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group. The ALB and the Auto Scaling group are replicated in a backup AWS Region. The minimum value and the maximum value for the Auto Scaling group are set to zero. An Amazon RDS Multi-AZ DB instance stores the application’s data. The DB instance has a read replica in the backup Region. The application presents an endpoint to end users by using an Amazon Route 53 record.The company needs to reduce its RTO to less than 15 minutes by giving the application the ability to automatically fail over to the backup Region. The company does not have a large enough budget for an active-active strategy.What should a solutions architect recommend to meet these requirements?
A. econfigure the application’s Route 53 record with a latency-based routing policy that load balances traffic between the two ALBs
B. reate an AWS Lambda function in the backup Region to promote the read replica and modify the Auto Scaling group values
C. onfigure the Auto Scaling group in the backup Region to have the same values as the Auto Scaling group in the primary Region
D. onfigure an endpoint in AWS Global Accelerator with the two ALBs as equal weighted targets
View answer
Correct Answer: B
Question #152
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #153
A retail company is hosting an ecommerce website on AWS across multiple AWS Regions. The company wants the website to be operational at all times for online purchases. The website stores data in an Amazon RDS for MySQL DB instance.Which solution will provide the HIGHEST availability for the database?
A. Configure automated backups on Amazon RDS
B. Configure global tables and read replicas on Amazon RDS
C. Configure global tables and automated backups on Amazon RDS
D. Configure read replicas on Amazon RDS
View answer
Correct Answer: D
Question #154
A company has migrated Its forms-processing application to AWS. When users interact with the application, they upload scanned forms as files through a web application. A database stores user metadata and references to files that are stored in Amazon S3. The web application runs on Amazon EC2 instances and an Amazon RDS for PostgreSQL database.When forms are uploaded, the application sends notifications to a team through Amazon Simple Notification Service (Amazon SNS). A team member then logs in and processes each form. The team member performs data validation on the form and extracts relevant data before entering the information into another system that uses an API.A solutions architect needs to automate the manual processing of the forms. The solution must provide accurate form extraction. minimize time to market, and minimize tong-term operational overhead.Which solution will meet these requirements?
A. Develop custom libraries to perform optical character recognition (OCR) on the forms
B. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
C. Host a new application tier on EC2 instances
D. Extend the system with an application tier that uses AWS Step Functions and AWS Lambda
View answer
Correct Answer: D
Question #155
A company hosts a metadata API on Amazon EC2 instances behind an internet-facing Application Load Balancer (ALB). Only internal applications that run on EC2 instances in separate AWS accounts need to access the metadata API. All the internal EC2 instances use NAT gateways.A new policy requires that traffic between internal applications must not travel across the public internet.Which solution will meet this requirement?
A. reate an HTTP API in Amazon API Gateway
B. reate an internal ALB
C. reate an internal ALB
D. reate a REST API in Amazon API Gateway
View answer
Correct Answer: C
Question #156
A company is hosting a critical application on a single Amazon EC2 instance. The application uses an Amazon ElastiCache for Redis single-node cluster for an in-memory data store. The application uses an Amazon RDS for MariaDB DB instance for a relational database. For the application to function, each piece of the infrastructure must be healthy and must be in an active state.A solutions architect needs to improve the application's architecture so that the infrastructure can automatically recover from failure with the least possible downtime.Which combination of steps will meet these requirements? (Choose three.)
A. se an Elastic Load Balancer to distribute traffic across multiple EC2 instances
B. se an Elastic Load Balancer to distribute traffic across multiple EC2 instances
C. odify the DB instance to create a read replica in the same Availability Zone
D. odify the DB instance to create a Multi-AZ deployment that extends across two Availability Zones
E. reate a replication group for the ElastiCache for Redis cluster
F. reate a replication group for the ElastiCache for Redis cluster
View answer
Correct Answer: ADF
Question #157
A company has 10 accounts that are part of an organization in AWS Organizations. AWS Config is configured in each account. All accounts belong to either the Prod OU or the NonProd OU.The company has set up an Amazon EventBridge rule in each AWS account to notify an Amazon Simple Notification Service (Amazon SNS) topic when an Amazon EC2 security group inbound rule is created with 0.0.0.0/0 as the source. The company’s security team is subscribed to the SNS topic.For all accounts in the NonProd OU, the security team needs to remove the ability to create a security group inbound rule that includes 0.0.0.0/0 as the source.Which solution will meet this requirement with the LEAST operational overhead?
A. odify the EventBridge rule to invoke an AWS Lambda function to remove the security group inbound rule and to publish to the SNS topic
B. dd the vpc-sg-open-only-to-authorized-ports AWS Config managed rule to the NonProd OU
C. onfigure an SCP to allow the ec2:AuthorizeSecurityGroupIngress action when the value of the aws:SourceIp condition key is not 0
D. onfigure an SCP to deny the ec2:AuthorizeSecurityGroupIngress action when the value of the aws:SourceIp condition key is 0
View answer
Correct Answer: D
Question #158
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #159
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #160
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #161
A company has created an OU in AWS Organizations for each of its engineering teams. Each OU owns multiple AWS accounts. The organization has hundreds of AWS accounts.A solutions architect must design a solution so that each OU can view a breakdown of usage costs across its AWS accounts.Which solution meets these requirements?
A. Create an AWS Cost and Usage Report (CUR) for each OU by using AWS Resource Access Manager
B. Create an AWS Cost and Usage Report (CUR) from the AWS Organizations management account
C. Create an AWS Cost and Usage Report (CUR) in each AWS Organizations member account
D. Create an AWS Cost and Usage Report (CUR) by using AWS Systems Manager
View answer
Correct Answer: B
Question #162
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #163
A company has its cloud infrastructure on AWS. A solutions architect needs to define the infrastructure as code. The infrastructure is currently deployed in one AWS Region. The company’s business expansion plan includes deployments in multiple Regions across multiple AWS accounts.What should the solutions architect do to meet these requirements?
A. Use AWS CloudFormation templates
B. Use AWS Organizations
C. Use AWS Organizations and AWS CloudFormation StackSets
D. Use nested stacks with AWS CloudFormation templates
View answer
Correct Answer: C
Question #164
A company runs an IoT platform on AWS. IoT sensors in various locations send data to the company’s Node.js API servers on Amazon EC2 instances running behind an Application Load Balancer. The data is stored in an Amazon RDS MySQL DB instance that uses a 4 TB General Purpose SSD volume.The number of sensors the company has deployed in the field has increased over time, and is expected to grow significantly. The API servers are consistently overloaded and RDS metrics show high write latency.Which of the following steps together will resolve the issues permanently and enable growth as new sensors are provisioned, while keeping this platform cost-efficient? (Choose two.)
A. Resize the MySQL General Purpose SSD storage to 6 TB to improve the volume’s IOPS
B. Re-architect the database tier to use Amazon Aurora instead of an RDS MySQL DB instance and add read replicas
C. Leverage Amazon Kinesis Data Streams and AWS Lambda to ingest and process the raw data
D. Use AWS X-Ray to analyze and debug application issues and add more API servers to match the load
E. Re-architect the database tier to use Amazon DynamoDB instead of an RDS MySQL DB instance
View answer
Correct Answer: CE
Question #165
A company is running a two-tier web-based application in an on-premises data center. The application layer consists of a single server running a stateful application. The application connects to a PostgreSQL database running on a separate server. The application’s user base is expected to grow significantly, so the company is migrating the application and database to AWS. The solution will use Amazon Aurora PostgreSQL, Amazon EC2 Auto Scaling, and Elastic Load Balancing.Which solution will provide a consistent user experience that will allow the application and database tiers to scale?
A. Enable Aurora Auto Scaling for Aurora Replicas
B. Enable Aurora Auto Scaling for Aurora writers
C. Enable Aurora Auto Scaling for Aurora Replicas
D. Enable Aurora Scaling for Aurora writers
View answer
Correct Answer: C
Question #166
A company is running an application on several Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The load on the application varies throughout the day, and EC2 instances are scaled in and out on a regular basis. Log files from the EC2 instances are copied to a central Amazon S3 bucket every 15 minutes. The security team discovers that log files are missing from some of the terminated EC2 instances.Which set of actions will ensure that log files are copied to the central S3 bucket from the terminated EC2 instances?
A. Create a script to copy log files to Amazon S3, and store the script in a file on the EC2 instance
B. Create an AWS Systems Manager document with a script to copy log files to Amazon S3
C. Change the log delivery rate to every 5 minutes
D. Create an AWS Systems Manager document with a script to copy log files to Amazon S3
View answer
Correct Answer: B
Question #167
A company is running a two-tier web-based application in an on-premises data center. The application layer consists of a single server running a stateful application. The application connects to a PostgreSQL database running on a separate server. The application’s user base is expected to grow significantly, so the company is migrating the application and database to AWS. The solution will use Amazon Aurora PostgreSQL, Amazon EC2 Auto Scaling, and Elastic Load Balancing.Which solution will provide a consistent user experience that will allow the application and database tiers to scale?
A. Enable Aurora Auto Scaling for Aurora Replicas
B. Enable Aurora Auto Scaling for Aurora writers
C. Enable Aurora Auto Scaling for Aurora Replicas
D. Enable Aurora Scaling for Aurora writers
View answer
Correct Answer: C
Question #168
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #169
A company has 50 AWS accounts that are members of an organization in AWS Organizations. Each account contains multiple VPCs. The company wants to use AWS Transit Gateway to establish connectivity between the VPCs in each member account. Each time a new member account is created, the company wants to automate the process of creating a new VPC and a transit gateway attachment.Which combination of steps will meet these requirements? (Choose two.)
A. From the management account, share the transit gateway with member accounts by using AWS Resource Access Manager
B. From the management account, share the transit gateway with member accounts by using an AWS Organizations SCP
C. Launch an AWS CloudFormation stack set from the management account that automatically creates a new VPC and a VPC transit gateway attachment in a member account
D. Launch an AWS CloudFormation stack set from the management account that automatically creates a new VPC and a peering transit gateway attachment in a member account
E. From the management account, share the transit gateway with member accounts by using AWS Service Catalog
View answer
Correct Answer: AC
Question #170
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #171
A video processing company wants to build a machine learning (ML) model by using 600 TB of compressed data that is stored as thousands of files in the company's on-premises network attached storage system. The company does not have the necessary compute resources on premises for ML experiments and wants to use AWS.The company needs to complete the data transfer to AWS within 3 weeks. The data transfer will be a one-time transfer. The data must be encrypted in transit. The measured upload speed of the company's internet connection is 100 Mbps. and multiple departments share the connection.Which solution will meet these requirements MOST cost-effectively?
A. Order several AWS Snowball Edge Storage Optimized devices by using the AWS Management Console
B. Set up a 10 Gbps AWS Direct Connect connection between the company location and the nearest AWS Region
C. Create a VPN connection between the on-premises network attached storage and the nearest AWS Region
D. Deploy an AWS Storage Gateway file gateway on premises
View answer
Correct Answer: A
Question #172
A company used Amazon EC2 instances to deploy a web fleet to host a blog site. The EC2 instances are behind an Application Load Balancer (ALB) and are configured in an Auto Scaling group. The web application stores all blog content on an Amazon EFS volume.The company recently added a feature for bloggers to add video to their posts, attracting 10 times the previous user traffic. At peak times of day, users report buffering and timeout issues while attempting to reach the site or watch videos.Which is the MOST cost-efficient and scalable deployment that will resolve the issues for users?
A. Reconfigure Amazon EFS to enable maximum I/O
B. Update the blog site to use instance store volumes for storage
C. Configure an Amazon CloudFront distribution
D. Set up an Amazon CloudFront distribution for all site contents, and point the distribution at the ALB
View answer
Correct Answer: C
Question #173
A company uses an on-premises data analytics platform. The system is highly available in a fully redundant configuration across 12 servers in the company’s data center.The system runs scheduled jobs, both hourly and daily, in addition to one-time requests from users. Scheduled jobs can take between 20 minutes and 2 hours to finish running and have tight SLAs. The scheduled jobs account for 65% of the system usage. User jobs typically finish running in less than 5 minutes and have no SLA. The user jobs account for 35% of system usage. During system failures, scheduled jobs must continue to meet SLAs. However, user jobs can be delayed.A solutions architect needs to move the system to Amazon EC2 instances and adopt a consumption-based model to reduce costs with no long-term commitments. The solution must maintain high availability and must not affect the SLAs.Which solution will meet these requirements MOST cost-effectively?
A. Split the 12 instances across two Availability Zones in the chosen AWS Region
B. Split the 12 instances across three Availability Zones in the chosen AWS Region
C. Split the 12 instances across three Availability Zones in the chosen AWS Region
D. Split the 12 instances across three Availability Zones in the chosen AWS Region
View answer
Correct Answer: D
Question #174
A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company’s on-premises network. Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.Which solution meets these requirements with the LEAST amount of operational overhead?
A. Set up an Amazon Simple Notification Service (Amazon SNS) topic in the security team's AWS account
B. Create new customer-managed prefix lists in each AWS account within the organization
C. Create a new customer-managed prefix list in the security team’s AWS account
D. Create an IAM role in each account in the organization
View answer
Correct Answer: C
Question #175
A company is running an application in the AWS Cloud. The application collects and stores a large amount of unstructured data in an Amazon S3 bucket. The S3 bucket contains several terabytes of data and uses the S3 Standard storage class. The data increases in size by several gigabytes every day.The company needs to query and analyze the data. The company does not access data that is more than 1 year old. However, the company must retain all the data indefinitely for compliance reasons.Which solution will meet these requirements MOST cost-effectively?
A. Use S3 Select to query the data
B. Use Amazon Redshift Spectrum to query the data
C. Use an AWS Glue Data Catalog and Amazon Athena to query the data
D. Use Amazon Redshift Spectrum to query the data
View answer
Correct Answer: C
Question #176
A company has VPC flow logs enabled for Its NAT gateway. The company is seeing Action = ACCEPT for inbound traffic that comes from public IP address 198.51.100.2 destined for a private Amazon EC2 instance.A solutions architect must determine whether the traffic represents unsolicited inbound connections from the internet. The first two octets of the VPC CIDR block are 203.0.Which set of steps should the solutions architect take to meet these requirements?
A. Open the AWS CloudTrail console
B. Open the Amazon CloudWatch console
C. Open the AWS CloudTrail console
D. Open the Amazon CloudWatch console
View answer
Correct Answer: B
Question #177
A company needs to architect a hybrid DNS solution. This solution will use an Amazon Route 53 private hosted zone for the domain cloud.example.com for the resources stored within VPCs.The company has the following DNS resolution requirements:On-premises systems should be able to resolve and connect to cloud.example.com.All VPCs should be able to resolve cloud.example.com.There is already an AWS Direct Connect connection between the on-premises corporate network and AWS Transit Gateway.Which architecture should the company use to meet these requirements with the HIGHEST performance?
A. Associate the private hosted zone to all the VPCs
B. Associate the private hosted zone to all the VPCs
C. Associate the private hosted zone to the shared services VPCreate a Route 53 outbound resolver in the shared services VPAttach all VPCs to the transit gateway and create forwarding rules in the on-premises DNS server for cloud
D. Associate the private hosted zone to the shared services VPC
View answer
Correct Answer: D
Question #178
A company has developed a new release of a popular video game and wants to make it available for public download. The new release package is approximately 5 GB in size. The company provides downloads for existing releases from a Linux-based, publicly facing FTP site hosted in an on-premises data center. The company expects the new release will be downloaded by users worldwide.
A. Store the game files on Amazon EBS volumes mounted on Amazon EC2 instances within an Auto Scaling group Configure an FTP service on the EC2 instances Use an Application Load Balancer in front of the Auto Scaling group
B. Store the game files on Amazon EFS volumes that are attached to Amazon EC2 instances within an Auto Scaling group Configure an FTP service on each of the EC2 instances Use an Application Load Balancer in front of the Auto Scaling group Publish the game download URL for users to download the package
C. Configure Amazon Route 53 and an Amazon S3 bucket for website hosting Upload the game files to the S3 bucket Use Amazon CloudFront for the website Publish the game download URL for users to download the package
D. Configure Amazon Route 53 and an Amazon S3 bucket for website hosting Upload the game files to the S3 bucket Set Requester Pays for the S3 bucket Publish the game download URL for users to download the package
View answer
Correct Answer: C
Question #179
An enterprise company wants to allow its developers to purchase third-party software through AWS Marketplace. The company uses an AWS Organizations account structure with full features enabled, and has a shared services account in each organizational unit (OU) that will be used by procurement managers. The procurement team’s policy indicates that developers should be able to obtain third-party software from an approved list only and use Private Marketplace in AWS Marketplace to achieve this requirement. The procurement team wants administration of Private Marketplace to be restricted to a role named procurement-manager-role, which could be assumed by procurement managers. Other IAM users, groups, roles, and account administrators in the company should be denied Private Marketplace administrative access.What is the MOST efficient way to design an architecture to meet these requirements?
A. Create an IAM role named procurement-manager-role in all AWS accounts in the organization
B. Create an IAM role named procurement-manager-role in all AWS accounts in the organization
C. Create an IAM role named procurement-manager-role in all the shared services accounts in the organization
D. Create an IAM role named procurement-manager-role in all AWS accounts that will be used by developers
View answer
Correct Answer: C
Question #180
A company is planning to host a web application on AWS and wants to load balance the traffic across a group of Amazon EC2 instances. One of the security requirements is to enable end-to-end encryption in transit between the client and the web server.Which solution will meet this requirement?
A. Place the EC2 instances behind an Application Load Balancer (ALB)
B. Associate the EC2 instances with a target group
C. Place the EC2 instances behind an Application Load Balancer (ALB) Provision an SSL certificate using AWS Certificate Manager (ACM), and associate the SSL certificate with the ALB
D. Place the EC2 instances behind a Network Load Balancer (NLB)
View answer
Correct Answer: C
Question #181
A company with several AWS accounts is using AWS Organizations and service control policies (SCPs). An administrator created the following SCP and has attached it to an organizational unit (OU) that contains AWS account 1111-1111-1111:Developers working in account 1111-1111-1111 complain that they cannot create Amazon S3 buckets. How should the administrator address this problem?
A. Add s3:CreateBucket with “Allow” effect to the SCP
B. Remove the account from the OU, and attach the SCP directly to account 1111-1111-1111
C. Instruct the developers to add Amazon S3 permissions to their IAM entities
D. Remove the SCP from account 1111-1111-1111
View answer
Correct Answer: C
Question #182
Example Corp. has an on-premises data center and a VPC named VPC A in the Example Corp. AWS account. The on-premises network connects to VPC A through an AWS Site-To-Site VPN. The on-premises servers can properly access VPC A. Example Corp. just acquired AnyCompany, which has a VPC named VPC B. There is no IP address overlap among these networks. Example Corp. has peered VPC A and VPC B.Example Corp. wants to connect from its on-premise servers to VPC B. Example Corp. has properly set up the network ACL and security groups.Which solution will meet this requirement with the LEAST operational effort?
A. Create a transit gateway
B. Create a transit gateway
C. Update the route tables for the Site-to-Site VPN and both VPCs for all three networks
D. Modify the Site-to-Site VPN’s virtual private gateway definition to include VPC A and VPC B
View answer
Correct Answer: A
Question #183
A company consists or two separate business units. Each business unit has its own AWS account within a single organization in AWS Organizations. The business units regularly share sensitive documents with each other. To facilitate sharing, the company created an Amazon S3 bucket in each account and configured low-way replication between the S3 buckets. The S3 buckets have millions of objects.Recently, a security audit identified that neither S3 bucket has encryption at rest enabled. Company policy requires that all documents must be stored with encryption at rest. The company wants to implement server-side encryption with Amazon S3 managed encryption keys (SSE-S3).What is the MOST operationally efficient solution that meets these requirements?
A. Turn on SSE-S3 on both S3 buckets
B. Create an AWS Key Management Service (AWS KMS) key in each account
C. Turn on SSE-S3 on both S3 buckets
D. Create an AWS Key Management Service, (AWS KMS) key in each account
View answer
Correct Answer: A
Question #184
A video streaming company recently launched a mobile app for video sharing. The app uploads various files to an Amazon S3 bucket in the us-east-1 Region. The files range in size from 1 GB to 10 GB.Users who access the app from Australia have experienced uploads that take long periods of time. Sometimes the files fail to completely upload for these users. A solutions architect must improve the app’s performance for these uploads.Which solutions will meet these requirements? (Choose two.)
A. Enable S3 Transfer Acceleration on the S3 bucket
B. Configure an S3 bucket in each Region to receive the uploads
C. Set up Amazon Route 53 with latency-based routing to route the uploads to the nearest S3 bucket Region
D. Configure the app to break the video files into chunks
E. Modify the app to add random prefixes to the files before uploading
View answer
Correct Answer: AD
Question #185
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #186
A retail company is operating its ecommerce application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The company uses an Amazon RDS DB instance as the database backend. Amazon CloudFront is configured with one origin that points to the ALB. Static content is cached. Amazon Route 53 is used to host all public zones.After an update of the application, the ALB occasionally returns a 502 status code (Bad Gateway) error. The root cause is malformed HTTP headers that are returned to the ALB. The webpage returns successfully when a solutions architect reloads the webpage immediately after the error occurs.While the company is working on the problem, the solutions architect needs to provide a custom error page instead of the standard ALB error page to visitors.Which combination of steps will meet this requirement with the LEAST amount of operational overhead? (Choose two.)
A. Create an Amazon S3 bucket
B. Create an Amazon CloudWatch alarm to invoke an AWS Lambda function if the ALB health check response Target
C. Modify the existing Amazon Route 53 records by adding health checks
D. Create an Amazon CloudWatch alarm to invoke an AWS Lambda function if the ALB health check response Elb
E. Add a custom error response by configuring a CloudFront custom error page
View answer
Correct Answer: AE
Question #187
A company has an organization in AWS Organizations. The company is using AWS Control Tower to deploy a landing zone for the organization. The company wants to implement governance and policy enforcement. The company must implement a policy that will detect Amazon RDS DB instances that are not encrypted at rest in the company’s production OU.Which solution will meet this requirement?
A. Turn on mandatory guardrails in AWS Control Tower
B. Enable the appropriate guardrail from the list of strongly recommended guardrails in AWS Control Tower
C. Use AWS Config to create a new mandatory guardrail
D. Create a custom SCP in AWS Control Tower
View answer
Correct Answer: B
Question #188
A company has registered 10 new domain names. The company uses the domains for online marketing. The company needs a solution that will redirect online visitors to a specific URL for each domain. All domains and target URLs are defined in a JSON document. All DNS records are managed by Amazon Route 53.A solutions architect must implement a redirect service that accepts HTTP and HTTPS requests.Which combination of steps should the solutions architect take to meet these requirements with the LEAST amount of operational effort? (Choose three.)
A. Create a dynamic webpage that runs on an Amazon EC2 instance
B. Create an Application Load Balancer that includes HTTP and HTTPS listeners
C. Create an AWS Lambda function that uses the JSON document in combination with the event message to look up and respond with a redirect URL
D. Use an Amazon API Gateway API with a custom domain to publish an AWS Lambda function
E. Create an Amazon CloudFront distribution
F. Create an SSL certificate by using AWS Certificate Manager (ACM)
View answer
Correct Answer: BCF
Question #189
A company has a serverless application comprised of Amazon CloudFront, Amazon API Gateway, and AWS Lambda functions. The current deployment process of the application code is to create a new version number of the Lambda function and run an AWS CLI script to update. If the new function version has errors, another CLI script reverts by deploying the previous working version of the function. The company would like to decrease the time to deploy new versions of the application logic provided by the Lambda functions, and also reduce the time to detect and revert when errors are identified.How can this be accomplished?
A. Create and deploy nested AWS CloudFormation stacks with the parent stack consisting of the AWS CloudFront distribution and API Gateway, and the child stack containing the Lambda function
B. Use AWS SAM and built-in AWS CodeDeploy to deploy the new Lambda version, gradually shift traffic to the new version, and use pre-traffic and post-traffic test functions to verify code
C. Refactor the AWS CLI scripts into a single script that deploys the new Lambda version
D. Create and deploy an AWS CloudFormation stack that consists of a new API Gateway endpoint that references the new Lambda version
View answer
Correct Answer: B
Question #190
A company is running a data-intensive application on AWS. The application runs on a cluster of hundreds of Amazon EC2 instances. A shared file system also runs on several EC2 instances that store 200 TB of data. The application reads and modifies the data on the shared file system and generates a report. The job runs once monthly, reads a subset of the files from the shared file system, and takes about 72 hours to complete. The compute instances scale in an Auto Scaling group, but the instances that host the shared file system run continuously. The compute and storage instances are all in the same AWS Region.A solutions architect needs to reduce costs by replacing the shared file system instances. The file system must provide high performance access to the needed data for the duration of the 72-hour run.Which solution will provide the LARGEST overall cost reduction while meeting these requirements?
A. Migrate the data from the existing shared file system to an Amazon S3 bucket that uses the S3 Intelligent-Tiering storage class
B. Migrate the data from the existing shared file system to a large Amazon Elastic Block Store (Amazon EBS) volume with Multi-Attach enabled
C. Migrate the data from the existing shared file system to an Amazon S3 bucket that uses the S3 Standard storage class
D. Migrate the data from the existing shared file system to an Amazon S3 bucket
View answer
Correct Answer: A
Question #191
A company has developed a web application. The company is hosting the application on a group of Amazon EC2 instances behind an Application Load Balancer. The company wants to improve the security posture of the application and plans to use AWS WAF web ACLs. The solution must not adversely affect legitimate traffic to the application.How should a solutions architect configure the web ACLs to meet these requirements?
A. Set the action of the web ACL rules to Count
B. Use only rate-based rules in the web ACLs, and set the throttle limit as high as possible
C. Set the action of the web ACL rules to Block
D. Use only custom rule groups in the web ACLs, and set the action to Allow
View answer
Correct Answer: A
Question #192
A company has 50 AWS accounts that are members of an organization in AWS Organizations. Each account contains multiple VPCs. The company wants to use AWS Transit Gateway to establish connectivity between the VPCs in each member account. Each time a new member account is created, the company wants to automate the process of creating a new VPC and a transit gateway attachment.Which combination of steps will meet these requirements? (Choose two.)
A. From the management account, share the transit gateway with member accounts by using AWS Resource Access Manager
B. From the management account, share the transit gateway with member accounts by using an AWS Organizations SCP
C. Launch an AWS CloudFormation stack set from the management account that automatically creates a new VPC and a VPC transit gateway attachment in a member account
D. Launch an AWS CloudFormation stack set from the management account that automatically creates a new VPC and a peering transit gateway attachment in a member account
E. From the management account, share the transit gateway with member accounts by using AWS Service Catalog
View answer
Correct Answer: AC
Question #193
A company is building an electronic document management system in which users upload their documents. The application stack is entirely serverless and runs on AWS in the eu-central-1 Region. The system includes a web application that uses an Amazon CloudFront distribution for delivery with Amazon S3 as the origin. The web application communicates with Amazon API Gateway Regional endpoints. The API Gateway APIs call AWS Lambda functions that store metadata in an Amazon Aurora Serverless database and put the documents into an S3 bucket.The company is growing steadily and has completed a proof of concept with its largest customer. The company must improve latency outside of Europe.Which combination of actions will meet these requirements? (Choose two.)
A. Enable S3 Transfer Acceleration on the S3 bucket
B. Create an accelerator in AWS Global Accelerator
C. Change the API Gateway Regional endpoints to edge-optimized endpoints
D. Provision the entire stack in two other locations that are spread across the world
E. Add an Amazon RDS proxy between the Lambda functions and the Aurora Serverless database
View answer
Correct Answer: AC
Question #194
A company is developing a new service that will be accessed using TCP on a static port. A solutions architect must ensure that the service is highly available, has redundancy across Availability Zones, and is accessible using the DNS name my.service.com, which is publicly accessible. The service must use fixed address assignments so other companies can add the addresses to their allow lists.Assuming that resources are deployed in multiple Availability Zones in a single Region, which solution will meet these requirements?
A. Create Amazon EC2 instances with an Elastic IP address for each instance
B. Create an Amazon ECS cluster and a service definition for the application
C. Create Amazon EC2 instances for the service
D. Create an Amazon ECS cluster and a service definition for the application
View answer
Correct Answer: C
Question #195
A financial services company in North America plans to release a new online web application to its customers on AWS. The company will launch the application in the us-east-1 Region on Amazon EC2 instances. The application must be highly available and must dynamically scale to meet user traffic. The company also wants to implement a disaster recovery environment for the application in the us-west-1 Region by using active-passive failover.Which solution will meet these requirements?
A. Create a VPC in us-east-1 and a VPC in us-west-1
B. Create a VPC in us-east-1 and a VPC in us-west-1
C. Create a VPC in us-east-1 and a VPC in us-west-1
D. Create a VPC in us-east-1 and a VPC in us-west-1
View answer
Correct Answer: C
Question #196
A company has a monolithic application that is critical to the company’s business. The company hosts the application on an Amazon EC2 instance that runs Amazon Linux 2. The company’s application team receives a directive from the legal department to back up the data from the instance’s encrypted Amazon Elastic Block Store (Amazon EBS) volume to an Amazon S3 bucket. The application team does not have the administrative SSH key pair for the instance. The application must continue to serve the users.Which solution will meet these requirements?
A. Attach a role to the instance with permission to write to Amazon S3
B. Create an image of the instance with the reboot option turned on
C. Take a snapshot of the EBS volume by using Amazon Data Lifecycle Manager (Amazon DLM)
D. Create an image of the instance
View answer
Correct Answer: A
Question #197
A company uses AWS Organizations with a single OU named Production to manage multiple accounts. All accounts are members of the Production OU. Administrators use deny list SCPs in the root of the organization to manage access to restricted services.The company recently acquired a new business unit and invited the new unit’s existing AWS account to the organization. Once onboarded, the administrators of the new business unit discovered that they are not able to update existing AWS Config rules to meet the company’s policies.Which option will allow administrators to make changes and continue to enforce the current policies without introducing additional long-term maintenance?
A. Remove the organization’s root SCPs that limit access to AWS Config
B. Create a temporary OU named Onboarding for the new account
C. Convert the organization’s root SCPs from deny list SCPs to allow list SCPs to allow the required services only
D. Create a temporary OU named Onboarding for the new account
View answer
Correct Answer: D
Question #198
A company is planning to store a large number of archived documents and make the documents available to employees through the corporate intranet. Employees will access the system by connecting through a client VPN service that is attached to a VPC. The data must not be accessible to the public.The documents that the company is storing are copies of data that is held on physical media elsewhere. The number of requests will be low. Availability and speed of retrieval are not concerns of the company.Which solution will meet these requirements at the LOWEST cost?
A. Create an Amazon S3 bucket
B. Launch an Amazon EC2 instance that runs a web server
C. Launch an Amazon EC2 instance that runs a web server Attach an Amazon Elastic Block Store (Amazon EBS) volume to store the archived data
D. Create an Amazon S3 bucket
View answer
Correct Answer: A
Question #199
A company wants to migrate its data analytics environment from on premises to AWS. The environment consists of two simple Node.js applications. One of the applications collects sensor data and loads it into a MySQL database. The other application aggregates the data into reports. When the aggregation jobs run, some of the load jobs fail to run correctly.The company must resolve the data loading issue. The company also needs the migration to occur without interruptions or changes for the company’s customers.What should a solutions architect do to meet these requirements?
A. Set up an Amazon Aurora MySQL database as a replication target for the on-premises database
B. Set up an Amazon Aurora MySQL database
C. Set up an Amazon Aurora MySQL database
D. Set up an Amazon Aurora MySQL database
View answer
Correct Answer: C
Question #200
A company ingests and processes streaming market data. The data rate is constant. A nightly process that calculates aggregate statistics is run, and each execution takes about 4 hours to complete. The statistical analysis is not mission critical to the business, and previous data points are picked up on the next execution if a particular run fails.The current architecture uses a pool of Amazon EC2 Reserved Instances with 1-year reservations running full time to ingest and store the streaming data in attached Amazon EBS volumes. On-Demand EC2 instances are launched each night to perform the nightly processing, accessing the stored data from NFS shares on the ingestion servers, and terminating the nightly processing servers when complete. The Reserved Instance reservations are expiring, and the company needs to determine whether to purchase new reservations or implement a new design.Which is the most cost-effective design?
A. Update the ingestion process to use Amazon Kinesis Data Firehose to save data to Amazon S3
B. Update the ingestion process to use Amazon Kinesis Data Firehose to save data to Amazon S3
C. Update the ingestion process to use a fleet of EC2 Reserved Instances with 3-year reservations behind a Network Load Balancer
D. Update the ingestion process to use Amazon Kinesis Data Firehose to save data to Amazon Redshift
View answer
Correct Answer: B

View The Updated AWS Exam Questions

SPOTO Provides 100% Real AWS Exam Questions for You to Pass Your AWS Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us