SAP-C02 practice questions
AWS · SAP-C02 · 300 questions
This practice test covers the AWS Certified Solutions Architect – Professional certification exam. Test your knowledge across all domains and topics outlined in the official exam guide.
This course contains the use of artificial intelligence.
About the SAP-C02 exam
- Exam fee
- $300 USD
- Time allowed
- 3 hours
- Questions
- 75
- Passing score
- 750 (scale 100-1000)
- Format
- Multiple choice or multiple response
Exam details published by the vendor, checked 28 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Design Solutions for Organizational Complexity · 78 questions
- A county needs separate VPCs for assessor, courts, and public works that must reach a central shared-services VPC for Active Directory and logging without creating a full mesh of VPC peerings. Which connectivity design best meets this requirement?
- A city utility must connect on-premises SCADA historians to an analytics VPC with consistent low latency and dedicated bandwidth for continuous telemetry. Which hybrid connectivity approach best fits these requirements?
- A regional library consortium already uses AWS Direct Connect for catalog syncs into one Region and must remain connected if the Direct Connect circuit fails. Which hybrid design provides resilient private connectivity?
- A transit authority requires bidirectional hybrid DNS: on-premises resolvers must answer queries for private Route 53 records in AWS, and domain-joined jump hosts in AWS must resolve corporate DNS names. Which approach meets this need?
- A school district must segment student SIS, staff administration, and guest Wi-Fi backends into separate subnets or VPCs, block casual lateral movement, and still allow tightly controlled access to shared services such as directory and logging. Which design best achieves this?
- A public-health department runs workloads in private subnets that must reach Amazon S3 and Amazon DynamoDB APIs without sending that traffic across the public internet or a NAT Gateway. Which design satisfies this requirement?
- Two cities merging IT operations both use overlapping 10.0.0.0/8 addressing and must connect selected workloads into AWS without renumbering every on-premises network on day one. Which approach best addresses the overlapping CIDR constraint?
- A county must choose AWS Regions for a citizen portal where data-residency rules constrain allowable locations and page-load latency for residents also matters. Which Region and AZ selection approach best balances these requirements?
- A municipal security operations center needs flow-level visibility of east-west traffic across Transit Gateway attachments to investigate anomalous paths between department VPCs. Which monitoring approach best supports this investigation?
- A parks department runs an ECS container platform in a shared city VPC alongside other applications and needs controlled egress plus tightly scoped service-to-service connectivity. Which networking approach best fits this multi-app VPC?
- A water utility hosts burst analytics gear in a co-location cage and must connect that environment to AWS for periodic large transfers. Architects must choose among Direct Connect, Site-to-Site VPN, and public endpoints. Which evaluation best matches professional hybrid design?
- A city's hub-and-spoke Transit Gateway design accidentally allows a sandbox account VPC to reach production courts systems through transitive routes. Which control best remediates this?
- A county application team proposes peering every microservice VPC to every other microservice VPC. The architect must recommend a scalable alternative for multi-VPC connectivity. What should the architect recommend?
- A municipal API in a shared networking account must privately reach Network Load Balancer targets that live in a spoke VPC application account without opening the spoke to broad network routing. Which pattern best fits?
- During an outage, a city network team must determine whether traffic is blackholed by a Transit Gateway route table misconfiguration, a network ACL deny, or a security group rule. Which troubleshooting approach is most appropriate?
- A regional emergency-management organization runs workloads across multiple Availability Zones but terminates all Direct Connect virtual interfaces on a single path lacking diversity. What should a resilience review recommend?
- A county workforce must sign in to many AWS accounts using Microsoft Entra ID without creating long-lived IAM users in each account. Which approach best meets this requirement?
- A city auditor requires that a contractor AWS account may deploy into a project account only through a break-glass role that enforces MFA and short session durations. Which cross-account access design best satisfies the auditor?
- A courts system must encrypt case files at rest so cryptographic key control remains with the justice AWS account rather than depending only on default keys owned by a shared security account. Which encryption strategy best meets this ownership requirement?
- A public permits website terminates TLS on Application Load Balancers across multiple AWS accounts and needs centrally requestable certificates with automatic renewal. Which certificate approach best fits?
- A municipality wants centralized detection of overly permissive IAM policies and unintended public resource exposure across all Organization accounts. Which security approach best provides these findings?
- All CloudTrail management events from every municipal AWS account must be delivered to an immutable logging-account bucket that member accounts cannot alter. Which auditing strategy best meets this requirement?
- A utility OT/IT bridge VPC must allow historian hosts to reach analytics only on specific ports, using security groups as the primary instance-level control and network ACLs as coarse subnet guardrails. Which prescription is correct?
- Resident PII moves from a public citizen portal to internal APIs and must remain encrypted in transit across public TLS termination and private backend hops. Which design best satisfies encryption-in-transit requirements?
- A school district wants continuous vulnerability visibility for Amazon EC2 instances and container images used by student-facing systems. Which service prescription best meets this need?
- After a phishing wave, a city needs org-wide visibility into suspicious API activity correlated across accounts for investigation and notifications. Which approach should the architect prescribe?
- A library consortium must prevent member libraries' accounts from disabling CloudTrail or creating unrestricted IAM admin users, while still detecting risky configurations. Which design best combines preventive and detective controls?
- Cross-account analytics consumers need access to a municipal shared data lake. Direct long-term access keys are rejected by security. How should consumers authenticate?
- A county encrypts tax data with AWS KMS and must separate key administrators from key users while enabling automatic key rotation where appropriate. Which design should the architect prescribe?
- Architects must not conflate citizen-facing sign-in with workforce AWS access for a municipal portal. Which identity pattern is correct?
- A municipal Security Hub administrator account aggregates findings. Leadership requires that member accounts cannot silently mute critical GuardDuty findings from central view. What should the architect emphasize?
- During review, route tables in a shared networking account send 0.0.0.0/0 from a protected subnet toward an inspection VPC rather than directly to an internet gateway. How should the architect treat that design?
- A 911 CAD system requires an RTO of minutes and near-zero RPO across Regions. A team proposes pilot light only. What should the architect recommend?
- A county property database needs automated failover across Availability Zones; multi-Region DR is optional for cost reasons. Which recommendation fits?
- A city needs continuous block-level replication and orchestrated failover for lift-and-shifted VMs, not only periodic AMI copies. Which service should the architect select?
- Court recordings require immutable retention and proof that restores work. Untested snapshots alone are insufficient. What should the backup strategy include?
- A municipal web tier must replace unhealthy instances automatically without waiting for human change windows. Which architecture best meets that requirement?
- Permit-application workers see seasonal peaks. Leadership prefers resilient capacity over vertical scale-up of one large instance. What should the architect recommend?
- Utility meter readings have a 15-minute RPO. Which data protection approach should the architect select?
- A library catalog must meet a stated RTO in a second Region while keeping costs lower than active-active multi-site. Which DR pattern fits best?
- A grants portal DR design should keep a minimal core data plane running in a standby Region and scale out only after disaster declaration. Which pattern is that?
- Private subnet egress depends on a single NAT Gateway in one Availability Zone. What redesign removes that single point of failure?
- Tax archives need automated cross-Region backup copies encrypted with KMS keys usable in the destination Region. Which design is appropriate?
- City leadership states that losing the last hour of 311 tickets after failover is unacceptable. How should that statement drive architecture?
- A damaged schema deploy corrupts data in a municipal database. Multi-AZ failover alone does not fix the logical corruption. What should the architect rely on?
- Emergency-management DR runbooks currently launch AMIs by hand. What improvement should the architect prioritize?
- A statewide alerts system targets multi-site active-active DR. What implication must the architecture address beyond duplicating web tiers?
- A newly consolidated metro government needs AWS accounts for security, logging, shared networking, sandboxes, and each department workload. Which structure should the architect evaluate first?
- A county previously created AWS accounts ad hoc and now wants standardized landing zones with guardrails. Which service should the architect recommend to baseline that multi-account governance?
- Member accounts must be prevented from leaving the organization or disabling central security services. Which governance control should the architect apply?
- A county SOC wants CloudWatch alarms and EventBridge security events from every workload account to land in one security and operations account so on-call can respond from a single place. Which multi-account notification strategy best meets that need?
- A network account owns a Transit Gateway and a Route 53 Resolver rule set that parks, courts, and public-works accounts must use without recreating those resources. How should those networking assets be shared?
- A municipal landing zone must apply strict SCPs to production courts accounts while giving experimental AI sandboxes looser guardrails. Which OU design best supports that governance model?
- City shared services must host AWS Directory Service once so assessor, permitting, and fleet accounts can join domain resources without each building its own directory. Which multi-account pattern is appropriate?
- A log archive account will receive organization CloudTrail and other logs. The bucket design must allow only approved trails or log writers to put objects and must prevent premature deletion. Which approach best meets those controls?
- Parks leadership needs a new AWS account for a recreation-registration project. How should the account be created so it stays inside the municipal landing-zone governance model?
- Security findings raised in member accounts must trigger automated response runbooks that run only in the central security account. Which event architecture supports that pattern?
- A city council IT committee wants chargeback-friendly AWS boundaries that match departments such as police, parks, and finance instead of one shared production account. Which account-structure approach aligns to that need?
- Courts workloads adjacent to CJIS-style policy needs must inherit Control Tower preventive and detective guardrails mapped to those requirements. What should architects do?
- A network account shares an AMI and a subnet via AWS RAM to a workload account that has SCPs denying certain EC2 and networking actions. What must architects understand about that interaction?
- Finance staff manage consolidated billing in the payer account while the SOC runs Security Hub and GuardDuty admin tooling elsewhere. How should those roles be separated in the org design?
- Two counties will federate a shared 911 platform on AWS. Each county's call-data plane must remain isolated even though some platform services are shared. Which multi-account approach best fits?
- Leadership asks whether AWS Config aggregators and Security Hub delegated administration belong in the baseline multi-account governance model. What is the correct stance?
- City finance requires every AWS resource to map to a department and fund code so chargeback invoices are accurate. Which cost-visibility strategy should architects implement?
- Cost Explorer shows a sharp rise in data-transfer charges tied to a public S3 access pattern for a citizen media site. What should architects do first as part of cost and usage monitoring?
- A citizen portal has steady baseline EC2 demand all year, while a monthly batch job spikes briefly and can tolerate interruption. How should purchasing options be matched?
- An internal city intranet on EC2 is rarely used yet remains on large instance types. Which service provides rightsizing visibility for that compute?
- Library media buckets have grown unexpectedly. Operations needs organization-wide storage cost visibility into incomplete multipart uploads and non-current versions. Which tool fits?
- Utilities OU spend is approaching the approved ratepayer IT budget. Leadership wants proactive alerts before actual overruns. Which AWS capability should they use?
- Sandbox accounts still run unused Application Load Balancers after experiments end. Which cost-visibility source commonly flags that waste?
- Before council approves funding for multi-Region warm-standby DR, architects must present a forward-looking cost estimate. Which tool should they use?
- Public-meeting video rendering can tolerate interruption, but real-time computer-aided dispatch (CAD) for first responders cannot. How should Spot be applied?
- Consolidated billing exists, yet finance still cannot attribute spend to parks versus police. What is missing for cost visibility?
- Rightsizing reviews currently look only at EC2 instance size, yet RDS databases and EBS volumes also drive waste. What should the visibility approach include?
- A county must choose between 1-year and 3-year Savings Plans while election-year budgets make long commitments politically uncertain. How should architects evaluate the tradeoff?
- A city FinOps team must give each department a monthly showback of AWS spend with service-level detail across dozens of accounts. Which approach best provides that granular organizational cost visibility?
- Architects propose multi-AZ deployment for a county permitting API to improve reliability. Finance will not approve until the cost impact of that HA choice is visible. What should the solutions architect emphasize before approval?
- A municipality’s sandbox accounts for students and vendors regularly overspend. Leadership wants notifications and the option to apply spend controls when budgets are exceeded. Which design best fits org cost governance?
Design for New Solutions · 87 questions
- A city mandates that all new networking and IAM baselines be deployed from a CI pipeline using infrastructure as code, not console click-ops. Which approach best meets that change-control requirement?
- A citizen payments API must support instant rollback if a new release fails health checks. Which deployment strategy best meets that requirement?
- A county wants fleets to stay patched and configuration-consistent without operators SSHing into snowflake servers. Which AWS approach best supports that configuration-management goal?
- A small municipal IT shop runs a custom ticket-binder service on self-managed servers and spends too much time patching the queue layer. What change best reduces infrastructure provisioning and patching overhead?
- Change management requires human approvals before production OU deploys, while sandbox accounts may deploy continuously. How should the deployment strategy align?
- A legacy Elastic Beanstalk civic app must move toward containers with an upgrade path that stages features and supports rollback. Which approach best fits?
- A city wants ML inference for permit-image checks but lacks staff to build and operate GPU clusters. Which design best delegates that complexity?
- A permitting fleet must upgrade reliably. Leadership prefers images that are baked in CI over long-lived golden images patched in place. Which pattern should the architect choose?
- Build and test run in a shared tools account, but production lives in separate accounts. How should CI/CD deploy safely across those accounts?
- An internal low-risk municipal wiki can accept brief downtime, but tax-filing-week services cannot. How should deployment strategies differ?
- Baseline IAM roles must be pushed to every account under the city’s OUs from the management plane. Which IaC pattern best fits org-scale deployment?
- A 24/7 utilities outage map must stay available during upgrades. Which combination best reduces downtime?
- Staging often differs from production, causing “works in staging” failures for a grants portal. What design best prevents that configuration drift?
- The next 311 mobile API release must roll back automatically when health degrades. Which mechanism best meets that requirement?
- Citizens must reach a DR Region when the primary Region fails health checks. Which DNS design best supports that continuity?
- Vital records require a documented RPO that automated database protection must meet across Regions. Which approach best fits?
- Emergency operations leadership needs evidence that disaster recovery designs meet real RTO targets. What practice best validates continuity?
- Court evidence retention requires automated backups across EBS, RDS, and EFS with immutability controls on the vault. Which design best meets that need?
- The mayoral grants portal has an RTO that backup-and-restore alone cannot meet, but full active-active is too costly. Which DR scenario best fits?
- GIS basemap services need a cost-conscious continuity design: keep data replication on, but minimize the app tier until disaster. Which scenario fits?
- Statewide emergency messaging requires multi-site active-active operation with dual-Region writes and low-latency citizen access. Which design elements are essential?
- When Availability Zone degradation threatens municipal workloads, recovery should start without waiting for a ticket queue. Which approach best uses centralized monitoring for recovery?
- A city archives department stores low-priority historical photo scans that can tolerate days of downtime after a loss. Leadership wants the most cost-effective continuity design that still meets a long RTO. Which approach best fits?
- A county constituent portal must remain available if an entire AWS Region fails. Architects currently run Multi-AZ inside one Region and assume that covers regional outages. What should they redesign for Region-level disruption?
- A municipal IT team must fail a large fleet of on-premises Windows applications into AWS after a data-center incident, with continuous block-level replication and orchestrated recovery. Which AWS approach best matches this hybrid DR need?
- A multi-Region public permitting portal should send residents to the nearest healthy Region for both latency and continuity. Which Route 53 approach best supports that goal?
- Ransomware operators who compromise a city's workload account may try to delete local snapshots and backups. Which backup design best keeps archives recoverable after that pattern?
- A utilities billing database runs Multi-AZ RDS, but the city has never practiced failover and has no tested runbooks. What continuity gap should architects close first?
- A seasonal parks reservation system needs continuity for peak summer demand but must stay cost-aware in the off-season. Which DR capacity approach best balances continuity and cost?
- A new city permit API needs IAM roles that separate read-only auditors, deployment pipelines, and runtime application tasks. Which design best follows least privilege?
- A new citizen services web tier sits behind an Application Load Balancer. Security wants host-level allow rules for HTTPS from the load balancer only, plus subnet-level explicit denies for known malicious CIDRs. How should SG and NACL responsibilities be split?
- A high-profile municipal elections results site expects volumetric DDoS and sophisticated Layer 7 abuse on election night. Which mitigation strategy best fits?
- All new S3 buckets that store resident personal data must default to strong encryption at rest and must not be publicly accessible. Which baseline best meets that requirement?
- A new courts case-management stack must call AWS APIs and shared internal services without traversing the public internet where policy forbids it. Which endpoint pattern should architects specify?
- A new benefits portal stores database usernames and passwords for its application tier. Security forbids secrets in environment files or container images. Which credential approach best fits?
- A city is standing up a new AWS Organizations OU for digital services. Security wants threat detection and a consolidated security findings view before any workload account goes live. What should be enabled in the baseline?
- Municipal policy requires critical OS and package patches on EC2 fleets within 30 days. Which approach best operationalizes that standard for a new solution?
- A new citizen mobile backend-for-frontend terminates users at CloudFront, then reaches an ALB and private origins. Which encryption-in-transit design should architects mandate?
- A new utility account login page sees bursts of credential-stuffing attempts from many IPs. Which application-layer control best blunts that pattern without redesigning the whole identity stack overnight?
- Developers building a new microservice for licensing renewals proposed baking long-term IAM access keys into the container image. What credential hygiene should the architecture require instead?
- A PCI-adjacent payment helper subnet for a city cashiering integration must not freely reach the internet. Which network security design best meets sensitive-tier egress requirements?
- A new analytics data lake bucket unexpectedly may receive resident PII from upstream jobs. Which managed security service is most appropriate to discover sensitive data landing in the lake?
- A courts e-filing stack is approaching go-live. Leadership wants a managed security posture checklist—such as AWS Foundational Security Best Practices—before traffic is allowed. How should Security Hub be used?
- Public HTTPS endpoints for a new municipal portal must use centrally issued certificates with automatic renewal. Setting aside client certificate-pinning debates, what should architects mandate?
- A 311 service database must stay highly available inside a single Region with automated failover if the primary instance fails. Which data-store pattern best meets that HA requirement?
- Snow-emergency service requests can spike suddenly against a city's intake API. Workers need time to process each request without dropping intake during the surge. Which decoupling pattern best fits?
- When a boil-water advisory is declared, multiple municipal systems (SMS gateway, web banner service, utility IVR, and partner APIs) must be notified without each system calling the others directly. Which integration pattern best provides reliable fan-out?
- A county planning office needs a multi-step building-permit workflow that calls inspection, fee, and zoning services in order, retries transient failures, and runs compensating steps if a later stage fails. Which approach best meets reliability and orchestration needs?
- A city clerk’s office runs a document OCR fleet on EC2 that backs up during quiet weeks but must expand when a mail-in form season fills an SQS queue. How should Auto Scaling be designed for reliability?
- A municipality must keep irreplaceable ordinance PDFs durable and available even if an entire AWS Region becomes unavailable. Which storage reliability strategy best fits?
- A busy county resident portal caches session and lookup data in ElastiCache. Leadership wants the cache tier to survive node failure without dropping the whole site’s sessions. What design improves cache resilience?
- Before tax-day traffic, a city anticipates a large spike in concurrent Lambda executions for filing helpers. Architects worry reliability will fail when the account hits its concurrency quota. What should they do first?
- A regional health department publishes the same API in two Regions and wants citizens steered toward the healthier, lower-latency endpoint. Which Route 53 approach fits?
- A 311 intake fleet on Auto Scaling may terminate instances during scale-in. In-flight citizen reports must not be lost when a worker dies. Which design best prevents lost work?
- A small municipal IT team needs high availability for a permits database but lacks staff to operate mirrored MySQL on EC2. What should the architect recommend?
- A county’s HA program documents only application failover. Database failover is assumed to ‘just work’ and has never been tested. What operating practice should architects enforce?
- Vital-records systems must stay readable if the primary Region fails. The county accepts active-passive cost and wants DNS to shift traffic when the primary is unhealthy. Which design fits?
- Snow-plow routing jobs sometimes receive poison messages that crash workers and block the queue. How should the team ensure recoverability?
- An EC2 Auto Scaling group for a utility customer portal must remain available if one Availability Zone fails. What capacity placement practice should architects apply?
- A tourism bureau serves static park maps globally and also exposes a latency-sensitive API that benefits from static anycast entry IPs. How should edge and global performance services be applied?
- Field sensors for a water utility emit high-scale device telemetry with simple key-based access patterns. Architects considered forcing everything into relational RDS. What is the better database choice?
- A property-assessment catalog is read-heavy for public browsing while writes remain modest on the primary. Latency for browse traffic is too high. Which performance approach fits?
- County IT runs overnight batch GIS rendering and daytime in-memory analytics on citizen datasets. How should EC2 instance families be chosen for performance?
- Public-works engineers need concurrent shared access to CAD drawings from multiple Linux compute nodes with file-lock semantics. Objects in a bucket alone have caused collaboration pain. Which storage choice best matches the access pattern?
- Court e-filing feels underpowered at peak while sandbox accounts sit overbuilt all month. What rightsizing strategy should architects adopt?
- During large mail-in form seasons, OCR processing demand spikes independently of steady citizen web traffic. How should the architecture scale?
- Citizen check-in latency spikes while overall DynamoDB table metrics look only moderately busy. How should performance monitoring help?
- A state open-data portal expects large concurrent downloads of GIS packages from distant clients. Which approach best supports large-scale access patterns?
- A grants-management tool sees long idle periods and occasional query bursts. Another reporting workload runs steady queries all day. How should Aurora capacity models be matched?
- Flood-modeling jobs are tightly coupled HPC-style tasks where inter-node latency dominates runtime. What placement strategy should the architect use?
- Sensor uploads arrive in unpredictable bursts that overwhelm downstream analytics if sent inline. How should architects protect throughput and avoid drops?
- A city is designing a new mobile 311 API. Engineers are debating services before agreeing how success will be measured. What methodology should lead the design?
- A county document-management database on Amazon EC2 needs sustained IOPS and throughput for peak scanning days without overpaying for idle capacity overnight. Which block-storage design best meets performance and cost goals?
- A city is designing compute for a always-on citizen portal baseline plus a fault-tolerant batch that transcodes public meeting videos. Which purchasing mix best aligns cost with workload behavior?
- Council meeting recordings land in Amazon S3, stay warm for weeks of citizen review, then are rarely opened. Which storage design best reduces long-term cost while preserving retrieval when needed?
- Architects modeling a new permitting stack find chatty application tiers talking constantly to a database and several AWS APIs. Which design choice most directly reduces data-transfer and NAT charges?
- A municipality compares self-managed MySQL on EC2 with Amazon Aurora MySQL-Compatible for a new case-management database. Staff already work overtime on patching and failover drills. Which TCO framing is most appropriate?
- A quiet departmental intranet launches on oversized EC2 and RDS classes “just in case.” Which cost practice should architects bake into the new-solution design?
- Before approving a new multi-account citizen-services architecture, council asks for an options memo with credible cost ranges. Which approach best supports that design decision?
- A new organizational unit will host several greenfield apps. Finance wants expenditure awareness before go-live, not after a surprise bill. What should architects implement?
- A city’s open-data portal serves popular CSV and GeoJSON files from an S3 origin to thousands of citizens. Origin egress cost is rising. Which design improves performance and reduces transfer cost?
- A parks-and-recreation booking app’s RTO can be met with multi-AZ in one Region. Stakeholders propose active-active in three Regions “for prestige.” What should the cost-aware architect recommend?
- Linux-based municipal microservices are being sized for a new ECS/EKS deployment. Performance tests pass on arm64 builds. Which compute choice best balances cost and performance?
- A greenfield VPC design places many private subnets across AZs, each expected to reach AWS APIs and limited internet destinations. NAT Gateway spend projections are high. What networking cost control should architects prioritize?
- A city’s architecture review board gates new solutions before launch. Which cost practice should be part of that review?
- Departments will fund their own apps in a shared landing zone. Leadership wants showback from day one of each new solution. What must architects implement at launch?
- A weekend-only batch fleet renders seasonal flood maps and sits idle most weekdays. The steady GIS API tier runs continuously. How should commitment purchases be applied?
Continuous Improvement for Existing Solutions · 75 questions
- An existing 311 stack pages operators for every noisy metric spike and lacks automatic healing. Which operational improvement best raises excellence?
- Application logs for an existing licensing portal are scattered across instance disks with inconsistent retention. What monitoring/logging improvement should architects prioritize?
- Permits application releases today are weekend click-ops with long outage windows. Which deployment-process improvement should the team adopt?
- Golden AMIs for a fleet are updated by an engineer copying files by hand onto running instances. Which automation should be prioritized?
- Jump-host configuration across accounts has drifted—different SSH settings and agent versions. Which AWS capability best enforces desired state continuously?
- Utilities operate a SCADA gateway stack in AWS with written AZ-loss runbooks that have not been exercised recently. What should architects schedule?
- DR planning documents for an existing tax system still describe retired data centers and omit current multi-AZ AWS resources. Which improvement is required?
- The tax portal still uses risky all-at-once production replacements that are hard to roll back. Which deployment strategy improvement should be introduced?
- On-call for an existing benefits site still executes runbooks by hand after CloudWatch alarms. How should auto-remediation be wired?
- Operators lack a single pane of glass across municipal workload accounts and jump between consoles. Which monitoring improvement fits org scale?
- A county operations team still bastions into EC2 with long-lived SSH keys and shared jump hosts, and auditors want session logging without opening inbound SSH. Which continuous-improvement change best meets that requirement?
- A city permitting portal’s CI/CD pipeline shifts production traffic immediately after deploy, and recent releases shipped latent bugs that residents hit first. Which improvement should the architects prioritize?
- A municipality’s citizen portal ops team fights every alert with equal urgency and cannot decide which reliability work to fund next. What should leadership introduce to prioritize improvement work?
- Residents again saw certificate-expiry warnings on a county tax site after a manual ACM renewal was missed. Which operational improvement should the team prioritize?
- A regional library consortium’s CloudWatch alarms fire without showing which department owns the noisy resource, so on-call pages the wrong team. Which observability improvement is most effective?
- A security audit of a city CI account finds long-lived IAM access keys embedded in pipeline workers that can deploy across production accounts. What strategy best remediates this secrets and credentials risk?
- IAM Access Analyzer reports unused administrative roles in a parks department account that still trust a broad set of principals. What should the security architects do to improve least privilege?
- A courts case-management review finds the team relies on a WAF alone while application tiers sit in public subnets with broad security groups and unencrypted data stores. Which conclusion is correct?
- County auditors must prove which workforce identity changed property-tax rate configuration last quarter across console, API, and application workflows. Which traceability approach best supports that review?
- A multi-account municipality repeatedly discovers S3 buckets accidentally marked public. Which automated monitoring and remediation approach should they prioritize?
- Windows file servers for a school district miss monthly patch windows because admins patch by remote desktop ad hoc. How should the patch and update process be redesigned?
- A city backup process writes unencrypted snapshots to the same account that runs production workloads, with no isolated copy for ransomware recovery. What secure backup redesign should architects implement?
- Policy requires 911 call recordings to be retained for a fixed number of years, with legal holds that must suspend deletion when litigation is active. Which improvement aligns technical controls to that requirement?
- Database passwords for a transit fare system still sit in SSM Parameter Store as plaintext String parameters. Which secrets-store improvement is most appropriate?
- GuardDuty findings for a utilities account pile up in Security Hub while MTTR stays high because responders lack a standard triage path. Which improvement should the architects prioritize?
- An AWS Organizations review shows municipal member accounts still use the root user for daily tasks and several roots lack MFA. Which identity-hygiene improvement should be implemented org-wide?
- A county wants to stop EC2 fleets from resolving and connecting to known-malicious domains on egress without rewriting every application. Which network-layer improvement fits?
- HR department EBS volumes were launched unencrypted and must now be encrypted with minimal downtime. Which remediation approach is appropriate?
- AMI bake pipelines for a public-health account ship images that later show critical CVEs in Amazon Inspector. Which vulnerability-response improvement should be prioritized?
- Amazon Macie reports SSN-like patterns in a municipal 'open data' S3 bucket that is publicly readable. What immediate remediation should architects drive?
- A permit-search API misses its p99 latency SLO. CloudWatch and DynamoDB metrics show a few partition keys absorbing most traffic. Which performance improvement best addresses the bottleneck?
- Product owners say resident-facing permit pages 'must feel instant on mobile,' but engineering has no numeric targets. How should architects translate that requirement?
- Compute Optimizer and CloudWatch show an Auto Scaling group for a library catalog tier chronically underutilized on oversized instance types. Which rightsizing action is most appropriate?
- An existing citizen portal still serves CSS, JavaScript, and images directly from a single-Region origin, causing slow loads for distant residents. Which managed performance adoption should architects propose?
- Partner agencies allowlist fixed public IPs to reach a multi-Region municipal API, and latency varies by client location. Which global performance offering should architects evaluate?
- A county emergency-management office runs tightly coupled flood-inundation batch models on EC2. Jobs often place workers far apart across AZs, and capacity is pieced together with ad-hoc On-Demand launches that miss peak storm windows. Which continuous-improvement change best raises throughput for this HPC-style civic workload?
- A city 311 portal team plans to insert a new Amazon ElastiCache layer in front of a hot RDS read path. Leadership wants the change promoted only after proving it under realistic citizen-traffic patterns. Which remediation approach best meets that continuous-improvement gate?
- A municipal permitting backend scales an Auto Scaling group using average CPU only. During filing deadlines the SQS work queue grows for minutes while CPU stays modest, so citizens see long waits. Which scaling-policy improvement best restores elasticity?
- A county microservices mesh for licensing still calls five downstream services synchronously on every citizen request, creating multi-hop latency and cascading timeouts under load. Which architecture pattern change best improves performance while preserving eventual consistency where allowed?
- After several performance remediations, a city digital-services team still only watches server CPU and 5xx rates. Citizens report intermittent slow page loads that operations never sees. Which monitoring toolset change best sustains the performance improvements?
- A utilities billing RDS MySQL database shows rising p95 query latency after a schema growth year. Performance Insights highlights repeated full-table scans and suboptimal parameters. Which data-tier remediation best addresses the bottleneck?
- A state agency SLA for a shared municipal identity portal requires measurable monthly uptime and p99 API latency. Today the city only pages on host-down events. Which improvement best aligns monitoring to the SLA and KPIs?
- A transit-authority analytics VPC routes all private-subnet egress through a single undersized NAT instance that saturates during evening GTFS feed pulls, throttling job completion. Which network-path remediation best improves throughput?
- City auditors run ad-hoc full-text searches across years of application logs stored in the same Amazon RDS instance that serves online permitting transactions, causing lock and I/O contention. Which managed-service adoption best improves performance fit?
- A public-works status site caches road-closure JSON at CloudFront with a multi-hour TTL. After storms, citizens see stale detours for too long even though origin updates quickly. Which cache-effectiveness change best balances performance and freshness?
- A parks-and-recreation registration app still uses a single-AZ Amazon RDS instance. An AZ impairment would take citizen payments offline with no tested failover. Which reliability remediation should the team implement first?
- A legacy courts case-management database on RDS was snapshotted manually only on Fridays. A midweek corruption event proved point-in-time recovery was unavailable. Which reliability improvement best closes that gap?
- A formerly single-instance municipal intranet sits on one EC2 host. Patch reboots and host failures cause city-staff outages. Which reliability pattern best remediates this?
- During a coastal storm, a city’s emergency notification platform hit API and concurrent-execution throttles that delayed outbound alerts. Postmortem shows soft service quotas were never reviewed. Which reliability action best addresses the root cause?
- On-call engineers for a public-health clinic portal still reboot unhealthy EC2 hosts by hand after paging. Leadership wants self-healing instead of manual intervention. Which change best enables that elastic reliability feature?
- Analytics show the city’s 311 mobile API traffic roughly doubling year over year. Current capacity and DR plans still assume last year’s peak. Which reliability-planning improvement best responds to that growth trend?
- An architecture review of a multi-account municipal landing zone finds possible hidden single points of failure: one NAT Gateway in a shared services VPC, one bastion, and a single-Region authoritative DNS pattern for critical apps. Which action best improves reliability evaluation?
- A regional utilities consortium tightened RPO for SCADA historian data replicated to AWS. The current design uses infrequent cross-Region snapshot copy that can lose many hours of telemetry. Which reliability change best matches the new RPO?
- City council shortened RTO for the citizen benefits portal from days to a few hours. The current DR method is backup and restore into an empty Region. Which DR improvement best fits the new objective?
- An Application Load Balancer for a county tax portal uses shallow TCP health checks. Instances that accept TCP but return application errors remain in service, causing intermittent citizen failures. Which HA improvement best fixes detection?
- A brittle synchronous chain across permitting, payments, and document services caused cascading outages when one dependency slowed. Which reliability redesign best reduces cascade risk?
- After a Region-wide impairment postmortem, a state’s emergency grants portal still relies on a manual multi-Region failover runbook executed under stress. Which Global Infrastructure reliability improvement best reduces human-error risk?
- A municipal inspections platform is mostly asynchronous, yet reliability dashboards still alert only on HTTP 5xx from the web tier. Backlogs and poison messages grow unnoticed. Which observability improvement best fits async reliability?
- A licensing web tier stores sessions only in local memory on each EC2 host, so Auto Scaling replacements and load-balancer drains drop citizen logins. Which reliability pattern best enables elastic, ASG-friendly behavior?
- An emergency mass-notification application improved architecture on paper but has not practiced recovery under failure. Leadership wants quarterly reliability improvement evidence. Which practice best exercises recovery?
- A city FinOps team reviews Cost and Usage Reports for sandbox OUs and finds Classic Load Balancers with zero traffic for months plus many unattached EBS volumes. Leadership wants a durable process to surface these waste patterns before renewing the next budget cycle. Which approach best identifies the unused resources from usage evidence?
- A county cloud office sees rising Elastic IP and EBS snapshot charges even though several citizen-facing apps were retired. Architects want AWS-native checks that highlight never-associated Elastic IPs and aged snapshots that can be deleted safely after review. Which approach best identifies those unused resources?
- A municipal budget office needs alerts when a department’s AWS forecast will exceed its monthly appropriation before month-end, not only after the invoice arrives. Which design best implements billing alarms aligned to expected usage patterns?
- A city wants monthly showback so each municipal department sees its own AWS spend by application tag rather than a single opaque IT bill. Which approach best investigates Cost and Usage Reports at a granular level for that showback?
- A transit agency’s FinOps policy requires untagged spend to stay below a stated percentage of the monthly bill. Today many new resources launch without the mandatory CostCenter and Application tags. Which strategy best expands tagging coverage for cost allocation and reporting?
- A public-health analytics platform runs a stateful citizen API on steady EC2 capacity and a separately scalable, fault-tolerant image-rendering fleet that can retry interrupted work. The architecture board wants lower compute cost without risking API availability. Which purchasing and capacity approach best fits?
- After several months of CloudWatch and Cost Explorer data, a citizen portal’s EC2/Fargate baseline CPU and spend look steady across business hours. Finance asks whether to adopt a commitment discount. Which action best adopts Savings Plans appropriately?
- CUR shows high data-processing charges from NAT Gateways and unexpected cross-AZ traffic between chatty microservices in a courts case-management VPC. Architects must cut networking spend without abandoning Multi-AZ for the data tier. Which optimization best addresses the waste?
- A library digital-archives bucket uses versioning. Storage Lens and CUR show large spend from incomplete multipart uploads and old noncurrent versions that are never restored. Which storage cost cleanup best recovers that spend?
- County non-production accounts run EC2 and RDS for QA all weekend even though testers only work weekday business hours. Leadership wants scheduled stop/start without redesigning every application. Which approach best uses scheduling to reduce cost?
- Weeks of Enhanced Monitoring and Performance Insights show a municipal permitting RDS instance consistently under 20% CPU and memory with no storage throughput saturation. Which continuous-improvement action best rightsizes based on that evidence?
- A document-management database volume was provisioned as io2 during a peak project. CloudWatch now shows IOPS and throughput well below io2 provisioning for sustained periods. Which cost-conscious architecture choice should the team make?
- A sandbox data-science OU suddenly generated a large GPU EC2 bill after a notebook instance type was misconfigured. The FinOps team wants faster detection next time. Which improvement best strengthens cost management alerting?
- Several lightly used AZ-local NAT Gateways in a parks-and-recreation VPC drive fixed hourly charges. Some architects want one shared NAT to save money; others worry about losing AZ isolation for egress during an AZ event. Which recommendation best balances cost and reliability?
- A city’s shared-services account accumulates orphaned AMIs and untagged ECR images from retired pipelines, steadily increasing snapshot and registry storage cost. Which action best reclaims that artifact sprawl cost?
Accelerate Workload Migration and Modernization · 60 questions
- A county portfolio assessment ranks a VMware file-and-print stack as low business value with high operational toil, while the citizen payments platform is high value and customer-facing. Leadership is choosing early AWS migration waves. Which prioritization best reflects portfolio assessment guidance?
- A county is exiting a datacenter and needs a single view of discovery status and migration-wave progress across Application Migration Service and related tools. Which approach best assesses and tracks the migration?
- During 7Rs planning for a municipality, architects classify: an unused departmental intranet as retire, air-gapped OT historians as retain on-premises, a simple brochure website as rehost, and citizen payments as refactor. Which statement best reflects correct 7Rs evaluation?
- Finance asks for a three-year TCO comparison between refreshing an aging on-premises SAN for records storage versus rehosting the same workloads to EC2 with EBS (and related AWS storage). Which evaluation best supports the migrate-versus-stay decision?
- A city’s migration PMO can sequence either a low-risk HR wiki or the courts e-filing platform first. The team wants early waves to build operational muscle before touching justice workloads. Which wave-planning choice is most appropriate?
- Before locking migration waves, a municipal enterprise architect must inventory Windows Server versions, Microsoft licensing postures, and upstream/downstream dependencies for line-of-business apps. Which activity best performs asset planning as input to selection?
- An application migration assessment for a permitting system finds hard-coded IP addresses to an on-premises file server and a legacy license host, blocking a clean early rehost. What should the assessment outcome emphasize?
- Business-critical systems adjacent to 911 dispatch depend on unfinished hybrid network and DR designs. The migration board must choose what moves now versus later. Which selection best reflects timing judgment?
- Discovery finds two departmental SharePoint farms with overlapping content and declining usage after a municipal reorganization. Stakeholders propose migrating both unchanged. Which 7Rs-oriented recommendation is best?
- A licensing review shows one candidate app can use License Included on AWS economically, while another has complex BYOL constraints that raise three-year TCO if moved early. How should licensing factor into early-candidate selection?
- A county Migration Hub portfolio assessment is about to lock wave one for courts and assessor systems, but Application Discovery Service just reported undocumented departmental servers that never appeared in the CMDB. What should the architects do before finalizing the wave?
- A city CIO wants the public open-data portal in an early migration wave for citizen visibility even though complexity is only medium and several critical billing systems score higher on technical risk. How should architects balance prioritization?
- A municipal records office still ships monthly archive tapes by courier to an off-site vault and wants a pathfinder migration that proves cloud storage value before touching line-of-business apps. Which process is the strongest early migration candidate?
- A county finance ERP on aging on-premises hosts shows chronically high change-failure rates and fragile release processes. During portfolio selection, which 7R direction should architects favor instead of a blind rehost?
- A transit authority's TCO model for migrating garage systems assumes every on-premises rack runs at 100% useful utilization. What must architects do during selection to keep the business case honest?
- A county GIS team must migrate a multi-petabyte historical imagery library to Amazon S3, but the municipal WAN cannot finish the transfer within the project window. Which approach should the architects select?
- A city records bureau needs nightly incremental sync from an on-premises NAS into Amazon S3 with scheduling, encryption, and transfer metrics instead of a hand-built rsync on a jump box. Which service should they choose?
- Partner human-services agencies must upload case PDFs into the county's governed Amazon S3 buckets using familiar SFTP workflows without giving partners broad AWS console access. Which migration transfer approach fits?
- A county clinic scheduling application runs on VMs that must be rehosted to AWS with continuous replication and a planned cutover window. Which application transfer mechanism should architects select?
- A municipal permitting database on Oracle must move to Amazon Aurora PostgreSQL. Architects need schema conversion assessment plus ongoing data migration. Which combination should they select?
- A school district plans a months-long migration wave that will continuously replicate large application and database volumes into AWS. Which networking approach best supports bulk migration traffic compared with VPN-only?
- Migrated county department apps still depend on corporate identities and group policies after cutover. What identity approach should architects decide as part of the migration plan?
- A regional library consortium is about to cut over the first production workload into AWS. What governance model should be in place first?
- Distant field offices for a state parks department must upload large survey bundles to Amazon S3; AWS Direct Connect is not available at those sites. Which S3 feature helps accelerate long-distance transfers over the public internet?
- A public-health department must sequence cutovers safely across interdependent case-management and lab systems. How should Application Discovery Service inform the migration approach?
- A city security office reviews migration tooling that will copy citizen data into AWS. Which security methods should be applied to the migration tools themselves?
- Department apps will resolve names across on-premises DNS and Amazon Route 53 private zones during a staggered municipal cutover. What must the migration approach include to avoid post-cutover black holes?
- A utility billing database can tolerate only minutes of downtime, not a full weekend outage. Which database transfer mechanism should architects choose?
- A county needs hybrid connectivity for early migration waves now, but Direct Connect provisioning will take months. How should architects document the phased network approach?
- Some city workloads run as ordinary VMs with agents available, while others sit in a VMware-centric estate with different operational constraints. How should architects choose application transfer mechanisms?
- A rehosted municipal intranet previously ran on a single tower server and must gain elasticity after landing in AWS. Which compute platform selection best fits?
- A small .NET departmental permitting helper app is being migrated, and the team wants less undifferentiated OS and platform operations. When is AWS Elastic Beanstalk an appropriate target?
- A Java case-management application for social services will be containerized during migration. Which AWS platform combination should architects select for hosting images and running tasks without managing servers?
- A large city already runs a multi-team Kubernetes platform with mature cluster operations skills and wants that model for newly migrated container workloads. Which hosting choice fits the organizational context?
- Public-works engineers share concurrent CAD drawings across multiple workstations after migration. Which storage service selection is appropriate instead of a single instance's Amazon EBS volume?
- A county is replacing aging Windows file servers that provide SMB shares and NTFS ACLs for public-health case files, planning drawings, and permit attachments, with departments in separate AWS accounts joined to the same Active Directory domain. Which target architecture should architects select for the migrated file platform?
- The planning department must archive decades of scanned building-permit PDFs and inspection photos that are rarely retrieved after the first year, while keeping the objects in a multi-account records bucket that legal can restore from without running a database. Which storage architecture should replace on-premises block LUNs?
- A public-works work-order application still requires iSCSI block volumes during a multi-year hybrid transition, even as newer permit systems already write to Amazon S3. Which storage pattern should architects use so the legacy app can keep its block interface while data lands in AWS?
- City utility billing OLTP must remain highly available after migration, while finance wants multi-year usage analytics that currently hammer the same on-premises SQL Server. Which database-platform selection should architects make for the new architecture?
- A multi-account public-health program is replacing a sticky-session SQL table that stores field-kit device IDs and inspection-app session tokens that are keyed lookups with bursty write rates. Which target datastore should architects select?
- A county 311 application stores MongoDB-compatible JSON case documents and currently runs a self-managed replica set on aging VMs. Architects must choose a new database platform that reduces undifferentiated operations unless a blocking engine feature is proven. Which recommendation is appropriate?
- Residents and clerks need ranked full-text search across municipal code, ordinances, and permit conditions, currently implemented as slow SQL LIKE queries on the permitting RDS database that also serves OLTP. Which architecture should replace that search path?
- A courts case-management vendor insists on an exotic database engine feature that Amazon RDS does not support, and the county otherwise standardizes on managed RDS and Aurora. How should architects treat a self-managed database on Amazon EC2?
- The county assessor office runs a six-hour nightly valuation batch that currently occupies a farm of always-on on-premises servers idle all day. After migration, which compute platform selection best fits that batch shape?
- A rehosted public-health epidemiology database will land on Amazon EC2 with Amazon EBS. On-premises SAN metrics show sustained 12,000 IOPS and 250 MiB/s during month-end reporting. How should architects size the block storage?
- A monolithic permitting application in a city account bundles citizen intake, card payments, and inspector workflow in one process, so a payment-vendor outage freezes new applications citywide. Which modernization opportunity should architects identify first?
- Planning staff upload permit-plan PDFs to a records bucket, and the current monolith blocks the upload thread while it generates thumbnails on an always-on EC2 worker. Which serverless enhancement should architects select?
- Finance and public-health accounts generate large weekend report packs on always-on EC2 workers that sit idle on weekdays. The jobs are already containerized. Which modernization should architects recommend?
- A parks-and-recreation registration database is quiet most of the year and spikes around summer-camp enrollment, currently over-provisioned on a fixed RDS instance in a departmental account. Which purpose-built database modernization fits?
- A legacy inspector-scheduling database in the public-works account is overwhelmed by repeated reads of hot keys such as open time slots and session data after more field tablets came online. Which modernization enhancement should architects add without a full schema rewrite?
- Nightly jobs that snapshot logs, rotate permit extracts, and start assessor batches currently run from cron on a shared jump host that assumes roles into several department accounts. Which integration modernization should replace that pattern?
- A brittle Bash script on a shared operations host copies extracts between the permitting system, finance, and GIS, with no retries, timeouts, or visible state when a step fails overnight. Which orchestration modernization should architects select?
- The GIS account publishes parcel-change events that the public-works work-order system must consume, but today's synchronous HTTP calls fail when work-order is patching, causing missed tickets. Which integration pattern should architects introduce?
- The city's open-data portal is a static site of CSVs, maps, and HTML with a few dynamic query APIs still on the permitting backend. The current design serves everything from a pair of always-on EC2 web servers. Which storage-and-delivery modernization should architects select?
- Permit-plan conversion Lambdas and Fargate tasks in the planning account must concurrently read and write intermediate CAD-derived files that exceed /tmp and must be visible to the next step. Which shared storage should architects attach?
- The county ERP that issues purchase orders cannot be rewritten in one release, but finance needs a new vendor-onboarding API this quarter. Which incremental modernization path should architects identify?
- Public-health clinics want a new mobile patient check-in feature with simple keyed writes and variable load, while the existing clinic system of record remains Oracle. Which purpose-built database approach should architects recommend for the new slice?
- The city's shared DevOps account still runs always-on EC2 build VMs that execute containerized test suites for permitting, GIS, and public-health pipelines, sitting idle between merges. Which container-service modernization should architects select for the test runners?
- Planning wants OCR on uploaded permit plans and image moderation on public 311 photos, but these are adjacent enhancements to existing S3-based intake—not a new AI product line. Which approach should architects take so the core architecture stays on integration?
- Citizen permit-status pages currently call the intake API, which calls payments, which calls inspections, and any hop timeout shows unknown during peak filing days. Which event-driven modernization should architects recommend?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by AWS.