AWS SAA-C03 Chapter 13 Practice Questions (100 Questions)

Practice questions for the AWS SAA-C03 (Solutions Architect Associate) exam, Chapter 13.

  1. Q1. Q901. A company creates dedicated AWS accounts in AWS Organizations for its business units. Recently, an important notification was sent to the root user email address of a business unit account instead of the assigned account owner. The company wants to ensure that all future notifications can be sent to different employees based on the notification categories of billing, operations, or security.Which solution will meet these requirements MOST securely?

    • A. Configure each AWS account to use a single email address that the company manages. Ensure that all account owners can access the email account to receive notifications. Configure alternate contacts for each AWS account with corresponding distribution lists for the billing team, the security team, and the operations team for each business unit.
    • B. Configure each AWS account to use a different email distribution list for each business unit that the company manages. Configure each distribution list with administrator email addresses that can respond to alerts. Configure alternate contacts for each AWS account with corresponding distribution lists for the billing team, the security team, and the operations team for each business unit.
    • C. Configure each AWS account root user email address to be the individual company managed email address of one person from each business unit. Configure alternate contacts for each AWS account with corresponding distribution lists for the billing team, the security team, and the operations team for each business unit.
    • D. Configure each AWS account root user to use email aliases that go to a centralized mailbox. Configure alternate contacts for each account by using a single business managed email distribution list each for the billing team, the security team, and the operations team.

    View question →

  2. Q2. Q902. A company runs an ecommerce application on AWS. Amazon EC2 instances process purchases and store the purchase details in an Amazon Aurora PostgreSQL DB cluster.Customers are experiencing application timeouts during times of peak usage. A solutions architect needs to rearchitect the application so that the application can scale to meet peak usage demands.Which combination of actions will meet these requirements MOST cost-effectively? (Choose two.)

    • A. Configure an Auto Scaling group of new EC2 instances to retry the purchases until the processing is complete. Update the applications to connect to the DB cluster by using Amazon RDS Proxy.
    • B. Configure the application to use an Amazon ElastiCache cluster in front of the Aurora PostgreSQL DB cluster.
    • C. Update the application to send the purchase requests to an Amazon Simple Queue Service (Amazon SQS) queue. Configure an Auto Scaling group of new EC2 instances that read from the SQS queue.
    • D. Configure an AWS Lambda function to retry the ticket purchases until the processing is complete.
    • E. Configure an Amazon AP! Gateway REST API with a usage plan.

    View question →

  3. Q3. Q903. A company is hosting a high-traffic static website on Amazon S3 with an Amazon CloudFront distribution that has a default TTL of 0 seconds. The company wants to implement caching to improve performance for the website. However, the company also wants to ensure that stale content is not served for more than a few minutes after a deployment.Which combination of caching methods should a solutions architect implement to meet these requirements? (Choose two.)

    • A. Set the CloudFront default TTL to 2 minutes.
    • B. Set a default TTL of 2 minutes on the S3 bucket.
    • C. Add a Cache-Control private directive to the objects in Amazon S3.
    • D. Create an AWS Lambda@Edge function to add an Expires header to HTTP responses. Configure the function to run on viewer response.
    • E. Add a Cache-Control max-age directive of 24 hours to the objects in Amazon S3. On deployment, create a CloudFront invalidation to clear any changed files from edge caches.

    View question →

  4. Q4. Q904. A company has deployed a multi-account strategy on AWS by using AWS Control Tower. The company has provided individual AWS accounts to each of its developers. The company wants to implement controls to limit AWS resource costs that the developers incur.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Instruct each developer to tag all their resources with a tag that has a key of CostCenter and a value of the developer's name. Use the required-tags AWS Config managed rule to check for the tag. Create an AWS Lambda function to terminate resources that do not have the tag. Configure AWS Cost Explorer to send a daily report to each developer to monitor their spending.
    • B. Use AWS Budgets to establish budgets for each developer account. Set up budget alerts for actual and forecast values to notify developers when they exceed or expect to exceed their assigned budget. Use AWS Budgets actions to apply a DenyAll policy to the developer's IAM role to prevent additional resources from being launched when the assigned budget is reached.
    • C. Use AWS Cost Explorer to monitor and report on costs for each developer account. Configure Cost Explorer to send a daily report to each developer to monitor their spending. Use AWS Cost Anomaly Detection to detect anomalous spending and provide alerts.
    • D. Use AWS Service Catalog to allow developers to launch resources within a limited cost range. Create AWS Lambda functions in each AWS account to stop running resources at the end of each work day.Configure the Lambda functions to resume the resources at the start of each work day.

    View question →

  5. Q5. Q905. A company has released a new version of its production application. The company's workload uses Amazon EC2, AWS Lambda, AWS Fargate, and Amazon SageMaker.The company wants to cost optimize the workload now that usage is at a steady state. The company wants to cover the most services with the fewest savings plans.Which combination of savings plans will meet these requirements? (Choose two.)

    • A. Purchase an EC2 Instance Savings Plan for Amazon EC2 and SageMaker.
    • B. Purchase a Compute Savings Plan for Amazon EC2, Lambda, and SageMaker.
    • C. Purchase a SageMaker Savings Plan.
    • D. Purchase a Compute Savings Plan for Lambda, Fargate, and Amazon EC2.
    • E. Purchase an EC2 Instance Savings Plan for Amazon EC2 and Fargate.

    View question →

  6. Q6. Q906. A company plans to rehost an application to Amazon EC2 instances that use Amazon Elastic Block Store (Amazon EBS) as the attached storage.A solutions architect must design a solution to ensure that all newly created Amazon EBS volumes are encrypted by default. The solution must also prevent the creation of unencrypted EBS volumes.Which solution will meet these requirements?

    • A. Configure the EC2 account attributes to always encrypt new EBS volumes.
    • B. Use AWS Config. Configure the encrypted-volumes identifier. Apply the default AWS Key Management Service (AWS KMS) key.
    • C. Configure AWS Systems Manager to create encrypted copies of the EBS volumes. Reconfigure the EC2 instances to use the encrypted volumes.
    • D. Create a customer managed key in AWS Key Management Service (AWS KMS). Configure AWS Migration Hub to use the key when the company migrates workloads.

    View question →

  7. Q7. Q907. An ecommerce company wants to collect user clickstream data from the company's website for real-time analysis. The website experiences fluctuating traffic patterns throughout the day. The company needs a scalable solution that can adapt to varying levels of traffic.Which solution will meet these requirements?

    • A. Use a data stream in Amazon Kinesis Data Streams in on-demand mode to capture the clickstream data. Use AWS Lambda to process the data in real time.
    • B. Use Amazon Kinesis Data Firehose to capture the clickstream data. Use AWS Glue to process the data in real time.
    • C. Use Amazon Kinesis Video Streams to capture the clickstream data. Use AWS Glue to process the data in real time.
    • D. Use Amazon Managed Service for Apache Flink (previously known as Amazon Kinesis Data Analytics) to capture the clickstream data. Use AWS Lambda to process the data in real time.

    View question →

  8. Q8. Q908. A global company runs its workloads on AWS. The company's application uses Amazon S3 buckets across AWS Regions for sensitive data storage and analysis. The company stores millions of objects in multiple S3 buckets daily. The company wants to identify all S3 buckets that are not versioning-enabled.Which solution will meet these requirements?

    • A. Set up an AWS CloudTrail event that has a rule to identify all S3 buckets that are not versioning-enabled across Regions.
    • B. Use Amazon S3 Storage Lens to identify all S3 buckets that are not versioning-enabled across Regions.
    • C. Enable IAM Access Analyzer for S3 to identify all S3 buckets that are not versioning-enabled across Regions.
    • D. Create an S3 Multi-Region Access Point to identify all S3 buckets that are not versioning-enabled across Regions.

    View question →

  9. Q9. Q909. A company needs to optimize its Amazon S3 storage costs for an application that generates many files that cannot be recreated. Each file is approximately 5 MB and is stored in Amazon S3 Standard storage.The company must store the files for 4 years before the files can be deleted. The files must be immediately accessible. The files are frequently accessed in the first 30 days of object creation, but they are rarely accessed after the first 30 days.Which solution will meet these requirements MOST cost-effectively?

    • A. Create an S3 Lifecycle policy to move the files to S3 Glacier Instant Retrieval 30 days after object creation. Delete the files 4 years after object creation.
    • B. Create an S3 Lifecycle policy to move the files to S3 One Zone-Infrequent Access (S3 One Zone-IA) 30 days after object creation. Delete the files 4 years after object creation.
    • C. Create an S3 Lifecycle policy to move the files to S3 Standard-Infrequent Access (S3 Standard-IA) 30 days after object creation. Delete the files 4 years after object creation.
    • D. Create an S3 Lifecycle policy to move the files to S3 Standard-Infrequent Access (S3 Standard-IA) 30 days after object creation. Move the files to S3 Glacier Flexible Retrieval 4 years after object creation.

    View question →

  10. Q10. Q910. A company runs its critical storage application in the AWS Cloud. The application uses Amazon S3 in two AWS Regions. The company wants the application to send remote user data to the nearest S3 bucket with no public network congestion. The company also wants the application to fail over with the least amount of management of Amazon S3.Which solution will meet these requirements?

    • A. Implement an active-active design between the two Regions. Configure the application to use the regional S3 endpoints closest to the user.
    • B. Use an active-passive configuration with S3 Multi-Region Access Points. Create a global endpoint for each of the Regions.
    • C. Send user data to the regional S3 endpoints closest to the user. Configure an S3 cross-account replication rule to keep the S3 buckets synchronized.
    • D. Set up Amazon S3 to use Multi-Region Access Points in an active-active configuration with a single global endpoint. Configure S3 Cross-Region Replication.

    View question →

  11. Q11. Q911. A company is migrating a data center from its on-premises location to AWS. The company has several legacy applications that are hosted on individual virtual servers. Changes to the application designs cannot be made.Each individual virtual server currently runs as its own EC2 instance. A solutions architect needs to ensure that the applications are reliable and fault tolerant after migration to AWS. The applications will run on Amazon EC2 instances.Which solution will meet these requirements?

    • A. Create an Auto Scaling group that has a minimum of one and a maximum of one. Create an Amazon Machine Image (AMI) of each application instance. Use the AMI to create EC2 instances in the Auto Scaling group Configure an Application Load Balancer in front of the Auto Scaling group.
    • B. Use AWS Backup to create an hourly backup of the EC2 instance that hosts each application. Store the backup in Amazon S3 in a separate Availability Zone. Configure a disaster recovery process to restore the EC2 instance for each application from its most recent backup.
    • C. Create an Amazon Machine Image (AMI) of each application instance. Launch two new EC2 instances from the AMI. Place each EC2 instance in a separate Availability Zone. Configure a Network Load Balancer that has the EC2 instances as targets.
    • D. Use AWS Mitigation Hub Refactor Spaces to migrate each application off the EC2 instance. Break down functionality from each application into individual components. Host each application on Amazon Elastic Container Service (Amazon ECS) with an AWS Fargate launch type.

    View question →

  12. Q12. Q912. A company wants to isolate its workloads by creating an AWS account for each workload. The company needs a solution that centrally manages networking components for the workloads. The solution also must create accounts with automatic security controls (guardrails).Which solution will meet these requirements with the LEAST operational overhead?

    • A. Use AWS Control Tower to deploy accounts. Create a networking account that has a VPC with private subnets and public subnets. Use AWS Resource Access Manager (AWS RAM) to share the subnets with the workload accounts.
    • B. Use AWS Organizations to deploy accounts. Create a networking account that has a VPC with private subnets and public subnets. Use AWS Resource Access Manager (AWS RAM) to share the subnets with the workload accounts.
    • C. Use AWS Control Tower to deploy accounts. Deploy a VPC in each workload account. Configure each VPC to route through an inspection VPC by using a transit gateway attachment.
    • D. Use AWS Organizations to deploy accounts. Deploy a VPC in each workload account. Configure each VPC to route through an inspection VPC by using a transit gateway attachment.

    View question →

  13. Q13. Q913. A company hosts a website on Amazon EC2 instances behind an Application Load Balancer (ALB). The website serves static content. Website traffic is increasing. The company wants to minimize the website hosting costs.Which solution will meet these requirements?

    • A. Move the website to an Amazon S3 bucket. Configure an Amazon CloudFront distribution for the S3 bucket.
    • B. Move the website to an Amazon S3 bucket. Configure an Amazon ElastiCache cluster for the S3 bucket.
    • C. Move the website to AWS Amplify. Configure an ALB to resolve to the Amplify website.
    • D. Move the website to AWS Amplify. Configure EC2 instances to cache the website.

    View question →

  14. Q14. Q914. A company is designing its production application's disaster recovery (DR) strategy. The application is backed by a MySQL database on an Amazon Aurora cluster in the us-east-1 Region. The company has chosen the us-west-1 Region as its DR Region.The company's target recovery point objective (RPO) is 5 minutes and the target recovery time objective (RTO) is 20 minutes. The company wants to minimize configuration changes.Which solution will meet these requirements with the MOST operational efficiency?

    • A. Create an Aurora read replica in us-west-1 similar in size to the production application's Aurora MySQL cluster writer instance.
    • B. Convert the Aurora cluster to an Aurora global database. Configure managed failover.
    • C. Create a new Aurora cluster in us-west-1 that has Cross-Region Replication.
    • D. Create a new Aurora cluster in us-west-1. Use AWS Database Migration Service (AWS DMS) to sync both clusters.

    View question →

  15. Q15. Q915. A company runs a critical data analysis job each week before the first day of the work week. The job requires at least 1 hour to complete the analysis. The job is stateful and cannot tolerate interruptions. The company needs a solution to run the job on AWS.Which solution will meet these requirements?

    • A. Create a container for the job. Schedule the job to run as an AWS Fargate task on an Amazon Elastic Container Service (Amazon ECS) cluster by using Amazon EventBridge Scheduler.
    • B. Configure the job to run in an AWS Lambda function. Create a scheduled rule in Amazon EventBridge to invoke the Lambda function.
    • C. Configure an Auto Scaling group of Amazon EC2 Spot Instances that run Amazon Linux. Configure a crontab entry on the instances to run the analysis.
    • D. Configure an AWS DataSync task to run the job. Configure a cron expression to run the task on a schedule.

    View question →

  16. Q16. Q916. A company runs workloads in the AWS Cloud. The company wants to centrally collect security data to assess security across the entire company and to improve workload protection.Which solution will meet these requirements with the LEAST development effort?

    • A. Configure a data lake in AWS Lake Formation. Use AWS Glue crawlers to ingest the security data into the data lake.
    • B. Configure an AWS Lambda function to collect the security data in .csv format. Upload the data to an Amazon S3 bucket.
    • C. Configure a data lake in Amazon Security Lake to collect the security data. Upload the data to an Amazon S3 bucket.
    • D. Configure an AWS Database Migration Service (AWS DMS) replication instance to load the security data into an Amazon RDS cluster.

    View question →

  17. Q17. Q917. A company is migrating five on-premises applications to VPCs in the AWS Cloud. Each application is currently deployed in isolated virtual networks on premises and should be deployed similarly in the AWS Cloud. The applications need to reach a shared services VPC. All the applications must be able to communicate with each other.If the migration is successful, the company will repeat the migration process for more than 100 applications.Which solution will meet these requirements with the LEAST administrative overhead?

    • A. Deploy software VPN tunnels between the application VPCs and the shared services VPC. Add routes between the application VPCs in their subnets to the shared services VPC.
    • B. Deploy VPC peering connections between the application VPCs and the shared services VPC. Add routes between the application VPCs in their subnets to the shared services VPC through the peering connection.
    • C. Deploy an AWS Direct Connect connection between the application VPCs and the shared services VPAdd routes from the application VPCs in their subnets to the shared services VPC and the applications VPCs. Add routes from the shared services VPC subnets to the applications VPCs.
    • D. Deploy a transit gateway with associations between the transit gateway and the application VPCs and the shared services VPC. Add routes between the application VPCs in their subnets and the application VPCs to the shared services VPC through the transit gateway.

    View question →

  18. Q18. Q918. A company wants to use Amazon Elastic Container Service (Amazon ECS) to run its on-premises application in a hybrid environment. The application currently runs on containers on premises.The company needs a single container solution that can scale in an on-premises, hybrid, or cloud environment. The company must run new application containers in the AWS Cloud and must use a load balancer for HTTP traffic.Which combination of actions will meet these requirements? (Choose two.)

    • A. Set up an ECS cluster that uses the AWS Fargate launch type for the cloud application containers. Use an Amazon ECS Anywhere external launch type for the on-premises application containers.
    • B. Set up an Application Load Balancer for cloud ECS services.
    • C. Set up a Network Load Balancer for cloud ECS services.
    • D. Set up an ECS cluster that uses the AWS Fargate launch type. Use Fargate for the cloud application containers and the on-premises application containers.
    • E. Set up an ECS cluster that uses the Amazon EC2 launch type for the cloud application containers. Use Amazon ECS Anywhere with an AWS Fargate launch type for the on-premises application containers.

    View question →

  19. Q19. Q919. A company is migrating its workloads to AWS. The company has sensitive and critical data in on-premises relational databases that run on SQL Server instances.The company wants to use the AWS Cloud to increase security and reduce operational overhead for the databases.Which solution will meet these requirements?

    • A. Migrate the databases to Amazon EC2 instances. Use an AWS Key Management Service (AWS KMS) AWS managed key for encryption.
    • B. Migrate the databases to a Multi-AZ Amazon RDS for SQL Server DB instance. Use an AWS Key Management Service (AWS KMS) AWS managed key for encryption.
    • C. Migrate the data to an Amazon S3 bucket. Use Amazon Macie to ensure data security.
    • D. Migrate the databases to an Amazon DynamoDB table. Use Amazon CloudWatch Logs to ensure data security.

    View question →

  20. Q20. Q920. A company wants to migrate an application to AWS. The company wants to increase the application's current availability. The company wants to use AWS WAF in the application's architecture.Which solution will meet these requirements?

    • A. Create an Auto Scaling group that contains multiple Amazon EC2 instances that host the application across two Availability Zones. Configure an Application Load Balancer (ALB) and set the Auto Scaling group as the target. Connect a WAF to the ALB.
    • B. Create a cluster placement group that contains multiple Amazon EC2 instances that hosts the application. Configure an Application Load Balancer and set the EC2 instances as the targets. Connect a WAF to the placement group.
    • C. Create two Amazon EC2 instances that host the application across two Availability Zones. Configure the EC2 instances as the targets of an Application Load Balancer (ALB). Connect a WAF to the ALB.
    • D. Create an Auto Scaling group that contains multiple Amazon EC2 instances that host the application across two Availability Zones. Configure an Application Load Balancer (ALB) and set the Auto Scaling group as the target. Connect a WAF to the Auto Scaling group.

    View question →

  21. Q21. Q921. A company manages a data lake in an Amazon S3 bucket that numerous applications access. The S3 bucket contains a unique prefix for each application. The company wants to restrict each application to its specific prefix and to have granular control of the objects under each prefix.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Create dedicated S3 access points and access point policies for each application.
    • B. Create an S3 Batch Operations job to set the ACL permissions for each object in the S3 bucket.
    • C. Replicate the objects in the S3 bucket to new S3 buckets for each application. Create replication rules by prefix.
    • D. Replicate the objects in the S3 bucket to new S3 buckets for each application. Create dedicated S3 access points for each application.

    View question →

  22. Q22. Q922. A company has an application that customers use to upload images to an Amazon S3 bucket. Each night, the company launches an Amazon EC2 Spot Fleet that processes all the images that the company received that day. The processing for each image takes 2 minutes and requires 512 MB of memory.A solutions architect needs to change the application to process the images when the images are uploaded.Which change will meet these requirements MOST cost-effectively?

    • A. Use S3 Event Notifications to write a message with image details to an Amazon Simple Queue Service (Amazon SQS) queue. Configure an AWS Lambda function to read the messages from the queue and to process the images.
    • B. Use S3 Event Notifications to write a message with image details to an Amazon Simple Queue Service (Amazon SQS) queue. Configure an EC2 Reserved Instance to read the messages from the queue and to process the images.
    • C. Use S3 Event Notifications to publish a message with image details to an Amazon Simple Notification Service (Amazon SNS) topic. Configure a container instance in Amazon Elastic Container Service (Amazon ECS) to subscribe to the topic and to process the images.
    • D. Use S3 Event Notifications to publish a message with image details to an Amazon Simple Notification Service (Amazon SNS) topic. Configure an AWS Elastic Beanstalk application to subscribe to the topic and to process the images.

    View question →

  23. Q23. Q923. A company wants to implement new security compliance requirements for its development team to limit the use of approved Amazon Machine Images (AMIs).The company wants to provide access to only the approved operating system and software for all its Amazon EC2 instances.The company wants the solution to have the least amount of lead time for launching EC2 instances.Which solution will meet these requirements?

    • A. Create a portfolio by using AWS Service Catalog that includes only EC2 instances launched with approved AMIs. Ensure that all required software is preinstalled on the AMIs. Create the necessary permissions for developers to use the portfolio.
    • B. Create an AMI that contains the approved operating system and software by using EC2 Image Builder.Give developers access to that AMI to launch the EC2 instances
    • C. Create an AMI that contains the approved operating system. Tell the developers to use the approved AMI. Create an Amazon EventBridge rule to run an AWS Systems Manager script when a new EC2 instance is launched. Configure the script to install the required software from a repository.
    • D. Create an AWS Config rule to detect the launch of EC2 instances with an AMI that is not approved.Associate a remediation rule to terminate those instances and launch the instances again with the approved AMI. Use AWS Systems Manager to automatically install the approved software on the launch of an EC2 instance.

    View question →

  24. Q24. Q924. A company is designing an application to connect AWS Lambda functions to an Amazon RDS for MySQL DB instance.The DB instance manages many connections.The company needs to modify the application to improve connectivity and recovery.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Use Amazon RDS Proxy for connection pooling. Modify the application to use the RDS Proxy for connections to the DB instance.
    • B. Create a new RDS instance for connection pooling. Modify the application to use the new RDS instance for connectivity.
    • C. Create read replicas to distribute the load of the DB instance. Create a Network Load Balancer to distribute the load across the read replicas
    • D. Migrate the RDS for MySQL DB instance to Amazon Aurora MySQL to increase DB instance performance.

    View question →

  25. Q25. Q925. A company is running a media store across multiple Amazon EC2 instances distributed across multiple Availability Zones in a single VPC.The company wants a high-performing solution to share data between all the EC2 instances,and prefers to keep the data within the VPC only.What should a solutions architect recommend?

    • A. Create an Amazon S3 bucket and call the service APIs from each instance's application.
    • B. Create an Amazon S3 bucket and configure all instances to access it as a mounted volume.
    • C. Configure an Amazon Elastic Block Store(Amazon EBS) volume and mount it across all instances.
    • D. Configure an Amazon Elastic File System (Amazon EFS) file system and mount it across all instances.

    View question →

  26. Q26. Q926. A company uses an Amazon DynamoDB table to store data that the company receives from devices. The DynamoDB table supports a customer-facing website to display recent activity on customer devices. The company configured the table with provisioned throughput for writes and reads. The company wants to calculate performance metrics for customer device data on a daily basis. The solution must have minimal effect on the table's provisioned read and write capacity.Which solution will meet these requirements?

    • A. Use an Amazon Athena SQL query with the Amazon Athena DynamoDB connector to calculate performance metrics on a recurring schedule.
    • B. Use an AWS Glue job with the AWS Glue DynamoDB export connector to calculate performance metrics on a recurring schedule.
    • C. Use an Amazon Redshift COPY command to calculate performance metrics on a recurring schedule.
    • D. Use an Amazon EMR job with an Apache Hive external table to calculate performance metrics on a recurring schedule.

    View question →

  27. Q27. Q927. A company is using AWS DataSync to migrate millions of files from an on-premises system to AWS. The files are 10 KB in size on average.The company wants to use Amazon S3 for file storage.For the first year after the migration,the files will be accessed once or twice and must be immediately available.After 1 year, the files must be archived for at least 7 years.Which solution will meet these requirements MOST cost-effectively?

    • A. Use an archive tool to group the files into large objects. Use DataSync to migrate the objects. Store the objects in S3 Glacier Instant Retrieval for the first year. Use a lifecycle configuration to transition the files to S3 Glacier Deep Archive after 1 year with a retention period of 7 years.
    • B. Use an archive tool to group the files into large objects. Use DataSync to copy the objects to S3 Standard-Infrequent Access(S3 Standard-lA). Use a lifecycle configuration to transition the files to S3 Glacier Instant Retrieval after 1 year with a retention period of 7 years.
    • C. Configure the destination storage class for the files as S3 Glacier Instant Retrieval. Use a lifecycle policy to transition the files to S3 Glacier Flexible Retrieval after 1 year with a retention period of 7 years
    • D. Configure a DataSync task to transfer the files to S3 Standard-lnfrequent Access (S3 Standard-lA). Use a lifecycle configuration to transition the files to S3 Deep Archive after 1 year with a retention period of 7 years.

    View question →

  28. Q28. Q928. A company has migrated several applications to AWS in the past 3 months.The company wants to know the breakdown of costs for each of these applications.The company wants to receive a regular report that includes this information.Which solution will meet these requirements MOST cost-effectively?

    • A. Use AWS Budgets to download data for the past 3 months into a .csv file. Look up the desired information.
    • B. Load AWS Cost and Usage Reports into an Amazon RDS DB instance. Run SQL queries to get the desired information.
    • C. Tag all the AWS resources with a key for cost and a value of the application's name. Activate cost allocation tags. Use Cost Explorer to get the desired information.
    • D. Tag all the AWS resources with a key for cost and a value of the application's name. Use the AWS Billing and Cost Management console to download bills for the past 3 months.Look up the desired information.

    View question →

  29. Q29. Q929. A company hosts a video streaming web application in a VPC.The company uses a Network Load Balancer (NLB) to handle TCP traffic for real-time data processing. There have been unauthorized attempts to access the application.The company wants to improve application security with minimal architectural change to prevent unauthorized attempts to access the application.Which solution will meet these requirements?

    • A. Implement a series of AWS WAF rules directly on the NLB to filter out unauthorized traffic.
    • B. Recreate the NLB with a security group to allow only trusted IP addresses.
    • C. Deploy a second NLB in parallel with the existing NLB configured with a strict IP address allow list.
    • D. Use AWS Shield Advanced to provide enhanced DDoS protection and prevent unauthorized access attempts.

    View question →

  30. Q30. Q930. A company has a web application that includes an embedded NoSQL database. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB).The instances run in an Amazon EC2 Auto Scaling group in asingle Availability Zone.A recent increase in traffic requires the application to be highly available and for the database to be eventually consistent.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Replace the ALB with a Network Load Balancer. Maintain the embedded NoSQL database with its replication service on the EC2 instances
    • B. Replace the ALB with a Network Load Balancer. Migrate the embedded NoSQL database to Amazon DynamoDB by using AWS Database Migration Service (AWS DMS).
    • C. Modify the Auto Scaling group to use EC2 instances across three Availability Zones. Maintain the embedded NoSQL database with its replication service on the EC2 instances.
    • D. Modify the Auto Scaling group to use EC2 instances across three Availability Zones. Migrate the embedded NoSQL database to Amazon DynamoDB by using AWS Database Migration Service (AWS DMS)

    View question →

  31. Q31. Q931. A company runs database workloads on AWS that are the backend for the company's customer portals. The company runs a Multi-AZ database cluster on Amazon RDS for PostgreSQL.The company needs to implement a 30-day backup retention policy.The company currently has both automated RDS backups and manual RDS backups.The company wants to maintain both types of existing RDS backups that are less than 30 days old.Which solution will meet these requirements MOST cost-effectively?

    • A. Configure the RDS backup retention policy to 30 days for automated backups by using AWS Backup.Manually delete manual backups that are older than 30 days.
    • B. Disable RDS automated backups.Delete automated backups and manual backups that are older than 30 days.Configure the RDS backup retention policy to 30 days for automated backups.
    • C. Configure the RDS backup retention policy to 30 days for automated backups. Manually delete manual backups that are older than 30 days
    • D. Disable RDS automated backups.Delete automated backups and manual backups that are older than 30 days automatically by using AWS CloudFormation. Configure the RDS backup retention policy to 30 days for automated backups.

    View question →

  32. Q32. Q932. A company has an employee web portal. Employees log in to the portal to view payroll details. The company is developing a new system to give employees the ability to upload scanned documents for reimbursement. The company runs a program to extract text-based data from the documents and attach the extracted information to each employee's reimbursement lDs for processing.The employee web portal requires 100% uptime.The document extract program runs infrequently throughout the day on an on-demand basis.The company wants to build a scalable and cost-effective new system that will require minimal changes to the existing web portal. The company does not want to make any code changes.Which solution will meet these requirements with the LEAST implementation effort?

    • A. Run Amazon EC2 On-Demand Instances in an Auto Scaling group for the web portal. Use an AWS Lambda function to run the document extract program. lnvoke the Lambda function when an employee uploads a new reimbursement document.
    • B. Run Amazon EC2 Spot Instances in an Auto Scaling group for the web portal.Run the document extract program on EC2 Spot Instances. Start document extract program instances when an employee uploads a new reimbursement document.
    • C. Purchase a Savings Plan to run the web portal and the document extract program. Run the web portal and the document extract program in an Auto Scaling group.
    • D. Create an Amazon S3 bucket to host the web portal. Use Amazon API Gateway and an AWS Lambda function for the existing functionalities. Use the Lambda function to run the document extract program.Invoke the Lambda function when the API that is associated with a new document upload is called.

    View question →

  33. Q33. Q933. A company has a multi-tier web application.The application's internal service components are deployed on Amazon EC2 instances.The internal service components need to access third-party software as a service (SaaS) APIs that are hosted on AWS.The company needs to provide secure and private connectivity from the application's internal services to the third-party SaaS application. The company needs to ensure that there is minimal public internet exposure.Which solution will meet these requirements?

    • A. Implement an AWS Site-to-Site VPN to establish a secure connection with the third-party SaaS provider.
    • B. Deploy AWS Transit Gateway to manage and route traffic between the application's VPC and the third- party SaaS provider.
    • C. Configure AWS PrivateLink to allow only outbound traffic from the VPC without enabling the third-party SaaS provider to establish a return path to the network.
    • D. Use AWS PrivateLink to create a private connection between the application's VPC and the third-party SaaS provider.

    View question →

  34. Q34. Q934. An online gaming company is transitioning user data storage to Amazon DynamoDB to support the company's growing user base.The current architecture includes DynamoDB tables that contain user profiles,achievements, and in-game transactions.The company needs to design a robust, continuously available,and resilient DynamoDB architecture to maintain a seamless gaming experience for users.Which solution will meet these requirements MOST cost-effectively?

    • A. Create DynamoDB tables in a single AWS Region. Use on-demand capacity mode. Use global tables to replicate data across multiple Regions
    • B. Use DynamoDB Accelerator(DAX) to cache frequently accessed data. Deploy tables in a single AWS Region and enable auto scaling. Configure Cross-Region Replication manually to additional Regions.
    • C. Create DynamoDB tables in multiple AWS Regions. Use on-demand capacity mode. Use DynamoDB Streams fon Cross-Region Replication between Regions
    • D. Use DynamoDB global tables for automatic multi-Region replication. Deploy tables in multiple AWS Regions.Use provisioned capacity mode.Enable auto scaling

    View question →

  35. Q35. Q935. A company needs to give a globally distributed development team secure access to the company's AWS resources in a way that complies with security policies.The company currently uses an on-premises Active Directory for internal authentication.The company uses AWS Organizations to manage multiple AWS accounts that support multiple projects.The company needs a solution to integrate with the existing infrastructure to provide centralized identity management and access control.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Set up AWS Directory Service to create an AWS managed Microsoft Active Directory on AWS.Establish a trust relationship with the on-premises Active Directory. Use IAM roles that are assigned to Active Directory groups to access AWS resources within the company's AWS accounts.
    • B. Create an IAM user for each developer.Manually manage permissions for each IAM user based on each user's involvement with each project.Enforce multi-factor authentication(MFA) as an additional layer of security.
    • C. Use AD Connector in AWS Directory Service to connect to the on-premises Active Directory. Integrate AD Connector with AWS IAM Identity Center. Configure permissions sets to give each AD group access to specific AWS accounts and resources.
    • D. Use Amazon Cognito to deploy an identity federation solution. Integrate the identity federation solution with the on-premises Active Directory. Use Amazon Cognito to provide access tokens for developers to access AWS accounts and resources

    View question →

  36. Q36. Q936. A company runs a Node.js function on a server in its on-premises data center.The data center stores data in a PostgreSQ database.The company stores the credentials in a connection string in an environment variable on the server.The company wants to migrate its application to AWS and to replace the Node.js application server with AWS Lambda. The company also wants to migrate to Amazon RDS for PostgreSQL and to ensure that the database credentials are securely managed.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Store the database credentials as a parameter in AWS Systems Manager Parameter Store. Configure Parameter Store to automatically rotate the secrets every 30 days. Update the Lambda function to retrieve the credentials from the parameter.
    • B. Store the database credentials as a secret in AWS Secrets Manager. Configure Secrets Manager to automatically rotate the credentials every 30 days. Update the Lambda function to retrieve the credentials from the secret.
    • C. Store the database credentials as an encrypted Lambda environment variable. Write a custom Lambda function to rotate the credentials. Schedule the Lambda function to run every 30 days
    • D. Store the database credentials as a key in AWS Key Management Service (AWS KMS). Configure automatic rotation for the key. Update the Lambda function to retrieve the credentials from the KMS key.

    View question →

  37. Q37. Q937. A solutions architect needs to connect a company's corporate network to its VPC to allow on-premises access to its AWS resources. The solution must provide encryption of all traffic between the corporate network and the VPC at the network layer and the session layer. The solution also must provide security controls to prevent unrestricted access between AWS and the on-premises systems.Which solution meets these requirements?

    • A. Configure AWS Direct Connect to connect to the VPC.Configure the VPC route tables to allow and deny traffic between AWS and on premises as required.
    • B. Create an IAM policy to allow access to the AWS Management Console only from a defined set of corporate IP addresses. Restrict user access based on job responsibility by using an IAM policy and roles.
    • C. Configure AWS Site-to-Site VPN to connect to the VPC.Configure route table entries to direct traffic from on premises to the VPC.Configure instance security groups and network ACLs to allow only required traffic from on premises.
    • D. Configure AWS Transit Gateway to connect to the VPC.Configure route table entries to direct traffic from on premises to the VPC.Configure instance security groups and network ACLs to allow only required traffic from on premises.

    View question →

  38. Q38. Q938. A company recently performed a lift and shift migration of its on-premises Oracle database workload to run on an Amazon EC2 memory optimized Linux instance.The EC2 Linux instance uses a 1 TB Provisioned IOPS SSD (io1) EBS volume with 64,000 IOPS.The database storage performance after the migration is slower than the performance of the on-premises database.Which solution will improve storage performance?

    • A. Add more Provisioned IOPS SSD (io1)EBS volumes. Use OS commands to create a Logical Volume Management(LVM) stripe.
    • B. Increase the Provisioned IOPS SSD (io1) EBS volume to more than 64,000 IOPS
    • C. Increase the size of the Provisioned IOPS SSD (io1) EBS volume to 2 TB.
    • D. Change the EC2 Linux instance to a storage optimized instance type.Do not change the Provisioned lOPS SSD (io1) EBS volume.

    View question →

  39. Q39. Q939. A company wants to replicate existing and ongoing data changes from an on-premises Oracle database to Amazon RDS for Oracle. The amount of data to replicate varies throughout each day.The company wants to use AWS Database Migration Service (AWS DMS) for data replication. The solution must allocate only the capacity that the replication instance requires.Which solution will meet these requirements?

    • A. Configure the AWS DMS replication instance with a Multi-AZ deployment to provision instances across multiple Availability Zones.
    • B. Create an AWS DMS Serverless replication task to analyze and replicate the data while provisioning the required capacity.
    • C. Use Amazon EC2 Auto Scaling to scale the size of the AWS DMS replication instance up or down based on the amount of data to replicate.
    • D. Provision AWS DMS replication capacity by using Amazon Elastic Container Service (Amazon ECS) with an AWS Fargate launch type to analyze and replicate the data while provisioning the required capacity.

    View question →

  40. Q40. Q940. A company runs its customer-facing web application on containers. The workload uses Amazon Elastic Container Service (Amazon ECS) on AWS Fargate. The web application is resource intensive.The web application needs to be available 24 hours a day,7 days a week for customers.The company expects the application to experience short bursts of high traffic.The workload must be highly available.Which solution will meet these requirements MOST cost-effectively?

    • A. Configure an ECS capacity provider with Fargate. Conduct load testing by using a third-party tool.Rightsize the Fargate tasks in Amazon CloudWatch.
    • B. Configure an ECS capacity provider with Fargate for steady state and Fargate Spot for burst traffic.
    • C. Configure an ECS capacity provider with Fargate Spot for steady state and Fargate for burst traffic
    • D. Configure an ECS capacity provider with Fargate. Use AWS Compute Optimizer to rightsize the Fargate task

    View question →

  41. Q41. Q941. A company runs its production workload on an Amazon Aurora MySQL DB cluster that includes six Aurora Replicas. The company wants near-real-time reporting queries from one of its departments to be automatically distributed across three of the Aurora Replicas. Those three replicas have a different compute and memory specification from the rest of the DB cluster.Which solution meets these requirements?

    • A. Create and use a custom endpoint for the workload.
    • B. Create a three-node cluster clone and use the reader endpoint
    • C. Use any of the instance endpoints for the selected three nodes
    • D. Use the reader endpoint to automatically distribute the read-only workload

    View question →

  42. Q42. Q942. A company runs an on-premises managed file transfer solution to collect images from its clients.The company uses an open source transfer tool to transfer and integrate the images into the company's workflow. The company then runs a custom application to add watermarks to the images. The company needs to migrate this workload to AWS and wants to use AWS managed services where possible. Uploaded images must be stored as objects.The company wants to automate the watermark addition.Which solution will meet these requirements?

    • A. Use AWS DataSync to automate file transfers. Store the images in an Amazon S3 bucket. Use an application that runs on Amazon EC2 instances to add watermarks.
    • B. Use REST APls to transfer files.Store the images in an Amazon S3 bucket. Use AWS Batch jobs to add watermarks.
    • C. Use SFTP with AWS Transfer Family to automate file transfers into Amazon S3 buckets. Configure the Transfer Family workflow to invoke an AWS Lambda function to add watermarks.
    • D. Use AWS Transfer Family to transfer images. Store the images in Amazon S3 Glacier Deep Archive.Run an AWS Step Functions state machine to add watermarks.

    View question →

  43. Q43. Q943. An application gives a company's users the ability to access product data. The product data is stored on an Amazon RDS for MySQL DB instance. The company has isolated an application performance slowdown and wants to separate read traffic from write traffic.A solutions architect needs to optimize the application's performance quickly.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Create a new DB instance to serve read traffic. Use an Elastic Load Balancing (ELB) load balancer to distribute traffic between DB instances.
    • B. Change the existing database configuration to a Multi-AZ DB instance deployment with one replica.Serve the read requests from the standby DB instance.
    • C. Create a new DB instance to serve read traffic. Use AWS Database Migration Service (AWS DMS) to synchronize data between the DB instances.
    • D. Create read replicas for the DB instance. Configure the read replicas with the same compute and storage resources as the source DB instance.

    View question →

  44. Q44. Q944. A company is planning to migrate a legacy application to AWS. The application currently uses NFS to communicate to an on-premises storage solution to store application data. The application cannot be modified to use any other communication protocols other than NFS for this purpose.Which storage solution should a solutions architect recommend for use after the migration?

    • A. A. AWS DataSync
    • B. Amazon Elastic Block Store (Amazon EBS)
    • C. Amazon Elastic File System (Amazon EFS)
    • D. Amazon EMR File System (Amazon EMRFS)

    View question →

  45. Q45. Q945. A company is migrating an application from an on-premises location to Amazon Elastic Kubernetes Service (Amazon EKS). The company must use a custom subnet for pods that are in the company's VPC to comply with requirements. The company also needs to ensure that the pods can communicate securely within the pods' VPC.Which solution will meet these requirements?

    • A. Configure AWS Transit Gateway to directly manage custom subnet configurations for the pods in Amazon EKS
    • B. Create an AWS Direct Connect connection from the company's on-premises IP address ranges to the EKS pods
    • C. Use the Amazon VPC CNI plugin for Kubernetes.Define custom subnets in the VPC cluster for the pods to use
    • D. Implement a Kubernetes network policy that has pod anti-affinity rules to restrict pod placement to specific nodes that are within custom subnets

    View question →

  46. Q46. Q946. A solutions architect is creating an application that will handle batch processing of large amounts of data. The input data will be held in Amazon S3 and the output data will be stored in a different S3 bucket. For processing, the application will transfer the data over the network between multiple Amazon EC2 instances.What should the solutions architect do to reduce the overall data transfer costs?

    • A. Place all the EC2 instances in an Auto Scaling group.
    • B. Place all the EC2 instances in the same AWS Region
    • C. Place all the EC2 instances in the same Availability Zone
    • D. Place all the EC2 instances in private subnets in multiple Availability Zones

    View question →

  47. Q47. Q947. A company is migrating a daily Microsoft Windows batch job from the company's on-premises environment to AWS.The current batch job runs for up to 1 hour.The company wants to modernize the batch job process for the cloud environment.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Create a fleet of Amazon EC2 instances in an Auto Scaling group to handle the Windows batch job processing
    • B. Implement an AWS Lambda function to process the Windows batch job. Use an Amazon EventBridge rule to invoke the Lambda function
    • C. Use AWS Fargate to deploy the Windows batch job as a container. Use AWS Batch to manage the batch job processing.
    • D. Use Amazon Elastic Kubernetes Service (Amazon EKS) on Amazon EC2 instances to orchestrate Windows containers for the batch job processing

    View question →

  48. Q48. Q948. A company is implementing a new application on AWS.The company will run the application on multiple Amazon EC2 instances across multiple Availability Zones within multiple AWS Regions.The application will be available through the internet. Users will access the application from around the world.The company wants to ensure that each user who accesses the application is sent to the EC2 instances that are closest to the user's location.Which solution will meet these requirements?

    • A. Implement an Amazon Route 53 geolocation routing policy. Use an internet-facing Application Load Balancer to distribute the traffic across all Availability Zones within the same Region.
    • B. Implement an Amazon Route 53 geoproximity routing policy. Use an internet-facing Network Load Balancer to distribute the traffic across all Availability Zones within the same Region.
    • C. Implement an Amazon Route 53 multivalue answer routing policy. Use an internet-facing Application Load Balancer to distribute the traffic across all Availability Zones within the same Region.
    • D. Implement an Amazon Route 53 weighted routing policy. Use an internet-facing Network Load Balancer to distribute the traffic across all Availability Zones within the same Region.

    View question →

  49. Q49. Q949. A company currently stores 5 TB of data in on-premises block storage systems. The company's current storage solution provides limited space for additional data. The company runs applications on premises that must be able to retrieve frequently accessed data with low latency. The company requires a cloud-based storage solution.Which solution will meet these requirements with the MOST operational efficiency?

    • A. Use Amazon S3 File Gateway. Integrate S3 File Gateway with the on-premises applications to store and directly retrieve files by using the SMB file system.
    • B. Use an AWS Storage Gateway Volume Gateway with cached volumes as iSCSl targets
    • C. Use an AWS Storage Gateway Volume Gateway with stored volumes as iSCSI targets
    • D. Use an AWS Storage Gateway Tape Gateway.Integrate Tape Gateway with the on-premises applications to store virtual tapes in Amazon S3.

    View question →

  50. Q50. Q950. A company that is in the ap-northeast-1 Region has a fleet of thousands of AWS Outposts servers. The company has deployed the servers at remote locations around the world. All the servers regularly download new software versions that consist of 100 files.There is significant latency before all servers run the new software versions.The company must reduce the deployment latency for new software versions. Which solution will meet this requirement with the LEAST operational overhead?

    • A. Create an Amazon S3 bucket in ap-northeast-1. Set up an Amazon CloudFront distribution in ap- northeast-1 that includes a CachingDisabled cache policy. Configure the S3 bucket as the origin.Download the software by using signed URLs.
    • B. Create an Amazon S3 bucket in ap-northeast-1. Create a second S3 bucket in the us-east-1 Region.Configure replication between the buckets. Set up an Amazon CloudFront distribution that uses ap- northeast-1 as the primary origin and us-east-1 as the secondary origin. Download the software by using signed URLs.
    • C. Create an Amazon S3 bucket in ap-northeast-1. Configure Amazon S3 Transfer Acceleration. Download the software by using the S3 Transfer Acceleration endpoint.
    • D. Create an Amazon S3 bucket in ap-northeast-1. Set up an Amazon CloudFront distribution. Configure the S3 bucket as the origin. Download the software by using signed URLs

    View question →

  51. Q51. Q951. A company is developing an application in the AWS Cloud.The application's HTTP API contains critical information that is published in Amazon API Gateway.The critical information must be accessible from only a limited set of trusted lP addresses that belong to the company's internal network.Which solution will meet these requirements?

    • A. Set up an APl Gateway private integration to restrict access to a predefined set of IP addresses
    • B. Create a resource policy for the APl that denies access to any IP address that is not specifically allowed.
    • C. Directly deploy the APl in a private subnet. Create a network ACL. Set up rules to allow the traffic from specific IP addresses.
    • D. Modify the security group that is attached to APl Gateway to allow inbound traffic from only the trusted IP addresses

    View question →

  52. Q52. Q952. A company uses GPS trackers to document the migration patterns of thousands of sea turtles. The trackers check every 5 minutes to see if a turtle has moved more than 100 yards (91.4 meters). lf a turtle has moved,its tracker sends the new coordinates to a web application running on three Amazon EC2 instances that are in multiple Availability Zones in one AWS Region.Recently,the web application was overwhelmed while processing an unexpected volume of tracker data. Data was lost with no way to replay the events.A solutions architect must prevent this problem from happening again and needs a solution with the least operational overhead.What should the solutions architect do to meet these requirements?

    • A. Create an Amazon S3 bucket to store the data. Configure the application to scan for new data in the bucket for processing
    • B. Create an Amazon API Gateway endpoint to handle transmitted location coordinates. Use an AWS Lambda function to process each item concurrently.
    • C. Create an Amazon Simple Queue Service (Amazon SQS) queue to store the incoming data. Configure the application to poll for new messages for processing
    • D. Create an Amazon DynamoDB table to store transmitted location coordinates. Configure the application to query the table for new data for processing. Use TTL to remove data that has been processed

    View question →

  53. Q53. Q953. A company is migrating a production environment application to the AWS Cloud.The company uses Amazon RDS for Oracle for the database layer. The company needs to configure the database to meet the needs of high l/O intensive workloads that require low latency and consistent throughput. The database workloads are read intensive and write intensive.Which solution will meet these requirements?

    • A. Use a Multi-AZ DB instance deployment for the RDS for Oracle database.
    • B. Configure the RDS for Oracle database to use the Provisioned IOPS SSD storage type
    • C. Configure the RDS for Oracle database to use the General Purpose SSD storage type
    • D. Enable RDS read replicas for RDS for Oracle

    View question →

  54. Q54. Q954. A company needs to save confidential medical results in an Amazon S3 bucket. The repository must allow a few approved users to add new files.The repository must restrict all other users to read-only access by using a write once, ready many (WORM) approach.The company must keep every file in the repository for a minimum of 1 year after its creation date.Which solution will meet these requirements with the LEAST implementation effort?

    • A. Configure the S3 bucket with multi-factor authentication (MFA) delete. Do not share the MFA secret with users to avoid deletion.
    • B. Use S3 Object Lock in compliance mode with a retention period of 1 year. Use an IAM policy that restricts file access to specified approved users
    • C. Use an IAM role to restrict all users from deleting or changing objects in the S3 bucket. Use an S3 bucket policy to only allow the IAM role
    • D. Configure the S3 bucket to invoke an AWS Lambda function every time an object is added. Configure the function to track the hash of the saved object so that modified objects can be marked accordingly.

    View question →

  55. Q55. Q955. A company hosts its core network services,including directory services and DNS, in its on-premises data center.The data center is connected to the AWS Cloud using AWS Direct Connect(DX).Additional AWS accounts are planned that will require quick,cost-effective,and consistent access to these network services.What should a solutions architect implement to meet these requirements with the LEAST amount of operational overhead?

    • A. Create a DX connection in each new account. Route the network traffic to the on-premises servers.
    • B. Configure VPC endpoints in the DX VPC for all required services. Route the network traffic to the on- premises servers.
    • C. Create a VPN connection between each new account and the DX VPC.Route the network traffic to the on-premises servers.
    • D. Configure AWS Transit Gateway between the accounts. Assign DX to the transit gateway and route network traffic to the on-premises servers.

    View question →

  56. Q56. Q956. A company is migrating its on-premises Oracle database to an Amazon RDS for Oracle database.The company needs to retain data for 90 days to meet regulatory requirements. The company must also be able to restore the database to a specific point in time for up to 14 days.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Create Amazon RDS automated backups.Set the retention period to 90 days.
    • B. Create an Amazon RDS manual snapshot every day. Delete manual snapshots that are older than 90 days
    • C. Use the Amazon Aurora Clone feature for Oracle to create a point-in-time restore. Delete clones that are older than 90 days.
    • D. Create a backup plan that has a retention period of 90 days by using AWS Backup for Amazon RDS

    View question →

  57. Q57. Q957. A company tracks customer satisfaction by using surveys that the company hosts on its website. The surveys sometimes reach thousands of customers every hour. Survey results are currently sent in email messages to the company so company employees can manually review results and assess customer sentiment.The company wants to automate the customer survey process. Survey results must be available for the previous 12 months.Which solution will meet these requirements in the MOST scalable way?

    • A. Send the survey results data to an Amazon APl Gateway endpoint that is connected to an Amazon Simple Queue Service (Amazon SQS) queue.Create an AWS Lambda function to poll the SQS queue,call Amazon Comprehend for sentiment analysis,and save the results to an Amazon DynamoDB table.Set the TTL for all records to 365 days in the future.
    • B. Send the survey results data to an APl that is running on an Amazon EC2 instance. Configure the APl to store the survey results as a new record in an Amazon DynamoDB table,call Amazon Comprehend for sentiment analysis,and save the results in a second DynamoDB table. Set the TTL for all records to 365 days in the future.
    • C. Write the survey results data to an Amazon S3 bucket. Use S3 Event Notifications to invoke an AWS Lambda function to read the data and call Amazon Rekognition for sentiment analysis. Store the sentiment analysis results in a second S3 bucket. Use S3 Lifecycle policies on each bucket to expire objects after 365 days.
    • D. Send the survey results data to an Amazon APl Gateway endpoint that is connected to an Amazon Simple Queue Service(Amazon SQS) queue. Configure the SQS queue to invoke an AWS Lambda function that calls Amazon Lex for sentiment analysis and saves the results to an Amazon DynamoDB table. Set the TTL for all records to 365 days in the future.

    View question →

  58. Q58. Q958. A company stores user data in AWS.The data is used continuously with peak usage during business hours.Access patterns vary, with some data not being used for months at a time.A solutions architect must choose a cost-effective solution that maintains the highest level of durability while maintaining high availability.Which storage solution meets these requirements?

    • A. Amazon S3 Standard
    • B. Amazon S3 Intelligent-Tiering
    • C. Amazon S3 Glacier Deep Archive
    • D. Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA)

    View question →

  59. Q59. Q959. A social media company has workloads that collect and process data.The workloads store the data in on- premises NFS storage.The data store cannot scale fast enough to meet the company's expanding business needs.The company wants to migrate the current data store to AWS.Which solution will meet these requirements MOST cost-effectively?

    • A. Set up an AWS Storage Gateway Volume Gateway. Use an Amazon S3 Lifecycle policy to transition the data to the appropriate storage class.
    • B. Set up an AWS Storage Gateway Amazon S3 File Gateway. Use an Amazon S3 Lifecycle policy to transition the data to the appropriate storage class.
    • C. Use the Amazon Elastic File System (Amazon EFS) Standard-Infrequent Access (Standard-lA) storage class. Activate the infrequent access lifecycle policy.
    • D. Use the Amazon Elastic File System (Amazon EFS) One Zone-lnfrequent Access(One Zone-lA) storage class. Activate the infrequent access lifecycle policy.

    View question →

  60. Q60. Q960. A company's image-hosting website gives users around the world the ability to upload,view, and download images from their mobile devices.The company currently hosts the static website in an Amazon S3 bucket. Because of the website's growing popularity,the website's performance has decreased.Users have reported latency issues when they upload and download images.The company must improve the performance of the websiteWhich solution will meet these requirements with the LEAST implementation effort?

    • A. Configure an Amazon CloudFront distribution for the S3 bucket to improve the download performance.Enable S3 Transfer Acceleration to improve the upload performance.
    • B. Configure Amazon EC2 instances of the right sizes in multiple AWS Regions. Migrate the application to the EC2 instances. Use an Application Load Balancer to distribute the website traffic equally among the EC2 instances. Configure AWS Global Accelerator to address global demand with low latency.
    • C. Configure an Amazon CloudFront distribution that uses the S3 bucket as an origin to improve the download performance. Configure the application to use CloudFront to upload images to improve the uploadperformance. Create S3 buckets in multiple AWS Regions. Configure replication rules for the buckets to replicate users' data based on the users' location. Redirect downloads to the S3 bucket that is closest to each user's location.
    • D. Configure AWS Global Accelerator for the S3 bucket to improve network performance.Create an endpoint for the application to use Global Accelerator instead of the S3 bucket.

    View question →

  61. Q61. Q961. A streaming media company is rebuilding its infrastructure to accommodate increasing demand for video content that users consume daily.The company needs to process terabyte-sized videos to block some content in the videos. Video processing can take up to 20 minutes.The company needs a solution that will scale with demand and remain cost-effective Which solution will meet these requirements?

    • A. Use AWS Lambda functions to process videos. Store video metadata in Amazon DynamoDB. Store video content in Amazon S3 Intelligent-Tiering
    • B. Use Amazon Elastic Container Service (Amazon ECS) and AWS Fargate to implement microservices to process videos. Store video metadata in Amazon Aurora. Store video content in Amazon S3 Intelligent- Tiering
    • C. Use Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB) to process videos. Store video content in Amazon S3 Standard. Use Amazon Simple Queue Service (Amazon SQS) for queuing and to decouple processing tasks
    • D. Deploy a containerized video processing application on Amazon Elastic Kubernetes Service (Amazon EKS) on Amazon EC2. Store video metadata in Amazon RDS in a single Availability Zone. Store video content in Amazon S3 Glacier Deep

    View question →

  62. Q62. Q962. A financial services company plans to launch a new application on AWS to handle sensitive financial transactions.The company will deploy the application on Amazon EC2 instances.The company will use Amazon RDS for MySQL as the database.The company's security policies mandate that data must be encrypted at rest and in transit.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Configure encryption at rest for Amazon RDS for MySQL by using AWS KMS managed keys. Configure AWS Certificate Manager (ACM) SSL/TLS certificates for encryption in transit.
    • B. Configure encryption at rest for Amazon RDS for MySQL by using AWS KMS managed keys. Configure IPsec tunnels for encryption in transit.
    • C. Implement third-party application-level data encryption before storing data in Amazon RDS for MySQL.Configure AWS Certificate Manager (ACM) SSL/TLS certificates for encryption in transit.
    • D. Configure encryption at rest for Amazon RDS for MySQL by using AWS KMS managed keys. Configure a VPN connection to enable private connectivity to encrypt data in transit.

    View question →

  63. Q63. Q963. A company has applications that run in an organization in AWS Organizations.The company outsources operational support of the applications.The company needs to provide access for the external support engineers without compromising security.The external support engineers need access to the AWS Management Console.The external support engineers also need operating system access to the company's fleet of Amazon EC2 instances that run Amazon Linux in private subnets.Which solution will meet these requirements MOST securely?

    • A. Confirm that AWS Systems Manager Agent(SSM Agent) is installed on all instances.Assign an instance profile with the necessary policy to connect to Systems Manager. Use AWS IAM Identity Center to provide the external support engineers console access. Use Systems Manager Session Manager to assign the required permissions.
    • B. Confirm that AWS Systems Manager Agent (SSM Agent) is installed on all instances. Assign an instance profile with the necessary policy to connect to Systems Manager. Use Systems Manager Session Manager to provide local IAM user credentials in each AWS account to the external support engineers for console access.
    • C. Confirm that all instances have a security group that allows SSH access only from the external support engineers' source lP address ranges.Provide local IAM user credentials in each AWS account to the external support engineers for console access.Provide each external support engineer an SSH key pair to log in to the application instances.
    • D. Create a bastion host in a public subnet. Set up the bastion host security group to allow access from only the external engineers'IP address ranges. Ensure that all instances have a security group that allows SSH access from the bastion host. Provide each external support engineer an SSH key pair to log in to the application instances. Provide local account IAM user credentials to the engineers for console access.

    View question →

  64. Q64. Q964. A company is migrating from a monolithic architecture for a web application that is hosted on Amazon EC2 to a serverless microservices architecture.The company wants to use AWS services that support an event- driven,loosely coupled architecture.The company wants to use the publish/subscribe (pub/sub) pattern. Which solution will meet these requirements MOST cost-effectively?

    • A. Configure an Amazon API Gateway REST API to invoke an AWS Lambda function that publishes events to an Amazon Simple Queue Service (Amazon SQS) queue. Configure one or more subscribers to read events from the SQS queue.
    • B. Configure an Amazon API Gateway REST API to invoke an AWS Lambda function that publishes events to an Amazon Simple Notification Service (Amazon SNS) topic. Configure one or more subscribers to receive events from the SNS topic.
    • C. Configure an Amazon API Gateway WebSocket API to write to a data stream in Amazon Kinesis Data Streams with enhanced fan-out. Configure one or more subscribers to receive events from the data stream.
    • D. Configure an Amazon API Gateway HTTP API to invoke an AWS Lambda function that publishes events to an Amazon Simple Notification Service (Amazon SNS) topic. Configure one or more subscribers to receive events from the topic.

    View question →

  65. Q65. Q965. A company's expense tracking application gives users the ability to upload images of receipts.The application analyzes the receipts to extract information and stores the raw images in Amazon S3.The application is written in Java and runs on Amazon EC2 On-Demand Instances in an Auto Scaling group behind an Application Load Balancer.The compute costs and storage costs have increased with the popularity of the application. Which solution will provide the MOST cost savings without affecting application performance?

    • A. Purchase a Compute Savings Plan for the maximum number of necessary EC2 instances. Store the uploaded files in Amazon Elastic File System (Amazon EFS).
    • B. Decrease the minimum number of EC2 instances in the Auto Scaling group.Use On-Demand Instances for peak scaling.Store the uploaded files in Amazon Elastic File System(Amazon EFS).
    • C. Decrease the maximum number of EC2 instances in the Auto Scaling group.Set up S3 Lifecycle policies to archive the raw images to lower-cost storage tiers after 30 days.
    • D. Purchase a Compute Savings Plan for the minimum number of necessary EC2 instances. Use On- Demand Instances for peak scaling. Set up S3 Lifecycle policies to archive the raw images to lower- cost storage tiers after 30 days

    View question →

  66. Q66. Q966. A solutions architect is creating an event-driven architecture for a new application. The solutions architect creates an Amazon Simple Notification Service (Amazon SNS) topic and subscribes an AWS Lambda function to the SNS topic.The solutions architect uses Amazon CloudWatch to validate that the system functions as expected.The solutions architect publishes a message to the SNS topic to test the functionality. The solutions architect views the output in Amazon CloudWatch and notices that the Lambda function is invoked multiple times.What is the is the most likely reason the Lambda function was invoked multiple times?

    • A. The Lambda function is subscribed to the SNS topic multiple times.
    • B. The SNS delivery policy is configured to deliver the message multiple times.
    • C. The SNS redrive policy is configured to deliver the message multiple times.
    • D. The Lambda function's application logic caused an error that results in retry attempts by the Lambda function.

    View question →

  67. Q67. Q967. A solutions architect needs to review a company's Amazon S3 buckets to discover personally identifiable information (PII). The company stores the PII data in the us-east-1 Region and us-west-2 Region.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Configure Amazon Macie in each Region. Create a job to analyze the data that is in Amazon S3.
    • B. Configure AWS Security Hub for all Regions. Create an AWS Config rule to analyze the data that is in Amazon S3
    • C. Configure Amazon Inspector to analyze the data that is in Amazon S3.
    • D. Configure Amazon GuardDuty to analyze the data that is in Amazon S3.

    View question →

  68. Q68. Q968. A social media company is expanding its Amazon DynamoDB backed infrastructure to accommodate increasing user activity.The company manages three data types:user profiles,posts,and comments.The company wants to ensure high performance for write-heavy queries.The new solution must ensure high availability.The new solution needs to provide low latency between the database layer and the application layer.The new solution must be able to handle dynamic traffic patterns for global users.The company must also track changes to items in the DynamoDB tables.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Create a single DynamoDB table to store all the data types. Use global secondary indexes(GSls) for queries. Use DynamoDB auto scaling to ensure adaptive capacity. Use Amazon Kinesis Data Streams to provide low latency and to track changes.
    • B. Use a separate DynamoDB table for each data type. Use on-demand capacity mode for all tables. Use DynamoDB Accelerator (DAX) to provide low latency. Use Amazon Kinesis Data Streams to track changes.
    • C. Use DynamoDB global tables to distribute data across AWS Regions and to provide low latency. Use a separate DynamoDB table for each data type. Use Amazon DynamoDB Streams to track changes.
    • D. Create a single DynamoDB table to store all data types. Use provisioned capacity mode to provide low latency. Use composite sort keys for queries. Use Amazon Data Firehose to track changes.

    View question →

  69. Q69. Q969. A company collects 10 GB of telemetry data every day from multiple devices. The company stores the data in an Amazon S3 bucket that is in a source data account.The company has hired several consulting agencies to analyze the company's data. Each agency has a unique AWS account.Each agency requires read access to the company's data.The company needs a secure solution to share the data from the source data account to the consulting agenciesWhich solution will meet these requirements with the LEAST operational effort?

    • A. Set up an Amazon CloudFront distribution. Use the S3 bucket as the origin.
    • B. Make the S3 bucket public for a limited time. Inform only the agencies that the bucket is publicly accessible.
    • C. Configure cross-account access for the S3 bucket to the accounts that the agencies own.
    • D. Set up an IAM user for each agency in the source data account. Grant each agency IAM user access to the company's S3 bucket.

    View question →

  70. Q70. Q970. A company is deploying a new web application on AWS in a VPC. The application needs to have secure and controlled access to Amazon DynamoDB to store application data.The application runs on multiple Amazon EC2 instances that are in multiple Availability Zones in the VPC. The company wants to design a solution to allow the EC2 instances to securely access the DynamoDB tables without traversing the public internet.Which solution will meet these requirements with the LEAST overhead? (Select TWO.)

    • A. Create an IAM role that has permission to access the DynamoDB tables.Associate the role with the EC2 instances.
    • B. Store IAM user access keys in environment variables on the EC2 instances. Configure the application to use the access keys to access DynamoDB.
    • C. Enable encryption at rest for DynamoDB by using AWS Key Management Service (AWS KMS).Configure the EC2 instances to use AWS KMS encryption.
    • D. Configure the application on the EC2 instances to use the AWS Security Token Service (AWS STS) AssumeRole API to assume an IAM role that grants access to the DynamoDB tables.
    • E. Use VPC endpoints for DynamoDB to allow private network traffic between the EC2 instances and DynamoDB.

    View question →

  71. Q71. Q971. A company uses a Microsoft SQL Server database. The company's applications are connected to the database. The company wants to migrate to an Amazon Aurora PostgreSQL database with minimal changes to the application code.Which combination of steps will meet these requirements?(Select TWO.)

    • A. Use the AWS Schema Conversion Tool (AWS SCT) to rewrite the SQL queries in the applications
    • B. Enable Babelfish on Aurora PostgreSQL to run the SQL queries from the applications
    • C. Migrate the database schema and data by using the AWS Schema Conversion Tool (AWS SCT) and AWS Database Migration Service (AWS DMS)
    • D. Use Amazon RDS Proxy to connect the applications to Aurora PostgreSQL
    • E. Use AWS Database Migration Service (AWS DMS) to rewrite the SQL queries in the applications

    View question →

  72. Q72. Q972. A company hosts its order processing system on AWS. The architecture consists of a frontend and a backend.The frontend includes an Application Load Balancer (ALB) and Amazon EC2 instances in an Auto-Scaling group.The backend includes an EC2 instance and an Amazon RDS MySQL database.To prevent incomplete or lost orders,the company wants to ensure that order states are always preserved.The company wants to ensure that every order will eventually be processed,even after an outage or pause.Every order must be processed exactly once.Which solution will meet these requirements?

    • A. Create an Auto Scaling group and an ALB for the backend. Create a read replica for the RDS database in a second Availability Zone. Update the backend RDS endpoint.
    • B. Create an Auto Scaling group and an ALB for the backend. Create an Amazon RDS proxy in front of the RDS database. Update the backend EC2 instance to use the Amazon RDS proxy endpoint.
    • C. Create an Auto Scaling group for the backend. Configure the backend EC2 instances to consume messages from an Amazon Simple Queue Service(Amazon SQS) FlFO queue.Configure a dead-letter queue (DLQ) for the SQS queue.
    • D. Create an AWS Lambda function to replace the backend EC2 instance. Subscribe the function to an Amazon Simple Notification Service(Amazon SNS) topic. Configure the frontend to send orders to the SNS topic.

    View question →

  73. Q73. Q973. An ecommerce company hosts an API that handles sales requests.The company hosts the API frontend on Amazon EC2 instances that run behind an Application Load Balancer(ALB).The company hosts the API backend on EC2 instances that perform the transactions. The backend tiers are loosely coupled by an Amazon Simple Queue Service (Amazon SQS) queue.The company anticipates a significant increase in request volume during a new product launch event. The company wants to ensure that the API can handle increased loads successfullyWhich solution will meet these requirements?

    • A. Double the number of frontend and backend EC2 instances to handle the increased traffic during the product launch event. Create a dead-letter queue to retain unprocessed sales requests when the demand exceeds the system capacity.
    • B. Place the frontend EC2 instances into an Auto Scaling group.Create an Auto Scaling policy to launch new instances to handle the incoming network traffic.
    • C. Place the frontend EC2 instances into an Auto Scaling group. Add an Amazon ElastiCache cluster in front of the ALB to reduce the amount of traffic the API needs to handle
    • D. Place the frontend and backend EC2 instances into separate Auto Scaling groups.Create a policy for the frontend Auto Scaling group to launch instances based on incoming network traffic. Create a policy for the backend Auto Scaling group to launch instances based the SQS queue backlog.

    View question →

  74. Q74. Q974. A company wants to design a microservices architecture for an application. Each microservice must perform operations that can be completed within 30 seconds.The microservices need to expose RESTful APIs and must automatically scale in response to varying loads. The APIs must also provide client access control and rate limiting to maintain equitable usage and service availability.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Use Amazon Elastic Container Service (Amazon ECS) on Amazon EC2 to host each microservice. Use Amazon API Gateway to manage the RESTful API requests.
    • B. Deploy each microservice as a set of AWS Lambda functions. Use Amazon API Gateway to manage the RESTful API requests.
    • C. Host each microservice on Amazon EC2 instances in Auto Scaling groups behind an Elastic Load Balancing(ELB)load balancer. Use the ELB to manage the RESTful API requests.
    • D. Deploy each microservice on Amazon Elastic Beanstalk. Use Amazon CloudFront to manage the RESTful API requests

    View question →

  75. Q75. Q975. A company temporarily stages transactional datasets in an Amazon S3 bucket before the company moves the datasets to their final destinations. Some datasets include personally identifiable information (PII).The company must remove PII data during staging before the company moves the datasets to their destinations. A solutions architect needs to configure Amazon Macie to continuously monitor the datasets.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Create an AWS Lambda function to launch an Amazon Macie discovery job when a new dataset is stored in the target S3 bucket if a Macie discovery job is not already running. Create a second Lambda function to remove the PII data that the Macie discovery job finds.
    • B. Set up Amazon Macie automated sensitive data discovery.Create an AWS Lambda function to remove the PII data that Macie finds.Configure an Amazon EventBridge rule to invoke the Lambda function when Macie discovers PII data.
    • C. Schedule a daily Amazon Macie discovery job. Create an AWS Lambda function to run once every day to remove the PII data that the daily Macie job finds.
    • D. Create an AWS Lambda function that runs once each day to list all datasets that are saved to the S3 bucket every day. Call Amazon Macie on the list of datasets. Create a second Lambda function to remove the PII data that Macie finds. Configure an Amazon EventBridge rule to invoke the PII removal Lambda function every day.

    View question →

  76. Q76. Q976. A company has an application on AWS. The company hosts the backend database in an Amazon DynamoDB table. The company uses Amazon Elastic Container Service (Amazon ECS) containers to host the application.Read operations are primarily key-based lookups.The application is read-heavy and often encounters a DynamoDB throughput exceeded exception.A solutions architect needs to design a cost-effective solution that will resolve the DynamoDB throughput exceeded exceptions.Which solution will meet these requirements with the FEWEST changes to the current architecture?

    • A. Use Amazon ElastiCache for Memcached to create a cache. Point key-based read operations to the cache.
    • B. Increase the read capacity of the DynamoDB table manually every time there is a spike in read requests.
    • C. Create a DynamoDB Accelerator (DAX) cluster. Point key-based read operations to the DAX cluster.
    • D. Use Amazon RDS to create a copy of the DynamoDB table. Point read operations to the Amazon RDS instance.

    View question →

  77. Q77. Q977. A company recently migrated a monolithic application to microservices.The updated application uses an event-driven architecture.The company wants to follow the principle of least privilege to secure resources for the application.The company began to remove unnecessary permissions after the migration.After the company removed some permissions,the company noticed that an Amazon CloudWatch log group stopped receiving log messages for one of the company's AWS Lambda functions. After the permission changes, the Throttles metric for the function was 2,and the Invocations metric was 2.What is the likely reason that the CloudWatch log group stopped receiving log messages from the Lambda function?

    • A. The IAM role for the Lambda function does not have the correct policy to send log messages to the CloudWatch log group.
    • B. The resource-based policy for the Lambda function does not have the correct policy to send log messages to the CloudWatch log group.
    • C. The IAM role for the CloudWatch log group does not have the correct policy to receive log messages from the Lambda function.
    • D. The IAM role for the service that attempts to invoke the Lambda function does not have the correct policy to allow the service to invoke the Lambda function.

    View question →

  78. Q78. Q978. A disaster response team is using drones to collect images of recent storm damage. The response team's laptops lack the storage and compute capacity to transfer the images and process the data. While the team has Amazon EC2 instances for processing and Amazon S3 buckets for storage,network connectivity is intermittent and unreliable.The images need to be processed to evaluate the damage.What should a solutions architect recommend?

    • A. Use AWS Snowball Edge devices to process and store the images
    • B. Upload the images to Amazon Simple Queue Service (Amazon SQS) during intermittent connectivity to EC2 instances
    • C. Configure Amazon Data Firehose to create multiple delivery streams aimed separately at the S3 buckets for storage and the EC2 instances for processing the images.
    • D. Use AWS Storage Gateway pre-installed on a hardware appliance to cache the images locally for Amazon S3 to process the images when connectivity becomes available

    View question →

  79. Q79. Q979. A company stores a large volume of critical data in Amazon RDS for PostgreSQL tables. The company is developing several new features for an upcoming product launch. Some of the new features require many table alterations.The company needs a solution to test the altered tables for several days.After testing, the solution must make the new features available to customers in productionWhich solution will meet these requirements with the HIGHEST availability?

    • A. Create a new instance of the database in RDS for PostgreSQL to test the new features. When the testing is finished,take a backup of the test database, and restore the test database to the production database
    • B. Create new database tables in the production database to test the new features. When the testing is finished,copy the data from the older tables to the new tables. Delete the older tables,and rename the new tables accordingly.
    • C. Create an Amazon RDS read replica to deploy a new instance of the database.Make updates to the database tables in the replica instance. When the testing is finished, promote the replica instance to become the new production instance
    • D. Use an Amazon RDS blue/green deployment to deploy e new test instance of the database. Make database table updates in the test instance. When the testing is finished, promote the test instance to become the new production instance.

    View question →

  80. Q80. Q980. A company wants to migrate several legacy .NET applications from an on-premises data center to AWS. The company converted the code base for the applications to use a newer version of .NET.The company needs a scalable, high-performance solution to host the updated .NET applications on AWS Which solution will meet these requirements with the LEAST ongoing administrative overhead?

    • A. Containerize the .NET applications. Create a task definition in Amazon Elastic Container Service (Amazon ECS) with AWS Fargate as the launch type. Configure auto scaling based on the amount of CPU and memory required.
    • B. Store the static content of the applications in an Amazon S3 bucket. Convert the.NET applications to AWS Lambda functions. Use Amazon API Gateway to route requests to the Lambda functions.
    • C. Deploy the.NET applications on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. Use path-based routing to route traffic to the applications
    • D. Package the applications into deployable archives. Create a new application on AWS Elastic Beanstalk.Upload the deployment archives to Elastic Beanstalk.

    View question →

  81. Q81. Q981. A company hosts an application on AWS that gives users the ability to download photos. The company stores all photos in an Amazon S3 bucket that is located in the us-east-1 Region.The company wants to provide the photo download application to global customers with low latency Which solution will meet these requirements?

    • A. Find the public IP addresses that Amazon S3 uses in us-east-1. Configure an Amazon Route 53 latency-based routing policy that routes to all the public IP addresses
    • B. Configure an Amazon CloudFront distribution in front of the S3 bucket. Use the distribution endpoint to access the photos that are in the S3 bucket.
    • C. Configure an Amazon Route 53 geoproximity routing policy to route the traffic to the S3 bucket that is closest to each customer's location.
    • D. Create a new S3 bucket in the us-west-1 Region. Configure an S3 Cross-Region Replication rule to copy the photos to the new S3 bucket.

    View question →

  82. Q82. Q982. A company uses an Amazon Aurora PostgreSQL provisioned cluster with its application. The application's peak traffic occurs several times a day for periods of 30 minutes to several hours.The database capacity is provisioned to handle peak traffic from the application,but the database has wasted capacity during hon-peak hours. The company wants to reduce the database costs.Which solution will meet these requirements with the LEAST operational effort?

    • A. Set up an Amazon CloudWatch alarm to monitor database utilization. Scale up or scale down the database capacity based on the amount of traffic.
    • B. Migrate the database to Amazon EC2 instances in an Auto Scaling group. Increase or decrease the number of instances based on the amount of traffic.
    • C. Migrate the database to an Amazon Aurora Serverless DB cluster to scale up or scale down the capacity based on the amount of traffic.
    • D. Schedule an AWS Lambda function to provision the required database capacity at the start of each day.Schedule another Lambda function to reduce the capacity at the end of each day.

    View question →

  83. Q83. Q983. A company is rebuilding its storage infrastructure to accommodate a growing volume of structured data, such as customer records,and unstructured data, such as medical images and diagnostic reports.The storage solution must provide data integrity,high availability,and instant data retrieval.Which solution will meet these requirements MOST cost-effectively?

    • A. Use Amazon RDS for MySQL to store structured data. Use Amazon FSx for Lustre to store the unstructured data.
    • B. Use Amazon S3 Standard to store both structured data and unstructured data.
    • C. Create Amazon Elastic Block Store (Amazon EBS) volumes to store both structured data and unstructured data
    • D. Use Amazon RDS for MySQL to store structured data. Use Amazon S3 Glacier to store the unstructured data.

    View question →

  84. Q84. Q984. A company is planning to use an Amazon CloudFront distribution to deploy an application. The CloudFront distribution uses an Amazon S3 bucket as the origin. Only authorized users should be able to access the application.Files that the company caches at edge locations must be accessible only after a user is authenticated.A solutions architect needs to design a secure and low-latency solution to meet these requirements.Which solution will meet these requirements?

    • A. Create an Application Load Balancer (ALB) as a second origin in CloudFront. Direct users to authenticate at the ALB first.
    • B. Use the origin response Lambda@Edge function in CloudFront to handle authentication and authorization
    • C. Create a Network Load Balancer (NLB) as a second origin in CloudFront. Direct users to authenticate at the NLB first.
    • D. Use the viewer request Lambda@Edge function in CloudFront to handle authentication and authorization.

    View question →

  85. Q85. Q985. A company is creating an application. The company stores data from tests of the application in multiple on- premises locations.The company needs to connect the on-premises locations to VPCs in an AWS Region in the AWS Cloud.The number of accounts and VPCs willincrease during the next year. The network architecture must simplify the administration of new connections and must provide the ability to scaleWhich solution will meet these requirements with the LEAST administrative overhead?

    • A. Create a peering connection between the VPCs. Create a VPN connection between the VPCs and the on-premises locations
    • B. Launch an Amazon EC2 instance. On the instance,include VPN software that uses a VPN connection to connect all VPCs and on-premises locations.
    • C. Create a transit gateway. Create VPC attachments for the VPC connections. Create VPN attachments for the on-premises connections.
    • D. Create an AWS Direct Connect connection between the on-premises locations and a central VPC.Connect the central VPC to other VPCs by using peering connections.

    View question →

  86. Q86. Q986. A company wants to improve the availability and performance of its hybrid application. The application consists of a stateful TCP-based workload hosted on Amazon EC2 instances in different AWS Regions and a stateless UDP-based workload hosted on premises.Which combination of actions should a solutions architect take to improve availability and performance? (Choose two.)

    • A. Create an accelerator using AWS Global Accelerator. Add the load balancers as endpoints.
    • B. Create an Amazon CloudFront distribution with an origin that uses Amazon Route 53 latency-based routing to route requests to the load balancers.
    • C. Configure two Application Load Balancers in each Region. The first will route to the EC2 endpoints, and the second will route to the on-premises endpoints.
    • D. Configure a Network Load Balancer in each Region to address the EC2 endpoints. Configure a Network Load Balancer in each Region that routes to the on-premises endpoints.
    • E. Configure a Network Load Balancer in each Region to address the EC2 endpoints. Configure an Application Load Balancer in each Region that routes to the on-premises endpoints.

    View question →

  87. Q87. Q987. A company runs a self-managed Microsoft SQL Server on Amazon EC2 instances and Amazon Elastic Block Store (Amazon EBS). Daily snapshots are taken of the EBS volumes.Recently, all the company EBS snapshots were accidentally deleted while running a snapshot cleaning script that deletes all expired EBS snapshots. A solutions architect needs to update the architecture to prevent data loss without retaining EBS snapshots indefinitely.Which solution will meet these requirements with the LEAST development effort?

    • A. Change the IAM policy of the user to deny EBS snapshot deletion.
    • B. Copy the EBS snapshots to another AWS Region after completing the snapshots daily.
    • C. Create a 7-day EBS snapshot retention rule in Recycle Bin and apply the rule for all snapshots.
    • D. Copy EBS snapshots to Amazon S3 Standard-Infrequent Access (S3 Standard-IA).

    View question →

  88. Q88. Q988. A company wants to use an AWS CloudFormation stack for its application in a test environment. The company stores the CloudFormation template in an Amazon S3 bucket that blocks public access. The company wants to grant CloudFormation access to the template in the S3 bucket based on specific user requests to create the test environment. The solution must follow security best practices.Which solution will meet these requirements?

    • A. Create a gateway VPC endpoint for Amazon S3. Configure the CloudFormation stack to use the S3 object URL.
    • B. Create an Amazon API Gateway REST API that has the S3 bucket as the target. Configure the CloudFormation stack to use the API Gateway URL.
    • C. Create a presigned URL for the template object. Configure the CloudFormation stack to use the presigned URL.
    • D. Allow public access to the template object in the S3 bucket. Block the public access after the test environment is created.

    View question →

  89. Q89. Q989. A company hosts its multi-tier, public web application in the AWS Cloud. The web application runs on Amazon EC2 instances, and its database runs on Amazon RDS. The company is anticipating a large increase in sales during an upcoming holiday weekend. A solutions architect needs to build a solution to analyze the performance of the web application with a granularity of no more than 2 minutes.What should the solutions architect do to meet this requirement?

    • A. Send Amazon CloudWatch logs to Amazon Redshift. Use Amazon QuickS ght to perform further analysis.
    • B. Enable detailed monitoring on all EC2 instances. Use Amazon CloudWatch metrics to perform further analysis.
    • C. Create an AWS Lambda function to fetch EC2 logs from Amazon CloudWatch Logs. Use Amazon CloudWatch metrics to perform further analysis.
    • D. Send EC2 logs to Amazon S3. Use Amazon Redshift to fetch logs from the S3 bucket to process raw data for further analysis with Amazon QuickSight.

    View question →

  90. Q90. Q990. A company has stored millions of objects across multiple prefixes in an Amazon S3 bucket by using the Amazon S3 Glacier Deep Archive storage class. The company needs to delete all data older than 3 years except for a subset of data that must be retained. The company has identified the data that must be retained and wants to implement a serverless solution.Which solution will meet these requirements?

    • A. Use S3 Inventory to list all objects. Use the AWS CLI to create a script that runs on an Amazon EC2 instance that deletes objects from the inventory list.
    • B. Use AWS Batch to delete objects older than 3 years except for the data that must be retained.
    • C. Provision an AWS Glue crawler to query objects older than 3 years. Save the manifest file of old objects. Create a script to delete objects in the manifest.
    • D. Enable S3 Inventory. Create an AWS Lambda function to filter and delete objects. Invoke the Lambda function with S3 Batch Operations to delete objects by using the inventory reports.

    View question →

  91. Q91. Q991. A company is building an application on AWS. The application uses multiple AWS Lambda functions to retrieve sensitive data from a single Amazon S3 bucket for processing. The company must ensure that only authorized Lambda functions can access the data. The solution must comply with the principle of least privilege.Which solution will meet these requirements?

    • A. Grant full S3 bucket access to all Lambda functions through a shared IAM role.
    • B. Configure the Lambda functions to run within a VPC. Configure a bucket policy to grant access based on the Lambda functions' VPC endpoint IP addresses.
    • C. Create individual IAM roles for each Lambda function. Grant the IAM roles access to the S3 bucket.Assign each IAM role as the Lambda execution role for its corresponding Lambda function.
    • D. Configure a bucket policy granting access to the Lambda functions based on their function ARNs.

    View question →

  92. Q92. Q992. A company has developed a non-production application that is composed of multiple microservices for each of the company's business units. A single development team maintains all the microservices. The current architecture uses a static web frontend and a Java-based backend that contains the application logic. The architecture also uses a MySQL database that the company hosts on an Amazon EC2 instance.The company needs to ensure that the application is secure and available globally.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Use Amazon CloudFront and AWS Amplify to host the static web frontend. Refactor the microservices to use AWS Lambda functions that the microservices access by using Amazon API Gateway. Migrate the MySQL database to an Amazon EC2 Reserved Instance.
    • B. Use Amazon CloudFront and Amazon S3 to host the static web frontend. Refactor the microservices to use AWS Lambda functions that the microservices access by using Amazon API Gateway. Migrate the MySQL database to Amazon RDS for MySQL.
    • C. Use Amazon CloudFront and Amazon S3 to host the static web frontend. Refactor the microservices to use AWS Lambda functions that are in a target group behind a Network Load Balancer. Migrate the MySQL database to Amazon RDS for MySQL.
    • D. Use Amazon S3 to host the static web frontend. Refactor the microservices to use AWS Lambda functions that are in a target group behind an Application Load Balancer. Migrate the MySQL database to an Amazon EC2 Reserved Instance.

    View question →

  93. Q93. Q993. A video game company is deploying a new gaming application to its global users. The company requires a solution that will provide near real-time reviews and rankings of the players.A solutions architect must design a solution to provide fast access to the data. The solution must also ensure the data persists on disks in the event that the company restarts the application.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Configure an Amazon CloudFront distribution with an Amazon S3 bucket as the origin. Store the player data in the S3 bucket.
    • B. Create Amazon EC2 instances in multiple AWS Regions. Store the player data on the EC2 instances.Configure Amazon Route 53 with geolocation records to direct users to the closest EC2 instance.
    • C. Deploy an Amazon ElastiCache for Redis duster. Store the player data in the ElastiCache cluster.
    • D. Deploy an Amazon ElastiCache for Memcached duster. Store the player data in the ElastiCache cluster.

    View question →

  94. Q94. Q994. A company is designing an application on AWS that processes sensitive data. The application stores and processes financial data for multiple customers.To meet compliance requirements, the data for each customer must be encrypted separately at rest by using a secure, centralized key management solution. The company wants to use AWS Key Management Service (AWS KMS) to implement encryption.Which solution will meet these requirements with the LEAST operational overhead?

    • A. Generate a unique encryption key for each customer. Store the keys in an Amazon S3 bucket. Enable server-side encryption.
    • B. Deploy a hardware security appliance in the AWS environment that securely stores customer-provided encryption keys. Integrate the security appliance with AWS KMS to encrypt the sensitive data in the application.
    • C. Create a single AWS KMS key to encrypt all sensitive data across the application.
    • D. Create separate AWS KMS keys for each customer's data that have granular access control and logging enabled.

    View question →

  95. Q95. Q995. A company needs to design a resilient web application to process customer orders. The web application must automatically handle increases in web traffic and application usage without affecting the customer experience or losing customer orders.Which solution will meet these requirements?

    • A. Use a NAT gateway to manage web traffic. Use Amazon EC2 Auto Scaling groups to receive, process, and store processed customer orders. Use an AWS Lambda function to capture and store unprocessed orders.
    • B. Use a Network Load Balancer (NLB) to manage web traffic. Use an Application Load Balancer to receive customer orders from the NLUse Amazon Redshift with a Multi-AZ deployment to store unprocessed and processed customer orders.
    • C. Use a Gateway Load Balancer (GWLB) to manage web traffic. Use Amazon Elastic Container Service (Amazon ECS) to receive and process customer orders. Use the GWLB to capture and store unprocessed orders. Use Amazon DynamoDB to store processed customer orders.
    • D. Use an Application Load Balancer to manage web traffic. Use Amazon EC2 Auto Scaling groups to receive and process customer orders. Use Amazon Simple Queue Service (Amazon SQS) to store unprocessed orders. Use Amazon RDS with a Multi-AZ deployment to store processed customer orders.

    View question →

  96. Q96. Q996. A company recently migrated a monolithic application to an Amazon EC2 instance and Amazon RDS. The application has tightly coupled modules. The existing design of the application gives the application the ability to run on only a single EC2 instance.The company has noticed high CPU utilization on the EC2 instance during peak usage times. The high CPU utilization corresponds to degraded performance on Amazon RDS for read requests. The company wants to reduce the high CPU utilization and improve read request performance.Which solution will meet these requirements?

    • A. Resize the EC2 instance to an EC2 instance type that has more CPU capacity. Configure an Auto Scaling group with a minimum and maximum size of 1. Configure an RDS read replica for read requests.
    • B. Resize the EC2 instance to an EC2 instance type that has more CPU capacity. Configure an Auto Scaling group with a minimum and maximum size of 1. Add an RDS read replica and redirect all read/ write traffic to the replica.
    • C. Configure an Auto Scaling group with a minimum size of 1 and maximum size of 2. Resize the RDS DB instance to an instance type that has more CPU capacity.
    • D. Resize the EC2 instance to an EC2 instance type that has more CPU capacity. Configure an Auto Scaling group with a minimum and maximum size of 1. Resize the RDS DB instance to an instance type that has more CPU capacity.

    View question →

  97. Q97. Q997. A company needs to grant a team of developers access to the company's AWS resources. The company must maintain a high level of security for the resources.The company requires an access control solution that will prevent unauthorized access to the sensitive data.Which solution will meet these requirements?

    • A. Share the IAM user credentials for each development team member with the rest of the team to simplify access management and to streamline development workflows.
    • B. Define IAM roles that have fine-grained permissions based on the principle of least privilege. Assign an IAM role to each developer.
    • C. Create IAM access keys to grant programmatic access to AWS resources. Allow only developers to interact with AWS resources through API calls by using the access keys.
    • D. Create an AWS Cognito user pool. Grant developers access to AWS resources by using the user pool.

    View question →

  98. Q98. Q998. A company hosts a monolithic web application on an Amazon EC2 instance. Application users have recently reported poor performance at specific times. Analysis of Amazon CloudWatch metrics shows that CPU utilization is 100% during the periods of poor performance.The company wants to resolve this performance issue and improve application availability.Which combination of steps will meet these requirements MOST cost-effectively? (Choose two.)

    • A. Use AWS Compute Optimizer to obtain a recommendation for an instance type to scale vertically.
    • B. Create an Amazon Machine Image (AMI) from the web server. Reference the AMI in a new launch template.
    • C. Create an Auto Scaling group and an Application Load Balancer to scale vertically.
    • D. Use AWS Compute Optimizer to obtain a recommendation for an instance type to scale horizontally.
    • E. Create an Auto Scaling group and an Application Load Balancer to scale horizontally.

    View question →

  99. Q99. Q999. A company runs all its business applications in the AWS Cloud. The company uses AWS Organizations to manage multiple AWS accounts.A solutions architect needs to review all permissions that are granted to IAM users to determine which IAM users have more permissions than required.Which solution will meet these requirements with the LEAST administrative overhead?

    • A. Use Network Access Analyzer to review all access permissions in the company's AWS accounts.
    • B. Create an AWS CloudWatch alarm that activates when an IAM user creates or modifies resources in an AWS account.
    • C. Use AWS Identity and Access Management (IAM) Access Analyzer to review all the company resources and accounts.
    • D. Use Amazon Inspector to find vulnerabilities in existing IAM policies.

    View question →

  100. Q100. Q1000. A company needs to implement a new data retention policy for regulatory compliance. As part of this policy, sensitive documents that are stored in an Amazon S3 bucket must be protected from deletion or modification for a fixed period of time.Which solution will meet these requirements?

    • A. Activate S3 Object Lock on the required objects and enable governance mode.
    • B. Activate S3 Object Lock on the required objects and enable compliance mode.
    • C. Enable versioning on the S3 bucket. Set a lifecycle policy to delete the objects after a specified period.
    • D. Configure an S3 Lifecycle policy to transition objects to S3 Glacier Flexible Retrieval for the retention duration.

    View question →