SAP-C02.pdf
Q: 1
A company uses a software package for surveys. During surveys, data is uploaded from a field
operator's device to an Amazon S3 bucket. A custom application that runs on several Amazon EC2
instances polls the S3 bucket for new dat
a. When new data is available, the software processes the data.
The data uploads are infrequent. The processing software can take up to 25 minutes to analyze each
data upload. The company wants to optimize the application workflow to process the S3 data.
Which solution will meet these requirements with the LEAST operational overhead?
Options
Q: 2
A company is running applications on AWS in a multi-account environment. The company's sales
team and marketing team use separate AWS accounts in AWS Organizations.
The sales team stores petabytes of data in an Amazon S3 bucket. The marketing team uses Amazon
QuickSight for data visualizations. The marketing team needs access to data that the sates team
stores in the S3 bucket. The company has encrypted the S3 bucket with an AWS Key Management
Service (AWS KMS) key. The marketing team has already created the IAM service role for QuickSight
to provide QuickSight access in the marketing AWS account. The company needs a solution that will
provide secure access to the data in the S3 bucket across AWS accounts.
Which solution will meet these requirements with the LEAST operational overhead?
Options
Q: 3
A company has 10 accounts that are part of an organization in AWS Organizations AWS Config is
configured in each account All accounts belong to either the Prod OU or the NonProd OU
The company has set up an Amazon EventBridge rule in each AWS account to notify an Amazon
Simple Notification Service (Amazon SNS) topic when an Amazon EC2 security group inbound rule is
created with 0.0.0.0/0 as the source The company's security team is subscribed to the SNS topic
For all accounts in the NonProd OU the security team needs to remove the ability to create a security
group inbound rule that includes 0.0.0.0/0 as the source
Which solution will meet this requirement with the LEAST operational overhead?
Options
Q: 4
A company with several AWS accounts is using AWS Organizations and service control policies (SCPs). An Administrator created the following SCP and has attached it to an organizational unit (OU) that contains AWS account 1111-1111-1111:

Developers working in account 1111-1111-1111 complain that they cannot create Amazon S3 buckets. How should the Administrator address this problem?
Options
Q: 5
A company recently acquired several other companies. Each company has a separate AWS account
with a different billing and reporting method. The acquiring company has consolidated all the
accounts into one organization in AWS Organizations. However, the acquiring company has found it
difficult to generate a cost report that contains meaningful groups for all the teams.
The acquiring company’s finance team needs a solution to report on costs for all the companies
through a self-managed application.
Which solution will meet these requirements?
Options
Q: 6
A company built an application based on AWS Lambda deployed in an AWS CloudFormation stack.
The last production release of the web application introduced an issue that resulted in an outage
lasting several minutes. A solutions architect must adjust the deployment process to support a
canary release.
Which solution will meet these requirements?
Options
Q: 7
A company recently deployed an application on AWS. The application uses Amazon DynamoDB.The
company measured the application load and configured the RCUs and WCUs on the DynamoDB table
to match the expected peak load. The peak load occurs once a week for a 4-hour period and is
double the average load. The application load is close to the average load tor the rest of the week.
The access pattern includes many more writes to the table than reads of the table.
A solutions architect needs to implement a solution to minimize the cost of the table.
Which solution will meet these requirements?
Options
Q: 8
A company has an organization in AWS Organizations. The company is using AWS Control Tower to
deploy a landing zone for the organization. The company wants to implement governance and policy
enforcement. The company must implement a policy that will detect Amazon RDS DB instances that
are not encrypted at rest in the company’s production OU.
Which solution will meet this requirement?
Options
Q: 9
A company is running a critical stateful web application on two Linux Amazon EC2 instances behind
an Application Load Balancer (ALB) with an Amazon RDS for MySQL database The company hosts the
DNS records for the application in Amazon Route 53 A solutions architect must recommend a
solution to improve the resiliency of the application
The solution must meet the following objectives:
• Application tier RPO of 2 minutes. RTO of 30 minutes
• Database tier RPO of 5 minutes RTO of 30 minutes
The company does not want to make significant changes to the existing application architecture The
company must ensure optimal latency after a failover
Which solution will meet these requirements?
Options
Q: 10
A company is running an application in the AWS Cloud. The application consists of microservices that
run on a fleet of Amazon EC2 instances in multiple Availability Zones behind an Application Load
Balancer. The company recently added a new REST API that was implemented in Amazon API
Gateway. Some of the older microservices that run on EC2 instances need to call this new API.
The company does not want the API to be accessible from the public internet and does not want
proprietary data to traverse the public internet
What should a solutions architect do to meet these requirements?
Options
Q: 11
A startup company hosts a fleet of Amazon EC2 instances in private subnets using the latest Amazon
Linux 2 AMI. The company's engineers rely heavily on SSH access to the instances for
troubleshooting.
The company's existing architecture includes the following:
• A VPC with private and public subnets, and a NAT gateway
• Site-to-Site VPN for connectivity with the on-premises environment
• EC2 security groups with direct SSH access from the on-premises environment
The company needs to increase security controls around SSH access and provide auditing of
commands executed by the engineers.
Which strategy should a solutions architect use?
Options
Q: 12
A company needs to audit the security posture of a newly acquired AWS account. The company’s
data security team requires a notification only when an Amazon S3 bucket becomes publicly
exposed. The company has already established an Amazon Simple Notification Service (Amazon SNS)
topic that has the data security team's email address subscribed.
Which solution will meet these requirements?
Options
Q: 13
A company recently completed the migration from an on-premises data center to the AWS Cloud by
using a replatforming strategy. One of the migrated servers is running a legacy Simple Mail Transfer
Protocol (SMTP) service that a critical application relies upon. The application sends outbound email
messages to the company’s customers. The legacy SMTP server does not support TLS encryption and
uses TCP port 25. The application can use SMTP only.
The company decides to use Amazon Simple Email Service (Amazon SES) and to decommission the
legacy SMTP server. The company has created and validated the SES domain. The company has lifted
the SES limits.
What should the company do to modify the application to send email messages from Amazon SES?
Options
Q: 14
A company has a multi-tier web application that runs on a fleet of Amazon EC2 instances behind an
Application Load Balancer (ALB). The instances are in an Auto Scaling group. The ALB and the Auto
Scaling group are replicated in a backup AWS Region. The minimum value and the maximum value
for the Auto Scaling group are set to zero. An Amazon RDS Multi-AZ DB instance stores the
application’s dat
a. The DB instance has a read replica in the backup Region. The application presents an endpoint to
end users by using an Amazon Route 53 record.
The company needs to reduce its RTO to less than 15 minutes by giving the application the ability to
automatically fail over to the backup Region. The company does not have a large enough budget for
an active-active strategy.
What should a solutions architect recommend to meet these requirements?
Options
Q: 15
A company that has multiple AWS accounts is using AWS Organizations. The company’s AWS
accounts host VPCs, Amazon EC2 instances, and containers.
The company’s compliance team has deployed a security tool in each VPC where the company has
deployments. The security tools run on EC2 instances and send information to the AWS account that
is dedicated for the compliance team. The company has tagged all the compliance-related resources
with a key of “costCenter” and a value or “compliance”.
The company wants to identify the cost of the security tools that are running on the EC2 instances so
that the company can charge the compliance team’s AWS account. The cost calculation must be as
accurate as possible.
What should a solutions architect do to meet these requirements?
Options
Q: 16
A company has developed a hybrid solution between its data center and AWS. The company uses
Amazon VPC and Amazon EC2 instances that send application togs to Amazon CloudWatch. The EC2
instances read data from multiple relational databases that are hosted on premises.
The company wants to monitor which EC2 instances are connected to the databases in near-real
time. The company already has a monitoring solution that uses Splunk on premises. A solutions
architect needs to determine how to send networking traffic to Splunk.
How should the solutions architect meet these requirements?
Options
Q: 17
A solutions architect is designing the data storage and retrieval architecture for a new application
that a company will be launching soon. The application is designed to ingest millions of small records
per minute from devices all around the world. Each record is less than 4 KB in size and needs to be
stored in a durable location where it can be retrieved with low latency. The data is ephemeral and
the company is required to store the data for 120 days only, after which the data can be deleted.
The solutions architect calculates that, during the course of a year, the storage requirements would
be about 10-15 TB.
Which storage strategy is the MOST cost-effective and meets the design requirements?
Options
Q: 18
An environmental company is deploying sensors in major cities throughout a country to measure air
quality The sensors connect to AWS loT Core to ingest timesheets data readings. The company stores
the data in Amazon DynamoDB
For business continuity the company must have the ability to ingest and store data in two AWS
Regions
Which solution will meet these requirements?
Options
Q: 19
A company is building a serverless application that runs on an AWS Lambda function that is attached
to a VPC. The company needs to integrate the application with a new service from an external
provider. The external provider supports only requests that come from public IPv4 addresses that are
in an allow list.
The company must provide a single public IP address to the external provider before the application
can start using the new service.
Which solution will give the application the ability to access the new service?
Options
Q: 20
A company manages hundreds of AWS accounts centrally in an organization in AWS Organizations.
The company recently started to allow product teams to create and manage their own S3 access
points in their accounts. The S3 access points can be accessed only within VPCs not on the internet.
What is the MOST operationally efficient way to enforce this requirement?
Options
Q: 21
A company has a serverless application comprised of Amazon CloudFront, Amazon API Gateway, and
AWS Lambda functions. The current deployment process of the application code is to create a new
version number of the Lambda function and run an AWS CLI script to update. If the new function
version has errors, another CLI script reverts by deploying the previous working version of the
function. The company would like to decrease the time to deploy new versions of the application
logic provided by the Lambda functions, and also reduce the time to detect and revert when errors
are identified.
How can this be accomplished?
Options
Q: 22
A company is developing a new service that will be accessed using TCP on a static port A solutions
architect must ensure that the service is highly available, has redundancy across Availability Zones,
and is accessible using the DNS name myservice.com, which is publicly accessible The service must
use fixed address assignments so other companies can add the addresses to their allow lists.
Assuming that resources are deployed in multiple Availability Zones in a single Region, which
solution will meet these requirements?
Options
Q: 23
A solutions architect has developed a web application that uses an Amazon API Gateway Regional
endpoint and an AWS Lambda function. The consumers of the web application are all close to the
AWS Region where the application will be deployed. The Lambda function only queries an Amazon
Aurora MySQL database. The solutions architect has configured the database to have three read
replicas.
During testing, the application does not meet performance requirements. Under high load, the
application opens a large number of database connections. The solutions architect must improve the
application's performance.
Which actions should the solutions architect take to meet these requirements? (Choose two.)
Options
Q: 24
A company needs to create and manage multiple AWS accounts for a number of departments from a
central location. The security team requires read-only access to all accounts from its own AWS
account. The company is using AWS Organizations and created an account for the security team.
How should a solutions architect meet these requirements?
Options
Q: 25
A company wants to migrate an application to Amazon EC2 from VMware Infrastructure that runs in
an on-premises data center. A solutions architect must preserve the software and configuration
settings during the migration.
What should the solutions architect do to meet these requirements?
Options
Q: 26
A company is using AWS Organizations to manage multiple AWS accounts. For security purposes, the
company requires the creation of an Amazon Simple Notification Service (Amazon SNS) topic that
enables integration with a third-party alerting system in all the Organizations member accounts.
A solutions architect used an AWS CloudFormation template to create the SNS topic and stack sets to
automate the deployment of Cloud Formation stacks. Trustedaccess has been enabled in
Organizations.
What should the solutions architect do to deploy the CloudFormation StackSets in all AWS accounts?
Options
Q: 27
A solutions architect must create a business case for migration of a company's on-premises data
center to the AWS Cloud. The solutions architect will use a configuration management database
(CMDB) export of all the company's servers to create the case.
Which solution will meet these requirements MOST cost-effectively?
Options
Q: 28
A company's interactive web application uses an Amazon CloudFront distribution to serve images
from an Amazon S3 bucket. Occasionally, third-party tools ingest corrupted images into the S3
bucket. This image corruption causes a poor user experience in the application later. The company
has successfully implemented and tested Python logic to detect corrupt images.
A solutions architect must recommend a solution to integrate the detection logic with minimal
latency between the ingestion and serving.
Which solution will meet these requirements?
Options
Q: 29
A company hosts a VPN in an on-premises data center. Employees currently connect to the VPN to
access files in their Windows home directories. Recently, there has been a large growth in the
number of employees who work remotely. As a result, bandwidth usage for connections into the
data center has begun to reach 100% during business hours.
The company must design a solution on AWS that will support the growth of the company's remote
workforce, reduce the bandwidth usage for connections into the data center, and reduce operational
overhead.
Which combination of steps will meet these requirements with the LEAST operational overhead?
(Select TWO.)
Options
Q: 30
A company’s solutions architect is evaluating an AWS workload that was deployed several years ago.
The application tier is stateless and runs on a single large Amazon EC2 instance that was launched
from an AMI. The application stores data in a MySOL database that runs on a single EC2 instance.
The CPU utilization on the application server EC2 instance often reaches 100% and causes the
application to stop responding. The company manually installs patches on the instances. Patching has
caused
downtime in the past. The company needs to make the application highly available.
Which solution will meet these requirements with the LEAST development time?
Options
Q: 31
A company use an organization in AWS Organizations to manage multiple AWS accounts. The
company hosts some applications in a VPC in the company's snared services account. The company
has attached a transit gateway to the VPC in the Shared services account.
The company is developing a new capability and has created a development environment that
requires access to the applications that are in the snared services account. The company intends to
delete and recreate resources frequently in the development account. The company also wants to
give a development team the ability to recreate the team's connection to the shared services
account as required.
Which solution will meet these requirements?
Options
Q: 32
A solutions architect has implemented a SAML 2 0 federated identity solution with their company's
on-premises identity provider (IdP) to authenticate users' access to the AWS environment. When the
solutions architect tests authentication through the federated identity web portal, access to the AWS
environment is granted However when test users attempt to authenticate through the federated
identity web portal, they are not able to access the AWS environment
Which items should the solutions architect check to ensure identity federation isproperly configured?
(Select THREE)
Options
Q: 33
A team of data scientists is using Amazon SageMaker instances and SageMaker APIs to train machine
learning (ML) models. The SageMaker instances are deployed in a
VPC that does not have access to or from the internet. Datasets for ML model training are stored in
an Amazon S3 bucket. Interface VPC endpoints provide access to Amazon S3 and the SageMaker
APIs.
Occasionally, the data scientists require access to the Python Package Index (PyPl) repository to
update Python packages that they use as part of their workflow. A solutions architect must provide
access to the PyPI repository while ensuring that the SageMaker instances remain isolated from the
internet.
Which solution will meet these requirements?
Options
Q: 34
A company is planning a one-time migration of an on-premises MySQL database to Amazon Aurora
MySQL in the us-east-1 Region. The company's current internet connection has limited bandwidth.
The on-premises MySQL database is 60 TB in size The company estimates that it will take a month to
transfer the data to AWS over the current internet connection.
The company needs a migration solution that will migrate the database more quickly
Which solution will migrate the database in the LEAST amount of time?
Options
Q: 35
A solutions architect works for a government agency that has strict disaster recovery requirements.
All Amazon Elastic Block Store (Amazon EBS) snapshots are required to be saved in at least two
additional AWS Regions. The agency also is required to maintain the lowest possible operational
overhead.
Which solution meets these requirements?
Options
Question 1 of 35