Amazon Certification Exam Answers
Verified answers and clear explanations for every Amazon certification exam. Browse by exam below, or practice the full set on ExamRoll.io.
Amazon ad server advanced ENG version All exam questions
- Aja wants to generate a report that includes last month’s media cost for her company's video campaigns.Which cost models should she look at in order to gain insight into this information?(Select all that apply)
- An account that has access to multiple linked accounts to it is called:
- An Italian events management company would like to run a campaign to target members who previously purchased tickets for past events. Which target audience would be best set up in SAS?
- An Italian events management company would like to run a campaign to target members who previously purchased tickets for past events.Which target audience would be best setup in A AS?
- Carla wants to a set a custom date range to serve versions while running her promotion.Which DCO rotation type will help her achieve this?
- DCO versions are used to:
- Diane works for a travel agency and wants to show different ads to users based on the destination page they’ve previously visited on her website.There are three offers-NewYork,Paris,andBerlin.What Activity Type can she use to achieve this?
- Each ad built as dynamic within SAS has one version automatically created by default. You can create and edit multiple other versions to fit your needs.
- How does attribution work when there is a Global-Local Advertiser structure?
- How many Account Extensions are allowed per account?
- How many attribution conversion models can be set upper advertiser?
- If using media targeting with DCO campaign,which of the following scenarios best describes the setup where a single creative version is applied to a single targeted placement audience?
- In a conversation about creative campaigns,Juri was recommended by a coworker to useD CO.Using a DCO can help with her campaign strategy by:
- James is a Native Account holder and his team has just expanded to Mexico, United Kingdom,andGermany.In order to gain insights from all 3 locales,what account setup and permission access steps should James take next?
- Jan ie wants to run an RDF report that displays data about conversion activities and events in the path to conversion.Which feed type should they activate to achieve this?
- Jean wants to update the trans coded assets,due to an update in the trans coding profile.To complete this for a placement ad that is already attached,heshould:
- Jill wishes to extract search engine reporting data(primarily for media cost information).What Direct Integration scans he use to do this?
- Juan has a video asset that he is ready to run with a Master Ad.He attaches the ad to its respective placement and gets a sign that"Video Auto Trans coding"has begun.Which of the following statements best describes the automatic process that is currently taking place?
- Ken wants to generate conversion reports that use different attribution models than the Primary model on the advertiser level.What nextstep can he take to achieve this?
- Mek a creates the following URL Variable to gain insight into revenue stats for recent concert sales on her company'swebsite (Concert Tickets.com/Purchase Amount_confirmation).What type of A AS variable is she utilizing in this case?
- Meka creates the following URL Variable to gain insight into revenue stats for recent concert sales on her company's website (ConcertTickets.com/PurchaseAmount_confirmation). What type of SAS variable is she utilizing in this case?
- Mina is customizing a global account and realizes a global conversion activity is inplace.This means the attribution is:
- Place the following steps in the correct order to create a Search Direct Integration:
- Place the steps to checking A AS re marketing cookies in chronological order:
- Sarah would like to enable a custom parameter to be sent to SAS for every impression event. The information received is available in cookie-level insights and RDF reports. Which setting would she use to accomplish this?
- SAS Search Integrations occur on the advertiser level.
- Setting up a DCO campaign differs greatly from launching a regular campaign in terms of SAS workflow.
- The default option for Tracking Search Campaigns is:
- What are the prerequisites to be able to create Global Conversion Activity?
- What is the first step in planning a DCO campaign?
- When customizing Tag manager,the mapping report contains the following sheets(select all that apply):
- When planning her DCO campaign Jennifer determined the exact KP Is she should review her strategy against.Which stage of the campaign should she check the performance?
- When variables are used as tokens, what is the correct format if the variable name is TestVariable?
- When variables are used as tokens,what is the correct format if the variable name is Test Variable? DCO versions are used to:
- Which criterion can be used only once in the IF section when customizing Tag Manager Activity rules?
- Which method to manageD CO versions is limited to one version at the time?
- Which of the following are relevant dynamic ads dimensions to lookout for when analyzing reports?(Select all that apply)
- Which of the following is NOT a feature of the mapping report?
- Which of the following is not an available SAS Target Audience type?
- Which of these report types are not standard for DCO campaign reporting?
- Which of these scenarios can media targeting be the most useful for?(Selectall thatapply)
- Which one of the following permission sets should be granted in order for a user to switch accounts?
- Which tag manager feature is a Chrome browser extension that allows users to analyzer e targeting cookies that exist on the browser and understand the current navigation journey?
- Which Target Audience feature allows you to define criteria of reaching audiences based on exposure?
- While setting up his global entity,Malik defines which Local Advertisers shall be affected and assigns them to this entity.Once the entity is saved,howarethe Local Advertisers affected?(select all that apply)
- Who has the access to setup Account Extensions?
- Yulia is trying to map an Activity Rule that will be triggered for audiences who have visited her client's page but have not purchased a product on the website. What criteria combination can she use in the Activity Rule to achieve this?
amazon ad server ENG version All exam questions
- A customer searched online for a truck to rent and"Trucksy"came up as one of theresults.Upon clicking on the paid search ad,they were taken to the"Trucksy" webpage where a Tag Manager triggered a conversion activity.Whichofthe following site activities was triggered in this case?
- A delivery group cannot be replaced if attached to a live placement.
- A delivery group is running four ads in sequential rotation with frequency cap set at three impressions per user per day.Which creative instance will load when served for the fourth time to the same user in the same day?
- All creative assets under your account a restored in a location called:
- Anna has access to multiple accounts in SAS and she is setting up a conversion RDF for all of them. By default (no additional settings applied) the system will generate:
- Anna wants to use a Raw Data Feed to perform an in depth analysis of activities recorded on the site and site referrals.What type of RDF report should Anna pull to get the best results?
- Anna’s user permissions allow her to access multiple agency accounts in SAS. How does she pull reports for a single agency account?
- Anthony needs to do an in-depth analysis of how customers interacted with the advertiser's ads. Which type of report will provide the best insights to Anthony?
- Arrange the steps in the correct order to generate Tag Manager.
- Attributes such as entity name, entity ID, date, duration, etc. which populate SAS report headings are also known as:
- Attributes such as entity name,entityID,date,duration,etc.which populate A AS report headings are also known as:
- Can you access SAS from the Sizmek Tags Tester tool and how?
- Data obtained by setting the line ID is passed to third-partiesvia:
- Each new RDF must be activated in SAS.
- Expert attribution(a premium feature)is enabled when a custom pathlength is set to include more than___events.
- History log stores data about edits to entities for 30 days. Edit logs older than one month are automatically deleted.
- How far in advance can raw data feeds be scheduled?
- How many different code versions are generated for each Tag Manager?
- If you see red highlighted fields in your click through and events spreadsheet during import validation,it means that:
- In-banner placement tags can be generated as one of these format options: script, iFrame and auto-detect type.
- Jason works for an advertiser called “Velda&Waag” who just set up a new Tag Manager in SAS and generated the tag code. What is the first step they should take in order to fully utilize benefits of Tag Manager, before sending the tag code to the webmaster for implementation?
- Jessica wants to create a report using a template that Anna has created.Howcan shedothis?Select all that apply.
- John is running a test campaign with C TR as the main K PI.He is trafficking five ads per placement and wants to make sure the best performing ads are displayed more often to viewers.Which setup is best suitable to John'sgoal?
- John is running a test campaign with CTR as the main KPI. He is trafficking five ads per placement and wants to make sure the best performing ads are displayed more often to end users. Which setup is best suitable to John's goal?
- Karina’s main campaign KP Is are C TR and impressions delivered.Which type of report is the best option to get this data?
- Lisa wishes to review a conversion report which lists out all dimensions related to the conversion-winning event, such as event date or event location (country). Which report field type is the best option for Lisa?
- Lisa wishes to review conversion winner event date and winner event location for the winning event.Which of the 3 report field types would Lisa select?
- Lux Kitty wants to find new keywords to add to their existing campaigns.Which downloadable report should they use to in form their direction?
- Match the cost models with the units they represent.
- Michael is looking for a report which will list out attributes of the path to conversion events such are ad names and publisher sites running the ads. Which report field type is the best option for Michael?
- P2C reports can include each conversion and the associated parameters, including custom parameters.
- Placement status doesn’t affect the placement tag publishing process.
- Raw data feeds are event-level raw data files exported from SAS.
- Samira is running a multi-ad campaign for a transport company and she needs each vehicle model's ID passed from the creative to the clickthrough URL. How can she achieve this?
- SAS raw data feeds cannot be generated ad-hoc, they can only be scheduled.
- SAS retargeting activities can be used to create target audiences in SAS.
- SAS Tag Manager can be generated in both JavaScript and noscript format.
- SAS Tag Manager is a single block of code that resides on an advertiser’s website for advertisers who want to measure site visits, measure conversions and manage any third-party pixels from the SAS user interface (UI).
- Sizmek Ad Suite offers multiple options for creative authoring, streamlined campaign management, advanced dynamic creative optimization, and Media Rating Council-accredited measurement.
- Tani a has requests to group placements for the same site,with the same cost settings,and the same placement start and end dates.What is the best option for Tani a to manage these requests?
- Tania is about to send placement tags to publishers. Some publishers are asking for different placement tag formats while others require different tag protocols. What is the best option for Tania to manage these requests?
- The Tag Tester tool browser icon will activate only on pages with the Tag Manager implemented.
- The type of third-party activity fired independently from any other A AS activity (addedinthe"Then"section of an activity rule)iscalled:
- The type of third-party activity fired independently from any other SAS activity (added in the "Then" section of an activity rule) is called:
- These are added to URLs to pass relevant campaign, placement, ad ID details to a third-party measurement system.
- Upon deploying a code on a website, the tag administrator has the power to control when and where will the activities fire. There is usually no need to further touch the website for any additional tag implementation.
- Users under the same SAS account cannot be restricted to specific advertisers.
- What are the key benefits of correlation between master ad and placement ad(s)?
- What are the key benefits of correlation between master ad and placement ad(s)? Select All Correct Responses
- What do all three report types in A AS have in common?
- What do all three report types in SAS have in common? Select All Correct Responses
- What is the default counting method for sales conversion activities?
- What is true for environments where JavaScript tags are not allowed or supported?
- What type of logic is used for Tag Manager activity rules?
- When do you need tore-implement the Tag Manager on a webpage?
- When recording conversion third-party activities for sites, instead of reporting the activity to all sites, only a single site is informed of the conversion, according to to the attribution model selected. This process in SAS is called:
- When using a script format to set site parameters to be passed into Tag Manager from the webpage,which of the following options allows you to define where Tag Manager retrieves insights?
- Where should the webmaster place the code if the advertiser wants to track conversions only on specific pages?
- Which attribution model serves as a baseline for collecting advertiser's conversion data?
- Which is the recommended communications protocol value for a Tag Manager?
- Which of the following statements are true in regards to no script tag implementation?
- Which option provides a log of activities that were performed by all users who have edited the entity?
- Which placement types require a creative in order to generate placement tags?
- Which placement types require creative attached in order to complete trafficking and generate placement tags? Select All Correct Responses
- Which section is the Tag Manager "publish" button located in the SAS UI?
- Which section is the Tag Manager"publish"button located in the A A SUI?
- Which settings tab is used to set up verification and viewability?
- Which tab under advertiser settings is used to setup Verification and View ability?
- Which tool in A AS is used for mass creative upload?
- Which type of activities can be added to activity rules in A AS?
- Which type of activities can be added to activity rules in SAS?
- Which type of activities can be added to activity rules in SAS? Select All Correct Responses
- Which types of campaigns can you include in A ASP 2 C reports?
- Which types of campaigns can you include in SAS P2C reports?
- You can access SAS directly from the Sizmek Tag Tester Tool.
- You must be connected to a VPN in order to access SAS RDF server.
amazon adertising foundations ENG version All exam questions
- A car insurance company recently ran an awareness campaign on Amazon promoting a new insurance bundle.The company does not sell on Amazon. Which of the following insights could be available to them?(Select3)
- A manufacturer of chewing gum recently launched a new spearmint flavor. They're looking to promote this new flavor to audiences that do not know about their product.Which of the following audiences should they select?(Select2)
- Advertisers can connect with_______to drive purchases for their products by engaging audiences that have recently considered products in a given category.
- Anita is running Amazon ads with placements on and off Amazon.Whichofthe following ad types could Anita be using?(Select2)
- Brighton is an advertiser selling holiday cookies on Amazon.He wants to reach shoppers who recently viewed or purchased products in the"bakery and dessert gifts"sub-category.Which audience solution will Brighton rely on to achieve this?
- Charlie wants to generate long-term,new demand for their brand by reaching those who are not currently engaging with the category.What stage of the customer journey should Charlie focus on?
- Cliff is an advertiser at a luxury bedding company and wants to reach shoppers that recently shopped for related products.Which of the following audiences should he select?(Select2)
- Cristobal is an advertiser at a cold medicine brand.He wants to understand the time of day that shoppers purchase from his brand.Which insight would be best for Cristobal to review?
- Darius is an advertiser at an office supply company.He wants to reach shoppers that recently viewed detail pages of other products similar to his brand's offerings.Which audience would you recommend for Darius to leverage in this campaign?
- Dreyfus is an advertiser looking to drive purchase for his brand'sproducts. Which metrics would be best for evaluating his campaign's purchase goals? (Select2)
- Ha Yoon is an advertiser at a cold brew coffee manufacturer.Which audience would be best for her to use to reach these shoppers on Amazon that herbrand already has a direct relationship with off Amazon?
- Hoku lani is an advertiser at a designer pottery brand.She recently rana campaign where her primary goal was to drive purchase for herbrand'sclearance on last season's wooden planters.Which metric would be the best indicator of this campaign's success in helping drive purchase?
- House War ez is running a campaign tore market to existing brand customers for cross-selling purposes.What stage of the customer journey is House War ez focusingon?
- Janka is an advertiser at a party supply brand.She wants to understand areas such as income range,agerange,and marital status of herbrand'sshoppers. which insight would be best for Janka to review?
- Jasmine wants to understand the impact a campaign had on the perception of her brand.Which of the following should she consult?
- Johan is an advertiser at a consumer electronics brand.He wants to understand the impact of his advertising by comparing changes from 30 days before the campaign to 30 days after.Which of the following would help him understand this?
- Law and a wants to expand the reach of herbrand's campaign beyond what is achievable through Amazon's websites and apps.Which inventory should she leverage?
- Miguel knows that the majority of e-commerce customers do not purchase after viewing a product for the first time.He want store engage those that have viewed hisbrand'sproducts.Which Amazon audience should Miguel leverage?
- Minoru is an advertiser at a consumer packaged goods company.He recently ran a campaign where his primary goal was to drive loyalty for his brand'slavender scented laundry detergent.Which metric would be the best indicator of this campaign's success in helping drive loyalty?
- Myung-dae is an advertiser at a hair care brand.He wants to understand the percentage of first time versus repeat buyers of his brand'sproducts.Which insight would be best for Myung-dae to review?
- Oj is tah wants to develop a strategy for her brandon Amazon.Whichofthe following audience solutions would best help her understand how customers currently view and purchase the brand’s products on Amazon?
- On is im wants to use display advertising tore engage shoppers that viewed their product detail page,but did not purchase.Which audience would be best for helping On is im achieve this goal?
- Q is mat is an advertiser at a bedding company.He wants to reach shoppers who purchased his brand's mattress so that he can promote bedding and pillows. Which audience would be best for helping him achieve this goal?
- Rhonda is an advertiser at a consumer packaged goods company that sells laundry detergent.She is looking tore engage her existing audiences to encourage repeat purchases on Amazon.Which audience(s)would best help Rhonda achieve this goal?(Select2)
- T and ra is setting up a campaign to drive awareness of herbrand's new book light. She wants to reach the community of readers on Good reads.Considering only this information,where should her ads be placed?
- Ta miko is an advertiser at a bowling supply company running a display campaign.She wants to learn more about audiences that share similar attributes to the audiences she is currently reaching through her campaign.Whatshould Ta miko consult to learn more about this?
- Tiny Feet has their own website.They want to reach their website's audience with an Amazon campaign.From which source should they transfer their audience?
- Uj araki san advertiser at a magazine company.He wants to reach shoppers who visited the subscription sign-uppage,but did not complete their sign ups.Which type of audience could he use to best reach this audience?
- What are Subscribe&Save metrics best used for?
- Where can display ads be placed?
- Which audience solution allows advertisers to reach shoppers that previously visited certain product detail pages on Amazon?
- Which inventory is available for Sponsored Products and Sponsored Brands campaigns?
- Which of the following ad types are located within shopping results and promote individual products?
- Which of the following are considered advertiser audiences?(Select2)
- Which of the following audiences might help Red Eye Coffee,a brand that sells canned coffees,increase consideration for their products?(Select2)
- Which of the following best describes a campaign with a consideration goal?
- Which of the following best describes advertiser audiences?
- Which of the following best describes the value of brand halo metrics?
- Which of the following is the Amazon DSP creative type that automatically optimizes based on a selected optimization goal?
- Which of the following metrics would be the strongest indicator of a campaign's ability to help drive awareness?
- Which of the following metrics would be the strongest indicator of a campaign's ability to help drive consideration?
- Wilfred o works for an advertising agency and is interested in leveraging Amazon Advertising to reach his audience in an unconventional way.Which solution would be appropriate for this goal?
- Yvonne's business sells hiking equipment on Amazon.She wants to use Amazon Advertising tore engage customers who have previously visited her website. Which audience solution will Yvonne rely on to achieve this?
Amazon Ads Advanced Retail All exam questions
- Accent Athletics recently started using Amazon Live, how can they use this tool to further engage with customers?
- All selling partners can offer Subscribe & Save discounts, regardless of account standing.
- Amazon Brand Analytics is available to all registered brands on Seller Central and Vendor Central.
- Amazon Retail Analytics is a set of dashboards that lets vendors analyze sales and operational data, such as revenue and inventory levels.
- Amazon.com sellers must be registered as a professional seller, with at least five seller feedback ratings per month, and an overall rating of 3.5 stars or higher to offer Deals.
- An optimized primary image on a product detail page has an all-white background, with the product filling at least 80% of the image area, and no text on the image.
- Arnav is an Amazon.com seller who wishes to offer a discount on eligible products when customers opt-in for auto-repeat delivery. What Amazon growth lever can Arnav leverage to achieve this?
- Banner images should be used to show your products in use as well as highlight your brand logo.
- Basic A+ Content includes which of the following attributes?
- How can a selling partner apply a product badge to their product listings?
- How can selling partners use A+ Content to help improve retail readiness?
- How can selling partners use the insights on the search catalog performance dashboard to help improve impressions?
- How can the insights from the market basket analysis report be used to help increase basket size?
- How many global marketplaces does the Amazon store operate in?
- In order for an Amazon.com brand owner to use the Subscribe & Save feature, they must use Fulfillment by Amazon (FBA) and their account must be in good standing.
- In order to create an Amazon Store you must navigate to the ________.
- Iris is an Amazon.com seller who sells refurbished cameras and televisions. They want to offer a Coupon to help drive product awareness during the holidays, but when they go to set up the Coupon, they get a notice that they are unable to offer this type of promotional offering. Which of the following reasons is why Iris is unable to offer Coupons to their customers?
- ____ is a clean room solution, used to help measure retail performance in which advertisers can easily perform analytics across pseudonym i zed signals, including Amazon Ads signals as well as their own inputs.
- Jack and Jill is a clothing company running a Sponsored Brands campaign. Midway through the campaign their Featured Offer status changes and they are no longer the Featured Offer. How will Jack and Jill's campaign be affected?
- Kitchen Smart has just released a new suite of products and wants to drive customer awareness. Which Amazon program can Kitchen Smart leverage to generate more reviews to help meet their goal?
- Kitchen Smart is a kitchen appliance company who wants to launch a new product. Which tool can they use to help identify unmet audience demand and create a new product to fit current audience needs?
- Kitchen Smart is an Amazon.com seller that wishes to run a promotional offering to help get customers to purchase complementary items together and get rid of some surplus inventory. Which type of promotional offering would be best for Kitchen Smart to run?
- Kitchen Smart wants to highlight a new, non-stick pan in a high-energy, engaging, video format. Which of the following programs should they consider using?
- Márcia is looking to optimize their product listing through enhancing their A+ Content. Which of the following best practices could help improve their content?
- Mary is a vendor who wants to make sure their product listing is eligible for the Featured Offer. They've checked stock availability, compliance documents, and pricing. What is the last required criteria Mary should check to ensure they are eligible for the Featured Offer?
- Nutrition Co. wants to use influence rs to promote products from their Amazon Store. Which type of promotional offering is best for Nutrition Co. to use?
- Only vendors invited by Amazon.com are eligible to create Coupons for customers.
- Organique is a beauty company who has reviewed the search query performance dashboard, and identified their brand share for clicks is low. Which of the following actions can they take to help drive clicks?
- Organique is running a Sponsored Products campaign for multiple products. Mid-campaign, their most popular product sells out and is now out of stock. How will Organique's ad be affected?
- Paulo is an Amazon.com vendor who wants to pro grammatically access their retail information on listings, orders, payments, and reports as they scale. Which API would be appropriate for Paulo to use?
- Products selected for promotional offerings should be top-performing and already have a large number of positive reviews, good conversion rate, and a high ranking.
- Sponsored Display ads will keep running if your products are no longer available to purchase or are no longer the Featured Offer.
- The only way for Amazon.com sellers to be eligible to offer Promotions, is to be enrolled in Amazon Brand Registry.
- To offer a Prime exclusive discount, the discounted price must beat the lowest customer bought price for the product in the past 30 days.
- Vendors can set up international selling on their own on Vendor Central under the Global Selling tab.
- Wang is editing the customizable section of their product detail page to include charts, image carousels, and videos. What type of content is this known as?
- What can Amazon Attribution help brands achieve?
- What can Amazon.com sellers and vendors use to gain valuable information about their sales and customers behavior?
- What does an active Amazon.com selling partner need to do to participate in Prime Day?
- What does the awareness index within Brand Metrics measure?
- What is the maximum amount of time a Prime exclusive discount can run for?
- What type of content is created once for all product detail pages that a brand owns and is meant to complement A+ Content?
- When considering to expand globally through an Amazon marketplace, why is proficiency in the local language necessary?
- When creating an Amazon Store, a dedicated URL is created for your brand.
- When running a Demographics report, brands and customer categories need to have 100 or more unique customers in the selected time range to be included in the analysis.
- When using Amazon Posts, it is unnecessary for you to specify where your posts should be displayed, as they will automatically be placed based on relevance and shopping engagement.
- When you participate in different promotional events, you can incorporate elements unique to local events in your listings based on the events’ characteristics.
- Which advertising and analytics measurement solution helps gives marketers insights into how non-Amazon marketing channels perform on Amazon.com?
- Which Deal type has the shortest offer run period?
- Which of the following Amazon Ads solutions appear in multiple locations both on and off Amazon.com?
- Which of the following considerations should be taken into account when selling in a new marketplace through an Amazon store?
- Which of the following could be considered a challenge when launching a new product?
- Which of the following describes the value of the Amazon Brand Analytics Demographics report for brand owners?
- Which of the following fees are required to be paid by selling partners and included in the total cost of running Coupons?
- Which of the following is the best example of an optimized title on a product detail page?
- Which of the following metrics within Brand Metrics quantifies the amount of orders your brand has generated relative to your most comparable peers?
- Which of the following Promotion types list the original price, the sale price, and the amount saved on the product detail page?
- Which of the following requirements must be met in order for Amazon.com vendors to offer a Promotion?
- Which of the following tools allows advertisers and partners to pro grammatically manage campaign planning, creative asset development, and advertising optimization?
- Which of the following tools in the Amazon Global Selling program helps sellers get paid in their local currency?
- Which of the following tools offers customers a way to personalize their shopping experience on Amazon.com, by elevating placements of products and content from brands they follow?
- Which type of product badge can help make browsing easier for customers by highlighting product recommendations and is based on a number of factors such as ratings, pricing, and availability?
- Which type of virtual bundle contains one or more components that cannot be purchased individually?
Amazon Ads Advanced Retail Certification All exam questions
- Benny is looking to optimize her product listing on her product detail pages through enhancing her A+ content. Which of the following best practices could help improve her content?
- Gerald is setting up his first product detail page and wants to include text and images only for his initial products. This is known as what kind of content?
- Gini wants to create a promotional offer on her products, specifically for Prime members. Which of the following eligibility criteria should she meet in order to create Prime exclusive discounts?
- ____ is a clean room solution, used to help measure retail performance in which advertisers can easily perform analytics across pseudonymized signals, including Amazon Ads signals as well as their own inputs.
- Nutrition Co. wants to use influencers to promote products from their Amazon Store. Which type of promotional offering is best for Nutrition Co. to use?
- Paulo is an Amazon.com vendor who wants to programmatically access their retail information on listings, orders, payments, and reports as they scale. Which API would be appropriate for Paulo to use?
- Wang has overstocked inventory and wants to run a lightening deal. What is the minimum percentage discount Wang can offer on his products?
- What insights does the Amazon Brand Analytics Demographics report provide to brand owners?
- What should Cathy do in order to participate in Prime Day?
- Where can Sani access the Amazon Retail Analytics dashboard to analyze her sales and operational data?
- Which Brand Metrics index quantifies the audience size that is aware of your brand relative to your most comparable peers?
- Which of the following growth levers offer discounted pricing, free shipping, and the convenience of regularly scheduled deliveries on eligible products to customers?
- Which of the following tools allow advertisers and partners to programmatically access their retail information on listings, orders, payments, and reports?
- Which of the following tools allows advertisers and partners to programmatically manage campaign planning, creative asset development, and advertising optimization?
- Which statement about Amazon Stores is true?
- Why should selling partners use the reports generated by Amazon Brand Analytics tools?
amazon ads advanced retail ENG version All exam questions
- Ar navis an Amazon.com seller who wishes to offer a discount on eligible products when customers opt-inforauto-repeat delivery.What Amazon growth lever can Arna v leverage to achieve this?
- Diego wishes to review the ordered revenue metric to identify the bestselling products that contribute to their Amazon.comsales.Which of the following reports or dashboards can Diego use to find these insights?
- How are fees charged to Amazon.com sellers when running a Lightning Deal?
- Iris is an Amazon.com seller who sells refurbished cameras and televisions.They want to offer a Coupon to help drive product awareness during the holidays,but when they goto setup the Coupon,they get a notice that they are unable to offer this type of promotional offering.Which of the following reasons is why Iris is unable to offer Coupons to their customers?
- ____is a clean room solution,used to help measure retail performance in which advertisers can easily perform analytics across pseudonym i zed signals, including Amazon Ads signals as well as their own inputs.
- Jane is an author who sells her books on Amazon.com.Jane wants to run a Promotion but realizes she is unable to.Which of the following reasons is prohibiting Jane from running a Promotion?
- Kitchen Smart has just released a new suite of products and wants to drive customer awareness.Which Amazon program can Kitchen Smart leverage to generate more reviews to helpmeet their goal?
- Kitchen Smart is a kitchen appliance company who wants to launch a new product.Which tool can they use to help identify un met audience demand and create a new product to fit current audience needs?
- Már cia is looking to optimize their product listing through enhancing their A+ Content.Which of the following best practices could help improve their content?
- Nutrition Co.wants to use influence rs to promote products from their Amazon Store.Which type of promotional offering is best for Nutrition Co.touse?
- Organ i que is a beauty company who has reviewed the search query performance dashboard,and identified their brand share for clicks is low.Whichofthe following actions can they take to help drive clicks?
- Organ i que is running a Sponsored Products campaign for multiple products. Mid-campaign,their most popular product sells out and is now out of stock.How will Organ i que'sad be affected?
- Wang is editing the customizable section of their product detail page to include charts,image carousels,andvideos.What type of content is this known as?
- What does an active Amazon.com selling partner need to do to participate in PrimeDay?
- What insights can you access on the Amazon Retail Analytics inventory report?
- When considering to expand globally through an Amazon marketplace,whyis proficiency in the local language necessary?
- When is a Coupon considered redeemed by customers?
- Where are Lightning Deals displayed?
- Which of the following criteria is a factor Amazon uses to choose the Featured Offer?
- Which of the following dashboards can help a vendor to discover any profitability issues due to market pricing or other factors that would impact their Featured Offer?
- Which of the following growth levers can only be used by brand owners who use Fulfillment by Amazon(FBA)?
- Which of the following is criteria for Professional Sellers to become eligible for the Featured Offer?
- Which of the following is required for Amazon.com vendors to be eligible to offer Deals?
- Which of the following is the best example of an optimized title on a product detailpage?
- Which of the following reports allows brand owners to lookup a specific keyword to see the products that Amazon.com customers are clicking on after searching?
- Which of the following statements about Amazon Stores is true?
- Which of the following tools allows advertisers and partners to pro grammatically manage campaign planning,creative asset development,and advertising optimization?
- Which of the following tools offers customers away to personalize their shopping experience on Amazon.com,by elevating placements of products and content from brands they follow?
- Which of the following types of promotional offerings can help drive sales by offerings limited-time savings?
- Which type of Deal requires the product to be selected by the Amazon Deals team and cannot be created by a selling partner?
- Which type of Deal runs for a full day and often offers a larger discount on a higher price point item?
- Zhang is a seller on Amazon.com who is using the Brand Follow feature for their Amazon Store.How can Zhang benefit from utilizing the Brand Follow feature?
Amazon Ads Campaign Optimization All exam questions
- A review of your Sponsored Display campaign shows low Click-through rates (CTRs) and low new-to-brand orders. Which of the following strategies might help optimize your campaign goals to drive performance?
- After analyzing your campaign insights, you find some campaigns are higher-performing than others in terms of purchases. Based on the insights, which of the following might help you optimize your campaigns?
- Amazon DSP and Sponsored ads have a range of reporting types such as Audience, Campaign Performance, Inventory, Location, and Product Retail reports that you can use to better understand your campaign’s performance and make optimization s.
- Campaign reports in Amazon DSP include performance signals for you to check performance activity on selected dates. Which of the following is a dimension available in the Campaign reports?
- Detail page visits help customers learn more about your product
- Diego wishes to review the ordered revenue metric to identify the best selling products that contribute to their Amazon.com sales. Which of the following reports or dashboards can Diego use to find these insights?
- During your campaign period for a new product, you saw that many customers chose to Subscribe & Save. What goals can you measure by checking how many customers chose to Subscribe & Save?
- During your campaign period, you found that some customers made their second or third purchase and decided to check the number of repeat purchases. Which goals are you measuring?
- How can you use Amazon sponsored ads (Sponsored Brands, Sponsored Display, Sponsored Products) and organic solutions (Stores, Brand Follow, Amazon Live, and Posts) together to achieve your business goals?
- In the advertising console you can get a Campaign report for each type of sponsored ads you're running, broken down at the campaign level.
- includes ads purchased through Amazon DSP and sponsored ads, as well as advertiser-owned datasets because Amazon DSP Which of the following reports can you use to measure the overall performance of Sponsored Brands?
- ____ is a clean room solution, used to help measure retail performance in which advertisers can easily perform analytics across pseudonym i zed signals, including Amazon Ads signals as well as their own inputs.
- Jane has been using Sponsored Display at all stages of the shopping journey for her campaign. She now needs access to other media formats and she is not active on Amazon DSP. Which of the following strategic recommendations is the best for Jane?
- Jorge's campaign goals are to increase customers' awareness and drive sales. What product or products should he consider to best optimize results?
- Li is setting up a Prime Day campaign for her client’s new pet care product. She has been leveraging both Sponsored Products and Sponsored Brands to reach customers and drive sales. With multiple ad types available from Amazon Ads, her client wants to know what additional ad type(s) can help achieve both goals effectively. What other ad type(s) can Li suggest to her client?
- Martha is using Sponsored Display to help drive awareness for her brand. She is measuring this by seeing if her Sponsored Display campaigns help drive viewable impressions. Which optimization strategy should Martha use to help reach the goal?
- Mateo's cleaning product campaign has lots of clicks and many customer visits to the detail pages but he has low conversions. What keyword strategy can he use to address this?
- One month ago, you completed a campaign to improve your brand awareness and audience engagement. Now you want to understand if you have reached your conversion goals. You have the ad cost of sales already, what else can you measure?
- Paulo is setting up a campaign for a new skincare product and wants to show the ads to as many customers as possible. Which keyword match type should he use?
- Report availability depends on the type of campaign that you’re running. For which of the sponsored ads campaigns can you generate a category benchmark (CBR) report?
- Saanvi wants to attract as many customers as possible to her product page. She also wants to engage the audiences who viewed the product detail page but did not purchase. Which sponsored ads should Saanvi use to achieve these objectives?
- Shirley is using Sponsored Products to engage shoppers looking for "coffee maker." To reach the shoppers who've previously browsed coffee makers, which of the following products should Shirley use?
- Sponsored ads and organic solutions together can provide premium reach at scale to engaged audiences both inside and outside Amazon-owned properties.
- Sponsored ads can be placed in the front-center locations such as on top of shopping queries, and Amazon DSP ads can be placed in top and bottom right of desktop, as well as in search pages, product detail pages, and thank you pages.
- The campaign pre-optimization checklist should be used at the review step of the campaign management process, right after you have completed setting up your campaign, to ensure the campaign has been set up correctly.
- the highest when there is exposure to both ad types so it may be worthwhile to increase investment in both to reach your You should have a wide variety of keywords to help increase impressions and clicks in your campaigns
- The return on engagement metric within Brand Metrics measures the average value to your brand based on a shopper's engagement in the prior 12 months.
- To grow brand consideration and conversion, which Amazon DSP multichannel products should you use?
- Using Sponsored Brands, Posts, and Stores together can help increase awareness by exposing your brand to more potential customers.
- Wang wants to help drive awareness for her product. wants to help drive awareness for her their product. Which of the following cross-product strategies can help Wang reach their goal?
- What does the click rate (CTR) on the search catalog performance dashboard include?
- What is different between the reporting scopes of Amazon DSP and AMC?
- What targeting option for display ads can help drive consideration goals?
- When should you reallocate your ad budget?
- When using a combination of sponsored ads and multichannel products, which of the following strategies can best help drive consideration?
- When using a combination of sponsored ads and multichannel products, which of the following strategies will help drive conversion?
- Which metric can you find on the Amazon Retail Analytics traffic dashboard?
- Which of the following is a benefit of Amazon Marketing Cloud (AMC)?
- Which of the following metrics can you use to measure your awareness goals?
- Which of the following metrics can you use to measure your conversion goals?
- Which of the following metrics can you use to measure your loyalty goals?
- Which of the following multichannel ad products is the most effective at driving your short-term goal of conversion?
- Which of the following reports allow vendors to analyze projected demand for their products which can be used for production and inventory planning purposes?
- Which of the following reports allows brand owners to look up a specific keyword to see the products that Amazon.com customers are clicking on after searching?
- Which of the following reports can you use to measure the overall performance of Sponsored Products?
- Which of the following results best indicates that you should increase your ad budget?
- Which of the following steps from the pre-optimization checklist confirms your campaign is set-up for the correct timing strategies?
- Which report is only available for Amazon DSP?
- Which sponsored ads appear on Amazon.com and allow you to create ads that include multiple products, along with your brand logo and a custom headline?
- Which targeting option should you use to help drive conversion goals?
- Which type of audiences should you use to help drive loyalty goals?
- Why would you use Amazon Marketing Cloud (AMC) to help optimize your campaign strategy?
- You can measure your custom ads campaign impressions and brand recall lift to see if you have reached your audiences effectively.
- You can use impressions as a metric to indicate success towards your conversion goals.
- You have created a FireTV campaign report for your campaign in the advertising console. Which of the following does this report measure?
- You have multichannel products of audio ads, Streaming TV, online video in your campaigns. Which goal can they best help you achieve?
- You may need to adjust your bids depending on the performance of your bid optimization strategy. Which of the following bid adjustments should you consider?
- You want to have a more nuanced set-up with only Amazon-owned and -operated inventory but also be able to reach third-party audiences at each stage of their shopping journey. Which of the following solutions is best for you?
- You've used Sponsored Brands to reach millions of customers to tell your brand story and differentiate your product. Which goals have you reached successfully?
- Your client is prioritizing performance and a line item has low performance and low delivery. What will you suggest to optimize the campaign for higher performance and delivery?
Amazon Ads Campaign Optimization Certification All exam questions
- Amazon DSP and Sponsored ads have a range of reporting types such as Audience, Campaign Performance, Inventory, Location, and Product Retail reports that you can use to better understand your campaign’s performance and make optimizations.
- Ana is spending a lot on ad clicks for her Sponsored Brands campaign but seeing few conversions. What is one keyword targeting strategy Ana should consider?
- Both Amazon DSP and Sponsored Display can help you increase consideration by optimizing bids for page visits with cost-per-click (CPC) billing and click-based attribution to focus on audiences most likely to convert.
- Detail page visits help customers learn more about your product so they help measure the success of your ability to drive repeat purchases.
- Gordon's Chocolatier wants to reach millions of customers to tell their brand story and differentiate their product. Which goal should they target with their new sponsored ads campaign?
- How can Organique, a botanical hair care company, assess the performance of their cross-product campaigns to get deeper insight into holistic performance?
- How can Superpower Batteries best use Amazon sponsored ads (Sponsored Brands, Sponsored Display, Sponsored Products) and organic solutions (Stores, Brand Follow, Amazon Live, and Posts) together to achieve their business goals?
- If Accent Athlectics' primary objectives are to drive conversion and increase sales, which combination of sponsored ads should you recommend for their next campaign?
- Li's current campaign goal is to increase conversion. Which targeting option should you recommend to Li to help meet their goal?
- One of your line items has low performance and low delivery. How should you adjust your budget to optimize a campaign for better performance and delivery?
- Report availability depends on the type of campaign that you’re running. For which of the sponsored ads campaigns can you generate a categorybenchmark (CBR) report?
- Report availability depends on the type of campaign that you’re running. For which of the sponsored ads campaigns can you generate an automatic targeting report?
- What would be the best bid adjustment to consider if Kitchen Smart's goal is to secure ad placement and increase impressions?
- When using a combination of sponsored ads and multichannel products, which of the following strategies will help drive consideration?
- Which metric included in Brand Metrics quantifies the size of the audience considering your brand relative to your most comparable peers, and is predictive and causally linked to sales.
- Which of the following are the downloadable reports available from Amazon DSP?
- Which report includes engagement metrics such as impressions, clicks, add-to-cart, purchases, and conversion rates to better understand your sales funnel?
- Which type of audiences should you use to help drive purchase goals?
- You can use negative keyword targeting for your Sponsored Display campaigns.
- Zhang wants to help potential customers make the decision to purchase their product. Which metric will best help Zhang monitor this campaign result?
amazon ads campaign optimization ENG version All exam questions
- A review of your Sponsored Display campaign shows low Click-through rates (CTRs)andlownew-to-brand orders.Which of the following strategies might help optimize your campaign goals to drive performance?
- High traffic indicates success towards_____goals because it shows successful engagement of prospective customers.
- How can Amazon multichannel products(Display,audioads,and streaming TV) work together to help you achieve your objectives?
- How can you use Amazon sponsored ads(Sponsored Brands,Sponsored Display,Sponsored Products)and organic solutions(Stores,Brand Follow, AmazonLive,andPosts)together to achieve your business goals?
- ____is a clean room solution,used to help measure retail performance in which advertisers can easily perform analytics across pseudonym i zed signals, including Amazon Ads signals as well as their own inputs.
- One of your line items has high performance but low delivery.How should you adjust your supply to optimize a campaign for better performance and delivery?
- One of your line items has low performance but high delivery.How should you adjust your budget to optimize a campaign for better performance and delivery?
- Organ i que is a beauty company who has reviewed the search query performance dashboard,and identified their brand share for clicks is low.Whichofthe following actions can they take to help drive clicks?
- Paulo is setting up a campaign for a new skin care product and wants to show the ads to as many customers as possible.Which keyword match type should he use?
- Report availability depends on the type of campaign that you’rerunning.For which of the sponsored ads campaigns can you generate an Attributed purchases report?
- S a an vi wants to attract as many customers as possible to her product page.She also wants to engage the audiences who viewed the product detail page but did not purchase.Which sponsored ads should S a an vi use to achieve these objectives?
- Shirley is using Sponsored Products to engage shoppers looking for"coffee maker."To reach the shoppers who've browsed coffee makers,whichofthe following,lessretail-focused options should Shirley use?
- Wang is using a combination of sponsored ads and multichannel products to help drive awareness for her product.Which of the following strategies can help Wang reach her goal?
- What does the repeat purchase behavior report primarily focus on?
- What optimization strategy would be best to use if a line item has high performance and high delivery?
- When considering sponsored ads and multichannel products to help drive loyalty, which of the following statements is correct?
- Which of the following indicates that you should increase your ad budget?
- Which of the following metrics are included on the top search terms report?
- Which of the following metrics can you use to measure your consideration goals?
- Which of the following multichannel ad products is the most effective at driving yourshort-term goal of conversion?
- Which of the following reports can you use to measure the overall performance of Sponsored Display?
- Which type of audiences should you use to help drive awareness goals?
- You have created a Fire TV campaign report for your campaign in the advertising console.Which of the following does this report measure?
- You have multichannel products of audio ads,Streaming TV,online video in your campaigns.Whichgoal(s)will they help you achieve?
- You used both Sponsored Products and Amazon DSP Display to promote the same products during the sametime.You did an analysis in AMC on these two ad types and found the purchase rate was 0.12%when customers are exposed to both ad types,0.10%when customers are exposed to Sponsored Products only, and0.09%when customers are exposed to Amazon DSP Display only.Howcan you interpret these insights to make strategic campaign decisions?
- You want to have a more nuanced set-up with only Amazon-ownedand-operated inventory but also be able to reach third-party audiences at each stage of their shopping journey.Which of the following solutions is best for you?
- You're reviewing your campaign set-up using the pre-optimization checklist. Which of the following steps should you complete as part of the checklist?
- You've used Sponsored Brands to reach millions of customers to tell your brand story and differentiate your product.Which goals have you reached successfully?
Amazon Ads Campaign Planning Certification All exam questions
- A beauty brand has been running Amazon Ads campaigns for six months. While some campaigns performed well, others didn't meet expectations. The brand needs to plan their upcoming holiday season strategy. What approach would best support their continued success?
- A beauty brand wants to create an immersive TV experience to increase brand awareness and engagement. Which Fire TV feature would be most effective?
- A brand is launching a new product and wants to understand how different ad channels work together to drive results. Which reporting tool should they use?
- A brand notices that while their conversion-focused campaigns perform well, they struggle to attract new customers. How could implementing a full-funnel strategy with multiple campaign goals address this issue?
- A brand notices their ads are getting impressions but wants to understand if customers are actually seeing them. Which measurement metric should they focus on?
- A brand's awareness campaigns show strong performance with high reach and video completion rates, but their sales metrics aren't increasing proportionally. How should they use Ads Planner to address this issue?
- A company wants to increase participation in their rewards program. Which feature of Ads Planner would be most beneficial for understanding and engaging their existing audience?
- A gardening company wants to understand how well their ads performed over the past 3 months to help plan future campaigns. What is the best way to use Amazon Ads measurement tools?
- A luxury skincare brand is launching in the Amazon store. They've created an Amazon Brand Store showcasing their brand story, ingredient sourcing, and complete product collection. However, they're noticing very few customers are visiting their Brand Store. Which advertising solution would be most effective in addressing this challenge?
- A luxury watch brand wants to remarket to customers who have viewed their products. Which audience solution should they use?
- A new brand is launching in the Amazon store and wants to build awareness before driving sales. Which combination of ad products would you recommend?
- A new brand is launching its first product line. Which campaign goal should they prioritize?
- A new premium pet food brand wants to launch a comprehensive marketing campaign using Amazon Ads. They aim to first build brand awareness, then drive consideration, and finally encourage purchases. Which advertising strategy sequence would be most effective?
- A new skincare brand wants to establish market presence using Amazon Ads signals. What would be the most strategic approach?
- A popular cookbook author released several bestsellers in the Amazon store and wants to promote their latest book to their most dedicated readers. Which audience type should they prioritize to maximize sales and encourage positive reviews?
- A premium sneaker brand launches running shoes. Ads Planner shows their audience watches sports content, fitness documentaries, and streams on Fire TV. Which ad strategy would work best?
- A startup tech company is launching a new smartwatch. Which approach is most suitable for their awareness campaign?
- A well-established online retailer notices high product page views and cart additions but low purchase completion rates. Which campaign goal should they prioritize to address this challenge?
- A yoga apparel brand's Ads Planner analysis shows their audience highly engages with fitness content and mindfulness programming on Prime Video. How should they adjust their strategy to best reach this audience?
- Amazon Ads measurement solutions can only measure performance within Amazon owned and operated (O&O) services.
- Amazon Ads signals can only be leveraged within Amazon owned and operated (O&O) properties like Prime Video, Twitch, and Amazon stores.
- Amazon Ads’ advertising solutions operate independently of each other, with each ad product serving a single, specific stage of the marketing funnel.
- An advertiser aims to expand their reach to new potential customers. Their current Sponsored Products campaigns are driving strong sales, but primarily from existing customers. Which strategy would most likely help achieve their goal of reaching new audiences?
- An advertiser has just completed a multi-channel campaign using various Amazon Ads products. What's the most comprehensive approach to analyzing the results?
- An advertiser is planning a multi-channel campaign on Amazon Ads and wants to optimize their budget allocation across different funnel stages and ad products. Which of the following best describes how Ads Planner can help achieve this goal?
- An advertiser notices inconsistent performance across their campaigns. How should they approach evaluating their overall advertising strategy to ensure long-term success?
- An advertiser notices that increasing their budget for a specific ad product shows diminishing returns in the reach curve on Ads Planner. What should they do?
- An advertiser notices their campaign has a high click-through rate but a low ROAS. Which conclusion about their conversion funnel is most likely accurate?
- An advertiser wants to connect their campaign measurement results with their future planning effectively. What's the best approach?
- An advertiser wants to focus on customer loyalty for their Amazon Ads campaign. Which of the following are the best metrics to measure?
- An advertiser wants to measure how effectively their campaign is moving shoppers from browsing to purchasing. Which set of metrics would be most relevant for this objective?
- An advertiser wants to measure the impact of their Amazon Ads on their own website sales. Which metric category should they focus on?
- An advertiser wants to simultaneously build brand awareness and drive immediate sales. Which combination of ad products would likely be most effective?
- An advertiser wants to understand both the total number of audience who saw their ads and how frequently the ads were shown. Which metrics should they analyze?
- Analyze the following scenario: Two advertisers in the same category have similar budgets. Advertiser A uses historical data and customer insights to inform their strategy, while Advertiser B focuses on matching competitor spending. Which approach is likely to be more effective and why?
- Before determining their media mix and budget allocation, advertisers should first set clear objectives based on Amazon Ads audience insights.
- For building brand awareness, which combination of ad formats is most effective?
- Guaranteed ad products provide more certainty but less flexibility compared to non-guaranteed ad products.
- How can a brand best use advertiser audiences to improve campaign effectiveness?
- How can advertisers use both pre-curated and custom audience groups to create a more nuanced and effective engagement strategy?
- How can an advertiser create a more integrated approach for awareness and sales campaigns?
- How do audience insights benefit advertisers in their campaign planning?
- How does Ads Planner accommodate advertisers with existing planning tools?
- How does Ads Planner help advertisers select appropriate ad formats?
- How does Amazon Ads optimize campaigns based on the selected goal and KPI?
- How does the customers' journey typically unfold on Amazon?
- How does the integration of Ads Planner into an advertiser's workflow contribute to a more cohesive and effective advertising strategy?
- How does using third-party audiences help advertisers?
- Searching for a brand, visiting product pages, adding items to cart, and completing purchases are all examples of what?
- The customer's journey is a strictly linear path from first view to purchase.
- What advantage does integrating Amazon Ads APIs into campaign management software provide?
- What are the three main types of supply sources used by Amazon Ads?
- What distinguishes Amazon audiences from advertiser audiences?
- What distinguishes guaranteed ad products from non-guaranteed ad products?
- What is required to create plans across both Amazon DSP and sponsored ads in Ads Planner?
- What is the key difference between the customers' journey and the marketing funnel?
- What is the primary benefit of implementing a full-funnel advertising strategy?
- What is the primary function of Amazon Ads' media planning suite?
- What is the primary purpose of Ads Planner?
- What makes Online Video (OLV) ads effective in reaching audiences across the customers’ journey?
- What type of audience solution allows advertisers to use their own first-party signals?
- What type of metrics help advertisers understand ad-attributed purchases from first-time customers of their brand?
- What type of signals does Amazon Ads use to inform audiences?
- What would be the most strategic approach for this brand to use Amazon Ads signals?
- When planning a multi-channel video campaign, which format offers the most flexibility in placement?
- When using Ads Planner, advertisers must select only one ad format type per campaign to ensure optimal performance.
- Which ad format delivers in-stream and out-stream video content across desktop, mobile, and tablet devices?
- Which ad format is described as "non-skippable 10-to-30-second ads that play for listeners"?
- Which ad format would be most effective for a brand wanting to reach listeners during music and news content?
- Which Amazon Ads format would be most appropriate for an advertiser specifically wanting to promote their products through auto-playing video content within Amazon store shopping results to achieve their awareness goal?
- Which factors does Ads Planner consider when optimizing campaigns? Select all that apply.
- Which KPI measures unique exposures from the start of a campaign?
- Which metrics are most appropriate for measuring the awareness stage campaigns?
- Which of the following best illustrates a strategic use of Amazon Ads solutions to address multiple stages of the customers’ journey?
- Which of the following is a key benefit of using Ads Planner for audience insights?
- Which of the following is NOT a category of custom audiences offered by Amazon Ads?
- Which of the following is required to use Ads Planner?
- Which type of audience solution uses Amazon browsing, streaming, and shopping signals?
- You manage advertising for a smart home device company. Your goal is to reach customers while they're actively engaging with similar technology in their homes. Which advertising solution would best align with your goals?
- You're an advertiser planning a campaign to promote your brand's sustainable home appliances. How would Ads Planner's audience insights benefit your campaign planning?
Amazon Ads Campaign Planning Certification Assessment All exam questions
- Adaeze is an advertiser at an athletic wear company promoting a new women's running shoe. She used audience insights to determine that shoppers most likely to engage with her brand were married women, so she tailored her creative to best reach this audience. Which audience insight did she use to learn this?
- Ads that appear on Fire TV may be best suited for which type of campaign goal?
- Advertisers focusing on a short-term business goal, like driving sales, should be reaching audiences in which stages of the decision journey?
- Alify has worked with Amazon to create a campaign that uses an Easter egg for unique shopping queries. For which of the following goals is this strategy LEAST likely to be effective?
- Amelie is setting up a link-out campaign for her client, a brand that sells home goods. The campaign's ad mentions a 25% off coupon for new customers. What should Amelie consider in order to promote a positive customer experience?
- Caren is planning an ad campaign aimed at retaining her brand's existing customers. Which solution would she use to drive loyalty through Subscribe & Save messaging?
- Chukwudi wants to understand when his brand's customers are most likely to buy so that he can do a homepage takeover on a day that shoppers are most likely to purchase his products. Which audience insight would help him find this information?
- Darci is reviewing an overlap for her brand and notes that one of the overlapping audiences has a size of 4. What does this indicate?
- HealthyByte wants to engage "healthy lifestyle" customers. They've determined that there are three core audiences that are likely to respond differently to different creatives. Which ad solution should HealthyByte consider using to effectively reach all three audiences?
- How can an advertiser use Amazon on box ads?
- Jaqueline used the audience planning tool to uncover an opportunity to engage shoppers that have shown purchase intent in her products but did not purchase. Which of the following approaches would you suggest to Jaqueline?
- Juan is looking to drive product discoverability for a new product during key research moments in the customer journey. Which of the following solutions best fits this use case?
- Nino is an advertiser for an apparel company that sells both men's and women's clothing. How might Nino best use audience insights to see how his brand performs in each category?
- Out-of-home (OOH) executions may be best suited for which type of goal?
- Select all that apply: Amazon Brand Analytics can help you understand…
- True or false? Advertisers of brands that do not sell on Amazon can leverage Amazon's industry-specific insights that can be used to make ads more relevant to customers.
- True or false? Amazon custom landing pages must be developed by the advertiser's creative team.
- True or false? An always-on strategy may help advertisers experiment during slow periods so they can uncover best practices to perform better during peak time.
- True or false? Customers tend to mostly shop during peak times, so campaigns should be limited to these specific peak periods.
- True or false? It's best to maximize the number of clicks a customer must take between the initial click of an ad and the end action, in order to obtain the most accurate conversion metrics.
- True or false? The audience planning tool can provide insights into how often an audience engages with a brand.
- True or false? The metrics in retail insights are ad attributed.
- Using the audience planning tool, Dae Woon has discovered an opportunity to engage audiences considering his brand but have not yet demonstrated purchase intent. Which of the following strategies would you recommend Dae Woon take in their next campaign?
- Wheelhouse, an advertising agency, wants to reengage shoppers who viewed one of their client's product pages but did not purchase. Which solution is best to reengage these shoppers?
- Which of the following options is the most useful strategy in reaching customers to achieve short-term goals?
- Which of these sponsored ad types is better suited for branding awareness campaigns?
- Which retail metric highlights how frequently an advertiser's products show up in organic widgets such as recommendations or "frequently bought together with"?
- Which sponsored ad is best suited to drive discoverability by helping to increase product visibility in shopping results and related product detail pages?
- Which type of campaign can help engage new customers and drive brand discovery?
Amazon Ads Foundations All exam questions
- A metric recommended for measuring loyalty goals is:
- A music store wants to understand the percentage of repeat customers to run a customized campaign. Which insight would be most useful to review to build a strategy around?
- A potential customer comes across a video of her favorite influencer using an organic skincare brand. She clicks the ad to learn more, explore the brand's website and signs up for their newsletter. What customer shopping journey stage does this scenario describe?
- A strategy to get the right shoppers to your store or website reflects the conversion stage of the customer shopping journey.
- Accent Athletics is running an ad to shoppers who recently considered products in the "golf shoes" category. What type of audience is Accent Athletics using to reach these shoppers?
- Accent Athletics recently launched a campaign and would like to measure the impact of ad tactics on shopping activities across retail outlets, while their campaign is still mid-flight. Which measurement solution should they use?
- Accent Athletics would like to run a campaign for "coffee lovers". Which audience type can they use to reach their ideal audience?
- Ad types like display ads, video ads, and audio ads are only available through Amazon owned and operated sites.
- Advertisers can use impressions as a metric to indicate success towards your conversion goals.
- Advertisers with a product or brand to promote can buy custom solutions, whether or not they sell products in the Amazon store.
- Amazon Ads campaigns can be delivered across formats, websites and devices where customers spend their time using Amazon DSP.
- Amazon Ads is available exclusively to advertisers in industries that involve retail sales.
- Amazon Ads metrics are unable to measure attributed ad impact wherever customers spend their time, such as on the advertiser’s website or through a measurement partner.
- Amazon Ads offers in-house creative services that cover creative strategy, creative optimization and editing, and net-new creative production.
- Amazon Ads offers media planning tools to help strategize with cross-channel planning solutions.
- Amazon DSP is a secure, privacy-safe, and cloud-based clean room solution, in which advertisers can easily perform analytics and build audiences across pseudonym i zed signals, including Amazon Ads signals as well as their own inputs.
- Amazon insights solutions like Omni channel Metrics and Amazon Brand Lift are fueled by insights from Amazon Shopper Panel.
- Amazon Publisher Direct is a channel available for ad placement on Amazon Ads.
- AMC is currently available for which of the following ad types?
- An advertiser selling cleaning supplies learns that there is a spike in purchases on Sundays. They decide to run a Brand Store homepage takeover on a Sunday to help capitalize on this purchase behavior. Which audience insight is reflected in this scenario?
- An automotive manufacturer wants to drive awareness for their new, large SUV, and want to reach an audience that is more likely to be interested in purchasing a family-sized car. Which of the following options should they choose when creating the audience for their campaign?
- Ana wants to increase purchases for her health food products by engaging audiences that have recently considered products in the vegan category. Which audience type should Ana use to achieve this?
- Ana wants to run a campaign to audio publishers around the world. Which ad channel should she use?
- Ana would like insight into how alternative marketing channels, like social, video, display, and email, impact shopping activity and sales performance on Amazon.com. Which Amazon Ads measurement solutions can she use?
- Audience insights is a report that provides non-ad-attributed metrics to help advertisers understand the halo effects from an advertising campaign.
- _______ audiences are based on regularly demonstrated shopping interactions reflective of broad interest groups.
- _______ audiences are pre-built audiences based on composition, shopping interactions, and preferences that indicate potential interest in your products or services.
- Audiences based on shopping interactions are built from which of the following shopping interactions?
- Campaign reporting insights reported on Amazon Ads include both industry standard metrics and Amazon.com proprietary metrics.
- Cloud Air wishes to incorporate customers who have taken frequent flights within the last year into their future Amazon Ads campaigns. Which insight and planning tool can help them achieve this?
- Custom ads are served on Amazon DSP.
- Detail page views and product review page views are measured at which stage of the customer shopping journey?
- During her recent campaign period, Sofía found that some audiences made their second or third purchase and decided to check the number of repeat purchases. Which goal is she measuring?
- ______ gives marketers insight into how their non-Amazon marketing channels across search, social, video, display, and email impact shopping activity and sales performance on Amazon.com.
- Gordon’s Chocolate wants to reach shoppers on Amazon.com with similar attributes as the brand's existing audience from web sales last holiday season. What type of audience can they engage to achieve this?
- ______ help advertisers benchmark against industry norms or conduct side-by-side comparisons to other media investments.
- ______ helps advertisers navigate a brand’s seller account and grow their business on Amazon.com with helpful tools and content, all from one convenient dashboard.
- How do Amazon Ads measurement solutions help advertisers?
- Imagine a customer has just discovered your brand, explored products, and made a purchase. What would be the appropriate action to nurture loyalty in this scenario?
- Industry standard metrics, such as click through rate, return on ad spend, and detail page view rate, are considered what type of metrics?
- Iris is a large corporate retailer who sells disposable cameras. What type of advertiser would Iris be considered?
- Iris, a disposable camera company, recently used social media campaigns to drive traffic to their Brand Store. Which stage of the customer shopping journey is most impacted by using this strategy?
- ______ is a free way for brands to feature their product portfolio and tell their brand story to educate and build long-term relationships with shoppers.
- _______ is a measurement and analytics solution that provides a way for advertisers to measure the aggregated, total impact of their ad tactics on shopping activities on Amazon.com or third-party websites, while campaigns are still mid-flight.
- ______ is a secure, privacy-safe, and cloud-based clean room solution, in which advertisers can easily perform analytics across pseudonym i zed signals, including Amazon Ads events as well as their own event tables.
- ______ is a self-service advertising solution designed for brands of any size to reach and inspire audiences where they watch content.
- _______ is a tool that allows you to auto generate customizable assets to feature a tailored background, logo, headline, or other copy.
- _______ is a tool that uses generative models and an advertiser's product information to create unique brand-themed product images in seconds.
- ______ is an Amazon Ads solution that allows advertisers to pro grammatically buy ads to help reach new and existing audiences where they spend their time.
- ______ is an audience planning tool that allows you to incorporate your own audiences into your Amazon Ads campaigns by onboarding directly into Amazon DSP.
- ______ is an opt-in, invitation-only program where participants can earn monthly rewards by sharing receipts from purchases made outside of Amazon.com, completing short surveys, and enabling ad verification for ads they see.
- Jane wants to run a campaign to reach readers of news and books. Which of the following options would be a channel to reach her desired audience?
- Jane wants to run ads on Alexa in-home devices. What type of ads should Jane run?
- Kitchen Smart is looking to understand the incremental impact of their offline sales. Which of the following solutions should they use?
- Kitchen Smart wants to understand how their Amazon Ads campaigns impacts traffic on their website. Which measurement solution can they use to gain this insight?
- Kitchen Smart would like to create a video for a Sponsored Brands campaign that copies details and images from their current product detail page. Which tool or service can Kitchen Smart use to achieve this?
- Li is an advertiser at a pharmaceutical company selling cold and flu medicine. She wants to compare product views across various geographical locations. Which audience type should Li use?
- Li is the owner of a boutique marketing agency that manages Amazon Ads campaigns for creatives. What type of advertiser would Li be considered?
- Li manages ad strategy at a pet supply company. He is interested in understanding the nature of his audience, such as the income or age range, on Amazon.com. Which insights would be most useful for him to review and craft the advertising strategy?
- Li would like to create a video asset for his recent campaign. He wants to augment his brand's existing video assets and feature brand elements like ratings and product details. Which of the following tools can he use?
- Li would like to reach viewers on streaming services like Freevee and Twitch. Which type of ad should Li use?
- Maria is an advertiser at a computer hardware company. Her company recently began selling their products on Amazon.com, and wants to reach shoppers with similar attributes to those that her brand has a direct relationship with. Which type of audience should Maria leverage in her next campaign?
- Maria runs a business selling cellphone cases using Brand Stores. What type of advertiser is Maria?
- Martha, a campaign manager, seeks a measurement and analytics solution to track the collective impact of her ad tactics on shopping activities during her client's recent product launch while campaigns are mid-flight. Which analytics solution is suitable for her needs?
- Mary is in charge of ad strategy at a hardware company. She wants to understand the time of day when her audience is most likely to purchase her brand’s products. Which insights would be useful for her to review to craft the advertising strategy?
- Metrics in the ______ stage help advertisers understand how their ads are driving customers to find out more information about their product.
- ______ metrics show the number of customers exposed to the ad, as well as the total number of exposures.
- Metrics such as the number of impressions served, how many unique customers were reached, and the click-through rate are related to which stage of the customer shopping journey?
- Overlap reports help advertisers to see overlap of audiences across their brand portfolio.
- Overlapping audiences enables advertisers to learn more about audiences on Amazon.com and discover new audiences that share common insights with a selected audience.
- Parents between the age of 30-35 is an example of which type of audience?
- Paulo is an advertiser whose company recently released a new mic stand that is designed to hold microphones that the company manufactures. He wants to focus this campaign on past microphone purchasers. Which audience combination would you recommend Paulo use to reach relevant audiences for his campaign?
- ______ refers to the knowledge, perception, and familiarity shoppers have of a brand.
- Repeat purchases, return on ad spend, percent of new-to-brand customers, and number of reviews are metrics related to which stage the customer shopping journey?
- Sophia runs a Brand Store that sells vintage apparel. She wants to launch a campaign that helps make her product and brand story more memorable. Sophia's campaign should be aligned with an awareness objective.
- Sponsored ads are managed on which of the following self-service tools?
- Sponsored Products ads are modified to be used through the Twitch channel.
- Taking action online to visit a product page or some other destination reflects which of the following advertising goals?
- The ______ allows advertisers to pass insights from other sources such as retail purchases, call centers, CRM, or mobile events.
- The ______ consolidates customer insights from various sources, providing a unified view of customers to create custom advertiser audiences.
- The cross-channel planner can help advertisers manage budget allocation and test their audience reach hypothesis to confirm or change their initial beliefs based on new insights.
- The ______ is a media planning solution which empowers advertisers to create full-funnel media plans across audience touch points on Amazon.com - including sponsored ads, display, online video, Streaming TV, audio and other places customers spend their time.
- The ______ measurement solution is reported when campaigns are in-flight and refreshed on a daily basis, allowing for advertisers to make mid-flight optimization s.
- The recommended metrics for analyzing building awareness are: impressions, viewable impressions, unique reach and frequency, and brand search.
- The Sofia Martinez agency is planning their media buying for next year to optimize their media mix and drive increased ROI. Which of the following solutions should they use?
- The ______ stage of the customer shopping journey involves a customer taking action towards a purchase.
- The ______ stage of the customer shopping journey involves driving traffic to a webpage for customers to take an action online.
- Utilizing audience planning solutions to analyze customer demographics and behaviors can help an advertiser create campaigns that will connect with their ideal audience.
- Video ads and display ads can be delivered through which of the following gaming and live streaming service marketing channels?
- Wang wants to run a campaign featuring video ads to audiences who enjoy gaming and live streaming service. Which ad channel should she use?
- What are Sponsored Products?
- What distinguishes Sponsored Brands ads from Sponsored Products ads?
- What do lifestyle audiences help advertisers to do?
- What insights can advertisers gain from utilizing planning solutions and tools?
- What is the objective of ensuring that your brand is the first choice for customers?
- What is the primary objective of awareness goals in ad campaigns?
- What is the primary purpose of advertisers leveraging planning solutions and tools in their ad campaigns?
- What is the primary purpose of Amazon Ads measurement solutions?
- What is the primary purpose of Sponsored Brands?
- What is the value proposition of the Site Visitation third-party measurement solution?
- What type of ads are delivered through Amazon Music?
- What type of content can be used for guiding potential customers in evaluating product options during the consideration stage?
- What type of study measures relative impact of different sources of advertising over time?
- When advertising, how do loyalty-based objectives differ from consideration-based objectives?
- Where do Sponsored Brands ads primarily show up?
- Which ad type helps to drive brand discovery among customers searching for similar products in relevant shopping results?
- Which ad type is suited for promoting a single product with a customizable message?
- Which audience solution includes audiences based on active website visitors, customers who are part of a loyalty program, and sales leads generated in the past 30 days?
- Which customer shopping journey stage is associated with boosting brand sales and growing business sales?
- Which of the following ad placements allows you to bridge your online and offline marketing through branded experiences and custom campaigns?
- Which of the following ad products allows advertisers to educate and inspire customers with real-time brand interaction through streaming?
- Which of the following ad types are cost-per-click (CPC) ads that promote individual product listings in the Amazon store and select premium apps and websites.
- Which of the following ad types help brands connect with viewers on streaming services like Freevee and Twitch?
- Which of the following ad types would be used in Whole Foods?
- Which of the following ad types would be used on IMDb?
- Which of the following advertising solutions compares brand-specific insights with existing market research?
- Which of the following Amazon Ads solutions can showcase your brand and products in a multipage, immersive shopping experience?
- Which of the following audiences based on shopping interactions can be used by an advertiser to either re-sell, cross-sell, or up-sell products?
- Which of the following audiences can be built from advertisers’ existing audiences, and leverage machine-learning algorithms to help reach new audiences with similar characteristics?
- Which of the following audiences includes shoppers that recently viewed products in a specific category or sub-category?
- Which of the following brand shopping experiences are used to inspire, inform, and entertain customers with real-time brand interaction within produced shows?
- Which of the following campaign actions describes an advertiser with a conversion business goal?
- Which of the following campaign actions describes an advertiser with an awareness business goal?
- Which of the following describes a partner type of advertiser?
- Which of the following describes a small and medium-sized business type of advertiser?
- Which of the following describes an advertiser strategy with a loyalty business goal?
- Which of the following describes an enterprise type of advertiser?
- Which of the following describes audience insights?
- Which of the following describes overlap reports?
- Which of the following describes the customers most likely to encounter Sponsored Display ads?
- Which of the following examples would be an outcome of a loyalty-based advertising goal?
- Which of the following features are provided in the cross-channel planner?
- Which of the following is a benefit of advertising with Amazon Ads?
- Which of the following is a brand shopping experience channel available for ad placement?
- Which of the following is a channel available for ad placement of Amazon Ads?
- Which of the following is a measurement and analytics advertising solution?
- Which of the following is a pre-built standard audience type available with Amazon Ads?
- Which of the following is a self-service tool to manage Amazon Ads campaigns across Amazon.com, mobile apps, and other affiliated sites?
- Which of the following is an Amazon Ads technology advertising tool?
- Which of the following measurement solutions should advertisers running awareness and consideration campaigns with Amazon Ads use to obtain performance insights and inform actions?
- Which of the following metrics are generated from first-time customers and help advertisers understand ad-attributed purchases?
- Which of the following solutions is a free way for brands to feature their product portfolio and tell their brand story to educate and build long-term relationships with shoppers.
- Which of the following tools can an advertiser use to add custom AI-generated brand images to their Sponsored Brands campaign?
- Which of the following tools can an advertiser use to create a custom audience from people who recently visited their website homepage?
- Which stage of the customer shopping journey would an advertiser look at Subscribe & Save metrics?
- Which third-party measurement solutions can estimate the impact of various marketing tactics on sales and then forecast the impact of future sets of tactics?
- Which third-party measurement solutions can identify purchase lifts not on Amazon.com?
- Why do advertisers set loyalty goals?
- You have used Sponsored Brands to reach millions of customers to tell your brand story and differentiate your product. Which goals have you reached successfully?
Amazon Ads Foundations Certification All exam questions
- A brand wants to automatically create display ads that update with current pricing and promotions from their Amazon product pages. Which creative tool should they use?
- A brand wants to create a custom, experiential campaign across Prime Video, Twitch, and Fire TV. Which Amazon Ads service specializes in these innovative experiences?
- A brand wants to create video ads without existing video assets, using only their product images and detail page content. Which Amazon Ads creative tool would best meet their needs?
- A brand wants to understand potential audience reach and optimize budget allocation across different ad types. Which planning solution would best help achieve these goals?
- A skincare brand on Amazon has increasing site traffic and new customer sales, but declining customer lifetime value and product ratings. Which metrics would best inform changes to their strategy?
- A skincare brand selling in the Amazon store wants to improve customer retention and product satisfaction. Which metrics should they monitor to inform their strategy?
- Accent Athletics a global sports company, would like to promote a new launch of sports equipment products in their Amazon Brand Store. Which of the following ad types will help them to achieve this?
- Accent Athletics wants a measurement solution that quantifies key shopping engagements at each stage of the shopping journey. Which of the following measurement solutions can they use to achieve this?
- Accent Athletics wants to understand how their digital advertising in the Amazon store influences purchases in physical stores. Which measurement solution should they use?
- Accent Athletics would like to measure the impact of ad tactics on shopping activities across retail outlets, while campaigns are still mid-flight. Which of the following measurement solutions can they use to achieve this?
- Amazon Ads offers Ads Planner to help advertisers develop clear strategies before investing their advertising dollars.
- Amazon DSP is a secure, privacy-safe, and cloud-based clean room solution, in which advertisers can easily perform analytics and build audiences across pseudonymized signals, including Amazon Ads signals as well as their own inputs.
- Amazon insights solutions like Omnichannel Metrics and Amazon Brand Lift are fueled by insights from Amazon Shopper Panel.
- Amazon Marketing Cloud is currently available for which of the following ad types?
- An eco-friendly skincare brand wants to run display ads directly on premium third-party publisher sites. Which Amazon Ads solution provides direct access to these publishers?
- Ana wants to run an audio ad campaign to reach listeners across first-party and third-party streaming audio services worldwide. Which Amazon Ads channel should she use?
- Brand Stores can receive traffic from both social media and sponsored advertising campaigns.
- During her recent campaign period, Sofía found that some audiences made their second or third purchase and decided to check the number of repeat purchases. Which type of goal are they measuring?
- ______ helps advertisers understand which of their digital advertising efforts beyond Amazon.com successfully drive Amazon store sales and influence purchase decisions.
- Impressions and reach metrics are used to measure success in the awareness stage of the customer journey.
- Iris, a disposable camera company, recently used Twitch Ads to introduce new customers to their products, telling their brand story to a new audience. Which type of campaign is this?
- ______ is a device where customers can browse, buy, download, and read e-books, newspapers, and magazines.
- ______ is a secure, privacy-safe, and cloud-based clean room solution, in which advertisers can easily perform analytics across pseudonymized signals, including Amazon Ads events as well as their own event tables.
- ______ is an Amazon Ads solution that allows advertisers to programmatically buy ads to help reach new and existing audiences where they spend their time.
- ____ is an available Amazon Ads media channel that allows advertisers to deliver video and display ads through its gaming and live streaming service.
- Jane has written three best seller books and recently launched a campaign for her next book using Sponsored Products. What type of advertiser is Jane considered?
- Kitchen Smart wants to create a new video ad using their product detail page images and information. Which Amazon Ads creative tool should they use?
- Li wants to advertise to audiences who enjoy gaming and interactive livestreaming content on Twitch. Which ad formats does this streaming platform support?
- Li wishes to drive consideration amongst shoppers who have recently browsed for products in the air sports category. Which audience type would best help Li achieve this goal?
- Li would like to enhance his existing video ad with Amazon ratings and brand elements. Which of the following tools should he use?
- Li would like to reach viewers on Twitch. Which type of ad should Li use?
- Mateo sells sports equipment on Amazon.com and would like to create a series of customized videos as a part of his brand awareness campaign. Which creative self-service tool can he use to create these videos?
- Meredith is creating a Microsoft Audience Network campaign and is selecting images. Which of the following statements are Microsoft Audience Network image requirements that Meredith must adhere to? Select all that apply.
- Paulo's company just launched a new mic stand. It's designed to work with their existing microphones. He wants to reach past microphone purchasers in his campaign. Which audience combination would best reach these relevant customers?
- Sophia wants to promote their vintage apparel brand to shoppers that have not yet heard of the brand or its products. Sophia's campaign objective is awareness.
- The add-to-cart metric provides insight into which stage of the customer marketing journey?
- The _______ is a media planning solution that helps advertisers develop full-funnel strategies, understand audience opportunities, and optimize budget allocation across sponsored ads, display, streaming TV, and other channels where customers spend their time.
- The ______ measurement solution is reported when campaigns are in-flight and refreshed on a daily basis, allowing for advertisers to make mid-flight optimizations.
- What is the main focus of purchase or conversion advertising goals?
- What type of ads are delivered on Amazon Music?
- Which ad type promotes individual product listings on Amazon using a cost-per-click model?
- Which advertising solutions can drive traffic to a Brand Store on Amazon.com?
- Which Amazon Ads channel allows advertisers to reach audiences through interactive livestreams and gaming content?
- Which custom audience tool can be used to create new audiences using traffic from the advertisers' website?
- Which customer shopping journey stage focuses on turning customer interest into measurable purchasing actions?
- Which free Amazon Ads solution allows brands to create a multipage, immersive shopping experience with its own web address (Amazon.com/brandname)?
- Which metrics help advertisers measure how effectively their ads increase brand recognition among new audiences?
- Which of the following best describes where customers encounter display ads?
- Which of the following is an example of an industry standard success metric available when using Amazon Ads?
- Which of the following is not mentioned as a type of shopping interaction used to build custom audiences in Amazon Ads?
- Which of the following solutions provides a report featuring annual and quarterly views of audience sizing across the customer journey?
- Which self-service Amazon Ads tool allows advertisers to create and manage video ads, device ads, and audio ads?
Amazon Ads Retail All exam questions
- A(n) ______ is a planned and organized effort to release a new product for sale.
- Actions such as clicking through an ad to see more products offered by a brand, subscribing to a newsletter, or following a brand on social media are examples of customer engagement that promotes long term-brand recognition and loyalty.
- Adsol, an advertising agency, needs to confirm whether their client, Organique, is presenting the Featured Offer for a specific product. Where can Adsol find this information?
- Advertising agencies are allowed to create Seller Central accounts on behalf of their clients who sell on Amazon.com, if they are able to provide the correct documentation.
- Agency professionals must contact Amazon to request access to their clients' Seller Central accounts.
- All Amazon.com sellers must pay referral fees, which vary by product listing, in addition to selling plan fees.
- ____ allows U.S. based Prime members to shop directly from sellers’ online stores with fast, free delivery, a seamless checkout experience, and free returns on eligible orders.
- Amazon retail can help brands connect with customers and help guide their shopping experience from discovery to purchase.
- An Amazon.com seller wants to look for answers to queries on Seller Central. Where should they navigate to?
- Ana is checking their client's product detail page for retail readiness. Which of the following issues should be flagged as needing improvement to be considered retail ready?
- Athletica Shoes sells their inventory directly to Amazon, whereas Shoez owns their inventory and uses Amazon.com to list products for sale. Which company is an Amazon.com vendor?
- Customer engagement refers to the quality of the connection between brands and customers, as well as the relevance of the message and the inspiration it sparks in customers to take action.
- Fulfillment by Amazon shipments can be managed in the Inventory tab of Seller Central.
- How can the Product Opportunity Explorer tool help sellers prepare for a new product launch?
- How could an Amazon.com seller benefit from the information found under the Performance section of the navigation bar on Seller Central?
- How does Vendor Central use the information from the product catalog to help with business operations?
- If you have a product you want to sell that already exists on Amazon.com, it must match to an existing product detail page.
- If you’re adding a product that’s new to Amazon.com and does not match an existing product listing, you're required to have a Global Trade Item Number (GTIN).
- In order to be eligible to sell products through Vendor Central, products must have a registered trademark.
- In the Fulfillment by Amazon (FBA) model, sellers pay storage and fulfillment fees including; long-term storage fees, unplanned services fees, and returns processing fees.
- including multi-user accounts, an approval workflow, tax exemptions, and dedicated customer support is the correct answer Which of the following documentation is required and must be submitted to create a Seller Central account?
- ____ is a paid program for sellers where Amazon takes care of customer service on your behalf for your self-fulfilled orders.
- _______ is a tool that brands can use to launch email marketing campaigns to their followers on Amazon.com.
- ____ is Amazon.com's drop ship program, where vendors ship directly from their warehouse to the customers.
- Jane is a new seller on Amazon.com who wishes to keep monthly expenses low. They estimate to sell less than 40 products a month, and only needs access to basic listing and order management tools. Which selling plan should Jane choose?
- Jane runs a small business which sells a low volume of handmade blankets that are shipped to Amazon.com customers in custom packaging. Which of the following would be the best fulfillment solution for Jane's business?
- Jane wants to use the A+ Content Manager to add rich content to product detail pages. What section of Vendor Central should they navigate to?
- Jane, a seller on Amazon.com, delivers products to customers directly from their own warehouse. Jane wants their products to be visible when shoppers select the Prime filter during their search process. Which fulfillment option should Jane use?
- John is a current seller on Amazon.com who wishes to take advantage of additional protective measures that can help manage listings, report violations, and monitor progress of their protection stats. Which of the following programs could John use?
- Kitchen Smart is a vendor who has an agreement with Amazon.com to allocate a small part of their warehouse to be used as an Amazon.com fulfillment center to fulfill Amazon.com orders. Which vendor fulfillment program is Kitchen Smart apart of?
- Li is an Amazon.com seller and is getting ready to launch a new product on Amazon.com. Which tool or feature can they use to learn more about their customers?
- Li is an Amazon.com seller who wants to sell a product that already exists on Amazon.com. Which of the following options would be the correct way to list this product?
- Maria runs a boutique clothing store in New York, and showcases their in-store inventory on Amazon.com. Maria provides same-day delivery to customers by utilizing Amazon Flex Driver delivery partners. Which shipping or delivery solution is Maria using?
- Organique is a beauty company selling products on Amazon.com and uses their own resources to fulfill orders. Which of the following best describes Organique?
- Organique is a successful Amazon.com seller looking for a fulfillment solution that can help offload some of their current storage, shipping, and customer service responsibilities. Based on this information, which of the following fulfillment options should Organique select?
- Paulo recently launched a Sponsored Products campaign to help boost sales of a new product. The only product in the campaign has just lost the Featured Offer. How will this affect the campaign?
- Style, color, and size are examples of _____, when referring to products listed on Amazon.com
- The ____ program is a business opportunity for entrepreneurs to launch and operate their own package-delivery businesses.
- The ____ represents key insights that impact customer satisfaction including; first contact resolution rate, average response time, and customer service rating.
- Variable closing fees, FBA fees, Amazon Ads fees, high-volume listing fees, and refund administration fees are examples of what type of fees for Amazon.com sellers?
- Vendors should connect with their Amazon vendor manager to learn more about shipping and inventory solutions they may be eligible for.
- What is the Amazon.com version of a SKU (Stock Keeping Unit) that is used to identify unique products listed on Amazon.com?
- What is the minimum number of customer reviews a product should have to be considered retail ready?
- What is the name of the self-service portal that Amazon.com sellers use to create listings, manage orders, and correspond with customers?
- What type of access must be granted for an agency to be able to view and edit Store names as well as use the Stores builder tool within Seller Central?
- Where can a seller manage their weekend delivery times for their Amazon.com products?
- Where can Amazon.com sellers access Seller University?
- Where on Vendor Central can vendors update product costs?
- Which Amazon.com selling plan gives sellers access to advanced selling tools such as, inventory management, B2B, API integration s, and bulk listings?
- Which business component is managed by vendors in Vendor Central?
- Which of the following actions can sellers complete in Seller Central?
- Which of the following actions can vendors complete in Vendor Central?
- Which of the following correctly describes the benefits of Amazon Business to selling partners?
- Which of the following could be considered a challenge when launching a new product?
- Which of the following delivery options provides ultrafast delivery on groceries and household essentials?
- Which of the following describes why you should monitor the performance of your sales and advertising campaigns throughout the campaign, instead of waiting until the campaign is over?
- Which of the following factors should be considered by a seller when selecting an Amazon.com selling plan?
- Which of the following fulfillment solutions is available to vendors, rather than sellers, who sell on Amazon.com?
- Which of the following is a customer engagement tool available on Seller Central?
- Which of the following is a paid service that gives Amazon.com sellers access to a designated Amazon account manager?
- Which of the following is an Amazon retail solution that combines the convenience and value of Amazon.com with a business-relevant product selection to address the needs of businesses and organizations?
- Which of the following is true about a product that is considered retail ready?
- Which of the following last mile delivery options helps ensures delivery to a secure location?
- Which of the following programs provides sellers with the opportunity to sell to other businesses through Amazon.com using a specialized suite of tools and features to enable B2B selling?
- Which of the following sections in Vendor Central is where you can view and download sales, inventory, and demand forecast insights?
- Which of the following statements accurately describes the Amazon Business Seller Program?
- Which of the following tools can be used to identify and fix listing issues affecting discover ability, product detail page experience, and customer returns?
- Which of the following two options are available when adding product listings through Vendor Central?
- Which type of product variation includes unique product details in the product detail page title?
- Which type of selling partner must be invited to sell on Amazon.com?
- Which Vendor Central tab allows you to update bank account, tax detail, warehouse, and return addresses?
Amazon Ads Retail Certification All exam questions
- Retail insights can look back to compare insights from ___________ in the past.
- Shunsuke is an advertiser at a kitchen appliance company. He ran an awareness campaign to promote his brand’s award winning toaster. A few months after the campaign ended, he noticed that the baseline performance was overall higher on glance views and conversion rate across many of his products. What is this likely to mean?
- Which Amazon.com selling plan gives sellers access to advanced selling tools such as, inventory management, B2B, API integrations, and bulk listings?
- Which of the following fulfillment solutions are available to vendors selling on Amazon.com?
- Which of the following tools can be used to identify and fix listing issues affecting discoverability, product detail page experience, and customer returns?
amazon ads retail ENG version All exam questions
- ____allowsU.S.based Prime members to shop directly from sellers’online stores with fast,free delivery,a seamless checkout experience,and free returns on eligible orders.
- An a is checking their client's product detail page for retail readiness.Whichof the following issues should be flagged as needing improvement to be considered retail ready?
- AnAmazon.com seller wants to look for answers to queries on Seller Central. Where should they navigate to?
- Athletic a Shoes sells their inventory directly to Amazon,whereas Shoe z owns their inventory and uses Amazon.com to list products for sale.Which company is anAmazon.comvendor?
- How can Amazon.com vendors provide access to their advertising agency so that they could help manage sponsored ads campaigns and Stores?
- How could an Amazon.com seller benefit from the information found under the Performance section of the navigation baron Seller Central?
- In order to register in Amazon Brand Registry,a selling partner must have which of the following?
- ____is a paid program for sellers where Amazon takes care of customer service on your behalf for yourself-fulfilled orders.
- ______is a partnership between Amazon and local businesses to provide free and secure locations to deliver and pickup Amazon packages.
- _____lets you communicate with Amazon.com customers via email or Seller Central.The service uses encrypted email addresses for both customers and sellers and is the only approved method for communicating with customers on Amazon.com to complete orders or to respond to customer service questions.
- Maria is responsible for managing a system integration for their client who sells as a vendor on Amazon.com.Which platform will Maria need access to in order to manage their client's system integration?
- Organ i que is a beauty company selling products on Amazon.com and uses their own resources to fulfill orders.Which of the following best describes Organ i que?
- Paulo recently launched a Sponsored Products campaign to help boost sales of a newproduct.The only product in the campaign has just lost the Featured Offer. How will this affect the campaign?
- Richard is a seller on Amazon.com that wants to use the Product Opportunity Explorer to explore consumer demand for new product ideas.Which tab in Seller Central can this tool be found?
- The variation format that features a display of swatch images instead of a drop-down menu is known as a_____?
- ____uses the power of Amazon technology combined with brand insights to detect and help reduce counterfeits.
- Variable closing fees,FBAfees,Amazon Ads fees,high-volume listing fees,and refund administration fees are examples of what type of fees for Amazon.com sellers?
- What does it mean for a product to be considered retail ready?
- What is the Amazon.com version of aS KU(Stock Keeping Unit)that is used to identify unique products listed on Amazon.com?
- Which Amazon.com selling plan gives sellers access to advanced selling tools suchas,inventory management,B2B,API integration s,and bulk listings?
- Which component of Seller Central provides high-level insights into various aspects of your Amazon.com retail business,including summaries of recent orders or payments,performance metrics,and selling notifications?
- Which of the following components of retail readiness could negatively affect campaign performance?
- Which of the following could be considered a challenge when launching a new product?
- Which of the following delivery options provides ultra fast delivery on groceries and household essentials?
- Which of the following documentation is required and must be submitted to create a Seller Central account?
- Which of the following is a paid subscription service that gives customers access to additional services on Amazon.com such as fast,free shipping,and exclusive deals?
- Which of the following programs provides sellers with the opportunity to sell to other businesses through Amazon.com using a specialized suite of tools and features to enable B 2 B selling?
- Which of the following resources are available to Amazon.com sellers on Seller University?
- Which of the following tools can be used to identify and fix listing issues affecting discover ability,product detail page experience,and customer returns?
- Which type of selling partner sells products to Amazon directly,which are then sold by Amazon on Amazon.com?
Amazon Advanced Networking Specialty ANS-C01 Certification All exam questions
- A 100-node HPC cluster in a VPC performs many DNS queries for RDS, S3, and on-prem resources accessible via Direct Connect. The cluster can scale 5–7x during peak events. The company currently uses two EC2 instances as the VPC DNS servers that forward queries to the VPC resolver and to on-prem DNS. DNS queries from nodes to resolve RDS and S3 endpoints are failing. What architectural change provides the most scalable DNS solution?
- A bank's mobile stack runs in a VPC that uses only IPv4. The bank must integrate a third-party API that requires IPv6. The servers are in private subnets, must initiate all IPv6 connections, and must not accept IPv6 traffic from the public internet. IPv6 has been enabled for the VPC and private subnets. What configuration will provide the required IPv6 egress-only behavior?
- A banking firm has an application that must reach only specific public IP addresses from a VPC. A route table for the application's subnet has routes to those public IPs via an internet gateway. The engineer needs email alerts when someone adds a default route in that subnet's route table that points to the internet gateway. Which solution requires the LEAST implementation effort?
- A CloudFormation template must create a virtual private gateway, a customer gateway, a VPN connection, and static routes in a route table. During testing, the stack fails and CloudFormation rolls back. What should the network engineer do to fix the error?
- A company (TGW-C) has multiple VPCs in us-east-1 using CIDRs within 10.10.0.0/16 and a transit gateway TGW-C with ASN 64520. A partner has VPCs in us-east-1 using CIDRs within 172.16.0.0/16 and a transit gateway TGW-P with ASN 64530. The engineer must connect the company’s VPCs to the partner’s VPCs in us-east-1 with minimal changes to both networks. Which solution meets this requirement?
- A company accesses a SaaS application hosted behind an NLB via AWS PrivateLink (interface endpoint) from its VPC. After adding a new Availability Zone and new subnets, the engineer cannot create an interface VPC endpoint in the new AZ. What is the likely cause?
- A company acquired a competitor; both have VPCs in AWS and those VPCs have overlapping IP address ranges. Both VPCs must access an AWS Marketplace partner service. Which approach ensures the VPC-hosted services and the Marketplace partner service can interoperate despite the overlap?
- A company added a new private VIF to a new Direct Connect connection, but the VIF's state is DOWN even though the physical connection shows UP and RUNNING in the console. The customer router shows an ARP entry for the VLAN interface toward AWS. What is a likely cause for the private VIF being DOWN?
- A company built a private REST API in Amazon API Gateway that on-prem clients must call over an existing AWS Direct Connect link. The engineer wants clients to reach the API endpoint via private connectivity without deploying additional infrastructure. Which option allows invoking the API without extra infrastructure?
- A company configured an AWS Cloud WAN core network with edge locations in us-east-1 and us-west-1. Each edge has two segments: development and staging, both using the default core network policy. A development VPC (10.0.0.0/16) is attached to the development segment in us-east-1; a staging VPC (10.5.0.0/16) is attached to the staging segment in us-west-1. Both VPC route tables send 0.0.0.0/0 to the core network. The team cannot get the two VPCs to communicate through the Cloud WAN; security groups and NACLs are not blocking traffic. What must the team do to enable communication between these VPCs via the core network?
- A company connects AWS Regions with transit gateways but two EC2 instances in different Regions cannot communicate. A network engineer must troubleshoot the connectivity. Which steps should the engineer take?
- A company currently encrypts traffic between an on-premises site and a single VPC using Site-to-Site VPN over two 1 Gbps Direct Connect links with public VIFs. The company will add 15 more VPCs in the same Region and needs the same encryption level for each on-prem to VPC connection. The new connections must not use public IP addresses and bandwidth per VPN will remain below the current provisioned speeds. Which combination of steps provides the required functionality with the least operational overhead? (Choose three.)
- A company deployed a web application on EC2 instances behind an Application Load Balancer (ALB) in an Auto Scaling group. Enterprise customers worldwide will use the app; their employees connect via HTTPS from office locations. Those corporate firewalls only allow outbound traffic to approved IP addresses. Employees must access the app with minimal latency. What infrastructure change should the network engineer make?
- A company deployed AWS Client VPN so remote users can reach resources in multiple peered VPCs and the on-premises datacenter. The Client VPN endpoint route table contains only 0.0.0.0/0. The endpoint’s security group has no inbound rules and a single outbound rule permitting all traffic to 0.0.0.0/0. Several remote users report web search results are showing incorrect geographic location data for them. Which combination of steps should a network engineer take to fix this with the LEAST service disruption? (Choose three.)
- A company deployed AWS Cloud WAN with a single edge location in us-east-1. The Cloud WAN configuration includes a production segment and a security segment, plus the default core network policy. The company created a production VPC (attached to the production segment) and an outbound inspection VPC (attached to the security segment). An AWS Network Firewall in the outbound inspection VPC inspects internet-bound traffic. The production VPC route table sends all internet-bound traffic to the Cloud WAN core network, and the outbound inspection VPC route table routes traffic through the Network Firewall. An EC2 instance in the production VPC cannot access the internet. Network Firewall rules are not blocking the traffic. Which combination of actions will resolve the issue? (Choose two.)
- A company deployed stateful IDS instances across three Availability Zones in a shared services VPC for traffic inspection of VPC-to-VPC traffic that flows through a transit gateway. After configuring transit gateway associations and routes, some test VPCs experienced intermittent cross–Availability Zone connections. What change should a network engineer make to fix this issue?
- A company deploys a web app into two AWS Regions. Each Region has one VPC with three EC2 web servers behind an Application Load Balancer (ALB). The company already has a Route 53 hosted zone for example.com. Users will use app.example.com. The DNS solution must route global users to the Region with the lowest response time and fail over to the next-lowest-region if the primary Region is unavailable. Which Route 53 configuration meets these requirements?
- A company deploys an application across five VPCs attached to a transit gateway. Instances in each VPC must be able to register dynamically to receive multicast streams. How should a network engineer configure AWS resources to support dynamic multicast registration and delivery?
- A company has 10 EC2 web servers in a production VPC and 10 web servers in an on-prem data center. They have a 10 Gbps Direct Connect between the data center and the production VPC. The data center uses 10.100.0.0/20. The company needs a load-balancing solution that accepts HTTPS from thousands of internet users and distributes requests across both cloud and on-prem servers. Sessions must stick to the same web server for their duration regardless of server location. Which solution satisfies these requirements?
- A company has 10 web-server EC2 instances in an Auto Scaling group in a production VPC and 10 web servers on-premises. A 10 Gbps Direct Connect links the data center to the VPC. The solution must accept HTTPS from thousands of external users and distribute sessions across both AWS and on-prem servers. Each HTTPS request must stick to the same backend server for the entire session regardless of server location. Which design satisfies these requirements?
- A company has a 1 Gbps Direct Connect link between its on-premises site and AWS. An on-prem application needs encrypted, private-IP communication with an application in a VPC. The traffic must not traverse the public internet. Which solution provides the required connectivity with the LEAST operational overhead?
- A company has a 2 Gbps Direct Connect hosted connection to a VPC in ap-southeast-2 and has added a 5 Gbps hosted connection from a different Direct Connect location in the same Region. The hosted connections terminate on different routers in the office with an iBGP session between those routers. The engineer wants the VPC to prefer the 5 Gbps connection for sending traffic to the office and fail over to the 2 Gbps connection only if the 5 Gbps link fails. Which approach satisfies this?
- A company has a Direct Connect connection from a US on-prem data center to a transit gateway in us-east-1 using a transit VIF. A new Europe data center in England will connect to workloads in a VPC in eu-west-2 using Direct Connect. The company needs full connectivity between the data centers and Regions with the lowest latency. How should the network be designed?
- A company has a Direct Connect private virtual interface (VIF) tied to a Direct Connect gateway from its US on-premises data center. After adding a new European data center with its own Direct Connect connection and private VIF attached to the same Direct Connect gateway, the company wants to enable Direct Connect SiteLink so the two data centers have a private inter-site network. What is the most operationally efficient way to do this?
- A company has a Direct Connect transit VIF to a transit gateway in the Europe (Paris) Region, and private workloads in VPCs attached to that transit gateway. The company acquired offices in Tokyo and needs to migrate those workloads to AWS in the Asia Pacific (Tokyo) Region within 5 days. The migrated workloads must be private (not internet-accessible) and must be able to access the Paris workloads. The Tokyo office must also be connected to the Paris data center. Which steps should the network engineer take to meet these requirements quickly?
- A company has a hybrid cloud with Direct Connect to AWS. VPCs are connected in a hub-and-spoke model via transit gateway and use a transit VIF with a Direct Connect gateway. The company uses a hybrid DNS model with Route 53 Resolver endpoints in the hub VPC for bidirectional DNS. A backend application in a VPC consumes messages via Amazon SQS over a private network. The network engineer wants an interface VPC endpoint for SQS that is reachable from on premises and from multiple VPCs. Which combination of steps should the engineer take so client applications can resolve DNS for the interface endpoint? (Choose three.)
- A company has a Production account and a Connectivity account. The transit gateway is in the Connectivity account and the auto-accept shared attachments feature is disabled. A network engineer must connect the Production VPC to the transit gateway. What sequence of steps should be performed across the accounts to accomplish this?
- A company has a VPC with a Site-to-Site VPN to on premises and uses the default DHCP options set. An application on an Amazon Linux 2 EC2 instance must retrieve an RDS secret from Secrets Manager via a private VPC endpoint and must also call an internal on-premises REST API at https://api.example.internal. Two on-premises Windows DNS servers perform internal resolution. The EC2 instance can reach the on-premises API by IP address but not by the hostname. What should a network engineer do to fix this and prevent the issue for other VPC resources?
- A company has an application deployed in two Regions with one VPC per Region (non-overlapping private CIDRs). The company needs to connect both VPCs to a single on-premises data center for testing. The application can use up to 800 Mbps. Which design provides the required connectivity with the least operational overhead?
- A company has an application VPC and a networking VPC peered together. The networking VPC hosts a Network Load Balancer (NLB). EC2 instances in the application VPC are targets for the NLB. A third VPC is peered to the networking VPC and contains a new version of the application running on EC2 instances in a different Availability Zone. How can the company allow the NLB to reach the new application instances? (Choose three.)
- A company has an AWS Direct Connect private virtual interface attached to a link aggregation group (LAG) consisting of two 10 Gbps links. A new security requirement mandates layer 2 encryption for external connections, and the network team plans to enable MACsec on Direct Connect to satisfy the requirement. Which set of actions should the network team perform to implement MACsec? (Choose three.)
- A company has an internal website behind an internal ALB in a VPC with CIDR 172.31.0.0/16. A Route 53 private hosted zone for example.com exists in that VPC. The company uses a Site-to-Site VPN between its office network and the VPC. Employees must access the internal site from the office using https://example.com. Which combination of steps will enable this? (Choose two.)
- A company has BU-1 and BU-2 business units. Each BU has two VPCs in us-east-1 and one VPC in ap-south-1. Resources must communicate within the same BU but must be isolated from other BUs. The company will add more BUs and expand into additional Regions. Which design meets these requirements with the highest operational efficiency?
- A company has deployed AWS Network Firewall in a VPC and needs to deliver Network Firewall flow logs to an Amazon OpenSearch Service cluster with the lowest possible latency. Which solution meets this requirement?
- A company has five VPCs in us-east-1. An internal web app runs in us-east-1. VPC-A must connect to an external partner's AWS environment in the same Region; the partner's VPC is VPC-B. Both VPC-A and VPC-B use the same IP range, so the company's EC2 instances in VPC-A cannot directly reach the partner's application. The solution must not disrupt either party's existing environment. Which two actions should the network engineer take? (Choose two.)
- A company has hundreds of application VPCs plus a shared-services VPC in a single Region and a VPN connection to on premises. Requirements: application VPCs must be isolated from each other; application VPCs need bidirectional traffic to on premises and to the shared-services VPC. The transit gateway was created with default route table association and propagation disabled. The engineer created VPC and VPN attachments and must now meet all requirements using the fewest transit gateway route tables. Which combination of actions achieves this? (Choose two.)
- A company has hundreds of VPCs that access public endpoints for Amazon S3 and AWS Systems Manager via NAT gateways. All traffic to S3 and Systems Manager flows through those NAT gateways. The network engineer must centralize access to these services and remove the need to use public endpoints, with the least operational overhead. Which solution achieves this?
- A company has hybrid connectivity between VPCs and its on-premises datacenter. The on-premises DNS server hosts the on-premises.example.com subdomain. The AWS workloads use aws.example.com across multiple VPCs and accounts. Resources in both locations can reach each other by IP, but the company wants workloads in the VPCs to resolve on-premises resources by their on-premises.example.com names. Which approach provides this with the MINIMUM operational overhead?
- A company has more than 50 AWS accounts across five Regions and wants simplified centralized security management using AWS Firewall Manager. The organization in AWS Organizations is created with all features enabled. Which combination of next steps should the company take to meet the requirement to manage firewall rules across all accounts? (Choose three.)
- A company has multiple business units that each run applications in separate AWS accounts and application VPCs in the same Region. Those applications must consume data from a central shared services VPC. The company requires granular security controls and an architecture that can scale as more business units connect to the shared services VPC. Which solution is the most secure and scalable?
- A company has multiple IPv4 Site-to-Site VPNs using virtual private gateways between its on-premises environment and several VPCs. Internal applications are experiencing high latency on the VPN paths. What solution will resolve the excessive latency?
- A company has multiple VPCs including a shared-services VPC and several application VPCs. All VPCs already have connectivity to on-premises DNS servers. Applications in the application VPCs must resolve on-premises internal domains, local VPC names, and domains hosted in Route 53 private hosted zones. What should a network engineer implement to meet these requirements?
- A company has one VPC in us-east-1 and plans a new VPC in us-east-2. The existing VPC has a Site-to-Site VPN to on-premises using a virtual private gateway. The engineer must link the existing VPC and the new VPC and add IPv6 support for the new VPC so new on-premises resources can connect to VPC resources over IPv6. Which solution meets these needs?
- A company has public EC2 application servers, each with an Elastic IP, and must perform firewall inspection on all internet traffic before it reaches the instances. A Gateway Load Balancer (GLB) and firewall fleet are deployed in a separate VPC. How should the network engineer modify the environment so internet traffic traverses the firewall fleet?
- A company has remote users who will move to Amazon WorkSpaces. WorkSpaces run in VPC A in the company's account. A network engineer wants to provide security visibility by inserting two firewall appliances behind a Gateway Load Balancer (GWLB). The engineer creates another account with VPC B and deploys the two firewall appliances in separate AZs in VPC B. What steps should the engineer take to configure network connectivity for this setup?
- A company has replaced an old TCP-based application-layer protocol with a new TCP-based protocol that uses different ports. After migrating dozens of EC2 instances and containers over several months, the team wants to confirm no remaining systems still use the old port. The verification must cause no downtime. Which approach meets this requirement?
- A company has stateful security appliances deployed in multiple AZs inside a centralized shared services VPC. A transit gateway attaches application VPCs and the shared services VPC. Application workloads run in private subnets across multiple AZs. The stateful appliances inspect all east–west VPC-to-VPC traffic. Users report that traffic between workloads in different Availability Zones is being dropped. ICMP pings between workloads across AZs fail. Security groups, appliance configs, and network ACLs are ruled out. What is causing the dropped traffic?
- A company has three VPCs in one AWS Region, each with 15 EC2 instances and no inter-VPC connectivity. A new application will deploy across all three VPCs and needs high bandwidth between nodes. Which approach provides the HIGHEST throughput between the VPCs?
- A company has three VPCs: production, nonproduction, and shared-services. Both production and nonproduction VPCs must be able to communicate with the shared-services VPC, but production and nonproduction must not communicate with each other. A transit gateway is used for connectivity. Which transit gateway route table configuration will enforce these requirements?
- A company has two AWS Direct Connect links: one terminating in us-east-1 and one in af-south-1. The company exchanges routes with AWS over BGP. How should BGP be configured so that the af-south-1 link acts as the backup (secondary) path to AWS?
- A company has two business units (BUs) with VPCs in us-east-1 and us-west-1. Each Region currently uses a transit gateway, and the regional transit gateways are peered. The company will add more Regions and BUs, and some BUs must be isolated from others. Which architecture provides the required isolation and scales with the least operational overhead?
- A company has two domain controllers in a shared-services VPC placed in private subnets. They are deploying a new application to a new VPC in the same account on a Windows Server EC2 instance that must join the domain hosted in the shared-services VPC. A Transit Gateway is attached to both VPCs and route tables on the Transit Gateway and in both VPCs have been updated. Security groups on the domain controllers and on the new instance permit only the ports required for domain traffic. The instance cannot join the domain. Which two steps will help diagnose the problem with the least operational effort?
- A company has two on-premises data centers: one in the us-east-1 Region and the other in us-east-2. Each data center connects to its nearest Direct Connect location. The company uses Direct Connect connections, transit VIFs, and a single Direct Connect gateway to provide connectivity to VPCs in us-east-1 and us-east-2. The data centers also have a private telecom link between them, but that link has experienced frequent disruptions. How can the company improve reliability between the two data centers?
- A company has two redundant active-passive AWS Direct Connect connections between its VPC workloads and on-premises data center. After an outage on one Direct Connect connection, failover to the secondary took more than a minute. The company wants failover to occur in seconds. Which change will produce the LARGEST reduction in BGP failover time?
- A company has two VPCs: VPC A (192.168.0.0/16) and VPC B (10.0.0.0/16) in separate Regions. Remote users outside the office need encrypted internet access to applications in both VPCs. The solution should minimize management overhead. Which combination of steps should the engineer implement? (Choose three.)
- A company has VPCs across 50 AWS accounts in an AWS Organization and needs to implement consistent web filtering using AWS Network Firewall. The filtering requirements are the same for all VPCs. The network engineer wants to minimize how many firewall policies and rule groups must be created. Which combination of steps will meet these requirements? (Choose three.)
- A company has VPCs and a transit gateway in us-east-1 that are connected to a Direct Connect gateway providing private connectivity to a US data center. The company opened a London office and will create VPC workloads in eu-west-2. London users must have private access to us-east-1 workloads, and the US data center must have access to workloads in eu-west-2. The solution should be flexible for growth and minimize operational effort. Which design meets these requirements with the least operational work?
- A company has VPCs in us-east-1 connected via a transit gateway. A network engineer is configuring an AWS Direct Connect to the transit gateway for a workload migration. The Direct Connect ConnectionState metric is UP, but the virtual interface (VIF) is DOWN. The on-prem router BGP and transit VIF settings appear correct, yet the engineer cannot ping the Amazon peer IP. Which combination of actions should the engineer take to troubleshoot? (Select three.)
- A company hosts an internal web application on EC2 instances in a private subnet behind a Network Load Balancer (NLB). The instances are in an Auto Scaling group and the application is accessed via a VPN to the on-premises network. After a SQL injection incident, a network engineer must implement controls to prevent SQL injection attacks going forward. Which combination of actions will address this? (Choose three.)
- A company hosts infrastructure services in multiple VPCs across multiple accounts in us-west-2. The VPC CIDR blocks do not overlap. The company needs encrypted Site-to-Site VPN connections from its data centers, with each data center routing to the closest AWS edge location. The solution must be highly available and support automatic failover. Which design meets these requirements?
- A company in early AWS adoption runs an application on-premises in Asia and needs new applications in us-east-1 to connect to that datacenter. The channel must reduce latency, avoid transcontinental public internet routing performance issues, and encrypt data in transit. Which solution can be deployed in the LEAST amount of time?
- A company is building a service that requires end-to-end encryption in transit so traffic is not decrypted between the client and the service backend. The service uses gRPC over TCP port 443 and must support thousands of concurrent connections. The backend runs on an Amazon EKS cluster with the Kubernetes Cluster Autoscaler and Horizontal Pod Autoscaler enabled. Mutual TLS is required for two-way authentication between clients and the backend. Which solution satisfies these requirements?
- A company is building an application where IoT devices send measurements to AWS. The app will have millions of users. The IoT devices cannot perform DNS resolution. The company needs an EC2 Auto Scaling setup so devices can reach an application endpoint without relying on DNS. What is the most cost-effective solution?
- A company is building new ecommerce features that use multiple microservices, each exposed on different paths. The microservices run on Amazon ECS. All public websites must use HTTPS. The application also requires the original client source IP addresses. Which load balancing approach should the network engineer implement to satisfy these requirements? (Choose two.)
- A company is deploying a highly available web server behind a load balancer that must route requests to multiple target groups based on the request URL. All traffic must be HTTPS and TLS must be terminated at the load balancer. The web servers need the client's IP address for accurate logging. Which design meets these requirements?
- A company is deploying a stateless web application on EC2 instances in private subnets behind an Application Load Balancer (ALB). The web app instances run in an Auto Scaling group. A separate stateful management application runs on EC2 in another Auto Scaling group. The company wants to use the same URL, hostname, port, and protocol for both applications, with the management app accessible under the path prefix /management. Access to the management interface must be limited to the company's on-premises IP ranges. An ACM SSL/TLS certificate will protect the web app. Which two actions should a network engineer take to satisfy these requirements? (Choose two.)
- A company is deploying AWS Cloud WAN with edges in us-east-1 and ap-southeast-2. There are segments for development, production, and shared services at each edge. Many VPCs will be attached to the core network and must land in the correct segment. The network team will tag attachments with Environment=`<segment name>`. The production segment in us-east-1 must require acceptance for attachment requests; all other attachments must not require acceptance. What rule configuration meets this requirement?
- A company is deploying third-party firewall appliances for traffic inspection and NAT inside its VPC, which has both public and private subnets. The firewalls must be placed behind a load balancer. Which design is the most cost-effective while meeting these requirements?
- A company is hosting an internet-facing app on Amazon EKS using the Amazon VPC CNI plugin for pod networking. They need to expose the app via a Network Load Balancer (NLB) and ensure pods see the original source IP from packets the NLB receives. How should the NLB and EKS service be configured to satisfy this?
- A company is implementing a hub-and-spoke design that uses a Gateway Load Balancer (GWLB) and GWLB endpoints. The hub contains the GWLB and virtual appliances; spoke VPCs have internet gateways. Which of the following sequences correctly describes the traffic path from an application in a spoke VPC to the internet?
- A company is migrating a containerized app. An ingress VPC has an NLB that sends traffic to front-end pods in an EKS cluster. The front end directs users to one of 10 services VPCs, each of which uses an NLB to distribute to service pods in EKS. The company expects over 10 TB/month of data transfer from the ingress VPC to services VPCs and wants the lowest-cost design for VPC-to-VPC communication. Which design meets the requirements at the LOWEST cost?
- A company is migrating a record-keeping app to AWS. All traffic between on-premises and AWS must be encrypted at every transit device during migration. The app will run across multiple AZs in one Region and use existing 10 Gbps Direct Connect dedicated links with MACsec-capable ports. A network engineer must secure the Direct Connect link at every transit device. They created a Connection Key Name and Connectivity Association Key (CKN/CAK) pair. Which additional steps should the engineer take? (Choose two.)
- A company is migrating an application from its on-premises datacenter to AWS. The application will run on Amazon EC2 instances inside a single VPC. During the three-month migration window, the EC2 instances must resolve hostnames for on-premises servers; after the migration, on-premises name resolution will no longer be required. Which approach requires the least configuration to meet these needs?
- A company is migrating an application to a new AWS account in a single Region. The app runs on EC2 instances in private subnets across multiple Availability Zones. Users connect via HTTPS from browsers. Inbound traffic must be balanced across AZs and instances, and all connections from the same client session must go to the same EC2 instance. The company also requires end-to-end encryption using the application SSL certificate. Which design meets these requirements?
- A company is migrating apps from a data center to AWS. Many apps must exchange data with an on-premises mainframe and require peak throughput of 4 Gbps. The design must be highly available and survive loss of circuits or routers. Which deployment meets these goals?
- A company is migrating to AWS using a Transit Gateway hub-and-spoke design. Its on-premises MPLS network enforces segmentation using MPLS VPNs with VRF separation. Two 10 Gbps Direct Connect links provide resilient, high-speed connectivity. The security team needs to replicate the MPLS VRF segmentation in AWS, supporting overlapping address spaces for multiple MPLS VPNs and minimizing operational overhead. Which solution meets these requirements with the least ongoing operational effort?
- A company is moving its on-premises network from a Virginia data center to a New York data center. Both the Virginia and New York Direct Connect locations are in the us-east-1 Region. The company must move a private VIF on an existing Direct Connect hosted connection from Virginia to New York. On premises accesses VPCs through a Direct Connect gateway in us-east-1. A new Direct Connect hosted connection has already been ordered for the New York location. Which approach will accomplish this with the MINIMUM downtime?
- A company is replacing internet VPN links with dedicated AWS Direct Connect connections and requires that all traffic be encrypted in transit. Which combination of actions will satisfy this requirement? (Choose three.)
- A company maintains several AWS Site-to-Site VPNs between its on-premises customer gateway and a transit gateway. The application currently uses IPv4 over the VPNs. The VPC has been updated to dual-stack and the company wants new workloads to be IPv6-only. IPv6 traffic fails over the existing VPNs. Which approach provides IPv6 support with the least operational overhead?
- A company manages resources across VPCs in multiple AWS Regions and needs to use an internal domain suffix aws.example.com for those resources. What must the network engineer do to apply the aws.example.com DNS suffix across all resources?
- A company migrated an application to AWS using EC2 instances in an Auto Scaling group across multiple AZs. The application calls a third-party vendor data service over HTTPS that uses a static ACL to allow specific client IP addresses. The company has a working Direct Connect to on premises. The network engineer must design a solution so the scaled application can continue accessing the vendor service while minimizing the need to update the vendor's allow list. Which solution meets this requirement with the least ongoing changes to the vendor's allow list?
- A company must audit and log all outbound internet traffic originating in private subnets across multiple Regions and VPCs connected via Transit Gateway. They plan to use AWS Network Firewall and need full logging of all traffic for auditing and alerting. How should Network Firewall logging be configured to ensure complete capture of alerts and flows?
- A company must capture and log traffic for Nitro-based EC2 instances. The network team enabled VPC Traffic Mirroring to send mirrored traffic to a second Auto Scaling group of EC2 instances and put a Network Load Balancer (NLB) in front of those targets, but no mirrored traffic reaches the EC2 instances behind the NLB. How should the team configure traffic mirroring to use the NLB endpoint?
- A company must migrate both its DNS registrar and DNS hosting to Amazon Route 53 without any downtime. The current DNS provider cannot handle the website traffic. What migration plan allows the company to switch quickly with zero interruption?
- A company must send all network traffic to and from its EC2 instances to a centralized third-party EC2 appliance for content inspection to meet a new regulation. Which design satisfies this requirement?
- A company needs to analyze TCP traffic destined for the internet that originates from EC2 instances in a VPC using a NAT gateway. They must collect source and destination IPs, ports, and the first 8 bytes of TCP payload, and then store and analyze all the data. Which solution meets these requirements?
- A company needs to archive financial data from an on-premises data center to Amazon S3. The company connects on-premises to AWS using Direct Connect with a Direct Connect gateway and a transit gateway. The data must not traverse the public internet and must be encrypted in transit. Which solution satisfies these constraints?
- A company needs to block potential botnet command-and-control traffic originating from any Amazon EC2 instances in its AWS environment. Which solution will satisfy this requirement?
- A company needs to manage Amazon EC2 instances from the command line for both Linux and Windows hosts. The EC2 instances are in an environment without internet access. Role-based access control must be enforced for instance management. The company’s on-premises environment is standalone. Which approach meets these requirements with the least operational overhead?
- A company needs to temporarily scale out on-premises application capacity by deploying servers on EC2. The EC2 servers must share data with on-premises servers, must not be internet-accessible, and all internet-bound traffic must go through the on-premises firewall. The EC2 servers also need to access a third-party web application. Which network configuration satisfies these requirements?
- A company operates a workload in a single AWS VPC. The architecture includes several interface VPC endpoints for AWS services (for example, Amazon CloudWatch Logs and AWS KMS). All endpoints use the same security group, which is not attached to any other resources. A security review found the shared security group is overly permissive. The company wants to tighten the security group rules but must not break access from VPC resources to AWS services via the interface endpoints. Current security group rules are:
- A company operates public applications in the US and Europe using three transit gateways in us-west-2, us-east-1, and eu-central-1 that are fully meshed. The company accidentally removed the route to the eu-central-1 VPCs from the us-west-2 transit gateway route table and also removed the route to the us-west-2 VPCs from the eu-central-1 transit gateway route table. How can a network engineer detect this misconfiguration with the least operational overhead?
- A company operates workloads across multiple VPCs and must securely reach a workload in VPC-A from an on-premises data center. A network engineer created an AWS Site-to-Site VPN to a transit gateway and enabled dynamic routing; connectivity worked. VPC-A's owner later added an additional CIDR to VPC-A and launched workloads using that CIDR, but the on-premises network cannot reach those new workloads. The network engineer must restore connectivity and ensure future VPC CIDR additions do not break connectivity with the least operational effort. Which approach meets these requirements most efficiently?
- A company plans to host public websites on AWS with multiple tiers (web, application, database). They will use AWS Network Firewall, AWS WAF, and VPC security groups. Firewalls must be deployed into the correct VPCs, policies for Network Firewall and AWS WAF must be centrally manageable, and application teams should be able to manage their own security groups while preventing overly permissive rules. What is the most operationally efficient solution that meets these needs?
- A company plans to migrate critical workloads to EC2 over a new 10 Gbps Direct Connect connection that terminates on a VPC attached to a transit gateway. The migration requires encrypted paths between the on-premises data center and AWS and must provide the HIGHEST throughput. Which configuration meets these requirements?
- A company registers the public domain example.com in a central AWS account using Amazon Route 53. The company wants to host a subdomain, test.example.com, in a different AWS account to provide name resolution for EC2 instances in that account, without transferring the parent domain. An engineer creates a new Route 53 hosted zone for the subdomain in the second account. Which steps must the engineer perform to finish the setup? (Choose two.)
- A company requires that all public DNS queries use an on-premises DNS security solution, except AWS service endpoints accessed via VPC endpoints. What steps should a network engineer perform to implement this design? (Choose three.)
- A company runs a highly available, scalable application on EC2 instances that are managed by an Auto Scaling group. The network team is rolling out IPv6 support in stages. In the first stage, they enabled IPv6 on public dual-stack Network Load Balancers (NLBs) whose target groups point to the Auto Scaling groups of the application EC2 instances. During testing, IPv6 requests reach the NLBs but do not reach the backend servers. What is the root cause?
- A company runs a hybrid cloud and has multiple AWS accounts under AWS Organizations. The team needs a managed list of on-premises IPv4 hosts that are allowed to access AWS resources. The list must support version control and be shareable with all AWS accounts in the organization. Which solution meets these requirements?
- A company runs a software solution on EC2 instances in a cluster placement group. The application's UI is a single HTML page (1,024 bytes). The software also processes files larger than 1,024 MB and serves those files to clients on request. Files are shared with the Don't Fragment flag, and the EC2 instances' ENIs are configured for jumbo frames. The UI is always reachable from allowed source IPs regardless of whether clients are in a VPC, on the internet, or on premises. However, clients sometimes fail to receive requested files because the files do not travel successfully from the server to the clients. Which of the following could be root causes of these failures? (Choose two.)
- A company runs an application in us-east-1 behind an ALB that receives HTTPS requests from vending machines worldwide. They plan to use AWS Global Accelerator and program the accelerator's static IPs into the vending machines so the application is reachable only through the accelerator, not directly via the internet-facing ALB URL. Which configuration will enforce access only through the accelerator?
- A company runs an application on EC2 instances behind a Network Load Balancer (NLB). A solutions architect added instances in a second Availability Zone and registered them with the NLB target group, but the operations team sees traffic only going to instances in the original Availability Zone. What is the most operationally efficient way to fix this?
- A company runs an application on EC2 instances behind an Application Load Balancer (ALB) with the instances in an Auto Scaling group. To comply with security standards, the company must collect all application access details including response codes, request paths, latencies, and client IPs, and be able to query that data for performance analysis. Which solution satisfies these requirements?
- A company runs application servers on EC2 in separate VPCs connected by a transit gateway. Instances are in private subnets with routes to the transit gateway for internal and external traffic. External traffic is inspected by firewall devices in a VPC that handle IGW traffic. The team wants to increase the per-packet payload size between EC2 instances while keeping all traffic via the transit gateway. What should the network engineer recommend?
- A company runs BIND-based custom DNS servers in a central VPC to provide name resolution for VPCs across multiple AWS accounts in the same AWS Organization. All VPCs are attached to a transit gateway. The central BIND servers forward queries for an on-premises DNS domain to DNS servers in the on-premises data center. Each VPC has a DHCP options set that points to the custom DNS servers so all VPCs use them. Multiple development teams need to use Amazon EFS. One team created a new EFS file system but an EC2 instance cannot mount it because the instance cannot resolve fs-33444567d.efs.us-east-1.amazonaws.com. What combination of actions will allow development teams across the organization to mount EFS file systems? (Choose two.)
- A company runs business applications on AWS across 50 accounts, thousands of VPCs, and three Regions in the US and Europe. The network engineer must provide connectivity from an on-premises data center to those Regions, and enable VPC-to-VPC traffic between Regions. The company already has an AWS Direct Connect link available. A transit gateway was created in each Region and the transit gateways were configured as inter-Region peers. Which design will provide on-premises connectivity into the Regions and allow inter-VPC communication across Regions?
- A company runs multi-site hybrid infrastructure across the US and UK, with resources in us-east-1 and eu-west-2. Each Region uses a transit gateway to connect 15 VPCs. The company configured a transit gateway peering connection between Regions. Data centers are connected by a private WAN and exchange IP routes via iBGP. Each data center has a Direct Connect connection that terminates on a Direct Connect gateway and associates a transit VIF to the local transit gateway. Traffic normally follows the geographically shortest path, and cross-Region transfers should use the private WAN to reduce AWS costs. The transit gateway associations on the Direct Connect gateway currently advertise only local Region VPC prefixes. Routes to the other Region are learned via BGP from the other data center in original, non-aggregated form. Recently cross-Region transfers failed because of WAN issues. Modify routing so such interruptions do not cause outages, while preserving the original traffic routing goals when the network is healthy. Which changes should the engineer make? (Choose two.)
- A company runs production applications in multiple AWS accounts in us-east-1. Each application sits on EC2 instances in private subnets behind an ALB. The ALB allows inbound port 80 traffic only from partner network IP ranges. When a new partner is added, the partner CIDR must be added to the ALB security group in each account. The network engineer needs a centralized, operationally efficient way to manage partner CIDR ranges across accounts. Which solution is best?
- A company serves internet applications using a single Route 53 public hosted zone for its domain. A three-tier application is being redeveloped; frontend EC2 instances are in public subnets with Elastic IPs, and backend components are in private RFC1918 subnets. Application components must be able to resolve and reach each other inside the VPC using the same hostnames used on the public internet. The engineer must also allow for future DNS changes (new names or retired entries). Which combination of actions meets these needs? (Choose three.)
- A company uses a 1 Gbps Direct Connect link to connect AWS to its datacenter. Employees access an application in AWS; many remote workers also VPN to the datacenter. During business hours both remote and on-site users report slowness. The company will deploy an additional AWS application that will require about 20% more bandwidth and wants more resilient AWS connectivity on a limited budget. What is the most cost-effective change?
- A company uses a 4 Gbps Direct Connect dedicated connection (LAG) to connect to five VPCs in us-east-1. Each VPC uses its own private virtual interface (VIF) to the on-premises network. Users report slowness and the engineer notices spikes in throughput that saturate the Direct Connect for about an hour each business day. The company needs to identify which business unit causes the spike and resolve the saturation. Which approach meets these requirements?
- A company uses a shared AWS account for connectivity to on-premises data centers. Private internal web services run in multiple AWS accounts and are accessed by office employees using DNS names in an on-premises zone named example.internal. Registering a new AWS-hosted service currently requires a manual multi-team change to the internal DNS. The company wants service owners to be able to register their DNS records directly, with minimal configuration changes and low cost. Which combination of steps should the network engineer implement? (Choose three.)
- A company uses a single Direct Connect link to connect its on-premises network to multiple VPCs (each with its own private VIF and VLAN) in the same Region and account. They will soon exceed the VPC and private VIF limits for that connection. What is the most scalable way to add more VPCs with on-premises connectivity?
- A company uses a transit gateway to connect many VPCs. Changes to security groups, network ACLs, or route tables in a VPC have in the past caused loss of connectivity. When such changes occur, the company wants an automatic verification that connectivity between resources within a single VPC still works. Which solution accomplishes this?
- A company uses a transit gateway to connect multiple VPCs. The on-premises network lacks a static public IP. The team needs AWS-side initiation of VPN connections from AWS to on-prem for traffic destined to on-prem. Which combination of steps should be performed to establish Site-to-Site VPN between the transit gateway and the on-prem network? (Choose three.)
- A company uses Amazon Route 53 Resolver DNS Firewall in a VPC to block all domains except those on an allow list. They worry that if the DNS Firewall becomes unresponsive, VPC resources will be affected because DNS queries might not resolve. To preserve application SLAs, DNS queries must continue to resolve even when Route 53 Resolver does not get a response from the DNS Firewall. What configuration change should the network engineer make to satisfy this requirement?
- A company uses Amazon WorkSpaces across seven VPCs in different Regions. Their cloud SIEM must analyze DNS queries from the WorkSpaces to identify domains contacted. The SIEM supports both polling and pushing logs. What is the most cost-effective design to meet this requirement?
- A company uses an AWS Site-to-Site VPN from its on-premises data center to a virtual private gateway. Due to internet congestion, availability and performance across the internet are poor. The network engineer must reduce these issues as quickly as possible with minimal administrative effort. Which solution meets these constraints?
- A company uses AWS Cloud WAN with edge locations in us-east-1 and us-west-1. A shared services segment exists at both edges, and each shared segment has VPC attachments to each inspection VPC. Inspection VPCs run AWS Network Firewall to inspect WAN traffic. A new business-unit (BU) segment is created at the us-east-1 edge with three BU VPCs attached. Regulations require that BU VPCs must not communicate with one another and that all internet-bound traffic be inspected in the inspection VPC. VPC route tables already send internet-bound traffic to the Cloud WAN core. More BU VPCs will be added later and must follow the same rules. Which actions provide the most operational efficiency? (Choose two.)
- A company uses AWS Local Zones to extend workloads from a VPC in a single Region. The Local Zone workloads must have two-way communication with the Regional VPC workloads. Which approach is the MOST cost-effective?
- A company uses AWS Network Firewall to inspect traffic to and from the internet. They need to capture full metadata (source/destination IPs, protocol) and record all traffic flows and any DROP or ALERT actions taken by the firewall. The firewall endpoints and route tables are correctly placed so traffic flows through Network Firewall. How should the firewall be configured to meet these logging and metadata requirements?
- A company uses AWS Network Firewall to protect outbound traffic for many VPCs in one account. EC2 instances host applications and are tagged with their application name; instances run in Auto Scaling groups. A Network Firewall stateful rule group must stay current as instances scale up and down. Which approach requires the least implementation and administrative effort?
- A company uses CloudFront with an Application Load Balancer (ALB) origin. The network engineer must ensure that all inbound traffic to the ALB originates from CloudFront, and the enforcement must be done at the network layer rather than in the application. Which solution is the MOST operationally efficient way to meet this requirement?
- A company uses many application VPCs connected to on-premises via Site-to-Site VPN. The network team is migrating to a Transit Gateway and configured the transit gateway with ECMP. Two temporary test VPCs were attached and two new Site-to-Site VPNs to the transit gateway were created, but the team cannot reach 2.5 Gbps across the pair of VPNs. What steps should the team take to improve bandwidth and reduce congestion? (Choose three.)
- A company uses third-party firewall appliances on-premises and wants the same inline inspection model in AWS. There is one VPC with an internet gateway and a fleet of web servers in an Auto Scaling group. The security and network teams need inline inspection of all packets to and from the web servers, and the solution must scale as the firewall appliance fleet scales. Which combination of actions should the teams take? (Choose three.)
- A company uses Transit Gateway Connect and two SD-WAN virtual appliances to extend its SD-WAN to AWS. Company policy dictates that only one SD-WAN appliance should carry AWS-bound workload traffic at a time. How should routing be configured so only the primary appliance is preferred?
- A company uses transit gateways to route between its VPCs. Each transit gateway has one route table that contains attachments and routes for the VPCs in the same AWS Region. Each VPC route table currently includes routes to all other VPC CIDR blocks reachable through the transit gateways. Some VPCs route traffic to local NAT gateways. The company plans to create many new VPCs and needs the most operationally efficient method to add the new VPC CIDR ranges to every VPC route table. Which solution best satisfies this requirement?
- A company uses VPC IP Address Manager (IPAM) with a top-level 10.0.0.0/8 pool and per-account IPAM pools, and shares pools via AWS RAM. The network engineer must prevent users in each AWS account from creating new VPCs unless the CIDR is allocated from that account's IPAM pool, and also prevent associating CIDRs to existing VPCs unless from the account's IPAM pool. Which solution satisfies these requirements?
- A company will deploy many SD-WAN sites and needs an SD-WAN hub appliance in a VPC attached to an existing transit gateway. The design must support at least 5 Gbps throughput from the hub appliance to other VPCs on the transit gateway. Which configuration meets this requirement?
- A company will host a secure web application across multiple EC2 instances and has a Route 53 hosted zone for the application's domain. The company wants to protect the domain from DNS cache-poisoning and allow browsers to authenticate to the application using a trusted third party. Which combination of actions meets these goals?
- A company will migrate an internal application to AWS. The app will run on EC2 instances in a single VPC and users will access it from on-premises data centers over AWS VPN or AWS Direct Connect. Users must use private domain names reserved for use in AWS, and each EC2 instance must automatically fail over to another EC2 instance in the same AWS account and VPC. The DNS design must not expose the application to the internet. Which solution satisfies these requirements?
- A company will migrate from an on-premises datacenter to AWS in phases. The network engineer sets up a temporary Site-to-Site VPN terminating at a virtual private gateway while awaiting a 10 Gbps Direct Connect that the provider needs 3 months to provision. The engineer observes the VPN bandwidth is capped at 1.25 Gbps despite a capable customer gateway device. What should the engineer do to increase VPN throughput until Direct Connect is available?
- A company will remove a NAT gateway used by private subnets in a us-west-2 VPC. Instances in the private subnets use the unified Amazon CloudWatch agent. After removing the NAT gateway, CloudWatch agent traffic must continue to work. Which combination of steps should the network engineer implement? (Choose three.)
- A company will run a compute-heavy data processing application on AWS. The VPC must have no direct internet access and strict network controls. Data scientists transfer data from an on-premises data center over a Site-to-Site VPN. The on-premises network uses 172.31.0.0/20 and the application VPC uses 172.31.16.0/20. Data scientists can launch instances but cannot transfer data from on premises. VPC flow logs of a ping show denied or missing traffic entries. What change will allow the data scientists to transfer data from the on-premises network?
- A company with multiple accounts and VPCs connected through a Transit Gateway needs deep packet inspection (DPI) for any traffic leaving a VPC boundary. All inspected traffic and DPI actions must be logged centrally in a log account. Which design meets these needs while minimizing administrative overhead?
- A company with multiple accounts and VPCs in one Region must log all network traffic for EC2 and Amazon RDS, retain the logs for 12 months with infrequent access after 90 days, and include metadata fields such as vpc-id, subnet-id, and tcp-flags. Which lowest-cost solution meets these requirements?
- A company's data center connects to a single AWS Region through an AWS Direct Connect dedicated connection. The company has one VPC in that Region. Application logs are stored on-premises and must be retained for 7 years. The company decides to copy those logs to an Amazon S3 bucket. Which approach satisfies these requirements?
- A company's network engineer builds and tests VPC network designs in a development account. The company must track changes to network resources, enforce strict compliance with network security policies, and retain historical network configurations. Which solution satisfies these requirements?
- A consulting firm manages AWS accounts for customers. One customer needs intrusion prevention added without re-architecting. The customer's environment has five VPCs across two US Regions connected by VPC peering and they do not plan to add more VPCs in the next 2 years. The solution must be able to inspect unencrypted traffic. Which approach satisfies these requirements?
- A containerized application on Amazon ECS (Fargate) requires SSL-initiated connections, must accept private connectivity from other AWS accounts, and must scale predictably. Which design satisfies these requirements?
- A critical application runs on EC2 instances behind an Application Load Balancer and must always be reachable on port 443 from the public internet. An outage occurred after an incorrect change to an EC2 security group. The network engineer needs an automated way to verify connectivity from the internet to the EC2 instances whenever the security group changes and to notify when connectivity is affected. Which solution satisfies these requirements?
- A data center has a 10 Gbps Direct Connect dedicated connection in us-west-1 attached to a Direct Connect gateway. From the same location there are two private VIFs attached to the same Direct Connect gateway. VIF 1 advertises 172.16.0.0/16 with an AS_PATH of 65000. VIF 2 advertises 172.16.1.0/24 with an AS_PATH of 65000 65000 65000. For traffic whose destination is in 172.16.1.0/24, which VIF will AWS use to route the traffic to the data center?
- A European carmaker is migrating customer-facing services and an analytics platform from two on-premises data centers to AWS. The sites are 50 miles (80.4 km) apart and that separation must be preserved in the cloud, with failover between the two cloud locations. The company uses multiple AWS accounts and provisions resources in eu-west-3 and eu-central-1. It orders two resilient 1 Gbps fiber connections from a Direct Connect Partner in each Region. The network engineer must connect all VPCs across accounts and on-premises networks so services remain available from both Regions during network issues. Which design meets these constraints?
- A financial company must log and retain all internet service traffic from any host for two years. In development they use VPC Traffic Mirroring with a Network Load Balancer (NLB) as the mirror target and mirror traffic into another account. When deployed in production, not all traffic is mirrored and the loss appears random. Which explanations could cause some traffic not to be mirrored? (Choose two.)
- A global company is connecting its primary and secondary data centers and a VPC and needs to maximize resiliency and fault tolerance for connections. Required bandwidth must exceed 10 Gbps and the solution should be cost-effective. Which option meets these needs most economically?
- A global company runs applications in us-east-1 inside a VPC. A London office connects to that VPC using a virtual private gateway for a Site-to-Site VPN. The company has a transit gateway peered with the VPC and other departmental VPCs. London users experience latency when accessing the applications. What should a network engineer do to reduce latency?
- A global film company uploads large 8K video files to EC2 via Site-to-Site VPNs that terminate on a Transit Gateway with BGP. File sizes tripled but uploads now take ten times longer than before. Which recommendations should a network engineer make to reduce upload times? (Choose two.)
- A global firm wants private access from its on-premises data center to an Amazon S3 bucket in us-west-2 without using public IP addresses. The VPC in us-west-2 uses RFC 1918 addressing and is connected to the data center over AWS Direct Connect. Route 53 resolves names inside the VPC and local DNS servers handle on-premises name resolution. What approach lets the on-premises applications download S3 objects using only private addressing?
- A global news site uses CloudFront with a custom domain service.example.com and an ALB origin at service-alb.example.com. Backend EC2 Windows instances are in an Auto Scaling group behind the ALB. Security policy requires encryption in transit for the entire path from users to backend. Which combination of changes is required to meet this policy? (Choose three.)
- A government contractor must build a multi-account, multi-VPC environment where all inter-VPC traffic is transparently inspected by a third-party appliance. The customer requires AWS Transit Gateway, high availability across Availability Zones, automated failover, and no asymmetric routing through the inspection appliances. Which combination of actions is part of a solution that meets these constraints? (Choose two.)
- A healthcare company is moving workloads to AWS. All traffic to and from on-premises must be encrypted in transit, and all cloud traffic must be inspected before it leaves the cloud for on-premises or the internet. Parts of the workload will be internet-facing for patient appointment booking and must be protected from DDoS, including financial protection for services that might scale during an attack. Which combination of actions should the network engineer take to satisfy these requirements? (Choose three.)
- A hybrid company uses Direct Connect with a single Site-to-Site VPN backup and is migrating to IPv6 by moving to dual-stack. They require a backup connectivity option to always be present. Which combination of steps will migrate the data center connectivity to support IPv6 in the least time? (Choose two.)
- A hybrid environment uses a 10 Gbps Direct Connect dedicated connection with multiple private VIFs terminating in multiple VPCs. Regulations require encrypting all WAN traffic regardless of transport. The company needs encryption that does not reduce available bandwidth. Which option meets this requirement?
- A hybrid environment uses Direct Connect between the on-premises datacenter and AWS. On-prem resources use corp.example.com and VPC resources use a Route 53 private hosted zone aws.example.com. An open-source recursive resolver in a VPC forwards corp.example.com to the on-prem DNS resolver, and the on-prem resolver forwards aws.example.com to the VPC resolver. The company will replace the recursive resolver with Route 53 Resolver endpoints. Which steps should a network engineer perform? (Choose three.)
- A legacy data processing solution is moved to EC2 instances in private subnets within one VPC. The solution uses Amazon S3 for input and output data and DynamoDB for state. VPC flow logs are collected. The solution uses a single NAT gateway to reach the internet to register a license at a vendor hostname. The company found NAT gateway charges (USE2-NatGateway-Bytes) are higher than expected. What should the network engineer do to identify and fix the issue? (Choose two.)
- A logistics company has multiple VPCs in a Region connected through a transit gateway. Several on-prem offices connect to the transit gateway using Site-to-Site VPN over the internet; each office has one transit gateway VPN attachment and two tunnels in an active-passive setup. The offices use static routes on both the VPN and the customer gateway. The company wants to use both IPsec tunnels for each office simultaneously to maximize total VPN bandwidth. What design changes are needed to achieve this?
- A marketing firm uses a hybrid network with AWS Direct Connect and an SD-WAN overlay to link branch offices. Several VPCs connect to a third-party SD-WAN appliance transit VPC in the same AWS account using AWS Site-to-Site VPNs. The company plans to attach more VPCs to that SD-WAN appliance transit VPC but is running into scalability limits, route table constraints, and rising costs with the current design. A network engineer must propose a solution that resolves these problems and eliminates dependencies while requiring the LEAST operational overhead. Which approach satisfies these requirements?
- A multi-account environment has one account per microservice. Each microservice runs in its own VPC with EC2 instances behind an NLB. A shared services account will host an API Gateway HTTP API to expose microservices privately. Access must be private (no public endpoints) and the company must control which internal entities can connect. The design must allow adding more microservices later. Which is the MOST secure solution that satisfies these requirements?
- A multi-VPC environment connects via a transit gateway to an on-premises datacenter over a Direct Connect gateway and redundant transit VIFs. The company must get notified whenever a new route is advertised from on premises to AWS over Direct Connect. What should a network engineer implement to meet this requirement?
- A network engineer adds IPv6-only subnets and launches an IPv6-addressed EC2 instance in a test VPC. The instance cannot reach an IPv4-only internet service. The engineer needs to enable the IPv6 instance to communicate with the IPv4-only service. Which solution meets the need?
- A network engineer configured Amazon CloudWatch Internet Monitor for a VPC-hosted application to collect internet health, latency, and traffic insights. The engineer wants to forward Internet Monitor health events to a third-party endpoint with minimal implementation work. Which approach meets this requirement with the least effort?
- A network engineer configured Traffic Mirroring to help detect and troubleshoot network anomalies, but the mirrored traffic is saturating the Amazon EC2 instance acting as the mirror target. That EC2 instance runs security analysis tools. The engineer needs a highly available, scalable design to handle the mirrored traffic. Which solution satisfies these requirements?
- A network engineer created the following to connect two production VPCs in different Regions (Prod A in eu-west-1 with 10.0.0.0/16 and Prod B in eu-central-1 with 10.1.0.0/16): 1) one transit gateway in each Region, 2) shared and accepted the transit gateways with the production accounts, 3) created a peering attachment between the transit gateways, 4) attached each VPC to its Region's transit gateway, 5) created transit gateway route tables and associated attachments, 6) added static routes in each transit gateway route table to send traffic to the remote VPC, and 7) enabled route propagation on the VPC route tables. Connections from Prod A to Prod B failed. What should the engineer do to achieve the required connectivity?
- A network engineer is creating a launch template for an Auto Scaling group that will run a Linux network appliance. The appliance needs a primary network interface plus a second interface that uses a public IP (an Elastic IP from the company's BYOIP pool) for application traffic to/from the internet. Which approach implements this design?
- A network engineer is designing a hybrid DNS setup for an AWS workload. Individual teams must be able to manage application hostnames in their development environments. The solution must integrate those application-specific hostnames with centrally managed on-premises DNS names, provide bidirectional name resolution, and minimize management overhead. Which combination of actions should the engineer take? (Choose three.)
- A network engineer is designing an active–passive AWS connection from two on-prem data centers. Each site has a Direct Connect transit VIF to a Direct Connect gateway associated with a transit gateway. Traffic from AWS to the on-prem data centers must prefer the primary data center and only go to the failover site during an outage. Which configuration accomplishes this?
- A network engineer is designing hybrid connectivity using AWS Direct Connect and a Transit Gateway. A Transit Gateway is attached to a Direct Connect gateway and 19 VPCs in different accounts. Two new VPCs will be attached. The IP admin assigned 10.0.32.0/21 to the first new VPC and 10.0.40.0/21 to the second. The prefix list has room for only one more CIDR entry before reaching the quota. How should the engineer advertise AWS routes to on-premises while meeting these constraints?
- A network engineer is designing private DNS integration for AWS workloads and on-premises systems. Five VPCs in eu-west-1 connect to on-premises via Direct Connect and communicate through a Transit Gateway. Each VPC has a private hosted zone using aws.example.internal. The engineer created a Route 53 Resolver outbound endpoint in a shared services VPC attached to the Transit Gateway. DNS queries ending with aws.example.internal must resolve using the private hosted zone; all other domains must be forwarded to the on-premises DNS resolver. Which configuration satisfies these requirements?
- A network engineer is migrating from an on-premises data center to an AWS Control Tower multi-account environment. A Transit Gateway exists in a central network services account and is shared with the Organization using AWS RAM. A shared services account hosts workloads that must be available organization-wide. The engineer needs to automate creation of common network components: provision a VPC for application workloads in each new and existing member account and connect those VPCs to the Transit Gateway in the central account. Which combination of steps will achieve this with the least operational overhead? (Choose three.)
- A network engineer lowered the TTL of several records in a public hosted zone for example.com to 60 seconds. The engineer wants to verify whether this change increased the number of DNS queries to Route 53 beyond expected levels by obtaining the query count for the example.com hosted zone. Which approach provides that information?
- A network engineer must add an AWS Network Firewall to control internet-bound traffic in an existing environment that contains five VPCs. Each VPC has an internet gateway, NAT gateways, public ALBs, and EC2 instances in private subnets across two Availability Zones. The engineer must be able to write rules that consider the environment’s public IP addresses regardless of traffic direction, minimize changes to production, and ensure high availability. Which combination of steps should the engineer take? (Choose two.)
- A network engineer must deploy AWS Network Firewall into an existing environment that includes: a transit gateway with all VPCs attached; hundreds of application VPCs; a centralized egress internet VPC with a NAT gateway and an internet gateway; a centralized ingress internet VPC hosting public ALBs; and on-premises connectivity via a Direct Connect gateway. The application VPCs have workloads in private subnets and their route tables send 0.0.0.0/0 to the transit gateway. The firewall must inspect east-west (VPC-to-VPC) and north-south (internet and on-premises) traffic with Suricata-compatible rules. The solution should require minimal architectural changes. Which combination of steps should the engineer take? (Choose three.)
- A network engineer must list the IP addresses that are sending traffic to an EC2 instance. VPC Flow Logs are enabled. The instance has one network interface with two IP addresses, but the flow logs only show traffic for the primary address. How can the engineer find flow log records for traffic destined to the secondary IP address?
- A network engineer must provide dual-stack connectivity (IPv4 and IPv6) between the company office and an AWS account. The on-premises router and the VPC both support dual-stack. The company has two AWS Direct Connect circuits to the office. The connection must be highly available and reliable for latency-sensitive traffic. Which choices satisfy these requirements? (Choose two.)
- A network engineer must update a hybrid network to support IPv6 for a VPC-hosted application. The existing infrastructure (transit gateway, Direct Connect, Site-to-Site VPN) cannot be modified. The VPC is dual-stack and instances must be prevented from being directly reachable on their IPv6 addresses from the internet, while still allowing outbound internet access. What is the most operationally efficient solution?
- A network engineer set up a Site-to-Site VPN between on-premises and a VPC using a virtual private gateway. The tunnel is up, but during Phase 2 rekey the customer gateway device reports receiving parameters that don't match what it's configured to accept. The customer gateway is already configured with the strongest algorithms provided in the AWS VPN config. What should the engineer do to troubleshoot and resolve this?
- A network engineer uses AWS Direct Connect with MACsec to encrypt traffic between the data center and the Direct Connect location. The MACsec secret key may be compromised and must be replaced with a secure key. Which action meets this requirement?
- A network operations team must centrally manage a cloud networking environment for multiple teams. Each team needs to deploy and manage its own resources. The environment must support IPv4 and IPv6 (dual-stack) and provide dual-stack internet connectivity. The company has an AWS Organization with a workload account and the network engineer created a dedicated networking account. Which combination of steps should the network engineer perform next? (Choose three.)
- A new ALB target group is enabled for slow start. A team registers EC2 instances as targets but finds the targets do not enter slow start. What is the reason the targets never entered slow start?
- A new web app runs on ECS Fargate behind an ALB in us-east-1. Route 53 hosts the domain. Content is mostly static (images/files) and seldom updated. Most users are in the United States, with some traffic from Canada and Europe. The design must lower latency for users at minimal cost, and all traffic must be encrypted in transit until it reaches the ALB. Which design meets these needs?
- A product recommendation service runs in a VPC with CIDR 192.168.224.0/19, behind an NLB and Auto Scaling. The production environment is in a separate VPC with CIDR 192.168.128.0/17. The company must integrate the production environment with the recommendation service in 5 days with minimal disruption. Which solution meets this requirement with the least impact to existing environments?
- A public application uses an Application Load Balancer (ALB) with an EC2 instance target group. The company wants to protect the app from malicious web requests and ensure end-to-end encryption. Which configuration will meet these requirements?
- A real estate company has an internal app where agents upload photos and videos to S3, with metadata in DynamoDB. The S3 bucket publishes PUT events to an SQS queue; an EC2 compute cluster polls SQS, processes objects, updates DynamoDB, and replaces objects. The EC2 instances must not have public IPs. Which network design is the most cost-effective as usage grows?
- A retail environment has ALBs in public subnets with backend EC2 instances in private subnets that use a NAT gateway for outbound internet calls. NAT gateway costs have spiked and an engineer must investigate the traffic traversing the NAT gateway. Which options can be used to analyze NAT gateway traffic? (Choose two.)
- A retail firm is migrating its on-premises application to AWS. It has two on-prem data centers (east and west coasts), each with four databases (largest is 500 GB). The data centers sync over two 10 GbE circuits. Each data center has two separate 1 GbE internet upstream links. The plan is eight VPCs: four in us-east-1 and four in us-west-2. You must provide VPC-to-VPC connectivity and secure connectivity between on-prem data centers and AWS for the migration. Expect traffic spikes between VPCs during database synchronization. The migration should run over one weekend and start as soon as technically possible. Minimize long-term operational and staffing costs. Which combination of steps satisfies these requirements? (Choose two.)
- A retailer has a Direct Connect link between its datacenter and AWS in eu-west-2 where multiple VPCs are attached to a transit gateway. The retailer recently created resources in eu-central-1 in a single VPC. The engineer must connect the eu-central-1 resources to both the on-premises datacenter and to resources in eu-west-2 while minimizing changes to the existing Direct Connect. What should the engineer do?
- A SaaS application uses two redundant 10 Gbps Direct Connect links to a colocation and must start encrypting traffic between AWS and the colocation edge routers while keeping the same bandwidth. The colocation already has encryption to the on-prem network. The company wants the solution with the least operational overhead. What should a network engineer do?
- A SaaS provider migrated a private SaaS app to AWS. Hundreds of customers connect from multiple data centers using VPNs and complex NAT rules. After migration, AWS-based customers must access the SaaS app directly from their VPCs, while on-premises customers must continue using IPsec tunnels. Which design satisfies these needs?
- A SaaS provider runs its service on EC2 instances in a VPC. Customers also run in AWS, but their IP ranges overlap with the provider's VPC. Customers will not disclose their internal IP ranges and they do not want to connect over the public internet. Which combination of steps is part of a solution that satisfies these constraints? (Choose two.)
- A second AWS Direct Connect connection is added to an existing setup. A resiliency test shows a failover event causes a 90-second traffic interruption before the backup connection carries traffic. What change will shorten failover time?
- A security appliance running on an EC2 instance must inspect all outbound traffic from a VPC to the on-premises datacenter. The network engineer needs to improve network throughput between the on-premises datacenter and the security appliance. Which two actions should the engineer take? (Choose two.)
- A security team is auditing two applications deployed across two EKS clusters that use the Amazon VPC CNI. The clusters are in different subnets of the same VPC and use Cluster Autoscaler. The team needs to determine which pod IPs communicate with which services across the VPC, but wants to limit the number of flow logs and only collect traffic for the two applications. Which approach meets the requirements with the LEAST operational overhead?
- A single VPC has public and private subnets across two Availability Zones. Static website content (images) is stored in Amazon S3. Web servers are EC2 instances in private subnets, in an Auto Scaling group behind an ALB. The environment uses Direct Connect with a public VIF to access S3. A network engineer finds EC2-to-S3 traffic is traversing a NAT gateway, increasing costs as traffic scales. How should the engineer change connectivity to avoid NAT gateway charges for S3 traffic?
- A Site-to-Site VPN between a transit gateway and on-premises uses BGP over two tunnels with active/active ECMP on the transit gateway. Traffic from on-premises goes out over tunnel A, but the EC2 return traffic comes back over tunnel B and is dropped at the customer gateway. The engineer must fix this without lowering total VPN bandwidth. What should be done?
- A Site-to-Site VPN shows IKE sessions ending when application connectivity fails. What action should the network engineer take so that if the IKE session goes down it will come back up?
- A Site-to-Site VPN to a branch office terminates on a transit gateway and uses static routes. The transit gateway route table contains many static routes that point to specific branch-office subnets. The branch office later expands its subnet ranges and connectivity fails. Which approach minimizes future administrative work while addressing this issue?
- A startup's application team is deploying a new multi-tier app to AWS. The app will run on Amazon EC2 instances in an Auto Scaling group behind a public Network Load Balancer (NLB) and must support both UDP and TCP traffic. Initially it will serve users in one geographic area, but the team plans to expand to multiple AWS Regions so deployments can be placed closer to end users. They want to control how much traffic each Region receives during phased rollouts of new versions, and they must minimize first-byte latency and jitter for users. How should the team design the network architecture to meet these requirements?
- A third-party pricing service communicates with EC2 instances over UDP port 50000. Responses sometimes appear malformed. The vendor wants to capture request and response data for debugging by accessing an EC2 instance that talks to the pricing service, but the company forbids direct access to production and requires analysis in a separate monitoring account. Which sequence of actions meets these constraints and captures the data?
- A transit gateway in Account A is shared using AWS RAM so other accounts can connect VPCs in the same Region. Account B has a VPC (10.0.0.0/16) with subnets 10.0.0.0/24 (us-west-2a) and 10.0.1.0/24 (us-west-2b). Two new subnets were added: 10.0.2.0/24 (us-west-2b) and 10.0.3.0/24 (us-west-2c). All subnets use the same route table; the default route 0.0.0.0/0 points to the transit gateway. Resources in 10.0.2.0/24 can reach other VPCs, but resources in 10.0.3.0/24 cannot. What must the engineer do so resources in 10.0.3.0/24 can reach other VPCs?
- A transit gateway sends flow logs to a CloudWatch Logs group. A Lambda analyzes the logs and publishes SNS notifications when a VPC generates traffic the transit gateway drops. Each notification includes account ID, VPC ID, and dropped packet totals. A new Lambda subscribed to the SNS topic must automatically stop the identified traffic from leaving the originating VPC by applying a network ACL to the transit gateway attachment subnets in that VPC. Which approach satisfies this requirement?
- A two-tier web application will run in a new single-Region VPC with an internet gateway and four subnets (two public with IGW routes, two private without a default route). The app runs on EC2 instances behind an external Application Load Balancer and must not be directly reachable from the internet. The app uses an S3 bucket in the same Region for GET and PUT operations. Design a VPC architecture that minimizes data transfer costs while meeting these requirements. Which solution should the engineer choose?
- A US-based company adds a hub-and-spoke hub in eu-west-1 and connects it to an existing us-east-1 environment with a transit gateway peering connection. Each Region uses an inspection VPC with AWS Network Firewall to centralize inspection. To save cost, the engineer decides that inter-Region traffic should be inspected in the Region where the traffic originates and adjusts transit gateway route tables accordingly. Intra-Region communication works, but inter-Region traffic fails. What change will resolve the inter-Region connectivity issue?
- A US-based financial firm with two on-premises data centers in the same Region needs secure, highly available hybrid connectivity to AWS. The company requires reliable encrypted access from its corporate networks to private resources in AWS located in us-east-1 and us-west-2, and it wants to send large volumes of data to Amazon S3 over the same connection. Which combination of actions should the network team take to satisfy these requirements? (Choose two.)
- A VPC (VPC1) has a single NAT gateway in AZ1 that provides internet access for EC2 instances in private subnets across AZ1, AZ2, and AZ3. During an outage, the NAT gateway became unavailable and internet access failed. The engineer must remove this single point of failure and add built-in redundancy. Which design meets the requirement?
- A web app uses an ALB across multiple AZs with Lambda targets and CloudWatch metrics. Some users report parts of the app aren't loading. The engineer has enabled ALB access logging. What should the engineer do next to identify which errors the ALB is logging?
- A web application running on EC2 instances behind an ALB and fronted by CloudFront was attacked. An AWS WAF web ACL is associated with the CloudFront distribution. The company needs to analyze attacks detected by WAF using Amazon Athena. What solution will enable this analysis?
- A web application runs in eight AWS Regions, each behind an HTTPS-only ALB that uses an ACM certificate. Each Region uses a different domain today. The company wants to present a single new domain globally and minimize latency for end users. Which combination of actions will achieve this? (Choose three.)
- A web application runs on EC2 instances behind an Application Load Balancer (ALB), and the ALB is the origin for a CloudFront distribution. The company uses a custom authentication system that issues a token to authenticated customers. The application must ensure GET/POST requests come only from authenticated customers. Design the MOST operationally efficient solution that lets the web application identify authorized customers.
- A web application runs on EC2 instances in private subnets across three Availability Zones behind an ALB. SSL/TLS is terminated at the ALB using ACM certificates. In testing with a single instance everything worked, but after production deployment users can log in but each new web request restarts the login flow. What should the network engineer do to fix this?
- A web translation service runs on EC2 instances in an Auto Scaling group behind an ALB in private subnets. Some customers (each in their own AWS account) must be allowed access to the service, but it must not be open to all customers. The solution should require minimal operational overhead. Which combination of steps meets these requirements? (Choose two.)
- Account 1 has a production VPC (VPC-A) in eu-west-1 attached to TGW-A, which is connected to an on-premises data center in Dublin via a Direct Connect transit VIF and Direct Connect gateway. Account 2 has a staging VPC (VPC-B) attached to TGW-B in eu-west-2. A network engineer must provide connectivity from VPC-B to the on-premises data center in Dublin. Which solutions will achieve this? (Choose two.)
- After a network security breach, a company must collect and analyze ALB logs that include client IP, target IP, target port, and user agent for each request. What is the most operationally efficient way to gather and analyze these logs?
- After an attacker exploited an application vulnerability on an internet-facing EC2 instance and spread malware over the internet, the company fixed the app and replaced the instance. The company needs a low-operational-effort solution that detects when an application deployed on an EC2 instance is propagating malware. Which approach meets this requirement with the least operational overhead?
- After an IP exhaustion incident that impacted service capacity, a network engineer must implement monitoring of IP usage across multiple VPCs (each with subnets in multiple AZs) and receive alerts before incidents occur. Which approach gives the required monitoring with the least operational overhead?
- After migrating EC2 instances to private subnets and routing internet traffic via a NAT gateway, long-running database queries to a public third-party database complete on the database side after 7 minutes but the client never receives responses. Which configuration change should the engineer make to resolve this?
- After replacing self-managed NAT instances with a managed NAT gateway, users report connections to the application close after about 6 minutes of inactivity. What should the network engineer do to resolve this?
- An account has four VPCs in us-east-1: one development VPC and three production VPCs. On-premises connectivity is via Direct Connect and a Direct Connect gateway. Production VPCs may exchange traffic, but the development VPC must be isolated from production. A transit gateway was created with a single route table (default association and propagation disabled), and all VPCs plus the Direct Connect gateway were attached. Each VPC route table points 0.0.0.0/0 to the transit gateway. What steps should the engineer take next to enforce isolation while allowing on-premises connectivity? (Choose three.)
- An application front end communicates with backend instances through a Network Load Balancer (NLB) in the same VPC. The application spans two Availability Zones and must minimize inter-AZ traffic. Front-end traffic should remain in the same Availability Zone unless there is no healthy target in that AZ, in which case it should fail over to the other AZ. Which configuration satisfies these requirements?
- An application in a VPC uses a NAT gateway for outbound internet access. A network engineer observes a high volume of suspicious outbound traffic from the VPC to IP addresses on a deny list. The engineer needs to determine which AWS resources are producing that traffic while keeping costs and administrative effort low. Which approach satisfies these requirements?
- An application processes credit card numbers and requires field-level encryption so only some components can decrypt sensitive fields. The customer-facing app runs as an ECS service behind an ALB in us-west-2, and CloudFront uses that ALB as the origin. Certificates come from a third-party CA and HTTPS is in use. Which combination of actions meets the requirements?
- An application running on EC2 instances in an Auto Scaling group behind an Application Load Balancer became unavailable after a security group change. A network engineer must implement a mechanism that automatically remediates noncompliant security group changes to prevent this downtime from recurring. Which solution satisfies this requirement?
- An application running on-premises and on EC2 accesses an S3 bucket over the public internet. EC2 instances connect to on-prem via a Site-to-Site VPN. New regulations mandate that traffic between the application servers and S3 must remain private and avoid public IP addresses. Which solution meets the requirement most cost-effectively?
- An application runs on EC2 in a single VPC across two Availability Zones. A shared inspection VPC with a GWLB and a fleet of marketplace inspection instances inspects traffic between the VPC and the internet. To save cost, only one inspection instance was deployed in each AZ used by the application. During maintenance of an inspection instance, some application instances experience internet session timeouts and cannot establish new sessions. Which combination of changes will fix the problem? (Choose two.)
- An application stores PII and requires all connections over HTTPS using TLS certificates that use Elliptic Curve Cryptography (ECC). The application has stateful connections between the web tier and end users and runs on multiple instances. The engineer must offload TLS to a load balancer and meet these requirements. Which load-balancing solution should be used?
- An application team cannot launch new resources because a VPC has exhausted usable IP addresses. The VPC CIDR is 172.16.0.0/16. Which additional CIDR block can be associated with this VPC?
- An Australian ecommerce company hosts services in ap-southeast-2 with multiple VPCs attached to a transit gateway and plans to replicate the architecture to us-west-1. The company wants connectivity between applications in the two Regions that maximizes bandwidth, minimizes latency, and reduces operational overhead. Which solution meets these goals?
- An Availability Zone in a Region has exhausted its IP address allocation and currently uses 10.10.1.0/24. The VPC CIDR is 10.10.0.0/16 and there is available space such that 10.10.1.0/22 would fit within the VPC. Network configurations are managed via CloudFormation. What change will add additional IP addresses to the existing VPC with the least operational overhead?
- An ecommerce application runs on EC2 instances in an Auto Scaling group to handle variable customer demand. The company must distribute customer traffic to the instances and must ensure that traffic is encrypted end-to-end (no intermediate decryption). Which solution satisfies these requirements?
- An ecommerce company must enforce DNSSEC (data authentication and integrity) for all domain names hosted in Route 53 across four public hosted zones and include alerting. Which combination of steps will implement DNSSEC signing and validation and provide alerts? (Choose three.)
- An education agency hosts a private competition in AWS. Each participating school uses a known centrally managed IP addressing scheme. Schools access the competition over Site-to-Site VPNs using BGP. All traffic must be encrypted in transit, only authorized endpoints may connect, and school firewalls block ICMP. The agency needs a cost-effective way to notify schools when their connectivity fails so they can take corrective action on-premises. Which combination of measures satisfies these needs most economically? (Choose two.)
- An engineer launched an EC2 instance in a VPC private subnet (the VPC has no public subnet). The instance runs code that should send messages to an Amazon SQS queue, but the queue receives no messages. The subnet uses the default network ACL and the instance uses the default security group, with no changes. Which of the following could explain the issue? (Choose two.)
- An insurance company is migrating workloads from on-premises to AWS. They require end-to-end DNS resolution and bidirectional DNS between AWS and on-premises. Workloads will move into multiple VPCs over time and depend on each other. Which solution meets these needs?
- An international company that provides tsunami early warning will use global IoT devices to collect wave data and send it to AWS as quickly as possible. They have three operation centers, each with a Direct Connect connection to AWS and at least two upstream ISPs to the internet. The company owns provider-independent IP space. IoT devices use TCP and have both landline and mobile internet connectivity. The solution will span multiple AWS Regions and Route 53 will be used for DNS. Which design provides the HIGHEST availability for connectivity from IoT devices to AWS services?
- An international company will deploy VPCs in us-east-1 and eu-west-2 plus on-premises data centers in the US and UK. They plan two Direct Connect links (one in each country), transit gateways in each Region, Direct Connect gateways, and transit VIFs attaching the Direct Connect gateways to the transit gateways. Transit gateways will be peered. The design must make traffic follow the shortest geographic path so on-prem traffic uses the local Direct Connect when available, and must automatically fail over using the private WAN if a Direct Connect link fails (and vice versa). How should the engineer configure which prefixes are advertised on the transit VIFs to meet these requirements?
- An IoT company collects data from thousands of sensors in the United States and South Asia. The sensors send data over a proprietary UDP-based protocol to an Auto Scaling group of EC2 instances behind a Network Load Balancer in us-west-2. Occasionally sensor data from South Asia is lost on the internet and never reaches the EC2 instances. Which solutions will address the packet loss? (Choose two.)
- An IoT company has sensor modules worldwide that send MQTT data to on-premises MQTT brokers at hardcoded public IP addresses. After migrating the brokers to EC2 in AWS, the company must avoid reconfiguring deployed hardware and minimize latency for global customers. What should the company do next?
- An online global game currently serves players from servers in us-west-2 behind an Elastic Load Balancer. To reduce latency, the company will deploy game servers to 11 more AWS Regions. How should the network engineer configure Amazon Route 53 so that players are routed to the game servers that give the best responsiveness?
- An online retail company runs a web application in the us-west-2 Region and plans to expand into Europe. The application must deliver low latency globally, identify users' IP addresses to provide localized content, support HTTP GET and POST methods, and fail over between Regions based on health checks for both GET and POST. Failover must occur in under 1 minute for all clients. Which architecture meets these requirements?
- An organization has 30 VPCs: three AWS Regions each host 10 VPCs. Each Region’s VPCs are attached to that Region’s transit gateway, and the transit gateways are peered across Regions. The organization wants to use AWS Direct Connect from its on-premises site to reach only four VPCs across the three Regions. The company has already provisioned four Direct Connect connections at two Direct Connect locations. Which set of steps will satisfy the requirement most cost-effectively? (Choose three.)
- An organization runs a highly available application across multiple VPCs and two on-premises data centers. All VPCs are in the same AWS Region and must be able to exchange large file transfers (multiple gigabytes) with each other and with the on-premises data centers. You must design an AWS Direct Connect solution that connects the on-premises data centers to each VPC while minimizing operational overhead. Which architecture satisfies the requirements with the least operational effort?
- AnyCompany (on premises) acquired Example Corp (entirely in AWS). They connect via Direct Connect and Transit Gateway. Example Corp has an app across two AZs in a VPC (10.0.0.0/16) with no internet gateway and must reach an on-premises app through a restricted contiguous source IP block 10.1.0.0/24 for compliance. The engineer added 10.1.0.0/24 as a secondary CIDR to the VPC. What is the next step to implement a highly available solution that ensures outbound traffic uses the approved IP addresses?
- Company A has a hosted Direct Connect, a Direct Connect gateway, and a transit gateway in us-east-1. Company B (recently acquired) has multiple application VPCs attached to a transit gateway in us-west-2 in a single account. CIDRs do not overlap. Company A wants to use its existing Direct Connect connection to access Company B's applications from on premises. Which solution will satisfy this requirement?
- Data transfer between on-premises systems and EC2 instances in VPCs is being limited by the throughput of a single Site-to-Site VPN to an AWS Transit Gateway. The design needs to be highly available, secure, and scale VPN throughput from on premises to VPCs as traffic grows. Which design meets these requirements?
- Design a DNS architecture so AWS accounts can resolve on-premises names, on-premises systems can resolve AWS names, and individual accounts can manage subdomains. The solution should use AWS native services and a single set of rules that work across accounts. Which combination of steps should the engineer take? (Choose three.)
- Design a hybrid network to connect a corporate network to 30 VPCs across 3 Regions that must interconnect and have centralized firewall inspection using a security-approved firewall. AWS-to-corporate connectivity must provide at least 2 Gbps. Which architecture meets these requirements?
- Developers are prohibited from launching VPC network infrastructure. Whenever a NAT gateway is created, the network security team must immediately be alerted to terminate it. The solution should be easy to deploy across multiple AWS accounts, have minimal admin overhead, and provide an accessible compliance history. Which solution satisfies these requirements?
- Developers need to test a web application in the staging AWS account using publicly resolvable subdomains under the company domain example.com (which is hosted in a production account). Developers can manage Route 53 in staging but cannot access production resources. What combination of steps will let developers create records under example.com from the staging account? (Choose two.)
- EC2 instances in a company's VPC were previously contacting AWS services over the public internet. The company deployed AWS PrivateLink endpoints so traffic no longer goes over the internet, but after deployment the EC2 instances lost all connectivity to the required AWS services. Which combination of actions should a network engineer take to restore access to the AWS services? (Choose two.)
- EC2 instances in private subnets must initiate all outbound requests, including traffic to the on-premises datacenter over Direct Connect. No external resource must initiate connections to these EC2 instances. The on-premises customer gateway uses a stateful firewall that filters traffic for multiple VPCs, and the company prefers to use a single IP match on the firewall to allow all EC2 traffic. Which option meets the requirements with the least operational overhead?
- Infrastructure engineers must automate deployment of Application Load Balancer components with the AWS CDK so that stacks are reusable and consistent across multiple environments, Regions, and accounts. The target accounts are bootstrapped and core network components (VPCs and private Route 53 zones) already exist. Which combination of steps minimizes manual effort when deploying the ALB components across environments and Regions? (Choose two.)
- The company must move data between its VPC and an on-premises data center using a dedicated-bandwidth connection, and all in-transit data must be encrypted. The company has engaged an APN Partner to set up the connection. Which combination of steps satisfies these requirements? (Choose three.)
- The company wants to centralize management of interface VPC endpoints and Route 53 zones in a shared services account while using a Transit Gateway hub-and-spoke model across accounts. The network services team must manage all Route 53 zones and interface endpoints centrally, and provide private access to AWS KMS without traffic going over the public internet. What should the engineer implement to achieve this?
- The security team enabled DNS Security Extensions (DNSSEC) for the company’s domain in Amazon Route 53 and asks who is responsible for rotating the DNSSEC keys. What explanation should the network engineer give?
- To add protection for encrypted sessions at Application Load Balancers by ensuring a unique random session key (forward secrecy), what should a network engineer do?
- Two companies are merging and each has a substantial AWS footprint with multiple VPCs. Both use Direct Connect with a Direct Connect gateway, and each has a Transit Gateway plus multiple Site-to-Site VPNs from its Transit Gateway to on-premises. The new design must maximize network visibility, throughput, logging, and monitoring. Which architecture meets these goals?
- Two data centers are interconnected with redundant links and use addresses in the 172.16.0.0/16 range. They run iBGP between the data centers with a private ASN and an IGP. The company has one VPC in AWS and an existing Direct Connect from the first data center to a Direct Connect gateway using a private VIF; that connection advertises a summarized 172.16.0.0/16 route. A second summarized route will be advertised from the second data center via a different Direct Connect location. The requirement is to route traffic to and from AWS through the first Direct Connect path, using the second connection only as failover. Which approach satisfies this requirement?
- Two on-premises data centers each connect to a Direct Connect gateway through a dedicated private virtual interface. The first data center's router advertises 110 routes to the Direct Connect gateway via BGP; the second advertises 60 routes. The Direct Connect gateway attaches to a VPC through a virtual private gateway. Resources in the VPC are intermittently unreachable from both data centers. The VPC route table shows that routes from the first data center are not being populated. To fix this in the most operationally efficient way, what should the network engineer do?
- Two production VPCs (VPC A and VPC B) span all AZs in us-east-1. A new regulation requires all traffic between these production VPCs to be inspected. The company deployed a shared VPC with a stateful firewall and a transit gateway attachment across all VPCs so traffic between VPC A and VPC B routes through the firewall. During testing, the transit gateway drops traffic when it flows between two Availability Zones. What change should the network engineer make to fix this with the LEAST management overhead?
- You are designing a hybrid architecture using a 1 Gbps Direct Connect from the data center to two Regions (us-east-1 and eu-west-1). VPCs in us-east-1 connect via a transit gateway and must access on-prem databases. Policy allows only one eu-west-1 VPC to connect to a single on-prem server. The on-prem network segments traffic between the databases and that server. How should the Direct Connect be configured to meet these constraints?
- You must design an architecture for an HPC workload where EC2 instances require 10 Gbps flows and up to 100 Gbps aggregate throughput across many instances with low-latency communication. Which deployment optimizes this workload?
Amazon AI Practitioner AIF-C01 Certification All exam questions
- A bank fine-tuned a large language model to speed up loan approvals. An external audit found the model approves loans more quickly for one demographic than for others. What is the most cost-effective fix?
- A bank is building a Bedrock-powered chatbot that will answer account-opening questions using public bank documents. The team will use prompt engineering to shape model responses. Which prompt engineering technique fits this scenario?
- A bank is fine-tuning an LLM on Amazon Bedrock to answer customer loan questions. To ensure the model does not expose private customer information, which action should the bank take?
- A base model hosted on Amazon Bedrock is being prompted with 10 examples once per day and is performing well. The company wants to reduce monthly costs. Which action will lower costs while keeping the same base model?
- A business running multiple ML models wants to detect changes in model performance so it can address problems quickly. Which AWS feature satisfies this requirement?
- A chatbot built on an Amazon Bedrock foundation model searches a large corpus of research papers, but it performs poorly because of many specialized scientific terms. After prompt engineering, performance is still inadequate. What should the company do to improve the chatbot?
- A chatbot returns images in response to user queries and must avoid producing inappropriate or unwanted images. Which solution will help prevent unsuitable image outputs?
- A chatbot uses an Amazon Bedrock LLM for intent detection and the team plans to apply few-shot learning to improve intent classification. What additional data should they include in prompts to support few-shot intent detection?
- A company building a conversational agent wants to reduce the risk that an LLM will be manipulated by prompt attacks to do harmful things or reveal secrets. Which action helps mitigate that risk?
- A company building an editorial assistant has low usage in its pilot, cannot predict future traffic, and wants to minimize costs. Which deployment option best fits these constraints?
- A company building tutoring applications with large language models needs configurable, enforceable safety controls so the LLMs adhere to standard usage policies. Which solution provides these safeguards with the least development effort?
- A company builds a generative AI solution with Amazon Bedrock and needs integrated vector database storage plus vector search. Which AWS service provides those vector storage and search capabilities?
- A company built a chatbot with a chosen foundation model and needs the bot to answer technical questions in the company’s specific tone without human help. Which approach will help the model produce responses that match the company’s tone?
- A company built a generative text summarization model with Amazon Bedrock and wants to use Bedrock’s automatic model evaluation to measure the model’s accuracy. Which evaluation metric is most appropriate for assessing the quality of generated summaries?
- A company built a model to predict item prices. The model performed well on the training data but its performance dropped significantly after deployment. What should the company do to address this issue?
- A company built an AI-driven resume screening system using a large dataset that underrepresents some demographic groups. Which core responsible AI principle does this scenario illustrate?
- A company built an Amazon Bedrock AI assistant to suggest products, but its responses are often generic or irrelevant. Which prompt-engineering technique is most likely to improve the relevance of the assistant's replies?
- A company built an image classifier to detect plant diseases from leaf photos and wants to know the proportion of images the model labeled correctly. Which evaluation metric should they use?
- A company built custom computer vision models and needs a simple labeling interface to reduce mistakes when the models encounter new real-world data. Which AWS service or tool should they use?
- A company choosing a foundation model for Amazon Bedrock wants to know how much text or context can be included in a single prompt. Which factor determines that limit?
- A company collected new data and then created a correlation matrix, computed summary statistics, and produced visualizations to understand the data. Which stage of the machine learning workflow is this?
- A company collecting global images of insect bites—covering different genders, ethnicities, and regions—for training a mobile diagnostic app is following which responsible AI principle?
- A company collects internet speed measurements from remote regions, stores the data in Amazon RDS, and plans to analyze daily variations and predict possible disruptions. What kind of data should they collect for modeling and analysis?
- A company compares machine translations produced by its tool with human translations on the same set of documents. Which evaluation strategy should they use to compare the tool’s translation quality relative to human translations?
- A company customized a foundation model in Amazon Bedrock and needs to upload a new dataset for validating the model's responses. Which AWS storage service should they use to upload that validation dataset?
- A company customizes models in Amazon Bedrock and wants the artifacts produced by model customization jobs encrypted with a company-managed encryption key. Which AWS service provides customer-managed keys for this purpose?
- A company deployed an AI/ML solution to help customer service agents answer frequently asked questions that change over time. Agents should be able to ask questions and receive automatically generated answers to common customer inquiries. Which approach is the MOST cost-effective way to meet these requirements?
- A company deploying ML models on AWS wants to provide transparency into model decision-making and offer explanations for predictions. Which AWS feature supports this need?
- A company deploys a SageMaker model that detects topics in social media posts. They need to show how individual input features affect the model's predictions. Which SageMaker capability provides feature-level explanations for model behavior?
- A company finds a foundation model producing images that do not match the prompts. They want to adjust prompting techniques to reduce irrelevant images. Which prompting approach directly helps exclude undesired content?
- A company has a machine learning model and wants insight into how the model arrives at its predictions. What is the term for understanding a model’s predictions?
- A company has access to Amazon Bedrock and wants to limit which Bedrock models specific employees can use. Which approach satisfies this requirement?
- A company has an image-classification model and wants to deploy it so a web app can get predictions without the company managing any servers. Which solution satisfies this requirement?
- A company has an ML model that predicts real estate sale prices and wants to serve predictions without managing servers or infrastructure. Which deployment option meets this requirement?
- A company has defined rules for how long data is stored and when it must be deleted. Which data governance policy does this describe?
- A company has developed multiple machine learning models and needs a centralized place to store, manage, and version them. Which AWS service or feature provides model storage, management, and versioning?
- A company has petabytes of unlabeled customer data and wants to group customers into tiers for targeted advertising. Which machine-learning approach is most appropriate for this task?
- A company has terabytes of structured data and wants an AI application that converts employee natural-language requests into SQL queries. Employees have limited technical skills. Which solution best meets this need?
- A company intends to use a generative AI model to give users real-time service quotes. Which selection criterion is most important for this application?
- A company is adding AI to its hiring and recruitment process and wants to reduce bias while supporting fair hiring decisions. Which core dimensions of responsible AI should they focus on? (Choose two.)
- A company is applying supervised learning on a small labeled dataset that is specific to a particular task. Which phase of the foundation model (FM) lifecycle does this activity represent?
- A company is building a chatbot that uses private documents. They need to convert those documents into vector representations before storing them. Which type of foundation model should they use?
- A company is building a lead-prioritization tool so staff can contact potential customers. Employees must be able to view and manually adjust the importance (weights) of input variables based on their domain expertise. Which type of ML model supports this requirement?
- A company is building a mobile app for visually impaired users that must listen to user speech and reply with voice. Which solution will meet those accessibility requirements?
- A company is building an AI assistant with Amazon Q Business and must restrict user interactions to company-approved topics. Which feature enforces those restrictions?
- A company is building an LLM-based question-answering chatbot to reduce the number of steps call center staff must take to answer customer inquiries. Which business metric should be used to evaluate the chatbot's impact?
- A company is building an ML model with Amazon SageMaker and needs a centralized way to share and manage feature variables across multiple teams. Which SageMaker capability should they use?
- A company is building conversational search agents and needs a database that can store and query vector embeddings generated by a generative AI model. Which AWS service supports storing and querying embeddings as vectors?
- A company is comparing large language models for a text summarization task and needs a metric to evaluate summary quality. Which metric is appropriate?
- A company is creating a chatbot to answer HR policy questions using a large language model and a large set of digital documents. Which technique will best improve the relevance of the generated answers?
- A company is creating a child-facing interactive app that generates new stories from classics using Amazon Bedrock. They need to ensure outputs and topics are child-appropriate. Which AWS capability should they use?
- A company is creating a generative AI application to help students with reading comprehension and must allow students to add illustrations to stories. Which solution meets this requirement?
- A company is evaluating Amazon Nova models available through Amazon Bedrock. They need a multimodal model that supports multiple languages and want the most cost-effective option. Which Nova model should they choose?
- A company is training a custom large language model for a chatbot aimed at teenagers. The chatbot should use the audience’s informal style, including creative spellings and abbreviations. Which metric is appropriate for evaluating the model’s performance?
- A company is training a foundation model and needs to raise its accuracy to a specified acceptance level. Which action will accomplish this?
- A company is using a pre-trained large language model (LLM) that must handle several tasks needing domain-specific technical knowledge. The LLM lacks information on some domain topics, and the company has unlabeled domain data available for tuning. Which fine-tuning approach should the company use?
- A company is using the Amazon Titan foundation model via Amazon Bedrock and needs to augment the model with relevant content from the company's private data sources. What should they do?
- A company must keep customers' personally identifiable information (PII) stored within the company's AWS Region. Which governance concept describes this requirement?
- A company must pick an Amazon Bedrock model to use internally and wants a model that produces responses in the style employees prefer. What is the best approach to evaluate which model matches that preferred style?
- A company must record every request sent to its Amazon Bedrock API and keep those logs securely for five years at the lowest possible cost. Which combination of AWS service and S3 storage class satisfies these requirements? (Choose two.)
- A company must run Amazon SageMaker training and inference in an isolated environment without internet access to meet compliance. Which option satisfies this requirement?
- A company must train a model to classify images of various animal species. It already has a large set of labeled images and will not label additional data. What learning approach should the company use?
- A company needs a chatbot to answer employee questions about company policies. Policies change frequently and the chatbot must reflect updates almost immediately. Which LLM-based approach satisfies this requirement?
- A company needs a generative AI model that provides responses to users in real time. Which model attribute should they evaluate to ensure fast user-facing responses?
- A company needs a generative AI system to produce thousands of unique, paragraph-length product descriptions per day that maintain a consistent style and tone. Which type of generative model is best suited for this?
- A company needs an AI capability to detect whether an IP address is coming from a suspicious source to protect its application from threats. Which solution type best meets this requirement?
- A company needs an interpretable machine learning model to evaluate loan application risk. Which model or algorithm choice best satisfies the requirement for interpretability?
- A company needs standardized documentation for model versioning and a development history while collaborating with research partners. Which solution provides that capability?
- A company needs to apply image operations such as transposing and rotating a set of images. Which option is the most operationally efficient way to perform these numeric image transformations?
- A company needs to automatically extract plain text from resumes submitted as PDF files to enable further processing. Which AWS service can convert PDF documents into text?
- A company needs to build a large dataset to train an AI assistant specialized in a particular subject area. Which dataset type best satisfies this need?
- A company needs to call Amazon Bedrock APIs from within its AWS account without exposing data to the public internet. What solution satisfies both private connectivity and avoidance of internet exposure?
- A company needs to classify human genes into 20 categories and requires an algorithm where the internal decision process can be documented and inspected. Which machine learning algorithm meets this requirement?
- A company needs to classify images of objects using features specific to their dataset. Which option requires the least development work while meeting this need?
- A company needs to create synthetic data that reflects patterns in their existing dataset. Which type of model is appropriate for generating such synthetic data?
- A company needs to extract the main points from lengthy policy documents to help employees find information faster. Which generative AI strategy should they use?
- A company needs to generate images for protective eyewear with high accuracy while minimizing incorrect annotations. Which solution best meets these requirements?
- A company needs to generate synthetic responses for many prompts from a large data set using an API. Responses do not need to be immediate. Which approach requires the least development effort?
- A company needs to limit which publicly available foundation models (FMs) employees can access. Which of these solutions satisfies that requirement?
- A company needs to run inference on archived datasets that are multiple gigabytes in size. The results do not need to be available immediately. Which Amazon SageMaker inference option fits this scenario?
- A company obtains ISO accreditation to manage AI risks and use AI responsibly. What does this accreditation indicate about the organization?
- A company plans a generative AI project to improve marketing and wants to increase revenue within the next 6 months. Which initial approach best supports this short-term business goal?
- A company plans to build an application using Amazon Bedrock but has a small budget and wants flexibility without committing long term. Which Bedrock pricing option satisfies these constraints?
- A company plans to customize a foundation model using its internal documents. Which approach accomplishes this?
- A company plans to have a large language model create source code from natural-language code comments. Which LLM capability best fits this requirement?
- A company plans to train its own LLM using only proprietary data and is worried about the environmental impact of training. Which Amazon EC2 instance family has the lowest environmental footprint for LLM training?
- A company plans to use Amazon Bedrock LLMs to build a chat interface that references product manuals stored as PDF files. Which approach is the most cost-effective?
- A company plans to use Amazon Q Business and must protect the security and privacy of its data. Which combination of actions will satisfy these requirements? (Choose two.)
- A company stores customer records in OpenSearch and needs an AI-based solution that turns queries into data requests, exports the results as CSV files, and uploads those files to Amazon S3. Which option provides the most operationally efficient way to implement this workflow?
- A company tags each financial transaction record as either personal or business and stores that category with the record. Which data-preparation step does this describe?
- A company trained a foundation model for one task and now needs to adapt it to a related but different task. Which fine-tuning approach is appropriate?
- A company used an Amazon Bedrock base model and trained a custom model to improve document summarization for internal use. What must the company do to use that custom model through Amazon Bedrock?
- A company uses a foundation model from Amazon Bedrock and wants to improve its accuracy using the company's own data. Which approach correctly describes how to fine-tune the model?
- A company uses a pre-trained foundation model on Amazon Bedrock but wants to provide it with more company-specific context. Which option is the most cost-effective way to add that context?
- A company uses a pre-trained LLM for a recommendation chatbot and needs the model's replies to be concise and in a specific language. Which approach will best steer the LLM to meet these output requirements?
- A company uses a third-party Bedrock model to analyze confidential documents and is worried about data privacy. Which statement correctly describes how Amazon Bedrock handles customer data for third-party models?
- A company uses Amazon Bedrock and wants to apply Bedrock Guardrails to detect and block harmful inputs and outputs. Which content categories can the guardrails filter? (Choose two.)
- A company uses Amazon Comprehend and has several custom trained models, each assigned to its own endpoint. The company wants an automated report of any endpoint that has not received traffic for over 15 days. Which AWS service can provide this monitoring capability?
- A company uses Amazon Nova Canvas to generate images and needs to prevent certain items from appearing in the outputs. Which technique should they use?
- A company uses Amazon SageMaker to produce article summaries in several languages and needs a metric to assess the quality of translated summaries across languages. Which evaluation metric should they use?
- A company uses Retrieval Augmented Generation with Amazon Bedrock and Stable Diffusion to create product images from text. Outputs are often generic and lack detail. Which change will most increase the specificity of the generated images?
- A company wants an AI assistant that can evaluate specific data sources, call external APIs, generate multiple response options, and then compare and prioritize those options. Which Amazon Bedrock capability best fits these requirements?
- A company wants an AI tool that lets employees view open customer claims, retrieve details for a specific claim, and access supporting documents. Which solution is appropriate?
- A company wants an Amazon Bedrock LLM to give more consistent outputs for the same input prompt. Which inference parameter change will make the model responses more deterministic?
- A company wants an LLM to produce product descriptions that follow a specific example format. Which prompt engineering method helps the model learn and produce outputs that match that format?
- A company wants an LLM-based chatbot to provide customer-service agents with contextual, policy-based answers in real time. The knowledge source is the company's policy documents. What is the most cost-effective solution?
- A company wants an ML model to analyze social media reviews and label each as neutral, positive, or negative. Which modeling approach is appropriate for this requirement?
- A company wants an ML solution to detect anomalies in sensor output but has no labeled examples. Which modeling approach is appropriate for unsupervised anomaly detection in this case?
- A company wants concise, feature-focused product descriptions from an LLM. Which prompt engineering approach is best to produce specific, consistent outputs for each product group?
- A company wants human-labeled data to fine-tune a foundation model but does not want to build labeling tools or manage a labeling workforce. Which AWS service provides that capability?
- A company wants its AI systems to be fair and explainable and plans to require training for the development team. Which training topic directly addresses those goals?
- A company wants its customer service chatbot to improve over time by learning from past interactions and feedback. Which learning approach supports this kind of self-improvement?
- A company wants to analyze customer calls and extract key information from the audio recordings. Which AWS service should they use to convert the call audio into text for further analysis?
- A company wants to automatically produce charts showing total sales for its best-selling products across multiple stores over the last 12 months. Which AWS offering should it use to automate chart generation?
- A company wants to build an AI assistant that lets employees search and query internal data. Which AWS service is designed for this purpose?
- A company wants to build an ML model to predict customer satisfaction and requires fully automated model tuning. Which AWS service should they use?
- A company wants to detect harmful or toxic language in social media comments but will not use labeled data to train a model. Which approach should the company use to identify toxic content?
- A company wants to experiment with generative AI in a low-cost sandbox environment. Which of these options is the most cost-effective choice for that purpose?
- A company wants to fine-tune a foundation model (FM) using AWS while ensuring that its data remains private and secure in the original AWS Region. Which combination of actions meets these requirements most cost-effectively? (Choose two.)
- A company wants to fine-tune a model hosted on Amazon Bedrock using sensitive data stored in private databases inside a VPC. The data must remain within the company’s private network. Which option satisfies this requirement?
- A company wants to instruction-fine-tune a foundation model so it can answer domain-specific questions. How should the company prepare the training data?
- A company wants to reuse existing pretrained domain models instead of training models from scratch to solve new but related tasks. Which ML strategy should they use?
- A company wants to segment customers based on demographics and purchasing patterns. Which algorithm is most appropriate for discovering such groups?
- A company wants to use an LLM on Amazon Bedrock to classify text as positive or negative sentiment. Which prompt-engineering technique is most appropriate?
- A company will deploy a conversational chatbot built from a fine-tuned Amazon SageMaker JumpStart model and must demonstrate compliance with multiple regulatory frameworks. Which capabilities can help demonstrate compliance? (Choose two.)
- A company will integrate a large language model (LLM) into its application and needs the model's responses to be as deterministic and consistent as possible. Which approach satisfies this requirement?
- A company will use a pre-trained generative AI model to create marketing content and must ensure the output matches the company's brand voice and messaging. Which solution best meets this requirement?
- A company will use a pre-trained model (no additional training) to detect vehicle crashes and contact emergency services within 30 seconds. Which model attribute should the company prioritize to meet this requirement?
- A company’s application must automatically group similar customers and products based on attributes, without labeled outcomes. Which machine learning approach should the company use?
- A company’s generative AI model for customer segmentation has been running in production for a long time and recently started producing inconsistent outputs. The company wants to assess model bias and detect drift. Which AWS service or feature should they use?
- A company’s job recommendation system is producing different suggestions based on gender for user profiles that are otherwise identical. According to AWS responsible AI best practices, which guiding principle should the company apply to remedy this bias?
- A company’s LLM produces hallucinated (incorrect) outputs. Which action can reduce hallucinations during inference?
- A customer service team is building an app that analyzes written customer feedback and automatically assigns each comment to categories such as product quality, customer service, or delivery experience. Which AI domain does this use case represent?
- A deep learning object detection model is in production. When the model processes a new image to find and label objects, which stage of the AI lifecycle is taking place?
- A deployed model’s inference quality declined after four months. The team wants to be notified if inference quality drops and to prevent recurrence. Which solution meets both goals?
- A design studio uses a foundation model on Amazon Bedrock to generate images for projects. They want to control how detailed versus how abstract each generated image appears. Which model parameter should they adjust?
- A documentary filmmaker wants to reach a wider audience by automatically adding subtitles and voice-overs in multiple languages. Which combination of steps will accomplish this? (Choose two.)
- A financial company needs to label each credit card transaction as either potentially fraudulent or non-fraudulent. Which type of machine learning model is appropriate for this requirement?
- A financial company uses ML for various tasks. Which of the following is an example of using a generative AI model?
- A financial company using AI-derived credit scores plans to expand into a new geographic market. To ensure lawful operation there, which type of local regulations should the company review?
- A financial firm deployed an ML model to predict customer churn and has one week of production data. They want to measure how accurately the model predicts churn against actual outcomes. Which metric should they use?
- A financial firm is developing a generative AI application to help with loan approval decisions and requires fair and responsible outputs. Which action helps achieve that requirement?
- A financial firm must produce reports demonstrating compliance with international regulations for handling sensitive customer data. Which AWS service provides that capability?
- A financial firm requires its generative AI chatbot to produce accurate, verifiable answers for regulatory compliance. Which solution helps prevent the underlying foundation model from producing hallucinated (factually incorrect) responses?
- A financial firm uses a generative AI model to set credit limits and wants to make the model’s decisions more transparent to customers. Which solution satisfies this requirement?
- A financial firm wants human review workflows for ML predictions, with configurable confidence thresholds that can be updated over time. Which AWS service provides this capability?
- A financial institution runs an Amazon Bedrock-based AI application inside a VPC that is not allowed any Internet access for compliance reasons. Which AWS feature enables private access to Bedrock without exposing the VPC to the public Internet?
- A financial institution uses a foundation model to support loan decisions and requires the model’s decisions to be explainable for audit and security reasons. Which factor most directly affects the explainability of the model’s decisions?
- A firm building a loan-approval ML model needs both bias detection and explainable predictions. Which AWS solution provides these capabilities?
- A food service company is collecting data to predict customers’ food preferences and wants to make sure all demographic groups are represented. Which data characteristic does this requirement describe?
- A food-service company wants an ML model to reduce daily food waste and boost sales, and it needs to continually improve model accuracy over time. Which solution meets these needs?
- A fraud detection system flags suspicious credit card transactions for employee review. The company wants to reduce the time spent reviewing flagged cases that are actually legitimate. Which evaluation metric best supports this goal?
- A global financial firm created an ML application to analyze stock market data and produce trend insights. The firm needs continuous oversight during development to ensure compliance with internal policies and industry regulations. Which AWS services can help evaluate and manage compliance? (Choose two.)
- A grocery chain is building a chatbot that must query live inventory and return item locations in the store. Which prompt engineering pattern is most appropriate for building this chatbot?
- A healthcare company needs an AI system that can read structured patient records, identify important medical details, and produce concise summaries. Which solution meets these needs?
- A healthcare organization plans to modernize an on-premises information system and use generative AI to answer patients' medical questions. Which AWS offering should they use to help ensure responsible AI behavior for the application?
- A healthcare provider has patient data collected over the past year and needs monthly trend analysis reports for disease outbreaks. They must include insights from the most recent month and want the most cost-effective inference approach. Which inference method should they choose?
- A healthcare provider trained a model on historical patient records (medical history, demographics, treatments) to deliver real-time predictions of 30-day readmission risk after discharge. Which activity best describes model inference in this scenario?
- A healthcare team has recorded hundreds of patient voice samples and is currently filtering those recordings by duration and language. Which phase of the ML lifecycle does this activity represent?
- A hospital is building an AI diagnostic tool using patient records and medical images, and regulations require that sensitive patient data must not leave the country where it resides. Which data governance approach ensures compliance and protects patient privacy?
- A hospital wants a generative AI solution with speech-to-text capability to help staff improve their clinical note dictation. Which AWS service provides this functionality?
- A hospital's AI system must give personalized treatment suggestions and explain the reasoning in a way that clinicians and patients can understand. Which human-centered design principle does this reflect?
- A language-learning app uses an LLM to rewrite text to be more readable. The training dataset includes original text paired with more readable versions, and the company wants outputs to match those examples. Which metric should they use to evaluate how closely the model’s outputs match the reference rewrites?
- A large retail bank wants an ML system to guide loan allocation decisions across different demographic groups. What action is needed to help ensure the model is unbiased?
- A large retailer receives thousands of customer support requests daily and wants to deploy Agents for Amazon Bedrock. Which benefit of Bedrock agents would most help this retailer handle many inquiries efficiently?
- A law firm plans to build an application with large language models that reads legal documents and extracts the main points. Which solution best satisfies this requirement?
- A lender is building a generative AI solution to offer discounts to new applicants and wants to minimize bias that could negatively affect some customers. Which actions should they take? (Choose two.)
- A lender uses an ML model to accept or reject loan applications and must make the decision-making process auditable and explainable for regulators. Which solution helps document and present the model's decisions for audits?
- A manufacturing company needs to automatically generate product descriptions in several languages. Which AWS service should it use to perform this translation?
- A manufacturing company processes consumer complaints using complex hard-coded logic and wants to scale that logic across markets and product lines. What advantage do generative AI models provide for this use case?
- A manufacturing company uses AI to inspect products and detect damage or defects. What type of AI application is this?
- A media company plans to deploy a custom ML model in production to recommend personalized content based on viewer behavior and demographics, and it needs to detect model quality drift over time. Which AWS service fulfills these requirements?
- A media streaming company is comparing Amazon Nova foundation models and wants to minimize cost when choosing between Nova Micro and Nova Lite. Which attribute comparison is relevant to their cost consideration?
- A media streaming company wants to enable natural language image search and filtering. They need a vector-capable database that supports similarity searches and nearest-neighbor queries. Which AWS service fits this need?
- A media streaming service wants to recommend movies to users based on their account viewing history. Which AWS service is designed for personalized recommendations?
- A medical company wants to prevent a Bedrock-deployed disease detection model from returning personal patient information and also receive notifications when policy violations occur. Which solution satisfies both requirements?
- A medical firm is fine-tuning a foundation model for diagnostic use and must provide transparency and explainability to satisfy regulations. Which solution helps provide explainability and simple model metrics?
- A multinational company requires that API traffic between its generative AI applications and foundation models must never traverse the public internet. Which AWS feature supports this requirement?
- A news organization publishes articles in English and wants to make those articles available in other languages. Which AWS solution fits this requirement?
- A practitioner trains a model that achieves strong performance on the training set but performs poorly on evaluation data. What is the most likely explanation?
- A product recommendation app uses a generative AI model. The company wants to minimize the application’s environmental footprint. Which approach best meets that goal?
- A production ML pipeline on Amazon SageMaker processes inputs up to 1 GB and jobs that can run up to an hour, but the application requires near real-time responses. Which SageMaker inference option is most appropriate?
- A publisher built a RAG solution to let users interact with daily-published content and wants near-real-time updates. Which RAG pipeline steps are appropriate to perform as offline batch processes? (Choose two.)
- A RAG application on Amazon Bedrock pulls financial news for daily newsletters, and users report politically biased content. Which Bedrock guardrail can detect and block that type of content?
- A research team has images of growing microbiological cultures but no labeled data identifying growth areas. Which machine learning technique is most appropriate to discover and identify regions of growth in the images?
- A research team will compare outputs from several generative models using a fixed prompt and wants a group of scientists to assess the outputs. Which AWS solution supports human evaluation of model outputs?
- A retail company wants to follow responsible practices when collecting data to build a product recommendation model. Which data-collection practice helps reduce bias?
- A retail store plans to use Amazon SageMaker DeepAR to forecast demand for a product over the coming weeks. Which type of input data is required for this forecasting task?
- A security camera ML system is disproportionately flagging people from a particular ethnic group. Which kind of bias is causing this unfair outcome?
- A security firm running foundation models on Amazon Bedrock needs to detect unauthorized attempts to call those models so it can apply appropriate IAM policies. Which AWS service should they use to find who tried to access Bedrock?
- A social media company wants to stop users from posting discriminatory content and plans to use Amazon Bedrock as part of the solution. How can Amazon Bedrock be used to help meet this requirement?
- A social media company wants to use an LLM for content moderation and evaluate outputs for bias or discrimination against groups or individuals with the least administrative effort. Which data source should they use?
- A social media firm wants to compare the toxicity of outputs from several LLMs available in SageMaker JumpStart while minimizing operational work. Which evaluation approach has the least operational overhead?
- A software vendor wants to boost developer productivity with AI. Which of these choices best achieves that goal?
- A solution uses LLMs to translate training manuals from English into other languages. To assess how accurate the translated text is, which evaluation metric should the company use?
- A support chatbot must use prior messages from the same customer to resolve a multi-turn issue. Which solution allows the LLM to access earlier customer content when generating a reply?
- A team is building a generative AI chatbot using a foundation model (FM) from Amazon Bedrock. During testing the chatbot is vulnerable to prompt injection attacks. Which approach will secure the chatbot with the least implementation effort?
- A team is building a machine learning model to predict the risk of heart disease. The dataset includes input features (age, cholesterol, blood pressure, smoking, exercise) and a label indicating whether each patient has heart disease. Which ML approach is appropriate?
- A team is building an LLM application using Amazon Bedrock and customer data stored in Amazon S3. Company policy requires that each team can access only their own customers' data. Which approach enforces this requirement?
- A team stores data in Amazon S3 and uses Amazon SageMaker Studio notebooks. Which configuration ensures controlled, private data flow from S3 into SageMaker Studio?
- A team wants to build and deploy machine learning models on AWS without writing code. Which AWS service or feature enables a no-code ML workflow?
- A team with limited AWS Glue programming experience needs assistance building a new solution that uses Glue. Which AWS service can assist them in using AWS Glue?
- A travel booking website needs AI-generated hotel descriptions that maintain a consistent writing style and branding across listings. Which AWS service is best suited to generate these textual descriptions?
- A university student is copying material from generative AI outputs to write essays. Which responsible generative AI concern does this example illustrate?
- A video production company wants to use generative AI to create new videos and speed up production with the fewest operational steps. Which approach is the most operationally efficient?
- A website uses an Amazon Bedrock generative AI assistant to help customers choose and buy products. The company wants to quantify the assistant's direct effect on sales. Which metric best measures this impact?
- After fine-tuning a large language model to answer help-desk queries, the company wants to measure whether accuracy improved. Which evaluation metric should they use?
- An accounting firm is deploying an LLM-based document processing system and wants to follow responsible AI practices. Which two actions should the firm take during development and deployment? (Choose two.)
- An AI agent answers customer questions using product manuals. Which approach will increase customer trust in the agent's answers?
- An AI company works with ISVs and needs email alerts when an ISV’s compliance reports are available. Which AWS service can deliver those compliance reports and associated notifications?
- An AI practitioner built a deep learning image classifier for material types and now needs to assess its performance. Which metric is most helpful for evaluating a classification model?
- An AI practitioner is building a search application that needs to handle queries containing both text and images. Which type of foundation model is the best fit to power this multi-modal search?
- An AI practitioner is creating a reusable prompt in Amazon Bedrock Prompt Management that must call external APIs or services during execution. Which feature should they use to enable calling external services?
- An AI practitioner is using a Bedrock base model to summarize customer service chat sessions and wants to keep logs of model inputs and outputs for monitoring. Which approach should they use to capture those invocation logs?
- An AI practitioner must choose a performance metric that shows the ratio of correctly classified items to the total number of items classified (both correct and incorrect). Which metric is that?
- An AI practitioner needs an algorithm to classify flower species using features: petal length, petal width, sepal length, and sepal width. Which algorithm is suitable for this classification task?
- An AI practitioner needs to evaluate models and provide explanations of predictions to customers and stakeholders. Which AWS feature or service provides explanation capabilities for model predictions?
- An AI practitioner needs to fine-tune an open-source LLM for text classification and the dataset is ready. Which approach minimizes operational overhead?
- An AI practitioner trained a custom Bedrock model using a dataset that included confidential information. They want to stop the model from producing outputs that reveal that confidential data. What is the correct way to prevent such responses?
- An AI practitioner uses an LLM to generate marketing copy. The text sounds plausible and authoritative but contains incorrect facts. What issue is the model exhibiting?
- An AI practitioner wants the outputs from a large language model (LLM) to be more diverse and creative. Which inference parameter should they adjust?
- An AI practitioner with minimal machine learning experience needs to predict employee attrition without writing code. Which Amazon SageMaker capability meets this need?
- An AI practitioner writing code wants to quickly generate a test case and produce documentation with minimal effort. Which choice will accomplish this with the least work?
- An airline wants a text-based conversational assistant (using LLMs and a knowledge base) to answer customers about schedules, bookings, and payments with minimal development effort. Which approach requires the least development work?
- An airline wants to use a generative AI model to translate its flight booking system code from one programming language to another. Which selection criteria should guide choosing the best model for this task?
- An Amazon Bedrock foundation model must access encrypted files stored in an S3 bucket that use S3-managed encryption keys (SSE-S3), but the model fails to read the data. What action will resolve the access issue?
- An animation studio needs to generate subtitles for its videos. Which AWS service is best suited for producing speech-to-text transcripts for subtitles?
- An e-commerce company wants to segment customers by purchase history and preferences to deliver personalized experiences in its app. Which machine learning approach should they use?
- An ecommerce business wants to personalize search recommendations for each user on its platform. Which AWS service is designed for that use case?
- An ecommerce company receives several gigabytes of customer data daily and trains a demand-forecasting model. They need to run inferences once per day. Which inference type is most suitable?
- An ecommerce company wants to determine customer sentiment from written product reviews. Which AWS services can be used to meet this requirement? (Choose two.)
- An ecommerce company wants to quantify the chatbot’s financial impact on operations. Which metric directly measures cost per customer interaction?
- An ecommerce firm is deploying a chatbot that answers product questions and returns order details. They need safeguards to filter harmful content from user inputs and from the bot's responses. Which Bedrock feature or resource should they use?
- An ecommerce site will publish an AI-powered chatbot that accepts customer input around the clock. Which input-side vulnerability must be addressed before launch?
- An education provider wants a generative AI model to vary the style and complexity of explanations based on the asker's age range. The application will supply the user's age range. Which approach achieves this with the least development effort?
- An ML model predicts customer churn well on training data but fails on new data. Which change is most likely to fix this overfitting problem?
- An ML practitioner wants to offer stakeholders transparency and explanations of how a model makes predictions. Which of the following best provides that explainability?
- An ML team is evaluating a model that predicts customer churn (a binary classification). Which metric is appropriate for measuring the model's performance on this task?
- An ML team shares model artifacts with other teams but retains training code and data. They want a publish-time mechanism to support auditing and transparency for their custom models. Which solution should they use when publishing those models?
- An online education company has a large repository of learning materials and wants an enterprise search solution. Which AWS service is designed for enterprise search?
- At which stage of the ML lifecycle are compliance and regulatory requirements identified?
- Customer emails uploaded to S3 may contain sensitive data. The company wants automated alerts whenever sensitive information is detected with minimal development effort. Which solution best fits this need?
- During security testing of a foundation model, testers intentionally bypass the model's safety protections to produce harmful content. What is this kind of technique called?
- During which phase of the generative AI model lifecycle are tests run to measure the model's accuracy?
- Each quarter, a company uses ML models to forecast demand and wants to produce a report that gives stakeholders clear explanations of how the models make predictions. Which item should the AI practitioner include in the report to provide model transparency and explainability?
- Employees provide location-based product descriptions and recommendations during customer calls. The company wants to automate this with foundation models. Which AWS service is appropriate for building and deploying these FMs?
- How are embeddings best described in AI and machine learning contexts?
- If a company adopts Amazon Bedrock, which security responsibility remains the company's responsibility?
- In AI terminology, what does inference mean?
- In evaluating a foundation model’s performance, what does the F1 score represent?
- In generative AI systems, what does the term "token" refer to?
- In Retrieval Augmented Generation (RAG), what is the main purpose of splitting large documents into chunks?
- Sentiment analysis belongs to which broader area of artificial intelligence?
- The company must pick a foundation model for generating product images and descriptive text, and needs to evaluate models by the types of outputs they can produce. Which model characteristic are they assessing?
- The company needs its foundation model to stay up to date by regularly incorporating new data through ongoing training. Which training approach meets this requirement?
- The company requires its models to be transparent and explainable. Which two Amazon SageMaker features provide capabilities that help achieve transparency and explainability? (Choose two.)
- The company wants to use Amazon Q Developer to boost developer productivity and aid software development. Which capability does Amazon Q Developer provide to help achieve this?
- To improve an LLM’s answers for complex problems that need detailed, step-by-step reasoning, which prompt engineering technique should be used?
- To improve the accuracy of responses from a generative AI application that uses a foundation model (FM) on Amazon Bedrock, which solution is the MOST cost-effective?
- To satisfy regulatory requirements for trustworthy AI management, which approach should a company take?
- To segment customers by demographics and purchasing behavior, which algorithm is best suited for grouping similar customers?
- Using Amazon SageMaker Model Monitor, a company detects data drift that exceeds the configured threshold and wants to prevent harm to the model’s predictions. Which action should they take?
- Using the Generative AI Security Scoping Matrix, a company identifies four solution scopes. Which scope gives the company the greatest responsibility for security?
- What are appropriate steps to use large language models (LLMs) securely on Amazon Bedrock?
- What is a key advantage of using Amazon SageMaker Model Cards to document AI models?
- What is a primary advantage of applying ongoing pre-training when fine-tuning a foundation model (FM)?
- What is the main purpose of a system prompt in generative AI applications?
- What is the purpose of tokenization in natural language processing?
- What is the role of vector embeddings in a large language model (LLM)?
- What is the term for the instructions given to foundation models so they produce more accurate responses to a query?
- What term describes numeric vector representations that AI and NLP models use to capture the meaning of real-world objects and concepts within text?
- When preparing a training dataset to fine-tune Amazon Bedrock foundation models for text-to-text tasks, which data format should be used?
- When training models on imbalanced datasets where some classes have many more examples than others, which metric best measures how well the model balances correctly detecting and labeling classes?
- When using Amazon Bedrock to generate inferences with a large language model, which factor primarily determines inference cost?
- Which Amazon Bedrock foundation model can be fine-tuned to handle text, images, and video understanding?
- Which approach best determines whether a foundation model (FM) meets the organization's business needs?
- Which AWS capability captures metadata and details about ML models and instance data to support governance and reporting?
- Which AWS offering can help an AI team rapidly deploy and use a foundation model inside the team's VPC?
- Which AWS service or feature can store vector embeddings and support vector search for use with foundation models and Retrieval-Augmented Generation workflows?
- Which AWS service provides access to foundation models that developers can use to build and scale generative AI applications?
- Which capability is provided by Amazon SageMaker Clarify?
- Which capability of Amazon OpenSearch Service enables building applications that function like vector databases?
- Which category of AI model is designed to predict continuous numeric values?
- Which evaluation metric is commonly used to assess foundation models (FMs) on text summarization tasks?
- Which highly scalable AWS service should a company use to monitor the performance and operational metrics of its machine learning systems?
- Which large language model parameter determines how many candidate next words or tokens are considered at each generation step?
- Which machine learning approach is trained using data where each example includes the correct output labels?
- Which machine learning approach supports training models while preserving data privacy and compliance when using AWS?
- Which method applied during the post-processing phase of the ML lifecycle can help reduce bias and toxic outputs in generative AI systems?
- Which method is appropriate for assessing how accurate a foundation model is at an image classification task?
- Which method splits a complex task into a sequence of smaller prompts that are sent to a large language model (LLM) one after another?
- Which metric best measures the runtime efficiency of serving AI models in production?
- Which of the following describes a feature of AI governance frameworks that supports trustworthy, human-centered AI?
- Which of the following describes a realistic risk or limitation associated with prompt engineering for generative models?
- Which of the following is a benefit of using infrastructure as code (IaC) within machine learning operations (MLOps)?
- Which of the following is a typical, practical application for generative AI?
- Which of the following is an example of unsupervised learning?
- Which of these is a valid use case for generative AI models?
- Which prompt-based attack specifically reveals the model's configured behavior or the underlying prompt template?
- Which prompting approach can help defend against prompt-injection attacks?
- Which statement accurately describes embeddings in generative AI?
- Which statement best describes the benefit of fine-tuning a foundation model (FM)?
- Which statement correctly describes Retrieval Augmented Generation (RAG)?
- While building a model to generate images of people in different occupations, you find the training data is biased and some attributes skew the outputs. Which mitigation technique addresses this issue?
- You are creating an educational game that must answer straightforward probability questions like: 'A jar has 6 red, 4 green, and 3 yellow marbles. What is the probability of drawing a green marble?' Which approach meets the requirement with the least operational overhead?
- You have a photo dataset of animals and want an automated method to identify and label the animals in each image without manual intervention. Which approach best fits this requirement?
Amazon AWS Certified Solutions Architect – Associate (SAA-C03) All exam questions
- A 4-year-old media company uses the AWS Organizations all features feature set. The finance team requires that billing information for member accounts must not be accessible to anyone, including the root user of the member accounts. Which solution meets this requirement?
- A bicycle sharing company is building a multi-tier architecture to track bicycle locations during peak hours. The company wants to use these data points in its existing analytics platform. A solutions architect must determine the most viable multi-tier option. The data points must be accessible via a REST API. Which action meets the requirements for storing and retrieving location data?
- A business application runs on Amazon EC2 and uses Amazon S3 for encrypted object storage. The chief information security officer requires that no application traffic between the two services traverse the public internet. Which capability should the solutions architect use to meet this requirement?
- A business system generates hundreds of CSV reports daily and saves them to a network share. The company needs to store this data in the AWS Cloud in near-real time for analysis with the least administrative overhead. Which solution meets these requirements?
- A business-critical application runs on Amazon EC2 instances and stores data in an Amazon DynamoDB table. The company must be able to revert the table to any point within the last 24 hours. Which solution meets this requirement with the LEAST operational overhead?
- A city runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). Users report sporadic performance issues that appear related to DDoS attacks from random IP addresses. The city wants a solution that requires minimal configuration changes and provides an audit trail for the DDoS sources. Which solution meets these requirements?
- A company added a read replica to an Amazon RDS for MySQL instance to handle additional read-only queries during end-of-year processing. After the period, the read replica has a steady 25% CPU usage and the primary has a steady 60% CPU usage. The company wants to rightsize the database while still providing enough performance for future growth. Which solution meets these requirements?
- A company builds an application that handles sensitive customer data using Amazon RDS, Amazon S3, and S3 Event Notifications that invoke AWS Lambda. The company uses AWS IAM Identity Center to manage user credentials. Development, testing, and operations teams need secure access to Amazon RDS and Amazon S3, following least privilege. Which solution meets these requirements with the LEAST operational overhead?
- A company built a stateless two-tier application using Amazon EC2 in a single Availability Zone and an Amazon RDS Multi-AZ DB instance. New management wants the application to be highly available. What should a solutions architect do to meet this requirement?
- A company built an application with Docker containers and needs to run it in the AWS Cloud using a managed service. The solution must scale container services in and out according to demand and must not require additional infrastructure or operational overhead. Which solutions meet these requirements? (Choose two.)
- A company built an image analysis application where users upload photos and select photo frames. Currently it uses a single Amazon EC2 instance and Amazon DynamoDB for metadata. User traffic varies significantly by time of day and the number of concurrent users will grow. The company must ensure the application can scale to meet demand. Which solution meets these requirements?
- A company collects 10 GB of telemetry data daily and stores it in an Amazon S3 bucket in a source data account. Several consulting agencies need read access to this data for analysis. The company must share the data from the source account using a solution that maximizes security and minimizes operational overhead. Which solution meets these requirements?
- A company collects and stores research data in an Amazon S3 bucket and processes the data in the AWS Cloud. The company must share the data with employees worldwide. The solution should be secure and minimize operational overhead. Which solution meets these requirements?
- A company collects customer satisfaction surveys on its website. Surveys can reach thousands of customers per hour. Results are currently emailed for manual review. The company wants to automate the workflow and keep survey results available for the previous 12 months. Which solution meets these requirements in the MOST scalable way?
- A company collects data from a vendor. The vendor stores its data in an Amazon RDS for MySQL database in the vendor's AWS account. The company’s VPC has no internet gateway, Direct Connect, or Site-to-Site VPN. The company needs access to the vendor database. Which solution meets this requirement?
- A company collects data from many participants using wearable devices and stores it in a DynamoDB table. The workload is constant and predictable. The company wants to remain at or below its forecasted DynamoDB budget. Which solution is MOST cost-effective?
- A company collects data from thousands of remote devices using a RESTful API running on an Amazon EC2 instance. The EC2 instance receives raw data, transforms it, and stores it in Amazon S3. The number of devices will soon grow into the millions. The company needs a highly scalable solution with minimal operational overhead. Which combination of steps should a solutions architect take? (Choose two.)
- A company collects temperature, humidity, and atmospheric pressure data from cities across multiple continents. Each site generates about 500 GB of data per day and has a high-speed Internet connection. The company wants to aggregate data from all sites as quickly as possible into a single Amazon S3 bucket while minimizing operational complexity. Which solution meets these requirements?
- A company containerized a Windows job that runs on the .NET 6 Framework inside a Windows container. The job must run in AWS every 10 minutes and runs between 1 and 3 minutes per execution. Which solution is MOST cost-effective?
- A company copies 200 TB of data from a recent ocean survey onto AWS Snowball Edge Storage Optimized devices. The company has a high performance computing (HPC) cluster hosted on AWS to search for oil and gas deposits. A solutions architect must provide the cluster with consistent sub-millisecond latency and high-throughput access to the data on the Snowball Edge Storage Optimized devices. The company is returning the devices to AWS. Which solution will meet these requirements?
- A company created a disaster recovery site in a different AWS Region. The company needs to transfer large amounts of data periodically between NFS file systems in the two Regions. Which solution meets these requirements with the least operational overhead?
- A company created a new organization in AWS Organizations with multiple accounts for development teams. Developers use AWS IAM Identity Center (AWS Single Sign-On) to access accounts. For each application, development teams must apply a predefined application name tag to resources they create. A solutions architect must allow resource creation only if the application name tag has an approved value. Which solution meets these requirements?
- A company creates dedicated AWS accounts in AWS Organizations for business units. An important notification was recently sent to a business unit account's root user email instead of the assigned account owner. The company wants future notifications sent to different employees depending on category (billing, operations, security). Which solution meets these requirements MOST securely?
- A company currently runs an application and a MySQL database on a single Amazon EC2 instance. The company requires a highly available, automatically scalable solution to handle increased traffic. Which option meets these requirements?
- A company currently stores 5 TB of data in on-premises block storage systems. The company's current storage solution provides limited space for additional data. The company runs applications on premises that must be able to retrieve frequently accessed data with low latency. The company requires a cloud-based storage solution. Which solution will meet these requirements with the MOST operational efficiency?
- A company currently uses an on-premises SFTP file transfer solution and is migrating to the AWS Cloud to scale and reduce costs by using Amazon S3. Employees must authenticate with the existing on-premises Microsoft Active Directory (AD) and the company wants to preserve current authentication and file access mechanisms. Which solution meets these requirements with the LEAST operational overhead?
- A company delivers on-demand training videos stored in an S3 bucket in us-east-2. The company created S3 buckets in eu-west-2 and ap-southeast-1 and wants to replicate data to them. The goal is to minimize latency for developers who upload videos and for students who stream videos near eu-west-2 and ap-southeast-1 while making the FEWEST application changes. Which combination of steps meets these requirements? (Choose two.)
- A company deployed a multiplayer mobile game that requires live location tracking of players using latitude and longitude. The data store must support rapid updates and retrieval of locations. The game stores location data in an Amazon RDS for PostgreSQL DB instance with read replicas, but during peak usage the database cannot maintain required read/write performance. The user base is rapidly increasing. What should a solutions architect do to improve data-tier performance?
- A company deployed a new auditing system that centralizes OS versions, patching, and installed software for Amazon EC2 instances. Ensure that all instances provisioned through EC2 Auto Scaling groups send reports to the auditing system as soon as they are launched and when they are terminated. Which solution achieves this most efficiently?
- A company deployed a serverless application that uses Amazon DynamoDB. After a large increase in users, the company wants to improve response time from milliseconds to microseconds and cache requests to the database with the LEAST operational overhead. Which solution meets these requirements?
- A company deployed a serverless application where an AWS Lambda function processes new documents uploaded to an Amazon S3 bucket. After a marketing campaign, many documents were not processed. What should a solutions architect do to improve this architecture?
- A company deployed its retail website globally. The site runs on multiple Amazon EC2 instances behind an Elastic Load Balancer in an Auto Scaling group across multiple Availability Zones. The company wants to serve different content versions based on the device used by customers. Which combination of actions should a solutions architect take to meet these requirements? (Choose two.)
- A company deploys a two-tier web application in a VPC. The web tier uses an Auto Scaling group in public subnets across multiple Availability Zones. The database tier is an Amazon RDS for MySQL DB instance in private subnets. The web tier cannot connect to the database, though the DB is running. Network ACLs, security groups, and route tables are still at their default settings. What should a solutions architect recommend to fix the application?
- A company deploys applications on Amazon Elastic Kubernetes Service (Amazon EKS) behind an Application Load Balancer in one AWS Region. The application needs to store data in PostgreSQL, require high availability for the data, and require increased capacity for read workloads. Which solution provides these requirements with the MOST operational efficiency?
- A company developed a new multiplayer video game as a web application in a three-tier architecture in a VPC with Amazon RDS for MySQL in the database layer. Several players will compete concurrently online. Developers want a near-real-time top-10 scoreboard and the ability to stop and restore the game while preserving current scores. What should a solutions architect implement to meet these requirements?
- A company enforces CloudTrail across multiple AWS accounts using AWS Organizations. CloudTrail logs are delivered to a centralized S3 bucket that has S3 Versioning enabled. An S3 Lifecycle policy deletes current object versions after 3 years. After year four, the bucket’s total number of objects keeps rising even though new log delivery remains constant. Which solution will most cost-effectively delete objects older than 3 years?
- A company engaged an AWS Managed Service Provider (MSP) Partner to assist with a migration. A solutions architect must share an Amazon Machine Image (AMI) from the company's AWS account with the MSP Partner's AWS account. The AMI is EBS-backed and its EBS snapshots are encrypted with a customer-managed AWS KMS key. What is the MOST secure way to share the AMI with the MSP Partner's AWS account?
- A company expects rapid growth. A solutions architect will create IAM groups and add new users to groups based on department. Which additional action is the MOST secure way to grant permissions to the new users?
- A company has 10 TB of log files in Apache Parquet format stored in an Amazon S3 bucket and occasionally needs to run SQL queries against them. Which is the most cost-effective solution?
- A company has 150 TB of archived image data on-premises that must be moved to AWS within a month. The current network allows up to 100 Mbps uploads and only during the night. What is the MOST cost-effective way to transfer the data and meet the deadline?
- A company has 5 PB of archived data on physical tapes. The company needs to preserve the data on the tapes for another 10 years for compliance purposes. The company wants to migrate to AWS in the next 6 months. The data center that stores the tapes has a 1 Gbps uplink internet connectivity. Which solution will meet these requirements MOST cost-effectively?
- A company has 5 TB of datasets consisting of 1 million user profiles and 10 million connections. The user profiles and connections form many-to-many relationships. The company needs an efficient way to find mutual connections up to five levels. Which solution meets these requirements?
- A company has 700 TB of backup data on network attached storage (NAS) in its data center. The backups must remain accessible for infrequent regulatory requests and be retained for 7 years. The company will migrate the data to AWS within 1 month and has 500 Mbps of dedicated public internet bandwidth available. What should a solutions architect do to migrate and store the data at the LOWEST cost?
- A company has a custom application with embedded credentials that retrieves data from an Amazon RDS for MySQL DB cluster. The company needs to secure the application with minimal programming effort. They have created credentials on the RDS database for the application user. Which solution meets these requirements?
- A company has a data ingestion workflow consisting of an Amazon SNS topic that receives notifications about new data deliveries and an AWS Lambda function that processes and stores the data. Occasionally the ingestion fails due to network connectivity issues, and those data are not ingested unless a job is manually rerun. What should a solutions architect do to ensure all notifications are eventually processed?
- A company has a data-ingestion workflow that uses an Amazon Simple Notification Service (Amazon SNS) topic to notify about new deliveries and an AWS Lambda function to process the data and record metadata. The workflow sometimes fails due to network connectivity issues; when it fails, the Lambda function does not ingest the data unless the company manually reruns the job. Which combination of actions should a solutions architect take so the Lambda function ingests all data reliably in the future? (Choose two.)
- A company has a furniture inventory application deployed on a fleet of Amazon EC2 instances across multiple Availability Zones behind an Application Load Balancer (ALB). The solutions architect observes that incoming traffic favors one EC2 instance, causing latency for some requests. What should the solutions architect do to resolve this issue?
- A company has a large Microsoft SharePoint deployment on-premises that requires Microsoft Windows shared file storage. The company wants to migrate this workload to AWS. The storage solution must be highly available and integrate with Active Directory for access control. Which solution satisfies these requirements?
- A company has a legacy data processing application that runs on Amazon EC2 instances. Data is processed sequentially, but the order of results does not matter. The application uses a monolithic architecture and currently scales only by increasing instance size. The developers are rewriting the application as microservices on Amazon Elastic Container Service (Amazon ECS). What should a solutions architect recommend for communication between the microservices?
- A company has a Microsoft .NET application running on an on-premises Windows Server and uses Oracle Database Standard Edition. The company plans to migrate to AWS with minimal code changes and wants a highly available AWS environment. Which two actions should the company take? (Choose two.)
- A company has a mobile chat application with its data store in Amazon DynamoDB. Users want new messages to be read with as little latency as possible. A solutions architect must design an optimal solution that requires minimal application changes. Which method should the solutions architect select?
- A company has a multi-tier application on EC2 instances in an Auto Scaling group with an Amazon RDS for Oracle database using Oracle-specific PL/SQL. Traffic is increasing, causing the EC2 instances to become overloaded and the RDS instance to run out of storage. The Auto Scaling group has no scaling metrics and only defines a minimum healthy instance count. Traffic will continue increasing at a steady but unpredictable rate before leveling off. What should a solutions architect do to ensure the system can automatically scale for the increased traffic? (Choose two.)
- A company has a multi-tier payment processing application running on virtual machines. Tiers communicate asynchronously through a third-party middleware that guarantees exactly-once delivery. The company wants the solution with the least infrastructure management that also guarantees exactly-once delivery for application messaging. Which two actions meet these requirements? (Choose two.)
- A company has a multi-tier web application whose internal services run on EC2 and need to call third-party SaaS APIs hosted on AWS. The company requires secure, private connectivity with minimal public internet exposure. Which solution meets these requirements?
- A company has a nightly batch that analyzes report files uploaded daily to an on-premises file system via SFTP. The company wants to move this to AWS with high availability, resilience, and minimal operational effort. Which solution meets these requirements?
- A company has a Node.js function on an on-premises server that uses a PostgreSQL database and stores the connection string in an environment variable. The company will migrate the application to AWS Lambda, migrate the database to Amazon RDS for PostgreSQL, and securely manage database credentials with the least operational overhead. Which solution meets these requirements?
- A company has a non-production application composed of multiple microservices for different business units. A single development team maintains all microservices. The current architecture uses a static web frontend, a Java backend for application logic, and a MySQL database hosted on an Amazon EC2 instance. The company needs the application to be secure and globally available with the least operational overhead. Which solution meets these requirements?
- A company has a production Amazon EKS cluster with managed node groups that use On-Demand Instances. The company needs a separate EKS cluster for development testing that will be used infrequently to test application resiliency. The EKS cluster must manage all nodes. Which solution meets these requirements MOST cost-effectively?
- A company has a production web application where users upload documents through a web interface or a mobile app. A new regulation requires that documents cannot be modified or deleted after they are stored. What should a solutions architect do to meet this requirement?
- A company has a small Python application that processes JSON documents and writes results to an on-premises SQL database. The application runs thousands of times per day. The company wants to move the application to the AWS Cloud and requires a highly available solution that maximizes scalability and minimizes operational overhead. Which solution meets these requirements?
- A company has a three-tier application for image sharing. The application uses an Amazon EC2 instance for the front-end layer, another EC2 instance for the application layer, and a third EC2 instance for a MySQL database. A solutions architect must design a scalable and highly available solution that requires the least amount of change to the application. Which solution meets these requirements?
- A company has a three-tier web application running on a single server and wants to migrate to AWS following the AWS Well-Architected Framework for security, scalability, and resiliency. Which combination of solutions meets these requirements? (Choose three.)
- A company has a web application for travel ticketing. The application is based on a database that runs in a single data center in North America. The company wants to expand the application to serve a global user base. The company needs to deploy the application to multiple AWS Regions. Average latency must be less than 1 second on updates to the reservation database. The company wants to have separate deployments of its web platform across multiple Regions. However, the company must maintain a single primary reservation database that is globally consistent. Which solution should a solutions architect recommend to meet these requirements?
- A company has a web application that is based on Java and PHP. The company plans to move the application from on premises to AWS. The company needs the ability to test new site features frequently. The company also needs a highly available and managed solution that requires minimal operational overhead. Which solution will meet these requirements?
- A company has a web application with an embedded NoSQL database. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group in a single Availability Zone. Traffic has increased and the application must be highly available; the database can be eventually consistent. Which solution meets these requirements with the LEAST operational overhead?
- A company has a web application with sporadic usage: heavy at the start of each month, moderate at the start of each week, and unpredictable during the week. The application uses a web server and a MySQL database server in a data center. The company wants to move to AWS and choose a cost-effective database platform that requires no database modifications. Which solution meets these requirements?
- A company has a web application with thousands of users. The application uses 8–10 user-uploaded images to generate AI images. Users can download the generated AI images once every 6 hours. A premium option lets users download generated AI images at any time. The company uses the user-uploaded images to run AI model training twice a year. Which storage solution meets these requirements MOST cost-effectively?
- A company has a web server on an Amazon EC2 instance in a public subnet with an Elastic IP address. The instance uses the default security group, and the default network ACL has been modified to block all traffic. A solutions architect must make the web server accessible from everywhere on port 443. Which combination of steps will accomplish this? (Choose two.)
- A company has a website behind an Application Load Balancer (ALB) that handles HTTP and HTTPS separately. The company wants all requests redirected so they use HTTPS. What should a solutions architect do?
- A company has a Windows-based application that must be migrated to AWS. The application requires a shared Windows file system that is accessible from multiple Amazon EC2 Windows instances deployed across multiple Availability Zones. What should a solutions architect do to meet this requirement?
- A company has a workload in an AWS Region. Customers connect to and access the workload by using an Amazon API Gateway REST API. The company uses Amazon Route 53 as its DNS provider. The company wants to provide individual and secure URLs for all customers. Which combination of steps will meet these requirements with the MOST operational efficiency? (Choose three.)
- A company has Amazon EC2 instances that run nightly batch jobs to process data. The EC2 instances run in an Auto Scaling group that uses On-Demand billing. If a job fails on one instance, another instance will reprocess the job. The batch jobs run between 12:00 AM and 06:00 AM local time every day. Which solution will provide EC2 instances to meet these requirements MOST cost-effectively?
- A company has an aging network-attached storage (NAS) array that presents SMB and NFS shares to client workstations. The company does not want to buy a new NAS or renew the support contract. Some data is frequently accessed while much is inactive. A solutions architect must migrate the data to Amazon S3, apply S3 Lifecycle policies, and keep the same client look and feel. Which AWS Storage Gateway type should the solutions architect provision?
- A company has an Amazon Elastic File System (Amazon EFS) file system containing a reference dataset. EC2-based applications need to read the dataset but must not modify it. The company wants to use IAM access control to prevent the applications from modifying or deleting the dataset. Which solution meets these requirements?
- A company has an Amazon S3 bucket that contains sensitive data files. The company runs an application on virtual machines in an on-premises data center and uses AWS IAM Identity Center. The application requires temporary access to the S3 objects. The company wants to grant the application secure access to the S3 bucket. Which solution meets these requirements?
- A company has an Amazon S3 data lake governed by AWS Lake Formation. The company wants to create an Amazon QuickSight visualization by joining the data lake with operational data stored in an Amazon Aurora MySQL database. The company must enforce column-level authorization so the marketing team can access only a subset of columns. Which solution meets these requirements with the LEAST operational overhead?
- A company has an Amazon S3 data lake. The company needs to transform the data daily and load it into a data warehouse that has massively parallel processing (MPP). Data analysts must create and train machine learning models using SQL on the data. Use serverless AWS services wherever possible. Which solution meets these requirements?
- A company has an application backed by an Amazon DynamoDB table. Compliance requires database backups to be taken every month, be available for 6 months, and be retained for 7 years. Which solution meets these requirements?
- A company has an application that uses an Amazon DynamoDB table. A solutions architect finds that many requests to the table are not returning the latest data. Users have not reported other database performance issues and latency is acceptable. Which design change should the solutions architect recommend?
- A company has an application where customers upload images to an Amazon S3 bucket. Each night, the company launches an Amazon EC2 Spot Fleet to process the day's images. Processing each image takes 2 minutes and requires 512 MB of memory. A solutions architect must change the application to process images as they are uploaded. Which change meets the requirements MOST cost-effectively?
- A company has an application workflow in which an AWS Lambda function downloads and decrypts files from Amazon S3. The files are encrypted with AWS Key Management Service (AWS KMS) keys. A solutions architect needs to ensure the correct permissions are set. Which combination of actions accomplishes this? (Choose two.)
- A company has an AWS account used for software engineering. The account has access to the company’s on-premises data center through a pair of AWS Direct Connect connections. All non-VPC traffic routes to the virtual private gateway. A development team created an AWS Lambda function through the console. The team needs to allow the function to access a database that runs in a private subnet in the company’s data center. Which solution will meet these requirements?
- A company has an AWS Direct Connect connection from its corporate data center to a VPC in us-east-1. The company acquired another organization that has VPCs and a Direct Connect connection to eu-west-2. The VPC CIDR ranges do not overlap. The company needs scalable connectivity among both Regions and both data centers while minimizing operational overhead. What should a solutions architect do?
- A company has an AWS Direct Connect connection from its on-premises location to an AWS account. The AWS account contains 30 different VPCs in the same AWS Region. The VPCs use private virtual interfaces (VIFs). Each VPC has a CIDR block that does not overlap with other company-controlled networks. The company wants centralized network management while allowing each VPC to communicate with all other VPCs and on-premises networks. Which solution meets these requirements with the LEAST operational overhead?
- A company has an employee web portal (100% uptime required) for payroll and is adding a feature that allows employees to upload scanned reimbursement documents. A program extracts text from these documents and links the extracted data to reimbursement IDs. The extract program runs infrequently on demand. The company wants a scalable, cost-effective solution with minimal changes to the existing portal and no code changes. Which solution meets these requirements with the least implementation effort?
- A company has an internal application on compute-optimized Amazon EC2 instances in an Auto Scaling group using Amazon EBS volumes. The company wants to identify cost optimizations across the EC2 instances, the Auto Scaling group, and the EBS volumes with the MOST operational efficiency. Which solution meets this requirement?
- A company has an on-premises application that uses SFTP to collect financial data from multiple vendors. The company migrated to AWS and has an application that uses Amazon S3 APIs to upload files, but some vendors use legacy systems that only support SFTP. The company wants a managed service solution with the least operational overhead so those vendors can continue uploading via SFTP. Which solution meets these requirements?
- A company has an on-premises business application that generates hundreds of files per day. These files are stored on an SMB file share and require low-latency access for the application servers. A new company policy requires that all application-generated files be copied to AWS. There is already a VPN connection to AWS, and the application team cannot modify the application code. Which service should a solutions architect recommend to allow the application to copy files to AWS?
- A company has an on-premises data center that is running out of storage capacity. The company wants to migrate its storage to AWS while minimizing bandwidth costs and allowing immediate retrieval of data at no additional cost. How can these requirements be met?
- A company has an on-premises MySQL transactional database to migrate to AWS. The migrated database must remain compatible with the company's applications and must scale automatically during demand spikes. Which migration solution meets these requirements?
- A company has an on-premises server that uses an Oracle database to process and store customer information. The company wants to use an AWS database service to achieve higher availability and to improve application performance. The company also wants to offload reporting from its primary database system. Which solution will meet these requirements in the MOST operationally efficient way?
- A company has an on-premises web application that experiences latency spikes twice monthly. At the start of a spike, CPU utilization immediately increases to 10 times normal. The company will migrate the application to AWS and wants automatic scaling to handle increased demand. The company will use AWS Elastic Beanstalk for deployment. Which solution meets these requirements?
- A company has an organization in AWS Organizations. The company runs Amazon EC2 instances across four AWS accounts in the root organizational unit (OU): three nonproduction accounts and one production account. The company wants to prohibit users from launching EC2 instances of a certain size in the nonproduction accounts. The company has created a service control policy (SCP) to deny launches of the prohibited instance types. Which solutions to deploy the SCP will meet these requirements? (Choose two.)
- A company has customers worldwide and wants to use automation to secure systems and network infrastructure. The security team must be able to track and audit all incremental infrastructure changes. Which solution meets these requirements?
- A company has data collection sensors at multiple locations that stream a high volume of data. The company wants a scalable, near-real-time platform on AWS to ingest and process the streaming data, and store the data in Amazon S3 for later reporting. Which solution meets these requirements with the LEAST operational overhead?
- A company has deployed a database in Amazon RDS for MySQL. Due to increased transactions, the database support team reports slow reads and recommends adding a read replica. Which combination of actions should a solutions architect take before implementing this change? (Choose two.)
- A company has deployed a multi-account strategy with AWS Control Tower and provided each developer with an individual AWS account. The company wants controls that limit AWS resource costs incurred by developers with the LEAST operational overhead. Which solution meets these requirements?
- A company has deployed an application that consists of microservices running on AWS Lambda and Amazon Elastic Kubernetes Service (Amazon EKS). Separate teams support each microservice and the company uses multiple AWS accounts, giving each team its own account. A solutions architect must design service-to-service communication over HTTPS (port 443) and provide a service registry for discovery with the least administrative overhead. Which solution meets these requirements?
- A company has established a new AWS account. The account is newly provisioned and no changes have been made to the default settings. The company is concerned about the security of the AWS account root user. What should be done to secure the root user?
- A company has five organizational units (OUs) as part of its organization in AWS Organizations. Each OU correlates to the five businesses that the company owns. The company's research and development (R&D) business is separating from the company and will need its own organization. A solutions architect creates a separate new management account for this purpose. What should the solutions architect do next in the new management account?
- A company has global users accessing an HTTP application deployed on Amazon EC2 in multiple Regions. The company wants to improve availability and performance, protect the app from common web exploits that affect availability or security, and require static IP addresses. What should a solutions architect recommend?
- A company has hundreds of Linux-based Amazon EC2 instances. Administrators used shared SSH keys to manage them, but an audit requires removing all shared keys. Which solution provides secure access with the LEAST administrative overhead?
- A company has migrated multiple Microsoft Windows Server workloads to Amazon EC2 instances that run in the us-west-1 Region. The company manually backs up the workloads to create an image as needed. In the event of a natural disaster in the us-west-1 Region, the company wants to recover workloads quickly in the us-west-2 Region. The company wants no more than 24 hours of data loss on the EC2 instances. The company also wants to automate any backups of the EC2 instances. Which solutions will meet these requirements with the LEAST administrative effort? (Choose two.)
- A company has millions of objects stored across multiple prefixes in an Amazon S3 bucket using the S3 Glacier Deep Archive storage class. The company must delete all data older than 3 years except for a specific subset that must be retained. The retained data set is already identified. The company requires a serverless solution. Which solution meets these requirements?
- A company has more than 5 TB of file data on on-premises Windows file servers that are accessed daily by users and applications. The company is migrating Windows workloads to AWS and needs access to both AWS and on-premises file storage with minimal latency, minimal operational overhead, and no major changes to existing file access patterns. Connectivity uses an AWS Site-to-Site VPN. What should a solutions architect do to meet these requirements?
- A company has multiple Amazon RDS DB instances in a development AWS account. All instances are tagged as development resources. The company needs the development DB instances to run only during business hours. Which solution meets these requirements with the LEAST operational overhead?
- A company has multiple AWS accounts in AWS Organizations across global offices. The company must update security group rules to add new office CIDR ranges or remove old CIDR ranges across the organization, while minimizing administrative overhead. Which solution is the MOST cost-effective for centralized management of those CIDR ranges?
- A company has multiple AWS accounts with applications in the us-west-2 Region. Each account stores application logs in Amazon S3 buckets. The company wants a centralized log analysis solution using a single S3 bucket. Logs must remain in us-west-2, and the solution should incur minimal operational overhead and cost. Which solution meets these requirements and is MOST cost-effective?
- A company has multiple Microsoft Windows SMB file servers and Linux NFS file servers on-premises and wants to consolidate file sharing in AWS. They need a managed storage service that supports both NFS and SMB, can share between protocols, and provides Availability Zone-level redundancy. Which solution meets these requirements?
- A company has multiple VPCs across AWS Regions to support workloads that are isolated from workloads in other Regions. A new requirement mandates that the company’s VPCs must be able to communicate with all other VPCs across all Regions. Which solution will meet these requirements with the LEAST amount of administrative effort?
- A company has NFS servers in an on-premises data center that need to periodically back up small amounts of data to Amazon S3. Which solution meets these requirements and is MOST cost-effective?
- A company has one million mobile app users and needs near-real-time data analysis. The data must be encrypted in near-real time and stored centrally in Apache Parquet format for further processing. Which solution provides this with the LEAST operational overhead?
- A company has primary and secondary data centers 500 miles (804.7 km) apart, interconnected by high-speed fiber. The company needs a highly available and secure network connection between its data centers and a VPC on AWS for a mission-critical workload. A solutions architect must choose the option that provides maximum resiliency. Which solution meets these requirements?
- A company has released a new production version of its workload that uses Amazon EC2, AWS Lambda, AWS Fargate, and Amazon SageMaker. The company wants to cost-optimize the steady-state workload now and cover the most services with the fewest savings plans. Which combination of savings plans meets these requirements? (Choose two.)
- A company has resources across multiple AWS Regions and accounts. A newly hired solutions architect finds no documentation of the resource inventory and needs to map resource relationships across all accounts and Regions. Which solution will provide this information with the MOST operational efficiency?
- A company has separate AWS accounts for finance, data analytics, and development. To control costs and improve security, the company wants to restrict which services each account can use. Which solution meets these requirements with the LEAST operational overhead?
- A company has several on-premises Internet Small Computer Systems Interface (iSCSI) network storage servers. The company wants to reduce the number of these servers by moving to the AWS Cloud. A solutions architect must provide low-latency access to frequently used data and reduce dependency on on-premises servers with minimal infrastructure changes. Which solution meets these requirements?
- A company has several web servers that frequently access a shared Amazon RDS MySQL Multi-AZ DB instance. The company requires a secure method for the web servers to connect to the database and must rotate user credentials frequently. Which solution meets these requirements?
- A company has thousands of edge devices that generate 1 TB of status alerts per day, with each alert about 2 KB. The solutions architect must implement a highly available ingestion and storage solution for future analysis that minimizes cost and infrastructure management. The company needs to keep 14 days of data available for immediate analysis and archive data older than 14 days. What is the MOST operationally efficient solution that meets these requirements?
- A company has two applications: a sender that sends messages with payloads to be processed, and a processing application that receives and processes those payloads. The sender sends about 1,000 messages per hour. Messages may take up to 2 days to process; failed messages must be retained so they do not block processing of other messages. Which solution meets these requirements and is the MOST operationally efficient?
- A company has two AWS accounts: Production and Development. The company needs to push code changes from the Development account to the Production account. In the alpha phase, only two senior developers in Development need access to Production. In the beta phase, more developers will need access for testing. Which solution meets these requirements?
- A company has two VPCs in the us-west-2 Region in the same AWS account. The company needs to allow network traffic between them. Approximately 500 GB of data will transfer between the VPCs each month. What is the MOST cost-effective solution to connect these VPCs?
- A company has two VPCs: Management and Production. The Management VPC connects to a single device in the data center via VPNs through a customer gateway. The Production VPC uses a virtual private gateway with two Direct Connect connections. The two VPCs communicate via a single VPC peering connection. What should a solutions architect do to mitigate any single point of failure in this architecture?
- A company hosts a containerized web application on on-premises servers that handle incoming requests. Traffic is growing rapidly and the on-premises servers cannot scale. The company wants to move the application to AWS with minimal code changes and minimal development effort. Which solution meets these requirements with the LEAST operational overhead?
- A company hosts a data lake on AWS containing data in Amazon S3 and Amazon RDS for PostgreSQL. The company needs a reporting solution that visualizes all data sources. Only management should have full access to all visualizations; the rest of the company should have limited access. Which solution meets these requirements?
- A company hosts a database that runs on an Amazon RDS instance deployed across multiple Availability Zones. The company periodically runs a script against the database to report new entries that are added. The script negatively affects the performance of a critical application. The company needs to improve application performance with minimal cost and the least operational overhead. Which solution will meet these requirements?
- A company hosts a dynamic web application on two Amazon EC2 instances. The company’s SSL certificate is on each instance for SSL termination. Increased traffic has caused SSL encryption/decryption to max out the web servers’ compute capacity. What should a solutions architect do to improve application performance?
- A company hosts a monolithic web application on an Amazon EC2 instance. Users report poor performance at specific times. CloudWatch shows CPU utilization is 100% during those periods. The company wants to resolve the performance issue and improve availability as cost-effectively as possible. Which combination of steps will meet these requirements? (Choose two.)
- A company hosts a multi-tier public web application on Amazon EC2 with an RDS database. The company expects a large increase in sales over a holiday weekend. A solutions architect must build a solution to analyze web application performance with a granularity of no more than 2 minutes. What should the solutions architect do?
- A company hosts a multi-tier web application on Amazon Linux Amazon EC2 instances behind an Application Load Balancer. Instances run in an Auto Scaling group across multiple Availability Zones. The Auto Scaling group launches more On-Demand Instances when users request high volumes of static web content. The company wants to optimize cost. How should a solutions architect redesign the application MOST cost-effectively?
- A company hosts a multiplayer gaming app on AWS. The app needs sub-millisecond read latency for frequently accessed data and must support one-time queries on historical data. Which solution meets these requirements with the LEAST operational overhead?
- A company hosts a PHP-based website analytics application on a single Amazon EC2 On-Demand Instance. The web server, PHP application, and MySQL database all run on that instance. During busy times the application shows performance degradation and 5xx errors. The company needs the application to scale seamlessly and cost-effectively. Which solution best meets these requirements?
- A company hosts a stateless website analytics application on a single Amazon EC2 On-Demand Instance. The application degrades and returns 5xx errors during busy times. The company needs the application to scale seamlessly. Which solution meets these requirements MOST cost-effectively?
- A company hosts a static marketing website on a single on-premises server and uploads updates infrequently via SFTP. The company will move the site to AWS and use Amazon CloudFront. The solutions architect must design the most cost-effective, resilient origin for CloudFront. Which solution meets these requirements?
- A company hosts a static website in Amazon S3 and wants to add a contact form with server-side components for name, email, phone, and message. The site expects fewer than 100 visits per month. The contact form must email the company when a user submits it. Which solution is MOST cost-effective?
- A company hosts a static website on Amazon S3 and uses Amazon Route 53 for DNS. As global demand increases, the company must decrease latency for users worldwide in the most cost-effective way. Which solution meets these requirements?
- A company hosts a static website on Amazon S3 behind Amazon CloudFront. The site uses a database backend. The site does not reflect recent updates from the Git repository. The CI/CD pipeline and webhooks indicate successful deployments to S3. What should a solutions architect do to ensure the site displays the updates?
- A company hosts a three-tier ecommerce application in AWS. The website is hosted on Amazon S3 and integrates with an API on three Amazon EC2 instances behind an Application Load Balancer (ALB). The API serves static and dynamic front-end content and backend workers that process sales requests asynchronously. The company expects sudden large spikes in sales requests during product launches. What should a solutions architect recommend to ensure all requests are processed successfully?
- A company hosts a three-tier web application in AWS. The database layer uses a Multi‑AZ Amazon RDS for MySQL server and the cache layer uses Amazon ElastiCache. The company wants a caching strategy that adds or updates cache data when a customer adds an item to the database, and the cache data must always match the database. Which solution meets these requirements?
- A company hosts a three-tier web application with a PostgreSQL database that stores document metadata. Documents are stored in Amazon S3. Documents are usually written only once but updated frequently. A monthly reporting process searches metadata using relational queries and takes several hours; the reporting must not block document modifications or additions. Implement a solution to speed up reporting with the least change to application code. Which solution meets these requirements?
- A company hosts a video streaming application in a VPC using a Network Load Balancer (NLB) to handle TCP traffic for real-time processing. There have been unauthorized access attempts. The company wants to improve security with minimal architectural changes to prevent unauthorized access attempts. Which solution meets these requirements?
- A company hosts a web app on RDS for MySQL with a primary DB instance and five read replicas. Replicas must lag no more than 1 second behind the primary. The database runs scheduled stored procedures, and replicas experience more lag during peak load. The solutions architect must reduce replication lag as much as possible while minimizing application code changes and ongoing operational overhead. Which solution meets these requirements?
- A company hosts a web application from an Amazon S3 bucket. The application uses Amazon Cognito to authenticate users and returns a JSON Web Token (JWT) that grants access to protected resources stored in another S3 bucket. After deployment, users report errors and cannot access the protected content. A solutions architect must provide the correct permissions so users can access the protected content. Which solution meets these requirements?
- A company hosts a web application on 10 Amazon EC2 instances, with traffic directed by Amazon Route 53. Users sometimes experience timeouts because DNS queries return IP addresses of unhealthy instances. What should a solutions architect implement to prevent these timeout errors?
- A company hosts a web application on a single Amazon EC2 instance that stores user-uploaded documents on an Amazon EBS volume. For better scalability and availability, the company added a second EC2 instance and EBS volume in another Availability Zone and placed both instances behind an Application Load Balancer. After this change, users report that each page refresh shows one subset of their documents or the other, but never all documents at once. What should a solutions architect propose so users see all of their documents at once?
- A company hosts a website on Amazon EC2 instances behind an Application Load Balancer (ALB). The site serves static content and traffic is increasing. The company wants to minimize hosting costs. Which solution meets these requirements?
- A company hosts a website on Amazon EC2 instances behind an Application Load Balancer (ALB). The website serves static content. Traffic is increasing and the company is concerned about rising costs. What should the company do to reduce costs?
- A company hosts an application on Amazon EC2 instances behind an Application Load Balancer (ALB) and uses Amazon Route 53 for DNS. The company needs a managed solution with proactive engagement to detect and respond to DDoS attacks. Which solution meets these requirements?
- A company hosts an application on Amazon EC2 instances in a single Availability Zone. The application uses the transport layer of the OSI model. The company needs to make the application architecture highly available. Which combination of steps will meet this requirement MOST cost-effectively? (Choose two.)
- A company hosts an application on AWS Lambda functions invoked by an Amazon API Gateway API. The Lambda functions save customer data to an Amazon Aurora MySQL database. Whenever the company upgrades the database, the Lambda functions fail to establish database connections until the upgrade is complete, causing customer data to be lost for some events. A solutions architect needs to design a solution that stores customer data created during database upgrades. Which solution will meet these requirements?
- A company hosts an application that uploads files to an Amazon S3 bucket. After upload, files are processed to extract metadata, which takes less than 5 seconds. Upload volume varies from a few files per hour to hundreds of concurrent uploads. Design a cost-effective architecture to meet these requirements. What should the solutions architect recommend?
- A company hosts an application that uses Amazon Cognito for user management. The application fetches data from Amazon DynamoDB via a REST API in Amazon API Gateway. The company wants an AWS-managed solution to control access to the REST API with minimal development effort. Which solution provides the least operational overhead?
- A company hosts an ecommerce application on a single Amazon RDS for MySQL DB instance. The company needs to mitigate the single point of failure with the LEAST implementation effort. Which solution meets this requirement?
- A company hosts an internal serverless application using Amazon API Gateway and AWS Lambda. Employees report high latency when they start using the application each day. The company wants to reduce this latency. Which solution meets the requirement?
- A company hosts core network services, including directory services and DNS, in its on-premises data center. The data center connects to the AWS Cloud using AWS Direct Connect (DX). Additional AWS accounts will need quick, cost-effective, and consistent access to these on-premises services. What should a solutions architect implement to meet these requirements with the LEAST operational overhead?
- A company hosts images of historical events. Users search and view images by the year the event occurred. On average, each image is requested only once or twice per year. The company wants a highly available, cost-effective solution to store and deliver the images. Which solution is MOST cost-effective?
- A company hosts its application on Amazon EC2 instances inside a VPC and creates a dedicated Amazon S3 bucket for each customer. The application must be able to securely access only the S3 buckets that belong to the company’s AWS account. Which solution provides this with the LEAST operational overhead?
- A company hosts its main public web application in one AWS Region across multiple Availability Zones. The application uses an Amazon EC2 Auto Scaling group and an Application Load Balancer (ALB). A web development team needs a cost-optimized compute solution to improve delivery of dynamic content globally to millions of customers. Which solution meets these requirements?
- A company hosts its public ecommerce website on AWS. The site uses an AWS Global Accelerator accelerator for internet traffic. The accelerator forwards traffic to an Application Load Balancer (ALB) that fronts an Auto Scaling group. The company recently detected a DDoS attack and wants a solution to mitigate future attacks with the LEAST implementation effort. Which solution meets these requirements?
- A company hosts its web application on AWS and wants to ensure all Amazon EC2 instances, Amazon RDS DB instances, and Amazon Redshift clusters are configured with tags. The company wants to minimize the effort to configure and operate this check. What should a solutions architect do to accomplish this?
- A company hosts its web application on AWS using seven Amazon EC2 instances. The company requires that the IP addresses of all healthy EC2 instances be returned in DNS query responses. Which Route 53 routing policy should be used to meet this requirement?
- A company hosts its web applications in the AWS Cloud. Elastic Load Balancers use certificates imported into AWS Certificate Manager (ACM). The security team must be notified 30 days before each certificate expires. What should a solutions architect recommend?
- A company hosts its website on an Auto Scaling group of Amazon EC2 instances in a single AWS Region and has no database. The company deploys the website to a second Region for growth and disaster recovery. The company wants to distribute traffic across both Regions and ensure traffic is not routed to a Region where the website is unhealthy. Which policy or resource should the company use to meet these requirements?
- A company hosts more than 300 global websites and applications and needs a platform to analyze over 30 TB of clickstream data per day. What should a solutions architect use to ingest and process the clickstream data?
- A company hosts multi-tier applications on AWS and must, for compliance and security, track configuration changes on its AWS resources and record a history of API calls made to these resources. What should a solutions architect do to meet these requirements?
- A company in the ap-northeast-1 Region has thousands of AWS Outposts servers at remote locations. Servers regularly download new software releases composed of 100 files, and deployments currently take a long time to complete. The company needs to reduce deployment latency for new releases with the least operational overhead. Which solution meets this requirement?
- A company ingests customer payment data into an Amazon S3 data lake. Payment data arrives on average once per minute. The company needs real-time analysis of the payment data and then ingestion into the data lake. Which solution provides the MOST operational efficiency?
- A company ingests large volumes of streaming data from an application running on Amazon EC2. The app sends data to Amazon Kinesis Data Streams configured with default settings. Every other day the application consumes the data and writes it to an Amazon S3 bucket for BI processing. The company finds that S3 is not receiving all the data sent to Kinesis Data Streams. What should a solutions architect do to resolve this?
- A company is building a cloud communications platform driven by APIs. The application runs on Amazon EC2 instances behind a Network Load Balancer (NLB), and external users access the application through Amazon API Gateway. The company needs protection from web exploits such as SQL injection and also wants to detect and mitigate large, sophisticated DDoS attacks. Which combination of solutions provides the MOST protection? (Choose two.)
- A company is building a data analysis platform on AWS using AWS Lake Formation to ingest data from sources such as Amazon S3 and Amazon RDS. The company needs a secure solution to prevent access to portions of data that contain sensitive information with the LEAST operational overhead. Which solution should be used?
- A company is building a file-sharing application that stores files in an Amazon S3 bucket and serves them via an Amazon CloudFront distribution. The company does not want users to access files directly through the S3 URL. What should a solutions architect do to satisfy these requirements?
- A company is building a game system that must send unique events concurrently to separate leaderboard, matchmaking, and authentication services. The system must also guarantee the order of events. Which solution meets these requirements?
- A company is building a marketing communications service that targets mobile app users. It must send confirmation messages via Short Message Service (SMS) and allow users to reply to those SMS messages. The company must retain the responses for one year for analysis. What should a solutions architect implement to meet these requirements?
- A company is building a microservices application that exposes a search catalog via REST APIs. The backend services run in containers in private VPC subnets. Which solution will meet these requirements?
- A company is building a microservices application using containers on AWS. The company wants to minimize ongoing maintenance and scaling effort and cannot manage additional infrastructure. Which combination of actions should a solutions architect take to meet these requirements? (Choose two.)
- A company is building a microservices-based application to deploy on Amazon Elastic Kubernetes Service (Amazon EKS). The microservices will call each other. The company wants the application to be observable so it can identify future performance issues. Which solution meets these requirements?
- A company is building a mobile app and expects millions of users. Authorized users must be able to stream the company’s content to their mobile devices. What should a solutions architect recommend?
- A company is building a mobile app that streams slow‑motion video clips. The app uploads raw video files to an Amazon S3 bucket, and clients retrieve videos directly from that bucket. The raw videos are large, causing buffering and playback issues on mobile devices. The company wants to improve performance and scalability while minimizing operational overhead. Which combination of solutions will meet these requirements? (Choose two.)
- A company is building a multi-tier web application with: web and application servers on Amazon EC2 Auto Scaling groups, and an Amazon RDS DB instance. The solutions architect must restrict access to the application servers so only the web servers can reach them. Which solution meets this requirement?
- A company is building a new application that will store a large and growing amount of data. The data will be analyzed hourly and will be modified by multiple Amazon EC2 Linux instances deployed across multiple Availability Zones. Which storage solution should a solutions architect recommend to meet these requirements?
- A company is building a new data platform that will ingest real-time streaming data from multiple sources. The data must be transformed before being written to Amazon S3, and the company needs to run SQL queries against the transformed data. Which solutions meet these requirements? (Choose two.)
- A company is building a new dynamic ordering website. The company wants to minimize server maintenance and patching. The website must be highly available and must scale read and write capacity as quickly as possible to meet changes in user demand. Which solution will meet these requirements?
- A company is building a new machine learning solution on AWS. Models are implemented as independent microservices that download about 1 GB of model data from Amazon S3 at startup and load it into memory. Users access models via an asynchronous API: they submit a request or a batch of requests and specify where results should be sent. Hundreds of users will use the models with irregular usage patterns—some models may be idle for days or weeks, while others receive bursts of thousands of requests. Which design should a solutions architect recommend to meet these requirements?
- A company is building a new mobile app and must apply traffic filtering to protect its Application Load Balancer (ALB) from common application-layer attacks such as cross-site scripting and SQL injection. The company has minimal infrastructure and operational staff and wants to reduce its operational responsibility for managing and updating servers. What should a solutions architect recommend?
- A company is building a new web-based customer relationship management application. The application will use several Amazon EC2 instances that are backed by Amazon Elastic Block Store (Amazon EBS) volumes behind an Application Load Balancer (ALB). The application will also use an Amazon Aurora database. All data for the application must be encrypted at rest and in transit. Which solution will meet these requirements?
- A company is building a RESTful serverless web application on AWS using Amazon API Gateway and AWS Lambda. Users are geographically distributed and the company wants to reduce API request latency for those users. Which type of API Gateway endpoint should a solutions architect use?
- A company is building a serverless application with an Amazon API Gateway REST API and AWS Lambda functions. The company needs a service that sends messages received from the API Gateway to multiple target Lambda functions and supports message filtering so each function receives only the messages it needs, with the LEAST operational overhead. Which solution meets these requirements?
- A company is building a shopping application on AWS. The catalog changes once per month and must scale with traffic. The company wants the lowest possible latency. Each user's shopping cart data must be highly available and must persist if the user disconnects and later reconnects. What should a solutions architect do to ensure shopping cart data is preserved at all times?
- A company is building a three-tier application on AWS: a static website for the presentation tier, a containerized application for the logic tier, and a relational database for storage. The company wants to simplify deployment and reduce operational costs. Which solution meets these requirements?
- A company is building a web application that hosts a content management system on Amazon EC2 instances behind an Application Load Balancer. The EC2 instances run in an Auto Scaling group across multiple Availability Zones. Users constantly add and update files, blogs, and other website assets in the content management system. A solutions architect must implement a solution so that all EC2 instances share up-to-date website content with minimal lag. Which solution meets these requirements?
- A company is building an Amazon Elastic Kubernetes Service (Amazon EKS) cluster for its workloads. All secrets that are stored in Amazon EKS must be encrypted in the Kubernetes etcd key-value store. Which solution will meet these requirements?
- A company is building an application on AWS that connects to an Amazon RDS database. The company wants to manage application configuration and securely store and retrieve database and other service credentials. Which solution meets these requirements with the LEAST administrative overhead?
- A company is building an application that provides order shipping statistics via a REST API. The company needs to extract those statistics, format them into HTML, and email the report to multiple addresses at the same time each morning. Which two steps should a solutions architect take to meet these requirements? (Choose two.)
- A company is building an application to transfer data to a product manufacturer. The company uses its own identity provider (IdP) and requires that the IdP authenticate application users during data transfer. The transfer must use the Applicability Statement 2 (AS2) protocol. Which solution meets these requirements?
- A company is building an ecommerce application and must store sensitive customer information while allowing customers to complete purchases. The company also needs to ensure sensitive customer data is protected even from database administrators. Which solution meets these requirements?
- A company is building an ecommerce web application on AWS. The application sends information about new orders to an Amazon API Gateway REST API to process. The company must ensure that orders are processed in the order they are received. Which solution meets this requirement?
- A company is concerned about web attacks against its public application, which uses an Application Load Balancer (ALB). A solutions architect must reduce the risk of DDoS attacks against the application. What should the solutions architect do?
- A company is concerned that two NAT instances cannot support the required traffic. A solutions architect wants a highly available, fault-tolerant, and automatically scalable solution. What should the solutions architect recommend?
- A company is consolidating many standalone AWS accounts into a multi-account architecture and will create new accounts for business units. The company needs centralized authentication to these accounts using its corporate directory. Which combination of actions should a solutions architect recommend? (Choose two.)
- A company is creating a new web application for its subscribers. The application will consist of a static single page and a persistent database layer. Traffic peaks at millions of users for 4 hours each morning, and drops to only a few thousand users for the rest of the day. The company's data architects require the ability to rapidly evolve their schema. Which solutions will meet these requirements and provide the MOST scalability? (Choose two.)
- A company is creating a prototype of an ecommerce website on AWS. The website consists of an Application Load Balancer, an Auto Scaling group of Amazon EC2 instances for web servers, and an Amazon RDS for MySQL DB instance that runs with the Single-AZ configuration. The website is slow to respond during searches of the product catalog. The product catalog is a group of tables in the MySQL database that the company does not update frequently. A solutions architect has determined that the CPU utilization on the DB instance is high when product catalog searches occur. What should the solutions architect recommend to improve the performance of the website during searches of the product catalog?
- A company is creating a REST API and requires TLSv1.3 on the API endpoints and a specific public third-party certificate authority (CA) to sign the TLS certificate. Which solution meets these requirements?
- A company is deploying a new application to Amazon EKS with AWS Fargate. The application needs persistent storage that is highly available, fault tolerant, and shared among multiple containers. Which solution meets these requirements with the LEAST operational overhead?
- A company is deploying a public web application to AWS behind an Application Load Balancer (ALB). The application must be encrypted at the edge with an SSL/TLS certificate that is issued by an external certificate authority (CA). The certificate must be rotated annually before expiration. What should a solutions architect do to meet these requirements?
- A company is deploying a serverless workload. A solutions architect must follow least privilege when configuring permissions for an AWS Lambda function. An Amazon EventBridge (Amazon CloudWatch Events) rule will invoke the function. Which solution meets these requirements?
- A company is deploying an application in three AWS Regions using an Application Load Balancer. Amazon Route 53 will distribute traffic across these Regions. Which Route 53 configuration should a solutions architect use to provide the MOST high-performing experience?
- A company is deploying an application on Amazon EC2 instances that writes to Amazon Elastic Block Store (Amazon EBS) volumes. The company must ensure all data written to the EBS volumes is encrypted at rest. Which solution meets this requirement?
- A company is deploying an application that processes large quantities of data in parallel. The company plans to use Amazon EC2 instances for the workload. The network architecture must be configurable to prevent groups of nodes from sharing the same underlying hardware. Which networking solution meets these requirements?
- A company is deploying an application that processes streaming data in near-real time on Amazon EC2 instances. The network architecture must be configurable to provide the lowest possible latency between nodes. Which combination of network solutions will meet these requirements? (Choose two.)
- A company is designing a containerized application on Amazon Elastic Container Service (Amazon ECS). The application needs a shared file system that is highly durable, provides mount targets in each Availability Zone in a Region, and can recover data to another Region with an RPO of 8 hours. A solutions architect wants to use AWS Backup to manage cross‑Region replication. Which solution meets these requirements?
- A company is designing a disaster recovery (DR) strategy for a production application backed by an Amazon Aurora MySQL cluster in the us-east-1 Region. The DR Region is us-west-1. The company's RPO is 5 minutes and RTO is 20 minutes. The company wants to minimize configuration changes and maximize operational efficiency. Which solution meets these requirements?
- A company is designing a new mobile app architecture in the AWS Cloud. The company uses organizational units (OUs) in AWS Organizations to manage accounts. The company wants EC2 instances to be tagged with data sensitivity using values of sensitive and nonsensitive. IAM identities must not be able to delete the tag or create instances without a tag. Which combination of steps will meet these requirements? (Choose two.)
- A company is designing a new web service that will run on Amazon EC2 instances behind an Elastic Load Balancing (ELB) load balancer. Many web service clients can only reach IP addresses authorized on their firewalls. What should a solutions architect recommend to meet the clients’ needs?
- A company is designing a solution to capture customer activity in different web applications to process analytics and make predictions. Customer activity in the web applications is unpredictable and can increase suddenly. The company requires a solution that integrates with other web applications. The solution must include an authorization step for security purposes. Which solution will meet these requirements?
- A company is designing a tightly coupled high-performance computing (HPC) environment in AWS and needs to optimize networking and storage for HPC. Which two solutions together meet these requirements? (Choose two.)
- A company is designing a web application on AWS that uses a VPN connection between its on-premises data centers and its VPCs. The company uses Amazon Route 53 for DNS. The application must use private DNS records so VPC resources can resolve on-premises services. Which solution meets these requirements in the MOST secure manner?
- A company is designing a web application on AWS to process insurance quotes. Users request quotes. Quotes must be separated by quote type, be responded to within 24 hours, and must not be lost. The solution should maximize operational efficiency and minimize maintenance. Which solution meets these requirements?
- A company is designing a web application with an internet-facing Application Load Balancer (ALB). The ALB must receive HTTPS traffic from the public internet, send only HTTPS traffic to EC2 web servers on port 443, and perform health checks over HTTPS on port 8443. Which combination of security group rules for the ALB will satisfy these requirements? (Choose three.)
- A company is designing an event-driven order processing system. Each order requires multiple independent validation steps. Each validation step is implemented as an idempotent AWS Lambda function and needs only a subset of the order event data. The components must be loosely coupled and each validation Lambda should receive only the data it requires. Which solution meets these requirements?
- A company is designing shared storage for a gaming application hosted in AWS. The storage must be accessible by SMB clients and be fully managed. Which AWS solution meets these requirements?
- A company is designing the network for an online multiplayer game that uses the UDP protocol and will deploy in eight AWS Regions. The architecture must minimize latency and packet loss to provide a high-quality gaming experience. Which solution meets these requirements?
- A company is developing a containerized application in a VPC that stores and accesses data in an Amazon S3 bucket. During development the application will transfer about 1 TB of S3 data per day. The company wants to minimize costs and avoid routing traffic over the internet when possible. Which solution meets these requirements?
- A company is developing a global mobile gaming app in a single AWS Region. The app runs on multiple Amazon EC2 instances in an Auto Scaling group, stores data in Amazon DynamoDB, and uses both TCP and UDP traffic between users and servers. The company requires the lowest possible latency for users worldwide. Which solution meets these requirements?
- A company is developing a mobile game that streams score updates to a backend processor and then posts results to a leaderboard. The solution must handle large traffic spikes, process updates in the order received, store processed updates in a highly available database, and minimize management overhead. What should the solutions architect implement?
- A company is developing a new application on AWS. The application includes an Amazon ECS cluster, an Amazon S3 bucket that stores application assets, and an Amazon RDS for MySQL database that contains a sensitive dataset. The company wants to ensure that only the ECS cluster can access the RDS database and the S3 bucket. Which solution meets these requirements?
- A company is developing a real-time multiplayer game that uses UDP between clients and servers in an Auto Scaling group. The game server platform must scale for spikes in demand, and developers want to store gamer scores and other non-relational data in a database that scales without intervention. Which solution should a solutions architect recommend?
- A company is developing a two-tier web application on AWS. Developers deployed the application on an Amazon EC2 instance that connects directly to a backend Amazon RDS database. The company must not hardcode database credentials in the application and must automatically rotate the database credentials on a regular schedule. Which solution meets these requirements with the LEAST operational overhead?
- A company is developing an application in AWS. The application's HTTP API is published in Amazon API Gateway and contains critical information that must be accessible only from a limited set of trusted IP addresses from the company's internal network. Which solution meets this requirement?
- A company is developing an application that uses a relational database for user data and configurations. Growth is expected to be steady; the workload will be variable and read-heavy with occasional writes. The company wants a cost-optimized, AWS-managed database that provides necessary performance. Which solution is MOST cost-effective?
- A company is developing an ecommerce application that will consist of a load-balanced front end, a container-based application, and a relational database. A solutions architect needs to create a highly available solution that operates with as little manual intervention as possible. Which solutions meet these requirements? (Choose two.)
- A company is developing machine learning models on AWS as independent microservices. Each microservice fetches about 1 GB of model data from Amazon S3 at startup and loads it into memory. Users access the ML models via an asynchronous API and can send single or batch requests. The company serves hundreds of users. Usage patterns are irregular: some models may be idle for days or weeks while others receive batches of thousands of requests. Which solution will meet these requirements?
- A company is developing software that uses a PostgreSQL database schema. The company needs to configure multiple development environments and databases for the company's developers. On average, each development environment is used for half of the 8-hour workday. Which solution will meet these requirements MOST cost-effectively?
- A company is extending a secure on-premises network to AWS using AWS Direct Connect. The on-premises network has no direct internet access. An on-premises application needs to access an Amazon S3 bucket. Which solution meets these requirements MOST cost-effectively?
- A company is hosting a website behind multiple Application Load Balancers. The company has different distribution rights for its content around the world. A solutions architect needs to ensure that users are served the correct content without violating distribution rights. Which configuration should the solutions architect choose to meet these requirements?
- A company is implementing a shared storage solution for a media application hosted in the AWS Cloud. The company needs SMB client access and a fully managed service. Which AWS solution meets these requirements?
- A company is implementing shared storage for a gaming application hosted in an on-premises data center and needs clients that use the Lustre protocol to access data. The solution must be fully managed. Which solution meets these requirements?
- A company is implementing shared storage for a media application hosted on AWS. The application requires SMB client access. Which solution meets these requirements with the LEAST administrative overhead?
- A company is launching a new application on an Amazon ECS cluster using the Fargate launch type. The company monitors CPU and memory because it expects high traffic at launch but wants to reduce costs when utilization decreases. What should a solutions architect recommend?
- A company is launching a new application that requires a structured database to store user profiles, application settings, and transactional data. The database must be scalable with application traffic and must offer backups. Which solution will meet these requirements MOST cost-effectively?
- A company is launching an application on AWS that uses an Application Load Balancer (ALB) to direct traffic to at least two Amazon EC2 instances in a single target group. Each environment uses an Auto Scaling group. The company requires both a development environment and a production environment; production will experience periods of high traffic. Which change configures the development environment MOST cost-effectively?
- A company is migrating a commercial off-the-shelf application to AWS. The software licensing model uses sockets and cores, with predictable capacity and uptime. The company wants to use its existing licenses purchased earlier this year. Which Amazon EC2 pricing option is MOST cost-effective?
- A company is migrating a data center to AWS. Several legacy applications run on individual virtual servers and cannot be redesigned. Each virtual server currently runs as its own EC2 instance. A solutions architect must ensure the applications are reliable and fault tolerant after migration. The applications will run on Amazon EC2 instances. Which solution meets these requirements?
- A company is migrating a distributed application to AWS. The legacy platform has a primary server that coordinates jobs across multiple compute nodes. The application serves variable workloads. The company wants to modernize the application to maximize resiliency and scalability. How should a solutions architect design the architecture to meet these requirements?
- A company is migrating a large amount of data from on-premises storage to AWS. Windows, Mac, and Linux Amazon EC2 instances in the same Region will access the data using SMB and NFS. Some data will be accessed routinely; the rest will be accessed infrequently. The company needs a storage solution with the LEAST operational overhead. Which solution meets these requirements?
- A company is migrating a microservices application from Amazon EC2 to Amazon Elastic Kubernetes Service (Amazon EKS). The EKS control plane must have endpoint private access = true and endpoint public access = false. The data plane nodes are placed in private subnets, but nodes are failing to join the cluster. Which solution will allow nodes to join the cluster?
- A company is migrating a monolithic web application on Amazon EC2 to a serverless microservices architecture and wants an event-driven, loosely coupled design using the publish/subscribe pattern. Which solution is the most cost-effective?
- A company is migrating a multi-tier on-premises application to AWS. The app uses a single-node MySQL database and a multi-node web tier. The company wants to minimize application changes during migration and improve resiliency afterward. Which combination of steps will meet these requirements? (Choose two.)
- A company is migrating a three-tier application to AWS that requires a MySQL database. Previously, users experienced poor performance creating new entries because users generated different real-time reports during working hours. Which solution will improve application performance after the migration to AWS?
- A company is migrating an application from on-premises to Amazon Elastic Kubernetes Service (Amazon EKS). The company must assign pods to custom subnets in the company's VPC to meet compliance, and ensure pods can communicate securely within that VPC. Which solution meets these requirements?
- A company is migrating an application to Amazon EC2 instances and must implement infrastructure metric alarms. Short bursts above 50% CPU utilization do not require action, but if CPU utilization rises above 50% at the same time that disk read IOPS are high, the company must act immediately. The solutions architect must also reduce false alarms. What should the solutions architect do to meet these requirements?
- A company is migrating an application to AWS and must encrypt sensitive data before storing it in Amazon S3. Which solution meets this requirement?
- A company is migrating an old application to AWS. The app runs a CPU-intensive batch job every hour that takes 15 minutes on average on an on-premises server with 64 vCPU and 512 GiB memory. Which solution will complete the batch job within 15 minutes with the LEAST operational overhead?
- A company is migrating an on-premises application to AWS and plans to use Amazon Redshift. Which of the following use cases are suitable for Amazon Redshift in this scenario? (Choose three.)
- A company is migrating an on-premises data center to AWS. The data center hosts a storage server that uses NFS and contains 200 GB of data. The migration must not interrupt existing services, and multiple AWS resources must be able to access the data via NFS. Which combination of steps will meet these requirements MOST cost-effectively? (Choose two.)
- A company is migrating an on-premises Oracle database to Amazon RDS for Oracle. The company must retain data for 90 days for regulatory reasons and be able to restore to any point in time for up to 14 days. Which solution meets these requirements with the LEAST operational overhead?
- A company is migrating an Oracle database to AWS. The database contains a single table with millions of high-resolution GIS images, each identified by a geographic code. During natural disasters, tens of thousands of images are updated every few minutes. Each geographic code maps to a single image. The company requires a highly available, scalable, and cost-effective solution for these events. Which solution best meets these requirements?
- A company is migrating applications and databases to AWS using Amazon ECS, AWS Direct Connect, and Amazon RDS. Which activities will be managed by the company's operations team? (Choose three.)
- A company is migrating applications from a self-managed on-premises Microsoft Active Directory to AWS. The applications run in multiple AWS accounts managed centrally with AWS Organizations. The security team needs single sign-on across all AWS accounts while continuing to manage users and groups in the on-premises Active Directory. Which solution meets these requirements?
- A company is migrating data and applications to AWS. The company needs secure access to data in Amazon S3 from the AWS Region and from the on-premises location without the data traversing the internet. The company already has an AWS Direct Connect connection between the Region and on-premises. Which solution meets these requirements?
- A company is migrating databases to Amazon RDS for PostgreSQL and applications to Amazon EC2 instances. The company wants to optimize costs for long-running workloads most cost-effectively. Which solution meets this requirement?
- A company is migrating five on-premises applications to VPCs in AWS. Each application is currently deployed in isolated on-premises virtual networks and should remain isolated in AWS. The applications must reach a shared services VPC, and all applications must be able to communicate with each other. If the migration succeeds, the company will repeat this for more than 100 applications. Which solution meets these requirements with the LEAST administrative overhead?
- A company is migrating its data processing application to AWS. The application runs several short-lived batch jobs that must not be disrupted. Data is generated after each batch job completes. The data is actively accessed for 30 days and then retained for 2 years. The company wants to minimize cloud costs. Which solution meets these requirements?
- A company is migrating its on-premises PostgreSQL database to Amazon Aurora PostgreSQL. The on-premises database must remain online and accessible during migration, and the Aurora database must stay synchronized with the on-premises database. Which combination of actions must a solutions architect take? (Choose two.)
- A company is migrating latency-sensitive HPC workloads that currently use on-premises NAS file shares. The company needs to provide NFS and SMB multi-protocol access and achieve the LEAST possible latency in AWS. Which combination of actions will meet these requirements with the least latency? (Choose two.)
- A company is migrating Linux-based web servers to AWS. The web servers must access files in a shared file store, and the application cannot be changed. What should a solutions architect do?
- A company is migrating millions of 10 KB files from on-premises to Amazon S3 using AWS DataSync. For the first year, each file will be accessed once or twice and must be immediately available. After one year, files must be archived for at least 7 years. Which solution is the most cost-effective?
- A company is migrating workloads to AWS. It has sensitive and critical data in on-premises relational databases running SQL Server. The company wants to increase security and reduce operational overhead in the cloud. Which solution meets these requirements?
- A company is migrating workloads to AWS. The company stores transactional and sensitive database data and wants to increase security while reducing operational overhead. Which solution meets these requirements?
- A company is moving a containerized application from on-premises to AWS. The application will have thousands of users soon after deployment, and the company prefers to minimize operational overhead when managing containers at scale. Which solution meets these requirements with high availability and low operational overhead?
- A company is moving its data management application to AWS and wants to adopt an event-driven, distributed, serverless workflow with minimal operational overhead. Which solution meets these requirements?
- A company is moving its on-premises Oracle database to Amazon Aurora PostgreSQL. The database has several applications that write to the same tables. The applications need to be migrated one by one with a month in between each migration. Management has expressed concerns that the database has a high number of reads and writes. The data must be kept in sync across both databases throughout the migration. What should a solutions architect recommend?
- A company is moving Windows Server SMB file shares to AWS and wants to use Amazon FSx for Windows File Server. Access is controlled by a self-managed on‑premises Active Directory, and the company must ensure the existing Active Directory groups continue to restrict access to FSx SMB shares, folders, and files after migration. The FSx for Windows File Server file system has been created. Which solution meets these requirements?
- A company is preparing a public-facing web application on Amazon EC2 instances in a VPC behind an Elastic Load Balancer (ELB). The company uses a third-party DNS provider. The solutions architect must recommend a solution to detect and protect against large-scale DDoS attacks. Which solution meets these requirements?
- A company is testing an application running on an Amazon EC2 Linux instance. A single 500 GB Amazon Elastic Block Store (Amazon EBS) General Purpose SSD (gp2) volume is attached to the EC2 instance. The company will deploy the application on multiple EC2 instances in an Auto Scaling group. All instances require access to the data stored on the EBS volume. The company needs a highly available and resilient solution that does not require significant application code changes. Which solution meets these requirements?
- A company is using a SQL database running on an Amazon RDS Single-AZ DB instance to store publicly accessible movie data. A script runs queries at random intervals each day to record the number of new movies added. The script must report a final total during business hours. The development team notices database performance is inadequate for development tasks while the script runs. A solutions architect must recommend a solution with the LEAST operational overhead. Which solution will meet this requirement?
- A company is using an Application Load Balancer (ALB) to present its application to the internet. The company observes abnormal traffic access patterns across the application. A solutions architect needs to improve visibility into the infrastructure to help the company analyze these abnormalities. What is the MOST operationally efficient solution that meets these requirements?
- A company launched a new application that runs on multiple Amazon EC2 instances across two Availability Zones. End users communicate with the application over TCP. The application must be highly available and automatically scale as user load increases. Which combination of steps will meet these requirements MOST cost-effectively? (Choose two.)
- A company launched an Amazon RDS for MySQL DB instance. Most connections come from serverless applications, and traffic spikes unpredictably. During high demand, applications receive database connection rejection errors. Which solution will resolve this issue with the least operational overhead?
- A company launched Linux application instances on Amazon EC2 in a private subnet and a Linux bastion host on an EC2 instance in a public subnet. A solutions architect must enable connections from the on-premises network (via the company internet connection) to the bastion host and then to the application servers. The security groups on all EC2 instances must allow this access. Which combination of steps should the solutions architect take? (Choose two.)
- A company lets users upload photos to an Amazon S3 bucket in eu-west-1 and wants to use CloudFront with a custom domain to upload the files. Which solutions will meet these requirements? (Choose two.)
- A company maintains a searchable repository of items in an Amazon RDS for MySQL database table with more than 10 million rows and 2 TB of General Purpose SSD storage. Millions of updates occur daily, and some insert operations are taking 10 seconds or longer due to database storage performance. Which solution addresses this performance issue?
- A company manages a data lake in an Amazon S3 bucket that many applications access. The bucket uses a unique prefix for each application. The company wants to restrict each application to its specific prefix and have granular control over objects under each prefix. Which solution meets these requirements with the LEAST operational overhead?
- A company manually manages MySQL databases on Amazon EC2, including replication and scaling. The company wants a solution that simplifies adding or removing compute capacity for the database tier, and that improves performance, scaling, and durability with minimal operational effort. Which solution meets these requirements?
- A company manually provisioned a prototype infrastructure that includes an Auto Scaling group, an Application Load Balancer, and an Amazon RDS database. After validating the configuration, the company wants the ability to instantly deploy the same infrastructure for development and production across two Availability Zones in an automated way. What should a solutions architect recommend?
- A company migrated a message-processing system to AWS. Messages are received in an ActiveMQ queue on an Amazon EC2 instance, processed by a consumer application on Amazon EC2, and results are written to a MySQL database on Amazon EC2. The company wants the application to be highly available with low operational complexity. Which architecture offers the HIGHEST availability?
- A company migrated a monolithic application to a single Amazon EC2 instance and Amazon RDS. The application modules are tightly coupled so the app runs on only one EC2 instance. The EC2 instance experiences high CPU utilization during peak times, and RDS read performance degrades. The company wants to reduce EC2 CPU usage and improve RDS read performance. Which solution meets these requirements?
- A company migrated a MySQL database from the company's on-premises data center to an Amazon RDS for MySQL DB instance. The company sized the RDS DB instance to meet the company's average daily workload. Once a month, the database performs slowly when the company runs queries for a report. The company wants to have the ability to run reports and maintain the performance of the daily workloads. Which solution will meet these requirements?
- A company migrated a two-tier application to AWS. The data tier is a Multi-AZ Amazon RDS for Oracle deployment with 12 TB of General Purpose SSD Amazon EBS storage. The application stores documents as BLOBs (average 6 MB). Database growth has reduced performance and increased storage costs. The company needs higher performance and a highly available, resilient, cost-effective solution. Which option meets these requirements?
- A company migrated an application to Amazon EC2 Linux instances. One EC2 instance runs several 1-hour scheduled tasks written in different languages. The company is concerned about performance and scalability when those tasks run on a single instance. Which solution will address these concerns with the LEAST operational overhead?
- A company migrated hundreds of on-premises VMs to Amazon EC2. The instances run various Windows Server versions and several Linux distributions. The company needs to automate OS inventory and updates, and produce a monthly summary of common vulnerabilities for each instance. What should a solutions architect recommend?
- A company migrated its application to AWS. The application runs on Amazon EC2 Linux instances in an Auto Scaling group across multiple Availability Zones. Files are stored on an Amazon Elastic File System (Amazon EFS) file system that uses EFS Standard-Infrequent Access storage. The application indexes the files and stores the index in an Amazon RDS database. The company wants to reduce storage costs with minimal changes to the application and services. Which solution will meet these requirements MOST cost-effectively?
- A company migrated its web application to AWS. The application currently runs multiple processes on a single EC2 instance: an Apache web server that serves static content, a PHP application, and a local Redis server used for sessions. The company wants a highly available redesign that uses AWS managed services. Which solution meets these requirements?
- A company migrated millions of archival files to Amazon S3. The solutions architect must encrypt all archival data using a customer-provided key, and the solution must encrypt both existing unencrypted objects and future objects. Which solution meets these requirements?
- A company migrated several applications to AWS in the past 3 months and needs a regular report showing cost breakdowns per application. Which is the most cost-effective solution?
- A company migrated to AWS and needs to protect traffic flowing in and out of its production VPC. Previously an on-premises inspection server performed traffic inspection and filtering. The company wants the same functionality in AWS. Which solution meets these requirements?
- A company migrates applications to AWS across multiple accounts managed with AWS Organizations. The security team needs single sign-on (SSO) across all accounts while continuing to manage users and groups in the on-premises self-managed Microsoft Active Directory. Which solution meets these requirements?
- A company migrating on-premises workloads to AWS already uses several Amazon EC2 instances and Amazon RDS DB instances. The company wants to automatically start and stop the EC2 instances and DB instances outside business hours, minimizing cost and infrastructure maintenance. Which solution meets these requirements?
- A company moved all media rendering data from on premises to Amazon S3 to reduce storage costs. The on-premises rendering application requires low-latency access to storage and must maintain its performance. Which storage solution meets these requirements MOST cost-effectively?
- A company moved its on-premises PostgreSQL database to an Amazon RDS for PostgreSQL DB instance. After launching a new product, the database workload increased. The company wants to accommodate the larger workload without adding infrastructure and in the MOST cost-effective way. Which solution meets these requirements?
- A company must design a resilient web application to process customer orders. The application must automatically handle increases in traffic and usage without degrading the customer experience or losing orders. Which solution meets these requirements?
- A company must enforce new data retention policies for all databases running on Amazon RDS DB instances: retain daily backups for a minimum of 2 years, with backups consistent and restorable. Which solution should a solutions architect recommend?
- A company must grant a team of developers access to its AWS resources while maintaining a high level of security and preventing unauthorized access to sensitive data. Which solution meets these requirements?
- A company must implement a data retention policy for regulatory compliance. Sensitive documents stored in an Amazon S3 bucket must be protected from deletion or modification for a fixed period. Which solution meets these requirements?
- A company must integrate with a third-party data feed that sends a webhook when new data is ready. A developer wrote an AWS Lambda function to retrieve the data when a webhook callback arrives. The developer needs to make the Lambda function available for the third party to call with the MOST operational efficiency. Which solution meets these requirements?
- A company must keep cryptographic keys in its on-premises key manager because of regulatory requirements. The on-premises key manager is outside the AWS Cloud. The company wants to manage encryption and decryption using keys retained outside AWS and that support various external key managers from different vendors. Which solution meets these requirements with the LEAST operational overhead?
- A company must migrate 10 PB of data to Amazon S3 within 6 weeks. The data center has a 500 Mbps internet uplink; other applications share the link. The company can use 80% of the internet bandwidth for this one-time migration. Which solution meets these requirements?
- A company must migrate 20 TB of data from a data center to the AWS Cloud within 30 days. The company’s network bandwidth is limited to 15 Mbps and cannot exceed 70% utilization. What should a solutions architect recommend to meet these requirements?
- A company must migrate a 20 TB MySQL database from its on-premises data center to AWS within 2 weeks, with minimal downtime and cost-effectiveness. Which solution will accomplish the migration MOST cost-effectively?
- A company must migrate its on-premises data center to AWS but, due to compliance, can use only the ap-northeast-3 Region. Company administrators are not allowed to connect VPCs to the internet. Which solutions satisfy these requirements? (Choose two.)
- A company must move data from an Amazon EC2 instance to an Amazon S3 bucket without routing any API calls or data over public internet routes. Only the EC2 instance should be allowed to upload data to the S3 bucket. Which solution meets these requirements?
- A company must predict monthly resource needs for manufacturing processes using historical data stored in an Amazon S3 bucket. The company has no ML experience and wants a managed service for training and predictions. Which combination of steps will meet these requirements? (Choose two.)
- A company must provide customers with secure access to data. The company processes customer data and stores results in an Amazon S3 bucket. The data is subject to strict regulations and must be encrypted at rest. Each customer must be able to access only their own data from their AWS account, and company employees must not be able to access customer data. Which solution meets these requirements?
- A company must retain application log files for 10 years. The application team frequently accesses logs from the past month, while logs older than 1 month are rarely accessed. The application generates more than 10 TB of logs per month. Which storage option is the MOST cost-effective while meeting the retention and access requirements?
- A company must retain user transaction data in an Amazon DynamoDB table for 7 years. What is the MOST operationally efficient solution that satisfies this requirement?
- A company must run a critical application on AWS that uses Amazon EC2 for its database. The database must be highly available and automatically fail over if a disruptive event occurs. Which solution will meet these requirements?
- A company must save medical trial results in an Amazon S3 repository where a few scientists can add new files and all other users have read-only access. No user may modify or delete any files, and every file must be retained for at least 1 year from its creation date. Which solution meets these requirements?
- A company must share accounting data with an external auditor. The data is stored in an Amazon RDS DB instance in a private subnet. The auditor has its own AWS account and requires its own copy of the database. What is the MOST secure way to share the database with the auditor?
- A company must store accounting records in Amazon S3. Records must be immediately accessible for 1 year and then archived for an additional 9 years. No one at the company, including administrators and the root user, can delete the records during the entire 10-year period. The records must be stored with maximum resiliency. Which solution meets these requirements?
- A company must store data from a healthcare application whose data changes frequently. A new regulation requires audit access at all levels of stored data. The application is on-premises and running out of storage. A solutions architect must securely migrate the existing data to AWS while satisfying the regulation. Which solution meets these requirements?
- A company near the eu-central-1 Region must migrate web applications to AWS. Regulations prevent launching some applications in eu-central-1. The company requires single-digit millisecond latency. Which solution meets these requirements?
- A company needs a backup strategy for a three-tier stateless web application. The web tier runs on EC2 instances in an Auto Scaling group with dynamic scaling. The database tier runs on Amazon RDS for PostgreSQL. The web application does not require temporary local storage on the EC2 instances. The recovery point objective (RPO) is 2 hours. The backup strategy must maximize scalability and optimize resource utilization. Which solution will meet these requirements?
- A company needs a backup strategy for Amazon EC2 data and several Amazon S3 buckets. Regulatory requirements mandate that backups be retained for a specific retention period and must not be altered during that period. Which solution meets these requirements?
- A company needs a cost-minimizing solution to archive old news video footage in AWS. Restores will be rare, but when needed files must be available within a maximum of five minutes. What is the MOST cost-effective option?
- A company needs a disaster recovery plan for its primary on-premises file storage volume. The volume is mounted from an Internet Small Computer Systems Interface (iSCSI) device on a local storage server and holds hundreds of terabytes of data. The company requires that end users retain immediate access to all file types from on-premises systems without added latency, and wants the LEAST change to existing infrastructure. Which solution meets these requirements?
- A company needs a fully managed shared storage solution for a gaming application hosted in AWS that must support Lustre clients. Which solution meets these requirements?
- A company needs a hybrid network architecture. Workloads run in AWS and on-premises and require single-digit millisecond latencies. The company uses an AWS Transit Gateway to connect multiple VPCs. Which combination of steps will meet these requirements MOST cost-effectively? (Choose two.)
- A company needs a secure connection between its on-premises environment and AWS for a small amount of traffic. The connection does not require high bandwidth and must be established quickly. What is the MOST cost-effective method to set up this connection?
- A company needs a serverless solution that collects Amazon EC2 Auto Scaling events across all applications in an AWS account and stores the status data in Amazon S3 for near-real-time dashboard updates. The solution must not affect the speed of EC2 instance launches. How should the company move the data to Amazon S3 to meet these requirements?
- A company needs a solution to enforce data encryption at rest on Amazon EC2 instances. The solution must automatically identify noncompliant resources and enforce compliance policies on findings. Which solution will meet these requirements with the LEAST administrative overhead?
- A company needs an AWS Lambda function in its primary account VPC to access files stored in an Amazon EFS file system in a secondary account. As files are added, the solution must scale to meet demand and be cost-effective. Which solution meets these requirements MOST cost-effectively?
- A company needs guaranteed Amazon EC2 capacity in three specific Availability Zones in a specific AWS Region for a 1-week event. What should the company do to guarantee the EC2 capacity?
- A company needs its ecommerce order-processing application on AWS to process each order exactly once, without degrading the customer experience during unpredictable traffic surges. Which solution meets these requirements?
- A company needs private connectivity from its VPC to a service hosted in an external provider's VPC. The connection must be private, restricted to the target service, and must be initiated only from the company's VPC. Which solution meets these requirements?
- A company needs real-time data ingestion: an API, streaming data transformation, and storage, with the LEAST operational overhead. Which solution meets these requirements?
- A company needs the ability to analyze proprietary application log files that are stored in JSON format in an Amazon S3 bucket. Queries will be simple and run on-demand. With minimal changes to the existing architecture and the least operational overhead, what should the solutions architect do?
- A company needs to clone large amounts of production data (stored on Amazon EBS volumes attached to EC2 instances) into a test environment in the same AWS Region. Changes to the cloned data must not affect production. The software requires consistently high I/O performance. A solutions architect must minimize the time required to clone the data. Which solution meets these requirements?
- A company needs to connect several VPCs in the us-east-1 Region that span hundreds of AWS accounts. The company's networking team has its own AWS account to manage the cloud network. What is the MOST operationally efficient solution to connect the VPCs?
- A company needs to create an Amazon Elastic Kubernetes Service (Amazon EKS) cluster using a managed node group backed by Amazon Elastic Block Store (Amazon EBS) volumes. The company must encrypt all data at rest using a customer managed key in AWS Key Management Service (AWS KMS). Which combination of actions will meet this requirement with the LEAST operational overhead? (Choose two.)
- A company needs to export its database once per day to Amazon S3 for other teams to access. Exported object sizes range from 2 GB to 5 GB. The S3 access pattern is variable and changes rapidly. The data must be immediately available and remain accessible for up to 3 months. The company wants the most cost-effective solution without increasing retrieval time. Which S3 storage class should the company use?
- A company needs to extract ingredient names from recipe records stored as text files in an Amazon S3 bucket. A web application will query a DynamoDB table using the ingredient names to determine a nutrition score. The company can tolerate non-food records and errors and has no employees with ML expertise. Which solution is the MOST cost-effective?
- A company needs to give a globally distributed development team secure access to AWS resources in compliance with security policies. The company uses an on-premises Active Directory for internal authentication and AWS Organizations to manage multiple AWS accounts across projects. The company wants a solution that integrates with existing infrastructure and provides centralized identity management and access control with the LEAST operational overhead. Which solution meets these requirements?
- A company needs to migrate 100 GB of historical data from on premises to an Amazon S3 bucket. The on-premises site has a 100 megabits per second (Mbps) internet connection. Data must be encrypted in transit. New data will be written directly to Amazon S3. Which solution meets these requirements with the LEAST operational overhead?
- A company needs to move 50 TB of data from on premises to AWS. A custom application in the data center runs a weekly data transformation job; the company will pause the application until the transfer completes and needs to resume the transformation job in AWS as soon as possible. The data center has no available network bandwidth for additional workloads. Which solution transfers the data and enables the transformation job to run in AWS with the LEAST operational overhead?
- A company needs to optimize Amazon S3 costs for an application that generates many non-recreatable files of about 5 MB each, stored in S3 Standard. Files must be retained for 4 years and be immediately accessible. They are frequently accessed during the first 30 days and rarely accessed afterwards. Which solution is MOST cost-effective?
- A company needs to prevent photos containing unwanted content from being uploaded to its web application. The solution must not involve training an ML model. Which solution meets these requirements?
- A company needs to provide employees with secure access to confidential files so that only authorized users can download them to their devices. The files are on an on-premises Windows file server that is running out of capacity because of increased remote usage. Which solution will meet these requirements?
- A company needs to reduce storage costs. All data is currently in the Amazon S3 Standard storage class. Data must be retained for at least 25 years. Data from the most recent 2 years must be highly available and immediately retrievable. Which solution meets these requirements?
- A company needs to reduce the cost of its Amazon EC2 instances. The company also changes the instance type and instance family every 2–3 months. What should the company do to meet these requirements?
- A company needs to review its AWS deployment to ensure Amazon S3 buckets do not have unauthorized configuration changes. What should a solutions architect do to accomplish this?
- A company needs to run an in‑memory database for a latency‑sensitive application on Amazon EC2. The app processes over 100,000 transactions per minute and requires high network throughput. A solutions architect must design a cost‑effective network layout that minimizes data transfer charges. Which solution meets these requirements?
- A company needs to securely transfer 50 TB of data to AWS within 2 weeks. The on-premises Site-to-Site VPN to AWS is already 90% utilized. Which AWS service should a solutions architect use to meet these requirements?
- A company needs to securely transfer data from its Salesforce SaaS account to Amazon S3. The data must be encrypted at rest with AWS Key Management Service (AWS KMS) customer managed keys (CMKs) and encrypted in transit. The Salesforce account has API access enabled. Which solution will meet these requirements?
- A company needs to store contract documents. A contract lasts for 5 years. During the 5-year period, the company must ensure that the documents cannot be overwritten or deleted. The company needs to encrypt the documents at rest and rotate the encryption keys automatically every year. Which combination of steps should a solutions architect take to meet these requirements with the LEAST operational overhead? (Choose two.)
- A company needs to store data in Amazon S3 and must prevent the data from being changed. New objects uploaded to S3 must remain immutable for an unspecified period until the company chooses to modify them. Only specific users in the AWS account should be able to delete the objects. What should a solutions architect do to meet these requirements?
- A company needs to transfer 600 TB of data from an on-premises NAS to AWS within 2 weeks. The data is sensitive and must be encrypted in transit. The company’s internet upload speed is 100 Mbps. Which solution meets these requirements MOST cost-effectively?
- A company needs to use its on-premises LDAP directory to authenticate users to the AWS Management Console, but the directory service is not SAML-compatible. Which solution meets this requirement?
- A company operates a food delivery service. Because of recent growth, the company's order processing system is experiencing scaling problems during peak traffic hours. The current architecture includes Amazon EC2 instances in an Auto Scaling group that collect orders from an application. A second group of EC2 instances in an Auto Scaling group fulfills the orders. The order collection process occurs quickly, but the order fulfillment process can take longer. Data must not be lost because of a scaling event. A solutions architect must ensure that the order collection process and the order fulfillment process can both scale adequately during peak traffic hours. Which solution will meet these requirements?
- A company operates a two-tier application for image processing. The application uses two Availability Zones, each with one public subnet and one private subnet. An Application Load Balancer (ALB) for the web tier uses the public subnets. Amazon EC2 instances for the application tier use the private subnets. Users report that the application is running more slowly than expected. A security audit of the web server log files shows that the application is receiving millions of illegitimate requests from a small number of IP addresses. A solutions architect needs to resolve the immediate performance problem while the company investigates a more permanent solution. What should the solutions architect recommend to meet this requirement?
- A company operates a web portal that delivers global breaking news, local alerts, and weather updates. Each user receives a personalized view composed of static and dynamic content. Content is served over HTTPS through an API server on an Amazon EC2 instance behind an Application Load Balancer (ALB). The company wants to deliver this content to users worldwide with the LEAST latency. How should a solutions architect design the application to minimize latency for all users?
- A company performed a lift-and-shift migration of an on-premises Oracle database to an Amazon EC2 memory-optimized Linux instance. The instance uses a 1 TB Provisioned IOPS SSD (io1) EBS volume configured for 64,000 IOPS. After migration, database storage performance is slower than on-premises. Which solution improves storage performance?
- A company performs monthly maintenance and must rotate credentials for Amazon RDS for MySQL databases across multiple AWS Regions. Which solution meets this requirement with the least operational overhead?
- A company plans to deploy a business-critical application in AWS that requires durable storage with consistent, low-latency performance. Which storage type should the solutions architect recommend?
- A company plans to deploy a new public web application on AWS. The application has a web server tier that runs on Amazon EC2 instances and a database tier that uses an Amazon RDS for MySQL DB instance. The application must be secure and accessible to global customers who have dynamic IP addresses. How should a solutions architect configure the security groups to meet these requirements?
- A company plans to migrate a legacy application to AWS. The application currently uses NFS to connect to an on-premises storage system to store application data. The application cannot be changed to use protocols other than NFS. Which storage solution should a solutions architect recommend after migration?
- A company plans to migrate a publicly accessible TCP-based application into its VPC. The current public endpoint (a hardware appliance) handles up to 3 million requests per second on a nonstandard TCP port with low latency. The company requires the same performance for the new AWS public endpoint. What should a solutions architect recommend?
- A company plans to migrate an on-premises legacy application to AWS. The application ingests customer order files from an on-premises ERP system and uploads them to an SFTP server. The existing ERP system is already connected to the AWS account. The new application must integrate with the ERP system, be secure and resilient, use SFTP, and process orders immediately when files arrive. Which solution meets these requirements?
- A company plans to migrate data to an Amazon S3 bucket. Data must be encrypted at rest in S3, and the encryption key must be rotated automatically every year. Which solution meets these requirements with the LEAST operational overhead?
- A company plans to migrate its on-premises monolithic application to AWS, keeping as much front-end and back-end code as possible while breaking the system into smaller services that different teams will manage. The company needs a highly scalable solution that minimizes operational overhead. Which solution meets these requirements?
- A company plans to rehost an application to Amazon EC2 instances that use Amazon Elastic Block Store (Amazon EBS) for attached storage. A solutions architect must ensure all newly created Amazon EBS volumes are encrypted by default and prevent creation of unencrypted EBS volumes. Which solution meets these requirements?
- A company plans to run a high performance computing (HPC) workload on Amazon EC2 instances that require low-latency network performance and high network throughput with tightly coupled node-to-node communication. Which solution meets these requirements?
- A company plans to store data on Amazon RDS DB instances and must encrypt the data at rest. What should a solutions architect do to meet this requirement?
- A company plans to use an Amazon DynamoDB table and wants to optimize costs. The table is mostly unused in the mornings. In the evenings, read/write traffic is unpredictable and can spike very quickly. What should a solutions architect recommend?
- A company previously migrated its data warehouse solution to AWS. The company also has an AWS Direct Connect connection. Corporate office users query the data warehouse using a visualization tool. The average size of a query returned by the data warehouse is 50 MB and each webpage sent by the visualization tool is approximately 500 KB. Result sets returned by the data warehouse are not cached. Which solution provides the LOWEST data transfer egress cost for the company?
- A company produces batch data from various databases and live stream data from network sensors and application APIs. The company needs to consolidate and process all incoming data, then stage it into different Amazon S3 buckets for one-time queries and later import into a BI tool for KPIs. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)
- A company produces event data that must be processed as it is received, preserving the original order throughout processing. The company wants a solution with minimal operational overhead. How should a solutions architect design this?
- A company provides a Voice over IP (VoIP) service using UDP connections on Amazon EC2 instances in an Auto Scaling group deployed across multiple AWS Regions. The company needs to route users to the Region with the lowest latency and provide automated failover between Regions. Which solution meets these requirements?
- A company provides an API so customers can retrieve financial information. The company expects spikes in requests during peak periods and requires consistently low-latency responses. The company needs to provide a compute host for the API with the LEAST operational overhead. Which solution should the company use?
- A company provides an API that automates tax computations based on item prices. During the holiday season the number of requests spikes and response times slow. A solutions architect must design a scalable, elastic solution. What should the architect implement?
- A company provides an online service that stores uploaded videos on Amazon EFS Standard so multiple EC2 Linux instances can access and process them. As the service has grown, storage costs have become too expensive. Which storage solution is MOST cost-effective?
- A company provides marketing services to stores. Stores upload transaction data via SFTP to the company; the company processes and analyzes the data to produce marketing offers. Some files can exceed 200 GB. Recently, some stores uploaded files that included personally identifiable information (PII) that should not have been included. The company wants administrators alerted if PII is shared again and wants automated remediation, with the least development effort. What should a solutions architect do?
- A company receives 10 TB of JSON instrumentation data per day from machines at a factory. The data is stored on a SAN in the on-premises factory data center. The company wants to send this data securely and reliably to Amazon S3 for near-real-time analytics. Which solution provides the MOST reliable data transfer?
- A company recently launched many workloads on Amazon EC2 instances and needs a repeatable strategy to remotely and securely access and administer those instances using native AWS services that align with the AWS Well-Architected Framework. Which solution meets these requirements with the LEAST operational overhead?
- A company recently migrated to the AWS Cloud and wants a serverless solution for large-scale, on-demand parallel processing of a semistructured dataset stored in Amazon S3 (logs, media files, transactions, IoT). The solution must process thousands of items in parallel. Which option provides the MOST operational efficiency?
- A company registered its domain with Amazon Route 53. The company uses Amazon API Gateway in the ca-central-1 Region as a public interface for backend microservice APIs consumed securely by third parties. The company wants the API Gateway URL to use the company's domain name and corresponding certificate so third parties can use HTTPS. Which solution meets these requirements?
- A company regularly uploads confidential data to Amazon S3 for analysis. Security policy requires objects be encrypted at rest, the encryption key must be automatically rotated annually, key rotation must be trackable in AWS CloudTrail, and key costs must be minimized. Which solution meets these requirements?
- A company regularly uploads GB-sized files to Amazon S3. After upload, a fleet of Amazon EC2 Spot Instances transcodes the files. The company needs to scale throughput when transferring data from the on-premises data center to Amazon S3 and when downloading data from Amazon S3 to the EC2 instances. Which solutions will meet these requirements? (Choose two.)
- A company rehosted a web application on Amazon EC2 instances in a single AWS Region and wants to redesign it to be highly available and fault tolerant. Traffic must reach all running EC2 instances randomly. Which combination of steps should the company take to meet these requirements? (Choose two.)
- A company requires a highly available, scalable storage solution that functions as a file system, can be mounted by multiple Linux instances in AWS and on premises via native protocols, and has no minimum size. The company has a Site-to-Site VPN between its data center and its VPC. Which storage solution meets these requirements?
- A company runs a batch application on Amazon EC2 instances with multiple Amazon RDS backend databases. The application is generating a high number of reads on the databases. A solutions architect must reduce database read load while ensuring high availability. What should the solutions architect do?
- A company runs a business-critical web application on Amazon EC2 instances behind an Application Load Balancer in an Auto Scaling group. The application uses an Amazon Aurora PostgreSQL database deployed in a single Availability Zone. The company wants high availability with minimal downtime and minimal data loss, and with the least operational effort. Which solution meets these requirements?
- A company runs a container application by using Amazon Elastic Kubernetes Service (Amazon EKS). The application includes microservices that manage customers and place orders. The company needs to route incoming requests to the appropriate microservices. Which solution will meet this requirement MOST cost-effectively?
- A company runs a containerized application on a Kubernetes cluster in an on-premises data center that uses MongoDB for storage. The company wants to migrate some environments to AWS without changing code or deployment methods and wants minimal operational overhead. Which solution meets these requirements?
- A company runs a containerized application on a Kubernetes cluster on-premises that uses AMQP to communicate with a message queue. The data center cannot scale fast enough and the company wants to migrate to AWS with the least operational overhead. Which solution meets these requirements?
- A company runs a content management system on a single Amazon EC2 instance that hosts both the web server and database. The company needs the website platform to be highly available and to scale to meet user demand. What should a solutions architect recommend?
- A company runs a critical Amazon EMR data job for 6 hours each day. The job cannot lose any data while it runs. Which EMR cluster configuration will meet these requirements MOST cost-effectively?
- A company runs a critical application on EC2 instances behind an ALB. The EC2 instances are in an Auto Scaling group and access an Amazon RDS DB instance. All resources are currently in a single Availability Zone. You must update the design to use a second Availability Zone to make the application highly available. Which solution achieves this?
- A company runs a critical customer-facing microservices application on Amazon EKS. The company needs a centralized solution to collect, aggregate, and summarize metrics and logs from the application. Which solution meets these requirements?
- A company runs a critical database on Amazon RDS for PostgreSQL and wants to migrate to Amazon Aurora PostgreSQL with minimal downtime and data loss, and with the least operational overhead. Which solution meets these requirements?
- A company runs a critical storage application in AWS using Amazon S3 in two Regions. The application must send user data to the nearest S3 bucket without public network congestion and must fail over with minimal S3 management. Which solution meets these requirements?
- A company runs a critical, stateful data analysis job each week before the first workday. The job requires at least 1 hour to complete and cannot tolerate interruptions. The company needs a solution to run the job on AWS. Which solution meets these requirements?
- A company runs a custom accounting application on Amazon EC2 and wants to migrate the data to a managed AWS service that requires minimal operational support and provides immutable, cryptographically verifiable logs of data changes. Which solution is the most cost-effective?
- A company runs a custom application on Amazon EC2 On-Demand Instances. The application has frontend nodes that must run 24/7 and backend nodes that run only briefly based on workload. The number of backend nodes varies during the day. The company needs to scale out and in according to workload. Which solution will meet these requirements MOST cost-effectively?
- A company runs a custom report program to analyze mobile app usage. The program generates multiple reports during the last week of each month; each report takes less than 10 minutes. The program is rarely used outside that last week. The company wants to produce reports as quickly as requested at the MOST cost-effective price. Which solution meets these requirements?
- A company runs a Docker-based application in its local data center. The application stores persistent data in a host volume and containers use that persistent data. The company wants to migrate to a fully managed service so it does not manage servers or storage infrastructure. Which solution meets these requirements?
- A company runs a global web application on Amazon EC2 instances behind an Application Load Balancer and stores data in Amazon Aurora. The company needs a disaster recovery solution that can tolerate up to 30 minutes of downtime and potential data loss. The DR solution does not need to handle production load when the primary infrastructure is healthy. What should a solutions architect implement?
- A company runs a highly available image-processing application on Amazon EC2 instances in a single VPC. The instances run in multiple subnets across several Availability Zones, and they do not communicate with each other. All instances download and upload images to Amazon S3 through a single NAT gateway. The company is concerned about data transfer charges. What is the MOST cost-effective way to avoid regional data transfer charges?
- A company runs a highly available SFTP service on two EC2 Linux instances with elastic IP addresses and shared storage. User accounts are Linux users on the servers. The company wants a serverless option that provides high IOPS performance, highly configurable security, and maintains control over user permissions. Which solution meets these requirements?
- A company runs a highly available web application on Amazon EC2 instances behind an Application Load Balancer. CloudWatch metrics show that, as traffic increases, some EC2 instances become overloaded with many outstanding requests. The overloaded instances have both a higher number of requests processed and longer response times than other instances. The company does not want new requests routed to instances that are already overloaded. Which solution meets these requirements?
- A company runs a highly dynamic, stateless batch processing job across many Amazon EC2 instances. The job can be started and stopped without negative impact and typically takes more than 60 minutes to complete. The company wants a scalable, cost-effective design. What should the solutions architect recommend?
- A company runs a highly sensitive application on Amazon EC2 backed by an Amazon RDS database. Compliance requires that all personally identifiable information (PII) be encrypted at rest. Which solution should a solutions architect recommend to meet this requirement with the LEAST infrastructure changes?
- A company runs a Java-based job on an Amazon EC2 instance. The job runs every hour, takes 10 seconds to complete, consumes 1 GB of memory, and causes brief CPU spikes while the rest of the time CPU utilization is low. The company wants to reduce costs while meeting these requirements. Which solution will meet these requirements?
- A company runs a large workload every Friday evening on Amazon EC2 instances in two Availability Zones in the us-east-1 Region. Normally no more than two instances run, but the company wants to scale to six instances each Friday for the recurring workload. Which solution meets this requirement with the least operational overhead?
- A company runs a legacy system on a single Amazon EC2 instance. The application code cannot be changed, and it cannot run on more than one instance. A solutions architect must design a resilient solution to improve recovery time. What should the architect recommend?
- A company runs a media store across multiple Amazon EC2 instances in multiple Availability Zones within a single VPC. The company needs a high-performing solution to share data among all EC2 instances and prefers to keep the data within the VPC. What should a solutions architect recommend?
- A company runs a microservice-based serverless web application that must retrieve data from multiple Amazon DynamoDB tables. A solutions architect must enable the application to retrieve the data with no impact on baseline performance and with the MOST operational efficiency. Which solution meets these requirements?
- A company runs a multi-tier ecommerce application on Amazon EC2 with an Amazon RDS for MySQL Multi-AZ DB instance. RDS uses the latest generation instance with 2,000 GB of storage on a General Purpose SSD (gp3) EBS volume. During peak demand, application performance degrades when read and write IOPS exceed 20,000. What should a solutions architect do to improve database performance?
- A company runs a multi-tier web application on premises. The web application is containerized and runs on Linux hosts connected to a PostgreSQL database that contains user records. Operational overhead of maintaining infrastructure and capacity planning limits growth. A solutions architect must improve the application's infrastructure. Which combination of actions should the solutions architect take? (Choose two.)
- A company runs a photo hosting service in the us-east-1 Region. Users from multiple countries upload and view photos. Some photos are heavily viewed for months; others are viewed for less than a week. Each photo upload can be up to 20 MB. The service uses photo metadata to determine which photos to display to each user. Which solution provides appropriate user access MOST cost-effectively?
- A company runs a photo-sharing application. Users upload photos to an Amazon S3 bucket at a rate of about 150 photos per day. The company wants a solution that creates a thumbnail for each new photo and stores the thumbnail in a second S3 bucket. Which solution meets these requirements MOST cost-effectively?
- A company runs a popular social media site where users upload images to share. The company wants to ensure images do not contain inappropriate content and wants to minimize development effort. What should a solutions architect recommend?
- A company runs a private Amazon API Gateway with two REST APIs in the same VPC. The BuyStock API calls the CheckFunds API to verify funds before a purchase. VPC flow logs show the BuyStock API calling CheckFunds over the internet instead of through the VPC. A solutions architect must ensure the APIs communicate through the VPC with the FEWEST code changes. Which solution meets this requirement?
- A company runs a production application on a fleet of Amazon EC2 instances that read messages from an Amazon SQS queue and process them in parallel. Message volume is unpredictable with intermittent spikes. The application must continually process messages without downtime. Which solution meets these requirements MOST cost-effectively?
- A company runs a production database on Amazon RDS for MySQL. The company must upgrade the database version for security compliance. Because the database contains critical data, the company wants a quick way to upgrade and test functionality without losing any data. Which solution will meet these requirements with the LEAST operational overhead?
- A company runs a public serverless application using Amazon API Gateway and AWS Lambda. Traffic recently spiked because of fraudulent botnet requests. Which steps should a solutions architect take to block requests from unauthorized users? (Choose two.)
- A company runs a public three-tier web application in a VPC on Amazon EC2 instances across multiple Availability Zones. EC2 instances in private subnets must communicate with a license server over the internet. The company wants a managed solution that minimizes operational maintenance. Which solution meets these requirements?
- A company runs a real-time data ingestion solution using the latest Amazon Managed Streaming for Apache Kafka (Amazon MSK). The solution is deployed in private subnets across three Availability Zones. A solutions architect must redesign the ingestion solution to be publicly accessible over the internet, and data in transit must be encrypted. Which solution meets these requirements with the MOST operational efficiency?
- A company runs a resource-intensive, customer-facing web application on Amazon ECS using AWS Fargate. The app must be available 24/7 and handle short bursts of high traffic. The workload must be highly available and cost-effective. Which solution meets these requirements most cost-effectively?
- A company runs a REST-based application on Amazon EC2 that receives near-real-time data from a third-party vendor. The application processes and stores the data. The vendor receives many 503 Service Unavailable errors when sending data because compute capacity spikes and the application reaches maximum capacity. Which design should a solutions architect recommend to provide a more scalable solution?
- A company runs a script on an Amazon EC2 instance that polls and processes messages from an Amazon Simple Queue Service (Amazon SQS) queue. The company wants to reduce operational costs while preserving the ability to process an increasing number of messages. What should a solutions architect recommend?
- A company runs a self-managed database on Amazon EC2 with Amazon Elastic Block Store (Amazon EBS) storage totaling 350 TB. The company takes daily EBS snapshots and retains them for 1 month. Daily change rate is 5% of the volumes. New regulations require keeping monthly snapshots for 7 years. The company wants to update its backup strategy to comply and ensure data availability with minimal administrative effort and with the lowest cost. Which solution meets these requirements MOST cost-effectively?
- A company runs a self-managed DNS solution on AWS that consists of Amazon EC2 instances in different AWS Regions and endpoints of a standard accelerator in AWS Global Accelerator. The company wants to protect this solution against DDoS attacks. What should a solutions architect do to meet this requirement?
- A company runs a self-managed DNS solution on three Amazon EC2 instances behind a Network Load Balancer (NLB) in us-west-2. Most users are in the United States and Europe. The company added three EC2 instances and a new NLB in eu-west-1. Which solution can route traffic to all EC2 instances across both Regions?
- A company runs a serverless website with millions of objects in an Amazon S3 bucket that is the origin for an Amazon CloudFront distribution. The bucket had no encryption set before the objects were uploaded. A solutions architect must enable encryption for all existing objects and for all future objects with the LEAST amount of effort. Which solution meets the requirement?
- A company runs a shopping application that stores customer data in Amazon DynamoDB. To protect against data corruption, the solutions architect must design a recovery solution with an RPO of 15 minutes and an RTO of 1 hour. What should the solutions architect recommend?
- A company runs a stateful production application on Amazon EC2 instances that requires at least two EC2 instances to always be running. A solutions architect must design a highly available, fault-tolerant architecture and creates an Auto Scaling group of EC2 instances. Which additional steps should the architect take to meet these requirements?
- A company runs a stateless web application in production on Amazon EC2 On-Demand Instances behind an Application Load Balancer. Usage is heavy for 8 hours each business day, moderate and steady overnight, and low on weekends. The company wants to minimize EC2 costs while maintaining availability. Which approach meets these requirements?
- A company runs a stateless web application with AWS Lambda functions invoked via Amazon API Gateway. The company wants Regional failover by deploying the application across multiple AWS Regions. What should a solutions architect do to route traffic across Regions?
- A company runs a three-tier application in a VPC. The database tier uses an Amazon RDS for MySQL DB instance. The company plans to migrate the RDS for MySQL DB instance to an Amazon Aurora PostgreSQL DB cluster. The company needs a solution that replicates the data changes that happen during the migration to the new database. Which combination of steps will meet these requirements? (Choose two.)
- A company runs a three-tier application on AWS that ingests sensor data from user devices. Traffic passes through a Network Load Balancer (NLB) to EC2 instances for the web tier and then to EC2 instances for the application tier, which call a database. What should a solutions architect do to improve the security of data in transit?
- A company runs a three-tier ecommerce application on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). Data is stored in an Amazon RDS for MariaDB Multi-AZ DB instance. The company wants durable customer session management during transactions. Which solutions meet this requirement? (Choose two.)
- A company runs a three-tier web app on Amazon EC2 in a single Availability Zone. The app uses a self-managed MySQL database on an EC2 instance with a 1 TB Provisioned IOPS SSD (io2) EBS volume. Peak traffic is expected to require 1,000 IOPS for reads and 1,000 IOPS for writes. The company wants to minimize disruptions, stabilize performance, reduce costs, retain capacity for double the IOPS, and move the database tier to a fully managed, highly available, fault-tolerant solution. Which option meets these requirements MOST cost-effectively?
- A company runs a three-tier web application in a VPC across multiple Availability Zones. Amazon EC2 instances in an Auto Scaling group host the application tier. The company needs an automated scaling plan that analyzes each resource's daily and weekly historical workload trends, and scales resources appropriately according to both forecasted and live utilization changes. Which scaling strategy should a solutions architect recommend?
- A company runs a three-tier web application in the AWS Cloud that operates across three Availability Zones. The application architecture has an Application Load Balancer, an Amazon EC2 web server that hosts user session states, and a MySQL database that runs on an EC2 instance. The company expects sudden increases in application traffic. The company wants to be able to scale to meet future application capacity demands and to ensure high availability across all three Availability Zones. Which solution will meet these requirements?
- A company runs a three-tier web application that processes customer orders. The web tier uses Amazon EC2 instances behind an Application Load Balancer. The processing tier uses EC2 instances. The company decoupled the web and processing tiers using Amazon Simple Queue Service (Amazon SQS). The storage layer is Amazon DynamoDB. During peak times some users report order processing delays. During these delays, the EC2 instances are at 100% CPU and the SQS queue backs up. Peaks are variable and unpredictable. The company needs to improve application performance. Which solution meets these requirements?
- A company runs a web application backed by Amazon RDS. A database administrator accidentally edited and lost data. The company wants the ability to restore the database to its state from 5 minutes before any change within the last 30 days. Which feature should the solutions architect include to meet this requirement?
- A company runs a web application on Amazon EC2 instances in a VPC private subnet. An Application Load Balancer (ALB) in the public subnets directs traffic to those EC2 instances. The company wants to restrict inbound traffic to the EC2 instances so that only the ALB can access them, preventing access from any other source. Which solution meets these requirements?
- A company runs a web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application stores data in an Amazon Aurora MySQL DB cluster. The company needs a disaster recovery (DR) solution. The acceptable recovery time objective is up to 30 minutes. The DR solution does not need to serve customers while the primary infrastructure is healthy. Which solution meets these requirements?
- A company runs a web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer that has sticky sessions enabled. The web server currently hosts the user session state. The company wants to ensure high availability and avoid user session state loss in the event of a web server outage. Which solution will meet these requirements?
- A company runs a web application on Amazon EC2 instances in an Auto Scaling group. The application uses an Amazon RDS for PostgreSQL DB instance. The application slows when traffic increases because the database has a heavy read load during peak traffic. Which actions should a solutions architect take to resolve these performance issues? (Choose two.)
- A company runs a web application on Amazon EC2 instances in multiple Availability Zones. The EC2 instances are in private subnets. A solutions architect created an internet-facing Application Load Balancer (ALB) and specified the EC2 instances as the target group, but internet traffic is not reaching the instances. How should the architect reconfigure the architecture to fix this?
- A company runs a web application on EC2 instances in an Auto Scaling group behind a target group. The application requires session affinity (sticky sessions). The application must be publicly available and protected by AWS WAF. Which combination of steps will meet these requirements? (Choose two.)
- A company runs a web application on multiple Amazon EC2 instances in a VPC. The application must write sensitive data to an Amazon S3 bucket without sending data over the public internet. Which solution meets these requirements?
- A company runs a web application on multiple Amazon EC2 instances in an Auto Scaling group that scales based on demand. The company wants to maximize cost savings without making long-term commitments. Which EC2 purchasing option should a solutions architect recommend?
- A company runs a website that uses a content management system (CMS) on Amazon EC2. The CMS runs on a single EC2 instance and uses an Amazon Aurora MySQL Multi-AZ DB instance for the data tier. Website images are stored on an Amazon Elastic Block Store (Amazon EBS) volume that is mounted inside the EC2 instance. Which combination of actions should a solutions architect take to improve the performance and resilience of the website? (Choose two.)
- A company runs all business applications in AWS and uses AWS Organizations to manage multiple accounts. A solutions architect needs to review all permissions granted to IAM users to determine which users have more permissions than required. Which solution meets this requirement with the LEAST administrative overhead?
- A company runs Amazon EC2 instances in a VPC that load source data into Amazon S3 buckets for later processing. Compliance requires that the data must not be transmitted over the public internet. Servers in the company's on-premises data center will consume the output from the application running on the EC2 instances. Which solution meets these requirements?
- A company runs Amazon EC2 instances in multiple AWS accounts that are individually billed. The company recently purchased a Savings Plan. Because business requirements changed, many EC2 instances were decommissioned. The company wants to apply its Savings Plan discounts to its other AWS accounts. Which combination of steps will meet these requirements? (Choose two.)
- A company runs an Amazon Aurora MySQL DB cluster with six Aurora Replicas. They want near-real-time reporting queries to be automatically distributed across three specific Aurora Replicas that use different compute and memory specs than the other cluster nodes. Which solution meets these requirements?
- A company runs an application in a private subnet behind an Application Load Balancer (ALB) in a VPC. The VPC has a NAT gateway and an internet gateway. The application calls the Amazon S3 API to store objects. Security policy requires that traffic from the application must not traverse the internet. Which solution meets these requirements MOST cost-effectively?
- A company runs an application in a VPC with public and private subnets across multiple Availability Zones. The application runs on EC2 instances in private subnets and uses an Amazon SQS queue. Design a secure connection between the EC2 instances and the SQS queue. Which solution meets these requirements?
- A company runs an application on a group of Amazon Linux EC2 instances and must retain all application log files for 7 years for compliance. A reporting tool must be able to access all log files concurrently. Which storage solution meets these requirements MOST cost-effectively?
- A company runs an application on Amazon EC2 instances and needs a disaster recovery solution with a recovery time objective (RTO) of less than 4 hours. The solution must use the fewest possible AWS resources during normal operations. Which solution meets these requirements in the MOST operationally efficient way?
- A company runs an application on Amazon EC2 instances in a private subnet. The application must process sensitive data from an Amazon S3 bucket without using the internet. Which solution meets these requirements?
- A company runs an application on Amazon EC2 instances in a private subnet. The application needs to store and retrieve data in Amazon S3 buckets. Regulations require that the data must not traverse the public internet. What should a solutions architect implement MOST cost-effectively?
- A company runs an application on Amazon EC2 instances in an Auto Scaling group behind an Elastic Load Balancing (ELB) load balancer. The application uses an Amazon DynamoDB table. For disaster recovery, the company wants the application to be available from another AWS Region with minimal downtime. Which solution provides the LEAST downtime?
- A company runs an application on Amazon EC2 instances that connects to an Amazon Aurora database. The EC2 instances use usernames and passwords stored locally in a file. The company wants to minimize the operational overhead of managing credentials. What should a solutions architect do?
- A company runs an application on Amazon EC2 instances with an Amazon RDS database. Database credentials were configured using the principle of least privilege. The security team wants to protect both the application and the database from SQL injection and other web-based attacks with the LEAST operational overhead. Which solution meets these requirements?
- A company runs an application on Amazon RDS for PostgreSQL that receives traffic only on weekdays during business hours. The company wants to optimize costs and reduce operational overhead based on this usage pattern. Which solution meets these requirements?
- A company runs an application on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster on Amazon EC2 instances. The application has a UI that uses Amazon DynamoDB and data services that use Amazon S3. The company must ensure that the EKS Pods for the UI can access only Amazon DynamoDB and that the EKS Pods for the data services can access only Amazon S3. The company uses AWS Identity and Access Management (IAM). Which solution meets these requirements?
- A company runs an application on an Oracle database and wants to migrate quickly to AWS because it has limited resources for database and backup administration and data center maintenance. The application uses third-party database features that require privileged access. Which option helps the company migrate the database to AWS MOST cost-effectively?
- A company runs an application on AWS that generates sensitive archival files. The company wants to rearchitect the application's data storage so files are encrypted before being sent to AWS, ensuring no third parties can access the data prior to encryption. The company has already created an Amazon S3 bucket. Which solution meets these requirements?
- A company runs an application on AWS that receives variable amounts of traffic. The application uses AWS Direct Connect to an on-premises MySQL-compatible database. The on-premises database consistently uses a minimum of 2 GiB of memory. The company wants to migrate the database to a managed AWS service and use auto scaling to handle unexpected increases in workload. Which solution meets these requirements with the LEAST administrative overhead?
- A company runs an application on AWS that uses an Amazon Aurora DB cluster. During peak hours when many users read data, monitoring shows write-query performance degradation. The company wants to increase scalability to handle peak demand cost-effectively. Which solution meets these requirements most cost-effectively?
- A company runs an application on EC2 On-Demand Instances in an Auto Scaling group. Peak load occurs at the same time every day. Users report slow performance at the start of peak hours, and performance recovers after 2–3 hours. The company wants the application to perform properly at the start of peak hours. Which solution will meet this requirement?
- A company runs an application on many Amazon EC2 instances that read and write to a continuously growing Amazon DynamoDB table. The application needs data only from the last 30 days. The company wants the lowest cost and minimal development effort. Which solution meets these requirements?
- A company runs an application on multiple Amazon EC2 instances that processes messages from an Amazon SQS queue, writes to an Amazon RDS table, and then deletes the message from the queue. Occasional duplicate records appear in the RDS table even though the SQS queue has no duplicate messages. What should a solutions architect do to ensure messages are processed only once?
- A company runs an application on several Amazon EC2 instances that store persistent data on an Amazon Elastic File System (Amazon EFS) file system. The company needs to replicate the data to another AWS Region using an AWS-managed service. Which solution will meet these requirements MOST cost-effectively?
- A company runs an application that stores data on an Amazon RDS for PostgreSQL Multi-AZ DB instance. Increased traffic is causing performance problems, and database queries are identified as the primary bottleneck. What should a solutions architect do to improve application performance?
- A company runs an application using Amazon ECS. The application creates resized versions of an original image and then makes Amazon S3 API calls to store the resized images in Amazon S3. How can a solutions architect ensure that the application has permission to access Amazon S3?
- A company runs an asynchronous API on Amazon API Gateway with an AWS Lambda function that stores user requests in Amazon DynamoDB before dispatching them to microservices. The company provisioned as much DynamoDB throughput as budget allows but still experiences availability issues and lost requests. What should a solutions architect do to address this without impacting existing users?
- A company runs an AWS Glue ETL job every day at the same time to process XML data stored in an Amazon S3 bucket. New data is added to the S3 bucket daily. A solutions architect notices that AWS Glue is reprocessing all the data each run. What should the solutions architect do to prevent AWS Glue from reprocessing old data?
- A company runs an AWS Lambda function in private subnets in a VPC. The subnets use a default route to the internet through an Amazon EC2 NAT instance. The Lambda function processes data and saves output to Amazon S3. Intermittently, the Lambda times out while uploading because the NAT instance's network is saturated. The company wants the Lambda to access Amazon S3 without traversing the internet. Which solution meets these requirements?
- A company runs an ecommerce application on Amazon EC2 instances that store purchase details in an Amazon Aurora PostgreSQL DB cluster. Customers experience application timeouts during peak usage. A solutions architect must rearchitect so the application can scale to peak demand MOST cost-effectively. Which combination of actions should the architect take? (Choose two.)
- A company runs an ecommerce application where each new order is published to a RabbitMQ queue on an Amazon EC2 instance in a single Availability Zone. A separate EC2 instance processes messages and stores details in a PostgreSQL database on another EC2 instance. All EC2 instances are in the same Availability Zone. The company wants the highest availability with the least operational overhead. What should a solutions architect do?
- A company runs an infrastructure monitoring service. The company is building a new feature that will enable the service to monitor data in customer AWS accounts. The new feature will call AWS APIs in customer accounts to describe Amazon EC2 instances and read Amazon CloudWatch metrics. What should the company do to obtain access to customer accounts in the MOST secure way?
- A company runs an internal browser-based application on EC2 instances behind an Application Load Balancer. The instances are in an Auto Scaling group across multiple Availability Zones. The group scales up to 20 instances during work hours and scales down to 2 instances overnight. Staff say the application is very slow at the start of the day, although it runs well by mid-morning. How should scaling be changed to address the complaints while keeping costs low?
- A company runs an on-premises application backed by a MySQL database. The company is migrating the application to AWS to improve elasticity and availability. The production database experiences heavy read activity during normal operation. Every 4 hours the development team pulls a full export of the production database to populate a staging database; during this export users experience unacceptable latency and the development team cannot use staging until the export finishes. A solutions architect must recommend a replacement architecture that eliminates the application latency and allows the development team to use the staging environment without delay. Which solution meets these requirements?
- A company runs an on-premises application on a Kubernetes cluster. The company recently added millions of new customers. The company's existing on-premises infrastructure is unable to handle the large number of new customers. The company needs to migrate the on-premises application to the AWS Cloud. The company will migrate to an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. The company does not want to manage the underlying compute infrastructure for the new architecture on AWS. Which solution will meet these requirements with the LEAST operational overhead?
- A company runs an on-premises ASP.NET application on Linux that is resource-intensive and customer-facing. The company wants to modernize to .NET, run the application in containers, scale based on Amazon CloudWatch metrics, and minimize operational maintenance. Which solution meets these requirements with the least operational overhead?
- A company runs an on-premises Microsoft Windows Server stock trading application and wants to migrate it to AWS. The design must be highly available and provide low-latency block storage access across multiple Availability Zones with the LEAST implementation effort. Which solution meets these requirements?
- A company runs an online marketplace web application that serves hundreds of thousands of users at peak. The company needs a scalable, near-real-time solution to share millions of financial transactions with several internal applications. Transactions must be processed to remove sensitive data before being stored in a document database for low-latency retrieval. What should a solutions architect recommend?
- A company runs an online transaction processing (OLTP) workload on AWS using an unencrypted Amazon RDS DB instance in a Multi-AZ deployment. Daily DB snapshots are taken. What should a solutions architect do to ensure the database and snapshots are always encrypted going forward?
- A company runs an Oracle database on premises and plans to migrate to AWS. The company wants to upgrade to the most recent version, set up disaster recovery, minimize operational overhead for normal operations and DR, and retain access to the database's underlying operating system. Which solution meets these requirements?
- A company runs an order-processing application on an Amazon EC2 instance that saves orders to an Amazon Aurora database. During peak traffic the application sometimes can't write orders fast enough. What should a solutions architect do to ensure orders are written reliably to the database as quickly as possible?
- A company runs an SMB file server in its data center that stores large files. Files are frequently accessed for the first few days after creation, and become rarely accessed after 7 days. Total data growth is nearing the company's storage capacity. The solutions architect must increase available storage without losing low-latency access to recently accessed files and must provide file lifecycle management to prevent future storage issues. Which solution meets these requirements?
- A company runs an SMB file server in its data center. The server stores large files that are frequently accessed for up to 7 days after creation. After 7 days, the files must still be accessible with a maximum retrieval time of 24 hours. Which solution meets these requirements?
- A company runs analytics software on Amazon EC2 instances that process jobs for data uploaded to Amazon S3. Users report some submitted data is not being processed. Amazon CloudWatch shows EC2 CPU utilization is consistently at or near 100%. The company wants to improve performance and scale based on user load. What should a solutions architect do?
- A company runs applications on Amazon EC2 and periodically assesses AWS costs. The company recently identified unusual spending and needs a solution to prevent it. The solution must monitor costs and notify stakeholders of unusual spending. Which solution meets these requirements?
- A company runs applications on Amazon EC2 instances backed by Amazon Elastic Block Store (Amazon EBS) using the latest Amazon Linux. Employees store and retrieve files 25 GB or larger and the company experiences availability issues. The solution must not require transferring files between EC2 instances and files must be available across many EC2 instances and across multiple Availability Zones. Which solution meets these requirements?
- A company runs applications on Amazon EC2 instances in a VPC. One application must call the Amazon S3 API to store and read objects. Company security rules prohibit any traffic from the applications from traversing the internet. Which solution meets these requirements?
- A company runs applications on Amazon EC2 instances in one AWS Region and wants to back them up to a second Region. The company also wants to be able to provision EC2 resources in the second Region and manage the instances centrally from one AWS account. Which solution meets these requirements MOST cost-effectively?
- A company runs applications on Amazon EC2 instances that connect to Amazon RDS databases using an IAM role with associated policies. The company wants to use AWS Systems Manager to patch the EC2 instances without disrupting the running applications. Which solution meets these requirements?
- A company runs applications on Amazon EKS clusters and on-premises Kubernetes clusters. The company wants a central view of all clusters and workloads with the least operational overhead. Which solution meets this requirement?
- A company runs applications on Amazon RDS for PostgreSQL in us-east-1. Machine learning models generate near real-time reports using the same RDS database, which slows database performance during business hours. The company needs to improve database performance most cost-effectively. Which solution meets these requirements?
- A company runs applications that connect to an Amazon RDS database. The applications scale on weekends and during peak seasons. The company wants to scale database connections with the LEAST operational overhead. Which solution meets this requirement?
- A company runs applications under an AWS Organizations account and outsources operational support to external engineers. The company must grant the external engineers AWS Management Console access and operating system access to Amazon EC2 instances (Amazon Linux) in private subnets, without compromising security. Which solution meets these requirements MOST securely?
- A company runs container applications on Amazon Elastic Kubernetes Service (Amazon EKS). The workload varies throughout the day. The company wants Amazon EKS to scale in and out with the workload. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)
- A company runs containerized applications on Amazon Elastic Kubernetes Service (Amazon EKS) using the Kubernetes Horizontal Pod Autoscaler. The workload fluctuates throughout the day. The number of nodes does not automatically scale out when the cluster nodes reach maximum capacity, causing performance issues. Which solution resolves this with the LEAST administrative overhead?
- A company runs containers in a Kubernetes environment in its local data center. The company wants to use Amazon Elastic Kubernetes Service (Amazon EKS) and other AWS managed services. Data must remain on-premises in the company's data center and cannot be stored offsite or in the cloud. Which solution meets these requirements?
- A company runs databases on Amazon RDS for PostgreSQL and requires a secure way to manage the master user password with a rotation every 30 days. Which solution meets these requirements with the LEAST operational overhead?
- A company runs demonstration environments for its customers on Amazon EC2 instances. Each environment is isolated in its own VPC. The company’s operations team needs to be notified when RDP or SSH access to an environment has been established.
- A company runs EC2 instances in a private subnet and Lambda functions that need direct network access to those EC2 instances. The application will run for at least 1 year, and the number of Lambda functions is expected to grow. The company wants to maximize savings across application resources and keep network latency low. Which solution meets these requirements?
- A company runs internal applications across multiple AWS accounts under AWS Organizations. A security appliance in the networking account must inspect inter-account application traffic. Which solution meets this requirement?
- A company runs internal systems on Amazon EC2. During a deployment, an administrator attempts to terminate an EC2 instance by using the AWS CLI but receives a 403 (Access Denied). The administrator is using an IAM role that has the following IAM policy attached: What causes the failed request?
- A company runs its application on Oracle Database Enterprise Edition and needs to migrate the application and database to AWS using Bring Your Own License (BYOL). The application uses third-party database features that require privileged access. Which migration solution will meet these requirements MOST cost-effectively?
- A company runs its application using Amazon EC2 instances and AWS Lambda functions. The EC2 instances are in private subnets of a VPC. The Lambda functions require direct network access to the EC2 instances for the application to work. The application will run for 1 year, and the number of Lambda functions used will increase during that year. The company must minimize costs across all application resources. Which solution meets these requirements?
- A company runs its ERP system in the us-east-1 Region on Amazon EC2 instances. A public API on those instances lets customers exchange information with the ERP system. International customers report slow API response times. Which solution will improve response times for international customers MOST cost-effectively?
- A company runs its legacy web application on AWS. The web application server runs on an Amazon EC2 instance in the public subnet of a VPC. The web application server collects images from customers and stores the image files in a locally attached Amazon Elastic Block Store (Amazon EBS) volume. The image files are uploaded every night to an Amazon S3 bucket for backup. A solutions architect discovers that the image files are being uploaded to Amazon S3 through the public endpoint. The solutions architect needs to ensure that traffic to Amazon S3 does not use the public endpoint. Which solution will meet these requirements?
- A company runs its product in an Auto Scaling group behind a Network Load Balancer and stores objects in an Amazon S3 bucket. After recent malicious attacks, the company needs continuous monitoring for malicious activity across the AWS account, workloads, and access patterns to the S3 bucket, with suspicious activity reported and shown on a dashboard. Which solution meets these requirements?
- A company runs Multi-AZ Amazon RDS for PostgreSQL for customer portal backends. The company needs to implement a 30-day backup retention policy. The company currently has both automated RDS backups and manual RDS snapshots and wants to keep both types of existing backups that are less than 30 days old. Which solution meets these requirements MOST cost-effectively?
- A company runs multiple Amazon EC2 Linux instances across two Availability Zones in a VPC. The applications use a hierarchical directory structure and must read and write rapidly and concurrently to shared storage. What should a solutions architect do to meet these requirements?
- A company runs multiple applications across different AWS accounts in an Organization and across multiple Regions. Each product team has tagged its compute resources in their accounts. The company wants more cost details for each product line from consolidated billing. Which combination of steps will meet these requirements? (Choose two.)
- A company runs multiple production applications. One application uses Amazon EC2, AWS Lambda, Amazon RDS, Amazon Simple Notification Service (Amazon SNS), and Amazon Simple Queue Service (Amazon SQS) across multiple AWS Regions. All resources are tagged with tag name "application" and a value that corresponds to each application. A solutions architect must provide the quickest way to identify all components with that tag. Which solution meets the requirement?
- A company runs multiple Windows workloads on AWS. Employees use Windows file shares hosted on two Amazon EC2 instances; the shares synchronize and keep duplicate copies. The company wants a highly available, durable storage solution that preserves the current user access method. What should a solutions architect do?
- A company runs multiple workloads on virtual machines (VMs) in an on-premises data center that cannot scale fast enough. The company needs to migrate workloads to AWS quickly using a lift-and-shift strategy for noncritical workloads. Which combination of steps will meet these requirements? (Choose three.)
- A company runs multiple workloads on-premises but the data center cannot scale quickly enough. The company needs to collect usage and configuration data about on-prem servers and workloads to plan a migration to AWS. Which solution meets these requirements?
- A company runs production and nonproduction workloads in multiple AWS accounts that are part of an organization in AWS Organizations. The company needs a solution that prevents modification of cost usage tags. Which solution satisfies this requirement?
- A company runs production workloads on Amazon EC2 instances with Amazon EBS volumes. A solutions architect must analyze current EBS volume costs and recommend optimizations that include estimated monthly savings. Which solution meets these requirements?
- A company runs self-managed Microsoft SQL Server on Amazon EC2 with Amazon EBS. Daily snapshots of the EBS volumes are taken. Recently, all EBS snapshots were accidentally deleted by a snapshot cleaning script that removed expired snapshots. A solutions architect must update the architecture to prevent data loss without keeping snapshots indefinitely. Which solution meets these requirements with the LEAST development effort?
- A company runs several Amazon RDS for Oracle On-Demand DB instances with high utilization in member accounts of an AWS Organizations organization. The finance team (with access to the management and member accounts) wants to optimize costs using AWS Trusted Advisor. Which combination of steps will meet these requirements? (Choose two.)
- A company runs several brands' websites on AWS. Each site produces tens of gigabytes of web traffic logs daily. Developers need a scalable, cost-effective solution to analyze traffic across all sites on demand once a week for several months. The solution must support standard SQL queries. Which solution is the MOST cost-effective?
- A company runs several business applications in three separate VPCs in us-east-1. The applications must communicate between VPCs and must consistently send hundreds of gigabytes of data each day to a latency-sensitive application in a single on-premises data center. Design a network connectivity solution that maximizes cost-effectiveness. Which solution meets these requirements?
- A company runs tests on an application that uses an Amazon DynamoDB table for 4 hours once a week. The company knows the number of read and write operations per second during the tests and does not use DynamoDB otherwise. A solutions architect needs to optimize table cost. Which solution meets these requirements?
- A company runs thousands of AWS Lambda functions and needs a secure way to store sensitive information that all functions use, with automatic rotation and minimal operational overhead. Which combination of steps meets these requirements with the LEAST operational overhead? (Choose two.)
- A company runs web servers using an Amazon RDS for PostgreSQL DB instance. A compliance standard requires a recovery point objective (RPO) of under 1 second for all production databases. Which solution meets this requirement?
- A company runs workloads in AWS and wants to centrally collect security data to assess company-wide security and improve workload protection. Which solution meets these requirements with the LEAST development effort?
- A company runs workloads on Amazon Elastic Container Service (Amazon ECS). The container images used by the ECS task definitions need to be scanned for Common Vulnerabilities and Exposures (CVEs). New images must also be scanned when created. Which solution meets these requirements with the FEWEST changes to the workloads?
- A company secures its AWS account root user with a multi-factor authentication (MFA) device and wants to ensure it will not lose access to the root user if the MFA device is lost. Which solution meets this requirement?
- A company sees an increase in Amazon EC2 costs on its latest bill. The billing team noticed unwanted vertical scaling of instance types for a few EC2 instances. A solutions architect must produce a graph comparing the last 2 months of EC2 costs and perform an in-depth analysis to identify the root cause with the LEAST operational overhead. How should the architect generate this information?
- A company sells large datasets stored in an Amazon S3 bucket in the us‑east‑1 Region. A web app on multiple Amazon EC2 instances behind an Application Load Balancer issues S3 signed URLs after purchase so customers can download datasets. Customers are located across North America and Europe. The company wants to reduce data transfer costs while maintaining or improving performance. What should a solutions architect recommend?
- A company serves a dynamic website from Amazon EC2 instances behind an Application Load Balancer in the us-west-1 Region. The site must support multiple languages and is experiencing high latency for users in other parts of the world. The company wants faster global performance without recreating the architecture across multiple Regions. What should a solutions architect do?
- A company sets up an organization in AWS Organizations that contains 10 AWS accounts. A solutions architect must design a solution to provide access to the accounts for several thousand employees. The company has an existing identity provider (IdP). The company wants to use the existing IdP for authentication to AWS. Which solution will meet these requirements?
- A company standardized on a particular EC2 instance family and sizes for an application. The company wants to maximize cost savings for the application over the next 3 years but may need to change the instance family and sizes within the next 6 months based on usage. Which purchasing option will meet these requirements MOST cost-effectively?
- A company stores 700 terabytes on a large NAS system in its corporate data center and has a 10 Gbps AWS Direct Connect. After a regulatory audit, the company has 90 days to move the data to the cloud. The company must move the data efficiently without disrupting access and must be able to access and update the data during the transfer window. Which solution meets these requirements?
- A company stores a data lake on Amazon S3 that ingests Apache Parquet data from multiple sources. The data requires several transformation steps (anomaly filtering, normalizing date/time values, and generating aggregates) before analysts can access the transformed data in S3. The company wants a prebuilt, no-code transformation solution that provides data lineage and data profiling, and that allows sharing the transformation steps across the company. Which solution meets these requirements?
- A company stores a large dataset in a single-AZ Amazon RDS for MySQL DB instance. The company wants business reporting queries to run without impacting write operations on the production DB. Which solution meets this requirement?
- A company stores a large volume of image files in an Amazon S3 bucket. Images must be readily available for the first 180 days, infrequently accessed for the next 180 days, then archived after 360 days but available instantly upon request. After 5 years, only auditors can access the images, and auditors must retrieve them within 12 hours. Objects cannot be lost during this process. A developer uses S3 Standard for the first 180 days and needs to create an S3 Lifecycle rule. Which configuration is the MOST cost-effective while meeting these requirements?
- A company stores a mapping of users to cost centers in an Amazon RDS database. The company needs to ensure that every resource created in a particular AWS account is tagged with the cost center ID of the user who created it. Which solution meets this requirement?
- A company stores about 300 TB in Amazon S3 Standard storage month after month. S3 objects are typically around 50 GB each and are frequently replaced with multipart uploads by a global application. The number and size of objects remain constant, but S3 storage costs are increasing each month. How should a solutions architect reduce costs?
- A company stores an AWS CloudFormation template in an Amazon S3 bucket that blocks public access. The company wants to grant CloudFormation access to the template based on specific user requests to create a test environment, following security best practices. Which solution meets these requirements?
- A company stores application logs in an Amazon CloudWatch Logs log group. A new policy requires storing all application logs in Amazon OpenSearch Service (Amazon Elasticsearch Service) in near-real time. Which solution achieves this with the LEAST operational overhead?
- A company stores backup files in Amazon S3 Standard. Files are accessed frequently for the first month, then not accessed afterward. The company must retain the files indefinitely. Which storage solution is MOST cost-effective?
- A company stores call transcript files monthly. Users access files randomly within 1 year of the call, but access becomes infrequent after 1 year. The company wants users to be able to query and retrieve files less than 1 year old as quickly as possible; delays for older files are acceptable. Which solution meets these requirements most cost-effectively?
- A company stores confidential data in an Amazon Aurora PostgreSQL database in the ap-southeast-3 Region, encrypted with an AWS KMS customer managed key. The company was acquired and must securely share a backup of the database with the acquiring company’s AWS account in ap-southeast-3. What should a solutions architect do to meet these requirements?
- A company stores copyrighted images on AWS for a global customer base. Customers must get fast access, and access must be blocked from specific countries. The company wants the lowest possible cost. Which solution meets these requirements?
- A company stores critical data in Amazon DynamoDB tables in the company's AWS account. An IT administrator accidentally deleted a DynamoDB table, causing significant data loss and operational disruption. The company wants to prevent this disruption in the future with the LEAST operational overhead. Which solution meets this requirement?
- A company stores critical data in an Amazon S3 bucket and must prevent accidental deletion. Which combination of steps should a solutions architect take to meet this requirement? (Choose two.)
- A company stores data in Amazon S3. According to regulations, the data must not contain personally identifiable information (PII). The company recently discovered that S3 buckets have some objects that contain PII. The company needs to automatically detect PII in S3 buckets and to notify the company’s security team. Which solution will meet these requirements?
- A company stores data in an Amazon Aurora PostgreSQL DB cluster. The company must retain all data for 5 years and then delete it, while audit logs of database actions must be kept indefinitely. The cluster already has automated backups enabled. Which combination of steps should a solutions architect take? (Choose two.)
- A company stores data in an on-premises Oracle database and needs the data available in Amazon Aurora PostgreSQL for analysis. The company connects on-premises to AWS using an AWS Site-to-Site VPN and must capture changes that occur in the source database during migration. Which solution meets these requirements?
- A company stores device data in an Amazon DynamoDB table that backs a customer-facing website. The table uses provisioned read and write capacity. The company needs to compute daily performance metrics on the device data with minimal impact on the table’s provisioned capacity. Which solution meets these requirements?
- A company stores frequently accessed objects in an Amazon S3 bucket and enforces strict encryption requirements. The company uses AWS Key Management Service (AWS KMS) for encryption but wants to reduce costs associated with S3 object encryption without making additional AWS KMS calls. Which solution meets these requirements?
- A company stores high-resolution pictures in an Amazon S3 bucket by keeping each picture as the latest object version to minimize application changes. The company wants to retain only the two most recent versions of each picture to reduce costs and wishes to minimize operational overhead. Which solution achieves this?
- A company stores its data on premises. The amount of data is growing beyond the company's available capacity. The company wants to migrate its data from the on-premises location to an Amazon S3 bucket. The company needs a solution that will automatically validate the integrity of the data after the transfer. Which solution will meet these requirements?
- A company stores log data from multiple accounts in centralized Amazon S3 buckets. A solutions architect must ensure the data is encrypted at rest before upload to S3 and encrypted in transit. Which solution meets these requirements?
- A company stores millions of ringtone files (each at least 128 KB) in Amazon S3 Standard. Downloads are infrequent for ringtones older than 90 days. The company wants to reduce storage costs while keeping frequently accessed files readily available. Which action is the MOST cost-effective?
- A company stores multiple Amazon Machine Images (AMIs) in an AWS account to launch Amazon EC2 instances. The AMIs contain critical data and configurations needed for operations. The company wants a solution to recover accidentally deleted AMIs quickly and with the LEAST operational overhead. Which solution meets these requirements?
- A company stores objects in Amazon S3 Standard. A solutions architect finds that 75% of the data is rarely accessed after 30 days. The company requires all data to remain immediately accessible with the same high availability and resiliency, while minimizing storage costs. Which storage solution meets these requirements?
- A company stores operations data in an Amazon S3 bucket. For an annual audit, an external consultant needs access to one annual report stored in the bucket for 7 days. The consultant must be able to access only that report. Which solution provides this access with the MOST operational efficiency?
- A company stores PDF documents in an Amazon S3 bucket and must legally retain all existing and new objects for 7 years. Which solution meets this requirement with the LEAST operational overhead?
- A company stores petabytes of data in Amazon S3 Standard across multiple buckets with unknown access patterns. The company needs a per-bucket solution to optimize S3 cost with the most operational efficiency. Which solution meets these requirements?
- A company stores raw collected data in an Amazon S3 bucket for various analytics workloads. Access patterns are unpredictable and cannot be controlled. The company wants to reduce S3 costs. Which solution meets these requirements?
- A company stores sensitive data in Amazon S3. A solutions architect must create an encryption solution that gives the company full control to create, rotate, and disable encryption keys, with minimal effort for any data that must be encrypted. Which solution meets these requirements?
- A company stores sensitive user information in an Amazon S3 bucket. The company wants to provide secure access to this bucket from the application tier running on Amazon EC2 instances inside a VPC. Which combination of steps should a solutions architect take to accomplish this? (Choose two.)
- A company stores several petabytes of data across multiple AWS accounts and uses AWS Lake Formation to manage its data lake. The data science team needs to securely share selective data from its accounts with the engineering team for analytics. Which solution meets these requirements with the LEAST operational overhead?
- A company stores test data in multiple on-premises locations and needs to connect those locations to VPCs in an AWS Region. The number of accounts and VPCs will increase over the next year. The network design must simplify administration of new connections and scale. Which solution meets these requirements with the LEAST administrative overhead?
- A company stores text files in Amazon S3 that contain customer chat messages, timestamps, and customer PII. The company must provide conversation samples to an external service provider for quality control. The provider needs to randomly select samples up to the most recent conversation. The company must not share customer PII. The solution must scale as conversations grow and have the least operational overhead. Which solution meets these requirements?
- A company stores user data in AWS that is used continuously, with peak usage during business hours. Access patterns vary and some data may not be used for months. A solutions architect must choose a cost-effective storage solution that provides the highest level of durability while maintaining high availability. Which storage solution meets these requirements?
- A company streams IoT data from automobile sensors to Amazon S3 via Amazon Kinesis Data Firehose, producing trillions of S3 objects per year. Each morning the company retrains ML models using the previous 30 days of data; quarterly it uses the previous 12 months for other analysis. Data must be available with minimal delay for up to 1 year, and retained for archival purposes after 1 year. Which storage solution is the most cost-effective?
- A company that primarily runs application servers on premises plans to migrate to AWS. The company wants to minimize the need to scale on‑premises iSCSI storage and keep only recently accessed data stored locally. Which AWS Storage Gateway configuration should the company use?
- A company used an Amazon RDS for MySQL DB instance for application testing and created two backups before terminating the instance: a database dump using mysqldump, and a final DB snapshot created on RDS termination. The company plans a new test cycle and wants to create a new DB instance on a MySQL-compatible edition of Amazon Aurora from the most recent backup. Which solutions will create the new DB instance? (Choose two.)
- A company uses a 100 GB Amazon RDS for Microsoft SQL Server Single-AZ DB instance in us-east-1 for customer transactions. The company requires high availability and automatic recovery for the DB instance. Reports run several times a year and cause transactions to take longer to post. The company needs to improve report performance. Which combination of steps will meet these requirements? (Choose two.)
- A company uses a content management system (CMS) for its corporate website, but patching and maintenance are burdensome. The company is redesigning the site. The website will be updated four times a year, requires no dynamic content, and must provide high scalability and enhanced security. Which combination of changes meets these requirements with the LEAST operational overhead? (Choose two.)
- A company uses a Microsoft SQL Server database and its applications connect to that database. The company wants to migrate to an Amazon Aurora PostgreSQL database with minimal changes to application code. Which combination of steps meets these requirements? (Choose two.)
- A company uses a mobile app that stores sensitive data encrypted at rest with AWS KMS. The company must prevent accidental deletion of KMS keys and send an email via Amazon SNS to administrators when a user attempts to delete a KMS key. Which solution meets these requirements with the LEAST operational overhead?
- A company uses a payment processing system that requires messages for a particular payment ID to be received in the same order they were sent. Otherwise, payments might be processed incorrectly. Which actions should a solutions architect take to meet this requirement? (Choose two.)
- A company uses Amazon API Gateway to manage its REST APIs that third-party service providers access. The company must protect the REST APIs from SQL injection and cross-site scripting attacks. What is the MOST operationally efficient solution that meets these requirements?
- A company uses Amazon Aurora for its global ecommerce application. Developers report poor application performance when monthly reports run. CloudWatch metrics show spikes in ReadIOPS and CPUUtilization during the reports. What is the MOST cost-effective solution?
- A company uses Amazon CloudFront and has enabled logging to an Amazon S3 bucket. The company needs to perform advanced analysis on the logs and build visualizations. What should a solutions architect do?
- A company uses Amazon EC2 instances and Amazon EBS volumes for an application. The company creates one snapshot of each EBS volume daily to meet compliance. The company wants an architecture that prevents accidental deletion of EBS snapshots without changing the storage administrator user's administrative rights. Which solution meets these requirements with the LEAST administrative effort?
- A company uses Amazon EC2 instances and stores data on Amazon EBS volumes. The company must ensure that all data is encrypted at rest by using AWS Key Management Service (AWS KMS) and must be able to control rotation of the encryption keys. Which solution meets these requirements with the LEAST operational overhead?
- A company uses Amazon EC2, AWS Fargate, and AWS Lambda to run workloads in its AWS account. The company wants to fully utilize its Compute Savings Plans and receive notifications when Compute Savings Plans coverage drops. Which solution meets these requirements with the MOST operational efficiency?
- A company uses Amazon Elastic Kubernetes Service (Amazon EKS) for a containerized application that stores sensitive values in Kubernetes secrets. The company wants the secrets encrypted with the LEAST operational overhead. Which solution meets this requirement?
- A company uses Amazon FSx for NetApp ONTAP in its primary AWS Region for CIFS and NFS file shares that are accessed by applications running on Amazon EC2 instances. The company needs a disaster recovery (DR) solution in a secondary Region. The replicated data in the secondary Region must be accessible using the same protocols as in the primary Region. Which solution will meet these requirements with the LEAST operational overhead?
- A company uses Amazon FSx for Windows File Server for EC2 instances with an SMB share in us-east-1. The company requires a 5-minute RPO for planned maintenance or unplanned disruptions, needs replication to us-west-2, and requires that the replicated data cannot be deleted by any user for 5 years. Which solution meets these requirements?
- A company uses Amazon RDS for PostgreSQL. The company must implement password rotation for the databases. Which solution provides password rotation with the LEAST operational overhead?
- A company uses Amazon RDS with default backup settings for its database tier. The company must make a daily backup to meet regulatory requirements and retain backups for 30 days. Which solution meets these requirements with the LEAST operational overhead?
- A company uses Amazon Route 53 latency-based routing for a UDP-based application hosted on redundant servers in on-premises data centers in the United States, Asia, and Europe. Compliance requires the application remain on premises. The company wants to improve performance and availability while keeping the app on premises. What should a solutions architect do to meet these requirements?
- A company uses Amazon S3 as its data lake. A new partner must use SFTP to upload data files. A solutions architect needs to implement a highly available SFTP solution that minimizes operational overhead. Which solution will meet these requirements?
- A company uses Amazon S3 to store confidential audit documents. The S3 bucket uses bucket policies that restrict access to the audit team IAM user credentials according to least privilege. Managers worry about accidental deletion of documents and want a more secure solution. What should a solutions architect do to secure the audit documents?
- A company uses an Amazon CloudFront distribution to serve website content and must require clients to use a TLS certificate when accessing the site. The company wants to automate TLS certificate creation and renewal. Which solution meets these requirements with the MOST operational efficiency?
- A company uses an Amazon EKS cluster and must ensure Kubernetes service accounts have secure, granular access to specific AWS resources using IAM roles for service accounts (IRSA). Which combination of solutions will meet these requirements? (Choose two.)
- A company uses an Amazon S3 bucket as a data lake. The bucket stores massive data accessed randomly by multiple teams and hundreds of applications. The company wants to lower S3 storage costs while keeping frequently accessed objects immediately available. What is the MOST operationally efficient solution?
- A company uses an AWS Batch job for its end-of-day sales process. The company needs a serverless solution that invokes a third-party reporting application when the AWS Batch job succeeds. The reporting application exposes an HTTP API that uses username and password authentication. Which solution meets these requirements?
- A company uses an event-driven model with AWS Lambda and wants to reduce startup latency for functions that run on Java 11. The applications do not have strict latency requirements, but the company wants to reduce cold starts and outlier latencies when functions scale up. Which solution meets these requirements MOST cost-effectively?
- A company uses an organization in AWS Organizations to manage AWS accounts that contain applications. The company sets up a dedicated monitoring member account in the organization. The company wants to query and visualize observability data across the accounts by using Amazon CloudWatch. Which solution will meet these requirements?
- A company uses AWS Cost Explorer to monitor AWS costs. The company notices that Amazon Elastic Block Store (Amazon EBS) storage and snapshot costs increase every month, but it does not provision additional EBS storage. The company wants to optimize monthly costs for current storage usage with the LEAST operational overhead. Which solution meets these requirements?
- A company uses AWS Key Management Service (AWS KMS) keys to encrypt AWS Lambda environment variables. A solutions architect must ensure the correct permissions are in place so the environment variables can be decrypted and used. Which steps must the solutions architect take to implement the required permissions? (Choose two.)
- A company uses AWS Lambda functions that rely on environment variables. The company does not want developers to see environment variables in plaintext. Which solution meets this requirement?
- A company uses AWS Organizations (all features enabled) and runs EC2 workloads in ap-southeast-2. An SCP prevents resource creation in other Regions. A security policy requires all data at rest be encrypted. An audit found employees created unencrypted EBS volumes. The company wants any new EC2 instances launched in ap-southeast-2 by any IAM or root user to use encrypted EBS volumes, with minimal impact on employees creating volumes. Which combination of steps meets these requirements? (Choose two.)
- A company uses AWS Organizations (all features enabled). The company requires auditing of all API calls and logins in every existing and new AWS account, wants a managed solution with minimal extra work and cost, and needs to be notified when any account is noncompliant with the AWS Foundational Security Best Practices (FSBP) standard. Which solution provides this with the least operational overhead?
- A company uses AWS Organizations and enforces a tagging policy that adds department tags to resources when they are created. The accounting team must determine Amazon EC2 costs by department across all AWS accounts in the organization. The accounting team has Cost Explorer access for all accounts and needs to view all reports from Cost Explorer. Which solution provides this MOST operationally efficiently?
- A company uses AWS Organizations and has AWS IAM Identity Center (AWS Single Sign-On) and AWS Control Tower configured. The company must manage multiple user permissions across accounts, split permissions between developer and administrator teams, and add new hires to the teams. Which solution meets these requirements with the LEAST operational overhead?
- A company uses AWS Organizations and tags resources by account. The company also uses AWS Backup to back up its AWS resources. The company needs to ensure all AWS resources are backed up with the LEAST operational overhead. Which solution meets this requirement?
- A company uses AWS Organizations and wants some accounts to operate with separate budgets. The company needs alerts and automatic prevention of provisioning additional resources on AWS accounts when a budget threshold is reached during a specific period. Which combination of solutions will meet these requirements? (Choose three.)
- A company uses AWS Organizations to create separate AWS accounts for each business unit. The root email recipient missed a notification sent to the root user email address of one account. The company wants to ensure future notifications are not missed and that they are limited to account administrators. Which solution meets these requirements?
- A company uses AWS Organizations to manage multiple AWS accounts for different departments. The management account owns an Amazon S3 bucket that contains project reports. The company wants to restrict access to this S3 bucket to only users of accounts within the AWS Organization. Which solution meets this requirement with the least operational overhead?
- A company uses AWS Organizations. A member account purchased a Compute Savings Plan but now uses less than 50% of its purchased compute. What should the company do so the organization receives the benefit of the Savings Plan?
- A company uses AWS Organizations. The security organizational unit (OU) needs to share approved Amazon Machine Images (AMIs) with the development OU. The AMIs are created from AWS KMS-encrypted snapshots. Which solutions meet these requirements? (Choose two.)
- A company uses AWS Systems Manager to manage and patch Amazon EC2 instances. The EC2 instances are registered by IP address in a target group behind an Application Load Balancer (ALB). New security protocols require instances to be removed from service during patching, but attempts now produce errors. Which combination of solutions will resolve the errors? (Choose two.)
- A company uses GPS trackers to document migration patterns of thousands of sea turtles. Trackers check every 5 minutes and, if a turtle moved more than 100 yards (91.4 meters), they send new coordinates to a web application running on three Amazon EC2 instances across multiple Availability Zones in one AWS Region. Recently the web application was overwhelmed by an unexpected volume of tracker data, and data was lost with no way to replay events. A solutions architect must prevent this from happening again with the least operational overhead. What should the solutions architect do?
- A company uses high block storage capacity on premises. The daily peak IOPS are no more than 15,000. The company wants to migrate workloads to Amazon EC2 and provision disk performance independently of storage capacity. Which Amazon Elastic Block Store (Amazon EBS) volume type will meet these requirements MOST cost-effectively?
- A company uses high-concurrency AWS Lambda functions to process an increasing number of messages from a queue during marketing events. The Lambda functions run CPU-intensive code. The company wants to reduce compute costs while maintaining service latency. Which solution meets these requirements?
- A company uses locally attached storage for a latency-sensitive application on premises and is performing a lift-and-shift migration to AWS without changing the application architecture. Which solution meets these requirements MOST cost-effectively?
- A company uses multiple AWS accounts for development. Some staff repeatedly launch oversized Amazon EC2 instances, causing the development accounts to exceed the annual budget. The company wants to centrally restrict which AWS resources can be created in these accounts. Which solution meets the requirement with the LEAST development effort?
- A company uses multiple AWS accounts under consolidated billing. It runs several active high‑performance Amazon RDS for Oracle On‑Demand DB instances for 90 days. The finance team has access to AWS Trusted Advisor in the consolidated billing account and in all member accounts. The finance team needs to review the appropriate Trusted Advisor checks to reduce RDS costs. Which combination of steps should the finance team take? (Choose two.)
- A company uses NFS to store large video files on on-premises network attached storage. Each file ranges from 1 MB to 500 GB. The total storage is 70 TB and is no longer growing. The company must migrate the video files to Amazon S3 as soon as possible while using the least possible network bandwidth. Which solution meets these requirements?
- A company uses Salesforce and needs to load existing data and ongoing changes from Salesforce into Amazon Redshift for analysis, and the data must not traverse the public internet. Which solution provides this with the least development effort?
- A company using AWS Organizations runs 150 applications across 30 accounts. It created a Cost and Usage Report in the management account that is delivered to an Amazon S3 bucket and replicated to a bucket in the data collection account. Senior leadership wants a custom dashboard that shows NAT gateway costs each day starting at the beginning of the current month. Which solution will meet this requirement?
- A company wants a more reliable architecture for its application. The application currently uses one Amazon RDS DB instance and two manually provisioned Amazon EC2 web servers in a single Availability Zone. An employee recently deleted the DB instance and the application was unavailable for 24 hours. What should a solutions architect do to maximize the reliability of the application's infrastructure?
- A company wants a scalable key management infrastructure to support developers who need to encrypt application data. What should a solutions architect do to reduce operational burden?
- A company wants a serverless solution to analyze existing and new data (using SQL). Data is stored in an Amazon S3 bucket, must be encrypted, and must be replicated to a different AWS Region. Which solution meets these requirements with the LEAST operational overhead?
- A company wants an application to store employee data in hierarchical relationships, requiring minimum-latency responses to high-traffic queries and protection of sensitive data. The company also needs to receive monthly email messages if any financial information is present in the employee data. Which combination of steps should a solutions architect take to meet these requirements? (Choose two.)
- A company wants to add its AWS usage cost to an operations-cost dashboard and must access cost data programmatically for the current year and a 12‑month forecast. Which solution provides this capability with the LEAST operational overhead?
- A company wants to analyze and troubleshoot AccessDenied and Unauthorized errors related to IAM permissions. AWS CloudTrail is enabled. Which solution will meet these requirements with the LEAST effort?
- A company wants to archive all AWS Systems Manager Session Manager logs to an Amazon S3 bucket. Which solution provides the MOST operationally efficient way to meet this requirement?
- A company wants to back up its on-premises virtual machines (VMs) to AWS. The backup solution exports on-premises backups to an Amazon S3 bucket as objects. The S3 backups must be retained for 30 days and automatically deleted after 30 days. Which combination of steps will meet these requirements? (Choose three.)
- A company wants to build a logging solution for its multiple AWS accounts. The company currently stores the logs from all accounts in a centralized account. The company has created an Amazon S3 bucket in the centralized account to store the VPC flow logs and AWS CloudTrail logs. All logs must be highly available for 30 days for frequent analysis, retained for an additional 60 days for backup purposes, and deleted 90 days after creation. Which solution will meet these requirements MOST cost-effectively?
- A company wants to build a map of its IT infrastructure to identify and enforce policies on resources that pose security risks. The security team must be able to query the infrastructure map and quickly find security risks. Which solution meets these requirements with the LEAST operational overhead?
- A company wants to build a web application on AWS. Client access requests to the website are not predictable and can be idle for a long time. Only customers who have paid a subscription fee can have the ability to sign in and use the web application. Which combination of steps will meet these requirements MOST cost-effectively? (Choose three.)
- A company wants to configure its Amazon CloudFront distribution to use SSL/TLS certificates and a custom domain name instead of the default distribution domain. Which solution will deploy the certificate without incurring additional costs?
- A company wants to deploy containerized workloads to a VPC across three Availability Zones. The solution must be highly available across AZs, require minimal application changes, and have the least operational overhead. Which solution meets these requirements?
- A company wants to direct users to a backup static error page if the primary website is unavailable. The primary website's DNS is hosted in Amazon Route 53 and points to an Application Load Balancer (ALB). The solution should minimize changes and infrastructure overhead. Which solution meets these requirements?
- A company wants to experiment with individual AWS accounts for its engineer team. The company wants to be notified as soon as the Amazon EC2 instance usage for a given month exceeds a specific threshold for each account. What should a solutions architect do to meet this requirement MOST cost-effectively?
- A company wants to host a scalable web application on AWS that will be accessed by users around the world. Users will upload and download unique files up to gigabytes in size. The development team wants a cost-effective solution that minimizes upload and download latency and maximizes performance. What should a solutions architect recommend?
- A company wants to improve availability and performance for a hybrid application. The application has a stateful TCP workload on Amazon EC2 instances across multiple AWS Regions and a stateless UDP workload on-premises. Which combination of actions should a solutions architect take to improve availability and performance? (Choose two.)
- A company wants to isolate workloads by creating a separate AWS account for each workload. The company needs centralized management of networking components and account creation with automatic security controls (guardrails). Which solution provides these capabilities with the LEAST operational overhead?
- A company wants to let a customer use on-premises Microsoft Active Directory to download files stored in Amazon S3. The customer's application uses an SFTP client to download the files. Which solution meets these requirements with the LEAST operational overhead and without changing the customer's application?
- A company wants to migrate a three-tier application from on premises to AWS. The web and application tiers run on third-party virtual machines (VMs). The database tier runs on MySQL. The company wants to make as few architecture changes as possible and needs a database solution that can restore to a specific point in time. Which migration approach meets these requirements with the LEAST operational overhead?
- A company wants to migrate an application to AWS and increase the application's availability. The company also wants to use AWS WAF in the application's architecture. Which solution meets these requirements?
- A company wants to migrate an existing application from its data center to the AWS Cloud to make it highly available and resilient. The application recently lost data when a database server crashed during a power outage. The company requires a solution that avoids single points of failure and can scale to meet user demand. Which solution meets these requirements?
- A company wants to migrate an on-premises data center to AWS. The data center hosts an SFTP server that stores its data on an NFS-based file system. The server holds 200 GB of data that needs to be transferred. The server must be hosted on an Amazon EC2 instance that uses an Amazon Elastic File System (Amazon EFS) file system. Which combination of steps should a solutions architect take to automate this task? (Choose two.)
- A company wants to migrate its MySQL database from on premises to AWS. The company recently experienced a database outage that significantly impacted the business. To prevent recurrence, the company wants a reliable database solution on AWS that minimizes data loss and ensures every transaction is stored on at least two nodes. Which solution meets these requirements?
- A company wants to migrate its on-premises application to AWS. The application produces output files ranging from tens of gigabytes to hundreds of terabytes. The data must be stored in a standard file system structure. The company wants an automatically scaling, highly available solution with minimal operational overhead. Which solution meets these requirements?
- A company wants to migrate its on-premises Microsoft SQL Server Enterprise edition database to AWS. The online application uses the database for transactions, and the data analysis team runs reports against the production database for analytics. The company wants to minimize operational overhead by using managed services where possible. Which solution will meet these requirements with the LEAST operational overhead?
- A company wants to migrate its on-premises MySQL database to AWS. The database receives frequent imports from a client-facing application, resulting in a high volume of write operations that may be degrading application performance. How should a solutions architect design the architecture on AWS?
- A company wants to migrate multiple on-premises Windows file servers into a single Amazon FSx for Windows File Server file system while preserving file permissions so access rights do not change. Which solutions meet the requirements? (Choose two.)
- A company wants to migrate two DNS servers to AWS. The servers host about 200 zones and receive 1 million requests per day on average. The company wants to maximize availability while minimizing operational overhead related to managing the two servers. What should a solutions architect recommend to meet these requirements?
- A company wants to monitor its AWS costs for a monthly financial review. The cloud operations team is designing an architecture in the AWS Organizations management account to query AWS Cost and Usage Reports for all member accounts. The team must run the query once a month and provide a detailed bill analysis. Which solution is the MOST scalable and cost-effective way to meet these requirements?
- A company wants to move its application to a serverless architecture. The solution must analyze existing and new data with SQL. The company stores the data in an Amazon S3 bucket. The data must be encrypted at rest and replicated to a different AWS Region. Which solution meets these requirements with the LEAST operational overhead?
- A company wants to prevent AWS CloudFormation stacks from deploying IAM resources that include an inline policy or a statement with "*", and to prohibit deployment of Amazon EC2 instances with public IP addresses. The company has AWS Control Tower enabled in its AWS Organizations organization. Which solution meets these requirements?
- A company wants to provide data scientists with near real-time read-only access to the company's production Amazon RDS for PostgreSQL database. The database is currently configured as a Single-AZ database. The data scientists use complex queries that will not affect the production database. The company needs a solution that is highly available. Which solution will meet these requirements MOST cost-effectively?
- A company wants to provide users with access to AWS resources. The company has 1,500 users and manages their access to on-premises resources through Active Directory user groups on the corporate network. The company does not want users to maintain another identity to access the resources. A solutions architect must manage user access to AWS resources while preserving access to the on-premises resources. What should the solutions architect do to meet these requirements?
- A company wants to rearchitect a large-scale web application to a serverless microservices architecture. The application is written in Python and currently runs on Amazon EC2. The company selected one component that handles hundreds of requests per second to test as a microservice. The solution must support Python, scale automatically, and require minimal infrastructure and operational support. Which solution meets these requirements?
- A company wants to reduce backup costs and eliminate physical backup tapes while preserving its on-premises backup applications and workflows. What should a solutions architect recommend?
- A company wants to reduce costs for its three-tier web architecture. Web, application, and database servers run on Amazon EC2 instances for development, test, and production environments. EC2 instances average 30% CPU utilization during peak hours and 10% during non-peak hours. Production instances run 24 hours a day. Development and test instances run at least 8 hours each day, and the company will automate stopping them when not in use. Which EC2 instance purchasing solution will meet the company's requirements MOST cost-effectively?
- A company wants to reduce the cost of its 1 Gbps AWS Direct Connect connection. Average utilization is under 10%. The solution must reduce cost without compromising security. Which option meets these requirements?
- A company wants to replicate existing and ongoing data changes from an on-premises Oracle database to Amazon RDS for Oracle using AWS Database Migration Service (AWS DMS). The data volume varies throughout the day and the solution should allocate only the capacity required for replication. Which solution meets these requirements?
- A company wants to restrict access to its web application's content using AWS authorization techniques. The company also wants a serverless authorization and authentication solution with low login latency that integrates with the web application and serves content globally. The application currently has a small user base but is expected to grow. Which solution meets these requirements?
- A company wants to restrict access to the content of a main web application using AWS authentication and to implement a serverless architecture for fewer than 100 users. The solution must integrate with the main web application, serve content globally, scale as the user base grows, and provide the lowest login latency cost-effectively. Which solution meets these requirements MOST cost-effectively?
- A company wants to run critical applications in containers for scalability and availability. The company prefers to focus on application maintenance and does not want to provision or manage the underlying infrastructure that runs the containers. What should a solutions architect recommend?
- A company wants to run high performance computing (HPC) workloads on AWS for financial risk modeling. The workloads run on Linux, use hundreds of Amazon EC2 Spot Instances, are short-lived, and generate thousands of output files that must be stored persistently for analytics and future use. The company needs a cloud storage solution that allows copying on-premises data to long-term persistent storage accessible to all EC2 instances, and a high-performance file system integrated with persistent storage for reading and writing datasets and outputs. Which combination of AWS services meets these requirements?
- A company wants to run its payment application on AWS. The application receives payment notifications from mobile devices. Notifications require basic validation before being sent for further processing. The backend processing is long running and needs adjustable compute and memory. The company does not want to manage infrastructure. Which solution meets these requirements with the LEAST operational overhead?
- A company wants to run stateless containerized applications in the AWS Cloud. The applications tolerate disruptions in the underlying infrastructure. The company needs a solution that minimizes cost and operational overhead. What should a solutions architect do?
- A company wants to set up Amazon Managed Grafana as its visualization tool and visualize data from an Amazon RDS database as a single data source. The solution must be secure and must not expose the data over the internet. Which solution meets these requirements?
- A company wants to standardize Amazon Elastic Block Store (Amazon EBS) volume encryption and minimize the cost and configuration effort to perform the volume encryption check. Which solution meets these requirements?
- A company wants to use AI to evaluate the quality of customer service calls. Calls are managed in four languages including English, and more languages will be added later. The company cannot maintain custom ML models and needs written sentiment analysis reports from call recordings; recorded text must be translated into English. Which combination of steps meets these requirements? (Choose three.)
- A company wants to use Amazon Elastic Container Service (Amazon ECS) to run its on-premises application in a hybrid environment. The application currently runs in on-premises containers. The company needs a single container solution that can scale on-premises, hybrid, or cloud, must run new containers in the AWS Cloud, and must use a load balancer for HTTP traffic. Which combination of actions meets these requirements? (Choose two.)
- A company wants to use an Amazon RDS for PostgreSQL DB cluster to reduce administrative overhead for production workloads. The database must be highly available with automatic failover in most scenarios under 40 seconds. The company also wants to offload reads from the primary and keep costs low. Which solution meets these requirements?
- A company wants to use NAT gateways in its AWS environment. The company's Amazon EC2 instances in private subnets must be able to connect to the public internet through the NAT gateways. Which solution will meet these requirements?
- A company wants to use the AWS Cloud to improve its on-premises disaster recovery (DR) configuration. The company's core production business application uses Microsoft SQL Server Standard, which runs on a virtual machine (VM). The application has a recovery point objective (RPO) of 30 seconds or fewer and a recovery time objective (RTO) of 60 minutes. The DR solution needs to minimize costs wherever possible. Which solution will meet these requirements?
- A company will create an Amazon EMR cluster for multiple teams. Each team’s workloads should have access only to the AWS services they need. The company also does not want workloads to be able to access the Instance Metadata Service Version 2 (IMDSv2) on the cluster EC2 instances. Which solution meets these requirements?
- A company will deploy an application on multiple Amazon EC2 Nitro-based instances in the same Availability Zone and needs the application to write to the same block storage volumes from multiple EC2 Nitro instances simultaneously for higher availability. Which solution meets these requirements?
- A company will deploy an internal web application on AWS that must be accessible only from the company office. The application must download security patches from the internet. The company has a VPC and an AWS Site-to-Site VPN to the office. Which design meets these requirements securely?
- A company will deploy its application on an Amazon Aurora PostgreSQL Serverless v2 cluster that will receive large amounts of traffic. The company wants to optimize cluster storage performance cost-effectively as load increases. Which storage configuration meets these requirements MOST cost-effectively?
- A company will display application metrics on an Amazon CloudWatch dashboard. The product manager needs periodic access but does not have an AWS account. Following the principle of least privilege, how should a solutions architect provide access?
- A company will migrate a Windows-based, three-tier application (application tier, business tier, and Microsoft SQL Server database tier) from on premises to AWS. The application requires SQL Server features such as native backups and Data Quality Services, and needs file sharing between tiers. How should a solutions architect design this architecture?
- A company will move a multi-tier application to AWS to improve performance. Tiers communicate via RESTful services and transactions are dropped when a tier is overloaded. The solutions architect must design a solution that resolves dropped transactions and modernizes the application, with the highest operational efficiency. Which solution meets these requirements?
- A company will move data to an Amazon S3 bucket. The data must be encrypted at rest in the S3 bucket, and the encryption key must be automatically rotated every year. Which solution meets these requirements with the LEAST operational overhead?
- A company will run a gaming application on Amazon EC2 instances in an Auto Scaling group. The application uses UDP packets. The company must allow the application to scale out and in as traffic varies. What should a solutions architect do to meet these requirements?
- A company will run Amazon EC2 instances that connect to an Amazon Aurora DB cluster. The infrastructure is deployed with an AWS CloudFormation template. The company wants the EC2 instances to authenticate to the database securely without maintaining static database credentials. Which solution meets these requirements with the LEAST operational effort?
- A company will run an application on Amazon ECS and Amazon RDS on-premises for compliance, using AWS Outposts. Which activities are the responsibility of the company's operational team? (Choose three.)
- A company will run an internet-facing application on multiple Amazon EC2 instances across multiple Availability Zones and multiple AWS Regions. Users are worldwide and should be routed to the EC2 instances closest to their location. Which solution meets these requirements?
- A company will run experimental workloads in AWS with a fixed budget. The CFO needs spending accountability per department and wants to receive a notification when spending reaches 60% of the budget. Which solution meets these requirements?
- A company will store confidential data in Amazon S3. For compliance, the data must be encrypted at rest, encryption key usage must be logged for auditing, and keys must be rotated every year. Which solution meets these requirements and is the MOST operationally efficient?
- A company will store data in Amazon S3 buckets in two AWS Regions and must use an AWS KMS customer managed key to encrypt all data in those S3 buckets. The data in both S3 buckets must be encrypted and decrypted with the same KMS key, and both the data and the key must be stored in each of the two Regions. Which solution meets these requirements with the LEAST operational overhead?
- A company will use Amazon DynamoDB as the primary database, but incoming data items can exceed DynamoDB item size limits (current maximum size 700 KB and growing). Which solution handles large data sizes with the most operational efficiency?
- A company with 15 employees stores employee start dates in an Amazon DynamoDB table. The company wants to send an email to each employee on their work anniversary. Which solution provides the MOST operational efficiency?
- A company with 700,000 registered users will offer a product that converts large .pdf files (average 5 MB) to .jpg images. The company needs to store both original and converted files and must design a scalable solution to accommodate rapidly growing demand that is also cost-effective. Which solution meets these requirements MOST cost-effectively?
- A company's application generates many files (~5 MB each) stored in Amazon S3. Company policy requires retaining the files for 4 years before deletion. Files must be immediately accessible at all times and are frequently accessed during the first 30 days but rarely after. Which storage lifecycle solution is MOST cost-effective?
- A company's application ingests data from multiple SaaS sources. The company uses Amazon EC2 instances to receive the data and upload it to an Amazon S3 bucket for analysis. The same EC2 instances also send a notification to the user when an upload completes. The company has observed slow application performance and wants to improve it as much as possible with the least operational overhead. Which solution meets these requirements?
- A company's application runs on Amazon EC2 instances and uses AWS Lambda functions. Production runs constantly because of global customers. Nonproduction development environments run in a different AWS account and are used only during business hours on weekdays; they're idle on weekends. The company wants to optimize costs. Which solution is MOST cost-effective?
- A company's application uses Network Load Balancers, Auto Scaling groups, Amazon EC2 instances, and databases deployed in an Amazon VPC. The company wants to capture near real-time information about traffic to and from the network interfaces in the VPC and send that information to Amazon OpenSearch Service for analysis. Which solution meets these requirements?
- A company's applications run on EC2 instances in Auto Scaling groups and experience sudden traffic spikes on random days. The company needs to maintain performance during these sudden increases in the most cost-effective way. Which solution best meets this requirement?
- A company's DNS provider is experiencing outages that disrupt a website hosted on AWS. The company wants to migrate quickly to a more resilient managed DNS service running on AWS. What should a solutions architect do to rapidly migrate DNS hosting?
- A company's dynamic website is hosted on on-premises servers in the United States. The company is launching its product in Europe and wants to improve site loading times for new European users. The site's backend must remain in the United States. The product launches in a few days and an immediate solution is required. What should the solutions architect recommend?
- A company's HTTP application is behind a Network Load Balancer (NLB). The NLB's target group uses an Amazon EC2 Auto Scaling group with multiple EC2 instances running the web service. The NLB is not detecting HTTP errors, which require manual restarts of the web service EC2 instances. The company wants to improve availability without writing custom scripts or code. What should a solutions architect do?
- A company's image-hosting site lets global users upload, view, and download images from mobile devices. The static website is hosted in an Amazon S3 bucket. As popularity grew, performance degraded and users reported latency when uploading and downloading images. The company must improve website performance with the LEAST implementation effort. Which solution meets this requirement?
- A company's infrastructure includes hundreds of Amazon EC2 instances that use Amazon Elastic Block Store (Amazon EBS). A solutions architect must ensure every EC2 instance can be recovered after a disaster. What should the solutions architect do to meet this requirement with the LEAST amount of effort?
- A company's near-real-time streaming application on AWS ingests data and runs a job that takes 30 minutes to complete. The workload often suffers high latency from large incoming data volumes. A solutions architect needs a scalable, serverless design to improve performance. Which combination of steps should the architect take? (Choose two.)
- A company's production environment runs Amazon EC2 On-Demand Instances continuously from Monday through Saturday. On Sunday the instances must run only 12 hours and cannot tolerate interruptions. The company wants to cost-optimize the environment while meeting these requirements. Which solution is MOST cost-effective?
- A company's SAP application uses a backend SQL Server database on-premises. The company will migrate the application and database to AWS. Performance data shows both the SAP application and the database have high memory utilization. Which instance-family choice meets these requirements?
- A company's software development team needs an Amazon RDS Multi-AZ cluster. The RDS cluster will serve as a backend for a desktop client that is deployed on premises. The desktop client requires direct connectivity to the RDS cluster. The company must give the development team the ability to connect to the cluster by using the client when the team is in the office. Which solution provides the required connectivity MOST securely?
- A company's web application runs on multiple Amazon EC2 instances behind an Application Load Balancer in a VPC, with an Amazon RDS for MySQL DB instance for data storage. The company needs to automatically detect and respond to suspicious or unexpected behavior in its AWS environment. AWS WAF is already in place. What should a solutions architect implement next to protect against threats?
- A company's website currently uses an Amazon EC2 instance store for its item catalog. The company wants the catalog to be highly available and stored in a durable location. What should a solutions architect do to meet these requirements?
- A company's website handles millions of requests per day and traffic continues to grow. A solutions architect needs to reduce latency when retrieving product details from a DynamoDB table with the LEAST operational overhead. Which solution should the architect implement?
- A company's website provides downloadable historical performance reports. The solution must scale globally, be cost-effective, minimize infrastructure provisioning, and provide the fastest possible response times. Which combination should a solutions architect recommend?
- A company’s API receives real-time data from monitoring devices and stores it in an Amazon RDS DB instance. The incoming data volume fluctuates and during heavy traffic the API times out because the database cannot process the write volume. A solutions architect must minimize database connections and ensure no data loss during heavy traffic. Which solution meets these requirements?
- A company’s application receives UDP data from thousands of geographically dispersed remote devices, processes it immediately, and may send a reply. No data is stored. The solution must minimize transmission latency and provide rapid failover to another AWS Region. Which solution meets these requirements?
- A company’s applications run on Amazon EC2 instances with IPv6 addresses. The applications must initiate outbound communications to external internet services, but the security policy requires that external services cannot initiate connections to the EC2 instances. What should a solutions architect recommend?
- A company’s applications use Apache Hadoop and Apache Spark on-premises. The infrastructure is not scalable and is complex to manage. A solutions architect must design a scalable solution that reduces operational complexity while keeping data processing on-premises. Which solution meets these requirements?
- A company’s data platform uses an Amazon Aurora MySQL database with multiple read replicas and DB instances across Availability Zones. Users report errors indicating too many connections. The company wants to reduce failover time by 20% when a read replica is promoted to primary writer. Which solution meets this requirement?
- A company’s ecommerce checkout workflow writes an order to a database and calls a payment service. Users experience timeouts during checkout; when they resubmit, multiple unique orders are created for the same transaction. How should a solutions architect refactor the workflow to prevent multiple orders?
- A company’s ecommerce website has unpredictable traffic and uses AWS Lambda functions to directly access a private Amazon RDS for PostgreSQL DB instance. The company wants predictable database performance and to ensure Lambda invocations do not overload the database with too many connections. What should a solutions architect do to meet these requirements?
- A company’s infrastructure includes Amazon EC2 instances and an Amazon RDS DB instance in a single AWS Region. The company wants to back up data in a different Region with the least operational overhead. Which solution meets this requirement?
- A company’s Java application consumes messages from Amazon SQS but cannot parse messages larger than 256 KB. The company wants the application to handle messages up to 50 MB with the FEWEST code changes. Which solution meets this requirement?
- A company’s new mobile app lets users worldwide view local news and post photos and videos. Content is accessed frequently within minutes of posting, then rapidly replaced and removed. Because the news is local, 90% of content is consumed within the AWS Region where it was uploaded. Which solution will provide the LOWEST latency for content uploads and optimize user experience?
- A company’s on-premises applications use both block storage and NFS and are running out of storage capacity. The company needs a high-performance solution that supports local caching without re-architecting the applications. Which combination of actions should a solutions architect take? (Choose two.)
- A company’s on-premises volume backup solution is at end of life. The company wants to adopt AWS for backups but keep local access to all data while it is backed up on AWS. The data backed up on AWS must be transferred automatically and securely. Which solution meets these requirements?
- A company’s online shopping app stores orders on an Amazon RDS for PostgreSQL Single-AZ DB instance. Management wants to remove single points of failure and minimize database downtime without changing the application code. Which solution meets these requirements?
- A company’s order system sends requests from clients to Amazon EC2 instances that process orders and store them in Amazon RDS. Users must currently reprocess orders when the system fails. The company wants a resilient solution that will automatically process orders after an outage. What should a solutions architect do to meet these requirements?
- A company’s ordering application stores customer data in Amazon RDS for MySQL. During business hours, employees run one-off reporting queries that cause long-running reads and lead to timeouts during order processing. The company must eliminate the timeouts but still allow employees to run queries. What should a solutions architect do to meet these requirements?
- A company’s security team requests that VPC Flow Logs be captured. The logs will be frequently accessed for 90 days, then accessed only intermittently afterward. How should a solutions architect configure the logs to meet these requirements?
- A company’s stateful application runs in memory on Amazon EC2 instances. The infrastructure was deployed with AWS CloudFormation using the M5 EC2 instance family. As traffic increased, application performance degraded and users experience delays. Which solution will resolve the issues with the MOST operational efficiency?
- A company’s web application runs on Amazon EC2 instances behind an Application Load Balancer. The company’s policy now requires that the application be accessible from only one specific country. Which configuration will enforce this requirement?
- A company’s website hosted on Amazon EC2 instances processes classified data stored in Amazon S3. Due to security concerns, the company requires a private and secure connection between its EC2 resources and Amazon S3. Which solution meets these requirements?
- A company’s website is used to sell products to the public. The site runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). There is also an Amazon CloudFront distribution, and AWS WAF is being used to protect against SQL injection attacks. The ALB is the origin for the CloudFront distribution. A recent review of security logs revealed an external malicious IP that needs to be blocked from accessing the website. What should a solutions architect do to protect the application?
- A consulting company provides tools and solutions to help customers gather and analyze data on AWS. The company needs to centrally manage and deploy a common set of solutions and tools so customers can use them via self-service. Which solution meets this requirement?
- A consumer survey company has collected years of regional data in an Amazon S3 bucket in one AWS Region. The company has granted a marketing firm in a different region access to the S3 bucket. The company wants to minimize data transfer costs when the firm requests data. Which solution meets these requirements?
- A containerized application runs on an Amazon EC2 instance and must download security certificates before it can communicate with other business applications. The company requires a highly secure solution to encrypt and decrypt the certificates in near real time, and it needs to store data in highly available storage after encryption. Which solution meets these requirements with the LEAST operational overhead?
- A critical web application currently runs on a single Amazon EC2 instance in a public subnet and uses a MySQL database. DNS is in Route 53. A solutions architect must make the application scalable and highly available and reduce MySQL read latency. Which combination of changes will meet these requirements? (Choose two.)
- A data analytics company has 80 global offices. Each office hosts 1 PB of data and has between 1 and 2 Gbps of internet bandwidth. The company must perform a one-time migration of large amounts of data from the offices to Amazon S3 and complete it within 4 weeks. Which solution will meet these requirements MOST cost-effectively?
- A data analytics company receives thousands of small data files periodically via FTP. An on‑premises batch job currently processes them overnight, taking hours. The company wants the AWS solution to process incoming files as soon as possible with minimal changes to the FTP clients. The solution must delete files after successful processing. Each file's processing takes 3–8 minutes. Which solution meets these requirements with the MOST operational efficiency?
- A developer has an application that uses an AWS Lambda function to upload files to Amazon S3 and needs permissions to perform the uploads. The developer already has an IAM user with valid IAM credentials for Amazon S3. What should a solutions architect do to grant the required permissions?
- A development team has an application in a development VPC with CIDR 192.168.0.0/24. You must create a new VPC in the same account and peer it with the development VPC. What is the SMALLEST CIDR block you can assign to the new VPC that is valid for a VPC peering connection to the development VPC?
- A development team is collaborating with another company that needs to poll an Amazon Simple Queue Service (Amazon SQS) queue in the development team's AWS account. The other company wants to poll the queue without using the development team's account permissions. How should a solutions architect grant access to the SQS queue?
- A development team is creating an event-based application that uses AWS Lambda functions. Events are generated when files are added to an Amazon S3 bucket. The team currently has Amazon Simple Notification Service (Amazon SNS) configured as the event target from Amazon S3. What should a solutions architect do to process the events from Amazon S3 in a scalable way?
- A development team needs to host a website (HTML, CSS, client-side JavaScript, and images) that will be accessed by other teams. Which method is the MOST cost-effective for hosting the website?
- A development team runs monthly resource-intensive tests on a general purpose Amazon RDS for MySQL DB instance with Performance Insights enabled. The tests run for 48 hours once a month and are the only process using the database. The team wants to reduce the cost of running the tests without reducing the DB instance's compute and memory attributes. Which solution is MOST cost-effective?
- A development team uses separate AWS accounts for development, staging, and production. Team members have been launching large Amazon EC2 instances that are underutilized. A solutions architect must prevent large instances from being launched in all accounts with the LEAST operational overhead. How can the architect meet this requirement?
- A digital image processing company wants to migrate its on-premises monolithic application to AWS. The company processes thousands of images and produces large files during processing. It needs a solution that can handle an increasing number of image-processing jobs and reduce manual workflow tasks. The company does not want to manage the underlying infrastructure. Which solution provides the required functionality with the LEAST operational overhead?
- A facility has badge readers at every entrance. When badges are scanned, readers send a message over HTTPS indicating who attempted to access that entrance. A solutions architect must design a highly available system to process these messages and make results available for the security team to analyze. Which architecture should the solutions architect recommend?
- A finance company runs an on-premises search application that ingests streaming data and provides real-time search and visualizations. The company plans to migrate to AWS using native services. Which solution meets these requirements?
- A finance company's customers request appointments with advisors via text messages. A web application on Amazon EC2 accepts requests and publishes the text messages to an Amazon Simple Queue Service (Amazon SQS) queue. Another EC2 application sends meeting invitations and confirmation emails, then stores meeting details in an Amazon DynamoDB table. As the company grows, customers report meeting invitations are taking longer to arrive. What should a solutions architect recommend to resolve this?
- A financial application produces reports averaging 50 KB each and stores them in Amazon S3. Reports are frequently accessed during the first week after production and must be retained for several years. Reports must be retrievable within 6 hours. Which solution is the MOST cost-effective?
- A financial company hosts a web application that uses an Amazon API Gateway Regional API endpoint to provide current stock prices. The security team has noticed an increase in API requests and is concerned about HTTP flood attacks taking the application offline. A solutions architect must design a protection with the LEAST operational overhead. Which solution meets this requirement?
- A financial company will store highly sensitive data in an Amazon S3 bucket and must ensure the data is encrypted in transit and at rest. The company must manage the encryption keys outside the AWS Cloud. Which solution meets these requirements?
- A financial services company launched a new application that uses an Amazon RDS for MySQL database. The application runs only 2 hours at the end of each week. The company needs to minimize the cost of running the database. Which solution meets these requirements MOST cost-effectively?
- A financial services company on AWS designed security controls to meet NIST and PCI DSS standards. Third-party auditors need evidence that the controls are implemented and operating correctly across hundreds of AWS accounts in a single AWS Organizations organization. Which solution provides monitoring of the controls across accounts?
- A financial services company wants to shut down two data centers and migrate more than 100 TB of data to AWS. The data has an intricate directory structure with millions of small files stored in deep hierarchies of subfolders. Most of the data is unstructured, and the company’s file storage consists of SMB-based storage types from multiple vendors. The company does not want to change its applications to access the data after migration. What should a solutions architect do to meet these requirements with the LEAST operational overhead?
- A financial services company will deploy a sensitive-transaction application on Amazon EC2 and use Amazon RDS for MySQL. Security policies require encryption at rest and in transit. Which solution provides this with the LEAST operational overhead?
- A fleet of Amazon EC2 instances ingests JSON data from on‑premises sources at up to 1 MB/s. When an EC2 instance reboots, in‑flight data is lost. The data science team needs near‑real‑time querying of ingested data. Which solution provides near‑real‑time querying, is scalable, and minimizes data loss?
- A frontend application uses an Amazon API Gateway API backend integrated with AWS Lambda. When requests arrive, the Lambda function loads many libraries, connects to an Amazon RDS database, processes the data, and returns it to the frontend. The company wants to minimize response latency for all users with the fewest operational changes. Which solution meets this requirement?
- A gaming company hosts a browser-based application on AWS. Users stream many videos and images that are stored in Amazon S3. The content is identical for all users, and millions of users worldwide now access these media files. The company wants to deliver the files while minimizing load on the origin in the most cost-effective way. Which solution meets these requirements?
- A gaming company is building a global Voice over IP application that must be highly available with automated failover across AWS Regions. The company wants to minimize user latency without relying on IP address caching on user devices. What should a solutions architect do to meet these requirements?
- A gaming company is moving its public scoreboard from a data center to AWS. The company uses Amazon EC2 Windows Server instances behind an Application Load Balancer to host the dynamic application. The company needs a highly available storage solution. The application includes static files and dynamic server-side code. Which combination of steps should a solutions architect take to meet these requirements? (Choose two.)
- A gaming company needs a highly available front-end tier for an application that runs on a modified Linux kernel and supports only UDP traffic. The front end must provide the best user experience: low latency, routing to the nearest edge location, and static IP addresses for access to application endpoints. What should a solutions architect implement to satisfy these requirements?
- A gaming company stores user data (geographic location, player data, leaderboards) in Amazon DynamoDB. The company needs continuous backups to an Amazon S3 bucket with minimal coding. Backups must not affect application availability or the table's read capacity units (RCUs). Which solution meets these requirements?
- A gaming company will launch a new internet-facing application in multiple AWS Regions. The application uses both TCP and UDP protocols. The company needs high availability and low latency for global users. Which combination of actions should a solutions architect take to meet these requirements? (Choose two.)
- A gaming platform sensitive to latency runs in every AWS Region on Amazon EC2 instances in Auto Scaling groups behind Application Load Balancers (ALBs). A solutions architect needs a mechanism to monitor application health and redirect traffic to healthy endpoints. Which solution meets these requirements?
- A gaming web application runs on Amazon EC2 instances behind an Application Load Balancer and stores data in Amazon RDS for MySQL. Users experience long delays caused by database read performance. The company wants to improve user experience while minimizing changes to the application architecture. What should a solutions architect do?
- A global company hosts a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). Static content is stored in an Amazon S3 bucket and the application serves dynamic content from the ALB. The company wants to reduce latency and improve performance for both static and dynamic content, using its own domain name registered in Amazon Route 53. What should a solutions architect implement?
- A global company runs applications in multiple AWS accounts in AWS Organizations. The applications use multipart uploads to upload data to multiple Amazon S3 buckets across AWS Regions. The company wants to report on incomplete multipart uploads for cost compliance purposes. Which solution will meet these requirements with the LEAST operational overhead?
- A global company stores sensitive data across AWS Regions in Amazon S3 buckets and adds millions of objects daily. The company wants to identify all S3 buckets that are not versioning-enabled across Regions. Which solution meets these requirements?
- A global company uses Amazon API Gateway to provide REST APIs for loyalty users in the us-east-1 and ap-southeast-2 Regions. A solutions architect must protect these API Gateway managed REST APIs across multiple accounts from SQL injection and cross-site scripting attacks with the LEAST administrative effort. Which solution should the architect use?
- A global ecommerce company hosts a web application with static and dynamic content and stores OLTP data in an Amazon RDS database. Users experience slow page loads. Which combination of actions should a solutions architect take to resolve this issue? (Choose two.)
- A global ecommerce company running a monolithic architecture needs a scalable, modular service architecture to manage growing product data. The company must preserve structured database schemas and provide storage for product data and images, with the least operational overhead. Which solution meets these requirements?
- A global ecommerce company runs critical workloads on AWS. The workloads use an Amazon RDS for PostgreSQL DB instance configured for Multi-AZ. Customers report application timeouts during database failovers. The company needs a resilient solution to reduce failover time. Which solution meets these requirements?
- A global marketing company has applications that run in the ap-southeast-2 Region and the eu-west-1 Region. Applications that run in a VPC in eu-west-1 need to communicate securely with databases that run in a VPC in ap-southeast-2. Which network design will meet these requirements?
- A global news company hosts a broadcast system on AWS. Reporters worldwide send live broadcasts using phone software that streams via the Real Time Messaging Protocol (RTMP). The solutions architect must provide reporters the ability to send the highest-quality streams and provide accelerated TCP connections back to the broadcast system. What should the solutions architect use?
- A global video streaming company uses Amazon CloudFront as a content distribution network (CDN). The company wants to roll out content in a phased manner across multiple countries. The company needs to ensure that viewers who are outside the countries to which the company rolls out content are not able to view the content. Which solution will meet these requirements?
- A group requires permissions to list an Amazon S3 bucket and delete objects from that bucket. An administrator created the following IAM policy and attached it to the group, but the group cannot delete objects. The company follows least-privilege access rules. Which statement should a solutions architect add to the policy to correct bucket access?
- A growing food delivery company has two Auto Scaling groups of Amazon EC2 instances: one group collects orders (fast) and another fulfills orders (longer processing). Data must not be lost during scaling events. The solution must allow both processes to scale properly during peak hours and optimize AWS resource usage. Which solution meets these requirements?
- A healthcare company is developing an AWS Lambda function that publishes notifications containing protected health information (PHI) to an encrypted Amazon SNS topic. The SNS topic uses AWS KMS customer managed keys for encryption. The company must ensure the application has the necessary permissions to publish messages securely to the SNS topic. Which combination of steps will meet these requirements? (Choose three.)
- A high-traffic static website is hosted on Amazon S3 with a CloudFront distribution that currently has a default TTL of 0 seconds. The company wants to add caching to improve performance but must ensure stale content is not served for more than a few minutes after a deployment. Which combination of caching methods should a solutions architect implement? (Choose two.)
- A hospital deployed a RESTful API using Amazon API Gateway and AWS Lambda to upload reports in PDF and JPEG formats. The hospital needs to modify the Lambda code to identify protected health information (PHI) in the reports. Which solution meets the requirement with the LEAST operational overhead?
- A hospital is designing a new application that collects patient symptoms. The design uses Amazon Simple Queue Service (Amazon SQS) and Amazon Simple Notification Service (Amazon SNS). Data must be encrypted at rest and in transit, and only authorized hospital personnel must be able to access the data. Which combination of steps should the solutions architect take to meet these requirements? (Choose two.)
- A hospital is digitizing a large archive of historical written records and will continue to add hundreds of documents per day. The data team will scan documents and upload them to AWS. A solutions architect must analyze the documents, extract medical information, and store the results so an application can run SQL queries on the data. The solution should maximize scalability and minimize operational effort. Which two steps should the solutions architect take? (Choose two.)
- A hospital must store patient records in an S3 bucket. The compliance team requires that all protected health information (PHI) be encrypted in transit and at rest, and that the compliance team administer the encryption key for data at rest. Which solution meets these requirements?
- A Java Spring Boot application runs as a pod on Amazon EKS in private subnets and needs to write data to an Amazon DynamoDB table without exposing traffic to the internet. Which combination of steps should a solutions architect take to accomplish this? (Choose two.)
- A large company wants to give globally located developers separate, limited-size, managed PostgreSQL databases for development. The databases will be low-volume and are needed only while developers are actively working. Which solution will meet these requirements MOST cost-effectively?
- A large international university has deployed compute services in AWS, including Amazon EC2, Amazon RDS, and Amazon DynamoDB. The university currently uses many custom scripts for backups and wants to centralize and automate backups using AWS-native options. Which solution meets these requirements?
- A law firm needs to publish hundreds of files so the public can read them. Modifications or deletions by anyone before a specified future date must be prevented. Which solution meets these requirements in the MOST secure way?
- A legacy application being migrated to AWS relies on hundreds of cron jobs that run for 1–20 minutes on various recurring schedules. The company wants to schedule and run these cron jobs on AWS with minimal refactoring and also support running jobs in response to a future event. Which solution meets these requirements?
- A legacy application must be migrated from an on-premises data center to AWS because of hardware capacity limits. The application runs 24/7 and its database storage will continue to grow over time. What is the MOST cost-effective migration approach?
- A legacy application produces CSV files and stores them in Amazon S3. A new commercial off‑the‑shelf (COTS) application can run complex SQL queries only against data in Amazon Redshift and Amazon S3, but it cannot process .csv files. The legacy application cannot be changed. Which solution enables the COTS application to use the legacy data with the LEAST operational overhead?
- A manufacturing company runs a report generation application on AWS as a monolith on a single Amazon EC2 instance. Each report takes about 20 minutes to generate. The application requires frequent updates to tightly coupled modules, causing downtime during patches. When interrupted, report generation restarts from the beginning. The company wants the application to be flexible, scalable, and gradually improved while minimizing downtime. Which solution meets these requirements?
- A manufacturing company’s machine sensors upload .csv files to an Amazon S3 bucket. Each .csv must be converted into an image as soon as possible for automatic graphical reports. Images become irrelevant after 1 month, but the .csv files must be kept to train machine learning models twice a year. The ML trainings and audits are scheduled weeks in advance. Which combination of steps will meet these requirements MOST cost-effectively? (Choose two.)
- A marketing company receives a large amount of new clickstream data in Amazon S3 from a marketing campaign. The company needs to analyze the clickstream data in Amazon S3 quickly and then decide whether to process the data further in the data pipeline. Which solution meets these requirements with the LEAST operational overhead?
- A marketing team has five years of news reports in PDF format and needs to extract content insights and sentiment. The solution must use Amazon Textract to process the PDFs and should require minimal operational overhead. Which solution meets these requirements?
- A media company has a multi-account AWS environment in us-east-1. An Amazon SNS topic in a production account publishes performance metrics. A Lambda function in an administrator account must be invoked by messages from the production SNS topic when significant metrics occur. Which combination of steps will meet these requirements? (Choose two.)
- A media company needs at least 10 TB of storage with maximum possible I/O performance for video processing, 300 TB of very durable storage for media content, and 900 TB for archival media that is not in use. Which set of services should a solutions architect recommend?
- A media company stores movies in Amazon S3 as single video files from 1 GB to 10 GB. They must provide streaming content within 5 minutes of purchase. Movies younger than 20 years have higher demand than movies older than 20 years. The company wants to minimize hosting costs based on demand. Which solution meets these requirements?
- A media company uses Amazon CloudFront to deliver publicly available streaming video stored in Amazon S3. The company wants to control who can access the S3-hosted video. Some users use a custom HTTP client that does not support cookies. Some users cannot change hardcoded URLs they use to access the content. Which services or methods meet these requirements with the LEAST impact to users? (Choose two.)
- A media company uses an Amazon CloudFront distribution to deliver content over the internet. Only premium customers should be able to access media streams and files stored in an Amazon S3 bucket. The company also delivers content on demand for specific uses, such as movie rentals or music downloads. Which solution meets these requirements?
- A media company wants to cache confidential media files stored in Amazon S3 so users worldwide can reliably and quickly access them. Which solution meets these requirements?
- A media company will migrate its user activity data store to AWS. The data store will grow to petabytes. The company needs a highly available data ingestion solution that supports on-demand SQL analytics of existing and new data and requires the LEAST operational overhead. Which solution meets these requirements?
- A media company’s website runs on EC2 instances behind an Application Load Balancer (ALB) with an Aurora database. The cybersecurity team reports the application is vulnerable to SQL injection. How should the company address this issue?
- A medical company must transform large volumes of clinical trial data from several customers. Data is extracted from a relational database, transformed with complex rules, and then loaded to Amazon S3. All data must be encrypted while it is processed and before it is stored in S3, and each customer's data must be encrypted with a customer-specific key. Which solution meets these requirements with the LEAST operational effort?
- A medical records company runs an application on Amazon EC2 instances in public subnets that processes files stored in Amazon S3. The EC2 instances access Amazon S3 over the internet and do not require any other network access. A new requirement mandates that file-transfer network traffic use a private route and not traverse the internet. Which network architecture change meets this requirement?
- A medical research lab produces study data that must be available with minimal latency to clinics across the country for their on-premises, file-based applications. The data files are stored in an Amazon S3 bucket and clinics have read-only access. What should a solutions architect recommend?
- A meteorological startup uses Amazon DynamoDB to store weather data and wants a new service that notifies managers of four internal teams each time a new weather event is recorded. The company does not want the new service to affect current application performance and wants the least operational overhead. What should a solutions architect do?
- A microservice must convert large uploaded images to compressed versions. When a user uploads an image through the web interface, the microservice should store the image in an Amazon S3 bucket, compress it with an AWS Lambda function, and store the compressed image in a different S3 bucket. The solution should use durable, stateless components and process images automatically. Which combination of actions meets these requirements? (Choose two.)
- A mobile game reads most metadata from an Amazon RDS DB instance. As popularity increased, metadata load times slowed and metrics indicate scaling the database alone won't help. The solutions architect must consider options that support snapshots, replication, and sub-millisecond response times. What should the solutions architect recommend?
- A multi-tier application runs six front-end web servers in an Amazon EC2 Auto Scaling group in a single Availability Zone behind an Application Load Balancer (ALB). A solutions architect must make the infrastructure highly available without modifying the application. Which architecture provides high availability?
- A multi-tier ecommerce application uses an Application Load Balancer in public subnets, a web tier in public subnets, and a MySQL cluster on Amazon EC2 instances in private subnets. The MySQL database must retrieve product catalog and pricing data hosted on the internet by a third-party provider. Design a strategy that maximizes security without increasing operational overhead. What should the solutions architect do?
- A multi-tier web application uses an Amazon Aurora MySQL DB cluster for storage and EC2 instances for the application tier. IT security requires that database credentials be encrypted and rotated every 14 days. What should a solutions architect do to meet this requirement with the LEAST operational effort?
- A new application runs on Amazon EC2 On-Demand Instances that scale frequently across multiple Availability Zones behind an Application Load Balancer (ALB). The architecture must support distributed session data management and the company is willing to modify application code if needed. What should the solutions architect do to provide distributed session data management?
- A new business application runs on two Amazon EC2 instances and uses an Amazon S3 bucket for document storage. A solutions architect must ensure the EC2 instances can access the S3 bucket. What should the architect do?
- A new deployment engineer will use AWS CloudFormation templates to create multiple AWS resources. A solutions architect wants the engineer to operate under least privilege. Which combination of actions should the solutions architect take? (Choose two.)
- A new internal web application must securely store and retrieve multiple employee usernames and passwords using an AWS managed service, with the least operational overhead. Which solution meets these requirements?
- A new web application will run on Amazon EC2 and use Amazon DynamoDB for backend storage. Traffic is unpredictable and expected read/write throughput is moderate to high. The application must scale with traffic and be cost-effective. Which DynamoDB table configuration best meets these requirements?
- A package delivery company runs an application on Amazon EC2 instances with an Amazon Aurora MySQL DB cluster. As the application grows, EC2 usage increases only slightly while DB cluster usage increases much faster. Adding a read replica reduces DB load only briefly; load continues to rise. The operations increasing DB usage are repeated read statements related to delivery details. The company needs to reduce the impact of repeated reads on the DB cluster MOST cost-effectively. Which solution meets this requirement?
- A payment processing application runs on AWS Lambda in private subnets across multiple Availability Zones. The application uses multiple Lambda functions and processes millions of transactions daily. The architecture must prevent duplicate payments. Which solution meets this requirement?
- A payment processing company records customer voice calls and stores the audio files in an Amazon S3 bucket. The company needs to extract text from the audio files and remove any personally identifiable information (PII) from the transcriptions. What should a solutions architect do to meet these requirements?
- A pharmaceutical company is generating rapidly increasing data volumes. Researchers regularly need a subset of the dataset immediately with minimal lag, while the full dataset does not require daily access. All data currently resides on on-premises storage arrays and the company wants to reduce capital expenses. Which storage solution should a solutions architect recommend?
- A photo processing application frequently uploads and downloads images from Amazon S3 buckets in the same AWS Region. Data transfer fees have increased and need to be reduced. Which solution will lower these costs?
- A production workload runs on 1,000 Amazon EC2 Linux instances and is powered by third-party software. The company must patch the third-party software on all EC2 instances as quickly as possible to remediate a critical security vulnerability. What should a solutions architect do to meet this requirement?
- A rapidly growing ecommerce company runs workloads in a single AWS Region and must create a disaster recovery strategy that includes a different AWS Region. The company wants the database in the DR Region to be up to date with the least possible latency. The remaining infrastructure in the DR Region should run at reduced capacity and be able to scale up if needed. Which solution provides the LOWEST recovery time objective (RTO)?
- A regional subscription-based streaming service runs in one AWS Region on EC2 instances in Auto Scaling groups behind Elastic Load Balancers. The architecture uses an Amazon Aurora global database across multiple Availability Zones. The company wants to expand globally and ensure minimal downtime. Which solution provides the MOST fault tolerance?
- A reporting system delivers hundreds of .csv files to an Amazon S3 bucket each day. The company must convert these files to Apache Parquet and store the results in a transformed data bucket. Which solution will meet the requirement with the LEAST development effort?
- A reporting team receives files daily in an Amazon S3 bucket and manually copies them to an analysis S3 bucket at the same time each day for Amazon QuickSight. More teams are sending larger files to the initial S3 bucket. The reporting team wants files copied automatically to the analysis bucket as they arrive, run AWS Lambda functions to perform pattern matching on the copied data, and send the data to a pipeline in Amazon SageMaker Pipelines. What should a solutions architect do to meet these requirements with the LEAST operational overhead?
- A research company runs a simulation application on Linux that writes intermediate data to an NFS share every 5 minutes. A Windows visualization desktop application reads that output and requires SMB. The company currently maintains two synchronized file systems, causing duplication. They must migrate to AWS without changing either application. Which solution meets these requirements?
- A research lab needs to process about 8 TB of data with sub-millisecond latencies and a minimum storage throughput of 6 GBps. Hundreds of Amazon Linux EC2 instances will distribute and process the data. Which solution meets the performance requirements?
- A retail company has multiple business teams, each managing its own AWS account under AWS Organizations. Each team stores product inventory in a DynamoDB table in its account. A central inventory reporting application runs in a shared account and must read items from all teams' DynamoDB tables. Which authentication option meets these requirements MOST securely?
- A retail company uses a regional Amazon API Gateway API for its public REST APIs. The API Gateway uses a custom domain name that maps to an Amazon Route 53 alias record. A solutions architect needs a deployment approach that minimizes customer impact and minimizes data loss when releasing a new API version. Which solution meets these requirements?
- A robotics company is building a public load balancer in AWS to ensure encrypted, seamless communication with backend services. The load balancer must route traffic based on query strings to different target groups. Which solution meets these requirements?
- A security audit shows Amazon EC2 instances are not patched regularly. A solutions architect needs to run regular security scans across a large EC2 fleet, apply patches on a regular schedule, and provide a report of each instance’s patch status. Which solution meets these requirements?
- A security team wants to limit access to specific services or actions across all AWS accounts in a large AWS Organizations organization. The solution must be scalable and provide a single place to maintain permissions. What should a solutions architect do?
- A serverless application uses Amazon API Gateway, AWS Lambda, and Amazon DynamoDB. The Lambda function needs permissions to read and write to the DynamoDB table. Which solution will give the Lambda function access to the DynamoDB table MOST securely?
- A serverless application uses Amazon API Gateway, AWS Lambda, and an Amazon RDS for PostgreSQL database. During peak or unpredictable traffic, the application experiences database connection timeouts. The company wants to reduce failures with the least code changes. What should a solutions architect do?
- A service running on Amazon EC2 instances in a private subnet reads and writes large amounts of data to an Amazon S3 bucket in the same AWS Region. The instances currently access S3 through a NAT gateway in a public subnet. The company wants to reduce data egress costs. Which solution is the MOST cost-effective?
- A social media company allows users to upload images to an application hosted in AWS. The images must be automatically resized for multiple device types. Traffic is unpredictable throughout the day. The company wants a highly available solution that maximizes scalability. What should a solutions architect implement?
- A social media company allows users to upload images to its website, which runs on Amazon EC2 instances. During upload, the website resizes images to a standard size and stores the resized images in Amazon S3. Users experience slow upload requests. The company wants to reduce coupling in the application and improve website performance. Design the most operationally efficient image upload process. Which combination of actions should the solutions architect take? (Choose two.)
- A social media company collects and processes data and currently stores it on on-premises NFS storage that cannot scale fast enough. The company wants to migrate the data store to AWS in the MOST cost-effective way. Which solution meets these requirements?
- A social media company is building a feature for its website. The feature will give users the ability to upload photos. The company expects significant increases in demand during large events and must ensure that the website can handle the upload traffic from users. Which solution meets these requirements with the MOST scalability?
- A social media company runs a rewards website that gives users points for uploading videos. Partners verify user eligibility using a unique user ID, and partners want to receive user IDs via an HTTP endpoint whenever the company awards points. Hundreds of vendors sign up daily. The company needs a scalable architecture that lets the website add partners quickly with the LEAST implementation effort. Which solution meets these requirements?
- A social media company runs its app on Amazon EC2 instances behind an ALB. The ALB is the origin for a CloudFront distribution. The app stores more than a billion images in an S3 bucket and processes thousands of images per second. The company wants to dynamically resize images and serve appropriate formats to clients. Which solution meets these requirements with the LEAST operational overhead?
- A social media company wants to store its database of user profiles, relationships, and interactions in the AWS Cloud. The company needs an application to monitor any changes in the database, analyze relationships between data entities, and provide recommendations to users. Which solution will meet these requirements with the LEAST operational overhead?
- A solutions architect configured a VPC with a small range of IP addresses. As the number of Amazon EC2 instances in the VPC grows, there are insufficient IP addresses for future workloads. Which solution resolves this issue with the LEAST operational overhead?
- A solutions architect created a Cache VPC for an Amazon ElastiCache cluster and an App VPC for the application’s Amazon EC2 instances. Both VPCs are in the us-east-1 Region. The EC2 instances must access the ElastiCache cluster. Which solution meets these requirements MOST cost-effectively?
- A solutions architect created two IAM policies named Policy1 and Policy2 and attached them to an IAM group. A cloud engineer is added as an IAM user to that group. Which action will the cloud engineer be able to perform?
- A solutions architect creates a VPC with two public subnets and two private subnets. A corporate security mandate requires launching all Amazon EC2 instances in private subnets. When the solutions architect launches an EC2 instance that runs a web server on ports 80 and 443 in a private subnet, no external internet traffic can reach the server. What should the solutions architect do to resolve this?
- A solutions architect designs a demo environment that runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). Traffic rises significantly during working hours and the environment is not required to run on weekends. Which combination of actions should the architect take to ensure the system can scale to meet demand? (Choose two.)
- A solutions architect designs storage in Amazon S3 for a digital media application. Objects must be resilient to the loss of an Availability Zone. Some files are accessed frequently, others are rarely accessed with an unpredictable pattern. The architect must minimize storage and retrieval costs. Which S3 storage option meets these requirements?
- A solutions architect has created a new AWS account and must secure AWS account root user access. Which combination of actions will accomplish this? (Choose two.)
- A solutions architect is building a document review app that stores documents in an Amazon S3 bucket. The solution must prevent accidental deletion of documents and ensure all versions remain available. Users must be able to download, modify, and upload documents. Which combination of actions meets these requirements? (Choose two.)
- A solutions architect is creating a data processing job that runs once daily and can take up to 2 hours to complete. If the job is interrupted, it must restart from the beginning. How should the solutions architect address this issue in the MOST cost-effective manner?
- A solutions architect is creating a new Amazon CloudFront distribution for an application that accepts some sensitive user-submitted information. The application already uses HTTPS but requires an additional layer of protection so the sensitive information remains protected across the entire application stack and is accessible only to specific applications. Which action should the solutions architect take?
- A solutions architect is creating an application that will handle batch processing of large amounts of data. The input data will be held in Amazon S3 and the output data will be stored in a different S3 bucket. For processing, the application will transfer the data over the network between multiple Amazon EC2 instances. What should the solutions architect do to reduce the overall data transfer costs?
- A solutions architect is deploying a complex Java application with a MySQL database. The Java application must run on Apache Tomcat and be highly available. What should the solutions architect do to meet these requirements?
- A solutions architect is designing a company’s disaster recovery (DR) architecture. The company has a MySQL database on an Amazon EC2 instance in a private subnet with scheduled backups. The DR design must include multiple AWS Regions and require the LEAST operational overhead. Which solution meets these requirements?
- A solutions architect is designing a disaster recovery (DR) strategy to provide Amazon EC2 capacity in a failover AWS Region. Business requirements state that the DR strategy must meet capacity in the failover Region. Which solution will meet these requirements?
- A solutions architect is designing a hybrid architecture to extend an on-premises environment to AWS. The company requires a highly available connection with consistent low latency to an AWS Region, wants to minimize costs, and is willing to accept slower traffic if the primary connection fails. What should the solutions architect do?
- A solutions architect is designing a multi-account AWS solution using AWS Organizations and has arranged accounts into organizational units (OUs). The architect needs to detect any changes to the OU hierarchy and notify the operations team of those changes with the LEAST operational overhead. Which solution meets these requirements?
- A solutions architect is designing a multi-tier application. Users upload images from mobile devices. The application generates a thumbnail for each image (which can take up to 60 seconds) and returns a success message to the user as quickly as possible to confirm receipt of the original image. The architect must design the application to dispatch requests asynchronously across tiers to meet these requirements. What should the solutions architect do?
- A solutions architect is designing a new API using Amazon API Gateway to receive user requests. Request volume is highly variable, and several hours can pass without any requests. Processing is asynchronous but should finish within a few seconds after a request. Which compute service should the API invoke to meet the requirements at the lowest cost?
- A solutions architect is designing a new service behind Amazon API Gateway. Request patterns will be unpredictable and can spike suddenly from 0 to over 500 requests per second. The total persisted data is currently less than 1 GB with uncertain future growth and can be queried with simple key-value requests. Which combination of AWS services would meet these requirements? (Choose two.)
- A solutions architect is designing a REST API in Amazon API Gateway for a cash-payback service. The application requires 1 GB of memory and 2 GB of storage for its computation, and it needs relational data storage. Which combination of AWS services will meet these requirements with the LEAST administrative effort? (Choose two.)
- A solutions architect is designing a stateless application to run on AWS. They created an AMI and launch template for the application. Jobs must be processed in parallel, and EC2 instances should be added and removed automatically based on workload. The application must be loosely coupled and job items must be durably stored. Which solution meets these requirements?
- A solutions architect is designing a three-tier web application with an internet-facing Application Load Balancer (ALB). The web tier and application tier run on Amazon EC2 instances in private subnets, and the database tier runs Microsoft SQL Server on EC2 instances in private subnets. Security is a high priority. Which combination of security group configurations should the architect use? (Choose three.)
- A solutions architect is designing a two-tier application to collect and process registration forms. The application must process submitted forms quickly, ensure each form is processed exactly once, and guarantee no data loss. Which solution meets these requirements?
- A solutions architect is designing a two-tier web application. The web tier is public-facing on Amazon EC2 in public subnets. The database tier runs Microsoft SQL Server on Amazon EC2 in a private subnet. Security is a high priority. How should security groups be configured? (Choose two.)
- A solutions architect is designing a VPC with multiple subnets to host EC2 instances and Amazon RDS DB instances. The VPC has six subnets across two Availability Zones: in each AZ there is a public subnet, a private subnet, and a database-dedicated subnet. Only EC2 instances in the private subnets should be able to access the RDS databases. Which solution enforces this requirement?
- A solutions architect is designing a VPC with public and private subnets. The VPC and subnets use IPv4 CIDR blocks. There is one public subnet and one private subnet in each of three Availability Zones (AZs) for high availability. An internet gateway provides internet access for the public subnets. The private subnets require internet access so Amazon EC2 instances can download software updates. What should the solutions architect do to enable internet access for the private subnets?
- A solutions architect is designing a workload to store hourly energy consumption per business tenant. Sensors send HTTP requests that add usage per tenant. The architect must use managed services when possible, and the workload will gain additional independent components over time. Which solution meets these requirements with the least operational overhead?
- A solutions architect is designing an application that allows business users to upload objects to Amazon S3. The solution must maximize object durability and keep objects readily available at any time for any length of time. Objects are accessed frequently during the first 30 days after upload, with much lower access likelihood afterward. Which solution is MOST cost-effective?
- A solutions architect is designing an asynchronous application to validate credit card data for a bank. The application must be secure and must process each request at least once. Which solution is the MOST cost-effective?
- A solutions architect is designing an AWS Identity and Access Management (IAM) authorization model for a company's AWS account. The company has designated five specific employees to have full access to AWS services and resources in the AWS account. The solutions architect has created an IAM user for each of the five designated employees and has created an IAM user group. Which solution will meet these requirements?
- A solutions architect is designing security controls for developer accounts created under AWS Organizations. Developers will have root user–level access to their own accounts, but the architect must ensure the mandatory AWS CloudTrail configuration applied to new developer accounts cannot be modified. Which action meets this requirement?
- A solutions architect is designing shared storage for a web application deployed across multiple Availability Zones. The web application runs on Amazon EC2 instances in an Auto Scaling group and will have frequent content updates. The solution must provide strong consistency so new content is returned immediately after changes. Which solutions meet these requirements? (Choose two.)
- A solutions architect is designing storage for a web application that stores and displays engineering drawings. All components will run on AWS. The design must support caching to minimize load times and must be able to store petabytes of data. Which combination of storage and caching should the solutions architect use?
- A solutions architect is designing the cloud architecture for a new application on AWS. The processing should run in parallel, adding and removing application nodes as needed based on the number of jobs to process. The processor application is stateless. The design must be loosely coupled and job items must be durably stored. Which design should the solutions architect use?
- A solutions architect is designing user authentication. The solution must invoke two-factor authentication for users who log in from inconsistent geographic locations, IP addresses, or devices. It must also scale to millions of users. Which solution meets these requirements?
- A solutions architect is optimizing a website for a global musical event. Performances will be streamed live and then offered on demand. Which service will improve performance for both real-time and on-demand streaming?
- A solutions architect is reviewing application resilience. A database administrator recently failed over an Amazon Aurora PostgreSQL writer instance during a scaling exercise, causing 3 minutes of downtime. Which solution will reduce downtime for scaling exercises with the LEAST operational overhead?
- A solutions architect manages an analytics application that stores large amounts of semistructured data in an Amazon S3 bucket. The architect wants parallel data processing to speed up processing and to enrich the data using information stored in an Amazon Redshift database. Which solution meets these requirements?
- A solutions architect must allow team members to access S3 buckets in two AWS accounts: development and production. Team members already use unique IAM users in the development account and belong to an IAM group with permissions. The solutions architect created an IAM role in the production account that grants access to the production S3 bucket. Which solution meets the requirements while following least privilege?
- A solutions architect must connect the corporate network to a VPC so on-premises systems can access AWS resources. The solution must encrypt all traffic between the corporate network and the VPC at the network and session layers, and must enforce security controls to prevent unrestricted access. Which solution meets these requirements?
- A solutions architect must create a disaster recovery plan for a high-volume SaaS platform whose data is stored in an Amazon Aurora MySQL DB cluster. The DR plan must replicate data to a secondary AWS Region. Which solution will meet these requirements MOST cost-effectively?
- A solutions architect must design a highly available Amazon ElastiCache for Redis solution that prevents performance degradation and data loss locally and within an AWS Region. The solution must provide high availability at both the node and Region levels. Which solution meets these requirements?
- A solutions architect must design a highly available application with web, application, and database tiers. HTTPS content should be delivered as close to the edge as possible with minimal latency, and the solution must be MOST secure. Which solution meets these requirements?
- A solutions architect must design a highly available infrastructure for a website powered by Windows web servers on Amazon EC2 instances. The solution must mitigate a large-scale DDoS attack originating from thousands of IP addresses. Downtime is not acceptable. Which actions should the solutions architect take to protect the website from such an attack? (Choose two.)
- A solutions architect must design a static website using Amazon CloudFront with an Amazon S3 origin. The company’s security policy requires that all website traffic be inspected by AWS WAF. How should the solutions architect meet this requirement?
- A solutions architect must design storage for client case files that are core company assets. The number of files will grow over time. Multiple EC2 application servers must be able to access the files simultaneously, and the solution must provide built-in redundancy. Which solution meets these requirements?
- A solutions architect must ensure that API calls to Amazon DynamoDB from Amazon EC2 instances in a VPC never travel across the internet. Which combination of steps should the solutions architect take to meet this requirement? (Choose two.)
- A solutions architect must host a high performance computing (HPC) workload on hundreds of Amazon EC2 instances that require parallel access to a shared file system for distributed processing of large datasets. Multiple instances will access the datasets simultaneously. The workload requires access latency within 1 ms. After processing, engineers need access to the dataset for manual postprocessing. Which solution will meet these requirements?
- A solutions architect must identify Amazon S3 buckets that are no longer accessed or are rarely accessed, with the least operational overhead. Which solution accomplishes this goal?
- A solutions architect must implement an automated compliance control that prohibits security group rules allowing SSH from 0.0.0.0/0. The company must be notified when the policy is breached and needs a solution as soon as possible with the least operational overhead. What should the solutions architect do?
- A solutions architect must migrate a Windows Internet Information Services (IIS) web application to AWS. The application depends on a file share hosted on the on-premises NAS. The architect plans to migrate the IIS web servers to Amazon EC2 instances in multiple Availability Zones and connect them to a replacement storage solution with an Elastic Load Balancer. Which replacement for the on-premises file share is MOST resilient and durable?
- A solutions architect must optimize costs for an application that uses Amazon EC2 instances, AWS Fargate, and AWS Lambda. EC2 instances host the data ingestion layer, with sporadic and unpredictable usage; those workloads can be interrupted at any time. The front end runs on Fargate and the API layer runs on Lambda; both have predictable utilization for the next year. Which combination of purchasing options will be MOST cost-effective? (Choose two.)
- A solutions architect must review the company's Amazon S3 buckets to discover personally identifiable information (PII). The PII is stored in the us-east-1 and us-west-2 Regions. Which solution will meet these requirements with the LEAST operational overhead?
- A solutions architect must secure a VPC that hosts Amazon EC2 instances containing highly sensitive data in a private subnet. Company policy allows these instances to access only approved third-party software repositories on the internet using the third party’s URLs. All other internet traffic must be blocked. Which solution meets these requirements?
- A solutions architect needs to continuously copy files from an Amazon S3 bucket to an Amazon EFS file system and to another S3 bucket. New files are added consistently to the source S3 bucket. Copied files should be overwritten only if the source file changes. Which solution meets these requirements with the LEAST operational overhead?
- A solutions architect needs to design a new microservice for a company’s application. Clients must be able to call an HTTPS endpoint to reach the microservice. The microservice also must use AWS Identity and Access Management (IAM) to authenticate calls. The solutions architect will write the logic for this microservice by using a single AWS Lambda function that is written in Go 1.x. Which solution will deploy the function in the MOST operationally efficient way?
- A solutions architect needs to securely store a database user name and password in AWS Systems Manager Parameter Store for an application running on an Amazon EC2 instance. What should the solutions architect do to create a secure parameter and allow the EC2 instance to access it?
- A solutions architect observes that a nightly batch job scales up automatically for 1 hour before the Auto Scaling group reaches the desired Amazon EC2 capacity. The peak capacity is the same every night and the batch jobs always start at 1 AM. The architect needs a cost-effective solution that allows the desired EC2 capacity to be reached quickly and lets the Auto Scaling group scale down after the jobs complete. What should the architect do?
- A solutions architect wants all new IAM users to have specific password complexity requirements and mandatory rotation periods. What should the solutions architect do?
- A solutions architect wants to use the following JSON text as an identity-based policy to grant specific permissions: Which IAM principals can the solutions architect attach this policy to? (Choose two.)
- A startup hosts a website on a single Amazon EC2 instance. The site is a stateless Python application with a MySQL database, serving low traffic. The company is concerned about instance reliability and must migrate to a highly available architecture without changing application code. Which combination of actions should a solutions architect take to achieve high availability? (Choose two.)
- A streaming media company is rebuilding its infrastructure to accommodate increasing demand for video content that users consume daily. The company needs to process terabyte-sized videos to block some content in the videos. Video processing can take up to 20 minutes. The company needs a solution that will scale with demand and remain cost-effective. Which solution will meet these requirements?
- A survey company stores several years of U.S. data in an Amazon S3 bucket that is 3 TB and growing. The company is sharing the data with a European marketing firm that has S3 buckets. The company wants to keep its data transfer costs as low as possible. Which solution will meet this requirement?
- A telemarketing company is building a customer call center on AWS. They need multiple-speaker recognition, generated transcript files, the ability to query transcripts for business analysis, and to retain transcripts for 7 years for auditing. Which solution meets these requirements?
- A three-tier web application has web servers in a public subnet and application and database servers in private subnets. A third-party virtual firewall appliance from AWS Marketplace is deployed in an inspection VPC and has an IP interface that accepts packets. A solutions architect must ensure all incoming traffic is inspected by the appliance before reaching the web servers, with the least operational overhead. Which solution meets these requirements?
- A three-tier web application used for employee training is accessed only 12 hours per day. The application stores data in an Amazon RDS for MySQL DB instance. The company wants to minimize costs. What should a solutions architect do?
- A transaction processing company runs weekly scripted batch jobs on Amazon EC2 instances in an Auto Scaling group. The number of transactions varies, but baseline CPU utilization during each run is at least 60%. The company must provision capacity 30 minutes before the jobs start. Engineers currently modify the Auto Scaling group manually and the company lacks resources to analyze capacity trends. Which solution will automate modifying the Auto Scaling group’s desired capacity with the LEAST operational overhead?
- A two-tier architecture has a public subnet for web servers and a database subnet for an Amazon RDS for MySQL DB instance. Web servers in the public subnet must be open to the internet on port 443. The DB instance must be accessible only to the web servers on port 3306. Which combination of steps should the solutions architect take to meet these requirements? (Choose two.)
- A two-tier ecommerce website runs on AWS. The web tier uses a load balancer that forwards traffic to Amazon EC2 instances. The database tier uses an Amazon RDS DB instance. The EC2 instances and the RDS DB instance must not be exposed to the public internet. The EC2 instances require internet access to complete payment processing through a third-party web service. The application must be highly available. Which combination of configuration options will meet these requirements? (Choose two.)
- A university research laboratory must migrate 30 TB from an on‑premises Windows file server to Amazon FSx for Windows File Server. The lab has a 1 Gbps network link that is shared by other departments. The lab wants the migration to maximize throughput but also be able to control how much bandwidth the service uses to limit impact on other departments. The migration must complete within 5 days. Which AWS solution meets these requirements?
- A vendor provides an application as a Docker container image that requires 50 GB of storage for temporary files. The infrastructure must be serverless. Which solution meets the requirements with the least operational overhead?
- A video game company is deploying a global gaming application that requires near real-time player reviews and rankings and fast data access. The data must persist on disk so it survives application restarts. Which solution provides this with the least operational overhead?
- A weather forecasting company collects continuous temperature readings, aggregates them into larger Apache Parquet files, encrypts the files using client-side encryption with KMS-managed keys (CSE-KMS), and writes them to an Amazon S3 bucket in daily prefixes. The company occasionally runs SQL queries to compute sample moving averages for a specific calendar day. Which solution is the MOST cost-effective to meet these requirements?
- A weather forecasting company needs to process hundreds of gigabytes of data with sub-millisecond latency. The company has an HPC environment on-premises and wants to expand to the cloud. A solutions architect must choose a highly available cloud storage solution that supports large amounts of sustained throughput and allows thousands of compute instances to simultaneously access and process the entire dataset. What should the solutions architect choose?
- A web application hosted on a single Amazon EC2 instance in a single public subnet is failing to handle increased traffic. The company needs high availability and scalability without rewriting the application. Which two steps will meet these requirements? (Choose two.)
- A web application runs on Amazon EC2 instances in multiple Availability Zones and provides access to a repository of text documents totaling about 900 TB. The application will experience periods of high demand. A solutions architect must choose a storage solution that scales to meet demand and is cost-effective. Which storage option meets these requirements MOST cost-effectively?
- A web application runs on multiple Amazon EC2 instances that are placed in individual target groups behind an Application Load Balancer (ALB). The public site is available to users. Engineers need a development hostname that routes to a single development EC2 instance for testing, and this routing must automatically continue to work if the development instance is replaced. Using a Route 53 hosted zone, which solution meets these requirements?
- A web application uses Amazon API Gateway in front of an AWS Lambda function and an Amazon DynamoDB table. Amazon Cognito user pools identify individual users. The solutions architect needs to ensure that only users with a subscription can access premium content. Which solution will meet this requirement with the LEAST operational overhead?
- After a breach of on‑premises applications, a company is migrating those applications to Amazon EC2. The company needs an active vulnerability scanning solution for the EC2 instances that produces a detailed report of findings. Which solution meets these requirements?
- After migrating a three-tier application to a VPC, the security team finds that least privilege is not being applied to Amazon EC2 security group ingress and egress rules between tiers. What should a solutions architect do to fix this?
- After migrating to AWS, users are provisioning oversized Amazon EC2 instances and changing security group rules without following change control. A solutions architect must track and audit inventory and configuration changes. Which actions should the architect take? (Choose two.)
- An Amazon EC2 administrator created the following policy associated with an IAM group containing several users: What is the effect of this policy?
- An Amazon EC2 instance is in a private subnet in a new VPC that has no outbound internet access. The EC2 instance must download monthly security updates from an external vendor. What should a solutions architect do to satisfy this requirement?
- An Amazon EventBridge rule targets a third-party API, but the third-party API has not received any incoming traffic. A solutions architect needs to determine whether the rule conditions are being met and whether the rule's target is being invoked. Which solution will provide this information?
- An analytics company runs multi-tier services in an Amazon VPC and wants to expose RESTful APIs to millions of users. Users must be authenticated before accessing the APIs. Which solution provides the MOST operational efficiency?
- An application allows users at a company's headquarters to access product data stored in an Amazon RDS MySQL DB instance. The operations team identified an application performance slowdown and wants to separate read traffic from write traffic. A solutions architect must quickly optimize the application's performance. What should the solutions architect recommend?
- An application ingests incoming messages that dozens of other applications and microservices then consume quickly. Message volume varies drastically and can spike to 100,000 messages per second. The company wants to decouple components and increase scalability. Which solution meets these requirements?
- An application places hundreds of 1 GB .csv files into an Amazon S3 bucket every hour. Each uploaded file must be converted to Apache Parquet format and written to an S3 bucket. Which solution provides the required functionality with the least operational overhead?
- An application processes sensitive financial data for multiple customers. Each customer's data must be encrypted separately at rest using a secure, centralized key management solution. The company will use AWS KMS. Which solution meets these requirements with the least operational overhead?
- An application running on Amazon EC2 instances across multiple Availability Zones must ingest real-time data from third-party applications and place the raw ingested data into an Amazon S3 bucket. Which solution meets these requirements?
- An application running on Amazon EC2 instances needs to access an Amazon S3 bucket without traffic traversing the internet. How should a solutions architect configure access to meet this requirement?
- An application running on an Amazon EC2 instance in VPC-A needs to access files on another EC2 instance in VPC-B. Both VPCs are in separate AWS accounts. The network administrator must design a secure solution to allow EC2 in VPC-A to access the EC2 in VPC-B. The connectivity should avoid a single point of failure and not have bandwidth concerns. Which solution will meet these requirements?
- An application runs in a private subnet and already uses Amazon Cognito with a user pool for authentication. The application needs to securely store user documents in an Amazon S3 bucket. Which combination of steps will securely integrate Amazon S3 with the application? (Choose two.)
- An application runs on Amazon EC2 instances across multiple Availability Zones in an Auto Scaling group behind an Application Load Balancer. The application performs best when EC2 CPU utilization is near 40%. What should a solutions architect do to maintain this performance across all instances in the group?
- An application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group across multiple Availability Zones. On the first day of every month at midnight, a month-end financial batch runs and immediately causes instance CPU to spike to 100%, disrupting the application. What should a solutions architect recommend so the application can handle the workload and avoid downtime?
- An application runs on Amazon EC2 instances behind an Elastic Load Balancer in an Auto Scaling group and uses an Amazon DynamoDB table. The company wants to ensure the application can be made available in another AWS Region with minimal downtime. What should a solutions architect do to meet this requirement with the LEAST downtime?
- An application runs on Amazon EC2 instances in an Auto Scaling group behind an Elastic Load Balancing (ELB) load balancer. The company expects a predictable spike in traffic each year during a holiday and wants the Auto Scaling group to proactively increase capacity to minimize user impact. Which strategy meets this requirement?
- An application runs on Amazon EC2 instances in private subnets and needs to access an Amazon DynamoDB table. What is the MOST secure way to access the table while ensuring traffic does not leave the AWS network?
- An application runs on Amazon EC2 Linux instances across multiple Availability Zones and needs a storage layer that is highly available, POSIX-compliant, maximally durable, shareable across instances, and frequently accessed for the first 30 days then infrequently thereafter. Which solution meets these requirements MOST cost-effectively?
- An application runs on an Amazon EC2 instance in a VPC. The application processes logs that are stored in an Amazon S3 bucket. The EC2 instance must access the S3 bucket without any Internet connectivity. Which solution provides private network connectivity to Amazon S3?
- An application runs on an Amazon EC2 instance that has an Elastic IP address in VPC A. The application requires access to a database in VPC B. Both VPCs are in the same AWS account. Which solution will provide the required access MOST securely?
- An application runs on five Amazon EC2 instances behind an Application Load Balancer (ALB) using a target group. Average CPU utilization is below 10% most of the time, with occasional spikes to 65%. You need to automate scalability to optimize cost while ensuring enough CPU during surges. Which solution meets these requirements?
- An application runs on several Amazon EC2 instances, each with multiple Amazon Elastic Block Store (Amazon EBS) data volumes attached. The EC2 instance configuration and data need nightly backups, and the application must be recoverable in a different AWS Region. Which solution meets these requirements with the MOST operational efficiency?
- An application serves clients in more than 20,000 retail storefronts worldwide. Backend web services run on Amazon EC2 behind an Application Load Balancer (ALB) and are exposed over HTTPS on port 443. Retail locations communicate over the public internet and register their allocated ISP IP address. The security team wants to restrict access to only the registered IP addresses. What should a solutions architect do?
- An application uses an Amazon RDS MySQL DB instance that is running low on disk space. A solutions architect needs to increase the disk space without downtime and with minimal effort. Which solution meets these requirements?
- An application uses an AWS Lambda function (invoked via Amazon API Gateway) to store data in an Amazon Aurora PostgreSQL database. During proof-of-concept, the company raised Lambda quotas to handle high-volume data loads. A solutions architect must recommend a design that improves scalability and minimizes configuration effort. Which solution meets these requirements?
- An application uses multiple AWS Lambda functions to retrieve sensitive data from a single Amazon S3 bucket. The company must ensure that only authorized Lambda functions can access the data, following the principle of least privilege. Which solution meets these requirements?
- An application will run on Amazon EC2 instances in private subnets across multiple Availability Zones in a VPC. The EC2 instances frequently access large, confidential files stored in Amazon S3 buckets for processing. The solutions architect must minimize data transfer costs. What should the architect do?
- An automobile sales website stores listings in a database on Amazon RDS. When an automobile is sold, the listing needs to be removed from the website and the data must be sent to multiple target systems. Which design should a solutions architect recommend?
- An AWS Lambda function needs read access to an Amazon S3 bucket in the same account. Which solution meets this requirement in the MOST secure way?
- An ecommerce application runs on Amazon EC2 for front-end and backend tiers, with the database on Amazon RDS for MySQL. The backend frequently issues identical queries that cause performance slowdowns. What should be done to improve backend performance?
- An ecommerce application runs on Amazon EC2 instances behind an Application Load Balancer in an Auto Scaling group across multiple Availability Zones. The application stores transactions in a MySQL 8.0 database running on a large EC2 instance; performance degrades as load increases. The application has far more reads than writes. The company wants an automatically scaling, highly available database solution for unpredictable read workloads. Which solution meets these requirements?
- An ecommerce application uses Amazon API Gateway and an AWS Lambda function, storing data in an Amazon Aurora PostgreSQL database. During a sales event a surge in orders caused timeouts. The solutions architect found high CPU and memory on the database due to many open connections. To prevent timeout errors with the least change to the application, which solution should the architect implement?
- An ecommerce application uses PostgreSQL on an EC2 instance. Monthly sales events cause unpredictable spikes in database usage and connection issues. The company needs to maintain performance during these unpredictable increases in the most cost-effective way. Which solution resolves this issue?
- An ecommerce company is building a distributed application composed of several serverless functions and AWS services. Workflows require manual approvals. The solution must combine multiple AWS Lambda functions into responsive serverless applications and orchestrate data and services that run on Amazon EC2 instances, containers, or on-premises servers, while minimizing operational overhead. Which solution meets these requirements?
- An ecommerce company is migrating its on-premises workload to the AWS Cloud. The workload includes a web application and a backend Microsoft SQL database. The company expects a high customer volume during a promotional event. The new infrastructure must be highly available and scalable with the LEAST administrative overhead. Which solution meets these requirements?
- An ecommerce company is running a seasonal online sale. The website runs on Amazon EC2 instances across multiple Availability Zones and must handle sudden traffic spikes during the sale. Which solution will meet these requirements MOST cost-effectively?
- An ecommerce company must run a scheduled daily job that aggregates and filters sales records for analytics. The sales records are stored in an Amazon S3 bucket; each object can be up to 10 GB. Depending on volume, the job can take up to an hour. CPU and memory usage are constant and known in advance. A solutions architect needs to minimize operational effort required to run the job. Which solution meets these requirements?
- An ecommerce company runs a PostgreSQL database on premises using high-IOPS Amazon Elastic Block Store (Amazon EBS) block storage. Daily peak I/O does not exceed 15,000 IOPS. The company plans to migrate to Amazon RDS for PostgreSQL and needs to provision disk IOPS independently of storage capacity. Which solution is the MOST cost-effective?
- An ecommerce company runs applications across AWS accounts in an AWS Organization. The applications use Amazon Aurora PostgreSQL databases in all accounts. The company must detect malicious activity by identifying abnormal failed and incomplete login attempts to the databases with the MOST operational efficiency. Which solution meets this requirement?
- An ecommerce company runs its application on AWS. The application uses an Amazon Aurora PostgreSQL cluster in Multi-AZ mode for the database. During a recent promotional campaign, the application experienced heavy read and write load. Users experienced timeout issues when accessing the application. A solutions architect needs to make the application architecture more scalable and highly available with the LEAST downtime. Which solution will meet these requirements?
- An ecommerce company stores about 300 MB of JSON analytics data per month. The company needs a disaster recovery solution that keeps the data accessible in milliseconds if required and retains the data for 30 days. Which option is the MOST cost-effective solution?
- An ecommerce company stores terabytes of customer data in AWS, including personally identifiable information (PII). Three applications will use the data; only one application needs the PII. The PII must be removed before the other two applications process the data. Which solution meets these requirements with the LEAST operational overhead?
- An ecommerce company uses Amazon Route 53 as its DNS provider. The company hosts its website on premises and in the AWS Cloud. The company's on-premises data center is near the us-west-1 Region. The company uses the eu-central-1 Region to host the website. The company wants to minimize load time for the website as much as possible. Which solution will meet these requirements?
- An ecommerce company uses Amazon SNS to send order messages to an on-premises HTTPS endpoint that the warehouse application processes. Some order messages were not received. A solutions architect must retain undelivered messages and analyze them for up to 14 days with the LEAST development effort. Which solution meets these requirements?
- An ecommerce company wants a disaster recovery solution for its Amazon RDS DB instances that run Microsoft SQL Server Enterprise Edition. The company's current recovery point objective (RPO) and recovery time objective (RTO) are 24 hours. Which solution will meet these requirements MOST cost-effectively?
- An ecommerce company wants to build and train machine learning (ML) models to visualize complex scenarios and detect trends in customer data. The architecture team must integrate the ML models with a reporting platform so the augmented data can be analyzed and used directly in business intelligence dashboards. Which solution meets these requirements with the LEAST operational overhead?
- An ecommerce company wants to collect user clickstream data from its website for real-time analysis. The website has fluctuating traffic throughout the day. The company needs a scalable solution that adapts to varying traffic levels. Which solution meets these requirements?
- An ecommerce company will deploy a web application on AWS: EC2 for the web app, Amazon RDS for the relational database, and Amazon S3 for static assets. The company wants a robust, resilient architecture. Which solution meets these requirements?
- An ecommerce company will launch a one-deal-a-day website on AWS. Each day one product is on sale for 24 hours. The site must handle millions of requests per hour with millisecond latency during peaks and require the LEAST operational overhead. Which solution meets these requirements?
- An ecommerce company’s Amazon RDS web application performance degrades due to an increase in read-only SQL queries from business analysts. A solutions architect needs to resolve the issue with minimal changes to the web application. What should the solutions architect recommend?
- An ecommerce company’s two-tier web application on Amazon EC2 is seeing increased traffic and delays in sending marketing and order confirmation email. The company wants to reduce time spent troubleshooting email delivery and minimize operational overhead. What should a solutions architect do?
- An ecommerce website runs on Amazon EC2 instances behind an Application Load Balancer (ALB) in an Auto Scaling group. The site is experiencing high request rates from illegitimate external systems whose IP addresses change frequently. The security team is concerned about potential DDoS attacks. The company must block these illegitimate requests with minimal impact to legitimate users. What should a solutions architect recommend?
- An entertainment company uses Amazon DynamoDB to store media metadata. The application is read-intensive and experiencing latency. The company lacks staff for extra operational overhead and needs to improve DynamoDB performance without reconfiguring the application. What should a solutions architect recommend?
- An external vendor needs access to the company’s AWS account to run an automated tool hosted in the vendor’s own AWS account. The vendor currently has no IAM access to the company’s account. Which solution will provide the MOST secure way to grant the vendor access?
- An external vendor will run an automated tool from the vendor’s own AWS account to perform work in the company’s AWS account. The vendor does not have IAM access to the company’s account. How should a solutions architect grant the vendor access?
- An IAM user made several configuration changes to AWS resources during a production deployment last week. A solutions architect discovered that a couple of security group rules are misconfigured and wants to confirm which IAM user made those changes. Which service should the solutions architect use to find this information?
- An image hosting company uploads large assets to Amazon S3 Standard. The company uses parallel multipart upload and overwrites if the same object is uploaded again. For the first 30 days, objects are accessed frequently. After 30 days, objects are accessed less often and access patterns are inconsistent. The company must optimize S3 storage costs while maintaining high availability and resiliency. Which combination of actions should a solutions architect recommend? (Choose two.)
- An image-hosting company stores objects in Amazon S3 buckets and wants to prevent accidental public exposure. All S3 objects in the account must remain private. Which solution meets these requirements?
- An image-processing company has a web application that uploads images to an Amazon S3 bucket. S3 event notifications publish object-creation events to an Amazon Simple Queue Service (Amazon SQS) standard queue. The SQS queue is the event source for an AWS Lambda function that processes images and emails results to users. Users report receiving multiple emails for each uploaded image. A solutions architect finds that SQS messages are invoking the Lambda function more than once, causing duplicate emails. What should the solutions architect do to resolve this issue with the LEAST operational overhead?
- An international company uses subdomains for each country (example.com, country1.example.com, country2.example.com). Workloads are behind an Application Load Balancer. The company wants to encrypt in-transit website traffic. Which combination of steps will meet these requirements? (Choose two.)
- An IoT company’s mattress sensors upload ~2 MB of data per mattress per night to an Amazon S3 bucket. Each mattress’s data must be processed and summarized as soon as possible. Processing requires 1 GB of memory and finishes within 30 seconds. Which solution meets these requirements most cost-effectively?
- An on-premises application generates large amounts of time-sensitive data that are backed up to Amazon S3. As the application has grown, users report internet bandwidth constraints. Design a long-term solution that allows timely backups to Amazon S3 with minimal impact on internet connectivity for internal users. Which solution meets these requirements?
- An on‑premises MySQL database used by the global sales team has infrequent access and requires minimal downtime. The database administrator wants to migrate it to AWS without choosing a specific instance type because the user base may grow. Which service should a solutions architect recommend?
- An online gaming application uses TCP and UDP multiplayer features. Route 53 points traffic to Network Load Balancers (NLBs) in multiple AWS Regions. The company needs to improve performance and reduce latency for expected user growth. Which solution meets these requirements?
- An online gaming company hosts its platform on Amazon EC2 instances behind Network Load Balancers (NLBs) across multiple AWS Regions. The NLBs can route requests to targets over the internet. The company wants to reduce end-to-end load time for its global players. Which solution meets this requirement?
- An online gaming company is migrating user data to Amazon DynamoDB to support growth. Current tables store user profiles, achievements, and in-game transactions. The company needs a resilient, highly available DynamoDB architecture to ensure a seamless gaming experience. Which solution meets these requirements MOST cost-effectively?
- An online learning company is migrating to the AWS Cloud. The company stores student records in a PostgreSQL database and requires the data to be available and online across multiple AWS Regions at all times. Which solution meets these requirements with the LEAST operational overhead?
- An online photo-sharing company stores photos in an Amazon S3 bucket in us-west-1. The company must store a copy of every new photo in us-east-1 with the LEAST operational effort. Which solution meets this requirement?
- An online retail company with more than 50 million active customers stores purchase data in Amazon S3 and additional customer data in Amazon RDS. The company wants to make all data available for analytics to various teams, with fine-grained access controls and minimal operational overhead. Which solution meets these requirements?
- An online video game company must maintain ultra-low latency for its game servers. The game servers run on Amazon EC2 instances. The company needs a solution that can handle millions of UDP internet traffic requests each second. Which solution will meet these requirements MOST cost-effectively?
- Developers need secure SSH access to Amazon EC2 instances running the latest Amazon Linux. Developers work remotely and from the corporate office. The EC2 instances are in a VPC private subnet and use a NAT gateway in a public subnet for internet access. The company prefers to use AWS services and minimize cost. What should a solutions architect do MOST cost-effectively?
- During an internal audit, a company wants to ensure that data in an Amazon S3 bucket used by the company’s AWS Lake Formation data lake contains no sensitive customer or employee data. The company needs to discover personally identifiable information (PII) and financial data such as passport and credit card numbers. Which solution meets these requirements?
- During migration testing, an application on Amazon EC2 On-Demand Instances takes a long time to launch and load memory before it is fully productive. Which solution will reduce the application launch time in the next testing phase?
- Management wants a report of AWS billed items listed by user for department budget planning. What is the most efficient way to obtain this report?
- Marketing data from multiple sources is uploaded to an Amazon S3 bucket. Data preparation jobs must run at regular intervals in parallel, with a few jobs that must run in a specific order later. The company wants to eliminate operational overhead for job error handling, retries, and state management. Which solution meets these requirements?
- On-premises devices generate .csv files and can write to an SMB file share. The company wants to analyze the data in AWS using SQL queries; analysts will run queries periodically throughout the day. Which combination of steps will meet these requirements most cost-effectively? (Choose three.)
- Organizers for a global event will publish daily reports as static HTML pages stored in an Amazon S3 bucket. The pages are expected to generate millions of views worldwide. Which action should a solutions architect take to deliver this content efficiently and effectively?
- The company is experiencing sudden demand increases and must provision large Amazon EC2 instances from an AMI in an Auto Scaling group. The solution must provide minimum initialization latency to meet demand. Which solution meets these requirements?
- The company wants to detect when the Amazon EC2 CreateImage API operation is called in its account and send an alert. The company currently copies AMIs only within the Region where they were created. Which solution meets this requirement with the LEAST operational overhead?
- The following IAM policy is attached to an IAM group. This is the only policy applied to the group. What are the effective IAM permissions of this policy for group members?
- To meet security requirements, a company needs to encrypt all application data in transit when communicating with an Amazon RDS MySQL DB instance. A recent audit showed encryption at rest is enabled with AWS KMS, but data in transit is not. What should a solutions architect do to satisfy the security requirements?
- Users upload small files into Amazon S3. After upload each file requires a one-time simple transformation into JSON for later analysis. Each file must be processed as quickly as possible after upload. Demand varies widely from high to low or none. Which solution meets these requirements with the LEAST operational overhead?
- Using an AWS CloudFormation template, a solutions architect deploys a three-tier web application. The web and application tiers run on EC2 instances, and the database tier is not publicly accessible. The application instances need to access Amazon DynamoDB without exposing API credentials in the template. What should the architect do?
- What should a solutions architect do to ensure that all objects uploaded to an Amazon S3 bucket are encrypted?
- You are designing a VPC with two public subnets for a load balancer, two private subnets for web servers, and two private subnets for MySQL. The web servers serve only HTTPS. A security group for the load balancer already allows port 443 from 0.0.0.0/0. Company policy requires least privilege for each resource. Which additional configuration should you apply to meet this requirement?
amazon campaign planning ENG version All exam questions
- Ada eze is an advertiser at an athletic wear company promoting a new women's running shoe.She used audience insights to determine that shoppers most likely to engage with herbrand were married women,so she tailored her creative to best reach this audience.Which audience insight did she use to learn this?
- Ali fy has worked with Amazon to create a campaign that uses an Easter egg for unique shopping queries.For which of the following goals is this strategy LEAST likely to be effective?
- Amelie is setting up a link-out campaign for her client,a brand that sells home goods.The campaign'sad mentions a 25%off coupon for new customers.What should Amelie consider in order to promote a positive customer experience?
- Brighton wants to understand the time between repeat purchases of his brand's products so he can find the ideal time tore engage shoppers and drive loyalty. Which audience insight would help Brighton achieve this goal?
- Chu kw udi wants to understand when his brand's customers are most likely to buy so that he can do a homepage takeover on a day that shoppers are most likely to purchase his products.Which audience insight would help him find this information?
- Dar ci is reviewing an overlap for herbrand and notes that one of the overlapping audiences has a size of 4.What does this indicate?
- Franco has pulled an overlap report to learn more about his brand'saudiences. He sees an affinity score of 2.What does this indicate?
- Green Telecommunications is about to launch a campaign with a creative that states"We have the fastest LG network."Why might this ad lead to a poor customer experience?
- Healthy Byte wants to engage"healthy lifestyle"customers.They've determined that there are three core audiences that are likely to respond differently to different creatives.Which ad solution should Healthy Byte consider using to effectively reach all three audiences?
- Jaque line used the audience planning tool to uncover an opportunity to engage shoppers that have shown purchase intent in her products but did not purchase. Which of the following approaches would you suggest to Jaque line?
- Juan Carlos is an advertiser of luxury perfumes.Juan Carlos would like to understand what audiences are the most similar ones to their existing customers that they could potentially reach through their advertising.He should use...
- Juan is looking to drive product discover ability for a new product during key research moments in the customer journey.Which of the following solutions best fits this use case?
- Meg is an advertiser at a consumer electronics company.She has run advertising campaigns on Amazon in the past,and after mixed results,wants to reconsider her approach.What should she first do before crafting an advertising strategy?
- Nino is an advertiser for an apparel company that sells both men'sandwomen's clothing.How might Nino best use audience insights to see how his brand performs in each category?
- OceanWorld,a swimwear brand,considers summer to be their peak season. What is the recommended approach for them to help customers discover, consider,and purchase their products during and outside of peak season?
- Out-of-home(OOH)executions maybe best suited for which type of goal?
- Ru fina referenced insights for similar brands and determined that,inherbrand's category,herbrand was below the category benchmark for time between purchases.What type of campaign strategy could Ru fina run to help herbrand reach the benchmark?
- Select all that apply:Amazon Brand Analytics can…
- Shunsuke is an advertiser at a kitchen appliance company.Her an an awareness campaign to promote his brand's award winning toaster.A few months after the campaign ended,he noticed that the baseline performance was overall higher on glance views and conversion rate across many of his products.What is this likely tomean?
- To by is adding video to his client's campaign plan because he recognizes that video is most effective in meeting which goal?
- What is one benefit of launching an out-of-home(OOH)campaign with Amazon?
- What stages of the shopping journey does the audience planning tool consider? Select all that apply.
- Wheelhouse,an advertising agency,want store engage shoppers who viewed one of their client's product pages but did not purchase.Which solution is best to re engage these shoppers?
- When should an advertiser consider leveraging below the fold(BTF)placements?
- Which Amazon custom advertising solution is described as"outofhome placements that are brought into homes"?
- Which custom solution allows advertisers access to premium placement on Amazon'shomepage?
- Which of the following is a benefit to combining display ads with sponsored ads?
- Which of the following is generally used to drive short-termsales?
- Which of the following options is the most useful strategy in reaching customers to achieve short-termgoals?
- Which of the following statements about the audience planning tool is INCORRECT.
- Which of the following strategies has been shown to increase reach of high-intent shoppers by 10 times?
- Which retail metric highlight show frequently an advertiser's products show up in organic widget s such as recommendations or"frequently bought together with"?
- Why is it important for an advertiser to consider the length of time between shoppers'discovery and final purchase?
- YY Finance does not sell product or services on Amazon but is interested in leveraging Amazon Advertising solutions.Which campaign type is NOT available to YY Finance?
Amazon Data Engineer Associate DEA-C01 Certification All exam questions
- A bank collects high-volume transactional data and streams it into Amazon Kinesis Data Streams using PutRecord. Network outages occur at certain times, and the data engineer needs exactly-once delivery semantics across the processing pipeline. Which approach will achieve that?
- A car sales company receives daily uploads from vendors as compressed files (up to 5 KB each) to Amazon S3 containing new listings. The company wants near-real-time visibility of new listings, an automated processing workflow to feed a dashboard, and the ability to run one-off queries and analytics at scale, all in the most cost-effective way. Which solution is the best fit?
- A company aggregates data from multiple AWS and third-party stores into a central data warehouse for analytics. Analysts require fast query responses and use Amazon QuickSight in direct query mode. Queries are typically run for a few hours per day with unpredictable spikes. Which option delivers the required performance with the least operational overhead?
- A company builds near real-time dashboards for time series data ingested into Amazon MSK. A custom pipeline consumes the stream and writes to Amazon Keyspaces, Amazon OpenSearch Service, and Avro objects in S3. Which option will make data available to the dashboards with the LEAST latency?
- A company collects log data in real time using Amazon Kinesis Data Streams and wants to run real-time queries and enrich the logs in Amazon Redshift. Which ingestion method provides the least operational overhead to get data into Redshift?
- A company currently keeps all of its data in S3 Standard. Access patterns show frequent access several times per day for the first 6 months, then once or twice per month between 6 months and 2 years, and only once or twice per year after 2 years. The data engineer must create an S3 Lifecycle policy that preserves high availability while minimizing cost. Which policy is the MOST cost-effective?
- A company currently runs Apache Airflow on-premises to orchestrate data pipelines that include SQL data quality checks. They want to migrate to AWS using managed services and minimize refactoring. Which solution accomplishes this with the least amount of code change?
- A company currently uses Athena CTAS SQL to perform ETL tasks but must switch to Apache Spark for analytics. Which feature will allow the company to use Spark to access Athena?
- A company enforces strict S3 access policies using IAM roles for internal teams. The company needs to be notified when a user violates the data access policy, and each alert must include the username of the violator. Which solution satisfies these requirements?
- A company extracts about 1 TB of data per day from sources such as SAP HANA, SQL Server, MongoDB, Kafka, and DynamoDB. Some sources have undefined or evolving schemas. The solution must detect schemas, perform ETL, and load the data into S3 within 15 minutes of data creation. Which approach provides the required functionality with the least operational overhead?
- A company gathers data from many sources into an S3 bucket, runs an AWS Glue ETL job to transform it, and stores the transformed output in an S3-based data lake queried by Amazon Athena. The company needs to identify matching records even when there is no shared unique identifier. Which solution will accomplish this?
- A company has 10–15 TB of uncompressed .csv files in Amazon S3 and plans to run a one-time evaluation using Amazon Athena. The company wants to transform the data to reduce query times and lower storage costs. Which file format and compression choice best satisfies these requirements for Athena queries?
- A company has an Amazon Redshift table named Orders that has been used for 6 months with weekly updates and deletes. The table uses an interleaved sort key on a column containing AWS Regions. The company wants to reclaim disk space to avoid running out of storage and also analyze the sort key column. Which Redshift VACUUM command accomplishes both goals?
- A company has an Amazon Redshift table named Sales that includes the column city_name. The company needs to select rows where city_name begins with "San" or "El". Which SQL statement accomplishes this?
- A company has an on-premises Oracle data warehouse and is building a data lake on Amazon S3. They need to load warehouse tables into S3 and keep them synchronized with daily incremental data. Each table has a monotonically increasing column, sizes under 50 GB, nightly refresh between 1 AM and 2 AM, and BI queries run from 10 AM to 8 PM. Which approach is the most operationally efficient?
- A company has five offices in different AWS Regions. Each office's HR team uses a distinct IAM role. Employee records are stored in an Amazon S3–based data lake. The data engineering team must restrict each HR department so it can access only records for employees in that department's Region. Which combination of actions provides this with the least operational overhead? (Choose two.)
- A company has three subsidiaries using different warehousing engines (Amazon Redshift, Teradata Vantage on AWS, and Google BigQuery). They want to consolidate data into an S3 data lake using Apache Iceberg. The new pipeline must connect to each source, run transformations using each source engine, join the results, and write to Iceberg with minimal operational effort. Which approach meets these requirements with the least operational overhead?
- A company has two systems on Amazon Kinesis Data Streams: an inventory management system that uses the Kinesis Producer Library (KPL) to publish, and an inventory reordering system that uses the Kinesis Client Library (KCL) to consume. The stream autoscaling is enabled. Before production deployment, the reordering system received duplicate records. Which factors could have caused the duplicates? (Choose two.)
- A company is building a data lake on Amazon S3 and must enforce row-level and column-level access controls for teams that will query via Amazon Athena, Redshift Spectrum, and Apache Hive on EMR. Which approach minimizes operational overhead?
- A company is building an analytics platform with Amazon S3 as the data lake and Amazon Redshift as the data warehouse. The firm intends to use Amazon Redshift Spectrum to query S3 data. Which actions will PRODUCE THE FASTEST query performance? (Select two.)
- A company is loading hundreds of files into a fact table in an Amazon Redshift cluster and wants the highest possible load throughput while using cluster resources efficiently. Which loading strategy will best meet these goals?
- A company is migrating a legacy application to an S3-based data lake. The legacy data contains duplicate records. The data engineer must identify and remove duplicates with the LEAST operational overhead. Which solution should the engineer choose?
- A company is migrating data from on-premises to AWS using an AWS Transfer Family server. Company policy requires using TLS 1.2 or later to encrypt data in transit. Which action satisfies this requirement?
- A company is migrating on-premises Hadoop clusters to Amazon EMR and needs to move an existing Apache Hive metastore into a persistent, serverless solution for the data catalog. Which approach is the most cost-effective and meets the serverless requirement?
- A company is migrating SQL Server databases from EC2 to Amazon RDS for SQL Server. Until migration completes, the analytics team must export large, joined data elements daily in Apache Parquet format to Amazon S3. Which solution is the MOST operationally efficient?
- A company is moving petabyte-scale on-premises workloads that use Apache Pig, Oozie, Spark, HBase, and Flink to AWS and wants lower operational overhead and serverless options while keeping equal or better performance. Which ETL service should they choose?
- A company keeps CSV files in Amazon S3. A data engineer must transform the CSVs and write the results to a new S3 bucket. The required transformations are: rename one column, drop specific columns, skip the second row of each file, create a new column derived from values in the first row, and filter rows by a numeric column. Which option meets these requirements with the least development effort?
- A company keeps customer data in an Amazon S3 bucket that multiple teams need to analyze, but the teams must not see any personally identifiable information (PII). Which option provides PII detection and redaction with the least operational overhead?
- A company loads daily transaction data into Amazon Redshift and wants to track which tables have completed loading. A data engineer will record load statuses in DynamoDB via a Lambda function. What is the best way to invoke the Lambda to write the statuses?
- A company maintains a data lake on AWS that ingests datasets from various business units. The storage is in Amazon S3, and the AWS Glue Data Catalog stores metadata. Analysts use Amazon Athena to run queries. The company needs to enforce fine-grained, column-level access controls for Athena based on user roles. Which approach satisfies this requirement?
- A company maintains petabytes of data across thousands of S3 buckets in the S3 Standard class. Access patterns are variable and sometimes months pass without access, but all data must remain retrievable in milliseconds. The company wants to lower storage costs with minimal operational overhead. Which option meets these constraints?
- A company migrates monthly from an on-premises Microsoft SQL Server to Amazon RDS for SQL Server. Migration costs have risen and the company wants a cost-effective approach with minimal application downtime. Which AWS service should they use?
- A company must apply two layers of server-side encryption to objects uploaded to an S3 bucket and wants to use a Lambda function to apply the encryption. Which approach meets this requirement?
- A company must manage costs and control the size of an existing Amazon DynamoDB table without interrupting ongoing reads or writes. They want data to be automatically removed after 1 month with minimal maintenance. Which approach meets these requirements?
- A company must retain customer records in Amazon S3 for 7 years after each record is created and must prevent any deletions or modifications, even by the root user. Using S3 Object Lock, which solution satisfies these requirements?
- A company needs a centralized data catalog and metadata management for cloud-based data sources (structured sources such as Amazon RDS and Redshift, and semistructured files in S3). The catalog must be refreshed regularly and detect metadata changes with minimal operational overhead. Which solution meets these requirements?
- A company operates a provisioned Amazon Redshift cluster used for ETL that supports critical analytics. A separate Redshift cluster is used by the sales team for BI. The sales team needs to access ETL cluster data weekly and join it with their BI cluster data without disrupting the ETL workloads and while minimizing compute usage on the ETL cluster. Which solution meets these requirements?
- A company operates AWS resources across multiple Regions and has an Amazon EFS file system in each Region. The data science team works only in one Region and their data must remain in that Region. A data engineer must create a consolidated dataset by processing files stored on each Regional EFS using a Step Functions state machine that orchestrates Lambda functions. Which option achieves this with the least effort?
- A company partitions its Amazon S3 data lake using object key paths like s3://bucket/prefix/year=2023/month=01/day=01. The AWS Glue Data Catalog must stay synchronized with S3 when new partitions are added. Which approach provides the lowest latency for keeping the catalog up to date?
- A company performs quarterly analyses of data in a data lake to run inventory checks. A data engineer uses AWS Glue DataBrew to find any personally identifiable information (PII) about customers in the data. The company's privacy rules include some custom PII categories that are not part of DataBrew's built-in data quality rules. The engineer must update the process to scan for these custom PII categories across many datasets in the data lake. Which approach meets the requirement with the least operational overhead?
- A company plans to migrate a data warehouse from Teradata to Amazon Redshift. Which option requires the least operational effort to perform the migration?
- A company plans to run Apache Spark jobs on a provisioned Amazon EMR cluster for big data analysis and requires high reliability. The big data team wants cost-optimized, long-running workloads while preserving current performance. Which combination of choices is the MOST cost-effective? (Choose two.)
- A company plans to upgrade Amazon EBS volumes from gp2 to gp3 and wants to avoid any downtime or data loss on the EC2 instances during the migration. Which approach accomplishes this with the LEAST operational overhead?
- A company provisions a log delivery stream inside a VPC and sends VPC flow logs to CloudWatch Logs. They need to forward the flow logs to Splunk in near real time for analysis with minimal operational overhead. Which solution meets this requirement?
- A company reads data from multiple Amazon RDS customer databases where field names and formats are inconsistent (for example, place_id in one database and location_id in another). The business must link customer records across databases even when field names differ. Which solution provides this capability with the LEAST operational overhead?
- A company receives 2 GB of sales transaction records daily in a MySQL database and has 100 GB of sales opportunities stored in Salesforce. The company wants a nightly process to correlate the two datasets with minimal operational overhead. Which solution meets this requirement?
- A company receives a daily ~2 GB .xls file in S3 with customer data. A data engineer concatenates the first-name and last-name columns and needs to count the number of distinct customers in the file. Which approach requires the least operational effort?
- A company receives CSV files with address fields Door_No, Street_Name, City, and Zip_Code. The company wants to combine those fields into a single column in a specific structured format with the least coding effort. Which approach meets this requirement?
- A company runs a data warehouse on Amazon Redshift and must record and retain all user and connection activity to satisfy security requirements. Which solution meets this need?
- A company runs a microservices application on Amazon EKS and needs robust monitoring to analyze logs and correlate cluster logs with application traces to find failure points across the request flow. Which combination of actions achieves this with the least development effort? (Choose two.)
- A company runs a provisioned Amazon EMR cluster using general-purpose Amazon EC2 instances. EMR managed scaling is configured to vary the task node count from one to five for a daily, long-running Apache Spark ETL job. Each run quickly scales the cluster to five task nodes; CPU utilization often hits its limit while memory stays below 30%. The company wants to change the EMR configuration to lower the cost of running the daily ETL job. Which option will most cost-effectively meet this requirement?
- A company runs an Amazon Redshift cluster on RA3 nodes and needs to scale read and write capacity to meet demand. Which action will enable concurrency scaling?
- A company runs an application on Amazon EC2 instances that currently generates temporary data. The company now needs the application data to persist even if the EC2 instances are terminated. A data engineer must launch new EC2 instances from an AMI and configure them to preserve the data. Which approach satisfies this requirement?
- A company runs applications on Amazon EC2 and needs to use SSL/TLS to encrypt traffic to AWS-managed infrastructure operated by a customer. The engineering team wants to simplify certificate creation, distribution, rotation, and automatic renewal and deployment. Which solution provides this with the least operational overhead?
- A company runs multiple AWS Glue ETL jobs that read S3 data using a DynamicFrame and load transformed data into Amazon RDS for MySQL once per day. Currently the jobs reprocess all objects in the S3 bucket, but the company wants the jobs to operate only on the daily incremental data. Which solution requires the LEAST amount of code changes?
- A company runs multiple ETL workflows that pull data from operational databases into an S3 data lake. These workflows use AWS Glue and Amazon EMR. The company wants to add automated orchestration while minimizing manual effort and operational overhead. Which solution meets these goals with the LEAST operational overhead?
- A company saves customer data in an S3 bucket encrypted with SSE-KMS. The data includes PII (for example, social security numbers). Any data tagged as PII must be masked before it is used for analytics. A subset of users must have secure access to the raw PII during pre-processing. The company wants a low-maintenance approach to mask and protect PII throughout the engineering pipeline. Which combination of solutions meets these requirements? (Choose two.)
- A company stores call logs in S3 that include sensitive customer information. The objects must be encrypted using keys that only certain employees can access. Which solution provides the required protection with the least effort?
- A company stores CloudTrail logs in an S3 data lake, catalogs them in AWS Glue, and partitions them by year. An Athena query on one of the tables recently returned no rows. Which troubleshooting steps should the data engineer take? (Choose two.)
- A company stores customer address tables in an AWS Lake Formation data lake. New regulations prohibit users from accessing rows for customers who are in Canada. Which approach prevents users from seeing rows where country = Canada with the LEAST administrative effort?
- A company stores daily portfolio performance records as .csv files in Amazon S3 and uses AWS Glue crawlers to catalog the data. The data must be available in the AWS Glue Data Catalog every day. Which configuration meets this requirement?
- A company stores data in an S3 bucket in an account named Hub-Account. The bucket is encrypted using a KMS key. A QuickSight instance in another account (BI-Account) must access that bucket. The S3 bucket policy was updated to grant the QuickSight service role access. What steps should be taken to enable cross-account QuickSight access to the encrypted S3 bucket? (Choose two.)
- A company stores datasets in S3 that include PII for ecommerce. An internal analytics app does not need PII and the company must avoid unnecessary sharing of PII. The data engineer must implement dynamic, per-application redaction with minimal operational overhead. Which solution should the engineer choose?
- A company stores JSON and CSV datasets in S3 and also has Amazon RDS for SQL Server, provisioned-capacity DynamoDB tables, and an Amazon Redshift cluster. Data scientists need to query all these sources using SQL-like syntax with minimal operational overhead. Which solution meets this requirement?
- A company stores large volumes of customer records in Amazon S3. Regulations require that new records be immediately accessible for the first 30 days; records older than 30 days are rarely accessed. How can the company minimize S3 storage costs while meeting this access requirement?
- A company stores log files in an S3 bucket and has discovered some files were accidentally deleted. The data engineer needs a solution that prevents accidental deletions going forward while imposing the least operational overhead. What should they do?
- A company stores millions of 1 KB JSON test-result files in S3 from global testing facilities. A data engineer must convert those files to Apache Parquet and load them into Amazon Redshift. The current pipeline uses AWS Glue for processing, Step Functions for orchestration, and EventBridge for scheduling. As more facilities are added, processing time has increased. Which change will most reduce the processing time?
- A company stores semi-structured transactional data in S3. Some files are tiny while others are tens of terabytes. The source sends a full JSON snapshot once per day and also sends changed records into the data lake. A data engineer must perform change data capture (CDC) to identify changes most cost-effectively. Which solution is the MOST cost-efficient?
- A company stores server logs in an Amazon S3 bucket and must retain them for exactly one year, after which they can be deleted. What is the simplest way to automatically remove logs older than one year with the least operational overhead?
- A company stores third-party provider data as objects in Amazon S3 and ran an AWS Glue crawler to populate the data catalog. The crawler produced multiple tables, but the company expected only a single table. Which combination of changes will ensure the AWS Glue crawler creates only one table? (Choose two.)
- A company stores transactional data in Amazon RDS inside a private subnet. A developer created an AWS Lambda function with default settings to perform inserts, updates, and deletes on the DB instance. The Lambda must connect privately to the DB instance without using the public internet. Which combination of steps will achieve this with the LEAST operational overhead? (Choose two.)
- A company transfers files from on-premises to an S3 bucket using an S3 File Gateway. A data engineer needs an automated process that launches an AWS Glue workflow to run multiple Glue jobs whenever a file transfer completes successfully. Which option provides that behavior with the least operational overhead?
- A company uploads CSV files to an Amazon S3 bucket. An AWS Glue crawler builds tables and schemas for the data, and an AWS Glue job processes the tables and writes the results into an Amazon Redshift database. The Glue job handles column mapping and creates the Redshift tables as needed. Re-running the Glue job causes duplicate rows to appear in the Redshift tables. The company needs a way to update the Redshift tables without introducing duplicates. Which approach satisfies this requirement?
- A company uploads data to an S3 bucket daily and uses the AWS Glue Data Catalog. Some days a daily report runs before all data arrives. The data engineer must send a message identifying any incomplete data to an existing Amazon SNS topic with minimal operational overhead. Which solution meets this need?
- A company uses a data mesh with a central governance account and AWS Lake Formation for cataloging and sharing. A new data product contains Amazon Redshift Serverless tables. The marketing team must receive access to only a subset of columns, and the compliance team must receive a different subset. Which combination of steps should a data engineer take to achieve this? (Choose two.)
- A company uses Amazon Athena for ad-hoc queries against S3 data and needs to separate query execution and history access between users, teams, and applications in the same AWS account. Which solution enforces those permission boundaries?
- A company uses Amazon DataZone for data governance and a business catalog. Their data resides in an Amazon S3 data lake and they use AWS Glue with the AWS Glue Data Catalog. A data engineer must make AWS Glue Data Quality scores available in the Amazon DataZone portal. Which approach satisfies this requirement?
- A company uses Amazon Redshift and finds that some columns have suboptimal compression encodings. The data engineer must improve the encoding choices for those tables. What is the appropriate action?
- A company uses Amazon Redshift and needs to automate refresh schedules for materialized views. Which solution will accomplish this with the least effort?
- A company uses Amazon Redshift for its data warehouse. While designing a physical schema, a data engineer finds a denormalized table that keeps growing but has no good candidate for a distribution key. Which distribution style should the engineer choose to minimize ongoing maintenance?
- A company uses Amazon S3 as a data lake and a multi-node Amazon Redshift cluster as a data warehouse. Data files in the lake are organized by their source, and the company currently issues a separate COPY command for each file location to load into a single Redshift table, which is slow. The company needs to speed up ingestion without increasing costs. What should they do?
- A company uses an Amazon QuickSight dashboard fed by AWS Glue jobs that process data stored in a single S3 bucket. New data is added daily, and dashboard queries are slowing because the AWS Glue jobs are running longer. Which actions should the data engineer take to speed up the AWS Glue jobs? (Choose two.)
- A company uses an AWS Lambda function that runs in a VPC to transfer files from a legacy SFTP server to Amazon S3. The Lambda function can connect to the SFTP server but times out when uploading to S3. The engineer must fix the timeouts securely and at minimum cost. Which solution meets these constraints?
- A company uses AWS DMS to continuously capture changes from an on-premises PostgreSQL database and replicate them to Amazon Redshift. The DMS ongoing replication task reads PostgreSQL transaction logs, but the data engineer observes high latency in CDC and suspects the PostgreSQL source is the bottleneck. Which approach will verify that the PostgreSQL database is the source of the latency?
- A company uses AWS Step Functions to orchestrate a data pipeline that runs Amazon EMR jobs to ingest data into Amazon S3 and to load data into Amazon Redshift. The Step Functions state machine was created manually. An EMR cluster was launched in a VPC, but the deployed state machine cannot run the EMR jobs. Which combination of steps should the company take to determine why the state machine cannot run the EMR jobs? (Choose two.)
- A company using a lake house architecture in Amazon Redshift wants users to sign in to the Redshift query editor with a third-party identity provider (IdP). As a data engineer, what is the first step to configure this authentication method?
- A company wants near-real-time analytics using Amazon Kinesis Data Streams and Amazon Redshift, ingesting several gigabytes per second, and leveraging existing BI tools. Which option minimizes operational overhead while making streaming data available for immediate analysis?
- A company wants to log every write to an S3 bucket into another S3 bucket in the same Region. Which option requires the least operational effort?
- A company wants to migrate an application and an on-premises Apache Kafka cluster to AWS using a replatform approach (not refactor). The application processes incremental updates from an on-premises Oracle database that are published to Kafka. Which managed solution provides the least operational overhead?
- A company wants to run ML analytics on data in an S3 data lake. They have two transformation needs: (1) perform scheduled daily transformations on 300 GB of various-format data that arrives at a set time, and (2) run a one-time transformation on terabytes of archived data in the lake. Amazon MWAA DAGs will orchestrate the workflows. Which two tasks should the DAGs schedule to meet these needs most cost-effectively? (Choose two.)
- A company will migrate data from an Amazon RDS for PostgreSQL DB instance in the eu-east-1 Region of Account_A to an Amazon Redshift cluster in the eu-west-1 Region of Account_B. To allow AWS Database Migration Service (AWS DMS) to replicate between those two data stores, what should the company do?
- A company will use Amazon Kinesis Data Firehose to deliver data to Amazon S3. The incoming files are 2 MB CSV files. The company must convert the CSV files to JSON and store them in Apache Parquet format in S3. Which approach requires the least development effort?
- A data engineer built an AWS Glue ETL pipeline and must crawl a table in Microsoft SQL Server, then write the crawl output to S3 and orchestrate the pipeline. What AWS feature provides this capability at the lowest cost?
- A data engineer configured an AWS Glue crawler to catalog data in an S3 bucket that contains both .csv and .json files. The crawler was set to exclude the .json files, but when running Athena queries the .json files are still being processed. The engineer must fix this without changing access to the .csv files and wants the shortest possible query times. What is the best solution?
- A data engineer configured an AWS Glue job to read data from an S3 bucket and supplied the required Glue connection and IAM role. When trying to run the job, an error reports issues with the Amazon S3 VPC gateway endpoint. What action will resolve the issue so the AWS Glue job can access the S3 bucket?
- A data engineer configures Amazon SageMaker Studio to use AWS Glue interactive sessions for data preparation but receives an AccessDenied error when attempting to prepare data. What change should the engineer make to obtain access to SageMaker Studio?
- A data engineer created the cloudtrail_logs table in Amazon Athena to query CloudTrail events for audits. The engineer needs a query that returns errors with error codes since 2024-01-01 and shows the top 10 by occurrence. Which of the following queries meets that requirement?
- A data engineer has a one-time need to read Apache Parquet objects in an S3 bucket and extract only a single column. Which option achieves this with minimal operational overhead?
- A data engineer ingests daily user behavior records with Amazon Kinesis Data Streams. The stream is being throttled because some shards (hot shards) receive much more traffic than others. How should the engineer stop the throttling?
- A data engineer is building a QuickSight dashboard to show company revenue across multiple AWS Regions. The visual should always display the total revenue for a Region regardless of the current drill-down level. Which QuickSight calculation accomplishes this?
- A data engineer is building an automated AWS Glue ETL pipeline that ingests compressed files from an Amazon S3 bucket and must support incremental processing. Which AWS Glue feature enables incremental ingestion?
- A data engineer is building an hourly AWS Glue ETL pipeline that reads from Amazon RDS and MongoDB, transforms data, and loads it into Amazon Redshift. Which combination of actions will achieve this with the LEAST operational overhead? (Choose two.)
- A data engineer is designing a hybrid data orchestration workflow that uses both on-premises and cloud resources and wants to prioritize portability and open-source tools. Which service should be used in both environments?
- A data engineer is designing an AWS Step Functions workflow that must process a large collection of files in parallel and apply the same transformation to each file. Which Step Functions state is appropriate for this requirement?
- A data engineer is loading third-party customer data into Amazon Redshift. One source field contains JSON-formatted values. To load the JSON into the data warehouse with the least effort, what should the engineer do?
- A data engineer is starting an Amazon EMR cluster. The dataset to load into the cluster resides in an Amazon S3 bucket and is encrypted with an AWS KMS key. An S3 path contains a PEM file for in-transit encryption. Which approach satisfies the requirement that data be encrypted both at rest and in transit?
- A data engineer manages a materialized view in Amazon Redshift that includes a load_date column indicating when each row was inserted. The engineer must remove all rows from the materialized view to free up the most database storage. Which command reclaims the MOST storage?
- A data engineer manages custom Python scripts used by multiple AWS Lambda functions to format data. Currently, when the scripts change, the engineer must update every Lambda function manually. Which approach reduces the manual effort to update the functions?
- A data engineer must clean and prepare several terabytes of raw data that reside in Amazon S3, then load the processed data into Amazon Redshift for analytics. Data analysts require the ability to run complex queries. The solution should remove the need for complex ETL pipelines and avoid managing infrastructure. Which approach provides the required functionality with the LEAST operational overhead?
- A data engineer must create a Lambda function that converts uploaded .csv files in S3 to Parquet and must trigger only when a user uploads a .csv file. Which solution provides this behavior with the least operational overhead?
- A data engineer must create an Amazon Athena table cities_usa that contains only US cities from the existing cities_world table. Which SQL statement should be used?
- A data engineer must create an enterprise data catalog covering S3 buckets and RDS databases, and the catalog must include storage format metadata. Which solution requires the least effort?
- A data engineer must improve SQL query performance on an Amazon Redshift cluster but cannot increase cluster size. Data is distributed with the EVEN distribution style. Some tables are hundreds of GB, others are under 10 MB. Which approach will improve performance given the constraints?
- A data engineer must ingest real-time streaming data and run time-based analytics with windows up to 30 minutes. The solution must be highly fault tolerant and require minimal operational overhead. Which option satisfies these requirements?
- A data engineer must load a dataset into an Amazon S3 data lake using AWS services. After profiling the data, the engineer discovers personally identifiable information (PII). The engineer needs to both profile the dataset and obfuscate the PII. Which approach will satisfy this requirement with the LEAST operational effort?
- A data engineer must load structured .csv files (15 columns) into an Amazon S3 data lake. Analysts run Amazon Athena queries that typically reference only one or two columns and seldom scan the entire file. Which approach is the most cost-effective?
- A data engineer must maintain a central metadata repository that is accessible from Amazon EMR and Amazon Athena queries and must import existing Apache Hive metadata into it with minimal development effort. Which solution should they use?
- A data engineer must orchestrate a pipeline that includes a single AWS Lambda function followed by one AWS Glue job and must use AWS-managed services. Which approach delivers this with the least operational overhead?
- A data engineer must orchestrate a set of ETL tasks in Python that include running Spark jobs on Amazon EMR, calling Salesforce APIs, and loading data into Amazon Redshift. The orchestration should handle retries and failures automatically. Which AWS service should the engineer use?
- A data engineer must orchestrate an Amazon EMR ETL pipeline that ingests data from multiple sources and maximize performance while minimizing cost. Which AWS orchestration service is the most cost-effective choice for this requirement?
- A data engineer must perform a one-time analysis that joins data stored in Amazon DynamoDB, Amazon RDS, Amazon Redshift, and Amazon S3. Which approach is the MOST cost-effective for joining these data sources for a single analysis job?
- A data engineer must update data quality rules across 1,000 AWS Glue Data Catalog tables due to changed business requirements. Which approach will accomplish this with the least operational overhead?
- A data engineer needs to create an empty duplicate of an existing Amazon Athena table (which has 1,000 rows) to perform data processing. Which CREATE TABLE query will produce an empty copy of the table?
- A data engineer needs to schedule a workflow that runs several AWS Glue jobs daily but does not require jobs to start or finish at a precise time. Which Glue execution-class choice is the most cost-effective for running these jobs?
- A data engineer opens an Amazon QuickSight dashboard backed by Amazon Athena queries on data in an S3 bucket and receives an insufficient-permissions error. Which issues could cause these permission errors? (Choose two.)
- A data engineer queries sales data in Amazon S3 using Amazon Athena. The query to sum sales by product for 2023 does not return results for all products. The original query is: SELECT product_name, sum(sales_amount) FROM sales_data - WHERE year = 2023 - GROUP BY product_name - How should the engineer change the Athena query to obtain the correct results?
- A data engineer runs Amazon Athena queries against data in Amazon S3 and uses the AWS Glue Data Catalog for metadata. Query planning is slow because the S3 dataset has a very large number of partitions. Which actions will reduce Athena planning time and resolve the bottleneck? (Choose two.)
- A data engineer runs pipelines on Amazon Managed Workflows for Apache Airflow (Amazon MWAA). A workflow recently failed, and the engineer needs to inspect Apache Airflow logs to determine why it failed. Which log type should the engineer examine to find the root cause of the failure?
- A data engineer runs resource-heavy analytics in Amazon Redshift once per month. Each month the engineer creates a provisioned Redshift cluster, runs the jobs, unloads backups to S3, and then deletes the cluster. The engineer wants a solution that removes the need to manage infrastructure manually and minimizes operational overhead. Which option best meets this requirement?
- A data engineer set up an AWS Glue Data Catalog for objects in S3 and needs incremental updates. S3 event notifications are sent to an SQS queue. Which combination of steps provides incremental catalog updates with the least operational overhead? (Choose two.)
- A data engineer used an AWS Glue crawler named Orders to create a Glue Data Catalog table. The engineer must add these new partitions: s3://transactions/orders/order_date=2023-01-01 and s3://transactions/orders/order_date=2023-01-02. The metadata should be updated to include the new partitions without scanning all folders and files under the table location. Which Amazon Athena DDL statement should the engineer run?
- A data engineer wants to improve Amazon Athena SQL query performance on a sales table and needs to inspect the execution plan and the cost of each operation for a specific query. Which statement should the engineer run?
- A data engineer wants to run real-time queries on Amazon Redshift data from a web-based trading application with minimal operational effort. Which option meets this requirement?
- A data lake on Amazon S3 contains records with personally identifiable information (PII). Multiple user groups need access to the raw data but must be restricted to only the PII fields they require. Which approach provides the required column-level access control with the least effort?
- A data processing pipeline with several dozen steps must emit real-time alerts when any step succeeds or fails. The pipeline uses Amazon S3, AWS Lambda, and AWS Step Functions. Which solution will monitor the pipeline and send notifications in real time?
- A developer is debugging an AWS Glue job that reads from S3 and writes to Amazon Redshift. Bookmarks are enabled and maximum concurrency is set to 1. The job writes successfully to Redshift, but subsequent runs reprocess files that were already loaded in earlier runs. What is the most likely cause?
- A factory publishes sensor data to Amazon Kinesis Data Streams and uses Kinesis Data Firehose to write the data to Amazon S3. The plant needs a near-real-time operational-efficiency display on a large screen with the lowest possible latency. Which solution provides the lowest latency?
- A finance firm uses Amazon Redshift and Redshift Spectrum to query data stored in a shared Amazon S3 bucket. The data comes from certified third-party providers, and each provider has separate connection details. Regulations require that none of the data be reachable from outside the firm's AWS environment. Which combination of actions should the company take to satisfy these requirements? (Choose two.)
- A financial company plans to build a data mesh that must include centralized governance, analytics, and access control. They will use AWS Glue for the data catalog and ETL. Which pair of AWS services should they use to implement the data mesh? (Choose two.)
- A financial firm runs Amazon Athena against a petabyte-scale dataset for a BI application. A nightly AWS Glue job refreshes the data once per day, while the BI app requires hourly refreshes for policy reasons. The goal is to reduce Athena costs without adding infrastructure and with minimal operational overhead. What is the best option?
- A fintech app added features that required a new topic in an existing Amazon MSK cluster. A few days later, CloudWatch alarmed on the cluster's RootDiskUsed metric. How should the company respond to that CloudWatch alarm?
- A gaming application stores events in Amazon DynamoDB and a data engineer must ingest that data into Amazon OpenSearch Service with near-real-time updates. Which solution meets this requirement?
- A gaming company collects clickstream events with Amazon Kinesis Data Streams and uses Kinesis Data Firehose to deliver JSON files to Amazon S3. Data scientists query the most recent data in Amazon Athena. The company wants to reduce Athena query costs without rebuilding the existing data pipeline. Which option minimizes management effort while meeting the requirement?
- A gaming company uses a NoSQL store for customer data and is migrating to AWS. They need a fully managed service that supports heavy OLTP traffic, single-digit millisecond latency, and global high availability with minimal operational overhead. Which service satisfies these requirements?
- A healthcare firm streams real-time telemetry from devices, equipment, and records into Amazon Kinesis Data Streams. The data must be stored in an Amazon Redshift Serverless warehouse and support near-real-time analytics plus queries on the previous day's data. Which solution delivers this with the least operational overhead?
- A lab's IoT sensors emit 100 KB payloads every 10 seconds. A downstream process polls an Amazon S3 bucket every 30 seconds to consume the data. Which architecture will deliver the data into S3 with the LEAST latency?
- A Lambda function is set up to read an object in an S3 bucket that is encrypted with a KMS key. The Lambda execution role includes permissions to access the S3 bucket, but the function fails to retrieve the object's contents. What is the most likely reason for the error?
- A manufacturing company collects IoT device data via Amazon Kinesis Data Streams. The payload contains device ID, capture date, measurement type, measurement value, and facility ID. The producer uses facility ID as the partition key. The operations team observed many WriteThroughputExceeded exceptions: some shards are overloaded while others are idle. How should the company resolve this hot-shard issue?
- A manufacturing firm needs to ingest sensor data in near real time, persist it in nested JSON format, and support queries with sub-10 millisecond latency. The solution should require minimal operational overhead. Which architecture meets these needs?
- A marketing firm stores clickstream data in Amazon S3 and runs daily SQL queries that JOIN S3 objects located in different buckets to produce KPIs. The company needs a serverless solution that supports partitioned querying while preserving ACID (atomicity, consistency, isolation, durability) guarantees and minimizing cost. Which option meets these requirements most cost-effectively?
- A marketing firm streams clickstream events to Kinesis Data Firehose and stores them in Amazon S3. They plan to build dashboards in Amazon QuickSight for hundreds of users across departments and need a scalable, cost-effective solution with daily updates. Which combination of steps meets these requirements most economically? (Choose two.)
- A marketing team stores data in Amazon S3 and uses versioning on some buckets. Multiple jobs write data to these buckets. To optimize storage costs, the company wants visibility into incomplete multipart uploads and obsolete object versions in the buckets. Which solution provides that information with the least operational effort?
- A media company collects data from SaaS applications via third-party tools and needs to store that data in Amazon S3 and analyze it with Amazon Redshift. Which AWS service or feature will accomplish this with the least operational overhead?
- A media company expects millions of daily events delivered to an Amazon Kinesis data stream. The company must transform these events and ingest them into an Amazon OpenSearch Service domain for real-time analysis. Which ingestion method has the LEAST operational overhead?
- A media company wants to enhance its recommendation engine by incorporating third-party datasets into its analytics platform with minimal time and effort. Which option provides those datasets with the least operational overhead?
- A mobile gaming company needs to capture data from its game app and make it available to three internal consumers. Each record is about 20 KB. The company wants optimal throughput from each device and requires a stream-processing application that provides dedicated throughput per internal consumer. Which solution meets these requirements?
- A new data lake on Amazon S3 will be queried with Amazon Athena. An on-premises Oracle database with 70 tables (all with primary keys) is the source; data changes occasionally. The company wants to ingest the tables daily into the lake with the least effort. Which solution should they use?
- A new data producer must onboard many pipelines from an on-premises data center to AWS. Each pipeline needs service accounts and credentials. Data must be transferred without using the public internet. Which solution meets these requirements?
- A partner drops a data file into an Amazon S3 bucket every day. An AWS Glue ETL job cleans and transforms the file daily and writes the result to Daily.csv in another S3 bucket. Sometimes the incoming file is empty or has missing required fields; when that happens, the company wants to keep the previous day's CSV. The engineer must ensure the prior day's file is overwritten only when the new daily file is complete and valid. Which solution accomplishes this with the least effort?
- A production AWS account stores security logs in CloudWatch Logs. A separate security AWS account will receive those logs for storage and analysis. The company needs to deliver the CloudWatch Logs from the production account to the security account using Amazon Kinesis Data Streams. Which approach satisfies this requirement?
- A provisioned Amazon Redshift cluster with five ra3.4xlarge nodes shows one node frequently at over 90% CPU while the other four are under 15% during normal operations. The cluster uses key distribution. The engineer wants to keep the same node count but balance load across nodes. What change will achieve this?
- A ReactJS frontend calls REST APIs through Amazon API Gateway. A data engineer needs to provide a Python script that can be invoked occasionally via API Gateway and must return responses to API Gateway. Which option gives the required behavior with the LEAST operational overhead?
- A retail company loads daily retail order CSV files into a single S3 path and uses Amazon Redshift Spectrum to query subsets of the more-than-100-column data. The third-party source produces over 30 CSV files per day (50–70 MB each). Users aggregate daily metrics, but query performance has degraded. Which combination of actions will resolve the performance issues with the least development effort? (Choose two.)
- A retail company stores transactions, store locations, and customer tables on a four-node reserved ra3.4xlarge Amazon Redshift cluster. All tables currently use EVEN distribution. The store location table is updated very infrequently, but queries are slow because the table is being broadcast to all four compute nodes. To reduce broadcasting and speed up queries in the most cost-effective way, what should the data engineer do?
- A retail company uses AWS Glue ETL for processing customer order data and needs to enforce custom validation rules to ensure correctness and consistency. What solution will meet this requirement?
- A retail firm stores customer data for many countries in an S3-based customer data hub used by analysts worldwide. Governance must ensure analysts can only access customer records for the same country as the analyst. Which approach enforces this with the least operational work?
- A retailer is expanding globally and needs Amazon QuickSight to compute currency exchange rates for financial reports with four-decimal precision. The calculations must be precomputed and stored in SPICE for fast, parallel, in-memory access. Where should the engineer define the calculated field to satisfy these requirements?
- A retailer keeps customer data in S3 that may contain PII. The company must ensure datasets containing PII are identified before sharing objects with partners. Which approach detects PII with the least manual effort?
- A retailer stores product lifecycle management data in an on-premises MySQL database that receives frequent updates. The company wants near-real-time insights integrated with other datasets and analyzed in Amazon Redshift. A Direct Connect link to AWS is already in place. Which solution requires the least development effort?
- A retailer uses Amazon Aurora PostgreSQL for live transactions and Amazon Redshift as a data warehouse. A daily ETL updates Redshift from PostgreSQL. To reduce Redshift costs, the engineer must keep only the most recent 15 months of data in Redshift, archive historical data, and still run analytics that combine live PostgreSQL data, current Redshift data, and archived historical data. Which steps will satisfy these requirements? (Choose two.)
- A retailer uses Amazon Redshift for real-time inventory management and has an ML model deployed on a SageMaker real-time endpoint. The company needs to produce immediate inventory recommendations and also forecast future inventory demand. Which of the following will satisfy these needs? (Choose two.)
- A security company stores IoT JSON data in Amazon S3 where the schema can change between device firmware updates. The analytics team needs a data catalog to index this data. Which is the most cost-effective solution to provide a catalog and handle evolving schemas?
- A serverless Step Functions workflow ingests data from an external API, transforms it with multiple AWS Lambda functions, and writes results to DynamoDB. The workflow must take different paths depending on the content of incoming messages. Which Step Functions state type should be used to implement conditional branching?
- A telco collects several thousand network usage data points per second and processes them in real time, aggregating and storing results in an Amazon Aurora DB instance. Sudden falls in usage typically indicate outages, and the company needs to detect those drops and respond immediately with the lowest possible latency. Which solution provides the least-latency detection?
- A transportation firm collects vehicle geolocation records of 10 bytes each, receiving up to 10,000 records per second. A few minutes of transmission delay are acceptable. They will use Amazon Kinesis Data Streams and need a reliable mechanism to send data while maximizing shard throughput efficiency. Which option is the most operationally efficient?
- After validating an Amazon Redshift stored procedure that inserts data into a noncritical table, the engineer needs it to run automatically every day. What is the most cost-effective way to accomplish this?
- Amazon Athena queries are being queued before execution. What can the data engineer do to prevent queries from being queued?
- An airline POC stores daily CSV metrics in S3 partitioned by date and queries them with Amazon Athena. As data grows, the company wants to optimize storage to improve query performance. Which two actions should they take? (Choose two.)
- An Amazon Redshift data warehouse team wants to detect anomalies that the query optimizer flags as potential performance problems. Which system table view should be used to log these optimizer-identified anomalies?
- An Amazon Redshift table named Employee uses a compound sort key composed of Region ID, Department ID, and Role ID. Which queries will gain the most performance improvement from this compound sort key? (Choose two.)
- An application consumes messages from an Amazon SQS queue but sometimes the application is down, causing messages to expire and be deleted after 1 day, resulting in data loss. Which actions will reduce data loss for the application? (Choose two.)
- An application running on EC2 instances in a VPC needs VPC flow logs collected and analyzed, and the company wants the most cost-effective solution. Which approach meets this requirement?
- An application stores data in a DynamoDB table using provisioned capacity. The workload has predictable scheduled peaks (an early Monday morning surge) and very low weekend usage. The company needs consistent performance during peaks at the lowest cost. Which solution is most cost-effective?
- An application uses Amazon API Gateway and an AWS Lambda function to fetch data from Amazon DynamoDB. Users report intermittent high latency. The team's investigation shows the API's Lambda function is frequently throttled whenever other Lambda functions have higher invocation rates. The company wants the API's Lambda to be isolated from other functions in the most cost-effective way. What should they do?
- An ecommerce business has multiple operational systems in AWS, each with a JDBC-compliant relational database storing the latest processing state. The operations team needs hourly visibility into orders across the entire fulfillment workflow. Which approach delivers this with the least development effort?
- An ecommerce company wants to migrate on-premises data ingestion pipelines to AWS without managing servers. The solution must orchestrate existing Python and Bash scripts without refactoring. Which option provides the least operational overhead?
- An ETL job must process daily .csv files that users place into an S3 bucket. Each file is smaller than 100 MB. Which implementation is the most cost-effective?
- An event-stream processing application runs in an Amazon EKS cluster and writes results to Amazon DynamoDB. The containers must access DynamoDB securely without embedding AWS credentials. Which solution satisfies this requirement?
- An EventBridge event is configured to invoke an AWS Lambda function, but invoking the function produces an AccessDeniedException. How should the data engineer fix this error?
- An insurance company archives transaction records compressed with gzip and needs to run occasional queries for audits in the most cost-effective way. Which approach should they use?
- An investment firm ingests an ever-growing volume of semi-structured data and needs to deduplicate records, removing duplicates and common misspellings. Which option provides this capability with the least operational overhead?
- An online retailer stores ALB access logs in S3 and queries them with Amazon Athena. The engineer created an unpartitioned Athena table, and query response times have grown as the data volume increased. Which approach will improve Athena query performance with the least operational effort?
- An online retailer stores order summaries in Amazon S3 that sometimes include customer PII. The data engineer must detect PII so the retailer can redact it. Which AWS service provides PII detection with the least operational overhead?
- An organization has an Amazon Redshift cluster accessed by over 100 users with different IAM roles. The organization needs to control access to database objects based on users' job roles, permissions, and data sensitivity. Which feature should be used to meet this requirement?
- An organization runs a critical application using Amazon RDS for MySQL. The workload is write-heavy with few reads. The DB instance shows very high CPU usage, which is degrading application performance. What steps should the data engineer take to lower the DB instance CPU utilization? (Choose two.)
- Customer data that includes PII is stored in Amazon Redshift. Different teams require different levels of access: marketing needs obfuscated claim details but full contact info; claims needs customer info for each claim they process; analytics needs only obfuscated PII. Which approach enforces these access rules with the least admin overhead?
- During a security assessment, a hard-coded Amazon Redshift credential was found inside an AWS Glue job script. A data engineer must fix the vulnerability by storing the credentials securely. Which two actions should the engineer perform? (Choose two.)
- Files from several sources arrive regularly in an Amazon S3 bucket. A data engineer needs to ingest new files into Amazon Redshift in near real time as soon as they appear in the S3 bucket. Which approach meets this requirement?
- Multiple Lambda functions all rely on shared custom Python formatting scripts. Currently, the engineer updates each Lambda individually when the scripts change. Which approach will allow updating the scripts without manually changing every function?
- To speed up Amazon Athena queries, a data engineer finds that all input files are uncompressed .csv and that most queries select a single column. Which change will MOST improve Athena query performance?
- Two developers branched from the GitHub repository's master branch, creating Branch A and Branch B. The Branch A developer already deployed to production; Branch B will be merged into master in next week's release. Before opening a pull request into master, which Git command should the Branch B developer run?
- Which query languages should the engineer use to develop graph applications on Amazon Neptune? (Choose two.)
- Which SQL statement creates a new empty Amazon Athena table new_table that has the same schema as an existing table old_table?
- You must build an ETL pipeline that ingests files (CSV, JSON, or Parquet) delivered every 15 minutes from 10 source systems into 10 Amazon Redshift tables. All files land in a single S3 bucket; file sizes vary from 10 MB to 20 GB. The pipeline must tolerate schema changes. Which solutions meet these requirements? (Choose two.)
- You must orchestrate a sequence of Amazon Athena queries every day; individual queries can run longer than 15 minutes. Which combination of steps is the MOST cost-effective? (Choose two.)
- You must securely move 5 TB of on-premises data to Amazon S3, with about 5% of the data changing daily. Updates must be propagated regularly; files are in multiple formats; the transfer must be automated and scheduled. Which AWS service provides the most operationally efficient solution?
Amazon DevOps Engineer Professional DOP-C02 Certification All exam questions
- A blue/green deployment is being configured for an existing three-tier app running on EC2 behind an ALB with Auto Scaling groups. Blue and green environments each have their own launch templates, Auto Scaling groups, and ALB target groups. Traffic for www.example.com currently points to the ALB. The deployment must switch all traffic at once from blue to green. What sequence achieves this?
- A build account runs a CodePipeline that builds a Lambda artifact in CodeBuild and stores encrypted artifacts in an S3 bucket using the aws/s3 AWS‑managed KMS key. The pipeline’s CloudFormation deploy actions run in separate development and production accounts and fail with access denied when those actions try to access artifacts. Which steps resolve the error? (Choose two.)
- A CI/CD pipeline built with CodePipeline and CodeBuild deploys five independent Lambda functions sequentially. An EventBridge rule starts the pipeline immediately when source changes occur. After months of use the pipeline takes too long to finish. What is the best change to speed up the pipeline?
- A CI/CD setup uses CodePipeline and CodeBuild. The CodeBuild project runs tests and produces a test report. The company must retain these test reports for 90 days. Which approach satisfies this retention requirement?
- A CloudFormation custom resource was used to provision AD Connector. The Lambda function executed and created the AD Connector, but CloudFormation remains in CREATE_IN_PROGRESS and does not finish. What should the engineer do to correct this?
- A CloudFormation stack in a single account sends stack event notifications to an SNS topic. You must automatically tag the specific stack instance only after a successful stack update (UPDATE_COMPLETE). A Lambda function exists that applies the tag. Which solution will ensure the Lambda runs only after an UPDATE_COMPLETE for that stack?
- A CloudFormation stack update failed due to a bad template and CloudFormation started rolling back, but the stack remains in UPDATE_ROLLBACK_FAILED and the application is still down. What actions should a DevOps engineer take so the rollback can finish successfully? (Choose two.)
- A CloudFormation stack update failed with the error: "both the deployment and the CloudFormation stack rollback failed. The deployment failed because the following resource(s) failed to update: [AutoScalingGroup]." The stack is now in UPDATE_ROLLBACK_FAILED. Which action will resolve the problem?
- A CloudFormation template creates an EC2 instance (with user data to install an app) and an S3 bucket used by the app to serve static pages. All resources must be removed when the stack is deleted, but stack deletion fails because the S3 bucket is not removed. What is the most efficient way to ensure all stack resources are deleted without errors?
- A CloudFormation template deploys an application to Amazon Linux EC2 instances using user data shell scripts. Instances have an instance profile with AmazonSSMManagedInstanceCore. After updating user data in the template and performing a stack update, running EC2 instances did not receive the updated application. What combination of actions will ensure the running instances get the application updates? (Choose two.)
- A CodeBuild project builds a Docker image and previously uploaded images to S3; you migrated to Amazon ECR and updated the project role and docker commands, but the build fails when attempting to access ECR. What change will fix the ECR authentication failure?
- A CodeBuild project uploads artifacts to a shared S3 bucket. The buildspec post_build uses --acl authenticated-read, and now anyone with an AWS account can download the artifacts. What should the DevOps engineer do to prevent this?
- A CodePipeline deployment sometimes results in the web application's home page returning a 503 instead of the expected 200. You added a CheckURL stage after deployment that should fail the pipeline if the home page does not return 200 OK. What is the appropriate next step to implement this automated test?
- A CodePipeline has a CloudFormation deploy action that creates an S3 bucket and a later S3 deploy action that must upload the build artifact into that created bucket. How should the pipeline be configured so the S3 deploy action uses the bucket created by the CloudFormation action? (Choose two.)
- A CodePipeline has sequential source, build, and deploy stages, each with a single action at runOrder 1. The team needs to add unit tests so that only code that passes tests is deployed. How should they integrate unit testing into the pipeline?
- A CodePipeline in eu-west-1 builds and deploys a Lambda app to eu-west-1. CodeBuild uses aws cloudformation package to produce an artifact that includes the Lambda .zip and the template. The CloudFormation deploy action uses that output artifact. The company now wants the same pipeline (in eu-west-1) to also deploy the Lambda to us-east-1. CodeBuild was updated to produce an additional output artifact for us-east-1. Which additional steps should be taken? (Choose two.)
- A CodePipeline is integrated with CodeDeploy to deploy application versions to EC2 instances across stages. A recent deployment failed because of a CodeDeploy problem. The DevOps team wants better monitoring and automated alerts during deployments to shorten time to resolution. What should the DevOps engineer implement to generate notifications when deployment issues occur?
- A CodePipeline runs: (1) CodeBuild compiles and runs unit tests, (2) CodeDeploy deploys to EC2 staging, (3) CodeDeploy deploys to EC2 production. QA wants to inspect the build artifact before production and run a manual penetration test that is invoked via a REST API. Which combination of changes should the DevOps engineer make? (Choose two.)
- A company acquired another company whose AWS accounts are standalone. The acquiring company manages accounts with AWS Organizations and wants to consolidate administration of all accounts while keeping full administrative control and centralizing security findings across all accounts. Which combination of actions should the DevOps team take? (Choose two.)
- A company configured an EventBridge custom event pattern to be notified when CodePipeline execution states fail. Which type of events will match that pattern?
- A company defines its app with the AWS Cloud Development Kit (CDK) and deploys it using a pipeline built with AWS CodePipeline and AWS CodeBuild. They want to add unit tests to the pipeline and ensure the deployment only continues if none of the unit tests fail. Which two steps will enforce that requirement?
- A company deployed a landing zone with an AWS Organizations structure and an SCP. Developers may create resources only with CloudFormation and the AWS CDK. A DevOps engineer finds that SQS queues deployed in different CloudFormation stacks have inconsistent configurations and the application cost-allocation tag is sometimes missing. The engineer needs to enforce tagging, encourage code reuse, and prevent inconsistent SQS configurations. What should the engineer do?
- A company deployed multiple AWS accounts with AWS Control Tower. The security team needs to automate Control Tower guardrails for all accounts in a specific OU, keep the guardrail configuration under version control with the ability to review and roll back changes, have the security team maintain the solution in its own OU, and restrict guardrail types so only approved new guardrails are allowed. Which solution provides the most operational efficiency?
- A company deploys an application to Amazon EC2 instances running Amazon Linux 2 and using AWS CodeDeploy. The repository has the shown file layout and the appspec.yml files section contains the indicated entries. What will happen to the config.txt file during deployment?
- A company deploys an application using EC2 instances and multiple CloudFormation stacks. Developers build and test locally, then upload artifacts and templates to S3; peers review changes before stack updates. The deployment process is error-prone and slow when updating each instance. The company wants to automate deployment but keep a final manual approval before modifying application or resources. Source and templates are already in CodeCommit and a CodeBuild project exists. Which steps meet the requirements? (Choose two.)
- A company has 100 GB of CSV log files in S3. SQL developers need to query the data, create graphs for visualization, and automatically store metadata from the CSVs with minimal effort. Which combination of steps (choose three) meets these needs with the least work?
- A company has 20 service teams, each in its own AWS account and each VPC using 192.168.0.0/22. Services run on EC2 instances behind ALBs and currently communicate over the public internet. Security now requires all cross-service traffic use HTTPS over private networking without routing through the internet. The solution should minimize changes required by each team. Which approach meets these requirements?
- A company has an event-driven JavaScript app built from decoupled managed AWS services that publish, consume, and route events. During testing, EventBridge rules are not delivering events to their targets. Testers need ways to view, debug, and avoid losing events without redeploying the app. Which combination of actions should the DevOps team take? (Choose three.)
- A company has multiple member accounts in an AWS Organization. The security team needs to programmatically list every Amazon EC2 security group and its inbound/outbound rules across member accounts using an AWS Lambda function that runs in the management account. Which combination of IAM/trust changes will allow the management-account Lambda to retrieve this information from member accounts? (Choose three.)
- A company is building an application that uses AWS Lambda for compute. All Lambda changes must be deployed using a canary strategy with automatic rollback on failures. The DevOps team must produce infrastructure-as-code and a CI/CD pipeline to meet these requirements. Which combination of steps will satisfy the requirements? (Choose three.)
- A company is deploying an Amazon ECS cluster that will run multiple services behind an Application Load Balancer (ALB) using multiple target groups. A DevOps engineer must collect both application logs and ALB access logs and deliver them to an Amazon S3 bucket for near-real-time analysis. Which combination of actions should the engineer take? (Choose three.)
- A company is migrating container workloads into a multi-account AWS Organizations setup. Application accounts run the workloads; a shared services account hosts centralized services. Compliance requires every container image to be scanned before deployment, images with no critical vulnerabilities may be consumed downstream, and pre-scan and post-scan images must be isolated so deployments cannot use pre-scan images. Which pair of steps centralizes this workflow with the least admin overhead? (Choose two.)
- A company is migrating Windows and Linux applications to AWS and will automate launching EC2 instances to match on-premises setups. Applications need shared storage accessible over SMB for Windows and NFS for Linux. The company is also creating a pilot-light DR environment in another Region and will automate launching EC2 instances there; storage must be replicated to the DR Region. Which storage solution meets these requirements?
- A company is moving from on-premises CI/CD to AWS. They want their packages and dependent public repositories available in CodeArtifact with minimal operational overhead. Which combination of steps should they take? (Choose two.)
- A company migrated containers to Amazon EKS and needs automated email notifications per EKS component. The plan is to use SNS topics and a Lambda function that inspects log events and publishes to the appropriate SNS topic. Which logging approach supports this design?
- A company migrated its application to an Amazon EKS cluster on EC2 and enabled autoscaling based on CPU. Under heavy load the application shows memory errors and does not scale out sufficiently. The company needs to collect and analyze memory metrics over time. Which combination of steps will achieve this? (Choose three.)
- A company migrates product development teams into a hybrid environment with four new AWS Regions, allowing developers to use the nearest Region. All teams use a shared set of Linux applications stored on an on-prem NetApp ONTAP volume mounted read-only. The applications are updated weekly. The engineer must replicate the data to all Regions so it stays current with deduplication and so deployments never depend on the on-prem storage. Which solution meets these requirements?
- A company must continuously keep Amazon Linux EC2 instances compliant with OS and application patches; application patches are stored in a custom repository. The engineer wants to automate patching using both the default OS repository and the custom repository with minimal effort. Which solution meets this need?
- A company needs a continuous delivery pipeline for code in a private GitHub repo that deploys components to Amazon ECS, Amazon EC2, and AWS Lambda, and that supports manual approvals. Which solution meets these requirements?
- A company observes unusual login attempts across many AWS accounts. An SNS topic already exists with the security team subscribed. Which approach requires the least operational effort to notify the security team when multiple failed Console login attempts occur?
- A company organizes its AWS accounts into organizational units (OUs) within AWS Organizations. APIs deployed in one account are bound to that account's VPC and currently have no authentication. Only principals from a specific OU should be allowed to call the APIs. The company applied a policy to the API Gateway interface VPC endpoint and updated the API Gateway resource policies to block calls that don't come via the interface endpoint. After this, invoking an API through the interface endpoint URL fails with the error: "User: anonymous is not authorized." Which combination of actions resolves this issue? (Choose two.)
- A company primarily uses EC2. The DevOps team needs to audit all EC2 instances for installation of prohibited applications. Which approach satisfies this requirement with the least operational overhead?
- A company replaced an S3-hosted static site at example.com with a dynamic application behind an ALB and added a weighted Route 53 record for the ALB. Some users still see the old static site. How can the engineer ensure only the dynamic content is served for example.com?
- A company requires all infrastructure to be deployed only within US Regions. The DevOps engineer must restrict which Regions can be used, immediately alert on any activity outside the policy, and have the controls automatically apply for any new non-US Region. Which combination of actions will satisfy these requirements? (Choose two.)
- A company requires disaster recovery and failover for its application (which uses a MySQL database and EC2 instances) with an RPO ≤ 2 hours and an RTO ≤ 10 minutes at all times. Which combination of deployments will satisfy these objectives? (Choose two.)
- A company requires security approval before any application changes are deployed to production using AWS CodePipeline, and the approval must be recorded and retained. Which combination of actions satisfies these requirements? (Choose two.)
- A company requires that every EC2 instance be launched from an AMI produced by the security team. Each month the security team emails the approved AMIs to developers, who then copy them into CloudFormation templates. A DevOps engineer wants to automate distribution of the approved AMI IDs to developers in the most scalable way. Which approach is best?
- A company requires that internal teams provision resources only via approved CloudFormation templates, and the security team needs automated detection when resources drift from their expected state. Which strategy satisfies both requirements with appropriate enforcement and automated monitoring?
- A company runs a custom application on EC2 instances in an Auto Scaling group that processes records through multiple sequential, compute-heavy steps. Each step takes up to 5 minutes. Currently, if any step fails the entire record must be reprocessed from the start. The company wants to reprocess only the failed steps with the least operational overhead. What is the most operationally efficient architecture to meet this?
- A company runs a file-reading application that stores files in a database on Amazon EC2 instances. Regulations require daily deletion of files from the EC2 instances at a specific time, and database records older than 60 days must be removed. Database deletions must occur after the file deletions. The company already has scripts for both deletion tasks and needs email alerts for any deletion-script failures. Which solution meets these requirements with the least development effort?
- A company runs a proprietary in-memory grid that requires updating /etc/cluster/nodes.config whenever cluster membership changes. Adding a node must be automated so the file lists the current member IPs and the service is restarted. What can a DevOps engineer do to automate this with minimal effort?
- A company runs a sensitive data ingestion app across multiple AWS accounts (in AWS Organizations). EC2 instances in Auto Scaling groups use a custom AMI and have no internet access; required VPC endpoints are in place. Administrators need automated, centrally controlled access to log in to instances for maintenance and troubleshooting, and the security team must be notified whenever instances are accessed. Which solution satisfies these requirements?
- A company runs an Amazon Connect instance in multiple AWS accounts, each using the default EventBridge event bus. The DevOps team must receive all Amazon Connect events consolidated into a single DevOps AWS account. What configuration will forward events from the other accounts to the DevOps account?
- A company runs an application on Amazon EKS and distributes it via Amazon CloudFront. AWS WAF is enabled and WAF logs are sent to a CloudWatch Logs log group named aws-waf-logs. The company wants alerts only when there are sudden changes in blocked traffic, not for other WAF log variations. WAF rules will be tuned over time. The DevOps engineer is subscribed to an existing SNS topic. Which solution satisfies these requirements?
- A company runs applications on Windows and Linux EC2 instances across multiple Availability Zones using Auto Scaling groups. They need durable shared storage that uses SMB for Windows, NFS for Linux, provides sub-millisecond latency, and is shared read/write across instances. Which three steps accomplish this?
- A company runs container workloads on AWS App Runner and stores container images in Amazon ECR. The DevOps engineer must continuously monitor the ECR repository and automatically produce a new container image when an OS or language-package vulnerability is detected. Which solution satisfies this requirement?
- A company runs infrastructure across Regions, AZs, on-premises servers, EC2, and AWS IoT Greengrass devices. The DevOps team will use AWS Systems Manager to automate patches and configuration across EC2, IoT devices, and on-prem servers. Systems Manager is available in the needed Regions. Which steps are required to implement automated patching and configuration across all these resources? (Choose three.)
- A company runs vulnerability scans for EC2 instances across many member accounts in an AWS Organization. VPCs attach to a shared transit gateway and egress via a central egress VPC. Amazon Inspector is enabled from a delegated administrator account, but some instances appear in Inspector’s “not scanning” list. Which combination of actions should the DevOps engineer take to fix this? (Choose three.)
- A company runs workloads on EC2 instances and requires that all instances use Instance Metadata Service Version 2 (IMDSv2). If an instance still allows IMDSv1, it must be terminated. Which approach satisfies this requirement?
- A company sends AWS Network Firewall flow logs to an S3 bucket and analyzes them with Amazon Athena. They now need to transform the flow logs and enrich them with additional data before they arrive in the existing S3 bucket. Which solution satisfies this requirement?
- A company serves proprietary content through a CloudFront distribution and must restrict access to only users from the corporate office IP ranges. A WAF web ACL is attached to the distribution and the ACL’s default action is currently Count. What is the lowest-operational-overhead way to enforce access only from the corporate IP ranges?
- A company stores images in an S3 bucket and needs a multi-Region strategy so it can fail over to a bucket in another Region. When an image is added to either bucket it must replicate to the other bucket within 15 minutes. Two-way replication between the buckets is enabled. Which additional steps should be taken? (Choose three.)
- A company stores source code and unit tests in an AWS CodeCommit repository. A CodePipeline pipeline triggers a CodeBuild project when code is merged to the main branch. The CodeBuild project must run the unit tests and, if they pass, tag the latest commit in the CodeCommit repository. How should the CodeBuild project be set up to accomplish this?
- A company uses Amazon Redshift as its data warehouse and wants a dashboard that shows changes to Redshift users and the queries they run. Which combination of steps will achieve this? (Choose two.)
- A company uses an AWS Storage Gateway in file gateway mode in front of an S3 bucket shared by multiple systems. A third party uploads objects directly to the S3 bucket overnight, but in the morning the Storage Gateway cache does not reflect those new objects (the objects are present in S3 when checked directly). Which solution ensures the Storage Gateway has all updated third-party files available by morning?
- A company uses AWS CodeArtifact repositories with public upstreams. Developers pull open-source packages from the internal repos. A critical vulnerability is found in the latest version of a package; the security team has produced a patched build and must prevent the vulnerable version from being downloaded while still allowing the security team to publish the patched version. Which actions satisfy both requirements? (Choose two.)
- A company uses AWS CodeDeploy and needs the deployment to meet these requirements: a subset of instances must remain serving traffic, traffic is balanced across those instances and they auto-heal; launch a new fleet automatically for the new revision with no manual provisioning; shift traffic to the new fleet in half-instance increments and require success only if at least half the instances receive traffic; remove temporary deployment files before routing traffic to the new fleet; after successful deployment, immediately terminate the original instances to reduce cost. How can this be implemented?
- A company uses AWS CodePipeline with AWS CodeDeploy to deploy an application to Amazon ECS using blue/green deployments. The team needs to run test scripts against the green environment (tests finish within 5 minutes) before shifting traffic. If tests fail, the deployment must roll back. Which approach satisfies this requirement?
- A company uses AWS Directory Service for Microsoft Active Directory as its identity provider and requires all infrastructure to be provisioned with AWS CloudFormation. A DevOps engineer created a CloudFormation template that defines an EC2 launch template, an IAM role, an EC2 security group, and an Auto Scaling group for Windows EC2 instances. All EC2 instances must be automatically joined to the AWS Managed Microsoft AD domain. Which approach provides the required domain join with the greatest operational efficiency?
- A company uses AWS Organizations and deploys all resources (including IAM and S3 policies) via CloudFormation from CodeCommit. Developers in some accounts recently cannot access an S3 bucket. The bucket has a policy attached (not shown here). What should the DevOps engineer do to resolve the access problem?
- A company uses AWS Organizations and wants its monitoring system to receive an alert when a root user signs in. The company also needs a dashboard that shows any activity generated by the root user. Which combination of steps will meet these requirements? (Choose three.)
- A company uses AWS Organizations to manage multiple accounts. Developers are refactoring apps to run as AWS Lambda functions in a VPC. The team stores shared data on an Amazon EFS file system in Account A and wants Lambda functions in Account B to mount the existing EFS access point. Company policy requires serverless deployments to be in Account B. Which combination of steps will enable Account B’s Lambda functions to access the EFS file system in Account A? (Choose three.)
- A company uses AWS Organizations with all features enabled and has configured AWS Control Tower and a landing zone. The company must provision multiple environment accounts and a CI/CD account, apply an initial baseline configuration to every account, and ensure Control Tower guardrails are enforced in all accounts. Which solution achieves this with the least operational overhead?
- A company uses AWS Organizations with separate accounts per department. They need to regularly: update Linux AMIs with patches to build a golden image, install a new Chef agent version if available into that image, and provide the new AMIs to department accounts. Which approach minimizes operational overhead?
- A company uses AWS Organizations. Each application team has its own account and limited access to a centralized shared services account. Teams need full access to manage (download, publish, grant) their own packages. Some common libraries must be shared with the entire organization. Which minimal-administration setup meets these needs? (Choose three.)
- A company uses CodePipeline to deploy updates to an API Gateway API and exports a JavaScript SDK from the console, uploading it to S3 behind a CloudFront distribution. The SDK should be updated automatically whenever a new API deployment happens. Which solution will accomplish this?
- A company uses CodePipeline with build, test, and deploy stages. They want to use AWS CodeDeploy for the deployment stage to install an RPM package to a fleet of EC2 instances launched from a common AMI and managed by an Auto Scaling group. Which steps should the DevOps engineer take? (Choose two.)
- A company wants OS-level and language-package vulnerability scanning integrated into its CI/CD pipeline so only images without CRITICAL or HIGH findings reach production. The pipeline is CodePipeline with CodeBuild, CodeDeploy, and an ECR repo. Which combination of steps achieves this? (Choose two.)
- A company wants to shorten the time to develop new features. It uses CodeBuild and CodeDeploy to build and deploy applications and has a separate CodePipeline CI/CD pipeline per microservice. The company needs more visibility into metrics such as average time between feature releases and mean time to recovery after failed deployments. Which solution gives that visibility with the least configuration effort?
- A company wants to use AWS CloudFormation to provision resources but must enforce strict tagging and resource constraints and limit deployments to two Regions. Developers need to be able to deploy multiple versions of the same application. Which solution ensures deployments conform to company policy?
- A company will deploy a workload to several hundred EC2 instances launched from a launch template in an Auto Scaling group. The workload reads from one S3 bucket, processes data, and writes results to another S3 bucket. The instances must have least-privilege permissions and must use temporary credentials. What steps are required? (Choose two.)
- A company will use AWS Systems Manager documents to bootstrap developers' physical laptops. Bootstrap code resides in GitHub. The Systems Manager agent is installed and registered on all laptops via an activation and activation ID. What should the DevOps engineer configure next in the Systems Manager document to retrieve the bootstrap code from GitHub?
- A company's DevOps group builds applications in AWS CodeBuild using NPM open-source packages from public registries. The company wants to host those NPM packages in private registries and perform validation on new package versions before the DevOps team starts using them. Which approach satisfies these requirements with the least operational overhead?
- A company's DevOps team manages multiple AWS accounts within an AWS Organizations organization. They need to ensure every Amazon EC2 instance uses only AMIs that the DevOps team approves and to automatically remediate any instances launched from unapproved AMIs. Individual account administrators must not be able to remove this restriction. Which solution meets these requirements?
- A company's internal web application currently runs on a single EC2 web server with a NAT instance for outbound internet access. The app must be made highly available. Which combination of architecture changes should be implemented? (Choose two.)
- A container workload in an EKS cluster uses Amazon Managed Service for Prometheus for monitoring. The DevOps team wants alerts to be sent to an SNS topic in the same account. Which combination of steps is required? (Choose three.)
- A content-sharing app will migrate from EC2/ALB blue/green deployments to API Gateway and Lambda. The team needs a deployment process that supports testing changes on a small subset of users (canary) before promoting them. Which deployment approach satisfies this requirement?
- A critical application is deployed in two AWS Regions and uses an Application Load Balancer in each Region. Route 53 alias records point to both ALBs, and Route 53 Application Recovery Controller (ARC) provides routing controls for failover testing. During a quarterly DR test both routing controls were accidentally turned off. The company wants to guarantee that at least one routing control is always ON. Which solution enforces that constraint?
- A custom AWS Config rule uses a Lambda function to check Amazon ECR repository policies for any statements allowing ecr:* actions. When a noncompliant repository is found, EventBridge routes the notification via SNS to a security team. The Lambda function fails to run during rule evaluations. What change fixes the problem?
- A database team maintains database resources in one CloudFormation template and a software team maintains web application resources in another template. The software team needs to reference database resources while keeping separate review/lifecycle processes and resource-level change-set reviews. The software team will deploy changes from its own CI/CD pipeline. What solution satisfies these requirements?
- A dev team uses CodeCommit, CodePipeline, and CodeBuild. Pull requests are used for changes, but failing tests in the main pipeline block progress. The team wants unit and integration tests to run on each pull request before merge. What solution meets this need?
- A developer in a shared development AWS account needs to create service-linked roles for services used in a proof of concept. The account is part of an AWS Organization. The developer must be able to create and configure service-linked roles, and nothing more. Which approach meets this requirement?
- A developer uses AWS SAM to prototype a Lambda function. The SAM template's AWS::Serverless::Function has CodeUri pointing to an S3 location. The developer packaged the function as package.zip, uploaded it to the S3 location, and ran sam deploy. After updating the function code and repeating those same steps (uploading to the same S3 key), sam deploy fails saying "no changes to deploy." Which approaches will deploy the updated code? (Choose two.)
- A development team creates new S3 buckets daily. The security team requires that all current and future buckets have encryption, logging, and versioning enabled, and that no bucket is ever publicly readable or writable. What should a DevOps engineer implement to ensure compliance?
- A development team in an AWS Organizations organization needs to use a Python package hosted in a centralized AWS CodeArtifact repository. Their CodeBuild jobs run in a VPC without internet access; they have created CodeArtifact VPC endpoints and updated the buildspec, but the build still cannot download the package. Which combination of actions should a DevOps engineer take so the team can use the CodeArtifact package? (Choose two.)
- A development team must make all environment changes only through AWS CloudFormation; direct console or CLI edits are disallowed. Developers use a developer IAM role that currently has the AdministratorAccess managed policy. A CloudFormationDeployment IAM role was created with an attached policy for deployments. The company wants to ensure that only CloudFormation uses the CloudFormationDeployment role and that developers cannot make manual changes to deployed resources. Which combination of steps will enforce this? (Choose three.)
- A DevOps engineer deployed a CloudFormation template that launches a web app (ALB, target group, launch template using Amazon Linux 2 AMI, Auto Scaling group, security group, and an RDS MySQL DB). The launch template’s user data runs a script to install and start the app. After updating the user data to a new app version and redeploying via the CI/CD pipeline, the ALB health checks fail and all targets show unhealthy. The CloudFormation stack shows UPDATE_COMPLETE, but an EC2 instance log shows Apache failed to start due to a configuration error. How can the engineer make CloudFormation fail the deployment if the user data script does not complete successfully?
- A DevOps engineer deploys a new application version with AWS CodeDeploy to EC2 instances. The deployment later fails; all events for the deployment ID show Skipped and no code was applied to the instances in the deployment group. Which of the following are valid causes? (Choose two.)
- A DevOps engineer frequently builds large Docker images with AWS CodeBuild and wants to speed up builds and reduce cost by reusing image layers across builds. Which approach best improves build performance and minimizes operational effort?
- A DevOps engineer is building a multi-stage AWS CodePipeline that requires a manual approval step between test and deploy. The development team uses a custom chat tool that accepts webhooks and requires near-real-time pipeline status and approval notifications. How should the engineer configure notifications so pipeline state changes and approval requests are posted to the chat tool?
- A DevOps engineer manages an Amazon ECS cluster running on EC2 instances in an Auto Scaling group. The engineer must capture and review all stopped tasks to investigate errors. Which approach satisfies this requirement?
- A DevOps engineer must automate restart actions when EBS-backed EC2 instances receive scheduled retirement events to reduce manual work. How can this be automated?
- A DevOps engineer must ensure that every user who signs in to the AWS Management Console is authenticated via the company's corporate identity provider (IdP). The company uses AWS Organizations. Which combination of steps will enforce this requirement? (Choose two.)
- A DevOps engineer must install a software package on 30 on-prem VMs and 15 EC2 instances, ensure the process is auditable, and automatically detect and alert on configuration drift. The environment is connected via AWS Direct Connect. Which solution provides the most operational efficiency?
- A DevOps engineer must let developers deploy CloudFormation stacks even though the developer IAM role lacks permissions to create the resources defined in the templates. The solution must follow least privilege. Which approach satisfies this?
- A DevOps engineer needs to back up sensitive objects from a private S3 bucket to a target bucket in a different AWS Region and different AWS account using S3 cross-Region replication. Which combination of actions is required to enable cross-account, cross-Region replication? (Choose three.)
- A DevOps engineer set up AWS Organizations and AWS Control Tower with OUs and landing zone. The organization needs a solution that automatically deploys CloudFormation templates and service control policies (SCPs) customized by OU or account whenever a user creates a new account through Control Tower Account Factory. Which approach provides the most automated deployment of the required resources to new accounts?
- A DevOps engineer wants to automate remediation for EC2 instances that require a restart after receiving AWS Health maintenance notifications. The engineer created an EventBridge rule. How should that rule be configured so the instances are restarted automatically?
- A DevOps engineer will deploy a Ruby application that needs to connect to an RDS for MySQL database, scale automatically, be highly available, preserve its data across application stack changes, support automated deployments with automatic rollback, and alert the team when a deployment fails. Which combination of steps meets these requirements? (Choose three.)
- A DevOps engineer wrote an IAM policy used by a Lambda function that stops EC2 instances tagged Environment: NonProduction on weekends. The policy was flagged as overly permissive. Which changes should the engineer make to follow least privilege? (Select three.)
- A DevOps engineer’s script incrementally archives on-premises data older than one month to S3 using PutObject and then deletes the local data. The script currently does not verify the S3 upload succeeded or that the object is intact. The engineer must ensure uploads are verified using MD5 before deleting local data. Which approaches meet this requirement? (Choose two.)
- A DevOps team deploys an ECS application behind an ALB using CodeDeploy with blue/green all-at-once. A recent release caused a large increase in response times and required a rollback. The team wants a deployment approach that lets them observe a new version before shifting all traffic and to roll back quickly if response times rise. Which combination of steps meets this?
- A DevOps team must ensure that specified AWS resource configuration changes are automatically reverted. Which solution fulfills this requirement?
- A DevOps team supports an application running on many EC2 instances in an Auto Scaling group, deployed via CloudFormation. One instance recently returned errors for a large share of requests while remaining healthy to EC2 and ELB health checks. Application logs are collected in CloudWatch using embedded metric format. The team needs an alert if any single EC2 instance accounts for more than half of all errors, with minimal operational overhead. Which combination of steps achieves this? (Choose two.)
- A fleet of 50 Linux EC2 instances in an Auto Scaling group behind an ALB sometimes fails ELB HTTP health checks and gets terminated before logs can be collected. How can log collection be automated so logs are retrieved before termination for root cause analysis?
- A fleet of Linux EC2 instances runs in one account and uses a Systems Manager Automation task for patching. During the latest patch cycle some instances failed because they ran out of disk space. What combination of actions ensures instances have enough disk space during future patching? (Choose two.)
- A global company uses AWS Control Tower and has one centralized DevOps account with CI/CD pipelines that deploy into application accounts. A CodeBuild project in the centralized DevOps account uses a service role and tries to deploy an application to an EKS cluster in an application account. The deployment fails with Unauthorized when CodeBuild attempts to access the cross-account EKS cluster. What change will fix the authorization error?
- A globally accessible API stack consists of API Gateway -> Lambda -> DynamoDB. The company requires both high reliability and low latency for users in North America and Europe. Which architecture meets these goals?
- A globally distributed product needs an API deployed redundantly across Regions. The API must be independently available from each location, respond to a custom domain, and optimize user request performance. How should Amazon API Gateway and routing be configured to meet these requirements?
- A healthcare company runs Amazon Linux EC2 instances and must continuously enforce patch compliance for the OS and applications using both a default and a custom repository. How can patch deployment be automated to use the default and the custom repository?
- A healthcare company wants to audit that a monitoring application runs only on EC2 Dedicated Hosts to control software licensing costs. The DevOps engineer must implement a workflow to detect noncompliant instances with minimal administrative overhead. Which approach meets this requirement with the least overhead?
- A high-traffic website runs on EC2 and uses Kinesis Data Streams to collect web logs. The Kinesis consumer app, also on EC2, falls behind when data spikes and records are dropped. Which solution improves handling of the stream with the least operational overhead?
- A Java application runs on ECS Fargate (port 8080); JVM metrics are exposed on port 9404. You want to scale the service based on the JVM thread count with minimal operational overhead. Which two approaches meet this requirement?
- A Lambda function is triggered by S3 events and must run whenever a specific bucket has new or modified objects. The function reads the S3 bucket name and object key from the event to fetch the object's contents, parse them, and write the results to a DynamoDB table. The function's execution role has permissions to read the bucket and write to DynamoDB, but during testing the function does not run when objects are added or modified. What will fix this issue?
- A Lambda function processes messages from an Amazon SQS standard queue (batch size 10) and writes results to S3. On day one, message arrival outpaces processing and many queued messages contain invalid data, causing valid messages to miss required processing deadlines. Which change will ensure valid messages meet their timeline?
- A Lambda function reads records from a Kinesis data stream and forwards them to a legacy REST API. About 10% of records have data errors and require manual handling. The Lambda has an SQS dead-letter queue configured for on-failure destinations, processes records in batches, and has retry logic. During testing many non-errored, already-processed records appear in the DLQ. Which event source option change will reduce the number of error-free records ending up in the DLQ?
- A Lambda function services read-only queries to an Amazon Aurora MySQL cluster. EventBridge events invoke the Lambda, and as invocation rate rises, database latency increases and throughput drops. Which combination of changes will improve performance? (Choose three.)
- A Lambda function starts a CloudFormation drift detection on a stack then exits. An EventBridge scheduled rule runs this Lambda hourly. An SNS topic exists and the engineer is subscribed to it. The engineer wants to be notified as soon as possible when drift is detected for that stack. Which solution satisfies this requirement?
- A Lambda function that creates AWS accounts via the Organizations API currently runs in the management account. You must move that Lambda to a separate AWS account but still allow it to create accounts in the organization, with its ability restricted to Organizations only. What approach meets this requirement before deploying the Lambda into the dedicated account?
- A large enterprise deploys a web application on EC2 instances behind an ALB with Auto Scaling across AZs. The application uses Amazon RDS for Oracle and DynamoDB, and there are dev, test, and prod environments. What is the most secure and flexible method to obtain credentials during deployment?
- A large organization with multiple AWS accounts under AWS Organizations needs to audit S3 access using the AWS CLI, monitor activity across all S3 buckets for issues, and prevent account users from disabling CloudTrail. What configuration satisfies these requirements?
- A legacy application migrated to EC2 behind an ALB and API Gateway needs deployments that minimize user disruption and allow rapid rollback with minimal application changes. Which approach meets these goals?
- A lift-and-shift migration left a single Auto Scaling group where each EC2 instance runs web, database, and Redis cache components, causing variable response times and overloaded instances. The company wants to separate components to improve availability and performance. Which architecture change will satisfy this requirement?
- A media company runs thousands of EC2 instances and uses Slack plus a shared email inbox for team communications. A DevOps engineer must forward all AWS-scheduled EC2 maintenance notifications to the Slack channel and the shared inbox. Notifications must include the instances’ Name and Owner tags. Which approach satisfies these requirements?
- A mission-critical, autoscaling application must be updated one instance at a time so the rest of the fleet stays serving traffic. The instance being updated is CPU-intensive and must be monitored; if its CPU exceeds 85% the deployment should automatically roll back. Which solution satisfies these requirements?
- A mobile application sends HTTP requests to an Application Load Balancer (ALB) that routes to an AWS Lambda function. Multiple app versions are in use and the app version is provided in the User-Agent header. The Lambda function has been modified to extract the API operation name, the application version from the User-Agent header, and the response code. What additional steps should the DevOps engineer take to collect metrics for each API operation by response code and by application version?
- A new AWS account will host many S3 buckets for applications and CloudTrail logs. Amazon Macie is enabled for the account. A DevOps engineer must reduce Macie costs while preserving required functionality. Which actions will lower cost without losing needed coverage? (Choose two.)
- A new AWS Control Tower landing zone has been created inside an AWS Organization. The landing zone must demonstrate compliance with the CIS AWS Foundations benchmarks, and the security team should view aggregated Security Hub findings across all accounts (only the security team can view aggregated findings). Specific users must be able to view findings for their own accounts. All accounts must be automatically enrolled in Security Hub when created. Which set of steps, performed mostly automatically, will achieve this? (Choose three.)
- A new platform on Amazon EKS hosts web applications that developers frequently update. Developers currently build Docker images and deploy them manually. The company wants an automated pipeline and must receive an SNS notification when ECR image scanning reports any HIGH or CRITICAL findings for OS or language-package vulnerabilities. Which combination of steps satisfies these needs? (Choose two.)
- A newly acquired company’s single AWS account joined an AWS Organization and was moved into an OU. A DevOps engineer in the management account assumes the OrganizationAccountAccessRole to access member accounts, but attempting to assume the role via the console in the new member account fails with "Invalid information in one or more fields." What action will let the DevOps engineer access the new member account?
- A newly migrated application in an Amazon EKS cluster immediately scales out to its configured maximum number of pods on deployment, even before any user traffic arrives. Other applications in the cluster operate normally. Which change will fix the application's scaling behavior?
- A penetration tester performed internal port scans against the company's EC2 instances and the scans went undetected. The company wants automatic notification when port scans are detected. They have created and subscribed to an SNS topic. What should they do next to get port scan notifications?
- A pipeline builds container images in one account and deploys to a production ECS cluster that will be moved to a different AWS account in the same Region. The production cluster must pull images over a private connection. Which design meets these requirements?
- A pipeline deploys the application to multiple Regions sequentially. You have Route 53 health checks based on CloudWatch alarms per Region. How do you ensure the pipeline waits to confirm a Region's application is healthy before moving to the next Region?
- A primary AWS Region hosts a web application and a secondary Region is a standby for disaster recovery. Requirements: session data must replicate across regions near-real-time; 1% of traffic should be routed to secondary continuously; automatic failover to secondary on primary disruption; secondary must scale to handle full traffic. How should these requirements be met?
- A product currently runs in one region on EC2 Auto Scaling instances behind an ALB with all data in an Amazon Aurora database. When expanding to Europe and Asia, the company wants a single, global product catalog but must keep customer information and purchase records stored regionally for compliance. With minimal application changes, how should the company meet these requirements?
- A production environment and its disaster recovery (DR) environment were deployed in the same AWS Region. Applications run on EC2 instances and use an FSx for NetApp ONTAP volume for storage; no application data is on the EC2 instances. AMIs were copied to a DR Region and CloudFormation templates were parameterized by Region. The storage RPO must be 10 minutes in the DR Region. What solution satisfies this requirement?
- A production environment uses AWS CodeDeploy blue/green deployments with EC2 Auto Scaling groups that launch Amazon Linux 2 instances. You must run a script that downloads and installs a license file onto replacement instances before they begin serving traffic. Which appspec.yml hook should run that script?
- A production VPC has a VPC flow log. The security team supplied a deny-list of IP addresses and wants near-real-time automated notifications if any deny-listed IP accesses the application, to justify adding protections like WAF. The product manager will approve changes only if the security team can demonstrate the issue, and cost must be minimized. Which additional steps meet the requirement most cost-effectively?
- A project on Amazon Linux failed a security review. You are reviewing a CodeBuild buildspec.yaml and must recommend security improvements. Which changes follow AWS best practices? (Choose three.)
- A recent CloudFormation stack update failed and a DevOps engineer found that some stack resources were manually modified. The engineer needs to detect manual modifications to CloudFormation-managed resources and alert the DevOps lead with minimal operational effort. What solution meets this need?
- A regional API Gateway REST API uses a custom domain and has its default endpoint disabled. Internal teams call the API, and the company wants to add mutual TLS (mTLS) for additional authentication between clients and the API. Which steps are needed to implement mTLS for this API? (Choose two.)
- A regulated company requires that DevOps engineers must not sign in to EC2 instances except for emergencies. If a login does occur, the security team must be alerted within 15 minutes. Which solution meets this requirement reliably?
- A research team needs full management control of resources in its AWS account, but must be prevented from creating IAM users. The team’s IAM Identity Center permission set grants AdministratorAccess. How can you ensure research team members cannot create IAM users?
- A REST API (API Gateway + Lambda) is deployed with CodePipeline/CodeBuild/CodeDeploy. Recent releases caused widespread customer-impacting errors. The DevOps team wants automatic rollback to the most recent stable version when an error occurs, affecting as few customers as possible. Which solution is most operationally efficient?
- A REST API in Amazon API Gateway exposes confidential data and must be callable only from specific company VPCs. Which configuration enforces access from only those VPCs?
- A retailer wants a dashboard integrated into existing CloudWatch dashboards that displays a pie chart of product transaction details. Which approach provides this capability with the least operational effort?
- A SaaS web app has users distributed across multiple ALBs, each with its own Auto Scaling group and EC2 fleet. There is no build stage; commits to CodeCommit must trigger simultaneous deployments to all ALBs and Auto Scaling groups. Which architecture requires the LEAST configuration?
- A satellite telemetry pipeline places small data packets into an Amazon SQS standard queue. A downstream application transforms the messages but sometimes cannot transform certain messages; those failed messages remain in the SQS queue. The DevOps engineer must retain failed messages and make them available to scientists for review and later reprocessing. Which solution meets these requirements?
- A security audit found security groups allowing SSH from 0.0.0.0/0. The security team must detect and remediate this as soon as possible across all accounts in a single AWS Organizations organization. Which approach accomplishes detection and automated remediation?
- A security team must record resource configurations, detect issues, and receive notifications. The account runs an EC2 Auto Scaling group that scales frequently. The team needs notification within 2 days if any EC2 security group allows 0.0.0.0/0 on port 22, and routine snapshots of resource configuration. An SNS topic already exists and the team is subscribed. Which solution satisfies these requirements?
- A security workflow invokes a Step Functions workflow when EventBridge matches certain events coming from multiple AWS services. CloudTrail records user actions, but some important events are not triggering the workflow. CloudTrail logs show no direct errors. Which steps will help identify the root cause of the missing EventBridge invocations? (Choose three.)
- A security-auditing application in one AWS account assumes an IAM role to access other accounts in the same AWS Organization. A security audit found that users in the audited member accounts can modify or delete the auditing application’s IAM role. The company needs to prevent anyone except a trusted administrator IAM role from changing that auditing role. Which approach will meet this requirement?
- A security-hardened AMI pipeline is built with EC2 Image Builder on a recurring schedule. The DevOps engineer needs Auto Scaling groups to always launch instances with the newest AMI and to update launch templates accordingly. Which approach gives the most operational efficiency?
- A serverless application in CodeCommit contains hardcoded database usernames and passwords. A DevOps engineer must automatically detect and prevent hardcoded secrets. Which is the MOST secure solution that meets these requirements?
- A serverless system uses a BeginResponse Lambda function that initializes data; afterward many Lambda functions must run in parallel, each depending only on the outputs from BeginResponse. Each downstream Lambda requires retryable invocations and independent concurrency control without losing messages. Which design provides the most operationally efficient solution?
- A serverless web and mobile backend uses Lambda and API Gateway. The backend Lambda deployment must be fully automated based on code pushed to the appropriate branch in CodeCommit. Requirements: separate pipelines for test and production, and automatic deploys only for test environments. What steps meet these requirements?
- A single AWS account in one Region runs hundreds of EC2 instances that are frequently launched and terminated. Security policy requires every running EC2 instance to have an instance profile; if none is attached, a default profile with no IAM permissions must be applied. The engineer found existing instances without an instance profile and ongoing launches that also omit a profile. What will ensure all current and future EC2 instances in the Region have an instance profile attached?
- A single developer currently stores project source code in an S3 bucket. The company will add developers and needs to avoid code conflicts and lost work, provide a test environment for newer versions, and let developers automatically deploy to test and production when repository code changes. What is the most efficient solution?
- A single EC2 instance runs an application whose metadata is stored in S3 and must be retrieved on restart. The instance must also restart or relaunch automatically if it becomes unresponsive. Which solution satisfies these needs?
- A single-Region application uses DynamoDB tables and S3 buckets. The company will deploy the app to a secondary Region and requires data to persist in both Regions and propagate immediately. Which solution provides the required behavior with the least operational overhead?
- A solution uses Amazon SQS standard queues, an AWS Lambda function, and a DynamoDB table. The Lambda function is triggered by SQS and writes items to DynamoDB. The design should maximize Lambda scalability and ensure that messages that Lambda successfully processes are not processed again. Which configuration satisfies these requirements?
- A staging website runs on a single Amazon EC2 instance backed by EBS. The company wants fast recovery and minimal data loss if the instance experiences network connectivity problems or a host power failure. Which option meets these requirements?
- A stateless application runs behind an ALB on EC2 instances in an Auto Scaling group. The group uses a fully baked custom AMI with no bootstrap. That AMI was recently deleted, causing the Auto Scaling group to fail to launch instances because the AMI ID no longer exists. Which sequence of actions should a DevOps engineer perform to restore functioning scaling? (Choose three.)
- A static website is hosted in an S3 bucket and deployed via CloudFormation. The template creates the S3 bucket and a custom resource that copies site content into the bucket from a source. The team needs to delete and recreate the stack to move the website, but CloudFormation fails to delete the stack cleanly. What is the most likely cause, and how should the engineer prevent this for current and future site versions?
- A team currently builds an artifact locally and uploads it to S3, runs a cache-clear command, downloads and unzips the artifact on each EC2 instance to deploy. The DevOps team wants a CI/CD process that can stop and roll back on failure and track deployment progress. Which combination of steps will achieve this? (Choose three.)
- A team has Lambda microservices that read from DynamoDB. Developers manually deploy code after tests. They now require cloud-based automated testing and deployment, with traffic to new versions shifted incrementally after deployment. Which approach delivers these requirements while maximizing developer velocity?
- A team has Python Lambda functions stored in CodeCommit and has added unit tests. They need to run these unit tests inside an existing CodePipeline and produce test reports that the company can view. Which solution satisfies this?
- A team uses AWS CodeCommit, CodePipeline, CodeBuild, and CodeDeploy. Pull requests that failed long-running tests were merged, causing rollbacks and wasted effort. The team wants automated tests for pull requests and clear test results visible during pull-request review. What should the DevOps engineer implement?
- A team uses AWS CodeDeploy for deployments of a Java/Tomcat application with an Apache webserver. They have separate deployment groups for developer, staging, and production and want to change the Apache log level dynamically during deployment based on the deployment group without creating separate application revisions or multiple script versions. How can they achieve this with minimal management overhead?
- A team uses CodeCommit for source control and CodePipeline for deployments. They configured the pipeline to trigger on changes to the remote main branch, but after a developer pushed changes the pipeline did not start even after 10 minutes. What should be checked to troubleshoot this trigger issue?
- A team uses private Amazon ECR registries and needs container images to be scanned regularly for package vulnerabilities. What action fulfills this requirement?
- A video platform is migrating MP4 videos to Amazon S3, serving them via CloudFront and EC2. Users hit a frontend that redirects to video URLs containing an authorization token validated by CloudFront. The CloudFront distribution is cached. The team must log authorization token checks to CloudWatch, prevent direct access to video files from CloudFront and S3, and implement token-signature checks provided by the frontend. They also want to perform rolling updates of the token-checking code with minimal operational overhead. Which solution best meets these requirements?
- A video streaming platform running on Amazon EKS at large scale is experiencing unauthorized logins and sudden user logouts. The company wants stronger platform-wide security, a summarized view of resource behaviors and interactions across the AWS environment (login attempts, API calls, network traffic), the ability to analyze network traffic while minimizing log management overhead, and fast investigation of potential malicious activity related to the EKS workload. Which solution meets these needs?
- A VPC with predictable traffic has VPC flow logs sent to a CloudWatch Logs log group. The team needs a monitoring solution that detects anomalies in VPC traffic patterns over time and can trigger a response when an anomaly is detected. How should they implement this?
- A web app on EC2 behind an ALB uses blue/green immutable deployments. Users are randomly logged out during testing and everyone is logged out when a new version deploys. The team needs users to stay logged in across scaling events and deployments with the least operational overhead. What is the most operationally efficient solution?
- A web application runs on an Amazon EKS cluster using Fargate behind an internet-facing Application Load Balancer. The application has stability problems and increased response times. You must configure observability in Amazon CloudWatch to troubleshoot, granting only the minimum required permissions. Which steps meet the requirement? (Choose three.)
- A web application runs on EC2 instances behind an ALB in an Auto Scaling group across multiple AZs and uses an Amazon RDS for MySQL instance. Route 53 points to the ALB with an alias record. Company policy now requires a geographically isolated DR site with an RTO of 4 hours and an RPO of 15 minutes, with minimal changes to the application stack. Which DR approach satisfies these requirements with the least application changes?
- A web application uses an Application Load Balancer (ALB) to route traffic to EC2 instances across three Availability Zones. A new application version was deployed to one Availability Zone for testing. If a problem occurs, the company needs to route traffic away from that Availability Zone until the deployment is rolled back, while keeping the application available and stable. Which approach provides the required behavior with the most operational efficiency?
- A web application uses CloudFront (S3 origin), API Gateway, Lambda, and an Aurora DB cluster. Under a large sales event, Lambda can handle peak requests but experiences latency on the initial burst because establishing DB connections is slow. Most Lambda invocations query the database. Which combination of actions will ensure scalability? (Choose three.)
- After acquiring another company and adding it as a new OU in AWS Organizations, a DevOps engineer must ensure the new OU can only launch t3.small EC2 instances and may launch instances only in US Regions. Which SCP configuration enforces these constraints?
- After initial setup of AWS IAM Identity Center, what should be done next so employees sign in with their existing Active Directory credentials from an external SAML IdP and AD groups are provisioned into IAM?
- After updating an ECS task definition with a new container image, an ECS service connected to an Application Load Balancer repeatedly stops and starts tasks because ALB health checks fail. What should a DevOps engineer check first to troubleshoot the failing deployment?
- All accounts in an organization have AWS Config configured manually. The company wants a centralized configuration so AWS Config is set up for all organization accounts and resource changes are recorded to a central account. Which actions should you take? (Choose two)
- All EC2 instances in an Auto Scaling group behind an Application Load Balancer have stopped serving traffic and are failing HTTP target group health checks. The application process is not running and system logs show many out-of-memory errors. To improve resilience against a possible memory leak and enable monitoring/alerts, which combination of actions should you take? (Choose two.)
- All in-house quality-control apps are containerized. Jenkins runs on Amazon EC2 instances that need ongoing patching and upgrades. The compliance officer requires build artifacts to be encrypted because they contain IP. What is the most maintainable way to meet this requirement?
- All S3 buckets must have server-side encryption enabled using AES-256 immediately upon creation, and existing unencrypted buckets must be brought into compliance. Which solution enforces AES-256 for new buckets and remediates existing buckets?
- An account less than one year old is in an AWS Organizations OU. The company wants an Organizations structure and an SCP that allow only services currently used in that account. IAM Access Analyzer will be used to determine active services. What steps will achieve this requirement?
- An administrator is setting up a repository to hold the company's container images and must apply a lifecycle rule that automatically deletes images with a particular tag when they are older than 15 days. Which option provides the required behavior with the greatest operational efficiency?
- An Amazon Aurora cluster uses a single DB instance and the application uses the instance endpoint for both reads and writes. An update is scheduled during a maintenance window and the cluster must remain available with minimal interruption. What should a DevOps engineer do to meet this requirement?
- An Amazon Aurora PostgreSQL global database has two secondary Regions. The database parameter group is configured to guarantee an RPO (recovery point objective) of 60 seconds. Occasionally write operations on the primary cluster are blocked because of this RPO configuration. You need to reduce how often write operations are blocked. Which action accomplishes this?
- An API Gateway REST API invokes a Lambda function that loads a large dataset from a DynamoDB table during initialization, causing cold starts of 8–10 seconds. The DynamoDB table uses DAX. The app experiences intermittent long responses and has widely varying traffic (a mid-day spike 10× higher than normal and near-end-of-day drop to 10% of normal). The DevOps engineer must reduce Lambda latency at all times of day. Which solution meets the requirement?
- An application currently runs in an Auto Scaling group of EC2 instances behind an ALB; the EC2 instances host Docker containers that call a MySQL database on separate EC2 instances. You need to convert the application to a serverless architecture while making the fewest changes. Which option accomplishes that with minimal changes?
- An application deployed to an EC2 instance during CodeDeploy’s BeforeInstall lifecycle event needs to install a Python package stored in a CodeArtifact repository. How should you grant the EC2 instance access to CodeArtifact for the install step?
- An application exposes an API that returns workload metrics. The company must collect, analyze, and visualize those metrics at scale to identify issues. Which set of actions will satisfy these requirements? (Pick three.)
- An application generates log events at 10 Hz, each event containing five different metrics, producing high data volume. The application will write logs to Amazon Timestream and run a daily query against the table. Which combination of steps gives the fastest query performance? (Choose three.)
- An application is deployed in two AWS Regions, and each Region stores objects in a local Amazon S3 bucket. Both deployments require access to all objects and metadata from both Regions. Two-way replication is configured between the buckets and S3 Replication metrics are enabled. Implement a mechanism that retries replication for objects that fail to replicate. Which approach satisfies this requirement?
- An application is deployed to EC2 instances behind an ALB. The application code is in CodeCommit. When code is merged to main, a Lambda function triggers a CodeBuild project that packages the code, stores artifacts in CodeArtifact, and uses Systems Manager Run Command to deploy the package to EC2. Past deployments produced defects, inconsistent versions across instances, and instances not running the latest code. Which actions will create a more reliable deployment process? (Choose two.)
- An application on EC2 frequently needs in-process restarts. Logs with restart errors are sent to a CloudWatch Logs group and an alarm notifies an engineer via SNS. The engineer manually restarts the app on instances. How can you automate restarting the application (without rebooting instances) in the most operationally efficient way?
- An application on EC2 instances in an Auto Scaling group must download and process growing S3 data during startup, causing multi-minute delays for new instances. What is the MOST cost-effective way to reduce the time before new instances are ready to serve requests?
- An application on EC2 instances is behind an Application Load Balancer. A CodeDeploy release fails during the AllowTraffic lifecycle event, but deployment logs show no explicit cause. What would explain this failure?
- An application on EC2 instances writes a login log that includes username, date, time, and source IP to a CloudWatch Logs log group. For a root-cause analysis, the company must determine how many times a specific user logged in over the past 7 days. Which approach will provide that count?
- An application running in an Auto Scaling group processes items from an SQS queue with long-running workers. The team needs to be alerted when the queue grows beyond expected size. The application logs are sent to a third-party tool and the team already uses an SNS topic for alerts. Which monitoring approach is most operationally efficient?
- An application running on Amazon EKS needs confidential credentials stored in Secrets Manager. The secrets are encrypted with a customer-managed KMS key. A Kubernetes service account for a third-party tool provides the secrets to applications by assuming an IAM role created to access Secrets Manager. The service account receives a 403 Forbidden when attempting to retrieve secrets. What is the root cause?
- An application running on EC2 instances in an Auto Scaling group processes a high volume of messages from an Amazon SQS queue. Processing a batch of messages took several hours, and the Auto Scaling group's average CPU utilization did not exceed the threshold of its target-tracking scaling policy. Application logs are sent to Amazon CloudWatch Logs. You need the queue to be processed faster with the least operational overhead. Which option satisfies this requirement?
- An application runs across Amazon EC2 and on-premises servers. Patching must be standardized across both environments and only occur during non-business hours. Which combination of actions satisfies these requirements? (Choose three.)
- An application runs in a single AWS Region on an Amazon EKS cluster and uses an Amazon Aurora MySQL cluster. Container images are built by AWS CodeBuild and stored in Amazon ECR. The company must replicate both the container images and the database state to a second Region with the least operational overhead. Which approach meets these needs?
- An application runs in a single AWS Region on EC2 instances behind an ALB with Auto Scaling and uses DynamoDB. A new office on another continent suffers high latency. How should you reduce latency and improve availability for users in both Regions? (Choose three)
- An application runs in two Regions. The primary Region uses an S3 bucket for data and a new bucket exists in the secondary Region. All existing and future objects must exist in both buckets, and failover between Regions must not lose data. Which combination of steps provides the required availability with the least operational overhead? (Choose three.)
- An application runs on an Auto Scaling group of On-Demand EC2 instances behind an ALB. The workload contains critical analysis that cannot tolerate interruptions and must scale quickly, and noncritical analysis that can tolerate interruptions and is memory-intensive. You must reduce scale-out latency for the critical workload while also processing the noncritical workload. Which combination of steps meets these requirements? (Choose two.)
- An application runs on EC2 instances behind an Application Load Balancer (ALB) across multiple Availability Zones. A misconfiguration in one AZ caused a partial outage. You need to test failover so the ALB avoids sending traffic to the failed AZ during a zonal shift. Which solution meets this requirement?
- An application stores PII in an S3 bucket encrypted with customer-managed KMS keys. All resources are deployed via CloudFormation. A dev environment in a different AWS account must be created from the template, and production S3 data must be copied weekly to the dev S3 bucket, but PII must be anonymized before leaving production. Each environment must use distinct KMS keys. Which combination of steps should the engineer take? (Choose two.)
- An application uses a MySQL-compatible Amazon Aurora Multi-AZ DB cluster with a cross-Region read replica for disaster recovery. The DevOps engineer needs to automate promotion of the replica to primary if the primary fails. Which solution will accomplish this?
- An application uses an Amazon CloudFront distribution with a public Application Load Balancer (ALB) in a Region as the default origin. The app is deployed to a secondary Region in a warm-standby setup and the business requires zero-second RTO for HTTP GET requests. How can failover to the secondary Region be automated so HTTP GETs meet that RTO?
- An application will run on an Amazon EKS cluster backed by Amazon EC2 nodes and must use an Amazon EFS filesystem through the installed EFS CSI driver. The EKS EC2 nodes fail to mount the EFS filesystem. Which remedies will resolve the issue? (Choose three.)
- An Auto Scaling group experienced failed EC2 instance launches that took hours to discover. The support team wants email alerts whenever an EC2 instance fails to start. Which action will provide that alerting?
- An Auto Scaling group launches EC2 instances from an AMI that already has the SSM Agent installed. Instances receive tags at launch. Instances must always have the correct OS configuration applied. Which solution ensures the instances have the required configuration immediately after launch?
- An automation account runs a CI/CD pipeline that creates new AWS accounts within an AWS Organization. A set of internal service teams operate from separate service accounts and want to receive CloudTrail events in their service accounts whenever the automation account calls the CreateAccount API to create a new account. What is the correct way to share those account-creation events with the service accounts?
- An AWS CodeBuild project is currently downloading a database population script from an S3 bucket using an unauthenticated request, which violates security policy. What is the most secure way to fix this?
- An AWS Organization (all features enabled) manages multiple accounts that run EC2 instances. The company requires that all current EC2 instances use Instance Metadata Service v2 (IMDSv2). They want to block any AWS API calls originating from EC2 instances that do not use IMDSv2. Which approach satisfies this requirement?
- An AWS Organization has an SCP at the root that allows IAM users to be created. DevOps must be able to create IAM users with any level of permissions and must be able to prevent other users from creating IAM users. Developers should be able to create IAM users but must not be able to grant excessive permissions. Developers have a CreateAndManageUsers role in each account. Which combination of steps will meet these requirements? (Choose two.)
- An AWS Organization is managed by a security team and a DevOps team; both use IAM Identity Center (SSO). The DevOps group has a permission set named DevOps with AdministratorAccess attached and applied to all accounts. The security team attached an SCP at the organization root to prevent DevOps from accessing IAM Identity Center in the management account, but DevOps can still access it. What change will block DevOps from accessing IAM Identity Center in the management account?
- An AWS Organization with one OU runs EC2 instances in member accounts. The company needs to ensure each EC2 instance’s credentials can only be used from the specific EC2 instance they are issued to. Which SCP configuration will enforce this?
- An EC2 instance in a VPC tries to download an object from a restricted S3 bucket but receives AccessDenied. What are possible causes? (Choose two.)
- An ecommerce company is building an AWS Control Tower landing zone and has configured the identity source in AWS IAM Identity Center (AWS SSO) to use an external SAML 2.0 IdP. The DevOps team wants a least-privilege permission model so each team can create and manage only its own resources. Which combination of actions will satisfy these requirements? (Choose three.)
- An ECS cluster on EC2 will no longer have internet access; NAT gateways and the internet gateway must be removed. ECS tasks must still pull images from private ECR repos and from a public ECR registry. Public images must be refreshed so new versions are available to the cluster within 24 hours. Which combination of steps (choose three) provides the required functionality with minimal operational overhead?
- An EKS cluster hosts an ML application whose model and container images have grown, causing pod startup times of minutes. The engineer must reduce startup times to seconds, including for pods scheduled on newly launched nodes. They created an EventBridge rule invoking an SSM Automation that prefetches images from ECR when new images are pushed and tag the cluster and node groups. What is the next step to meet the requirement?
- An EKS cluster using managed node groups hosts microservices. The team has installed the Kubernetes Metrics Server and wants Pods to autoscale based on a target CPU utilization percentage with minimal operational effort. What combination accomplishes this?
- An EKS cluster with EC2 node groups uses the Kubernetes Horizontal Pod Autoscaler and the EKS cluster Autoscaler. The DevOps team must collect cluster, node, and pod metrics and capture logs in CloudWatch to establish baseline thresholds. They need email notifications via SNS if thresholds are exceeded or if the Autoscaler fails. Which combination of steps should they take? (Choose three.)
- An EKS cluster with managed node groups and an associated OIDC provider fails to provision gp3 EBS volumes when a PVC is requested. kubectl describe pvc shows a StorageClass provisioning failure and EC2:UnauthorizedOperation when attempting to create the EBS volume. How can you fix this?
- An engineer used AWS CloudFormation to provision an Amazon ECS cluster and an EC2 Auto Scaling group for the container instances. After the stack completed, the EC2 instances launched but registered with a different ECS cluster than intended. What change should be made to the CloudFormation template to ensure the instances register with the correct ECS cluster?
- An existing CodePipeline in eu-west-1 stores build artifacts in an S3 bucket and deploys a Lambda using a CloudFormation deploy action. The pipeline must be updated to also deploy the Lambda to us-east-1. An additional artifact for us-east-1 has already been created. Which steps should the DevOps engineer take? (Choose two.)
- An HPC workflow builds container images with CodeBuild and pushes them to ECR, then deploys them to EKS. To meet compliance, images must be signed before EKS deployment; signing keys must be rotated automatically and signing events must be attributable to users. Which approach requires the least operational effort?
- An internal web application must call S3 APIs in a specific AWS account and the company wants to authenticate using its existing OpenID Connect IdP (auth.company.com). The IdP supports only OIDC. Which combination of steps will securely enable the web application to access S3? (Choose three.)
- An on-prem Go application must be moved to AWS. The dev team wants blue/green deployments and A/B testing capability. Which solution meets these requirements?
- An on-premises backend API serves requests for an API Gateway endpoint. Customers report high response latency, which API Gateway latency metrics confirm. To diagnose the issue, the team needs to collect relevant telemetry without adding extra latency to requests. Which two actions should they take? (Choose two.)
- An operations team needs to read AWS WAF logs and create alarms for patterns in those logs. The solution should require the least operational effort. What is the simplest way to provide log access and allow alarms to be created?
- An order-processing Lambda consumes messages from an Amazon SQS queue and writes results to a DynamoDB table. The Lambda runs with reserved concurrency. Customers report the order history page is delayed in showing processing status. Which actions should a DevOps engineer take to diagnose and fix the latency? (Choose two.)
- An organization centrally manages users from an operations account and disallows creating users in workload accounts. The operations team needs administrator access to each workload account. Which combination of actions will provide that access? (Choose three.)
- An organization has all features enabled in AWS Organizations, with 10 accounts now and plans to grow to ~500 accounts and multiple OUs. CloudTrail and AWS Config are enabled in existing accounts. How can you ensure AWS Config is automatically enabled for every new account created in the organization?
- An organization in AWS Organizations (all-features enabled) must ensure every EC2 instance in the organization's accounts has the CostCenter tag key and that the tag value is an approved cost-center value. Some developers add arbitrary values to avoid notifications from a scanning script. Which approach enforces correct tag keys and approved values across the OU?
- An organization in AWS Organizations uses all-features and a hierarchy of OUs under the root. All OUs and accounts have been registered and enrolled in AWS Control Tower. The company must apply custom changes to the AWS Config configuration recorder in every current account and ensure the same customizations are applied automatically to any accounts enrolled into Control Tower in the future. Which set of steps meets this requirement?
- An organization manages 500 AWS accounts under AWS Organizations and finds many unattached EBS volumes. They want a Lambda function deployed to every account that runs every 30 minutes and tags EBS volumes that have been unattached for 7 days or more. Which approach is the most operationally efficient?
- An organization requires governance with these constraints: restrict resource access to the same two Regions for all accounts; limit allowed AWS services to a specific set; use Active Directory for authentication; and have identical job-function-based permissions in every account. Which solution meets these requirements?
- An organization uses AWS Control Tower to manage its AWS Organizations landing zone and has defined an OU structure and core accounts. The DevOps team created a centralized account to host CloudFormation and AWS Service Catalog resources. The company wants to let member accounts request a set of customizations through AWS Control Tower. Which steps, taken together, will provide this capability? (Select three.)
- An organization uses AWS Organizations (all features enabled) and AWS Backup in a primary account that encrypts backups with a KMS key. The company set up cross-account backups to a new account's backup vault and created a KMS key in the new account. When a backup job runs in the primary account, backups are created locally but are not copied to the new account's vault. Which steps must be taken so backups can be copied to the new account's backup vault? (Choose two.)
- An organization uses AWS Organizations to manage multiple accounts. Security policy requires marking any unencrypted Amazon EBS volumes as noncompliant. A DevOps engineer must deploy an automated, always-present compliance check. Which approach accomplishes this?
- An organization uses AWS Organizations with a root OU and a child OU. The root OU's SCP allows all actions on all resources. The child OU's SCP allows all DynamoDB and Lambda actions and denies all other actions. There is an account named vendor-data in the child OU. An IAM user in that account has the AdministratorAccess IAM policy but receives AccessDenied when attempting to launch an EC2 instance. What change should be made so the IAM user can launch EC2 instances in the vendor-data account?
- CloudWatch Logs send log data to a Kinesis data stream that a single consumer Lambda reads and writes to S3. The team observes high latency for some log processing and ingestion. Which actions will reduce that latency? (Choose three.)
- CodeDeploy is doing in-place deployments across EC2 instances in an Auto Scaling group using the CodeDeployDefault.OneAtATime configuration. After a deployment finishes, two of five instances still run the previous revision while three run the new one. What is the most likely cause?
- Developers assume the AWS CDK deployment role to deploy infrastructure that includes Lambda functions and their IAM roles. A security review found the developers and the CDK deployment role have excessive permissions, and the Lambda roles created by CDK are overly permissive. Developers must not be able to grant additional permissions. Which approach meets the requirement with the least operational overhead?
- Developers must tag all Amazon EBS volumes with a Backup_Frequency tag (values: none, daily, or weekly). Some volumes are sometimes left untagged. The company requires that all EBS volumes always have a Backup_Frequency tag and that the default is at least weekly when unspecified. Which solution enforces this requirement?
- Developers use AWS CodeCommit with feature branches and pull requests to merge changes into the main branch. They must be prevented from pushing directly to the main branch. Developers were granted the AWSCodeCommitPowerUser managed policy, which currently allows direct pushes to main for every repository. How can the company prevent developers from pushing directly to the main branch?
- Developers use EC2 instances as remote workstations. The company wants to detect when users create or modify security group rules that allow unrestricted inbound access, remove those rules automatically, and notify the security team by email in near real time. A Lambda function exists that, given a security group ID, removes rules that allow unrestricted access and publishes notifications to an SNS topic. What step should the DevOps engineer take next to meet the requirements?
- Developers use Linux EC2 instances as bastion hosts with SSH access restricted by security group rules to specific IP addresses. The security team must be notified if those security group rules are changed to allow SSH from any IP address (0.0.0.0/0). What should the DevOps engineer implement to satisfy this requirement?
- EC2 instances in an Auto Scaling group created by CloudFormation require a configuration file maintained in source control. Instances should have the latest configuration at launch, and changes to the CloudFormation template should be reflected on all instances with minimal delay. Which solution achieves this?
- Employees connect to EC2 instances over RDP and you must count how many RDP sessions are initiated each day. Which steps (choose three) will collect metrics for daily RDP session counts?
- Employees have limited AWS permissions, but DevOps engineers can assume an administrator role. The security team needs near-real-time notifications whenever the administrator role is assumed. What should be implemented?
- GuardDuty is producing many findings from suspicious sources. How can you automatically block traffic across the VPC whenever GuardDuty identifies a new suspicious source?
- How can the team run integration tests against a copy of the production Amazon RDS Multi-AZ DB cluster before applying changes to production?
- How can you prevent developers from attaching an Elastic IP to production EC2 instances and ensure the security team is alerted if any production instance has an Elastic IP at any time?
- If you remove the FullAWSAccess policy from the Development OU and attach a policy that allows all actions on EC2 resources, what is the resulting effective permission for users in the Development OU?
- In a multi-account setup, the company routes all outbound traffic through a Transit Gateway into a network operations account. There, traffic is inspected by a firewall appliance before reaching the internet gateway. The firewall writes logs to CloudWatch Logs and classifies events as CRITICAL, HIGH, MEDIUM, LOW, and INFO. The security team must be alerted whenever any CRITICAL events appear. What should the DevOps engineer implement to satisfy this requirement?
- Instances currently launch in a public subnet and use a user-data script to download and install application artifacts from the internet. A new security classification requires the instances to have no internet access, and although instances launch healthy, the application is not installed. Which approach will install the application while ensuring no internet access?
- Logs are stored in CloudWatch Logs and must be archived to S3, be rarely accessed after 90 days, and retained for 10 years. Which combination of steps should the DevOps engineer take? (Choose two.)
- Multiple applications in one account send logs to CloudWatch. A data analytics team must collect application performance and custom metrics, transform them, and store the transformed metrics in S3. Any new metrics added to the CloudWatch namespace must be collected automatically. Which solution has the least operational overhead?
- Multiple development groups share a single AWS account. A senior manager wants to be notified via a third-party API call when resource usage approaches service limits, and expects the least development effort. Which solution achieves this with minimal development work?
- Multiple development teams share a single AWS account. All EC2 resources must be tagged within one hour of creation with the creator's user ID and a cost center ID. CloudTrail logs are delivered to an S3 bucket. The engineer wrote a Lambda to apply cost-center tags. Which solution ensures resources are tagged promptly and reliably?
- On-premises devices retrieve configuration files from an Amazon EFS filesystem over a Direct Connect link. Traffic must remain private and encrypted, devices must follow least-privilege AWS access, and operators need to revoke access for a single device without impacting others. Which steps satisfy these requirements? (Choose two.)
- Production account policy requires any EC2 instance that has been accessed interactively to be terminated within 24 hours. All production apps run in Auto Scaling groups and send logs using the CloudWatch Logs agent. How can you automate detecting a manual login and ensuring such instances are terminated within 24 hours?
- Raw data is stored in an S3 bucket. Three different applications must access the raw data, but each application requires different redaction before reading it. What solution meets this requirement so each app gets redacted data independently?
- RDS storage autoscaling is enabled for several DB instances. The DevOps team wants to show autoscaling events on a CloudWatch dashboard. Which approach will produce a CloudWatch metric they can graph for autoscaling events?
- Teams use CodeCommit repositories across multiple AWS accounts within an AWS Organization. Developers sign in via IAM Identity Center with an external IdP and assume a developer role to use Git. A security review found developers can modify the main branch of any repository. You must restrict each team so they can only modify the main branch of repositories they own. Which combination of steps will enforce this? (Choose three.)
- The application requires an RPO of 2 hours and an RTO of 10 minutes. The app uses a MySQL database and EC2 web servers. Which combination of deployment choices will satisfy these recovery objectives? (Choose two.)
- The application writes access logs to a CloudWatch Logs log group; each log line contains the response code and application name. You need a CloudWatch metric that counts requests whose response code falls within a specific range and that have a specific application name. What approach satisfies this requirement?
- The CI pipeline builds container images with CodeBuild and stores them in ECR. The security team needs fast detection and notification of image vulnerabilities with minimal operational overhead. Which combination of actions (choose two) meets this need?
- The company changed corporate network IP ranges. Ten S3 buckets across different accounts restrict access to the private corporate network range. Two organizational units (OUs) must have their access revoked. How should you update the buckets and revoke access for the two OUs?
- The company has many apps built with different languages and frameworks, running on-premises across various OSs. Each team has its own release process. The company wants centralized source control, a consistent automated delivery pipeline, and minimal infrastructure maintenance after migrating to AWS. What approach meets these goals?
- The company is organized into teams, each owning an AWS account within an AWS Organizations organization. Teams must retain full admin privileges in their own accounts, but they may only use AWS services that have been approved through a request-and-approval process. How should a DevOps engineer enforce this policy across accounts?
- The company manages many accounts in Organizations and wants preventive and detective controls applied now and automatically to any accounts created later. Which solution provides guardrails across current and future accounts?
- The company must encrypt all AMIs that are shared across accounts. You have an unencrypted custom AMI in the source account, and an Auto Scaling group in the target account will launch EC2 instances from the AMI. A KMS key exists in the source account. Which additional steps are required? (Choose three.)
- The company needs a solution to query application logs from EC2 instances and AWS account API activity. Which setup satisfies this requirement?
- The company needs to ensure VPC flow logs are enabled for all current and future VPCs in the account. VPCs are managed with a CloudFormation stack, but users may create VPCs directly. Which approach enforces flow logs for existing and newly created VPCs by any IAM user?
- The company runs applications in AWS accounts that are members of an AWS Organizations organization. Those applications use Amazon EC2 and Amazon S3. The company wants to detect compromised EC2 instances, suspicious network behavior, and unusual API calls across current and future accounts. When such events are detected, the company wants to publish a notification to an existing Amazon SNS topic used by its operations team. Which approach meets these requirements and follows AWS best practices?
- The company runs tests in a single AWS account on Amazon EC2 instances. AWS Config is enabled with the restricted-ssh managed rule. The team needs an automated, real-time notification that is customized and includes the noncompliant security group's name and ID whenever any security group violates the restricted-ssh rule. An SNS topic already exists with the appropriate subscribers. What should the DevOps engineer do next to meet this requirement?
- The company stores CloudFormation templates and Docker images in one Region and needs a DR process in another Region with an RPO of 8 hours and an RTO of 2 hours. Building images can sometimes take longer than 2 hours. Which cost-effective solution meets the RPO and RTO?
- The company uses an AWS Organizations organization to manage developer accounts. All data must be encrypted in transit, but several S3 buckets in developer accounts currently allow unencrypted (non-SSL) requests. A DevOps engineer must enforce TLS (SSL) for data in transit for every existing S3 bucket in accounts in the organization. Which approach satisfies this requirement?
- The company uses RDS for all databases and AWS Control Tower to manage accounts. All databases must be encrypted at rest. The security engineer must be notified about any noncompliant (unencrypted) RDS instances across accounts. Which solution provides the most operational efficiency?
- The company wants notifications if new vulnerabilities are discovered on EC2 instances and also needs an audit trail of all login activity on the instances. Which solution meets both needs?
- The company wants to replace its bash deployment scripts with AWS developer tools while preserving these deployment steps: run unit tests, stop/start services, unregister and re-register instances with an ALB, and update file permissions. Which solution will provide the same deployment functionality using AWS services?
- The DevOps engineer must automate restarts for several EC2 instances after receiving AWS Health notifications, and the remediation must run only during the company’s scheduled maintenance windows. How should an Amazon EventBridge rule be set up to trigger Systems Manager to restart the instances?
- The EKS cluster runs pods whose images are in ECR. Node IAM role permissions for Pod Identity have already been updated. What else is required to provide Pod Identity access for pods running in the cluster?
- The environment uses IAM Identity Center for all users. The security team wants any new IAM user’s credentials disabled immediately and to receive a notification. Which combination of steps should be taken? (Choose three)
- The organization delegates a specific IP address range for VPC CIDRs and non-cloud hardware. You must prevent principals outside the company IP range from performing AWS actions across the organization’s accounts. Which approach will enforce this requirement?
- The organization uses AWS Organizations and enabled AWS Config across member accounts via CloudFormation StackSets. Trusted access is enabled and a member account is the delegated administrator for AWS Config. The security team needs a centralized security baseline of AWS Config rules (including remediation actions) that is enforced for all existing and future member accounts. Non-admin users in member accounts must be prevented from modifying the centrally managed baseline. Which approach satisfies these requirements?
- The SecOps team must receive an SNS email notification if any member account in the organization disables S3 Block Public Access at the bucket level. The solution must not rely on changes in member accounts and must prevent member accounts from disabling the notification. Which solution meets these requirements?
- The security team must ensure CloudTrail stays enabled across all accounts in an AWS Organization and prevent account users from turning it off. Which control will enforce this?
- The security team relies on CloudTrail to detect critical security issues. The DevOps engineer needs to automatically remediate when CloudTrail logging is turned off, and wants the solution to minimize downtime for CloudTrail log delivery. Which approach provides the least delay?
- The security team requires that all internet-facing Application Load Balancers (ALBs) and Amazon API Gateway APIs have AWS WAF web ACLs. The organization has hundreds of AWS accounts in AWS Organizations and AWS Config is enabled. Some externally facing ALBs are not associated with WAF web ACLs. Which steps should the DevOps engineer take to prevent future violations? (Choose two.)
- The security team uses manual AWS KMS key rotation and needs notifications when any customer keys have not been rotated for more than 90 days. Which solution accomplishes this?
- To prevent loss of SNS notification messages when the downstream RDS database is unavailable (for example, shut down), which changes will prevent message loss? (Choose two.)
- To provide a secondary-Region CodeCommit repository that developers can add as a remote and keep up to date after merges in the primary Region, which approach meets the requirement?
- Using AWS Control Tower and CloudFormation, the company requires that every S3 bucket created by CloudFormation in the multi-account environment must be encrypted with AWS KMS keys. Which approach enforces this requirement?
- Using AWS Control Tower management account and CloudFormation StackSets, a DevOps engineer must enable Amazon GuardDuty for accounts that have not already enabled it. To avoid StackSets deployment failures, how should the CloudFormation template be designed?
- Which combination of steps will ensure that only the Lambda function's execution role can access a Secrets Manager secret encrypted with KMS, following least-privilege principles? (Choose two.)
- Which solution will, with minimal development effort, detect AWS service misconfigurations across all organization accounts near real time, automatically remediate within 15 minutes, and provide a centralized dashboard with accurate timestamps?
- You are authoring a CloudFormation template to deploy a web service on EC2 instances in a private subnet behind an Application Load Balancer (ALB). The service must accept requests from IPv6 clients. What changes should you make in the template so IPv6 clients can reach the service?
- You are configuring a blue/green deployment for an ECS application using AWS CodeDeploy and CloudFormation. During the deployment window the app must remain highly available and traffic should shift 10% to the new version every minute until fully shifted. What CloudFormation configuration accomplishes this?
- You configured an Amazon S3 event source to trigger an AWS Lambda function when objects are created or updated in a specific S3 bucket. The Lambda uses the bucket name and object key from the event to read the object and parse its contents, then writes parsed data to a DynamoDB table. The Lambda's execution role has permissions to read the S3 bucket and write to DynamoDB, but the function is not invoked when objects are added or modified. What fixes the issue?
- You deploy an application across Amazon Linux EC2 instances and need to monitor system metrics fleet-wide. You want to observe the relationship between network traffic and the application's memory usage, with metrics collected at 60-second intervals. Which approach meets these requirements?
- You must apply a core set of security baseline resources across existing AWS accounts in an Organization. Account teams have AdministratorAccess per account. CloudTrail and AWS Config must be enabled in all Regions and baseline resources must not be editable or deletable by individual account admins, but those admins must be allowed to edit/delete their own CloudTrail trails and AWS Config rules. Which solution is the most operationally efficient?
- You must centralize CloudWatch Logs into an S3 bucket in a dedicated AWS account for all current and future log groups across your organization. Which solution accomplishes this?
- You must identify the top users and roles across every AWS account in an organization (Organizations with all features enabled) to improve security. Which approach provides the most operational efficiency for finding the top users and roles?
- You must install antivirus software on every Amazon Linux EC2 instance in an account. The solution must discover all instances and use a Systems Manager document to install the software when it’s absent. Which implementation satisfies the requirements?
- You must migrate a Linux application to AWS that requires specific versions of Tomcat, HAProxy, and Varnish, needs OS-level tuning, automated application version deployments, scalable infrastructure, and automatic replacement of unhealthy servers. Which solution should you use?
- You need a CloudWatch alarm that stops EC2 instances when the average NetworkPacketsIn is less than 5 for at least 3 hours within a 12-hour window, evaluating hourly, and instances must continue running if metric data is missing during the evaluation. The alarm uses a threshold of 5 and a 1-hour evaluation period. What additional settings are required?
- You need a deployment stage for a serverless app (AWS Lambda) that minimizes customer impact from failed deployments and provides monitoring for issues. Which deployment configuration meets these goals?
- You need a weekly-published standard base container image to be available in us-west-2, us-east-2, and eu-central-1. Which solution meets this requirement with minimal operational complexity?
- You need an automated, organization-wide process to isolate compromised Amazon EC2 instances when they receive a specific tag. Which combination of steps will implement this across all accounts? (Choose two.)
- You need the cheapest approach to run an EC2-based image batch processing cluster. The job cannot use containers, stores checkpoints on NFS, tolerates interruptions, and takes 30 minutes to configure a generic Linux EC2 instance. What is the MOST cost-effective design?
- You need to add integration tests to an existing CodePipeline workflow that builds a container image for an Amazon ECS service and pushes the image to ECR with a new tag. The tests must verify that the new service version is reachable and that API endpoints return successful responses. An ECS cluster for testing already exists. Which three actions provide this with the least management overhead?
- You need to deploy an IAM role to the Organizations management account and all member accounts using CloudFormation, with the least operational overhead. Trusted access for CloudFormation is enabled and the organization has 10 accounts. Which approach meets the requirement with minimal operational work?
- You need to enforce server-side encryption for all EBS volumes and SQS queues created or updated by CloudFormation stacks in all accounts within a specific OU, and enforcement must occur before CloudFormation stack operations. Which solution will enforce this across the OU?
- You need to perform a blue/green deployment for a three‑tier app on EC2 with RDS. Blue and green environments each have their own launch template, Auto Scaling group, and target group; the ALB can route to either target group and Route 53 points at the ALB. The deployment requirement is to switch all traffic at once from blue to green once the green instances have the new software. What should you do?
- You operate hundreds of EC2 instances in a single region within one AWS account. New instances are launched and terminated hourly; some existing instances have been running more than a week. Company policy mandates that every running EC2 instance must have an instance profile attached. There is a default instance profile that must be attached to any instance missing a profile. Which approach enforces this requirement?
- Your fleet of Amazon Linux EC2 instances is managed with AWS Systems Manager; SSM Agent is installed and all instances use IMDSv2. Company policy requires developers to use only Amazon Linux. You need all newly created EC2 instances to be automatically managed by Systems Manager with the most operational efficiency. Which solution accomplishes this?
- Your organization uses AWS Control Tower and enrolled all existing accounts. You want all newly created AWS accounts to be automatically enrolled in Control Tower. You have an existing Step Functions workflow (in the same account as Control Tower) that creates new accounts. Which two steps should you add to the workflow to ensure new accounts are enrolled in Control Tower? (Choose two.)
- Your organization uses AWS Organizations and Control Tower and holds an Enterprise Support plan. You provision new accounts using Account Factory for Terraform (AFT), but newly created accounts default to Basic Support. What change ensures new accounts are created with Enterprise Support?
- Your organization uses AWS Organizations and has an IAM team that will manage AWS IAM Identity Center. The IAM team must have only the minimum permissions needed to administer Identity Center and must not obtain unnecessary access to the Organizations management account. The team must be able to create new Identity Center permission sets and assignments for both new and existing member accounts. Which combination of steps satisfies these constraints? (Choose three.)
- Your Python application code is stored in AWS CodeCommit and the deployment pipeline uses AWS CodePipeline in the same account. Company security policy requires all code be scanned for vulnerabilities before production deployment, and any findings must stop the deployment. Which solution meets this requirement?
Amazon DSP All exam questions
- Amazon DSP allows you to create and download custom reports and configure reports with specific metrics and dimensions to suit your campaign goals.
- Amazon DSP campaigns can link to an Amazon destination, such as a product detail page on Amazon.com as well as non-Amazon destinations, such as a brand's website.
- Amazon DSP is available to advertisers that both sell and do not sell in the Amazon store.
- Amazon Publisher Direct (APD) provides advertisers direct access to a vast number of premium connected TV (CTV), video, and display, and publishers around the world.
- Anand is considering using Amazon Publisher Director (APD) and third-party exchanges to accessing more inventory sources. Which of the following best describes the benefits of this approach?
- Audiences that allow you to reach shoppers who view content on Prime Video, IMDb, Twitch, and Kindle, are best described as:
- Bhindi runs ads for a brand that does not sell products or services in the Amazon store. They want to include pricing or savings for a static banner display ad. What must they do to ensure this creative is compliant with Amazon Ads guidelines and acceptance policies?
- Danbi noticed their display campaign had high impressions, but did not receive many views. This most likely indicates that:
- Display ads on Amazon.com must always contain the advertiser's brand name and/or logo.
- For any conversion event, the “total” metric will include both brand halo conversions and promoted conversions.
- Gerald is writing copy for their upcoming display campaign to promote their new sunscreen. Which copy would meet policy requirements?
- Harout is currently using Sponsored Products with keyword targeting to reach shoppers while they browse Amazon products. However, they see an opportunity to run additional campaigns to help drive awareness for their brand's offerings. Using Amazon DSP, what would you recommend?
- Jack and Jill want to run an ad with copy that reads "Learn more about our brand". Is this copy compliant with policy?
- Jean-Pierre is looking to run a display campaign to help drive awareness for their financial services company, which does not sell products in the Amazon store. How can they use Amazon DSP to achieve their goal?
- Jiwoo is interested in growing awareness for their brand using Amazon DSP. What would be the best way for them to get started?
- Josue wants to create a display campaign that links to their Amazon product detail page. Why must they use eCommerce display ads for this?
- Kitchen Smart wants to run an ad with copy that creates a sense of urgency for their new food processor that reads "Hurry, buy now!" Is this compliant with Amazon Ads guidelines and acceptance policies?
- Mak is analyzing and reviewing the inventory forecast for their recent consideration campaign, and noticed that of the ten audiences they included, in-market audiences are outperforming others. What would be the best way to optimize this campaign?
- Programmatic advertising uses software to automate the process of buying and selling digital ad inventory through real-time auctions.
- Ralf is looking to run a full-funnel campaign using Amazon DSP. They are planning to run a video campaign focused on driving reach and a display campaign using ASIN re targeting to drive conversions. What type of campaign would you recommend to further support this strategy?
- Renaldo is writing copy for their upcoming display campaign to promote their new digital watches. Which copy would meet policy requirements?
- Romane noticed their display campaign had a high detail page view rate, but low conversion rate. This most likely indicates that:
- size responsive ads. The ad experience is constructed using ASIN details from the product detail page is correct because Advertisers can use Amazon DSP as part of a full-funnel approach to build brand awareness when shoppers may not be actively shopping by serving ads across thousands of popular apps and third-party websites.
- thousands of brand-safe websites, devices, ad formats as part of a single campaign is correct because Amazon DSP enables Finnigan wants to grow new-to-brand sales. Which campaign strategy would best help them achieve this goal?
- To create a custom report focused on segmentation analysis, which of the following dimensions would you select when generating your report?
- Video ads purchased on Amazon DSP includes which of the following formats?
- Wenjing is a campaign planner at an agency. They have a client who sells car insurance and do not offer any products for sale in the Amazon store. Is this company eligible to use Amazon DSP?
- What Amazon DSP feature allows advertisers to improve their campaign performance by automatically adjusting bids based on the predicted likelihood of a user converting?
- What are the different pricing models available for programmatic ads on Amazon DSP?
- What are the main benefits of using Amazon DSP?
- What breakdowns are available in custom reports to analyze inventory?
- What can brand halo help advertisers better understand?
- What is a key benefit of the user interface offered by Amazon DSP?
- What is a key feature of Amazon DSP that allows advertisers to reach a wide range of audiences?
- What is a recommended best practice for setting up Amazon DSP campaigns to improve performance?
- What is the benefit of using "Prioritize KPI target" when setting up bidding priority during campaign setup?
- What is the primary benefit of the budget optimization feature in Amazon DSP campaigns?
- What is the primary benefit of the real-time capabilities of a demand-side platform (DSP) in programmatic advertising?
- What is the primary purpose of a demand-side platform (DSP)?
- What is the standard attribution window for Amazon DSP?
- What mechanism does programmatic advertising uses to deliver the most effective ads to audiences?
- What time unit breakdowns are available for campaigns with custom reporting?
- Where can audio ads purchased with Amazon DSP run?
- Where on Amazon DSP can advertisers explore and select the best creative assets to optimize their campaigns?
- Which Amazon DSP service model allow advertisers to create campaigns on their own and without insertion orders?
- Which Amazon DSP service model provides full programmatic campaign management and is billed using an insertion order?
- Which best describes brand halo conversion?
- Which best describes the benefit of running cross-device campaigns?
- Which best describes the benefit of using the Discovery tab in Amazon DSP?
- Which is the most significant benefit of using Amazon DSP for brands that do not sell their products in the Amazon store?
- Which metric would best reflect success in driving awareness?
- Which metric would best reflect success in driving consideration?
- Which metric would best reflect success in driving conversion?
- Which metric would best reflect success in driving loyalty?
- Which of the following are best described as components supplied by the advertiser, or pulled directly from the product detail page, to automatically generate creative variants using the ad components, such as a headline, description, and image?
- Which of the following best describes "Prioritize spending full budget, while maximizing performance" when setting bidding priority during campaign setup?
- Which of the following best describes a common use case for Amazon Ad Tag (AAT)?
- Which of the following best describes Amazon Ads guidelines and policies around claims?
- Which of the following best describes asset-based creative (ABC) for display ads?
- Which of the following best describes brand safety pre-bid targeting?
- Which of the following best describes Performance+ audiences?
- Which of the following best describes the conversion rate?
- Which of the following is best described as a creative that traffics shoppers to an Amazon store page and uses advertiser’s uploaded ad components?
- Which of the following is best described as measurement of aggregated audience interactions with ads that have contributed to an advertiser’s goal?
- Which of the following is the correct hierarchy for campaign setup in Amazon DSP? Top line starts from left to right.
- Which type of goals do Performance+ campaigns best support?
- Why does Amazon DSP prioritize clicks over views when assessing attribution?
- You are working on a new display ad and want to add a custom image. What is the maximum word count allowed in a custom image?
- Zoya is analyzing their recent campaign, and notice that certain supply sources are performing better than others across key metrics. What would be the best way to optimize their campaign?
Amazon DSP Advanced All exam questions
- A customer purchases a product from your brand that is not a tracked ASIN for your campaign. The purchase will be counted as a brand halo purchase, allowing you to understand the overall lift in brand-wide conversions from your campaign.
- A customer views an ad, clicks on the ad, and then makes a purchase. What type of activity is this?
- A non-endemic advertiser wants to exclude existing customers from their new-to-brand campaign. Which audience solution allows them to do this most effectively?
- A shopper interacts with ads from two different campaigns from the same brand, they first click an ad promoting the brand's mirrorless cameras and later click an ad promoting the brand’s camera cases. The shopper ends up purchasing the mirrorless camera after clicking on the ad for the camera cases. Conversion will be awarded to which campaign?
- A shopper interacts with ads from two different campaigns from the same brand, they first click an ad promoting the brand's mirrorless cameras and later click an ad promoting the brand’s camera cases. The shopper ends up purchasing the mirrorless camera from the brand. Purchase conversion will be awarded to which campaign?
- A shopper's journey to purchasing a coffee maker on Amazon over a 20-day period involved the following interactions: -March 5 - Sponsored Products ad view -March 12 - Sponsored Brands ad view -March 17 - Video ad view -March 20 - Purchase Based on Amazon Ads' attribution methodology, which ad interaction will be credited for this conversion?
- A shopper’s journey to purchasing a laptop on Amazon over a 20-day period involved the following interactions: -March 5 - Sponsored Products ad view -March 15 - Display ad click -March 17 - Video ad view -March 20 - Purchase Based on Amazon Ads' attribution methodology, which ad interaction will be credited for this conversion?
- A skincare brand wants to reach females who are in-market for either beauty products or haircare. How should they set up their audience targeting?
- Ads are only eligible for conversions if users have either clicked or viewed the ads.
- All content must be served from the ad server’s domain and may not call from other domains.
- All lines in an order are opted into budget optimization, but the most efficient line has the lowest allocated budget. What is an optimization you could make to help allocate more budget to that top-performing line?
- Amar, an advertiser, wants to track traffic on his brand’s website as well as physical retail transactions. What tool could he use to track both things?
- Amazon Ads enables you to create brand-based audiences around which of the following behavior types? Select All Correct Responses
- Amazon Ads is integrated with multiple supply-side platforms (SSPs), meaning you can easily access your negotiated inventory with third-party suppliers via Amazon DSP, and run all of your campaign strategies in one place.
- Amazon Advertising tag (AAt) supports conversion insights.
- Amazon Advertising tag (AAt) supports conversion insights. Therefore, you do not need to use a simple conversion pixel for conversion insights, optimization, and reporting.
- Amazon DSP supports creation of lookalike audiences from:
- An advertiser is looking to secure inventory on the homepage of xyz.com and wants to buy it for $20 CPM. Entering into which type of private marketplace deal with the publisher would guarantee their inventory at a fixed price?
- An advertiser selling products in the Amazon store implements Amazon Ad Tag (AAT) on their external website. What is the primary benefit of this strategy?
- An advertiser wants to exclude existing customers from their new-to-brand campaign. Which audience solution allows them to do this most effectively?
- An advertiser wants to expand their reach using audiences that don't rely on cookies. Which of the following should they choose that best meets these requirements?
- An advertiser who sells products on their own website, but not on Amazon, wants to use Amazon DSP to improve their advertising strategy. Which of the following is the MOST appropriate use of Amazon Ad Tag (AAT) for this advertiser?
- An advertising agency is simultaneously running 25 campaigns for their client. While they want to maximize performance, they also want to minimize manual campaign manipulation. Which optimization strategy should they choose?
- Arturo is planning the creative strategy for an upcoming campaign. What is the best approach to take?
- Attribution reinstatements occur 10 days, 2 weeks, and 4 weeks after the original conversion is attributed to a campaign. This process then occurs on a rolling basis following each reinstatement.
- Attribution restatements occur 10 days, 2 weeks, and 4 weeks after the original conversion is attributed to a campaign.
- Automate budget allocation will detect low spending line items (less than $5 a day) and shift remaining budget to higher spending line items within the campaign.
- Automated budget optimization will detect low spending line items (less than $5 a day) and shift remaining budget to higher spending line items within the campaign.
- Beatrix is interested in using a third-party measurement provide to get additional metrics on placements like Streaming TV ads and mobile apps. Which solution would you recommend for their use case?
- Bjorn is using a third-party tag for their upcoming display campaign, but the third-party tag indicates it is “Unrecognized” in Amazon DSP. How would you help them troubleshoot this issue?
- Bulksheets are recommended to manage:
- Bulksheets are recommended to manage: Select All Correct Responses
- Bulksheets are which file format?
- By choosing the “While spending full budget, maximize performance” bid strategy, you want to maximize your campaign performance at a given base bid.
- Choosing this simple pixel type allows you to manage fewer pixels and gives more flexibility when embedding them.
- Creative macros are short commands or shortcuts for commands used to pass back metrics to a third party.
- Creative macros can be used to allow third-parties to view metrics to provide greater visibility into third-party creatives served through Amazon DSP.
- Dev has uploaded a creative including their brand logo, a call to action to “shop now”, high quality imagery, legible text, the prime day logo, and 15 second animation. The creative was rejected due to non-compliance with creative guidelines. Why was the item non-compliant?
- Fill in the blank: If the projected spend of all line items sums to an amount less than your order budget, then your budget is _______
- Finn has submitted a video advertisement intended to promote an upcoming sale. The ad includes the brands logo, a "Learn More" button, high-resolution product shots, clearly readable text, a seasonal discount banner, and a 15-second animation. The ad was rejected for not meeting creative guidelines. What caused the ad to be non-compliant?
- For your campaign to receive credit for conversions, you must associate the appropriate ASINs or events to your campaign in order settings.
- Harshdip is running a campaign with the ‘Prioritize target KPI’ bid strategy and is pacing at 100% but not hitting the desired goal KPI. What optimization strategy can the advertiser use to improve performance?
- How do Amazon Publisher Cloud (APC) deals differ from traditional contextual deals on the web?
- How will conversions be impacted (if at all) after a campaign ends?
- Hyunh is working on a campaign and wants to ensure that they spend the full amount of their budget during the campaign flight. Which bidding priority should they use to meet this goal?
- If a campaign is under delivering and the advertiser wants to catch up without spending the entire budget immediately, which pacing profile is most appropriate?
- If a campaign is underdelivering and the advertiser wants to catch up without spending the entire budget immediately, which pacing profile is most appropriate?
- If Amazon Ads has an existing server-to-server integration with a third-party measurement provider, you must use the adapter URL Amazon Ads provides, you cannot use a pixel.
- If you associate two events to an order, and they both have the same conversion name, the combined ad-attributed conversions for both those events will be aggregated into one column in reporting.
- If you have an existing server-to-server integration with a third-party measurement provider, you must use the adapter URL Amazon Ads provides, you cannot use a pixel.
- If you use third-party served creatives in Amazon DSP, which of the following policies are true? Select All Correct Responses
- If you want to control your pacing and performance trade-off for your advertising campaign, what is the best option to choose in order settings?
- Is it a best practice to select multiple private marketplace deals on the same line item?
- Jason, an advertiser for a brand that does not sell on Amazon, is running a link out campaign and wants to drive traffic to his automotive website. What type of component-based creative should Jason use to achieve this?
- Johan wants to reach potential customers who have shown interest in their products but haven't purchased yet. Which audience solution is most appropriate?
- Jose wants to run a campaign during Black Friday and Cyber Monday, aligning their brand with relevant content. Which deal package would be most appropriate for this purpose?
- Kaia received notification that a digital camera creative was rejected. The creative showcases the "Iris Snapshot 3" model. However, the landing page linked in the ad features the "Iris Snapshot 3 Lite" version. Why was this creative rejected based?
- Luan wants to reach shoppers who have shown interest in their products or similar products on Amazon.com. In order to engage audiences based on shopping behaviors, which type of signals should they use?
- Luan wants to reach shoppers who have shown interest in their products or similar products on Amazon.com. Which type of signals should they use?
- Marion is running a campaign, but observes that the performance and delivery are both low. What action would you recommend they take?
- Morgan wants to combine data from various sources, including their own signals and Amazon DSP data. Which tool should they use to analyze the data and create custom audiences?
- Mounira wants to create a custom audience based on interactions with their Streaming TV ads. Which custom solution should they use?
- Mounira wants to create a custom audience based on interactions with their Streaming TV ads. Which type of signals should they use?
- Multiple buyers can participate, delivery is not guaranteed, and no priority access is typically offered versus open auction buying. This describes which type of deal?
- reached its frequency cap for that user, and The Amazon Ads view ability threshold set for the line item did not meet the Which auction type is a digital buying model where the highest bidder above the floor price wins the auction, and pays exactly the amount they bid?
- Select all settings you must adjust when setting up a private marketplace deal in Amazon DSP. Select All Correct Responses
- Serena, an advertiser, notices that her latest Amazon Ads campaign is showing significantly different attribution results compared to the previous campaign she ran earlier in the year. Review the factors that she identifies: -The campaigns leveraged the same strategy. -One campaign yielded more clicks and conversions. -One campaign was running during Black Friday, while the other ran during the spring time. Which of the factors is most likely to cause differing attribution results between two Amazon Ads campaigns?
- the Amazon store and third-party websites, enabling campaign optimization and reporting because the primary purpose of Events Which of the following is not a benefit of "prioritize KPI target" type of bidding priority?
- third-party tag in the tag source section of creative settings.
- Third-party video creative type supports which of the following third-party tags?
- To encourage repeat purchases from existing customers who bought products within the last year, which audience type should a brand use when promoting complementary products?
- Ursus is interested in expanding reach of their ads beyond Amazon O&O. Which supply source would you recommend they consider?
- Using the audience builder in Amazon DSP, you are able to create custom audiences based on which of the following? Select All Correct Responses
- Vanessa, an advertiser selling in the Amazon store wants to set up a creative to drive traffic to specific product detail pages. What type of component-based creative should Vanessa use to achieve this?
- What does ASP (Additional Spend Potential) represent in Amazon DSP?
- What does interoperability with third-party ad IDs allow advertisers to do?
- What is a benefit of server-to-server (S2S) integration s in Amazon DSP?
- What is a benefit of server-to-server (S2S) integrations in Amazon DSP?
- What is a key benefit of using a data management platform (DMP) to transfer existing audiences to Amazon DSP for activation in your Amazon Ads campaigns?
- What is a key benefit of using Dynamic Creative Optimization (DCO) in ad campaigns?
- What is a recommended step to optimize an under performing deal on the SSP side?
- What is a recommended step to optimize an underdelivering deal on the SSP side?
- What is a recommended step to optimize an underperforming deal on the SSP side?
- What is Amazon DSP’s attribution lookback window?
- What is the key difference between a Private Auction (PA) deal and a Preferred Deal (PD) on Amazon DSP?
- What is the primary focus of Performance+ for endemic advertisers?
- What is the primary focus of Performance+?
- What is the primary purpose of Events Manager on Amazon DSP?
- What is the use of a third-party impression URL in Amazon DSP?
- What should an advertiser do if the sum of projected spend across line items is less than the total lifetime order budget?
- What should be included in a third-party tag to ensure accurate impression counting?
- What should you do if none of the creatives associated with a line item match the ad size requirements in the request?
- What strategies does Performance+ offer to help achieve KPIs?
- What tactics does Performance+ offer to help achieve KPIs?
- What type of video creative does Amazon DSP support for third-party tags?
- When are conversions for Amazon DSP campaigns reported?
- When assigning multiple audience segments to a line item, an advertiser wants to increase scale by serving ads to shoppers in any of the selected segments. Which option should they choose?
- When directing to an Amazon Ads site for mobile in-app ads with a third-party tags, you can use a 1x1 pixel or a redirect.
- When setting up a campaign with multiple line items using budget optimization, what is the best practice for pacing profiles?
- When should an advertiser consider using bid modifiers?
- When using Amazon Advertising tag (AAt), you must install event code on each page of your website where the user action takes place or use a tag manager to ensure AAt is placed on each page.
- When would you NOT want to use the "prioritize KPI target" bidding priority in Amazon DSP?
- When you’re creating a simple pixel in Amazon DSP, which of the following is true?
- Where can you access and manage deals (deals on Amazon 1P Publisher properties i.e. Prime Video, Twitch, etc. and on third-party supply) on Amazon DSP?
- Where can you access and manage deals on Amazon DSP?
- Which action can you take after creating Amazon Ad tag?
- Which activity provides a stronger signal of an ad's impact on a conversion.
- Which best describes the "lead-in" stage for a bid calendar for a high traffic event?
- Which bid strategy would you require to frequently monitor and optimize in order to balance performance and spend?
- Which is a tool where advertisers buy ads in an automated fashion?
- Which of the below is NOT considered a conversion metric?
- Which of the below scenarios is correct based on the below shopper journey for ads served in Amazon DSP? July 3rd: Desktop display ad view --> July 24th: Mobile display ad click --> July 25th: Video ad view --> July 30th: Purchase made
- Which of the below statements is true for private auction deals?
- Which of the below statements is true for private auction deals? Select All Correct Responses
- Which of the following are reasons your private marketplace deal may not be bidding?
- Which of the following are reasons your private marketplace deal may not be bidding? Select All Correct Responses
- Which of the following are short commands or shortcuts for commands passed to Amazon DSP to enhance ad line and creative monitoring capabilities externally, without the need to generate multiple third-party tag sets.
- Which of the following best describes if line items in your budget have "optimized out"?
- Which of the following best describes rule-based audiences?
- Which of the following best describes the range of creative formats available on Amazon DSP?
- Which of the following deal types are an invitation-only, pre-negotiated arrangement between a publisher and an advertiser?
- Which of the following deal types helps access inventory at fixed pricing with higher prior it iz ation?
- Which of the following deal types helps access inventory at fixed pricing?
- Which of the following deal types is a pre-negotiated arrangement between a publisher and an advertiser?
- Which of the following enables third-party providers to accurately perform certain functions, such as counting impressions and clicks?
- Which of the following is a benefit of similar audiences?
- Which of the following is a best practice for budget optimization to help maximize delivery and performance?
- Which of the following is a best practice for budget optimization to help maximize delivery?
- Which of the following is a key feature of Responsive eCommerce Creative (REC) on Amazon DSP?
- Which of the following is a policy for using third-party served creatives on Amazon DSP?
- Which of the following is an insight collected through Amazon DSP’s Amazon Advertising tag (AAt) solution?
- Which of the following is not a benefit of “prioritize KPI target” type of bidding priority?
- Which of the following pre-negotiated deal arrangement between a publisher and an advertiser gives you the highest prioritization?
- Which of the following represents the best practices for setting up third-party deals in Amazon DSP?
- Which of the following statements accurately describes attribution restatement for Amazon DSP campaigns?
- Which phase of a high traffic event would you recommend gradually easing off bids?
- Which setting must you adjust when setting up a private marketplace deal in Amazon DSP?
- Which solution gives advertisers the ability to pass dynamic events for audience creation and conversion management, enabling personalized audience targeting using detailed visitor data, including product views, purchases, and cart abandonment s?
- Which solution gives advertisers the ability to pass dynamic events for audience creation and conversion management, enabling personalized audience targeting using detailed visitor data?
- Which supply source enable advertisers to access addressable, display, online video (OLV), and reserved, high win-rate STV ad supply across the open internet and from premium publishers and broadcasters?
- Which supply source enable advertisers to access addressable, display, online video (OLV), and reserved, high wiZavier wants to engage audiences who recently engaged with video game content on Twitch. Which type of signals should they use?
- With Amazon Advertising tag (AAt), you can capture hundreds of events using one tag and use them for creating multiple audiences.
- With Amazon DSP, advertisers can access both 1P and 3P supply.
- Xiaoyan is interested in deals that provide invitation-only access to select inventory with flexibility in pricing. Which type of deals are they looking for?
- You are running a campaign with the bid strategy “Maximize performance,” and your campaign is under-pacing, but you are hitting your goal KPI. What is an optimization you can implement to improve pacing?
- You can append a third-party tags to a mobile Amazon Ads owned and operated creative to enable you to pull view ability reporting in the third-party’s portal.
- You can create audiences from data captured by Amazon Ad tag, in the audiences tab of Amazon DSP.
- You can download campaign settings and upload modifications via bulksheets in either your advertiser, order, or entity view.
- You can download or upload bulksheets across advertisers within the same entity.
- You can modify parameters to include in bulksheet downloads.
- You can securely transfer audiences from third-party insight providers (DMPs, etc.) to Amazon DSP via Amazon’s Advertiser Audiences. Which of the following statements is true?
- You can securely transfer audiences from third-party insight providers (DMPs, etc.) to Amazon DSP via Amazon’s Advertiser Audiences. Which of the following statements is true? Select All Correct Responses
- You can set up a private marketplace deal manually or through an API.
- You can use mobile advertising IDs as a file type to create hashed audiences
- you will need to append your third-party tag in the tag source section of creative settings, For video, the third-party video creative type supports VAST 2, VPAID Flash, and VPAID JS third-party tags, and When directing to an Amazon Ads site for mobile in-app ads with third-party tags, Amazon Ads requires using a 1x1 pixel and not a redirect. These policies are true because If you select “Maximize performance” as the bid strategy in order settings, but uncheck “bid optimization models,” what happens?
- You're an advertiser running a full funnel campaign for Black Friday/Cyber Monday. You leveraged an event lead-in strategy and have planned conversion focused ads to run day of event. It’s now the Day of event. What should be your primary focus during this stage to maximize your advertising impact?
- You're managing an e-commerce website and want to create a remarketing campaign to engage users who have abandoned their shopping carts on your website. Which audience creation tool would be most effective for reaching cart abandoners with personalized ads and special offers?
- Your order is running the “While spending full budget, maximize performance” bid strategy and opted into “bid optimization models.” The lines in your order start under-pacing. This will most likely cause which of the following?
- Zavier wants to engage audiences who recently engaged with video game content on Twitch. Which type of signals should they use?
amazon dsp advanced ENG version All exam questions
- A customer views an ad,clicks on the ad,and then makes a purchase.Whattype of activity is this?
- Advertiser A bids$0.45,Advertiser B bids$0.65,and Advertiser C bids$1.05. Which of the following is true in a second-price auction?
- Bulk sheets are recommended to manage:
- How will conversions be impacted(ifatall)after a campaign ends?
- If you select“Maximize performance”as the bid strategy in order settings,but uncheck“bid optimization models,”what happens?
- If you use third-party served creatives in Amazon DSP,which of the following policies are true?
- Please select all of the pixel solutions offered by the Amazon DSP.
- Third-party video creative type supports which of the following third-partytags?
- This type of pixel can be generated by navigating to the events tab in Amazon DSP.
- What advertiser insights can you use to build lookalike audiences?
- What is Amazon DSP’s attribution look back window?
- Which activity provides a stronger signal of an ad's impact on a conversion.
- Which auction type is a digital buying model where the highest bidder above the floor price wins the auction,and pays exactly the amount they bid?
- Which bid strategy would you require to frequently monitor and optimize in order to balance performance and spend?
- Which of the below scenarios is correct based on the below shopper journey for ads served in Amazon DSP?July3rd:Desktop display ad view-->July24th: Mobile display ad click-->July25th:Video ad view-->July30th:Purchase made
- Which of the following are reasons your private marketplace deal may not be bidding?
- Which of the following are short commands or shortcuts for commands passed to Amazon DSP to enhance ad line and creative monitoring capabilities externally, without the need to generate multiple third-party tag sets.
- Which of the following are true?
- Which setting must you adjust when setting up a private marketplace deal in AmazonDSP?
- Which simple pixels elections provide flexibility after the pixel is created?
- You are running a campaign with the bid strategy“Maximize performance,”and your campaign is under-pacing,but you are hitting your goal K PI.Whatisan optimization you can implement to improve pacing?
- You can securely transfer audiences from third-party insight providers(DMPs, etc.)to Amazon DSP via Amazon’s Advertiser Audiences.Which of the following statements is true?
Amazon DSP Certification All exam questions
- A campaign had a ROAS goal of $3.50 or higher, and a CPM goal of less than $1.75. Using the following report, select the statement that is true.
- A client is interested in implementing a comprehensive audience targeting strategy using Amazon DSP but is unsure about the available data sources. Which of the following accurately represents the complete set of audience targeting capabilities available through Amazon DSP?
- A customer views an ad on April 1st, clicks the ad on April 4th, views the ad again on April 7th, and purchases the product on April 9th. Which of the following receives the credit for conversion?
- A KDP author wants to advertise a newly released series with a Sponsored Brands campaign. They target the ASINs of their well-known best selling titles. Which targeting method are they using?
- A media buyer at an agency is setting up their first campaign to reach audiences watching premium TV shows and movies through Prime Video. Their client specifically wants to appear alongside popular TV series and movies. Which media type should they select in Amazon DSP?
- Advertisers are allowed to edit an Amazon customer review to appear in an ad if the review contains spelling or grammatical errors.
- Advertisers can use Amazon DSP as part of a full-funnel approach to build brand awareness when shoppers may not be actively shopping by serving ads across thousands of popular third-party apps and websites.
- Amazon Ads enables you to create brand-based audiences around which of the following behavior types?
- Amazon Attribution allows advertises to measure their non-Amazon media and report on Amazon conversion metrics, including sales.
- Amazon DSP ads cannot contain imagery or text that mimics or alters Amazon's branding or logo.
- Amazon DSP campaigns can link in to an Amazon destination, such as a product detail page on Amazon.com, or link out to non-Amazon destinations, such as a brand's website.
- Amazon DSP is available to both endemic advertisers (who sell in the Amazon store) and non-endemic advertisers (who do not sell in the Amazon store).
- Amazon DSP is only available in a self-service model.
- Amazon Publisher Direct (APD) only provides advertisers access to Amazon-owned and operated inventory, like Amazon.com and IMDb.
- Amazon Publisher Direct (APD) provides advertisers direct access to a vast number of premium ad formats (connected TV (CTV), video, and display) and publishers around the world.
- Amazon's ad policies are only relevant for ads served ON Amazon.
- An advertiser has decided to exclude “IM – cell phones” from all seven lines in an order. What bulk edit feature would allow you to do this?
- Anand is considering using Amazon Publisher Direct (APD) and third-party exchanges to accessing more inventory sources. Which of the following best describes the benefits of this approach?
- Anand is considering using Amazon Publisher Director (APD) and open internet exchanges to access more inventory sources. Which of the following best describes the benefits of this approach?
- Antonio has a line-item that is under-delivering. Which of the following manual optimization tactics should he consider? (Select 2)
- As a new advertiser concerned about brand reputation, you are planning to run a campaign using Amazon DSP and want to ensure your brand's ads won't appear alongside sensitive content across various media types. How does Amazon DSP address this concern?
- ASINs, or products, within the Amazon Attribution console are selected at the order level.
- At which point during the campaign management timeline should an advertiser establish goals and KPIs?
- Attribution contention occurs at the product, or ASIN, level; if you select the same products in multiple orders, your attribution tags with the same promoted products will be eligible with each other for attribution.
- Auction buying is unguaranteed buying.
- Brand or author awareness is measured by ___.
- Bree has set up a campaign in Amazon DSP which utilizes a deal ID. What supply is she leveraging?
- Campaign efficiency is measured by ___. Select all that apply.
- Charlotte is looking to launch a cross-device campaign to promote her brand. Is she able to achieve this with Amazon DSP?
- Choose the best answer that describes promoted conversion metrics.
- Dean wants to highlight the three titles in his fantasy trilogy. Which sponsored ad could he use to achieve this?
- Display ads purchased with Amazon DSP can run on Amazon-owned inventory and open internet inventory across multiple channels, including desktop, mobile, Connected TV (CTV), and audio environments.
- Finnigan wants to grow new-to-brand sales. Which campaign strategy would best help them achieve this goal?
- Fire TVs are shared devices and have strict requirements to protect all members of a household.
- Flynn wants to download a custom report from Amazon DSP which will allow him to view the performance on audiences his campaign reached, as well as those not directly reached. Which of the following dimensions should he select for this use case?
- For which advertising method are prices negotiated and based on a fixed CPM with no auction involved?
- For which reason(s) might you add a new pixel to your order?
- Georgeanne is optimizing her children's books campaign and wants to increase brand awareness. Which of the following is the best strategy to achieve this goal?
- Hong has launched a campaign for his client which will run for 60 days. When is the earliest recommended time he should begin reviewing performance data toward optimization?
- How can advertisers calculate return on ad spend and other cost based metrics?
- How long is Amazon's lookback window from the point of conversion, used in reporting ad-attributed metrics?
- If a KDP author has a goal to maximize brand awareness, which of the following is the recommendation for selecting ASINs?
- If you want to access open-exchange mobile web display inventory, what type of line item do you need to create?
- In-line editing allows you to adjust key line item settings at the order level, without needing to open up and save each individual line item again.
- Jack and Jill want to run an ad with copy that reads "Learn more about our brand". This is compliant with Amazon Ads guidelines and acceptance policies.
- Janice has set up a sponsored ad for her new series of cookbooks. She has selected the keyword "computer" for this ad. Which principle explains why her ad may not display?
- Josue wants to create a display campaign that links to their Amazon product detail page. Why should they use eCommerce display ads for this?
- Juan’s advertising goal is sales efficiency. What optimizations should he make to his campaign? Select all that apply.
- KitchenSmart wants to run an ad with copy that creates a sense of urgency for their new food processor that reads "Hurry, buy now!" This is compliant with Amazon Ads guidelines and acceptance policies.
- Kris is managing a campaign where one of the line items is beating the performance goal, yet underdelivering. Which of the following is the recommended approach?
- Marta is an advertiser running campaigns focused on improving consideration metrics of their promoted and brand halo products. Which metrics would be most useful to measure consideration from her campaign?
- Match each campaign goal with the appropriate optimization type.
- Muriel wants to find new keywords to add to her existing campaigns advertising her crime novels. Which downloadable report should they use to inform their direction?
- Olga has several line items under her campaign. Two of the line items are underdelivering and not meeting performance goals, while two are high-performing. Which of the following is the recommended optimization strategy?
- Omar writes science fiction novels. He notices he has been paying for clicks when customers search for "science textbooks." Which keyword match type should Omar use to ensure ads are not served to customers searching for science textbooks?
- Once you create a new advertiser, you will need to notify your Amazon representative for approval.
- Overter is a financial services company that does not sell products or services on Amazon. They are running a campaign on Amazon promoting a new credit card, where the ad directs users to an enrollment page off of Amazon. What type of campaign is this?
- PMP allows you access to direct deals with publishers.
- Ralf is looking to run a full-funnel campaign using Amazon DSP. They are planning to run a video campaign focused on driving reach and a display campaign using ASIN retargeting to drive conversions. What type of campaign would you recommend to further support this strategy?
- Ramona wants to promote her best selling graphic novel with creative that showcases just that title. Which sponsored ad could help her ensure she is appearing in shopping results and related product detail pages in order to drive sales?
- Reid wants to review how well his campaign is performing toward an awareness goal. Which of these metrics will be most relevant to him? (Select 2)
- Santiago is running a Sponsored Products campaign with a daily budget of $20. On Tuesday, the campaign spent $20. Based on this, which of the following would be a true statement?
- Spencer analyzed performance for his Sponsored Products campaign for mystery thriller books and realized that they are running out of budget every day. If he cannot increase his budget, what alternative action(s) would be appropriate? (select all that apply)
- Sponsored products are generally used for which objective?
- Stores can include contact information such as phone numbers, emails, or physical addresses.
- Stores do not require a minimum spend.
- Supply via private marketplaces (PMPs) is only available to Amazon DSP managed service users.
- The language for promotions and bundles must be which of the following?
- The performance metrics shown in the custom report cannot be customized.
- There was a viewable display ad on July 15th, a non-viewable video ad on July 22nd, and a viewable video ad on July 29th. The customer had clicked on the first display ad on July 15th and purchased the product on August 5th. Which of the following receives the credit for conversion?
- There was a viewable video ad on September 25th, a non-viewable display ad on September 26th, a viewable video ad on October 1st, and a non-viewable display ad on October 3rd. The customer purchases the product on Oct 6th. Which of the following receives the credit for conversion?
- Third-party exchanges rely on which buying method?
- To create a custom report broken down by ASIN type, which of the following dimensions would you select when generating your custom report?
- Violet is reviewing her campaign report and notices high detail page views (DPV) but low purchase rates. Which of the following is indicated by such results?
- Wesley has been advertising his graphic design books on Amazon for over a year. He notices the campaign performance has been slightly declining, and he wants to know which keywords aren't performing well. Which downloadable report should he use?
- What amount of ratings and reviews does the ASIN selected for an Amazon DSP ad with e-commerce creative require in order to be within Amazon's ad policies?
- What are benefits of observing which Amazon audiences are reached by your non-Amazon ads? Select all that apply.
- What does Amazon strive for through its ad policies? (Select 2)
- What is the recommendation for using full-width images?
- What method(s) of optimization does Amazon DSP offer?
- What might you do to optimize Store pages with high conversions but low views?
- When setting up your Store, which tactic can encourage targeted exploration?
- When shoppers click on an ad and are directed to an advertiser's product detail page on Amazon, which customer flow is this?
- Which advertising method may involve real-time bidding?
- Which is Amazon's recommendation regarding a line item's supply sources?
- Which is the correct hierarchy within the Amazon DSP?
- Which KPIs are associated with an awareness goal? (Select 3)
- Which method has shown better return on ad spend (ROAS), according to Amazon data, 2018?
- Which of the below are ways advertisers can measure their non-Amazon ads with Amazon Attribution? Select all that apply.
- Which of the following are features of the Store builder?
- Which of the following describes Amazon Publisher Services (APS)? (Select 2)
- Which of the following describes the viewability standard used by Amazon DSP?
- Which of the following is a requirement for all Amazon DSP advertisements?
- Which of the following is considered paid traffic?
- Which of the following items are allowed in your Store?
- Which of the following pieces of content could cause your Store to be rejected?
- Which of the following refers to the line item setting that increases delivery during the first half of the campaign (up to 25%), then up to 5% during the second half?
- Which of the following scenarios are true for campaign management features in Amazon DSP?
- Which of the following statements about private marketplaces (PMPs) are true?
- Which of these ad copy examples is compliant with Amazon Ads’ Guidelines and Acceptance Policies for claims and substantiation?
- Which of these ad examples is compliant with Amazon Ads’ Guideines and Accepted Policies for branding?
- Which of these ad examples is compliant with Amazon Ads’ guidelines and acceptance policies for ads running on desktop?
- Which sentence best describes the insights gained from reviewing the total detail page view rate (DPVR) metric?
- Which statement accurately describes programmatic advertising compared to direct advertising?
- Which targeting method is better suited to help authors stay on top of search trends and discover new keywords that are generating clicks and sales?
- Which type of advertiser(s) can leverage Amazon DSP for link in campaigns?
- Which type of Amazon Attribution report would you use to view your keyword level Google Ads performance?
- Why should an advertiser upload all creative asset sizes that are available during campaign set up?
- Would “Shop now” or “Click here” be a compliant CTA? Take a moment to think about why you’ve selected that answer.
- You can delete Amazon DSP orders as long as they have not yet gone live.
- You want to leverage the automated optimization feature for the majority of line items in an order, but you do have a specific need for spend on one line item. Which of the following is the best solution for you?
- You want to use a targeting segment that includes (A) Age 25-24 and (B) Device tablet. Which targeting expression would you use?
amazon dsp ENG version All exam questions
- A campaign had aRO AS goal of$3.50orhigher,and aC PM goal of less than $1.75.Using the following report,select the statement that is true.
- A customer views an a don April 1 st,clicks the a don April 4 th,views the ad again onApril7th,and purchases the product on April 9 th.Which of the following receives the credit for conversion?
- Amazon Garage,Twitch,Whole Foods Market,and Amazon Fresh stores are examples of which type of audience?
- Amazon uses internally developed systems to detect and filter out invalid activity, such as robots that generate fake clicks.
- An advertiser has decided to exclude“IM–cellphones”from all seven lines in an order.What bulked it feature would allow you to do this?
- Antonio has a line-item that is under-delivering.Which of the following manual optimization tactics should he consider?(Select2)
- At which point during the campaign management timeline should an advertiser establish KPIs?
- At which point during the campaign management timeline should an advertiser use manual optimization levers?
- Bree has set up a campaign in the Amazon DSP which utilizes a deal ID. What supply is she leveraging?
- Bree has setup a campaign in Amazon DSP which utilizes a deal ID.Whatsupply is she leveraging?
- Charlotte is looking to launch a cross-device campaign to promote her brand. Is she able to achieve this with the Amazon DSP?
- Display ad homepage restricts the following items from display on the homepage
- Display ads cannot contain imagery or text that mimics Amazon's branding or logo.
- Flynn wants to download a report from the Amazon DSP which will allow him to view the performance on audiences his campaign reached, as well as those not directly reached. Which of the following reports should he choose for this use case?
- For which scenario(s) should an advertiser consider optimization?
- Hong has launched a campaign for his client which will run for 60 days.Whenis the earliest recommended time he should begin reviewing performance data toward optimization?
- If you want to access open-exchange mobile web display inventory,whattypeof line item do you need to create?
- IMDb is an example of which type of supply source?
- Joaquin is launching a campaign for his client,TinyFeet,and only wants to buy fixed-price inventory.Which of the following options should he choose?
- Martina is managing a campaign that isn't tracking toward the intended goal. What is the recommended approach?
- Martina is managing a campaign that isn't trending toward the intended goal. What is the recommended approach?
- Olga has several line items under her campaign.Two of the line items are under delivering and not meeting performance goals,while two are high-performing.Which of the following is the recommended optimization strategy?
- Opal is introducing the Amazon DSP to her team. Which of the following points should she include in her presentation?
- Reid wants to review how well his campaign is performing toward an awareness goal.Which of these metrics will be most relevant to him?(Select2)
- Select all that apply.Ad copy and legibility must be:
- The Amazon DSP automated budget optimization allocates budgets based on which of the following?
- The reporting and analysis hub transforms which two reports into a graphical analysis of campaign reporting?
- The World Times, a publisher, has set their inventory's price floor to $1.00. Advertiser A bids $0.89, Advertiser B bids $1.04, and Advertiser C bids $1.11. What is the outcome in a first-price auction?
- The World Times, a publisher, has set their inventory's price floor to $1.05. Advertiser A bids $0.93, Advertiser B bids $1.14, and Advertiser C bids $1.19. What is the most likely outcome in a second-price auction?
- There is a dedicated team that manually audits inventory for compliance with Amazon's quality standards.
- There was a viewable display a don July 15 th,anon-viewable video a don July 22nd,and a viewable video a don July 29 th.The customer had clicked on the first display a don July 15 th and purchased the product on August 5 th.Whichofthe following receives the credit for conversion?
- There was a viewable video a don September 25 th,anon-viewable display a don September 26 th,a viewable video a don October 1 st,andanon-viewable display a don October 3 rd.The customer purchases the product on Oct 6 th.Whichofthe following receives the credit for conversion?
- To create a custom report broken down by AS IN type,which of the following dimensions would you select when generating your custom report?
- True or false? Advertisers are allowed to edit an Amazon customer review to appear in an ad if the review contains spelling or grammatical errors.
- True or false? Amazon makes decisions around ad policy in favor of long-term benefits rather than short-term profitability.
- True or false? Amazon's ad policies are only relevant for ads served ON Amazon.
- True or false? Auction buying is unguaranteed buying.
- True or false? PMP preferred deals are an option that bypass auctions completely.
- True or false? Supply via private marketplaces (PMPs) is only available to the Amazon DSP managed service users.
- True or false? The Amazon DSP is only available in a self-service model.
- True or false? The metrics shown in the performance dashboard (interactive performance report) cannot be customized.
- Using the audience builder in Amazon DSP,you are able to create custom audiences based on which of the following?
- Using the following report,which audience segment might the campaign manager choose to add to their targeting approach?
- Using the following report,which audience segment might the campaign manager choose to remove from their targeting approach?
- Violet is reviewing her campaign report and notices high detail pageviews(DPV) but low purchase rates.Which of the following is indicated by such results?
- What amount of ratings and reviews does the AS IN selected for an Amazon DSP adwithe-commerce creative require in order to be within Amazon'sad policies?
- What does Amazon strive for through it sad policies?(Select2)
- What does the ASIN selected for a display ad with e-commerce creative require in order to be within Amazon's ad policies?
- What is the value of Amazon's pre-bid analysis? (Select 2)
- What method(s) of optimization does the Amazon DSP offer?
- Whatmethod(s)of optimization does Amazon DSP offer?
- When should an advertiser care most about brand halo metrics?
- Which KP Is are associated with an awareness goal?(Select3)
- Which of the below are best practices when setting up Amazon DSP campaigns?
- Which of the below explains Amazon DSP’s order copying capabilities:
- Which of the following ad copy examples is compliant with Amazon Ads guidelines and acceptance policies for pricing and savings?
- Which of the following ad copy examples is compliant with Amazon Advertising’s guidelines and acceptance policies for pricing and savings?
- Which of the following are benefits of Amazon's automatic optimization? (Select 2)
- Which of the following are benefits of Amazon's automatic optimization? (select all that apply)
- Which of the following are variables that may affect campaign performance?
- Which of the following audiences can be reached using the Amazon DSP?
- Which of the following best describes the core value behind Amazon's ad policies?
- Which of the following call to action(CTA)is most likely to be compliant with Amazon's creative acceptance policies?
- Which of the following copy is most likely to be compliant with Amazon's creative acceptance policies?
- Which of the following describes Amazon DSP's capability to delete individual line items within a campaign?
- Which of the following describes Amazon Publisher Services(APS)?(Select2)
- Which of the following describes the viewability standard used by the Amazon DSP?
- Which of the following is NOT a true statement?
- Which of the following is the recommended optimization strategy for line items that are performing and delivering above goal?
- Which of the following may not be compliant with Amazon's creative acceptance policies? (Select 2)
- Which of the following metrics are non-ad-attributed?
- Which of the following scenarios are true for campaign management features in AmazonDSP?
- Which of the following statements about private marketplaces(PMPs)aretrue?
- Which of the following statements most closely describes automatic optimization in the Amazon DSP?
- Which of the following supply strategies may lead to better performance through the ability to scale and diversify formats and content?
- Which of these buying method provides advertisers higher priority to inventory?
- Which pricing model allows advertisers to set a price range for any single impression?
- Which supply option consists of exclusive inventory available through the Amazon DSP?
- Which supply option should an advertiser select to access inventory from Amazon's direct publisher integration?
- Which type of advertiser(s) can leverage the Amazon DSP for link in campaigns?
- Which type of advertiser(s)can leverage Amazon DSP for linkin campaigns?
- Which type of Amazon audience segment should you use when trying to drive sales of a new product?
- Who incurs the cost of invalid impressions resulting from domain spoofing?
- Why is a call to action (CTA) not allowed in the custom image of a display ad with e-commerce creative?
Amazon Machine Learning Specialty MLS-C01 All exam questions
- A B2B e-commerce company wants a simple, operationally light approach to reject fraudulent transactions, accepting some loss of profitable transactions or customers. Which solution will meet this need with the least operational effort?
- A bank deployed an XGBoost classifier in SageMaker to decide which customers qualify for a low-rate credit promotion. The model’s accuracy is acceptable, but the team must explain why particular customers were denied. What is the most operationally efficient way to produce per-customer explanations?
- A bank has 10 years of customer data in CSV files on-premises. The data science team wants to quickly perform transformations and explore the data before building a production model in SageMaker, with minimal development effort. Which approach minimizes effort and enables fast transformation and insights?
- A bank ingests raw transaction data from an Amazon Kinesis data stream. The solution must compute rolling averages from the stream, store those features in SageMaker Feature Store, and serve them to models in near real time. Which design meets these requirements?
- A bank used SageMaker with the built-in XGBoost algorithm and ran a Bayesian automatic hyperparameter tuning job using validation accuracy as the objective. The deployed model currently has 75% accuracy. The bank has given the ML specialist one day to improve production accuracy. What is the fastest way to try to improve the model within that time?
- A bank used XGBoost trained on 7 years of transaction data to build a credit eligibility model. The model is accurate but the credit team (with little data science expertise) cannot understand why some customers are denied. What is the most operationally efficient way for the data science team to provide explanations to the credit team?
- A beauty-supply retailer wants an hourly report of store visitors derived from years of security video. The report must categorize visitors by hair style and hair color. Which approach requires the least development effort?
- A car engine manufacturer collects time-stamped sensor data (engine temperature, RPM, etc.) while vehicles are driven. The company wants to predict upcoming engine faults so drivers can be notified in advance. The data lake holds the historical sensor streams for training. Which predictive modeling approach is MOST appropriate to deploy in production?
- A chemical company needs a model that maximizes the chance of detecting abnormal process behavior (labels: 0 = normal, 1 = abnormal). Which of these metric pairs indicates the model most likely to detect abnormalities?
- A city wants to forecast air pollutant concentrations (parts per million) for the next two days using only daily observations from the past year. For this prototype in Amazon SageMaker, which algorithm is most likely to give the best forecasting performance?
- A clothing company keeps its complete product sales history in Amazon S3 and currently uses custom exponential smoothing (ETS) models to forecast demand for existing products. The company needs a method to forecast demand for a new product variation that hasn't sold before. Which approach best meets this requirement?
- A company already collects social media posts into an S3 bucket and needs a quick solution to evaluate sentiment, visualize trends, and configure alerts with minimal infrastructure and data science effort. Which combination of AWS services best achieves this quickly?
- A company collected 10,000 equipment event samples over 3 months to build a predictive maintenance model. There are 100 failure events evenly spread across 50 machine types. How should the company prepare the training data to improve model accuracy given the class imbalance and sparse failures per type?
- A company collects sensor data (temperature, pressure, etc.) to predict equipment failures. Before training, the ML specialist must detect and remove outliers with minimal operational overhead. Which approach meets this requirement with the least effort?
- A company currently uses EC2 instances for a custom ingestion pipeline that sends on-prem server logs, mobile app logs, and IoT sensor data to S3 and OpenSearch Service. They want a new serverless pipeline that scales automatically and is cost-effective. Which architecture meets these requirements most economically?
- A company has 10 TB of data in an Amazon Redshift cluster. The data engineering team uses SageMaker Studio for analysis and model development, but only a subset of the Redshift data is needed for training. They need a secure, cost-effective way to export the relevant subset to Amazon S3 for model development. Which solutions satisfy these requirements? (Choose two.)
- A company has an experimental ML model that must be validated on production traffic without impacting the current live model. Only one model can handle user requests at a time. Which deployment approach lets you evaluate the new model’s predictions in production without affecting live traffic?
- A company has both structured and unstructured data in S3 and needs to run SQL queries over it. Which solution requires the least amount of work to enable SQL querying?
- A company has historic property data in CSV on S3 with a header, categorical fields, and missing values. Data scientists filled missing values with zeros, dropped categorical fields, and trained a default open-source linear regression model; prediction accuracy is under 50%. They want to improve model performance and launch quickly with minimal operational overhead. Which option best meets this goal?
- A company has petabytes of audio recordings on-premises and needs to transcribe them to text and store the transcripts in S3 as quickly as possible. The on-premises network to AWS is limited to 100 Mbps. The transcription algorithm requires GPUs for inference. Which solution will deliver transcripts to the S3 bucket fastest?
- A company has video feeds from a subway station and needs a model that alerts the manager when passengers cross the yellow safety line while no train is present. The model must detect the yellow line, people crossing it, and trains. Bounding-box object detection did not clearly separate the line, people, and trains. Which labeling approach will most effectively improve the model while keeping the video data private?
- A company hosts a custom PyTorch CNN image classifier on a SageMaker endpoint and wants higher throughput and lower latency for users. Which option is the most cost-effective way to improve performance?
- A company hosts ML infrastructure in AWS and the team in the office connects via an IPsec VPN to a VPC. The VPC has enableDnsHostnames and enableDnsSupport set to true, and the office DNS resolvers point to the VPC DNS. The company forbids accessing SageMaker notebooks over the public internet; all access must remain private over the VPN and inside the AWS network. Which solution meets these requirements with the least development effort?
- A company is building an AI yoga instructor that must count the number of students in a class and determine whether students perform stretches correctly by measuring limb positions and angles. Using SageMaker to extract frames from class video, which two computer-vision model types together require the least effort to implement these features? (Choose two.)
- A company is converting many paper receipts into images and needs to extract entities like date, location, notes, and custom fields (receipt numbers). They already use OCR to get text but document layouts vary and building label workflows is time-consuming. They also have a small NER dataset that needs much more training data. Which approach will require the least effort to get reliable entity extraction?
- A company is training models in SageMaker using 200 TB of data stored in S3. The dataset consists of many files, each larger than 200 MB. The company wants the fastest processing time with minimal setup effort. Which data access method should they use?
- A company needs a chatbot that answers customers’ questions using the company’s documentation as the source of truth. Which approach minimizes development effort?
- A company needs a scalable image repository that grows automatically, supports versioning, and keeps multiple immediately accessible copies in different AWS Regions. Which storage option meets these requirements?
- A company needs an auditing solution that can analyze feature-level metadata, generate reports about that metadata, and allow setting feature sensitivity and authorship. Which option meets these requirements with the least development effort?
- A company operates wind turbines, weather stations, and solar panels that produce telemetry. Devices are distributed across locations and have intermittent internet. Data scientists need a scalable, secure, high-throughput ingestion pipeline that stores raw telemetry in Amazon S3 for anomaly detection and predictive maintenance. Which ingestion approach satisfies these requirements?
- A company periodically retrains ML models using new streaming device data. They need a high-throughput, durable, scalable ingestion system that can tolerate up to 5 minutes of ingestion latency and apply basic transformations during ingestion. Which approach provides the most operational efficiency?
- A company processes hundreds of printed PDF and JPG documents daily and needs an automated, low-maintenance workflow to extract specific text fields and classify documents. Which solution requires the least operational effort?
- A company records millions of orders daily in Amazon DynamoDB. New orders are added continuously as customers submit them. A data scientist must produce peak-time predictions and create an Amazon QuickSight dashboard that shows near real-time order data. Which approach minimizes the time between a new order being written to DynamoDB and QuickSight being able to access that new data?
- A company requires SageMaker notebook instances to run inside a VPC with no internet access, and training data is in S3. Which approach satisfies the security requirement (no internet connectivity) while allowing SageMaker functionality?
- A company runs a daily ETL pipeline implemented as Python scripts on a large EC2 instance to clean, transform, enrich, and compress terabytes of user interaction data stored in S3. The process takes over 20 hours, and they want to move off EC2 to a managed, serverless solution with minimal development effort. Which approach meets these requirements?
- A company runs a SageMaker-hosted recommendation model in a single Availability Zone and requires an RTO (recovery time objective) of 5 minutes for high availability. Which option achieves high availability with the least effort?
- A company sends weekly marketing emails with special offers, but few customers redeem them. A team is building a SageMaker model to recommend personalized offers for each customer using their profile and past acceptances. Which option gives the most operational efficiency for producing recommendations to feed the bulk email system?
- A company stores daily aggregated inputs and model predictions as a single S3 object (100 GB per day) to monitor model drift. The daily object size will grow over time. Every quarter the company samples the prior 90 days to check for drift, and after 90 days the data must be retained for compliance. They want to minimize storage costs while preserving the same durability. Which S3 storage-class and lifecycle combination meets these requirements?
- A company stores documents in Amazon S3 but has no predefined product categories. A data scientist must build a model to derive product categories for all documents with maximum operational efficiency. Which solution is the most operationally efficient?
- A company streams click data into Kinesis and delivers it to an S3 data lake via Kinesis Data Firehose. As volume grows, S3 ingestion rate remains steady but Kinesis Data Streams and Firehose backlog grows. Which action is MOST likely to increase the ingestion throughput into S3?
- A company streams CSV records in real time and wants to store them on Amazon S3 in Apache Parquet format. Which option requires the least development effort to convert incoming CSV data to Parquet before storing in S3?
- A company trains a classifier to detect credit card fraud; about 2% of transactions are fraudulent. The business priority is to capture as many fraudulent transactions as possible. Which evaluation metrics should the data scientist optimize? (Choose two.)
- A company trains a CNN image model daily in File mode on a single On-Demand EC2 instance with one epoch. They add about 10,000 new images each day and want to speed training and reduce costs without modifying code. Which change will best meet that goal?
- A company uses Amazon SageMaker with EC2 instances for training and inference and wants to reduce training costs without changing the current architecture. Training jobs can tolerate interruptions and results can be waited for days. Which combination of resources should the company use to lower costs most cost-effectively? (Choose two.)
- A company uses Amazon Textract to extract text from thousands of scanned legal documents daily. Documents that fail business validation are routed back to human reviewers, delaying loan processing. What should the company do to reduce overall loan processing time?
- A company uses an LSTM to label each sentence in multi-page documents as “risk” or “no risk.” Despite trying many network structures and hyperparameter settings, performance is poor. Which change will likely give the LARGEST performance improvement?
- A company uses SageMaker image classification (ImageNetV2 CNN) but finds the model misses many less-common animal species. They collected 10,000 labeled images of rare species in S3 and plan to train using Pipe mode. Which combination of steps should the ML engineer take? Select two.
- A company using a legacy telephony platform wants to move to AWS and implement: multilingual call transcription, call categorization, detection of main customer issues, and sentiment analysis for each transcript line (positive/negative and scoring). Which AWS solution provides all these features with the least custom model training?
- A company wants to add a natural-language conversational layer to its BI dashboards so executives can ask questions in text or speech and get answers from the reports. Which combination of AWS services should be used to build this conversational interface? (Choose three.)
- A company wants to build a spam classifier for email text. They have a few thousand labeled examples and plan to fine-tune a pre-trained BERT model (trained on English Wikipedia). How should the specialist initialize the BERT model before fine-tuning on the custom labeled emails?
- A company wants to create a cloud data repository for ML using Amazon S3. All data (about 40 TB) resides on-premises. They need a solution to transfer and continuously synchronize data between on-prem object storage and S3 that supports encryption, scheduling, monitoring, and data integrity checks. Which solution satisfies these requirements?
- A company wants to detect which houses have solar panels from satellite imagery. They collected 8,000 training images and will use SageMaker Ground Truth for labeling. The internal team is small and has no ML experience. Which workflow requires the least effort from this team?
- A company wants to group customers into classes indicating whether they will churn within the next six months. The dataset is labeled with churn/non-churn outcomes. What type of machine learning model should be used?
- A company wants to predict house sale prices using multivariable linear regression. The dataset includes features such as lot size, living area, non-living area, bedroom count, bathroom count, year built, and postal code. Which procedure should a machine learning specialist use to eliminate irrelevant features and reduce model complexity?
- A company wants to prompt users for additional verification when they access the site from unusual locations. They have terabytes of web logs with source IPs and, for authenticated requests, login names. Which approach should you use to build the ML-based decision that flags when to request extra information?
- A company will send promotional packages for a new product and wants at least 90% of all likely buyers to receive the materials. A linear learner model currently has 80% recall and 75% precision. How should the company retrain the model to prioritize reaching 90% recall?
- A company will train and host an ML model in SageMaker. All data must be encrypted at rest. The company wants AWS to maintain the root of trust for the encryption keys and to have key usage logged, while minimizing operational overhead. Which option satisfies these requirements with the least operational effort?
- A consumer goods company has full sales history for many product variants and currently uses ARIMA models. They want to forecast demand for a new product that will be launched soon. Which approach should a Machine Learning Specialist use?
- A convolutional neural network ends with a fully connected layer of 10 outputs representing 10 animal classes. Which function should be applied to that layer so the model outputs a probability distribution across the 10 classes?
- A credit card company needs to detect fraudulent transactions in real time. A labeled historical dataset (fraud vs. legitimate) is stored in Amazon S3. After removing missing values, a data scientist trains an XGBoost classifier in Amazon SageMaker. The model metrics are: TPR 0.700, FNR 0.300, TNR 0.977, FPR 0.023, and overall accuracy 0.949. Which action should the data scientist take to improve model performance given the apparent class imbalance?
- A credit card company wants to speed up training of a credit scoring model built from thousands of raw attributes, many of which are highly correlated. Training is slow and the model overfits. Which feature-engineering technique will reduce dimensionality and training time without discarding much information?
- A credit card fraud detection model must find as many fraudulent transactions (positives) as possible; only about 2% of transactions are fraud. Which two evaluation metrics should the data scientist optimize to prioritize capturing positives?
- A cybersecurity company needs to score incoming security events for anomalies in real time and also store the anomaly scores in its data lake for later analysis. What is the most efficient design to achieve real-time anomaly scoring as data is ingested and persist the results to S3?
- A data engineer extracts monthly training data from Amazon Redshift into Amazon S3. The source schema includes TransactionTimestamp (timestamp), CardName (varchar), and CardNo (varchar). The engineer must (1) remove rows with CardNo = NULL, (2) split TransactionTimestamp into TransactionDate and TransactionTime, and (3) rename CardName to NameOnCard. The solution must minimize infrastructure setup, be automated monthly, and place minimal load on the Redshift cluster. Which solution meets these requirements?
- A data engineer finds many of 100 features in a customer tabular dataset are highly correlated. Which actions should they take to address multicollinearity? (Choose two.)
- A Data Engineer is building a model that uses customer credit card details. How can they ensure the data remains encrypted and the card numbers are protected?
- A data engineer is using Amazon SageMaker Data Wrangler to evaluate customer data for a behavior prediction model. To improve model performance they need to check for multicollinearity. Which steps require the least operational effort to detect multicollinearity? (Choose two.)
- A data engineer must enable data scientists to access ETL scripts in AWS Glue directly from Amazon SageMaker notebooks inside a VPC. The data scientists should be able to run the Glue job and then trigger SageMaker training. Which combination of steps should the engineer take? (Choose three.)
- A data engineer must share datasets in Amazon S3 with data scientists in three departments: Finance, Marketing, and Human Resources. Some datasets are sensitive and should be accessible only to Finance. How should the engineer configure S3 access to meet these requirements?
- A data engineer subscribed an S3 bucket to an AWS Data Exchange product that delivers economic indicators. The engineer must join that incoming economic data with an existing table in Amazon Athena and complete all transformations within 30–60 minutes. Which cost-effective solution meets these requirements?
- A data science team built a custom training image for SageMaker Studio, but when they try to launch that image in Studio they see an error inside the application. Which AWS service should they use to view the logs for diagnosing this error?
- A data science team stores a tabular dataset in Amazon S3. The team wants to try various feature transformations (for example, categorical encoding), visualize the resulting distributions, and then automate the chosen feature-processing workflow. Which solution provides the most operational efficiency?
- A data science team will store many different training datasets and must support automatic scaling, cost efficiency, and SQL-based exploration. Which storage approach is best suited for this use case?
- A data scientist analyzes employment data with about 10 million rows and 10 features. Income and age distributions are both right-skewed. Which feature transformations would help correct skewness? (Select two.)
- A data scientist defined transformations and feature engineering in SageMaker Data Wrangler and saved them to SageMaker Feature Store. New historical data lands periodically in S3 and must be transformed and added to the online feature store, prepared for training and inference using native integrations. Which solution requires the least development effort?
- A data scientist evaluates a GluonTS DeepAR model and finds coverage scores of 0.489 at the 0.5 quantile and 0.889 at the 0.9 quantile on the test set. What is a reasonable conclusion about the distributional forecast calibration?
- A data scientist has 20 TB of CSV data in Amazon S3 and needs to convert it to Apache Parquet with the least effort. What is the simplest way to perform this conversion?
- A data scientist has a new model that outperforms the current production model on test data. They want to run A/B testing in the production SageMaker endpoint to verify performance on real traffic before fully replacing the model. Which steps are required to perform A/B testing? (Choose two.)
- A data scientist has image data stored on Amazon EFS and must train an image classification model in SageMaker with minimal steps and integration work. What is the simplest way to meet this requirement?
- A data scientist has sales data by StoreID, Region, Date, and Sales Amount and wants to analyze yearly average sales for each region and compare each region’s performance to the overall regional average. Which visualization will best show the trend and regional comparisons?
- A data scientist imports a dataset into Amazon SageMaker Data Wrangler and views the feature summary. One feature shows a prediction-power score of 1. What is the most likely explanation for this score?
- A data scientist inspects a feature and finds the distribution mode < median < mean. Which transformation is most appropriate to transform this data so a linear regression model can be applied?
- A data scientist is building a binary disease classifier from a random sample of 400 patients, where the disease prevalence is about 3%. Which cross-validation strategy is most appropriate to evaluate the model?
- A data scientist is modeling an urban traffic system where traffic behavior at each signal is correlated with the others, subject to small random noise. To analyze patterns and reduce congestion, which modeling approach is most appropriate?
- A data scientist is training a multilayer perceptron (MLP) for a multiclass problem. One class is rare and the model's recall for that class is unacceptably low. The scientist has already adjusted the number and size of hidden layers without meaningful improvement and needs a quick solution to raise recall. Which approach should be used?
- A data scientist is tuning a deep learning object-detection model and must run many parallel hyperparameter trials, stop poorly performing trials early, and allocate more resources to promising trials. Which hyperparameter search technique will minimize total compute time while meeting these requirements?
- A data scientist is tuning a hyperparameter x that is very sensitive; the optimal value lies between 0.5 and 1.0 and is believed to be near 1.0. They need to find the optimal value with minimal runs and consistent conditions. Which hyperparameter scaling type should they use?
- A data scientist must build a fraud detection model with far fewer fraud examples than legitimate ones, needs to check for bias before finalizing, and wants to move quickly with minimal operational overhead. Which option best meets these requirements?
- A data scientist must forecast three months of product sales. Analysis shows sales are seasonal, affected by holidays, and correlated with sales of other products in the category. Which approach requires the least development effort to incorporate seasonality, holidays, and related-item correlations into the forecast?
- A data scientist must migrate an on-premises ETL process to AWS. The current process runs on a schedule and uses PySpark to merge and format several large data sources into one consolidated output for downstream jobs. Requirements for the cloud solution: combine multiple sources, reuse existing PySpark code, run on the existing schedule, and minimize the number of servers to manage. Which architecture meets these requirements?
- A data scientist must produce an initial exploratory analysis of customer comments using charts and a word cloud, and wants to apply feature engineering before building an NLP model. Which two feature-engineering techniques should be used to prepare text for visualization and modeling? (Choose two.)
- A data scientist needs near-real-time SQL querying over a stream of GZIP-compressed files. Which option provides the lowest-latency way to query the stream using SQL?
- A data scientist needs specific Python packages preinstalled on SageMaker notebook instances. What is the recommended way to ensure those packages are installed automatically when a notebook instance starts?
- A data scientist needs to build a SageMaker built-in model to classify various vegetables. The dataset has many features and the company wants to minimize memory usage during training and deployment. The company also requires the ability to find similar data points for any test example. Which algorithm choice satisfies these constraints?
- A data scientist needs to explore roughly 500 GB of historical inventory data stored as CSV files in an Amazon S3 data lake. They want to use SQL for exploration and the company wants to minimize cost and operational overhead. Which approach satisfies these requirements with the least operational management?
- A data scientist needs to package code into a container that produces both a new scikit-learn model forecast and a benchmark forecast, and wants AWS to handle operational maintenance of the container. Which packaging approach satisfies this requirement?
- A data scientist plotted the k-means clustering inertia (sum of squared distances) for k values from 1 to 10. Based on the elbow in the plot, which k is a reasonable choice?
- A data scientist stores financial datasets in S3 and queries them with Athena. They deployed an ML model on a SageMaker endpoint and want to invoke it from Athena, but invocations fail and the data scientist's IAM user cannot call the endpoint. Which combination of actions will enable the IAM user to invoke the SageMaker endpoint? (Choose three.)
- A data scientist trained a sequence-to-sequence model for English→Japanese translation using 500,000 sentence pairs. Short sentences (about five words) translate well, but translations for very long sentences (around 100 words) are poor. What change will most likely fix the problem?
- A data scientist trained an XGBoost model to flag fraudulent financial transactions. The training set is highly imbalanced (100,000 non-fraudulent vs. 1,000 fraudulent). On validation the model shows 99.1% accuracy but too many false negatives (fraudulent transactions predicted as non-fraudulent). Which two actions should the data scientist take to reduce false negatives?
- A data scientist trains a large PyTorch model on SageMaker; each training job takes about 10 hours. They suspect training isn’t converging and that GPU utilization might be poor. Which approach requires the least development effort to detect and address these training issues?
- A data scientist used SageMaker to train and deploy a loan-default prediction model. The training was done by manually extracting data and running steps in a SageMaker Studio notebook. Prediction accuracy is drifting downward over time. Which combination of steps is the most operationally efficient way to maintain model accuracy? (Choose two.)
- A data scientist used the SageMaker Neural Topic Model (NTM) to recommend tags for blog posts stored as JSON in S3. The model suggests stopwords like "a," "an," and "the," and sometimes rare but valid words. The team wants to keep the rare words but ensure stopwords are not recommended. What should the data scientist do?
- A data scientist using an Amazon SageMaker notebook instance needs secure access to objects in a specific S3 bucket. What is the recommended way to grant the notebook secure access to that S3 bucket?
- A data scientist wants to assess pretraining bias in loan amount distributions relative to categorical variables (such as loan type and region). Which pretraining bias metrics should be used to compare distributions? (Choose three.)
- A data scientist will use Amazon SageMaker Data Wrangler to ingest historical S3 data for exploratory data analysis to find rare anomalies. To minimize compute resources while performing EDA, which import option should the data scientist choose?
- A data scientist will use SageMaker k-means to segment customers and must choose the optimal number of clusters (k). Which visualization approach will most reliably identify the best k?
- A dataset contains insurance claims with record IDs, a final outcome among 200 categories, and timestamps. The goal is to predict how many claims will occur in each category month-to-month a few months ahead. Which type of model is appropriate?
- A dataset has one column with 30% missing values. You believe other columns can help reconstruct the missing entries while preserving dataset integrity. Which imputation method should you use?
- A dataset in S3 is encrypted with SSE-KMS. What must be done so a SageMaker notebook instance can read that S3 data?
- A dataset of insurance claims contains a claim ID, the final outcome (one of 200 categories), and the outcome date. Some records are partial (they list only 3–4 possible outcomes instead of the full set). There are hundreds of records per outcome and data cover the last 3 years. The data scientist must predict the monthly count of claims per outcome category several months ahead. Which approach best meets this requirement?
- A dataset repository on S3 contains personally identifiable information that must be redacted before model training. Which option minimizes development effort to remove PII from the data?
- A dataset stored in Amazon S3 contains PII and must meet these requirements: it must only be reachable from a specific VPC and it must not traverse the public internet. How can you meet these constraints?
- A deep neural network fits the training data well but performs poorly on test data. Which of the following should you consider to reduce overfitting? (Choose three.)
- A developer has collected 40 product reviews in S3 and a data scientist needs more labeled review data to train models. Which additional data sources are appropriate to augment the dataset? (Choose three.)
- A developer has hourly historical demand data in Amazon S3, but some hours are missing. The developer wants to check if an ARIMA model is suitable. What is the best way to verify ARIMA suitability?
- A developer wants to bring a custom algorithm to Amazon SageMaker by packaging it in a Docker image. How should the container be prepared so SageMaker can start the training job correctly?
- A device manufacturer has over 1,000 candidate features and wants to find the most important features that influence sales price. Which feature-selection techniques should be used? (Choose three.)
- A factory had a pilot that ran image inference using AWS IoT Greengrass on an industrial PC, uploading images to S3 and invoking a SageMaker endpoint. When scaling to thousands of machines, internet bandwidth became saturated and latency is unacceptable. What is the most cost-effective way to reduce latency and resolve the network capacity issue?
- A farm collects overlapping images of a 100-acre field using tractor-mounted cameras and has labeled images of common weed classes. They need a model that detects specific weed types and their locations in the field and will serve real-time inferences on SageMaker endpoints. Which approach will provide accurate detections of weed types and positions?
- A finance company must forecast a commodity price using daily historical data. The data scientist should train models on 80% of the dataset and validate on the remaining 20%. How should the data be split so that model comparisons are valid for time-series forecasting?
- A finance team has stock return data for 5,000 companies with 2,000 features each. They want to identify the top 15 features most useful for predicting future returns with minimal operational overhead. Which approach meets this need?
- A financial services firm is adopting SageMaker and is concerned about preventing data exfiltration. Which mechanisms can an ML engineer use to control data egress from SageMaker? (Select three.)
- A financial services firm is building a serverless data lake on Amazon S3 that must: allow querying old and new S3 data with Amazon Athena and Redshift Spectrum, support event-driven ETL pipelines, and provide easy metadata discovery. Which solution meets these requirements?
- A financial services firm wants to automate loan decisions using an ML model. Each record includes third-party credit history and customer demographics. Every prediction must include an explanation showing why the applicant was approved or denied. Using Amazon SageMaker, which solution provides this functionality with the least development effort?
- A firm needs to classify user behavior as fraudulent or normal using two features: account age (x) and transaction month (y). The plotted class distribution shows a pattern where the classes are not linearly separable. Which model will achieve the HIGHEST classification accuracy?
- A free-to-play game company needs to predict whether a new user will become a paying customer within one year. The labeled training set contains 1,000 positive examples and 999,000 negative examples (1,000,000 total) with 200 features. A random forest achieved >99% accuracy on the training set but performs poorly on the test set. Which actions should the team take to address this problem? (Choose two.)
- A fruit processor needs a classifier to categorize apples into three varieties. They have 150 labeled images per class and applied transfer learning using an ImageNet-pretrained network. After tuning, the best results were: 68% training accuracy and 67% validation accuracy. What action should the specialist take to improve accuracy?
- A geospatial company stores daily satellite images in Amazon S3 for vessel detection. Training data grows incrementally and a SageMaker training job using a single ml.p2.xlarge instance in File input mode recently began failing due to insufficient local storage; the only change was more data. The solution must fix the storage issue while optimizing performance and minimizing training cost. What change should the ML specialist make?
- A global bank trained a churn model on 1,000 customer records, of which 100 are labeled as customers who left. After training in SageMaker Data Wrangler, the model predicts only the negative class (never predicts churn). What change to the training data will most likely fix this and produce more accurate churn predictions?
- A global financial firm uses a gradient boosting regression model to estimate customer credit scores. The dataset contains categorical fields (for example, city and housing status) and financial fields recorded in different units (for example, balances in dollars and interest in cents). Training accuracy is 99% but test accuracy is 75%. Which preprocessing steps will most improve the model's test performance?
- A health care company trains a neural network to classify X-rays as normal or abnormal. The dataset contains 1,000 labeled training images and 200 test images. A network with 50 hidden layers achieves 99% accuracy on the training set but only 55% accuracy on the test set. Which of the following changes should the specialist consider to address this problem? (Choose three.)
- A healthcare company requires that Amazon SageMaker notebook instances access sensitive training data in S3 without any traffic traversing the public internet. Which combination of steps should an ML specialist perform to meet these requirements? (Choose two.)
- A large mobile network operator built a model to predict customers likely to cancel their service so it can offer retention incentives. After testing on 100 customers the model produced the shown evaluation results. Why would this model be acceptable to deploy to production?
- A law firm wants to automatically detect whether each contract page is signed and obtain a confidence score per page. Which Amazon Textract API call returns signature detection along with per-page confidence scores in a single synchronous operation?
- A library stores members' face images in an S3 bucket and uses Amazon Rekognition CompareFaces to match live images to stored images. The library requires that images be encrypted at rest and encrypted in transit when used by Rekognition, and must ensure the images are not used to improve Rekognition as a service. Which architecture meets these requirements?
- A linear model predicting real-time ad bids is overfitting and the team needs to reduce the feature set. Which approach will both reduce features and prevent overfitting?
- A linear regression model was overfitting, so you applied L1 regularization. After training, every feature weight became zero. What is the best next step to improve the model?
- A machine learning engineer preparing data for a classification model notices a few continuous numeric features have values much larger than the others. A domain expert confirms the features are informative and the dataset is representative. The trained model's accuracy is lower than expected. Which preprocessing step will most improve inference accuracy?
- A machine learning specialist must produce near-real-time probabilities that a credit card transaction is fraudulent. How should this problem be formulated?
- A Machine Learning Specialist needs to recommend products to users by leveraging existing user behavior and preferences, using similarity between users to predict items a user will like. Which approach best fits this objective?
- A machine learning team runs a custom training algorithm on SageMaker that needs external assets. They must submit both their algorithm code and algorithm-specific parameters to SageMaker. Which two AWS services should they use to build and supply a custom algorithm on SageMaker? (Choose two.)
- A manufacturer has 8 defect classes and provided ~100,000 images per class. During training, the model achieves 90% training accuracy but only 80% validation accuracy, while human-level performance is ~90%. What should you investigate to address this gap?
- A manufacturer has a large labeled history of sales and wants to forecast how many units of a particular part to produce each quarter. Which machine learning approach is appropriate for predicting a continuous numeric quantity?
- A manufacturer has months of sensor telemetry and manual inspection labels in a data lake. They need an automated model that classifies each product as good quality, replacement-market quality, or scrap based on the inspection labels. Which modeling approach is most likely to give the most accurate predictions for this multiclass supervised classification problem?
- A manufacturer needs near-real-time predictions from models that analyze up to 200 sensor readings per machine, but some factories have unreliable internet. Which deployment architecture best supports near-real-time inference at each factory?
- A manufacturer sells 100 varieties of steel rods with differing grades and dimensions and has 50 years of sales history. A data scientist must forecast future demand for the rods. Which approach is the most operationally efficient?
- A manufacturing company runs a SageMaker scikit-learn model that labels each device as normal or anomalous based on 4 days of telemetry. Each device's 4-day telemetry is written as a separate file to S3 every hour. Running the model across all devices takes 5 minutes. What is the most cost-effective way to run the model over the telemetry for all devices?
- A manufacturing company stores last year’s production volume data in a PostgreSQL database. Business analysts (who do not write code) must be able to prepare the data and build a model to forecast future production volume. Which end-to-end solution requires the least effort and no coding?
- A manufacturing company with remote facilities and limited internet has a large labeled image dataset on-premises for defect detection. They need a solution that lowers compute costs, scales training efficiently, and lets the trained model run in low-connectivity facilities for real-time conveyor-belt inference. Which solution meets these requirements?
- A media company has a very large archive of unlabeled images, text, audio, and video and needs to quickly index assets so researchers can find relevant content. The team has limited ML expertise. Which approach will produce searchable tags fastest?
- A media company needs low-latency article recommendations for readers in one city. Traffic peaks during predictable times (morning, lunch, after work) and is light otherwise. Inference responses are under 4 MB. Which deployment option minimizes latency and is most cost-effective?
- A media company wants to automatically recognize celebrities in user-uploaded photos and also capture the uploader’s IP address and upload timestamp so uploads from unauthorized locations can be blocked. Which solution requires the least development effort?
- A medical diagnostic model was trained on an imbalanced dataset where healthy patients far outnumber diseased patients. False positives (incorrectly labeling healthy patients as diseased) increase company costs. Which metric best reflects model performance given this concern?
- A medical imaging team has many unlabeled CT scans in S3 and must build a labeling pipeline that only authorized users can access. Which set of steps will build the labeling pipeline with the least development effort?
- A model trained on ~10,000 controlled images fits the training set well but performs poorly on unseen test images (training error decreases with epochs while test error remains high). Which actions will help address this problem? (Choose two.)
- A monitoring system writes 1 TB of metric records every minute to Amazon S3. Analysts query this data with Amazon Athena, but queries are slow because of the data volume. Which file format stored in S3 will improve Athena query performance?
- A multiple-choice survey allows respondents to select multiple options per question. You must represent every respondent’s selections completely in a dataset to train a logistic regression model. Which approach provides a comprehensive representation suitable for logistic regression?
- A music streaming company needs a feature pipeline that stores features for offline training and for online inference, preserves feature history, and gives data scientists searchable access. Which option meets these needs with the least operational overhead?
- A national census collects roughly 500 responses per person. Which pair of algorithms would be appropriate to gain insights from this high-dimensional survey data? (Choose two.)
- A pharmaceutical company audits clinical trial site documents (text) and needs to discover the top 10 topics across the corpus so auditors can prioritize reviews. Documents mentioning adverse events must be prioritized. A data scientist will use statistical topic modeling to find abstract topics and list top words per topic. Which algorithms are best suited? (Choose two.)
- A podcast platform detects low engagement by analyzing a 10-minute sliding window of user events. You must ingest events and transform the most recent 10 minutes of data before running inference with minimal operational overhead. Which design is best?
- A podcast platform records high-volume user events and runs an anomaly detection model using a 10-minute running window. Each event needs small transformations before inference. Which event ingestion and pre-processing design provides the required transformations with the least operational overhead?
- A port operator collects real-time sensor data from large cranes (rotation speed, tension, energy, vibration, pressure, temperature) and wants to apply ML for predictive maintenance. Which findings would indicate that an ML-based predictive maintenance solution is appropriate? (Choose two.)
- A prediction service produces 100 TB of prediction data daily. You must create a visualization of the daily precision-recall curve and provide a read-only view to the Business team. Which option requires the least amount of coding?
- A production SageMaker endpoint is configured with automatic scaling. During testing, the team observes that new instances are launched but traffic is routed to them before they finish initializing. You need to prevent new instances from receiving traffic until they are ready. What change should you make?
- A production SageMaker real-time endpoint running the built-in object detection model on a P3 instance shows low GPU utilization. Which deployment change will make better use of provisioned inference resources?
- A public web application collects large amounts of free-text user feedback. Product managers have labeled a large historical dataset into a fixed set of categories (for example, UI issues, performance issues, feature requests, chat issues). An ML engineer must automate multi-class classification of new feedback using Amazon SageMaker. Which SageMaker algorithm is the most appropriate for this task?
- A publisher wants to build a targeted marketing classifier that predicts subscription status from a table with numeric and categorical features (for example, age and education). Which Amazon SageMaker built-in algorithm is most suitable for this supervised classification task?
- A quick-service restaurant wants to count customers in line at a register and alert managers when the line is too long. Locations have very limited outbound bandwidth and cannot stream multiple videos to the cloud. Which solution best meets the bandwidth constraint and delivers the line-length alerts?
- A real estate firm wants to predict house prices using a historical dataset with 32 features. Which modeling approach is appropriate for this task?
- A real estate price prediction model deployed on a website has gradually lost accuracy. The engineer needs to improve the model and be alerted automatically about future performance degradations. Which approach meets both needs?
- A recommendation model initially increased customer purchases but its impact has declined over time, while the deployed model has not changed. What should you do to improve performance?
- A regression model to predict house prices was fit but performs poorly on both training and test sets (high error on both). Which actions should the data scientist take to improve model accuracy? Select three.
- A retail company collects customer comments from social media, its website, and call logs. Each product mention can belong to multiple company-defined categories (labels) that are not mutually exclusive. For example, a mention of “Sample Yogurt” should be labeled as "yogurt", "snack", and "dairy product". Using Amazon Comprehend and needing the fastest delivery, which feature should the team use to train their model?
- A retail company currently has operators manually classify customer claims into categories and store each claim record (including its category) in a central database. The company has no data science team and needs a solution that requires no machine learning expertise to automatically assign categories and route incoming claims to queues. Which approach meets these constraints?
- A retail company gets very few purchases per customer and relies on many new users. When splitting data for training and testing a custom recommender, how should the data scientist create a test set that reflects real usage?
- A retail company runs a daily sales forecasting model that has been producing inaccurate predictions for the last 3 weeks. Each day, an AWS Glue job merges model inputs, the model's predictions, and actual daily sales into files that are stored in Amazon S3. The ML team identifies that the inaccuracies are caused by shifts in the feature value distributions and needs a solution that will detect such data drift in the future with the least operational overhead. Which approach meets this requirement?
- A retail company's daily sales forecasting model has been producing inaccurate forecasts for three weeks. An AWS Glue job appends actual sales and model predictions to S3 each day. The ML team is investigating model degradation in a SageMaker Studio notebook. Which visualization will most accurately show model degradation over time?
- A retail ML specialist is forecasting daily sales for a store using 10 years of historical daily sales. About 5% of days have missing values. The forecast errors are highest around seasonal events, where predictions are consistently biased. Which two actions should the specialist take to try to improve model performance? (Choose two.)
- A retailer built a simple linear model to predict sales from price, and the residual plot indicates a clear non-linear pattern. Which actions should the ML engineer take next to improve prediction accuracy? (Choose three.)
- A retailer collects purchase records from 20,000 stores and sends them to Amazon S3 using Amazon Kinesis Data Firehose. Each store runs a small server application that transmits the data over the internet. The data is used to retrain a machine learning model daily. The data science team identified existing fields that should be combined into new attributes before training. Which change will produce the transformed records while adding the least operational overhead?
- A retailer deployed Amazon Personalize and observed that recommended-item sales spike right after deployment but then quickly fall. Only historical data from before a recent marketing campaign was used for training. What change should you make to improve and sustain recommendations?
- A retailer has 1,000 customer reviews (each labeled for durability concerns) and many reviews contain empty fields. The team must build a model to detect reviews mentioning product durability and have it ready within 2 days. Which approach is the most direct way to meet this 2-day requirement?
- A retailer is collecting purchase records from 20,000 stores into Amazon S3 via Amazon Kinesis Data Firehose. Daily model training requires simple attribute transformations and some field combinations. Which change requires the least development effort to apply these simple transformations before training?
- A retailer needs 30-day demand forecasts for thousands of items using years of daily data. Stockouts are much more costly than overstock. Item-level features (category, brand, safety stock) are available, and a binary promotion flag exists but only has known future values for 5 days. Which Forecast algorithm and evaluation metric should be selected to maximize profit under these constraints?
- A retailer needs a recommendations system that provides recommendations for existing users based on each user's browsing history and filters out items the user already purchased. Which solution meets these requirements with the least development effort?
- A retailer stores 100 GB of transactional data in S3 daily and needs to detect the data schema, perform transformations on the S3 data, and use ML to detect fraud, all with minimal operational overhead. Which combination of services should they use? (Choose three.)
- A retailer uses overhead photos of product tops on shelves to detect which items were removed. They labeled 1,000 images covering 10 different items, but model performance is poor. Which approach best meets the company's long-term needs?
- A retailer with 2,000 stores needs forecasts per geographic area that account for holidays and weather. They want to test the model for 2–3 days and need it to adapt to supply chain and store constraints. Which combination of steps provides the required functionality with the least operational overhead? (Choose two.)
- A SageMaker endpoint running the built-in Image Classification model on an ml.m5.xlarge instance is experiencing unacceptable inference latency, and ModelLatency is the dominant contributor. Latency worsens when multiple users call the endpoint concurrently. Which action will reduce inference latency for these researchers?
- A SageMaker notebook instance has been running for several weeks and new Jupyter and SageMaker software updates are available. Your security policy requires that running notebook instances use the latest SageMaker-managed software and security updates. What is the simplest way for a data scientist to ensure the notebook instance receives those updates?
- A sanitized dataset has features whose scales differ by orders of magnitude. To maximize prediction accuracy in production, which sequence of steps should you follow before modeling?
- A security team ran a pilot with 100 cameras that uploaded images to object storage and used an image recognition service to tag images and store results in a search index. They now want to scale to thousands of cameras globally to detect suspicious activities by non-employees in near real time. Which architecture should they consider?
- A security vendor receives telemetry every 30 seconds from thousands of global endpoints. Records are ~1 KB with 50 fields. Data is ingested into Kinesis Data Streams, and hourly summaries must be produced for Athena queries that will read 7–12 fields. Which approach requires the least customization to transform and store the ingested data?
- A sentiment analysis model has low validation accuracy, and the data scientist suspects a very large vocabulary with low average word frequency is the issue. Which preprocessing or method would best improve validation accuracy?
- A social media company will train an image-classification model (using SageMaker’s built-in image classifier) to detect offensive content. They will use pipe mode to speed training. The dataset is split into Training, Validation, and Test folders, with class subfolders, images resized uniformly, and two manifest files named training.lst and validation.lst. They created separate S3 buckets for training and validation uploads. What additional data-preparation step should they perform before uploading to S3?
- A Specialist has a very large training dataset in S3 (millions of records). They want to avoid copying all data to a SageMaker notebook's 5 GB EBS volume but still train on the complete dataset. Which workflow allows using the full dataset for training with minimal local copying?
- A specialist must choose between a naive Bayes model and a full Bayesian network. Pearson correlations between features have absolute values ranging from 0.1 to 0.95. Which model better represents this data?
- A specialist needs to move and transform data for training. Some data must be processed near-real time and other data hourly. Existing Amazon EMR MapReduce jobs perform cleaning and feature engineering. Which two services can feed data into those MapReduce jobs? (Choose two.)
- A specialist performed a load test on one instance and found peak requests per second (RPS) without degradation ≈ 20 RPS. For initial deployment they will use an invocation safety factor of 0.5. SageMakerVariantInvocationsPerInstance is measured per minute. What value should they set for SageMakerVariantInvocationsPerInstance?
- A startup runs complex deep neural network training using GPUs. The workflow pulls datasets from S3, loads a TensorFlow model from the company git repo, runs locally, and writes progress to S3. The job supports pausing and resuming, is queued centrally, and currently takes several hours. Managers want this weekly workload automated to run each Monday and complete by Friday at lowest cost while scaling. Which architecture best meets this requirement at the lowest cost?
- A system saves new documents to S3 every 3 seconds. Three SageMaker model versions exist to classify each document, and the company wants to deploy all three to classify each incoming document while keeping operational overhead minimal. Which deployment approach meets this requirement with the least management effort?
- A team has a TensorFlow training script that they currently run locally and want to train on SageMaker as cost-effectively as possible. Which TensorFlow estimator configuration will reduce training cost the most while still using the existing script?
- A team must automate inspection of drone photos to find corroded areas (multiple areas per photo possible). Corrosion appears in only about 0.1% of photos. Engineers categorize each corroded area as urgent repair, scheduled maintenance, or no action. Which combination of steps should the team take to build this solution? (Choose three.)
- A team must build a model that determines whether people in images are wearing the company’s retail brand. Given a labeled image dataset, which type of machine learning model is most appropriate?
- A team set their SageMaker hyperparameter tuning job to stop based on MaxNumberOfTrainingJobs. They want tuning to halt automatically when the tuning algorithm determines that no configuration is likely to improve the objective metric by more than 1% over the current best job. Which tuning completion criterion achieves this behavior?
- A team trained a CNN on Amazon SageMaker with GPUs and will deploy it to a SageMaker endpoint for real-time mineral image identification. They already know the expected traffic pattern and need to choose the best instance type and configuration. Which approach requires the least development effort to pick the right instance configuration?
- A team trains an Apache MXNet digit classifier in SageMaker and wants (1) an alert if the model starts overfitting and (2) auditors to be able to review SageMaker API activity. What is the simplest solution with minimal code and steps?
- A team using Amazon SageMaker finds the default built-in image classification algorithm (ResNet) gives low accuracy and they want to use an Inception architecture instead. Which approaches will let them train with Inception? (Choose two.)
- A team wants to build a churn-prediction model and run predictions directly inside an Amazon Redshift cluster using Redshift ML. Which steps should they take? (Choose three.)
- A team wants to run multiple versions of a prediction model in production long-term, control the proportion of inferences served by each version, and minimize implementation effort. Which solution best meets these needs?
- A team will build a binary fraud detector using only two features: account age and transaction month. The class distributions (shown) suggest certain separability. Which model is likely to achieve the highest accuracy?
- A team will preprocess text with part-of-speech tagging and key phrase extraction, then feed the processed text into a custom classifier already implemented and trained with Apache MXNet. Which approach lets the team deliver this solution most quickly?
- A telecom company deployed a model trained on several years of data from one region to identify customers likely to cancel when they call support. The company will roll out a global product and fears the model may wrongly route many calls from regions without training data to a specialist team. What approach most effectively addresses this risk?
- A TensorFlow model uses an existing train.py script and static training data stored as TFRecord files. The team wants to provide this data to SageMaker with the least development work. What is the simplest way to supply the training data to SageMaker without changing the training code?
- A time-series forecasting model implemented in TensorFlow runs on a single GPU and takes ~23 hours to train daily. The team expects training data to grow and needs to retrain hourly in the future while minimizing code and infrastructure changes. What change will best allow the training to scale for future demand?
- A trucking company collects about 100 GB of new images per day from trucks worldwide. They want to explore ML use cases and ensure that only specific IAM users can access the data. Which storage option gives the most flexibility for processing and allows access control via IAM?
- A university wants to predict whether an applicant will enroll so it can target recruitment efforts. The data scientist has academic histories and wants to build applicant profiles for prediction. Which two steps should the data scientist take to build a model that predicts enrollment likelihood? (Choose two.)
- A utility company will forecast energy usage for residential and commercial customers using 10 years of historical consumption plus features like weather, occupancy, and holidays. Using a managed forecasting service, which algorithm is most appropriate for this scenario?
- A web company trains a deep learning multi-class model and sees 90% accuracy on training data but only 70% on test data (overfitting). To maximize accuracy on validation and test sets before deployment, which action is most likely to help the model generalize best?
- A wholesaler supplies clothing to thousands of stores and needs a model that predicts daily sales per item per store. Over half the stores are less than six months old. Sales are consistent week to week. The current dataset is weekly-aggregated and omits weeks with no sales. Five years of data (100 MB) are in cloud storage. Which issues are likely to harm forecast performance, and what actions should you take to address them? (Choose two.)
- After training a regression model, a specialist wants to determine whether predictions tend to be systematically above or below the true values. Which diagnostic method will show whether the model is overestimating or underestimating the target?
- After training a time-series forecasting model in SageMaker, a Specialist needs to run load tests on the endpoint and monitor latency, memory, and CPU during the test. Which approach provides a consolidated view of these metrics during load testing?
- An aircraft engine manufacturer collects 200 time-series metrics during testing and wants near-real-time detection of critical defects while retaining all data for offline analysis. Which approach is MOST effective for near-real-time anomaly detection?
- An Amazon Lex bot uses a custom slot type with three values: "comedy", "adventure", and "documentary". Users sometimes say words like "funny", "fun", or "humor", and Lex fails to map these to the existing slot values. You cannot change the Lambda fulfillment code or the DynamoDB data. What is the best way to make Lex accept those utterances as the same category?
- An amusement park wants to capture, monitor, and store real-time video from cameras at several entrances. Security staff need immediate viewing access; stored footage must be indexed and available to the data science team. Which is the most cost-effective solution that satisfies these requirements?
- An autonomous vehicle company trained object-detection models with transfer learning using PyTorch in SageMaker. Vehicles have limited compute and battery; the company needs to reduce model size and runtime without substantially harming accuracy. Which approach will improve the model’s computational efficiency?
- An autonomous vehicle team uses transfer learning with PyTorch and the SageMaker SDK. They need to reduce inference time for low-latency self-driving use. Which process should they use to analyze and improve model inference performance?
- An e-commerce company classifies product images by product line. A computer vision model trained with an image-classification algorithm has low accuracy on new products. Images are uniform size and stored in cloud object storage. The company needs faster improvement to deploy for new products. Which steps would raise accuracy? (Choose three.)
- An e-commerce company finds that customers seldom view the items the site recommends. The company wants to show product recommendations that customers are more likely to purchase. Which option will achieve this in the shortest amount of time?
- An e-commerce site’s search results are not surfacing the items customers are most likely to buy. The company wants the simplest, lowest-operational-effort fix to present results ranked by what customers are most likely to want. Which solution meets that need with the least operational overhead?
- An ecommerce business needs a scalable repository that stores structured and unstructured data, provides a central data catalog, enables self-service access, and enforces granular access controls and encryption. Which minimal-setup combination will achieve this? (Choose three.)
- An ecommerce company has a deployed SageMaker factorization machines (FM) endpoint for product recommendations. The team trained two new models (TensorFlow and PyTorch) and needs to run A/B tests with these routing rules: send 70% of traffic to the FM model, 15% to the TensorFlow model, 15% to the PyTorch model; but for customers from Europe, route all traffic to the TensorFlow model. Which architecture supports this behavior?
- An ecommerce company has unlabeled historical transaction CSV data in S3 and needs to detect anomalous transactions (fraud). Which combination of models should they use to detect anomalies in this unlabeled dataset? (Choose two.)
- An ecommerce company wants to create five customer segments using age, income, and location, but the existing labels are unknown. A previously trained XGBoost model predicts whether a customer will respond to an email using those features. Why is the XGBoost model unsuitable for creating five segments, and what change would satisfy the requirement?
- An ecommerce site hosts a TensorFlow product recommendation model on a SageMaker endpoint using three compute-optimized instances to handle expected peak traffic. At the start of each month response times spike and some users see errors. Most traffic occurs weekdays from 8 AM to 6 PM in a single time zone. Which two actions most effectively fix the problem while minimizing cost? (Choose two.)
- An ecommerce team trains a large image classification model with 10,000 classes across many training iterations. They need to minimize operational overhead and cost while avoiding loss of work and retraining. Which approach best satisfies these needs?
- An ecommerce team wants to deploy a new SageMaker model behind their existing real-time recommendation API without changing client applications, and they want to test the new model on a portion of production traffic before full rollout. Which approach provides this with the least operational overhead?
- An employee found a video clip with Spanish audio and wants to perform sentiment analysis but only speaks English. Which combination of services is the most efficient way to get sentiment from the clip?
- An engraving company wants to automate quality control for engraved plaques. They have an S3 bucket with images of defective plaques that should be rejected. Low-confidence automated predictions must be routed to an internal review team using Amazon Augmented AI (A2I). Which solution meets these requirements?
- An insurer trained an Amazon SageMaker built-in Object Detection model (TensorFlow) to find scratches and dents in car photos. The model shows much better performance on the training set than on the test set. Which action is most appropriate to improve the model's performance on the test (validation) data?
- An interactive dictionary needs vector features for words so the app can show words used in similar contexts. Which approach best provides those features for a nearest-neighbors model?
- An ML engineer needs to examine the distribution of car prices for a specific car type in a dataset with attributes like brand, type, fuel efficiency, and price using SageMaker Data Wrangler. Which visualization is most appropriate to inspect the range and distribution of prices for that car type?
- An ML engineer needs to retrieve only the most recent version of a single customer's metadata record from SageMaker Feature Store for real-time inference. Which API or method should the engineer use?
- An ML engineer used Bayesian optimization in SageMaker for hyperparameter tuning and optimized for precision. They now want to optimize recall instead and expand the search range for some hyperparameters, including the previous range. Which approach will complete the new tuning job in the least time?
- An ML specialist builds a credit scoring model using 3 years of transaction and third-party metadata but finds low accuracy on both training and test sets. Which actions would improve model accuracy? (Choose two.)
- An ML specialist collects daily usage logs and appends customer metadata including age, then creates two categorical features: dayofweek and binned_age. To explore how usage varies by day of week across age groups, which analysis method should the specialist use?
- An ML specialist has a custom container image used to train an image classifier in Amazon SageMaker and wants to compare hyperparameter optimization (HPO) results from that custom image to results from SageMaker's built-in image classification algorithm. All experiments and HPO jobs must be launched from scripts inside SageMaker Studio notebooks. Which approach will let the specialist do this in the least amount of time?
- An ML specialist is building a computer vision model to classify 10 traffic sign categories. The team has 100 labeled images per class stored in Amazon S3 and an additional 10,000 unlabeled images. All images are 224×224 from dash cameras. After several training runs the model is overfitting the training data. Which actions should the specialist take to reduce overfitting? (Choose two.)
- An ML specialist is fitting a linear least squares regression model on 1,000 examples and 50 features, and notices two features are perfectly linearly dependent. Why is this problematic for linear least squares regression?
- An ML specialist is preparing data with a PySpark job that includes complex window aggregations. They want to test how different feature counts and sample sizes affect model performance. Which approach lets them record transformation parameters and results so they can evaluate and compare data preparation variants?
- An ML specialist is running distributed training of a BERT model on eight SageMaker instances. The training data resides in S3. What combination of steps should be taken to protect data during distributed training? (Choose three.)
- An ML specialist must forecast daily sales for one store using 10 years of historical daily sales data. About 10% of days in the historical record have missing sales values. The forecasting model underperforms. Which action is most likely to improve model performance?
- An ML specialist trains a DeepAR forecasting model on CPU-based EC2 On-Demand instances and training takes many hours. Which two actions will reduce the total training time? (Choose two.)
- An ML specialist trains deep-learning computer-vision models on an EC2 instance with a 12:1 CPU:GPU ratio and finds the GPU is idle about half the time. They must reduce training costs without lengthening job durations. Which option meets this requirement?
- An ML Specialist uses a SageMaker notebook instance in a private subnet and stores important data on its attached EBS volume. They cannot find the notebook instance's EC2 instance or EBS volume inside their VPC. Why is the instance not visible in the customer's VPC?
- An ML specialist’s deep-learning sentiment model trained on movie reviews exhibits overfitting after validation. Which actions will most improve generalization and reduce overfitting? (Choose three.)
- An on-premises web app with a PostgreSQL database must upload non-sensitive daily data to Amazon S3 for model retraining. Sensitive data must never leave the data center and all cloud-bound traffic must use IPsec. How should you securely transfer only non-sensitive data to S3 each day?
- An online delivery company has one XGBoost model per city stored in S3 and currently hosts each model on its own EC2 instance (5% utilization). They want the web app to select the fastest courier in real time for both existing and new users while minimizing operational overhead. Which solution achieves this with the least management effort?
- An online fashion company wants an S3-based data lake that supports real-time analytics, interactive analysis of historical data, clickstream analytics, and personalized product recommendations. Which combination of AWS services should be used to meet these requirements?
- An online retailer combined many data sources into a single table with 980 variables. You need to build a model to discover groups of customers likely to respond to a marketing campaign. Which pair of techniques should you use?
- An online retailer will send up to 100 transactions per second into Amazon Kinesis Data Streams. Each JSON record is 100 KB. What is the minimum number of Kinesis shards required to ingest this data without exceeding shard limits?
- An online store uses linear regression to predict future book sales. One numeric feature is 'duration' (days the book has been listed). Exploratory analysis shows the relationship between sales and duration is skewed and non-linear. Which transformation is most appropriate to improve the model?
- An XGBoost model performs well on test data but overfits and performs poorly on unseen data. Which hyperparameter adjustment is recommended to reduce overfitting?
- At a marathon, each runner has a race ID printed on the front of their shirt. The company must extract those race IDs from runner images with the least operational overhead. Which option meets this requirement?
- Automatic model tuning jobs are taking a long time and continue running even when they are no longer improving the objective metric. You want tuning to stop unpromising training jobs automatically to speed optimization. Which SageMaker automatic model tuning setting should you enable?
- Before selecting features for a risk-analysis model, an ML engineer wants to estimate how much each training feature contributes to the target. Which SageMaker Data Wrangler approach is appropriate to obtain feature contribution or importance estimates?
- Company acronyms are being mispronounced when generating speech with Amazon Polly. What should be done to ensure correct pronunciation in future synthesized documents?
- Design a daily ETL workflow with these requirements: start when new data is uploaded to S3; once all needed uploads are present, run an ETL job that joins the new data with multiple-terabyte datasets in S3; write the join results back to S3; and notify an administrator if any job fails. Which architecture meets these requirements?
- During development, a data scientist uses a cloud notebook to run light feature-engineering tasks during business hours. A data engineer uses the same notebook about once per day to run heavy memory-intensive preprocessing (about 2 hours); preprocessing does not use GPUs. Currently both run on a general-purpose ml.m5.4xlarge notebook instance. The monthly AWS budget has been exceeded. Which change will yield the greatest cost savings?
- Each morning, a rental car company needs automated insights about the previous day’s reservation demand. Data should stream to S3 in near real time, detect high-demand vehicles per location, and appear on a dashboard that refreshes automatically. Which approach delivers this with the least development effort?
- Editors need a search tool that returns articles where queried words are most important and representative in the document corpus. The initial tool returns general word matches and requires manual filtering. Which solution will capture per-document word importance and frequency so the tool highlights articles where queried words matter most?
- Given a confusion matrix for a movie-genre classifier, what are the true-class frequency for Romance and the predicted-class frequency for Adventure?
- Given a two-feature dataset (account age and transaction month) for labeling behavior as fraudulent or normal, which of the following models is most likely to achieve the highest recall for the fraudulent class?
- Given only the shown residual plot for a linear regression model, what is the MOST likely issue with the model?
- Given the forecast plot from a time-series model (showing predicted values vs. actuals), what conclusion can you draw about the model's behavior based only on that plot?
- In a high-risk environment for a binary classifier, missing a positive case (false negative) has no cost, but making a false positive is extremely costly. Which performance metric should be the primary focus when optimizing this model?
- SageMaker notebook instances in a VPC use interface endpoints so API traffic stays on the AWS network, but users outside the VPC still can access the notebook instances over the internet. What actions should you take to prevent external users from accessing the notebooks while allowing legitimate VPC-based access?
- To prepare 1 million sentences for Word2Vec embeddings (example: "The quck BROWN FOX jumps over the lazy dog"), which operations should be applied to sanitize and prepare the text consistently? (Choose three.)
- To protect sensitive training data from being exfiltrated by malicious code running in a training container, which action provides the strongest protection?
- Using Amazon SageMaker Data Wrangler, a data scientist wants to pick predictor variables that best predict a target. The predictors are correlated with the target and the scientist wants to understand variance in different directions across feature space. Which approach meets these needs?
- Using SageMaker Clarify, an ML specialist discovered that the training data has noticeably fewer examples for customers aged 40–55 than for other age groups. Which type of pretraining data bias does this observation represent?
- When checking a feature for a linear regression model, the data shows a strongly right-skewed distribution. Which transformation is most appropriate to help satisfy the regression assumptions?
- When launching an Amazon SageMaker training job with a built-in algorithm, which parameters are required to be provided? (Choose three.)
- When preparing CSV training data for a SageMaker built-in algorithm, converting the dataset to a numpy.array reduced training speed. What should you do to optimize training data for SageMaker built-in algorithms?
- Which AWS services integrated with Amazon SageMaker provide logs of user API activity (such as model deployment events) and metrics for resource utilization and errors on hosted endpoints? (Choose two.)
- Which metric is generally most appropriate for comparing and evaluating classification models against each other?
- While training a neural network with mini-batches for a classification task, the training accuracy fluctuates wildly between iterations. What is the most likely cause?
- While training a regression model that predicts delivery time in minutes, which evaluation metrics should the data scientist use? (Choose two.)
- While tuning a tree-based ensemble model with AUC as the objective, which visualization helps decide how to adjust a hyperparameter range (for example, maximum tree depth) to reduce training time and cost?
- You are building a full Bayesian network for a public-transit dataset. One discrete variable represents how many minutes a commuter waits for a bus; buses arrive every 10 minutes and the observed mean wait is 3 minutes. Which prior distribution is most appropriate for this discrete waiting-time variable?
- You are building a logistic regression model to predict customer churn using 100 continuous numerical features. Marketing has no guidance on which features matter and wants an interpretable model showing how features affect the outcome. During training you observe a large gap between training and validation accuracy. Which two actions will (1) reduce overfitting and (2) support feature interpretability? (Choose two.)
- You are building a regression model to predict patient outcomes. In a dataset of 4,000 patients (all over age 65), 450 records have the age recorded as 0 while other features look reasonable. How should you handle these incorrect age values?
- You are building a regression model to predict rental rates. A categorical feature Wall_Color indicates the property's dominant exterior color. Which feature-engineering methods will allow this model to use the Wall_Color data? (Choose two.)
- You are building an automated trading agent that recommends how many units of an asset to buy or sell and at what price to maximize long-term returns. The agent will be continuously trained on streaming transaction data. Which type of machine learning algorithm is appropriate for this sequential decision-making problem with long-term reward optimization?
- You are building linear prediction models (like linear or logistic regression) for a dataset with many features. Exploratory analysis shows many features are highly correlated, which can destabilize the model. What should you do to reduce the negative effects of having many correlated features?
- You are developing a TensorFlow project that uses Amazon SageMaker for training but will be offline without Wi‑Fi for an extended period. Which approach allows you to continue working locally with minimal changes?
- You are packaging a custom ResNet training environment into a Docker container to run on GPU instances (NVIDIA) in SageMaker (using EC2 P3 instances). What must you do so the container can use the GPUs properly?
- You are predicting future employment rates from many economic features whose magnitudes differ greatly. To prevent features with large magnitudes from dominating the model, what preprocessing step should you apply before training?
- You are training a supervised image classifier to detect cats. You have 1,000 total images and a fixed test set of 100 images. You observe that over 75% of misclassifications occur when owners hold cats upside down. Which technique will specifically reduce this type of error?
- You are tuning a logistic regression model and want to evaluate how different classification thresholds affect performance. Which evaluation tool should you use?
- You built a bird classification model by randomly splitting the dataset into training and validation sets. Training accuracy is very high but the model performs poorly on the validation set. You discover the original dataset is imbalanced. What should you do to improve validation performance?
- You built an XGBoost model to predict whether a customer will return a purchase. Only 5% of examples are returns. You must maximize detection of returned items while working with a small compute budget. What is the most cost-effective hyperparameter tuning approach?
- You created a VPC with a VPC interface endpoint for the SageMaker Service API. You want to restrict access so only certain EC2 instances and IAM users can call the SageMaker API. The VPC has a single public subnet. Which two actions will secure access to the endpoint? (Choose two.)
- You have a 2 TB dataset in Amazon S3 and a trained model container stored in Amazon ECR. You must run a cost-effective, scalable batch scoring job for the dataset. Which option is the most cost-effective scalable solution?
- You have a dataset of 1,000,000 labeled 200x200 images indicating whether a car is present or not. Which neural network architecture and output layer choice is most likely to produce the highest accuracy for detecting the presence of a car in an image?
- You have a dataset of customer shopping behavior with thousands of features and many numeric columns per customer. You want to quickly find natural groupings among customers and visualize the result. What should you do?
- You have a dataset of supplier locations recorded as two-letter country codes (for example, NZ for New Zealand). You must convert these codes into numeric variables for model training while (1) avoiding any information loss and (2) minimizing the increase in dimensionality. Which transformation meets these requirements?
- You have a dataset with a categorical Day_Of_Week field and you need to convert it into binary indicator variables for use by a machine learning model. Which technique should you use?
- You have a labeled dataset of 1,200 products, each described by 15 numeric features (title, dimensions, weight, price, etc.) and assigned to one of six categorical product classes. Which model is most appropriate to train for classifying new products using this dataset?
- You have a labeled image dataset with two classes: lion or cheetah. You want to train a model that, given a new image, predicts whether it contains a lion or a cheetah. Which SageMaker algorithm choice is appropriate?
- You have a pretrained hybrid model composed of a CNN followed by a 3-layer RNN that was trained to classify a different set of objects. To adapt it to a new but related classification task with the least effort, which actions should you take? (Choose two.)
- You have a tabular dataset with 10,000 rows and 1,020 features. There are no missing values, few duplicates, and about 200 feature pairs with correlation > 0.9. Feature means are similar to medians. Which feature-engineering approach should you apply when training a model in SageMaker?
- You have a tabular dataset with 150 correlated features that have different numeric ranges and you need to reduce dimensionality with minimal impact on model performance before training a regression model. Which preprocessing approach meets this goal?
- You have an existing TensorFlow training script (train.py) that reads static training data stored as TFRecord files. You need a scalable storage solution for training on Amazon SageMaker with the least amount of code changes. Which approach minimizes development effort?
- You have CSV files in Amazon S3 that include a timestamp column formatted like: March 1st, 2020, 08:14pm. You hypothesize that weekday, month, and hour affect the target variable, so you need to add three new features (day of week, month, hour) to the dataset. Which approach adds these features while requiring the least operational overhead to produce a new file in S3?
- You have customer and insured-pet profiles, policy details, premiums, and claims stored in a relational database. A marketing manager wants to run a targeted social-media campaign to find new potential customers with similar profiles. Which modeling approach is most appropriate to identify distinct customer segments for matching on social media?
- You have customer data for an online retailer (demographics, visit history, location). The goal is to discover customers' shopping patterns, preferences, and trends to improve the site and provide personalized recommendations. Which approach is most appropriate?
- You have historical CSV data in S3 containing product inventory demand and need to prepare it for Amazon Forecast. How should you transform and upload the data so Forecast can train models effectively?
- You have historical training data stored in Amazon RDS and want to train a SageMaker model using that data for a production end-to-end workflow. What is the recommended approach to get the RDS data into SageMaker for training?
- You have implemented a custom training algorithm inside a Docker container that Amazon SageMaker will use. How should you package the container so SageMaker can start training correctly?
- You have IoT soil sensor data in a 10 GB Amazon DynamoDB table and weather event data as 5 GB of JSON files in Amazon S3. You want to prepare this combined dataset to train an Amazon SageMaker model with the least administrative overhead. Which approach best accomplishes the required transformation?
- You must analyze user comments on a global news website to identify the most discussed topics. Comments are written in English and Spanish. Which steps would accomplish this task? (Select the best option.)
- You must build a real-time predictive maintenance pipeline that receives device data from remote sites (no Direct Connect or VPN). The pipeline must: ingest data into Amazon S3 in real time, transform incoming raw records into clean CSV during ingestion, store the original raw records in S3, and place any records that fail transformation into a designated S3 location for human review. Which architecture requires the least effort to meet these requirements?
- You must maximize AUC for a binary classification problem using XGBoost and need to search for good values of eta, alpha, min_child_weight, and max_depth with minimal operational overhead. Which approach requires the least operational effort?
- You must produce embedding vectors from an English sentence collection so downstream models can use them. Sentences often reuse words in different contexts and include question–answer pairs; the embeddings should capture word context and sequence/QA information. Which SageMaker options can generate embeddings that meet these needs? (Choose two.)
- You must run a SageMaker Processing job from a SageMaker notebook to read data from a private S3 bucket encrypted with a KMS customer master key, preprocess it, and write results back to the same bucket. The preprocessing code is stored in a container image in Amazon ECR. What set of permission-related actions should you take to permit the notebook to create and run the processing job and allow the job to access the S3 bucket, the KMS key, and the ECR image?
- You must train and host a SageMaker model using sensitive customer data that must be encrypted at rest. The company wants AWS to maintain the root of trust for the keys but also requires that all key usage is logged. Which encryption approach satisfies these requirements?
- You need a serverless, real-time ingestion and analytics pipeline for high-volume streaming JSON events. The pipeline must buffer data, convert JSON to a columnar format optimized for queries without losing data, store results in a highly available datastore, and let analysts run SQL queries and connect BI dashboards. Which design best meets these requirements?
- You need to detect whether people in images are wearing the company logo. Given a labeled image dataset for training, which type of algorithm is most appropriate?
- You need to ingest streaming data and persist it as Apache Parquet files for analysis. Which AWS service both ingests streaming data and can deliver it in Parquet format to storage?
- You need to merge two datasets—customer orders and product catalog descriptions—that have different structures and formats, matching similar records and removing duplicates. Which solution is the most appropriate for matching and cleansing this data?
- You need to perform exploratory data analysis (EDA) on a petabyte-scale dataset, without managing cluster infrastructure, paying only for queries you run, and writing analysis in Python from a Jupyter notebook. Which solution satisfies these constraints?
- You need to query a dataset in Amazon S3 using Amazon Athena. The dataset contains over 800,000 CSV records; each record has 200 columns and is about 1.5 MB in size, but most queries access only 5–10 columns. Which format conversion will minimize query runtime?
- You need to resample irregular, partly missing time-series data to daily frequency and export it for modeling with the least implementation effort. Which tool is the simplest option?
- You need to run sentiment analysis on one million social media posts using Amazon Comprehend. Which approach will finish processing the dataset in the least amount of time?
- You need to use Amazon SageMaker DeepAR to forecast required input materials and energy, but most training records have missing target values and the data is stored as JSON. Which approach requires the least development effort to handle the missing target values for training DeepAR?
- You need to visualize recommendation data across four variables: map two variables to the x and y axes, use color to encode a third variable, and use marker size to represent a fourth variable. Which visualization and tool will support these mappings?
- You operate a production model endpoint with automated model-quality monitoring. After the monitoring system reports violations, you retrain the model using a dataset that reflects current production traffic, deploy the new model, and run the first monitoring job. Violations persist on the endpoint. What should you do to resolve the reported violations?
- You plan to create a long-running Amazon EMR cluster with 1 master node, 10 core nodes, and 20 task nodes, and want to use Spot Instances to reduce cost. Which nodes are appropriate to run on Spot Instances?
- You received a CSV dataset in S3 that you will use for ML training. Before training, you must find missing or invalid values and count outliers with the least operational effort. Which approach meets this requirement?
- You train a multilayer perceptron on a multiclass dataset where one target class is rare and recall for that class is too low. Changing the MLP architecture doesn’t help. What change is most likely to improve recall quickly?
- You train a text classifier with a built-in word-embedding algorithm. The dataset has five classes with these sample counts: A=300, B=292, C=240, D=258, E=310. You shuffle and set aside 10% for testing. After training, confusion matrices for train and test sets are produced. What conclusion can be drawn from these results?
- You trained a scikit-learn logistic regression model locally and now want to deploy it on Amazon SageMaker for inference only. What steps are required so SageMaker can host the locally trained model?
- You trained an image classification model and see signs of overfitting: 99% training accuracy but only 75% test accuracy. What change should you make and why?
- You uploaded 5 TB of data to SageMaker Studio and completed data cleaning. Before training, you need an analysis report that highlights potential dataset bias. Which two actions provide this with the least overhead? (Choose two.)
- You uploaded data to an S3 bucket encrypted with AWS KMS. How should you configure a SageMaker notebook so it can read that encrypted dataset from S3?
- You uploaded sales data into SageMaker Studio and need feature importance scores to guide feature engineering with minimal development effort. Which option provides importance scores with the least work?
- You used 3 years of monthly inventory data for one SKU across 10 warehouses in Amazon Forecast. With DeepAR+ the predictor’s MAPE is much worse than the human forecasts. Which changes to the CreatePredictor API call could improve accuracy? (Choose two.)
- You want to detect fraudulent accounts and identify whether a newly created account matches any previously known fraudulent accounts. You are cleansing logs with AWS Glue during ingestion. Which approach should you use to find likely duplicate or matching fraudulent accounts?
- You want to reduce the total computation time required for a large SageMaker hyperparameter tuning job (previous smaller jobs took weeks). Which two actions will most reduce overall tuning computation time?
- You want to route a small portion of traffic to a new model version for preview users, evaluate it, and then gradually shift all traffic to the new model over a fixed timeframe with minimal operational overhead. Which SageMaker approach accomplishes this with the least operational work?
- You're performing transfer learning for vehicle make-and-model classification using a pretrained model trained on general images. You have a large labeled dataset of vehicle images. How should you initialize the model before retraining on your vehicle dataset?
- Your data science team uses managed notebook instances to access data in secured object storage. Security policy requires that all notebooks run inside a private corporate network with no internet access, and all traffic to storage and managed ML services must stay within the cloud provider's network. How should notebook instances be configured to satisfy these requirements?
- Your organization disallows direct internet access from managed notebook instances but still needs to use the managed ML service. How can you enable the managed service without granting internet access to the notebook instances?
- Your organization has multiple SageMaker Studio domains (one per department). You want a central proxy app that authenticates users with the company's identity provider and then routes each user to their department's Studio domain. You will store the domain mapping in a DynamoDB table. Which API should the proxy use to send users to the correct Studio domain?
amazon marketing cloud All exam questions
- How can you determine if NULL values are the result of aggregation thresholds or a natural occurrence within your report?
- How would you adapt this query to limit results to Sponsored Products keyword targeting only?SELECTad_product_type,targeting,customer_search_term, match_type,SUM(spend)/100000000 AS total_cost_dollars,((SUM(spend)/100000000)/SUM(impressions))*1000AS avg_cpm,SUM(impressions)AS impressions,SUM(clicks)ASclicks, (SUM(clicks)/SUM(impressions))AS c tr FROM sponsored_ads_traffic WHERE match_typeIN('PHRASE','BROAD','EXACT')GROUPBY1,2,3,4
- If you want to understand more about which product or pixel your conversion events are associated with,which field in the amazon_attributed_events_*tables should you leverage?
- New-to-brand metrics are only relevant for__________.
- Since the amazon_attributed_events_*tables contain ad-attributed conversions across all of your Amazon Ads media,you can aggregate them by sponsored ads vs.Amazon DSP using the__________.
- SuperPower Batteries,a consumer packaged goods brand,is new to AMC and wants to learn more about what tables are available to query.Where in the AM CUI can they find this information?
- The_____________field in the conversions_with_relevance table categorizes the relationship between the conversion event and the campaign it is relevant to.
- The___________function can be used to append a string to ID fields(suchas campaign_id),preventing issues reading the accurate ID values within Excel.
- The_________________panel within AMC is a repository of Amazon-authored SQL templates and includes associated use cases,instructions,and a guide to interpret the results.
- There is not a field for campaign ID in the sponsored_ads_traffic table,sothe _____________field can be used to filter to traffic events from the relevant sponsored ads campaigns.
- This panel provides access to additional subscription-based insights from Amazon or third parties;these insights can be joined with your Amazon Ads events that are already available in AMC.
- To minimize the number of values rendered NULL due to aggregation thresholds, youcan:
- What is an exploratory query?
- What is required to access AM CAP Is?
- When analyzing the relationship between frequency and purchase rate,what actionable insight can you leverage for campaign optimization?
- Where can you find the details of the entities(AmazonDSP,sponsored ads,etc.) linked to an AMC Instance?
- Which event table can be used when attributing conversions to your campaign using custom logic(e.g.,28 day look back window)?
- Which of the following Amazon services can be used to visualize aggregated AMC reports in a dashboard?
- Which of the following statements about paid features(beta)isfalse?
- Which of the following statements about the amazon_attributed_events_*tables istrue.
- Which of these exploratory queries would allow you to generate a list of all Amazon DSP creative active during your chosen time window?
- Which of these statements is false regarding the amazon_attributed_events_by_conversion_timetable?
- Which table should you use in a query meant to help you choose new Amazon audiences that may benefit your Amazon DSP campaign performance?
- Which table would you leverage for a query when your objective is to understand how your current audience strategy is performing for your campaigns?
- Which two functions can be used together to filter records based on presence of a string within a column'svalues?
- Which value is not available for Sponsored Products?
- Why are developer resources required for creating first-party tables in AMC?
- Why is this query unsuitable for assembling a rule-based audience of those who have completed a conversion event?SELECTuser_id FROM conversions
- Why should you wait until 14 days after the enddate of your query date range to run analyses that leverage the amazon_attributed_events_by_traffic_timetable?
- Youcanusea_________filter to limit your query results based on one or more conditions.
Amazon Marketing Cloud (AMC) All exam questions
- A single on-Amazon transaction that includes multiple ASINs from your brand will be represented by a single conversion event within each of the amazon_attributed_events_* tables.
- AMC audience creation leverages a separate set of tables than those utilized for AMC reporting.
- AMC audiences is an API-only feature.
- AMC can be used by brands that don’t sell their products directly in the Amazon store.
- AMC supports most common SQL functions, but there are some unsupported SQL functions.
- AMC users have access to all AMC instances in an account by default.
- Clicks are considered conversion events and appear as individual records within the amazon_attributed_events_* tables.
- Columns in the HIGH and VERY_HIGH aggregation threshold categories cannot be used when applying ____________ to your query.
- Conversions measured via Events Manager can be made available for querying in AMC.
- Cost and fee fields are always reported in microcents.
- Custom parameters help make queries more reusable because they __________.
- Developers can access AMC APIs via the Amazon Ads API gateway.
- Display ads purchased with Amazon DSP can run on Amazon-owned inventory and third-party inventory in both desktop and mobile environments.
- FROM amazon_attributed_events_by_traffic_time WHERE purchases = 1 GROUP BY 1 because the query includes a WHERE Which environment allows you to inspect AMC tables at record level?
- How would you adapt this query to limit results to Sponsored Products keyword targeting only? SELECT ad_product_type, targeting, customer_search_term, match_type, SUM(spend)/100000000 AS total_cost_dollars,((SUM(spend)/100000000)/SUM(impressions))*1000 AS avg_cpm, SUM(impressions) AS impressions, SUM(clicks) AS clicks, (SUM(clicks)/SUM(impressions)) AS ctr FROM sponsored_ads_traffic WHERE match_type IN('PHRASE', 'BROAD', 'EXACT') GROUP BY 1,2,3,4
- If you run multiple Amazon DSP and sponsored ads campaigns and reached similar audiences, which query can help you understand your customers’ conversion paths that have the highest conversion rate?
- In AMC, a conversion is defined as an Amazon.com purchase event.
- Iris, a consumer electronics brand, recently started using AMC to perform analytics on events related to their Amazon Ads campaigns. Why should Iris consider using the instructional query library?
- Nutrition Co., a health snack company, would like to know the total impressions that have been delivered per campaign, per supply_source, per device_type. Which of the following represents how to write this query?
- Overlap analyses enable you to generate insights by comparing different groups of __________ values in isolation and when overlapped.
- Paid features tables are only available in advertiser instances.
- Performance reporting, such as Path to Conversion reporting, can be constrained to specific conversion events (e.g. purchases of a specific ASIN).
- quickly get campaign IDs or other values used to filter in another query because an exploratory query is typically used to gather Which of the following statements about paid features (beta) is false?
- Super Power Batteries, a consumer packaged goods brand, is new to AMC and wants to learn more about what tables are available to query. Where in the AMC UI can they find this information?
- The _________ field contains the pseudonym o us ad identifier associated with a given impression. It is often used in calculations to understand unique reach volumes.
- The __________ field functions as a grouping indicator for the impression and any associated clicks, view events, or conversion events.
- The ___________ function can be used to append a string to ID fields (such as campaign_id), preventing issues reading the accurate ID values within Excel.
- The submitted queries table provides details of the query executed and a link to download your aggregated report as a _______ when it’s ready.
- There is no universal methodology or join key that can be used to combine tables in all query scenarios.
- This table contains impression and click events from Sponsored Products, Sponsored Brands, Sponsored Display, and Sponsored Television campaigns
- This UI component is considered the day-to-day operating room for the analytics practitioner and is used to author and execute SQL queries, as well as download the results.
- To minimize the number of values rendered NULL due to aggregation thresholds, you can:
- user_id values cannot be viewed in the AMC user interface or downloaded from AMC.
- What are custom parameters?
- What are the two ways to access AMC?
- What can Amazon shopping insights be used for?
- What is a primary usage of the UNION ALL function in AMC queries?
- What is an AMC sandbox?
- What is one limitation of AMC SQL?
- What is SQL optimization in the context of AMC?
- What is the Amazon Ads attribution lookback window?
- What is the max window over which AMC can accrue Amazon Ads events?
- What types of Sponsored Products records will have spend metrics?
- When determining total impressions served over a given date range, you can use dsp_impressions or dsp_views.
- Where can you activate AMC audiences?
- Where can you find the details of the entities (Amazon DSP, sponsored ads, etc.) linked to an AMC Instance?
- Which AMC tables would be required for determining the Amazon-attributed conversion volumes per frequency bucket (including Amazon DSP traffic only)?
- Which event table can be used when attributing conversions to your campaign using custom logic (e.g., 28 day lookback window)?
- Which of the following business questions can be answered with an overlap analysis?
- Which of the following statements about AMC lookalike (LAL) audiences is false?
- Which of the following statements about the amazon_attributed_events_* tables is true.
- Which of the following statements is true about using queries within the instructional query library?
- Which of these analyses can be accomplished with an overlap query?
- Which of these is NOT a method of optimizing your AMC SQL?
- Which of these queries will only include purchase records from the underlying table?
- Which of these statements is false regarding AMC audiences?
- Which of these statements is false regarding the amazon_attributed_events_by_conversion_time table?
- Which of these statements is true regarding recurring query automation?
- Which of these use cases can be achieved when using Amazon Ads events in conjunction with first-party inputs?
- Which signals are not available within AMC?
- Which two functions can be used together to filter records based on presence of a string within a column's values?
- Why is it considered a good best practice to exclude NULL user_id values from reach and frequency queries?
- Why is the AMC sandbox a helpful environment for testing queries?
- Why is this query unsuitable for assembling a rule-based audience of those who have completed a conversion event? SELECT user_id FROM conversions
- Why should you wait until 14 days after the end date of your query date range to run analyses that leverage the amazon_attributed_events_by_traffic_time table?
- Why would this query fail? SELECT campaign, SUM(impressions) AS impressions FROM dsp_impressions
- Within the amazon_attributed_events_* tables, Amazon Ads will only attribute conversion events to click events for sponsored ads CPC (cost-per-click) campaigns.
- You can use a _________ filter to limit your query results based on one or more conditions.
Amazon Marketing Cloud Certification All exam questions
- A beauty brand operates both a direct-to-customer website and 50 retail store locations. They want to measure the true return on ad spend by tracking conversions that happen outside of Amazon. Which first-party data use case should they implement?
- A beauty brand selling on Amazon wants to understand whether customers exposed to their ads browse differently than customers who discover products organically. They're deciding between Amazon flexible shopping insights and Amazon Retail purchases. Which feature best addresses their specific need?
- A beverage brand uses AMC's New-to-Brand Gateway ASIN analysis and discovers significant variation in which products attract first-time customers versus repeat buyers. How should they apply this insight to their marketing strategy?
- A beverage brand wants to identify which products are most effective at attracting first-time customers. Which AMC analysis should they use?
- A beverage brand wants to understand how their Amazon display campaigns influence purchases at major grocery retailers. Which premium feature should they consider?
- A brand discovered that customers who saw their ads during Thursday Night Football were significantly more likely to browse their product collection afterward. Which two AMC signal types were combined to generate this insight?
- A brand manually compiles reports from multiple advertising consoles (Sponsored Products, Sponsored Display, Amazon DSP) and cannot answer cross-channel attribution questions. How does AMC address this challenge?
- A brand wants to re-engage shoppers who added products to their cart but didn't complete the purchase. What AMC audience strategy should they implement?
- A brand wants to reach customers exposed to both Sponsored Ads and Amazon DSP campaigns. What AMC capability enables this?
- A brand wants to understand how customers move from seeing a display ad to watching a streaming TV ad before making a purchase. Which clean room benefit does this scenario demonstrate?
- A brand wants to understand which products customers research before making a purchase. Which AMC signal type should they analyze?
- A coffee brand wants to build an audience of customers who viewed their brand store page on Amazon at least three times in the past 30 days but haven't made a purchase. Which audience creation method should they use?
- A company uploads their first-party conversion insights to AMC to understand the relationship between their website events and Amazon advertising signals. What type of analysis does this enable?
- A cosmetics brand wants to identify which Amazon Ads audience segments drove the highest purchase rates in their recent campaign. Which analysis should they conduct?
- A data analyst wants to generate SQL for a custom analysis but needs to understand the logic before executing it. Which tool provides both SQL generation and transparency?
- A eco-friendly homegoods brand wants to scale customer acquisition by reaching shoppers similar to their highest-value customers. Which AMC audience-building strategy should they use?
- A financial services company runs campaigns across streaming TV, display, and audio but cannot determine which channel combinations drive the highest conversion rates. What AMC capability should they use to understand this?
- A financial services company wants to create an audience of customers similar to those who have opened accounts with total deposits over $5,000 in the past 12 months to promote their premium investment services. Which AMC capabilities makes this precise audience segmentation possible?
- A financial services marketing director asks why investing in first-party data infrastructure is more strategic than simply purchasing third-party audience segments. What is the most compelling reason?
- A fitness brand discovered through overlap analysis that only 15% of customers saw both their sponsored ads and programmatic campaigns, but those customers had significantly higher purchase rates. What does this insight reveal about their advertising strategy?
- A fitness brand wants to expand their customer base by finding new shoppers similar to their highest-spending customers based on purchase amount. Which audience strategy should they use?
- A home furnishings retailer has successfully connected their CRM data and D2C website conversions to Ads Data Manager. They now want to combine this first-party data with Amazon's shopping and streaming signals to identify high-spending customer segments. Which stage of the workflow should they move to next?
- A home goods brand wants to understand long-term customer value and identify customers who purchased kitchen appliances 3 years ago who may be ready to upgrade. They need to analyze purchase patterns across multiple years to create specific audiences. Which premium feature provides the extended historical insights they need?
- A home goods retailer wants to recover lost sales from customers showing purchase intent. They identify customers who added products to cart but haven't completed checkout. What type of AMC audience should they create based on this cohort?
- A marketer needs step-by-step guidance on creating a lookalike audience but doesn't know where to start. What should be their first action?
- A marketer wants to understand if combining Sponsored Products with Amazon DSP drives better results than either channel alone. Which query template should they use?
- A marketing team manually compiles reports from multiple advertising consoles, taking 8-10 hours weekly. They cannot answer cross-channel questions. How does AMC address both challenges?
- A media buyer with no SQL experience needs to quickly understand which campaigns overlap with their audience. Which AMC tool should they use?
- A mid-sized advertiser lacks SQL expertise and wants to scale AMC analytics across 15 product categories with automated reporting dashboards. They're deciding whether to build capabilities in-house or work with a certified partner. Which factor most strongly suggests working with a partner?
- A retail brand wants to start using AMC but their team has mixed expertise. They have media planners who understand campaign strategy but have never written SQL, and analysts who can write queries but need business context. How should these roles work together for successful AMC implementation?
- A retailer wants to combine their customer purchase signals with a media partner's streaming viewership signals to understand how cross-channel exposure influences purchasing behavior — without either party sharing raw customer information. Which solution should they use?
- A seasonal outdoor gear brand wants to create an audience of customers who purchased winter equipment during the previous two holiday seasons to reach them for this year's winter campaign. They need to analyze purchase patterns from November 2023 through February 2025. Which AMC capability enables this long-term analysis?
- A sporting goods retailer has connected their email list, CRM data, and in-store purchase history to Ads Data Manager. They want to understand which Amazon touchpoints (streaming ads, display ads, sponsored products) are most effective at driving their high-spending customers to purchase. Where in the workflow should they conduct this analysis?
- A travel company wants to create an audience that combines insights from customers who watched their streaming video ads, browsed vacation packages, and made bookings. Which AMC capability enables this comprehensive audience segmentation?
- A travel services company currently pulls separate reports from Amazon DSP, display, and streaming TV campaigns, spending significant time on manual compilation. They want to understand how different advertising channels work together in the customer journey. What AMC capability addresses this challenge?
- An advertiser has created a high-value customer lookalike audience in AMC. How can they activate this audience across their advertising strategy?
- An advertiser wants to analyze how their Amazon DSP campaigns and Sponsored Products campaigns work together to drive conversions. Which AMC capability should they use?
- An advertiser wants to measure how well an AMC audience drives purchases in Amazon DSP. What is the best practice for setting up and analyzing this audience's performance?
- An advertiser's new AMC lookalike audience has been running for 3 weeks with disappointing performance. What should you recommend?
- An analyst wants to learn AMC query techniques while still generating reliable results for their team. Which approach should they take?
- An athletic apparel brand implemented a first-party data strategy that combined their CRM data, D2C website conversions, and in-store purchase data with Amazon's advertising signals in AMC. Their analysis revealed that customers exposed to both Amazon DSP video ads and their off-Amazon marketing were significantly more likely to make large purchases. Why was AMC critical to discovering this insight?
- An athletic apparel company notices customers frequently purchase running shoes but rarely buy matching athletic wear. They want to promote their new apparel line to existing shoe buyers. Which audience strategy best addresses this cross-sell opportunity?
- An athletic brand wants to prove whether their new Amazon DSP campaigns provide additional value beyond their existing Sponsored Products campaigns. Which AMC analysis should they use?
- An audience segment has the third-highest reach but the lowest purchase rate in your campaign. If your primary goal is maximizing conversions with limited budget, what action should you take?
- An automotive manufacturer wants to see the complete customer journey from initial ad exposure to dealership visits to final vehicle purchases. Which premium feature should they implement?
- An electronics brand wants to understand which customer behaviors lead to purchases. They notice some customers browse multiple products before buying, while others watch streaming content first, and some add items to cart repeatedly. Which AMC capability helps them identify the most effective behavior patterns?
- An experienced analyst wants to build an advanced query that doesn't fit any existing template. They're comfortable writing SQL and need complete creative freedom to define their analysis logic. Which AMC tool best supports their needs?
- An insurance company wants to create a lookalike audience reaching customers who own both a car and motorcycle for an upcoming "insurance bundling" campaign. Which premium feature enables audience creation based on self-declared vehicle ownership?
- An outdoor gear company has connected their D2C website purchase insights to Ads Data Manager. They want to increase their advertising effectiveness by reaching audiences on Amazon who exhibit similar characteristics to their top spending customers on their website. Which use case should they implement to achieve this goal?
- An overlap analysis shows that customers exposed to DSP + Sponsored Brands have a 0.13% purchase rate, while those exposed to only Sponsored Brands have a 0.09% purchase rate. What does this indicate?
- Andre wants to understand how his Amazon DSP campaigns and Sponsored Ads work together. Which AMC use case should he select to compare performance across different ad product combinations?
- Antonio, a media planner without SQL skills, wants to quickly analyze how his Sponsored Products and Amazon DSP campaigns work together. Which AMC tool should he use to get insights without writing code?
- Considering the amazon_attributed_events_ tables contain ad-attributed conversions across all of your Amazon Ads media, which of the following fields would allow you to aggregate them by sponsored ads vs. Amazon DSP?
- For sponsored ads Cost-per-Click (CPC) campaigns, only click events are eligible for attribution of conversion events.
- How long can AMC accrue and retain Amazon Ads events?
- How would you adapt this query to obtain cost and impression metrics by supply_source?
- If a company is already sharing first-party and third-party data with another agency to optimize their marketing strategy, why would they want to use a clean room?
- If a company wanted to increase their bids, programmatically, for their desired customers, what Amazon tool would support their needs?
- Iris, a consumer electronics brand, would like to modify a query to only include purchase records from the underlying table. Which of the following represents how the query should be written?
- Many customers report seeing irrelevant ads daily. Which industry trend does this scenario best illustrate?
- Olivia reviews an audience measurement report for the DSP_Display_2024 campaign and notices that "IM - Lip Care" was NOT applied to the campaign but shows a 0.13% purchase rate with 64,958 reach. This segment is considered:
- Rule-based audience creation leverages a separate set of tables than those utilized for AMC reporting.
- The _________ field contains the pseudonymous ad identifier associated with a given impression. It is often used in calculations to understand unique reach volumes.
- The LIKE function is unsupported by AMC. Which of the following AMC-supported functions can serve as a substitute?
- The Path to Conversion by Campaign Groups IQ considers all touch points but the output is based on the timing of the first impression of the campaign group.
- There is not a field for campaign ID in the sponsored_ads_traffic table, so the _____________ field can be used to filter to traffic events from the relevant sponsored ads campaigns.
- This table contains impression and click events from Sponsored Products (SP), Sponsored Brands (SB), and Sponsored Display (SD) campaigns.
- What is a key advantage of AMC's lookback capability compared to standard campaign reporting?
- What is Amazon Ads' clean room solution that enables advertisers to analyze campaign performance and shopping insights?
- What is first-party data?
- What is multi-party collaboration in AMC?
- What is one way that a clean room maintains privacy?
- What is required to access AMC APIs?
- What is the first step when using AMC to answer a business question?
- What is the primary difference between AMC's core capabilities and premium features?
- What is the primary difference between matched and unmatched segments in an audience measurement report?
- When analyzing customer journeys, a brand discovers that customers exposed to multiple touchpoints convert at significantly higher rates than single-touchpoint customers. What does this insight suggest about their media strategy?
- When creating a lookalike audience, an advertiser must choose between a more similar model (smaller audience) or less similar model (larger audience). Which scenario best justifies using a less similar lookalike model?
- When should an advertiser consider subscribing to premium features rather than using AMC's core capabilities?
- Where in the AMC interface should you navigate to access instant visualizations, recent projects, and your favorited use cases all in one place?
- Which action can be used to determine if NULL values are a natural occurrence within your report or the result of aggregation thresholds?
- Which AWS service can be leveraged by the AWS Admin to provide appropriate permissions and access keys to AMC API users?
- Which environment allows you to inspect AMC tables at record level?
- Which field can be used to filter to traffic events from the relevant sponsored ads campaigns?
- Which field in the amazon_attributed_events_ tables should you leverage if you want to understand more about which product or pixel your conversion events are associated with?
- Which function can be used to append a string to ID fields (i.e., campaign_id) to prevent issues when reading the values in Excel?
- Which industry change has made it more challenging to reliably show how media engagement influences purchase decisions?
- Which of the following statements about paid features (beta) is false?
- Which of these are examples of signal inputs that can used within a clean room?
- Which of these elements are driving the need for clean room use in advertising?
- Which of these is an example of a controlled output from a clean room?
- Which of these options best defines a clean room?
- Which of these statements is false regarding rule-based audiences?
- Which panel within the AMC UI contains a repository of Amazon-authored SQL templates along with use cases, instructions and examples of query results.
- Which signal type provides insights into how customers watch and engage with content across Amazon properties like Thursday Night Football?
- Which solution is purpose-built for first-party data workflows?
- Which statement about rule-based audiences is incorrect?
- Which use case category includes both Rule-Based Audiences and Lookalike Audiences?
- Why is it important to verify that all required inputs are available in AMC before running an analysis?
- You are writing a query and would like to know the total impressions that have been delivered per campaign, per supply_source, and per device_type. Which of the following represents how you should write the query?
- You can activate AMC rule-based audiences on _____________.
- You create a lookalike audience in AMC based on customers who are high-value purchasers and shop weekly. What will the resulting audience contain?
- You must connect your organization's AWS account to AMC in order to leverage the AMC APIs.
- You need to design an AMC learning path for a new team with mixed technical skills: some media planners with no SQL experience and some analysts comfortable with queries. What combination of tools would you recommend?
- You need to design an AMC measurement approach for a brand that wants to: (1) determine if Amazon DSP provides incremental value over Sponsored Ads, and (2) identify which audience segments perform best. What combination of analyses would you recommend?
Amazon ML Engineer Associate MLA-C01 Certification All exam questions
- A bank needs to build a SageMaker AI model to decide customer eligibility for a new product using algorithms that SageMaker directly supports. The model must be explainable to regulators. Which modeling choice satisfies these requirements?
- A batch processing job runs on EC2 instances for 90 minutes each weekend, tolerates interruptions, and will run weekly for six months. Which EC2 purchasing option is the most cost-effective for this workload?
- A binary classification model labels products as "Passed" or "Failed" and sorts items accordingly on an assembly line. Which evaluation metrics should be used to assess the model's performance? (Choose two.)
- A business needs to pull named entities from a PDF to train a classifier. Which approach will extract those entities and save them in the SHORTEST time frame?
- A company builds an internal cost-estimation tool using a SageMaker model. Users upload high-resolution images; the model must process each image, predict the object's cost, and notify the user when processing completes. Which design meets these requirements?
- A company built a computer vision model and needs version tracking and guidance on EC2 instance types for hosting on SageMaker. They haven't hosted models on SageMaker before. Which approach provides model versioning and instance-type recommendations?
- A company built a data ingestion pipeline that uses Amazon Kinesis Data Firehose to send ecommerce sales transactions into Amazon OpenSearch Service. The Firehose buffer interval is set to 60 seconds. An OpenSearch linear model produces real-time sales forecasts that appear on an OpenSearch dashboard. The company requires sub-second latency for the real-time dashboard. Which architectural change will achieve that requirement?
- A company collects audio, video, and text in various languages and needs a large language model (LLM) to summarize content that’s in Spanish, completing the task in the least amount of time. Which solution is fastest?
- A company currently serves its ML model on 10 Reserved accelerated instances and must deploy a new model version to an Amazon SageMaker real-time endpoint. The deployment must continue to use the original 10 instances to serve both versions, include one extra Reserved Instance to use during deployment, and perform the transition with no downtime. Which deployment approach satisfies these constraints?
- A company has 6 ■■ of labeled training data stored on an Amazon FSx for NetApp ONTAP SVM in the same VPC as Amazon SageMaker. An ML engineer must make that training data accessible to SageMaker training jobs. Which option meets this requirement?
- A company has a large unstructured dataset containing many duplicate records across key attributes. Which AWS solution will identify duplicates with the least amount of custom coding?
- A company has a model deployed to a SageMaker real-time endpoint and needs to deploy a new model, but must compare the new model’s performance to the current model before shifting all traffic. Which approach accomplishes this with the least operational effort?
- A company has a model packaged in a container and will integrate it with an existing Python web app. They want to host the model on AWS using Kubernetes, avoid managing the control plane, provision resources reproducibly, and provision the infrastructure using Python. Which solution meets these constraints?
- A company has a trained ML model in Amazon SageMaker that must be hosted in production with high availability, minimal latency, and the ability to handle unpredictable bursts of requests. Each request will be between 1 KB and 3 MB. The inference capacity must scale proportionally with demand. How should the company deploy the model?
- A company has an NFS-style data store accessed by Linux systems and needs a hybrid solution so on-premises servers and SageMaker notebooks can share the data. File locking is required for data producers. Which AWS storage option satisfies these requirements?
- A company has an S3 folder that contains mixed file types (CSV, JSON, XLSX, and Apache Parquet). An ML engineer will use AWS Glue DataBrew to process the data and must save the final output back to S3 so AWS Glue can consume it later. Which approach satisfies these requirements?
- A company has deployed a model to an Amazon SageMaker endpoint and needs to record and monitor every API invocation for that endpoint, plus receive a notification when the number of invocation events exceeds a threshold. Which solution satisfies these requirements?
- A company has greatly increased the volume of CSV files stored in an Amazon S3 bucket. Data transformation scripts and queries have become much slower. An ML engineer must implement a solution that optimizes the data for query performance with the LEAST operational overhead. Which option satisfies this requirement?
- A company has historical labels indicating whether customers required long-term support. They need an ML model to predict whether new customers will require long-term support. Which modeling approach is appropriate?
- A company has large S3 datasets (historical and streaming) that must be ingested into SageMaker Feature Store so the online store reflects recent data immediately and an offline store maintains a complete history. Which solution satisfies these requirements?
- A company has many chat recordings from customer conversations and needs to determine product success by analyzing customer sentiment as quickly as possible. Which action will provide the fastest way to evaluate sentiment?
- A company hosts multiple real-time SageMaker models that require accelerated instances and have different scaling needs. Cold starts must be prevented for every model. Which design meets these constraints?
- A company is building a classifier to rate monthly sales performance (1–5) for the past 20 years. The dataset includes month, sales region, regional aggregate sales, and number of stores. Two months each year show consistently high aggregate sales (seasonal spikes). After one-hot encoding categorical features and training, model accuracy on the validation set is worse than expected. What step will most likely improve validation accuracy?
- A company is building a model with Amazon SageMaker and must track model bias and show results on a dashboard. After creating a bias monitoring job, how should the engineer capture the bias metrics for dashboarding?
- A company is building a web-based AI application with Amazon SageMaker that provides ML experimentation, training, a central model registry, deployment, and monitoring. Training data resides in Amazon S3 and must remain secure and isolated. To manage multiple model versions centrally with the least operational overhead, which approach should they use?
- A company is migrating a Retrieval-Augmented Generation application to AWS. Documents have already been moved into an S3 bucket. The application requires semantic text search over those files. Which AWS solution meets this requirement?
- A company is migrating PyTorch-based models from on-premises to SageMaker and wants to reuse its custom training scripts as much as possible. Which SageMaker feature supports running existing scripts with minimal changes?
- A company is moving a large language model (LLM) from on-premises training to Amazon SageMaker for use in a live conversational system that answers real-time credit-card queries. Which SageMaker approach should be used to train and deploy the LLM?
- A company is training a replacement model for one currently served by a SageMaker real-time endpoint. An ML engineer must measure the new model’s latency and accuracy under production traffic without impacting current users. Which evaluation approach satisfies this requirement?
- A company must deploy a custom-trained classification model on AWS to provide near real-time, low-latency predictions and to handle varying request volumes. Which deployment option meets these requirements?
- A company must recalibrate a binary classifier to maximize correct predictions for both positive and negative classes. Which evaluation metric should the ML engineer use for this recalibration?
- A company must train a SageMaker model on over 300 GB of data composed of 200 MB files stored in Amazon S3 Standard and also used by a dashboard. Which SageMaker training data ingestion option is the most cost-effective for this situation?
- A company must use a SageMaker built-in algorithm to rank customers by their likelihood of repaying loans. Which built-in algorithm should be used for this supervised ranking/classification task?
- A company needs a near-real-time pipeline for high-volume ecommerce clickstream data: ingest, process, and visualize. The solution must support SQL-based processing and Jupyter notebooks for interactive work. Which architecture satisfies these needs?
- A company needs a no-code way to transform a large Parquet dataset in Amazon S3 by applying one-hot encoding to some columns and write the transformed data back to the same S3 bucket. Which solution meets these constraints?
- A company needs a serverless, internal-only chat interface for employees to search a large internal document knowledge base. Which combination of steps will satisfy these requirements?
- A company needs feature engineering, aggregation, and data preparation, then an AWS solution to process and store the resulting features. Which approach meets these needs?
- A company needs to ingest data from Amazon S3, Amazon Redshift, and Snowflake into Amazon SageMaker Data Wrangler. The ingested data must always reflect the latest changes in the source systems. Which approach meets this requirement?
- A company plans to use a SageMaker built-in algorithm to build a recommender that must predict on high-dimensional, sparse input data. Which SageMaker algorithm is appropriate for this recommendation problem?
- A company produced two models: Model A detects fraudulent transactions and will be invoked on every transaction; Model B forecasts next-month sales and will be called once per month. Both must be deployed to production using SageMaker AI. Which hosting approach should the company use?
- A company receives daily CSV files in S3 that contain customer interaction data used to retrain a model. Before retraining, credit card numbers in those files must be masked. Which solution accomplishes this with the least development effort?
- A company runs an Amazon SageMaker AI domain in a public subnet of a newly created VPC. The network is configured and engineers can access the domain. The company discovered suspicious traffic originating from a specific IP address and needs to block that IP. Which network configuration change will accomplish this?
- A company runs automated processes that create SageMaker training jobs. New compliance rules forbid collecting aggregated metadata from training jobs. Which solution will stop SageMaker from collecting metadata for submitted training jobs?
- A company runs custom PyTorch training scripts and proprietary datasets on-premises and needs to move these models to AWS with minimal effort. Which approach requires the least work to migrate?
- A company runs ML workflows on an on-premises Kubernetes cluster. Each ML service is packaged as a standalone Docker image. They need to lift and shift to an Amazon EKS cluster with the least operational overhead. Which solution meets this requirement?
- A company runs real-time inferences with SageMaker. Auto scaling for the EC2 instances backing the endpoint launches new instances before previous scale-out instances are fully ready, causing inefficiencies and delays. Which change will improve scaling behavior while preserving response-time performance?
- A company stores clickstream data in an S3 bucket in AWS Account A and needs to train an ML model in SageMaker AI in Account B for a 10-day job. Training must use only private IP addresses and no training metadata may be shared with AWS. Which solution meets these constraints?
- A company stores daily time-series clickstream data in Amazon S3 (millions of rows per day). ML engineers run daily reports and analyze three-day trends with Amazon Athena. Data must be retained for 30 days before archival. Which design gives the highest data retrieval performance?
- A company stores MP4 videos in Amazon S3 and previously required 4 months to label all video frames for a motion-classification model. They need to retrain the model using the existing SageMaker workflow and want to reduce labeling time. Which approach will decrease labeling time?
- A company stores sensitive training data in Amazon S3 and must ensure SageMaker training jobs are network-isolated from the internet. Which configuration will provide the required network isolation while allowing access to the S3 data?
- A company stores training data as a CSV in S3 and must encrypt it while controlling which applications can access the encryption key. Which solution satisfies these requirements?
- A company stores training data in nested JSON files in S3 and needs a tabular format for XGBoost training. Which approach has the least operational overhead to convert those JSON files to tabular data?
- A company tracks sneaker sale prices over time in an Amazon QuickSight dashboard using prices scraped from many retailers. The company wants to detect unusually high price outliers and show them visually. Which approach satisfies these requirements?
- A company training a deep learning model on SageMaker wants to optimize hyperparameters to minimize validation loss using the least compute time. Which tuning strategy should they choose?
- A company uses a neural network and retrains it when performance drops. The current training job uses SageMaker distributed data parallelism (DDP) and takes several hours. What change will reduce total training time?
- A company uses Amazon Athena to query an S3 dataset that contains a target variable they want to predict. They need to determine whether a model can successfully predict the target with minimal development effort. Which option provides this information with the least work?
- A company uses AWS Lake Formation to manage a data lake containing structured and unstructured data. ML engineers are assigned to specific advertising campaigns and must query data with Amazon Athena and browse objects directly in S3. Each engineer must only access resources for their assigned campaigns. What is the most operationally efficient solution to enforce campaign-based access?
- A company uses different APIs to generate text embeddings and must automatically rotate the API tokens every 3 months. Which approach satisfies this requirement?
- A company wants a central catalog for all ML models that currently reside in multiple AWS accounts and are stored in Amazon ECR repositories. What approach will create a central model catalog across accounts?
- A company wants its own labeling specialists to perform image labeling tasks on AWS. How should the company register those specialists so they receive tasks within AWS?
- A company wants to catch as many fraudulent transactions as possible with its ML model. Which evaluation metric should be prioritized to maximize identified fraud cases?
- A company wants to lower costs for containerized ML workloads running on EC2 instances, Lambda, and an ECS cluster. EC2 and ECS use EBS volumes to store predictions and artifacts. The ML engineer must identify underutilized resources and get recommendations to reduce cost with minimal development effort. Which option should they choose?
- A company wants to reduce the energy consumption and compute resources used by its training jobs to improve sustainability. Which actions will decrease energy use and computational cost associated with training? (Choose two.)
- A company will add an internal generative AI Q&A interface using a popular open-source LLM. Which two steps will deploy the interface with the least operational overhead? (Choose two.)
- A company will create multiple ML prediction models. Training data is stored in Amazon S3 and the full dataset is larger than 5 TB and contains CSV, JSON, Parquet, and text files. The data must undergo several sequential processing steps that include complex transformations and some NLP work that can take hours to run. The entire process must be automated. Which solution meets these needs?
- A company will deploy a model for production inference on a SageMaker endpoint. Typical request payloads are between 100 MB and 300 MB, and each request must complete within 60 minutes. Which SageMaker inference option should be used?
- A company’s data scientists use Amazon SageMaker notebook instances and currently attach individual IAM roles to each notebook. The company wants to centralize permission management for the team. Which approach satisfies this requirement?
- A company’s XGBoost model in production shows a significant drop in F1 score after several months, compared with the baseline threshold recorded earlier by SageMaker Model Monitor. What is the most likely cause of the reduced F1 score?
- A compute-optimized instance will be used for SageMaker training 35 hours per week for the next 55 weeks, and the company wants to lower training costs. Which option best reduces cost given these requirements?
- A conversational assistant routes requests to Anthropic Claude through Amazon Bedrock. Users notice that asking similar questions multiple times sometimes yields different answers. To make responses more consistent and less random, what parameter changes should the ML engineer apply?
- A CPU-based model will serve real-time predictions with intermittent traffic during business hours and idle periods after hours. Which SageMaker hosting option is the most cost-effective for this pattern?
- A credit-risk model shows 99% training accuracy but only 82% validation accuracy. The company needs to fix this performance gap before deploying. Which measures address overfitting and improve generalization?
- A custom forecasting model must be hosted; the workload is predictable and sustained during the same 2-hour window each day with many invocations needing fast responses. The company wants AWS to manage the infrastructure and autoscaling. Which hosting option meets these requirements?
- A dataset contains ordered tabular features with sensitive values that must be masked (not discarded) before another team begins model development. Which service should the ML engineer use to mask the sensitive fields with minimal effort?
- A deployed model based on a genetic algorithm may take several minutes to produce a prediction and must process requests that include up to 100 MB of data. Which deployment option minimizes operational overhead while meeting these requirements?
- A deployed SageMaker model endpoint must trigger alerts when data-quality issues occur in production. Which configuration will provide such alerts?
- A deployed XGBoost model on a SageMaker endpoint receives live inference requests via an AWS Lambda function. The team needs to detect if the model's accuracy degrades over time using incoming live data. Which solution fulfills this need?
- A financial firm receives thousands of JSON market-data records per second and needs a scalable AWS solution with minimal operational overhead to detect anomalous data points in real time. Which design meets these requirements?
- A fraud detection model runs in production on a SageMaker endpoint. A new model version must be evaluated using live traffic without impacting production users. Which strategy achieves this?
- A healthcare company hosts a SageMaker endpoint that predicts patient readmission risk. They prioritize high recall and will tolerate false positives. The current model degraded, so they trained and deployed a new model as a shadow variant and monitored live traffic for one month. The shadow has higher recall but lower precision than the existing model. What should the company do next?
- A healthcare provider wants to detect anomalous patient vital-sign patterns using an unlabeled dataset (health records, medication history, lifestyle). Which algorithm and hyperparameter choice is appropriate for unsupervised anomaly detection in SageMaker?
- A hospital runs a nightly batch inference job with an ML model that validates x-ray results. The hospital needs to produce a daily report on model data quality and model performance. Which solution will provide the required daily monitoring and reporting?
- A linear regression model shows very high accuracy on the training set but performs poorly on new, unseen data. What action should the ML engineer take to address this problem?
- A logistics company installed in-vehicle cameras to monitor drivers and wants to reduce distraction-related accidents with minimal operational effort. Which solution requires the least operational work to identify driver distractions?
- A medical company has English-language health records and patient self-reported text and needs to extract insights from that text with minimal development effort. Which AWS service is the best fit?
- A medical company will run hundreds of training iterations with many features, algorithms, and hyperparameters and must record the characteristics and results of each run. Which solution provides this tracking with the least implementation effort?
- A medical organization stores clinical records containing PII and PHI. An ML engineer must ensure that neither PII nor PHI is used for model training. Which approach satisfies this requirement?
- A model deployed on premises uses data stored in Amazon S3 and processes sensitive information to power a live conversational engine in a hybrid cloud setup. The ML engineer must detect and remove sensitive data with minimal operational overhead. Which solution meets this requirement?
- A model deployed to a SageMaker serverless endpoint shows higher latency in production than in tests. The engineer suspects the extra latency is caused by model startup time. What should they check to verify this?
- A model must run once per night to predict next-day stock values. The input is 3 MB collected that day, and inference completes in under 1 minute. How should you deploy this model in Amazon SageMaker to meet these requirements?
- A model predicts presence of a specific weed using SageMaker built-in linear-learner with predictor_type set to multiclass_classifier. The team wants to minimize false positives. Which hyperparameter change should they make?
- A model was deployed to a SageMaker endpoint inside a VPC with two private subnets and one security group. The model needs to download from and upload to an S3 bucket without any traffic traversing the internet. Which option satisfies this requirement?
- A music streaming company streams song ratings into an S3 bucket and has an AWS Glue Data Catalog pointing to that bucket. The company wants a repository for these ratings that stays synchronized for both batch training and real-time inference. Which solution satisfies this requirement?
- A neural network trained with stochastic gradient descent shows high, oscillating training and validation loss that decreases for a few epochs and then increases repeatedly. What action should the ML engineer take to stabilize and improve training?
- A production ML model that has been meeting targets suddenly shows degraded performance and falls below thresholds. What is a likely cause of this sudden performance drop?
- A production SageMaker endpoint runs model version v1. A new version v2 must be tested in production with minimal risk and without disrupting live traffic. What is the best approach to validate v2 before switching over?
- A real-time analytics application must ingest and transform 5 GB of social media data per minute, then load it into a datastore that supports fast queries. Which architecture meets these requirements?
- A real-time fraud detection model currently uses SageMaker Asynchronous Inference but consumers are experiencing delays. You must improve inference latency and also generate alerts when model quality degrades. Which solution meets these requirements?
- A recommendation model for an ecommerce site must use all client interaction data as input. Traffic volume varies throughout the day. Which type of SageMaker inference endpoint is the most cost-effective for this usage pattern?
- A retail company is building an AI assistant that uses a large documentation corpus for general questions. For price-related answers, the company requires using only documents less than one month old. Which solution satisfies this requirement?
- A SageMaker AI pipeline runs distributed processing and training inside a private VPC. To encrypt network communication between instances participating in distributed jobs, what should the ML engineer enable?
- A SageMaker domain is running in a public subnet and the network is configured correctly, but there is now suspicious traffic originating from a particular IP address. The company needs to block that IP from accessing the domain. Which network configuration change accomplishes this?
- A SageMaker pipeline that includes Model Monitor reports baseline_drift_check violations in the MonitoringExecution output, causing the pipeline to fail. What is the appropriate action to address these drift violations?
- A SageMaker training job reads millions of S3 files, each several megabytes, and training performance is slow. Which change will most quickly improve training throughput?
- A set of AWS Glue jobs (orchestrated by an AWS Glue workflow) produce data used by Amazon SageMaker Pipelines. The Glue jobs can run on a schedule or be started manually. You must integrate these Glue jobs into the SageMaker pipelines with the least operational overhead. Which approach satisfies this?
- A simple neural network’s validation performance improves initially but then worsens after a certain number of epochs. Which of the following changes would help prevent this degradation? (Choose two.)
- A single Amazon Redshift cluster is the company’s sole data source and it contains some sensitive fields. A data scientist needs access to some sensitive columns without altering the source data or storing anonymized copies in the database. Which solution requires the least implementation effort?
- A single SageMaker Studio domain is used for development. You need automated alerts when SageMaker compute costs exceed a specified threshold. Which solution requires the least changes and works correctly?
- A team is using SageMaker along with AWS-owned and open-source libraries. They must prevent SageMaker from collecting metadata about usage and errors during training. Which configuration meets this requirement?
- A team wants to use Retrieval Augmented Generation (RAG) with an open-source LLM running on Amazon Bedrock. The RAG source documents (CSV and DOCX files) are stored in an S3 bucket. Which approach requires the least operational overhead to enable RAG over those files?
- A team will deploy Amazon SageMaker notebook instances but must ensure no notebook instance allows root access. Which method will prevent the deployment of notebook instances that grant root privileges?
- A travel company wants an ML model to recommend the next airport destination for users. They have millions of records with user location, recent searches, and 2,000 possible airports. The data includes categorical features and a target expected to be a high-dimensional sparse matrix. The team must use Amazon SageMaker built-in algorithms and has one-hot encoded categorical features. Which built-in algorithm should be used?
- A vendor delivers cleaned, ready-to-use training data to the company's Amazon S3 bucket every 3–4 days. The company has a SageMaker pipeline to retrain the model. The ML engineer needs the pipeline to run automatically when new data arrives in S3 with the least operational overhead. Which solution should they implement?
- AcmeRetail uses the SageMaker Model Registry to manage production-ready models. The ML team wants to configure automated deployment to a staging endpoint whenever a new model package version is approved in the registry. Which design will reliably trigger an automated deployment when a model package version is set to Approved?
- AdInsights operates a real-time personalization endpoint and must detect bias drift weekly using live traffic. The team already enabled data capture to s3://adinsights-capture/. What is the recommended approach to schedule bias checks on the endpoint’s live traffic using SageMaker Model Monitor so that bias metrics run on new data every week?
- AdMarketInc runs a recommendation model training on a single p3.16xlarge that takes ~12 hours per trial. They have a strict budget and can run at most ~20 full training trials. Model evaluations are moderately noisy but each trial is expensive. Which SageMaker Automatic Model Tuning strategy should they choose to most efficiently find a near-optimal hyperparameter configuration within their limited trial budget?
- Adverto is evaluating SageMaker Serverless Inference versus an always-on real-time endpoint for a batch of models with highly spiky traffic (many minutes of zero requests, occasional bursts). Which statement about the Serverless Inference cost model versus an always-on real-time endpoint is most accurate for minimizing cost in this workload?
- AdView Inc. wants to build a single SageMaker Data Wrangler flow that joins an S3 CSV of campaign logs with a Redshift table of customer profiles and then exports the cleaned, joined dataset to Parquet. The Redshift cluster is in a private subnet. What is the correct sequence of actions to implement this in Data Wrangler while ensuring connectivity and correctness?
- After aggregating the data, the ML engineer needs an automated way to detect anomalies in the dataset and to visualize the findings. Which solution meets both requirements?
- After changing an S3 bucket used for training data from SSE-S3 to SSE-KMS, SageMaker training jobs begin failing with AccessDenied errors. The engineer made no other configuration changes. What should the engineer do to fix the failures?
- All raw data for an ML project is stored in Amazon S3. An ML engineer must build data ingestion pipelines and model deployment pipelines on AWS. Which combination of services should the engineer use?
- All training data for multiple business groups is stored in S3 within a single AWS account. ML engineers must only access the training data for their own business group and must be prevented from accessing other groups' data. All training runs occur in SageMaker. How should the company enforce the required access controls?
- An airline runs a SageMaker real-time endpoint to adjust ticket prices based on demand. Previous deployments failed to scale quickly enough when website traffic rose. The ML engineer must configure target-tracking auto scaling to respond rapidly to sudden traffic spikes. Which configuration will be most responsive?
- An Amazon Comprehend custom model exists in Account A in the us-east-1 Region. The engineer needs to copy that model to Account B in the same Region with minimal development effort. Which approach achieves this?
- An application will call Amazon Q Business APIs to produce product recommendations, and the company must ensure responses never include the name of its main competitor. Which configuration enforces this?
- An AWS Lambda function monitors ML model metrics. The engineering team needs to send an email when a metric exceeds a threshold. Which implementation meets this requirement?
- An ecommerce team deployed a forecasting model to a SageMaker real-time endpoint for near real-time inventory management, but model accuracy degrades over time. They need a long-term automated approach to detect issues that should trigger retraining. Which solution meets this requirement?
- An IoT company trains and tests an XGBoost object-detection model in Amazon SageMaker and needs to track performance metrics across hyperparameter variants. The engineers also need to send SMS notifications after each training job completes. Which combination of AWS services meets these needs?
- An ML engineer configures auto scaling for an inference component behind an Amazon SageMaker endpoint with a target-tracking policy of 100 invocations per model per minute. The endpoint scales normally during business hours, but at each business day start there are zero instances available to handle requests, causing delays. How should the engineer ensure the endpoint can handle incoming requests at the start of each business day?
- An ML engineer created a binary classification model outside SageMaker and stored the model artifacts in S3. The engineer and a SageMaker Canvas user are in the same SageMaker domain. What requirements must be met so the engineer can share the model with the Canvas user? (Choose two.)
- An ML engineer deployed a sentiment-analysis model to a SageMaker endpoint and must provide stakeholders with explanations of how the model makes predictions. Which solution will produce explanations for the model's outputs?
- An ML engineer has a day_of_week column with values Monday, Tuesday, Wednesday, Thursday, Friday, Saturday, and Sunday. Which technique should the engineer use to convert this categorical column into binary indicator variables?
- An ML engineer has survey answers that are only “yes” or “no.” They need to transform these responses into a single feature that improves model training without increasing the dataset’s dimensionality. Which methods satisfy these constraints? (Choose two.)
- An ML engineer is assembling training data for a binary classification model (labels: Class A, Class B). They want to check whether the classes are balanced and, without removing existing records, bring the dataset into balance if needed. Which approach satisfies this requirement?
- An ML engineer is building a fraud detection model. Data sources include transaction logs and customer profiles in S3 plus tables from an on-premises MySQL database. Which AWS service or capability can centrally aggregate these varied data sources for ML use?
- An ML engineer is building a model in SageMaker Canvas to make continuous numeric predictions using 10 years of historical data. Which evaluation metric should the engineer use to assess the model’s predictive performance?
- An ML engineer is building a model to predict housing and apartment prices using three features: square meters, price, and building age. The dataset (10,000 rows) contains extreme values: one very large mansion and one extremely small apartment. To ensure the model makes accurate predictions for typical properties, which preprocessing approach should be used?
- An ML engineer is choosing a model for production where false negative predictions are far more costly than false positives. Which metric should the engineer prioritize most when selecting the model?
- An ML engineer is inspecting a classification dataset before training a model in Amazon SageMaker and suspects a large class-label imbalance that could bias the model. Which pre-training metric should the engineer use to confirm class imbalance?
- An ML engineer is optimizing a model that predicts customer behavior and needs to inspect input data and model predictions to identify patterns that might bias performance across demographics. Which solution provides this analysis?
- An ML engineer is preparing input for a neural network to predict advertising campaign success. The dataset includes the advertisement’s color scheme as a categorical feature. Which feature-engineering method should the engineer use for this categorical color data?
- An ML engineer is training a binary health-risk model (positive = likely at risk, negative = unlikely) with ages 30–60 included as a feature. The difference in proportions of labels (DPL) for the positive class is +0.9 for the 40–45 age group versus other ages, indicating overrepresentation. How should the engineer correct this imbalance?
- An ML engineer is training a logistic regression model to predict subscription churn. The dataset includes two categorical string features: location (3 distinct categories) and job_seniority_level (more than 10 distinct categories). How should these features be preprocessed for the model?
- An ML engineer must build a pipeline that discovers and removes PII from petabytes of unstructured data, and then use the cleaned data to train SageMaker models. Which solution meets this requirement at scale?
- An ML engineer must build a pipeline that uses Amazon Athena for two workloads: large-scale batch transforms and model training, and near-real-time low-latency queries for inference and analytics. Which file format will produce the LOWEST latency for both batch and near-real-time processing?
- An ML engineer must call Amazon Bedrock APIs from EC2 instances that are in a private subnet and must remain private. The instances have a security group allowing access within the private subnet. How should the engineer connect the EC2 instances to Amazon Bedrock?
- An ML engineer must deploy four models (each built with a different framework) into a SageMaker inference pipeline and allow clients to call invoke_endpoint for each model. Which cost-effective solution satisfies these requirements?
- An ML engineer must ensure a dataset complies with PII regulations and prevent SageMaker training instances from using any PII. What is the most operationally efficient solution?
- An ML engineer must ensure all data in transit is encrypted for an Amazon SageMaker training job, including the communications that SageMaker uses during training. Which action will satisfy this requirement?
- An ML engineer must extract meaningful, unique keywords from documents using AWS services with the least operational management. Which approach meets this requirement?
- An ML engineer must fine-tune a large language model (LLM) for text summarization using Amazon SageMaker and must use a low-code/no-code workflow. Which option satisfies these constraints?
- An ML engineer must merge and transform weekly data from two sources: large CSV files in S3 (each with millions of rows) and an Amazon Aurora cluster. The merged output must be written to another S3 bucket. Which option provides this with the LEAST operational overhead?
- An ML engineer must monitor a SageMaker model to automatically detect shifts in the input feature distributions. Which approach provides this capability with minimal operational overhead?
- An ML engineer must process thousands of existing CSV files plus new CSV uploads stored in a central S3 bucket. All CSVs share the same column layout and include a transaction date column that must be queried. Which solution delivers this with the least operational overhead?
- An ML engineer must run model inferences asynchronously over large datasets and schedule regular checks of model input data quality, with alerts when data-quality changes occur. Which solution satisfies these requirements?
- An ML engineer must use AWS CloudFormation to create the ML model that an Amazon SageMaker endpoint will host. Which CloudFormation resource should the engineer declare to represent that model?
- An ML engineer needs custom Python libraries available in SageMaker processing jobs, training jobs, and pipelines. Which option provides that capability with the LEAST implementation effort?
- An ML engineer needs to extract, transform, and load data from Amazon S3 for analytics, discover the data schema, and store metadata with minimal manual effort. Which option accomplishes this?
- An ML engineer needs to load historical data directly into SageMaker from Amazon S3, Amazon Athena, and Snowflake to build models. Which tool should they use to query and import these sources into SageMaker?
- An ML engineer needs to predict apartment prices for a particular location. Which evaluation metric is appropriate for measuring the model’s predictive performance?
- An ML engineer receives datasets containing missing values, duplicates, and extreme outliers and must merge them into a single dataframe and prepare the data for machine learning. Which solution meets these needs?
- An ML engineer trained an accident-detection model using Data Wrangler and achieved strong training/validation results, but production performance suffers due to varied camera image quality. Which change will improve accuracy fastest?
- An ML engineer trains a neural network in a SageMaker Studio notebook using an estimator. The Python training script uses Distributed Data Parallel (DDP) on a single instance that has multiple GPUs, but the GPUs are underutilized. The engineer needs to find where in the training script to optimize resource usage. Which approach will identify that point?
- An ML engineer trains multiple models using the same ML framework and wants to host them in Amazon SageMaker while minimizing inference costs. Which hosting option is the most cost-effective?
- An ML engineer uses Amazon QuickSight anomaly detection to flag very high or very low machine operating temperatures compared to normal. Severity is set to "Low and above" and Direction is set to "All." If the engineer changes Direction to "Lower than expected," what effect will be observed in anomaly detection results?
- An ML engineer wants a SageMaker notebook to automatically stop after 1 hour of idle time. How can this be implemented?
- An ML engineer will use Amazon SageMaker Canvas to train a model with complex-structured data stored in Amazon S3. Which file format will minimize pre-processing time for that data?
- An ML engineer will use an Amazon EMR cluster for large batch processing where any data loss is unacceptable. Which instance purchasing strategy is the most cost-effective while ensuring no data loss?
- An ML model deployed with Amazon SageMaker uses Model Monitor. After updating the model, the ML engineer observes data quality failures in Model Monitor checks. What action should the engineer take to address the data quality issues that Model Monitor flagged?
- An ML model trained on SageMaker is overfitting, and the training set includes irrelevant features. To reduce overfitting and lessen the influence of unnecessary features, which action should the engineer take?
- An ML model will score customers in an online application to determine which product to show. The engineer needs to minimize response latency. How should the model be deployed in SageMaker to meet low-latency requirements?
- An ML pipeline should automatically start a retraining job whenever data drift is detected. How should the engineer configure the pipeline to detect drift and trigger retraining?
- Before fully releasing a new model, a company needs to validate it online on 10% of production traffic. The model is served by a SageMaker endpoint behind an Application Load Balancer. Which setup provides the required 10% online validation with the least operational overhead?
- Before training, the dataset’s class imbalance must be resolved with minimal operational effort. Which option best accomplishes this?
- BioGenix stores multiple terabytes of raw and preprocessed training datasets in an S3 bucket. Datasets are frequently used during active development but become infrequently accessed after 90 days. The team wants a low‑management, cost‑optimized storage strategy that minimizes retrieval surprises when occasional re-training happens. Which S3 configuration is the best fit?
- BrightDrive wants to replace a low-traffic real-time GPU endpoint with SageMaker Serverless Inference for cost savings. They need to control concurrency and understand latency trade-offs. Which statement most accurately describes how to configure serverless and the trade-offs compared with a persistent real-time endpoint?
- BrightRetail's MLOps team wants data scientists in SageMaker Studio to be able to launch training jobs against a specific S3 training prefix, but the team must prevent those users from listing or reading other S3 prefixes in the same bucket and from changing KMS key policies. Which least-privilege IAM design will accomplish this?
- Customer data is stored daily in compressed, date-partitioned files in S3. Analysts monthly download, validate, and upload results to QuickSight. The engineer must automatically check data quality before it’s sent to QuickSight with the LEAST operational overhead. Which solution fits best?
- Customers upload images (totaling up to 50 MB each) and an ML model generates textual descriptions. The images are stored in Amazon S3 and the processing must scale with minimal operational overhead. Which architecture best satisfies these requirements?
- Data scientists require fine-grained control over ML workflows, the ability to visualize jobs and workflows as a DAG, and a persistent history of experiments with model lineage for audit and compliance. Which AWS solution meets these needs?
- DataCoral, a fintech startup, runs sensitive model training on SageMaker using custom Docker containers that must never access the public internet. Their security policy requires blocking all outbound internet traffic from training containers while still allowing access to S3 training data via VPC endpoints. Which configuration change will meet the requirement when launching a SageMaker training job?
- DataPulse, an analytics company, wants to fine-tune a foundation model in Amazon Bedrock to improve responses on its product-support dialogues. You have prepared a training file and uploaded it to s3://datapulse-bedrock/train/support_finetune.jsonl. Bedrock expects one training example per line. Which of the following is the correct preparation and submission workflow to create a Bedrock fine-tuning (model customization) job?
- DataStream Inc. wants a repeatable CI/CD pipeline for model development that: triggers on Git commits, runs unit tests and static checks, triggers SageMaker Pipelines training, registers a model to the Model Registry, and promotes to a production endpoint after manual approval. The team prefers to use managed SageMaker tooling to provision the CI/CD infra (CodePipeline, CodeBuild, IAM roles). Which approach best meets their requirement with minimal hand-built pipelines and integrates with SageMaker Studio for developer onboarding?
- DataWave Inc. runs a low-latency fraud model on a SageMaker real-time endpoint (single production variant). They want to perform a shadow test by routing 5% of live production traffic to a new model variant (the shadow) while 95% continues to the current variant; responses from the shadow model should not be returned to clients (they will be logged for offline comparison). What is the most appropriate, least-intrusive way to implement this within SageMaker?
- During an image classification training job, an engineer observes class imbalance in the dataset. Which action should the engineer take to address the imbalance?
- During distributed training on SageMaker, the engineer notices poor instance performance caused by communication overhead between training nodes. How can the engineer minimize inter-instance communication overhead?
- During exploratory data analysis several categorical features contain missing values. How can the ML engineer use SageMaker to handle these missing categorical values?
- EcoSensors builds a defect-detection classifier for manufacturing with defects ~0.5% prevalence. Missing a defect (false negative) has very high operational cost, but inspecting false positives also consumes resources. Select TWO evaluation metrics the team should prioritize during validation and hyperparameter tuning to ensure the model performs well in this imbalanced, high-cost-of-miss setting.
- EdgeAI builds a computer vision model they must deploy to a fleet of heterogeneous edge devices (Raspberry Pi 3, NVIDIA Jetson TX2, and arm64 Linux gateways). They want to maximize inference throughput and reduce memory footprint. Which statement about using SageMaker Neo compilation is most accurate for this scenario?
- EduLogic wants to compare two Bedrock models for answer accuracy and safety before rolling one into production. They need to run automatic, repeatable metrics at scale and also collect human judgments for edge cases. Which architecture best implements both automated evaluation with built-in metrics and human evaluation for sampled outputs?
- Every new Amazon SageMaker notebook instance must have a custom script installed automatically. Which approach achieves this with the LEAST operational overhead?
- FinBank receives multi-page PDF invoices (3–10 pages each) in an S3 bucket and needs to extract structured key/value fields (InvoiceNumber, InvoiceDate, InvoiceTotal) and persist the results to DynamoDB. Several teams tried DetectDocumentText but the key/value pairing is unreliable. What is the most appropriate Textract approach and configuration to reliably extract structured form fields at scale in this AWS environment?
- FinCorp runs a fraud-detection pipeline in AWS. You created multiple SageMaker Feature Groups with offline store enabled to persist historical feature values to S3. Data scientists need to generate training datasets that join transaction records (CSV in S3 with a transaction_timestamp) to the correct historical feature values as of each transaction time using SQL in Athena. Which configuration and step will reliably enable performant, correct joins on historical feature timestamps for large training exports?
- FinInsights deployed a JumpStart foundation model endpoint for low-latency financial-text generation on an ml.g5.xlarge instance. After a successful pilot, they need 3× higher sustained throughput with similar latency tail behavior. What is the most direct, supported change to the SageMaker JumpStart endpoint to meet this requirement?
- FinPredict runs many consecutive training jobs with the same instance type and would like to reduce startup latency. They consider enabling SageMaker Warm Pools to reuse provisioned infrastructure across jobs. Which statement correctly describes what warm pools provide and an important limitation to plan for?
- FinSight has an automated ML pipeline in CodePipeline that stages new S3 datasets into training-buckets. Before any dataset is used for training, security requires detection of PII and automatic blocking of pipeline progress if PII is found. Which integration approach using Amazon Macie will allow the pipeline to conditionally proceed or fail based on PII findings?
- FinSight LLC runs a pre-training bias assessment with SageMaker Clarify on a loan-approval dataset stored in an S3 bucket (s3://finsight-prod/data). The Clarify pre-training report shows Class Imbalance (CI) = 0.12 for the target label (acceptable below 0.2) and Difference in Positive Proportions (DPP) for gender (male vs female) = 0.18 (exceeds the policy threshold of 0.10). The model team plans to retrain on an ml.c5.4xlarge training instance. What is the most appropriate immediate action to address these Clarify results before retraining?
- FinSight, a fintech startup running in account 111122223333 in us-east-1, has built a SageMaker asynchronous inference endpoint for heavy document processing. Their requirement: allow up to 50 concurrent inferences per model container and publish an SNS notification when each async inference completes (success or failure). Which TWO configuration steps must an ML engineer perform to meet both requirements?
- FinTrust (AWS account 111122223333) runs an automated ML pipeline in SageMaker Studio that must preprocess transaction data, train a fraud detection model, evaluate it, and register a vetted model package in the Model Registry. You need to implement a SageMaker Pipeline that includes a ProcessingStep to run data preprocessing and evaluation, a TrainingStep that consumes the processed data, and a final RegisterModel step that records model metrics produced by the evaluation. Which pipeline implementation approach meets the requirement and ensures the RegisterModel step records the evaluation metrics produced by the ProcessingStep?
- FinTrust Inc. trains a tabular fraud-detection model and stores the training CSV in s3://fintrust-training/transactions/. The ML platform team must create a SageMaker Model Monitor data-quality baseline (statistics and constraints) from the training data so that daily monitoring of production inference input schema and distributions can alert on drift. Which is the most appropriate, minimal-effort way to produce a Model Monitor baseline suitable for use by a MonitoringSchedule?
- ForecastOps, an online transportation company, needs probabilistic hourly demand forecasts for thousands of distinct routes. Each route has correlated patterns (some share holiday/covariate signals), and the team wants prediction intervals (quantiles) and the ability to include route metadata and holiday covariates. Which Amazon Forecast algorithm is the best match for this requirement?
- GreenField Media runs SageMaker training and hosts models in the same AWS account. They require all training and hosting instances to be launched in specific private subnets and use security groups that restrict traffic to their internal analytics VPC only. Which SageMaker configuration change will correctly enforce use of the specified subnets and security groups for both training and endpoint hosting?
- GreenLeaf Farms runs a Rekognition Custom Labels project to classify images of plant diseases. The engineering team has 12,000 labeled images in an S3 bucket organized by prefix (s3://greenleaf-data/images/) and a SageMaker Ground Truth augmented manifest (JSON Lines) that references each image and its label. They need to start a training job in Rekognition Custom Labels that uses the labeled images and enforces a 80/20 train/test split. What is the most appropriate next step to ensure Rekognition can train the custom image-classification model?
- HealthAI Diagnostics plans to publish a Model Card for a radiology model before promoting it from a SageMaker Model Registry staging package to production. The compliance team requires that the Model Card contains an intended use statement, evaluation results by demographic slices, and a risk rating with mitigation steps. Which practice will best satisfy the requirement and streamline operational use with SageMaker?
- HealthBridge (a healthcare app) will expose an LLM through Amazon Bedrock. Compliance requires blocking medical-diagnosis instructions, removing any personally identifiable information (PII) from model outputs, and logging violations. What is the appropriate Bedrock guardrail configuration and integration to meet these requirements?
- HealthData Labs wants to track drift in feature attributions (SHAP values) for a clinical risk model. They have computed training-set SHAP values already and stored them in s3://healthdata-baselines/shap/. Production endpoint captures inputs and model outputs to s3://healthdata-capture/. Which approach will let them use SageMaker monitoring to detect changes in SHAP distributions over time?
- HealthMetrics deployed a fraud detection model to a SageMaker real-time endpoint. The team needs to audit and show lineage from the deployed endpoint back to the preprocessing job, training job, and evaluation artifacts created in their SageMaker Pipeline runs. Which sequence of actions and APIs provides the most complete lineage for a deployed model?
- Hundreds of data scientists store models in SageMaker Model Registry model groups. The team wants to organize existing models into three categories (computer vision, NLP, speech recognition) to improve discoverability without changing model artifacts or existing groupings. What approach satisfies these constraints?
- LogisticsPro must enable data capture on a SageMaker endpoint so that 10% of requests (both request and response) are stored in s3://logisticspro-endpoint-capture/ for downstream offline monitoring. Which TWO EndpointConfig/DataCaptureConfig settings must be changed to accomplish this?
- MediAnalytics built an XGBoost classifier for hospital readmission predictions and used SageMaker Clarify for post-training explainability. Global SHAP summary shows patient_age as a top positive contributor to readmission risk, but the Clarify-generated partial dependence plot (PDP) for patient_age is non-monotonic and appears to conflict with SHAP. The data team suspects patient_age is correlated with several comorbidity features. What is the most appropriate interpretation and next step?
- MediaWatch runs a real-time video classification model and wants to alert when model execution time rises. Which CloudWatch metric should be used to detect increased model container inference time only, and what is the recommended way to alarm on sustained increases for a particular variant of an endpoint?
- MediCare AI wants to deploy a new model version to production using a blue/green strategy with minimal downtime and an automatic rollback if the new variant produces an elevated 5xx error rate. Which approach provides controlled traffic shifting and an automatic rollback mechanism within AWS SageMaker capabilities?
- MediLabel, a healthcare startup, needs to label sensitive X-ray images with a private group of radiologists and ensure label consolidation across multiple annotators (use consensus/aggregation). Which setup and configuration will meet their security and consolidation requirements when creating a SageMaker Ground Truth labeling job?
- MediLex operates a SageMaker real-time endpoint (ml.m5.large instances) for an NLP inference API. CloudWatch metrics reported an average of 800 invocations per minute over the last peak 5-minute interval and the metric InvocationsPerInstance is 100 invocations/minute. The endpoint currently runs 8 instances. The SRE team wants to right-size to meet the same peak traffic while maintaining the same per-instance load (target 150 invocations per instance). Using the CloudWatch InvocationsPerInstance or aggregate invocation data, how many instances should they provision to reach the 150 invocations/instance target?
- MedScan Health needs a SageMaker endpoint that runs an image preprocessing container, then a TensorFlow model container, then a postprocessing container in sequence for each request. They want a single HTTP endpoint URL for clients. Which SageMaker deployment approach best satisfies this requirement with minimal extra networking and correct model lifecycle behavior?
- MovieStreamX wants to show a personalized "Recommended for You" carousel on each signed-in user's homepage that leverages the user's past streaming interactions and demographic metadata. For anonymous homepage landing pages they want a simple "Trending Now" carousel that surfaces currently popular titles. Which Amazon Personalize recipes should be used for the personalized carousel and for the trending carousel respectively, and what is an important configuration difference between them?
- Multiple teams developed prediction models locally using Python with scikit-learn and TensorFlow. The company must rebuild and integrate those models into an ML infrastructure managed with SageMaker and add them to a model registry. Which approach minimizes operational overhead?
- NexaVision is evaluating distributed strategies for two workloads: (A) training ResNet50 on ImageNet across 8 x p3.8xlarge GPUs where the full model easily fits on a single GPU but they need higher effective batch size, and (B) training a 100B-parameter transformer where a single GPU cannot hold the model weights. For these two distinct workloads, choose TWO choices describing which SageMaker distributed approach is appropriate for each.
- NimbusBiotech requires all model training artifacts and the EBS scratch volumes used by training instances to be encrypted with their customer-managed KMS key. They also want SageMaker training jobs to be able to read/write S3 training data encrypted with that key. Which combination of steps will correctly enforce encryption at rest for both S3 and EBS for SageMaker training?
- OrbitalHealth is rolling out SageMaker Studio to 400 analysts across multiple business units. They want centralized identity management, single sign-on, and integration with the company's existing corporate identity provider for onboarding and offboarding. Which Studio Domain authentication mode should they choose and why?
- PowerGrid Inc trains a model to forecast hourly electricity load over multiple years stored in an S3 data lake and uses SageMaker Processing jobs for feature engineering. The team considered using a standard k-fold (scikit-learn KFold with shuffle=False) cross-validation during hyperparameter tuning on SageMaker, but worries about temporal leakage. Which validation strategy and SageMaker integration is the best practice to avoid leakage while supporting robust hyperparameter tuning?
- QuantGen plans to accelerate large-scale GPU training on SageMaker. They want to enable GPU kernel fusion and operator-level optimizations provided by SageMaker Training Compiler. Which statement correctly describes how to enable it and which frameworks are supported for that optimization?
- RAG Inc. is designing a RAG pipeline and must choose an embedding model and similarity search configuration to use Amazon OpenSearch Service. (select TWO)
- RetailStream LLC has a classification endpoint that captures predictions to s3://retailstream-capture/predictions/. They also have labeled ground truth produced by a SageMaker Ground Truth labeling job stored as a manifest in s3://retailstream-labels/manifest/. The data-science team needs model-quality monitoring that compares predictions with the true labels. What is the correct way to supply ground truth to SageMaker Model Monitor so the MonitoringSchedule can compute model quality metrics?
- RetailVision has 240 per-store personalization models (each ~120 MB) that are queried infrequently (minutes between requests per model). They currently host each model as a separate endpoint, which is costly. They want to consolidate to minimize cost while keeping acceptable cold-start latency when a model is first requested. What is the best SageMaker-hosting approach to reduce cost in this scenario?
- select TWO: DetectEye operates a fraud model with 0.3% positive class and plans to train an XGBoost model on SageMaker. They want to address severe class imbalance while preserving as much signal as possible and avoiding label noise amplification. Which TWO interventions are most appropriate to try first in this production context?
- select TWO: LexaLegal, a legal-tech startup, needs an Amazon Comprehend custom entity recognizer to identify party names, legal clauses, and statute references. Their labeling team can either produce annotated documents with entity spans or curate lists of known statute identifiers. Which two training-data approaches can they use when creating a Comprehend custom entity recognizer?
- Shared Amazon SageMaker Studio notebooks are reachable only via a VPN. The company must enforce access controls to stop attackers from using presigned URLs to reach the notebooks. Which configuration meets this requirement?
- ShopEZ runs SageMaker Model Monitor nightly. Monitoring outputs JSON results to s3://shopez-monitoring/results/`<model-package-id>`/run-YYYYMMDD.json and includes a field constraint_violations_count. The team wants an automated flow that starts an existing SageMaker Pipeline called 'retrain-pipeline' when constraint_violations_count > 0. Which architecture most directly and reliably implements that automated retrain trigger?
- ShopRight has a latency-sensitive product recommendation endpoint that must fetch feature vectors in single-digit milliseconds for each incoming inference request. The features are customer-session attributes that change frequently. Which setup gives the most reliable low-latency retrieval pattern for real-time inference while staying within managed SageMaker services?
- ShopScale runs dozens of SageMaker training jobs (script mode with built-in XGBoost) under an Experiment. Each training job logs a metric 'validation:accuracy' at each epoch into the TrialComponent. The ML team needs an automated programmatic report that compares validation:accuracy at epoch 10 across all trial components in the Experiment to pick the best run for deployment. Which approach will give the most direct, programmatic way to aggregate that metric across runs?
- SmartRetail stores dozens of inference models in an S3 model store and uses a SageMaker multi-model endpoint on an ml.m5.xlarge instance to host them. A developer needs to invoke a specific model named retail-v3-2025.tar.gz from the multi-model endpoint using the SageMaker runtime API. Which invocation approach will load and run that specific model at request time?
- StreamDocs, a legal-document SaaS, is building an Amazon Bedrock knowledge base from a large S3 bucket of PDFs. They want vector search that supports semantic retrieval and stores document metadata (document_id, page). Which configuration best balances retrieval quality, maintainability, and AWS managed components?
- StreamlineAI runs a custom PyTorch training script (script mode) that produces periodic model checkpoints. They want to use SageMaker Managed Spot Training to reduce cost. The training script writes checkpoints to /opt/ml/checkpoints and the company stores artifacts under s3://streamlineai-checkpoints/training1/. Which configuration will let a managed-spot SageMaker training job resume from the last checkpoint after an interruption?
- StreamSense runs a weekly hyperparameter sweep that normally costs $12,000 for on-demand ml.p3.2xlarge instances. To reduce cost they enabled SageMaker managed spot training and configured checkpointing and a max_wait_time 2x the training duration. The cost report for the sweep shows the managed spot run billed $1,200. Based on SageMaker managed spot behavior, what maximum savings percentage vs the original on-demand cost is most consistent with SageMaker managed spot training potential savings?
- StreamVid maintains terabytes of raw CSV logs in S3 and needs automated profiling and repeatable transformation (parse timestamps, drop low-cardinality columns, convert to Parquet) before training. Which DataBrew workflow best meets these requirements and what must be ensured for scheduled runs?
- TerraSight is preparing to train the SageMaker built-in Object Detection algorithm on images annotated by Ground Truth. The Ground Truth output is an augmented manifest (JSON Lines) that references image S3 URIs and bounding-box coordinates. Which data format should TerraSight use to import the labeled bounding-box dataset to the SageMaker built-in Object Detection training job?
- The application must provide an on-demand workflow to assess bias drift for models deployed to real-time endpoints. Which action meets this requirement?
- The company requires a manual approval workflow so that only authorized model versions can be deployed to production endpoints. Which solution satisfies this requirement?
- The ML engineer needs to train the fraud detection model using a SageMaker built-in algorithm. Which algorithm is the appropriate choice for this task?
- The team is running consecutive training jobs in SageMaker and wants to minimize infrastructure startup time for each job. Which option will reduce startup latency?
- The training dataset includes both categorical and numerical features. To maximize model accuracy with the least operational overhead, how should the ML engineer prepare these features?
- Training data was normalized with min–max scaling in AWS Glue DataBrew. Production inference data must be normalized exactly the same way before being sent to the model. Which approach satisfies this requirement?
- Using AWS Glue, an engineer must transform multiple similar time-series files from a vendor into the format required by the SageMaker DeepAR forecasting algorithm and compress them to reduce storage cost. Which approach satisfies these requirements?
- Using SageMaker Data Wrangler, an engineer finds a text categorical feature with thousands of slightly different values caused by spelling errors. Which encoding method should be used so the processed feature can be used for classification?
- Using SageMaker's XGBoost, a fraud detection model fits the training data very well but fails to detect fraud on new, unseen transactions. What change should the ML engineer make to improve generalization to new transactions?
- VideoAI stores 40 TB of raw video frames in S3 and trains on GPU instances that have only 1 TB of instance storage. Their training loop reads the dataset sequentially for several epochs and can stream records from stdin-compatible interfaces. Which SageMaker input mode should they choose and why?
- VisionWorks is evaluating upfront commitments to reduce SageMaker compute costs and must understand how SageMaker Savings Plans compare to EC2 Savings Plans in scope and terms. Select TWO statements that correctly describe SageMaker Savings Plans.
- Which Amazon SageMaker algorithm is appropriate when a model must both identify an object in an image and return its location within the image?
- Which AWS service will automatically create and manage versions of ML models as new model artifacts are produced?
- Which evaluation metrics are applicable for assessing the quality of a time-series forecasting model? (Choose two.)
- While fine-tuning a deep learning model in SageMaker Studio, you expect issues such as vanishing gradients, underutilized GPU, and overfitting. You need realtime, comprehensive metrics during training and automatic reactions (predefined actions) when these problems are detected, with minimal operational overhead. Which option meets these needs?
- While training a text-generation model, the loss does not converge after several epochs and validation accuracy oscillates. To help the model generalize, which adjustment is most appropriate?
- You have a large collection of unlabeled images that only employees may access. To achieve the highest labeling accuracy, which combination of steps should you take? (Choose two.)
- You need to host a trained model that receives an uneven request rate during the day. The hosting must scale to peak demand but minimize cost when idle. Which hosting approach meets these constraints?
- You plan to use Amazon Redshift ML in a primary AWS account while the source data is in an S3 bucket in a secondary account. You need a pipeline in the primary account that accesses the secondary-account S3 bucket without requiring public IPv4 addresses. Which architecture meets these requirements?
- You receive a 50 MB Apache Parquet file for a fraud detection model that contains several correlated, unnecessary columns. What is the least-effort way to remove those columns from the file?
Amazon retail for advertisers Certification All exam questions
- Alecia is selling her products on Amazon, using her own resources to fulfill orders. Which of the following best describes Alecia?
- Allido, Inc. sells products on Amazon that they store in their own warehouse. Amazon carriers collect the products from Allido's warehouse in order to ship them to customers. Which shipping method is this describing?
- Amazon Brand Analytics can report on which geographic sales data?
- Aquloo needs to add more products to their catalog in Seller Central. Which component in the navigation bar will they access?
- ARA Premium can report on which geographic sales data?
- Athletica Shoes sells their inventory directly to Amazon, whereas Shoez owns their inventory and uses Amazon to list products for sale. Which company is an Amazon vendor?
- Bianka sees that her client has not been selected to present the Featured Offer ("Buy Box") on their product. What suggestion(s) should she give to her client?
- Canent Global is interested in selling products on Amazon. What is the first thing they should confirm?
- Chantell, a seller on Amazon, wants her products to be visible when shoppers select the Prime filter during their search process. Which shipping option should she use?
- Darnell wants to ensure his client, a Vendor Central user, is presenting the Featured Offer ("Buy Box") for a particular product. What suggestion(s) should he provide?
- East Appliances has chosen to leverage Fulfilled by Amazon for shipping. Which statement best explains their choice?
- Eduardo is an advertiser at a major consumer packaged goods company. He is looking to run a cross-promotional campaign to promote products that are frequently purchased together. Which part of Amazon Brand Analytics would be most useful for him to review to best understand these trends for his brand?
- Electronick is a wholesaler that works directly with an Amazon representative. EverRight owns their brand and inventory. What is EverRight's role in this scenario?
- EpiCamera has 5 compatible, related products that they'd like to group together for customer convenience. Which of the following describes this?
- Examine the product detail page below. Which of the following elements is not retail ready?
- Fabian is checking his client's product detail page for retail readiness. Which of the following issues should he flag as needing improvement to be considered retail ready?
- GamezCo is presenting the Featured Offer ("Buy Box") on a gaming console they sell. Which of the following is true?
- Grant owns the brand behind the products he sells on Amazon. Is Grant a vendor or seller?
- How could a Seller Central user benefit from the information found under the Performance section of the navigation bar?
- How many ASINs can you review in a peer set with Amazon Brand Analytics?
- How many ASINs can you review in a peer set with ARA Premium?
- In Vendor Central, where should a user navigate to in order to access the advertising console?
- Jeremy needs to confirm whether his client, a seller named Comps Now, is presenting the Featured Offer for a specific product. Where should Jeremy look?
- John is proposing an advertising campaign that leverages multiple Amazon retail programs. Which of the following are programs he may choose to include?
- Kendrick prefers to manage storage, logistics, and shipping for products he sells on Amazon. Which shipping method is he using?
- Koepp has noticed a number of negative reviews and low ratings for one of their products. It turns out that some customers feel that the product isn't functioning as expected after 6+months of use. What would be the best approach for Koepp to improve the product's retail readiness?
- Kya is editing the customizable section of her product detail page to include charts, video, and narrative comments. What is this section referred to as?
- Lamar recently launched a Sponsored Products campaign to boost sales of a new product, but the only ASIN in the campaign has gone out of stock. What will occur?
- Maria needs access to her client's Seller Central account in order to manage their sponsored ads campaigns. For which section will she need permissions?
- Maria works at an advertising agency that represents a Vendor Central user. Which tool can she access to view the client's inventory data and catalog quality?
- Match the retail program with its description.
- Moriah is a Seller Central user utilizing Amazon's fulfillment centers to pack and ship their products to customers. Which best describes Moriah?
- Nina is setting up an advertising campaign for her vendor client. What access and permission will she need to manage their product detail pages?
- Noelle is an advertiser at a hair care brand, and is looking to drive more sales of her brand's shampoo line. She wants to better understand the cadence for replenishment of her shampoo so that she can better create advertising to reengage shoppers when they may be looking to buy again. What should Noelle look at in Amazon Brand Analytics?
- Pratiksha is an advertiser that recently received budget approval to run a campaign on Amazon. Before investing, Pratiksha wants to understand the current drivers of performance to determine where there is the greatest opportunity. Which part of ARA Premium would be most useful for her to review?
- Raphael is an advertiser at a regional apparel retailer. A strategic initiative is to expand their brick-and-mortar presence to new locations next year. Which part of Amazon Brand Analytics would be most useful for him to review?
- Raphael is an advertiser at a regional apparel retailer. A strategic initiative is to expand their brick-and-mortar presence to new locations next year. Which part of ARA Premium would be most useful for him to review?
- Theo, an Amazon seller, is adding a product to his inventory list in Seller Central. He knows his product is eligible to sell because he has seen that product on Amazon in the past. Is Theo correct?
- True or false? A minimum of 4 product images is suggested for a product to be retail ready.
- True or false? A selling partner must be invited to become a Vendor Central user.
- True or false? A Vendor Central user can update a product image and see it live immediately.
- True or false? Advertising agency employees can create Seller Central accounts on behalf of their clients.
- True or false? Agency professionals must contact Amazon to request access to their client's Seller Central account.
- True or false? Enhanced content is a customizable section that selling partners can use to create positive customer experiences that empower shoppers with enough information to make an informed buying decision.
- True or false? Once a vendor sells their products to Amazon, they no longer need to access Vendor Central.
- True or false? Only businesses can shop on Amazon Business.
- True or false? Optimizing the enhanced content section can improve organic SEO.
- True or false? The product detail page should NOT include "what's in the box" shots as it may lead to confusion for shoppers.
- True or false? Vendors will use Fulfillment by Amazon (FBA) or Merchant Fulfilled Network (MFN) to ship products to customers.
- What factors should be considered by a seller when selecting a selling plan in Seller Central?
- What is Amazon's version of a SKU (stock keeping unit) that is used to identify unique products on Amazon?
- What is the guiding principle behind all Amazon retail programs?
- What is the minimum star rating a product should have to be considered retail ready?
- What is the name of the portal that Amazon sellers use to create listings, manage orders, and correspond with buyers?
- What is the primary difference between Fulfillment by Amazon (FBA) and Merchant Fulfilled Network (MFN)?
- What section of Vendor Central allows users to access Amazon Vine?
- What section of Vendor Central allows users to manage A+ Content?
- What should a Vendor Central user update to enable customers to discover their products using the search bar?
- Where in Vendor Central can a user find recommendations to improve their business and increase sales?
- Which best defines a parent ASIN?
- Which best describes Merchant fulfilled network?
- Which metric highlights how frequently an advertiser's products show up in organic widgets such as recommendations or "frequently bought together with"?
- Which of the following action(s) can a Vendor Central user take to manage products?
- Which of the following allows vendors to run sponsored ads that appear on Amazon product detail pages and within shopping results?
- Which of the following best describes conversion share?
- Which of the following examples best articulates the use of an alternative purchase report?
- Which of the following is an optimal main image?
- Which of the following is included on a product detail page?
- Which of the following is not a benefit of Amazon Brand Analytics?
- Which of the following is not a benefit of ARA Premium?
- Which of the following is not a benefit of retail insights?
- Which of the following is NOT an Amazon retail program?
- Which of the following is NOT included in the retail readiness checklist?
- Which of the following is true regarding product variations?
- Which type of selling partner must be invited to sell on Amazon?
- Zoope, an Amazon seller, launched a new product last week that has 7 reviews. What is the suggested method for them to improve the retail readiness for this product?
Amazon Security Specialty SCS-C02 All exam questions
- A company accidentally deleted the private key for an Amazon Elastic Block Store (Amazon EBS)–backed Amazon EC2 instance. A security engineer must regain access to the instance. Which combination of steps will accomplish this? (Choose two.)
- A company adopted compliance requirements to log all user actions across every account in an AWS Organizations organization. The company must trigger alarms for specified actions and deliver alerts to an email distribution list with near-real-time responsiveness. Which solution meets these requirements?
- A company centrally stores all AWS CloudTrail logs in an Amazon S3 bucket managed by the security team. The team must prevent unauthorized access and detect or prevent any tampering of the logs. Which combination of actions should be implemented? (Choose three.)
- A company collects logs from on-premises devices on an on-premises server. The company wants a near real-time analytics solution using AWS services and needs to retain logs for 365 days for pattern matching and substring searches, with minimal development effort. Which solution meets these requirements with the least development overhead?
- A company configured a gateway VPC endpoint for Amazon S3 in a VPC. Only one subnet in the VPC uses the endpoint by routing S3 traffic through it. The VPC also has an internet gateway. From an Amazon EC2 instance in that subnet, a security engineer tries to use the instance profile credentials to retrieve an object from an S3 bucket, but the request fails. The instance profile permissions, S3 bucket policy, security group, and network ACLs have all been verified as correct. What else should the security engineer check to determine why the request is failing?
- A company created a VPC for a new application in a new AWS account. The VPC is peered to an existing VPC in another account in the same Region for database access. Amazon EC2 instances will be frequently created and terminated in the application VPC, but only some need to connect to the databases in the peered VPC over TCP port 1521. A security engineer must ensure that only the required instances can reach the databases. What should the engineer do?
- A company deploys a distributed web application on Amazon EC2 instances behind an Application Load Balancer (ALB) that terminates TLS. The company requires that TLS traffic to the ALB remain secure even if the certificate’s private key is compromised. How should a security engineer satisfy this requirement?
- A company deploys a suite of applications with several AWS CloudFormation stacks. Some team members encounter permission errors when deploying stacks, while others succeed. All team members assume a role that grants the permissions required for their job functions, and all have permissions to operate on the stacks. Which combination of steps will most securely ensure consistent stack deployments? (Choose three.)
- A company deploys AWS Lambda functions with AWS CloudFormation. Developers are trying to debug a deployed function, but it is not writing output to Amazon CloudWatch Logs. Which combination of actions should a security engineer take to resolve this? (Choose two.)
- A company enabled Amazon GuardDuty and wants to automate response to potential threats, starting with RDP brute-force attacks originating from Amazon EC2 instances in its environment. The goal is to block traffic from a suspicious instance until investigation and remediation are complete. Which solution meets these requirements?
- A company enabled DNS Security Extensions (DNSSEC) for a subdomain that is hosted in Amazon Route 53. DNSSEC signing is enabled and a key-signing key (KSK) has been created. Testing shows a broken chain of trust. How should the security engineer resolve this issue?
- A company engaged a third party to audit several AWS accounts. Cross-account IAM roles were created in each target account. The auditor is unable to access some of the accounts. Which of the following could be causing this issue? (Choose three.)
- A company has a set of Amazon EC2 instances in a single private subnet of a VPC with no internet gateway. The Amazon CloudWatch agent is installed on all instances to collect logs from a specific application. To keep log traffic private, the networking team created VPC endpoints for CloudWatch (monitoring) and CloudWatch Logs and attached them to the VPC. The application is generating logs, but they are not appearing in CloudWatch. Which combination of steps should the security engineer take to troubleshoot this issue? (Choose three.)
- A company has an application built with AWS Lambda, Amazon S3, Amazon Simple Notification Service (Amazon SNS), and Amazon DynamoDB. An external application uploads objects to the company’s S3 bucket and tags each object with the date and time. A Lambda function periodically reads objects from the S3 bucket based on these tags and writes selected values to a DynamoDB table. The data contains PII. The company must automatically remove data older than 30 days from both the S3 bucket and the DynamoDB table. Which solution provides the highest operational efficiency?
- A company has an AWS Organizations structure with separate accounts for each business unit. All AWS CloudTrail logs are centralized in an Amazon S3 bucket in the top-level account, which the IT governance team can access. A security engineer created an IAM role in the top-level account for each business unit account, granting read-only access to the bucket objects with that unit’s log prefix. What must be done in each business unit account to allow an IAM user there to read its CloudTrail logs?
- A company has enabled Amazon GuardDuty in all AWS Regions. In one VPC, an EC2 instance functions as an FTP server and receives a high volume of connections from many client locations. GuardDuty flags this as a brute-force attack. The company marked the finding as a false positive, but GuardDuty continues to generate it. How can a security engineer reduce noise without sacrificing visibility into legitimate anomalies?
- A company has formed a new partnership with a vendor that will process the company’s customer data. The company will upload data files as objects to an Amazon S3 bucket, and the vendor will download the objects for processing. The objects contain sensitive data. A security engineer must ensure that objects do not remain in the S3 bucket for longer than 72 hours. Which solution meets this requirement?
- A company has hundreds of AWS accounts in a single-Region AWS Organizations setup. A dedicated security tooling account is the delegated administrator for both Amazon GuardDuty and AWS Security Hub. GuardDuty and Security Hub are automatically enabled for all existing and new accounts. During control testing, the team launched an EC2 instance and issued DNS queries to example.com to trigger a GuardDuty DNS finding, but no finding appeared in the Security Hub delegated administrator account. What is the most likely reason the finding was not created?
- A company has secured the root user of its AWS account and enabled AWS CloudTrail with logs delivered to Amazon S3. A security engineer needs near real-time alerts when the root user successfully signs in to the AWS Management Console. Which solutions will provide these notifications? (Choose two.)
- A company has several petabytes of data that must be retained for 7 years to meet regulatory requirements. The compliance team asks the security officer to design a strategy that prevents any modification or deletion of the data. Which solution is the most cost-effective?
- A company has two AWS accounts, Account A and Account B. Each account has a VPC. An application in the VPC in Account A must write to an Amazon S3 bucket in Account B. The application in Account A already has permission to write to the bucket. Both the application and the S3 bucket are in the same AWS Region. The company must not send traffic over the public internet. Which solution meets these requirements?
- A company has two AWS accounts: Account A and Account B. Account A provides an IAM role that users in Account B assume to upload sensitive documents to S3 buckets in Account A. A new requirement states users may assume the role only when authenticated with multi-factor authentication (MFA). What is the lowest-risk, lowest-effort way to meet this requirement?
- A company hosts a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application is experiencing a DoS attack. Logs show requests originate from a small set of client IP addresses that rotate frequently. The company needs to block the malicious traffic with minimal ongoing operational effort. Which solution meets these requirements?
- A company hosts a web server on AWS and stores the site’s content in an Amazon S3 bucket. A security engineer must use Amazon CloudFront to accelerate content delivery, and the S3 content must not be publicly accessible directly from the bucket. Which solution meets these requirements?
- A company hosts frontend services on Amazon EC2 instances behind an Application Load Balancer. The EC2 instances use Amazon Elastic Block Store (Amazon EBS) volumes, and large image and music files are stored in Amazon S3. The company has implemented controls to prevent, detect, and isolate potential ransomware attacks and now wants a disaster recovery strategy to return to normal operations if an attacker bypasses those controls. The recovery point objective (RPO) is 1 hour. Which solution meets these requirements?
- A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The site is under a global DDoS attack from a specific IoT device brand that has a distinctive User-Agent header. A security engineer is creating an AWS WAF web ACL to associate with the ALB and must add a rule that blocks these requests now and in the future without affecting customers. Which rule statement meets these requirements?
- A company in France uses Amazon Cognito with the Hosted UI as an identity broker for sign-in and sign-up. The application’s users are expected to be in France, but after launch the security team observes fraudulent sign-ups, mostly from outside France. The team needs to perform custom validation during sign-up and accept or reject registrations based on the result. Which combination of actions will meet these requirements? (Choose two.)
- A company is building an AWS-hosted application that stores sensitive information. The support team has infrastructure access, including databases. The security engineer must protect the sensitive data against breaches while minimizing operational overhead, and credentials must rotate regularly. What should the security engineer recommend?
- A company is concerned about DDoS attacks. Its web application runs on Amazon EC2 instances and serves static content (images and videos) from Amazon S3. A security engineer must design a resilient, cost-effective architecture that can withstand DDoS events. Which solution meets these requirements most cost-effectively?
- A company is creating an organization in AWS Organizations. The company needs to integrate user management with an external identity provider (IdP) and centrally manage access to all AWS accounts and applications from the management account. Which solution will meet these requirements?
- A company is deploying a new application stack that includes web and backend servers on Amazon EC2 in an Auto Scaling group that uses launch templates, and an Amazon Aurora MySQL DB cluster. EBS volumes back the EC2 instances. No components are currently encrypted at rest. A security engineer must implement encryption at rest. Which combination of actions will meet these requirements? (Choose two.)
- A company is developing an ecommerce application on Amazon EC2 with an Amazon RDS for MySQL database. For compliance, data must be encrypted in transit and at rest. The solution must minimize operational overhead and cost. Which approach meets these requirements?
- A company is migrating an application server to AWS, but due to compliance the database must remain on premises. The database is highly sensitive to network latency, and all traffic between AWS and on premises must be encrypted with IPsec. Which combination of AWS services will satisfy these requirements? (Choose two.)
- A company is migrating containerized workloads to Amazon Elastic Container Service (Amazon ECS) clusters. The company needs to detect potential threats in the workloads and enhance the security posture of the clusters. Which solution meets these needs?
- A company is migrating its Amazon EC2 workloads to Instance Metadata Service Version 2 (IMDSv2). A security engineer must determine whether any EC2 instances are still using Instance Metadata Service Version 1 (IMDSv1). How can the engineer confirm that the IMDSv1 endpoint is no longer being used?
- A company is migrating its Linux-based web servers to an Amazon EC2 Auto Scaling group. Currently, administrators SSH into static instances to retrieve log files, and the company frequently runs queries on the logs for application session and user issue analysis. The company wants to ensure that no logs are lost during scale-in events and to minimize cost. Which combination of actions should a security engineer take? (Choose two.)
- A company is opening new stores. On each store’s launch day, the company wants to deploy a customized web application for that store. Each store will have separate non-production and production environments, each in its own AWS account. The company uses AWS Organizations and has an OU dedicated to these accounts. Third-party developer teams will perform most of the development work. A security engineer must ensure teams follow the company’s AWS resource deployment plan and must restrict access to the plan to only developers who need it. A CloudFormation template that implements the deployment plan already exists. What should the security engineer do next to meet these requirements most securely?
- A company is setting up a multi-account environment with AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On). The company must restrict development teams to specific AWS Regions and restrict each account to only approved AWS services, with the least operational overhead. Which solution meets these requirements?
- A company is testing incident response procedures for destination containment. The company must isolate a critical Amazon EC2 instance immediately while keeping it running. The instance is the only resource in its public subnet and has active connections to other resources. Which solution will contain the instance immediately?
- A company is testing its incident response plan for compromised credentials. A database runs on an Amazon EC2 instance, and the sensitive database credentials are stored as a secret in AWS Secrets Manager with rotation enabled via an AWS Lambda function based on the generic rotation template. The EC2 instance and the Lambda function are in the same private subnet. The VPC has a Secrets Manager VPC endpoint. Rotation is failing, and CloudWatch Logs shows: “setSecret: Unable to log into database.” The VPC endpoint is functioning as expected. Which solution resolves the error?
- A company manages access with IAM users and groups across AWS accounts in an AWS Organizations organization and uses an external identity provider (IdP) for workforce single sign-on (SSO). The company needs a single management portal to access accounts in the organization, with the external IdP as the federation source. Which solution meets these requirements?
- A company manages accounts with AWS Organizations and has an SCP at the root to prevent sharing resources with external accounts. The marketing team’s AWS account must be allowed to share resources with external accounts, but all other accounts must remain restricted. All accounts are in the same OU. Which solution meets these requirements?
- A company manages multiple AWS accounts with AWS Organizations. A central account publishes base Amazon Machine Images (AMIs) for Amazon EC2. The company uses AWS Systems Manager for software inventory and patching. A security engineer needs an organization-wide solution that detects EC2 instances missing a required corporate software package and automatically installs the software when it is absent. Which approach meets these requirements?
- A company manages multiple AWS accounts with AWS Organizations. The security team notices that some member accounts are not sending AWS CloudTrail logs to a centralized Amazon S3 logging bucket. The team must ensure that every existing account and any new account has at least one trail configured. Which actions should the team take?
- A company manages public certificates in AWS Certificate Manager (ACM), including imported and ACM-issued certificates with mixed validation methods. A security engineer must design a monitoring solution that sends email alerts when a certificate is nearing expiration. What is the most operationally efficient approach?
- A company must detect unauthenticated access attempts to its Amazon EKS clusters without making any configuration changes to the existing EKS deployments. Which solution provides this with the least operational effort?
- A company must follow security best practices when deploying resources from an AWS CloudFormation template. The template needs to configure sensitive database credentials. The company already uses AWS Key Management Service (AWS KMS) and AWS Secrets Manager. Which solution meets the requirements?
- A company must prevent Amazon S3 objects from being shared with IAM principals that are outside its AWS Organizations organization. The company is creating a service control policy (SCP) to enforce this requirement and has already enabled S3 Block Public Access on all buckets. What should the SCP do to meet the requirement?
- A company must prevent permanent deletion of critical data stored in Amazon S3 and replicate that data from its primary AWS Region to a secondary Region for disaster recovery. Even users with administrator access must be unable to permanently delete data in the secondary Region. Which solution meets these requirements?
- A company must retain Amazon CloudWatch Logs data for 90 days and receive an alert in AWS Security Hub when any log group retention policy is noncompliant. Which solution provides the required notifications?
- A company must retain backups of Amazon RDS DB instances and Amazon Elastic Block Store (Amazon EBS) volumes in geographically distant locations (hundreds of miles apart). Which option meets this requirement with the least operational effort?
- A company needs a centralized solution to analyze log files across an AWS Organizations organization. The solution must aggregate and normalize events from the entire organization, from all AWS Marketplace solutions running in the company’s accounts, and from on-premises systems. Which solution will meet these requirements?
- A company needs a forensic logging solution for hundreds of Docker-based applications running on Amazon EC2. The solution must provide real-time analytics, support message replay, and persist the logs. Which AWS services should be used? (Choose two.)
- A company needs a native AWS solution to alert on repeated failed logins to its bastion hosts: trigger a notification when 5 failed authentication attempts occur within 5 minutes, and send the alert only to the system administrator responsible for the affected host. Which approach meets these requirements?
- A company needs a scalable, native AWS solution for multi-account authentication and authorization without adding user-managed infrastructure. AWS Organizations (all features) and AWS IAM Identity Center (AWS Single Sign-On) are already enabled. What additional steps should the security engineer take?
- A company needs automated email alerts when AWS access keys from developer accounts are detected on public code repositories. Which solution will deliver these email notifications?
- A company needs email alerts for CRITICAL findings from AWS Security Hub. There is no existing integration. Which solution will meet this requirement?
- A company needs host-based security for Amazon EC2 instances and container images in Amazon Elastic Container Registry (Amazon ECR). SSM Agent is installed on all EC2 instances. All AWS accounts are in a single AWS Organizations organization. The company will analyze workloads for software vulnerabilities and unintended network exposure and send findings to AWS Security Hub at the organization level. The solution must automatically deploy to all current and new member accounts and automatically scan new workloads as they appear. Which solution meets these requirements?
- A company needs to analyze access logs for an Application Load Balancer (ALB) that routes traffic to the company’s online login portal. The company must use visualizations to identify login attempts by bots from a known list of IP addresses. Which solution will meet these requirements?
- A company needs to automate a daily security report. An AWS Lambda function in us-west-2 reads Amazon Inspector findings ingested into AWS Security Hub and is triggered on a schedule by Amazon EventBridge. The function is failing to generate the report. Provide a least-privilege fix. Which solution meets these requirements?
- A company needs to capture object-level activity in its Amazon S3 buckets and verify the integrity of the log files with a digital signature. Which solution will meet these requirements?
- A company needs to permanently remove SSH keys from a subset of its Amazon Linux 2 EC2 instances that share the same IAM instance profile. Three users with IAM accounts still require shell access to perform critical tasks. How should a security engineer provide this access?
- A company needs to securely deploy resources and workloads across multiple AWS accounts within an AWS Organizations organization. The company will manage infrastructure as code (IaC) with AWS CloudFormation using only approved architectural patterns. The company must also enforce mandatory tagging and specific configuration standards for resource creation. Which solution meets these requirements?
- A company operates a batch-processing system that uses Amazon S3, Amazon EC2, and AWS Key Management Service (AWS KMS) across two AWS accounts. Account A hosts an S3 bucket for input and output objects, encrypted with a KMS key in Account A. Account B hosts a VPC with EC2 instances that access the S3 bucket via a bucket policy. The VPC has DNS hostnames and DNS resolution enabled. The company must redesign the system without code changes so that no AWS API calls from the EC2 instances traverse the internet. Which combination of steps meets these requirements? (Choose two.)
- A company operates a custom online gaming application and uses Amazon Cognito for authentication and authorization. The security engineer needs to implement fine-grained authorization in the application based on existing Cognito user attributes. The company already has a Cognito user pool and identity pool. Which approach meets these requirements?
- A company operates a large fleet of Linux and Windows Amazon EC2 instances in private subnets. The company requires the most secure possible method for remote administration in AWS. Which solution meets these requirements?
- A company operates a microservices architecture on AWS using Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Aurora. The company manages hundreds of AWS accounts with AWS Organizations and needs a centralized logging and security monitoring solution across all accounts. The solution must automatically detect security issues with minimal operational overhead. Which approach best meets these requirements?
- A company operates a web-based account management portal for an online game. Users sign in with a unique username and password. The portal is served by an Application Load Balancer protected by an AWS WAF web ACL that includes the AWS managed Core Rule Set (CRS). The security team detected a credential stuffing attack using credentials exposed in other breaches. The team must reduce the likelihood of successful credential stuffing while minimizing impact on legitimate users. Which combination of actions will meet these requirements? (Choose two.)
- A company operates all workloads in the us-east-1 Region and has no multi-Region resources. The company must replicate its workloads and infrastructure to us-west-1. A security engineer needs to store secrets in both Regions with AWS Secrets Manager, encrypted by AWS Key Management Service (AWS KMS), with minimal latency and the ability to operate if only one Region is available. The engineer has created the secrets in us-east-1. What should the engineer do next?
- A company operates in a hybrid cloud environment with strict compliance requirements. The company needs a report that includes evidence from on-premises workloads together with evidence from AWS resources. A security engineer must implement a solution to collect, review, and manage this evidence to demonstrate compliance with company policy. Which solution will meet these requirements?
- A company plans to migrate applications to a single AWS Region using Amazon EC2, Elastic Load Balancing (ELB), and Amazon S3. The migration must be completed quickly and must meet the following: data encrypted at rest, data encrypted in transit, and endpoints monitored for anomalous network activity. Which combination of actions should a security engineer take with the least effort? (Choose three.)
- A company plans to use AWS Key Management Service (AWS KMS) to protect data at rest and requires client-side encryption. Multiple test projects are causing a surge in AWS usage, with applications issuing many KMS requests per second for encryption. The company needs a solution that prevents throttling, improves key usage for client-side encryption, and is cost optimized. Which solution meets these requirements?
- A company prohibits use of the root user. The security team needs immediate alerts whenever root credentials are used to sign in to the AWS Management Console. How should the team accomplish this?
- A company requires end-to-end encryption for traffic between external clients and an application hosted on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). How should a security engineer meet this requirement?
- A company requires HTTPS for access to its web applications. The applications run on Amazon EC2 instances behind an Application Load Balancer (ALB) in a VPC. A security engineer must ensure the load balancer only accepts connections on port 443, even if an HTTP listener is accidentally configured. Which configuration accomplishes this?
- A company requires that no Amazon EC2 security group allows SSH access from 0.0.0.0/0. The company wants continuous compliance monitoring and near-real-time notifications if any security group becomes noncompliant. A security engineer has enabled AWS Config with the restricted-ssh managed rule. What should the engineer do next to meet these requirements?
- A company runs a cron job on an Amazon EC2 instance on a schedule. The cron job invokes a bash script that encrypts a 2 KB file. A customer managed AWS Key Management Service (AWS KMS) key and policy are configured, and the EC2 instance role has the required permissions. Which process should the bash script use to encrypt the file?
- A company runs a public website on an Amazon EC2 instance. The site must be accessible over HTTPS, and administrators use SSH for server management. The website is in subnet 10.0.1.0/24, and administration occurs from subnet 192.168.100.0/24. You need to create the instance’s security group. Which actions should you take to meet the requirements in the most secure way? (Choose two.)
- A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application listens on ports 80 and 443 at the ALB, which terminates SSL and forwards only HTTP (port 80) to instances. The ALB is in public subnets associated with a network ACL named NACL1. The application instances are in private subnets associated with NACL2. An Amazon RDS for PostgreSQL DB instance (port 5432) is in a separate private subnet associated with NACL3. All NACLs currently allow all inbound and outbound traffic. Which network ACL changes will harden security while preserving functionality?
- A company runs a web application on Apache HTTP Server on Amazon EC2 instances in an Auto Scaling group. The instances send Apache access logs to an Amazon CloudWatch Logs log group that is set to retain logs for 1 year. The company found that a specific IP address is making suspicious requests. A security engineer needs to analyze the past week of logs to determine how many requests were made from that IP and which URLs were requested, with the least effort. What should the engineer do?
- A company runs a web application that stores sensitive data in an Amazon DynamoDB table. The company requires end-to-end data protection and the ability to detect any unauthorized modifications. Which solution meets these requirements?
- A company runs Amazon EC2 Linux instances. The security team received a report listing common vulnerability identifiers (CVEs) that may affect the instances. A security engineer must verify patch compliance, identify at-risk instances, and automatically apply the required patches. Which approach meets these needs?
- A company runs an Amazon Aurora database in a VPC with no internet access and private DNS hostnames enabled. A security engineer configured AWS Secrets Manager to automatically rotate the database credentials by using the default AWS Lambda rotation function in the same VPC. Rotation fails because the Lambda function cannot reach the Secrets Manager endpoint. What is the most secure way to allow the Lambda function to communicate with Secrets Manager?
- A company runs an Amazon RDS for MySQL DB instance in a VPC that must not send or receive traffic over the public internet. Due to policy restrictions, the company cannot use the default AWS Lambda rotation function that AWS Secrets Manager provides, so a custom Lambda function was deployed in the VPC to rotate the secret. The DB instance’s security group allows connections from this function. However, when invoked, the function cannot reach Secrets Manager to complete rotation. What should the security engineer do to enable the function to rotate the secret?
- A company runs an application on Amazon EC2 behind an Application Load Balancer. The application also uses Amazon S3 and Amazon SQS and scales with AWS Auto Scaling. The security policy mandates least-privilege access, which is already enforced on existing resources. A security engineer must establish private connectivity from the application to these AWS services. Which combination of actions will satisfy this requirement? (Choose three.)
- A company runs an application on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local storage. After a scale-in event, a security engineer observed that logs were lost. The company must ensure log durability and availability, and retain all logs for at least 1 year for audits. What should the security engineer recommend?
- A company runs an application on Amazon EC2 instances behind an Application Load Balancer (ALB). The company needs secure, VPN-less access to the application and must allow access only when users meet specific security conditions, including device posture. Which solution meets these requirements?
- A company runs an application on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group and use Amazon Elastic Block Store (Amazon EBS) volumes. A security engineer must preserve all forensic evidence from one instance. In what order should the engineer perform the steps?
- A company runs an application on Amazon EC2 instances that process confidential customer data. The company must restrict access and does not allow opening inbound ports, maintaining bastion hosts, or managing SSH keys. A security engineer needs secure access to the instances and wants to capture, store, and access fully encrypted session logs. Which solution meets these requirements?
- A company runs an AWS Lambda function that generates thumbnail images from larger originals. The function needs read and write permissions to an Amazon S3 bucket in the same AWS account. Which options will grant the function the required access? (Choose two.)
- A company runs application logic on AWS Lambda across hundreds of AWS accounts managed with AWS Organizations. The company needs to continuously monitor all Lambda functions for vulnerabilities and publish findings to a dashboard. Lambda functions that are in testing or development must not appear on the dashboard. Which combination of actions meets these requirements? (Choose two.)
- A company runs applications on Amazon RDS for MySQL. A security audit found an RDS DB instance that is not encrypted at rest, violating policy. The security engineer must encrypt all existing RDS databases with server-side encryption and detect any future noncompliant creations. Which combination of actions meets these requirements? (Choose two.)
- A company runs internal microservices on Amazon Elastic Container Service (Amazon ECS) with the Amazon EC2 launch type and uses Amazon Elastic Container Registry (Amazon ECR) private repositories. A security engineer must encrypt the ECR repositories with AWS Key Management Service (AWS KMS) and scan container images for common vulnerabilities and exposures (CVEs). Which solution will meet these requirements?
- A company runs its application on Amazon Elastic Container Service (Amazon ECS) using the AWS Fargate launch type. A security engineer suspects some incoming requests are malicious and needs to inspect the running container to retrieve log files and memory dumps with minimal operational overhead. Which approach meets these requirements?
- A company runs its containerized application on Amazon Elastic Container Service (Amazon ECS). The company must ensure container images have no critical vulnerabilities and must restrict access to the images to specific IAM roles and specific AWS accounts, with minimal operational overhead. Which solution meets these requirements?
- A company runs Kubernetes applications on Amazon Elastic Kubernetes Service (Amazon EKS) and uses Amazon GuardDuty with EKS Protection enabled. However, GuardDuty is not monitoring the Kubernetes-based applications. What action will enable GuardDuty to monitor these applications?
- A company runs long-running analytics on data stored in Amazon S3. The jobs run on Amazon EC2 instances in a private subnet with no internet access, using an Auto Scaling group. The EC2 instances and S3 buckets are in the same AWS account and use an S3 gateway VPC endpoint with the default policy. Each instance’s profile role explicitly allows s3:GetObject and s3:PutObject only for the required S3 buckets. The company discovers that one or more instances are compromised and are exfiltrating data to an S3 bucket outside the company’s AWS Organizations organization. A security engineer must stop the exfiltration while keeping the processing jobs operational. Which solution will meet these requirements?
- A company runs multiple applications in a single VPC behind an Application Load Balancer that is associated with an AWS WAF web ACL. The security team has identified port scans originating from a specific public IP range. A security engineer must deny requests from that IP range. Which solution will meet these requirements?
- A company runs servers on Amazon EC2 instances in a VPC. External vendors access these servers over the internet. The company deployed a new application on EC2 instances in a new CIDR range. Security groups and network ACLs allow the required inbound ports, but vendors still cannot connect. Which change will provide vendor access to the application?
- A company runs web and mobile applications in Amazon ECS containers with the Fargate launch type. Each business unit uses a separate AWS account and stores images in a private Amazon Elastic Container Registry (Amazon ECR) repository in its own account. A security engineer must recommend a solution to scan ECS containers and ECR registries for operating system and language-library vulnerabilities. The audit team needs centralized visibility into potential vulnerabilities across all accounts. Which solution meets these requirements?
- A company runs workloads on Amazon EC2. The company must continuously scan the EC2 instances for software vulnerabilities and unintended network exposure. Which solution will meet these requirements?
- A company runs workloads on Amazon EC2. The company needs continuous monitoring for software vulnerabilities and must display the findings in AWS Security Hub. No agents can be installed on the EC2 instances. Which solution meets these requirements?
- A company runs workloads on hundreds of Amazon EC2 instances. After a recent incident where malware ran until the instance was manually terminated, the company enabled Amazon GuardDuty to detect malware on EC2. The security engineer must automate the response when GuardDuty flags an instance as infected, to mitigate the incident in accordance with the AWS Well-Architected Framework guidance for incident response. Which solution meets these requirements?
- A company runs workloads only in the us-east-1 Region and now needs to replicate its workloads and infrastructure to the us-west-1 Region. A security engineer must implement AWS Secrets Manager to store secrets in both Regions, encrypted with AWS Key Management Service (AWS KMS). The solution must minimize latency and continue to work if only one Region is available. The secrets have been created in us-east-1. What should the security engineer do next?
- A company stores data in Amazon S3 Glacier. A new vault lock policy was applied to 10 TB of data, and the initiate-vault-lock operation was called 12 hours ago. An audit found a typo in the policy that allows unintended access. What is the most cost-effective way to fix this?
- A company stores sensitive data in an Amazon S3 bucket encrypted with server-side encryption with Amazon S3 managed keys (SSE-S3). A security engineer must prevent any modifications to the objects. Which solution meets this requirement?
- A company stores sensitive data in AWS Secrets Manager. A security engineer must send an email notification when anomalous GetSecretValue API calls occur. An Amazon EventBridge rule is already configured to capture all Secrets Manager events delivered by AWS CloudTrail. Which solution meets these requirements?
- A company stores website images in an Amazon S3 bucket and uses Amazon CloudFront to distribute them. The company has discovered access from countries where it does not have distribution rights. Which actions should the company take to secure the images and limit distribution? (Choose two.)
- A company streams live video using HTTP Live Streaming (HLS) through Amazon CloudFront. HLS segments videos into thousands of small files. The origin is hidden so all users must access the CloudFront URL. The web app authenticates subscribers against an internal repository, and a CloudFront key pair has been issued. What is the simplest and most effective way to protect the content?
- A company subscribes to a third-party cloud security scanner that integrates with AWS Security Hub. The security engineer must automatically remediate findings generated by this integration. Which solution meets this requirement?
- A company suspects an attacker exploited an overly permissive role to extract credentials from Amazon EC2 instance metadata. The company uses Amazon GuardDuty and AWS Audit Manager, and has AWS CloudTrail and Amazon CloudWatch logging enabled across all accounts. A security engineer must determine whether the stolen credentials were used from outside the company’s accounts to access company resources. Which solution provides this information?
- A company uses a collaboration application. The security engineer needs automated alerts from AWS Security Hub in the us-west-2 Region to appear in a channel whenever Security Hub receives a new finding. A Lambda function reformats the message and sends it to the application’s API. An Amazon EventBridge rule targets the Lambda function. After enabling the rule, the channel is flooded with alerts, many from Amazon Inspector that require no action. With the least operational effort, how can the engineer stop the Amazon Inspector alerts?
- A company uses a third-party identity provider (IdP) with SAML-based SSO for its AWS accounts. After the IdP renewed an expired signing certificate, users receive the following error when attempting to sign in: Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken). A security engineer must resolve the issue while minimizing operational overhead. Which solution meets these requirements?
- A company uses Amazon CloudFront with two origins: a dynamic application on Amazon EC2 and an Amazon S3 bucket for static content. A security review found that HTTPS responses from the application are missing the X-Frame-Options HTTP header required to mitigate clickjacking. A security engineer must ensure the entire stack is compliant by adding the header to responses. Which approach meets this requirement?
- A company uses Amazon Cognito as its OAuth 2.0 identity platform for web and mobile applications. The company must capture both successful and unsuccessful sign-in attempts and be able to query the data. Which solution will meet these requirements?
- A company uses Amazon Elastic Container Registry (Amazon ECR) for its production applications. A security engineer must implement an automated solution to report any vulnerabilities that ECR enhanced scanning detects and send instant notifications to the company’s Slack account. Which solution provides the most operational efficiency?
- A company uses Amazon GuardDuty. The security team wants every High severity finding to automatically create a ticket in a third-party ticketing system via email. Which approach meets this requirement?
- A company uses Amazon Macie, AWS Firewall Manager, Amazon Inspector, and AWS Shield Advanced. The company wants to receive alerts when a DDoS attack occurs. Which solution meets this requirement?
- A company uses Amazon Route 53 Resolver in a hybrid DNS setup. Forwarding rules send queries for specific authoritative domains to on-premises DNS servers. A new mandate requires the company to log and query DNS traffic forwarded to those on-premises servers. The logs must include the source instance IP address and the DNS name requested as seen by Route 53 Resolver. Which solution meets these requirements?
- A company uses Amazon Simple Notification Service (Amazon SNS) topics to publish messages from application components to custom logging services. The company is concerned that sensitive data could be published and then exposed in transaction and debug logs. Which solution protects sensitive data in these SNS messages from accidental exposure?
- A company uses an AWS Key Management Service (AWS KMS) customer managed key with imported key material. Company policy requires annual key rotation. How should a security engineer meet this requirement for this customer managed key?
- A company uses an AWS Organizations organization with all features enabled and provisions new accounts through AWS Control Tower Account Factory. Trusted access for AWS Account Management is enabled. The company must ensure all new accounts in the organization are enrolled as AWS Security Hub member accounts. Which solution requires the least development effort?
- A company uses an external identity provider (IdP) for federation into multiple AWS accounts. A security engineer must quickly determine which federated user terminated a production Amazon EC2 instance one week ago. What is the fastest way to identify the user?
- A company uses an organization in AWS Organizations with a dedicated security account. All activity across all member accounts must be logged centrally to the dedicated security account and retained securely for 2 years with no deletions or modifications allowed. Which combination of steps meets these requirements with the least operational overhead? (Choose two.)
- A company uses AWS Config rules to identify Amazon S3 buckets that do not comply with the company’s data protection policy. The buckets are distributed across multiple AWS Regions and multiple AWS accounts within an AWS Organizations organization. The company needs a solution to remediate existing noncompliant buckets and any future noncompliant buckets. Which solution will meet these requirements?
- A company uses AWS Key Management Service (AWS KMS). When attempting to attach an encrypted Amazon Elastic Block Store (Amazon EBS) volume to an Amazon EC2 instance, the attachment fails. The company discovers that a customer managed key has become unusable because its imported key material was deleted. The data on the EBS volume is needed. A security engineer must recommend a way to decrypt the volume’s encrypted data key and attach the volume. Which solution will meet these requirements?
- A company uses AWS Lambda functions and has enabled Amazon Inspector with Lambda standard scanning and Lambda code scanning. In the Amazon Inspector console, some functions are not being scanned with the reason “scan eligibility expired.” What should the security engineer check to determine why these scans are failing?
- A company uses AWS Lambda functions to automate incident response for Amazon EC2 instances. The functions collect artifacts (for example, instance ID and security group configuration) and write a summary to an Amazon S3 bucket. The company’s VPC has public subnets with an internet gateway and private subnets with a NAT gateway. All S3 traffic related to incident response must stay on the AWS network and must not traverse the public internet. Which solution meets these requirements?
- A company uses AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On) to manage access across multiple AWS accounts. A security engineer creates a reusable permission set in IAM Identity Center that includes both an AWS managed policy and a customer managed policy. Although the engineer has full administrative permissions in the management account, assigning this permission set to a user who has access to multiple accounts fails. How should the engineer resolve the assignment failure?
- A company uses AWS Organizations and has AWS CloudTrail enabled in all Regions. A security engineer must ensure CloudTrail cannot be disabled. Which solution meets this requirement?
- A company uses AWS Organizations and has begun using AWS Identity and Access Management (IAM) Access Analyzer to refine overly broad access. The company needs to automatically remediate any newly created IAM policies that allow public or cross-account access, remove external access, and notify the security team. Which combination of steps should a security engineer take to meet these requirements? (Choose three.)
- A company uses AWS Organizations and needs to centralize AWS Security Hub in a dedicated account to monitor all existing and future accounts across all AWS Regions with minimal operations effort. Which combination of actions meets these requirements? (Choose two.)
- A company uses AWS Organizations and plans to add about 1,000 more accounts. Currently, only the central security team can create IAM roles. To reduce bottlenecks, application teams need to provision their own IAM roles, but the roles must be constrained in scope and must not allow privilege escalation. What is the solution with the least operational overhead?
- A company uses AWS Organizations and plans to grow from 2 to more than 50 AWS accounts over the next year. GuardDuty is already enabled in existing accounts. The company wants a centralized view of GuardDuty findings for all current and future accounts and needs GuardDuty to be automatically enabled for any new account. What should the company do?
- A company uses AWS Organizations and runs Amazon Elastic Kubernetes Service (Amazon EKS) clusters in multiple AWS accounts. A security engineer has integrated Amazon EKS with AWS CloudTrail, storing trails in an Amazon S3 bucket in each account to monitor API calls. However, CloudTrail logs do not show Kubernetes pod creation events. To view Kubernetes events in Amazon CloudWatch, what should the security engineer do?
- A company uses AWS Organizations and runs production workloads in multiple AWS accounts. A security engineer must implement a solution that proactively detects suspicious activity across all production accounts, automatically remediates incidents, sends a notification to an Amazon Simple Notification Service (Amazon SNS) topic for critical findings, and centralizes all security incident logs in a dedicated account. Which solution meets these requirements?
- A company uses AWS Organizations and wants to deploy standard design patterns (EC2, ELB, Amazon RDS, and Amazon EKS or Amazon ECS) across environments with AWS CloudFormation StackSets. Developers currently build their own CloudFormation stacks through a centralized CI/CD pipeline in a shared services account. The security team has defined configuration requirements and must be notified of any noncompliant resources without slowing developer delivery. What is the most operationally efficient solution?
- A company uses AWS Organizations to manage hundreds of accounts. Some accounts grant access to external AWS principals through cross-account IAM roles and Amazon S3 bucket policies. The company needs to determine which external principals have access to which accounts. Which solution will provide this visibility?
- A company uses AWS Organizations to manage multiple AWS accounts for human resources, finance, software development, and production. All developers are in the software development account. Some developers have launched Amazon EC2 instances with unapproved software. The company must ensure developers can launch EC2 instances only with approved applications and only in the software development account. Which solution meets these requirements?
- A company uses AWS Organizations to manage several accounts and processes a large volume of sensitive data. Data is stored in Amazon S3 and Amazon DynamoDB, and is accessed by AWS Lambda functions and containerized services on Amazon EKS on AWS Fargate. The company must encrypt all data at rest and enforce least privilege for data access. The company has created a customer managed AWS KMS key. What should the company do next to meet these requirements?
- A company uses AWS Organizations with separate OUs for development and production. Only AWS accounts in the production OU should be allowed to write VPC Flow Logs to a specific Amazon S3 bucket. When adding a Condition element to the S3 bucket policy for s3:PutObject, how should the security engineer configure the condition?
- A company uses AWS Organizations with three workload organizational units (OUs): Production, Development, and Testing. AWS CloudFormation templates define and deploy infrastructure into accounts within these OUs. Each OU has a distinct service control policy (SCP). A CloudFormation stack update succeeds in the Development and Testing OUs but fails in an account in the Production OU with an "insufficient IAM permissions" error. What should the security engineer do first to troubleshoot this issue?
- A company uses AWS Signer for all AWS Lambda functions. A developer recently left the company. The company must ensure that code authored by that developer can no longer be deployed to the Lambda functions. Which solution meets this requirement?
- A company uses AWS WAF to protect a custom public API running on Amazon EC2 behind an Application Load Balancer. The web ACL uses an AWS Managed Rules rule group. After a software upgrade to the API and its client, some requests fail and cause instability. Logging was not enabled on the web ACL. The security engineer enables AWS WAF logging to Amazon CloudWatch Logs and must immediately restore service, identify the issue, and ensure logging cannot be disabled in the future. Which additional steps should the engineer take?
- A company uses EC2 user data scripts that include sensitive values to bootstrap Amazon EC2 instances. A security engineer discovered that these sensitive values are visible to users who should not have access. What is the most secure way to protect the sensitive information used during instance bootstrapping?
- A company uses identity federation to authenticate users into an identity account (987654321987), where they assume an IAM role named IdentityRole. They then assume an IAM role named JobFunctionRole in the target AWS account (123456789123) to perform their duties. A user cannot assume the role in the target account. The role in the identity account has an attached IAM policy (not shown). What change is required to allow the user to assume the appropriate role in the target account?
- A company uses infrastructure as code (IaC) with AWS CloudFormation templates and an existing CI/CD pipeline to deploy AWS resources. After a security audit, the company wants to enforce policy as code to prevent deploying noncompliant resources (for example, an unencrypted Amazon EBS volume). Which solution will meet this requirement?
- A company uses on-premises ADFS with SSO for access to the AWS Management Console. A legacy web application was migrated to an Amazon EC2 instance and does not include built-in authentication. Employees need to access the application from anywhere on the internet, but access must be restricted to employees only, without modifying the application. How should a security engineer implement this?
- A company uses SAML federation for access to AWS accounts. An isolated workload account runs immutable Amazon EC2 infrastructure with no routine human access. The company requires a "break-glass" capability to access the workload account and EC2 instances if SAML fails. An audit found that the workload account does not have this capability. The company must implement break-glass access, log all activity, and notify the security team. Which combination of solutions will meet these requirements? (Choose two.)
- A company uses SAML federation with AWS Identity and Access Management (IAM) for SSO. The identity provider’s certificate was rotated, and users now receive the error: “Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken).” A security engineer must fix the immediate issue and prevent recurrence. Which actions should the engineer take? (Choose two.)
- A company using AWS Organizations has more than 100 AWS accounts and plans to add more. The company also uses an external corporate identity provider (IdP). The company must provide users with role-based access to these accounts while maximizing scalability and operational efficiency. Which solution meets these requirements?
- A company using AWS Organizations is migrating workloads to AWS. The application team will deploy Amazon EC2 instances, Amazon S3 buckets, Amazon DynamoDB tables, and Application Load Balancers. The company requires that: • All EC2 instances are launched only from approved AWS accounts. • All DynamoDB tables follow a standardized naming convention. • All infrastructure in any account in the organization must be deployed via AWS CloudFormation templates. Which combination of actions should the application team take? (Choose two.)
- A company using AWS Organizations needs to provide short-term credentials to third-party AWS accounts for access to accounts in the organization, for both AWS Management Console and third-party SaaS application access. The solution must strengthen trust to prevent two external accounts from using the same credentials and require minimal operations. Which solution meets these needs?
- A company will process sensitive data on Amazon EC2 instances and use Amazon CloudWatch Logs to collect, store, and access log files for developer troubleshooting. A security engineer must prevent developers from viewing sensitive data in the logs, and the control must automatically apply to all new log groups. Which solution will meet these requirements?
- A company with a single AWS account uses an Amazon EC2 instance to test application code. The instance was recently found to be compromised and serving malware. Analysis shows the compromise occurred 35 days ago. A security engineer must quickly implement continuous monitoring that automatically emails the company’s security team for high-severity compromised-instance findings. Which combination of steps will meet these requirements? (Choose three.)
- A company with many member accounts in AWS Organizations is concerned about potential misuse of root user credentials. The company wants to ensure that even if root credentials are compromised, the account remains protected. Which solution meets this requirement?
- A company’s application currently encrypts files by using an AWS Key Management Service (AWS KMS) AWS owned key. The security team wants the flexibility to switch to new key material for all future files whenever a potential key compromise is suspected. A security engineer must implement a solution that allows on-demand key changes. Which solution meets these requirements?
- A company’s application uses many Amazon DynamoDB tables. Auditors determined the tables do not meet the company’s data protection policy. The policy requires backups twice per month at midnight on the 15th and 25th, with a retention period of 3 months. Which combination of actions should a security engineer take to comply? (Choose two.)
- A company’s data scientists use Amazon SageMaker to read, process, and write data to an Amazon S3 bucket. Each project has a dedicated S3 prefix, and bucket policies restrict access by prefix. Projects last up to 60 days, and the security team requires that data not remain in S3 after a project ends. What is the MOST cost-effective solution?
- A company’s engineering team is developing an application that creates AWS Key Management Service (AWS KMS) customer managed key grants for users. Immediately after a grant is created, users must be able to use the KMS key to encrypt a 512-byte payload. During load testing, AccessDeniedException errors occasionally occur on the first attempt to encrypt. What should the security specialist recommend to eliminate these errors?
- A company’s online game stores player usernames and passwords in an Amazon Aurora database. With hundreds of thousands of users, password reset and login assistance requests are overwhelming the customer service team. The company needs to provide an alternative login method that offloads password management while securely protecting player credentials. Which solution should the company implement?
- A company’s security policy requires all Amazon EC2 instances to use the Amazon Time Sync Service. AWS CloudTrail is enabled in all accounts, and VPC flow logs are enabled for all VPCs. The security engineer must identify any EC2 instances that attempt to use public NTP servers on the internet. Which solution meets these requirements?
- A company’s web application runs behind an Application Load Balancer (ALB). The application is under a credential stuffing attack causing many failed login attempts from numerous IP addresses. All malicious requests share the same user-agent string from a known mobile device emulator. The solution must mitigate the attack while allowing legitimate logins. Which approach meets these requirements?
- A company’s web servers on AWS are under a Layer 3 and Layer 4 DDoS attack. Which combination of AWS services and features provides protection in this scenario? (Choose three.)
- A consulting agency needs temporary access to a company’s production AWS account for a security audit. Multiple consultants will require access. The agency has its own AWS account. The company mandates MFA for all access and prohibits long-term credentials. Which solution meets these requirements?
- A developer is receiving AccessDenied errors when invoking AWS service APIs from a workstation. The workstation already has environment variables and shared configuration files set up for multiple cross-account roles. A security engineer must configure credentials for the current task so they are evaluated without conflicting with existing credentials. Where should these credentials be specified?
- A development team is building a supply chain application that stores sensitive inventory data in an Amazon S3 bucket. The data will be encrypted with an AWS Key Management Service (AWS KMS) customer managed key. The data must be shared with hundreds of vendors, each using principals from their own AWS accounts. The vendor list will change weekly. The solution must support cross-account access with minimal operational overhead. What is the most efficient way to manage key access control?
- A development team released an open source toolset for a SaaS application, hosted in a public source code repository. The company discovered that the repository contains an IAM access key and secret key that grant access to internal AWS resources. A security engineer must determine whether the exposed credentials have been misused and prevent any further use. Which combination of actions will meet these requirements? (Choose two.)
- A DevOps team manages permissions with AWS Identity and Access Management (IAM). An EC2 instance profile role with the AWS managed ReadOnlyAccess policy is attached to an application running on Amazon EC2. When the application tries to read an object from an Amazon S3 bucket that is encrypted with a KMS key, it receives an AccessDenied error. The S3 bucket policy allows access for everyone in the account, and the object has no ACL. What should the administrator do to resolve the IAM access issue?
- A global ecommerce company hosts its website on AWS and uses Amazon CloudFront for content delivery. To comply with new data regulations, the company must block requests originating from certain countries. What is the most cost-effective solution?
- A healthcare company has acquired another organization and inherited its AWS environment. Ahead of an audit, the company must discover personal health information (PHI) in Amazon S3 buckets and identify any publicly accessible S3 buckets. The company also needs to collect evidence with minimal operational effort. Which combination of actions meets these requirements? (Choose three.)
- A healthcare company has multiple AWS accounts in an AWS Organizations organization. The company stores sensitive patient data in Amazon S3 and must prevent users from deleting any S3 bucket across all accounts. What is the most scalable way to enforce this control?
- A legacy application runs on a single Amazon EC2 instance and uses a hardcoded IAM access key to access the Amazon S3 bucket DOC-EXAMPLE-BUCKET1 in the same AWS account. The key has s3:GetObject permission only for this bucket. The application has been taken offline for noncompliant access practices. AWS CloudTrail is enabled in all Regions and delivers logs to the S3 bucket DOC-EXAMPLE-BUCKET2 (same account). CloudTrail is not configured to deliver to Amazon CloudWatch Logs. The company needs to determine whether any objects in DOC-EXAMPLE-BUCKET1 were accessed with that access key in the last 60 days and, if so, whether any of the accessed .txt files contained PII. Which combination of actions should the security engineer take? (Choose two.)
- A Linux-based Amazon EC2 instance that uses Amazon EBS storage in a development account is making outbound connections to known malicious IP addresses. The VPC (us-east-1) has an internet gateway and two subnets (us-east-1a and us-east-1b), each with a route table that uses the internet gateway as the default route and the default network ACL. The suspicious instance is the only instance in the us-east-1b subnet. Which response will immediately contain the incident and facilitate root-cause investigation?
- A malware outbreak has affected several Amazon EC2 instances. A key indicator is outbound traffic on TCP port 2905 to internet-based command-and-control hosts. A network ACL rule has been deployed to deny this outbound traffic at the subnet level. The security engineer must identify which EC2 instances are attempting connections on TCP port 2905. Which option will identify the affected instances with the least operational effort?
- A new workload in ap-northeast-2 runs in three Amazon EC2 Auto Scaling groups. All workloads in this Region must retain system and application logs for 7 years. A security engineer must ensure logs are not lost during scaling and are retained only for the required period. Which combination of steps will meet these requirements? (Choose three.)
- A production AWS account receives an Amazon GuardDuty finding of type Impact:IAMUser/AnomalousBehavior. A security engineer must execute the investigation playbook and collect analysis without impacting the application. Which option provides the fastest path to meet this requirement?
- A public subnet hosts two Amazon EC2 instances and uses a custom network ACL. The design must: (1) allow outbound access to an internet service over TLS (TCP 443) and (2) deny inbound traffic to MySQL (TCP 3306). Which network ACL rules satisfy these requirements?
- A security administrator enabled AWS Security Hub for all accounts in an AWS Organizations organization. The security team requires near-real-time response and remediation for AWS resources that do not meet security standards, with centralized audit logging. The organization has already reached the quotas for the number of SCPs attached to the OU and SCP document size and wants to avoid any SCP changes. The solution must maximize scalability and cost-effectiveness. Which combination of actions should the administrator take? (Choose three.)
- A security administrator needs to restrict use of root user credentials across member accounts in an AWS Organizations organization. All features are enabled. The management account is used only for billing and administration, not for operations. How can the administrator restrict member account root user usage across the organization?
- A security analyst is troubleshooting alerts for suspicious security group changes. The team stated that an Amazon CloudWatch alarm monitors the corresponding AWS CloudTrail events. The analyst tested by modifying a security group but received no alert. Which troubleshooting step should the analyst take?
- A security engineer at a large enterprise manages a data processing application used by 1,500 subsidiary companies. The parent company and all subsidiaries use AWS. The application listens on TCP port 443 and runs on Amazon EC2 behind a Network Load Balancer (NLB). For compliance, the application must be accessible only to subsidiaries and must not be exposed to the public internet. The engineer has received the public and private CIDR ranges for each subsidiary. Which solution should the engineer implement to enforce these access restrictions?
- A security engineer created an Amazon S3 bucket policy with an explicit deny that blocks access for all users. A few days later, the engineer added a new statement to allow read-only access for a specific employee. The employee still receives Access Denied. What is the most likely reason?
- A security engineer discovers that the company does not enforce a minimum password length. The company uses the following identity providers: - AWS Identity and Access Management (IAM) federated with on-premises Active Directory - Amazon Cognito user pools that store users for a custom AWS Cloud application Which combination of actions will enforce a required minimum password length? (Choose two.)
- A security engineer is building an Amazon EC2 isolation procedure for incident response. The goal is to block all inbound and outbound traffic to a target instance except access by the forensics team. Each instance has its own security group, and multiple instances share the same subnet. During testing, the engineer opens an SSH session to the target, then removes existing security group rules and adds rules to allow the forensics team on port 22. The existing SSH session remains active, although ICMP to the public IP is blocked. What should the engineer do to fully isolate the instance?
- A security engineer is building an AWS Lambda function that must use a role named LambdaAuditRole to assume a role named AcmeAuditFactoryRole in another AWS account. When the code runs, it fails with: “An error occurred (AccessDenied) when calling the AssumeRole operation.” Which combination of actions will resolve the error? (Choose two.)
- A security engineer is building an incident response plan to detect suspicious activity for VPC-hosted resources across as many AWS Regions as possible in a cost-effective way. Which combination of steps will best meet these requirements? (Choose two.)
- A security engineer is designing an ecommerce application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application uses an Amazon RDS DB instance. Only HTTP/HTTPS traffic to the application should be exposed to the internet. The application must call an external payment provider that allows traffic only from a predefined list of source IP addresses. Communications with the provider must not be disrupted as the environment scales. Which combination of actions should the security engineer recommend? (Choose three.)
- A security engineer is developing a Java application on Amazon EC2 that connects to an Amazon RDS database using a user name and password. The engineer needs to protect the credentials and minimize downtime during password rotation. Which combination of actions will meet these requirements? (Choose two.)
- A security engineer is implementing ABAC to allow only specific principals to put objects in an Amazon S3 bucket. Principals already have Amazon S3 access. The bucket policy should allow s3:PutObject only when the object's Team tag matches the principal’s Team tag. During testing, a principal can still put objects when the tag values do not match. Which combination of factors explains why PutObject succeeds when the tag values differ? (Choose two.)
- A security engineer is launching a website at example.com and needs to enforce HTTPS for all client connections. Which is a valid place to store the SSL/TLS certificate for this purpose?
- A security engineer is replacing broad AWS managed IAM policies attached to an IAM role used by a script that runs with the AWS CLI. The current role has AmazonEC2FullAccess, AmazonDynamoDBFullAccess, and AmazonVPCFullAccess. The engineer must create a least privilege policy in the most operationally efficient way. What should the engineer do?
- A security engineer is setting up an AWS CloudTrail trail for all AWS Regions in an account. For added security, the logs use server-side encryption with AWS KMS (SSE-KMS) and log file integrity validation. During testing, the engineer can read the digest files but cannot read the log files. What is the most likely cause?
- A security engineer is setting up SAML 2.0 federation for a multi-account environment. AWS IAM Identity Center is configured as the identity provider (IdP), and IAM roles grant access to the AWS accounts. A federated user reports that authentication fails with the new setup. What is the most operationally efficient way to troubleshoot?
- A security engineer is troubleshooting a single web server that is not receiving any internet traffic. Other web servers are working normally. The environment uses network ACLs, security groups, a virtual security appliance, and Application Load Balancers (ALBs) for load distribution. All internet-bound traffic must pass through the virtual security appliance. The engineer has verified that the security group rules, network ACL rules, and virtual appliance rules are correct. Which additional items are valid to check? (Choose two.)
- A security engineer is troubleshooting an AWS Lambda function named MyLambdaFunction that fails when trying to read objects from an Amazon S3 bucket named DOC-EXAMPLE-BUCKET. The bucket has a bucket policy in place. Which change to the policy will ensure the Lambda function can read the objects?
- A security engineer is using Amazon EC2 Image Builder to create an AMI. The pipeline is configured to deliver build logs to an Amazon S3 bucket. When the pipeline runs, the build fails with the error: "AccessDenied: Access Denied (403)." The engineer must fix the issue following least-privilege best practices. Which combination of actions will meet these requirements? (Choose two.)
- A security engineer manages a traditional three-tier web application running on Amazon EC2 instances. The application is facing an increasing number of internet-based attacks. Which actions should the security engineer take to identify known vulnerabilities and reduce the exposed attack surface? (Choose two.)
- A security engineer managing AWS Organizations wants to validate that service control policies (SCPs) align with best practices. Which approach should the engineer use?
- A security engineer must design a process to investigate and respond to potential security incidents on Amazon EC2 instances. All instances use Amazon EBS, and AWS Systems Manager with SSM Agent is installed on every instance. The process must follow AWS security best practices and meet these requirements: preserve both volatile and non-volatile memory, update instance metadata with the incident ticket, keep the instance online but isolated, and capture investigative activity during volatile data collection. Which combination of steps meets these requirements with the least operational overhead? (Choose three.)
- A security engineer must design an AWS Key Management Service (AWS KMS) solution for Amazon EBS volumes that contain sensitive data. The key material must automatically expire after 90 days. Which option meets this requirement?
- A security engineer must design controls for Amazon EC2 instances in a VPC that process sensitive workloads. The solution must detect and remediate software vulnerabilities on the instances. Which approach satisfies this requirement?
- A security engineer must detect and report sensitive data stored in an Amazon S3 bucket. Notifications must be sent to an existing Amazon Simple Notification Service (Amazon SNS) topic. Which solution delivers this with the least implementation effort?
- A security engineer must detect whether any Amazon EC2 instances are being used for cryptocurrency mining and send notifications to an Amazon Simple Notification Service (Amazon SNS) topic when related activity occurs. Which solution satisfies these requirements?
- A security engineer must enable seamless encryption of Amazon S3 objects without requiring users to manage encryption keys directly. The solution must scale with minimal ongoing management, and the organization must be able to immediately revoke and delete the encryption keys. Which approach meets these requirements?
- A security engineer must implement a solution that automatically re-enables AWS CloudTrail across multiple AWS Regions if it is ever turned off. What is the most efficient way to accomplish this?
- A security engineer must implement a write-once-read-many (WORM) control for data stored in Amazon S3 buckets that use the S3 Standard storage class. The solution must prevent overwriting or deleting objects by any user, including the root user. Which approach meets these requirements?
- A security engineer must monitor Amazon Aurora MySQL DB instances and send email alerts when unknown users attempt to log in to the database endpoint. Which solution provides this capability with the least operational overhead?
- A security engineer must restrict a contractor’s IAM user to Amazon EC2 console access only and prevent access to all other AWS services, even if additional permissions are granted through IAM group membership. What should the security engineer do to meet these requirements?
- A security engineer must run an AWS CloudFormation template that provisions infrastructure for a production stack with web servers and a MySQL database. The template has been validated in pre-production. The production execution must follow least privilege and maintain separation of duties between the engineer’s IAM account and CloudFormation. Which approach meets these requirements?
- A security engineer must update an IAM policy to require multi-factor authentication (MFA) for IAM users accessing certain production services. Each authenticated session must be valid for no longer than 2 hours. Which conditions should be added to the policy to meet these requirements? (Choose two.)
- A security engineer needs to analyze Apache web server access logs that are stored in an Amazon S3 bucket. The logs were generated by Amazon EC2 web servers that have the Amazon CloudWatch agent installed. The engineer will use Amazon Athena to analyze the logs. The query must identify IP addresses that attempted and failed to access restricted content at the /admin URL path and must also identify the URLs those IP addresses attempted to access. Which query will meet these requirements?
- A security engineer needs to change the Amazon S3 log file prefix for an existing AWS CloudTrail trail. When saving the change in the CloudTrail console, the engineer receives the error: "There is a problem with the bucket policy." What action will allow the change to be saved?
- A security engineer needs to configure an Amazon CloudFront distribution in front of an Amazon S3 bucket that hosts a static website. Access must be allowed only from a specified set of client IP addresses, and users must not be able to access the content directly through S3 URLs. Which solution meets these requirements?
- A security engineer needs to forward custom application security logs from an Amazon EC2 instance to Amazon CloudWatch. The CloudWatch agent is installed, and the log file paths are added to the agent configuration. The awslogs service is running on the instance, but the logs are not appearing in CloudWatch. What should the engineer do next to resolve the issue?
- A security engineer needs to generate an alert when three or more failed AWS Management Console sign-in attempts occur within a 5-minute window. A CloudTrail trail is already in place. Which solution will meet these requirements?
- A security engineer needs to receive email notifications whenever Amazon GuardDuty, AWS Identity and Access Management (IAM) Access Analyzer, or Amazon Macie generate a high-severity finding. The company uses AWS Control Tower for governance and has AWS Security Hub enabled with all service integrations. Which solution provides the required alerts with the least operational overhead?
- A security engineer needs to send email alerts via Amazon Simple Notification Service (Amazon SNS) to the security team for Amazon GuardDuty findings with High severity. The engineer also needs to deliver these findings to a visualization platform for deeper analysis. Which solution meets these requirements?
- A security engineer rotated all IAM access keys in an AWS account and enabled the following AWS Config managed rules: mfa-enabled-for-iam-console-access, iam-user-mfa-enabled, access-keys-rotated, and iam-user-unused-credentials-check. After invoking the IAM GenerateCredentialReport API, all resources appear as noncompliant. What is the most likely reason?
- A security engineer uses Amazon Macie to scan the company’s Amazon S3 buckets for sensitive data. There are many buckets and objects. The engineer must identify which buckets contain sensitive data and then run deeper scans on those buckets, with minimal administrative overhead. Which solution meets these requirements?
- A security engineer with administrator permissions signs in to the AWS Lambda console and tries to view Amazon CloudWatch logs for a function named myFunction. When selecting the option in the Lambda console to view logs in CloudWatch, an "error loading Log Streams" message appears. The Lambda function’s execution role has the following IAM policy statements. How should the security engineer resolve the error?
- A security team is building an Amazon EventBridge-based alerting solution to detect new Amazon S3 objects with public access and any S3 bucket policy or setting changes that make data public. EventBridge listens for specific AWS CloudTrail API events and immediately sends details to the team via Amazon Simple Notification Service (Amazon SNS). The team configured EventBridge to match s3:PutObjectAcl, s3:DeleteBucketPolicy, and s3:PutBucketPolicy events. In testing (with CloudTrail management events enabled in the same Region and a verified event pattern), EventBridge triggers for s3:DeleteBucketPolicy and s3:PutBucketPolicy but not for s3:PutObjectAcl. The team must ensure s3:PutObjectAcl generates an EventBridge event without causing false notifications. What should they do?
- A security team must record and centrally retain AWS API call activity for all current and future Regions. What is the simplest way to meet these requirements?
- A security team needs automatic alerts when any AWS access key is older than 90 days without rotation. What is the simplest solution to implement?
- A startup initially operated in one AWS Region and created a regional AWS CloudTrail trail (via the AWS CLI) that delivers logs to an Amazon S3 bucket. After adding resources in multiple Regions, the engineer observes that logs from the new Regions are not delivered to S3. With minimal operational effort, how should this be fixed?
- A systems engineer is troubleshooting a test environment that includes an inline virtual security appliance. The development team also wants to use security groups and network ACLs to meet various security requirements. Which configuration change is required to allow the virtual security appliance to route traffic?
- A team stores an application’s database password in AWS Secrets Manager. Only a limited and frequently changing set of IAM principals should be able to access the secret. A security engineer needs a solution that maximizes flexibility and scalability. Which approach meets these requirements?
- A VPC spans two Availability Zones. Each AZ has one private subnet and one public subnet. There are three route tables: one shared by the public subnets and one private route table per AZ. All four subnets are attempting to route outbound traffic through the VPC’s internet gateway. Which actions should the security engineer take to remediate this? (Choose two.)
- After a DDoS event against a public Application Load Balancer (ALB), a company placed Amazon CloudFront in front of the ALB. However, some clients still reach the ALB directly, and the Amazon EC2 instances continue to serve that traffic. Which combination of actions ensures the EC2 instances only receive requests that come through CloudFront? (Choose two.)
- After migrating to AWS, a company is replacing software load balancers running on EC2 instances with AWS Elastic Load Balancers. The security engineer must ensure that all load balancer logs are centralized and searchable for audits and that metrics are available to show which TLS ciphers are in use. Which solution meets these requirements?
- After noticing a billing anomaly, a security consultant finds that a former employee retained access for the past 30 days. With no prior activity monitoring in place, the consultant must quickly identify which resources this user created or modified. Which solution meets these needs?
- After recovering EC2 instances from Amazon EBS snapshots during an incident, a company using an AWS Key Management Service (AWS KMS) customer managed key for snapshot encryption performs a disaster recovery gap analysis. The company needs a solution to recover EC2 instances even if the primary AWS account is compromised and its EBS snapshots are deleted. Which solution meets this requirement?
- An Amazon API Gateway API invokes an AWS Lambda function that must call a SaaS platform. The SaaS platform issues a unique client token to authorize the Lambda function. A security engineer must encrypt the token at rest and supply it to the Lambda function at runtime in the most cost-effective way. Which solution meets these requirements?
- An Amazon CloudWatch Logs agent is successfully streaming logs, but logging stops after the associated log stream has been active for a set number of hours. What actions will help identify the cause? (Choose two.)
- An Amazon EC2 Auto Scaling group launches Amazon Linux instances and installs the Amazon CloudWatch agent to send logs to Amazon CloudWatch Logs. Instances assume an IAM role with a policy that currently allows publishing custom metrics to CloudWatch. Instances run in a private subnet with internet access through a NAT gateway. The CloudWatch Logs agent is running and correctly configured, and network connectivity to AWS is verified, but no logs appear in CloudWatch Logs. What should the security engineer do to ensure logs are published?
- An Amazon EC2 instance in a VPC is receiving a high volume of suspicious traffic on an open TCP port from a specific external source. The port must be blocked for that source without affecting other users. What should the security team do?
- An Amazon EC2 instance suddenly shows high CPU usage. It is unclear whether the instance is compromised or performing normal OS background tasks. Which actions should a security engineer take before starting the investigation? (Choose three.)
- An application on Amazon EC2 processes sensitive data, including credit card numbers. The numbers must be sent to a highly isolated component that encrypts, stores, and decrypts them, and issues tokens for use elsewhere in the application. Only the tokenization component may access the raw numbers. What solution should be used for the tokenization component?
- An application running on Amazon EC2 instances needs to retrieve objects from an Amazon S3 bucket. All objects in the bucket are encrypted with an AWS Key Management Service (AWS KMS) customer managed key. The VPC has no internet access and uses a gateway VPC endpoint for Amazon S3. The application cannot retrieve objects. Which factors could be causing this issue? (Choose three.)
- An application running on Amazon EC2 pulls messages from Amazon SQS. After recent IAM changes, the instances can no longer receive messages. Which actions should you take to troubleshoot while maintaining least privilege? (Choose two.)
- An application runs on an Amazon EC2 instance with an attached IAM role that permits use of an AWS Key Management Service (AWS KMS) customer managed key and access to an Amazon S3 bucket containing 2 TB of sensitive data. A security engineer discovers a potential vulnerability on the instance that could expose the data but cannot immediately stop the instance. What is the fastest way to prevent exposure of the sensitive data?
- An application team wants to use AWS Certificate Manager (ACM) to request public certificates for encrypting data in transit. The team will use an AWS managed distribution and caching service to improve performance for customers, with one primary custom domain and multiple alternate domain names. The domains are not hosted in Amazon Route 53. Certificates must automatically renew indefinitely. Which combination of steps should the team take? (Choose three.)
- An audit identified potential threats that could appear as spikes in DNS access, abnormal EC2 instance traffic, abnormal network interface traffic, and unusual Amazon S3 API calls, originating from various sources at any time. The company needs continuous, near-real-time monitoring to detect these threats. Which solution will meet these requirements?
- An AWS account administrator attached a managed policy to an IAM group to require that each user authenticate with multi-factor authentication (MFA). After enabling the policy, users report that they cannot run Amazon EC2 commands with the AWS CLI. How should the administrator resolve this while still enforcing MFA?
- An AWS account has two S3 buckets: bucket1 and bucket2. bucket2 does not have a bucket policy. bucket1 has a specific bucket policy. The same account has an IAM user named alice with a specific IAM policy. Which buckets can alice access?
- An AWS Lambda function was misused to modify data. A security engineer needs to identify who invoked the function and what it returned. However, there are no logs from the function in Amazon CloudWatch Logs. Which explanation accounts for the missing logs?
- An ecommerce company is designing a new application architecture for an upcoming release. All client traffic originates from the internet. TLS must be terminated for inbound requests, but end-to-end TLS to the application is not required due to performance concerns. The application receives HTTP and HTTPS traffic on ports 80 and 443. What should a security engineer implement to meet these requirements?
- An ecommerce company runs its web application on Amazon Elastic Container Service (Amazon ECS). Container images are stored in Amazon Elastic Container Registry (Amazon ECR). The security team needs both continuous and on-push image scanning, must view findings on a centralized dashboard alongside other security findings, and must exclude specific repositories from scanning. Which solution will meet these requirements?
- An ecommerce site was unavailable for 1 hour due to a DDoS attack. The security team wants to minimize downtime during future attacks. Which two actions will help achieve this? (Choose two.)
- An engineer accidentally committed an AWS access key and secret access key to a public GitHub repository for the company’s open-source project. The manager promptly disabled the key. The company must assess the impact of the exposure with the least management overhead. What should a security engineer do?
- An external consultant needs to use a laptop to access two VPCs that are peered in the same AWS Region. The company wants to grant access only to these VPCs without exposing other network resources. Which solution should be used?
- An IAM user receives Access Denied errors when trying to access objects in an Amazon S3 bucket. The user and the bucket are in the same AWS account. The bucket uses server-side encryption with AWS KMS keys (SSE-KMS) and a customer managed key from the same account. There is no bucket policy. The user’s IAM policy allows kms:Decrypt on the key and s3:List* and s3:Get* on the bucket and objects. What is a possible reason the user cannot access the objects?
- An international company needs to aggregate AWS Security Hub findings across all AWS Regions and multiple accounts, and build a centralized custom dashboard that correlates these findings with operational data for deeper analysis. Which combination of steps will meet these requirements? (Choose three.)
- An online media company runs its application on Amazon EC2 instances with Amazon Linux 2 and manages the fleet with AWS Systems Manager. The company uses the AWS-AmazonLinux2DefaultPatchBaseline in Patch Manager for patches and updates. For an upcoming high-profile event, the company needs a solution to immediately deploy security patches to all instances in response to incidents or vulnerabilities and to provide centralized proof that patches were applied successfully. Which combination of actions will meet these requirements? (Choose two.)
- An organization in AWS Organizations has an Amazon S3 bucket in one account that is currently public. A security engineer must make the bucket private and ensure it cannot be made public in the future. Which solution meets these requirements?
- An organization uses AWS CloudTrail to monitor API activity. An audit shows CloudTrail is not delivering events to the configured Amazon S3 bucket. Which initial actions should be taken to restore delivery of CloudTrail events to S3? (Choose two.)
- An organization uses AWS Organizations in a single Region. The management account is management-01. AWS Config is enabled in all accounts, and security-01 is the delegated administrator for AWS Config. All accounts report compliance status to the delegated administrator account through an AWS Config aggregator. Account administrators can manage their own AWS Config rules. A security engineer must automatically deploy a standard set of 10 AWS Config rules to all current and future accounts in the organization and ensure AWS Config is enabled automatically for new accounts. Which combination of steps will meet these requirements? (Choose two.)
- An organization uses AWS Organizations with eight member accounts and anticipates a maximum of 20 accounts. The company runs all workloads on AWS and has a new security policy requiring: • No account runs workloads in a VPC within that account. • All workloads must launch into subnets of a centrally managed VPC accessible by all accounts. • No account can modify another account’s application resources within the shared VPC. • The centrally managed VPC must reside in an existing account named Account-A in the organization. A CloudFormation template in Account-A creates the VPC and multiple subnets and exports the subnet IDs as stack outputs. Which solution completes the setup to satisfy these requirements?
- An organization uses AWS Organizations with service control policies (SCPs). The root SCP currently includes a restriction that affects Amazon Simple Email Service (Amazon SES). Developers belong to a group with an IAM policy that allows ses:* actions. The account is in an OU with an SCP that allows SES. Developers receive not authorized errors when accessing SES in the AWS Management Console. What change must a security engineer make so developers can access SES?
- Apex Games keeps production secrets (database passwords and API tokens) in a dedicated security account’s AWS Secrets Manager. Due to policy, workloads in other AWS accounts cannot assume cross-account roles. The workloads must read these secrets directly at runtime. What is the MOST secure way to enable this?
- ApexRetail’s incident response team found that the Security team’s KMS customer managed key was disabled at 03:14 UTC. The company has an organization-level CloudTrail that delivers all management events to an S3 bucket. They must quickly determine which federated user performed the DisableKey API call, the source IP, and whether MFA was used. What is the most efficient approach using existing log data?
- ApexVideo runs a global streaming platform fronted by Amazon CloudFront with an origin Application Load Balancer. A recent DDoS caused aggressive scaling and elevated egress charges. The CISO wants to minimize financial exposure from future DDoS events without changing the application architecture. What should the security team do to ensure AWS credits for unexpected scaling charges tied to DDoS events?
- Aster Retail enforces an SCP that denies iam:PassRole unless the role has the tag Approved=true. ECS in multiple accounts now fails to launch tasks because it needs to pass its service-linked role, which cannot be tagged. How should the security team modify the SCP to allow ECS while keeping the guardrail?
- BlueFerry Insurance uses AWS Organizations with 40 accounts across multiple Regions. Compliance requires a single Security Hub view in account SecAdmin (us-east-1) that aggregates findings from all member accounts and Regions with minimal operational overhead and no custom cross-account forwarding. What should the security architect do?
- BluePallet runs Amazon ECS on EC2. An internal audit showed containers could reach 169.254.169.254 to fetch instance profile credentials, bypassing task‑level least privilege. They cannot migrate to Fargate. What is the most effective change to prevent containers from accessing instance metadata while preserving task IAM roles?
- BlueSky Bank’s SOC analysts want a one-click “Quarantine EC2” option inside AWS Security Hub to isolate instances referenced by specific findings. Clicking the action should invoke an existing Lambda function with the full finding context, including the selected resource ARN. What is the most appropriate design to meet this requirement with minimal friction for analysts?
- BlueSky Retail runs an Aurora PostgreSQL cluster for its order service. Security requires automatic rotation of the application user’s database password every 30 days without granting the application user ALTER USER privileges or exposing the master credentials to applications. What is the MOST appropriate solution?
- BrightKite’s DevOps team receives a GuardDuty finding: UnauthorizedAccess:EC2/SSHBruteForce targeting an EC2 instance in a public subnet. The instance currently allows TCP/22 and TCP/8080 from 0.0.0.0/0, but administrators need to retain SSH access from corporate offices. What is the most effective immediate remediation?
- ByteWorks exposes a multi‑tenant REST API on Amazon API Gateway (REST API) that must accept JWTs issued by an external IdP (Okta). Authorization must evaluate tenant claims, return an IAM policy, and pass custom context to the backend. The team wants to reduce authorization latency via caching. What should they implement?
- CardNet segregates PCI DSS workloads into a dedicated Organizational Unit (OU). They need preventative restrictions (for example, no Internet Gateways in PCI accounts, approved Regions only) and ongoing control mapping to PCI best practices with centralized visibility. What is the MOST appropriate approach?
- Company A (Account A) acquired Company B (Account B). Company B stores files in an Amazon S3 bucket. Administrators granted an IAM user in Account A permissions to access the S3 bucket in Account B, but the user still cannot access the objects. What action will resolve this?
- Company policy mandates that all API keys be encrypted and stored in a centralized security account managed by the security team, separate from source code. An audit found an API key committed with the source of an AWS Lambda function in an AWS CodeCommit repository in the DevOps account. How should the security team store the API key securely?
- Contoso Retail runs an internet-facing Application Load Balancer (ALB) and several other public-facing services in the same public subnets. The security team needs to immediately block abusive traffic originating from 198.51.100.0/24 for all resources in those subnets, not just the ALB. What should they do?
- Contoso Retail uses Amazon ECR and deploys to Amazon ECS. Security mandates that no image with High or Critical CVEs can be promoted to production. They want automated enforcement in their CI/CD pipeline with minimal manual steps. Which combination of actions will meet these requirements? (Choose two.)
- CortexRetail’s incident response team is investigating potential SSH brute-force attempts. VPC Flow Logs from three VPCs are delivered to separate CloudWatch Logs log groups. The team needs, within minutes, a ranked list of the top 10 source IPs with REJECTed traffic to destination port 22 over the last 15 minutes across all VPCs. What should they do?
- Data scientists use Amazon SageMaker to train AI/ML models with large, sensitive datasets stored in an Amazon S3 bucket. Training typically takes 30 days. The company’s data retention policy requires deletion of any data older than 45 days from the S3 bucket. The bucket is already secured appropriately. What should a security engineer do to enforce this retention policy?
- DataForge exposes a small internal admin tool via a Lambda function URL. They must restrict access so only callers from their AWS Organization can invoke it and require SigV4 authentication. They do not want to add API Gateway. What should they do?
- DataMosaic’s analytics platform runs in private subnets with no NAT gateways. Jobs must download data from Amazon S3 and call a partner’s API hosted in the partner’s AWS account without traversing the public internet. The solution must scale across hundreds of subnets with minimal ops overhead. Which actions should the networking team take? (Choose two.)
- DataWorks mandates that every new EC2 instance and every new RDS DB instance must include CostCenter and DataOwner tags at creation time across all accounts in the organization. The control must be preventive. What is the BEST way to meet this requirement?
- During a review of thousands of AWS Lambda functions, a security engineer finds sensitive data in environment variables that are visible as plaintext in the Lambda console. The secrets are short values. What is the most cost-effective remediation?
- Fabrikam Games allows its DevOps group to create IAM roles for EC2 workloads. Security must ensure any role they create cannot exceed a defined set of permissions (read-only to the DynamoDB table Scores and publishing to CloudWatch Logs), regardless of what policies DevOps attaches later. What is the MOST effective approach?
- Fabrikam Health already uses the AWS Config managed rule restricted-ssh to detect security groups allowing 0.0.0.0/0 on TCP/22. They want automatic remediation within one minute that removes the offending ingress as soon as the rule reports NON_COMPLIANT. What is the most suitable approach?
- FinchRide is launching a mobile app that must allow unauthenticated users to browse public content in Amazon S3 and authenticated users to save personal preferences in a DynamoDB table directly from the client. The security team requires least privilege per user without shipping long‑lived credentials in the app. Which approach should the Solutions Architect recommend?
- FinSec engages an external auditor operating in a separate AWS account to analyze an encrypted EBS volume from a compromised instance. FinSec must maintain encryption and limit the auditor’s access to only this evidence. Which steps are required to provide the auditor a usable copy of the snapshot? (Choose two.)
- FinServe Analytics runs a production Amazon RDS for PostgreSQL instance in us-east-1 that was created unencrypted. Compliance now requires encryption at rest using a customer managed KMS key. They want to minimize downtime during migration. What should they do?
- FinServe Bank operates 200 AWS accounts in AWS Organizations across multiple OUs. The CISO wants to enforce a consistent compliance baseline with automatic remediation for common findings (for example, unencrypted EBS volumes) and to view organization-wide compliance in one place. What is the MOST efficient approach?
- FinVerse hosts its public DNS for finverse.com in Amazon Route 53. The security team must enable DNSSEC to protect against DNS spoofing while continuing to use the same domain registrar. What is the correct approach?
- From Application Load Balancer access logs, a security engineer observes excessive requests from a single IP address. How can the engineer throttle requests from that IP without completely blocking it?
- GlassRiver Bank’s SOC detected potential exfiltration to 198.51.100.77:443. VPC Flow Logs are enabled to CloudWatch Logs with the default fields. They need to quickly identify which EC2 instance initiated the traffic. What should the analyst do?
- GlobalBank operates 40 AWS accounts in AWS Organizations. The security team needs centralized enforcement so that: (1) all internet-facing ALBs have a standard AWS WAF web ACL, (2) organization-wide security group rules prevent 0.0.0.0/0 except on approved ports, and (3) Shield Advanced is enabled on internet-facing resources with DRT access. They want automatic application to new accounts and resources. What should they implement?
- HealthSync uses a symmetric customer managed KMS key with imported key material (origin EXTERNAL) to encrypt application data. A new compliance control mandates automatic annual rotation managed by AWS with minimal operational overhead. What is the best approach to meet this requirement?
- Helios Media is building a DevSecOps pipeline in AWS CodePipeline/CodeBuild. The security team must enforce infrastructure policy-as-code before deployment and add static application security checks on each pull request, failing the build if high-severity issues are found. Which two actions should the team implement? (Choose two.)
- Kappa Labs needs to store 15 API keys for upstream partners. Keys must be encrypted with a customer-managed KMS key, retrieved individually, and versioned independently for rollback. Engineers attempted to use a SecureString StringList and encountered errors. What should they do?
- Lumen AI wants to prevent data exfiltration from its VPC by blocking outbound HTTPS to known malicious domains and also detect internal port scans. They prefer a managed, inline inspection service. Which solution best meets these requirements?
- Lumen Analytics runs several public-facing ALBs across multiple Regions. Their ACM public certificates use email validation and renewals often fail due to quarantined emails, causing outages. They want fully automated certificate renewal and deployment to ALBs with no manual steps. What should they do?
- MediaFlux has a Control Tower landing zone. The security team must prevent resource creation outside us-east-1 and us-west-2 and must block any public read access to S3 buckets across all enrolled accounts. Which guardrails should they enable? (Choose two.)
- NeonPay’s data lake in Amazon S3 contains large volumes of synthetic test data with known test credit card numbers that are triggering numerous Amazon Macie findings. The team needs to suppress these false positives while continuing to detect real PANs, with minimal changes to S3 data layout. What is the MOST effective approach?
- NewsFlare Media’s public ALB is targeted by large volumetric DDoS attacks and by bot traffic performing credential stuffing. They want to reduce scaling costs during attacks and apply managed and rate-based rules with minimal application changes. Which two actions should the security team take? (Choose two.)
- Nimbus Games has Amazon GuardDuty and Amazon Detective already enabled across all accounts. A GuardDuty finding indicates Backdoor:EC2/C&CActivity.B on an instance role. The IR lead wants to quickly understand the related API calls made by that role, recent network peers, and failed versus successful connections without building custom queries. What should the lead use first?
- Nimbus Retail needs to patch 500 Amazon Linux and Windows EC2 instances across Dev and Prod. Requirements: Dev auto-approves all security patches immediately; Prod auto-approves only Critical/Important patches after 7 days and excludes kernel packages; Instances are targeted by tags; Compliance must be reported centrally. What is the BEST configuration?
- Nordic Bio runs a Lambda function in Account A that must encrypt data using a KMS key in Account B. Due to platform constraints, the Lambda code cannot assume a role in another account. What should the security team do to enable this cross-account encryption without code changes?
- Northwind Insurance operates a central security account with an ACM Private CA. Application teams in multiple AWS accounts must request and renew private TLS certificates using ACM in their own accounts and attach them to ALBs, with no manual CSR handling. Which TWO actions should the security team take to enable this? (Choose two.)
- Omnix Health wants automatic containment when GuardDuty raises EC2 compromise findings, while preserving remote forensic access. The SOC requires that affected instances be quarantined to block all external traffic except Systems Manager, and that EBS snapshots be created for evidence. Which solution best meets the requirement?
- Orbit Media uses Azure AD as an external identity provider with AWS IAM Identity Center. They want to implement ABAC so users can access only resources matching their costCenter. Which actions are REQUIRED to achieve this? (Choose two.)
- Orion Analytics must enforce IMDSv2 across all EC2 instances. They already use the AWS Config managed rule ec2-imdsv2-check and want fully automated, least-privilege remediation that sets HttpTokens to required without rebooting instances. What should they do?
- Orion Foods serves dynamic pricing via CloudFront backed by an ALB. Competitors are scraping /prices aggressively, and security also wants browsers to enforce strict security headers without changing the origin. Which actions should the team take to meet both goals with minimal operations overhead? (Choose two.)
- Orion Retail stores database credentials in AWS Secrets Manager in Account B, encrypted with a customer managed KMS key in Account B. A microservice running in Account A (role: arn:aws:iam::111111111111:role/OrdersAppRole) needs read-only access to the secret. The team added an IAM policy to the role allowing secretsmanager:GetSecretValue on the secret ARN but still receives AccessDenied errors from KMS. What should the security team do to grant least-privilege cross-account access?
- Quanta ML wants to create a least-privilege policy for an application role based on actual API usage over the last month. They plan to use IAM Access Analyzer policy generation. Which steps should they take? (Choose two.)
- Quasar Finance operates a single AWS account in eu-west-1. The security team wants to automatically quarantine any EC2 instance that is the target of a GuardDuty UnauthorizedAccess:EC2/SSHBruteForce finding with severity 5 or higher, but only if the instance has the tag Quarantine=true. They want to use EventBridge for near-real-time automation and avoid quarantining untagged instances. Which combination of steps should they implement? (Choose two.)
- RetailHub’s compliance team needs to achieve PCI DSS across 50 AWS accounts. They want to continuously collect evidence (for example, IAM configuration, CloudTrail activity, ELB logging) mapped to PCI controls and generate auditor-ready reports with minimal manual effort. Which service should they use?
- The company has had issues related to specific Host headers and hostnames. As a first step, the company configured AWS WAF web ACLs. The security engineer must build a centralized log analytics solution for AWS WAF logs and be able to filter requests by host with the highest operational efficiency. Access logging for the web ACLs is being enabled. What should the engineer do next?
- The company will create separate child accounts in AWS Organizations for DevOps teams. AWS CloudTrail is enabled in all accounts and delivers audit logs to an Amazon S3 bucket in a central account. The security engineer must prevent DevOps team members from modifying or disabling this configuration. How should this be enforced?
- To meet new compliance requirements, a company must ensure that all Amazon RDS DB instances and DB clusters use encrypted storage. The company needs an automated solution that emails an alert whenever an unencrypted DB instance or cluster is created and also deletes the unencrypted resource. Which option is the most operationally efficient?
- To secure connectivity between a company’s VPC and its on-premises data center, a security engineer tested ICMP by sending a ping from an on-premises host (203.0.113.12) to an Amazon EC2 instance (172.31.16.139). The ping received no reply. Which action should be taken to allow the ping to succeed?
- Two Amazon EC2 instances located in different subnets are unable to communicate with each other, even though other hosts in the same subnets can communicate and the security groups have appropriate ALLOW rules. Which troubleshooting step should be performed?
- Verdant Analytics connects dozens of VPCs through an AWS Transit Gateway and built a centralized inspection VPC with AWS Network Firewall. After enabling inspection, inter-VPC sessions are intermittently dropped due to asymmetric routing. Which actions are required to ensure reliable stateful inspection across the Transit Gateway? (Choose two.)
- Verdant Bioinformatics encrypts large research files produced by their ETL jobs and is hitting AWS KMS request throttling and rising costs. They want to adopt an envelope encryption pattern to reduce KMS API usage while maintaining strong security. Which two actions should they implement? (Choose two.)
- Voxel Media hosts a data lake with billions of small objects in Amazon S3 using SSE-KMS with a customer managed CMK. Recently, KMS request charges spiked and occasional throttling occurred during heavy PUT/GET bursts. They must retain SSE-KMS. What is the most effective change to reduce KMS requests and costs without altering compliance posture?
- What are the most secure ways to protect the root user of a newly created AWS account? (Choose two.)
- While reviewing an AWS CloudFormation template, a security engineer finds a parameter with a default value that exposes an application API key in plaintext. The value is referenced multiple times in the template. The engineer must replace the parameter, keeping the ability to reference the value throughout the template. What is the most secure solution?
Amazon Solution Architect Professional SAP-C02 Certification All exam questions
- A big data analytics cluster will run on many Linux Amazon EC2 instances across multiple Availability Zones. Every node must have read/write access to shared underlying file storage. The file system must be POSIX-compatible, highly available, resilient, and support very high throughput. Which storage solution satisfies these requirements?
- A blog site runs on EC2 instances in an Auto Scaling group behind an ALB and stores content on Amazon EFS. The site added video support and traffic increased tenfold, causing buffering and timeouts at peak times. Which is the most cost-effective and scalable deployment to resolve user performance issues?
- A car rental company built a serverless REST API used by its mobile app. The stack uses Amazon API Gateway with a Regional endpoint, AWS Lambda, and an Amazon Aurora MySQL Serverless DB cluster. After opening access to partners, request volume rose sharply and caused intermittent database memory errors. Logs show many clients issue repeated HTTP GET requests for identical queries over short intervals. Traffic is concentrated during business hours with spikes on holidays. The company wants to support the increased load while minimizing cost growth. Which approach meets these requirements?
- A centralized logging service running on EC2 receives logs from hundreds of AWS accounts using AWS PrivateLink. Each client account has an interface VPC endpoint for the logging service. The logging service runs on EC2 instances behind a Network Load Balancer (NLB) spread across subnets. Clients cannot send logs through the VPC endpoint. Which combination of steps should a solutions architect take to fix this? (Choose two.)
- A company bought appliances from multiple vendors. Each appliance has IoT sensors that send status messages in each vendor's proprietary format to a legacy app that parses them into JSON. Parsing is simple but vendor-specific. Once per day, the app parses all JSON records and writes them to a relational database for analysis. The company wants a new data analysis design that is faster and more cost-effective. Which solution meets these requirements?
- A company built APIs using Amazon API Gateway with Regional endpoints. These APIs invoke AWS Lambda functions and use API Gateway authentication. A review found a subset of APIs that must not be publicly accessible and should be callable only from within a VPC. All calls must be from authenticated users. Which solution accomplishes this with the least effort?
- A company centralizes VPC flow logs from many accounts into a single S3 bucket. Logs are stored as text files compressed with gzip and must be retained indefinitely. Analysts run ad hoc Athena queries against these logs, but query performance is degrading as log volume grows. You must both improve query performance and reduce storage usage. Which change will provide the LARGEST performance improvement?
- A company consolidated multiple acquired AWS accounts into a single AWS Organizations setup. The finance team needs a self-managed application that can generate cost reports grouped meaningfully across the companies. Which solution will provide the required reporting capability?
- A company created an API in Amazon API Gateway that invokes Lambda functions and deployed it to a Production stage. An external development team is the only API consumer. Usage spikes at certain times, raising cost concerns. The company wants to limit usage and costs without modifying the Lambda functions. What is the MOST cost‑effective solution?
- A company currently deploys infrastructure in one AWS Region and wants to define the infrastructure as code with plans to expand to multiple Regions and multiple AWS accounts. What approach should the solutions architect use to manage and deploy the infrastructure across accounts and Regions?
- A company currently serves files via an internet-accessible SFTP server running on a single EC2 instance with an attached Elastic IP. Customers connect using that Elastic IP and SSH. The EC2 instance’s security group allows access from all customer IP addresses. The solutions architect must improve availability, reduce infrastructure management complexity, and minimize disruption for customers — without changing how customers connect. Which solution meets these constraints?
- A company currently uses a load balancer to distribute traffic to EC2 instances in a single Availability Zone. The company wants to re-architect the solution to meet these needs: inbound requests must be filtered for common web vulnerabilities, rejected requests must be forwarded to a third-party auditing application, and all resources must be highly available. Which architecture meets these requirements?
- A company deployed a private REST API in API Gateway that must be accessible only from an application inside a VPC. An EC2 instance in the VPC cannot reach the API. Which solution provides connectivity between the EC2 instance and the private API?
- A company deployed an application that uses Amazon DynamoDB. The operations team measured expected load and provisioned the table's RCUs and WCUs to match the anticipated peak. The workload has a weekly 4-hour peak that is double the average traffic; for the remainder of the week, traffic is near the average. The access pattern is write-heavy (many more writes than reads). You must recommend a cost-minimizing approach that meets these requirements. Which solution should you choose?
- A company deploys applications into multiple VPCs attached to a Transit Gateway. Any VPC that sends internet-bound traffic must route through a shared services VPC. Each VPC subnet uses the default VPC route table pointing to the Transit Gateway; the Transit Gateway uses its default route table for VPC attachments. A security audit shows an EC2 instance in one VPC can communicate with EC2 instances in any other company VPC. Each VPC should only be able to communicate with a specific, limited set of authorized VPCs. What should the solutions architect do to enforce this?
- A company deploys AWS Lambda functions that connect to an Amazon RDS for PostgreSQL database in QA and production environments. Credentials must not be embedded in application code and database passwords must be rotated automatically. Which solution meets these requirements?
- A company develops multiple projects across several AWS accounts under the same AWS Organization. Costs must be allocated to the owning project via a Project tag. The operations team found many EC2 instances missing the Project tag. Which actions should a solutions architect take to find current untagged instances and prevent future instances from being launched without the Project tag? (Choose three.)
- A company enabled VPC Flow Logs for its NAT gateway and observes Action = ACCEPT for inbound traffic from public IP 198.51.100.2 destined for a private EC2 instance. The VPC CIDR's first two octets are 203.0. The solutions architect must determine whether this represents unsolicited inbound traffic from the internet. Which steps should the architect take?
- A company exposes a primary API using Amazon API Gateway and Lambda functions, and some customers also access a legacy API running on a single Amazon EC2 instance. The company wants stronger protection to help prevent DoS attacks, scan for vulnerabilities, and block common exploits. What combination of AWS services should the solutions architect use to meet these security requirements?
- A company has 50 member AWS accounts and wants to use AWS Transit Gateway to connect VPCs across those accounts. When a new member account is created, the company wants to automate creating a new VPC and attaching it to the Transit Gateway. Which combination of actions will achieve this? (Choose two.)
- A company has 60 TB of software images stored on-premises in Europe and wants to move them to an Amazon S3 bucket in the ap-northeast-1 Region. New images are produced daily and must be encrypted in transit. The company wants an automated solution that requires no custom development to transfer both the existing data and future images to S3. What is the next step in the transfer plan?
- A company has a 1 Gbps AWS Direct Connect link between its on-premises data center and AWS and uses BGP. As user demand grows, the company needs a more highly available, fault-tolerant, and secure connectivity solution that is also cost-effective. Which change meets these requirements most cost-effectively?
- A company has a hybrid environment with on-premises servers and EC2 instances in three VPCs located in three different AWS Regions. The company has one AWS Direct Connect connection from the data center to the nearest Region. On-premises servers need access to EC2 instances in all three VPCs and also require access to AWS public services. What is the least-cost combination of steps to meet these requirements? (Choose two.)
- A company has a MongoDB replica set running on-premises accessible over AWS Direct Connect. A solutions architect must migrate the on-premises MongoDB database to Amazon DocumentDB (with MongoDB compatibility). Which migration approach should the architect use?
- A company has a single AWS account. IT support currently uses named IAM users to sign into the AWS Management Console and wants to stop managing separate IAM users while continuing to use their on-premises Active Directory credentials. The solutions architect will implement AWS IAM Identity Center (AWS SSO). Which solution meets the requirement most cost-effectively?
- A company has about 1 million .csv files on a VM on premises totaling 10 TB now and growing by about 1 TB per week. They must back up the data to AWS daily, and apply custom filters to include only specific source directories. A Direct Connect link is available. Which solution provides automated daily backups with the least operational overhead?
- A company has an API deployed in a single Region: API Gateway Regional + Lambda. The API calls an external vendor API, stores data in a DynamoDB global table, and the vendor API key is stored in AWS Secrets Manager encrypted with a customer-managed KMS key. The company wants the API components to run across multiple Regions in an active-active setup. Which set of changes will achieve this with the LEAST operational overhead? (Choose three.)
- A company has an AWS Organization with one account per department. Application teams deploy independently and the company wants to lower compute costs, manage costs across departments, and improve department-level billing visibility, without losing flexibility in selecting compute resources. Which solution meets these needs with minimal effort?
- A company has an on-premises monitoring solution that uses a PostgreSQL database for event persistence, but the database cannot scale for heavy ingestion and runs out of storage. A VPN to AWS is already in place. The solution must use managed AWS services to reduce ops overhead; provide an automatically scaling buffer with no admin; enable near-real-time dashboards; and support semi-structured JSON with dynamic schemas. Which combination of AWS components will satisfy these requirements? (Choose two.)
- A company has built a serverless electronic document management system in the eu-central-1 Region. The web app is delivered via an Amazon CloudFront distribution with an Amazon S3 origin. The app calls Amazon API Gateway Regional endpoints, which invoke AWS Lambda functions that store metadata in an Amazon Aurora Serverless database and place documents into an S3 bucket. The company needs to reduce latency for users outside Europe. Which two actions will improve global latency? (Choose two.)
- A company has hundreds of VPCs across many AWS accounts and wants to connect those accounts to its on-premises network. Site-to-Site VPNs already exist in a single AWS account. The company wants to control which VPCs can talk to which other VPCs with minimal operational effort. Which combination of steps will achieve this? (Choose three.)
- A company has Linux EC2 instances that users access via SSH with EC2 SSH key pairs. Each instance must have a unique EC2 key pair. The company requires an on-demand automatic rotation process that rotates all EC2 key pairs and stores the keys securely encrypted. The company can tolerate under one minute of downtime during rotation. Which solution satisfies these requirements?
- A company has many separate AWS accounts with no centralized billing or management. They use Microsoft Azure Active Directory on-premises and want to centralize AWS billing/management, adopt identity federation instead of manual user provisioning, and use temporary credentials rather than long-lived access keys. Which set of steps will meet these goals? (Choose three.)
- A company has multiple AWS accounts in an AWS Organizations organization. The company needs to centralize storage of AWS account activity and run SQL queries against the activity from a central location. Which solution satisfies these requirements?
- A company has multiple lines of business (LOBs) under a parent. The company requires: a single consolidated AWS invoice for all LOB accounts; invoice detail that breaks out costs per LOB account; the ability to restrict services and features in LOB accounts per governance policy; and each LOB account must have full administrator permissions despite governance restrictions. Which combination of steps should the solutions architect implement to satisfy these requirements? (Choose two.)
- A company has separate AWS accounts for multiple business units. Each business unit manages its own network with several VPCs that use overlapping CIDR ranges. The marketing team built a new internal application and wants it reachable from the other business units using private IP addresses only. Which solution accomplishes this with the LEAST operational overhead?
- A company has several Python AWS Lambda functions deployed as .zip packages and a Lambda layer (also a .zip) with common libraries. The .zip files (functions and layer) are stored in an S3 bucket. The company must automatically scan the Lambda functions and the layer for CVEs. Additionally, a subset of Lambda functions must receive automated code scans for potential data leaks and other vulnerabilities; those code scans must run only for selected functions, not all. Which combination of actions satisfies these requirements? (Choose three.)
- A company hosts a community forum using an ALB fronting Docker containers in Amazon ECS, with data in Amazon RDS for MySQL and container images in ECR. They require a disaster recovery SLA with an RTO ≤ 24 hours and RPO ≤ 8 hours. Which is the MOST cost-effective solution that meets these RTO/RPO targets?
- A company hosts a website with a backend service deployed in a primary AWS Region and a disaster recovery (DR) Region. A single Amazon CloudFront distribution fronts the site. The company created a Route 53 failover record with health checks pointing to the primary Region’s backend and configured that record as an origin for the CloudFront distribution. A secondary failover Route 53 record points to the DR Region backend. Both Route 53 records have a TTL of 60 seconds, but failover currently takes longer than one minute. Which design provides the fastest failover time?
- A company hosts an intranet app on EC2 instances behind an ALB. Currently, users authenticate against an internal database. The company must use an existing AWS Directory Service for Microsoft Active Directory so that all directory users can access the app. Which solution will meet this requirement?
- A company hosts an on-premises Git repository and uses webhooks to trigger logic running in AWS. The webhook code currently runs on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB); the Git server calls the ALB. The company wants to convert this to a serverless architecture with the least operational overhead. Which solution should you recommend?
- A company hosts its application in Amazon EC2 instances in us-east-1. Artists across North America and Europe upload very large, high-resolution images from mobile phones to a centralized Amazon S3 bucket in us-east-1. European users report slow upload performance. How can a solutions architect improve upload performance for users in Europe?
- A company ingests a continuous stream of market data at a constant rate and stores it. A nightly aggregation job runs for about 4 hours to compute statistics; the analysis is noncritical and can be retried on the next run if it fails. The current system uses a pool of 1-year Reserved Instances running constantly to ingest and store data on attached EBS volumes. A scheduled script launches On-Demand EC2 instances nightly to run the aggregation, which access data over NFS from the ingestion servers, and terminates them when work finishes. The Reserved Instance reservations are expiring. The company wants the most cost-effective option. Which solution should the architect recommend?
- A company ingests millions of 1 MB image files per day and analyzes them in 1 GB batches. After analysis, the application zips each batch and archives the zip file to an on-premises NFS server. The company has Hyper-V compute capacity on premises but no additional storage. It wants to archive images on AWS, be able to retrieve archived data within one week, and schedule transfers during non-business hours while enforcing bandwidth limits over a 10 Gbps Direct Connect link. Which cost-effective solution meets these requirements?
- A company introduced a security requirement to inspect all traffic from corporate AWS instances in its VPC for policy violations and to block specific IP addresses. To meet this, the company deployed EC2 instances running approved proxy software in private subnets as transparent proxies, updated subnet route tables to use the proxy instances as the default route, and attached security groups compliant with policy. Despite these changes, traffic from instances in private subnets is not being forwarded to the internet through the proxies. What should a solutions architect do to fix this?
- A company is building a latency-sensitive application. Several Java AWS Lambda functions perform library loading, class initialization, and generation of unique IDs in initialization code outside the handler. The functions must initialize as fast as possible. Which approach is the most cost-effective to meet startup performance requirements?
- A company is building a static-content website on Amazon S3 with Amazon CloudFront. Users must be able to upload and download large files. Company policy requires that all data be encrypted both in transit and at rest. Which combination of actions will satisfy the encryption requirements? (Choose three.)
- A company is building an Amazon Connect contact center and defining a disaster recovery strategy across AWS Regions. The contact center includes dozens of contact flows, hundreds of users, and dozens of claimed phone numbers. Which DR approach yields the LOWEST recovery time objective (RTO)?
- A company is building an on-demand video service using microservices. The service will launch with 5 million users and grow to 30 million users after 6 months. The application is deployed on Amazon ECS using AWS Fargate. ECS services communicate over HTTPS. A solutions architect must implement blue/green deployments, route traffic to each ECS service through a load balancer, and ensure the application automatically scales the number of tasks in response to an Amazon CloudWatch alarm. Which design meets these requirements?
- A company is changing how it patches EC2 instances. Currently instances patch over the internet via a NAT gateway in the application account's VPC. A dedicated private VPC in a core account hosts EC2 instances acting as a patch source repository. The company wants to use Systems Manager Patch Manager and the core account patch repository to patch EC2 instances in the application account, while preventing all instances in the application account from accessing the internet. The instances still need access to Amazon S3 (where application data is stored), Systems Manager, and the patch repository in the core account. Which solution meets these requirements?
- A company is deploying a new web application and needs shared storage for Linux application servers. The dataset is up to 100 GB. Peak activity lasts 3 hours daily and requires 225 MiB/s of read throughput. The solution must be Multi-AZ and replicate a copy of the data to another AWS Region for disaster recovery with an RPO under 1 hour. Which design meets these needs?
- A company is deploying a third-party firewall appliance (from AWS Marketplace) into a shared-services VPC to inspect and protect all outbound internet-bound traffic from the organization’s VPCs. The architect must prioritize reliability and minimize failover time between firewall appliances within the same AWS Region. Routing from the shared-services VPC to other VPCs is already configured. Which of the following steps should the architect recommend? (Choose three.)
- A company is developing a serverless API using API Gateway and Lambda. The Lambda functions share common libraries and custom classes. A solutions architect needs to simplify deployments and maximize code reuse. Which solution satisfies these requirements?
- A company is implementing AWS Organizations to restrict its developers to use only Amazon EC2, Amazon S3, and Amazon DynamoDB. The developers' account is in a dedicated OU. After applying an SCP that lists only those services, IAM users in the developers account can still use services not listed in the SCP. What should the solutions architect do to prevent developers from using services outside the policy scope?
- A company is launching a global online game using Amazon EC2 instances in three Regions: us-east-1, eu-west-1, and ap-southeast-1. Leaderboards, player inventory, and event status must be available across Regions. Any Region should be able to scale to handle the combined load from all Regions, and users must be automatically routed to the Region with the lowest latency. Which design meets these requirements with the LEAST operational overhead?
- A company is migrating a data-processing application to AWS. Currently, users upload media files via a web portal; the web server saves uploads to NAS and sends a message to a processing server via a message queue. Each media file can take up to 1 hour to process. The number of files queued is much higher during business hours and decreases rapidly after hours. What is the MOST cost-effective migration design?
- A company is migrating a legacy application (one app server + one MS SQL Server DB) from VMware VMs on-premises to AWS. Each VM consumes 500 TB across multiple attached volumes. There is a dedicated 10 Gbps AWS Direct Connect to the nearest Region, unused by other services. Which combination of steps will migrate the application with the LEAST downtime? (Choose two.)
- A company is migrating a legacy Windows file server that holds sensitive, irreplaceable data to Amazon FSx for Windows File Server. The data must be copied to another AWS Region for disaster recovery, and compliance requires that data never traverse the public internet. The company prefers managed AWS services where possible. Which design meets these requirements?
- A company is migrating a website consisting of a load balancer, a Linux-based CMS that requires NFS-compatible persistent storage, and a MySQL database. The solution must scale from 2 EC2 instances to 30 instances for unpredictable traffic, require no changes to the CMS, and prevent data loss. Which design meets these requirements?
- A company is migrating a website to a containerized microservices architecture on AWS and has deployed the app to an Amazon ECS cluster. The security policy requires least-privilege network and IAM configurations. After deployment, which steps are required to meet these requirements? (Choose two.)
- A company is migrating an application from an on-premises VMware environment to Amazon EC2 and must preserve the software and configuration settings. What should the solutions architect do to meet these requirements?
- A company is migrating an application to AWS and prefers fully managed services where possible. The application must store large important documents with these requirements: (1) very high durability and availability, (2) encryption at rest and in transit at all times, and (3) the company must manage and periodically rotate the encryption key. Which solution should the solutions architect recommend?
- A company is migrating an on-premises application and MySQL database to AWS. The data is highly sensitive and continuously updated. Data must not traverse the internet, and must be encrypted both in transit and at rest. The database is 5 TB. The target schema exists in an Amazon RDS for MySQL instance. The company has a 1 Gbps AWS Direct Connect with both public and private virtual interfaces configured. Design a migration with minimal downtime that satisfies the security constraints. Which solution meets these requirements?
- A company is migrating an on-premises VMware environment (Linux VMs) to AWS. A solutions architect must produce a diagram that shows network dependencies between servers, including host IP addresses, hostnames, and how the hosts connect to each other. Which approach will collect the required information and generate the dependency diagram?
- A company is migrating applications to AWS and has established a Direct Connect link in a central network account. The company will have hundreds of AWS accounts and VPCs. Corporate on-premises systems must access AWS resources transparently and communicate with all VPCs. The company also wants to route cloud outbound traffic to the internet via the on-premises data center. Which combination of steps satisfies these requirements? (Choose three.)
- A company is migrating applications to AWS but lacks full knowledge of application dependencies. One application has many low-latency dependencies that use a custom IP-based protocol on port 1000. The company has installed the AWS Application Discovery Agent and collected months of data. How should the company identify which servers need to be migrated with the application (the servers that communicate on port 1000) so they can be moved together?
- A company is migrating business-critical applications from an on-premises data center to AWS. The on-premises environment uses a Microsoft SQL Server Always On cluster. The company wants to move to an AWS-managed database service and requires a heterogeneous migration (SQL Server → MySQL). Which approach satisfies these requirements?
- A company is migrating its data center to AWS as quickly as possible. Hundreds of VMware VMs run many applications; each VM uses a shared Windows folder for common files. The share is larger than 100 GB. The compliance team requires a change request for every software installation or modification on each VM. The company has a 10 Gbps AWS Direct Connect link to AWS. Which sequence of steps will complete the migration in the least time?
- A company is migrating its massive multiplayer game's infrastructure to AWS. The leaderboard needs microsecond read latencies and single-digit-millisecond write latencies, the dataset size is single-digit terabytes, and writes must become available within a minute after a primary node failure. Data must also be persisted for later analytics. Which option meets these requirements with the least operational overhead?
- A company is migrating its on‑premises IoT platform to AWS. The platform consists of: a MongoDB cluster storing collected and processed IoT data; an app that uses MQTT to poll devices every 5 minutes; periodic jobs that generate reports (jobs run 120–600 seconds); and a public web application that serves reports. The company wants to reduce operational overhead while maintaining performance. Which combination of steps provides the required solution with the LEAST operational overhead? (Choose three.)
- A company is migrating two simple Node.js applications from on premises to AWS. One app collects sensor data and writes to a MySQL database; the other aggregates data into reports. When aggregation jobs run, some load jobs fail. The migration must resolve the loading failures and occur without disruption or changes visible to customers. What should a solutions architect recommend?
- A company is modernizing an application and migrating it to AWS. Currently, user profile data is stored as text in a single table in an on-premises MySQL database. After modernization, users will upload video files up to 4 GB each, and other users must be able to download those videos. The video storage must scale rapidly and must not degrade application performance. Which solution meets these requirements?
- A company is moving its blog platform to AWS. On‑premises servers connect to AWS over a Site-to-Site VPN. Multiple authors update blog content several times per day; the content is served from a NAS file share. The company must migrate the blog without blocking ongoing content updates. The blog runs on EC2 instances across multiple Availability Zones behind an Application Load Balancer. The company also needs to transfer 200 TB of archival data from on‑premises to Amazon S3 as quickly as possible. Which combination of steps will satisfy these requirements? (Choose two.)
- A company is moving to the cloud and wants to size new Amazon EC2 instances accurately. It needs to gather metrics such as CPU, memory, and disk utilization, obtain an inventory of running processes on each VM, and monitor network connections to map inter-server communications. Which approach will collect this information MOST cost-effectively?
- A company is preparing to migrate many Windows and Linux servers—some physical and some virtual—plus multiple database types to AWS. They lack an accurate inventory and want to rightsize during migration. A solutions architect must collect information about network connectivity and application relationships and produce a migration plan. Which approach will provide the required data and plan?
- A company is refactoring a monolithic application into a modern design on AWS. The CI/CD pipeline must: allow multiple releases per hour, and enable rapid rollbacks. Which deployment design meets these requirements?
- A company is releasing a new 5 GB game package for public download. Currently it serves previous releases from a Linux-based public FTP site in an on-premises datacenter. The company expects global downloads and wants improved download performance and low transfer costs for users worldwide. Which solution best meets these goals?
- A company is setting up a 1 Gbps AWS Direct Connect link from its on-premises network to AWS. The design uses a Direct Connect gateway and a Transit Gateway so multiple VPCs and on-premises resources can communicate. The company must reach VPC resources over a transit virtual interface (transit VIF) on that Direct Connect connection. Which combination of steps will satisfy these requirements? (Choose two.)
- A company is updating an online ordering application hosted on Amazon ECS, using DynamoDB for storage and a public ALB for user access. Attacks against the application have increased. The company must prevent attacks and ensure business continuity with minimal interruptions and be cost-effective. Which combination of steps meets these requirements MOST cost-effectively? (Choose two.)
- A company manages hundreds of AWS accounts in an AWS Organizations organization with all features enabled. The finance team has a daily budget and must receive an email when the organization's AWS costs exceed 80% of that daily budget. Which implementation will track costs and send the required email notification?
- A company manages its infrastructure in a single AWS account. Three engineers administer and develop in that account. Occasionally, one engineer modifies another engineer's EC2 security group and introduces noncompliant security settings. A solutions architect must implement a system that records changes made by engineers and sends alerts when EC2 security group settings become noncompliant. What is the FASTEST way to achieve this?
- A company manages multiple AWS accounts with AWS Organizations. Regulatory rules require that specific member accounts be restricted to a predefined set of AWS Regions where resources can be deployed. Resource tagging must be enforced according to a group standard and managed centrally with minimal configuration. Which approach should a solutions architect use to implement these requirements?
- A company manages multiple AWS accounts with AWS Organizations. Some shared applications run in a VPC in the shared services account. A Transit Gateway is attached to that VPC. A development team needs access from a development account to the shared services applications. The development environment is frequently destroyed and recreated, and the team must be able to recreate its connection to the shared services account as needed. Which design meets these requirements?
- A company manufactures IoT sensors and embeds each sensor with an X.509 certificate, issued by the company's private certificate authority (CA), that contains a unique serial number. Certificates are installed on devices during manufacturing. After sensors are installed in stores, they must be able to send data to AWS, but they must not be able to send data before installation. Which provisioning approach meets these requirements?
- A company migrated a web application to AWS. The architecture uses an Amazon CloudFront distribution that forwards requests to an Application Load Balancer (ALB), and Amazon ECS handles the application processing. A security audit found the application is reachable directly via both the CloudFront domain and the ALB endpoint. The company requires that the application be accessible only through CloudFront. Which solution accomplishes this with the LEAST effort?
- A company migrated an application to AWS. The app runs on two EC2 instances behind an Application Load Balancer (ALB). The MySQL database runs on a separate EC2 instance and is read-heavy. Each EC2 instance stores frequently updated static content on its attached Amazon EBS volume; the static content must be copied to each EBS volume when updated. Load varies throughout the day, and during peak times the application cannot serve all requests. Tracing shows the database cannot handle peak read traffic. Which solution will increase the application's reliability?
- A company migrated to AWS and has AWS Business Support. It wants to monitor cost-effectiveness of Amazon EC2 instances across accounts. Instances are tagged by department, business unit, and environment. Development instances have high cost but low utilization. The company needs to detect and stop underutilized development EC2 instances. An instance is underutilized if it had average daily CPU utilization of 10% or less and network I/O of 5 MB or less for at least 4 of the past 14 days. Which solution achieves this with the LEAST operational overhead?
- A company must aggregate Amazon CloudWatch Logs from multiple AWS accounts into a central logging account. Logs must remain in their Region of origin. The central account will normalize logs and stream them to a security tool. The solution must handle high ingestion volume and scale with diurnal load (heavier in business hours). Using an AWS Control Tower design for multi-account logging, which combination of steps should be implemented? (Choose three.)
- A company must collect 6 TB of proprietary-format experiment data from sensors in a remote location with no internet. Sensors can periodically upload files via FTP, but they cannot act as FTP servers or use other protocols. The company needs to centralize the uploads locally and move the data to AWS object storage as soon as possible after the experiment. Which solution satisfies these constraints?
- A company must design a disaster-recovery (DR) plan for its ecommerce website. The site runs on t3.large EC2 instances in an Auto Scaling group across multiple Availability Zones and uses an Amazon RDS for MySQL DB instance. In a disaster, traffic must fail over to a secondary Region. The target RPO is 30 seconds and the RTO is 10 minutes. Which solution meets these objectives most cost-effectively?
- A company must enable 400 employees to work remotely after an unexpected disaster. Desktops are a mix of Windows and Linux and have multiple installed applications (browsers, mail clients, etc.). The solution must integrate with the on-premises Active Directory so employees use their existing credentials, require multifactor authentication (MFA), and replicate the current desktop experience. Which approach satisfies these requirements?
- A company must implement disaster recovery for a critical app that currently runs in a single AWS Region. The web frontend uses EC2 instances behind an Application Load Balancer (ALB). The app writes to an Amazon RDS for MySQL DB instance and outputs processed documents to an Amazon S3 bucket. The finance team runs direct queries against the database to produce reports; during peak times these queries consume DB resources and degrade application performance. Design a disaster-recovery solution that minimizes data loss and eliminates the performance impact of the finance team's queries. Which solution satisfies these requirements?
- A company must migrate 60 on-premises legacy Windows applications built on the .NET Framework to AWS. The company wants to minimize migration time, avoid any application code changes, and not manage underlying infrastructure. Which migration approach meets these requirements?
- A company must migrate a three-tier .NET web application (which depends on MySQL) from on-premises to AWS to handle 200,000 daily users and provide scalability and high availability. Which design steps should the solutions architect take to meet these requirements?
- A company must migrate an Amazon RDS for Oracle database to an RDS for PostgreSQL instance in a different AWS account with zero downtime and minimal migration cutover time. The migration must replicate all existing data and any new data created during migration, and the target must be identical to the source at completion. Applications use a Route 53 CNAME for the RDS for Oracle endpoint. The source DB is in a private subnet. Which combination of steps should the solutions architect take? (Choose three.)
- A company must migrate its customer transactions database from on-premises to AWS. The current database is Oracle on a Linux server. A new security requirement mandates rotating the database password annually. Which solution meets the requirements with the LEAST operational overhead?
- A company must migrate its on‑premises databases to Amazon RDS. The environment contains Microsoft SQL Server, MySQL, and Oracle databases, and some databases include custom schemas and stored procedures. Which combination of actions should the company take to perform the migration? (Choose two.)
- A company must move some on-premises Oracle databases to AWS but keep others on premises for compliance. The on-premises databases include spatial data and run cron jobs for maintenance. From AWS, the company needs to connect directly to on-premises systems and query on-premises data as foreign tables. Which architecture meets these requirements?
- A company must retain all data in a single Amazon S3 bucket for 1 year. The security team is concerned that leaked long-term credentials could allow an attacker to access the AWS account and tamper with or delete objects. Which solution will ensure both existing and future objects in the bucket are protected for the required retention period?
- A company needs a multi-account AWS environment that enforces a consistent baseline for management and security while allowing account-level flexibility for different compliance needs. The environment must integrate with the existing on-premises AD FS for federation and minimize operational overhead. Which approach meets these requirements with the LEAST operational overhead?
- A company needs a one-time migration of an on-premises 60 TB MySQL database to Amazon Aurora MySQL in us-east-1. The current internet connection is low bandwidth and transferring the data over the internet would take about one month. The company needs the fastest possible migration. Which option will migrate the database in the least amount of time?
- A company needs a solution to manage AWS WAF rules across multiple AWS accounts organized in different OUs. Administrators must be able to add or remove accounts or OUs from managed WAF rule sets and automatically update/remediate noncompliant WAF rules across all accounts with minimal operational overhead. Which solution meets these requirements?
- A company needs an AWS Transfer Family SFTP server that delivers PGP-encrypted files from a third-party supplier into an Amazon S3 bucket. The files must be automatically decrypted after being received. The solutions architect created an IAM role with a policy granting access to AWS Secrets Manager and the S3 bucket. The role’s trust policy allows the transfer.amazonaws.com service to assume the role. To complete an automated decryption workflow using a Transfer Family managed workflow, what should the solutions architect do next?
- A company needs AWS-based disaster recovery for hundreds of Windows servers that all mount a shared file share. Requirements: RTO 15 minutes, RPO 5 minutes, support native failover and fallback, and be as cost-effective as possible. Which solution best meets these requirements?
- A company needs to back up on-premises NFS file storage to Amazon S3 and retain archives after 5 days. They can accept a multi-day retrieval time for archived data. Which solution is the MOST cost-effective while providing NFS compatibility?
- A company needs to count unique users per client (daily, weekly, monthly) for an application that already writes all logs, including successful logins, to CloudWatch Logs via the CloudWatch agent. They want to introduce this licensing metric with the least changes to the application. Which approach accomplishes this?
- A company needs to migrate an Amazon Aurora MySQL DB cluster from one AWS account to a new AWS account in the same Region. Both accounts are in the same AWS Organization. The company wants to minimize database service interruption before switching DNS to the new database. Which migration strategies meet this requirement? (Choose two.)
- A company needs to migrate an on-premises SFTP service (currently running on a Linux VM) to AWS. Uploaded files are made available to downstream applications via an NFS share. The migration must provide high availability and present external vendors with a stable set of static public IP addresses that the vendors can allow. The company already has an AWS Direct Connect link between its data center and its VPC. Which solution meets these requirements with the least operational overhead?
- A company needs to migrate an on-premises VMware cluster of 120 VMs (multiple OS types and many custom-installed packages) to AWS. The on-premises environment also includes a 10 TB NFS server. A 10 Gbps AWS Direct Connect link is available for the migration. Which approach will complete the migration to AWS in the LEAST amount of time?
- A company needs to optimize costs for an AWS environment that uses multiple accounts under AWS Organizations. Three years ago the company bought EC2 Standard Reserved Instances that recently expired. The company expects to need EC2 compute for another 3 years and has also deployed a new serverless workload. Which purchasing strategy gives the MOST cost savings?
- A company needs to send data from on-premises systems privately (without traversing the internet) to Amazon S3 buckets that exist in three different AWS accounts. The company has no existing dedicated connectivity to AWS. Which combination of steps should a solutions architect recommend? (Choose two.)
- A company needs to store and process images uploaded from a mobile app. Usage peaks weekdays 8 AM–5 PM with thousands of uploads per minute; otherwise the app is rarely used. Users must be notified when processing completes. Which combination of actions should a solutions architect take to enable scalable image processing? (Choose three.)
- A company operates a centralized EC2 application in a shared VPC. Client applications in up to 10 business-unit VPCs must access the centralized application, which is fronted by a Network Load Balancer (NLB). Some business-unit VPC CIDR blocks overlap with the shared VPC and some overlap with each other. Only authorized business-unit VPCs should be allowed to reach the centralized application. Which network design provides the required connectivity from the business-unit VPCs to the centralized application?
- A company operates a static content distribution platform serving customers around the world. Customers consume content from their own AWS accounts. The content is hosted in an Amazon S3 bucket. The company uploads content from on-premises to S3 using an S3 File Gateway. The company wants to improve performance and reliability by serving content from the AWS Region geographically closest to each customer. On-premises data must be routed to Amazon S3 with minimal latency and without using the public internet. Which combination of steps achieves these goals with the least operational overhead? (Choose two.)
- A company operates a web application on a single EC2 instance that becomes slow at peak times when CPU utilization exceeds 95%. A user-data script installs custom packages on the instance at launch, which makes instance startup take several minutes. The company will create an Auto Scaling group using a launch template, with mixed instance types, varying CPU capacities, and a maximum capacity limit. The company wants to reduce application latency when new instances are launched during scaling events. Which approach satisfies this requirement?
- A company operates an IoT solution with millions of home sensors in the United States. Sensors use MQTT to send data to a custom MQTT broker on a single EC2 instance. Sensors connect to the broker at iot.example.com (Route 53). The broker writes data to DynamoDB. The broker has been overloaded multiple times, causing data loss. Which solution will improve reliability and meet the requirements?
- A company operates in a manually created VPC while using AWS CloudFormation to provision other resources. A new mandate requires all infrastructure to be managed automatically. What is the lowest-effort approach to bring the existing manually created VPC under automated management?
- A company plans a global image service where up to 10,000 users worldwide may upload images at peak. Each uploaded image must have text overlaid and then be published to the website. Which architecture should the solutions architect implement to handle uploads and processing at scale?
- A company plans to migrate 1,000 VMware virtual machines to AWS. As part of planning, they want to collect server-level metrics (CPU details, RAM usage, OS information, running processes) from on-premises hosts, then query and analyze that data. Which solution satisfies these requirements?
- A company plans to migrate 20 infrequently used but business-critical applications (a mix of Java and Node.js) to AWS. The company wants to minimize cost and standardize on a single deployment approach. Most apps run as part of month-end processing with few concurrent users, but they can run at other times. Typical memory use is under 1 GB, with some peaks up to 2.5 GB. One critical Java billing-report application accesses multiple data sources and can run for several hours. What is the MOST cost-effective deployment strategy?
- A company plans to migrate a legacy on‑premises Java web application to AWS. The app runs on Apache Tomcat and uses PostgreSQL. The company cannot modify the source code but can deploy the JAR files. Traffic spikes at the end of each month. Which solution meets these needs with the LEAST operational overhead?
- A company plans to migrate its container-based website to AWS. The site uses microservices deployed on an on-premises, self-managed Kubernetes cluster. All Kubernetes manifests are stored in source control. The website data is in a PostgreSQL database. An open-source container image registry runs alongside the on-premises environment. Which AWS architecture will require the LEAST effort to migrate while preserving these details?
- A company plans to migrate many on-premises applications (Linux and Windows) to AWS. They have physical machines and VMs and need to capture system configuration, performance metrics, running processes, and network connections; group on-premises applications into migration sets; and receive recommended EC2 instance types and costs for running workloads on AWS. Which combination of steps should the solutions architect take? (Choose three.)
- A company plans to migrate many Windows virtual machines from its on-premises data center to AWS. They have validated a few sample workloads and have established an AWS Site-to-Site VPN to a VPC. Simple Network Management Protocol (SNMP) is enabled on each VM. They cannot add more VMs on-premises or install additional software on the existing VMs. Discovery must be imported automatically into AWS Migration Hub so a total cost of ownership (TCO) report can be generated for the entire migration. Which solution satisfies these constraints?
- A company plans to migrate thousands of on-premises servers (Linux and Windows), SAN storage, Java and PHP apps (MySQL), and Oracle databases to AWS. The environment includes many dependent services, and existing documentation is incomplete and out of date. A solutions architect must discover the current environment, understand network and application dependencies, and estimate post-migration cloud costs. Which tools or services should the architect use to plan the migration? (Choose three.)
- A company plans to migrate thousands of VMs from a VMware ESXi environment to AWS. The company lacks a configuration management database and has limited visibility into VM utilization. A solutions architect must deliver an accurate inventory for migration planning with the least operational overhead. Which approach meets this requirement?
- A company plans to replace desktop PCs with Amazon WorkSpaces accessed via thin clients. The desktops access applications that handle clinical-trial data, and corporate policy requires that application access be restricted to the company branch office locations only. The company anticipates adding another branch office within 6 months. Which solution meets these requirements with the MOST operational efficiency?
- A company policy permits engineers to provision only approved resources and mandates using AWS CloudFormation to create those resources. You must enforce this restriction for the IAM role that engineers assume. What should you do to implement enforcement?
- A company provisioned a multi-account AWS environment using AWS Control Tower. The security team will deploy both preventive and detective controls across all accounts and needs a centralized view of the security posture for every account. Which solution provides a centralized security view and meets these requirements?
- A company publishes a Regional API (API Gateway Regional endpoint) that should be used by six U.S.-based partners who each call the API once per day to submit sales figures. After deployment, the API is receiving 1,000 requests per second from 500 different IP addresses worldwide, likely from a botnet. The company wants to protect the API while keeping costs low. Which approach best secures the API?
- A company receives a continuous stream of JSON-formatted environmental sensor data and needs a real-time AWS solution that stores the data in a schema-flexible (no fixed schema) database. Which architecture meets these requirements?
- A company requires all internal application connectivity to use private IP addresses. The solutions architect created interface VPC endpoints to connect to AWS public services, but DNS names are resolving to public IP addresses and internal services cannot reach the interface endpoints. What should the solutions architect do to fix this?
- A company requires that all Windows EC2 instances be joined to an Active Directory domain hosted on AWS, and it wants to enforce enhanced security (for example, MFA) using managed AWS services where possible. Which solution meets these requirements?
- A company runs a 3-year project with an application that uses 20 Amazon EC2 On-Demand instances registered to a Network Load Balancer target group across two Availability Zones. The application is stateless and runs 24/7. Normal CPU utilization is about 10%, but CPU rises to 100% during brief busy periods lasting a few hours. Users report slow responses. Which new architecture will resolve the slow-response problem MOST cost-effectively?
- A company runs a blog application using Amazon API Gateway, Amazon DynamoDB, and AWS Lambda. The REST API has these endpoints: GET /posts/{postId}, GET /users/{userId}, and GET /comments/{commentId}. Users are actively discussing topics in comments, and the company wants comments to appear in real time to boost engagement. Which design will reduce comment latency and improve the user experience?
- A company runs a critical app using Amazon RDS for MySQL in Multi-AZ. A recent RDS failover test caused a 40-second application outage. A solutions architect needs to reduce outage time to under 20 seconds. Which combination of steps will achieve this? (Choose three.)
- A company runs a heavily used web application on-premises where users upload media files to a file server. The application server is overutilized and uploads sometimes fail; the company frequently expands storage on the file server. They plan to migrate to AWS, want authenticated access for users across the US and Canada, will consider refactoring, and want to speed development with the least operational overhead. Which solution best meets these requirements?
- A company runs a large containerized workload with about 100 services on Amazon ECS. Developers have started running tasks on AWS Fargate instead of EC2. Historically the account has nearly reached its maximum number of EC2 instances. The company is concerned about hitting the maximum number of ECS tasks for Fargate and wants to notify the dev team when Fargate usage reaches 80% of the service quota. What should a solutions architect implement?
- A company runs a microservice as an AWS Lambda function. The microservice writes to an on-premises SQL database that supports only a limited number of concurrent connections. When Lambda invocation volume increases, the database is overwhelmed and crashes, causing downtime. The company has an AWS Direct Connect link between the VPC and the on-premises datacenter. The company wants to protect the database from being overwhelmed. Which solution satisfies these requirements?
- A company runs a production web application that includes an Amazon API Gateway HTTP API which invokes an AWS Lambda function. The Lambda function processes requests and stores data in a database. The company wants integrated user authorization and already uses a third-party identity provider that issues OAuth tokens for other applications. Which solution meets these authorization requirements?
- A company runs a proprietary stateless Linux binary (source code not available) on an EC2 instance. The app is single-threaded, requires 2 GB of RAM, is CPU intensive, and executes roughly every 4 hours for up to 20 minutes. You need to redesign the architecture to meet these requirements. Which approach should you choose?
- A company runs a three‑tier web app on‑premises: Apache frontend, monolithic Java middle tier, and PostgreSQL storage. A recent promotion overloaded all tiers, the app crashed, and the database hit read capacity limits. Several promotions are planned. You must design a migration to AWS that maximizes scalability and minimizes operational effort. Which three steps accomplish this? (Choose three.)
- A company runs a time-sensitive transaction-processing application in Docker containers on VMs. The containers use shared storage for transaction data. Transaction volume is unpredictable. The company cannot modify the application or continue managing the container host VMs. They need low-latency storage that automatically scales throughput as demand rises and must stop administering the Docker hosting environment. How should they migrate to AWS?
- A company runs a web-front-end application on three Linux VMs behind an HTTP request–based load balancer in its on-premises data center. The application needs file storage for critical data. The company must migrate the app to AWS as quickly as possible and keep the AWS architecture highly available while making the FEWEST changes to the existing architecture. Which migration option satisfies these requirements with minimal architectural changes?
- A company runs a Windows Server application on VMware vSphere on premises. The application reads data in a proprietary format that the application itself must interpret. Servers are manually provisioned. As part of the disaster recovery (DR) plan, the company wants to be able to run the application temporarily on AWS if the on-premises environment fails, and then return the application to on-premises after recovery. The recovery point objective (RPO) is 5 minutes. Which solution provides DR capability on AWS with the LEAST operational overhead?
- A company runs an Amazon Aurora PostgreSQL DB cluster in a single AWS Region. The database team must capture and monitor all data activity across the databases. Which solution will accomplish this requirement?
- A company runs an Amazon EKS cluster (with an AWS managed node group) and stores container images in Amazon ECR. Security policy requires continuous vulnerability scanning of all AWS resources. Which option meets this requirement with the least operational overhead?
- A company runs an application on 20 persistent Linux EC2 instances that store data on multiple attached EBS volumes. The company must keep backups in a separate AWS Region and be able to recover instances and configurations within 1 business day, losing no more than one day of data. The company has limited staff and already has a CloudFormation template that can deploy the required network in the secondary Region. Which backup and recovery solution meets these requirements while minimizing operational overhead and cost?
- A company runs an application on EC2 and Lambda that stores temporary objects in Amazon S3; objects are deleted after 24 hours. The company deploys new application versions by creating CloudFormation stacks for the required resources and deletes the old stack after validation. Recently deletion of an old development stack failed. A solutions architect must resolve the deletion failure without major architectural changes. Which solution meets this requirement?
- A company runs an application on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). On startup, instances run user-data scripts to download critical application content from an S3 bucket. Instances launch but, after some time, are terminated with the message: “An instance was taken out of service in response to an ELB system health check failure.” Auto Scaling repeatedly launches and terminates instances in a loop. The only recent change was adding a large amount of critical content to the S3 bucket. The company does not want to modify user-data scripts in production. What should a solutions architect do so the production environment can deploy successfully?
- A company runs an ecommerce static website hosted on Amazon S3 with CloudFront. API Gateway invokes Lambda functions for user requests and order processing. Lambda functions store data in an Amazon RDS for MySQL cluster that currently uses On-Demand instances. DB usage has been consistent for 12 months. Recently the site experienced SQL injection and web exploit attempts. Customers report order processing latency increases during traffic peaks, and Lambdas often have cold starts. As the company grows, it needs scalable, low-latency performance during traffic peaks, lower database costs, and protection from SQL injection and web exploits. Which solution meets these needs?
- A company runs an event-ticketing platform on AWS and wants to lower costs. The platform uses Amazon EKS on Amazon EC2 for most workloads and an Amazon RDS for MySQL DB instance. New features will run on Amazon EKS with AWS Fargate. The workload has infrequent, date-driven demand spikes. Which approach is the MOST cost-effective for this environment?
- A company runs an on-premises intranet application and will use AWS Elastic Disaster Recovery to back it up to AWS. Replication traffic must not traverse the public internet, the application must not be accessible from the internet after recovery, and replication should not consume all available network bandwidth. Which combination of steps will meet these requirements? (Choose three.)
- A company runs applications across hundreds of production AWS accounts in an AWS Organization and uses AWS Backup centrally. They want all backups to remain resilient even if privileged credentials in any production account are compromised. Which combination of measures will meet this requirement? (Choose three.)
- A company runs applications for several business units across multiple AWS accounts within an AWS Organization. Every cloud resource already has a tag named BusinessUnit with the appropriate business unit value. The company needs to allocate and visualize cloud costs by business unit. Which solution satisfies these requirements?
- A company runs custom network-analysis software to inspect traffic entering and leaving a VPC. The software is deployed with an AWS CloudFormation template onto three Amazon EC2 instances that are managed by an Auto Scaling group. Network routing is configured so traffic is directed to the EC2 instances. When the analysis software stops working, the Auto Scaling group replaces the failed instance, but the network routes are not updated to reference the replacement instance. Which combination of actions will solve this problem? (Choose three.)
- A company runs development, testing, and production environments 24/7 in eu-west-1 using stateful EC2 instances and Amazon RDS for MySQL. Databases are 500–800 GB. Development and testing teams work business hours on business days; production runs continuously. All resources have an environment tag (development, testing, or production). The company wants to lower costs with the least operational effort. What should a solutions architect implement?
- A company runs EC2 instances with a stable, continuous load and Lambda functions with variable, unpredictable load. The application uses an Amazon MemoryDB for Redis cluster as a cache. To minimize monthly cost overall, which purchasing strategy should the company adopt?
- A company runs Grafana on a single Amazon EC2 instance to visualize and monitor AWS workloads. The company has invested effort building dashboards and needs them to be highly available with downtime no longer than 10 minutes. The company also wants to minimize ongoing maintenance. Which solution meets these requirements with the LEAST operational overhead?
- A company runs its core business logic on a fleet of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). Route 53 record api.example.com points to the ALB. The development team must deploy a major update to the business logic such that during a testing window only 10% of customers receive the new version, and each customer must consistently use the same version for the duration of the testing window. How should the company deploy the update to satisfy these requirements?
- A company runs its ecommerce site in a single AWS Region. The stack includes EC2 instances behind an ALB, a DynamoDB table, a Route 53 custom domain name pointing to the ALB, and an ACM certificate attached to the ALB. There is no CDN in use. The company wants to replicate the full application stack in a second Region for disaster recovery, future growth, and improved user latency, while minimizing administrative overhead. Which combination of actions should the solutions architect take? (Choose three.)
- A company runs large batch-processing simulation jobs on data stored in an S3 bucket. The jobs are fault-tolerant (can be interrupted) and outputs are stored in a separate S3 bucket. Each job processes 15–20 GB of input data. Which architecture will meet the requirements most cost-effectively?
- A company runs many services in its on-premises data center that is connected to AWS using AWS Direct Connect (DX) and an IPsec VPN. The service data is sensitive and cannot traverse the public internet. The company wants to offer these services to other companies that are running in AWS. Which solution will allow other AWS customers to connect to the on-premises services without using the internet?
- A company runs microservices on EC2 instances in multiple Availability Zones behind an ALB. A new REST API was built in Amazon API Gateway. Some legacy microservices running on EC2 need to call the new API, but the company requires that the API not be exposed to the public internet and that traffic not traverse the public internet. What should a solutions architect do to satisfy these constraints?
- A company runs nightly automated model retraining using AWS Step Functions. The workflow uses multiple Lambda tasks; any task failure causes the entire workflow to fail. Retraining has failed several nights without notifications. The solutions architect must ensure notifications are sent for all retraining failures. Which combination of steps should be implemented? (Choose three.)
- A company runs online contests via a mobile app on AWS, selecting a random winner at contest end. Contest durations vary and no contest data must be retained after a contest ends. Currently the company uses custom code on Amazon EC2 instances behind an Application Load Balancer, storing contest entries in Amazon RDS. The company wants a new architecture that reduces contest costs. Which solution is the most cost-effective while meeting the requirements?
- A company runs over 20 applications in a single VPC using EC2, ECS, and RDS. Three engineering teams each own multiple applications, and resources are tagged for application and team. The company uses IAM for daily access. The finance team needs to identify monthly AWS costs per application and per team, produce 12-month historical comparison reports, and forecast costs for the next 12 months. Which combination of actions will provide these cost reports? (Choose three.)
- A company runs proprietary ETL and aggregation logic, stores results in Amazon Redshift, and sells the resulting data to customers. Previously the company exported files from Redshift and sent them to customers via FTP. The company will use AWS Data Exchange to distribute the data and must verify customer identities before sharing. Customers also need access to the most recent published data. Which solution meets these needs with the LEAST operational overhead?
- A company runs workloads across many AWS accounts managed via AWS Organizations. Workloads include Amazon EC2, AWS Fargate, and AWS Lambda, and demand varies unpredictably across accounts. The solutions architect computed a 6-month average usage per account to estimate future usage. Which purchase option will yield the MOST cost savings for the organization's compute usage over the next 3 years?
- A company sends application logs to an Amazon OpenSearch Service cluster deployed inside a VPC. All data must remain inside the VPC. Developers need to access OpenSearch from their local developer machines: some work from home, others from three company office locations. Which solution allows secure direct access from developers' local machines to the OpenSearch cluster in the VPC?
- A company sends AWS WAF logs to Amazon S3 through Amazon Kinesis Data Firehose. An Amazon Athena query runs once per day to retrieve the previous 24 hours of WAF logs. Although daily log volume is stable, the query is taking progressively longer over time. You need to prevent query runtime from continuing to increase while minimizing operational overhead. Which solution meets these requirements?
- A company stores container images in Amazon Elastic Container Registry (Amazon ECR). Each new image version receives a unique tag. The company needs an automated process that scans newly pushed images for common vulnerabilities and exposures (CVEs), automatically deletes image tags that have Critical or High severity findings, and notifies the development team when such deletions occur. Which solution satisfies these requirements?
- A company stores data in multiple DynamoDB tables and needs a serverless, automatically scaling HTTPS API to expose that data publicly. Which solutions meet the requirements? (Choose two.)
- A company stores data on-premises on a Windows file server and generates 5 GB of new data daily. Part of its Windows workload has migrated to AWS and that data must be available on a cloud file system. The company already has an AWS Direct Connect link between on-premises and AWS. Which migration approach should the company use?
- A company stores documents in an Amazon EFS file system that is encrypted with a KMS key. The file system is mounted to an EC2 instance running proprietary software. AWS Backup automatic backups are enabled using the AWS Backup default backup plan. The company must be able to recover deleted documents within an RPO of 100 minutes. Which approach will satisfy this requirement?
- A company stores files and images in S3 across multiple storage classes and has seen a large increase in S3 costs over the past year. A solutions architect must review the past 12 months of data access trends and determine the proper storage class for objects. Which solution provides the required trend analysis?
- A company stores IoT data in an Amazon S3 data lake. Data scientists run analytics on EC2 instances in public subnets of a VPC in a different AWS account; these EC2 instances already have an IAM role permitting S3 access. Company policy requires only authorized networks may access IoT data. Which combination of steps should a solutions architect implement to meet these requirements? (Choose two.)
- A company stores millions of frequently accessed objects in Amazon S3 Standard with server-side encryption using AWS KMS (SSE-KMS). As access grows, KMS costs on the monthly bill are rising due to the high request volume. The solutions architect needs to reduce costs with minimal application changes and the least operational overhead. Which solution should be used?
- A company stores sensitive data in an Amazon S3 bucket. The security team must log all object-level activity for that bucket and retain the logs for 5 years. The security team also must receive an email notification whenever there is an attempt to delete data in the bucket. Which combination of steps meets these requirements most cost-effectively? (Choose three.)
- A company stores user-uploaded videos in an S3 bucket using S3 Standard. Videos are frequently accessed during the first 180 days after upload and rarely after 180 days. Videos are accessed by named and anonymous users. Most videos exceed 100 MB. Uploads often fail due to poor connectivity, so multipart uploads are used. A solutions architect must optimize S3 costs. Which combination of actions will meet these requirements? (Choose two.)
- A company streams IoT sensor data about city traffic into Amazon Kinesis Data Streams. Multiple applications consume from the stream, but several consumers are being throttled and receive ReadProvisionedThroughputExceeded errors. Which actions should the solutions architect take to resolve the throttling? (Choose three.)
- A company takes daily automated Amazon RDS snapshots and retains them for 7 days. They need snapshots every 6 hours retained for 30 days, want centralized monitoring across AWS Organization accounts, and prefer minimal operational overhead. Which solution meets these requirements with the LEAST operational overhead?
- A company that runs seasonal job boards is experiencing increased traffic. The backend consists of two Amazon EC2 instances behind an Application Load Balancer, and Amazon DynamoDB is used as the datastore. During peak seasons, application read and write performance degrades. Which option yields a scalable architecture that can handle peak loads with the LEAST development effort?
- A company used IaC to create two EC2 instances that have remained unchanged for years. Rapid business growth caused the operations team to introduce an Auto Scaling group, which replaces instances during spikes. Company policy requires monthly OS security updates that sometimes require a reboot. After a recent patch that required reboot, the Auto Scaling group terminated the patched instances and launched new, unpatched instances. Which combination of actions should the solutions architect recommend to prevent this from happening again? (Choose two.)
- A company uses Amazon OpenSearch Service to analyze data. It loads data into an OpenSearch cluster with 10 data nodes from an S3 bucket that uses S3 Standard. The data remains in the cluster for one month for read-only analysis, after which the index is deleted. For compliance, the company must retain a copy of all input data. The company wants to reduce ongoing costs. Which solution meets the requirements most cost-effectively?
- A company uses AWS CloudFormation for deployments and stores application binaries and templates in versioned Amazon S3 buckets. Developers use an EC2 instance as an IDE, pulling binaries from S3, modifying them, running local unit tests, and uploading results back to S3. The team wants to implement CI/CD with AWS CodePipeline and has these requirements: use AWS CodeCommit for source control; automate unit tests and security scans; notify developers when unit tests fail; enable runtime feature toggles and dynamic deployment customization; require lead-developer approval before deployment. Which solution meets these requirements?
- A company uses AWS CloudFormation to provision infrastructure in member accounts. Resources rarely change and are sized correctly. Occasionally developers create test resources and forget to delete them; most test resources remain for a few days. The company wants to automate discovery of unused resources and detect when AWS costs are increasing. The solution must identify resources that cause cost increases and automatically notify the operations team. Which approach meets these requirements?
- A company uses AWS CodeCommit and needs to keep a backup copy of the repository data in a second AWS Region. Which approach satisfies this requirement?
- A company uses AWS CodePipeline to deploy an application to an Amazon EC2 Auto Scaling group. All resources are defined in CloudFormation templates. Application artifacts are stored in Amazon S3 and deployed using instance user data scripts. As the application grew, recent changes to CloudFormation templates caused unexpected downtime. How should the solutions architect improve the CI/CD pipeline to reduce the chance that template changes cause outages?
- A company uses AWS Control Tower with AWS Organizations and wants to restrict development accounts (organized in a specific OU) so that they can only launch burstable EC2 and RDS instance types and cannot use unrelated services. Developers have many individual development accounts. Which approach should a solutions architect recommend to enforce these restrictions?
- A company uses AWS Lambda functions that must connect to a Microsoft SQL Server DB instance on Amazon RDS. There are separate development and production environments; developers may access development credentials, but production credentials must be encrypted using a key that only members of the IT security team's IAM group can use. The key must be rotated regularly. What should a solutions architect implement in the production environment to satisfy these requirements?
- A company uses AWS Organizations and allows developers to request accounts for experimentation using their company email. The company wants to prevent developers from launching costly services or running services unnecessarily and must give each developer a fixed monthly budget. Which combination of steps will meet these requirements? (Choose three.)
- A company uses AWS Organizations and Control Tower for governance and a Transit Gateway for multi-account VPC connectivity. The application team deployed a web app (Lambda + RDS) in an application account. DBAs in a separate DBA account centrally manage databases and use an EC2 instance in the DBA account to access an RDS instance in the application account. The application team stores DB credentials in AWS Secrets Manager in the application account and currently shares secrets manually with the DBAs. Secrets are encrypted with the default AWS-managed Secrets Manager key in the application account. Design a solution that gives the DBAs access to the database without manual secret sharing.
- A company uses AWS Organizations and deployed a landing zone with AWS Control Tower. The company needs governance so that Amazon RDS DB instances that are not encrypted at rest in the production OU are detected. Which solution satisfies this requirement?
- A company uses AWS Organizations and needs a consolidated list of all EC2 instances across accounts that show underutilized CPU or memory, along with recommendations for downsizing those instances. Which solution achieves this with the LEAST effort?
- A company uses AWS Organizations and requires creating an Amazon SNS topic in every member account for integration with a third-party alerting system. The solutions architect used a CloudFormation template and plans to deploy it with CloudFormation StackSets. Trusted access for CloudFormation StackSets in Organizations has been enabled. What steps should the solutions architect take to deploy the StackSet across all AWS accounts?
- A company uses AWS Organizations with three organizational units (OUs). Each OU contains over 100 accounts. Every account has a single VPC in the same Region per OU, and none of the VPC CIDR ranges overlap. The requirement is that VPCs within the same OU can communicate with each other, but VPCs in different OUs cannot. Which solution accomplishes this with the LEAST operational overhead?
- A company uses AWS Organizations. Each development team has its own AWS account, each with a single VPC and nonoverlapping CIDR blocks. An Amazon Aurora DB cluster resides in a shared services account, and all development teams must access live data from that cluster. Which solution provides the required connectivity to the DB cluster with the least operational overhead?
- A company uses CloudFormation to deploy infrastructure and is concerned that deleting a production stack could also delete important data in Amazon RDS databases or Amazon EBS volumes. How can the company prevent accidental deletion of those data resources when a stack is deleted?
- A company uses CloudFront for a global web application. Over time performance has degraded and the CloudFront cache hit ratio has steadily declined. Metrics show that some URLs include query strings whose parameters are inconsistently ordered and sometimes use mixed-case letters versus lowercase, reducing cache hits. What actions should a solutions architect take to increase cache hit ratio as quickly as possible?
- A company uses multiple AWS accounts for production and non-production workloads across DevOps teams. They want to centrally restrict access to a small set of AWS services that DevOps teams do not use, while allowing access to services currently in use. They already invited all accounts into AWS Organizations. They also want to administer groups of accounts together. Which combination of actions should a solutions architect take? (Choose three.)
- A company using AWS Organizations (all features enabled) has separate accounts per business unit. Administrators in each account must use Amazon Athena to view detailed cost and usage data for only their own account. IAM permissions to configure Cost and Usage Reports are available, and a centralized Cost and Usage Report for the entire organization is already delivered to an S3 bucket. Which approach provides the required per-account access with the least operational complexity?
- A company validated Amazon WorkSpaces in a proof of concept and now requires high availability across two AWS Regions. WorkSpaces is deployed in a failover Region and a hosted zone exists in Amazon Route 53. What should the solutions architect configure to enable high availability for WorkSpaces across the two Regions?
- A company wants a multi-account AWS structure with centralized access and private-network traffic. MFA is required at login, and specific roles map to user groups. Separate accounts required: development, staging, production, and shared-network. Production and shared-network must have connectivity to all accounts. Development and staging must only have access to each other. Which combination of steps should a solutions architect take to meet these requirements? (Choose three.)
- A company wants a single S3 bucket for data scientists to store work documents. Users authenticate via AWS IAM Identity Center, and the data scientists are in a specific Identity Center group. The company needs each scientist to access only their own documents and requires monthly reports showing which documents each user accessed. Which combination of steps satisfies these requirements? (Choose two.)
- A company wants to change how internal cloud costs are reported to each business unit. The company uses AWS Organizations with a separate account per business unit and currently enforces tagging (application, environment, owner). They need a centralized, cost-effective solution that sends monthly cost reports to each business unit and notifies them when spending exceeds thresholds. What is the most cost-effective solution?
- A company wants to deploy AWS WAF web ACLs to improve application security for an app behind an Application Load Balancer. The web ACLs must not block legitimate traffic. What is the recommended way for the solutions architect to configure the web ACL rules to avoid impacting valid users?
- A company wants to let employees work from home by connecting via VPN to access internal applications hosted in VPCs across multiple AWS accounts. Currently on-premises office users access these apps over a Site-to-Site VPN and VPC peering from the main account to other accounts' VPCs. For a scalable and cost-effective AWS Client VPN solution for remote employees, what should the solutions architect do?
- A company will containerize a multi-tier web application (web, application, database) and migrate it from an on-premises data center to AWS. The solution must be fault tolerant and scalable. Some frequently accessed data must always be available across application servers. Frontend web servers require session persistence and must scale for traffic spikes. Which option meets these requirements while minimizing ongoing operational overhead?
- A company will deploy a distributed in-memory database across EC2 instances: one primary node and eight worker nodes. The primary node handles cluster health, accepts client requests, distributes work to worker nodes, and aggregates responses. Worker nodes replicate data partitions among themselves. The application requires the lowest possible network latency for maximum performance. Which placement and instance choice is best?
- A company will deploy an Amazon EKS cluster for a workload that will create an unpredictable number of stateless pods, often many at once during rapid replica scaling. How should the cluster be configured to MAXIMIZE node resilience?
- A company will host a web application on EC2 instances and must load-balance traffic across instances. A security requirement mandates end-to-end encryption between the client and the web servers (TLS from client through the load balancer to the instances). Which design satisfies this requirement?
- A company will manage many AWS accounts for different departments from a central location. The security team must have read-only access to every account from its own AWS account. The company uses AWS Organizations and has created an account for the security team. What is the correct way for the solutions architect to provide the security team with read-only access to member accounts?
- A company will migrate a Dockerized application that uses an NFSv4 file share. The architect must design a secure, scalable container solution that removes the need to provision or manage underlying infrastructure. Which option meets these requirements?
- A company will migrate from on‑premises to AWS and will use multiple AWS accounts managed under AWS Organizations. They will create a few accounts initially and add more later. A solutions architect must enable AWS CloudTrail for all accounts. What is the MOST operationally efficient design to enable CloudTrail across the organization?
- A company will migrate its on-premises, self-managed Kubernetes cluster (hosting website containers) to Amazon EKS with managed node groups that use a fixed number of nodes. The on-premises PostgreSQL database will be migrated to Amazon RDS for PostgreSQL. A solutions architect must estimate the total cost of ownership (TCO) for the workload before migration. Which approach will provide the required TCO details?
- A company will migrate many VMs to AWS and needs an initial on-premises assessment, visualization of application dependencies between VMs, and a report assessing the on-premises environment. The company can install collector software on-premises. Which approach provides the required information with the least operational overhead?
- A company will split resources into hundreds of AWS accounts across multiple Regions and needs a solution that denies access to any operations outside specifically allowed Regions. Which approach satisfies this requirement?
- A company with an on-premises data center is developing a new solution on AWS using Kubernetes. Development and test workloads run on Amazon EKS clusters in AWS. Production requires both the EKS control plane and data plane to remain on-premises, but the company prefers an AWS-managed Kubernetes solution with minimal operational overhead. Which option satisfies these requirements with the least operational overhead?
- A company with hundreds of AWS accounts has centralized procurement for Reserved Instances (RIs). Business units must submit RI purchase or modification requests to a central procurement team; previously business units performed RI purchases/changes directly in their accounts. A solutions architect must enforce this new process securely. Which combination of steps should be taken? (Choose two.)
- A company with hundreds of AWS accounts in an AWS Organization will push Docker images to Amazon ECR. Only accounts within the Organization should access the images. The company’s CI/CD pipeline runs frequently; the company wants to retain all tagged images but keep only the five most recent untagged images. Which approach meets these requirements with the LEAST operational overhead?
- A company's security team must approve every new IAM user. When a new IAM user is created, the user must have all access removed automatically and the security team must be notified to approve the user. The account already has a multi-Region CloudTrail trail. Which combination of steps will accomplish this? (Choose three.)
- A company’s Amazon Connect agents are receiving many automated spam calls. Agents must be able to mark a caller as spam so that the caller’s number is automatically blocked from reaching an agent in the future. Which solution is the MOST operationally efficient to implement?
- A company’s CI/CD pipelines in GitHub Actions currently use an IAM user’s long-lived secret key to call AWS. An existing IAM role with the required permissions exists. The security team now forbids long-lived secret keys for pipelines. Which short-lived authentication method meets the requirement with the least operational overhead?
- A company’s database runs on an Amazon RDS for MySQL DB instance in us-east-1. They must make the same data available to customers in Europe with minimal latency and no stale data. Both US and European customers must be able to write, and writes made by one region must be visible in the other in real time. Which solution will satisfy these requirements?
- A company’s IoT platform currently runs on-premises: a server uses MQTT to collect telemetry from devices every 5 minutes and stores device metadata in a MongoDB cluster. A periodically running on-premises app aggregates and transforms telemetry+metadata to produce reports; those jobs run 120–600 seconds. A separate web app always runs to serve reports. The company is moving to AWS and wants to reduce operational overhead. Which combination of steps will meet the requirements with the LEAST operational overhead? (Choose three.)
- A company’s on-premises call center hardware is aging and experiencing downtime. The call center sends an automated, interactive two-way text survey to customers after calls. The company wants to migrate to AWS to improve reliability with the LEAST ongoing operational overhead. Which solution is best?
- A compliance audit found that some Amazon EBS volumes in an AWS account were created unencrypted. You must ensure that all new EBS volumes are encrypted at rest with the LEAST amount of effort. Which approach meets this requirement?
- A containerized application runs on EC2 instances with public IPs. Apache Kafka is self-hosted on those EC2 instances, and PostgreSQL has been migrated to Amazon RDS for PostgreSQL. The company expects a surge in orders for a product release. Which architectural changes will reduce operational overhead and support the increased load?
- A containerized application uses Amazon ECS and API Gateway. Data is stored in Amazon Aurora and Amazon DynamoDB. Infrastructure is provisioned by CloudFormation and deployments use CodePipeline. The disaster recovery (DR) requirements are RPO = 2 hours and RTO = 4 hours. Which solution meets these RPO/RTO objectives most cost-effectively?
- A critical application currently has its data tier in a single AWS Region. The data tier includes a DynamoDB table and an Amazon Aurora MySQL DB cluster. The current Aurora engine supports a global database. The application tier is already deployed in two Regions. Company policy requires that critical applications have both application and data tiers deployed across two Regions. RTO and RPO must be a few minutes. Which combination of steps will make the data tier compliant? (Choose two.)
- A critical application runs on a single EC2 instance and uses an ElastiCache for Redis single-node cluster plus an RDS for MariaDB DB instance. Every component must be healthy and active for the application to function. You need to redesign so the infrastructure can automatically recover from failures with minimal downtime. Which combination of changes should you implement? (Choose three.)
- A critical monolithic application runs on an Amazon EC2 instance (Amazon Linux 2). The legal department requires the instance’s encrypted EBS volume data to be backed up to an S3 bucket. The application team does not have the instance’s administrative SSH key pair, and the application must remain serving users during the backup. Which solution meets these requirements?
- A critical stateful web application runs on two Linux EC2 instances behind an ALB with an RDS for MySQL database. DNS is in Route 53. The resilience objectives are: application tier RPO 2 minutes and RTO 30 minutes; database tier RPO 5 minutes and RTO 30 minutes. The company does not want major architecture changes and wants optimal latency after failover. Which solution meets these objectives?
- A custom application lets users upload images. Uploads invoke a Lambda function that processes and stores images in S3. The application calls the Lambda function by a specific function version ARN. Image processing parameters are provided via environment variables. The team frequently changes environment variables to tune processing, then publishes a new function version and updates the application to call the new version ARN, causing user disruption. How can a solutions architect simplify this workflow with the LEAST operational overhead?
- A customer-facing image-storage service will receive batches of large images from millions of users, resize them, and keep them in Amazon S3 for up to 6 months. Demand varies widely. The solution must be enterprise-scale, reliable, and allow failed processing jobs to be retried. Which design is the most cost-effective while meeting these requirements?
- A data lake stored in an S3 bucket must be accessible to hundreds of applications across many AWS accounts. Policy requires that the S3 bucket not be reachable over the public internet, and each application must have least-privilege access. A solutions architect plans to use S3 access points restricted to specific VPCs for each application. Which combination of actions should the architect take to implement this? (Choose two.)
- A data-collection application runs in eu-north-1 and writes processed records to an S3 bucket in eu-north-1 that is queried by Athena. The company is expanding the data-collection capability to sa-east-1 and ap-northeast-1 and deploys the collectors, Kinesis streams, and Lambda processors in those Regions, but keeps the S3 bucket centralized in eu-north-1 for analysis. During testing, data arriving from the new Regions to the central S3 bucket shows significant lag. Which change will reduce that cross-region arrival lag the MOST?
- A data-heavy application runs on hundreds of EC2 instances and currently uses a shared file system hosted on several EC2 instances containing 200 TB of data. A monthly job runs once per month, reads a subset of files, runs about 72 hours, and the compute instances scale in an Auto Scaling group. The shared file system EC2 hosts are always running. All resources are in the same Region. You need to replace the shared file system servers to reduce cost while ensuring high-performance access for the 72-hour job. Which option yields the LARGEST overall cost reduction while meeting the needs?
- A delivery company will migrate a third-party route-planning app to AWS. The vendor supplies a supported Docker image from a public registry. The image can scale to many containers and each delivery-area section runs its own set of containers with a custom configuration to process only that section's orders. The company needs to allocate resources cost-effectively based on running container count and minimize operational overhead. Which solution meets these requirements with the least operational burden?
- A design team updates static icons and assets in a development account and then needs to upload the tested assets into an S3 bucket in the company's production account. The design team should be given access to upload to the production bucket without exposing other parts of the production environment. Which combination of steps accomplishes this? (Choose three.)
- A document-processing server on Linux generates and modifies files at about 5 documents per second and needs fast local filesystem performance. Many applications were updated to use the S3 API, but this processing server cannot be updated immediately. After processing completes, files must be publicly available from S3 within 30 minutes. Which option meets the requirement with the least effort?
- A finance company hosts a data lake in Amazon S3. Each night several third parties upload financial data over SFTP. The company currently runs its own SFTP server on an EC2 instance in a public subnet; a cron job on that instance moves uploaded files into the data lake. The SFTP server is reachable at sftp.example.com via Amazon Route 53. How should a solutions architect improve the reliability and scalability of this SFTP solution?
- A finance company runs a business-critical application on current-generation Linux EC2 instances with a self-managed MySQL database that has heavy I/O. The application handles moderate traffic most of the month but slows during the final three days because of month-end reporting. The infrastructure already uses ELBs and Auto Scaling for compute. Which action will let the database handle the month-end load with the least performance impact?
- A financial company will migrate a web app to EC2 instances in an Auto Scaling group inside a dedicated VPC. The company uses a legacy third-party security appliance (no cloud-native offering) that must inspect all packets entering and leaving the VPC in real time without impacting application performance. The design must be highly available within the Region. Which combination of steps should the solutions architect take? (Choose two.)
- A financial services company builds an analytics solution on Amazon EMR for survey data. Three personas need controlled, least-privilege access: Administrator (provisions EMR clusters), Data engineer (runs ETL), and Data analyst (runs SQL/Hive queries). The personas should only be able to launch approved/authorized applications and all resources they create must be tagged. Which solution enforces these requirements?
- A financial services company imported millions of historical stock trades into a DynamoDB table that uses on-demand capacity mode. Each night at midnight a few million new records are loaded. Reads occur in bursts throughout the day and repeatedly request a small set of keys. The company needs to reduce DynamoDB costs. What strategy should be recommended?
- A financial services company will launch a new web application in us-east-1 on EC2. The application must be highly available and autoscaling in us-east-1, and the company wants an active-passive disaster recovery environment in us-west-1. Which design meets these requirements?
- A fleet of IoT devices writes data as ORC files into HDFS on a persistent Amazon EMR cluster. Analysts run SQL queries with Apache Presto on the same EMR cluster. Queries scan large volumes, always complete in under 15 minutes, and run only between 5 PM and 10 PM. The company wants a more cost-effective solution that still allows SQL querying. Which solution is the most cost-effective and meets the requirements?
- A flood-monitoring agency has over 10,000 sensors that continuously send updates under 1 MB each. On-premises application servers receive sensor updates, transform them into human-readable records, and write results to an on-premises relational database. Analysts run simple SQL queries on the live data. Due to maintenance (patches/updates), these servers have downtime, and while a server is down the remaining servers cannot handle the load, causing data loss. The agency wants higher availability and lower operational effort and cost. The architect recommends using AWS IoT Core to ingest sensor data. What additional design should the architect recommend to meet the requirements?
- A forms-processing application on EC2 and RDS stores uploaded scanned forms in S3 and sends notifications via Amazon SNS for a human team to validate and extract data, then call an external API. You must automate form processing with accurate extraction, minimal time to market, and minimal ongoing operational overhead. Which solution best meets these goals?
- A game launch must support many global players immediately after release. Currently the game is in a single Region and uses: an S3 bucket for game assets and a DynamoDB table for player scores. You must design a multi-Region solution that reduces latency, improves reliability, and requires minimal implementation effort. What should you do?
- A gaming company must rehost its gaming platform on AWS. The platform requires high-performance compute, and the leaderboard updates frequently. Currently an Ubuntu compute-optimized instance runs a Node.js front end. Game state is stored in an on-premises Redis instance. The migration should optimize application performance in AWS. Which solution meets these requirements?
- A genomic device sends 8 KB of data every second to a data platform. Requirements: near-real-time analytics, flexible/parallel/durable ingestion, and delivering processed results into a data warehouse. Which design should a solutions architect choose?
- A global ecommerce company needs scalable storage for legacy on-premises file-based applications. Requirements: be able to mount volumes as iSCSI devices from on-prem application servers, keep low-latency access to frequently accessed data, and take point-in-time copies of volumes using AWS Backup. Which solution satisfies these requirements?
- A global education company runs a web app on ECS in an Auto Scaling group behind an ALB. Weekly, the authentication service is overwhelmed by a surge of failed login attempts coming from about 500 IP addresses that change every week. A solutions architect must prevent these failed login attempts from overloading the authentication service with the most operational efficiency. Which solution meets this requirement?
- A global manufacturer needs to migrate most applications to AWS but must keep some apps in-country or on-premises due to data regulations or single-digit millisecond latency needs. Some factory sites have limited network infrastructure. Developers must have a consistent experience and use the same tools, APIs, and services whether apps run on-premises, in the cloud, or hybrid. Which solution provides a consistent hybrid experience for these requirements?
- A global media company is deploying an app in multiple Regions with Amazon DynamoDB global tables backing it to keep user experience consistent across two major continents. Each Region deployment uses a public Application Load Balancer (ALB). The company manages public DNS internally and wants the app reachable via an apex domain. Which option meets the requirement with the LEAST effort?
- A global SaaS provider runs its platform across multiple AWS accounts managed by AWS Organizations. All API calls to AWS resources must be audited, tracked for changes, and stored durably and securely to satisfy regulatory compliance. The solution should minimize operational overhead. Which approach meets these requirements?
- A global ticketing mobile app displays a barcode that event scanners read. After scanning, scanner devices call a backend API to validate the barcode against a database and then update a single database table to mark the barcode as used. The company will host the database in three AWS Regions and needs a DNS name api.example.com. Which architecture provides the LOWEST latency for barcode validation and the update operation?
- A global web application runs on a single EC2 instance and performs read‑intensive operations on an Amazon RDS for MySQL database. During peak load the EC2 instance becomes unresponsive and needs manual restarts. You must improve reliability with minimal development effort. Which solution best meets this requirement?
- A government agency requires all Amazon EBS snapshots to be stored in at least two additional AWS Regions and wants to minimize operational overhead. Which solution satisfies these requirements?
- A health insurer stores PII in an Amazon S3 bucket and currently uses server-side encryption with S3-managed keys (SSE-S3). A new requirement mandates that all existing and future objects in the bucket be encrypted with keys managed by the company’s security team (customer-managed keys). The S3 bucket does not have versioning enabled. Which approach satisfies this requirement?
- A hybrid environment has EC2 instances in a VPC that send application logs to CloudWatch and read data from on-premises relational databases. The company needs near-real-time visibility into which EC2 instances are connected to the databases and already uses Splunk on premises for monitoring. How should a solutions architect forward the necessary network log traffic to Splunk to meet these requirements?
- A Java application was deployed to AWS Elastic Beanstalk using a single-instance environment to save costs during development. Testing shows sustained CPU utilization above 85%, causing performance bottlenecks. You must mitigate the CPU bottleneck before production with the least operational overhead. What should you do?
- A large company has seen an unexpected spike in Amazon RDS and Amazon DynamoDB charges. The organization uses AWS Organizations with many development and production accounts. There is no enforced tagging strategy across accounts, though guidelines require infrastructure to be deployed with AWS CloudFormation and consistent tags. Management mandates that all existing and future DynamoDB tables and RDS instances include cost center and project ID values. Which approach should the solutions architect recommend to satisfy these requirements?
- A large enterprise runs workloads in VPCs across hundreds of AWS accounts. Each VPC has public and private subnets across multiple AZs; NAT gateways in public subnets provide internet access for private subnets. In a hub-and-spoke design, all private subnets in spoke VPCs must send internet-bound traffic through a NAT gateway located in a centralized egress VPC in a central account. A NAT gateway already exists in that egress VPC. Which additional steps should the solutions architect take to meet the requirement?
- A large mobile gaming company migrated all on-premises infrastructure to AWS. A solutions architect is auditing the environment against the Well-Architected Framework and reviewing historical costs in Cost Explorer. The architect notices large charges from the creation and termination of large EC2 instance types. Developers are launching EC2 instances for testing and are choosing inappropriate instance types. You must implement a control so developers can only launch approved instance types. Which solution satisfies this requirement?
- A latency-sensitive trading platform uses Amazon DynamoDB (on-demand mode). The solutions architect must improve performance and ensure high availability while achieving minimal latency. Which option meets these requirements?
- A legacy application that uses MongoDB is being migrated to AWS. Company policy requires all EC2 instances to be in private subnets without internet access, all application-database communication to be encrypted, and the database to scale with demand. Which solution satisfies these constraints?
- A legacy application uses multiple .NET Framework components that share a Microsoft SQL Server database and communicate asynchronously using Microsoft Message Queueing (MSMQ). The company is migrating to containerized .NET Core components and wants to refactor the app to run on AWS. The .NET Core containers need complex orchestration, full control over networking and host configuration, and the database model is strongly relational. Which architecture meets these requirements?
- A legacy application was migrated to AWS and runs on three EC2 instances (one in each of three AZs) in private subnets. These instances are targets for an Application Load Balancer (ALB) in three public subnets. The application must call on-premises systems that accept traffic only from a single company IP address. The security team has brought only that one IP to the cloud and allocated an Elastic IP for it. The solution must allow the application to reach on-premises systems and automatically handle failures. Which design meets these requirements?
- A legacy on-premises .NET application (load-balanced web tier, load-balanced application tier, and Microsoft SQL Server database) is being migrated to AWS. The company prefers managed services and does not want to rewrite the application. The solutions architect must eliminate scaling issues while minimizing licensing costs as the application scales. Which option is the most cost-effective solution that meets these goals?
- A legacy workload has the stateless application tier on a single large EC2 instance launched from an AMI, and the MySQL database on a single EC2 instance. CPU on the app server often hits 100%, causing outages. Patching is applied manually and has caused downtime. The company needs to make the application highly available with the least development effort. Which solution meets this requirement?
- A life sciences team generates about 200 GB per genome from sequencers. They run 10–15 jobs per day. Each job can take several hours with ideal compute. Sequencing data is stored on an on-prem SAN and the company has a high-speed AWS Direct Connect link. Final results must be stored in Amazon S3. The team wants to move the genomics analysis platform to AWS to scale with demand and reduce turnaround time. Which solution meets these requirements?
- A live-events company runs a ticketing application on EC2 instances in an Auto Scaling group and uses PostgreSQL for the database. Sale events produce one-time scheduled spikes in demand. The company needs a scaling approach that maximizes availability during these scheduled sale events. Which solution meets these needs?
- A manufacturer has IP cameras at the end of each assembly line and a SageMaker-trained model to detect defects from still images. The factory must provide local feedback to workers when a defect is detected, even if internet connectivity is lost. A local Linux server hosts an API that delivers feedback. How should the company deploy the ML model so detection and local feedback work when offline?
- A media application uploads user photos to Amazon S3 for processing by AWS Lambda. Application state is stored in DynamoDB. When thousands of users upload at once, photo processing fails due to Lambda concurrency limits and DynamoDB write/read performance. Which combination of actions should increase performance and reliability? (Choose two.)
- A media company has a 30-T8 repository of digital news videos stored on tape in an on-premises tape library and referenced by a Media Asset Management (MAM) system. The company wants to automatically enrich video metadata (for example, objects, scenery items, and faces) and make videos searchable via the MAM. A face catalog already exists with images of people who appear in the videos. The company plans to migrate videos to AWS and has a high-speed AWS Direct Connect link. The company wants to move video files directly from its current file system with the least ongoing management overhead and minimal disruption to the existing system. Which solution meets these requirements?
- A medical company runs a REST API on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The ALB is in three public subnets and the EC2 instances are in three private subnets. A CloudFront distribution uses the ALB as the origin. What should a solutions architect recommend to strengthen origin security (protecting the ALB from direct access) for requests coming from CloudFront?
- A metadata service collects information from on-premises apps and is accessed by consumer devices (TVs, internet radios). Older devices cannot support certain HTTP response headers; your on-premises load balancer currently strips those headers for requests identified by User-Agent. The application functions have been migrated to AWS Lambda and you want a serverless solution that still supports legacy devices by removing problematic headers. Which solution meets these requirements?
- A migrated application stores structured product data and transient user session data. The company wants product data and session data decoupled and wants replication to another AWS Region for disaster recovery. Which design gives the HIGHEST performance?
- A mobile app feature lets users upload photos and videos at any time. The media is stored in an S3 bucket using S3 Standard and delivered through CloudFront. After 30 days, most objects are accessed infrequently, but some remain frequently accessed. The company requires millisecond retrieval for all objects at the lowest possible storage cost. Which solution meets these requirements?
- A mobile game company serves game assets from EC2 instances behind an ALB in two Regions. Clients must fetch assets from the geographically closest Region; if assets are unavailable in the nearest Region, clients should fail over to the other Region. How should a solutions architect implement this behavior?
- A mobile game's backend runs on on-premises VMs exposing a REST API. Business logic uses multiple API keys and reads player session data from central file storage. Load varies and has peaks causing insufficient capacity and high latency when fetching session data. The API model must remain unchanged. Which cloud architecture meets needs for variable load handling and low-latency access?
- A monolithic REST API for a mobile app runs on five EC2 instances in public subnets and is fronted by a Route 53 multivalue answer record that points directly to the instances' IPs. Sudden large traffic spikes are overwhelming the app. Which solution will allow the application to scale to the new, variable load with the LEAST operational overhead?
- A multi-tenant SaaS uses shared Amazon DynamoDB tables and AWS Lambda for its application layer. Each request includes a tenant ID. The company wants to bill tenants based on their individual DynamoDB resource consumption and already has an AWS Cost and Usage Report (CUR). Which approach provides a granular per-tenant view of DynamoDB costs with the least operational overhead?
- A multi-tier application stores temporary data in S3 objects that are valid for 45 minutes and must be deleted after 24 hours. Each application version is deployed via a CloudFormation stack and when an older stack is deleted, CloudFormation fails to delete an S3 bucket, causing stack deletion to fail. Without major architectural changes, how can this be resolved?
- A new application must run on five EC2 instances in a single Region. The application requires very high throughput and low-latency network connectivity between all instances. There is no need for fault tolerance. Which deployment meets these networking requirements?
- A North American company with headquarters on the East Coast is deploying a web application in us-east-1 (primary). The application must scale dynamically, be resilient, and support an active-passive disaster recovery configuration with us-west-1 (standby). After creating a VPC in us-east-1, what steps should the solutions architect take to meet these requirements?
- A partner sends plaintext credit-card data (about 5,000 records every 15 minutes) into an S3 bucket (server-side encrypted). The company must automatically mask PANs, remove/merge fields, and transform records into JSON, then send results to another S3 bucket for internal processing. The design should be easily extensible for additional feeds. Which solution satisfies these requirements?
- A popular web application runs on multiple Linux EC2 instances in an Auto Scaling group inside a private subnet, with an Application Load Balancer targeting those instances. Systems Manager Session Manager and SSM Agent are configured on all instances. After a new release, some instances are marked unhealthy and are terminated, reducing capacity. CloudWatch logs are inconclusive. How should you obtain access to an instance for troubleshooting?
- A private intranet service will run on EC2 instances in a VPC that is connected to the on-premises network via a Site-to-Site VPN. The new service must resolve hostnames in the company.example DNS zone; that zone is hosted only on-premises and reachable only from the corporate network. What solution enables instances in the VPC to resolve company.example names so the service can integrate with existing on-premises services?
- A project account (not allowed to join the company’s AWS Organization) is launching EC2 instances larger than needed. The company wants to restrict that account so developers can launch only t3.small instances and only in us-east-2. What should a solutions architect do to enforce these requirements within the project's account?
- A public API runs as Amazon ECS tasks on AWS Fargate behind an Application Load Balancer (ALB). Service Auto Scaling scales tasks based on CPU. Recently, a surge of SQL injection attacks caused the service to scale to its maximum and the API became unusable. The architect must stop SQL injection attacks from reaching the ECS service, allow legitimate traffic, and maximize operational efficiency. Which solution meets these requirements?
- A public retail web application uses an Application Load Balancer (ALB) in front of EC2 instances across multiple AZs and an Amazon RDS MySQL Multi-AZ backend. Target group health checks use HTTP and point at the product catalog page. Auto Scaling maintains the web fleet based on ALB health checks. Recently the app suffered an outage; Auto Scaling repeatedly replaced instances, while web server metrics looked normal. Investigation showed the database was heavily loaded and queries were very slow. Which two changes together will address the issue and improve monitoring of overall application availability and functionality for future growth? (Choose two.)
- A Python script runs on an EC2 instance every 10 minutes to ingest and process files from an S3 bucket; each file takes about 5 minutes to process and is processed only once. CloudWatch metrics show the EC2 instance is idle around 40% of the time. The company wants the workload to be highly available, scalable, and to reduce ongoing management overhead. Which solution meets these requirements most cost-effectively?
- A quick-service restaurant chain runs a point-of-sale and management backend on AWS that uses a DynamoDB table in provisioned throughput mode. The table is sized for peak traffic using 100,000 read capacity units and 80,000 write capacity units. Daily traffic is predictable: very high for about 4 hours and lower the rest of the day. The company wants to lower DynamoDB costs and reduce operational overhead for IT. Which solution meets these goals most cost-effectively?
- A research center migrated 1 PB of on-premises object storage into a single Amazon S3 bucket. 100 scientists each have a personal folder; all scientists are members of one IAM user group. The compliance officer wants to prevent scientists from accessing each other’s data and must report which scientist accessed which objects. The reporting team has little AWS experience and prefers a ready-to-use, low‑operational-overhead solution. Which two actions should a solutions architect recommend? (Choose two.)
- A research company runs daily simulations on hundreds of Amazon Linux 2 EC2 instances. Occasionally an instance requires an engineer to SSH in to resolve a stuck simulation. The security policy requires that no two EC2 instances share the same SSH key and that all SSH connections are logged in AWS CloudTrail. How can a solutions architect meet these requirements?
- A retail company has an on-premises datacenter in Europe and an AWS footprint in eu-west-1 and us-east-1. They need to route on-premises traffic into VPCs in either Region, and support routed traffic directly between VPCs in those Regions. No single network point of failure is allowed. They already have two 1 Gbps Direct Connect links from on-premises to two separate Direct Connect locations in Europe (DX-A and DX-B). Each Region has a single AWS Transit Gateway for intra-Region inter-VPC routing. Which design meets these requirements?
- A retail company runs an e-commerce site across multiple AWS Regions and requires the website to remain operational at all times for online purchases. The site uses an Amazon RDS for MySQL DB instance for data storage. Which option provides the highest availability for the database?
- A retail company runs multiple applications that register orders, process returns, and provide analytics. Currently, they use a MySQL transactional database and an Oracle OLAP analytics database, all on EC2. Several application components produce events from different sources; a weekly ETL copies application data to the analytics database. The company wants an event-driven, serverless redesign that provides near real‑time analytics. Which architecture meets these requirements?
- A retail ordering application currently uses a load-balanced EC2 fleet for web hosting, database API services, and business logic. The company wants to refactor to a decoupled, scalable architecture that retains failed orders for later processing while minimizing operational overhead. Which architecture best meets these goals?
- A retailer runs its e-commerce app on EC2 instances behind an Application Load Balancer (ALB) with an Amazon RDS backend. CloudFront is configured with the ALB as the origin to cache static content. Route 53 hosts public DNS. After an app update, the ALB sometimes returns HTTP 502 (Bad Gateway) due to malformed HTTP headers returned to the ALB. Reloading the page immediately usually succeeds. While the company fixes the root cause, the solutions architect needs to show a custom error page instead of the ALB default with minimal operational overhead. Which combination of steps achieves this? (Choose two.)
- A SaaS application on AWS uses AWS Lambda for compute and an Amazon RDS for MySQL Multi-AZ database. During high-demand market events, database connection counts spike and users experience slow responses. The company needs to improve the database’s scalable performance and availability to handle many concurrent connections from Lambda. Which solution meets this need?
- A SaaS application runs on Amazon EC2 instances in an Auto Scaling group behind a Network Load Balancer (NLB) across three Availability Zones in one Region. The company is deploying the application to additional Regions and must provide static IP addresses to customers (so customers can allowlist them). The solution must automatically route customers to the geographically closest Region. Which solution satisfies these requirements?
- A SaaS application runs on API Gateway (HTTPS), AWS Lambda, and Aurora Serverless v1 deployed across multiple AZs. The deployment used AWS SAM. There is no disaster recovery (DR) plan. The company requires the application to be recoverable in another AWS Region with an RTO of 5 minutes and an RPO of 1 minute. Which DR approach meets these recovery objectives?
- A SaaS company currently uses a standalone SMTP server to send emails and stores an email template that is merged with customer data before sending. The company wants to migrate this functionality to AWS with minimal operational overhead and at the lowest cost. Which solution will meet these goals most cost-effectively?
- A SaaS company deployed an Amazon API Gateway REST API with Lambda integration across multiple Regions in the same production account. Customers pay for a tiered capacity measured in API calls per second; the premium tier allows up to 3,000 RPS and customers are identified by API keys. Several premium customers across Regions report 429 Too Many Requests on various API methods during peak hours. Logs show the Lambda function is never invoked. What is the likely cause of the 429 errors for these customers?
- A SaaS company runs its media solution across 50 VPCs in multiple Regions and accounts. One VPC is a management VPC. Compute resources in each VPC operate independently. A new feature requires full connectivity among all 50 VPCs and one-way access from each customer VPC to the management VPC for license validation. The management VPC hosts the license-validation compute resource. The solution will continue to scale to more VPCs. Which combination of actions will provide the required connectivity with the least operational overhead? (Choose two.)
- A SaaS provider exposes a proprietary service via AWS PrivateLink. The service runs on three EC2 instances behind a Network Load Balancer (NLB) in private subnets across multiple Availability Zones in eu-west-2. All customers are currently in eu-west-2, but a new customer in us-east-1 requires access. The company created a new VPC and subnets in us-east-1 and configured inter-Region VPC peering between the Regions. The company does not want to deploy new EC2 resources in us-east-1 immediately. Which solution enables the new us-east-1 customer to access the service without deploying instances in us-east-1?
- A SaaS provider exposes APIs through an Application Load Balancer (ALB) in us-east-1 that forwards requests to an Amazon EKS cluster. The APIs use several non-standard REST methods (LINK, UNLINK, LOCK, UNLOCK). Users outside the United States experience long and inconsistent response times. The solutions architect must improve global performance while minimizing operational overhead. Which solution accomplishes this?
- A sales reporting application runs in a US Region. It uses a Regional Amazon API Gateway and AWS Lambda to generate on-demand reports from an Amazon RDS for MySQL database. The frontend is on Amazon S3 and served via CloudFront. Route 53 currently uses a simple routing policy to point to the API Gateway API. The company will expand to Europe soon, and more than 90% of database traffic is read-only. API Gateway and Lambda are already deployed in the new Region. Which design minimizes latency for users downloading reports?
- A scientific organization must copy text and image files from a source Amazon S3 bucket (owned by Account A) to a destination S3 bucket in a second AWS account (Account B). Several radar stations upload time-sensitive data to the source bucket; each station's objects use a unique key prefix. Replication is implemented with an S3 replication rule that covers all objects in the source bucket. One radar station produces the most accurate data and its objects must be monitored to confirm replication completes within 30 minutes of upload. Which approach will meet these requirements?
- A security audit found many unencrypted EBS volumes across multiple AWS accounts. You must encrypt those volumes and ensure future unencrypted volumes are detected automatically. The company also wants centralized compliance and security management across accounts. Which combination of actions should you take? (Choose two.)
- A security audit found several unencrypted Amazon EBS volumes attached to thousands of EC2 instances in a company account. Company policy mandates EBS volume encryption. The company needs an automated remediation to encrypt existing unencrypted volumes and to prevent development teams from creating unencrypted volumes. Which solution meets these requirements?
- A security audit found that a development team committed IAM user secret access keys inside application code to an AWS CodeCommit repository. The security team wants an automated mechanism to detect and remediate these exposed credentials so they are secured automatically. Which solution will ensure credentials are discovered and remediated automatically?
- A serverless app in one Region publishes URLs via an Amazon SNS topic to an Amazon SQS queue. An AWS Lambda function uses that SQS queue as an event source, fetches each URL, extracts metadata, and writes results to an Amazon S3 bucket in the same Region. The company wants to run the same URL processing in additional Regions (to compare localized site differences), but all URLs must be published from the existing Region and all output must be written to the original S3 bucket in the current Region. Which combination of changes will create a multi-Region deployment that satisfies these requirements? (Choose two.)
- A serverless application uses AWS Lambda and DynamoDB. New functionality requires Lambda functions to access an Amazon Neptune DB cluster located across three subnets in a VPC. Which solutions will allow the Lambda functions to access both the Neptune cluster and DynamoDB? (Choose two.)
- A serverless application uses CloudFront, API Gateway, and Lambda. Deployments are currently done by creating a new Lambda version and running a CLI script to update. If the new version has errors, another CLI script redeploys the previous version. The company wants faster deployments and quicker detection and rollback when errors occur. Which approach accomplishes this?
- A serverless e-commerce app uses API Gateway to invoke Java-based Lambda functions that connect to an Amazon RDS for MySQL database. During a traffic spike, API performance suffered and database connections failed. The company wants to reduce Lambda latency and support traffic bursts with minimal changes. Which solution meets the requirements with the least application modification?
- A serverless Lambda function running inside a VPC must call an external provider that accepts requests only from a single public IPv4 address (the provider will allowlist that address). You must supply one public IP to the provider so the Lambda-based application can use the service. Which solution provides the required single public IP for outbound requests from the Lambda function?
- A serverless system contains a central user service (DynamoDB) that stores sensitive data. Other microservices maintain local copies of parts of that sensitive data in various storage services. When the central user service deletes a user, every other microservice must immediately delete its copy. Which design satisfies this requirement?
- A serverless web application is deployed with Lambda functions via CloudFormation. A recent release caused an outage. The deployment process needs to support canary-style releases to shift a portion of traffic to a new Lambda version. Which approach accomplishes this?
- A software company has remote engineers. Active Directory Domain Services (AD DS) runs on an EC2 instance. Company policy requires that all internal, nonpublic services in the VPC be accessible only via a VPN and that VPN access require multi‑factor authentication (MFA). What should a solutions architect implement to satisfy these requirements?
- A software company runs resources across multiple AWS accounts and Regions. The application VPC (us-east-1) has CIDR 10.10.0.0/16. A shared-services VPC in a different account in us-east-2 uses CIDR 10.10.10.0/24. A CloudFormation attempt to create a VPC peering between the application VPC and the shared-services VPC failed. Which factors could cause the peering failure? (Choose two.)
- A software team needs short-lived test environments for pull-request validation. Each environment is a single EC2 instance in an Auto Scaling group and must report results to a central server in the on-premises data center. A transit gateway with a VPN attachment to on-premises already exists. The process of creating and deleting environments must be fully automated and require minimal operational overhead. Which approach meets these requirements with the LEAST operational overhead?
- A solution will run on AWS and receive connections from thousands of devices that must send and receive real-time MQTT messages. Each device must authenticate using its own unique X.509 certificate. Which architecture provides this capability with the least operational overhead?
- A solutions architect deployed a web app accessible from two AWS Regions under a custom domain using Amazon Route 53 latency-based routing. For each Region, the architect created weighted record sets that point to a pair of web servers in different Availability Zones. During a disaster-recovery test, all web servers in one Region were stopped, but Route 53 did not automatically route traffic to the other Region. Which of the following could explain this behavior? (Choose two.)
- A solutions architect imported a VM from an on-premises environment using VM Import/Export and created an AMI. An Amazon EC2 instance launched from that AMI runs in a public subnet within a VPC and has a public IP address. The EC2 instance does not appear as a managed instance in the AWS Systems Manager console. Which combination of troubleshooting steps should the solutions architect take? (Choose two.)
- A solutions architect is deploying a new security tool into several AWS Regions that were not previously used. The deployment uses an AWS CloudFormation stack set. The stack set's template defines an IAM role that uses a custom (explicit) name. After creating the stack set, none of the stack instances are created successfully. What should the solutions architect do so the stacks can be deployed successfully?
- A solutions architect is designing an AWS account and networking structure for multiple teams that all operate in the same AWS Region. The company needs a VPC that connects to the on-premises network and expects less than 50 Mbps of total traffic to/from on-premises. Which combination of steps is the MOST cost-effective way to meet these requirements? (Choose two.)
- A solutions architect is performing a blue/green deployment for an AWS Elastic Beanstalk application. They created a new environment identical to the current environment and deployed the updated application into it. What is the next step to complete the update with minimal disruption?
- A solutions architect launched multiple EC2 instances within a placement group in a single Availability Zone. Under increased load, the architect tried to add more instances to the placement group but received an insufficient capacity error. What should the architect do to troubleshoot and resolve this problem?
- A solutions architect must add centrally managed, rule-based filtering for outbound internet traffic for all AWS accounts in an AWS Organization. The organization has more than 100 accounts, uses a centralized AWS Transit Gateway for routing between accounts, each account has an internet gateway and a NAT gateway, and all resources are in a single Region. Peak outbound traffic will not exceed 25 Gbps per Availability Zone. Which solution meets these requirements?
- A solutions architect must analyze EC2 instance and EBS volume usage to determine efficiency. The company runs several large, high-memory EC2 instances hosting database clusters in active/passive configurations. Utilization varies by application and no clear pattern is known. The architect must analyze the environment and act on findings in the most cost-effective way. Which solution best meets these requirements?
- A solutions architect must build a cost-effective business case for migrating an on-premises data center to AWS. The architect will use a configuration management database (CMDB) export of all servers. Which solution is the MOST cost-effective way to analyze that CMDB export for migration planning?
- A solutions architect must copy objects from an S3 bucket in one AWS account to a new S3 bucket in another account using the AWS CLI. Which combination of steps will allow the copy to succeed? (Choose three.)
- A solutions architect must enforce MFA for a team of cloud engineers who use the AWS CLI to upload objects to an S3 bucket. Each engineer has an IAM user, access keys, and a virtual MFA device. The IAM users are members of an IAM group named S3-access. MFA must be required for any actions in Amazon S3. Which solution meets these requirements?
- A solutions architect must inventory and assess applications and databases in a newly acquired company’s undocumented on-premises data center before migrating to AWS. Traffic patterns are variable and some apps run monthly batch processes. The architect needs to discover the portfolio and dependencies to build a migration business case. Which solution provides the required discovery and reporting?
- A solutions architect must migrate mission-critical legacy Microsoft SQL Server databases to AWS and modernize the data architecture with near-zero downtime. Which migration approach satisfies these constraints?
- A solutions architect must provide secure Remote Desktop (RDP) access to Windows EC2 instances in a VPC, integrating centralized user management with the company’s on-premises Active Directory. Access to the VPC is over the internet, and the company can establish a Site-to-Site VPN using existing hardware. Which solution is the MOST cost-effective while meeting requirements?
- A solutions architect needs to ensure that only authorized AWS users or roles can call a new Amazon API Gateway endpoint. The architect also wants an end‑to‑end trace of each request to measure latency and build service maps. How can API Gateway access control and request tracing be implemented to satisfy both requirements?
- A solutions architect wants to cost-optimize and right-size EC2 instances in a single account, ensuring decisions consider CPU, memory, and network metrics. Which combination of actions should the architect take? (Choose two.)
- A stable Java application depends on VMs in the company data center and the company wants to modernize while minimizing server administration and code changes. Which migration approach meets these goals with the least code modification?
- A startup moved a high-traffic ecommerce site to AWS and now needs CI/CD that notifies engineers of failed builds, provides zero downtime deployments, and supports seamless rollbacks. Developers use a private GitHub repo and Jenkins for builds and unit testing. The team will use AWS CodePipeline to orchestrate builds and deployments. Which design satisfies the notification, zero-downtime, and rollback requirements?
- A startup runs a fleet of Amazon Linux 2 EC2 instances in private subnets and engineers rely on SSH for troubleshooting. The VPC has private and public subnets, a NAT gateway, and a Site-to-Site VPN to on-premises. Current EC2 security groups allow direct SSH from the on-premises network. The company wants stronger SSH controls and auditing of commands run by engineers. Which approach should a solutions architect recommend?
- A static website is hosted in Amazon S3 and delivered with CloudFront. The site calls an Amazon API Gateway REST API whose methods are backed by AWS Lambda functions. The company needs a CSV report every two weeks that lists, for each API Lambda function: the recommended memory configuration, the recommended cost, and the price difference between the function’s current configuration and the recommendation. The CSV files will be stored in S3. Which solution requires the least development effort?
- A team routes behavioral data for the company. The VPC design is Multi-AZ with public and private subnets, an internet gateway, and each public subnet contains a NAT gateway. Applications in private subnets read and write to Amazon Kinesis Data Streams. Cost Explorer shows consistently high EC2‑Other charges due to increasing NatGateway-Bytes costs. The solutions architect must reduce costs while preserving application functionality. What should the architect do?
- A telecom company uses AWS with a Direct Connect between on-premises and AWS. The application runs on EC2 instances in multiple AZs behind an internal ALB. Clients on the on-premises network connect to the application using HTTPS; TLS terminates at the ALB. The ALB uses multiple target groups and path-based routing. The company will deploy an on-premises firewall appliance that only allows traffic to known IP addresses. Which solution will allow on-premises traffic to reach the application and satisfy the firewall allow-list requirement?
- A third-party SaaS provider runs its service inside a VPC on AWS and exposes its functionality through APIs. Your company will call those APIs from resources inside your VPC. Company policy requires private connectivity that does not traverse the public internet, and resources in your VPC must not be accessible from outside your VPC. All access must follow least privilege. Which solution satisfies these constraints?
- A third-party web application packaged as a Docker image runs on AWS Fargate (Amazon ECS) behind an Application Load Balancer (ALB). Only a specific list of users must be allowed internet access to the application. The application cannot be modified and cannot be integrated with an external identity provider. All users must authenticate with multi-factor authentication (MFA). Which solution satisfies these constraints?
- A ticketing application runs on an Amazon ECS cluster and is delivered via CloudFront. A single ECS service is the CloudFront origin. The app limits the number of active users in the purchase flow; allowed users are identified by an encrypted attribute in their JWT; others are routed to a waiting room. Under high load, the waiting room itself is causing load that disrupts ticket purchases. What change will provide the most reliable ticket purchase experience during high load?
- A ticketing service runs on Linux EC2 instances in an Auto Scaling group. The service reads a pricing file stored in an S3 bucket (S3 Standard). A third‑party central pricing system updates the pricing file every 1–15 minutes; the file has several thousand line items. Each EC2 instance downloads the file at launch, but instances sometimes use stale pricing, causing incorrect customer charges. Which solution will solve this problem MOST cost‑effectively?
- A travel agency chain runs an application on two fixed Amazon EC2 instances behind a Route 53 multivalue record that returns the instances' Elastic IPs. The app uses DynamoDB for primary storage and a self-hosted Redis cache. Destination content is updated quarterly; updates spike load and have caused downtime. You must make the app highly available and able to handle the update load. Which solution meets these needs?
- A travel company uses Amazon SES to send email notifications and must enable logging to troubleshoot delivery problems. The company also needs to support searches by recipient, subject, and time sent. Which combination of steps should a solutions architect implement? (Choose two.)
- A US company acquired a European company. The US team built a new microservices application that runs across five VPCs in the us-east-2 Region. The application must be able to access resources in a single VPC in the eu-west-1 Region and must not have access to any other VPCs. The VPC CIDR ranges in both Regions do not overlap. All AWS accounts are consolidated under one AWS Organizations organization. Which solution meets these requirements MOST cost-effectively?
- A utility company collects smart meter usage every 5 minutes. Data arrives via Amazon API Gateway, goes to an AWS Lambda function, and is stored in an Amazon DynamoDB table. During a pilot, Lambda ran 3–5 seconds, but as meters scale, Lambda durations increased to 1–2 minutes, and more metric types increased duration further. There are many ProvisionedThroughputExceededException errors on DynamoDB PUTs and many TooManyRequestsException errors from Lambda. Which combination of changes will resolve the problems? (Choose two.)
- A vehicle manufacturer collects telemetry via MQTT from many vehicles. Data is processed every 5 minutes and copied to on-premises storage for anomaly detection by custom apps. Because on-premises storage can't scale to peaks, data is lost. Which AWS-based solution with the least operational overhead solves the scaling and analytics needs?
- A video company must move 600 TB of compressed files (thousands of files) from on-premises NAS to AWS as a one-time transfer within 3 weeks. On-premises compute is insufficient for ML, the transfer must be encrypted in transit, measured shared internet upload speed is 100 Mbps, and multiple departments share the link. Which cost-effective solution meets the requirements?
- A video processing pipeline uses EC2 instances in an Auto Scaling group to process videos from an SQS queue. Each video takes about 30 minutes to process. The SQS queue has a redrive policy to a dead-letter queue with maxReceiveCount set to 1. The queue visibility timeout is 1 hour. CloudWatch alarms notify the team when messages arrive in the dead-letter queue. Several times per day, messages show up in the DLQ and videos have not been processed. Application logs show no errors. What change will prevent this problem?
- A video-processing application runs as a Node.js AWS Lambda function that is triggered by S3 when a new image is uploaded. The function downloads images from one S3 bucket, transforms them, writes the transformed image to a second S3 bucket, and updates metadata in DynamoDB. As image sizes increased, the Lambda function now frequently times out; the function timeout is already set to the maximum. The company does not want to manage servers. Which combination of changes should the solutions architect implement to avoid invocation failures? (Choose two.)
- A video-streaming company released a mobile app that uploads user video files to an Amazon S3 bucket in the us-east-1 Region. Files range from 1 GB to 10 GB. Users in Australia experience very slow uploads and occasional failed uploads. As a solutions architect, propose changes to improve upload performance for these users. Which two of the following will meet the requirement?
- A weather service hosts frequently updated high-resolution weather maps and static HTML in an S3 bucket in eu-west-1 and fronts the site with CloudFront. After expanding to serve users in us-east-1, users there sometimes experience slow map loading. Which combination of steps will resolve the us-east-1 performance issues? (Choose two.)
- A weather-data solution receives telemetry from thousands of stations via an API Gateway REST API integrated with a Lambda function. The Lambda calls a third-party service for preprocessing; when that third party becomes overloaded, preprocessing fails and data is lost. The architect must ensure no data is lost and enable processing to occur later if failures happen. What should the architect implement?
- A web application allows users to upload short videos. Videos are stored on EBS volumes and analyzed by custom recognition software. The site uses EC2 Auto Scaling for the web tier and a separate Auto Scaling group processing an SQS queue. The company wants to reduce operational overhead by using managed AWS services where possible and remove third-party software dependencies. Which re-architecture meets these goals?
- A web application generates dynamic content on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The company uses CloudFront with the ALB configured as the origin and Route 53 has an A record for www.example.com pointing to the CloudFront distribution. The solutions architect must make the application highly available and fault tolerant across Regions. Which solution meets this requirement?
- A web application in a VPC runs on EC2 instances behind an ALB that uses AWS WAF. An external customer must connect to the application, and the company must supply IP addresses to all external customers. Which approach provides IP addresses with the least operational overhead?
- A web application is moved from on-premises to AWS. The third-party API it calls allows only a single public CIDR block to be whitelisted by each client. The web application will run on EC2 instances in private subnets behind an ALB in public subnets. NAT gateways provide internet access for the private instances. How should the architect ensure the third-party API continues to accept calls from the migrated application using the same client IP block?
- A web application runs in a single AWS Region on microservices hosted on AWS Fargate (Amazon ECS) and uses an Amazon RDS for MySQL instance for data. Route 53 handles DNS. A CloudWatch alarm triggers an EventBridge rule when the application fails. Design a disaster recovery solution that provides recovery in a second Region and minimizes recovery time. Which approach meets the requirement?
- A web application runs on EC2 instances in an Auto Scaling group behind a public Application Load Balancer (ALB). Only users from a specific country should be able to access the app. The company also needs to log blocked access requests. The solution should require minimal maintenance. Which approach satisfies these requirements?
- A web application serves static content from an S3 bucket behind CloudFront and dynamic content via an ALB routing to EC2 Auto Scaling groups. The domain is in Route 53. During peak times some users receive HTTP 503 Service Unavailable errors from the ALB. The company wants to show a custom error page immediately when this error occurs, with minimal operational overhead. Which solution meets the requirement?
- A web application stores static assets in an S3 bucket in us-east-1. The company needs multi-Region resiliency and already created a second S3 bucket in another Region. Which solution provides the required resiliency with the LEAST operational overhead?
- A web application uses a CloudFront distribution to serve images from an S3 bucket. Third-party tools sometimes upload corrupted images into the bucket. The company has Python logic that reliably detects corrupted images and wants to integrate that detection with minimal latency between ingestion and when the content is served. Which integration approach meets this requirement?
- A web application uses Amazon API Gateway, AWS Lambda, and Amazon DynamoDB. After a marketing campaign, many requests have much longer response times. CloudWatch Logs for API Gateway show errors on 20% of requests. For the Lambda function, the Throttles metric is 1% and Errors is 10%. Application logs show that errors coincide with calls to DynamoDB. What change should the solutions architect implement to improve response times as traffic grows?
- A web application uses Amazon CloudFront with two custom origins: one origin forwards to an Amazon API Gateway HTTP API (which uses a JWT authorizer), and the other origin forwards to an Application Load Balancer (ALB). The application uses an OpenID Connect (OIDC) identity provider (IdP). A security audit finds that the API is protected by a JWT authorizer but the ALB accepts unauthenticated requests. How can the solutions architect ensure both backend origins accept requests only from authenticated users?
- A web-crawling process runs on a fleet of t2.micro EC2 instances. Instances poll an SQS queue of target URLs, crawl each URL in 10 seconds or less, and write results to a shared Amazon EFS file system mounted on every instance. URLs are added to the queue infrequently, and metrics show instances sit idle when the queue is empty. You must redesign for cost optimization. Which two changes together are most cost-effective?
- A website runs on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). An AWS WAF web ACL is associated with the ALB. The site is being targeted by application-layer attacks that cause sudden large traffic increases. WAF access logs show attacks originate from many different IP addresses. Which mitigation requires the LEAST operational overhead?
- A website runs on four EC2 instances behind an ALB. When the ALB marks an instance unhealthy, a CloudWatch alarm goes to ALARM and an operator manually adds a replacement instance. The company wants a highly available solution that automatically replaces failed EC2 instances while minimizing downtime during migration to the new design. Which sequence of steps should the solutions architect use?
- A Windows content-management application runs on a single EC2 instance in development and stores static content on a 2 TB EBS root volume. For production, the app must run on at least three EC2 instances across multiple Availability Zones, be joined to Active Directory, use Windows ACLs for file access, and maintain exactly the same content on all running instances at any time. The solution should minimize management overhead. Which design meets these requirements with the least operational work?
- A Windows desktop application is packaged for deployment to users’ Windows machines. The company acquired another organization whose employees primarily use Linux, and the company wants to rehost the Windows application on AWS with minimal development effort. All employees must authenticate before using the app, and the company uses on-premises Active Directory but wants simplified access management for AWS. Which solution rehosts the application on AWS with the least development work?
- A workload runs across thousands of EC2 instances in a VPC that has public and private subnets. Public subnets route 0.0.0.0/0 to an internet gateway; private subnets route 0.0.0.0/0 to a NAT gateway. You must migrate the fleet to IPv6 while ensuring instances in private subnets are not reachable from the public internet. What should the solutions architect do?
- A workload runs on Amazon EC2 Spot Instances in an Auto Scaling group. The launch template currently specifies two placement groups and a single instance type. Recently, Auto Scaling reported launch failures, causing longer wait times for users. To improve reliability of the Spot-based workload, which change should you make?
- Accompany is building a system to collect sensor data from hundreds of factory devices. Devices publish data every 5 seconds to AWS IoT Core. The data must be enriched before it is loaded into an Amazon S3 data lake and new sensor data must be available in S3 within 30 minutes of collection. No other applications consume the IoT Core messages. Which solution is the MOST cost-effective while meeting these requirements?
- Account A owns an S3 bucket with data files that must be accessed by a business partner’s IAM user (User_DataProcessor) in Account B. What steps must the companies take so User_DataProcessor can access the S3 objects from Account B? (Choose two.)
- After a merger, the company has multiple existing AWS accounts for different business units. A central management account sent invitations to member accounts to join an AWS Organization. The solutions architect must enable centralized billing and centralized access policy management. What is the next step to allow the management account to manage member accounts?
- After an acquisition, a company manages two AWS Organizations. In one organization it runs multiple service-provider applications exposed as AWS PrivateLink-powered VPC endpoint services; in the other it runs multiple service-consumer applications. The solutions architect finds data transfer charges are much higher than expected. Which developer deployment guidelines will reduce data transfer charges across the environment? (Choose two.)
- After an application update, your ALB intermittently returns 502 (Bad Gateway) errors caused by malformed HTTP headers. Reloading the page immediately usually succeeds. You want to present a custom error page to visitors while the root cause is being fixed, with the least operational overhead. Which combination of actions should you take? (Choose two.)
- After replatforming to AWS, a migrated server hosts a legacy SMTP service required by a critical app. The legacy SMTP server sends outbound email over unencrypted TCP port 25 and does not support TLS. The company validated an Amazon SES domain and removed SES sending limits. How should the application be changed to send outbound mail through Amazon SES?
- An administrator attached a service control policy (SCP) to an organizational unit (OU) that contains AWS account 1111-1111-1111. Developers in that account report they cannot create Amazon S3 buckets. What should the administrator do to resolve the issue so developers can create buckets?
- An Amazon EMR cluster (using EMRFS) runs critical batch work every day starting at 1:00 AM and takes about 6 hours. The cluster currently uses On-Demand instances for primary, core, and task nodes, and completion time is not urgent. The architecture should be reviewed to reduce compute costs. Which change should the solutions architect recommend?
- An Amazon Redshift cluster (using reserved nodes) is experiencing intermittent CPU-heavy bursts from complex read queries while a team runs a deep audit. The cluster must continue to serve read and write queries at all times. Which option provides the required burst capacity in the MOST cost-effective way?
- An Amazon WorkSpaces deployment uses Amazon FSx for Windows File Server as the profile share. The FSx file system is 10 TB and has reached maximum capacity, preventing new sessions. The solutions architect must restore user access and prevent recurrence. Which approach meets these requirements?
- An application built with Amazon API Gateway, AWS Lambda, and Amazon DynamoDB is returning increasing numbers of errors for PUT requests. Most PUT requests come from a small set of clients authenticated with API keys, and one client is generating many of the requests. The API is noncritical and clients can retry failed requests, but visible errors are damaging customer perception. What should you recommend to improve customer experience?
- An application currently reads and writes objects in a single Amazon S3 bucket. The company will deploy the application to a second AWS Region and wants the simplest solution with the least operational overhead to allow the application to operate across Regions. Which design meets these requirements?
- An application deployed on AWS Elastic Beanstalk uses Amazon Aurora and is fronted by a CloudFront distribution that uses the Elastic Beanstalk domain as its origin. CloudFront is configured with an alternate domain name that users access. Each week the application is taken offline for maintenance; during that time the company wants visitors to see an informational page (not a CloudFront error). The first step — creating an S3 bucket — is already done. Which three actions should the solutions architect take next to implement this behavior?
- An application generates reports and stores them in an Amazon S3 bucket. Users download reports via application-generated signed URLs. The security team discovered that the objects are publicly accessible and anyone can download them unauthenticated, so report generation was suspended. Which set of actions will immediately fix the security exposure without disrupting the application's normal download workflow?
- An application in the Source AWS account uses Lambda functions (deployed from deployment packages) and stores inventory in an Amazon Aurora cluster. Automated Aurora backups are enabled. The company needs to migrate the Lambda functions and the Aurora database to a Target AWS account with minimal downtime. Which approach satisfies these constraints?
- An application is experiencing inconsistent response times and higher error rates because synchronous calls to third-party services (invoked by an AWS Lambda function) are causing delays. You need to decouple third-party calls and ensure all calls are eventually completed. What is the appropriate solution?
- An application migrated to AWS has a static website frontend currently running on two EC2 instances behind an ALB and a Python backend on three EC2 instances behind another ALB. Instances are large On-Demand general-purpose types sized for on-premises peak load, but traffic is concentrated during lunchtime and light otherwise. The solutions architect must reduce infrastructure cost without harming availability. Which combination of actions should be taken? (Choose two.)
- An application on AWS uses an Amazon Aurora MySQL DB instance that is experiencing too many open connections. Most application operations are inserts. Database credentials are currently stored in a plaintext configuration file. The solutions architect must design a solution that handles the current connection load, secures credentials, and supports automatic credential rotation on a regular schedule. Which solution satisfies these requirements?
- An application requires an RPO under 5 minutes and an RTO under 10 minutes. The database is expected to be about 10 TB and must support failover to a secondary Region. Which database solution meets these business recovery objectives at the LOWEST cost?
- An application running on EC2 polls an Amazon EFS file system for new files. When a new file appears, the app selects a Docker container image to process the file, starts the appropriate container, and passes the file location. Processing can take up to 2 hours; when finished, the container writes the result back to EFS and exits. The company wants to remove the EC2 instances that run these containers. Which refactoring approach meets the requirement?
- An application running on ECS Fargate uses Amazon Aurora MySQL as its relational store. Regulatory requirements demand cross-Region recovery with no data loss and minimal operational overhead. Which solution meets these constraints with the least operational effort?
- An application runs as a ReplicaSet of multiple pods in an Amazon EKS cluster whose nodes span multiple Availability Zones. The app produces many small files that must be concurrently accessible from all replicas. Backups must be retained for 1 year. Which design provides the FASTEST storage performance while meeting these requirements?
- An application runs in us-east-1 across three Availability Zones behind an Application Load Balancer, and its MySQL database runs on an Amazon EC2 instance. The company requires a cross-Region disaster recovery design with an RTO under 5 minutes and an RPO under 1 minute. Application servers have been deployed in us-west-2 and Route 53 health checks with DNS failover to us-west-2 are configured. What additional action should the solutions architect take to meet the recovery objectives?
- An application runs on a single Amazon EC2 instance launched by an Auto Scaling group (min=1, max=1) in a private subnet. The application uses an Amazon RDS for MySQL DB instance. The VPC has subnets in three Availability Zones but only a single NAT gateway is deployed. The architect must ensure the application can operate across multiple Availability Zones. Which solution meets this requirement?
- An application runs on AWS with a MySQL database on an EC2 instance in a VPC with two private subnets, and a website on Apache Tomcat in a single EC2 instance in a different VPC with one public subnet. There is a VPC peering connection between the database and website VPCs. The website recently experienced multiple outages from high traffic. Which actions should a solutions architect take to improve application reliability? (Choose three.)
- An application runs on EC2 instances behind an Application Load Balancer in an Auto Scaling group. Because the application scales out and in frequently, instance logs disappear after scale-in. How can the development team retain and view application logs after instances are terminated by scale-in events?
- An application runs on EC2 instances in an Auto Scaling group and deployment uses AWS CodePipeline. Instances scale frequently, and during deployments the company installs the CodeDeploy agent on new instances and associates them with the CodeDeploy deployment group manually. The application must go live within 24 hours. What should a solutions architect recommend to automate deployments with the LEAST operational overhead?
- An application runs on EC2 instances in an Auto Scaling group behind an Application Load Balancer. Instance logs are copied to a central S3 bucket every 15 minutes. The security team found that logs from some terminated instances are missing. Which set of steps will ensure logs from terminating EC2 instances are copied to the central S3 bucket before those instances are terminated?
- An application runs on EC2 instances in an Auto Scaling group that currently specifies a single instance type. CPU and memory metrics show the instances are underutilized. You need to reduce EC2 cost permanently and improve utilization with the fewest future configuration changes. Which solution meets this requirement?
- An application runs on EC2 instances in private subnets behind an internet-facing Application Load Balancer (ALB). The ALB is the origin for a CloudFront distribution. A WAF web ACL (with AWS managed rules) is attached to the CloudFront distribution. The company wants to prevent any internet traffic from reaching the ALB directly. Which option accomplishes this with the least operational overhead?
- An application runs on EC2 instances that all share the same security group. The application must access an Amazon Aurora DB cluster that has its own security group. To provide least-privilege network access between the EC2 instances and the Aurora cluster, which combination of security group rules should be added? (Choose two.)
- An application stores several terabytes of unstructured data in an Amazon S3 bucket using the S3 Standard storage class. Data grows by several gigabytes per day. The company queries and analyzes this data but never accesses objects older than 1 year. For compliance, all data must be retained indefinitely. Which design is the most cost-effective while allowing queries over the data?
- An application uses an Amazon Aurora PostgreSQL DB cluster with one small primary instance and three larger read replicas. The app runs in an AWS Lambda function that opens many short-lived connections to the read replicas for read-only queries. During unpredictable high-traffic periods, the application becomes unreliable and the database reports too many connections. Which change will improve the application's reliability?
- An application uses an Amazon RDS for MySQL Multi-AZ DB instance in us-east-1. After performing a failover test, the application lost DB connections and could not reconnect; only after restarting the application did connections recover. Design a solution so the application can re-establish connections after a failover without requiring an application restart.
- An application uses an ElastiCache for Redis cluster for caching. The cluster already has encryption at rest enabled, but not encryption in transit, and clients can access the cache without authentication. A solutions architect must require client authentication and enable end-to-end in-transit encryption. Which solution meets these requirements?
- An application uses AWS KMS to encrypt data before placing it into an Amazon S3 bucket in one AWS Region. Company policy requires data be encrypted prior to upload and decrypted by the application on read. The S3 bucket is replicated to other Regions. The application must be able to encrypt and decrypt the data across Regions and use the same key for decryption in every Region. Which solution meets these requirements?
- An application uses AWS Lambda and ECS on Fargate and stores data in an Aurora MySQL database. The workload is write-heavy and traffic is highly spiky with long idle periods and sudden increases. The current memory-optimized DB instance cannot handle variable load. Which is the MOST cost-effective design to scale for these traffic patterns?
- An application will be exposed through an AWS Lambda function for hundreds of customers. Each customer must receive a configurable quota of requests over a specific time period, and quotas must reflect customer usage patterns (some customers need higher quotas for shorter periods). Which approach satisfies these requirements?
- An asynchronous HTTP application implemented as a Lambda function is invoked through a public API Gateway endpoint in us-east-1. You must redesign the application to support failover to another AWS Region. Which design meets this requirement?
- An AWS Organization has a single OU named Production that contains all accounts. Root-level deny-list SCPs are used to restrict access to certain services. A newly invited account from an acquired business unit cannot update existing AWS Config rules to comply with company policy. Which approach allows the new account administrators to make required changes now while preserving and enforcing the existing policies with minimal ongoing maintenance?
- An AWS partner (org1) is building a service that needs API/CLI access to resources in a customer account that belongs to a different AWS Organization (org2). The access must be least privilege and programmatic. What is the MOST secure way for org1 to access org2 resources?
- An e-commerce application receives and processes orders, then stores order data in Amazon DynamoDB. Traffic is sporadic but can spike during campaigns; the system must scale and process orders with minimal delay. Which design is the MOST reliable, simple, highly available, and loosely coupled way to receive and process orders?
- An ecommerce application exposes an API through Amazon API Gateway that invokes AWS Lambda functions. Data is stored in an Amazon RDS for PostgreSQL DB instance. During a flash sale, API calls spiked and the application slowed: CloudWatch showed many Lambda invocations, a large number of database connections, and high CPU on the DB instance. What should the solutions architect recommend to improve performance?
- An ecommerce application in a single Region uses a five-node Amazon Aurora MySQL cluster that handles many writes. The company must replicate the Aurora data to another Region for disaster recovery with an RPO of 1 hour and at lowest possible cost. Which solution provides the required replication at the lowest cost?
- An ecommerce site uses CloudFront, an Apache web server tier on EC2 instances in an Auto Scaling group, and an Amazon Aurora MySQL DB cluster. During a promotion users experienced errors and timeouts when adding items to carts. Some web servers were terminated before their logs could be collected, and Aurora metrics were insufficient for analyzing query performance. Which combination of actions improves visibility into application performance during peak traffic? (Choose three.)
- An education company uses Amazon WorkSpaces and stores user profiles on an Amazon FSx for Windows File Server file system. The FSx file system is joined to a self-managed Active Directory and uses a DNS alias. As user adoption grows, logon times have become unacceptably slow. The existing file system was created on HDD storage with 16 MBps throughput. A solutions architect must improve file system performance during a scheduled maintenance window with the least administrative effort. What should the solutions architect do?
- An enterprise wants developers to purchase approved third-party software only through a Private Marketplace in AWS Marketplace. The company uses AWS Organizations with all features enabled and has a shared-services account in each OU for procurement managers. Procurement administration must be limited to a role named procurement-manager-role (assumable by procurement managers). All other IAM users, groups, roles, and account administrators must be denied Private Marketplace administrative access. What is the MOST efficient architecture to meet these requirements?
- An environmental company deploys air-quality sensors across major cities. Sensors use AWS IoT Core to ingest time-series readings and the company stores the data in Amazon DynamoDB. For business continuity, they must be able to ingest and store data in two AWS Regions. Which solution satisfies this requirement?
- An event-driven ordering system uses an Amazon SQS standard queue. During testing, processing stopped because a single order message caused a backend error and blocked subsequent messages. The queue visibility timeout is 30 seconds, while backend processing times out after 10 seconds. A solutions architect must allow investigation of faulty messages and ensure subsequent messages continue to be processed. What should the solutions architect do?
- An events company runs a ticketing platform on an Amazon ECS cluster composed of EC2 On-Demand Instances in an Auto Scaling group that uses predictive scaling. The company knows event dates and times in advance, and events cause large traffic spikes. The ECS cluster frequently downloads ticket assets from an Amazon S3 bucket that is in the same AWS Region and account; traffic currently flows across a NAT gateway. The company wants to reduce costs without lowering availability. Which combination of steps will meet these requirements? (Choose two.)
- An existing application currently reads database credentials from an encrypted file in Amazon S3. For the next version, the security engineer requires: strong randomly generated database passwords stored in a secure AWS-managed service; deployment of application resources via AWS CloudFormation; and automated credential rotation every 90 days. You will author a CloudFormation template to deploy the application. Which CloudFormation resources satisfy these requirements with the LEAST operational overhead?
- An external security audit found that many AWS Lambda execution roles in a serverless app have overly broad IAM policies (for example, full S3 and DynamoDB access). The company wants each function to have only the minimal permissions needed. A solutions architect must determine the exact permissions each Lambda function requires with the least effort. What should the architect do?
- An HPC cluster on AWS runs a tightly coupled workload that produces many shared files on Amazon EFS. Performance was acceptable with 100 EC2 instances but dropped significantly at 1,000 instances. Which set of design choices will maximize cluster performance? (Choose three.)
- An image-processing service runs in a VPC across two Availability Zones. Each AZ has a public and a private subnet. EC2 instances run in the private subnets and are fronted by an ALB in the public subnets. The service needs internet access and uses two NAT gateways. Images are stored in Amazon S3 and the EC2 instances retrieve approximately 1 ■■ of data from the S3 bucket each day. The company emphasizes a high security posture. The solutions architect must minimize costs without weakening security or increasing operational overhead. Which solution meets the requirements?
- An IoT platform ingests sensor data via Node.js API servers on EC2 behind an Application Load Balancer and stores it in an RDS MySQL instance on a single 4 TB General Purpose SSD. Sensor count is growing; API servers are overloaded and RDS shows high write latency. Which two actions together provide a permanent, scalable, and cost-efficient resolution as more sensors are added?
- An on-premises analytics platform runs across 12 servers in a fully redundant configuration. It handles scheduled jobs (hourly and daily) that take 20 minutes to 2 hours and have strict SLAs (65% of load) and ad-hoc user jobs that finish within 5 minutes and have no SLA (35% of load). During failures, scheduled jobs must preserve SLAs while user jobs can be delayed. You must move to EC2 and use consumption-based pricing with no long-term commitments, maintaining high availability and SLAs for scheduled jobs at minimal cost. Which option is the most cost-effective while meeting requirements?
- An on-premises application uses a shared SMB file share for data. The company will migrate file storage to an Amazon S3 bucket but the application must continue to access the data over SMB until the application is rewritten to use native S3 APIs. The solution must migrate the data to AWS while allowing the on-premises application to keep accessing it via SMB. Which design meets these requirements?
- An on-premises application writes thousands of images nightly to a mounted NFS share. After migration the application will run on EC2 with an Amazon EFS mount. A Direct Connect link exists. Prior to cutover, what is the most operationally efficient way to replicate newly created on-premises images to the EFS file system?
- An on-premises application writes to an SMB file share and creates a copy on a second SMB share in the same data center. The files are metadata files and image files. The company wants to store the copy on AWS and be able to access the data via SMB from either the data center or AWS in a disaster. The copy is infrequently accessed but must be available within 5 minutes. Which solution meets these requirements?
- An on-premises Java web application uses MongoDB to store subscriber data. The company must migrate the application to AWS with the same architecture, deploy it for high availability, and cannot change the application code. Which AWS-based architecture will meet these requirements?
- An on-premises Microsoft SQL Server creates a nightly 200 GB export to a local drive. The company wants to store these backups in Amazon S3. A 10 Gbps AWS Direct Connect link exists between the data center and AWS. Which approach is the MOST cost-effective way to meet the requirement?
- An on-premises order-processing platform uses a web front end (VMs), RabbitMQ for messaging, and a Kubernetes cluster for the containerized backend. The company wants to migrate to AWS without making major application changes and with the least operational overhead. Which architecture meets these constraints?
- An on-premises SaaS provider accepts several files daily via multiple public SFTP endpoints. Customers have added the SFTP endpoint IP addresses to their outbound firewall allow lists and cannot change those allowed IPs. The company wants to migrate to AWS and reduce operational overhead while preserving the existing source IPs customers allow. Which solution satisfies these requirements?
- An on-premises VPN provides employees remote access to their Windows home directories. Remote workforce growth has saturated the data center VPN bandwidth during business hours. The company needs an AWS solution that supports more remote users, reduces on-premises VPN bandwidth usage, and minimizes operational overhead. Which combination of steps achieves this with the least operational overhead? (Choose two.)
- An online gaming company runs production gaming EC2 instances that must remain available year-round and an analytics application that is interruptible and uses S3 data. Which cost-optimized approach meets these needs?
- An online magazine is launching its first global edition and expects a large spike in traffic. Current architecture: ALB, EC2 web/app servers, and Amazon Aurora MySQL; much of the site is read-heavy and some static content exists. Performance for a global audience is the top priority for the week after launch. Which combination of actions should a solutions architect take to reduce response times globally? (Choose two.)
- An online retailer presently runs a stateful web application and MySQL database on a single on-premises server. To handle increased traffic from marketing campaigns, the company will migrate to AWS and needs the HIGHEST level of reliability. Which architecture offers the greatest reliability?
- An online survey application runs as microservices in an auto-scaling Amazon ECS cluster behind an Application Load Balancer (ALB). The ALB is a custom origin for an Amazon CloudFront distribution. One survey collects sensitive data that must be encrypted while it moves through the application. Only the data-handling microservice should be able to decrypt that data. Which solution satisfies these requirements?
- An operational workload runs on Amazon EC2 instances in an Auto Scaling group. The VPC spans two Availability Zones (AZs), with one subnet in each AZ targeted by the Auto Scaling group. The VPC is connected to on-premises infrastructure and that connectivity must not be disrupted. The Auto Scaling group maximum is 20 instances. The current IPv4 addressing is: VPC 10.0.0.0/23, AZ1 subnet 10.0.0.0/24, AZ2 subnet 10.0.1.0/24. A third AZ is now available in the Region. You must add the new AZ for the Auto Scaling group without adding IPv4 address space and without service downtime. Which approach satisfies these constraints?
- An organization centrally manages hundreds of AWS accounts with AWS Organizations. Product teams now create and manage S3 Access Points in their accounts. All S3 Access Points must be accessible only from VPCs (no internet access). What is the most operationally efficient way to enforce this requirement across the organization?
- An organization has 10 AWS accounts in AWS Organizations. Each account runs AWS Config and belongs to either the Prod OU or the NonProd OU. Each account has an EventBridge rule that notifies an SNS topic when an EC2 security group inbound rule is created with source 0.0.0.0/0; the security team subscribes to the SNS topic. For all NonProd OU accounts, the security team must remove the ability to create security group inbound rules that allow 0.0.0.0/0. Which approach achieves this with the LEAST operational overhead?
- An organization has hundreds of AWS accounts grouped into OUs for each engineering team. Each OU owns multiple accounts. The solutions architect must provide each OU with a breakdown of usage costs across the accounts that OU owns. Which solution meets this requirement?
- An organization has many AWS accounts organized under AWS Organizations. A transit account hosts a shared Transit Gateway and Site-to-Site VPN connections from the company’s global offices. The networking team must centrally manage a list of internal IP ranges (the global offices’ networks) so developers in other accounts can reference that list when granting access. Which solution provides this centralized list with the least operational overhead?
- An organization has multiple AWS accounts under AWS Organizations. Each account hosts VPCs, EC2 instances, and containers. The compliance team runs a security tool in each VPC on EC2 instances and aggregates results into a dedicated compliance account. All compliance resources are tagged with costCenter=compliance. The company needs an accurate cost calculation for those security tools so the compliance team’s account can be charged. What should a solutions architect do?
- An organization manages hundreds of AWS accounts using AWS Organizations. A solutions architect needs to implement baseline protection against the OWASP Top 10 web application vulnerabilities using AWS WAF for all current and future Amazon CloudFront distributions in the organization. Which combination of actions should the solutions architect take to provide that baseline protection? (Choose three.)
- An organization manages more than 1,000 AWS accounts with AWS Organizations. A new developer organization must receive 540 existing developer member accounts. Each account is fully configured to operate independently. What sequence of steps should a solutions architect take to move all developer accounts into the new developer organization? (Choose three.)
- An organization manages multiple AWS accounts in AWS Organizations. The company needs a daily alert to the architecture team when Amazon EC2 usage is more than 10% higher than the average EC2 usage over the previous 30 days. Which solution accomplishes this requirement?
- An organization runs two firewall appliances in a centralized networking account. Each firewall runs on a manually configured, highly available EC2 instance. A Transit Gateway connects that VPC to member account VPCs. Each firewall uses a static private IP used by member-account route tables to route internet-bound traffic. A misconfigured script previously terminated both firewall instances. When rebuilding, the company now has a startup script to configure the firewall software. The organization needs a more modern, horizontally scalable deployment while continuing to use the vendor firewall (the vendor confirms compatibility with AWS services). Which combination of actions provides the most cost-effective, scalable solution? (Choose three.)
- An organization uses AWS Organizations to manage accounts and deploys all infrastructure with AWS CloudFormation. The finance team needs chargeback reporting and asked business units to tag resources with a predefined list of project values. When finance filtered the AWS Cost and Usage Report by project, they found noncompliant project tag values. The company wants to enforce the allowed project tag values for new resources with the least effort. What should you do?
- An organization uses AWS Organizations to manage multiple AWS accounts. A solutions architect must enforce a policy where only administrator roles can perform IAM actions across the organization. The architect does not have access to every AWS account. Which approach enforces this with the least operational overhead?
- An organization uses AWS Organizations with consolidated billing and OUs for Finance, Sales, HR, Marketing, and Operations. Each department has accounts for dev, test, pre-prod, and production. The HR department purchased Reserved Instances (RIs) in its production account for a system that will launch there. HR needs to ensure other departments cannot share those RI discounts. Which action accomplishes this?
- An organization uses AWS Organizations with separate accounts for finance and marketing. The finance team’s data processing app (in the finance account) uses Lambda and stores confidential data in a DynamoDB table. The marketing team (in a different account) must have access to only specific attributes of that DynamoDB table. How should a solutions architect provide the marketing team the required limited access?
- An organization uses AWS Organizations with two OUs under the root: Research and DataOps. Regulatory rules require that all resources in the organization be created only in the ap-northeast-1 Region. Additionally, EC2 instances launched in accounts under the DataOps OU must be limited to a predefined set of instance types. The solution must be efficient to operate and require minimal ongoing maintenance. Which combination of actions will enforce these constraints? (Choose two.)
- An organization uses multiple AWS accounts for VPC-hosted internal applications. A security team maintains a central allow list of internal IP CIDR ranges and currently notifies other account owners when the allow list changes. Developers in each account add CIDR ranges into their security groups. The solutions architect must distribute the common CIDR ranges across all accounts with the least operational overhead. Which approach meets this requirement?
- An unauthenticated static website (www.example.com) hosted on Amazon S3 and delivered via CloudFront uses AWS WAF. The site includes a registration form that calls an Amazon API Gateway endpoint, which invokes a Lambda function that forwards data to an external API. During testing, the submission triggers a CORS error. The CloudFront origin is configured to include an Access-Control-Allow-Origin header set to www.example.com. What should the solutions architect do to fix the CORS error?
- Data scientists use Amazon SageMaker instances and APIs inside a VPC that has no internet access. Training datasets are in Amazon S3 and accessed via interface VPC endpoints for S3 and SageMaker APIs. Occasionally the team needs access to the public Python Package Index (PyPI) to update packages. The SageMaker instances must remain isolated from the internet. Which solution provides PyPI access while keeping the VPC isolated?
- Design a reference architecture for three-tier applications (web, application, NoSQL) that must be highly available within a Region, support failover to another Region within 1 minute for disaster recovery, and minimize user impact and cost. Which combination of actions meets these goals? (Choose three.)
- Developers in multiple AWS accounts in your Organization can create VPCs and launch EC2 instances in a single Region. Each EC2 instance downloads about 1 TB/day from S3, causing high inter-account data-transfer and NAT gateway charges plus compute costs. The company wants to proactively enforce approved architectural patterns (for example, using gateway endpoints) across developer accounts without slowing developer velocity, and do this cost-effectively. Which solution best meets these requirements?
- DNS records for example.com are in a private Route 53 hosted zone in Account A. Applications and databases run in Account B. You are deploying a two-tier app in a new VPC in Account B and created a db.example.com CNAME record in the private hosted zone in Account A for the RDS endpoint. The application EC2 instance cannot resolve db.example.com, although the record is correct in Route 53. What steps should you take to fix name resolution? (Choose two.)
- Drivers upload delivery confirmation (signature photos) via FTP from handhelds to a single EC2 instance. Each device writes files into user-specific directories; the EC2 instance queries a central DB to add metadata, then archives the file to S3. As volume grows, the FTP server on the EC2 instance is dropping connections and failing; a cron reboot was used as a temporary workaround. Devices cannot be changed. Design a scalable solution that guarantees files reach the archive and that backend systems are updated.
- During a game launch, a company ran 12 r6g.16xlarge (memory optimized) Amazon EC2 instances behind a Network Load Balancer. Monitoring showed actual usage at about one quarter of the CPU and memory expected. Demand has now dropped and become more variable. The company will replace the fixed fleet with an Auto Scaling group that scales based on CPU and memory to minimize cost. Which Auto Scaling configuration is the most cost-effective while meeting the requirements?
- Example Corp. has an on-premises data center connected to VPC A in their AWS account via a Site-to-Site VPN. Example Corp. acquired AnyCompany, which has VPC B. There is no IP overlap. VPC A and VPC B are peered. On-premises servers can reach VPC A but cannot reach VPC B. Network ACLs and security groups are configured correctly. Which solution provides connectivity from on-premises to VPC B with the least operational effort?
- External auditors in a single AWS account need secure, read-only access to the company's AWS account for financial audits. The solution must follow AWS security best practices. Which approach should the solutions architect implement?
- In a multi-account AWS Organization, the sales account stores petabytes in an S3 bucket encrypted with a KMS key. The marketing account uses Amazon QuickSight and needs access to the sales S3 data. Marketing has already created the QuickSight service role in its account. You must provide secure cross-account access with the least operational overhead. Which solution is best?
- In a multi-account AWS Organizations environment, a solutions architect must allow an IAM user in Account A to assume a role in Account B. The environment already uses SCPs, resource-based policies, identity-based policies, trust policies, and session policies. Which combination of steps is required? (Choose three.)
- Mobile banking apps are running on Amazon EC2 instances in a VPC and need to resolve DNS names in an on-premises Active Directory domain. The on-premises data center connects to AWS over AWS Direct Connect. Which option provides DNS resolution to the on-premises AD domain for instances in the VPC with the least administrative overhead?
- More than 10,000 sensors publish data using MQTT to an on-premises Apache Kafka cluster that transforms the data and stores results in Amazon S3. The Kafka server recently crashed and data was lost during recovery. The company needs a highly available, scalable AWS design to avoid future data loss. Which solution satisfies these requirements?
- Multiple development teams deploy production workloads into a shared production AWS account. Recently, members of one development team terminated an EC2 instance belonging to another team. Developers use SAML federation via AWS Organizations to assume roles. You must prevent developers from managing instances belonging to other teams while still allowing them to manage their own instances. Which strategy meets these requirements?
- Sensors mounted across factories stream environmental data (humidity, light, etc.) to AWS. The company needs real-time streaming and analysis, and must immediately notify the operations team when any parameter falls outside acceptable ranges. Which design meets these requirements?
- The CISO requires CI/CD changes so patch deployments happen as quickly as possible with minimal downtime and the ability to roll back quickly. The web app runs on a fleet of EC2 instances behind an Application Load Balancer. Source is on GitHub; builds use an existing CodeBuild project; CodePipeline will trigger builds from GitHub. Which CI/CD deployment configuration satisfies the requirements?
- The company has migrated development and production workloads into a new AWS Organization and created separate member accounts for dev and prod. Consolidated billing is linked to the management account. The solutions architect must create an IAM user in the management account that can stop or terminate resources in both member accounts. Which approach fulfills this requirement?
- The company is backing up EC2 instances, Amazon EFS file systems, and Amazon RDS DB instances and must meet these constraints: custom daily/weekly/monthly retention; immediate cross-Region replication of backups; a single view of backup status across the environment; immediate notifications on any backup failure. Which combination of steps meets these requirements with minimal operational overhead? (Choose three.)
- The company must connect its on-premises data center to AWS and link all VPCs across multiple Regions with transitive routing between VPC networks. The solution should reduce outbound network costs, increase bandwidth, and provide a consistent network experience for users. Which design meets these requirements?
- The company must monitor many Amazon S3 buckets across two AWS Regions and report the percentage of objects that are encrypted. Compliance teams need a single dashboard showing these metrics. Which approach meets the requirements with the least operational overhead?
- The company registered 10 domains used for marketing. Each domain should redirect visitors to a specific target URL; the domains and their target URLs are stored in a JSON document. DNS is managed in Amazon Route 53. You must implement a redirect service that accepts HTTP and HTTPS requests and requires minimal operational effort. Which combination of steps should you take? (Choose three.)
- The company uses an on-premises Active Directory for authentication and wants employees to sign in to all AWS accounts in an AWS Organizations setup using the same identities. Site-to-Site VPN already connects the on-premises network to every AWS account. Company policy requires conditional access based on AD groups and roles, and all user identities must be managed in a single place. Which approach satisfies these requirements?
- The company uses AWS Organizations to manage multiple accounts. Every EC2 instance must include a BusinessUnit tag for cost allocation. An audit found some instances missing the tag and the company manually added them. How should a solutions architect enforce the BusinessUnit tag going forward?
- The company wants a business-continuity plan in AWS in case their main on-premises application (running on physical servers that also host other apps) fails. The app uses MySQL and the OSs are EC2-compatible. Which approach provides the required continuity with the least operational overhead?
- The company wants to enforce standardized tags with specific values when users create resources across the AWS Organization. Each organizational unit (OU) requires distinct tag values. What approach will enforce these tagging requirements?
- The company wants to require Amazon EBS encryption at rest for existing production accounts and for any production accounts created in the future. They want a solution that includes built-in blueprints and guardrails. Which combination of steps will achieve this? (Choose three.)
- The Creative team stores images in an S3 bucket in the Creative account and uses a custom AWS KMS key attached to that bucket. The Strategy account needs read-only access to view objects. A cross-account IAM role named strategy_reviewer exists in the Strategy account. When users assume strategy_reviewer and attempt to read objects, they get Access Denied. You must grant the Strategy account only the minimum required permissions. Which combination of steps should you take? (Choose three.)
- The QA manager currently launches application test environments using a CloudFormation template in an AWS account by assuming a role with CloudFormation, EC2, and Auto Scaling permissions. The QA department wants testers to be able to launch their own short‑lived environments, but testers should not receive broad permissions. Which setup will meet these goals?
- The security team must be notified only when an Amazon S3 bucket becomes publicly exposed in a newly acquired AWS account. The company already has an SNS topic with the security team’s email subscription. Which approach will send notifications only when a bucket is publicly exposed?
- To meet regulatory requirements, a solutions architect must design a solution that stores the company's critical data in multiple public AWS Regions (including the U.S.) and provides access to that data from the company’s global WAN. Security requires that traffic to this data must not traverse the public internet. Which design provides a highly available, cost-effective solution that meets these constraints?
- Two business units in separate AWS accounts share sensitive documents. Each account has an S3 bucket and the company configured low-way replication between the buckets. Neither bucket currently has encryption at rest enabled, and policy requires SSE-S3. The buckets contain millions of objects. What is the most operationally efficient way to enable SSE-S3 for existing objects and meet the policy?
- Using AWS Control Tower, a company has an OU that contains multiple AWS accounts. The company must ensure that no new or existing Amazon EC2 instances in those accounts can obtain a public IP address. Which solution enforces this requirement?
- Using AWS Organizations, a solutions architect from the management account used the IAM user Support1 to create a new member account with email finance1@example.com. What is the recommended method to create IAM users in that newly created member account?
- You are auditing security for a Lambda function that retrieves the latest changes from an Amazon Aurora database. Both Lambda and the DB are in the same VPC. Database credentials are provided through Lambda environment variables. The Lambda function aggregates data and writes it to an S3 bucket encrypted with SSE-KMS. Data must not traverse the Internet. If database credentials are compromised, the company wants to minimize impact. What should you recommend?
- You are converting an existing, ephemeral nonproduction AWS environment into a CloudFormation template. The environment includes an EC2 instance whose instance profile allows it to assume a role in a parent account. You recreated the role in a CloudFormation stack (using the same role name) and deployed the stack in the child account. Afterwards, the EC2 instance cannot assume the role in the parent account due to insufficient permissions. What should you do to fix the problem?
- You are defining DNS behavior for an existing VPC that uses CIDR 10.24.34.0/24 and Route 53 Resolver. New requirements state that DNS resolution inside the VPC must use private hosted zones only, while instances that receive public IP addresses must also be assigned corresponding public hostnames. Which configuration ensures correct name resolution within the VPC?
- You are designing a mobile timesheet application. Employees submit timesheets weekly, with most submissions on Fridays. Payroll administrators must run monthly reports from the stored data. The infrastructure must be highly available and scale with incoming submissions and reporting demand while minimizing operational overhead. Which combination of steps meets these requirements? (Choose two.)
- You are designing a new TCP-based service that must be highly available across Availability Zones and reachable via the publicly resolvable DNS name my.service.com. The service uses a fixed TCP port and requires fixed IP addresses that external partners will whitelist. Resources are deployed across multiple Availability Zones in a single Region. Which design meets these requirements?
- You are designing storage for a new global application that ingests millions of small records per minute from devices. Each record is under 4 KB, must be stored durably with low-latency retrieval, and is retained only for 120 days. Estimated annual storage is 10–15 TB. Which storage approach is the most cost-effective while meeting requirements?
- You are migrating a two-tier, stateful web application to AWS using Aurora PostgreSQL for the database, EC2 Auto Scaling for the application tier, and Elastic Load Balancing. The application requires a consistent user experience as both the application and database tiers scale. Which configuration will provide consistent session behavior and allow both tiers to scale appropriately?
- You built a web application that uses an API Gateway Regional endpoint and an AWS Lambda function. Consumers are near the Region. The Lambda function queries an Amazon Aurora MySQL database that has three read replicas. Under high load, the application opens many database connections and fails to meet performance targets. Which actions should you take to improve performance? (Choose two.)
- You must deploy an application across two AWS Regions simultaneously and keep the objects in the two S3 buckets synchronized. Choose the combination of steps that meets the requirement with the LEAST operational overhead. (Choose three.)
- You must design a hybrid DNS solution that uses an Amazon Route 53 private hosted zone for cloud.example.com for resources inside VPCs. On-premises systems must resolve and connect to cloud.example.com. All VPCs must be able to resolve cloud.example.com. There is an existing AWS Direct Connect link to an AWS Transit Gateway. Which architecture provides the HIGHEST performance to meet these requirements?
- You must design a multi-Region architecture for an Amazon RDS for PostgreSQL database used by a web application. The database is deployed from a CloudFormation template that exists in both the primary and secondary Regions. Automated backups are enabled. Recovery objectives: RTO = 15 minutes, RPO = 2 hours. The web app uses an Amazon Route 53 record to route traffic to the database. Which two actions together will produce a highly available, compliant architecture? (Choose two.)
- You must design an event-processing solution that scales automatically with the number of incoming events and, on processing failure, moves the problematic event to a separate queue for later review. Which architecture meets these requirements?
- You must implement client-side encryption for objects uploaded to a new Amazon S3 bucket using a customer master key (CMK) in AWS KMS. An IAM role has a policy attached, and tests show the role can read existing test objects from the bucket, but uploads fail with a forbidden error. Which KMS action must be added to the IAM policy so uploads succeed while meeting requirements?
- You must migrate a legacy on-premises application to AWS. The application runs on two servers behind a load balancer. The software requires a license file tied to the server NIC MAC address; the vendor takes 12 hours to issue a new license file. The application also uses configuration files that reference the database server by static IP address (hostnames are not supported). Which combination of steps will provide a highly available architecture for the application servers in AWS? (Choose two.)
- You must store a large quantity of archived documents and make them available to employees via the corporate intranet. Employees access the system over a client VPN into a VPC. The data must not be publicly accessible. The documents are copies of physical-media data, request rate will be low, and retrieval speed and availability are not a concern. Which solution provides the required access at the lowest cost?
- You need to refactor a traditional EC2-hosted web application into container-based microservices in two separate environments (production and testing). Load varies but you know the minimum and maximum expected load. You want a serverless design that minimizes operational overhead and is most cost-effective. Which solution should you choose?
- You provide a REST API through Amazon API Gateway integrated with Lambda functions and store API data in DynamoDB. You want the API to be able to fail over to another AWS Region. Route 53 is used for DNS and weather.example.com already exists. Which design meets the requirement for cross-Region failover?
- You run a multi-tier web app on EC2 instances behind an ALB in a primary Region. The ALB and Auto Scaling group are replicated in a backup Region, but the Auto Scaling group min and max are both set to zero. An RDS Multi-AZ instance stores data and has a read replica in the backup Region. Route 53 provides the user endpoint. You need to reduce RTO to under 15 minutes and enable automatic failover to the backup Region without an active-active strategy. What should you recommend?
- Your company has a single 1 Gbps AWS Direct Connect link to one AWS Region. It uses a single private virtual interface that connects to one VPC. You must add a redundant Direct Connect connection in the same Region and enable connectivity to additional Regions using the same pair of Direct Connect connections as you expand. Which solution satisfies these requirements?
- Your environment includes on-premises servers and Amazon EC2 instances that use various patching tools. Management requires a single consolidated report showing the patch status across both on‑premises servers and EC2 instances. Which actions should a solutions architect take to meet this requirement?
- Your organization manages multiple AWS accounts with AWS Organizations. The infrastructure team owns a dedicated infrastructure account that contains a VPC to serve as the common network. Individual accounts must not manage their own networks, but they must be able to create resources inside subnets provided by the shared network. Which combination of actions should you perform to meet these requirements? (Choose two.)
Amazon Sponsored Ads All exam questions
- A bid is the average amount that you’re willing to invest for a click or view of your ad.
- A daily budget is the average amount that you’re willing to spend each day and is calculated over what timeframe?
- A new Kitchen Smart ad has the call-to-action (CTA) to "shop now before it's too late." Based on Amazon sponsored ads policies, would this ad be approved?
- Accent Athletics only sells recycled footwear and they want their match type to be very specific to that product. Which keyword targeting method should they use?
- Accent Athletics submitted a new Sponsored Brands ad that says "Amazing deal! $75 off today only!" Based on Amazon sponsored ads policies, would this ad be approved?
- Alejandro wants to advertise handmade hairbrushes and wants to target similar products with 4-5 star ratings. Which targeting method should they use?
- An ad for Organique isn’t receiving enough impressions. What bid adjustment would help make the ad more competitive and display it to more customers?
- Based on Amazon sponsored ads policies, is political content allowed in ad campaign copy?
- Based on sponsored ads campaign policies, approved ad copy can include the following:
- Based on sponsored ads campaign policies, prohibited content includes the following:
- Businesses in the U.S. that have a Brand Store on Amazon will automatically be enrolled in which solution?
- For their campaign targeting strategy, Márcia wants to limit the products contained in "gourmet candies." How can they limit the products in this category?
- Gordon's Chocolat i er's new ad says "Great savings on truffles." Based on Amazon sponsored ads policies, would this ad be approved?
- How would you describe a benefit to advertisers adhering to Amazon sponsored ads policies when building advertising campaigns?
- If Accent Athletics' business objective is to improve customer loyalty, what type of solution would meet their needs?
- If Gordon's Chocolat i er's business objective is to increase sales and conversion, what type of ad solution would meet their needs?
- If Iris has a business goal to link customers to their website so they can order pizza, which recommended ad solution would meet their needs?
- If Jack & Jill's business objective is to drive traffic to their product detail pages, what type of ad solution would meet their needs?
- If Jorge has multiple campaigns, where can they quickly access a specific campaign?
- If Jorge's business goal is to increase sales and conversion rates, which ad solution can help them?
- If Kitchen Smart's business objective is to reach more customers, what type of ad solution would meet their needs?
- If Saanvi's business goal is to encourage repeat purchases and improve customer loyalty as part of an always-on brand strategy, which solution can help them?
- If Super Power Batteries' business objective is to reach more customers, what type of ad solution would best meet their needs?
- If you already know the high-performing keywords in your campaign, which keyword targeting method should you consider?
- If you want to modify multiple campaigns at once, which component of the campaign manager tab should you use?
- Iris Cameras is new to Amazon ads and planning their first Sponsored Products campaign. Which bid type should they use to make their bids more competitive and improve the chance for their ad to be displayed?
- Iris has a new logo that includes a custom photo of a traveler using their camera on safari and taking a photo of a lion. Based on Amazon sponsored ads policies, would this ad be approved?
- Jack & Jill doesn't sell their products in the Amazon store. What solution can help grow their business?
- Jane wants to run their Sponsored Brands campaign as always on, without an end date. What budget option should she use?
- John sets his Sponsored Products ad daily budget to $500 USD. What is his potential spend for a 30-day month?
- Li Juan wants to prevent an ad from being served if customers look for an exact word. Which keyword targeting method should they consider?
- Manual targeting is available for Sponsored Products.
- Match the bidding strategy to the definition. Amazon will increase your bids in real time for clicks that may be more likely to convert to a sale, and reduce them for clicks that are less likely to convert to a sale.
- Match the bidding strategy to the definition. Amazon will reduce your bids in real time for clicks that may be less likely to convert to a sale.
- Match the bidding strategy to the definition. Amazon will use your exact bid for all opportunities and won’t adjust your bids based on likelihood of a conversion.
- Match the customer action example with the sponsored ad solution for improving customer loyalty: Writes a product review
- Organique is about to launch their first sponsored ads campaign and are unsure how customers will find their new specialty beauty product. Which keyword targeting method should they consider?
- Richard's campaign received a high number of clicks in the first couple of hours of the day and used up their small daily budget. How will this affect their campaign?
- Select the advertising console tab you would use to access Brand Metrics, a visual experience to help identify opportunities to drive shoppers from awareness to conversion.
- Select the advertising console tab you would use to access custom recommendations based on your campaigns, account activity, and shopper trends.
- Select the advertising console tab you would use to access translation features.
- Select the advertising console tab you would use to create a Brand Store.
- Select the advertising console tab you would use when you want to make changes across various campaigns.
- Select the phrase that describes the value behind Amazon sponsored ads policies.
- Shirley wants to target specific products that are similar and/or related to her product. Which targeting method should they use?
- Sponsored ads can help get your advertising messages in front of consumers where they are actively spending time and open to discovering new brands and products.
- Sponsored Brands can help drive traffic to your Brand Store.
- Sponsored Display and Sponsored TV campaigns buying model is setting a bid amount per thousand viewable impressions (vCPM).
- Sponsored Products, Sponsored Display, and Sponsored TV campaigns operate on a daily budget, while Sponsored Brands campaigns can operate either on a daily budget or a lifetime budget.
- Super Power Batteries includes has an ad that includes a direct comparison to competitor brands. Based on Amazon sponsored ads policies, would this ad be approved?
- Superpower Batteries has insights about which keywords audiences are frequently reviewing. Which keyword targeting method should they consider?
- What information is required to create an advertising console account?
- What is a benefit of choosing a daily budget over a lifetime budget for a campaign?
- What is a benefit of using sponsored ads?
- What is a requirement for ads that contain holiday messaging?
- What is Amazon's core principle that guides its sponsored ads policies?
- What is one general policy requirement for sponsored ads?
- What is one reason your sponsored ad submission may result in your campaign being rejected?
- What is one way that Sponsored Brands can reach customers while they shop?
- What is one way that Sponsored Display can reach customers while they shop?
- What is the minimum daily budget for a Sponsored Products campaign?
- What is the minimum lifetime budget for a Sponsored Brands campaign?
- What is the primary purpose of the advertising console?
- What phrase best describes Amazon sponsored ads?
- What will happen if you use the same email for your sponsored ads account as your seller central account?
- When targeting by individual product, which filter would Liu adjust if they want to target a complementary product to the one in their ad?
- Where can you monitor your campaign's performance?
- Where do sponsored ads help reach shoppers?
- Where would an advertiser go to access the advertising console?
- Where you can organize groups of campaigns?
- Which action is a benefit of automatic targeting with sponsored ads?
- Which action is a benefit of manual targeting with Sponsored Products?
- Which automatic targeting option may show your ad to shoppers who view the detail pages of products similar to yours?
- Which benefit applies when advertisers adhere to Amazon sponsored ads policies?
- Which bidding strategy may deliver more conversions for your ad spend?
- Which of the following sponsored ads solutions can help advertisers reach more customers and build brand awareness.
- Which solution will help ensure a company's new product will appear within shopping results and product detail pages?
- Which sponsored ad solution would help increase your sales in the Amazon store?
- Which targeting option should an advertiser use if they are new to Sponsored Brands?
- Which type of advertiser brands can use Sponsored TV?
- Why are Amazon sponsored ads policies important?
- You can use multiple sponsored ads solutions together to help drive business objectives.
- Zhang wants to prevent their ads from appearing on irrelevant shopping results and product detail pages. Which targeting method should they use to designate products where the ad should not be served.
Amazon Sponsored Ads Advanced All exam questions
- A campaign is seeing an increase in ad clicks but few conversions. What could be causing this?
- Accent Athletics is running a Sponsored Display campaign for their running shoes. What action can they take to optimize the ad creatives to increase sales?
- Accent Athletics wants to drive loyalty among shoppers for their most popular running shoes with new color options. Which of the following sponsored ads video products is best suited to help them reach their business goal?
- Amazon Video Builder can create videos by pulling product images and copy from your product detail pages.
- An advertiser is running a campaign promoting four types of chocolate including milk, dark, caramel, and nuts from 10 different geographies. Which is the most efficient way of managing the ad campaign?
- An advertiser is running a campaign promoting two flavors of ice cream: chocolate and vanilla. The chocolate ice cream has four sub-categories of flavors (choco chip, choco mint, caramel, coffee) while the vanilla ice cream has two sub-categories of flavors (honey, bourbon). Which is the most efficient way of managing the ad campaign?
- An advertiser is running a Sponsored Products campaign and wants to offer a 50% discount on their products. Which deal should they offer on the ad campaign to sell their products?
- An advertiser is running a Sponsored Products campaign for kids clothing. How can the advertiser optimize the campaign budget?
- An advertiser is running ad campaigns using Sponsored TV and wants to target audiences watching third-party streaming TV services. Which of the following products can be integrated with their ad campaigns?
- An advertiser is running two ad campaigns with different deals. Campaign 1 has a Best Deals offer with a return on ad spend of $8.42, while it's $4.82 for campaign 2 that has a Subscribe & Save offer. How can the advertiser optimize their ad creatives to improve performance of both the campaigns?
- An advertiser is running two ad campaigns with different headlines. Campaign 1 has a click-through rate of 20%, while it's 8% for campaign 2. How can the advertiser optimize their ad creatives to improve the performance of both campaigns?
- An advertiser is using keywords to reach audiences shopping for their products in the Amazon store. Which sponsored ads video product supports their keyword targeting strategy?
- An advertiser wants to add video to their Sponsored Brands campaign to showcase their newly launched products. What is an example of a best practice they should follow when creating a video ad?
- An advertiser wants to add video to their Sponsored Display campaign to showcase the use of their products. What is an example of a best practice they should follow when creating a video ad?
- An advertiser wants to build new, short-term demand for their brand on Amazon.com. Which stage of the customer shopping journey should they target?
- An advertiser wants to capture existing demand for their brand by reaching shoppers already considering the brand. Which stage of the customer shopping journey should they target?
- An advertiser wants to expand their reach using Amazon Publisher Direct and IMDb.com. Which sponsored ads video product can fulfill their need for display solutions?
- An advertiser wants to generate new, long-term demand for their brand. Which stage of the customer shopping journey should they target?
- An advertiser wants to improve the video creatives for their Sponsored TV ads. What is an example of a best practice to follow when creating a video ad?
- Bid optimization can help increase viewable impressions, page visits, or conversions based on the bid optimization you selected.
- Gordons Chocolat i er is running a Sponsored Brands campaign for their newly launched milk chocolates. What action can they take to optimize the ad creatives to build brand awareness?
- Gordons Chocolat i er wants to drive consideration among shoppers for their newly launched caramel chocolates. Which of the following sponsored ads video products is best suited to help them reach their business goal?
- How will you best optimize your strategy to increase the number of clicks on your ads?
- If Accent Athletics' business goal is to drive customers to their Brand Store, which advertising metrics will help them measure performance?
- If Iris' business goal is to drive traffic to the product detail page, which advertising metrics will help them measure performance?
- If Jack & Jill's business goal is to increase sales, which advertising metrics will help them measure performance?
- If Kitchen Smart's business goal is to increase sales in the Amazon store, which advertising metrics will help them measure performance?
- If Superpower Batteries' business goal is to encourage repeat purchases, which advertising metrics will help them measure performance?
- If your ads are winning bids, which advertising metric will showcase the results?
- Iris is running a Sponsored Brands video ad campaign to sell their digital cameras. What action can they take to optimize the video ad creatives to improve campaign performance?
- Iris wants to drive awareness among shoppers for their digital camera accessories that complement their products. Which of the following sponsored ads products is best suited to help them reach their business goal?
- Jack & Jill created a Sponsored Brands video ad campaign to promote their newly launched kids watches. What is an example of a best practice to improve the performance of their ad campaign?
- Jack & Jill is running a Sponsored Brands video ad campaign to sell their newly launched kids watches. What action can they take to optimize the video ad creatives to improve the campaign performance and increase sales?
- Kitchen Smart created a Sponsored Display video ad campaign to promote the benefits of using their automatic appliances. What is an example of a best practice to improve the performance of their ad campaign?
- Kitchen Smart is running a Sponsored Display video ad campaign to sell their kitchen accessories. What action can they take to optimize the video ad creatives to improve campaign performance?
- Martha is using Sponsored Display to help drive awareness for her brand through viewable impressions. Which optimization strategy should Martha use to help reach the goal?
- One of your line items has low performance and low delivery. How should you adjust your budget to optimize your campaign for better performance and delivery?
- Relevant ad creatives are directly proportional to the performance of your campaigns.
- SuperPower Batteries wants to improve their video ad creatives for Sponsored TV ads. What best practice should they follow to drive ad recall with customers?
- Superpower Batteries wants to reach customers during the Prime Day shopping festival. How can they optimize their ad creatives?
- Take a look at the sample advertised product report shown below and analyze the different performance metrics. Which is the best performing campaign for advertising cost of sales (ACOS)?
- Take a look at the sample report shown below and analyze the different performance metrics. Based on the information, which placement of products generated the most revenue?
- Take a look at the sample search term report shown below and analyze the different performance metrics. Which is the best performing product/keyword for average cost per click (aCPC)?
- Take a look at the sample search term report shown below and analyze the different performance metrics. Which is the best performing product/keyword for return on ad spend (ROAS)?
- The ability to customize ad creatives is dependent upon the targeting tactic selected.
- What are ad creatives?
- What bid adjustments would you recommend to Kitchen Smart if their goal is to secure ad placement and increase impressions and clicks?
- What recommended action will you take to increase the conversion rate of your ads?
- Which advertising metrics showcase the amount made for every dollar spent on advertising?
- Which advertising metrics showcase the percentage of sales spent on advertising?
- Which creative service can help you develop ad campaigns to build brand awareness, consideration, and conversion?
- Which of the following products should be in the same ad group to optimize campaign management?
- Which of the following reports can you use to measure the overall performance of Sponsored Brands?
- Which report summarizes ad performance by campaign for a selected date range and provides information on metrics campaign by campaign?
- Which sponsored ads video product allows you to run streaming TV campaigns to reach audiences who are streaming content?
- Which sponsored ads video product uses both keyword targeting and product targeting to build targeting strategies?
- Which sponsored ads video product uses contextual targeting to promote products?
- Which targeting strategy allows all of the products in an ad group to be targeted using the same set of keywords or products?
- Which targeting strategy allows you to choose a set of keywords that will be used to target all of the products within an ad group?
- Which targeting strategy allows you to target specific ASINs that are complementary to the product you are promoting using video ads?
- Which tool can help you create video ads using text and images at no cost?
- You can optimize your bidding strategy by setting bid multipliers by placement type.
- You have created a Fire TV campaign report in the advertising console. Which of the following does this report measure?
- You should have a wide variety of keywords to help increase impressions and clicks in your campaigns.
- You want to identify keyword performance by ad placement to gather insights on impressions and clicks. Which report will provide you with the required advertising metrics?
- You want to showcase the summary of clicks, spend, and average cost per click for all of your campaigns. Which report will provide you with the required advertising metrics?
- You want to understand how your customers are shopping for products. The search term report indicates that the Sponsored Products running shoes campaign has a click-through rate of 10%. How do you interpret this information?
- You want to understand the cost of advertised products. The search term report indicates that the searches for "women perfumes" have a click-through rate of just 5%. Which of the following metrics should be looked at to help understand the advertising cost?
- Your campaign reports show that you have products with high advertising cost of sales (ACOS). What bid adjustment should you make to optimize your campaigns?
- Your primary campaign goal is to increase awareness. Which Sponsored Brands report would provide you with the most relevant information to review performance?
Amazon Sponsored Ads Advanced Certification All exam questions
- A campaign is seeing an increase in ad clicks but few conversions. How will you interpret this information?
- Accent Athletics is running a Sponsored Display campaign for their running shoes. What action can they take to optimize the ad creatives to increase traffic on their product detail page?
- An advertiser is running a Sponsored Display video ad campaign to sell running shoes. What is an example of a best practice they should follow when creating a video ad?
- An advertiser sells home decor and wants to reach customers during the holiday season. What is an example of a best practice they should follow when creating a video ad?
- An advertiser wants to drive consideration among shoppers for their most popular watches with newly launched color options. Which sponsored ads video product is best suited to help them reach their business goal?
- Gordons Chocolatier is running a Sponsored Brands campaign for their newly launched milk chocolates. What action can they take to optimize the ad creatives to build brand awareness?
- Gordons Chocolatier wants to drive consideration among shoppers for their newly launched caramel chocolates. Which of the following sponsored ads video products is best suited to help them reach their business goal?
- If an advertiser has a business goal of building brand awareness, which advertising metric will help them measure performance?
- Iris wants to drive awareness among shoppers for their digital camera accessories that complement their products. Which of the following sponsored ads video products is best suited to help them reach their business goal?
- KitchenSmart is running a Sponsored Display video ad campaign to sell their kitchen accessories. What action can they take to optimize the video ad creatives to improve campaign performance?
- What bid adjustment would you recommend to Kitchen Smart if their goal is to secure ad placement and increase impressions?
- Which advertising metric showcase the amount you have spent for a click?
- Which report provides insights into sales and performance metrics for keywords, ASINs, and categories in all campaigns that received at least one impression?
- Which report summarizes your Sponsored Brands ads performance for a selected date range and provides information on metrics campaign by campaign?
- Which sponsored ads video product allows ads to appear on video-dedicated placement in the Amazon store, Amazon Publisher Direct, and third-party publisher?
- Which targeting strategy allows products within the same ad group to be targeted using the same set of keywords?
- You want to identify keywords that perform better on certain placements in order to adjust your bids and expand your targets. Which report will provide you with the required advertising metrics?
- You want to understand how your customers are shopping for products. The search term report indicates that the Sponsored Brands athleisure clothing campaign has a click-through rate of 12%. How do you interpret this information?
Amazon Sponsored Ads Certification All exam questions
- Accent Athletics has just launched a new line of products. Which sponsored ad could help them ensure they are appearing in related product detail pages in order to drive discoverability?
- Accent Athletics’ new ad says "Last chance for deep discounts!" Based on Amazon sponsored ads policies, would this ad be approved?
- After you create a Sponsored Brands campaign with a lifetime budget, you can increase the budget but you can’t decrease it.
- Alejandro wants to advertise plastic gaming dice and wants to reach a broad audience interested in card games. Which targeting method should they use?
- All businesses that have a Brand Store on Amazon will automatically be enrolled in which solution?
- Based on sponsored ads campaign policies, comparative claims must include what?
- Gordon's Chocolatier's new ad says "Great savings on truffles." Based on Amazon sponsored ads policies, would this ad be approved?
- How can Accent Athletics edit more than one live Sponsored Products campaign at the same time?
- If Gordon's Chocolatier's business objective is to increase sales and conversion, what type of ad solution would meet their needs?
- If Iris' business goal is to link customers to their website, which recommended ad solution would meet their needs?
- If Jorge's business goal is to expose their brand to more potential customers, which recommended ad solution can help them?
- If Nikhil wants to organize groups of campaigns, which component of the campaign manager tab should they use?
- If Richard's business goal is to drive more traffic, which recommended ad solution can help them?
- Janice has set up a sponsored ad for her new line of picture frames. She has selected the keyword “computer” for this ad. Which principle explains why her ad may not display?
- Kitchen Smart wants to prevent their electronic mixer ads from being served on irrelevant shopping results. Which keyword targeting method should they use?
- Li wants to advertise organic essential oils and wants to exclude searches for non-organic oils. Which targeting method should they use?
- LuxKitty wants to find new keywords to add to their existing campaigns. Which downloadable report should they use to inform their direction?
- Match the bidding strategy to the definition. Bids that allow you to link multiple keywords to a single bid value.
- Match the bidding strategy to the definition. Bids which are calculated from a group of recent winning bids similar to yours over the past seven days.
- Match the customer action example with the sponsored ad solution for building brand awareness: Hears an ad while listening to a podcast
- Match the customer action example with the sponsored ad solution for building brand awareness: Sees an ad while watching a favorite show.
- Over what timeframe is a daily budget calculated?
- Over what timeframe is a lifetime budget for Sponsored Brands calculated?
- Paulo sets his Sponsored Display ad daily budget to $1,500 USD. What's his potential spend for a 30-day month?
- Select the advertising console tab you would use to access reporting on the targeting strategies used.
- Sponsored ads are generally used for which objective?
- Sports Lab is a small advertiser that does not have access to developer resources. They want to quickly see an overview of how their campaigns are performing. Which of the following reporting methods best fits their need?
- Sports Lab would like to target their ads to display to shoppers viewing bicycles with a 4+ star rating. Which sponsored ad could they leverage for this strategy?
- Super Power Batteries is about to launch their sponsored ads campaign and wants to target batteries that are similar to theirs. Which targeting filter should they consider?
- There are minimum spend requirements for sponsored Ads.
- There are no minimum spend requirements for sponsored Ads.
- True or false? An advertiser can leverage the API to manage their sponsored ad campaign by working with a third-party integration provider.
- What is a general policy requirement for Amazon sponsored ads?
- What is a reason why it's important for advertisers to follow Amazon sponsored ads policies?
- What is one feature brand logos can contain according to Amazon sponsored ads policies?
- Where can you register for a sponsored ads account?
- Which bidding strategy will reduce your bids in real time for clicks that may be less likely to convert to a sale?
- Which filter would Liu adjust if they want to target a complementary product to the one in their ad?
- Which of the following options can be used to manage a sponsored ad campaign?
- Which of the following will notify advertisers when their campaign has run out of budget during the day?
- Which sponsored ad type(s) provides new-to-brand metrics?
- Which type of endemic advertiser brands can use sponsored ads?
- Why does Amazon set a high customer experience bar for the ads that are served with Amazon Ads?
- You can use sponsored ads solutions together to help drive business objectives.
- Zhang wants to advertise wicker baskets and wants to prevent their ads from appearing on irrelevant shopping results. Which targeting method should they use?
Amazon SysOps Administrator Associate SOA-C02 Certification All exam questions
- A bucket is receiving millions of LIST requests. Which AWS services or features can help you identify the source of those requests? (Choose two.)
- A business must keep confidential financial records in Amazon S3 and its policy forbids any S3 bucket from being publicly readable or writable. A SysOps administrator needs a solution that automatically detects and removes S3 permissions that grant public read or write access, with minimal ongoing operational effort. Which AWS service should the administrator choose to accomplish this most efficiently?
- A business runs an Amazon RDS database and needs to introduce a caching tier while ensuring the solution remains highly available. Which pair of actions will satisfy both requirements? (Choose two.)
- A CloudFormation stack deletion is failing (DELETE_FAILED) because the stack created a security group that other security groups reference. The application has been retired and the administrator must remove the stack without disrupting other systems. Which action will accomplish this most efficiently?
- A CloudFormation template creates multiple EC2 instances successfully in us-east-1 but fails in us-west-2 with the error AMI [ami-12345678] does not exist. How can the administrator make the template work in every region?
- A CloudFormation template currently creates an EC2 instance and an RDS instance. You must update the template so CloudFormation always creates the DB instance before it launches the EC2 instance. What change should you make to the template?
- A CloudFormation template deploys an Amazon Linux EC2 instance, an Amazon Aurora cluster, and includes a hardcoded database password that must be rotated every 90 days. What is the most secure method to manage and rotate this database password?
- A CloudFormation template deploys an encrypted Amazon Machine Image (AMI). The AMI was copied into another AWS account so the template can be used there, but when creating the stack in the target account the deployment fails. What should the SysOps administrator do to fix the problem?
- A CloudFormation template includes an AWS::EC2::Instance resource and a custom resource implemented by a Lambda function that needs to perform actions on that EC2 instance. During deployment the Lambda custom resource runs before the EC2 instance exists and fails. How do you ensure the custom resource waits until the EC2 instance is created?
- A CloudFormation template provisions an Amazon RDS instance to create disposable development environments; the stack is deleted when the environment is no longer needed. The RDS data must persist beyond stack deletion so it can be reused. What is the most reliable and efficient method to ensure the RDS data is retained after the stack is deleted?
- A CloudFormation template provisions an S3 bucket. A user signs in to the corporate AWS account using Active Directory credentials and attempts to deploy the template but the stack creation fails. Which of the following could cause the failure? (Choose two.)
- A CloudFormation template successfully launched an EC2 instance in us-east-1 but failed when used in us-west-2. Which of the following is a likely cause of the failure?
- A CloudFormation template was used to create an EventBridge rule that targets an AWS Lambda function. The Lambda is intended to log event details to CloudWatch Logs and has permissions to write logs. However, the Lambda is not being invoked by the rule. What change to the CloudFormation stack will fix this?
- A CloudFormation-managed stack creates EC2 instances. The administrator wants the instances and their data to persist even if someone deletes the CloudFormation stack. Which CloudFormation configuration meets this requirement?
- A CloudFront distribution has a cache hit ratio below 10%. You want to boost the cache hit rate, speed up delivery, and reduce origin strain. Which combination of actions will help? (Choose two.)
- A CloudFront distribution has a single Amazon S3 bucket as its origin. The administrator must ensure that objects in the bucket can only be retrieved through CloudFront, not by direct S3 URLs. Which configuration accomplishes this requirement?
- A CloudFront distribution uses an on-premises web server as a custom origin and requires TLS between CloudFront and that origin. The setup worked for months but users are now getting HTTP 502 (Bad Gateway) responses for pages that include CloudFront-delivered assets. What should a SysOps administrator check first to correct the issue?
- A company aggregates raw video uploads into a single S3 bucket in the US, but teams in Europe and Australia experience slow uploads for large files. What are the most cost-effective ways to speed up uploads to that US S3 bucket? (Select two.)
- A company asks you to deploy an existing application into four additional AWS Regions. The application currently runs on over 100 EC2 instances in us-east-1 and uses fully configured AMIs. A CloudFormation template exists that deploys the stack in us-east-1. What is the most operationally efficient way to deploy the application into the other Regions?
- A company collects application data for analytics. For the first 90 days the data will be accessed infrequently but must be highly available with millisecond retrieval. After 90 days, the data must be retained long term at lower cost, with retrieval time under 5 hours. Which storage lifecycle design is the most cost-effective while meeting these requirements?
- A company copies data from S3 buckets in three AWS Regions to its on-premises data center over the internet via a VPN, but occasional ISP congestion causes inconsistent transfer times. What is the most cost-effective way to get predictable transfer performance from S3 to the data center?
- A company currently hosts a simple web app on EC2 instances behind a load balancer in eu-west-2 and uses a Route 53 simple routing record. They plan to create additional, identical deployments in us-east-1 and ap-south-1 and want users routed to the region that yields the fastest response time. What should the SysOps administrator do?
- A company currently hosts its website in us-east-1 and is deploying a copy to eu-central-1. European visitors should be routed to the site in eu-central-1, and all other visitors should go to the us-east-1 site. The DNS is managed in Route 53. Which routing policy should the administrator use on the record set to satisfy this requirement?
- A company delivers its website using CloudFront and needs to store access logs centrally with encryption at rest. Which solution satisfies these requirements?
- A company deploys RDS for PostgreSQL Multi-AZ instances using a CloudFormation template that sets the allocated storage to 100 GB. Databases are created each Monday and removed on Friday. Occasionally they trigger CloudWatch alarms for low disk space. How can the administrator prevent the instances from running out of storage with the MINIMUM changes to the application?
- A company has a Direct Connect link between its on-premises data center and a VPC. The VPC uses a Route 53 private hosted zone for internal AWS service names. The on-premises servers must be able to resolve names in that private hosted zone. What solution achieves this?
- A company has an IPsec VPN tunnel between its VPC and its on-premises network. The tunnel shows as UP, but EC2 instances cannot ping on-premises hosts. What should a SysOps administrator do to restore connectivity?
- A company has enabled server access logging for its S3 buckets and wants an automated way to detect and remediate any existing or newly created buckets that do not have access logging enabled. Which solution provides the most operationally efficient enforcement?
- A company has hundreds of objects in an S3 bucket and needs to replace an existing tag on every object with a new tag. Which approach is the most operationally efficient way to accomplish this?
- A company hosts a public website from an S3 bucket in us‑east‑1 and serves it via an Amazon CloudFront distribution. The company wants protection from DDoS and needs fine control over the rate threshold that triggers mitigation. Which deployment meets that need?
- A company hosts a site on EC2 instances behind an ALB and uses Route 53 for DNS. The company needs the domain's apex (root) to point to the website. Which DNS record type should be used for the zone apex?
- A company intends to ensure non-production Amazon EC2 instances remain stopped overnight. The IT manager must get near real-time notifications whenever an EC2 instance tagged as environment=non-production is started during the night. Which solution provides this behavior with the LEAST operational overhead?
- A company is establishing many AWS accounts under a single AWS Organizations environment and needs a centralized login solution that integrates with AWS Organizations and a third-party SAML 2.0 identity provider. What is the recommended approach for centrally managing sign-in and permissions across all accounts?
- A company is expanding its AWS usage and wants to provision separate accounts for each team with consistent baseline settings and governance. Account creation and bootstrapping must be scalable and efficient so new accounts are created with guardrails already applied. Which option best meets this need?
- A company is launching an ecommerce site in an AWS Region in France and wants only users located in France to reach the initial release. Later releases will expand to additional countries. Which Route 53 routing policy configuration enforces access from France only?
- A company is migrating an internet web application from EC2 instances to an AWS Lambda function. During the cutover period, some requests must go to the legacy EC2 application and others to the Lambda function based on the URL path. Which solution satisfies this routing requirement?
- A company is migrating applications to AWS and already uses Chef recipes for configuration management. The team wants to keep using their existing Chef recipes after moving to AWS with minimal operational effort. Which solution is the most operationally efficient and preserves use of Chef recipes?
- A company is moving its production Windows file server to AWS. The solution must remain available if an Availability Zone fails or during maintenance, support SMB access, and preserve Windows ACL-based file permissions. Which option satisfies these requirements?
- A company is releasing an updated version of its website but wants to expose it to only 20% of users initially. The DNS is managed in Amazon Route 53. Which Route 53 configuration will accomplish a controlled 20% rollout?
- A company keeps backup files in an Amazon S3 bucket and requires that those backups cannot be removed for at least 90 days after creation. What should a SysOps administrator implement to satisfy this constraint?
- A company keeps data files in S3 and must label the data and locate any sensitive personal information within those objects. Which AWS service and configuration will accomplish this requirement?
- A company keeps sensitive information in an S3 bucket and must record all access attempts. The risk team must be alerted immediately whenever an object delete operation occurs. Which solution fulfills both requirements?
- A company manages example.com in Route 53 and placed a CloudFront distribution in front of its web app. The site should be reachable at www.example.com and must use CloudFront. What is the most cost-effective way to configure Route 53 so www.example.com resolves through the CloudFront distribution?
- A company manages infrastructure using AWS Service Catalog and needs to reproduce the existing portfolio in a different AWS account. What is the most operationally efficient method to replicate the infrastructure in the new account?
- A company migrated a write-once, read-many (WORM) drive into an S3 bucket that has Object Lock enabled in Governance mode. During the transfer some unnecessary objects were copied into the bucket. When a SysOps admin tries to delete those objects using the AWS CLI, the delete fails with an error. Which steps will allow the admin to successfully remove those objects? (Choose two.)
- A company migrated servers to EC2 and wants to stream instance logs to Amazon CloudWatch Logs following AWS best practices. What should the SysOps administrator implement to meet this requirement?
- A company must archive sensitive records to Amazon S3 Glacier and ensure that no AWS account can modify the data. The retention policy requires that the vault lock be enforced under the proper validation timeframe. Which approach satisfies the compliance need?
- A company must enforce strict quarterly budget limits across 25 AWS-hosted applications. Separate teams are accountable for storage, compute, and database costs. The SysOps administrator needs an automated way to notify each team when their forecasted spend will exceed the quarterly limit set by finance. The solution must not introduce extra compute, storage, or database charges. Which option satisfies these constraints?
- A company must guarantee that every object uploaded to an S3 bucket is stored encrypted. Which of the following will enforce encryption for uploads? (Choose two.)
- A company needs a backup plan for EC2 and RDS resources with these retention rules: daily backups kept 6 days, weekly kept 4 weeks, monthly kept 11 months, yearly kept 7 years. Which strategy meets these retention needs with the LEAST administrative effort?
- A company needs a solution to capture every API call made to its Amazon S3 objects. What should a SysOps administrator configure to meet this requirement?
- A company needs an inventory of applications running across many EC2 instances. Users and IAM roles with required permissions for AWS Systems Manager are configured. The latest Systems Manager Agent is running on every instance. While enabling inventory collection, the administrator notices some instances in the same subnet are not managed by Systems Manager. What must the administrator do to resolve this?
- A company needs to replicate EBS volume backups to another AWS Region. Most source EBS volumes are encrypted, but some are not; the company requires that all copied backups be encrypted. Which option provides the required encryption while minimizing operational overhead?
- A company needs to retain audit logs for ten years and ensure the logs cannot be altered after they are stored. Which storage solution fulfills these requirements?
- A company operates many EC2 instances and needs to alert the operations team whenever any instance changes state (for example, starts or stops). Which approach is the most operationally efficient to meet this requirement?
- A company policy mandates that every EC2 instance must include a defined set of tags; instances missing the required tags must be terminated automatically. What is the MOST operationally efficient way to implement this requirement?
- A company processes messages with a worker application running on three EC2 instances in an Auto Scaling group that uses a simple scaling policy. The workers poll messages from an Amazon SQS queue. Sporadic surges in messages are degrading processing performance, and the SysOps administrator must scale the Auto Scaling group to handle higher queue volume. Which approach best satisfies this requirement?
- A company provisioned an Amazon FSx for Windows File Server with tight storage capacity and created an SNS topic subscribed to a SysOps administrator's email. The administrator must receive an email alert when available free space on the file system falls below 100 GB. Which combination of actions will fulfill this requirement? (Choose two.)
- A company replaced on-premises tape hardware with an AWS Storage Gateway Tape Gateway. Backup jobs occasionally fail with a “Not Enough Space” error when writing to AWS virtual tapes. The organization wants to avoid these failures and ensure there are always sufficient virtual tapes available in AWS with minimal operational overhead. What should the SysOps administrator do?
- A company runs a dynamic web application on EC2 instances behind an Application Load Balancer (ALB) with DNS managed by Route 53. A static S3 website must serve as an automated backup if the app fails. Which combination of steps will implement fully automated failover to the S3 site? (Choose two.)
- A company runs an HPC application on a single EC2 instance and needs to scale to multiple instances that require low‑latency, high‑bandwidth communication between them. What should the SysOps administrator do to meet this networking requirement?
- A company runs an internal web app on EC2 instances behind an Application Load Balancer. The instances are in an Auto Scaling group that spans only one Availability Zone. The SysOps administrator must make the application resilient to AZ failures. Which change should be made to achieve high availability?
- A company runs its database on an Amazon RDS for PostgreSQL DB instance and requires that all client connections to the DB be encrypted. What should a SysOps administrator do to enforce encryption for connections?
- A company runs its website on EC2 instances in the us-east-1 Region and plans to deploy additional web servers in eu-central-1. The database must remain in us-east-1. After launching the eu-central-1 instances, those servers cannot reach the database in us-east-1. Which solution is the most operationally efficient way to restore connectivity?
- A company runs jobs that can finish at any time. Currently the jobs use multiple EC2 On-Demand Instances and usually run just under two hours. If a job fails it must restart from the beginning. Which approach is the most cost-effective to run these jobs?
- A company runs many EC2 instances based on the Amazon Linux 2 AMI. The SysOps administrator needs a low-maintenance way to capture interactive user command sessions (commands and their outputs), store those recordings durably, and trigger alerts based on log contents. Which approach provides the required functionality with the least operational overhead?
- A company runs several write-heavy, multi-tenant applications using a single MySQL database on one EC2 instance. The company requires a highly available database solution that handles multi-tenant write activity. Which migration target should the SysOps admin choose?
- A company serves its site through CloudFront using the domain www.example.com and has an ACM certificate for that domain. All connections to CloudFront must use TLS. Which two actions should a SysOps administrator perform to enforce encrypted viewer connections? (Choose two.)
- A company stores media in an S3 bucket and uses CloudFront to distribute it. Licensing restrictions prevent distribution in certain countries. Which approach is the MOST operationally efficient way to block users in the restricted countries from accessing the content?
- A company stores objects across 50 S3 buckets all in the same AWS Region and wants its EC2 instances to access those buckets over a private connection. The company requires a solution that does not add extra charges. Which design meets these constraints?
- A company uploads important files to an S3 bucket and wants to detect if an object becomes corrupted during upload. What should the SysOps admin include in the upload request to ensure the object integrity can be verified?
- A company uploads multiple gigabytes of files to Amazon S3 every day and needs higher throughput and faster upload performance. Which configuration will best improve upload speeds to S3?
- A company uses AWS Certificate Manager (ACM) for public TLS certificates. A SysOps admin needs to send an email alert when any certificate has fewer than 14 days until expiration. Which solution provides that notification with the least operational effort?
- A company uses AWS IAM Identity Center (AWS Single Sign-On) integrated with Active Directory. An admin grants access to a newly created AWS account by assigning the Active Directory Domain Users group, since every employee is a member of that group. When employees attempt to sign in, they are denied access. What action will fix the login failures?
- A company uses multiple AWS accounts under AWS Organizations. There is an OU for production and another for development. Corporate rules permit developers to use only preapproved AWS services in the production account. What is the most operationally efficient way to enforce this restriction for the production account?
- A company wants a report listing security groups that permit RDP (TCP/3389) access from anywhere on the internet. Which AWS service should a SysOps admin use to obtain this information?
- A company wants recommendations for right-sizing and optimal configurations for Lambda functions across multiple AWS accounts. What is the correct service to enable to obtain and export these Lambda recommendations?
- A company wants specific, company-defined tags that are applied to resources to appear on its AWS billing reports. What must the SysOps administrator do to ensure these tags show up on the bill?
- A company wants to enforce stricter tagging to track Amazon EC2 and Amazon RDS costs. A SysOps administrator needs to find all resources that violate the required tagging policy. What is the MOST operationally efficient way to detect resources that are missing the mandated tags?
- A company will migrate workloads from EC2 to AWS Fargate and expects to stop using EC2 in 6 months. They have estimated their future Fargate spend and want to maximize discounts without ending up with unused reservations. Which purchase option best meets these constraints?
- A company will operate stateful web applications on EC2 instances in an Auto Scaling group, running continuously all year. The business wants the flexibility to change instance sizes within the same instance family later in the year based on usage patterns. Which EC2 purchase option offers the most cost-effective solution while meeting this requirement?
- A company's website runs on EC2 instances in an Auto Scaling group. Users report slower performance every weekend from 6 PM to 11 PM. The SysOps administrator needs the simplest, most operationally efficient way to improve capacity during those peak windows. What is the best solution?
- A company’s applications write transaction data multiple times per minute to a single Amazon RDS DB instance. As transaction volume grows, the company needs automatic failover for disaster recovery that preserves committed transactions. Which solution meets this need?
- A compliance requirement mandates that admin passwords for RDS DB instances be rotated at least once per year. Which approach meets this requirement with the least operational overhead?
- A compute cluster consists of 20 EC2 instances: 2 always-on control nodes and 18 task nodes used for processing. Control nodes must run 24/7; task nodes run about 4 hours per day and can be started by the control nodes. All instances are currently On-Demand. How can you reduce cost while meeting availability and runtime requirements? (Choose two.)
- A containerized application runs in Amazon ECS on EC2 instances. You only need to capture network traffic exchanged between the ECS tasks themselves. Which combination of steps should you take? (Choose two.)
- A data analytics process on an EC2 host needs the CloudWatch agent to send metrics that include custom dimensions. How can the SysOps administrator configure the CloudWatch agent to include those extra dimensions?
- A data file should arrive in an S3 bucket every hour. An S3 event triggers a Lambda function to process each arrival. Occasionally a file does not arrive, and the application team wants to be alerted when no file is received during an hour. Which solution is the most operationally efficient and satisfies this requirement?
- A developer created a Lambda function triggered by S3 PutObject events. The function reformats the object and writes it back to the same bucket, causing a recursive invocation loop during testing. The developer asks the SysOps administrator to immediately stop the recursion without causing errors. What should the administrator do?
- A development EC2 instance is uploading 500,000 files of 1 GB each to an S3 bucket in the same Region with default encryption. Application logs show it is frequently waiting for writes to S3; network bandwidth is not the bottleneck. What change should improve S3 upload throughput?
- A development team adds a new S3 bucket named DOC-EXAMPLE-BUCKET to hold large user uploads from around the world. After going live, uploads from some regions are noticeably slower than the team's existing S3 buckets. What should the SysOps admin do to improve upload performance for the new bucket?
- A development team deployed a new Lambda function 15 minutes ago and it has been invoked multiple times, but there are no log entries in CloudWatch Logs. Which of the following is a likely reason?
- A development team needs identical, on-demand environments composed of EC2 instances and an RDS database. Environments should be provisioned only when needed and must be torn down every night to reduce costs. What is the MOST operationally efficient design to satisfy these requirements?
- A fleet of EC2 instances uploads build artifacts to a vendor that now enforces an allow list and requires all uploads to originate from a single public IP. What modification should the SysOps administrator make to ensure all uploads come from one IP address?
- A fleet of hundreds of EC2 instances each has two 1 GiB gp2 EBS volumes. A critical workload is saturating the EBS IOPS. Company rules forbid changing instance types or volume types without lengthy testing. What is the fastest way to improve EBS I/O performance without altering instance or volume types?
- A fleet of Linux EC2 Spot Instances uses attached EBS volumes restored from snapshots and is frequently started and stopped. After restoring volumes from snapshots, the initial I/O throughput is lower than expected and the workload cannot get the nearly full provisioned IOPS it requires. What should a SysOps administrator do to ensure restored EBS volumes immediately deliver expected performance?
- A gaming company will deploy its game across multiple AWS Regions. Each Region has an Auto Scaling group of EC2 instances behind an Application Load Balancer. The company wants Route 53 to send players to the nearest Region and to automatically fail over traffic if a Region becomes unhealthy. Which combination of steps should the administrator take? (Choose two.)
- A global app allows anyone to upload videos from their mobile phones. All uploads go over the public internet to an S3 bucket located in us-east-1 for processing. Users who are physically far from us-east-1 experience slow uploads and often cancel. Which approach will speed uploads for users who are geographically distant from the bucket?
- A global company processes sensitive PII via an internal portal hosted in a corporate data center connected to AWS over AWS Direct Connect. The application stores PII in Amazon S3, and policy requires that traffic between the portal and S3 must not traverse the public internet. What should the SysOps administrator implement to ensure S3 traffic remains on AWS private networks?
- A global firm uses five AWS Regions and needs a consolidated list of all EC2 instances, whether they have tags or not. The output should include each instance's ID and its tags. What is the most operationally efficient method to produce this report across all Regions?
- A global multi-Region deployment exists for production services. The administrator needs to route traffic according to the geographic location of the resources. Which Route 53 routing policy should be used to steer traffic based on resource locations?
- A globally served website hosted on EC2 behind an Application Load Balancer (ALB) is configured as the origin for a CloudFront distribution to reduce load on web servers. After a week there is no reduction in server load and requests still appear to be hitting the ALB directly. Which issues could explain this behavior? (Choose two.)
- A high-performance Windows workload requires a storage volume that consistently delivers 10,000 IOPS. The company wants to avoid paying for capacity they do not need. Which storage option provides the required consistent IOPS at the lowest cost?
- A Jenkins server on EC2 uses a 500 GB gp2 EBS volume. Nightly builds require sustained 3,000 IOPS, but CloudWatch shows the volume’s BurstBalance hits 0 during builds. Which change will meet the sustained IOPS requirement most cost-effectively?
- A KMS customer master key (CMK) was created with imported key material and is referenced by alias in a Java application for encryption. The organization needs to rotate the key material every six months. What is the proper procedure to rotate this imported-material CMK?
- A Lambda function in Account A must read objects from an S3 bucket that resides in Account B. The SysOps administrator will create IAM roles in both accounts to enable this access. Which role configuration will satisfy this requirement?
- A Lambda function is intermittently failing multiple times per day. A SysOps administrator needs to determine how many times this error occurred over the past 7 days with the least operational effort. Which approach is the most efficient?
- A Lambda function must run automatically at the end of each day to produce a report from data stored in Amazon S3. What is the MOST operationally efficient way to schedule this Lambda invocation?
- A large IT organization uses LDAP groups to control on-premises access and wants to migrate to AWS without giving everyone broad access. What is the most appropriate way to allow users to sign in with existing LDAP credentials while granting different permissions based on job function?
- A legacy application on EC2 instances fails when total CPU utilization exceeds 80%. As a temporary mitigation while the app is rewritten, a SysOps administrator must restart instances when CPU goes above 80%. Which approach accomplishes this with the LEAST operational overhead?
- A legacy web app was moved from on-premises to a single EC2 instance and must keep a fixed public IP for client traffic. Users access the app using example.com. You need a solution that requires minimal ongoing maintenance. Which two actions together satisfy these requirements? (Choose two.)
- A long-running, stateful service runs on a single xlarge general purpose On-Demand EC2 instance. Metrics show it uses about 80% of memory and 40% of CPU. The SysOps administrator needs to lower costs without degrading performance. Which instance type change meets this goal?
- A manufacturing company uses an RDS instance for inventory and has several Lambda functions that connect to the database using hardcoded credentials. Credentials must never be stored in plaintext and must be rotated every 30 days. Which solution provides this with the least operational overhead?
- A marketing push will drive more traffic to a web application that uses API Gateway and Lambda. The app stores data in an Amazon Aurora MySQL cluster with one Aurora Replica. Read/write ratio is about 95% reads and 5% writes. How should a SysOps administrator configure the database to scale for the expected higher load?
- A marketing update changed 150 images on a website that is delivered through CloudFront, but some updated images still show the old versions. The distribution’s default TTL is 1 week. What is the most operationally efficient method to ensure the new images are served immediately?
- A media outlet runs a public news and video site on AWS. The site keeps an index of video metadata in an Amazon DynamoDB table configured with provisioned capacity, and the video files themselves reside in an Amazon S3 bucket. During a high-traffic event, reads against the DynamoDB table were throttled and videos failed to appear. Operators temporarily raised the table's provisioned read capacity manually. The team wants to be alerted before throttling occurs in the future. An Amazon SNS topic has been created and the operators' email is subscribed. What action should the team take next to meet this requirement?
- A memory-heavy application runs on EC2 instances in an Auto Scaling group behind an Elastic Load Balancer. The admin needs autoscaling to react based on how many users are connected to the app. Which solution will meet this requirement?
- A mission-critical application runs continuously and uses EC2, Fargate, and Lambda across multiple Regions and operating systems. The company wants maximum cost savings while keeping the flexibility to change workloads. Which purchasing option best meets these goals?
- A MySQL database (1.75 TB) will be restored on an EC2 instance and requires up to 10,000 read IOPS. The database size is not expected to grow. Which EBS volume choice meets the performance requirement at the lowest cost?
- A new web application is launched on multiple EC2 instances behind an Application Load Balancer in an Auto Scaling group. Users complain they are being asked to log in repeatedly. What should the SysOps administrator do to stop frequent reauthentication?
- A new workload uses an Amazon RDS for MySQL Multi-AZ database. The company requires all data at rest to be encrypted and keys to be rotated annually. Which configuration satisfies these requirements?
- A newly created CloudWatch alarm remains in the INSUFFICIENT_DATA state. The alarm monitors the mem_used_percent metric from an EC2 instance in a public subnet. The unified CloudWatch agent is installed and running on the instance, but the metric is not visible in CloudWatch. What should a SysOps admin do to correct this?
- A partner vendor will host a company's data inside an S3 bucket in the vendor's AWS account. The vendor has asked the company to supply a KMS key for encrypting that data and has shared an IAM role ARN that the vendor will assume. What should the SysOps administrator do to enable this integration securely?
- A personal finance app stores sensitive financial files in Amazon S3 and requires server-side encryption. The company does not want to supply its own keys, but it needs an audit trail showing who used the key and when. Which encryption option meets these needs?
- A policy requires disabling access keys and passwords for any IAM user who hasn’t been active for 90 days or more. You must implement an automated, operationally efficient solution to disable unused credentials. Which design meets this requirement?
- A predictable workload runs across several AWS Regions using Lambda and On-Demand EC2 instances. The compute consumed in each Region fluctuates by user location. Which purchasing strategy should a SysOps admin use to reduce cost while accommodating regional variance?
- A private S3 bucket contains sensitive data. You must capture IP addresses from failed authentication attempts to access objects, store those logs in a way that they cannot be changed or deleted for 90 days. Which design meets these requirements?
- A production Aurora MySQL cluster is a single writer node and is heavily queried for reporting. The cluster suffers intermittent performance problems due to high CPU and reaching max connections. A SysOps admin needs to stabilize performance. Which solution will address this requirement?
- A production Auto Scaling group was supposed to maintain a minimum of three EC2 instances, but it scaled down to two and the group's configuration now shows a minimum of two. Which AWS service can reveal who changed the Auto Scaling group's minimum capacity?
- A production EC2 instance uses an EBS volume that has reached 100% utilization, causing the application on the instance to fail. Which action will restore application functionality in the SHORTEST possible time?
- A production environment currently runs on a single EC2 instance that hosts both the web application and a MariaDB database. Company policy mandates high availability for production systems. Which design change will bring this environment into compliance?
- A production Multi-AZ Amazon RDS for MySQL (db.m6g.xlarge) is hitting 'too many connections' errors frequently. The administrator wants to minimize code changes and fix the problem cost-effectively. Which approach best meets these constraints?
- A public advertisement causes sudden, unpredictable traffic spikes to an application running in an Auto Scaling group. Instance boot includes a lengthy process that creates machine-specific caches, so startup is slow. The Auto Scaling group must be able to handle surges that may require scaling to 100 instances. Which solution ensures capacity is available quickly for these surges?
- A public website is hosted behind an Application Load Balancer that currently only has an HTTP listener on port 80. You have a validated public certificate for www.example.com in ACM. Existing users must continue to use the same endpoint, but all traffic between clients and the ALB needs to be encrypted. Which set of actions should you take?
- A public-facing website recently had problems where some links returned missing pages and others returned incorrect content, even though the infrastructure and resources appeared healthy and logs showed no errors. Administrators only found out after user reports. The company wants an early detection system for these kinds of functional issues with minimal operational effort and fast deployment. Which option meets these needs?
- A relational database on a burstable EC2 instance shows periodic latency. It uses a 350 GB gp2 EBS volume. CloudWatch shows VolumeReadOps drops to under 10% of peak during the slow periods. What change should the SysOps admin make to achieve steady high I/O performance?
- A reporting process that previously completed in 15 minutes now takes an hour. The application runs on EC2 instances and reads data from an Amazon RDS for MySQL instance. CloudWatch shows consistently high Read IOPS on the RDS instance, even when reports are not running. The administrator must improve both performance and availability of the database. Which solution meets these goals?
- A retail site runs on multiple EC2 instances behind an Application Load Balancer and must be served over HTTPS. Which combination of steps should the SysOps administrator take? (Choose two.)
- A Route 53 record has been created to point a domain name to a static website hosted in Amazon S3. The site’s DNS name is www.example.com but the S3 bucket is named DOC-EXAMPLE-BUCKET. After creating the record set in Route 53, the site at www.anycompany.com does not load. Which of the following explains why the website does not appear?
- A runaway process is consuming 100% of a CPU on an EC2 instance. A SysOps admin wants the instance to automatically reboot if this condition lasts longer than 2 minutes. How can this be achieved?
- A scheduled Lambda function currently runs without VPC access and fetches datasets from the internet. The application will be changed so the Lambda must write to an RDS DB instance located in a private subnet. The VPC has two public and two private subnets. What configuration allows the Lambda to reach the private DB and still access the internet?
- A secure website is hosted on EC2 instances behind an ALB using an AWS Certificate Manager (ACM) certificate. Users with older browsers cannot access the site properly. What is the most operationally efficient way for the SysOps administrator to resolve compatibility problems for legacy browsers?
- A security administrator in their own AWS account needs read access to inspect VPC configurations in several developer AWS accounts inside an AWS Organization. What is the most secure way to grant that access?
- A security policy forbids direct SSH/RDP to EC2 instances; authorized staff use AWS Systems Manager Session Manager instead. Users cannot connect to one Ubuntu EC2 instance that has the SSM Agent preinstalled, but they can use Session Manager to access other instances in the same subnet. The users belong to an IAM group that has Session Manager permissions for all instances. What action should a SysOps administrator take to fix the problem?
- A security team requires a way to prove that AWS CloudTrail log files have not been modified after delivery. The organization already uses IAM to restrict who can access particular trails. What is the MOST operationally efficient method to guarantee and validate the integrity of each delivered CloudTrail file?
- A serverless application on Lambda connects to an Amazon RDS for MySQL instance and users are now seeing frequent "too many connections" errors. The DB is already configured with the highest available max_connections. What should the SysOps administrator do to prevent these connection errors?
- A serverless application was deployed into a production VPC using AWS CloudFormation. The stack includes a Lambda function, a DynamoDB table, and an API Gateway. The administrator needs to delete the CloudFormation stack but keep the DynamoDB table intact. What should be done before deleting the stack?
- A service deployed on Linux EC2 instances in an Auto Scaling group sometimes crashes due to an application bug, and a full fix may take weeks. The SysOps administrator must implement an automated recovery mechanism so that the service is restarted if it stops on any instance. Which of the following solutions meet this requirement? (Select two.)
- A single-instance Amazon RDS database is experiencing CPU and I/O saturation during peak read traffic. Which two actions should the SysOps administrator take to reduce read load and improve performance? (Choose two.)
- A single-page app serves static content from S3 through CloudFront and uses an EKS cluster for API requests. Users sometimes say the site is down even though the index page and EKS cluster checks look healthy. Which additional monitoring will proactively detect a site outage before users report it?
- A single-Region deployment hosts an app on Amazon EC2 that must accept both HTTP and non-HTTP TCP connections. The company wants to use the AWS global network to reduce latency and also place the instances in an Auto Scaling group behind an Elastic Load Balancer. What architecture should a SysOps administrator implement to satisfy these requirements?
- A single-writer Amazon Aurora PostgreSQL cluster experienced over 90% utilization for 11 minutes when a weekly automated report ran, causing user-facing slowdowns. How should the administrator prevent weekly performance degradation caused by the report?
- A Site-to-Site VPN connects an on-premises network to a VPC. You launched a Windows EC2 instance with only a private IP in a private subnet. The instance’s security group allows inbound RDP from the on-premises CIDR and the on-prem firewall permits RDP over the VPN, but users time out when trying to RDP to the instance. What should you do to troubleshoot the connectivity problem?
- A small application that’s frequently updated must be installed automatically on all new EC2 instances. What is the simplest method to install it when instances launch?
- A social media service has strict data residency rules and needs DNS routing that directs users to a specified list of AWS Regions based on the user’s geographic location. Which Amazon Route 53 routing policy will satisfy this requirement?
- A stateful web application runs on EC2 instances in an Auto Scaling group behind an ALB with a single target group. The ALB is the origin for a CloudFront distribution. Users are experiencing intermittent logouts. Which two changes should the SysOps administrator implement to fix session loss? (Choose two.)
- A stateless application runs on a single Amazon EC2 instance. During business hours the instance’s CPU frequently spikes to about 90%, and users report slow response times. Which approach is the MOST operationally efficient way to improve the application's responsiveness?
- A stateless web application runs on 10 On-Demand EC2 instances in an Auto Scaling group. The service requires at least 6 instances to satisfy traffic demands. What is the most cost-effective way to ensure the application stays available while meeting the minimum instance requirement?
- A static website is hosted in an S3 bucket with static website hosting enabled and objects uploaded, but accessing the site returns 403 Forbidden - Access Denied. What modification will resolve the error?
- A static website is hosted in S3 and delivered through CloudFront using the Managed-CachingDisabled cache policy. Developers frequently update a particular S3 object, and users see the correct content on first load, but a browser refresh does not retrieve the updated object. What change should a SysOps administrator recommend to ensure refreshed pages fetch the latest file?
- A static website is stored in an Amazon S3 bucket and delivered through a CloudFront distribution that has a default TTL of 86,400 seconds. After uploading new site files to S3, visitors still receive the previous content. The SysOps admin needs the updated site to appear for users immediately. What action accomplishes this?
- A SysOps admin consolidated multiple secure websites onto a single server, each site bound to a different TCP port. The admin plans to launch a duplicate server in another Availability Zone and place both behind a load balancer for high availability. Which AWS CLI command will install one of the site certificates onto the load balancer listener?
- A SysOps admin deployed a CloudFormation template that creates EC2 instances, an Elastic Load Balancer, and an RDS DB instance. The EC2 instances and the load balancer were created successfully, but DB creation failed. By default, how does CloudFormation behave in this situation?
- A SysOps admin enabled VPC Flow Logs to deliver data to Amazon CloudWatch Logs. After inspecting the CloudWatch Logs, the admin sees fewer packets than expected. Comparing those logs with packet captures taken from the on-premises network, the admin suspects the flow logs are missing some traffic. Which of the following could explain the discrepancy?
- A SysOps admin hosts a static website in an Amazon S3 bucket and wants to ensure visitors can only reach the site through a single CloudFront distribution. Users must not be able to bypass CloudFront and access the S3 website endpoint directly. Which AWS feature should the admin use to enforce that requirement?
- A SysOps admin is using IAM credentials to upload an object to a customer’s S3 bucket named DOC-EXAMPLE-BUCKET but receives AccessDenied. Which combination of changes will resolve the permission failure? (Choose two.)
- A SysOps admin launches a public-facing website on an EC2 instance placed in an existing public subnet and associates an Elastic IP. The admin then attached a security group allowing inbound HTTP (port 80) from 0.0.0.0/0. A new network ACL was created and applied to the subnet permitting inbound HTTP from 0.0.0.0/0. Despite these changes, the site is still unreachable from the internet. What is the most likely reason?
- A SysOps admin maintains a legacy application that is CPU-bound and can only scale by increasing instance size. It currently runs on a single t3.large EC2 instance and CPU utilization spikes to 90% with high latency after a few minutes. Which modification will most directly reduce the CPU-related performance bottleneck?
- A SysOps admin must deploy a new Auto Scaling group composed of EC2 Spot Instances across many instance types. The fleet should draw from the Spot pools that maximize availability for the number of instances requested. Which Spot allocation approach satisfies this requirement?
- A SysOps admin observes that an Amazon CloudFront distribution is seeing a cache hit rate below 10%. Which configuration changes will help raise the cache hit rate for this distribution? (Select two.)
- A SysOps administrator deployed an Amazon EKS cluster that runs pods on AWS Fargate. The cluster is up and running. To manage the cluster using kubectl from the administrator’s workstation, what must be configured locally so kubectl can reach the cluster API?
- A SysOps administrator exported a CloudFormation template of existing infrastructure in us-west-2 and tried to use that same template to create a stack in eu-west-1. The stack failed partway through, returned an error, and rolled back. Which two reasons could explain this failure? (Choose two.)
- A SysOps administrator finds 5 GB of incomplete multipart upload parts in an S3 bucket and wants to reduce the number of these abandoned multipart uploads. What is the appropriate way to address this?
- A SysOps administrator has written an IAM policy (not shown) for a developer that grants limited permissions to specific services. Which of the following operations does the policy permit?
- A SysOps administrator is responsible for hundreds of EC2 instances running Windows and Linux. Each instance is tagged with its operating system and all instances are reachable through AWS Systems Manager Session Manager. A zero-day vulnerability requires custom mitigation scripts supplied by the security team for each OS. The administrator must run the provided code quickly across the fleet and produce a report proving successful execution on every instance. What is the fastest way to accomplish this?
- A SysOps administrator is troubleshooting performance on an Amazon RDS for MariaDB instance and needs to view database load broken down by detailed wait events. Which approach provides that level of insight?
- A SysOps administrator launched an EC2 instance in a private subnet. From that instance, curl https://www.example.com fails to connect. What should the administrator do to restore outbound HTTPS connectivity from the instance?
- A SysOps administrator launched four new Amazon Linux 2 EC2 instances using the standard AMI. The team needs to manage these instances through AWS Systems Manager, but the instances do not appear in the Systems Manager console. What action will enable Systems Manager management for these instances?
- A SysOps administrator manages many Windows EC2 instances in one account. Each instance is tagged with key OS and value Windows. The company uses Systems Manager for patching and has the CloudWatch agent installed inconsistently across instances. The administrator needs to apply a consistent CloudWatch agent configuration to all instances. Which combination of steps will achieve this? (Choose two.)
- A SysOps administrator manages over 50 EC2 instances across a single production account running multiple operating systems. Company policy requires monthly OS patching. The administrator wants to use AWS Systems Manager to reduce the manual hours spent on patching. Which combination of actions should the administrator perform? (Choose three.)
- A SysOps administrator monitors the Personal Health Dashboard in multiple AWS accounts that belong to an AWS Organizations organization. After adding 10 new accounts, the administrator wants to see all Personal Health Dashboard alerts across the organization in one place with minimal effort. What should the administrator do?
- A SysOps administrator must alert when disk utilization for EBS volumes attached to Linux EC2 instances exceeds 80%. Which combination of actions is required to collect the metric and trigger an alarm? (Choose three.)
- A SysOps administrator must deploy an application instances across 10 EC2 instances that need to be highly available and placed on distinct underlying hardware. Which placement approach satisfies these requirements?
- A SysOps administrator must ensure that every current and future Amazon S3 bucket in the account has server access logging enabled. If a bucket is found without logging, an automated process must enable logging on that bucket. Which solution satisfies this requirement?
- A SysOps administrator must grant a set of IAM users access to AWS services by attaching a policy to them, and also needs the ability to modify that policy and create new versions. Which combination of steps meets these requirements? (Choose two.)
- A SysOps administrator must implement automatic rotation for database credentials used by Amazon RDS. The credentials should be rotated every 30 days and the approach must integrate with RDS while minimizing operational effort. Which option accomplishes this with the least overhead?
- A SysOps administrator must limit Systems Manager Session Manager access to specific groups of EC2 instances. The instances are already labeled with the required tags. What additional tasks must the administrator perform to enforce access controls? (Choose two.)
- A SysOps administrator must produce a report listing the number of bytes sent to and received from each member of an Application Load Balancer (ALB) target group. Which combination of actions should the administrator perform to achieve this? (Choose two.)
- A SysOps administrator must protect the credentials for an Amazon RDS instance that a CloudFormation template will create. The credentials must be stored encrypted and support automatic rotation. Which approach satisfies these requirements?
- A SysOps administrator must provision a fault-tolerant set of Amazon EC2 instances for a high-performance computing workload that needs the lowest possible latency between nodes. Which steps should the administrator perform to satisfy these constraints? (Choose two.)
- A SysOps administrator must reduce RDS failover time by at least 10% in a highly available deployment (EC2 Auto Scaling behind an ALB and an RDS Multi-AZ database). Which change will achieve this reduction?
- A SysOps administrator needs to deploy infrastructure as code and wants a single AWS CloudFormation template that can be reused for multiple environments (for example, dev, test, prod). How should the administrator design the CloudFormation template?
- A SysOps administrator needs to share Amazon RDS snapshots between AWS accounts belonging to different business units. The snapshots must remain encrypted at rest. What approach should the administrator use to accomplish this?
- A SysOps administrator notices that a specific Amazon CloudWatch alarm remains continuously in the ALARM state. What is a likely explanation for why the alarm never leaves ALARM?
- A SysOps administrator reviews an AWS CloudFormation template and observes that stack creation fails. What is the reason the stack cannot be created?
- A SysOps administrator runs an application on EC2 instances behind an Application Load Balancer in a simple scaling Auto Scaling group using default settings. The group scales on the RequestCountPerTarget metric. The administrator observes that RequestCountPerTarget exceeded the threshold twice within 180 seconds. What will happen to the Auto Scaling group in this scenario?
- A SysOps administrator set up CloudWatch alarms for DiskReadBytes and DiskWriteBytes on an EC2 instance to alert based on read/write activity for attached EBS volumes. A local monitoring tool on the instance shows the volume I/O exceeded thresholds, but the CloudWatch alarms never entered the ALARM state. What change will make the CloudWatch alarms report correctly?
- A SysOps administrator starts a Linux EC2 instance in a public subnet and obtains its public IP address. Each attempt to SSH into the instance times out. What change will permit the administrator to remotely connect to the instance?
- A SysOps administrator uses AWS Systems Manager Session Manager to open sessions to EC2 instances. After launching a new EC2 instance, it does not appear in the list of managed instances available for Session Manager, even though the Systems Manager Agent is installed and running. What is the most likely cause?
- A SysOps engineer is troubleshooting performance issues for a company's web application that runs on EC2 instances inside an Auto Scaling group. Traffic surges happen unpredictably and rapidly during the day. The Auto Scaling group is not scaling out quickly enough during sharp spikes, causing slow responses for users. The company wants to control costs while ensuring quick scaling — larger traffic surges should cause larger capacity increases than smaller surges. How should the Auto Scaling group be configured to achieve this behavior?
- A SysOps team wants to automate recovery of an EC2 instance when the underlying host fails. The recovered instance must retain the same private IP and the same Elastic IP as the original instance. The team also must get an email when recovery begins. Which solution satisfies these requirements?
- A systems administrator deleted an Amazon EBS snapshot by mistake, and the company needs a way to recover snapshots for a defined time window after accidental deletions. Which solution provides the ability to recover deleted snapshots for a specified retention period?
- A team accidentally deleted several production DynamoDB tables by running a Lambda that called DeleteTable, causing an outage. You must reduce the likelihood of accidental deletions and limit data loss if deletions happen. Which two actions together best meet these goals? (Choose two.)
- A team is auditing which Trusted Advisor checks are visible for an AWS account. Which factor determines how many Trusted Advisor checks are available to them?
- A team keeps internal files in an Amazon S3 bucket that uses SSE-S3 for server-side encryption and has versioning enabled. The team has already copied all existing objects to a destination bucket in a different AWS account for disaster recovery. The SysOps administrator needs the simplest operational method to keep new objects in the source bucket replicated to the cross-account destination. Which approach is the most operationally efficient?
- A team manages hundreds of EC2 instances and needs to know if any instances will be impacted by upcoming AWS hardware maintenance. Which approach gives that information with the least administrative effort?
- A team will deploy an Amazon Aurora MySQL cluster for a demo environment whose data must be reset every day. Which approach provides the greatest operational efficiency to restore the database to a prior state daily?
- A temporary public static website is hosted in Amazon S3. A bucket was created with default settings, static website hosting enabled, and index.html and error.html objects uploaded. Accessing the website URL returns HTTP 403 Forbidden (Access Denied). What should the SysOps administrator do to fix this?
- A user accidentally modified a database property in a CloudFormation template and executed a stack update, causing application downtime. The DevOps team must still be able to deploy stacks, but accidental changes to particular critical resources must be blocked. Which change to the deployment process will satisfy this requirement?
- A user cannot RDP from a home PC over the internet to a bastion host running Windows on EC2. Which of the following are plausible reasons for the connection problem? (Choose two.)
- A user connected to an EC2 host in a private subnet cannot retrieve http://www.example.com using curl. The VPC configuration shows: the private subnet routes 0.0.0.0/0 to a NAT Gateway; the instance's outbound security group rule allows only port 443 to 0.0.0.0/0; the instance's inbound security group permits ports 22 and 443 from the user's IP; the subnet's inbound NACL permits port 22 and ephemeral ports (1024–65535) from anywhere. What change will enable the curl http request to succeed?
- A user increased the size of an EBS volume attached to a Windows EC2 instance from the EC2 console, but the instance's file system still shows the old capacity. What must a SysOps administrator do to make the extra space usable by the OS?
- A vendor supplies a unit-testing product as an Amazon Machine Image (AMI) for EC2. Configuration settings are kept in Amazon DynamoDB and test outputs are saved to Amazon S3. The product requires at least three EC2 instances to run, and the testing team wants the ability to add three more EC2 instances using Spot Instances when Spot prices meet a target. As a SysOps administrator, design a highly available deployment with minimal operational maintenance. Which approach satisfies these requirements with the least overhead?
- A VPC currently uses IPv4 only with public and private subnets, NAT gateways, route tables, and ACLs already configured. The VPC is assigned an IPv6 CIDR, subnet IPv6 addresses are added, routes updated, and ACLs changed to permit IPv6. Public subnets can access the internet over IPv6, but private subnets cannot initiate IPv6 outbound connections. What should the SysOps administrator do to provide outbound-only IPv6 internet access from the private subnets?
- A VPC has an IPv6 CIDR block and needs outbound internet connectivity. The admin has added the necessary components, but instances still cannot reach internet hostnames. Which additional route entry must be added to the VPC route tables to enable IPv6 internet access?
- A VPC includes a public subnet where a NAT gateway is deployed and a private subnet with EC2 instances that use that NAT gateway to download updates. VPC flow logs for the NAT gateway's ENI are being sent to CloudWatch Logs. The SysOps administrator needs to determine the top five internet destinations that the private subnet instances contact for downloads. What is the most operationally efficient way to get this list?
- A VPC is connected to an on-premises data center via Site-to-Site VPN. EC2 instances in the VPC need to resolve DNS names for example.com using the on-premises DNS servers. Which configuration satisfies this requirement?
- A VPC was created successfully from a CloudFormation template. You need to deploy the same CloudFormation template into many member accounts that are managed under a single AWS Organizations management account. Which method will accomplish this with the least operational effort?
- A web app uses an EC2-hosted MySQL database. The administrator must reduce potential data loss and recovery time if the database server fails, while minimizing operational effort. Which solution is the most operationally efficient?
- A web application is running on three EC2 instances behind an Application Load Balancer. Sporadic spikes in traffic are causing performance to suffer. Which design will automatically scale the application to handle variable load?
- A web application on an EC2 Linux instance shows short spikes in CPU that last about 5 minutes several times each night. You need to capture which process ID is using the CPU during those spikes with as little effort as possible. What should you implement?
- A web application on Auto Scaling EC2 instances experienced out-of-memory errors. The team increased the app memory and now wants to collect operating system memory metrics in CloudWatch, but no memory metric exists for the instances. What should the administrator do to produce a CloudWatch memory metric for these EC2 instances?
- A web application running on an EC2 instance publishes its access logs to CloudWatch Logs. The logs are structured and include HTTP response codes. The team needs an efficient way to monitor how often the server returns HTTP 404 responses. What is the MOST operationally efficient solution?
- A web application runs across several Amazon EC2 instances in an Auto Scaling group. The company wants the group to add instances whenever the instances' CPU utilization goes above 50%. Which Auto Scaling configuration should the SysOps administrator choose to satisfy this requirement?
- A web application runs on EC2 instances behind an Application Load Balancer and is reachable via a public URL. A SysOps administrator needs a monitoring solution that mimics customer interactions (following the same paths and actions) and will alert when fewer than 95% of checks succeed. Which solution satisfies this requirement?
- A web application runs on EC2 instances in a single AWS Region and must remain fully available and perform without degradation even if one Availability Zone fails. The application requires at least 12 instances in total at all times. Which deployment uses the fewest running instances while meeting those requirements?
- A web application runs on EC2 instances registered to an Application Load Balancer (ALB). The instances are in an Auto Scaling group. The administrator wants a CloudWatch alarm that triggers only when every registered target behind the ALB is unhealthy. Which metric condition should the alarm evaluate?
- A web application runs on two EC2 instances behind an Application Load Balancer across two AZs and uses an Amazon RDS Multi-AZ database. Route 53 directs dynamic requests to the ALB and static content requests to an S3 bucket. Users report extremely slow page loads. Which actions will improve site performance? (Choose two.)
- A web application stack uses CloudFront (web distribution), an Application Load Balancer (ALB), Amazon RDS, and EC2 in a VPC. All services have logging enabled. A SysOps administrator needs to examine HTTP (Layer 7) status codes returned by the application. Which log sources will contain those HTTP status codes? (Choose two.)
- A web portal deployed via a single CloudFormation stack in us-east-1 uses an Elastic Load Balancer and Route 53 for DNS. The portal must be resilient across Regions. Which setup meets this requirement?
- A website backed by an Amazon Aurora cluster is experiencing slow response times during peak periods. Users perform searches that are seldom repeated, and traffic patterns vary by season and day. To improve performance while using resources efficiently, which solution should the administrator implement?
- A website is hosted in the Sydney Region and stores many static images and videos in Amazon S3. Customers in the US and Europe report slow load times for media, but users in Australia experience no problems. Which change will produce the greatest improvement in media load performance for the US and European users?
- A website runs a web tier (EC2 Auto Scaling group across two AZs) and a DB tier (RDS for MySQL Multi-AZ). Database subnet network ACLs are restricted to only the web subnets that need DB access; the web subnets use default NACL rules. A third subnet was recently added to the Auto Scaling group. After scaling, some users intermittently see errors that the web server cannot connect to the database. Route tables and security groups have been verified. What changes should a SysOps admin make so web servers in the new subnet can reach the DB instance? (Choose two.)
- A website sits behind an ALB origin for a CloudFront distribution. After routing all traffic through CloudFront with a Route 53 CNAME, mobile clients begin receiving the desktop version of the site. What should the SysOps administrator change to ensure CloudFront preserves device-specific responses?
- A website will run on EC2 instances behind an Application Load Balancer. You will manage DNS with Route 53. Which Route 53 record type should you use to point the zone apex (for example, company.com) to the ALB?
- A website's objects are stored in an S3 bucket with Versioning enabled and served through CloudFront. Recently some files were updated but retained the same object keys, yet users still see the old content. What is the correct way for an administrator to ensure the updated objects are served immediately?
- A Windows file server runs on a fleet of EC2 instances across multiple Availability Zones, but application servers cannot access files concurrently from that fleet. What is the most operationally efficient way to provide concurrent access to the same files for the application servers?
- Accompany wants to track how many Amazon EC2 instances are running and automatically request a service quota increase when the instance count reaches a defined threshold. Which approach satisfies these requirements?
- Account A runs a production app on an EC2 instance that must query a DynamoDB table in Account B. What is the MOST secure way to grant the EC2 instance in Account A access to the table in Account B?
- Administrators across multiple member accounts in an AWS Organization — including those who have root credentials for their accounts — must be prevented from using Amazon DynamoDB, while they retain access to other AWS services. Which method will enforce this restriction organization-wide?
- After a deployment a web application was found vulnerable to cross-site scripting (XSS) during penetration testing, which could expose user data. Which AWS service can help protect the application from this type of attack?
- After acquiring another company and its AWS accounts, Cost Explorer shows that 20% of costs are attributed to "No Tagkey." How should you assign tags to those untagged resources so costs can be allocated properly?
- After applying user-defined tags to resources, the company cannot yet filter by those tags in the AWS Cost Explorer console 20 days later. Why can't the tags be used for Cost Explorer filtering?
- After deploying a new feature, some Auto Scaling group EC2 instances became unhealthy and were terminated before an administrator could investigate. The admin wants an AWS Lambda function to run whenever an instance is being replaced so they can gather diagnostics. How should the admin ensure the Lambda function is invoked during instance replacement?
- After migrating an application to a VPC that is connected to the on-premises network via a Site-to-Site VPN, the application can no longer resolve internal hostnames that an on-premises DNS server answers. Which approach will allow the VPC-based application to resolve the on-premises domain names?
- After moving an application to AWS, a company runs it on EC2 instances across several instance families. Performance problems appear on some instances during testing, and strict budget controls require selecting instance types that match workload needs. Which course of action should the SysOps administrator take?
- After purchasing Savings Plans, the company wants email alerts when daily Savings Plans utilization falls below 90%. Which of the following will achieve this?
- After replacing NAT instance appliances with NAT gateways, EC2 instances in a private subnet cannot reach the internet. Which of the following could be reasons for this failure? (Choose two.)
- After terminating EC2 instances, several Elastic IP addresses remain allocated but unassociated. The company wants to automatically release any Elastic IP addresses that are left unattached after instance termination with the LEAST operational effort. Which design best satisfies this requirement?
- All new Amazon EC2 Windows instances in the account must have a third-party .msi agent installed and kept up to date automatically. The environment already uses AWS Systems Manager and instances are tagged. Which combination of steps will achieve this with the least operational overhead? (Choose two.)
- An account's root user has multi-factor authentication enabled, but the physical MFA device was lost. A SysOps administrator must change the account's AWS Support plan. How should the administrator sign in to proceed?
- An administrator built a custom AMI in the eu-west-2 Region and used it to start EC2 instances there. The administrator now needs to launch instances from that same AMI in us-east-1 and us-east-2. What must be done so the AMI can be used in those other Regions?
- An administrator created a custom EC2 instance with software and encrypted EBS volumes using AWS-managed keys. They made an AMI from that instance and want to share that AMI with other company AWS accounts. Company policy requires AMIs to be encrypted with KMS customer-managed keys and only accessible to authorized accounts. Which process securely shares the AMI while meeting the requirement?
- An administrator creates a new VPC containing one public subnet and one private subnet. The administrator successfully launches 11 EC2 instances inside the private subnet. When attempting to start a 12th instance in the same subnet, the launch fails with an error indicating there are no available IP addresses. What should the administrator do to accommodate additional EC2 instances in that subnet?
- An administrator creates two separate VPCs in the same AWS account: VPC-A and VPC-B. A Linux EC2 instance runs in VPC-A, and an Amazon RDS for MySQL instance is deployed in a private subnet in VPC-B. The application on the EC2 instance must connect to the database in VPC-B. What should the administrator do to allow the EC2 instance to reach the RDS instance?
- An administrator enabled S3 Cross-Region Replication for a source bucket. By default, which of the following items is replicated to the destination bucket?
- An administrator has automated backups enabled for an Amazon RDS for PostgreSQL instance with a 7-day retention period, but no automated snapshots have been produced for over a month. What is a likely explanation for the absence of automated backups?
- An administrator in Account A has created an AWS Service Catalog portfolio and shared it with a different administrator in Account B. What action can the Account B administrator perform on the shared portfolio?
- An administrator needs to download OS patches from the internet to an EC2 instance located in a private subnet. The VPC has an internet gateway and a NAT gateway placed in a public subnet, but the instance still cannot reach the internet. The private subnet must remain unreachable from the public internet. Given the following route tables, what entry should be added to the private subnet’s route table to enable outbound internet access?
- An administrator runs an application on Amazon EC2 instances and needs to allow that application to call an Amazon DynamoDB table. Which approach satisfies this requirement securely and correctly?
- An alarm on the Aurora PostgreSQL FreeLocalStorage metric indicates the production database is low on temporary space. The administrator finds a weekly report consumes most of the temp storage. What is the appropriate action to address the temporary storage contention caused by the report?
- An Amazon Aurora MySQL cluster has automatic backups, point-in-time recovery, and backtracking enabled. You must revert the existing production cluster to a specific recovery point within the last 72 hours, performing the rollback in-place on the same DB cluster. What should you use?
- An Amazon EC2 instance has become unresponsive, and the EC2 console shows that the instance is failing the system status checks. What is the administrator's first action to try to restore service?
- An Amazon Linux 2 EC2 instance is not sending its logs to CloudWatch Logs even though the CloudWatch agent is running and the agent configuration is correct. Company policy requires all EC2 logs be published to CloudWatch Logs. What should the SysOps administrator check to resolve this?
- An Amazon RDS for PostgreSQL cluster has automated backups enabled with a 7-day retention. An administrator must create a new RDS cluster containing data no older than 24 hours from the original cluster. Which options satisfy this requirement while minimizing operational effort? (Choose two.)
- An application currently sends unique messages to an Amazon SQS standard queue. The team wants to move to an SQS FIFO queue. What changes are required to migrate successfully?
- An application currently uses an overly permissive IAM role that grants full access to all AWS services. The SysOps administrator needs to produce a policy that grants only the permissions the application actually requires. What steps should the administrator take to generate such a policy?
- An application deployed on EC2 instances across multiple Availability Zones must scale to millions of requests per second and handle highly variable, bursty traffic. The solution must provide a single static IP address per Availability Zone. Which service satisfies these requirements for distributing traffic to the instances?
- An application deployed on EC2 instances connects to data in an Amazon RDS instance. In production the app cannot connect, although the database is reachable from a bastion host shell. Web server logs repeatedly show: *** Error Establishing a Database Connection Which of the following could explain the connection failures? (Choose two.)
- An application ingests messages from thousands of alarm systems. Messages comprise high-priority alarm alerts and lower-priority informational messages (arming/disarming, sensor states). All messages are stored in a single Amazon SQS queue and processed by EC2 workers in an Auto Scaling group. The administrator must ensure alarm alerts are processed before informational messages. Which design meets this requirement?
- An application is deployed active-passive across two Regions. Each Region has EC2 instances in an Auto Scaling group behind an ALB. DNS is managed in Route 53. The SysOps administrator must set up automatic failover to the secondary Region. What should be done?
- An application is hosted by a third-party provider at app.example.com. You own the domain company.com and manage its DNS in Amazon Route 53. You want users who visit www.company.com to be directed to the third-party-hosted application. Which Route 53 record type should you create?
- An application is hosted on Amazon EC2 instances that are part of an Auto Scaling group using a launch template. Traffic varies during the day and scale-in events occur frequently. When an instance is removed during scale-in, EC2 Auto Scaling terminates it before developers can SSH in to investigate. What change will prevent an instance from being terminated so developers have time to log in and debug it?
- An application is reachable both through a CloudFront distribution and directly via an internet-facing Application Load Balancer (ALB). The administrator must ensure the app is only accessible through CloudFront and not directly through the ALB, without modifying the application code. Which configuration accomplishes this?
- An application is writing log events to Amazon CloudWatch Logs, and one field records application latency. The administrator needs to track the p90 (90th percentile) of that latency field over time. What should be done to collect that metric?
- An application on an EC2 instance needs permissions to send, receive, and delete messages from specific Amazon SQS queues. Which approach provides the required permissions in the most secure way?
- An application requires a temporary, high-speed cache on an EC2 host. The cache is frequently updated and does not need to persist across instance reboots. Which storage choice will deliver the best possible performance for this cache?
- An application running in a VPC that uses the default DHCP options needs to resolve the on-premises SQL Server host name mssql.example.com, but DNS lookups fail. Which change will allow the VPC-hosted application to resolve that on-premises domain name?
- An application runs across hundreds of EC2 instances in three Availability Zones and calls a third-party API on the internet. The third party requires a fixed list of source IP addresses to whitelist. Which design will provide a set of static outbound IPs for the traffic?
- An application runs across Linux EC2 instances in an Auto Scaling group. The instances are launched from a launch template and use gp3 EBS volumes for primary storage. The team needs all instances to access the same files with data consistency. Which solution will provide a shared, consistent file system for all instances?
- An application runs behind an Application Load Balancer (ALB) in the us-west-2 Region. A Route 53 record set contains an alias for app.anycompany.com that points to that ALB using a simple routing policy. The company has deployed the same application into ap-southeast-2 because many new users are in that region and are seeing high latency. A SysOps admin must ensure requests are automatically routed to the lowest-latency ALB for each user without changing the hostname. Which approach satisfies this requirement?
- An application runs exclusively on Amazon EC2 Spot Instances within an Auto Scaling group that also uses scheduled scaling actions. However, instances frequently fail to start on schedule and are interrupted multiple times per day. What change will help ensure instances launch reliably at scheduled times and experience fewer interruptions?
- An application runs on a set of Amazon EC2 instances behind an Elastic Load Balancer and is managed by an Auto Scaling group. For most of the day performance is stable, but each day there is the same 4-hour spike in traffic that degrades performance. Which solution is the MOST operationally efficient way to address the recurring slowdown?
- An application runs on EC2 instances behind an Application Load Balancer (ALB). The SysOps admin must create a custom health check for the instances. What is the most operationally simple way to implement this?
- An application runs on EC2 instances behind an Application Load Balancer and is scaled with an Auto Scaling group. Occasionally the application becomes slow; CloudWatch shows some instances have very high CPU. The administrator must build a CloudWatch dashboard that automatically shows CPU metrics for every EC2 instance, including instances launched later by Auto Scaling. What is the most operationally efficient way to do this?
- An application runs on EC2 instances behind an Application Load Balancer (ALB) in an Auto Scaling group. The application starts producing errors whenever total requests exceed 100 requests per second. The administrator needs to collect total request counts over a two-week period to find when the threshold was exceeded. What is the appropriate way to gather this data?
- An application runs on EC2 instances behind an Application Load Balancer distributed across three Availability Zones. Customers require that the application be accessible via no more than two static IP addresses. What solution should the SysOps administrator implement?
- An application runs on EC2 instances inside private subnets of a VPC. The application must be able to download software updates from the internet, and company policy mandates that all EC2 instances reside in private subnets. What should a SysOps administrator do to provide internet access for outbound updates while keeping instances private?
- An application runs on three EC2 instances across three Availability Zones behind a Network Load Balancer (NLB). The administrator must restrict instance traffic so that only requests coming from the NLB are allowed. Which approach meets this requirement with the least operational work?
- An application team cannot state normal usage or future growth, yet you must create CloudWatch alarms for the application. Which approach should you recommend for alarm creation under these conditions?
- An application uses a filesystem API to read and write data. It runs on EC2 instances across multiple Availability Zones and all instances must share the same filesystem. Data is small today but is expected to grow to tens of terabytes over time. Which storage approach scales best for this requirement?
- An application uses Amazon RDS for MariaDB in Multi-AZ and suffers several minutes of unavailability whenever a planned maintenance failover occurs. What should a SysOps administrator implement to minimize application downtime during failover?
- An application uses an Amazon EFS file system. A recent application bug corrupted several files, and the company wants a cost-effective way to back up and recover EFS so that individual files can be restored quickly. Which option best satisfies these requirements at the lowest cost?
- An application uses an Aurora MySQL cluster with a single read replica. Read performance worsens when connections exceed 200; normal load is about 180 connections but sometimes spikes above 200. The administrator needs the system to scale automatically as user connections rise and fall. Which approach satisfies this requirement?
- An application uses MySQL on an EC2 instance with a General Purpose SSD (gp) EBS volume. After code changes, you need to create a new MySQL instance from a snapshot of production for realistic load testing. Which restore option will produce a new volume that behaves most like the current production volume?
- An application will be deployed to EC2 instances in an Auto Scaling group and requires installing dependencies. Updates are released weekly and the build process must include a vulnerability scan when creating the AMI. Which approach provides the greatest operational efficiency while meeting these needs?
- An application’s database was moved from a public subnet that used a public endpoint into a private subnet to remove public network access. After this change, an AWS Lambda function that needs read access can no longer reach the database. The administrator must restore connectivity without opening the database to the public internet. Which approach satisfies this requirement?
- An Aurora MySQL cluster with one read replica slows down when concurrent client connections exceed 200 (typical load ~180, with spikes past 200). The team wants the database to autoscale as demand varies. Which change will meet this goal?
- An Auto Scaling group for a web application experiences slow scale-out because instance bootstrapping scripts take a long time. The administrator wants to shorten time to serve traffic during scale-out without increasing excess capacity. Which change will accomplish this most effectively?
- An Auto Scaling group fronts EC2 instances behind an ALB and the application is receiving malicious traffic originating from a single public IP. You must block that IP address from reaching the application. Which solution will block the IP effectively?
- An Auto Scaling group has just scaled up after CloudWatch recorded a spike in the ALB RequestCount metric. The administrator wants to identify the source IP addresses for these requests. Where is this information logged?
- An Auto Scaling group has two nearly identical scaling policies: one adds 5 instances when average CPU reaches 80%, and the other adds 10 instances at the same 80% threshold. When the CPU hits 80%, what will the Auto Scaling group do?
- An Auto Scaling group launches Amazon EC2 instances and scales using average CPU utilization as the metric. The Auto Scaling events show InsufficientInstanceCapacity errors. What steps should a SysOps administrator take to fix this problem? (Choose two.)
- An Auto Scaling group of EC2 instances runs Application A behind a Network Load Balancer in the same subnet. On-premises systems cannot reach Application A on port 8080. Flow logs were reviewed and show rejected traffic. What explains the rejected connections?
- An Auto Scaling group of On-Demand EC2 instances processes messages from an SQS queue. Each message can take up to 12 hours to finish processing. The Auto Scaling group scales based on the queue length. How should the SysOps administrator prevent in-flight message processing from being interrupted by instance termination?
- An Auto Scaling lifecycle hook is set to send events to EventBridge, which should trigger a Lambda function to configure new EC2 instances. The Lambda then calls the complete-lifecycle-action to let instances enter service. During testing the Lambda is never invoked. What should you do to fix this?
- An AWS Lambda function is performing many CPU-bound operations and is slower than required, creating a throughput bottleneck. What should a SysOps administrator change to improve the function’s performance?
- An AWS Organization creates a new member account. A SysOps administrator needs to upgrade that account to AWS Business Support. Which steps should the administrator take? (Choose two.)
- An EC2 instance (t3.large) running a test web app consistently shows high CPU usage. The team determines the app would perform better on a compute-optimized large instance. What is the proper procedure for the SysOps admin to change the instance type?
- An ecommerce app keeps many idle connections to an Amazon Aurora cluster and during peaks the database returns "Too many connections." Clients also receive errors. Which change will fix this issue?
- An ecommerce application uses an Amazon Aurora cluster with memory-optimized instances (one writer and one reader). During sudden traffic spikes CloudWatch shows high RAM usage and increased SELECT latency. The change must improve DB cluster performance with minimal downtime and without data loss. Which modification is the best choice?
- An ecommerce site uses Amazon ElastiCache for Memcached to cache popular product queries. CloudWatch metrics show many cache evictions. Which actions will help reduce eviction counts? (Choose two.)
- An ElastiCache for Redis cluster consists of two xlarge nodes in different Availability Zones and the monitoring shows approximately 75% of memory is freeable. The application requires high availability to be preserved. What is the most cost-effective method to resize the cluster?
- An encrypted S3 bucket resides in ap-southeast-2 but users in eu-west-2 access it over the internet and need faster transfer performance for large files. Which approach will improve throughput for these remote users?
- An external auditor is assessing the company’s AWS-hosted infrastructure for PCI DSS compliance. Which action should a SysOps administrator take to provide the auditors with AWS compliance documentation?
- An HPC workload runs on multiple Amazon EC2 instances and requires the lowest possible latency and the highest network throughput between the instances. How should a SysOps administrator place the EC2 instances to meet these networking requirements?
- An IAM user has a policy attached (policy contents not shown). Which of the following specific actions would be permitted for that IAM user?
- An IAM user's access key was accidentally published in a public repository. The SysOps administrator must determine what actions the compromised key was used to perform. Which method should be used to identify actions taken with that key during the suspected timeframe?
- An ML-based monitoring service is configured as an EventBridge API destination to consume Auto Scaling events. CloudWatch indicates the EventBridge rule is firing, but the monitoring service is not receiving events. The SysOps administrator wants to capture client error details with minimal operational effort. Which solution should be implemented?
- An on-premises application needs backups to AWS but all backed-up data must remain available locally. The backup software can only write to POSIX-compatible block devices. Which AWS backup approach satisfies these constraints?
- An on-premises application uses the hostname host1.onprem.private. Another app on an EC2 instance uses host1.awscloud.private. A Site-to-Site VPN connects the two networks, but the on-prem app cannot resolve the EC2 hostname. Which configuration will allow the on-premises DNS resolver to resolve host1.awscloud.private?
- An on-premises environment needs to resolve records in a Route 53 private hosted zone (example.com) over a Direct Connect link to a VPC. What should the SysOps administrator configure so an on-premises DNS server can query the example.com private hosted zone?
- An online retailer uses ElastiCache for Redis to cache popular product queries. The cluster is currently evicting keys at random, regardless of TTL, and the cache hit rate is lower than desired. Without increasing the cluster size or cost, how can the SysOps administrator improve the hit ratio?
- An organization has an active Amazon EFS file system (fs-85ba41fc) used by 10 EC2 instances. They are concerned the file system is not encrypted. How can they ensure the file system is encrypted while preserving data access?
- An organization has many AWS accounts under AWS Organizations. The central management account needs to automate resource deployment across the member accounts. Which approach satisfies this requirement?
- An organization has multiple AWS accounts under AWS Organizations. Administrators have been using the root user credentials in member accounts, and the company wants to block any root-user actions on EC2 resources across all member accounts. What is the appropriate way for a SysOps administrator to enforce this requirement centrally?
- An organization manages accounts with AWS Organizations and needs a backup strategy for all EC2 instances across every account. The approach should be the most operationally efficient way to apply backups company-wide. Which solution meets this requirement?
- An organization must provision an application and its supporting resources across several AWS Regions using a single CloudFormation template. They use AWS Organizations and want to initiate and manage the deployment from a single management account. Which approach should a SysOps administrator use to satisfy these constraints?
- An organization runs an encrypted Amazon RDS for Oracle instance and needs its backups to be routinely available in a different AWS Region. Which approach is the MOST operationally efficient and satisfies this requirement?
- An organization tracks five Trusted Advisor service quota metrics in a single AWS Region and wants to be emailed whenever any quota’s usage goes above 60%. What approach satisfies this requirement?
- An organization uses AWS Control Tower and wants to centralize identity by federating AWS IAM Identity Center with an external SAML 2.0 identity provider. What items must the SysOps administrator have available before connecting the external IdP? (Choose two.)
- An organization uses AWS Organizations and must restrict EC2 instance creation to an approved set of AWS Regions only. The administrator needs to stop anyone in the company from launching EC2 instances in disallowed Regions. What is the most operationally efficient way to enforce this policy across all member accounts?
- An organization uses AWS Organizations with multiple AWS accounts and wants centralized user and permission management integrated with its on-premises Active Directory. IAM Identity Center (SSO) is enabled and Direct Connect exists. Which solution is the most operationally efficient to integrate the on-premises AD with IAM Identity Center?
- An organization uses AWS Organizations with separate accounts for security and for logging. The SysOps administrator must implement a centralized alerting approach so that when any account’s resource metric crosses a defined threshold, an alert is generated. Which implementation satisfies this requirement?
- An organization wants a centralized, automated method across all accounts in AWS Organizations to detect security groups that permit inbound traffic from 0.0.0.0/0 and to automatically remediate violations by replacing that wide-open source with the company's approved intranet CIDR. What actions should a SysOps administrator implement to achieve this?
- An RDS database running as a Multi-AZ DB instance failed a security audit because it is unencrypted. Which method will bring the database into compliance by enabling encryption?
- An S3 gateway endpoint is configured in a VPC whose private subnets lack outbound internet access. A user on an EC2 instance in one of those private subnets is unable to PUT a file into an S3 bucket in the same Region. Which change will resolve the upload failure?
- AnyCompany acquired Example Corp and needs to integrate AnyCompany’s CloudWatch alarms for EC2 into Example Corp’s ticketing system. The ticketing system exposes an HTTPS endpoint that accepts tickets in a specific JSON structure. Which solution will enable CloudWatch alarms to create tickets at the external HTTPS endpoint with the least development effort?
- Attempts to launch EC2 instances into a VPC are failing because there are no available private IPv4 addresses. Which combination of actions will allow the SysOps administrator to launch the instances? (Choose two.)
- AWS Backup is configured to snapshot a single EC2 instance that has one EBS volume. Snapshot 1 captures 10 GiB of data. Snapshot 2 occurs later when 4 GiB of the volume's data has changed. Snapshot 3 happens after an additional 2 GiB of new data is written, bringing the volume to 12 GiB total. How much snapshot storage will be required in total to store all three snapshots?
- CloudTrail is enabled and delivers log files to an Amazon S3 bucket. The operations team is worried that delivered log files might be altered after arrival in the bucket. Going forward, how can the administrator verify that individual CloudTrail log files were not modified after delivery?
- CloudTrail is enabled in an AWS account, and the requirement is to automatically re-enable CloudTrail immediately if it gets turned off — without writing custom code. Which approach meets this requirement?
- CloudWatch alarms based on static thresholds are not helping an EKS cluster operate efficiently. The SysOps admin wants a solution that detects anomalous behavior and offers actionable recommendations for remediation. Which option meets these requirements?
- Company policy now forbids any S3 data in the account from being publicly accessible. What action should a SysOps administrator take to enforce this requirement across the account?
- Customers are experiencing higher latency when requesting static website files stored in an Amazon S3 bucket. A SysOps administrator notes the bucket is receiving an extremely high number of GET requests. What approach will reduce latency by lowering direct load on the S3 bucket?
- Customers upload files to S3 and an SQS message containing the object ARN is sent. An EC2-based worker polls SQS and processes files; processing time varies with file size. To reduce customer-perceived delays, an administrator creates an AMI from the existing instance and a launch template. How should Auto Scaling be configured to improve responsiveness?
- Developers must only launch EC2 instances from an approved set of AMIs, but some are still starting instances from unapproved images. The operations team needs an automated way to detect and terminate any EC2 instance launched from an AMI that is not on the approved list. Which approach satisfies this requirement?
- Developers must receive immediate notifications when a specific AWS Lambda function throws an error. Which configuration accomplishes this requirement?
- Developers run long CPU-heavy jobs on EC2 and frequently forget to terminate instances when idle. You must monitor CPU utilization and automatically terminate underutilized instances. Which solution meets this requirement?
- During a DR test, a company must restore recent EBS snapshots to a new EC2 instance in another Availability Zone and immediately validate that the restored volumes deliver their full provisioned performance. Which configuration will provide the required performance as quickly as possible?
- During load testing, high CPU on EC2 instances behind an ALB causes the Auto Scaling group to scale out. You need to diagnose the high CPU issue on the instances before new instances are launched. What action will prevent additional scale-out events so you can troubleshoot?
- EC2 instances are in a private subnet and must access S3 buckets in the same Region. No changes are allowed to the instances or application, and the instances must not have internet access. Which approach satisfies these constraints?
- Every time a new object is added to a specific Amazon S3 bucket, the company needs an automated email alert and a database record inserted. Which design is the MOST operationally efficient way to achieve both tasks?
- GuardDuty reports suspicious outbound network traffic from an EC2 instance and identifies an unfamiliar external IP address as the destination. The administrator needs to prevent traffic to that external IP immediately. Which action will accomplish this?
- Hybrid applications use resources both on premises and in AWS. Users sometimes report the apps are unavailable. A CloudWatch alarm already monitors the Site-to-Site VPN tunnel status. The Ops team needs high-priority tickets created automatically in an internal ticketing system when the VPN tunnel goes down. Which design meets this need?
- Managers of member accounts in an AWS Organization want billing notifications when estimated monthly charges exceed a set threshold, but they cannot create billing alarms despite having correct IAM permissions. What is the most likely reason?
- Multiple EC2 instances in a dev environment run a resource-heavy app. The SysOps administrator needs an automated way to stop these instances when they are idle. Which method will meet this need?
- Multiple Lambda functions each produce about 1 GB of CloudWatch Logs per day in separate log groups. The security team wants counts of application errors grouped by error type across all these log groups. What should the SysOps admin use?
- Objects are being replicated from a production S3 bucket in one account to a destination bucket in a nonproduction account using cross-account, cross-Region replication. When trying to access the replicated objects in the destination bucket, the administrator gets Access Denied. What change will allow access to the replicated objects?
- On-call engineers must frequently access EC2 instances in a private subnet for troubleshooting. Instances run either current AWS Windows AMIs or Amazon Linux, and an IAM role already exists for authorization. Which solution grants the engineers access by using IAM permissions on that role?
- Patch Manager in AWS Systems Manager is being used to apply updates to a set of EC2 instances. A patch baseline and maintenance window are configured, and instances are selected by a tag. What additional step is required so Systems Manager can access and patch those EC2 instances?
- Public access has been blocked on all corporate S3 buckets. The administrator wants an automated notification if any bucket becomes publicly readable later. What is the most operationally efficient way to accomplish this?
- Route 53 hosted zones are centrally managed in a shared AWS account. A developer in the development account needs a new TLS/SSL certificate for an application in that account. What is the correct way for the SysOps administrator to obtain and validate the certificate?
- Scientists upload large datasets to an S3 bucket using multipart uploads, but uploads often fail due to poor client connectivity. The company wants visibility into the size of incomplete multipart uploads and to automatically remove any parts left incomplete after 7 days to control storage costs. Which implementation satisfies these needs?
- Several business units must provision EC2 instances, but the company requires that they use only approved, standardized instance configurations. What is the best way for the SysOps administrator to enforce that requirement?
- Some EC2 instances are reported as healthy by the Auto Scaling group but are marked unhealthy in the ALB target group. Which of the following is a likely cause?
- The admin must monitor free disk space on EBS volumes attached to Windows EC2 instances and receive email alerts before low storage impacts performance. What should the admin implement?
- The architecture team must get immediate email alerts whenever any new EC2 instances are started in the production AWS account. What should the SysOps administrator implement to meet this requirement?
- The company enforces a rule that no security group should allow SSH from 0.0.0.0/0. A SysOps administrator must implement a solution that alerts the operations team when a security group breaks this rule and must automatically remediate the offending rule. Which design satisfies both requirements?
- The company has common infrastructure components declared in several CloudFormation templates. The SysOps admin needs modular templates for these shared components with their own parameters and conditions. Which CloudFormation approach satisfies this requirement?
- The company hosts production workloads in multiple AWS accounts. EC2 instances run Amazon Linux 2 across several VPCs. Each VPC uses its own Route 53 private hosted zone for internal DNS. A VPC in Account A must be able to resolve private DNS records that belong to a private hosted zone associated with a VPC in Account B. What steps should the SysOps administrator take to enable this cross-account resolution?
- The company is nearing its EC2 instance service quota and needs an automatic alert when utilization of that quota reaches 70% so scaling issues can be addressed. Which approach provides the most operationally efficient way to get this notification?
- The company migrated servers to EC2 and needs to monitor memory utilization and free disk space using CloudWatch. What is the appropriate action for a SysOps administrator to enable those metrics across all instances?
- The company must enforce tag requirements on all Amazon DynamoDB tables across accounts. A SysOps admin needs a low-maintenance solution that finds tables missing required tags and remediates them. Which solution provides enforcement with the least ongoing operational work?
- The company needs a managed file system that presents Windows SMB shares on premises and also makes those shares available in AWS with minimal latency. Which solution should the SysOps administrator deploy?
- The company needs to ensure specific software is installed on EC2 instances automatically when they launch. Which AWS service and configuration will perform this installation at instance startup?
- The company needs to monitor its public website and send an Amazon SNS notification if availability falls below 99% as experienced by end users. Which design will produce an accurate user-experience view and meet the requirement?
- The company plans to run EC2 instances using only IPv6 addresses. These instances must be prevented from receiving inbound connections from the public internet, yet they must be able to initiate outbound internet connections. The VPC is dual-stack and the subnets are IPv6-only. How should the SysOps administrator configure routing to satisfy these requirements?
- The company put a public Network Load Balancer in front of its application. The application instances do not use Elastic IP addresses. Users should reach the app using the corporate domain name. What is the most cost-effective Route 53 configuration to route traffic to the NLB?
- The company requires a recorded history of any changes to security groups and wants the SysOps administrator notified whenever a security group is modified. Which implementation accomplishes both goals?
- The company requires that all AWS account activity be logged with CloudTrail and that an administrator be alerted when CloudTrail log files are altered or removed. How should the SysOps administrator meet both requirements?
- The company runs servers on premises and in AWS. A SysOps administrator needs to automate tasks across all on-premises servers using AWS tooling but must avoid placing long-lived credentials on those servers. What is the recommended way to register and manage the on-premises servers with AWS for automation?
- The company updated its security policy: any sensitive, regulated workloads must run on physical servers that are not shared with other AWS customers or with other AWS accounts belonging to the company. Which deployment option enforces this requirement?
- The company uses CloudTrail to record user activity and must protect those log files from being altered, removed, or forged to meet new security standards. Which approach fulfills this requirement?
- The company wants continuous monitoring to detect when any EC2 security group permits SSH from the public internet and to automatically close that port when detected. Which combination of actions should the SysOps administrator implement? (Choose two.)
- The company wants to block developers from launching a specific EC2 instance family across multiple AWS accounts that are managed with AWS Organizations. What is the most operationally efficient way to apply the service control policy restriction to all those accounts?
- The company wants to lower costs for its Amazon EC2 and AWS Lambda usage. Which of the following steps should a SysOps administrator perform to help achieve cost reduction goals?
- The company will host a static website for example.com and www.example.com using Amazon S3. How should you set up S3 to serve both the root domain and the www subdomain?
- The finance team needs near-real-time dashboards (with hourly granularity) showing cost trends across multiple AWS accounts in an Organization. What is the most operationally efficient solution to provide detailed cost metrics and dashboards?
- The finance team needs project-level cost visibility in Cost Explorer. What initial setup must a SysOps administrator perform so costs can be broken down by project?
- The finance team wants alerts when actual and forecasted AWS spending exceed defined thresholds. Which solution provides these notifications with minimal ongoing operational effort?
- The organization requires MFA for all IAM users and wants all API calls made via the CLI to be authenticated with MFA. An IAM policy denying calls without MFA was attached, but users still make CLI API calls without being prompted for tokens. What additional step is needed so CLI API calls require MFA?
- The organization uses AWS Organizations and must create automated daily incremental backups for any EBS volume tagged with Lifecycle: Production in a primary account. They also want to prevent users from deleting these production snapshots via EC2 permissions. Which solution meets both needs?
- The organization wants to receive an email alert whenever an IAM CreateUser API call occurs in the account. Which combination of steps should a SysOps administrator take to achieve this? (Choose two.)
- The security team is tracking growth in the number of IAM policies in use and needs a report that shows how many policies exist compared to AWS service limits. Which AWS service should be used to compare current IAM policy usage against available quotas?
- The security team needs confirmation that every current object in an S3 bucket is encrypted. Which solution provides the most operationally efficient way to verify encryption status across all objects?
- The security team wants a native AWS service to continuously assess all member accounts in an AWS Organization against the CIS AWS Foundations Benchmark. Which approach is the most operationally efficient?
- The security team wants continuous detection of potentially unauthorized AWS Management Console sign-ins that originate from multiple geographic locations within an AWS account. Which AWS service and finding should be used to automatically detect these suspicious console logins?
- The SysOps administrator must monitor inter-Region data transfer spending and notify an email distribution list when transfer costs reach 75% of a predefined threshold. Which approach meets these requirements?
- There are 100 Windows EC2 instances in an environment. The CloudWatch agent is installed on all instances with a baseline config that collects log files. Now 50 instances need to start collecting DHCP logs as well. What is the most operationally efficient way to implement this change?
- To enforce tagging policy, an administrator needs any EC2 instance that lacks a department tag to be terminated almost immediately after creation. Which implementation will detect noncompliant instances and terminate them in near real time?
- Trusted Advisor flags an S3 bucket policy that allows open access. The bucket owner explains the bucket is used as the origin for a CloudFront distribution. What is the appropriate action to ensure objects in S3 are served only via CloudFront and not directly from S3 URLs?
- Trusted Advisor reports that all application servers for a financial service are flagged as Low Utilization EC2 instances. The application runs on three instances across three Availability Zones. The administrator needs to lower running costs without altering the application’s availability or architecture. Which action meets this requirement?
- Two VPCs exist in the account: VPC A uses CIDR 10.0.0.0/16 and VPC B uses CIDR 172.31.0.0/16. A VPC peering connection with ID pcx-12345 is established between them. After configuring peering, which entries should be present in VPC A's route table? (Choose two.)
- Users report they are being unexpectedly logged out of a stateful web app earlier than its 15-minute timeout. The app runs on EC2 instances in an Auto Scaling group behind an Application Load Balancer (one target group). The ALB is the origin for a CloudFront distribution. Sticky sessions are enabled on the ALB using duration-based cookies, and the app also issues its own session cookie. Which combination of changes should the SysOps administrator implement to stop the premature logouts? (Choose two.)
- VPC flow logs are configured to deliver records to CloudWatch Logs, but no logs are arriving. Which issue is most likely preventing the flow logs from being published to CloudWatch Logs?
- When an AWS incident occurs that could affect an organization's resources, which AWS offering provides information about which of that organization's specific resources are impacted?
- When creating a CloudFormation stack, an EC2 instance resource fails with an InsufficientInstanceCapacity error. Which steps should the SysOps administrator take to fix this? (Choose two.)
- When provisioning additional EC2 instances in anticipation of higher traffic, the request fails with an InstanceLimitExceeded error. What is the appropriate action to resolve this limitation?
- While an application rewrite is underway (12 months), the company needs an automated, low‑operational-effort way to find and rotate IAM access keys that are at least 30 days old, and then continue rotating keys every 30 days. Which solution provides the required automation with the least operational overhead?
- While analyzing VPC Flow Logs to debug connectivity, an administrator notices there are no entries for rejected traffic. What action should be taken to ensure the logs capture all traffic, including rejected packets?
- While creating an EC2 Auto Scaling group in a fresh AWS account, the group cannot reach its minimum capacity. The Auto Scaling activity shows: "Status Reason: Your quota allows for 0 more running instance(s). You requested at least 1." Which action will correct this problem?
- While testing a CloudFormation stack, the creation failed and CloudFormation automatically deleted the stack and any resources that had been created, preventing failure analysis. For future stacks, the SysOps admin wants to keep resources that were successfully created when a stack creation fails. What stack creation option achieves this?
- Who must sign in to modify the name of an AWS account?
- Within an AWS Organization, the company requires that S3 buckets in all production accounts never be deletable. What is the SIMPLEST way for a SysOps administrator to enforce that no S3 buckets in those accounts can be deleted?
- Within AWS Organizations, a SysOps admin is attempting to enable AWS Compute Optimizer and tag policies from the management account to apply across all member accounts, but activation of tag policies is unavailable. What is the most likely cause?
- You added an Auto Scaling group and an Application Load Balancer to handle increased traffic for an application running on EC2, but the instances are failing the ALB health checks. What is the best first step to diagnose the problem?
- You are attempting to delete an AWS CloudFormation stack but its status is DELETE_FAILED. You have verified you have the required permissions. Which of the following could cause the DELETE_FAILED status? (Choose two.)
- You are configuring an Auto Scaling group for an application. The fleet must maintain 50% spare CPU capacity at all times to handle sudden spikes. Traffic rises substantially from 09:00 to 17:00 every day. How should you configure scaling to meet these requirements?
- You are configuring an AWS-managed VPN and must create a customer gateway resource for a device that sits inside your data center behind a NAT gateway. Which IP address should you supply when creating the customer gateway in AWS?
- You are configuring AWS Client VPN so that on-premises users can access resources in a VPC, but compliance requires that only traffic destined for the VPC go across the VPN tunnel. How should the Client VPN endpoint be configured to enforce this?
- You are deploying a web application with AWS Elastic Beanstalk and need deployments that always keep the previous capacity fully available while the new version deploys. Which Elastic Beanstalk deployment policies meet this requirement? (Choose two.)
- You are deploying an Auto Scaling group via a CloudFormation template. The launch template runs a user data script that calls cfn-signal when finished, but CloudFormation fails to create the Auto Scaling Group because the wait condition does not receive the required signals. What should you do to fix this failure?
- You are deploying resources with CloudFormation StackSets across two Regions in the same account. One Region's stack operation fails and the stack instance shows the status OUTDATED. What is the likely reason for this failure?
- You are designing for an RDS for PostgreSQL instance whose database credentials must be rotated monthly. Client applications generate write-heavy traffic and have bursts of many connections. Which combination best satisfies credential rotation and handling connection spikes?
- You are implementing Route 53 failover for an on-premises website that has an active primary server and a passive secondary server. The primary should receive traffic only when its health check returns HTTP 2xx or 3xx responses; otherwise all traffic must go to the secondary. The failover routing and set IDs are already configured for both records. What is the next configuration step?
- You built an application as an AWS CloudFormation template that you will deploy across multiple Regions. You manually created a CloudWatch dashboard in the console, and each stack deployment must have its own dashboard. How can you automate creation of the CloudWatch dashboard whenever the CloudFormation stack is deployed?
- You create custom AMIs by launching EC2 instances via a CloudFormation template, installing software with AWS OpsWorks (which can take 2–3 hours), and then imaging the instances. Sometimes the install stalls, and you want the CloudFormation stack to fail and roll back if that happens. What should you add to the template to enforce this with a 4-hour limit?
- You created a new VPC and added resource records to an existing Route 53 private hosted zone so that those names should resolve inside the VPC. What final action completes the setup so the VPC can resolve the private zone names?
- You deploy an application to EC2 instances via CodeCommit and CodePipeline. The app requires sensitive database credentials on the instances. Which solutions store and retrieve those secrets most securely? (Choose two.)
- You enabled VPC flow logs (default format) and are delivering them to CloudWatch Logs. Now you must include the tcp-flags field for deeper troubleshooting. What should you do?
- You have a DynamoDB table and must replicate it to another AWS Region for disaster recovery. What action should you take to enable cross-Region replication of this table?
- You have a Python script that performs nightly maintenance using the AWS SDK. The script must run automatically every night with minimal operational overhead. Which option is the best choice?
- You have a two-tier web application running two EC2 instances in a single Availability Zone in us-east-1. You need to move one of those instances to a different Availability Zone. Which approach will accomplish this?
- You have a VPC with public and private subnets, and custom network ACLs are in use. Private subnet instances cannot reach the internet. An internet gateway is attached to the public subnet and the private subnet routes to a NAT gateway in the public subnet. EC2 instances use the VPC default security group. What is the most likely cause of the connectivity problem?
- You have two AWS CloudFormation stacks: the first creates a VPC and its networking components (subnets, route tables, internet gateway), and the second deploys application resources into that VPC. The second template must reference the resources created by the first with minimal manual effort. How should this be done?
- You must aggregate application log files from a custom app running on hundreds of Ubuntu EC2 instances and store them in CloudWatch Logs with minimal operational overhead. Which method is the best choice?
- You must automate patching for Windows EC2 instances using AWS Systems Manager Patch Manager. Development instances should auto-approve patches 2 days after release; production instances should auto-approve 5 days after release. All patching must occur within the same 2-hour maintenance window. Which approach satisfies these requirements?
- You must deliver protected digital assets to authorized users via Amazon CloudFront while preventing public access. Which configuration satisfies this requirement?
- You must monitor a specific process running on Linux EC2 instances and ensure that if the process stops, it is automatically restarted. The CloudWatch agent is already deployed on all instances. Which configuration will provide process monitoring and automated restarts?
- You must prevent accidental deletion or overwriting of objects in an S3 bucket. Noncurrent object versions need to be retained for 90 days and then permanently removed. All stored data must remain in the same AWS Region as the original bucket. Which configuration meets these constraints?
- You must provision a single CloudFormation-managed resource that brings together multiple AWS services and that can be created and removed via the CloudFormation console. Which CloudFormation resource type should you define?
- You must set up Route 53 records so that example.com and www.example.com resolve to an Application Load Balancer. Which pair of actions should you take to accomplish this? (Choose two.)
- You need a cost-effective disaster recovery plan for an application using EC2 instances behind an ALB in an Auto Scaling group, with an Aurora PostgreSQL database. RTO and RPO are both 15 minutes. Which combination of actions meets these targets at the lowest cost? (Choose two.)
- You need a shared file system for multiple Windows EC2 servers. You created an Amazon EFS file system, but the Windows instances cannot mount it. What action should you take so the Windows EC2 instances can share files?
- You need an automated way to stop any EC2 instance that averages under 10% CPU utilization for a continuous 60-minute period. Which approach is the MOST operationally efficient?
- You need to alert when free disk space on EC2 instances with attached EBS volumes falls below a threshold, but only if EBS DiskReadOps is also above a threshold. You already have an Amazon SNS topic for notifications. How can you ensure a notification is sent only when both conditions are true?
- You need to deploy an application in multiple AWS Regions and want user traffic routed to the Region with the lowest latency. If a Region becomes unhealthy, traffic should automatically fail over to another Region that has a healthy application instance. The solution must provide the fastest possible failover. Which option satisfies these requirements?
- You need to host a simple nonproduction static webpage using an S3 bucket you just created (default settings). Which combination of steps should you perform? (Choose two.)
- You need to host a static web app on Amazon S3, but company policy forbids making any S3 buckets public. You have uploaded the static files to the S3 bucket. Which approach satisfies the requirement to serve the site without making the bucket public?
- You need to provide a migration account with a copy of a production RDS database snapshot. The RDS instance is encrypted with a KMS key (alias production-rds-key). What is the approach with the LEAST administrative overhead to share the snapshot with the migration account?
- You need to search historical JSON-format logs stored in Amazon S3 from 10 Lambda functions for error messages. Error values may appear under different fields, but all error strings start with the same prefix. Which method is the most operationally efficient way to analyze those log files?
- You need to securely share a single object from a private S3 bucket with several users who do not have AWS accounts. Which approach is the most operationally efficient?
- You need to set up an Amazon EFS file system so that multiple EC2 instances in the same VPC but spread across several Availability Zones can access the shared storage with minimal latency. There are two EC2 instances in each Availability Zone. Which approach will provide the lowest-latency access for each instance?
- You need to upload a single 1 TB file from your data center into an S3 bucket using multipart upload. Which method should you use to perform the upload?
- You observed a surge in RequestCount on an ALB and want to find the client IP addresses responsible for the traffic. Where can you retrieve the source IP addresses for requests handled by the ALB?
- You provisioned a VPC with one public subnet and one private subnet. Instances launched in the private subnet cannot reach the internet. The VPC subnets are still using the default network ACL, and all security groups permit all outbound traffic. What change will enable internet access for the instances in the private subnet?
- You want CloudFront to honor different TTLs for individual pages while still enforcing the distribution’s minimum and maximum TTL settings. Which method will allow per-object TTL variation within those limits?
- You will host a public website on EC2 behind a load balancer and secure it with ACM certificates. The load balancer must automatically redirect HTTP traffic to HTTPS. Which configuration meets these requirements?
- Your account is a member of an organization using consolidated billing. You have tagged resources by environment (for example: dev, test, prod) and need a report showing costs broken down by environment. What is the correct step to enable cost reporting by those tags for the organization?
- Your account runs 90 EC2 instances in eu-west-1 today but will move those workloads to eu-west-3 in two months. The company wants to lower EC2 spend and is willing to commit for 1 year starting next week. You need a purchasing option that gives discounts for these 90 instances regardless of region during that 1-year term. Which option satisfies this?
- Your company runs a microservices app on an Amazon EKS cluster and expects a large spike in requests next month. To avoid outages and minimize operational effort, which approach should you use to automatically scale the application?
- Your company uses a single AWS Organization with all features enabled and wants AWS Config turned on in every member account and in every Region. Which method achieves this with the least operational effort?
- Your organization manages multiple AWS accounts with AWS Organizations and currently creates IAM roles manually. You want an automated, scalable way to create and manage IAM roles across the accounts. What is the MOST operationally efficient solution?
- Your organization runs a sensitive workload in an AWS account and uses ServiceNow for incident management. Security groups are already configured. The requirement is to automatically open a ServiceNow incident whenever any security group rule is modified. Which approach accomplishes this with the least operational overhead?
- Your VPC was originally in a single Availability Zone and connected to on-premises via a Site-to-Site VPN on the virtual private gateway. You added new subnets in a different Availability Zone and launched resources there, but those new resources cannot reach the on-premises network while the original resources still can. What should you do to restore connectivity for the new subnets?
Amazon Twitch Gameplan All exam questions
- A content creator can become a Partner without reaching Affiliate status first.
- Advertising agencies are free to utilize Twitch logos and trademarks without prior Twitch consent in their creative campaigns, provided that the content only runs on the Twitch platform
- Affiliate streamers must achieve Partner status to be able to monetize their channel.
- As you select advertising strategies, they must coincide with Twitch's Ad Acceptance policy while still aligning with Twitch audiences, ad product offerings, and technical affordances.
- Channel mods can do which of the following? (Select all that apply)
- Channel pages are where viewers go to watch a live stream or past broadcast, find information about the streamer, and connect with the community.
- Custom branded extensions are live apps that empower streamers to enhance their channels with an added layer of interactivity between the streamer, audience, and content.
- Custom influencer campaigns are available for all Twitch accounts.
- Even though there are millions of content creators and streamers on Twitch, ads are only shown on what channels?
- In order to stream on Twitch, you will need to purchase a studio style microphone, a broadcast webcam along with a high speed internet router to get started.
- In what two locations is TwitchCon held every year?
- Once a content creator reaches the Affiliate level, they have access to extras such as a subscription button for their fans and the ability to create a custom emote.
- Once you find a category on Twitch that interests you, you can search for channels within it that are live at that very moment.
- The Homepage Headliner display unit surrounds Twitch’s most premium inventory and can scale seamlessly with varied screen resolution and display sizes without the risk of branding being compromised.
- The name of Twitch’s annual in-person conference is called:
- The Sponsored Influencer Program allows brands to sponsor, on average, a 2-hour livestream with a Twitch streamer
- The Super Leaderboard display unit does not expand outside of specified parameters and does not support video.
- Twitch can create revenue opportunities for brands by connecting them with influencers through custom programs.
- Twitch Custom Commercials require entirely net new video assets to create.
- Twitch got its start in 2005 as the place for livecasting or streaming your life 24/7 via the web under which of the following names:
- Twitch has tools to allow advertising customers to customize their brand suitability settings?
- Twitch holds creators, both Affiliates and Partners, responsible for all activity on their channel.
- Twitch is an unmoderated service.
- Twitch Premium Video packages are always above the fold and highly visible display units, but viewers can skip the content after three (3) seconds if the advertising is not relevant to them.
- Twitch Premium Video packages are incorporated into live Twitch broadcasts, are highly visible, are above the fold, and are:
- Twitch sponsors esports teams and hosts tournaments for games like Fortnite and League of Legends.
- Twitch’s Ad Acceptance policy will remain separate from the Amazon Ad Acceptance policy, while considering and aligning closely.
- Twitch’s Brand Partnership Studios is available to all clients, but they’re accompanied by a high spend threshold and require more production time to go live.
- Twitch’s goal with measuring campaign performance includes: (select all that apply)
- Twitch’s popular emojis are called:
- Viewers can connect directly and in real time with content creators through the chat feature.
- What are the three steps in the creative evaluation process?
- What describes the types of behaviors allowed and prohibited on Twitch?
- What is the correct description of the Show and Tell program within Twitch Tried and True?
- What is the correct description of the Super Leaderboard?
- What is the primary function of the Headliner ad unit on Twitch?
- What is the primary objective of conducting a Reach campaign?
- What is the primary purpose of conducting live A/B tests on Twitch?
- What Stream Display Ad wraps ad creative around the Twitch live stream, providing advertisers with a high impact advertising solution to help increase brand awareness
- When a Twitch employee enters a streaming chat, what icon is used to signify their status?
- When advertising globally, all ads must be in the primary official language that the advertiser is located in.
- When advertising on Twitch, the landing page viewers are directed to must match and be related products and/or services.
- When does a user see a First Impression Takeover video?
- Where is the Medium rectangle/square advertising unit found on Twitch?
- Which of the following celebrities is an important part of the Twitch cultural experience, with a dedicated channel on Twitch that streams old episodes of their TV show 24/7?
- Which of the following is NOT a content category on Twitch?
- Which of the following is not able be measured by Twitch's bespoke measurement capabilities?
- Which of the following is NOT prohibited content, products, or service?
- Which of the following organizations is one of Twitch’s trusted third party resources to obtain industry standard video metrics?
- Which statement accurately describes safety versus suitability?
- Which Twitch Content Control is appropriate for most advertisers?
Amazon Video Ads All exam questions
- Aditi is trying to increase brand favor ability and long-term demand for her pet food brand with Amazon Ads. Which video ads solutions would best help them reach these goals?
- Advertisers pay for Sponsored Brand video ads when ads are viewed by shoppers.
- Amazon and across thousands of apps and websites at each stage of the customer journey. Amazon's audience solutions are Ilya is currently using Display ads to promote their brand. They are considering adopting Online Video ads, but are unsure of how it will support their strategy to drive consideration for their products. What is the strongest benefit of using both solutions together?
- Amy is running a Sponsored Brands video campaign focused on driving conversion. Which keyword strategy would you recommend to best help them achieve this goal?
- Araceli wants to improve branded searches. Which ad solutions should they use together to help drive this?
- Baixue is trying to improve immediate, short-term sales with video ads to complement their current Sponsored Products campaigns. Which strategy would you recommend to help them achieve this goal?
- Baodi is planning a full-funnel campaign and plans to use different types of video ads to meet different campaign objectives. Which measurement solution can they use to help understand and analyze the sequence, frequency, and type of audience interactions on the path to conversion?
- Bhavish is interested in driving incremental reach to help increase visibility of his brand among audiences beyond linear TV. Which video ad solutions would best help them meet this goal?
- Ciaran is running a Sponsored Brand video campaign focused on driving consideration. Which keyword strategy would you recommend to best help them achieve this goal?
- Claudette wants to use Online Video ads and Streaming TV ads together, but is unsure how to best use them to drive campaign objectives. Which of the following recommendations will most likely improve campaign performance?
- DeShaun is interested in quickly testing different video creatives to see which is most effective at driving conversions. Based on this objective, which video ad solution would you recommend?
- Giorgio is interested in measuring the impact of brand marketing efforts across diverse campaign objectives. Which type of measurement solution will help them gain this insight?
- Hans is running a Sponsored Brands video campaign and wants to drive awareness for his brand's products. Which keyword match type will best help them reach their goal?
- Horace recently ran a campaign using multiple ad types for the holidays. They want to understand what type of audiences they are reaching, how their campaign impacts customer perception of their brand, and how the campaign impacted purchase intent. Which third-party measurement solutions will help them get these insights?
- If your advertising objective is to build new, short-term demand and encourage browsing shoppers to consider your brand, which Amazon video ad product would be most appropriate?
- If your advertising objective is to capture existing demand and reach audiences who are already considering your brand, which Amazon video ad product would be most appropriate?
- If your video ad will play with the audio muted by default, which best practice should you follow for the creative?
- Jhonas is interested in combining audience data from multiple sources to create new audiences to use in an upcoming Twitch ads campaign. Which solution will best help them craft this audience?
- Joop is running a Sponsored Brands video campaign to help drive conversion. Which keyword strategy would best help them meet their goal?
- Khan is running a Sponsored Brands video campaign focused on driving awareness. Which keyword strategy would you recommend to best help them achieve this goal?
- Michael is interested in using video to showcase their brand's products in action. Based on this objective, which video ad solution would you recommend?
- Negative targeting prevents your ads from displaying when customers use a term that matches your negative product selection.
- Optimization levers can help advertisers set benchmarks for which key measures to help achieve campaign results?
- Ormina is interested in advertising during live broadcasts featuring creator-driven content to reach a specific demographic. Which video ad solution would best help them meet this goal?
- Reporting in Amazon Brand Lift is anonymized and privacy safe.
- Sponsored Brands video ads and Sponsored Display video ads use keyword and product targeting to increase product discover ability.
- Sponsored Brands video ads can be linked to a product detail page or to a Brand Store, which can help drive consideration for your brand.
- Sponsored Display video ads can appear in the Amazon store, IMDb.com, Amazon Publisher Direct, and third-party websites/apps.
- Streaming TV and Online Video can use Amazon Audiences in their campaigns.
- Streaming TV incremental household reach is a post-campaign reporting solution that helps brands measure the unique, incremental audience reached through Amazon Streaming TV ad campaigns, above and beyond their linear TV campaigns.
- Thelma wants to create a custom audience to support their next Online Video ads campaign. Which solution will best help them build this audience to meet their campaign objectives?
- Timo is planning a new Streaming TV campaign and wants to identify new audience segments to reach with their next campaign. Which Amazon solution would best help them get the information they're looking for?
- To increase the effectiveness of your Sponsored Brands video ads, which best practice should you follow?
- True or false: It is recommended you include facts about your product in Sponsored Brands video campaigns.
- Ursula wants to use Amazon's audience solutions to reach potential customers who have interacted with products similar to the ones they are promoting in their Sponsored Display video campaign. Which Amazon Audience solution do you recommend they use?
- Using multiple ad types together can help improve full-funnel performance.
- Using multiple video ads solutions together to create a full-funnel strategy can help increase incremental reach, detail page view rates, and purchases.
- What is one benefit of using Prime Video ads?
- What is the key benefit of using both Online Video and Streaming TV ads?
- What is the key benefit of using Streaming TV incremental household reach report?
- What is the primary benefit of using overlap reports for your Streaming TV ad campaign?
- Where can advertisers link their Sponsored Brands video campaigns?
- Where can Twitch premium ads appear?
- Which Amazon video ad product allows you to showcase your products and brands through immersive storytelling like tutorials and demos?
- Which Amazon video ad product gives advertisers the opportunity have their ads display alongside influential streamers and diverse, interactive content in real time?
- Which audience solution allows you to transfer your existing audiences to the Amazon DSP from multiple sources?
- Which audience solution helps you build custom audiences based on aggregated signals across an advertiser's website?
- Which of the following best describes "keyword targeting"?
- Which of the following best describes "product targeting"?
- Which of the following best describes Amazon's audience solutions?
- Which of the following best describes Connected TV (CTV)?
- Which of the following best describes Fire TV ads?
- Which of the following best describes targeting reports?
- Which of the following best describes the benefits of the keyword placement report?
- Which of the following is a key benefit for using Amazon Marketing Cloud for advertisers running video ads campaigns?
- Which of the following is an advertising and analytics measurement solution that gives marketers insight into how their non-Amazon marketing channels perform on Amazon?
- Which of the following most accurately describes the benefit of using more than one video ad product to move towards a full funnel approach to strengthen your marketing efforts?
- Which of the following most accurately describes the options available for refining category targeting?
- Which solution helps brands measure the unique, incremental audiences reached through Streaming TV ads?
- Which video ad product offers in-stream or out-stream video ads that can appear on Amazon affiliated sites and third-party publisher sites?
- Which video ad product provides audience solutions that include geographic region, dayparting, and demographic insights?
- Why are Online Video ads well-suited for helping increase brand awareness?
- Wyatt recently ran a campaign using multiple video ads ahead of a holiday. They want to understand the impact of having multiple touch points on their sales. Which third-party measurement solution will best help them meet this goal?
- Xiao recently ran a Twitch ads campaign to promote an upcoming e-sports event. They want to understand if the campaign helped drive traffic to the event. Which third-party measurement solutions will best help them get these insights?
- Yoonjae is planning an ad campaign to help drive registrations for an upcoming event in South Korea. Which solutions will help them reach audiences by geographic location?
- You can transfer your audiences to Amazon DSP from multiple sources such as an advertiser hashed audience and a data management platform (DMP).
- Yuan recently ran a Streaming TV campaign and wants to reach audience segments that were not originally included in the campaign. Which solution will help them identify which Amazon audience segments are most responsive to their ads?
- Yuliya sees an opportunity to reach audiences that are already considering their brand's products. Which Amazon video ads solution would best help them achieve their goal?
Amazon Video Ads Certification All exam questions
- A brand has built awareness and reached millions of viewers. Which solutions should they layer in to drive conversion?
- A brand ran a Prime Video campaign for awareness and wants to re-engage those viewers. Which strategy should they implement?
- A brand wants to engage audiences during the consideration phase with product demonstrations. Which solutions are most effective?
- A brand wants to integrate video into a broader campaign that includes Display ads and Sponsored Products. At which funnel stage should they introduce video?
- A brand wants to maximize awareness and reach among streaming audiences. Which video solution should they prioritize?
- A brand wants to measure long-term customer value and repeat purchase behavior. Which stage and measurement solution is most appropriate?
- A brand wants to re-engage viewers who watched their Streaming TV ad. Which consideration-stage solution should they implement next?
- A brand wants to understand how their remarketing campaigns are moving viewers closer to consideration and identifying new brand consideration opportunities. Which measurement solution combination is most appropriate?
- A consumer electronics brand selling on Amazon wants to launch a new product line. They need to reach Gen Z and Millennial audiences, re-engage interested viewers, and create a frictionless shopping experience. Which full-funnel strategy should they implement?
- A luxury automotive brand wants to reach viewers who haven't seen their linear TV ads and drive them to local dealerships. Which Streaming TV capabilities should they combine?
- A non-endemic advertiser's previous reliance on linear TV and print advertising wasn't effectively connecting with digital-first shoppers or creating clear paths from online research to dealership visits. What should they do?
- Aditi is trying to increase brand favorability and long-term demand for her pet food brand with Amazon Ads. Which video ads solutions would best help them reach these goals?
- After downloading the Amazon Live Creator app, what is the next step in the setup process?
- An advertiser is planning a new Streaming TV campaign and wants to build audience strategies using entertainment viewership preferences. Which tool should they use during the Plan phase?
- An advertiser wants to create scheduled reports that automatically deliver campaign performance data. Which reporting surface should they use?
- An advertiser wants to drive immediate conversions on Amazon. Which video solutions are most appropriate?
- An advertiser wants to maximize the impact of their video campaign by reaching audiences across multiple touchpoints. What strategy should they employ?
- An advertiser wants to prove that their video campaigns are driving offline store visits and connecting digital video exposure to physical locations. Which measurement solution is most appropriate?
- An endemic advertiser wants to create a full-funnel video strategy. Which of these combinations would be most effective?
- An endemic advertiser's previous campaigns using single ad solutions in isolation weren't creating opportunities to guide shoppers from discovery to purchase. What strategy should they implement?
- An endemic brand wants to use Amazon Live for product education during the consideration phase. What should they combine it with for maximum effectiveness?
- Anna is deciding what video ad solution to use. Anna wants an in-stream and out-stream video ad that has a creative builder and she can test different creative variables. Which video ad solution should Anna select?
- At which funnel stage does Amazon Live provide its primary strategic value?
- Can Sponsored ads campaigns use AI to generate video content?
- For Twitch short-form ads (6-15 seconds), what brand name placement drives higher CTR?
- From the campaign type page, what would you select to set up a programmatic campaign?
- How can you use overlap reports?
- How does Online Video support full-funnel strategy?
- Ilya is currently using Display ads to promote their brand. They are considering adopting Online Video ads, but are unsure of how it will support their strategy to drive consideration for their products. What is the strongest benefit of using both solutions together?
- iRIS is planning a holiday shopping campaign and wants to embed video into their multi-format campaign with Display ads and Sponsored Products. Which video solution could they add to complement Display remarketing and provide deeper product education?
- Lisa is an advertiser currently running Streaming TV and Online Video ad campaigns. Lisa wants to understand her audiences' characteristics. Which of the following can Lisa use to better understand her audiences?
- Lua is interested in analyzing campaign cost insights with conversion metrics from Amazon Attribution to help make decisions for where to invest video ads budget next. Which solution will best help them get this insight?
- Ryan is running Sponsored Brands video campaigns and would like his ads to appear for relevant shopping search queries. Which the following options could Ryan use?
- Sabre, a non-endemic automotive brand, wants to drive dealership visits and test drive appointments. Which conversion-focused solution should they prioritize?
- Select one answer. Amazon video creative solutions for Sponsored Brands video, Streaming TV, and Online Video ads can...
- Select one answer. Which is a measurement solution you can use to gain insights on how non-Amazon marketing channels impact shopping activity and sales in the Amazon store?
- Select one answer. With Sponsored Brands video ads, you can set up your targeting to be:
- Select one answer. You are deciding what video ad solution to use. You want an in-stream and out-stream video ad that is available that has a creative builder and you can test different creative variables. Which video ad solution should you select?
- Select one answer. You are planning your marketing strategy for your Online Video ads campaign. You would like to activate against lifestyle, in-market or look-a-like audiences, which Amazon DSP audience solution would you use to access those audience segments?
- Select one answer. You are planning your Online Video ad campaign. You would like to conduct a holistic measurement of the shopping journey across video, audio, display, and sponsored ads. What measuring solution could you use?
- Select one answer. You are setting up your Sponsored Brands video ad campaign for your brand of hair products. You want to keep track of your campaign status to see if your campaign is running, paused, ended, or terminated. You can so by using:
- Select one answer. You are setting up your Streaming TV ads campaign and want to use pre-built audiences and custom audiences that include lifestyle, in-market, lookalike, purchases, streaming, and ASIN remarketing audiences. Which of the following would you use?
- Select one answer. You can use Amazon Audiences for Streaming TV and Online Video to:
- Select one answer. You have just concluded your Streaming TV ad campaign on your brand of candles. You would like to set up a study on the Amazon Shopper Panel to measure the impact of your marketing efforts. Specifically, you want to understand your audiences’ attitudes and preferences. You can do so using:
- Select one answer. You want a video ad that can appear both in-stream (before, during, and after video content) and out-stream (in non-video environments between text and images). Which ad product would you select?
- Select one answer. You want to drive relevance about your furniture brand. You set up an Online Video ad campaign. You can incorporate your brand's existing audiences to your campaign by:
- Select one answer. You want to understand the impact of shopping activity and sales on Amazon from your non-Amazon marketing channels (i.e. search, social, etc). Which of the following would you use?
- Select one answer. You want your video ads to run on Freevee, Twitch, and Fire TV. Which video ad product would you choose?
- Select one answer. You would like to understand the overall performance of your Sponsored Brands video campaign in a certain range of time. Which report should you use?
- Select one answer. You would like your Sponsored Brands video campaign ads to appear for relevant shopping search queries. Which the following options could you use?
- Select one answer. Your brand has a Store on Amazon. You would like to connect your video to a sub-page on your Store. Which video ad solution would you use?
- Select the two video ads that can be non-skippable and skippable.
- Select the video ad that is only non-skippable.
- Since Sponsored Brands videos play with the audio off, your on-screen message should be clear and easy to understand without audio.
- Sponsored Brands video ads and Sponsored Display video ads use keyword and product targeting to increase product discoverability.
- Sponsored Display Video ads reach audiences *only* through third-party websites.
- True or false: Adding one or two speakers in Online Video ads can help increase detail page views.
- True or false: Sponsored Display video reaches audiences through Amazon Audiences.
- True or false: Streaming TV ads cannot help increase the incremental reach of your media strategy.
- True or false: We recommend introducing your brand at the end of your video ads.
- True or false: We recommend telling a story in your Streaming TV ads.
- True or false: We recommend that you ensure that your Sponsored Brands video ads work without sound and that any on-screen text is readable.
- True or false: We recommend you do NOT include audio or voice over in your Streaming TV ads.
- True or false: We recommend you include as many facts about your product as possible in your Sponsored Brands video ads.
- True or false: With Online Video ads, you can reach relevant audiences through a multi-channel content strategy.
- True or false: You can use Amazon Ads creative builders to build compelling video assets and test multiple versions of your video ad that can help increase your ad’s impact on customers.
- True or false. Sponsored Brands video can enhance campaign performance by helping to drive revenue and brand consideration.
- True or false. Within keyword targeting for Sponsored Brands video, there are three keyword match types: exact match, broad match, and phrase match.
- True or false. You are an advertiser and want to understand your audiences' characteristics. You are currently running Streaming TV and Online Video ad campaigns. You can use Amazon insights to better understand your audiences.
- True or false. You are running a Sponsored Brands video ad campaign and are strategizing allocation of your budget. With keyword and product targeting, you can choose to customize bid amounts based on marketing goals.
- True or false. You are running a Streaming TV ad campaign featuring your athletic clothing and want your ads to reach viewers in the New York City area. However, Streaming TV does not allow targeting by geographic location.
- True or false. You are setting up your Online Video ad campaign and want to plan your audience's engagement at every stage of the customer journey. Unfortunately, you cannot access the audience planning tool with Online Video ads.
- True or false. You are setting up your Sponsored Brands video campaign and want to optimize reach and increased discoverability. You can use both keyword and product targeting to do so.
- True or false. You are setting up your Sponsored Display video campaign for your kitchenware brand. You can use automatic targeting capabilities.
- True or false. You can use Amazon Attribution during your Online Video ad campaign to monitor the effectiveness of your non-Amazon campaigns and make in-flight adjustments to your campaign.
- True or false. You can use Amazon Audiences and keyword/product targeting options to better understand audiences' characteristics and access first party shopping insights.
- True or false. You can use keyword and product targeting for Sponsored Brands video.
- True or false. You can use third-party insights to measure the brand reach and lift of your Online Video campaign.
- True or false. You cannot link Sponsored Brands video ads to your Amazon Stores.
- True or false. You cannot measure the incremental reach of your Streaming TV ad campaign.
- True or false. You cannot see the shopping queries entered by customers shopping on Amazon that results in a click of one of your Sponsored Brands video ads.
- True or false. You cannot test creative, messaging, or tactics of your Online Video ad campaign.
- What are the three Amazon Live implementation approaches?
- What are the three main ways to buy video ads through Amazon Ads?
- What are the three primary reporting surfaces in Amazon Ads?
- What are the three Twitch activation layers? (Select all that apply)
- What are the three types of interactive video ad formats?
- What are the two formats of Online Video (OLV) ads?
- What are two main categories of common creative rejection reasons?
- What best describes Amazon's video advertising supply beyond owned properties?
- What best practice should guide Amazon Live content strategy?
- What capabilities do third-party integrations like Adobe Express and Canva provide?
- What capability makes interactive video ads unique for driving lower-funnel goals?
- What is a critical requirement for Interactive Video Ads to ensure optimal user experience?
- What is a key best practice for Online Video ads when the objective is to drive sales?
- What is a key best practice for Streaming TV ads to capture viewer attention?
- What is Complete TV used for in the framework?
- What is the Amazon Ads Authenticated Graph?
- What is the core capability that makes interactive video ads unique?
- What is the first step in setting up an Amazon Live?
- What is the key benefit of combining multiple video ad solutions throughout the customer journey?
- What is the minimum spend requirement for Expert mode?
- What is the primary benefit of Complete TV?
- What is the primary purpose of Fire TV Feature Rotator?
- What is the primary use case for Sponsored Brands video?
- What is the primary use case for Twitch's High Impact solutions (FITO and Headliners)?
- What is the purpose of VAST tags in video advertising?
- What is the strategic value of repurposing Amazon Live content?
- What key capability difference distinguishes Expert mode from Smart mode?
- What key capability does Report Builder provide for advertisers managing multiple accounts?
- What technology advantage does Twitch's Premium Media offer through SureStream?
- When setting up an Amazon Live broadcast, what elements must be configured before going live?
- When should an advertiser use Online Video on IMDb.com as a placement strategy?
- Which Amazon creative solution uses AI to provide end-to-end creative services from strategy to production?
- Which Amazon-owned properties are included in Amazon's video ad supply?
- Which are the correct steps to set up a DSP campaign?
- Which campaign setup path requires the most technical expertise and campaign management experience?
- Which creative solution is specifically designed for endemic brands to create video content from still images?
- Which is a measurement solution you can use to measure the impact of Streaming TV ads?
- Which measurement solutions are ideal for the Awareness stage?
- Which report should you use to understand how keyword and product targeting of your Sponsored Brands video campaign are performing over time?
- Which tool can be used during the "Plan" phase to build audience strategies leveraging first-party data and shopping signals?
- Which video solutions are available through Smart mode?
- Why is it essential to review and align ad creatives to Amazon's creative guidelines and technical specifications before submission?
- With Online Video ads, you can
- Wyatt recently ran a campaign using multiple video ads ahead of a holiday. They want to understand the impact of having multiple touchpoints on their sales. Which third-party measurement solution will best help them meet this goal?
- You are setting up your Online Video ad campaign and want to plan your audience's engagement at every stage of the customer journey. Which of the following tools could you use?
- You want to get holistic insights from event-level ads datasets across Amazon-owned and operated properties. Which of the following would you use?
amazon video ads ENG version All exam questions
- Select five answers.What are five Amazon video ad solutions?
- Select one answer.Amazon video creative solutions for Sponsored Brands video, Sponsored Display video,Streaming TV,and Online Video ads can...
- Select one answer.Contextual targeting for Sponsored Display video is:
- Select one answer.In Sponsored Display video ads,advertisers can....
- Select one answer.Read the answer options and select the correct answer.
- Select one answer.What kind of video ad solutions are Sponsored Brands video?
- Select one answer.What would you use to show recommendations of your audience based on comparisons between your audience and Amazon audience segments who have shown similar interests?
- Select one answer.Where do Sponsored Display video ads reach audiences?
- Select one answer.Which is a measurement solution you can use to gain insights onhownon-Amazon marketing channels impact shopping activity and sales in the Amazon store?
- Select one answer.Which is a measurement solution you can use to measure the impact of Streaming TV ads?
- Select one answer.Which of the following video ads can use Amazon Audiences targeting?
- Select one answer.You are deciding what video ad solution to use.Youwantan in-stream and out-stream video ad that is available that has a creative builder and you can test different creative variables.Which video ad solution should you select?
- Select one answer.You are planning your marketing strategy for your Online Video ads campaign.You would like to activate against lifestyle,in-marketor look-a-like audiences,which Amazon DSP audience solution would you use to access those audience segments?
- Select one answer.You are planning your Online Video ad campaign.Youwould like to conduct a holistic measurement of the shopping journey across video, audio,display,and sponsored ads.What measuring solution could you use?
- Select one answer.You are setting up your Sponsored Brands video ad campaign for your brand of hair products.You want to keep track of your campaign status to see if your campaign is running,paused,ended,or terminated.Youcansoby using:
- Select one answer.You are setting up your Streaming TV ads campaign and want tousepre-built audiences and custom audiences that include lifestyle,in-market, lookalike,purchases,streaming,and AS IN re marketing audiences.Whichofthe following would you use?
- Select one answer.You can use Amazon Audiences for Streaming TV and Online Videoto:
- Select one answer.You have just concluded your Streaming TV ad campaign on your brand of candles.You would like to setup a study on the AmazonS hopper Panel to measure the impact of your marketing efforts.Specifically,youwantto understand your audiences’attitudes and preferences.You can do sousing:
- Select one answer.You want a video ad that can appear both in-stream(before, during,and after video content)andout-stream(innon-video environments between text and images).Which ad product would you select?
- Select one answer.You want to better understand your customers by learning about their behaviors.Which of the following would you use?
- Select one answer.You want to drive relevance about your furniture brand.You setup an Online Video ad campaign.You can incorporate your brand'sexisting audiences to your campaign by:
- Select one answer.You want your video ads toru nonFree vee,Twitch,andFire TV.Which video ad product would you choose?
- Select one answer.You would like your Sponsored Brands video campaign ads to appear for relevant shopping search queries.Which the following options could youuse?
- Select one answer.Your Streaming TV video ads...
- Select the two video ads that are only non-skippable.
- Select the two video ads that can be non-skip p able and skip p able.
- Select three answers.In Sponsored Brands ads,advertisers....
- Select three answers.Online Video ads....
- Select three answers.Select the Amazon audience solutions available for video ads that are enabled by the Amazon DSP.
- Select three answers.Which of the following can you use to measure the performance of your Sponsored Brands video ad?
- Select three answers.Which of these measurement solutions can you use to measure the impact of Streaming TV ads?
- Select two answers.How can you assess the impact of Sponsored Brands video?
- Select two answers.Sponsored Brand video ads...
- Select two answers.What video ad solutions can be bought through the Amazon DSP?
AWS Cloud Practitioner CLF-C02 Certification All exam questions
- A centralized group of users has outgrown on-premises file storage. The company wants to expand file storage for this group while keeping the benefit of local shared performance. What is the MOST operationally efficient AWS solution?
- A company aims to attract and develop a digitally fluent, diverse, and inclusive workforce with the right mix of technical and non-technical skills. Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on workforce, skills, and organizational culture?
- A company aims to run workloads efficiently in AWS, reduce operational overhead, and improve procedures. Which pillar of the AWS Well‑Architected Framework addresses these goals?
- A company builds an application using AWS Lambda to run Python code. Under the AWS shared responsibility model, which tasks are the company's responsibility? (Choose two.)
- A company built a new in-house application but cannot predict its future usage patterns. Which AWS cloud benefit is the company aiming to gain?
- A company currently backs up 10 TB of data to a tape library using a third-party service. Their on-premises backup server is running out of capacity, and they want to use AWS for backups while keeping their existing backup workflows unchanged. Which AWS service should they use?
- A company currently manages its own Docker environment on Amazon EC2 and wants a managed alternative that handles cluster sizing, scheduling, and environment maintenance. Which AWS service provides that functionality?
- A company designs workloads so components are updated frequently and changes are made in small, reversible steps. Which AWS Well-Architected Framework pillar does this practice support?
- A company has a compute workload that is steady, predictable, and must not be interrupted. Which Amazon EC2 purchasing options are the MOST cost-effective choices? (Choose two.)
- A company has a predictable, business-critical EC2 compute workload for the next 3 years and wants to minimize costs. Which option best meets these requirements?
- A company has a temporary, variable workload running on EC2 that must complete short bursts of work without being interrupted. Which EC2 purchase option meets this requirement?
- A company has applications running on Amazon EC2 instances and needs to evaluate application vulnerabilities and identify infrastructure deployments that don’t follow best practices. Which AWS service should the company use?
- A company has data lakes used for high performance computing (HPC) workloads. Which Amazon EC2 instance family is most appropriate for HPC?
- A company has large datasets that auditors access only twice per year. Which Amazon S3 storage class will store the data at the lowest cost?
- A company has launched an Amazon EC2 instance. Under the AWS shared responsibility model, which task is AWS responsible for?
- A company has moved workloads to AWS and wants operational support to run at scale more efficiently and securely. Which AWS offering should they use for hands-on operational management?
- A company has multiple AWS accounts running compute workloads that must not be interrupted. The company wants to receive billing discounts based on total AWS usage. Which AWS feature or purchasing option will provide those discounts?
- A company has public applications running behind Application Load Balancers and wants to improve global application performance for end users. Which AWS service will help achieve this?
- A company hosts a web application on EC2 and needs to apply custom rules to inspect and control incoming web traffic. Which AWS service provides this capability?
- A company intends to run containers on AWS but requires complete control over the underlying compute hosts. Which AWS offering satisfies this requirement?
- A company is evaluating whether to move from AWS Business Support to AWS Enterprise Support. Which additional benefit does Enterprise Support provide?
- A company is linking multiple VPCs and on-premises networks and wants a single AWS service to act like a cloud router to simplify network peering. Which service should they use?
- A company is migrating applications to AWS and wants to ensure each application is granted only the minimum permissions required. Which AWS service provides this capability?
- A company is migrating backup storage to AWS and needs a cloud-backed storage solution that keeps a local cache for on-premises access. Which AWS service provides this capability?
- A company is migrating its public website to AWS and wants to host the website’s domain name using an AWS service. Which service should they use?
- A company is migrating its server-based applications to AWS and wants to calculate the total cost of ownership for the compute resources they will run on AWS. Which two AWS tools or services should they use? (Choose two.)
- A company is moving an on-premises server to an Amazon EC2 instance. The server must run continuously for the next 12 months. Which EC2 pricing model is the most cost-effective for this workload?
- A company is moving development and test environments to AWS to boost agility and lower costs. These workloads are nonproduction, often underutilized, and can tolerate occasional interruptions. Which Amazon EC2 pricing option is the most cost-effective for this use case?
- A company is moving from on-premises to the AWS Cloud. Which of the following are benefits of this migration? (Choose two.)
- A company is preparing to migrate to AWS and needs to produce cost estimates for its AWS use cases. Which AWS tool can it use to generate those cost estimates?
- A company is preparing to migrate to AWS and wants to define measurable business outcomes that show the value of the migration. Which phase of the cloud transformation journey includes those activities?
- A company is transferring its on-premises data center to AWS and needs to move 50 petabytes of file data to the cloud while minimizing operational overhead. Which AWS option should they choose?
- A company launching an ecommerce site with a large product image catalog needs to track and control ongoing costs to stay within budget. Which AWS service should they use to monitor and analyze costs?
- A company located in an area with limited internet connectivity must perform local data processing on premises and needs a solution that can function without a stable internet connection. Which AWS service meets this requirement?
- A company migrating an application to AWS needs to collect usage and configuration information about its application components. Which service should they use?
- A company migrating to AWS plans to run experimental workloads for about 3 to 6 months. Which pricing option best fits this temporary usage pattern?
- A company migrating to AWS wants to use the AWS Cloud Adoption Framework to define and monitor business outcomes during its cloud transformation. Which governance capability within the AWS CAF supports this need?
- A company must build and publish interactive BI dashboards that include insights enhanced by machine learning. Which AWS service or tool should they use?
- A company must collect and process 10 TB of data on-site and then transfer it to AWS. The site has intermittent network connectivity. Which AWS service meets these requirements?
- A company must deploy a PostgreSQL database on Amazon RDS and ensure it is highly available and fault tolerant. Which RDS deployment option should they choose?
- A company must determine who accessed an AWS service and what actions were taken during a specific time period. Which AWS service provides this audit trail information?
- A company must host an application in a particular geographic area to satisfy regulatory requirements. Which aspect of the AWS global infrastructure helps meet this need?
- A company must keep data on premises to meet regulatory requirements, but also wants low-latency connectivity between its on-premises resources and AWS. Which AWS offering can satisfy both requirements?
- A company must keep some workloads on-premises for compliance but wants the remaining workloads in AWS while using the same APIs for both. Which AWS offering meets these requirements?
- A company must plan, schedule, and execute hundreds of thousands of compute jobs on AWS. Which AWS service is designed to run large-scale batch computing workloads like this?
- A company must retain documents using a write-once, read-many (WORM) model to satisfy legal and compliance rules. Which Amazon S3 capability enables this requirement?
- A company must run a web server on Amazon EC2 instances for at least one year, and the server cannot be interrupted. Which EC2 purchasing option is the most cost-effective for this scenario?
- A company must run its application using Amazon EC2 but keep the hardware on-site for compliance. Which AWS offering allows AWS infrastructure to run in the company's data center?
- A company must run some workloads in AWS and keep other workloads on its on-premises servers for compliance. Which AWS service provides consistent AWS infrastructure and services on-site?
- A company needs a bridge between technology and the business to promote a culture of continuous learning and growth. Which AWS CAF perspective serves that role?
- A company needs a centralized user portal so employees can sign in to external business applications that support SAML 2.0. Which AWS service provides this capability?
- A company needs a datastore that can scale to handle millions of database queries per second for its application. Which AWS service meets this requirement?
- A company needs a fully managed, highly available, and scalable file storage solution that clients can access over the SMB protocol. Which AWS service should they use?
- A company needs a portal for end users to access assigned AWS accounts and cloud applications, and to manage access for third-party SaaS apps. Which AWS service fulfills this requirement?
- A company needs a solution to schedule regular rotation of database user credentials while minimizing operational effort. Which AWS service best meets this requirement with the least operational overhead?
- A company needs continuous monitoring for threats, malicious activity, and unauthorized behavior across its AWS accounts, workloads, and S3 buckets. Which AWS service provides this capability?
- A company needs EC2 instances for an application that will run continuously for more than one year. Which EC2 purchase option is the most cost-effective for this scenario?
- A company needs its Amazon EC2 instances to be placed in separate physical locations within the same geographic region, with independent power sources and isolated network connectivity for each location. Which configuration satisfies these requirements?
- A company needs its on-premises applications to store and retrieve files in Amazon S3 using standard file system protocols. Which AWS service provides this capability?
- A company needs on-premises workloads to access Windows file shares hosted in AWS but does not want to add any new infrastructure or applications in its data center. Which AWS service enables this?
- A company needs Payment Card Industry (PCI) reports that validate AWS security controls. Where can the company retrieve these reports?
- A company needs strategic planning help before releasing a business-critical application and wants infrastructure event management plus real-time support during the release. Which action meets these needs?
- A company needs to allow an EC2 instance to access an Amazon S3 bucket securely without sending traffic over the public internet. Which option achieves this?
- A company needs to allow users in one AWS account to access resources in a different AWS account. The users currently lack permission to access those resources. Which IAM feature should be used?
- A company needs to archive data that users seldom access to reduce storage costs. Which Amazon S3 feature should they use?
- A company needs to audit password and access key rotation details for compliance. Which AWS service or tool provides this information?
- A company needs to block website access from users in specific countries. Which AWS service should they use to enforce this restriction?
- A company needs to check whether multi-factor authentication (MFA) is enabled for every user in its AWS account. Which AWS resource provides this information?
- A company needs to classify resources and track AWS costs at a detailed level by department, environment, and application. Which approach will meet this requirement?
- A company needs to deploy applications to AWS quickly and minimize the operational complexity of managing AWS resources. Which service should they use?
- A company needs to develop, test, and deploy an application in AWS quickly. Which cloud computing benefit best supports this requirement?
- A company needs to group users so it can assign permissions to the group rather than to each user individually. Which AWS service or feature lets the company create and manage user groups with permissions?
- A company needs to hire external consultants to help operate and support its AWS environment. Which AWS program or resource enables engagement with third-party consulting partners?
- A company needs to manage single sign-on and centralized access for users across multiple AWS accounts in an AWS Organization. Which AWS service should they use?
- A company needs to move 2 TB of data to AWS. Which type of transfer would result in no charge to the company?
- A company needs to move a very large number of files (millions) from its on-premises data center to AWS in a one-time migration. Which AWS service is best suited for transferring these files?
- A company needs to procure third-party software to run in its AWS environment. Which AWS service or marketplace should it use to purchase that software?
- A company needs to provide customer support that includes voice calls and web chat. Which AWS service should they use?
- A company needs to query and analyze data stored in Amazon S3 using a programming language. Which AWS service should they use?
- A company needs to retain infrequently accessed data for archive and long-term backup purposes. Which AWS storage option is the most cost-effective for this use case?
- A company needs to run a preinstalled third-party firewall on an Amazon EC2 instance. Which AWS offering can provide that prebuilt firewall image?
- A company needs to run applications that control on-premises factory equipment and requires the lowest possible latency. Which AWS solution should they use?
- A company needs to run graph queries that return customers’ names, addresses, and transactions, and analyze relationships to flag possible fraud. Which AWS database service is appropriate for this use case?
- A company needs to run workloads that are heavy on CPU across several Amazon EC2 instances. Which EC2 instance family is best suited for this requirement?
- A company needs to track monthly cost and usage for all Amazon EC2 instances in a particular AWS environment. Which AWS tool or service will provide that reporting?
- A company needs to transfer 75 petabytes of data from its on-premises data centers to AWS. Which AWS service is the most cost-effective option for this volume of data?
- A company needs to transfer unstructured data to AWS with encryption in transit and end-to-end data validation. Which AWS service meets these requirements?
- A company on the AWS Business Support plan needs access to the AWS DDoS Response Team (DRT) for DDoS mitigation. Which AWS offering must the company use to gain DRT access?
- A company owns Standard Reserved Instances (RIs) for Amazon EC2 but will move part of the workload to a different instance family. How can the company make use of the Standard RIs they no longer need?
- A company planning a migration to AWS needs a monthly estimated total cost for future Amazon EC2 instances and related storage. Which tool should they use?
- A company plans to deploy an application worldwide using AWS. Which deployment model should they choose to achieve global coverage?
- A company plans to migrate a PostgreSQL database to AWS but uses it infrequently. Which option provides the least operational management?
- A company plans to migrate applications to AWS. An audit finds its content management system (CMS) cannot run in cloud environments as-is. Which two migration strategies would move the CMS to the cloud with the least amount of effort? (Choose two.)
- A company plans to migrate its database to a managed AWS service that supports PostgreSQL compatibility. Which AWS services meet this requirement? (Choose two.)
- A company plans to migrate its on-premises container infrastructure to AWS and wants to avoid unexpected administration and operational costs by moving toward a serverless model. Which AWS service best fits this requirement?
- A company plans to migrate its on-premises SQL Server database to AWS and wants AWS to manage routine database administration. Which AWS service meets this requirement?
- A company plans to modernize a monolithic application by breaking it into microservices and deploying those services on AWS. Which migration strategy describes this approach?
- A company plans to move all on-premises systems to AWS and wants an estimate of the cost to run their current setup in the cloud. Which AWS tool or framework should they use to get that cost estimate?
- A company plans to move its on-premises workloads to AWS and needs to separate those workloads so different departments can be charged separately. Which AWS services or capabilities satisfy these requirements? (Choose two.)
- A company plans to run a continuously operating workload on Amazon EC2 for more than one year. Which option offers a lower hourly price compared to On-Demand Instances?
- A company plans to run a NoSQL database on Amazon EC2 instances. Which of the following tasks is the responsibility of AWS in this scenario?
- A company plans to run several stateless services on Amazon EC2 for short durations and needs the most cost-effective pricing model. Which EC2 pricing option is best?
- A company plans to use an Amazon Snowball Edge device to move files into AWS. Which Snowball Edge–related activity is provided at no charge?
- A company plans to use AWS Managed Services (AMS) for operational support. Which AMS feature matches the company's need for managed landing zones and network operations?
- A company preparing to migrate to AWS needs inventory details about its on-premises servers (hostname, IP address, MAC address). Which AWS service provides that information?
- A company requires a dedicated, low-latency connection with consistent network performance between its on-premises data center and AWS. Which AWS service meets this requirement?
- A company requires a fully managed file server that natively supports Microsoft workloads and the SMB protocol. Which AWS service should they choose?
- A company requires a fully managed Windows file server for Windows-based applications. Which AWS service should they use?
- A company requires a global content delivery solution that provides secure distribution of data, video, applications, and APIs with low latency and high transfer speeds. Which AWS service provides this capability?
- A company requires a private, dedicated network connection between its on-premises data center and AWS that does not traverse the public internet. Which AWS option meets this requirement?
- A company requires an Amazon S3 storage option that provides object access latency measured in single-digit milliseconds. Which S3 storage class fits this requirement?
- A company requires low-latency access to on-premises systems and needs to meet strict data residency rules. Which AWS solution should they use to design a compliant, low-latency architecture?
- A company running on-premises servers is starting a new business line and needs extra servers quickly. Which cloud computing advantage helps provision additional infrastructure rapidly?
- A company runs a critical Amazon RDS DB instance and requires high availability with a recovery time under 5 minutes. Which solution satisfies this requirement?
- A company runs a fault-tolerant batch-processing application on AWS that can tolerate interruptions. To minimize costs, which AWS offering should they use?
- A company runs a MariaDB database on-premises and plans to move it to AWS. Which AWS service will host this relational database with the least operational overhead?
- A company runs a monolithic on-premises application that is hard to scale and maintain. They plan to migrate it to AWS and split it into microservices. Which AWS Well-Architected best practice does this plan follow?
- A company runs a petabyte-scale data warehouse and wants a fully managed service that removes the need to manage hardware and software. Which AWS service satisfies this requirement?
- A company runs a website on Amazon EC2 and needs global reach with low latency for users. Which AWS service should they use?
- A company runs a workload in AWS. Which AWS best practice most directly helps ensure the architecture is as cost-effective as possible?
- A company runs Amazon EC2 instances and Application Load Balancers and wants stronger DDoS protections plus near real-time visibility into attacks. Which AWS service fulfills these needs?
- A company runs an Amazon EC2 workload continuously (24/7) and will need the same instance family and type for the next 12 months. Which combination of purchasing options will MOST reduce costs? (Choose two.)
- A company runs big-data analytics and massively parallel processing on AWS test and development servers and can tolerate occasional interruptions. Which EC2 purchasing option is the most cost-effective?
- A company runs EC2 instances in a research lab for 3 hours each week and the instances must not be interrupted. Which EC2 purchasing option is the most economical for these requirements?
- A company runs MySQL on self-managed servers in an on-premises data center and wants to move to a managed AWS database service. Which migration approach should they use?
- A company runs production workloads on AWS and must choose the least expensive AWS Support plan that still meets production support needs. Which plan should they choose?
- A company runs short-lived batch jobs on Amazon EC2 that can tolerate interruptions and resume from where they stopped. Which EC2 purchasing option is the most cost-effective for these workloads?
- A company runs thousands of stateless, fault-tolerant simulations that run up to 3 hours each on AWS Batch. Which EC2 pricing model best reduces cost while meeting these requirements?
- A company stores 5 TB of data in Amazon S3 and wants to run occasional queries on it for analysis. Which AWS service is the most cost-effective choice for running these queries?
- A company stores objects in an Amazon S3 bucket. Which of the following is the responsibility of AWS?
- A company stores records that may include personally identifiable information (PII) in Amazon S3. They need a service that scans all S3 buckets for PII and sends immediate alerts when issues are found. Which AWS service should they use?
- A company stores sensitive customer records in an S3 bucket and wants to prevent accidental deletion or overwriting of objects. Which S3 feature should they enable?
- A company transfers data between an Amazon S3 bucket and an on-premises application. Under the AWS shared responsibility model, who is responsible for securing that data?
- A company undergoing organizational transformation wants to be more responsive to customers as it migrates to the AWS Cloud. According to the AWS Cloud Adoption Framework (AWS CAF), which tasks should the company perform? (Choose two.)
- A company uses a central data platform to ingest different data types and needs AWS services to discover, transform, and visualize that data. Which two services should the company use?
- A company uses Amazon DynamoDB as its application database. Under the AWS shared responsibility model, which tasks are AWS's responsibility? (Choose two.)
- A company uses Amazon RDS and needs to ensure the database is highly available. Which RDS feature should be used?
- A company uses Amazon WorkSpaces. Under the AWS shared responsibility model, which of the following is AWS’s responsibility?
- A company uses an external identity provider and wants employees to access AWS accounts and services without creating separate AWS credentials. Which AWS service enables this capability?
- A company uses multiple AWS security services and wants a service that aggregates findings and organizes security alerts into a single dashboard. Which AWS service should they use?
- A company wants a centralized AWS service to enforce organizational compliance and control who can deploy, manage, and decommission AWS resources. Which AWS service is designed to provide that governance?
- A company wants a fully managed NoSQL database on AWS that can automatically scale throughput to match workload demand. Which service fits this requirement?
- A company wants a managed AWS service that can build container images from source code and deploy the containerized web application automatically. Which service should they use?
- A company wants a managed service to run relational databases that handles installation and periodic software updates. Which AWS service should they use?
- A company wants a report listing all IAM users and showing the status of their credentials (passwords, access keys, MFA devices). Which AWS feature provides this information?
- A company wants a single, consistent tool for interacting with AWS services from the command line. Which AWS tool provides this capability?
- A company wants EC2 instances to be added and removed automatically so capacity scales up and down with changing workloads. Which AWS feature or service provides this functionality?
- A company wants its workloads to run correctly and consistently throughout their lifecycle. Which pillar of the AWS Well-Architected Framework focuses on that goal?
- A company wants reusable templates to provision multiple AWS resources consistently. Which AWS service provides this capability?
- A company wants to administer its AWS resources using a graphical web interface. Which AWS service provides that capability?
- A company wants to analyze its data and create interactive visualization dashboards for users. Which AWS service provides interactive business intelligence dashboards and visual analytics?
- A company wants to automate infrastructure deployment with infrastructure as code and deploy identical production stacks across multiple AWS Regions. Which AWS service supports this requirement?
- A company wants to centrally define and enforce Amazon VPC security group policies across multiple AWS accounts in an organization under AWS Organizations. Which AWS service enables this centralized management?
- A company wants to consolidate its call centers and improve customer voice and chat interactions with agents. Which AWS service provides a cloud-based contact center solution?
- A company wants to continuously refine its procedures and operations to deliver business value. Which pillar of the AWS Well-Architected Framework does this describe?
- A company wants to evaluate its operational readiness and identify and reduce operational risks before launching a new product. Which AWS Support plan provides guidance and assistance for this scenario without extra charge?
- A company wants to find Amazon S3 buckets that are shared with other AWS accounts. Which AWS feature or service will help identify cross-account S3 sharing?
- A company wants to give employees a single intelligent search interface so they can search questions and retrieve precise answers. Which AWS service provides this capability?
- A company wants to identify and prioritize business transformation opportunities and assess readiness to move applications to AWS. Which AWS framework or tool should they use for that purpose?
- A company wants to make its AWS usage more sustainable by tracking, measuring, reviewing, and forecasting emissions produced by its AWS workloads. Which AWS tool or service can they use for this purpose?
- A company wants to manage cloud resources with infrastructure-as-code (IaC) templates and must meet internal compliance requirements. Which AWS service should they use to provide approved product and configuration catalogs?
- A company wants to migrate a legacy workload from its on-premises data center to AWS without making any changes to the workload. Which migration strategy best fits this requirement?
- A company wants to migrate an on-premises NoSQL workload to Amazon DynamoDB. Which AWS service is appropriate for that migration?
- A company wants to migrate its on-premises NFS file workload to AWS while preserving file-level access semantics. Which Storage Gateway option should they choose?
- A company wants to move multiple on-premises SQL databases to AWS and minimize the operational effort of managing database servers. Which AWS service provides the least operational overhead?
- A company wants to perform automated video analysis to identify employees entering its offices. Which AWS service should it use?
- A company wants to produce Amazon QuickSight dashboards weekly using its AWS billing data. Which AWS tool or feature should they use to get the detailed billing data needed for those dashboards?
- A company wants to protect its AWS data, systems, and assets while performing risk assessment and mitigation. Which pillar of the AWS Well-Architected Framework supports these goals?
- A company wants to rapidly set up a continuous integration and continuous delivery (CI/CD) pipeline. Which AWS service should they choose?
- A company wants to replace its on-premises contact center with a cloud-based solution that offers built-in AI features to improve customer experience. Which AWS service should they adopt?
- A company wants to rightsize its Amazon EC2 instances. Which change reduces instance sizing with the least operational overhead?
- A company wants to run a data warehouse for analytics without managing the underlying data warehouse infrastructure. Which AWS service meets this requirement?
- A company wants to run application stacks in AWS using preconfigured instances. Which service meets this requirement?
- A company wants to serve its website to a global audience with low latency for users worldwide. Which AWS service should they use?
- A company wants to store files in the AWS Cloud and provide users with direct download access via a public URL. Which AWS service or feature should they use?
- A company wants to store server log data to analyze customer experiences in the most cost-efficient way. Which AWS storage service is the most economical choice?
- A company wants to tag and track AWS usage costs by business category. Which AWS feature or service should they use to accomplish this?
- A company wants to understand how cloud computing improves operational agility. Which statement describes how AWS provides agility to users?
- A company wants users to sign in once and then authenticate and gain access to resources across multiple AWS accounts using the same credentials. Which AWS service enables this?
- A company will commit to ongoing use of its production Amazon EC2 instances to reduce overall costs. Which pricing options provide the lowest cost when making such a commitment? (Choose two.)
- A company will host a static website on Amazon EC2 instances for global users and needs to minimize latency. Which solution meets this requirement?
- A company will onboard remote employees who need Windows virtual desktops they can access from anywhere using either their computer client or a web browser. Which AWS service provides this managed virtual desktop solution?
- A company will run a compute-heavy workload that requires GPUs. Which EC2 instance family is appropriate?
- A company will run an application on Amazon EC2 instances continuously for one year. Which EC2 purchasing option is the most cost-effective for this steady, long-term use?
- A company will run critical production EC2 instances for at least three years and wants the lowest-cost pricing option. Which EC2 pricing model should they choose?
- A company will run web servers on Amazon EC2 to serve customers worldwide. Most users access the site only during specific hours of the day. To minimize ongoing operational cost, how should the EC2 instances be deployed?
- A company will store 5 MB audio files in Amazon S3, rarely access them, but must be able to retrieve them immediately. Which S3 storage class is the most cost-effective fit?
- A company will store data in AWS that is rarely accessed. When access is needed, the data must be retrievable within 12 hours. The company wants the lowest possible storage cost per gigabyte. Which Amazon S3 storage class satisfies these requirements?
- A company with multiple AWS accounts needs a single consolidated bill and centralized security and compliance management. Which AWS feature or service should they use?
- A company with multiple business units wants centralized governance: automate account creation, enforce service control policies, and simplify billing. Which AWS service should they use?
- A company’s physical tape library for backups is full and they want to extend tape storage capacity into AWS. Which AWS service should they use to integrate the tape library with the cloud?
- A company’s website is experiencing a DDoS attack. Which AWS service is designed to help protect the site from these attacks?
- A developer must use the AWS CLI to access AWS resources. Which credential or item must be created in the developer's AWS account to allow CLI access?
- A developer needs to provision development and production infrastructure in a repeatable, consistent way. Which AWS service should be used to define and deploy those environments?
- A developer needs to quickly deploy an application on AWS without manually creating each required resource. Which AWS service should they use?
- A developer needs to run a simple query over multiple comma-separated (.csv) report files stored in Amazon S3 and produce a summary with the least operational overhead. Which service should they use?
- A developer wants users to access AWS resources using temporary security credentials. Which AWS service should the developer use to issue these temporary credentials?
- A developer with limited AWS experience needs to quickly deploy a scalable Node.js web application to the AWS Cloud with minimal administration. Which AWS service should they choose?
- A developer with no prior AWS experience wants a simple service to begin building a web application. Which AWS service should they choose to get started quickly?
- A development team wants to create multiple test environments quickly and repeatably. Which AWS service is designed to deploy these environments as templates?
- A gaming company needs EC2 instances running continuously for one year with predictable, steady traffic and no interruptions. Which EC2 purchasing option provides the most cost savings while ensuring availability?
- A global company needs a managed security service that blocks SQL injection attacks and provides detailed access logging for its e-commerce applications. Which AWS service fulfills these requirements?
- A global firm wants experienced, worldwide AWS experts to help migrate third-party applications faster and follow AWS best practices. Which AWS offering provides this professional migration assistance?
- A library needs to automatically categorize electronic books by analyzing their content. Which AWS service should they use?
- A new AWS customer needs programmatic (API) access to interact with AWS Support. Which support plan should they choose to get this capability at the lowest cost?
- A new developer needs AWS credentials. Which of the following are recommended security best practices? (Choose two.)
- A reporting web application runs on EC2 instances only weekly and at month end and can be stopped when idle. Which EC2 pricing model is the most cost-effective for this use case?
- A research team collects data at remote sites with limited or no internet access and needs to capture data in the field and later transfer it to AWS. Which AWS service supports this workflow?
- A research team has a fixed grant split into monthly allocations and wants to be alerted if spending surpasses the planned monthly amount. Which AWS feature will notify them when costs exceed the set amount?
- A retail company is comparing building a new mobile app on-premises versus in the AWS Cloud. Which two of the following are benefits of using the AWS Cloud? (Choose two.)
- A retailer is migrating on-premises workloads to AWS and needs to automatically handle seasonal traffic spikes cost-effectively. Which AWS features will help accomplish this? (Choose two.)
- A shipping company operates cargo vessels that gather sensor data while at sea, where connectivity is intermittent or absent. The company needs to collect, preprocess, and store the data on the ship, then transfer it to AWS after returning to connectivity. Which AWS service best fits this use case?
- A stateful workload will run on Amazon EC2 for the next three years. Which pricing model is the most cost-effective for this long-term, stateful workload?
- A test workload can be interrupted and does not need to run continuously. Which Amazon EC2 purchasing option is the most cost-effective for this scenario?
- A user has been given permission to change their own IAM user password. Which AWS tools can the user use to change that password? (Choose two.)
- A user needs a relational database but cannot manage the hardware, resiliency, or replication. Which AWS service should they choose?
- A user needs to inspect all S3 buckets' access control lists (ACLs) and bucket policies from the S3 console. Which AWS feature provides that capability?
- A user needs to quickly provision a fully managed nonrelational (NoSQL) database on AWS without managing servers or database software. Which service should they use?
- A user needs to securely automate credential storage and rotation for secrets shared between applications while minimizing management effort. Which AWS service should they use?
- A workload is being moved from a local data center to an architecture that will be split between the local data center and AWS. What type of migration does this describe?
- A workload will run continuously for one year and cannot tolerate interruptions. Which Amazon EC2 purchasing option is the MOST cost-effective for this scenario?
- According to the AWS shared responsibility model, which of the following maintenance tasks is the customer's responsibility?
- According to the AWS shared responsibility model, which of the following is an AWS responsibility?
- According to the AWS shared responsibility model, which of these is fully the responsibility of AWS?
- According to the AWS shared responsibility model, which of these is the customer’s responsibility?
- After acquiring another company, an organization now has two AWS accounts and wants to consolidate billing for them. Which AWS service should they use?
- After an ecommerce company moves its infrastructure to AWS, which cost remains the company’s direct responsibility?
- After launching an Amazon EC2 instance using the latest Amazon Linux 2 AMI, which methods can a system administrator use to connect to the instance? (Choose two.)
- After launching an EC2 instance, which AWS resource should be used to control inbound and outbound network traffic at the instance level?
- After migrating and rightsizing systems, a company wants a service that continuously reports on optimization and security so future changes or growth don’t compromise the environment. Which AWS service should they use?
- After migrating to AWS and paying for services on an as-needed basis, which cloud benefit is the company experiencing?
- After moving its workload to AWS, a company wants to optimize its existing Amazon EC2 resources. Which AWS services or tools can help with that? (Choose two.)
- An Amazon EC2 instance resides in a private subnet. The instance must initiate outbound internet access to download operating system updates, but it must not be directly reachable from the internet. Which AWS managed component provides this capability?
- An application currently runs on EC2 and the company plans to partially move to a serverless architecture within a year. The company prefers to pay for capacity up front to save money. Which AWS purchasing option best optimizes their costs?
- An application is continuously generating unstructured data. The company needs a storage solution that is durable and easy to query. Which AWS service should they use?
- An application is deployed in multiple AWS Regions worldwide. The company wants to increase the application's performance and availability. Which AWS service should they use?
- An application needs temporary, limited-permission credentials to call other AWS APIs. Which AWS service or feature provides these short-lived credentials?
- An application on an Amazon EC2 instance needs to call other AWS services securely. Which AWS feature should be used to grant that secure access?
- An application requires powerful hardware, but students will access it from inexpensive, low-powered laptops. Which AWS service lets the company deliver the application without buying backend infrastructure or high-end client machines?
- An application requires sending, storing, and receiving messages between components, and it must process messages in first-in, first-out (FIFO) order. Which AWS service should be used?
- An application running on Amazon EC2 must remain available and operational continuously for three or more years. Which EC2 purchasing option should the company choose to obtain a discount on instance pricing?
- An application running on Amazon EC2 sometimes experiences sudden spikes in traffic. The company wants the application to scale automatically in response to demand while minimizing cost. Which AWS service or concept should they use?
- An application running on multiple Amazon EC2 instances publishes messages using Amazon SNS. Which AWS feature should be used to grant the application the permissions it needs to call AWS services securely?
- An e-commerce business has deployed a web application on Amazon EC2 instances and wants incoming HTTP requests to be evenly distributed across all healthy instances. Which AWS service or resource should they use?
- An e-commerce company wants to distribute incoming traffic across the EC2 instances hosting its website. Which AWS service should it use?
- An e-commerce system has multiple applications that need to exchange messages asynchronously. Which AWS service should be used to enable message queuing between these applications?
- An e-learning provider runs an application for only 2 months each year on Amazon EC2 and cannot tolerate any downtime during those months. Which EC2 purchasing option is the most cost-effective for this scenario?
- An EC2 instance that was used for development is now unreachable and no longer listed in the AWS Management Console. Which AWS service can you use to identify what action caused the instance to become inaccessible?
- An ecommerce company is migrating data-center workloads with highly variable usage to AWS. Which benefits of AWS make this type of migration cost-effective? (Choose two.)
- An ecommerce company wants Auto Scaling to add or remove EC2 instances based on CPU usage. Which AWS feature or service can trigger an Amazon EC2 Auto Scaling action to do this?
- An employee needs access to Amazon RDS but only via the AWS CLI and SDKs (no console access). To follow least privilege, which two actions should the company take?
- An engineer will store objects in Amazon S3 where some objects are accessed daily and others are accessed only once a year. Which S3 storage class is the most cost-effective choice for this mixed access pattern?
- An external auditor requests a list of all IAM users and the status of their credentials and access keys. What is the easiest method to supply this information?
- An IAM user was given an access key rather than a password. What is that access key intended to be used for?
- An independent software vendor needs to distribute and share its custom Amazon Machine Images (AMIs) with potential customers. Which AWS service enables that distribution?
- An On-Demand Amazon Linux EC2 instance ran for 3 hours, 5 minutes, and 6 seconds. For how long will the customer be billed?
- An on-premises application runs for less than five minutes each time and is invoked only a few times per day. To move this application to AWS in the most cost-effective way, which service should the company use?
- Application developers need to script rapid provisioning and management of AWS resources. Which AWS tool should they use to accomplish this?
- Before migrating to AWS, a practitioner needs to obtain AWS compliance reports. How can these reports be accessed?
- Deploying an application across multiple Availability Zones within a single AWS Region provides which benefit?
- Designing cloud architecture to enable ongoing innovation and continuous improvement of processes corresponds to which pillar of the AWS Well-Architected Framework?
- Developers are allowed to deploy applications but should not have to provision or manage the underlying infrastructure. Which AWS service lets developers deploy applications without handling the infrastructure?
- During organizational transformation for an AWS cloud migration, a company wants to become more responsive to customer feedback. According to the AWS Cloud Adoption Framework (AWS CAF), which action supports that goal?
- Employees frequently move between teams and need permissions that match their job responsibilities. Which IAM construct should the company use to provide appropriate permissions with the least operational overhead?
- Employees need remote access to persistent Windows or Linux desktops from any supported device, at any time and from any location. Which AWS service provides this capability?
- Employees working from home need to use personal devices to access a managed desktop environment hosted in AWS. Which AWS service provides that managed remote workstation?
- Following security best practices, how should an Amazon EC2 instance be granted access to upload an object to an Amazon S3 bucket?
- For a batch job that runs once a week and takes about 5 hours to complete, which AWS service is the appropriate choice to run this workload?
- For a steady production workload on Amazon EC2 that will run for one year, which instance purchasing option is the most cost-effective?
- For a workload that can tolerate interruptions, which Amazon EC2 purchasing option provides the LARGEST discount compared to On-Demand pricing?
- For Amazon EC2 Reserved Instances, which term length provides the greatest cost savings?
- For an always-on application running on Amazon EC2 that processes a growing backlog from an SQS queue for years, which EC2 purchasing option will deliver the greatest cost savings?
- For an always-on, appropriately sized database server needed for one year, which Amazon EC2 pricing option delivers the greatest cost savings?
- For an ML research project that needs substantial compute for several months and can run jobs at any time, which EC2 purchasing option provides the lowest cost?
- For an uninterruptible task that runs once per year for 24 hours, which Amazon EC2 pricing model is the most cost-efficient?
- For short-duration workloads that can be interrupted and where cost savings are a priority, which Amazon EC2 instance purchasing option should be used?
- For which scenario are Amazon EC2 On-Demand Instances the most cost-effective choice?
- How can the company securely authenticate to Linux-based Amazon EC2 instances?
- How does AWS cloud computing help organizations lower costs? (Choose two.)
- How much data can you store in Amazon S3?
- If a company migrating to AWS requires full control over patching guest operating systems, which service should it choose?
- If a company runs its databases on Amazon EC2 instances, which of the following is an AWS responsibility?
- If a company runs workloads on AWS, which service requires the company to manage and patch the guest operating system?
- If a company wants to deploy a third-party intrusion-detection solution from its AWS account, which AWS resource should it use?
- If a company’s Amazon EC2 instances show low utilization, which AWS service should be used to obtain rightsizing recommendations for those instances?
- If a customer wants to use their existing per-socket, per-core, or per-virtual-machine software licenses for Microsoft Windows Server on AWS, which type of Amazon EC2 instance must they use?
- If a vendor offers its security software as a SaaS solution on AWS, where can a company purchase that solution?
- If an AWS account exceeds the Free Tier limits or the Free Tier period ends, what will occur?
- If an AWS managed IAM policy doesn’t provide needed permissions for users, what is the appropriate way to fix this?
- In the AWS shared responsibility model, what does the phrase “security of the cloud” mean?
- In which situation is creating an IAM user more appropriate than creating an IAM role?
- In which ways does the AWS Cloud provide a lower total cost of ownership (TCO) for computing resources compared to on-premises data centers? (Choose two.)
- Select the option(s) that are pillars of the AWS Well-Architected Framework. (Choose two.)
- The company frequently does not use all of its Amazon EC2 capacity for stateless workloads and wants to reduce EC2 costs. Which EC2 purchasing option is most appropriate?
- The company has AWS Enterprise Support and expects a large traffic increase to its website hosted on Amazon EC2 in two months. What should the company do to evaluate readiness for the launch?
- The company is preparing to migrate to AWS and needs detailed information about its on-premises servers, applications, and usage patterns, but does not want to replicate workloads to AWS yet. Which AWS service or tool should they use?
- The company needs a browser-based interface to interact with various AWS services. Which AWS offering provides that web-based access?
- The company needs a highly available, scalable DNS service to route users around the world to its new global ecommerce platform. Which AWS service fulfills this requirement?
- The company needs a secure network connection from its on-premises data center to AWS within one week. Which solution meets this requirement?
- The company needs stateless network filtering for resources in a VPC. Which AWS tool or feature provides stateless network filtering?
- The company needs the ability to launch Amazon EC2 instances on demand, ensure they are available without interruption when required, and pay for compute by the second. Which EC2 purchasing option meets these needs?
- The company needs to audit recent account activity to determine who performed actions and what those actions were. Which AWS service provides this type of event logging for auditing?
- The company needs to host a static website using AWS services with the least operational overhead. Which solution meets this requirement?
- The company needs to run graph queries to detect fraud patterns in real time. Which AWS service is designed for graph databases and will meet this requirement?
- The company needs to run its marketing and order-processing applications on different instance types with varying CPU, memory, storage, and networking. Which AWS service provides that capability?
- The company plans to migrate on-premises relational databases to AWS and wants the deployment to be geographically close to its current location. Which AWS construct should they use to choose the Amazon RDS deployment area?
- The company plans to use container-based workloads that run for about 4 hours at a time and does not want to provision or manage servers. Which AWS service should they choose?
- The company requires a firewall that controls network traffic to and from a single Amazon EC2 instance, without affecting other instances in the same subnet. Which AWS feature meets this requirement?
- The company stores a large volume of data in AWS and wants to detect if any of it is sensitive. Which AWS service helps identify sensitive data?
- The company uses separate AWS accounts for different teams. The finance team wants a single consolidated invoice that covers all company accounts. Which AWS service or tool should the finance team use?
- The company wants a tailored assessment of its on-premises environment and an estimate of projected AWS running costs. Which AWS tool provides this?
- The company wants to confirm that AWS services and the AWS infrastructure are operating normally. Which two services provide this operational status information? (Choose two.)
- The company wants to review user activity by recording and analyzing API calls. Which AWS service provides this capability?
- The company will run multiple workloads for different business units and wants to separate and track costs for each unit with the least operational overhead. Which solution meets this requirement?
- The finance team needs to track past months' AWS cost and usage and automatically produce reports. Which AWS feature or service should they use to meet this requirement?
- To centrally store configuration settings and application passwords in the most cost-effective way, which AWS service should you use?
- To deliver images and videos globally with minimal latency in a cost-effective way, which approach should the company use?
- To deliver low latency to users around the world, which characteristic of the AWS Cloud is most relevant?
- To deliver real-time data from an on-premises data center to an application running on AWS with consistent connectivity and low latency, which connection option should the company use?
- To discover, prepare, move, and combine data from multiple sources for analytics and machine learning, which AWS serverless data integration service should be used?
- To ensure Amazon EC2 instances remain available even if a natural disaster impacts a specific geographic area, which solution should be used?
- To ensure an AWS workload remains operational when components fail, what is an AWS best practice?
- To ensure EC2 instances remain available even if a natural disaster affects a geographic area, which approach should the company take?
- To maintain dedicated bandwidth and a more consistent network experience than the public internet, which AWS service should the company select?
- To protect a web application on AWS from network-layer DDoS attacks, which service should be used?
- To protect applications from SQL injection attacks, which AWS service or feature should the company use?
- To provide managed Windows virtual desktops and applications to remote employees over secure connections, which AWS services should the company use? (Select two.)
- To run an experimental workload on an EC2 instance continuously for up to 12 hours and then stop it, which EC2 purchasing option is the most cost-effective?
- Under the AWS Shared Responsibility Model for Amazon DynamoDB, which of the following is a customer responsibility?
- Under the AWS shared responsibility model for AWS Lambda, which task is the customer's responsibility?
- Under the AWS shared responsibility model, for which of the following is the customer responsible for applying operating system updates and security patches?
- Under the AWS shared responsibility model, what is the customer's responsibility when using AWS Lambda?
- Under the AWS shared responsibility model, which control is shared between AWS and the customer?
- Under the AWS shared responsibility model, which of the following are customer responsibilities? (Choose two.)
- Under the AWS shared responsibility model, which of the following is a shared responsibility between AWS and the customer?
- Under the AWS shared responsibility model, which of the following is always the customer's responsibility to manage?
- Under the AWS shared responsibility model, which of the following is an AWS responsibility?
- Under the AWS shared responsibility model, which of the following is the customer's responsibility?
- Under the AWS shared responsibility model, which of the following tasks are the customer’s responsibility? (Choose two.)
- Under the AWS shared responsibility model, which of these is AWS’s responsibility?
- Under the AWS shared responsibility model, which of these is the customer's responsibility?
- Under the AWS shared responsibility model, which of these tasks is the customer's responsibility?
- Under the AWS shared responsibility model, which task is AWS responsible for?
- Under the AWS shared responsibility model, which task is the customer responsible for?
- Under the AWS shared responsibility model, which task is the customer’s responsibility?
- Under the AWS shared responsibility model, which task is the responsibility of AWS?
- Under the AWS shared responsibility model, which tasks are AWS's responsibility? (Choose two.)
- Under the AWS shared responsibility model, which responsibilities fall to the customer? (Select two.)
- Using Amazon DynamoDB, which responsibility remains with the customer under the AWS shared responsibility model?
- Using AWS Identity and Access Management (IAM) to grant users only the permissions required to perform a task is known as:
- What capability does the Amazon S3 Intelligent-Tiering storage class provide?
- What does AWS provide to help customers meet Payment Card Industry Data Security Standard (PCI DSS) requirements for specific AWS services?
- What is a key benefit customers gain by migrating their on-premises workloads to the AWS Cloud?
- What is a key benefit of using an Elastic Load Balancer (ELB) with applications running on AWS?
- What is a primary benefit of adopting AWS serverless computing?
- What is the main purpose of Amazon GuardDuty?
- What is the most operationally efficient way to take a one-time backup of an EBS volume that is attached to an EC2 instance?
- What is the primary purpose of Amazon CloudFront?
- What is the primary purpose of using AWS CloudFormation templates?
- What is the purpose of an internet gateway in a VPC?
- What is the term for selecting the optimal Amazon EC2 instance types and sizes to meet performance and capacity needs while minimizing cost?
- What method allows developers to call AWS services directly from application code?
- What must be attached to a VPC to allow instances in that VPC to receive inbound traffic from the internet?
- What type of assistance does the AWS Enterprise Support Concierge team provide?
- What type of workload is best suited to run on Amazon EC2 Spot Instances?
- When a company migrates an on-premises production workload to AWS, which of the following benefits might it gain? (Choose two.)
- When configuring AWS Identity and Access Management (IAM), which practice follows security best practices?
- When connecting on-premises networks to AWS using Direct Connect and planning to grow from a few VPCs to hundreds in one Region, which service or feature simplifies and scales connectivity across many VPCs?
- When is it most appropriate to use Amazon EC2 On-Demand Instances?
- When learning the AWS Cloud Adoption Framework (AWS CAF), which CAF perspective includes the strategy management capability?
- When migrating on-premises infrastructure to AWS, which cloud advantage helps reduce upfront capital expenses?
- When modernizing a monolithic application into microservices on AWS, which migration strategy should be used?
- When using Amazon RDS, which responsibility remains with the customer?
- When using the AWS Cloud Adoption Framework to identify capability gaps, during which phase of the cloud transformation journey are those gap-identification activities performed?
- When you use AWS services, which responsibility belongs to AWS?
- Where can a compliance officer obtain AWS Service Organization Control (SOC) reports?
- Where should a user go to obtain AWS compliance documentation and reports (for example, certifications and audit reports)?
- Which action can a company implement using security groups in AWS?
- Which action is a security best practice for granting applications access to sensitive data stored in an Amazon S3 bucket?
- Which actions are recommended best practices for an AWS account root user? (Choose two.)
- Which Amazon EC2 pricing option can provide cost reductions of up to 90%?
- Which Amazon EC2 purchasing option is the most cost-effective for running a continuous simulation for three years?
- Which Amazon RDS capability automatically creates a primary DB instance and synchronously replicates its data to a standby instance in a different Availability Zone?
- Which Amazon S3 feature can produce a report that lists object tags, bucket names, and prefixes?
- Which Amazon S3 feature enables fast, secure transfers of files over long distances between client devices and an S3 bucket?
- Which Amazon S3 feature uses the AWS backbone network and edge locations to reduce latency between end users and S3?
- Which Amazon S3 storage class is the most cost-effective for data that is infrequently accessed and can be regenerated if lost?
- Which Amazon S3 storage class is the most cost-effective when access patterns are unknown?
- Which architectural principle describes provisioning resources on demand and releasing them when they are no longer required?
- Which architectural principle helps an application remain available when an individual component fails?
- Which architectural principle refers to separating dependent components so a failure in one does not directly break others in the AWS Cloud?
- Which AWS advantage is illustrated by on-demand services that let organizations convert upfront fixed costs into variable operating expenses?
- Which AWS architectural principle lets you provision resources when required and release them when they are no longer needed?
- Which AWS architectural principle promotes minimizing dependencies between application components?
- Which AWS benefit is always available at no cost, regardless of the AWS Support plan a user has?
- Which AWS capability should a company use to track cloud costs in detail by department and project?
- Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on monitoring and maintaining day-to-day operations to ensure services meet business requirements?
- Which AWS Cloud Adoption Framework (AWS CAF) perspective is primarily concerned with managing identities and permissions across the organization?
- Which AWS Cloud Adoption Framework (CAF) perspective is centered on business strategy and delivers real-time, strategy-focused insights?
- Which AWS Cloud Adoption Framework (CAF) perspective is concerned with creating and maintaining a catalog of data products?
- Which AWS Cloud benefit enables lower costs because AWS aggregates usage across all customers?
- Which AWS Cloud benefit is demonstrated when an architecture continues operating through failures with only minimal downtime?
- Which AWS Cloud design principle is being followed when a company enables AWS CloudTrail to record API activity and changes?
- Which AWS cloud principle best helps a company rapidly test a new application?
- Which AWS component enables incoming internet traffic to reach resources inside a VPC?
- Which AWS concept describes the ability to provision resources when they are needed and release them when they are no longer required?
- Which AWS feature acts as a firewall at the subnet level inside a VPC?
- Which AWS feature acts as a virtual firewall applied at the VPC subnet level?
- Which AWS feature automatically adjusts the number of Amazon EC2 instances in use based on current application load?
- Which AWS feature can be configured to restrict network access at the subnet level?
- Which AWS feature can detect if an Amazon S3 bucket or an IAM role has been shared with an external principal?
- Which AWS feature can record details about incoming and outgoing network traffic for resources in an Amazon VPC?
- Which AWS feature can you use to establish a firewall that controls traffic entering and leaving an Amazon VPC subnet?
- Which AWS feature lets you capture and record information about the network traffic within a VPC?
- Which AWS feature or service provides a report that lists the multi-factor authentication (MFA) device status for every user in an AWS account?
- Which AWS feature provides logs of the inbound and outbound IP traffic for network interfaces in a VPC?
- Which AWS features allow you to create a network connection between two VPCs? (Select two.)
- Which AWS framework or tool should a company use to evaluate its readiness to migrate applications to the AWS Cloud?
- Which AWS group provides paid engagements across specialized practice areas to help accelerate a customer's cloud adoption?
- Which AWS managed service is specifically designed to perform extract, transform, and load (ETL) operations?
- Which AWS networking constructs accept IP address ranges specified using CIDR notation? (Choose two.)
- Which AWS networking service provides a central gateway to connect multiple VPCs and on-premises networks?
- Which AWS offering allows a company to have its own logically isolated portion of the AWS Cloud?
- Which AWS offering allows developers to programmatically connect to AWS and deploy resources?
- Which AWS offering can establish a private network connection between an on-premises environment and resources in the AWS Cloud?
- Which AWS offering enables moving petabytes of on-premises data to AWS without using an internet connection?
- Which AWS offering gives a web-based graphical interface that users can use to manage AWS services?
- Which AWS offering is a browser-based, pre-authenticated shell that you can launch directly from the AWS Management Console?
- Which AWS offering lets you define and provision AWS resources using familiar programming languages?
- Which AWS option lets a company lower EC2 costs by committing to a certain level of usage?
- Which AWS product lets an organization use file protocols (for example, NFS) to read and write objects in Amazon S3?
- Which AWS resource can host AWS WAF rules to protect web traffic?
- Which AWS resource provides answers to the most frequently asked security questions AWS receives from users?
- Which AWS resource provides example cloud solution architectures and reference designs?
- Which AWS security service automatically discovers and classifies sensitive data and intellectual property stored in AWS?
- Which AWS security service defends applications from DDoS attacks using continuous detection and automatic inline mitigation?
- Which AWS service allows a single account to pay and manage billing for multiple linked AWS accounts?
- Which AWS service allows distributed applications to send both SMS text messages and email notifications?
- Which AWS service allows you to host a NoSQL database in the AWS Cloud?
- Which AWS service analyzes an AWS environment and gives best-practice recommendations across cost, performance, service limits, fault tolerance, and security?
- Which AWS service assists migration planning by discovering and collecting configuration, usage, and behavior data from on-premises data centers?
- Which AWS service automates the deployment of application code to Amazon EC2 instances and to on-premises servers?
- Which AWS service can a company use to identify IAM access keys that have not been rotated recently?
- Which AWS service can a company use to manage encryption keys in the cloud?
- Which AWS service can a company use to manage cryptographic keys in the cloud?
- Which AWS service can an administrator use to provide virtual desktop environments to employees?
- Which AWS service can automatically convert and migrate an on-premises virtual Windows Server into a server that runs on AWS infrastructure?
- Which AWS service can be used to migrate existing Amazon EC2 instances from one AWS Region to another?
- Which AWS service can convert written text into spoken audio for an accessibility application?
- Which AWS service can detect security groups that are misconfigured and allowing unrestricted access to specific ports?
- Which AWS service can generate personalized product recommendations by using your company's customer data?
- Which AWS service can inspect and block malicious HTTP and HTTPS requests that are sent to Amazon CloudFront distributions?
- Which AWS service can notify customers when they exceed their defined spending thresholds?
- Which AWS service can produce reports or configuration data that external auditors can use?
- Which AWS service can record and show when an Amazon EC2 instance was terminated?
- Which AWS service can scan your AWS environment to identify security vulnerabilities on Amazon EC2 instances?
- Which AWS service can securely store Amazon RDS credentials and automatically rotate database user passwords on a scheduled basis?
- Which AWS service can send notifications when a specific Amazon CloudWatch alarm is triggered?
- Which AWS service can the company use to add a conversational chatbot to its website?
- Which AWS service can the company use to allow customers to sign into its online store using social media or other external identity providers?
- Which AWS service converts speech to text to help create meeting notes?
- Which AWS service converts text into natural-sounding speech?
- Which AWS service enables a company to define and provision its infrastructure using code (infrastructure as code)?
- Which AWS service enables a developer to use a template to provision consistent copies of the company’s AWS environment for development, test, and production?
- Which AWS service enables a hybrid architecture by extending AWS infrastructure, services, APIs, and tools into data centers, co-location sites, or on-premises facilities?
- Which AWS service enables a mobile application’s users to sign in using social identity providers (for example, Facebook or Google)?
- Which AWS service enables users to ask natural-language questions of BI data and receive answers with relevant visualizations inside dashboards?
- Which AWS service enables users to create interactive business intelligence dashboards that can include machine learning insights?
- Which AWS service enables you to define and provision your cloud infrastructure using templates (in other words, manage infrastructure as code)?
- Which AWS service gives a single, central place to monitor the progress and status of application migrations?
- Which AWS service helps deploy an application closer to end users to reduce latency?
- Which AWS service helps discover and collect information about an on-premises data center to support a migration to AWS?
- Which AWS service helps locate and protect sensitive or personally identifiable information stored in Amazon S3 buckets?
- Which AWS service helps provide highly available applications with quick failover across Regions and Availability Zones?
- Which AWS service helps set up and govern a new multi-account environment for a company with multiple accounts and teams?
- Which AWS service helps you deploy and manage applications in the AWS Cloud?
- Which AWS service helps you plan and track the migration of servers and applications to AWS, including inventory and migration status?
- Which AWS service implements a publish–subscribe model using publishers and subscribers?
- Which AWS service integrates with other AWS services to manage and provide encryption for data at rest?
- Which AWS service is a cloud security posture management (CSPM) tool that consolidates findings from AWS services and partner products into a standardized view?
- Which AWS service is a fully managed database that is compatible with MySQL?
- Which AWS service is a fully managed NoSQL database?
- Which AWS service is a relational database that is compatible with MySQL and PostgreSQL?
- Which AWS service is a scalable key-value database that delivers sub-millisecond latency at large scale?
- Which AWS service is a target for sizing recommendations from AWS Compute Optimizer based on workload metrics?
- Which AWS service is designed as a purpose-built time-series database to store and analyze trillions of events each day?
- Which AWS service is designed to handle very large-scale data in a data warehouse environment?
- Which AWS service is designed to help build, train, and deploy custom machine learning models?
- Which AWS service is designed to search and find text within documents stored in Amazon S3?
- Which AWS service is designed to transfer data between AWS storage services?
- Which AWS service is intended to securely store and encrypt database passwords and other secret values?
- Which AWS service is provided at no cost to all AWS customers?
- Which AWS service is responsible for providing DNS resolution?
- Which AWS service is specifically intended for workloads that require a NoSQL database?
- Which AWS service is used to perform encryption for Amazon EBS volumes?
- Which AWS service issues temporary, federated security credentials to allow access to AWS resources?
- Which AWS service lets a company define and centrally enforce data-protection policies across compute, storage, and database resources?
- Which AWS service lets a company manage deployed IT offerings and control its infrastructure-as-code templates through a catalog?
- Which AWS service lets a company run application code without provisioning or managing servers?
- Which AWS service lets a company set spending thresholds and receive alerts when those thresholds are exceeded?
- Which AWS service lets customers record and review API calls made in their AWS accounts?
- Which AWS service lets organizations define and provision infrastructure using code (infrastructure as code)?
- Which AWS service lets organizations subscribe to RSS feeds that provide updates about AWS service issues?
- Which AWS service lets you create and deploy copies of resources across different AWS Regions?
- Which AWS service lets you create new AWS accounts, group multiple accounts for organization and workflow purposes, and apply policies to account groups?
- Which AWS service lets you define and deploy consistent, repeatable infrastructure configurations?
- Which AWS service lets you define and manage cloud infrastructure using common programming languages such as TypeScript, Python, Java, and .NET?
- Which AWS service lets you obtain compliance and audit reports on demand?
- Which AWS service lets you run SQL queries directly against data objects stored in an Amazon S3 bucket?
- Which AWS service lets you securely store and retrieve encrypted credentials on demand?
- Which AWS service lets you visually design and assemble serverless applications?
- Which AWS service manages access permissions to AWS resources by using policies?
- Which AWS service offers a fully managed graph database optimized for highly connected datasets?
- Which AWS service offers a managed relational database with features such as automated backups and database snapshots?
- Which AWS service offers highly durable object storage for files and objects?
- Which AWS service or feature can be used to block SQL injection attacks?
- Which AWS service or feature can be used to enforce security rules that apply to individual Amazon EC2 instances?
- Which AWS service or feature can detect resources that are shared externally from your account?
- Which AWS service or feature improves application network performance by routing traffic over the AWS global network?
- Which AWS service or feature lets you connect multiple VPCs and on-premises networks through a central hub routing platform?
- Which AWS service or feature lets you establish a dedicated network connection between your on-premises data center and the AWS Cloud?
- Which AWS service or feature lets you provision AWS infrastructure programmatically?
- Which AWS service or feature provides a private network connection between AWS and an on-premises corporate network?
- Which AWS service or feature provides governance, compliance tracking, and auditing of activity across AWS accounts?
- Which AWS service or feature requires an internet service provider (ISP) and access to a colocation facility to set up?
- Which AWS service or feature should be used to monitor an EC2 instance for possible spikes in disk write activity?
- Which AWS service or resource can show which AWS services a particular user accessed during a specified date range?
- Which AWS service or tool can detect and produce reports about IAM resources in one AWS account that are shared with another AWS account?
- Which AWS service or tool can help a company migrate on-premises databases to managed cloud database services using a simplified migration process?
- Which AWS service or tool enables automated deployment of application updates?
- Which AWS service or tool provides real-time monitoring of AWS resources and applications?
- Which AWS service or tool should be used to migrate an on-premises PostgreSQL database to Amazon RDS?
- Which AWS service protects web applications from common exploits such as SQL injection and cross-site scripting?
- Which AWS service provides a highly available, scalable DNS service for applications running on AWS?
- Which AWS service provides a hybrid storage solution that gives on-premises environments access to virtually unlimited cloud-backed storage?
- Which AWS service provides a managed NFS file system that can be mounted by AWS compute resources?
- Which AWS service provides a managed PostgreSQL database suitable for online transaction processing (OLTP)?
- Which AWS service provides a private network connection between an on-premises data center and AWS?
- Which AWS service provides a recorded history of API calls and information about resources that have been created in an AWS account?
- Which AWS service provides a shared file system that can be mounted by multiple Amazon EC2 instances?
- Which AWS service provides a single endpoint and distributes incoming web traffic across multiple EC2 instances?
- Which AWS service provides access to AWS security and compliance reports that can be downloaded and submitted to auditors or regulators?
- Which AWS service provides access to AWS-issued compliance reports, certifications, accreditations, and third-party attestations?
- Which AWS service provides alerts and tracking to help monitor and control overall operating costs for an AWS environment?
- Which AWS service provides auditing of API activity across an AWS account?
- Which AWS service provides command-line access to AWS tools and resources directly from a web browser?
- Which AWS service provides continuous scanning of Amazon EC2 instances for software vulnerabilities?
- Which AWS service provides CPU utilization metrics for a company's Amazon EC2 instances so a systems administrator can monitor them?
- Which AWS service provides highly durable, effectively infinite scalable object storage for static content at the lowest cost?
- Which AWS service provides information about the operational status and availability of AWS services?
- Which AWS service provides interactive dashboards and visualizations to analyze business data?
- Which AWS service provides machine-learning capabilities to detect and analyze objects and activities in images and videos?
- Which AWS service provides on-demand access to security and compliance reports for AWS infrastructure?
- Which AWS service provides on-demand, self-service access to AWS compliance and security control reports?
- Which AWS service provides on-premises applications with low-latency access to data that is stored in AWS?
- Which AWS service provides private connectivity between supported AWS services and your VPCs without sending traffic over the public internet?
- Which AWS service provides serverless compute so the company can run code without managing servers?
- Which AWS service provides serverless compute specifically for running containers so you don't manage the underlying servers?
- Which AWS service provides user sign-up and authentication capabilities for web and mobile applications?
- Which AWS service records account activity and API calls so you can determine who deleted resources?
- Which AWS service records and evaluates resource configuration changes and can automate remediation actions?
- Which AWS service records API activity and user actions in your AWS account so you can see when API calls are made against your resources?
- Which AWS service records, tracks, and audits configuration changes made to your AWS resources?
- Which AWS service should a company use to analyze and search large collections of images?
- Which AWS service should a company use to create workforce users and centrally manage their sign-in security and access across all of the company’s AWS accounts and applications?
- Which AWS service should a solutions architect use to keep a fleet of EC2 instances healthy by automatically replacing any impaired instances?
- Which AWS service should a user choose to detect potential compromises or threats to instances or accounts proactively?
- Which AWS service should be used to trigger an AWS Lambda function when an Amazon EC2 instance transitions to the “stopping” state?
- Which AWS service simplifies monitoring and troubleshooting by collecting metrics and logs from applications and cloud resources?
- Which AWS service transforms video and audio files into formats that will play on smartphones?
- Which AWS service uses edge locations to cache and deliver content to users?
- Which AWS service uses machine learning to analyze log data from Amazon EC2 instances and helps accelerate security investigations?
- Which AWS service uses predefined assessment templates to identify vulnerabilities on Amazon EC2 instances?
- Which AWS services are covered by AWS Savings Plans? (Select two.)
- Which AWS services can help a company build a loosely coupled architecture? (Choose two.)
- Which AWS services can host PostgreSQL databases? (Choose two.)
- Which AWS services or features allow you to connect an on-premises network (for example, a corporate data center) to an Amazon VPC? (Choose two.)
- Which AWS services or features assist with disaster recovery for Amazon EC2 instances? (Select two.)
- Which AWS services or features help ensure high availability and lower latency by enabling failover across multiple AWS Regions? (Choose two.)
- Which AWS services or tools can be used to send a notification when AWS costs exceed a specified threshold? (Choose two.)
- Which AWS services or tools can help identify rightsizing opportunities for Amazon EC2 instances? (Choose two.)
- Which AWS services use global edge locations? (Select two.)
- Which AWS storage option is temporary (ephemeral) and is removed when its associated Amazon EC2 instance is stopped or terminated?
- Which AWS Support plan includes access to a support concierge?
- Which AWS Support plan, at the lowest cost, provides the full set of AWS Trusted Advisor checks?
- Which AWS Support plans include access to a Technical Account Manager (TAM)? (Choose two.)
- Which AWS tool allows customers to forecast service usage and costs, plan instance reservations, and create custom alerts when usage or spending exceeds defined thresholds?
- Which AWS tool analyzes historical workload data and provides recommendations to right-size Amazon EC2 instances?
- Which AWS tool helps users visualize, analyze, and manage their AWS costs and usage over time?
- Which AWS tool lets a company visualize and analyze its AWS costs and usage over a chosen time period?
- Which AWS tool or service can be used to estimate the cost of a project before any infrastructure is provisioned?
- Which AWS tool provides a baseline inventory of on-premises workloads and estimates the projected cost to run those workloads in AWS?
- Which AWS tool provides rightsizing recommendations for EC2 instances at no extra charge?
- Which AWS tool provides visualizations of past AWS spending and projections for future costs?
- Which AWS tool should a company use to estimate the cost of an architecture before migrating to AWS?
- Which AWS value proposition describes the ability to scale infrastructure up or down based on demand?
- Which AWS Well-Architected Framework pillar is focused on ensuring that workloads perform their functions and can rapidly recover from failures?
- Which benefit of the AWS Cloud allows a business to provision compute, storage, and database resources within minutes?
- Which benefits are provided by using consolidated billing in AWS? (Select two.)
- Which benefits does a company gain by moving from on-premises IT to the AWS Cloud? (Choose two.)
- Which capabilities belong to the platform perspective in the AWS Cloud Adoption Framework (AWS CAF)? (Choose two.)
- Which capability does the AWS Pricing Calculator provide?
- Which capability in the AWS Cloud Adoption Framework (AWS CAF) is associated with the business perspective?
- Which capability in the AWS Cloud Adoption Framework (AWS CAF) is categorized under the People perspective?
- Which characteristic of the AWS Cloud enables users to eliminate underutilized CPU capacity?
- Which choice represents a physical location within the AWS global infrastructure?
- Which cloud computing advantage is a company using when it deploys resources in multiple AWS Regions to improve application availability for users in other countries?
- Which cloud computing benefit allows a company to provision infrastructure for new applications within minutes?
- Which cloud computing benefit allows you to scale resources up and down according to application load?
- Which cloud computing benefit enables a company to deliver applications to users worldwide using AWS Regions, Availability Zones, and edge locations?
- Which cloud concept describes the ability to automatically acquire resources when needed and release them when they are no longer required?
- Which cloud concept is exemplified by using AWS Compute Optimizer to choose appropriate instance types?
- Which cloud practice is illustrated by using AWS Cost Explorer to analyze resource usage and identify optimization opportunities?
- Which combination of an AWS service and an AWS Support plan provides checks and recommendations for cost optimization, security, fault tolerance, performance, and service quotas?
- Which complimentary AWS tool produces data-driven business cases to support cloud migration and planning?
- Which cost-saving recommendation can AWS Cost Explorer provide?
- Which deployment model includes using AWS Outposts as part of the infrastructure for deploying applications?
- Which design approach is an example of the performance efficiency pillar in the AWS Well-Architected Framework?
- Which design practices should a company apply to AWS workloads to maximize sustainability and reduce environmental impact? (Choose two.)
- Which design principle corresponds to the Reliability pillar in the AWS Well-Architected Framework?
- Which design principle from the AWS Well-Architected Framework supports operational excellence in the cloud?
- Which design principles belong to the Reliability pillar of the AWS Well-Architected Framework? (Choose two.)
- Which design principles help fulfill the reliability pillar of the AWS Well-Architected Framework? (Choose two.)
- Which EC2 pricing option can cause a running instance to be interrupted if AWS capacity becomes temporarily unavailable?
- Which EC2 purchasing option provides the most cost-effective way to run an application continuously without interruptions?
- Which elements make up the AWS Cloud global infrastructure? (Choose two.)
- Which free AWS platform lets users join community groups, ask and answer questions, and read community-created best-practice articles?
- Which fully managed AWS service centralizes and automates data protection across AWS services and hybrid environments?
- Which fully managed AWS service helps you create, test, and manage custom Amazon EC2 images?
- Which managed AWS service can discover and help protect sensitive data stored in Amazon S3?
- Which managed AWS service lets you quickly deploy a non-containerized Java web application and automatically provisions capacity, load balancing, scaling, and health monitoring?
- Which measure should a company implement to improve security for its AWS account?
- Which native AWS capability allows control of network traffic between specific EC2 instances within a VPC?
- Which of the following actions are examples of rightsizing AWS resources to reduce cloud expenses? (Choose two.)
- Which of the following actions helps improve security in AWS?
- Which of the following are benefits of using the AWS Cloud? (Choose two.)
- Which of the following are benefits provided by AWS Trusted Advisor? (Choose two.)
- Which of the following are capabilities in the AWS CAF security perspective? (Choose two.)
- Which of the following are capabilities in the security perspective of the AWS Cloud Adoption Framework (AWS CAF)? (Choose two.)
- Which of the following are capabilities within the governance perspective of the AWS Cloud Adoption Framework? (Choose two.)
- Which of the following are economic benefits of using the AWS Cloud? (Choose two.)
- Which of the following are managed using AWS Identity and Access Management (IAM)? (Choose two.)
- Which of the following are perspectives in the AWS Cloud Adoption Framework (AWS CAF)? (Choose two.)
- Which of the following are pillars of the AWS Well-Architected Framework? (Choose two.)
- Which of the following are recommended best practices when using AWS Identity and Access Management (IAM)? (Choose two.)
- Which of the following are recommended phases in the AWS Cloud Adoption Framework (CAF) cloud transformation journey? (Choose two.)
- Which of the following are valid ways to strengthen security on AWS? (Choose two.)
- Which of the following AWS services are serverless? (Choose two.)
- Which of the following AWS services supports running MySQL database engines?
- Which of the following best describes a benefit of economies of scale from cloud computing?
- Which of the following can be components of a VPC? (Select two.)
- Which of the following capabilities belong to the People perspective of the AWS Cloud Adoption Framework? (Choose two.)
- Which of the following describes how Amazon EC2 Auto Scaling groups can be used to scale capacity in the AWS Cloud?
- Which of the following functions as an instance-level (host) firewall to control inbound and outbound traffic?
- Which of the following is a benefit of AWS cloud computing that helps lower variable costs?
- Which of the following is a benefit of using AWS cloud computing?
- Which of the following is a benefit provided by the AWS Cloud?
- Which of the following is a capability provided by AWS CloudTrail?
- Which of the following is a capability that belongs to the Platform perspective of the AWS Cloud Adoption Framework (AWS CAF)?
- Which of the following is a perspective in the AWS Cloud Adoption Framework (AWS CAF) that covers foundational capabilities?
- Which of the following is a recommended architectural design principle when building on AWS?
- Which of the following is a recommended design principle from the AWS Well-Architected Framework?
- Which of the following is a Well-Architected Framework design principle for building cloud applications?
- Which of the following is defined as an environment composed of one or more data centers?
- Which of the following methods can be used to encrypt objects at rest in Amazon S3? (Choose two.)
- Which of the following tasks are the responsibility of AWS under the AWS shared responsibility model? (Choose two.)
- Which of the following tasks related to Amazon EC2 instances are the customer’s responsibility? (Choose two.)
- Which of these actions requires signing in as the AWS account root user?
- Which of these are benefits of migrating to the AWS Cloud? (Select two.)
- Which of these are benefits provided by AWS Trusted Advisor? (Choose two.)
- Which of these are characteristics of network access control lists (network ACLs) in AWS? (Choose two.)
- Which of these AWS services can be used without incurring additional service charges?
- Which of these AWS services is provided to customers at no charge?
- Which of these AWS services operate as serverless offerings? (Select two.)
- Which of these capabilities are part of the Governance perspective in the AWS Cloud Adoption Framework? (Choose two.)
- Which of these is a fully managed graph database service offered by AWS?
- Which offering provides discounted pricing on some AWS services in return for a committed spending agreement?
- Which option is the most secure method for storing application passwords on AWS?
- Which option represents a capability under the AWS Cloud Adoption Framework (AWS CAF) business perspective?
- Which pair of AWS tools can be used together to migrate a commercial relational database to an Amazon-managed open-source database? (Choose two.)
- Which party shares responsibility with AWS for the security and compliance of an AWS account and its resources?
- Which perspective in the AWS Cloud Adoption Framework (AWS CAF) includes the capability for designing an effective data and analytics architecture?
- Which phase of the AWS CAF cloud adoption journey is focused on demonstrating how the cloud accelerates business outcomes?
- Which pillar of the AWS Well-Architected Framework emphasizes efficient and organized allocation of compute resources?
- Which pillar of the AWS Well-Architected Framework emphasizes the ability to automatically recover from service interruptions?
- Which pillar of the AWS Well-Architected Framework supports making frequent, small, and reversible changes to your cloud environment?
- Which pillar of the AWS Well‑Architected Framework addresses a system’s ability to recover from failures and to automatically acquire resources to meet demand?
- Which programming languages are supported by the AWS Cloud Development Kit (AWS CDK)? (Choose two.)
- Which responsibilities are handled by AWS under the shared responsibility model? (Choose two.)
- Which service should a company use to centrally manage employee access across multiple AWS accounts?
- Which services can be used to block network traffic to an EC2 instance? (Choose two.)
- Which software development framework lets you define cloud resources in code and deploy them using AWS CloudFormation?
- Which statement best explains how the AWS Cloud helps organizations increase agility in their processes and infrastructure?
- Which statement correctly describes a core capability of Amazon S3?
- Which statement correctly describes the AWS account root user?
- Which statements correctly describe relationships among parts of the AWS global infrastructure? (Choose two.)
- Which statements describe how the AWS Cloud supports cost savings? (Choose two.)
- Which tool allows a developer to incorporate AWS service features directly into application code?
- Which two items describe elasticity in the AWS Cloud? (Choose two.)
- Which two of the following are AWS best-practice recommendations for using AWS Identity and Access Management (IAM)? (Choose two.)
- Which two statements describe the meaning of agility in AWS cloud computing? (Choose two.)
- Which type of credential provides a user with programmatic access to AWS through the AWS CLI or AWS APIs?
- Which VPC component provides a virtual firewall that controls traffic at the Amazon EC2 instance level?
- Which Well-Architected concept describes a system’s ability to remain functional when it encounters operational issues?
- While migrating to AWS, a company wants to detect security misconfigurations or unusual behavior and prioritize protective controls. Which AWS CAF security perspective capability addresses this need?
- Who can enable encryption for data at rest on Amazon Elastic Block Store (Amazon EBS)?
- Who can manage the access keys for the AWS account root user in an environment using AWS Identity and Access Management (IAM)?
- Who is responsible for managing encryption of Amazon Aurora database clusters and their snapshots according to the AWS shared responsibility model?
- Who is responsible for rotating IAM user access credentials and secret keys under the AWS shared responsibility model?
- Within the AWS Cloud Adoption Framework (AWS CAF), which perspective covers capabilities such as configuration management and patch management?
AWS Developer Associate DVA-C02 Certification All exam questions
- A .NET Core Lambda function needs to interact with DynamoDB and S3 while minimizing deployment package size and reducing invocation latency. Which approach meets these goals?
- A batch processing application uses API Gateway endpoints with deployment stages for dev, UAT, and prod. The development team needs each stage’s API to call different third-party service endpoints (one endpoint per stage). Which solution lets the team configure stage-specific endpoints?
- A BGP-based AWS VPN connects on-premises to a VPC. The developer can reach an EC2 instance in subnet A but cannot reach one in subnet B within the same VPC. Which logs will show whether traffic is reaching subnet B?
- A build pipeline publishes artifacts to an AWS CodeArtifact repository. The developer needs to cache dependencies from Maven Central (a public registry) with minimal changes to the existing pipeline. Which approach satisfies this requirement?
- A CI/CD pipeline builds container images, pushes them to Amazon ECR, and then deploys to an EKS development namespace for dynamic testing. The team wants to add an image analysis stage earlier in the pipeline to scan images before deploying to EKS. Which solution provides the most operational efficiency?
- A CI/CD pipeline uses AWS CodeArtifact and AWS CodeBuild. Build artifacts are 0.5–1.5 GB, builds run often, and each build downloads many dependencies from CodeArtifact, slowing the builds. How can the developer reduce the number of dependencies downloaded for each build to improve performance?
- A CloudFormation stack creates resources and also defines parameters in Systems Manager Parameter Store that the application reads and updates at runtime. When the developer updated the stack to add tagged resources, the Parameter Store values were reset, overwriting changes the application had made. The developer wants to change the deployment so parameter values are not reset by stack updates and to minimize development effort. What should the developer do?
- A CloudFormation template deploys VPC and EC2 security groups. A manager discovers some engineers changed security group settings on a few EC2 instances for testing. A developer must determine what changes were made. Which method will identify the modifications?
- A CloudFormation template must include an existing Amazon RDS hostname that is stored as a plaintext parameter in AWS Systems Manager Parameter Store. How should the developer reference that Parameter Store value inside the CloudFormation template?
- A CloudFormation template refers to subnets that another CloudFormation template (owned by the networking team) created. The developer's stack fails on first launch. Which template mistakes could cause this failure? (Choose two.)
- A CloudFront distribution uses an origin access identity (OAI) to access a private S3 bucket. The bucket denies access to everyone else. The app requires users to view a public login page, then receive signed cookies to access private directories. The distribution uses the default cache behavior with restricted viewer access pointed at the S3 origin. Accessing the login page returns a 403 Forbidden. How can the developer allow unauthenticated access to the login page while keeping private content secure?
- A CloudWatch Logs log group (created 2 months ago) must have future log data encrypted with a customer-managed AWS KMS key to meet a security requirement. Which option meets this need with the least effort?
- A CodeBuild stage in a deployment pipeline needs database credentials to run integration tests. Company policy mandates automatic rotation of all database credentials. Which method securely supplies rotating credentials to the build with the least operational overhead?
- A CodeDeploy deployment failed with the error: “HEALTH-CONSTRAINTS — The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.” Which two issues could cause this failure? (Choose two.)
- A CodePipeline pipeline builds a Java application. A new dependency in a .jar file must trigger a pipeline build when a new version is available. Which solution meets this requirement?
- A CodePipeline pipeline triggers from changes to the main branch in CodeCommit, uses CodeBuild for build/test stages, and uses CodeDeploy for deployment. After a recent source change, CodeDeploy did not deploy the updated application. Which two explanations are possible? (Choose two.)
- A company automates bootstrapping of new EC2 instances using CloudFormation templates that run scripts containing sensitive values. The solution must integrate with CloudFormation and securely manage those secrets. Which option provides the most secure integration with CloudFormation?
- A company built an application where Amazon API Gateway invokes AWS Lambda functions, and those Lambda functions process data and save it to Amazon DynamoDB. The company needs to monitor the full application to find potential architectural bottlenecks that could harm customers. Which approach delivers this capability with the LEAST development effort?
- A company caches session data in a DynamoDB table and wants an automated way to remove expired session items. What is the simplest way to automatically delete old items?
- A company deployed an application on AWS Elastic Beanstalk and set the environment's Auto Scaling group desired capacity to five EC2 instances. If capacity drops below four instances during deployments, application performance degrades. The environment uses the all-at-once deployment policy. What is the MOST cost-effective change to prevent the performance problem during deployments?
- A company deploys a B2B service to dedicated infrastructure in each customer account. Before releasing a feature, the team must run integration tests on real test infrastructure (EC2 instances and an RDS database) across multiple AWS accounts. You need a continuous delivery process that provisions the test infrastructure in those accounts and then runs the integration tests with the LEAST administrative effort. Which solution meets this requirement?
- A company deploys the same CloudFormation template to separate stacks for each environment. The developer must notify the QA team when new deployments occur in the final preproduction environment. What is the best way to provide those notifications?
- A company enables S3 Versioning and finds multiple versions of the same object because an on-premises application updates objects several times per day. The company wants the bucket to retain only the current version and the one immediately prior. Which solution accomplishes this?
- A company exposes a REST API through Amazon API Gateway that invokes a single Lambda function. The function is invoked infrequently by multiple concurrent clients. The code is optimized, but the company wants to reduce the function’s startup (cold-start) time. What should a developer do?
- A company exposes read access to objects in an S3 bucket for various customers, using IAM permissions so each customer can only access their files. A regulation mandates enforcing encryption in transit for S3 interactions. Which change enforces encryption in transit for the bucket?
- A company has a mobile app that calls API Gateway, which invokes Lambda functions. They want to test new Lambda function features with a subset of users before full deployment, without affecting other users and with minimal operational effort. What is the simplest way to do this?
- A company has hundreds of Lambda functions and the QA team must invoke them through Lambda function URLs. The QA team is in an IAM group. A developer needs to configure authentication so the QA group can call the public function URLs. Which solution satisfies this requirement?
- A company has multiple branch offices that each upload a daily sales report to a shared Amazon S3 bucket at a set time. A single AWS Lambda function processes all branch reports in one run and writes results to a database. The processing must start once per day at a specific time. Which option meets these requirements most cost-effectively?
- A company hosts a client-side web app in an S3 bucket and serves it via CloudFront at https://www.example.com. The developer consolidates common JavaScript and web font files into a central S3 bucket for reuse by multiple subsidiary sites, but browsers block those shared JS and font files during testing. What should the developer do so browsers will allow the shared JavaScript files and web fonts to be used by the other web applications?
- A company hosts a custom application on on-premises Linux servers and exposes it through Amazon API Gateway. X-Ray tracing is enabled on the API test stage. What is the simplest way to enable AWS X-Ray tracing from the on-premises servers with the least configuration?
- A company hosts a static website on Amazon S3 and provides APIs via Amazon API Gateway that invoke Lambda functions. During spikes in traffic, users report intermittent slowness (no failed requests). A developer needs to identify slow executions across all Lambda functions. Which approach meets this need?
- A company installed smart meters at customer sites that record power usage every minute and send readings to a remote endpoint. The company needs an endpoint to receive readings and store them in a database. They must record location ID and timestamp and offer customers low-latency access to current and historical usage on demand. Demand will grow substantially and the solution should scale without downtime and be cost-effective. Which storage solution best meets these requirements?
- A company is building a web application on AWS. When a customer requests a report, the application will generate the report and make it available to the customer within one hour. Reports should remain accessible for 8 hours. Some reports exceed 1 MB. Each report is unique to the requesting customer. The application must delete reports older than 2 days. Which approach provides the required behavior with the LEAST operational overhead?
- A company is building serverless apps with Lambda. They need a set of test events to exercise Lambda functions in a development environment. The events are created once and must be used and editable by all developers in an IAM group. Which solution satisfies these needs?
- A company is converting an application backend from EC2 to serverless. The app and an RDS for MySQL instance run in a single VPC, both deployed in private subnets. The company needs Lambda functions to connect to the DB instance. Which approach meets the requirement?
- A company is deploying a compute-heavy application on a fleet of Amazon EC2 instances. The application stores data on attached Amazon EBS volumes created at deployment time. The application processes sensitive data, and all stored data must be encrypted without affecting application performance. Which solution satisfies these requirements?
- A company is deploying a serverless application that uses Amazon API Gateway and Lambda to development, test, and production environments. Which option requires the least development effort to support multiple environments?
- A company is launching a photo-sharing app on AWS. Users upload images to an S3 bucket. A Lambda function generates thumbnails and stores them in another S3 bucket. During development the Lambda function sometimes takes more than 2 minutes to generate thumbnails, but the company requires each image to be processed in under 30 seconds. What change should the developer make to meet this requirement?
- A company is migrating a noncritical application to a single EC2 instance. The application will read and write objects in Amazon S3. Following AWS security best practices, which method should the company use to grant the application access to S3?
- A company is migrating a PostgreSQL database to AWS and wants database credentials that are stored securely and automatically rotated, with no additional application code changes. Which option meets these requirements?
- A company is migrating legacy internal applications to AWS and is redesigning its internal employee directory with native AWS services. You must store employee contact details plus high-resolution photos and allow searching and retrieval of each employee's details and photos via AWS APIs. Which design accomplishes this?
- A company is moving an on-premises database to Amazon RDS for MySQL. The workload is read-heavy and the company wants to refactor the application for optimal read performance. Which option achieves the best read scaling with the LEAST current and future effort?
- A company keeps trial signup records in a DynamoDB table and tracks trial data in a spreadsheet. They want the spreadsheet automatically updated whenever an individual trial starts, is updated, or ends. Which solution accomplishes this?
- A company launched a signup portal where users provide email addresses to get product updates. A developer built an AWS Lambda function (deployed with AWS SAM) that writes these emails to DynamoDB. The developer must expose the Lambda over HTTP as a REST endpoint with the LEAST extra configuration. Which of the following will meet this requirement? (Choose two.)
- A company manages infrastructure with AWS CloudFormation for dev, pre-prod, and production. To scale, a developer updates the RDS DB instance type in the pre-production CloudFormation stack. After deploying the update, the stack enters an UPDATE_ROLLBACK_FAILED state. What is the most likely cause?
- A company moved secure files into a private S3 bucket with no public access and wants a serverless app that lets employees sign in and securely share files with others. Which AWS feature should they use to provide secure, shareable access to those files?
- A company must ingest large volumes of data from many sources, apply multiple business-rule transformations in sequence, support reprocessing when errors occur, be scalable, and require minimal maintenance. Which AWS service should be used to orchestrate and automate these data flows?
- A company needs a low-cost, simple, and secure way to distribute firmware downloads to customers worldwide, with control over who can access the downloads. Which solution fits this requirement?
- A company needs to programmatically manage an API key to call a third-party HTTP API from its application. Integration with the application code must not negatively affect performance. Which option stores and provides the API key MOST securely?
- A company needs to provide secure, encrypted-at-rest database credentials with scheduled rotation for its AWS-hosted databases (Amazon RDS, Amazon DocumentDB, and Amazon Aurora). Which solution meets these security and rotation requirements most securely?
- A company needs to share reference documents stored in an S3 bucket it owns with external workshop attendees for 7 days. What is the most secure way to share those documents for that period?
- A company plans to send promotional notifications using Amazon SNS FIFO topics. They need to measure the publish rate and the latency of these topics. Which approach gives the required telemetry with the least operational overhead?
- A company publishes new AWS Lambda function versions regularly and uses aliases for production. They want to roll out a new version to a fixed percentage of production traffic initially (traffic shifting) to improve releases. Which configuration achieves this behavior?
- A company receives orders from multiple partners via API Gateway that invoke a shared Lambda function. After processing each partner's orders, the partner needs to be notified only about its own orders. The company plans to add partners over time with minimal code changes. Which approach is the most scalable?
- A company requires that all Amazon RDS instances be provisioned from AWS CloudFormation templates as part of an AWS CodePipeline CI/CD workflow. The database master password must be generated automatically during deployment. Which solution accomplishes this with the least development effort?
- A company requires that all cloud resources be deployed with CloudFormation and wants immediate notifications to the security team if an IAM role is created outside CloudFormation. An SNS topic exists with the security team's email subscribed. Which solution will send immediate notifications when a role is created without CloudFormation?
- A company runs a critical application on Amazon ECS using EC2 instances and plans to migrate it to ECS on AWS Fargate. A developer is configuring Fargate and ECS capacity providers to minimize downtime during migration. Which configuration will accomplish this with the least downtime?
- A company runs a critical application where API Gateway exposes an HTTP API integrated with a Lambda function. The application stores data in an RDS for MySQL instance (2 vCPUs, 64 GB RAM). During unpredictable peak periods some API calls return HTTP 500 errors. CloudWatch Logs show “too many connections.” The database must remain available except during scheduled maintenance. How can the company make the application resilient to connection spikes?
- A company runs a payment application on Amazon EC2 instances behind an Application Load Balancer. The EC2 instances are in an Auto Scaling group across multiple Availability Zones. The application must retrieve secrets at startup and export them as environment variables. Secrets must be encrypted at rest and rotated monthly. Which solution meets these requirements with the least development effort?
- A company runs a serverless backend (API Gateway, Lambda, DynamoDB) for a VR game and has seen a sudden global increase in new users. The company observes delays retrieving user data. Which AWS service or feature will reduce database response times to microseconds?
- A company runs an application on EC2 instances that connect to an Amazon RDS for SQL Server database. A developer needs to store and access the database credentials, enable automatic rotation, and avoid embedding credentials in code. Which is the MOST secure solution?
- A company runs containerized image-processing applications on on-premises Kubernetes clusters that share a single NFS file store. The NFS capacity is exhausted and the company must migrate to AWS quickly. The Kubernetes clusters on AWS must be highly available. Which combination of steps will satisfy these requirements? (Choose two.)
- A company runs EC2 instances in multiple AWS accounts and wants a single SQS queue in the primary account to collect all EC2 instance lifecycle events from every account. Which design accomplishes this?
- A company runs its learning management system on EC2 instances behind an Application Load Balancer (ALB) in a single AWS Region. The domain is managed in Route 53. The company wants to improve performance for global users with the least operational overhead. Which solution will improve global performance with minimal operational effort?
- A company runs web apps on EC2 using AWS Elastic Beanstalk. A developer must change configuration so that new settings apply only to newly launched instances. Which deployment types meet this requirement? (Choose two.)
- A company stores premium content in an S3 bucket and wants only paying subscribers of its website to be able to download those files. The bucket and objects are currently private. How can the company restrict download access for a given premium file to paid subscribers only?
- A company stores sales data in a DynamoDB table with DynamoDB Streams enabled. Each item has a TransactionStatus attribute with values failed, pending, or completed. The company wants to be notified for failed sales where Price exceeds a threshold. What approach requires the least development effort to set up this notification?
- A company stores sensitive credentials for applications in development, staging, pre-production, and production. Credentials must be encrypted, automatically rotated, and each environment must have its own version of the credentials. What is the most operationally efficient solution?
- A company stores tabular data in multiple S3 buckets. They received an alert that customer credit card data may have been exposed in a data table on a public application. A developer needs to find all possible exposures in the application environment. Which solution will identify these exposures?
- A company streams application logs to CloudWatch Logs. The development team must get an email when any log line contains the word "ERROR." The developer created an SNS topic and subscribed the team. What should the developer do next to send email notifications when "ERROR" appears in logs?
- A company uses a central AWS CDK application across multiple accounts to manage deployment stacks. A developer needs to automate detection and deletion of unused resources that supported previous stacks but are no longer needed. The solution must integrate smoothly with the existing CDK-based deployment flow and require the least configuration. Which approach satisfies these requirements?
- A company uses a custom root certificate authority (Root CA) chain (10 KB) to issue SSL certificates for on-premises HTTPS endpoints. Hundreds of AWS Lambda functions pull data from these endpoints. A developer initially bundled the Root CA certificate file inside each Lambda deployment package and updated the execution environment trust store when the environment initializes. After 3 months the Root CA has changed and must be updated. The developer needs a solution that lets the Root CA certificate be updated for all deployed Lambda functions without rebuilding or redeploying each function, across separate AWS accounts for dev, test, and prod. Which two steps together meet these requirements most cost-effectively? (Choose two.)
- A company uses a single AWS account (no Organizations) and has a CodePipeline that must test CloudFormation templates in the primary Region and a disaster-recovery (DR) Region. What solution provides the most operational efficiency?
- A company uses Amazon Cognito user pools for authentication and has enabled multi-factor authentication (MFA). The company wants to send an email alert each time a user successfully logs in. What is the MOST operationally efficient way to implement this requirement?
- A company uses Amazon RDS as its application database. After a campaign, read traffic surged and increased latency. The company needs a caching layer that is encrypted and highly available. Which caching solution meets these requirements?
- A company uses an API Gateway REST endpoint as a webhook so an on-premises SCM system can publish events to EventBridge in a central AWS account. An EventBridge rule in the central account handles deployments. The company also needs the same events to be available in multiple receiver AWS accounts, without changing the SCM webhook configuration. How can a developer accomplish this?
- A company uses an AWS Lambda function to transfer files from an Amazon S3 bucket to the company's SFTP server. The Lambda function connects to the SFTP server using a username and password stored in Lambda environment variables. A developer must store these credentials in encrypted form. Which solution satisfies this requirement?
- A company uses API Gateway to invoke a Lambda function. There are separate Lambda versions for PROD and DEV, and each has an alias pointing to its version. API Gateway has one stage pointing to the PROD alias. The company wants API Gateway to expose both PROD and DEV Lambda versions simultaneously and distinctly. Which approach satisfies this requirement?
- A company uses API Gateway with the built-in API key validation. A new registration page calls CreateApiKey to provision an API key and returns it to the user. When a new user tries to call the API with that key, they get 403 Forbidden. Existing users are unaffected. What additional API call or update must the registration code perform so the new user can use the API?
- A company uses AWS CloudFormation to deploy resources and needs to update an existing stack. What should the company examine to understand how the proposed changes will affect currently running resources?
- A company wants its employees to sign in to the AWS Management Console using their existing credentials stored in an on-premises Microsoft Active Directory. Each employee must get permissions to EC2, S3, and Lambda based on their role. Which solution provides this with the LEAST operational overhead?
- A company wants to host and manage static websites in AWS. The site source code is stored in various version control systems (AWS CodeCommit, Bitbucket, GitHub). The company requires phased deployments (development, staging, UAT, production) triggered by merges to corresponding branches, uses HTTPS for all traffic, and prefers a solution that does not require continuously running servers. Which option provides the required functionality with the LEAST operational overhead?
- A company wants to test a new feature in existing software with a small subset of users while the current version stays deployed. If testing succeeds, the company will roll out the new version to all other users simultaneously. Which deployment strategy fits this need?
- A company will store one application form submission per user in a DynamoDB table. Each item includes username, submission date, validation status (UNVALIDATED, VALID, NOT VALID), and a rating from 1 to 5. To ensure records are well distributed across partitions during a surge of submissions, which attribute should be used as the partition key?
- A containerized application needs to call a third-party service using API keys. The developer needs a secure method to store the keys and provide them to the containers. Which of the following are appropriate? (Choose two.)
- A data-collection app uses API Gateway, Lambda, and S3. Users upload files and then wait while a long validation runs; they must refresh the dashboard to see results. Some users upload many large files and repeatedly refresh. The developer must change the app so the dashboard receives immediate validation results for a file without reloading the whole page. Which solution is the most operationally efficient?
- A deployed Lambda function is CPU-bound and needs faster response times. Which change will most improve the function's performance?
- A deployment via AWS CodeDeploy to EC2 instances is failing during tests. CloudWatch logs show an IAM_ROLE_PERMISSIONS error. What should you do to fix this permission error for the CodeDeploy service role?
- A developer added a CloudWatch Logs metric filter to count exceptions in application logs, but no metric data appears. Why might no filtered results be returned?
- A developer authored an AWS Serverless Application Model (AWS SAM) template that defines several Lambda functions, an S3 bucket, and a CloudFront distribution. One Lambda function is intended to run at the CloudFront edge (Lambda@Edge), and the S3 bucket is an origin for the distribution. Deploying the SAM stack into eu-west-1 fails. What is a likely cause of the failure?
- A developer built a game that stores player data in an Amazon DynamoDB table where the partition key is the player's country. After a sudden surge of players from one country, the application starts throwing ProvisionedThroughputExceededException errors. What should the developer do to address these errors?
- A developer built a Lambda function to process .csv files placed into an S3 bucket. Which combination of steps will trigger the Lambda function whenever a .csv file is uploaded to the bucket? (Choose two.)
- A developer built a microservice that uses AWS Lambda to process messages from an Amazon SQS standard queue. The Lambda function enriches each SQS message by calling external APIs and then writes the data to an Amazon Redshift table. The queue must support up to 1,000 messages per second. During testing, duplicate rows were repeatedly inserted into the Redshift table because duplicate SQS messages were processed; all duplicate messages were enqueued within 1 minute of each other. How should the developer fix this problem?
- A developer built a serverless application that uses API Gateway, Lambda functions, and Route 53. During testing the developer sees errors but cannot immediately find the root cause. To search across all application logs with the least operational overhead, what should the developer do?
- A developer built a serverless application with AWS SAM that includes AWS Lambda functions. What is the correct order of steps to deploy the application successfully?
- A developer created a Lambda function that runs on a schedule to list all S3 buckets in an account and store that list in a DynamoDB table. When running the function with the AWSLambdaBasicExecutionRole managed policy, the function fails with a permissions error. Which combination of permissions will fix the error? (Choose two.)
- A developer created a Lambda function that sends an Amazon SNS notification when an S3 object larger than 50 MB is uploaded. The function was tested via the CLI and worked. After adding an S3 event notification to the bucket, uploading a 3,000 MB file does not trigger the Lambda. Which of the following could explain why the Lambda function is not being invoked?
- A developer created an AWS Lambda function that calls multiple AWS services and observed that the function's execution time is higher than expected. The developer must investigate interactions between the services without modifying the function's code. Which approach meets this requirement?
- A developer deployed a new version of an AWS Lambda function. To validate it, the developer must route 50% of traffic to the new version and 60% of traffic to the current version. What is the MOST operationally efficient way to accomplish this?
- A developer deployed a web application with an Amazon API Gateway REST API using a CloudFormation template that included RestApi, Resource, Method, Stage, and Deployment resources. After adding a new resource and methods, the stack update completed successfully, but calls to the new methods return 404 Not Found. What should the developer add to the CI/CD pipeline so the newly added methods become available after deployment?
- A developer deploys an application on EC2 instances in Account A. The application must read from an existing Amazon Kinesis data stream in Account B. Which actions are needed to grant the application access to the stream? (Choose two.)
- A developer enables versioning on an S3 bucket where each object can have multiple versions. Objects must be permanently removed one year after creation. What should the developer configure next to meet this retention policy?
- A developer exposes a Lambda function through Amazon API Gateway. During testing, API Gateway reports timeouts even though the Lambda function completes within its configured timeout. Which CloudWatch metrics for API Gateway should the developer examine to diagnose the problem? (Choose two.)
- A developer exposes a web API via an internet-facing Application Load Balancer (ALB) using an HTTPS listener and has configured an Amazon Cognito user pool. The developer wants to ensure every request to the API is authenticated through Cognito. What should be done?
- A developer has a legacy on-premises application that other AWS-hosted apps depend on. The developer wants to monitor and troubleshoot all applications from a single place using Amazon CloudWatch. How can the developer send logs from the on-premises server to CloudWatch?
- A developer has a single pre-production AWS account that runs an AWS SAM CloudFormation stack. They edited a Lambda function and added SNS topics and want to do a one-time deploy of these changes for testing without impacting the existing pre-production application used by the release pipeline. What should the developer do?
- A developer has built a REST API using Amazon API Gateway and AWS Lambda and wants to enable local testing of the API using the AWS SAM CLI. Which AWS SAM CLI subcommand allows running the API locally for testing?
- A developer has deployed CDK stacks (including Lambda assets) to an alpha environment in Account A using cdk deploy. Deploying the same stacks for the first time in a second account (beta) fails with a NoSuchBucket error. Which CDK CLI command should be run in the beta account before redeploying to fix this issue?
- A developer has fixed a bug in a production AWS Lambda function and validated the change in a test environment. The developer wants to roll the update out gradually in production so that initially only 10% of users see the new code. What is the appropriate approach?
- A developer hosts a static website in an S3 bucket served through CloudFront using origin access control (OAC) so the bucket is not public. Users can access explicit file URLs (for example, /products/index.html) but receive an error when requesting directory URLs (for example, /products/). Without making the S3 bucket public, how can directory requests be served so they return the default index file?
- A developer hosts a static website on Amazon S3 and serves it through CloudFront using a custom domain. A CI/CD pipeline (triggered by CodeCommit) runs a build stage that executes a CodeBuild project referencing a buildspec.yml. The build uploads updated static files to the S3 bucket and the updates are visible at the S3 website URL, but the CloudFront distribution still serves the old content. What should the buildspec.yml do to ensure CloudFront serves the updated files?
- A developer hosts a static, public website in an S3 bucket and delivers it through CloudFront. The requirement is that users must not be able to retrieve content directly from the S3 bucket — all access must go through the CloudFront distribution. Which solution enforces this requirement?
- A developer initialized a new AWS CDK project in CodeCommit and must (1) write unit tests for the generated IaC templates and (2) run a validation across all CDK constructs to ensure key security configurations are enforced. Which combination of actions provides these checks with the least development overhead? (Choose two.)
- A developer initializes the AWS SDK outside of an AWS Lambda handler function (for example, as a global variable). What is the PRIMARY advantage of doing this?
- A developer integrates an ecommerce platform with multiple third-party payment APIs, but those providers offer no test environment. The developer needs to validate integration logic without calling the real third-party APIs. Which solution meets this need?
- A developer is adding AWS X-Ray to an application that handles personally identifiable information (PII). The app runs on EC2 instances. Trace messages include encrypted PII and are sent to Amazon CloudWatch. The developer must ensure that no PII leaves the EC2 instances. Which solution meets this requirement?
- A developer is analyzing HTTP access logs on EC2 instances that are behind a public Application Load Balancer (ALB). The server logs show only the ALB's IP address rather than the client's public IP. What must the developer change so the HTTP server log contains the originating client's public IP address?
- A developer is building a batch application that will run on an Amazon EC2 instance and needs read access to an Amazon S3 bucket. To follow security best practices, how should the developer grant S3 read access to the application running on the EC2 instance?
- A developer is building a global video search app. Each video file averages 2.5 TB. Files must be available with instant access for the first 90 days; after 90 days, retrieval times of over 10 minutes are acceptable. Which solution meets these requirements most cost-effectively?
- A developer is building a highly secure, serverless healthcare application. The application needs to write temporary data to the /tmp directory of an AWS Lambda function. Which approach should the developer use to encrypt that temporary data?
- A developer is building a Lambda function that reads from an Amazon DynamoDB table. The table name is currently hard-coded in the function, but the table name may change in the future. The developer wants to avoid modifying the Lambda code when the table name changes. Which solution is the MOST efficient?
- A developer is building a mobile app that displays images stored in an S3 bucket. Users must be able to sign in with their Amazon account and with supported social media accounts. Which solution provides this authentication capability?
- A developer is building a proof-of-concept to validate a container-based deployment approach for a company's first AWS environment. To deploy the containerized app with the least operational effort, which steps should the developer take? (Choose two.)
- A developer is building a Ruby application and needs a service that automates deployment, scaling, and environment management without requiring knowledge of the underlying infrastructure. Which AWS service best fits this requirement?
- A developer is building a serverless application on AWS and wants a faster development workflow that deploys only incremental changes for testing instead of redeploying the entire application on every commit. What should the developer use to meet this requirement?
- A developer is building a serverless application with the AWS CDK that provisions multiple Lambda functions and API Gateway APIs during CloudFormation stack creation. On the developer workstation, both AWS SAM and AWS CDK are installed. How can the developer run a specific Lambda function locally for testing?
- A developer is building an application that runs on EC2 instances in an Auto Scaling group and needs to externalize session state so instances can be stateless. Which AWS services could be used to store session state? (Choose two.)
- A developer is building authentication for a new mobile app. Users must be able to sign up, sign in, and access protected backend AWS resources. Which solution satisfies these requirements?
- A developer is configuring AWS CodePipeline for a project. During each build step, the pipeline must generate a test report. Which solution meets this requirement?
- A developer is configuring AWS CodePipeline for deployment. The source code is in a GitHub repo and the pipeline's source stage is already set to that repo and branch. The developer wants the repository package's unit tests to run in the pipeline environment. Which steps will achieve this with the LEAST overhead? (Choose two.)
- A developer is creating a CloudFormation custom resource backed by a Lambda function to configure an Amazon OpenSearch Service domain. The Lambda must use the OpenSearch internal master user credentials to access the domain. What is the most secure way to provide these credentials to the Lambda function?
- A developer is creating a DynamoDB table with the AWS CLI. The table must use server-side encryption with an AWS owned encryption key. How should the developer create the table to satisfy this requirement?
- A developer is creating a three-tier web application that must handle at least 5,000 requests per minute. The web tier must remain fully stateless, but user session state must be preserved. Which approach externalizes session data while keeping latency as low as possible?
- A developer is debugging an application that uses Amazon DynamoDB (us-west-2). The app runs on an Amazon EC2 instance and needs read-only access to a table named Cars. The EC2 instance has an IAM role with a policy attached, but when the app attempts to read the Cars table it gets Access Denied. How should the developer fix this issue?
- A developer is debugging an application that uses several Lambda functions which call an API exposed by API Gateway. The API Gateway method uses an Amazon Cognito authorizer. The Lambda functions include the user ID in the Authorization header when calling the API. All GET requests to the API return HTTP 403. How can the developer fix this?
- A developer is deploying an existing Lambda function whose deployment package and dependencies are stored in Amazon S3 using an AWS CloudFormation template. The CloudFormation template defines an AWS::Lambda::Function resource. What is the minimal-effort way to reference the function code stored in S3 within the template?
- A developer is deploying containers on an ECS cluster using Fargate with an Ubuntu-based image. The application needs shared persistent data accessible by multiple ECS tasks and remaining available after containers stop. Which solution meets these requirements?
- A developer is deploying updated Lambda code that tracks user online activity. The web application invokes the Lambda via the AWS SDK. The developer wants only a small percentage of SDK-invoked requests to call the new code while most continue to call the original code. Which approach satisfies this requirement?
- A developer is implementing AWS Signature Version 4 signed requests and has already built the canonical request, created the string to sign, and computed the signing key. Which approaches can the developer use to attach the signature to the HTTP request? (Choose two.)
- A developer is intermittently receiving HTTP 400 ThrottlingException errors when calling the CloudWatch API and no data is returned on failure. What best practice should be applied first to mitigate this?
- A developer is investigating why users receive duplicate emails. The application posts messages to an SQS queue; a Lambda function polls the queue and sends email through Amazon SES. During high traffic, duplicates occur. Which of the following could cause the duplicate emails? (Choose two.)
- A developer is migrating features from a legacy monolith to AWS Lambda. The application data resides in an Amazon Aurora DB cluster in private subnets of a VPC. The account has one VPC; the Lambda functions and the DB cluster are in the same AWS Region and account. The Lambda functions must access the DB cluster securely without traversing the public internet. Which configuration satisfies this requirement?
- A developer is monitoring an application on an EC2 instance and has created a custom CloudWatch metric with 1-second granularity. The developer must receive an Amazon SNS notification within 30 seconds if a problem occurs. What should the developer do to meet this requirement?
- A developer is preparing an Amazon API Gateway API (with a Lambda backend) so frontend teams can start building the UI before the backend is implemented. The frontend team needs endpoints that return predefined HTTP status codes and JSON bodies. The developer created a method for an API resource. Which approach fulfills these requirements?
- A developer is scripting an automated deployment for a serverless app and wants to use an existing AWS Serverless Application Model (SAM) template. Which of the following should the developer use? (Choose two.)
- A developer is using AWS SAM to build a serverless app and currently tests in a development environment. They need to add testing and staging environments for QA and want to use an AWS SAM feature that supports deploying to multiple named environments with minimal effort. Which approach is the least development-intensive?
- A developer manages an Amazon API Gateway REST API used by customers via a frontend UI with Amazon Cognito authentication. The developer has a new API version that introduces new endpoints and includes breaking interface changes. The developer needs to give other team developers beta access to the new API without impacting existing customers. Which approach accomplishes this with the LEAST operational overhead?
- A developer manages many secrets in AWS Secrets Manager used by several applications. Over time some secrets are rotated or no longer used. The developer needs to determine which Secrets Manager secrets are currently used by applications without causing downtime. What approach should the developer take?
- A developer manages three AWS accounts, each with an Amazon RDS instance in a private subnet. The developer needs to create and later update database users consistently across all three accounts with minimal operational effort. Which approach provides the most operational efficiency?
- A developer migrated an application to Amazon EKS and moved images to Amazon ECR. They created a new AWS account and updated the application configuration to point to new backend resources. The pipeline build and deployment succeeded, but the running application is still connecting to the old backend. Investigation shows the application configuration still references the original EKS cluster. Which reason explains why the application did not connect to the new resources?
- A developer must build a cost-effective proof-of-concept REST endpoint that returns the weather forecast for a company office. The solution should use AWS caching where possible and will only receive light traffic during testing. Which implementation is the most cost-effective?
- A developer must create an API Gateway endpoint at /auth to test JWT authorization using API Gateway's built-in authorizer (no custom authorizer code). Which configuration satisfies this requirement?
- A developer must deploy the same Elastic Beanstalk application (using an Application Load Balancer) in three AWS Regions via CloudFormation, and use AWS Certificate Manager (ACM) to supply SSL certificates for each ALB. What is the correct way to provide certificates for each ALB?
- A developer must diagnose performance problems in production for distributed applications implemented with AWS Lambda functions that invoke other components. What is the best way to identify and troubleshoot the root cause in production?
- A developer must encrypt files locally (outside AWS) using symmetric encryption inside the application before uploading them to an Amazon S3 bucket. Which approach satisfies these requirements?
- A developer must migrate on-premises data to S3 using AWS KMS for encryption, and the encryption keys must support automatic annual rotation. Which type of KMS key should be used to satisfy these requirements?
- A developer must provide a custom machine-learning library (currently 15 GB and growing) to all AWS Lambda functions in an application. Which approach satisfies this requirement so every Lambda function can access the library?
- A developer must run geographic load tests for an API across multiple AWS Regions and wants to deploy the required resources in each Region without changing the application code. Which approach meets this requirement?
- A developer must store application configuration values that expire at a certain date and time and receive notifications before they expire. Which approach provides this functionality with the least operational overhead?
- A developer must store customer orders in DynamoDB and the company requires that all data at rest be encrypted using a key generated and managed by the company. What should the developer do to satisfy this requirement?
- A developer must test and debug an application locally. The application's deployment package is stored in Amazon S3. Which approach lets the developer run the code locally with the least setup?
- A developer must transfer expired items from a DynamoDB table to Amazon S3. The table uses TTL to expire items. The application must process each expired item and then store it in S3; processing plus storage takes 5 minutes per item. Which solution accomplishes this with the least operational overhead?
- A developer must use a reusable template to automate deployment of an application onto Amazon EC2 instances. The solution must support repeated deployments, installation and updates of application resources, produce identical environments, and allow rollbacks to previous versions. Which solution satisfies these requirements?
- A developer must use MFA to access data in an S3 bucket located in a different AWS account. Which AWS STS API operation should be called with the MFA information to meet this requirement?
- A developer needs a solution that builds code from an AWS CodeCommit repository, runs unit tests for every change, and provides detailed, accessible test reports. Company policy requires comprehensive unit testing and that test results be available. Which solution meets these requirements?
- A developer needs feature toggles to hide unreleased features in a web application until they're ready. Which solution meets this requirement for managing feature flags and toggling them on or off?
- A developer needs microsecond read latencies for frequently accessed product items, and the application cache must be updated whenever products are created, updated, or deleted to ensure consistency. Which solution satisfies these requirements?
- A developer needs temporary access to resources in a different AWS account. Which approach provides the most secure temporary access?
- A developer needs the database connection string for a Lambda function to be changeable without modifying the function code, to simplify testing and deployments. What is the best way to meet this requirement?
- A developer needs to expand an application to another AWS Region by copying AMIs and creating a new application stack. Company policy requires that all AMIs be encrypted in every Region, but some current AMIs are unencrypted. How can the developer expand to the destination Region while ensuring AMIs are encrypted?
- A developer needs to extract custom processing-time metrics from AWS Lambda logs, analyze them, create alarms, and detect issues in real time. Which approach satisfies these requirements?
- A developer needs to fetch several specific items from a DynamoDB table using a single API call while minimizing load on the database. Which DynamoDB API should be used?
- A developer needs to produce immediate test responses for an API built with Amazon API Gateway so other teams can begin testing right away. Which approach should the developer use to generate responses without requiring a backend implementation?
- A developer needs to update a Lambda function that processes user-uploaded photos and test the update by splitting user traffic between the current function and the new version. Which combination of steps accomplishes this? (Choose two.)
- A developer packaged a Lambda function as a .zip file and tried to upload it from the Lambda console Functions page, but the console returned an error indicating the package could not be uploaded. Which of the following methods can be used to publish the code? (Choose two.)
- A developer packaged a small application (requires minimal CPU and memory) as a container image. The app fetches data from an external API, processes it, and writes results to S3. The application must run once every hour in an existing Amazon ECS cluster. Which option minimizes infrastructure management overhead?
- A developer placed an RDS database in the private subnet of VPC-A. The developer also created a Lambda function in the default VPC that tries to connect to the RDS database but cannot. What is the appropriate way to allow the Lambda function to access the RDS instance?
- A developer ran the AWS CLI command aws dynamodb get-item --table-name demoman-table --key '{"id": {"N":"1993"}}' after configuring the CLI with a specific IAM user's credentials. The command returned errors and no item was returned. What is the most likely reason for the failure?
- A developer registered a Lambda function as a target for an Application Load Balancer (ALB) using the CLI, but the Lambda is not invoked when requests hit the ALB. Why is the Lambda not being called?
- A developer requires product-owner approval before deploying code to production. CodePipeline is used for deployment. An SNS topic is configured to notify the product owner. What is the MOST operationally efficient way for the developer to obtain approval from the product owner in this pipeline?
- A developer stores many objects in a single Amazon S3 bucket and needs to optimize the bucket for high request rates. How should the objects be organized to meet this requirement?
- A developer updated a custom application that runs on AWS Elastic Beanstalk. Which of the following methods will deploy the new application version to the Elastic Beanstalk environment after the changes are complete? (Choose two.)
- A developer updated a Lambda function used by an API Gateway backend for a web app and needs to test the updated function without affecting production users. Which approach is the MOST operationally efficient way to test the updated Lambda without impacting production traffic?
- A developer updated an AWS Lambda function to run inside a VPC private subnet so it can group data from public APIs. The VPC has an internet gateway attached and uses default network ACL and security group settings. After the change, the Lambda function can no longer reach the public APIs even though the APIs are reachable. How should the developer restore outbound internet access for the Lambda function?
- A developer used the AWS Copilot CLI during development to deploy a containerized application and committed the code to a new CodeCommit repository. The developer now needs an automated deployment pipeline for production with minimal operational effort. What is the most efficient way to create the automation?
- A developer uses AWS Amplify Hosting and wants to add end-to-end testing to reduce bugs before production. Where should the developer add E2E tests so they run during the Amplify build process?
- A developer uses AWS CloudFormation to deploy an Amazon API Gateway API and an AWS Step Functions state machine. The state machine must reference the API Gateway endpoint after the template deploys. Which cost-effective CloudFormation approach allows the state machine to reference the API endpoint?
- A developer uses AWS IAM Identity Center (AWS SSO) to access AWS via the CLI and SDKs from a local workstation. API calls worked initially but are now returning Access Denied, and no local configuration or scripts were changed. What is the most likely cause of the access failures?
- A developer uses AWS SAM for an application with API Gateway, Lambda, and DynamoDB. Currently when only Lambda code changes are pushed, the entire application artifacts are rebuilt. The developer wants to use AWS SAM Accelerate to redeploy only the changed Lambda functions by running a single command. Which command accomplishes this?
- A developer uses AWS Step Functions where each step invokes a Lambda function. The state machine fails in the GetResource task with either IllegalArgumentException or TooManyRequestsException. Requirement: when IllegalArgumentException occurs, the state machine should stop immediately. When TooManyRequestsException occurs, the state machine should retry the GetResource task one more time after a 10-second wait; if that retry fails, the state machine should stop. How can the developer implement the Lambda retry behavior without adding extra steps to the state machine?
- A developer uses S3 Event Notifications to invoke Lambda functions for image processing. In the same AWS account there is a development S3 bucket and Lambda, and a production S3 bucket and Lambda. Uploads to the development bucket are incorrectly invoking the production Lambda. The developer must prevent development uploads from affecting production with the least disruption. What should the developer do?
- A developer uses SSH keys to access AWS CodeCommit. The SSH keys are associated with a user who currently has a certain set of permissions. The developer needs to allow that user to create and delete branches. Which specific IAM permissions should be added to follow the principle of least privilege?
- A developer uses WebSocket APIs in Amazon API Gateway and wants to enforce access control via an API Gateway Lambda authorizer. The developer also wants credential caching to avoid sending secret keys or auth tokens on every request. Which combination of steps should be taken? (Choose two.)
- A developer wants the option to roll back to a previous Lambda version if a new deployment causes errors, while minimizing user impact. Which deployment pattern accomplishes this with the least user disruption?
- A developer wants to add request validation to an API in production but must test the validation before modifying the production deployment. Which approach minimizes operational overhead for testing the changes first?
- A developer wants to deploy a new application version to a test environment on AWS Elastic Beanstalk. Which deployment policy provides the fastest deployment time?
- A developer wants to log important events during a Lambda invocation and include a unique identifier for the specific invocation. Which approach satisfies this requirement?
- A developer wants to review server logs from a highly available Python web application running on multiple EC2 instances without SSHing into each instance. What change requires the LEAST modification to the application to centralize logs?
- A developer wants to share application source code with teammates for long-term storage, versioning, and grouped change tracking. Which AWS service is the appropriate choice?
- A developer wants to test optimized changes to a Lambda that backs a REST API in API Gateway by routing a small percentage of live traffic to the updated code without changing the API URL. Which steps accomplish this?
- A developer will author an AWS CloudFormation template locally and then deploy the CloudFormation stack to AWS. What is required on the developer’s machine to perform these tasks?
- A developer working in a feature branch did not pull recent changes from the main branch and now faces merge conflicts. What is the easiest way to resolve the conflicts with least development effort?
- A developer's application invokes Lambda functions asynchronously, but some events fail randomly. The developer needs to capture the specific events that failed for investigation. Which configuration will collect failed asynchronous events for later inspection?
- A developer's application uses an Amazon DynamoDB table with a local secondary index (LSI). During testing the table returns ProvisionedThroughputExceededException errors, even though the test suite's request rate did not exceed the table's overall provisioned capacity. What is the most likely cause?
- A developer's application uses an AWS Lambda function to process messages from an Amazon SQS queue. The Lambda function sometimes fails or times out, and the developer must capture and investigate the messages that could not be processed with the least operational overhead. Which approach satisfies this requirement?
- A developer’s application uses AWS Lambda and CloudFormation. As usage increased, Lambda functions began hitting rate limits when they fetch a Systems Manager Parameter Store advanced parameter on every invocation. The parameter only changes during deployments. Because usage is unpredictable, the developer wants a cost-effective way to avoid the Parameter Store rate limiting. Which solution best meets this requirement?
- A development team uses AWS CodeCommit across multiple AWS accounts and is growing to include remote developers. The company must provide secure access to the repositories for these developers while minimizing operational overhead. Which solution best meets this requirement?
- A development team wants code changes to trigger an immediate build and deployment. Which of the following approaches can be used to start an AWS CodePipeline when source code changes occur? (Choose two.)
- A DynamoDB table for product orders uses orderId as the partition key only (no sort key). The application needs to support queries by customerId. Which option enables querying the table by customerId?
- A DynamoDB table named orders has a primary partition key id and a global secondary index accountIndex with partition key accountId and sort key orderDateTime. A Lambda function must retrieve the orders for accountId = 100. Which DynamoDB API call will return those items using the least read capacity?
- A DynamoDB table publishes change events to a DynamoDB stream. A Lambda function processes those stream events. Sometimes incoming orders have an order quantity of 0. You need to build a dashboard that shows how many unique customers are affected by this problem each day. What should you implement?
- A DynamoDB table stores product reviews. Each item contains a Review ID (partition key), Product ID, User ID, Product Rating (1-5), and an optional comment. The most common query is: for a given Product ID, return the top 10 reviews with the highest ratings. Which index will give the fastest responses for this query?
- A DynamoDB table uses OrderID (partition key) and NumberOfItemsPurchased (sort key), both as Number types. Query results are currently returned sorted by NumberOfItemsPurchased in ascending order. The developer wants the query results sorted in descending order by NumberOfItemsPurchased. How can this be accomplished?
- A financial company must retain original customer records (which include PII) in Amazon S3 for 10 years. Only certain internal users may access PII; third parties must receive records with PII removed. A Lambda function named removePii can strip PII. How can the developer ensure a single stored object is returned either intact or with PII removed depending on the requester?
- A frontend developer needs to write integration tests that exercise both success and error HTTP responses from an API Gateway-backed serverless backend. The tests should cover positive and negative cases with minimal setup effort while the logic tier is still under development. Which approach requires the least development effort?
- A gaming company deploys a web portal using Elastic Beanstalk and sometimes releases updates three or four times per day. The company wants to deliver new features to all users quickly while minimizing user impact and maximizing availability. Which Elastic Beanstalk deployment policy best meets these goals?
- A gaming site needs to update and persist both players' records in a single transaction so that if any update fails the entire transaction rolls back. Which AWS services or features can provide the required transactional behavior? (Choose two.)
- A Kinesis Data Firehose delivery stream receives customer records that include personally identifiable information. The developer must remove customer identifier patterns before saving the data to an S3 bucket. What is the appropriate way to meet this requirement?
- A Kinesis Data Streams application stores clickstream data that may not be consumed for up to 12 hours. How can you enable encryption-at-rest for the data in the Kinesis stream?
- A Lambda function asynchronously creates short videos that can take up to 10 minutes. After creation, a download URL is sent to the user's browser and must remain valid for at least 3 hours. Which solution meets these requirements?
- A Lambda function calls a third-party API that enforces a requests-per-minute limit. If requests exceed that limit, the API returns rate-limit errors. How should the developer configure the Lambda function to avoid hitting the third-party rate limits?
- A Lambda function configured to run in a VPC must connect to an RDS for SQL Server instance in a private subnet on port 1433, but the function fails to connect. Which steps should you take to debug the connectivity issue? (Choose two.)
- A Lambda function consumes messages from an Amazon SQS queue that is configured with a dead-letter queue (DLQ). Some messages failed processing due to a bug that has since been fixed. The developer now wants to reprocess the failed messages. Which action should the developer take?
- A Lambda function consumes messages from an Amazon SQS standard queue but sometimes processes the same message multiple times. What is the most cost-effective way to stop duplicate processing?
- A Lambda function creates temporary files under 10 MB during each invocation. The files are read and modified multiple times while the function runs and do not need to persist afterward. Where is the appropriate place to store these temporary files?
- A Lambda function generates a 3 MB JSON file containing sensitive data and uploads it daily to S3. The developer must ensure the file is encrypted before uploading. Which change should the developer implement so the data is encrypted prior to the upload?
- A Lambda function generates avatars for profile images uploaded to an S3 bucket under the /original/ prefix. Some images cause the avatar generator to time out. The developer wants a fallback that resizes the image using a second Lambda function when the generator fails. Which approach accomplishes this with the least development effort?
- A Lambda function has production and development version aliases. A developer needs a staging setup to route traffic to both the development and production versions for testing. Which solution will enable that behavior?
- A Lambda function in a shared account must call ec2:DescribeInstances in multiple development accounts. To follow least privilege, how should the permissions be configured across accounts?
- A Lambda function is triggered by an SQS queue and calls a third-party ML API that can take up to 60 seconds to respond. The Lambda timeout is 65 seconds. The developer sees the function sometimes processing duplicate SQS messages. What should the developer change so the function does not process duplicates?
- A Lambda function is triggered from an Amazon SQS queue. During testing, some messages reappear in the queue while they are still being processed by the function. How can you stop the messages from reappearing?
- A Lambda function issues queries to an Amazon Aurora MySQL DB instance and, during tests, encounters too many connections errors on the DB. Which option solves this problem with the least operational overhead?
- A Lambda function logs timestamps, processing times, and request statuses using the default Lambda logging (CloudWatch Logs). You need to create CloudWatch metrics from those logs and publish them under a custom CloudWatch metrics namespace. Which approach meets these requirements?
- A Lambda function must connect to an Amazon RDS DB instance that resides in a private subnet within a VPC. The company created an IAM role with the required DB permissions and attached it to the Lambda function. What additional configuration is required so the Lambda function can access the DB instance?
- A Lambda function must connect to an Amazon RDS for MySQL database. Credentials need to be encrypted and the database password should rotate automatically. Which solution satisfies these requirements?
- A Lambda function must make HTTP POST requests to an internal application running on EC2 instances in a private subnet within the same AWS account. Which solution enables the Lambda function to reach the internal application?
- A Lambda function named ProcessMessages is invoked asynchronously when messages are published to an SNS topic called InputTopic. The team uses a second SNS topic, ErrorTopic, to receive failure alerts. The developer wants to get notifications to ErrorTopic whenever ProcessMessages fails to process a message. What should they configure?
- A Lambda function needs access to a small set of highly sensitive objects in an S3 bucket. The company follows least privilege and only allows temporary credentials. What is the MOST secure way to grant the Lambda function access to those S3 objects?
- A Lambda function needs network access to private resources inside a VPC. Which approach provides that access with the least operational overhead?
- A Lambda function needs read access to an S3 bucket and read/write access to a DynamoDB table. The correct IAM policy already exists. What is the most secure method to grant the function the required access?
- A Lambda function needs rotated database credentials and secure storage, and integration with Lambda should require minimal management. Which solution should the developer choose to store, rotate, and provide the RDS credentials to the Lambda function with the least operational overhead?
- A Lambda function needs to read an item from a DynamoDB table, modify some attributes, and create the item if it does not exist. The function has the primary key. Which IAM permissions should be granted to the Lambda function to allow these operations?
- A Lambda function processes messages from IoT devices. The company needs near-real-time throughput metrics that count how many messages the function receives and processes per time interval. Initialization and post-processing should not be included in the throughput measurement. What should the developer implement?
- A Lambda function processes objects from an S3 bucket but some invocations are slower than others due to initialization (loading libraries, creating clients). The developer needs predictable, low-latency invocation durations and requires that initialization work occur during allocation time rather than during each invocation. Which combination of steps will achieve this? (Choose two.)
- A Lambda function processes records from a Kinesis data stream, but record processing has slowed. The Lambda iterator age is increasing and function duration is consistently high. Which actions should the developer take to speed up processing? (Choose two.)
- A Lambda function requires a third-party library composed of many files totaling 100 MB. The library must be available in the Lambda execution environment, and the developer wants to minimize the deployment package size and operational overhead. Which approach meets these requirements with the least operational work?
- A Lambda function running in a VPC polls an SQS queue via a VPC endpoint, then computes a rolling average of numeric values from messages. Initial tests show the rolling average is inaccurate. How can the developer ensure an accurate rolling average?
- A Lambda function running in AWS needs to put events to an EventBridge event bus using the SDK and no explicit credentials in code. After deployment, the function logs AccessDeniedException errors when calling PutEvents. How should the developer fix this?
- A Lambda function runs in a VPC and is triggered by S3 object uploads. The function writes result files and appends entries to a shared log file that must be accessible to other Lambda functions, AWS services, and on-premises systems. Which storage solution meets these shared-file and append requirements?
- A Lambda function searches items in a DynamoDB table that uses email_address as the partition key and stores attributes like customer_type, name, and job_title. The function triggers as users type into a customer_type text field and should return partial matches for email_address for a given customer_type. The developer cannot recreate the table. What should be done to support partial email_address matching per customer_type?
- A Lambda function subscribed to an SNS topic should process only messages that indicate email address changes; other subscribers will handle other message types. You want the solution that requires the least development work. Which approach should you use?
- A Lambda function that converts large image files has grown after adding a new module. The larger bundle has made deployments slower. How can a developer decrease the deployment time for the Lambda function?
- A Lambda function that inserts new customers into an Amazon RDS database runs multiple times per hour and is slower than expected. The function and RDS are in the same VPC. Which change will improve performance?
- A Lambda function that runs on a schedule must authenticate to a third-party system with an API key. The API key must remain encrypted at rest. Which approach meets this requirement?
- A Lambda function will create temporary files totaling 100 MB while it runs; those files are not needed after the function completes. What is the most efficient way for the function to handle these temporary files?
- A Lambda function will process messages from an Amazon SQS queue. The developer wants to include unit testing in the CI/CD pipeline for this function. What is an appropriate way to run unit tests for the function?
- A Lambda-based application must have minimal latency and predictable start times. All environment setup must complete before each invocation. Which solution satisfies these requirements?
- A legacy application was migrated into a Lambda function that performs many third-party API calls to pull data at month end, then processes it to produce monthly reports. The third-party provider introduced limits: a fixed number of API calls per minute and per day (provided in response headers), returning errors when limits are exceeded. The entire data-processing run may now take days if the app must throttle to avoid exceeding limits. What is the most operationally efficient way to refactor this serverless workflow to respect those limits?
- A marketplace app stores item prices in DynamoDB with ElastiCache in front. Prices change frequently, and sellers report that after they update a price, the listing still shows the old price. What is the most likely cause?
- A microservices application written in Python uses AWS X-Ray. Some services are not appearing on the X-Ray service map during testing. What should the developer do to ensure all services show up in the X-Ray service map?
- A migrated application sends shipping requests that must be processed in order, without duplicates. Requests are up to 250 KB and take 5–10 minutes to process. The current system produces duplicate, lost, or out-of-order requests. How should a developer rearchitect the solution to guarantee ordered, non-duplicated processing?
- A mobile app writes millions of blog posts per day to a DynamoDB table; each post is an item. The app only needs recent posts, and items older than 48 hours can be removed. What is the MOST cost-effective method to automatically delete posts older than 48 hours?
- A monolithic desktop image-processing app that runs every 5 minutes and completes within 1 minute is being reimplemented as a Python AWS Lambda function. In AWS tests, the Lambda is invoked every 5 minutes but now takes over 2 minutes to finish. Which change will improve the Lambda's performance?
- A multi-node Windows legacy application uses a network share as a central repository for .xml configuration files. The company is migrating the application to EC2 and needs a highly available configuration repository at minimal cost. Which solution is the MOST cost-effective way to provide a highly available repository for the configuration files?
- A multimedia app will let guest users view sample content before they create accounts for full access. The company wants to identify users who already have accounts and also track how many guest users later register. Which combination of actions meets these needs? (Choose two.)
- A new feature should be available only to a specific group of premium customers. A developer needs to be able to toggle the feature on and off rapidly (for example, in response to performance or feedback) and validate changes before deploying, without causing user disruption. What should the developer use?
- A new serverless user portal is performing slowly. Analysis shows a single API Gateway endpoint calling a Lambda function is responsible, but that Lambda calls other APIs and AWS services. Using operational best practices, how can a developer find which external call is causing the increased latency?
- A newly deployed AWS Lambda function in a shared account is showing increased throttle metrics in CloudWatch. Which operationally efficient actions will reduce throttling? (Choose two.)
- A photo-sharing app stores images in S3. A third-party auditor manually inspects images and records results 1–24 hours after upload to a DynamoDB table keyed by the S3 object key. The third party exposes the audit results via a REST API. You need an automated process to tag each S3 object with its audit result, implemented in the most operationally efficient way. Which approach should you take?
- A photo-sharing app stores original images in Amazon S3 and serves them through CloudFront. Each mobile device sends its display dimensions and resolution as GET parameters. To serve optimized images per device and improve load time and quality cost-effectively, which solution is best?
- A process automatically retrieves API credentials for multiple banking sources and invokes a Lambda function tied to a CloudFormation custom resource. The developer wants to store these API credentials with minimal operational overhead and maximum security. Which approach is the most secure and requires the least operational effort?
- A production static website in S3 invokes an Aurora PostgreSQL database via a Lambda function. The site uses a Lambda alias that points to a specific function version. Database credentials must be rotated every two weeks, and older deployed Lambda versions must be able to access the latest credentials. Which solution satisfies these requirements?
- A production web application runs on four EC2 instances behind an Elastic Load Balancer and is managed by AWS Elastic Beanstalk. A developer needs to update the platform version (Node.js) and deploy new application code for testing without any downtime. Which deployment approach satisfies these requirements?
- A publicly accessible single-page web app (client-side) calls a third-party HTTP API that requires an API key provided in an HTTP header. The company’s API key must not be exposed to end users. Which cost-effective solution ensures the API key is kept secret?
- A Python application running on EC2 needs request tracing to debug performance. Which combination of actions should be taken? (Choose two.)
- A Python AWS Lambda function is triggered by S3 object-creation events; it reads from S3 and writes to a DynamoDB table. The function executes on invocation but fails when attempting to write to DynamoDB. What is the MOST likely cause?
- A real-time messaging app uses API Gateway WebSocket APIs with an HTTP backend. The developer must detect a client that repeatedly connects and disconnects and be able to remove that client. Which changes should be made? (Choose two.)
- A REST service uses API Gateway with Lambda integration and needs to support multiple versions for testing. What is the BEST approach to run different versions concurrently for testing?
- A retailer built a serverless app that runs an AWS Lambda function to compute order success rates and saves results in a DynamoDB table. A developer needs a simple way to invoke the Lambda every 15 minutes. Which option satisfies this with the least development effort?
- A serverless app uses API Gateway to invoke a Lambda function. A developer fixes a bug in the Lambda code and wants to route 10% of live production traffic to the new Lambda version to test it. Which steps should the developer take? (Choose two.)
- A serverless app uses Step Functions and Lambda to process uploaded report files. The UI calls an API (API Gateway + Lambda) to start processing; large or complex files are causing the API requests to time out. The UI team wants the API to return immediately so the UI can show a confirmation, and the backend must send an email when processing completes. How should the developer configure the API to meet these requirements?
- A serverless application (one Lambda function and one S3 bucket) is being deployed with AWS SAM. The Lambda function only needs read access to the S3 bucket. How should the SAM template grant the function the required read permission?
- A serverless application built with AWS Lambda will be deployed using the AWS SAM CLI. Which step should you perform before deploying the application with SAM?
- A serverless application is monitored with AWS X-Ray. User interactions and transactions (low volume) are important to fully trace, while background operations (health checks, polling, connection maintenance) are high-volume and low-value to record. The default X-Ray sampling records only the first request per second plus some additional requests. How should the developer configure sampling to trace user interactions and transactions without wasting resources on background tasks?
- A serverless application must react to changes in a DynamoDB table using a Lambda function. How should the developer configure the Lambda function to capture table changes?
- A serverless application must store sensitive API keys as environment variables and requires automatic yearly rotation of the encryption keys. The company wants a solution that requires no application development effort. Which option meets these needs?
- A serverless application uses a Lambda function and writes logs to CloudWatch Logs. A CloudFormation template creates the log group. The application needs to know the log group's name at runtime. How can the CloudFormation template be changed so the application can access the log group's name when it runs?
- A serverless application uses Lambda functions behind API Gateway. CodeDeploy will be used to automate Lambda updates. Deployments must minimize user exposure to potential errors and cannot cause downtime outside the maintenance window. Which CodeDeploy deployment configuration meets these requirements while minimizing total deployment time?
- A serverless application with hundreds of Lambda functions connects to an Amazon Aurora PostgreSQL database. Each Lambda scale-out creates a new DB connection, increasing resource usage. You need to reduce the number of database connections without reducing Lambda scalability. What should you implement?
- A serverless ecommerce workflow uses API Gateway to invoke a Lambda function that calls a third-party stock API. During peak load the third-party API fails when overwhelmed. The company needs a solution that prevents overwhelming the third-party API. Which design meets this need?
- A serverless Lambda function processes orders and calls an external payment API that sometimes fails. The support team should be notified in near real time only when the external API error rate exceeds 5% of transactions in an hour. An existing SNS topic already notifies the support team. Which solution meets this requirement?
- A serverless ticketing system generates an order ID and then runs inventory and payment Lambda functions in parallel. If a seat is accidentally sold twice, the first order received must get the seat and only that order’s payment should be processed. If the first order’s payment is rejected, the second order should get the seat and its payment should be processed. Which design meets these requirements?
- A serverless workflow uses AWS Step Functions to invoke several Lambda functions. One Lambda intermittently times out during high load. The developer wants the workflow to automatically retry that function when a timeout error occurs. What change will accomplish this?
- A service uploads images to an S3 bucket. Each upload should trigger a Lambda function to create a thumbnail and also send an email notification. How should the developer wire S3 events, the Lambda thumbnail processor, and the email notifications?
- A set of microservices run on Amazon EC2 and the developer needs end-to-end tracing of requests across services and the ability to debug issues across the call path. What should the developer do?
- A social media app stores frequently changing, complex data in an RDS database and must serve reads with minimal latency. The current architecture struggles with rapid updates. Which solution will best improve performance?
- A social media app uses the AWS SDK for JavaScript in the browser to obtain user credentials from AWS STS. App assets are stored in an S3 bucket and delivered through a CloudFront distribution with the S3 bucket as the origin. Currently, the role credentials the app assumes are stored in plaintext inside a JSON file in the frontend code. The developer must remove hardcoded credentials while still allowing the app to obtain credentials. Which approach satisfies this requirement?
- A Step Functions state machine pauses when it receives an order until another service confirms the order by adding a record to a DynamoDB table. Which solution will allow the state machine to resume processing after the DynamoDB record appears?
- A stock trading application must send SMS trade-confirmation messages to users in the exact order trades occur, and must avoid sending duplicate messages. Which solution meets these ordering and deduplication requirements?
- A stock-trading application requires sub-millisecond latency for processing trade requests. Trading data is stored in DynamoDB, but load testing shows data retrieval is slower than required. Which solution will reduce retrieval latency with minimal effort?
- A team deploys web servers and an Amazon RDS database from a single CloudFormation template across multiple environments. A recent accidental deployment caused the primary development database to be deleted and recreated, losing data. Which actions will prevent accidental deletion of the database in future deployments? (Choose two.)
- A team develops multiple Lambda functions that all depend on the same third-party library, which is updated frequently. The team wants the Lambda functions to always use the latest library version with the least operational overhead. What is the best solution?
- A team is building a CI/CD pipeline using AWS CodePipeline and needs a place to store the application source code that the pipeline will use. Which AWS service should host the source code?
- A team is building a serverless app and must store an external API key as part of an AWS Lambda configuration. The team requires full control over the AWS KMS keys that will encrypt the API key and wants the key material accessible only to authorized principals. Which option satisfies these requirements?
- A team is building serverless infrastructure using the AWS Serverless Application Model (AWS SAM) and must deploy everything with CloudFormation templates. What change should they make to their CloudFormation templates to use AWS SAM?
- A team is deploying an application on Amazon EC2 instances. During testing the instances fail to access an Amazon S3 bucket. Which steps should the team take to debug the problem? (Choose two.)
- A team is designing a mobile app that must require multi-factor authentication (MFA). Which steps should they take to implement MFA? (Choose two.)
- A team is moving to microservices. Each service must only depend on its own datastore. The Payments service (using DynamoDB) needs near-real-time data originating in the Accounts DynamoDB table. What approach gives the simplest, decoupled, and reliable way to obtain updates from Accounts?
- A team is seeing more bugs in their Node.js Lambda functions. They want automated tests that closely emulate the Lambda runtime, allow other developers to run tests locally, and run as part of the CI/CD pipeline before AWS CDK deployment. Which solution meets these requirements?
- A team needs to roll out a new API version to a small subset of users via Amazon API Gateway and wants a simple, safe, and transparent deployment method. Which option is the easiest way to route a portion of traffic to the new API version within API Gateway?
- A team needs to securely store fixed one-time license keys that must be accessed by automation scripts running on EC2 instances and by CloudFormation stacks. Which cost-effective option should they use?
- A team runs an Amazon API Gateway REST API that invokes an AWS Lambda function. Users report poor performance caused by Lambda cold starts. The team must reduce the Lambda initialization time. Which option accomplishes this?
- A team updated a CloudFormation template for a stack that already includes a DynamoDB table. Before deploying, they accidentally changed the DynamoDB table's logical name in the template. The DeletionPolicy attribute is at its default for all resources. What will CloudFormation do as a result of this change?
- A team uses AWS SAM templates for a microservices app made of many Lambda functions and wants to automatically test new deployments by routing a small percentage of traffic to updates before full rollout. Which steps provide the most operationally efficient solution? (Choose two.)
- A team uses one CloudFormation template to deploy web servers and an RDS database across environments. After an accidental deployment, the development database was dropped and recreated, causing data loss. Which actions will prevent accidental deletion of the database in the future? (Select two.)
- A team wants to run unit tests automatically in a CodePipeline CI/CD workflow. Tests produce a report showing each check's result. Which approach requires the least operational overhead to run these tests and surface the report during the pipeline execution?
- A three-tier application uses an Application Load Balancer (ALB), EC2 instances, and Amazon RDS. A Route 53 alias record points to the ALB. When accessing the ALB from a laptop, the request times out. Which logs should the developer check to confirm whether the request reached the AWS network?
- A very large Lambda deployment fails with InvalidParameterValueException saying the unzipped size exceeds the maximum. Which actions can resolve this? (Choose two.)
- A video surveillance application stores 1 GB average (max 2 GB) files in S3. A Lambda function processes each file once, and processing is I/O intensive requiring multiple reads of the file. After processing the file is deleted. Which option gives the best performance for this workload?
- A VPC contains multiple VPC endpoints for Amazon S3. A developer needs an S3 bucket policy that ensures access to the bucket is allowed only when requests come through those VPC endpoints. Which solution satisfies this requirement?
- A web application behind a CloudFront distribution needs near-real-time monitoring for error rates and anomaly detection. Which combination of actions should a developer take to build a dashboard that provides the most frequent monitoring? (Choose two.)
- A web application is served from EC2 instances behind an internet-facing ALB. You must place Amazon CloudFront in front of the ALB and ensure client data coming from outside the VPC is encrypted in transit. Which two CloudFront settings should you use? (Choose two.)
- A web application on EC2 streams logs to CloudWatch Logs. The company must receive an SNS notification when application error messages exceed a defined threshold within a 5-minute window. Which solution accomplishes this?
- A web application runs on EC2 instances built from a custom AMI and is provisioned with CloudFormation in us-east-1. The company wants to deploy the same stack in us-west-1, but stack creation in us-west-1 fails with an error that the AMI ID does not exist. The developer must fix this with minimal operational effort. Which solution accomplishes that?
- A web application serves secure documents stored in a private S3 bucket and must allow only authenticated users to download a specific document for 15 minutes after request. Which approach meets these requirements?
- A web application uses API Gateway with a Lambda backend. A developer fixed a bug in the Lambda code and must validate the fix in a new development environment before promoting it to production. There is only a production stage available, and the developer must prevent other developers from overwriting the test changes. Which combination of steps achieves this with the least effort? (Choose two.)
- A website collects daily poll responses in a DynamoDB table and only needs to retain responses until the next day. The developer added an expiration_date attribute to each item. What is the simplest way to automatically remove expired responses from the table?
- A website displays a daily newsletter stored in English. When a user visits, a Lambda function queries the company's on-premises database for the current newsletter, calls Amazon Translate TranslateText to translate it for the user, and returns the translated text. Traffic has increased and the on-premises database is overloaded, slowing responses. The company cannot change the database. Which change will improve the Lambda function's response time?
- A website runs on an EC2 instance with Auto Scaling to handle peak traffic. Users worldwide are experiencing high latency when loading static assets that are served from the EC2 instance, even during off-peak times. Which two actions will reduce latency for the static content? (Choose two.)
- A website serves static files from an S3 bucket through an Amazon CloudFront distribution. After deploying updated files to S3, the updates are visible in the bucket but not on the site served by CloudFront. What should the developer do to make the new artifacts appear on the site?
- Account A stores PII in a DynamoDB table named PII. An application running on EC2 instances in Account B needs access to that table. In Account A an IAM role AccessPII was created with permissions for the PII table and a trust policy allowing principals from Account B to assume the role. Which steps should developers perform in Account B to enable the application to access the PII table? (Choose two.)
- Accounts are organized under AWS Organizations. An application in Account A stores environment variables as parameters in AWS Systems Manager Parameter Store. A new application in Account B needs to use those same parameters from Account A without duplicating them into Account B. Which solution provides access with the LEAST operational overhead?
- After deploying to production, S3 events in development environments started invoking the production Lambda functions, causing unwanted executions. The team must stop cross-environment invocations and follow security best practices. Which solution meets these requirements?
- An Amazon Kinesis Data Firehose delivery stream receives records containing personally identifiable information. The data must have pattern-based customer identifiers removed before being stored in Amazon S3. What is the best way to implement this transformation?
- An Amazon RDS for MySQL DB instance named "mysql-db" was deleted within the last 90 days. A developer must identify which IAM user or role performed the deletion. Which approach will provide this information?
- An analytics workflow uses an AWS Lambda function invoked asynchronously to process transaction records. Sometimes the asynchronous invocations fail. When a failure occurs, the developer wants a second Lambda function to be invoked to handle the error and record details. Which solution meets this requirement?
- An API Gateway API invokes a Lambda function via a Lambda alias. A developer updated the code and wants to let other developers test the new version without affecting customers who use the API. Which approach provides this with the least operational overhead?
- An API Gateway API sends requests to a Lambda function. The API is experiencing increased latency because the Lambda function has limited CPU available to handle requests. Before deploying to production, the developer must increase the Lambda function's CPU. Which action will accomplish this?
- An API Gateway endpoint integrated with a Lambda function returns the error: 'Method completed with status: 502'. What is the most likely fix?
- An API Gateway REST API has a single resource with a GET method integrated with a Lambda function. You published a new version of the Lambda function and want to test it before routing production traffic to it. Tests must not affect the production REST API and should require minimal operational overhead. What should you do?
- An API implemented with CloudFront, API Gateway, and Lambda receives at least four requests per second. Many users run the same query via POST. The developer wants to cache POST responses to reduce load. What should they do?
- An application accepts customer data via an API Gateway API that calls Lambda functions. The Lambdas store data in an Amazon Aurora MySQL cluster. After adding a CloudFront distribution with field-level encryption that uses an AWS KMS key, all data in the database changed from plaintext to ciphertext. You must ensure data is stored in the database as plaintext rather than as the ciphertext produced by CloudFront field-level encryption. What should you do?
- An application calls DynamoDB using the low-level BatchGetItem operation and often receives responses that include entries in UnprocessedKeys. Which actions will make the application more resilient when UnprocessedKeys are returned? (Choose two.)
- An application deployed in an Asia Pacific AWS Region calls AWS STS at the default global endpoint (https://sts.amazonaws.com) and is experiencing intermittent latency. What should the developer do to fix the latency issue?
- An application deployed on Amazon ECS uses an Amazon RDS for MySQL DB instance. The app issues far more reads than writes. During peak traffic, application performance drops and the DB instance’s ReadLatency metric in CloudWatch spikes suddenly. What change should the developer make to improve performance?
- An application deployed on an EC2 instance needs to read and write to multiple S3 buckets. The developer wants the EC2 instances to make secure API requests without managing credentials and must follow the principle of least privilege. Which solution meets these requirements?
- An application deployed on IoT devices sends data to a RESTful API implemented by an AWS Lambda function. Each request includes a unique identifier. Traffic can spike unpredictably, and when requests are throttled the client may retry, causing duplicate requests. The API must handle duplicates without inconsistency or data loss. Which solution meets these requirements?
- An application deployed via CloudFormation uses API Gateway REST APIs integrated with Lambda and DynamoDB. There are development, testing, and production stages, each with its own DynamoDB table. Changes promoted to production have caused unexpected problems even though they worked in dev and test. For the next release, the developer needs to route 20% of production traffic to the new API deployment and 80% to the existing production deployment, minimizing the chance that any single customer sees errors. What is the best approach?
- An application extracts metadata from files uploaded to S3 using Lambda functions and stores the metadata in DynamoDB. The developer wants to view the Lambda function logs to troubleshoot unexpected behavior. Given this configuration, where are the Lambda execution logs stored?
- An application fetches sensitive data from a third-party system and formats it into a PDF larger than 1 MB. The developer will encrypt the file on disk using a KMS symmetric customer-managed key and later decrypt it for download. Using the GenerateDataKey API, which approach correctly enables encrypting the PDF so it can be decrypted later?
- An application in Account A needs to retrieve a Secrets Manager secret that is encrypted under a KMS key in Account B. The application's role already has Secrets Manager permissions in Account B. To allow the role in Account A to use the KMS key in Account B with least privilege, which KMS permissions should be added to the key policy?
- An application inserts items into a DynamoDB table configured with provisioned capacity. The app runs on a burstable 'nano' EC2 instance and is failing with ProvisionedThroughputExceededException. Which actions should the developer take to address this? (Choose two.)
- An application invokes an AWS Lambda function asynchronously. The developer wants to capture messages that caused failed Lambda invocations so the application can retry them later. Which approach accomplishes this with the least operational overhead?
- An application is slow under increased read demand. The reads are for historical, read-only records retrieved from an Amazon RDS database using custom views and queries. You must improve performance without modifying the database schema and minimize management overhead. Which approach will achieve this?
- An application keeps user data in S3 buckets across multiple Regions. A developer must analyze the S3 objects to discover sensitive data and ensure that all findings from every bucket are available in the eu-west-2 Region. Which approach delivers this with the least development effort?
- An application must encrypt hundreds of video files within the application before storing them, using a unique key per video. How should the developer implement encryption in the application?
- An application needs the client IP address but now runs behind an Application Load Balancer, so all requests appear to come from the same IP. The application must remain horizontally scalable. What is the MOST cost-effective fix?
- An application on EC2 instances requires dynamic feature flags shared across applications. The app must poll at intervals for updated flag values and cache the values when retrieved. Which solution provides the most operationally efficient implementation?
- An application on EC2 previously used IAM user access keys stored in environment variables to call DynamoDB via boto. The developer attached an instance role with the same permissions and then deleted the IAM user. After restarting, the app logs show AccessDeniedException, but the developer can run DynamoDB CLI commands using their personal account on the server. What is the MOST likely cause of the exception?
- An application on EC2 produces gigabytes of data daily. Files are rarely accessed but must be retrievable within minutes during the first year. Files must be retained for 7 years. What is the most cost-effective storage strategy?
- An application on EC2 serves objects stored in an S3 bucket to users. After enabling S3 Block Public Access on the bucket, users can no longer download objects. The requirement is that only users authenticated through the application can access the objects. Which combination of steps will securely meet this requirement? (Choose two.)
- An application processes messages from an Amazon SQS standard queue inside an Amazon ECS task. To process messages as cost-effectively as possible, which actions should the developer take? (Choose two.)
- An application processes millions of events in real time that arrive through an API. Which service allows multiple consumers to process the stream concurrently while being the most cost-effective?
- An application produces large volumes of AWS X-Ray trace data hourly. You want users to filter the returned traces by custom attributes. How should you add custom attributes so they can be used in X-Ray filter expressions?
- An application reads from a Kinesis data stream. The stream’s shards are configured for normal traffic, but during peak tests the application can’t ingest data fast enough. What is the most cost-effective change to make the stream handle peak traffic?
- An application reads items from a DynamoDB table where each item has an expirationDate timestamp attribute. The application finds items by this timestamp to archive and then delete them. The application will be retired soon, and the developer needs a low-code replacement for this behavior. Which approach requires the least amount of new code?
- An application receives daily batches of orders from partners and uses an AWS Lambda function to process each batch. If a batch contains zero orders, the Lambda function must publish to an Amazon SNS topic as quickly as possible. Which combination of steps accomplishes this with the least implementation effort? (Choose two.)
- An application requires that new users register using their social media accounts (OAuth/social identity providers). Which AWS service should the developer use to enable this sign-up method?
- An application running as microservices on Amazon ECS with Fargate is returning errors to users. Which of the following steps should a developer take to diagnose and fix the issues? (Choose two.)
- An application running in ECS Fargate behind an ALB stores database credentials inside the application. The company wants to store credentials more securely and enable periodic rotation with minimal operations effort. Which solution best meets these requirements?
- An application running on Amazon EC2 calls the DynamoDB REST API. Periodically, writes fail with ProvisionedThroughputExceededException. Which changes will most cost-effectively reduce these errors? (Choose two.)
- An application running on Amazon EC2 must send a chat message to the company’s support team when it detects an invalid transaction. To call the chat API it needs an access token that must be encrypted at rest and in transit and must be accessible from other AWS accounts. Which approach provides these requirements while minimizing management overhead?
- An application running on Amazon ECS needs configurable limits (maximum simultaneous connections and max transactions per second) that will change over time. The developer requires that updates to these configuration values be deployed automatically with no downtime. Which solution satisfies these requirements?
- An application running on Amazon ECS requires several variables: remote API authentication data, the API URL, and credentials. The authentication info and API URL must be available to all current and future app versions across dev, test, and prod. Which approach retrieves these values with the FEWEST changes to the application?
- An application running on an Amazon EC2 instance needs to securely upload files to an Amazon S3 bucket. What is the MOST secure way to grant the application the required permissions?
- An application running on an EC2 instance failed when trying to read from an S3 bucket. The developer discovered that the EC2 instance's associated IAM role lacked S3 read permissions. What is the least disruptive way to grant the application the required read access?
- An application running on an EC2 instance lists objects in an S3 bucket but displays no objects during testing. What is the most secure way to fix this so the application can list the bucket contents?
- An application running on an EC2 instance needs to call APIs to access objects in an S3 bucket. Which combination of steps provides the most secure configuration? (Choose two.)
- An application running on an EC2 instance needs to determine the instance's public IPv4 address. What method should the application use to obtain it?
- An application running on AWS Elastic Beanstalk generates user-specific PDFs, stores them in an unversioned Amazon S3 bucket, and emails them via Amazon SES. Users stop accessing PDFs after 90 days, and there are many obsolete PDFs in the bucket. A developer must remove PDFs older than 90 days with the least development effort. What should the developer do?
- An application running on EC2 instances must be able to write objects to an Amazon S3 bucket. Which policy should the developer update so the instances can write to S3?
- An application running on EC2 instances stores data in an S3 bucket. All data must be encrypted in transit. How can a developer ensure that all traffic to the S3 bucket is encrypted?
- An application running on EC2 uses an Amazon RDS for SQL Server database. Security requires database credentials to be rotated at least weekly. How should the developer configure credentials to meet this requirement?
- An application running on EC2 writes custom DECRYP_ERROR messages into CloudWatch Logs. The development team must be alerted in real time when these errors appear in production with minimal operational effort. What is the best solution?
- An application runs across multiple AWS Regions and shows intermittent performance problems. A developer must implement distributed tracing with AWS X-Ray to find the root cause. What should the developer do regarding Region annotations so tracing works correctly across AWS services and the application's own services?
- An application runs behind a load balancer using HTTP/HTTPS and needs access to the original client IP addresses. Which load balancing solution satisfies this requirement?
- An application runs on AWS Elastic Beanstalk. You must deploy updates without any downtime and route a specific percentage of incoming traffic to the new version during an evaluation period. Which Elastic Beanstalk deployment policy accomplishes this?
- An application runs on EC2 instances in an Auto Scaling group and experiences variable daily load. The company needs detailed EC2 instance metrics to right-size instances and must also monitor custom application metrics. Which solution satisfies both needs?
- An application runs on many EC2 instances behind an Elastic Load Balancer. Where should session data be stored so it can be reliably served across requests from different instances?
- An application stores data in Amazon DynamoDB and currently processes it in a nightly batch. Analysts want processed results available in near-real time as data arrives. Which architectural pattern allows processing data as it is received?
- An application stores data in DynamoDB. Some queries are slow because they filter on an attribute that is neither the table partition key nor sort key. The dataset will grow significantly. What change will improve query performance for that attribute?
- An application stores incoming JSON files in S3, then a Lambda transforms them and writes items to DynamoDB. Sudden traffic spikes cause DynamoDB throttling. Which change will remove throttling and smooth writes into DynamoDB?
- An application stores objects in Amazon S3. The developer must enforce in-transit encryption for S3 access, and all objects containing personal data must be encrypted at rest with AWS KMS customer-managed keys that can be rotated on demand. Which combination of actions satisfies these requirements? (Choose two.)
- An application stores objects in an Amazon S3 bucket using the PutObject API. The objects must be encrypted at rest using server-side encryption with Amazon S3–managed keys (SSE-S3). Which approach satisfies this requirement?
- An application stores sensitive files in Amazon S3 and must encrypt data at rest. Company policy requires an audit trail that shows when the AWS KMS key was used and which principal used it. Which server-side encryption option satisfies this requirement?
- An application stores sensitive user data and includes a CloudFront distribution plus multiple Lambda functions that handle requests. Each request contains more than 20 data fields; certain fields must be encrypted and only specific components of the application should be able to decrypt them. Which solution meets these requirements?
- An application uses a DynamoDB table containing millions of items and receives 30–60 requests per minute. The developer needs near-real-time processing whenever items are added or updated with the MINIMUM changes to existing application code. Which approach should the developer use?
- An application uses a DynamoDB table with attributes: partNumber (partition key), vendor (sort key), description, productFamily, and productType. Some modules frequently query for lists of products by productFamily and productType. Which change will improve query performance for those access patterns?
- An application uses a Lambda function to write data to an Amazon RDS for PostgreSQL database. A developer created a database user for the application and wants to manage the user credentials in AWS Secrets Manager, rotating the password regularly. The rotation process must ensure high availability and no application downtime during secret rotation. What should the developer configure?
- An application uses a Lambda function with an SQS queue named high priority queue as an event source. A second SQS queue, low priority queue, is being added. The Lambda function must always read up to 10 concurrent messages from high priority queue before consuming from low priority queue, and the Lambda must never exceed 100 concurrent invocations. Which configuration meets these requirements?
- An application uses Amazon API Gateway to invoke a Lambda function and is sensitive to latency. A developer must configure the Lambda function to reduce cold-start latency that occurs during scaling. What should the developer do?
- An application uses Amazon Aurora with multiple read replicas to scale read queries. One replica is receiving most or all traffic while another sits idle. How can you fix this imbalance?
- An application uses Amazon Cognito user pools and identity pools and must let users upload and download their own files to Amazon S3 (file sizes 3 KB–300 MB). Files must be handled securely so users can only access their own data. Which option provides the HIGHEST level of security?
- An application uses Amazon ElastiCache to cache database data, and the cached data must update dashboards in real time. Which caching strategy best ensures the cache contains fresh data for immediate dashboard display?
- An application uses an Amazon Cognito user pool for authentication. You need to add a new REST API that authenticates requests using that user pool with the least amount of development effort. Which approach should you choose?
- An application using Amazon RDS experiences periodic read-heavy traffic spikes that degrade query performance. The team wants a multithreaded, scalable caching solution to offload read requests and improve performance with the least complexity. Which option is the simplest appropriate solution?
- An application was migrated from an on-premises MySQL database to Amazon RDS for MySQL. The application must connect to the RDS instance without using long-term database credentials. Which solution satisfies this requirement?
- An application will store personal health information (PHI) and must keep the data encrypted at all times. Data is stored in an encrypted Amazon RDS for MySQL DB instance. The developer wants to improve performance by caching frequently accessed data and needs the ability to sort or rank cached datasets. Which solution meets these requirements?
- An application writes clickstream data to Amazon Kinesis. The stream experiences periodic spikes and PutRecords calls sometimes fail with the shown response. Which techniques can help mitigate this error? (Choose two.)
- An application’s CloudFormation template references a Lambda deployment package stored in S3 by specifying the S3 object key. Each time the stack is updated, the Lambda function does not change even though the zip is updated in S3. How can the developer ensure CloudFormation updates the function when the code changes?
- An Auto Scaling group is slow to make instances available because the UserData script runs for a long time. The solution must ensure instances are available quickly, always have the latest application version, apply security updates, minimize the number of images created, and validate images. Which combination of steps meets these requirements? (Choose two.)
- An AWS application reads messages from an SQS queue and processes them in batches, then sends results to another SQS queue consumed by a legacy system. The legacy system can take up to 5 minutes to process some messages and cannot be changed. The developer must prevent out-of-order updates in the legacy system. Which solution meets this requirement?
- An AWS CloudFormation stack deletion fails with DELETE_FAILED for the resource ASGInstanceRole12345678. What is the appropriate action to resolve this so the stack can be deleted successfully?
- An AWS CodeBuild project fails because the combined length of all environment variables exceeds the allowed character limit. What is the recommended approach to handle many or large environment values?
- An AWS Lambda function is invoked asynchronously to process events, but some invocations fail intermittently. The developer needs to capture and analyze these failed events to troubleshoot, with minimal development effort. What should the developer do?
- An AWS Lambda function is subscribed to an Amazon SNS topic. You must ensure that a record of every Lambda invocation is added to an Amazon SQS queue. Which solution satisfies this requirement?
- An AWS Lambda function polls messages from an Amazon SQS standard queue and makes an HTTP request to an external API for each message. The company wants to ensure the Lambda function never issues more than two concurrent requests to that third-party API. Which configuration satisfies this requirement?
- An AWS Lambda function should be triggered whenever items in an Amazon DynamoDB table are updated. The function and its execution role are configured, and DynamoDB Streams are enabled for the table, but the Lambda function is still not being invoked. What action will connect DynamoDB table updates to the Lambda function invocations?
- An e-commerce application uses Amazon API Gateway with AWS Lambda backend functions. The company needs a separate, observable test environment to validate code before promoting it to production. Which design meets this requirement?
- An e-commerce application uses multiple Lambda functions where each function performs a specific step in an order workflow. The functions must run in a defined sequence. Which solution ensures the functions execute in order with the least operational overhead?
- An EC2 instance has an attached IAM role that explicitly denies all Amazon S3 API actions. The same instance also has an AWS credentials file containing an access key and secret access key that grant full administrative privileges. Given these multiple IAM access methods on the instance, which statement is correct?
- An EC2-hosted photo-processing app must process each photo in under 5 seconds; if processing exceeds 5 seconds the development team must be notified. What approach provides the time measurement and alerting with the least operational overhead?
- An ecommerce API publishes order messages to an Amazon SQS queue. You must enrich the order data before sending it to the fulfillment system, using the least development effort. Which solution should you implement?
- An ecommerce app needs to call three independent third-party systems concurrently when a sale occurs. You implemented three separate Lambda functions (one per third party) and want each to run regardless of the others' success or failure. Which design satisfies this requirement?
- An ecommerce application runs behind an Application Load Balancer. A developer wants to analyze traffic patterns by client IP address to investigate unexpected load during off-peak hours. Which HTTP header should the developer inspect to get the originating client IP address?
- An ecommerce application stores data in Amazon RDS for MySQL. The developer needs a caching layer to serve information about the most-viewed products. Which solution meets this requirement?
- An ecommerce frontend calls a POST API via API Gateway that invokes a Lambda function asynchronously to process orders. Occasionally orders are not processed, and Lambda logs show no errors. What should the developer do to diagnose and resolve the missing order processing?
- An ecommerce site uses a Lambda function that writes orders to an Amazon RDS for MySQL database. The service must return order confirmations immediately. During a marketing surge, the operations team saw “too many connections” errors from RDS, even though DB cluster metrics show healthy CPU and memory. What should the developer do to fix the connection errors?
- An ecommerce team needs to be alerted when an Amazon EC2 instance's CPU utilization rises above 80% during a sales event. Which solution will meet this requirement?
- An Elastic Beanstalk environment running recent Amazon Linux instances shows no memory metrics in the Beanstalk console. The application has degraded performance suspected to be memory-related. How should the developer collect memory usage data for the instances?
- An engineer set up an A/B test in an Amazon CloudWatch Evidently project with two feature variations: Variation A and Variation B. The engineer now wants to test only Variation A and have Variation A always returned when the application's endpoint is called. What is the correct way to force Variation A for only the engineer's use?
- An event platform stores leaderboard results in DynamoDB and retains them for 30 days, after which a scheduled job deletes old data. The table uses fixed write capacity, but during busy months the scheduled delete job causes write throttling. The developer needs a long-term solution that removes old leaderboard records and optimizes write throughput. Which approach satisfies this?
- An event-driven system has one Lambda function that processes data and must send the processed data to a subset of four consumer Lambda functions. Routing is based on the value of one field in the data. Which solution provides the required routing with the least operational overhead?
- An EventBridge Pipe uses an Amazon SQS queue as its source and publishes every source event to an EventBridge event bus. A Lambda function in the pipe looks up each event’s stream status from a database and appends that status to the event. The company only wants events published to the event bus when the stream status is ready. What should they do?
- An existing application with hardcoded DB credentials is deployed in two Regions in an active-passive failover setup. You must move credentials out of code and meet the disaster-recovery strategy. Which is the MOST secure solution that satisfies the multi-Region requirement?
- An HTTP API in API Gateway invokes a Lambda function that performs several independent tasks. The tasks can take up to 10 minutes in total. Users report the endpoint sometimes returns an HTTP 504 status, although the Lambda invocations succeed. What change will prevent the endpoint from returning HTTP 504 errors?
- An image-storage web app runs on EC2 instances in an Auto Scaling group behind an ALB. Images are stored in S3. The company wants a new feature where test requests are routed to a separate target group hosting a beta version of the app. Which approach accomplishes this with the least effort?
- An integration environment has an SQS queue that triggers a Lambda to transform messages and call a third-party API. Increased usage causes the third-party API to return many HTTP 429 Too Many Requests, blocking message processing. How should the developer fix this?
- An internal website with sensitive content will be exposed publicly, but access must be restricted so only employees who authenticate via the company's OpenID Connect (OIDC) identity provider can reach it. The website cannot be modified. Which combination of steps will implement this requirement? (Choose two.)
- An IT team stores sensitive images in Amazon S3. After a year, images are moved to archival storage; they are rarely accessed but must remain highly resilient and be retrievable within 24 hours when needed. Which storage approach is the most cost-effective while meeting these requirements?
- An ML pipeline built with AWS Step Functions includes Lambda functions. An SQS queue provides model parameters to train models, and trained models are uploaded to S3. The developer wants to run and test the pipeline locally without making real SQS or S3 service calls. Which option meets this need?
- An on-premises e-commerce web application that stores session state is being migrated to AWS. The application must be fault tolerant, scale natively, and avoid any user-visible interruptions during service outages. Which is the best place to store session state in AWS?
- An on-premises environment exposes audit logs via an HTTP endpoint. The company wants an automated, low-operational-effort solution to regularly ingest large volumes of these logs into AWS for storage and queries. Which solution best meets the requirement?
- An online food company uses an API Gateway HTTP API integrated with a Lambda that writes orders to DynamoDB. New partners may require additional Lambda functions to receive orders. The company has an S3 bucket and wants every order and update stored in S3 for analysis with minimal development effort. What is the simplest way to ensure all orders and updates are written to S3?
- An online retail app currently runs on two on-prem servers: a web server that renders pages and stores session state in memory, and a MySQL database server that stores orders. Under heavy load, the web server's memory usage nears 100% due to session management. When migrating the web tier to EC2 instances in an Auto Scaling group behind an ALB, what additional changes should be made to improve performance?
- An Orders DynamoDB table uses OrderID as the partition key (no sort key) and contains over 100,000 items. You need to efficiently retrieve all orders whose OrderSource attribute equals 'MobileApp'. What is the most efficient design to improve user experience?
- An Orders table uses customer_id as the partition key, order_id as the sort key, and includes order_date as an attribute. A new access pattern requires querying by order_date and order_id. You must add a Lambda to support this access pattern with minimal operational overhead. What should you do?
- An organization requires encryption for all traffic between users and CloudFront, and also between CloudFront and the origin web application. Which actions will meet these requirements? (Choose two.)
- An organization runs application components across several AWS accounts and needs to gather and visualize distributed tracing data across those accounts. Which AWS service should be used to collect and view those traces?
- An organization stores very large files in Amazon S3 and is building a web app that displays metadata about those files to users. After a user selects a file based on metadata, the app will allow the file to be downloaded. The metadata index must support single-digit millisecond lookups. Which AWS service should be used to provide that metadata indexing and low-latency retrieval?
- An S3 bucket contains sensitive data encrypted with a KMS key. Several other AWS accounts need permission to call GetObject on the bucket. How can you ensure that all requests to retrieve objects use encryption in transit?
- An SQS queue is an event source for a Lambda function that converts video files to a lower resolution. The Lambda is timing out on longer videos, and its timeout is already set to the maximum allowed. How can a developer prevent these timeouts without modifying the function code?
- APIs exposed through Amazon API Gateway have caching enabled. Customers need a way to invalidate the API cache when they are testing. What should a developer provide so customers can invalidate the API cache during testing?
- Before a production release, a developer needs to freeze changes in an AWS CodeCommit repository while continuing to work on new features. QA will test the release and perform bug fixes isolated from the main branch. After release, all bug fixes must be merged into main. Which workflow meets these requirements?
- Clients receive HTTP 400 errors when calling an Amazon API Gateway endpoint. How can a developer investigate the cause of these 400 responses?
- Code for a Lambda function is stored in an S3 bucket and must be deployed across multiple AWS accounts in the same Region. A CloudFormation template will run in each account to deploy the function. What is the MOST secure way to let CloudFormation retrieve the Lambda code from the S3 bucket?
- Credentials used to connect to an external SaaS provider are currently stored in plaintext in a configuration file. The developer must secure these API credentials and enforce automatic rotation every quarter. Which solution provides the most secure approach?
- During an ECS deployment with CodeDeploy, the company must route 10% of live traffic to the new task version initially, then after 15 minutes shift the remaining traffic to the new version. Which predefined CodeDeploy traffic control configuration fulfills this requirement?
- During development, a mobile app calls a backend through API Gateway. For integration testing, the developer wants API Gateway to return different simulated backend responses without invoking the actual backend. Which approach provides this behavior with the least operational overhead?
- For an in-place deployment using AWS CodeDeploy, what is the correct sequence of lifecycle hooks that run?
- Four Lambda functions connect to an Amazon RDS relational database. The security team requires the database password to be rotated automatically every 30 days. Which solution is the most secure way to meet this requirement?
- Frontend developers need to continue work while the backend API in API Gateway isn't ready. What is the most operationally efficient way to allow frontend integration to continue?
- Given an IAM policy that restricts s3:GetObject and s3:PutObject for a bucket named DOC-EXAMPLE-BUCKET with an exception for objects whose keys start with 'secrets', what level of access do those actions allow?
- IoT devices upload a data file once per hour to an Amazon S3 bucket. A Lambda function is configured to process these files and should run immediately when each file is uploaded. The Lambda function is already configured with the S3 bucket information. How should the developer ensure the function is invoked as soon as a file is uploaded?
- Many AWS Lambda functions in an application share the same dependencies. The developer frequently updates those dependencies across each function, causing duplicated effort. What is the simplest way to keep shared dependencies up to date with minimal added complexity?
- Many Lambda functions in an application connect to a single Amazon RDS database. The database credentials must be stored securely, and when the credentials are updated the Lambda functions must be able to use the new credentials without changing code or configuration. Which solution meets these requirements?
- Multiple AWS Lambda functions require access to internal data science libraries and reference datasets. Different teams manage the libraries and the data and must be able to update them independently. The Lambda functions run in the company's central VPC. Which solution provides the Lambda functions access to the libraries and data?
- Multiple development teams need to publish an API using API Gateway before the backend is ready so dependent teams can continue work. The API should return mocked responses and HTTP status codes without an integrated backend. Which solution satisfies this requirement?
- Multiple Lambda functions consume messages from an SNS topic and write to an Amazon Aurora database. Company policy requires that all Lambdas use a single, securely encrypted database connection string. Which solution meets this requirement?
- Multiple Lambda functions share the same custom libraries. The developer wants a centralized, versioned, and easy way to update these libraries with the least development effort. Which option meets this need?
- Several Lambda functions write data to the same S3 bucket. One Lambda function is reported to be writing slowly. The developer needs to measure the latency between that Lambda function and S3. Which approach provides that latency measurement?
- Some messages in an Amazon SQS queue contain sensitive data. A developer must ensure all messages are encrypted at rest. Which solution satisfies this requirement?
- The company imports SSL certificates from a third-party provider into AWS Certificate Manager (ACM) for use by public websites. The security team must receive a notification 90 days before any imported certificate expires. The company already has an Amazon SQS queue and an Amazon SNS topic with the security team's email subscribed. Which approach will deliver the required 90-day-before-expiration notification?
- The ExamScores DynamoDB table uses student_id as the partition key and subject_name as the sort key, with top_score as an attribute. The app needs to quickly return the student_id of the top scorer for each subject. Which change will speed up these queries?
- To reduce risk when releasing a new version of an existing Lambda function, you need to split traffic between the current version and the new version for testing. Which approach meets this requirement?
- Two containerized microservices run on Amazon ECS on EC2 instances. Service A reads from an Amazon Aurora (RDS) database; Service B reads from a DynamoDB table. How can you grant each microservice the minimum required privileges?
- Two Lambda functions use the same large Python library, and both deployment packages are approaching the zipped size limit. To reduce package size with the least operational overhead, what should the developer do?
- Users authenticate to an API via a third-party IdP through Amazon Cognito. The developer mapped the IdP attribute Department to a custom Lambda authorizer, intending to allow only Sales department users. The developer changes their department to Sales in the IdP but is still denied access; logs show the access token still has Department=Engineering. What might explain why the token still reports Engineering instead of Sales?
- Users of a new application upload documents to Amazon S3 and the document contents must not be accessible to any third party. Which type of encryption will meet this requirement?
- Users upload documents to an S3 bucket through a web UI. An S3 event triggers a Lambda function to process each upload, but the Lambda sometimes times out. With the Lambda configured using default settings, what happens to the S3 event when the function times out?
- Users upload short video files averaging 10 MB. After upload, a message must be placed on an Amazon SQS queue so the file can be processed, and the files must be accessible for processing within 5 minutes. Which option is the most cost-effective while meeting the requirements?
- Using AWS CloudFormation to deploy a two-tier app with Amazon RDS, the company needs the RDS password to be randomly generated during deployment and rotated automatically without changing the application. What is the most operationally efficient solution?
- Using AWS CloudFormation, a developer needs to set a Lambda function timeout based on a template parameter named Environment. The template contains a mapping called EnvironmentData that stores timeout values per environment. Which intrinsic function should be used to set the Timeout from the mapping?
- Using AWS SAM, a developer wants to deploy updated Lambda functions so that 10% of traffic is routed to the new version for the first 10 minutes (canary), and if no issues occur, shift 100% of traffic to the new version. What change to the SAM template achieves this?
- Using AWS SAM, you want a quick way to locally test Lambda functions with event payloads that match the events AWS services generate. Which method requires the least development effort to produce realistic test events?
- When authoring an AWS CloudFormation template, what is the most operationally efficient way to obtain the AWS Region where the template is being deployed?
- When creating a CloudFormation template that deploys EC2 instances across multiple AWS accounts, the developer must restrict instance types to an approved list. How should the template include this approved list of EC2 instance types?
- When deploying a CloudFormation stack that defines IAM resources with explicit (custom) names, stack creation fails with an InsufficientCapabilities error. What must you specify to allow CloudFormation to create IAM resources that use specified names?
- When designing a DynamoDB table for a customer rewards application, the developer wants to optimize query performance and reduce the chance of hot partitions before running performance tests. Which attribute is the best choice to use as the partition key?
- When using the AWS Encryption SDK, how does the SDK keep track of the data encryption key (DEK) that was used to encrypt a data object?
- Which AWS CLI command launches a new Amazon EC2 instance?
- While creating a CloudFormation stack via the AWS CLI, you want any resources that were successfully created to remain if the stack creation or update fails. Which CLI option should you include when creating or updating the stack to preserve already-provisioned resources on failure?
- While testing a REST application deployed with API Gateway and Lambda, a login attempt with invalid credentials returns HTTP 405 METHOD_NOT_ALLOWED, even though the request method is correct for the resource. Which HTTP status code should the application return for invalid credentials?
- While troubleshooting an application's permissions to modify an Amazon RDS database, a developer has the IAM role used by the application. Which AWS CLI command structure should the developer use to test what the role can assume?
- You are adding a caching layer in front of an Amazon Aurora database and must ensure the application always reads the most up-to-date value for each item. Which caching strategy satisfies this requirement?
- You are authoring a CloudFormation template to deploy a serverless application that uses API Gateway, DynamoDB, and Lambda. Which AWS tool or framework should you use to define serverless resources in YAML?
- You are authoring AWS CloudFormation templates to deploy an application on Amazon ECS using AWS CodeDeploy. You want to roll out a new application version to only a percentage of users before making it available to everyone (a phased/blue-green style deployment). How should you implement this within CloudFormation?
- You are beginning development of a new version of an application while the previous version remains in production. You must continue to deploy fixes and updates to the current production version while developing the new version. The new-version code is stored in AWS CodeCommit. What branching strategy meets these requirements?
- You are building a mobile app that does not require user sign-in. What is the most efficient way to grant these anonymous app users limited access to AWS resources?
- You are building a mobile photo-storage app that must support tens of thousands of users. The backend uses API Gateway integrated with Lambda to process uploads, and DynamoDB stores photo metadata. Users must sign up, upload photos (300 KB–5 MB), and retrieve their previous uploads. Which architecture meets these requirements with the least operational overhead?
- You are building an application that ingests a stream of user-supplied data. Multiple EC2-based processors must consume the stream concurrently in real time, and each processor must be able to resume without data loss after interruptions. More processors will be added later, and you want to minimize duplicated data. Which solution meets these requirements?
- You are building APIs with API Gateway REST API and need to restrict certain resources so only registered users can access them. Tokens should expire automatically and be refreshable. How do you meet these requirements?
- You are debugging a Java-based AWS Lambda function and want to use request tracing to diagnose issues. Which AWS service should you use to collect and view trace data for Lambda invocations?
- You are deploying a new Node.js AWS Lambda function that runs outside of a VPC. The function must query an Amazon Aurora database that is not publicly accessible, and you expect unpredictable bursts of database traffic. What should you do to allow the Lambda function to access the database reliably under bursts?
- You are deploying an application to Amazon ECS on AWS Fargate. The container needs environment variables passed in for the application to start. Where should you specify these environment variables?
- You are designing a serverless game application where users register and sign in via a web browser. Requests from the web app invoke Lambda functions behind an API Gateway HTTP API. You want a sign-in/registration solution that minimizes operational overhead and ongoing identity management. Which option meets these requirements?
- You are launching a global application that must deliver different content based on each user’s country and preferred language. The content must be served reliably and with low latency. Which design meets these requirements?
- You are testing an application that invokes a Lambda function asynchronously. The function fails even after two automated retries during testing. What is the recommended way to capture and investigate the failed events?
- You are troubleshooting connectivity between application servers and database servers running on Amazon EC2. Which AWS services or tools should you use to help identify the faulty component? (Choose two.)
- You created a customer-managed AWS KMS key and must ensure sensitive configuration data (API keys, etc.) used by a Lambda-based application is encrypted in transit. What should you do next to satisfy the encryption requirement?
- You created a new Amazon S3 bucket in one AWS CloudFormation stack. What is the most efficient way to reference that S3 bucket from a different CloudFormation stack?
- You created an API Gateway REST resource /LandingPage with a GET method using mock integration to serve an HTML landing page that links to your backend APIs. What integration request/response mapping configuration should you use so the API returns HTML content for the landing page?
- You created reusable code packaged as a zip that multiple Lambda functions need to use. You must deploy this shared code and update the Lambda functions to use it with the highest operational efficiency. Which solution is best?
- You have a distributed microservices application running on EC2, and message volumes make it hard to correlate logs across services for a given transaction. You need to trace requests through the services to analyze message flow. Which combination of steps should you take? (Choose two.)
- You have an API Gateway REST API in us-east-2 and want to front it with Amazon CloudFront using a custom domain. You have an SSL/TLS certificate from a third-party provider. How should you configure the custom domain and certificate?
- You manage encryption keys in AWS KMS and must ensure keys can be made unusable immediately when they are no longer required. The solution should be highly available and not require managing compute infrastructure. Which option satisfies these requirements?
- You must automate deployments for a serverless, event-driven application. You need reusable infrastructure templates, the ability to test the application locally before deployment, and to include infrastructure changes within an existing AWS CodePipeline pipeline. Which approach satisfies these requirements?
- You must build a workflow that processes messages arriving in an Amazon SQS queue. After a message arrives, the workflow should wait a specified delay before invoking a Lambda function to process it. Which approach provides this behavior with the LEAST operational effort?
- You must deploy an AWS Lambda function whose dependency file is 500 MB. Which deployment method meets this requirement?
- You must design a fault-tolerant system that preserves client session data if an Amazon EC2 instance fails. Which approach ensures session data is not lost when an instance goes down?
- You must manage AWS infrastructure as code and be able to deploy multiple identical copies, stage changes, and roll back to previous versions. Which approach fulfills these requirements?
- You need a Lambda function to securely query an Amazon Aurora database that resides in a private subnet of VPC1. Which configuration will allow the Lambda function to access the database securely?
- You need a serverless, automated mechanism to invoke an AWS Lambda function every 10 minutes. Which solution is appropriate?
- You need an automated, low-effort, reliable way to deploy AWS Lambda functions and their supporting infrastructure for a new serverless application. Which approach provides the least operational overhead?
- You need to deploy a new version of an Elastic Beanstalk application such that the application remains at full capacity with no downtime, while minimizing the cost of any extra resources used during deployment. Which Elastic Beanstalk deployment policy should you choose?
- You need to insert a record into a DynamoDB table immediately after a new file is added to an S3 bucket. Which sequence of steps accomplishes this?
- You need to store movie information where each movie has a title, release year, genre, and optional varying details about cast/crew (different movies may have different extra fields). Required queries: get all details for a specific title and release year; get all details for all movies with a given title; get all details for all movies in a given genre. Which data model meets these requirements?
- You offer public, unauthenticated read-only APIs (updated daily) using API Gateway and Lambda, and the service needs better responsiveness. Which action will help improve API performance?
- You plan to expose a REST API using Amazon API Gateway and AWS Lambda across three environments: development, test, and production. How should you deploy to minimize the number of resources to manage?
- You want the ability to quickly and seamlessly roll back an AWS Lambda function to previous code versions with minimal operational overhead. What is the simplest way to achieve this?
- You want to test an AWS Lambda function locally that will be triggered by an S3 object upload before deploying it to production. Which approach requires the least operational effort to achieve this?
- Your application runs in us-west-1 and you want redundancy in us-east-1. The application secrets are stored in AWS Secrets Manager in us-west-1. How can you replicate those secrets to us-east-1?
- Your application stores items in DynamoDB and you need to query by the table's partition key combined with an alternate sort key value, and you must read the most recent data including recent writes. How should you design the query?
- Your company has two AWS accounts: production (hosts the source S3 bucket) and development (destination S3 bucket). Data in the production bucket is encrypted with a customer-managed AWS KMS key. You will copy the data into the development account’s S3 bucket and must use a KMS key in the development account to encrypt the copied data. That KMS key in development must allow access from the production account. Which approach satisfies these requirements?
- Your organization imports SSL/TLS certificates from a third-party provider into AWS Certificate Manager (ACM) to use with public web apps. You must notify the security team 90 days before any imported certificate expires. The security team is subscribed to an existing Amazon SNS topic and there is an existing SQS queue. Which solution will reliably notify the security team 90 days before expiration?
- Your team runs CI/CD pipelines in AWS CodePipeline. You need to add unit tests that run as part of the pipeline before artifacts are staged for testing. How should you integrate unit tests into the CI/CD pipelines?
Measure Campaigns With Amazon Attribution (Seller) All exam questions
- Amazon Attribution allows advertisers to measure their non-Amazon media and report on Amazon conversion metrics, including sales.
- Amazon Attribution allows advertisers to measure their search, social, display, video, and email non-Amazon media channels.
- ASINs within the Amazon Attribution console are promoted at the Order level.
- Attribution contention occurs at the ASIN level. This means if you promote the same ASINs across multiple orders your attribution tags with the same promoted ASINs will be eligible with each other for attribution.
- Attribution contention occurs at the Order level, which means attribution tags within the same order compete with each other for attribution.
- Attribution tags are generated when you create line items.
- Attribution tags should be placed on both Amazon and non-Amazon Advertising ads.
- Choose the best description for promoted conversion metrics.
- Choose the correct answer. Which type of Amazon Attribution report would you use to view your keyword level Google Ads performance?
- Marta is an advertiser focused on improving consideration metrics of her promoted and brand halo ASINs. Which metrics would be most useful to measure consideration from her campaign?
- Sri is an advertiser interested in improving her media’s performance by generating more “add to carts” with her non-Amazon Advertising media. Which recommendation would you make for her?
- When measuring campaigns using Amazon Attribution, what is the next step after you create an order?
- Which of the following best describes the insights gained from reviewing the Total Detail Page View Rate (DPVR) metric?
- Which sentence below best describes how ads are measured using Amazon Attribution?
- Which sentence best describes what Amazon Attribution enables advertiser to accomplish?
Pass your Amazon exam — faster
Every verified answer and explanation in one place. Practice the full exam and save hours of prep — free to start.
Pass your exam →Guides & tips
- Amazon DOP-C02: CI/CD Pipelines and Deployment Strategies — Study Guide
- Amazon DOP-C02: Containers and Serverless Operations — Study Guide
- Amazon DOP-C02: Event-Driven Architectures and Automation — Study Guide
- Amazon DOP-C02: High Availability, Resilience and Disaster Recovery — Study Guide
- Amazon DOP-C02: Infrastructure as Code and Configuration Management — Study Guide
- Amazon DOP-C02: Monitoring, Logging and Observability — Study Guide