57 practice questions for Domain 1 of the AWS Certified Solutions Architect - Professional (SAP-C02) exam, which makes up 26% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 1: Design Solutions for Organizational Complexity
1. An organization must connect 60 VPCs across three Regions and several accounts, with segmentation between production and development traffic. Which solution meets these requirements?
Answer and explanation
Answer: B. Transit Gateway replaces a full peering mesh with a hub, supports multiple route tables for segmentation, and peers across Regions. Peering every pair grows quadratically and is non-transitive. Collapsing 60 VPCs destroys account and environment isolation. PrivateLink exposes individual services rather than providing general routed connectivity.
2. An on-premises data center must reach AWS with consistent bandwidth, and a backup path must carry traffic if the primary circuit fails. Which solution meets these requirements?
Answer and explanation
Answer: A. Direct Connect delivers consistent bandwidth and a VPN provides a diverse backup path, with BGP preference keeping traffic on the dedicated circuit while it is healthy. Two VPNs both ride the internet and give no bandwidth guarantee. A faster single circuit is still a single point of failure. AWS does not reroute a failed customer circuit onto another path automatically.
3. Instances in a VPC must resolve names held in an on-premises DNS zone, and on-premises hosts must resolve names in a private hosted zone. Which solution meets these requirements?
Answer and explanation
Answer: C. Bidirectional hybrid resolution requires an outbound endpoint with a forwarding rule for the on-premises domain and an inbound endpoint so on-premises resolvers can query Route 53. Copying records into a private zone duplicates and drifts. A public zone publishes internal names to the internet. Host files do not scale and drift immediately.
4. An architect must determine why traffic between two VPCs attached to a transit gateway is not flowing, without generating test traffic. Which solution meets these requirements?
Answer and explanation
Answer: D. Path analysis evaluates route tables, security groups, and network ACLs statically and names the component that blocks the path, with no traffic sent. Flow Logs record only traffic that was actually attempted. Test instances generate the traffic the requirement excludes. Attachment metrics report volume rather than configuration faults.
5. Applications in private subnets across many accounts must reach Amazon S3 without any route to the internet, at the lowest cost. Which solution meets these requirements?
Answer and explanation
Answer: D. Gateway endpoints for S3 carry no hourly charge and keep traffic on the AWS network, which is both the cheapest and the most direct option. Interface endpoints work but bill hourly per endpoint per Availability Zone. A centralized NAT gateway routes to the internet and bills for data processing. A proxy fleet adds instances to operate.
6. An organization must allow a security team in one account to assume read-only roles in 200 member accounts without maintaining a trust policy per account. Which solution meets these requirements?
Answer and explanation
Answer: C. StackSets deploy a consistent role to every account including new ones, and a trust condition on the organization removes per-account maintenance. Manual creation does not scale to 200 accounts. Shared user credentials destroy attribution. Access to the management account alone does not reach member account resources.
7. An organization must centralize security findings, configuration compliance, and API activity from every account for audit. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, E. An organization trail captures API activity across every account into one archive, and delegated administration of Security Hub and Config aggregates findings and compliance centrally. Per-account trails with local buckets scatter the evidence. Monthly manual exports are inconsistent and stale. Detective investigates individual findings rather than aggregating across accounts.
8. An architect must integrate a third-party identity provider so workforce users reach AWS accounts with corporate credentials and centrally assigned permissions. Which solution meets these requirements?
Answer and explanation
Answer: C. IAM Identity Center connects once to the external provider and assigns permission sets across organization accounts from one place. Per-account SAML configuration multiplies work by the number of accounts. Synchronised IAM users create the long-term identities federation eliminates. Cognito serves application end users rather than workforce account access.
9. An organization must ensure that data encrypted in a shared services account can be decrypted by principals in specific member accounts only. Which solution meets these requirements?
Answer and explanation
Answer: C. A customer managed key exposes a key policy where cross-account decrypt permission is granted explicitly, which is the control the requirement describes. AWS managed keys and S3 managed keys expose no key policy for cross-account grants. Distributing a client-side key spreads the secret and provides no revocation path.
10. A workload must survive the loss of a Region with a recovery time objective of 10 minutes and a recovery point objective near zero, at moderate cost. Which solution meets these requirements?
Answer and explanation
Answer: D. Warm standby keeps a functioning scaled-down environment with continuous replication, so failover is scaling up and shifting traffic, which fits ten minutes at moderate cost. Active-active meets the targets at the highest cost the question moderates. Provisioning the application tier at failover time typically exceeds ten minutes. Backup restore takes hours.
11. An architect must design automatic recovery for a stateful workload whose instances occasionally fail their application health checks. Which solution meets these requirements?
Answer and explanation
Answer: C. ELB health checks act on application-level failure, and externalising state lets a replacement instance serve immediately. EC2 health checks observe only reachability, and instance storage does not survive replacement. An alarm requires a person to act. A larger instance does not make recovery automatic.
12. An organization growing from 30 to 400 accounts must standardize account provisioning and apply preventive and detective controls consistently. Which solution meets these requirements with the LEAST custom engineering?
Answer and explanation
Answer: C. Control Tower automates landing zone setup, account provisioning, and consistent controls, which is purpose-built for this scale. Custom automation recreates that capability at high maintenance cost. A checklist depends on human consistency across hundreds of accounts. Reducing the account count weakens isolation.
13. An organization must share a set of private subnets from a central networking account with application accounts so they can launch resources into them. Which solution meets these requirements?
Answer and explanation
Answer: A. AWS RAM shares subnets so participant accounts create resources in them while the owner retains control of the network. Peering and transit gateway connect separate VPCs that each account still administers. Recreating subnets produces separate networks rather than shared ones.
14. An organization must be notified centrally when specified events occur in any member account. Which solution meets these requirements?
Answer and explanation
Answer: B. Cross-account event bus forwarding delivers matching events to one place in near real time and can be deployed consistently with StackSets. Per-account SNS topics configured by owners drift. Polling CloudTrail centrally adds latency and cost where an event path exists. Config records configuration state rather than arbitrary events.
15. An organization must attribute spend to business units across 200 accounts and detect unexpected increases as they occur. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, D. Activated cost allocation tags attribute spend to business units, and Cost Anomaly Detection alerts on statistically unusual increases without preset thresholds. Monthly invoice review is retrospective. Fixed budget thresholds catch only totals crossing a line and miss anomalies within budget. Quarterly Trusted Advisor review is neither timely nor attribution-focused.
16. An organization runs a steady baseline of EC2, Fargate, and Lambda usage and frequently changes instance families. Which purchasing option meets these requirements?
Answer and explanation
Answer: A. Compute Savings Plans apply across instance families and Regions and also cover Fargate and Lambda, so the discount follows a changing mix. Standard Reserved Instances lock to a family. Convertible Reserved Instances allow exchange but cover EC2 only. Spot is unsuitable for steady production that cannot absorb interruption.
17. Two VPCs in different accounts must exchange traffic, and the design must avoid the operational overhead of a transit gateway for a single pair. Which solution meets these requirements?
Answer and explanation
Answer: D. Peering is the simplest option for a single pair and carries no hourly attachment charge. A transit gateway is justified when many VPCs must interconnect. PrivateLink exposes individual services rather than general connectivity. A VPN between two VPCs adds encryption overhead for traffic that already stays on the AWS network.
18. An architect must select a Region for a workload whose users are concentrated in one country with a data residency requirement. Which consideration is decisive?
Answer and explanation
Answer: D. A residency obligation eliminates every Region outside the jurisdiction regardless of other merits, so it is evaluated first. Price, zone count, and launch date are secondary considerations among the Regions that remain eligible.
19. Traffic between a VPC and Amazon S3 must stay on the AWS network and be restricted to buckets owned by the organization. Which solution meets these requirements?
Answer and explanation
Answer: A. A gateway endpoint keeps S3 traffic on the AWS network at no hourly charge, and an endpoint policy conditioned on the organization prevents access to external buckets. An interface endpoint works but bills hourly. A NAT gateway routes to the internet. Bucket policies protect the organization's own buckets and say nothing about external ones.
20. An organization must prevent any member account from creating resources outside two approved Regions, and the restriction must survive a local administrator. Which solution meets these requirements?
Answer and explanation
Answer: A. A service control policy caps permissions for every principal in a member account and cannot be removed locally, and a NotAction exception keeps global services usable. IAM policies can be detached by account administrators. A Config rule reports after creation. Region opt-out is available only for some Regions.
21. An architect must ensure that encryption keys used across an organization can be audited centrally and that their use is attributable. Which solution meets these requirements?
Answer and explanation
Answer: A. Customer managed keys expose a key policy the organization authors and record every cryptographic operation in CloudTrail. AWS managed keys expose no key policy. S3 managed keys provide no key usage trail. Distributed client-side keys have no central audit path.
22. A workload must recover from Regional failure within four hours, and the business accepts losing up to one hour of data. Which strategy is most cost-effective?
Answer and explanation
Answer: B. A four-hour recovery time allows the application tier to be provisioned at failover, which is what makes pilot light the cheapest option meeting the targets. Warm standby and active-active both meet the targets at higher continuous cost. Daily snapshots give a recovery point of up to 24 hours, which exceeds the one-hour allowance.
23. An architect must decide between scaling a workload up and scaling it out. Which characteristic favours scaling out?
Answer and explanation
Answer: C. Partitionable, stateless work scales out well because capacity is added by adding instances. A single large in-memory dataset and a per-server licence both favour scaling up. Requiring the largest instance type is itself a scale-up characteristic.
24. An architect must design a backup strategy whose recovery points survive the compromise of the account holding the production data. Which solution meets these requirements?
Answer and explanation
Answer: B. Isolating backups in a separate account with an enforced retention lock means a compromise of the production account cannot destroy them. A second Region in the same account shares the same administrative blast radius. Versioning and higher frequency both remain within the compromised account.
25. An architect must remove a single point of failure where one instance holds session state for a web tier. Which solution meets these requirements?
Answer and explanation
Answer: A. Externalising session state makes the web tier stateless, so losing an instance loses no sessions. A larger instance is still one instance. Faster detection does not prevent the outage. Snapshots restore data after a failure rather than avoiding the interruption.
26. An organization must give a central team read-only visibility into every member account without granting broad permissions. Which solution meets these requirements?
Answer and explanation
Answer: A. A StackSets-deployed read-only role reaches every account including new ones and is assumed from the central account with temporary credentials. Administrator access grants far more than visibility. Shared user credentials destroy attribution. Management account access does not reach member account resources.
27. An architect must decide how to organize accounts for an organization with production, development, and shared services workloads across three business units. Which approach is appropriate?
Answer and explanation
Answer: D. Organizational units should reflect where different policies must apply, since that is what policy inheritance acts on. Tags do not enforce separation. A single account provides no blast radius isolation. An account per workload without regard to policy creates administrative sprawl without a governance rationale.
28. An organization must detect unexpected cost increases without setting a threshold for every service. Which solution meets these requirements?
Answer and explanation
Answer: B. Cost Anomaly Detection learns each dimension's normal pattern and alerts on statistically unusual spend without preset thresholds. Per-service budgets require a threshold for each and miss anomalies within budget. Monthly invoice review is retrospective. Quarterly checks are neither timely nor anomaly-based.
29. An architect must attribute shared infrastructure cost to the business units that consume it. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, C. Tags attribute cost only once they are applied consistently and activated for billing, which requires both the standard and the activation. Per-application accounts are one attribution approach but the question concerns shared infrastructure within accounts. Reserved Instances affect price rather than attribution. Detailed monitoring reports metrics.
30. Two VPCs with overlapping CIDR ranges must exchange traffic for a specific application. Which solution meets these requirements?
Answer and explanation
Answer: D. PrivateLink connects at the service level without requiring routable, non-overlapping address space. Peering and transit gateway both require non-overlapping CIDRs. Renumbering a VPC is disruptive and often infeasible for an established workload.
31. A transit gateway must isolate production VPCs from development VPCs while both reach a shared services VPC. Which solution meets these requirements?
Answer and explanation
Answer: B. Transit gateway route tables control which attachments can reach which, so separate tables with a shared services route in each achieve isolation with a common hub. A single table routes everything to everything. Two gateways duplicate the hub. Security groups control instance reachability rather than routing between VPCs.
32. An on-premises data center needs resilient connectivity to AWS with no single point of failure in either the circuit or the AWS device. Which solution meets these requirements?
Answer and explanation
Answer: B. Separate locations and devices remove single points of failure in both the circuit and the AWS side. A VPN backup provides resilience but at lower bandwidth over the internet. Two connections at one location share the location's risk. Two virtual interfaces share the same physical connection.
33. Traffic between VPCs attached to a transit gateway must be inspected by a firewall, and the inspection VPC is in a different account. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, D. Sharing the gateway lets the inspection VPC attach from its own account, and route tables direct spoke traffic through it. Direct peering bypasses the gateway. A separate gateway breaks the topology. Appliance mode belongs on the inspection VPC attachment rather than the spokes.
34. An organization must ensure that developers can create IAM roles for their applications but cannot grant those roles permissions beyond a defined ceiling. Which solution meets these requirements?
Answer and explanation
Answer: A. A required boundary caps what any created role can do regardless of its attached policies. Full access with audit permits escalation between audits. A central team is a bottleneck. Pre-created roles cannot anticipate every application's needs.
35. A third-party SaaS provider must access resources in a customer's account, and the access must be revocable without contacting the provider. Which solution meets these requirements?
Answer and explanation
Answer: B. A cross-account role with an external ID is assumed by the provider and revoked by deleting or modifying the role unilaterally. Shared access keys are a standing credential the provider holds. A resource policy without expiry is revocable but the external ID protects against confused deputy. Root credentials must never be shared.
36. Security findings from all accounts must be aggregated centrally, and remediation must be automated for a defined set of finding types. Which solution meets these requirements?
Answer and explanation
Answer: A. Delegated administration aggregates centrally and EventBridge routes matching findings to automated remediation. Per-account manual review does not scale. Monthly export review is slow. GuardDuty alone lacks aggregation and does not cover all finding sources.
37. An architect must encrypt data in transit between two application tiers within the same VPC. Which consideration applies?
Answer and explanation
Answer: A. Encryption in transit requires the application or a proxy to negotiate TLS. VPC traffic is isolated but not encrypted at the payload level by default. Security groups filter. VPC endpoints reach AWS services rather than encrypting tier-to-tier traffic.
38. A workload must survive the failure of a dependency it calls synchronously without failing user requests. Which solution meets these requirements?
Answer and explanation
Answer: A. A circuit breaker stops calling a failing dependency and returns a fallback, which is graceful degradation. A longer timeout holds requests. Indefinite retries exhaust resources. A second Region helps the dependency's availability but the workload still needs a strategy when it fails.
39. A backup strategy must protect against an administrator accidentally deleting all backups. Which solution meets these requirements?
Answer and explanation
Answer: B. A separate account with an enforced vault lock puts backups beyond the reach of an administrator in the source account. Versioning in the same account is deletable by the same administrator. MFA adds a step rather than preventing an authorised deletion. Frequency does not protect against deletion of all copies.
40. An architect must decide whether a workload should scale up or scale out to handle growth. Which characteristic favours scaling up?
Answer and explanation
Answer: B. Unpartitionable in-memory state must live on one instance, which favours a larger one. Independent stateless requests and single-instance failure tolerance both favour scaling out. A per-core licence penalises larger instances.
41. An architect must design automatic recovery for a stateful application running on a single EC2 instance. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, C. Durable state outside the instance plus automatic replacement or recovery gives recovery without data loss. Instance store is lost with the instance. Manual snapshots require a manual restore. A larger instance is still a single instance.
42. An organization must prevent member accounts from leaving the organization. Which solution meets these requirements?
Answer and explanation
Answer: C. A service control policy denying the leave action prevents it from within the member account. Removing administrator access is broader and can be reversed by root. Config records rather than prevents. A root password governs authentication rather than the leave action.
43. Resources in a central account must be shared with member accounts without duplicating them. Which solution meets these requirements?
Answer and explanation
Answer: C. RAM shares supported resource types with organizational principals, covering new accounts automatically. Copying duplicates and drifts. Individual resource policies require per-account maintenance. Cross-account roles give access to the account rather than sharing specific resources.
44. An organization must be alerted when any member account's CloudTrail is stopped. Which solution meets these requirements?
Answer and explanation
Answer: D. The organization trail captures the StopLogging call from any account, and EventBridge alerts on it. Weekly review is slow. A Config rule per account reports status without central alerting unless aggregated. The organization trail records the event but does not by itself alert.
45. An organization must right-size EC2 instances across hundreds of accounts based on actual utilization. Which solution meets these requirements?
Answer and explanation
Answer: D. Compute Optimizer analyses utilization across the organization and recommends specific sizes. Manual metric review does not scale. Blind downsizing risks outages. Reserved Instances lock in the current sizes.
46. Reserved Instance discounts purchased in one account must benefit usage in other accounts of the organization. Which configuration is required?
Answer and explanation
Answer: C. Consolidated billing with RI sharing applies the discount to matching usage in any linked account. Per-account purchase loses the flexibility. Reserved Instances cannot be transferred between accounts. Consolidating workloads defeats the account structure.
47. A Savings Plan's commitment appears underused, and the organization must determine whether it was sized correctly. Which approach is appropriate?
Answer and explanation
Answer: D. Utilization shows how much of the commitment is used and coverage shows how much eligible usage falls outside it, which together diagnose the sizing. The total bill mixes eligible and ineligible usage. Savings Plans cannot be cancelled. Increasing usage to fit a commitment is backwards.
48. An organization must centralize outbound internet access for many VPCs rather than deploying a NAT gateway in each. Which solution meets these requirements?
Answer and explanation
Answer: D. A shared egress VPC behind a transit gateway concentrates NAT capacity. Per-VPC gateways multiply cost, peering is non-transitive and scales poorly, and public addressing exposes instances.
49. An organization must resolve private hosted zone records from an on-premises network. Which solution meets these requirements?
Answer and explanation
Answer: D. An inbound endpoint lets on-premises resolvers query Route 53. A public zone exposes internal names, replication drifts, and host files do not scale.
50. A central inspection VPC must receive traffic from many spoke VPCs and return it symmetrically. Which solution meets these requirements?
Answer and explanation
Answer: C. Appliance mode preserves flow symmetry for stateful inspection through a transit gateway. Direct peering bypasses the hub, per-spoke appliances multiply cost, and a NAT gateway is not an inspection device.
51. An organization must ensure that encryption keys used by a workload cannot be used outside a specified Region. Which solution meets these requirements?
Answer and explanation
Answer: B. KMS keys are Regional by construction, which enforces the boundary. A service control policy is a valid additional control but the key's Regionality is the primary answer, replication would extend rather than restrict use, and tags do not bound Region.
52. An organization must prevent a workload's IAM role from being assumed by a principal in another account. Which solution meets these requirements?
Answer and explanation
Answer: A. A trust policy condition on the organization prevents external assumption. A boundary caps permissions once assumed, session duration limits time, and removing policies disables legitimate use.
53. A workload must survive the loss of a Region with no data loss for committed transactions. Which solution meets these requirements?
Answer and explanation
Answer: A. Cross-Region latency makes synchronous replication impractical, so the realistic design is asynchronous replication with monitored lag. Minute-level snapshots give a larger recovery point, and read replicas are asynchronous too.
54. An architecture must limit the blast radius of a failure to a subset of users. Which solution meets these requirements?
Answer and explanation
Answer: B. Cell-based architecture bounds a failure to one partition of users. Multi-zone and multi-Region designs improve availability without limiting which users a software fault affects, and more instances do not partition.
55. An organization must apply a configuration setting across all accounts that persists as AWS adds new features to the service. Which solution meets these requirements?
Answer and explanation
Answer: A. Declarative policies maintain a service configuration as it evolves. StackSets deploy a point-in-time state, a service control policy restricts actions rather than maintaining configuration, and auditing is retrospective.
56. An organization must charge internal teams for shared infrastructure they consume. Which solution meets these requirements?
Answer and explanation
Answer: D. Metering with proportional allocation attributes shared cost accurately. Equal division ignores consumption, platform attribution hides the consumers, and estimation is unreliable.
57. An organization must forecast next quarter's AWS spend. Which solution meets these requirements?
Answer and explanation
Answer: C. Forecasting from historical usage with adjustments for known changes is the defensible method. Extrapolating one month ignores trend and seasonality, budget requests are targets, and a calculator prices a static design.