93 practice questions for Domain 2 of the AWS Certified Solutions Architect - Professional (SAP-C02) exam, which makes up 29% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 2: Design for New Solutions
58. A deployment strategy must allow an immediate return to the previous version if the new version misbehaves, without waiting for instances to be replaced. Which solution meets these requirements?
Answer and explanation
Answer: A. Blue/green keeps the previous environment intact so rollback is a traffic shift measured in seconds. Rolling strategies, with or without an additional batch, must replace instances again to revert. All-at-once has no previous environment to return to.
59. An architect must reduce the operational burden of patching and provisioning for a new three-tier application. Which combination of choices meets these requirements? (Select TWO.)
Answer and explanation
Answer: C, D. Fargate and Aurora Serverless remove instance provisioning and patching entirely, which is the stated goal. Patch baselines, snapshot scheduling, and golden AMI pipelines are all good practice but retain the operational burden the requirement asks to reduce.
60. A business continuity plan must be exercised regularly so recovery procedures are known to work. Which solution meets these requirements?
Answer and explanation
Answer: C. Only exercising the failover proves the standby can serve traffic and that the procedure works end to end. A runbook review validates understanding. Backup completion and resource existence verify preconditions rather than the outcome.
61. A relational database must be recoverable in a second Region with a recovery point objective under one minute. Which solution meets these requirements?
Answer and explanation
Answer: B. An Aurora global database replicates to a secondary Region with typical lag well under a second. Hourly snapshot copies give a recovery point up to an hour old. Multi-AZ and replicas protect against zone failure but reside in one Region. A point-in-time restore into another Region takes far longer than a minute.
62. An architect must design a backup strategy covering EBS volumes, RDS databases, EFS file systems, and DynamoDB tables under one policy with cross-Region copies. Which solution meets these requirements?
Answer and explanation
Answer: C. AWS Backup applies a single policy across many supported services with copy rules that replicate recovery points to another Region. Data Lifecycle Manager covers EBS snapshots and AMIs but not RDS, EFS, or DynamoDB. A custom function recreates the capability with more failure modes. Manual snapshots are neither scheduled nor consistent.
63. A large public web application must be protected against volumetric DDoS attacks and application-layer exploits, with cost protection against attack-driven scaling. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, D. Shield Advanced adds enhanced mitigation, response team access, and cost protection against attack-driven scaling, and WAF addresses application-layer exploits. Shield Standard is automatic but includes none of those additions. A port 443 security group permits exactly the traffic the attack uses. GuardDuty detects threats without mitigating them inline.
64. An architect must specify how a new workload's roles are scoped so no identity holds more permission than its function requires. Which approach meets these requirements?
Answer and explanation
Answer: D. A role per function scoped to specific actions and resources is least privilege, and a boundary closes the escalation path where a role can create roles. One broad role over-permits every function. A role per person does not scale and confuses identity with function. Wildcards with denies are fragile and hard to reason about.
65. A new application must remain available when an Availability Zone fails, and peak load requires 12 instances. Which solution meets these requirements at the lowest instance count?
Answer and explanation
Answer: A. Eighteen across three zones leaves twelve serving when one zone is lost, which is exactly peak at the lowest total. Twelve across three leaves eight. Twenty-four across two also survives with twelve but requires six more instances. A single zone with a standby image means an outage while capacity is rebuilt.
66. An architect must decouple a synchronous order service from a fulfilment service that is occasionally unavailable. Which solution meets these requirements?
Answer and explanation
Answer: C. A queue decouples their availability entirely, so orders are durably accepted while the consumer is down and drained when it recovers. A synchronous call with retries still fails when the service is fully down. A shared Auto Scaling group couples their failure domains. More capacity reduces but does not remove the coupling.
67. Users worldwide must be routed to the Regional endpoint nearest them, and an unhealthy Region must be removed from rotation. Which solution meets these requirements?
Answer and explanation
Answer: A. Latency routing selects the Region with the lowest measured latency for each user, and health checks remove an unhealthy endpoint. Geolocation routes by the user's country rather than by measured latency. Weighted routing distributes by proportion. Simple routing performs no health evaluation.
68. A read-heavy workload must serve a small set of frequently requested items with sub-millisecond latency. Which solution meets these requirements?
Answer and explanation
Answer: C. An in-memory cache returns repeated reads in microseconds, which is the only option that reaches sub-millisecond consistently. Read replicas still execute queries against disk-backed storage. A larger instance and higher IOPS both improve database performance without reaching in-memory latency.
69. An architect must select a database for a workload requiring millisecond key-value lookups at unpredictable scale with no capacity planning. Which solution meets these requirements?
Answer and explanation
Answer: D. DynamoDB serves key-value lookups at single-digit millisecond latency and on-demand mode absorbs unpredictable traffic without capacity planning. RDS and Aurora involve query planning and connection management. Redshift is an analytical warehouse unsuited to point lookups.
70. A new workload's data will be accessed heavily for 30 days, occasionally for 90 more, and rarely afterwards, with a seven-year retention requirement. Which solution meets these requirements at the lowest cost?
Answer and explanation
Answer: D. A predictable time-based pattern is cheapest with explicit transitions to progressively colder classes while retaining the data. Expiring at 120 days violates the retention requirement. Standard pays frequent-access rates for cold data. Intelligent-Tiering adds a monitoring charge for a pattern already understood.
71. An architect must reduce the data transfer cost of a new application serving large media files to internet users. Which solution meets these requirements?
Answer and explanation
Answer: C. CloudFront reduces per-gigabyte egress pricing relative to direct origin transfer and serves repeat requests from cache, cutting origin transfer as well. A cheaper Region changes compute price rather than egress volume. A larger instance transfers the same bytes. A colder storage class reduces storage cost while adding retrieval charges.
72. An architect must select a deployment approach for a new workload where a failed release must be reversible within seconds. Which solution meets these requirements?
Answer and explanation
Answer: C. Blue/green keeps the previous environment running so reverting is a traffic shift measured in seconds. Rolling strategies must replace instances again to revert. All-at-once has no previous environment to return to.
73. An architect must reduce the operational burden of a new workload's configuration management across hundreds of instances. Which solution meets these requirements?
Answer and explanation
Answer: D. State Manager reapplies a desired configuration on a schedule, correcting drift without operator action. User data runs only at launch and does not correct later drift. A runbook depends on people. Rebuilding from a golden AMI for every configuration change is disproportionate.
74. A new workload must adopt managed services wherever possible to reduce undifferentiated operational work. Which combination of choices supports this? (Select TWO.)
Answer and explanation
Answer: B, C. Fargate and Aurora Serverless remove instance provisioning and patching entirely. Patch baselines and snapshot automation are good practice but retain the operational burden being reduced. Combining tiers in one Auto Scaling group couples their scaling and failure domains.
75. A new workload's database must fail over to a second Region with a recovery point measured in seconds. Which solution meets these requirements?
Answer and explanation
Answer: A. An Aurora global database replicates to the secondary Region with typical lag well under a second. Cross-Region read replicas have higher and more variable lag. Fifteen-minute snapshot copies give a recovery point of up to fifteen minutes. Multi-AZ protects against zone failure within one Region.
76. An architect must design DNS failover so users are directed away from a Region whose application has failed while its infrastructure remains reachable. Which solution meets these requirements?
Answer and explanation
Answer: D. A health check against an application endpoint detects a failed application that an infrastructure reachability check would report healthy. A shorter time to live speeds propagation once a change is made but does not detect the failure. Weighted routing distributes traffic without evaluating health.
77. An architect must ensure that a disaster recovery plan for a new workload is exercised without disrupting production. Which approach is appropriate?
Answer and explanation
Answer: B. Serving real traffic from the standby is the only test that proves it can. An isolated restore confirms the data is recoverable without exercising traffic, routing, or dependencies. A runbook review validates understanding. Replication completion is a precondition.
78. An architect must design centralized monitoring so a failure in any component of a new multi-Region workload is detected proactively. Which solution meets these requirements?
Answer and explanation
Answer: C. Central aggregation with alarms on missing success signals detects a component that has stopped reporting, which an error-only alarm misses. Per-Region dashboards depend on someone looking. CPU alarms report load rather than component health. Detailed monitoring increases resolution without adding detection logic.
79. A new public API must authenticate end users and authorize requests without the application handling credentials. Which solution meets these requirements?
Answer and explanation
Answer: D. Cognito handles user authentication and issues tokens API Gateway validates, so the application never handles credentials. IAM access keys are for AWS API access rather than application end users. IP restriction authenticates a network location. A shared key identifies the caller collectively rather than individual users.
80. An architect must specify network flows for a new three-tier workload so each tier accepts traffic only from the tier above it. Which solution meets these requirements?
Answer and explanation
Answer: C. Security group referencing expresses the relationship between tiers and remains correct as instances are replaced and addresses change. CIDR-based rules permit anything in that range, including resources that are not part of the tier. Separate VPCs add complexity for a control security groups provide. Network ACLs are stateless and operate on ranges.
81. An architect must define a patch management strategy for a new workload that must remain compliant with an organizational standard. Which solution meets these requirements?
Answer and explanation
Answer: B. A baseline defines which patches are approved, a window constrains when they are applied, and the service reports compliance against the standard. Nightly unrestricted updates ignore approval and timing. Weekly rebuilds are disproportionate and still need a patched image. Operator-initiated patching is inconsistent and unreported.
82. A new application must mitigate large-scale attacks against its public endpoint while keeping legitimate traffic served. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, E. WAF filters application-layer attacks and Shield Advanced adds enhanced DDoS mitigation with response team access and cost protection. A port 443 security group permits exactly the traffic an attack uses. Larger instances absorb load rather than filtering. Monitoring observes without mitigating.
83. An architect must design a new workload so a failure in one component cannot exhaust the resources of another. Which pattern applies?
Answer and explanation
Answer: B. Bulkhead isolation gives each component its own pool so exhaustion in one cannot starve another. Backoff reduces pressure during failure without isolating resources. A shared pool is the coupling being removed. A single Auto Scaling group couples their scaling and failure domains.
84. A new workload depends on a downstream service that occasionally becomes unresponsive, causing requests to queue until the workload exhausts its threads. Which pattern applies?
Answer and explanation
Answer: A. A circuit breaker stops sending requests to a failing dependency and fails fast, which prevents thread exhaustion. A longer timeout holds threads longer. A larger pool delays exhaustion. Immediate retries add load to a service already failing.
85. An architect must ensure a new workload's Auto Scaling group replaces instances that are running but not serving requests correctly. Which configuration meets these requirements?
Answer and explanation
Answer: D. ELB health checks evaluate the application, so an instance that is reachable but not serving correctly is replaced. EC2 health checks observe only instance and hypervisor reachability. A shorter grace period may terminate instances still starting. More capacity dilutes rather than removes the failing instances.
86. A new workload must stay within a service quota that its expected growth will approach within six months. Which approach is appropriate?
Answer and explanation
Answer: C. Alarming on quota usage gives warning before requests fail, which is what prevents the outage. Graceful failure is a useful fallback but accepts the failure. Spreading across Regions adds complexity to avoid a limit that can be raised. An error rate alarm fires only once failures occur.
87. An architect must choose a routing policy so users are served from the Region nearest them, with an unhealthy Region removed automatically. Which solution meets these requirements?
Answer and explanation
Answer: D. Latency routing selects the Region with the lowest measured latency for each user and health checks remove an unhealthy endpoint. Geolocation routes by the user's country rather than measured latency. Weighted routing distributes by proportion. Multivalue returns several answers without latency awareness.
88. A new workload writes large objects and reads them repeatedly from many Regions. Which solution meets these requirements?
Answer and explanation
Answer: A. CloudFront caches objects at edge locations near users, which serves repeated global reads without replicating storage. Replicating to every Region multiplies storage cost and complexity. EBS volumes are zonal and must be populated per instance. EFS file systems are Regional and cannot be mounted across Regions.
89. A new analytics workload issues complex joins over 30 TB with high concurrency. Which solution meets these requirements?
Answer and explanation
Answer: A. Redshift is a columnar massively parallel warehouse built for complex joins at this volume under concurrency. Athena performance varies with file layout and concurrent query limits. RDS is transactional and not designed for 30 TB analytics. DynamoDB cannot express complex joins.
90. An architect must design a new workload to absorb a spike that arrives faster than the downstream system can process. Which pattern applies?
Answer and explanation
Answer: D. A queue decouples arrival rate from processing rate and absorbs the spike durably. Sizing for the largest spike pays for that capacity continuously. Rejecting requests loses work. A longer timeout holds connections while the backlog grows.
91. A new workload requires a purpose-built database for highly connected data queried by relationship depth. Which solution meets these requirements?
Answer and explanation
Answer: C. Neptune is a graph database built for traversing relationships efficiently. DynamoDB is key-value and document oriented. Redshift is an analytical warehouse. A relational engine can model relationships but multi-hop traversal requires repeated joins that degrade with depth.
92. An architect must model the data transfer cost of a new multi-Region design before it is built. Which approach is appropriate?
Answer and explanation
Answer: D. Data transfer is frequently a significant and surprising proportion of a multi-Region bill, so it must be modelled per boundary before the design is committed. Assuming it is negligible is the common error. Measuring after the fact is too late to influence the design. Omitting it understates the cost.
93. A new workload has a predictable steady baseline and unpredictable bursts. Which purchasing approach is appropriate?
Answer and explanation
Answer: B. Committing only to the predictable baseline captures the discount without paying for unused commitment, while bursts are served flexibly. Committing to the peak pays for capacity that is idle most of the time. All On-Demand forgoes the discount on predictable usage. Spot is unsuitable for a workload that cannot absorb interruption.
94. An architect must plan an upgrade path for a workload to adopt a new major version of a managed service with breaking changes. Which approach is appropriate?
Answer and explanation
Answer: B. A parallel environment allows validation before commitment and a clean rollback. In-place upgrade with breaking changes risks an outage with no easy reversal. Delaying to deprecation forces the upgrade under pressure. Fixing breakage in production experiments on users.
95. A new workload must be deployed across many accounts with a consistent configuration that account owners cannot alter. Which solution meets these requirements?
Answer and explanation
Answer: A. StackSets deploy consistently and a service control policy prevents local modification. Manual deployment drifts. Trusting owners is not enforcement. Owner-deployed templates vary in execution.
96. A workload's change management process must ensure that every infrastructure change is reviewed and reversible. Which approach is appropriate?
Answer and explanation
Answer: A. Version-controlled infrastructure with reviewed merges and pipeline rollback makes every change reviewed and reversible by construction. Console changes with tickets are unreviewed and hard to reverse. Direct changes by anyone skip review. Quarterly audit is retrospective.
97. A workload's recovery point objective is one hour, and its database is replicated asynchronously to a second Region. Which additional consideration applies?
Answer and explanation
Answer: D. Asynchronous replication can lag under load, so the lag must be monitored against the objective. It does not guarantee the objective. Synchronous replication across Regions is generally impractical for latency. Relaxing the objective changes the requirement rather than meeting it.
98. An architect must design DNS so that failover to a second Region does not depend on the primary Region being available to make the change. Which solution meets these requirements?
Answer and explanation
Answer: A. Route 53 health-checked failover records operate globally and do not depend on the failed Region. A script in the primary Region fails with it. Manual update is slow and error-prone. A load balancer in the primary Region is unavailable when that Region fails.
99. A disaster recovery test must be performed without affecting production users. Which approach is appropriate?
Answer and explanation
Answer: A. A synthetic or mirrored test exercises the failover path without risking users. Failing over production during business hours risks users. Skipping testing leaves the plan unvalidated. Restore alone tests one step.
100. A multi-Region application's data must be readable and writable in both Regions with conflict resolution. Which solution meets these requirements?
Answer and explanation
Answer: C. Global tables accept writes in every Region and resolve conflicts with last-writer-wins. Read replicas are read-only. Aurora global database has a single writer Region. Nightly copies are neither active nor current.
101. An organization must confirm that its standby Region has sufficient capacity and quota to absorb production load before a failover is needed. Which solution meets these requirements?
Answer and explanation
Answer: D. Readiness checks verify continuously that the standby can take load. Default quotas may be insufficient. A one-time check goes stale. Requesting increases during a failover adds delay to an incident.
102. Centralized monitoring must detect a failure in a Region's application before the Region's own monitoring can report it. Which approach is appropriate?
Answer and explanation
Answer: B. External canaries detect a failure even when the Region's own monitoring is impaired. Regional alarms may be unavailable in a Regional failure. User reports are slow. Status pages describe AWS services rather than the application.
103. A new workload must call AWS services from EC2 instances without the instances holding any credentials. Which solution meets these requirements?
Answer and explanation
Answer: C. An instance profile supplies automatically rotated temporary credentials with no secret on the instance. User data and configuration files store long-term keys. Retrieving keys from Secrets Manager still places long-term keys on the instance.
104. A new application's secrets must be rotated automatically, and the application must not need redeployment when they rotate. Which solution meets these requirements?
Answer and explanation
Answer: A. Retrieving from Secrets Manager at use time picks up rotated values with no redeployment. Environment variables and configuration files require a restart or redeployment. Hardcoding requires a code change.
105. A new workload must reach Amazon S3 and DynamoDB from private subnets without a NAT gateway. Which solution meets these requirements?
Answer and explanation
Answer: B. Gateway endpoints exist for exactly these two services and carry no hourly charge. Interface endpoints work but bill hourly and gateway endpoints are the intended option here. Public addresses expose the instances. A proxy adds a component to manage.
106. A new web application must be protected against attacks that exploit application logic rather than known signatures. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, C. Rate limiting bounds abuse and application-level checks address logic flaws WAF cannot see. Managed rule groups cover known patterns rather than business logic. Instance size and Shield Standard do not address logic attacks.
107. An architect must decide how to apply patches to a new fleet where instances are replaced frequently. Which approach is appropriate?
Answer and explanation
Answer: B. An immutable image pipeline patches once and replaces instances, which suits a fleet that already cycles. In-place patching of short-lived instances is wasted effort. Manual patching is inconsistent. Short-lived instances are still exposed while running.
108. A new workload must remain available during an Availability Zone failure without over-provisioning by more than 50 percent. Which configuration meets these requirements?
Answer and explanation
Answer: B. Three zones sized for peak across any two survives a zone loss at 50 percent over-provisioning. Two zones each at full peak is 100 percent over-provisioning. One zone does not survive zone loss. Three zones at exactly peak total lose a third of capacity when a zone fails.
109. An application's components communicate through a message queue, and a consumer occasionally fails to process a message. Which configuration prevents a poison message from blocking the queue?
Answer and explanation
Answer: A. A dead-letter queue with a receive count limit isolates a message that fails repeatedly. A longer visibility timeout delays each retry. Deleting on first failure loses messages that fail transiently. Indefinite retries block the queue.
110. A new workload must recover from a database failover with minimal application disruption. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: C, E. The cluster endpoint follows failover, and retry with backoff reconnects after the brief interruption. A hardcoded address points at the old primary. Disabling timeouts hangs on a dead connection. A single long-lived connection drops at failover with no recovery.
111. A new application must fail over between Regions based on the health of the application rather than the infrastructure. Which health check configuration is appropriate?
Answer and explanation
Answer: C. An application endpoint check detects an application that is running but broken. A load balancer check confirms reachability. CPU and status checks report infrastructure health.
112. A new workload must scale on a metric that reflects user-facing performance rather than resource utilization. Which configuration is appropriate?
Answer and explanation
Answer: D. Latency or requests per target scales on what users experience. CPU may not correlate with user-facing performance. Scheduled scaling does not respond to actual demand. Manual scaling is slow.
113. A new application must be designed so a failure in the reporting subsystem cannot affect order processing. Which pattern applies?
Answer and explanation
Answer: B. Asynchronous decoupling isolates failure domains. Shared process and synchronous calls couple them. A shared Auto Scaling group couples scaling and replacement.
114. A new workload must serve global users with dynamic content that cannot be cached. Which solution meets these requirements?
Answer and explanation
Answer: A. Multi-Region or Global Accelerator reduces the distance dynamic requests travel. CloudFront without caching still terminates at the edge but offers limited benefit for fully dynamic content compared with regional presence. Instance size and compression do not shorten distance.
115. A new database workload has unpredictable traffic with long idle periods. Which solution meets these requirements?
Answer and explanation
Answer: A. Serverless v2 scales capacity to load including down toward minimum during idle. Peak-sized provisioning pays through idle periods. Read replicas add read capacity without scaling down. Provisioned DynamoDB capacity does not scale down automatically without auto scaling and the question implies a relational workload.
116. An architect must select storage for a workload requiring shared POSIX file access from many instances with high throughput. Which solution meets these requirements?
Answer and explanation
Answer: D. EFS and FSx for Lustre both provide shared POSIX access, with Lustre at higher throughput. EBS attaches to one instance in the general case. S3 lacks full POSIX semantics. Instance store is local and ephemeral.
117. A new workload's read traffic is dominated by a small set of frequently accessed keys. Which pattern is appropriate?
Answer and explanation
Answer: B. A cache serves hot keys in microseconds and removes the load from the store. Read replicas still execute each read. A larger instance serves the same reads faster at higher cost. Partitioning spreads keys but the hot keys remain hot.
118. A new workload must process a very large batch job as quickly as possible with the ability to use spare capacity. Which solution meets these requirements?
Answer and explanation
Answer: A. Batch schedules across many instance types and capacity pools, using Spot for cost and On-Demand for reliability. A single instance limits parallelism. A fixed group forgoes Spot. Lambda has a duration limit unsuited to long batch work.
119. A new workload will run steadily for three years, and the organization wants the largest possible discount with flexibility to change instance family. Which purchasing option meets these requirements?
Answer and explanation
Answer: A. A three-year Compute Savings Plan gives the deepest commitment discount while following changes in family and Region. Standard RIs lock to a family. One-year Convertibles give a smaller discount. On-Demand forgoes the discount entirely.
120. A new workload will generate large volumes of logs that must be retained for seven years but rarely read. Which solution meets these requirements at the lowest cost?
Answer and explanation
Answer: D. Deep Archive is the cheapest class for rarely read long-term data. CloudWatch Logs and S3 Standard are priced for active access. EBS is priced for attached block storage.
121. An architect must design a new workload so that its cost can be tracked per customer. Which approach is appropriate?
Answer and explanation
Answer: C. Tagging attributes dedicated resources and metering allocates shared ones. Equal shares are inaccurate. An account per customer may be appropriate for large customers but does not scale to many. Workload-level tracking gives no per-customer figure.
122. A new workload must be deployed across accounts with each environment's configuration held separately from the template. Which solution meets these requirements?
Answer and explanation
Answer: D. External configuration referenced at deployment keeps one template. Separate and hardcoded templates drift, and manual entry is error-prone.
123. A new workload's deployment must be validated in a production-like environment before release. Which solution meets these requirements?
Answer and explanation
Answer: D. A staging environment built from the same definition is representative. A hand-built environment differs, production validation risks users, and unit tests do not exercise the deployment.
124. A new workload must support deploying individual components independently. Which solution meets these requirements?
Answer and explanation
Answer: A. Separate stacks with defined interfaces allow independent deployment. A single stack couples them, scheduled joint deployment removes independence, and manual ordering does not scale.
125. An architect must choose a deployment approach for a workload where the database schema change is not backward compatible. Which solution meets these requirements?
Answer and explanation
Answer: C. Expand and contract migration keeps both versions working during the rollout. Simultaneous deployment breaks one version, downtime is what the requirement avoids, and schema rollback is often impossible once data is written.
126. A new workload's recovery must be tested without affecting the production environment. Which solution meets these requirements?
Answer and explanation
Answer: A. Recovering into an isolated environment from the real recovery points validates the procedure safely. Recovering over production risks it, job completion is a precondition, and a runbook review is not a test.
127. A new workload's data must be recoverable after a logical corruption that replicates to the standby. Which solution meets these requirements?
Answer and explanation
Answer: B. Replication copies corruption, so independent point-in-time backups are required. Replicas and additional copies all carry the corrupted data.
128. A new workload must continue accepting writes during a Regional failure. Which solution meets these requirements?
Answer and explanation
Answer: D. Accepting writes during a Regional failure requires an active-active design with conflict resolution. Active-passive, pilot light, and warm standby all require a failover before writes resume.
129. A business continuity plan must define what the business does while a workload is unavailable. Which solution meets these requirements?
Answer and explanation
Answer: A. Business continuity covers what the business does during the outage as well as how the system recovers. A purely technical plan leaves the business without a process, assuming a short outage is optimistic, and after-the-fact documentation is not a plan.
130. An architect must decide the recovery point objective for a new workload. Which solution meets these requirements?
Answer and explanation
Answer: A. The objective derives from business tolerance and then constrains the technology. A universal zero is expensive and often unnecessary, deriving it from the available method inverts the logic, and the longest interval ignores the requirement.
131. A new workload must encrypt data with a key that can be revoked instantly across all copies. Which solution meets these requirements?
Answer and explanation
Answer: D. A single controlling key can be disabled or its imported material deleted, rendering every copy unreadable at once. Separate keys require individual revocation, deleting copies is slow and may miss some, and rotation retains old material for decryption.
132. A new workload must restrict which principals can decrypt its data independently of who can read the objects. Which solution meets these requirements?
Answer and explanation
Answer: A. With SSE-KMS the key policy is a second independent gate. SSE-S3 has no separate permission check, a shared client-side key is held by everyone who has it, and Block Public Access prevents public exposure.
133. A new workload must ensure that a compromised application cannot read other tenants' data. Which solution meets these requirements?
Answer and explanation
Answer: D. Per-tenant credentials mean a compromise reaches only the tenant being served. Application filtering relies on code correctness, a shared key permits decryption of everything, and prefixes alone are not a permission boundary.
134. A new workload must authenticate service-to-service calls without shared secrets. Which solution meets these requirements?
Answer and explanation
Answer: A. IAM authentication verifies the caller's role identity without a shared secret. API keys and bearer tokens are shared secrets, and IP restriction authenticates a network location.
135. A new workload must ensure that a misconfigured resource policy cannot expose data outside the organization. Which solution meets these requirements?
Answer and explanation
Answer: B. A resource control policy bounds access to organization resources irrespective of their resource policies. Review depends on a reviewer, Access Analyzer reports rather than prevents, and denying policy changes blocks legitimate updates.
136. A new workload must log every access to sensitive data for later audit. Which solution meets these requirements?
Answer and explanation
Answer: C. Data events record object-level access with the caller and must be enabled in advance. Management events cover resource-level operations, access logging is best-effort, and quarterly review is not a log.
137. A new workload must be prevented from being deployed with an overly permissive security group. Which solution meets these requirements?
Answer and explanation
Answer: C. Policy-as-code in the pipeline prevents the deployment. Post-deployment review and Config rules both detect after the resource exists, and creation restrictions do not evaluate the configuration.
138. A new workload must degrade gracefully when a non-essential dependency is unavailable. Which solution meets these requirements?
Answer and explanation
Answer: C. Classifying dependencies and continuing without the non-essential ones is graceful degradation. Failing on any dependency, retrying indefinitely, and removing useful features all produce worse outcomes.
139. A new workload must avoid a retry storm when a downstream service recovers from an outage. Which solution meets these requirements?
Answer and explanation
Answer: B. Jitter spreads retries so a recovering service is not immediately overwhelmed. Immediate and fixed-schedule retries converge, and extra capacity absorbs rather than prevents the storm.
140. A new workload must continue operating when its configuration store is briefly unavailable. Which solution meets these requirements?
Answer and explanation
Answer: A. A local cache with defined staleness tolerance survives a brief outage. Failing and retrying both block, and embedding configuration removes the ability to change it without redeployment.
141. An architect must verify a new workload meets its availability target before launch. Which solution meets these requirements?
Answer and explanation
Answer: C. Modelling and then validating with fault injection tests the design against the target. Published figures ignore how components combine, multi-zone alone does not guarantee a figure, and measuring afterwards is too late.
142. A new workload must serve a read-heavy API with predictable sub-10-millisecond latency. Which solution meets these requirements?
Answer and explanation
Answer: A. An in-memory cache reaches single-digit millisecond and lower latency consistently. Replicas, larger instances, and higher IOPS all still execute queries against disk-backed storage.
143. A new workload must process a large dataset in parallel with results combined at the end. Which solution meets these requirements?
Answer and explanation
Answer: B. Fan-out with aggregation parallelises the work. Sequential processing, scheduled batches, and more memory all leave the work serialized.
144. A new workload's static assets must be delivered with the lowest latency to a global audience. Which solution meets these requirements?
Answer and explanation
Answer: D. A content delivery network caches at the edge near users. Origin serving leaves distance, per-Region replication is complex and costly, and compression reduces bytes without shortening distance.
145. An architect must select a data store for a workload requiring flexible queries across many attributes. Which solution meets these requirements?
Answer and explanation
Answer: B. Matching the store to the access patterns is the selection criterion. Scanning a key-value store for non-key attributes is expensive, throughput alone ignores query capability, and familiarity is a constraint rather than a criterion.
146. A new workload's cost must be estimated before any resources are provisioned. Which solution meets these requirements?
Answer and explanation
Answer: C. Modelling each component's usage including transfer produces a defensible estimate. Similar workloads differ, provisioning first is after the fact, and linear scaling by users ignores architecture.
147. A new workload must avoid paying for capacity during a lengthy development period. Which solution meets these requirements?
Answer and explanation
Answer: D. Usage-based services cost little when development is intermittent. Production-sized provisioning, reservations, and large instances all pay for idle capacity.
148. An architect must decide whether a managed service justifies its price over a self-managed equivalent. Which solution meets these requirements?
Answer and explanation
Answer: C. Total cost including operational effort and risk is the comparison. Hourly charges omit the largest component, and choosing on appearance or convenience is not analysis.
149. A new workload's storage cost must be minimized without knowing the access pattern in advance. Which solution meets these requirements?
Answer and explanation
Answer: B. Intelligent-Tiering suits unknown patterns by responding to observed access. Standard pays frequent-access rates, Deep Archive imposes retrieval delay, and fixed transitions require a known pattern.
150. An architect must build cost awareness into a new workload's design. Which solution meets these requirements?
Answer and explanation
Answer: A. Tagging from the outset and defining cost metrics makes cost visible to the team building it. Post-hoc review, account-level budgets, and delegating to finance all detach cost from design decisions.