Continuous Improvement for Existing Solutions

Domain 3: Continuous Improvement for Existing Solutions

81 practice questions for Domain 3 of the AWS Certified Solutions Architect - Professional (SAP-C02) exam, which makes up 25% of its scored content. Your answers count towards one score and one timer for the whole exam.

Domain 3: Continuous Improvement for Existing Solutions

25% of scored content · 81 practice questions

151. An existing workload produces alerts that operators routinely resolve with the same manual steps. Which solution most improves operational excellence?

Answer and explanation

Answer: C. Encoding a known remediation and triggering it from the alarm removes the toil and records every step in execution history. Raising the threshold hides the condition. Better documentation makes manual work easier rather than unnecessary. A larger rotation spreads the toil rather than eliminating it.

152. An organization must verify that its recovery actions work under realistic failure conditions, with a guardrail that halts the test if impact spreads. Which solution meets these requirements?

Answer and explanation

Answer: A. Fault Injection Service runs defined experiments with stop conditions that halt automatically if a guardrail alarm fires. Manual termination has no guardrail and is not repeatable. A restore test measures recovery time without exercising the live failure path. A procedural review validates understanding rather than behaviour.

153. An audit finds that several roles in an existing environment hold permissions they have never used. Which solution meets these requirements?

Answer and explanation

Answer: C. Unused access analysis reports roles and permissions that have gone unexercised over a configured period, so removal is evidence-based. Cutting first and fixing failures causes outages during real operations. Deleting roles reactively breaks workloads. A boundary permitting the same actions narrows nothing.

154. An existing environment stores database credentials in application configuration files across many instances. Which solution meets these requirements?

Answer and explanation

Answer: B. Secrets Manager stores the value encrypted, rotates it on a schedule, and serves it through an instance role with no file to distribute. A String parameter is neither encrypted nor rotated. Encrypting the file still places the plaintext on the host once read. Manual rotation with redistribution is the burden being removed.

155. An organization must ensure that vulnerabilities detected in running workloads trigger an automated response rather than waiting for a review cycle. Which solution meets these requirements?

Answer and explanation

Answer: A. Routing findings to an automated runbook closes the gap between detection and remediation and records each step. A weekly meeting and quarterly analysis both leave the vulnerability in place. More frequent scanning detects sooner without acting.

156. An existing global application suffers high latency for users far from its single Region, and its traffic is dynamic and not cacheable. Which solution meets these requirements?

Answer and explanation

Answer: A. Global Accelerator routes traffic onto the AWS backbone from the nearest edge, which reduces latency for dynamic content that cannot be cached. CloudFront with caching disabled still terminates at the edge but is built around caching and offers less benefit for this profile. Read replicas address database reads rather than application latency. Larger instances do not shorten distance.

157. An architect must identify the bottleneck in an existing multi-tier application where end-to-end latency has increased. Which solution meets these requirements?

Answer and explanation

Answer: A. X-Ray attributes latency to individual segments across the request path, which localises the bottleneck. CPU metrics show load without tying it to a request path. Scaling everything is expensive guesswork. Error logs identify failures rather than slow but successful calls.

158. An existing workload has a single NAT gateway serving private subnets in three Availability Zones. Which change most improves reliability?

Answer and explanation

Answer: D. A NAT gateway per zone removes the single point of failure and also eliminates cross-zone data charges. A second gateway in the same zone fails with that zone. A NAT instance is less available than a managed gateway even in an Auto Scaling group. Subnet sizing is unrelated to the dependency.

159. An existing application approaches a service quota during traffic peaks, and requests begin failing. Which solution meets these requirements?

Answer and explanation

Answer: C. Alarming on quota usage warns before requests fail, which is what prevents the outage. An error rate alarm fires only once failures have occurred. Backoff handles transient throttling without raising the ceiling. Spreading across Regions adds complexity to avoid a limit that can be increased.

160. An architect must identify underutilized resources across an existing estate and size them correctly. Which solution meets these requirements?

Answer and explanation

Answer: C. Compute Optimizer analyses utilization and recommends specific configurations, and the Cost and Usage Report shows what each resource costs. Cutting the largest line items ignores whether they are justified. Blind halving risks outages. Budget alerts report spend without identifying waste.

161. An existing workload's data transfer costs are dominated by traffic from private subnets to Amazon S3 through a NAT gateway. Which solution meets these requirements?

Answer and explanation

Answer: A. A gateway endpoint costs nothing and removes both the NAT data processing charge and the traffic from the NAT path. Public subnets trade a cost problem for a security exposure. A NAT instance shifts cost to a managed instance and scales poorly. Transfer Acceleration adds a premium.

162. An existing workload's deployments require a manual configuration step that operators occasionally omit. Which improvement is appropriate?

Answer and explanation

Answer: D. Encoding the step in the pipeline removes the possibility of omission. A more prominent checklist entry still relies on a person. A verifier adds a second person who can also forget. Logging omissions records the failure without preventing it.

163. An architect must prioritize automation opportunities across an existing solution stack. Which criterion is most appropriate?

Answer and explanation

Answer: D. Frequency multiplied by manual effort and risk identifies where automation returns most, which is the standard prioritisation. Technical interest, component age, and current training levels do not measure the value of automating.

164. An existing workload's logging strategy produces high volumes that are rarely queried after the first week. Which improvement is appropriate?

Answer and explanation

Answer: A. A short retention in the queryable store with older logs moved to cheaper storage matches cost to access pattern while retaining the data. Reducing verbosity loses detail needed during incidents. Deleting after a week fails most retention requirements. Indefinite retention in the expensive store is the cost being addressed.

165. An audit of an existing environment must establish whether any resource policy grants access outside the organization. Which solution meets these requirements?

Answer and explanation

Answer: D. Access Analyzer evaluates resource and trust policies for access outside the defined zone of trust and reports it continuously. Manual review does not scale and is point-in-time. CloudTrail records access that occurred rather than access that is permitted. GuardDuty detects threat activity.

166. An existing environment stores long-lived IAM access keys on application servers. Which improvement is appropriate?

Answer and explanation

Answer: B. An instance profile supplies automatically rotated temporary credentials with no secret stored on the host, which removes the exposure entirely. Rotation, encryption at rest, and IP restriction all reduce risk while the long-lived credential remains.

167. An existing environment must be assessed continuously for resources that drift from a required security configuration. Which solution meets these requirements?

Answer and explanation

Answer: B. A conformance pack evaluates resources continuously against rules and remediation corrects drift automatically. A quarterly review leaves months of drift undetected. CloudTrail records changes without evaluating compliance. Inspector assesses software vulnerabilities rather than configuration.

168. An existing environment must prioritize its response to detected vulnerabilities rather than treating all findings equally. Which approach is appropriate?

Answer and explanation

Answer: A. Severity combined with exposure and business criticality directs effort where the consequence of exploitation is greatest. Detection order, resource count, and per-service totals all ignore how much harm a given finding could cause.

169. An existing workload's performance target must be expressed so improvement can be measured objectively. Which formulation is appropriate?

Answer and explanation

Answer: D. A percentile target for a specific operation under stated load is measurable and reflects the experience of the slowest users. A subjective statement cannot be measured. An average across all operations hides the slow tail and mixes unlike work. Instance count is an input rather than an outcome.

170. An architect must evaluate a proposed performance remediation before recommending it. Which approach is appropriate?

Answer and explanation

Answer: D. Measuring the change against a baseline under representative load establishes whether it helps this workload. Published specifications describe a different context. Applying it in production experiments on users. A practice being recognised does not establish its effect here.

171. An existing workload's bottleneck must be identified before any change is made. Which approach is appropriate?

Answer and explanation

Answer: B. Instrumenting the request path localises the time, which directs the remediation. Scaling everything is expensive guesswork. A diagram shows structure rather than behaviour. Cost comparison does not identify a performance constraint.

172. An existing workload's growth trend must be understood before capacity decisions are made. Which approach is appropriate?

Answer and explanation

Answer: C. Projection requires enough history to distinguish trend from seasonal variation. A single month's peak may be seasonal rather than representative. A week's average understates peaks. Provisioning to the budget ignores what the workload needs.

173. An existing workload has a single database instance with no standby. Which improvement most directly addresses reliability?

Answer and explanation

Answer: C. A Multi-AZ deployment maintains a standby in another zone and fails over automatically, which removes the single point of failure. More frequent backups shorten data loss after a failure without preventing the outage. A larger instance is still one instance. A replica in the same zone shares the zone's failure.

174. An existing workload relies on a component that cannot be made redundant. Which approach is appropriate?

Answer and explanation

Answer: A. When redundancy is unavailable, the available levers are limiting the blast radius through graceful degradation and knowing how long recovery takes. Accepting the risk without analysis leaves both unknown. A larger instance reduces failure probability and closer monitoring shortens detection time, but neither limits the impact when the component does fail.

175. An architect must identify resources that are provisioned but never used across a large existing estate. Which solution meets these requirements?

Answer and explanation

Answer: C. Trusted Advisor and Compute Optimizer identify idle and over-provisioned resources, and the Cost and Usage Report attributes cost to each. Invoice review aggregates by service rather than resource. Self-reporting is inconsistent. Terminating untagged resources risks deleting production.

176. An existing workload's storage cost is dominated by data that is rarely accessed after 60 days, with unpredictable access thereafter. Which solution meets these requirements?

Answer and explanation

Answer: A. Intelligent-Tiering suits unpredictable access because it moves objects between tiers automatically without retrieval charges for the frequent and infrequent tiers. A fixed transition to deep archive imposes retrieval delay and cost on unpredictable access. Expiry deletes data that is still needed. Keeping everything in Standard is the cost being addressed.

177. An architect must design a billing alarm that gives useful warning rather than firing at the end of the month. Which approach is appropriate?

Answer and explanation

Answer: D. A forecast-based alarm warns while there is still time to act within the period. An alarm at the full budget fires once the money is spent. Invoice review is entirely retrospective. Resource count does not track spend.

178. An existing workload's runbooks are out of date, and operators improvise during incidents. Which improvement is appropriate?

Answer and explanation

Answer: D. Executable, tested, versioned automation stays current because it is exercised and changes with the infrastructure. Annual document review goes stale between reviews. Operator knowledge is not transferable. Ticket records are retrospective.

179. An existing workload's deployment process requires four hours of downtime for each release. Which improvement is appropriate?

Answer and explanation

Answer: D. Zero-downtime deployment removes the outage rather than scheduling around it. Less frequent, overnight, or batched releases reduce or relocate the downtime without eliminating it and increase the risk per release.

180. An existing workload has no way to know whether a recent change caused a performance regression. Which improvement is appropriate?

Answer and explanation

Answer: A. Baselines with deployment markers make a change's effect visible. User impressions are unreliable. Monthly comparison mixes many changes. Blind upsizing hides regressions at increased cost.

181. An existing workload's configuration is managed by hand, and instances drift from the expected state. Which solution meets these requirements?

Answer and explanation

Answer: D. Scheduled desired-state enforcement corrects drift automatically. Weekly rebuilds are disruptive and still allow drift between rebuilds. Quarterly audit finds drift late. Restricting access reduces but does not correct drift.

182. An existing environment must retain data for a regulatory period and delete it afterwards, with proof that deletion occurred. Which approach is appropriate?

Answer and explanation

Answer: B. Lifecycle expiry deletes on schedule and audit records prove it. Manual deletion is unreliable. Indefinite retention violates the deletion requirement. A colder class retains the data.

183. An existing environment has resources that are not compliant with encryption requirements, and the team must find and fix them at scale. Which approach is appropriate?

Answer and explanation

Answer: A. Config rules with remediation find and fix non-compliant resources continuously. Manual review does not scale. Reminders rely on owners. Encryption by default addresses only new resources.

184. A security review must confirm that every layer of an existing workload has appropriate controls, not just the perimeter. Which approach is appropriate?

Answer and explanation

Answer: C. Defence in depth requires controls at every layer so a bypass of one is caught by another. Reviewing only the perimeter, only the firewall, or only IAM leaves other layers unexamined.

185. An existing workload's user actions must be traceable end to end across services for compliance. Which approach is appropriate?

Answer and explanation

Answer: A. A propagated correlation identifier ties every log entry for a request together. Timestamps are ambiguous under concurrency. Entry-point logging misses downstream actions. Independent review cannot connect the entries.

186. An existing environment must respond automatically when a vulnerability is detected in a running container. Which approach is appropriate?

Answer and explanation

Answer: A. Automated redeployment from a patched image closes the vulnerability without manual delay. Email and logging leave it open. Stopping the container causes an outage without fixing the image.

187. An existing environment must implement a backup process that is verified rather than assumed to work. Which approach is appropriate?

Answer and explanation

Answer: D. Only a test restore proves a backup is usable. Job completion, file existence, and configuration review do not confirm the data can be restored and is intact.

188. An existing workload's performance target must be defined so it can be measured and enforced. Which formulation is appropriate?

Answer and explanation

Answer: D. A percentile target for a named operation over a window is measurable and reflects tail latency. Subjective and average formulations are unmeasurable or hide the tail. Competitor comparison is not a measurable internal target.

189. An architect must propose a managed service to replace a self-managed component in an existing workload. Which justification is appropriate?

Answer and explanation

Answer: D. A proposal must weigh operational burden and risk against cost and capability. Recency, vendor recommendation, and peer usage are not analysis.

190. An existing workload's database is the bottleneck under load, and the queries cannot be changed. Which combination of steps meets these requirements? (Select TWO.)

Answer and explanation

Answer: C, E. Read replicas and caching both reduce load on the primary without changing queries. A larger connection pool and more application instances increase load on the bottleneck. Backup frequency is unrelated to query load.

191. An existing workload's right-sizing must be based on evidence rather than guesswork. Which approach is appropriate?

Answer and explanation

Answer: B. Utilization analysis with tooling recommendations grounds the decision in evidence. Guessing, copying another workload, and inertia are not evidence.

192. A performance bottleneck in an existing workload is suspected to be network-related. Which diagnostic is appropriate?

Answer and explanation

Answer: D. Measurement against the instances' limits establishes whether the network is the constraint. Blind upsizing and zone consolidation may help or may not, without diagnosis. Enhanced networking is a possible remedy rather than a diagnostic.

193. An existing workload's usage has grown steadily, and capacity must be planned to stay ahead. Which approach is appropriate?

Answer and explanation

Answer: D. Projecting the trend identifies the constraint and its timing so expansion is planned rather than reactive. Waiting for errors or full utilization means an outage. Blind doubling wastes cost.

194. An existing workload has a self-managed message broker on a single instance. Which improvement most directly addresses reliability?

Answer and explanation

Answer: C. A managed multi-AZ broker removes the single point of failure and the operational burden. A larger instance remains single. Snapshots aid recovery without preventing the outage. Monitoring detects rather than prevents.

195. An existing workload's self-healing must be improved so it recovers from common failures without operator action. Which combination of steps meets these requirements? (Select TWO.)

Answer and explanation

Answer: B, D. Automatic replacement and automated remediation both remove the operator from the recovery path. A larger rotation, documentation, and dashboards all still depend on a person acting.

196. An existing environment has EBS volumes and snapshots that are no longer attached to anything. Which approach is appropriate?

Answer and explanation

Answer: D. Identifying and verifying before deletion recovers cost without risk. Deleting everything unattached may remove volumes awaiting reattachment. Unused storage still costs. EBS volumes have no cheaper class to move to.

197. An existing workload's data transfer costs are unexpectedly high. Which approach is appropriate?

Answer and explanation

Answer: D. Transfer types are priced differently and the fix depends on which dominates. Uniform reduction and compression may not address the dominant cost. Consolidating to one zone sacrifices availability.

198. An existing environment must be reviewed for cost at a granular level to find specific waste. Which source provides this?

Answer and explanation

Answer: C. The Cost and Usage Report provides per-resource detail queryable by any dimension. The invoice total and service-level views aggregate away the detail. Free Tier usage is unrelated.

199. An existing workload runs on Spot Instances but is frequently interrupted. Which improvement reduces interruptions?

Answer and explanation

Answer: B. Diversification across pools reduces the chance all are reclaimed together. A single pool concentrates interruption risk. Switching to On-Demand removes the saving. Fewer instances do not reduce interruption frequency per instance.

200. An existing workload's incidents are resolved but the same causes recur. Which solution meets these requirements?

Answer and explanation

Answer: A. Structured reviews with tracked actions address recurrence. Ticket closure records without learning, more responders handle more incidents, and dashboards improve visibility without preventing recurrence.

201. An existing workload's operational knowledge is held by a small number of engineers. Which solution meets these requirements?

Answer and explanation

Answer: C. Executable runbooks and automation transfer knowledge into a form anyone can apply and that stays current through use. Wikis, rotation changes, and recordings all go stale.

202. An existing workload's changes frequently cause incidents. Which solution meets these requirements?

Answer and explanation

Answer: A. Measuring failure rate and deploying progressively with verification reduces the impact of a bad change. Fewer changes make each one larger and riskier, more approvals slow delivery without catching defects, and quiet periods limit exposure without preventing failure.

203. An existing workload's operators cannot tell whether a deployment caused a metric change. Which solution meets these requirements?

Answer and explanation

Answer: B. Deployment annotations make the correlation immediate. Manual correlation is slow, fewer deployments reduce information, and more metrics add noise without linking to deployments.

204. An existing workload's operational tasks are performed differently by each engineer. Which solution meets these requirements?

Answer and explanation

Answer: B. Automation makes execution identical and auditable. Procedures depend on adherence, single ownership creates a bottleneck, and weekly review is retrospective.

205. An existing workload's operational metrics are collected but never acted on. Which solution meets these requirements?

Answer and explanation

Answer: B. Separating actionable metrics with thresholds from informational ones focuses attention. More metrics, larger dashboards, and weekly reviews all increase volume without creating action.

206. An existing environment has IAM roles whose permissions have grown over time. Which solution meets these requirements?

Answer and explanation

Answer: C. Evidence of actual use directs safe removal. Cutting first causes outages, deleting apparently unused roles risks breakage, and a boundary matching the current policy narrows nothing.

207. An existing environment must detect credentials that have not been rotated. Which solution meets these requirements?

Answer and explanation

Answer: B. The credential report identifies key age directly. Blanket rotation is disruptive, deleting all keys breaks workloads, and multi-factor authentication does not apply to programmatic keys.

208. An existing environment's S3 buckets must be checked for public exposure. Which solution meets these requirements?

Answer and explanation

Answer: D. Account-level Block Public Access with a Config rule covers existing and future buckets. Manual review does not scale, new-bucket-only leaves existing exposure, and quarterly review is slow.

209. An existing environment must detect when a resource is created without encryption. Which solution meets these requirements?

Answer and explanation

Answer: B. Config rules detect continuously and can remediate. Weekly review, partial defaults, and documentation all leave gaps.

210. An existing environment's network exposure must be assessed without generating traffic. Which solution meets these requirements?

Answer and explanation

Answer: C. Network Access Analyzer evaluates configuration statically. Port scans generate traffic and test only what is attempted, manual review does not scale, and flow logs record traffic that occurred.

211. An existing environment must prevent privilege escalation through role creation. Which solution meets these requirements?

Answer and explanation

Answer: D. A required boundary permits delegation while capping escalation. A central team is a bottleneck, monthly audit is retrospective, and denying IAM blocks legitimate work.

212. An existing environment must confirm no resource policy grants access outside the organization. Which solution meets these requirements?

Answer and explanation

Answer: A. Access Analyzer evaluates policies for access beyond the zone of trust continuously. Manual review does not scale, CloudTrail records access that occurred, and blocking policy changes prevents legitimate updates.

213. An existing environment's secrets are stored in application configuration files. Which solution meets these requirements?

Answer and explanation

Answer: A. A managed store with run-time retrieval removes the secret from the host and enables rotation. Encryption and file permissions still place the plaintext on the host when read, and rotating in files requires redistribution.

214. An existing environment must ensure security findings are acted on within a defined period. Which solution meets these requirements?

Answer and explanation

Answer: D. Tracking age with ownership and escalation drives resolution. Alerting on everything produces noise, weekly review is manual, and archiving hides unresolved findings.

215. An existing environment must verify that a control cannot be disabled by an account administrator. Which solution meets these requirements?

Answer and explanation

Answer: A. Testing the denial confirms the control holds. Reviewing the document checks intent, owner confirmation is unverified, and alerting detects rather than prevents.

216. An existing environment must reduce the number of principals holding administrative access. Which solution meets these requirements?

Answer and explanation

Answer: D. Scoping routine work and reserving elevated access with just-in-time elevation reduces standing privilege safely. Immediate removal breaks operations, multi-factor authentication strengthens without reducing, and auditing is retrospective.

217. An existing workload's database queries have degraded as data volume grew. Which solution meets these requirements?

Answer and explanation

Answer: A. Plans and indexes appropriate at a smaller volume may not remain so, which examination reveals. Larger instances, replicas, and higher IOPS all run the same inefficient queries faster at higher cost.

218. An existing workload's caching layer has a low hit rate. Which solution meets these requirements?

Answer and explanation

Answer: C. Understanding the access pattern directs what to cache. A larger cache, shorter time to live, and more nodes all act without knowing why the hit rate is low.

219. An existing workload's requests are slow only for users in one geography. Which solution meets these requirements?

Answer and explanation

Answer: A. Measuring by geography localises the cause before remediation. Instance size, zone count, and database capacity address the workload rather than the distance.

220. An existing workload's performance varies unpredictably under identical load. Which solution meets these requirements?

Answer and explanation

Answer: D. Variable performance under constant load points to a shared or credit-based resource. Blanket capacity increases are expensive guesswork, reducing concurrency masks it, and a second Region does not address the constraint.

221. An existing workload's performance improvements must be prioritized. Which solution meets these requirements?

Answer and explanation

Answer: B. Measuring where time is spent directs effort to the largest contributor. Familiarity, uniform effort, and code size do not indicate impact.

222. An existing workload has no measurement of how often it fails to meet its availability target. Which solution meets these requirements?

Answer and explanation

Answer: A. An indicator with an objective and error budget quantifies availability against the target. Incident counts, infrastructure uptime, and on-call logs all measure something adjacent.

223. An existing workload's dependencies have not been assessed for their own reliability. Which solution meets these requirements?

Answer and explanation

Answer: D. Mapping dependencies and designing for the weakest is how a composite availability is understood. Assumption, blanket retries, and extra capacity do not establish what will fail.

224. An existing workload recovers from failures but the recovery is not verified. Which solution meets these requirements?

Answer and explanation

Answer: D. Controlled fault injection verifies recovery deliberately. Configuration review checks intent, waiting for a real failure is discovery by outage, and more redundancy does not verify behaviour.

225. An existing workload's failure modes are not documented. Which solution meets these requirements?

Answer and explanation

Answer: D. A structured failure mode analysis identifies what has not yet failed as well as what has. Past incidents, component lists, and monitoring all describe the present rather than anticipate failure.

226. An existing environment's cost has grown without a corresponding increase in business volume. Which solution meets these requirements?

Answer and explanation

Answer: C. Attribution over time identifies what grew and directs investigation. Blanket budget cuts, deleting apparently unused resources, and discounts all act without understanding the cause.

227. An existing workload's compute cost must be reduced without changing its architecture. Which solution meets these requirements?

Answer and explanation

Answer: A. Right-sizing and commitment discounts reduce cost without architectural change. Containerization and serverless rewrites are architectural, and a Region move affects rate rather than usage.

228. An existing environment has resources in Regions where no workload runs. Which solution meets these requirements?

Answer and explanation

Answer: B. Removing the resources and restricting Regions addresses both the current cost and its recurrence. Leaving, moving, and tagging all retain the cost.

229. An existing workload's data transfer cost is significant and its cause is unclear. Which solution meets these requirements?

Answer and explanation

Answer: D. Identifying the dominant transfer type directs the remedy, since each is priced and addressed differently. Uniform reduction, compression, and zone consolidation may address the wrong one.

230. An existing environment's commitment discounts are underused. Which solution meets these requirements?

Answer and explanation

Answer: A. Utilization and coverage together show whether the commitment is too large or the usage uncovered. Cancelling is generally not possible, buying more without analysis compounds the problem, and reshaping workloads to fit a commitment inverts the logic.

231. An existing environment must prevent cost from growing unnoticed between reviews. Which solution meets these requirements?

Answer and explanation

Answer: D. Anomaly detection and budgets routed to owners surface growth as it happens. Quarterly review is retrospective, a single budget hides which team grew, and approving every creation blocks delivery.