51 practice questions for Domain 4 of the AWS Certified Solutions Architect - Professional (SAP-C02) exam, which makes up 20% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 4: Accelerate Workload Migration and Modernization
232. An organization must decide which of 400 on-premises applications to migrate first. Which solution meets these requirements?
Answer and explanation
Answer: D. A portfolio assessment establishes dependencies, migration strategy, and cost for each application, which is what wave planning requires. Alphabetical order ignores dependency and value. Largest-first ignores complexity and risk. Volunteer-led sequencing produces an unplanned order.
233. An application is a commercial product whose vendor offers an equivalent software-as-a-service subscription. Which migration strategy applies?
Answer and explanation
Answer: A. Repurchasing moves to a different product, typically a subscription, rather than migrating the existing installation. Replatforming and rehosting both carry the existing product forward. Refactoring rewrites an application the organization does not own.
234. A 900 TB dataset must be moved to AWS from a site whose network link would take several months to transfer it. Which solution meets these requirements?
Answer and explanation
Answer: A. Physical transfer is the standard answer when available bandwidth would take months. DataSync and Transfer Acceleration both optimise a link that is fundamentally too slow for this volume. Provisioning Direct Connect takes weeks and still requires the transfer time on top.
235. An Oracle database must be migrated to Amazon Aurora PostgreSQL with minimal downtime, and its stored procedures use Oracle-specific constructs. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: D, E. SCT converts schema and procedural objects and reports what must be rewritten by hand, and DMS with change data capture keeps the target current so cutover is brief. A full load only implies a long outage. An S3 export and import performs no schema conversion and no ongoing replication. Rehosting on EC2 postpones the migration rather than performing it.
236. An architect must select a mechanism to migrate hundreds of on-premises virtual machines to AWS with minimal application change. Which solution meets these requirements?
Answer and explanation
Answer: C. Application Migration Service performs block-level replication and launches equivalent instances, which is a lift-and-shift with minimal change. Rebuilding and reinstalling is manual and inconsistent at this scale. Manual image export and import is slow and error-prone for hundreds of machines. Containerizing is a refactor rather than a migration.
237. A migrated application runs on EC2 instances that are idle overnight and at weekends, and the team wants a target architecture that costs nothing when idle. Which solution meets these requirements?
Answer and explanation
Answer: A. Lambda bills per invocation and costs nothing when idle, which matches the requirement exactly. A smaller instance and ECS on EC2 both still run instances through the idle periods. Reserved Instances discount idle hours rather than eliminating them.
238. A migrated workload uses a self-managed MongoDB deployment on EC2 instances. Which target platform reduces operational burden with minimal application change?
Answer and explanation
Answer: D. DocumentDB supports MongoDB-compatible drivers, so the application works with configuration changes rather than a rewrite while AWS manages the platform. DynamoDB has a different API requiring the adaptation being avoided. Flattening into a relational schema discards the document model. A JSON column stores documents without the document query semantics.
239. A migrated monolith must be decomposed so that a failure in its reporting function no longer affects order processing. Which solution meets these requirements?
Answer and explanation
Answer: A. Decoupling into independent services with asynchronous communication means a reporting failure cannot block order processing. More capacity and more zones replicate the coupled monolith. Restarting on failure interrupts order processing as well.
240. A migrated batch workload runs for four hours nightly and tolerates interruption. Which modernization reduces cost the most?
Answer and explanation
Answer: A. Fargate Spot offers a substantial discount for interruption-tolerant tasks and removes instance management. On-Demand is the baseline price. Reserved Instances commit to continuous usage a four-hour nightly job does not have. A larger instance raises the hourly rate.
241. An architect must identify which component of a migrated application is the best candidate for a purpose-built database. Which approach meets these requirements?
Answer and explanation
Answer: C. Purpose-built selection matches each access pattern to a suitable data model, which is what the practice means. Standardizing on one service ignores that some patterns fit poorly. Keeping everything relational forgoes the opportunity entirely. Hourly price ignores fitness and total cost.
242. An architect must calculate the total cost of ownership of an on-premises workload to compare it with an AWS design. Which costs must be included beyond hardware?
Answer and explanation
Answer: C. A defensible total cost of ownership includes facilities, power, cooling, network, licensing, and operational staff effort, because these are real costs that the comparison must capture. Narrower definitions understate the on-premises figure and make the comparison misleading.
243. An application will be decommissioned within six months. Which migration strategy applies?
Answer and explanation
Answer: D. Retiring decommissions an application that is no longer needed rather than migrating it. Retaining keeps it where it is for now. Rehosting and replatforming both move it, which is effort spent on something about to be switched off.
244. An architect must select a transfer mechanism for 40 TB of data where the available network link can complete the transfer in four days. Which solution meets these requirements?
Answer and explanation
Answer: B. Four days over an existing link is acceptable, and DataSync transfers efficiently with integrity verification. Snow Family is for cases where bandwidth would take weeks or months. The CLI transfers without task-level verification or scheduling. Provisioning Direct Connect takes weeks and is unnecessary for a one-off transfer of this size.
245. An architect must apply security controls to a migration that replicates production data to AWS. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: C, E. Encrypting the replicated data and scoping the service role to named resources protect the data and limit what a compromise could reach. Administrator permissions exceed what migration requires. Disabling logging removes the audit trail during the highest-risk period. A public endpoint exposes the replication path.
246. An architect must select a governance model for accounts created during a large migration. Which approach is appropriate?
Answer and explanation
Answer: D. A landing zone applies controls from the moment an account exists, which avoids a window of ungoverned workloads. Applying controls afterwards leaves that window open. A single account removes blast radius isolation. Per-team configuration guarantees inconsistency.
247. A migrated application uses a shared file system accessed concurrently by many Linux instances. Which target service is appropriate?
Answer and explanation
Answer: B. EFS provides a shared POSIX file system many Linux instances mount concurrently. EBS volumes attach to one instance at a time in the general case. S3 is object storage without file semantics. FSx for Windows File Server serves the SMB protocol for Windows workloads.
248. A migrated workload runs a container platform the team already operates with Kubernetes tooling and manifests. Which target platform minimizes change?
Answer and explanation
Answer: C. EKS runs Kubernetes, so existing manifests and tooling work with minimal change. ECS has a different API and requires task definitions to be authored. Elastic Beanstalk is a different deployment abstraction. A self-managed scheduler retains the operational burden managed Kubernetes removes.
249. A migrated application performs a long-running document conversion synchronously within its request path. Which modernization is appropriate?
Answer and explanation
Answer: C. Moving long-running work out of the request path lets the front end return immediately and the conversion scale independently. A longer timeout holds connections. A larger instance shortens but does not remove the synchronous wait. Caching helps only for repeated conversions of the same document.
250. A migrated workload's components are tightly coupled through direct synchronous calls, and a failure in any component fails the whole request. Which modernization is appropriate?
Answer and explanation
Answer: B. Asynchronous messaging decouples availability so one component's failure does not fail the request chain. More retries and longer timeouts keep the coupling while extending the failure. Co-locating components on one instance increases coupling.
251. An architect must select an integration service for a migrated workload where several consumers must each receive every event. Which solution meets these requirements?
Answer and explanation
Answer: D. The fan-out pattern delivers a copy to each subscribed queue, giving every consumer its own buffer and retry behaviour. A shared queue delivers each message to one consumer. Sequential invocation couples the producer to every consumer. Polling S3 adds latency and cost.
252. An application portfolio must be prioritized for migration waves. Which criteria are appropriate?
Answer and explanation
Answer: D. Value, complexity, dependencies, and risk together sequence waves rationally. Alphabetical order and age are arbitrary. Owner preference ignores dependencies and risk.
253. An application has a large licence cost that would be eliminated by replacing it with a managed AWS service. Which migration strategy applies?
Answer and explanation
Answer: A. Replatforming to a managed equivalent captures the licence saving. Rehosting carries the licence. Retaining changes nothing. Retiring assumes the application is not needed.
254. A migration assessment must establish an application's dependencies on other systems. Which approach is appropriate?
Answer and explanation
Answer: C. Discovery Service observes actual connections and maps dependencies empirically. Owner recollection and documentation are often incomplete. Assuming none guarantees surprises.
255. A database must be migrated with a change of engine and minimal downtime. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, D. SCT converts the schema and DMS with CDC keeps the target current until cutover. A full load only implies a long outage. CSV export has no schema conversion or ongoing replication. Rehosting postpones the engine change.
256. Hundreds of virtual machines must be migrated with minimal change and a short cutover. Which solution meets these requirements?
Answer and explanation
Answer: B. Application Migration Service performs continuous block-level replication with a short cutover. Manual rebuild and VM export do not scale. Containerizing is a refactor.
257. A migration must move user identities so that migrated applications authenticate against a directory in AWS. Which solution meets these requirements?
Answer and explanation
Answer: B. Directory Service with a trust allows migrated applications to authenticate against AWS while users remain in the source directory during transition. IAM users are for AWS access rather than application authentication. Cognito serves application end users rather than enterprise directory identity. Permanent on-premises authentication is a dependency the migration should remove.
258. A migration's security must ensure that replication traffic between on premises and AWS is encrypted and the migration tooling is least-privileged. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: D, E. Encrypted transport and a scoped role protect the data and limit the tooling. Administrator access exceeds need. Unencrypted public replication exposes data. Disabling logging removes the audit trail during the highest-risk period.
259. A migrated application uses a self-managed Redis cache on EC2. Which target platform reduces operational burden?
Answer and explanation
Answer: C. Managed in-memory services remove patching and failover management. A larger instance is still self-managed. RDS and S3 are not in-memory caches.
260. A migrated application stores files on a Windows file server accessed by SMB. Which target storage is appropriate?
Answer and explanation
Answer: A. FSx for Windows File Server provides SMB with Windows semantics. EFS is NFS for Linux. S3 is object storage. EBS is block storage for one instance.
261. A migrated workload's database has predictable steady traffic and the team wants the lowest operational burden. Which target platform is appropriate?
Answer and explanation
Answer: A. Managed relational services remove operational tasks for a relational workload. Self-managed retains them. DynamoDB requires a redesign. Redshift is analytical.
262. A migrated application has a scheduled job that runs for two minutes each hour on a dedicated instance. Which modernization is appropriate?
Answer and explanation
Answer: C. A two-minute hourly job fits Lambda exactly and eliminates the idle instance. A smaller instance is still idle most of the hour. More frequent runs and added jobs change the workload to fit the infrastructure.
263. A migrated application polls a database table for new work items. Which modernization is appropriate?
Answer and explanation
Answer: D. Event-driven processing removes polling latency and load entirely. More frequent polling adds load. Less frequent polling adds latency. An index speeds the poll without removing it.
264. A migrated application's search feature uses SQL LIKE queries against a relational database. Which purpose-built service improves this?
Answer and explanation
Answer: A. OpenSearch provides inverted-index full-text search that LIKE queries cannot. A larger instance runs the same scans faster. DynamoDB and Redshift do not provide full-text search.
265. A migrated application handles image uploads synchronously, resizing each image before responding. Which modernization is appropriate?
Answer and explanation
Answer: D. Asynchronous resizing lets the upload return immediately and scales independently. A larger instance shortens but keeps the synchronous wait. Client resizing shifts work to untrusted clients. Skipping resizing loses the feature.
266. A migrated application's components must be identified as candidates for decoupling. Which characteristic indicates a candidate?
Answer and explanation
Answer: C. Independent failure and scaling characteristics indicate a boundary worth decoupling. A component sharing lifecycle with another may belong with it. No dependencies means nothing to decouple from. Code size is not a coupling indicator.
267. An organization must decide which applications to migrate first from a portfolio with unclear dependencies. Which solution meets these requirements?
Answer and explanation
Answer: D. Discovery establishes the dependencies that determine safe sequencing. Size, owner willingness, and build order all ignore what must move together.
268. An application's migration business case must account for costs beyond infrastructure. Which solution meets these requirements?
Answer and explanation
Answer: A. A complete case includes migration effort, dual running, retraining, and optimization. Infrastructure figures alone understate the investment.
269. A migration must move a large dataset while the source remains in use. Which solution meets these requirements?
Answer and explanation
Answer: C. Bulk transfer with incremental synchronization keeps the target current while the source stays in use. A single transfer loses subsequent changes, downtime is what the requirement avoids, and changes alone cannot reconstruct the whole.
270. A migration wave must be validated before the source environment is decommissioned. Which solution meets these requirements?
Answer and explanation
Answer: D. Parallel running with output comparison validates the migration before commitment. Decommissioning on completion or after a fixed period both assume success, and indefinite retention pays for both.
271. A migration must minimize the risk of an unsuccessful cutover. Which solution meets these requirements?
Answer and explanation
Answer: A. A tested rollback makes an unsuccessful cutover recoverable. Fixing in place under pressure is risky, and quiet periods and longer windows limit exposure without providing a way back.
272. A migration must transfer data whose sensitivity requires it not to traverse the public internet. Which solution meets these requirements?
Answer and explanation
Answer: D. Private connectivity or physical shipment keeps the data off the public internet. TLS protects confidentiality while still traversing it, and compression and scheduling address volume and timing.
273. A migration's schema conversion has produced objects the tool could not convert. Which solution meets these requirements?
Answer and explanation
Answer: A. The conversion report identifies what needs manual rework, which must then be tested. Proceeding with gaps leaves the application broken, rehosting postpones the conversion, and discarding objects loses function.
274. A migrated application's session state is held in memory on each server. Which solution meets these requirements?
Answer and explanation
Answer: A. External session state makes the tier stateless. Session affinity ties users to servers, more memory delays the constraint, and fewer servers reduce capacity.
275. A migrated application writes to a local file system that several instances must now share. Which solution meets these requirements?
Answer and explanation
Answer: D. A shared file system gives every instance consistent access. Scheduled replication is eventually consistent, a single writer is a bottleneck and a failure point, and more local storage does not share it.
276. A migrated application's scheduled jobs run on a single server using cron. Which solution meets these requirements?
Answer and explanation
Answer: C. A managed scheduler removes the single-server dependency. Cron on every server duplicates execution, improving one server's reliability leaves the dependency, and manual execution does not scale.
277. A migrated application's licensing is tied to physical cores. Which solution meets these requirements?
Answer and explanation
Answer: D. Core-based licensing makes dedicated hosts or license-included options a material decision that must be modelled. Larger instances may increase licence cost, Spot does not address licensing, and deferring risks a compliance breach.
278. A migrated application's configuration is embedded in its deployment artifact. Which solution meets these requirements?
Answer and explanation
Answer: C. External configuration decouples change from deployment. Rebuilding, per-environment artifacts, and post-deployment editing all couple configuration to the artifact or drift.
279. A migrated application's monolithic database is a bottleneck for several independent features. Which solution meets these requirements?
Answer and explanation
Answer: C. Separating by bounded context lets each feature use a suitable store. A larger instance, replicas, and internal partitioning all keep the shared bottleneck.
280. A migrated application's batch processing runs overnight and delays reporting. Which solution meets these requirements?
Answer and explanation
Answer: A. Incremental or streaming processing removes the batch delay. More frequent and faster batches reduce but do not remove it.
281. A migrated application must adopt managed services incrementally without a rewrite. Which solution meets these requirements?
Answer and explanation
Answer: D. Incremental replacement behind stable interfaces delivers value progressively at lower risk. A full rewrite is high risk, waiting forgoes the benefit, and simultaneous replacement compounds the risk.
282. An architect must identify which parts of a migrated application would benefit most from modernization. Which solution meets these requirements?
Answer and explanation
Answer: A. Change frequency, operational burden, and business value together indicate where modernization returns most. Age, size, and uniform effort do not.