All practice questions
1462 questions
A company is designing a mobile application that allows authenticated external users to upload profile documents directly to a shared Amazon S3 bucket. The application authenticates users via an external OpenID Connect (OIDC) compliant identity provider. The architecture must strictly prevent the storage of long-term credentials on the mobile devices, enforce the principle of least privilege, and avoid manual administrative overhead for user provisioning. Which TWO actions should a solutions architect take to meet these security requirements? (Select TWO).
Select all that apply
A Solutions Architect is establishing a multi-account AWS environment for a financial organization. The compliance guidelines require that no member accounts can modify VPC flow logs or delete customer managed keys. Additionally, all administrative access to the AWS accounts must be mapped directly to the organization's existing corporate identity provider. Which two actions should the Solutions Architect implement to meet these requirements?
Select all that apply
An enterprise is migrating a critical, write-heavy core banking application to AWS. The database architecture must satisfy the following resiliency requirements:
- Within the primary AWS region, the database must achieve high availability with zero data loss (Recovery Point Objective, ) and automated failover in less than 30 seconds.
- Across a secondary AWS region, the disaster recovery solution must support active read scaling during normal operations, maintain a cross-region replication lag under 2 seconds ( seconds), and allow failover to the secondary region in less than 5 minutes ( minutes).
Which database configuration meets these requirements with the lowest operational overhead?
A financial technology company operates an online transaction processing (OLTP) application using Amazon RDS for PostgreSQL. The primary database runs in us-east-1 with a Multi-AZ deployment. To comply with disaster recovery regulations, the company requires a secondary database copy in us-west-2. The solution must achieve a Recovery Point Objective (RPO) of less than 5 minutes and a Recovery Time Objective (RTO) of less than 15 minutes in the event of a total failure of the us-east-1 region. Which strategy should a solutions architect implement to meet these disaster recovery requirements?
A retail company expects a massive surge in website traffic during an upcoming marketing campaign. The company needs to design a high-performing data ingestion solution to collect clickstream data in JSON format, transform it into Apache Parquet format, and store it in Amazon S3 for near-real-time analytics. The volume of incoming data is highly unpredictable and fluctuates rapidly. The solution must scale automatically to handle peak throughput without any manual intervention or administrative overhead. Which solution meets these requirements with the highest performance and the least operational effort?
An enterprise uses a multi-account AWS architecture. Internal auditors authenticate via an identity provider (IdP) federated with a central Identity AWS account. The auditors need to read sensitive audit logs stored in an Amazon S3 bucket located in a separate Production AWS account. The S3 bucket is encrypted using a customer managed AWS KMS key in the Production account. A solutions architect must design a secure access strategy that adheres to the principle of least privilege.
Which strategy should the solutions architect implement to meet these requirements?
A global healthcare SaaS provider hosts its telemedicine platform on AWS. The architecture consists of an Amazon CloudFront distribution caching static web content, an Application Load Balancer (ALB), and an Amazon ECS cluster running containerized microservices on AWS Fargate. During a high-profile launch, the platform experiences a distributed denial of service (DDoS) attack consisting of a massive Layer 3/4 UDP reflection attack, a Layer 7 HTTP GET flood targeting the patient search API endpoint, and concurrent SQL injection attempts on the database through the search parameters. The provider needs to implement a solution that automatically detects and mitigates the Layer 3/4 volumetric attacks at the network edge, identifies and blocks the SQL injection attempts and the Layer 7 HTTP GET flood before they reach the ECS cluster, protects the organization from unexpected billing spikes caused by the scale-up of resources during the attack, and prevents attackers from bypassing CloudFront and targeting the ALB directly. Which combination of configurations should the solutions architect implement to meet these requirements?
A company wants to set up a multi-account environment on AWS. They need to automate the provisioning of new accounts with pre-configured security baselines. Additionally, they must manage user access by federating their existing external directory. Which combination of actions should a solutions architect recommend? (Select TWO.)
Select all that apply
A company hosts a public-facing web application on AWS. The company needs to protect the application from common web exploits, such as SQL injection, and from infrastructure-layer DDoS attacks, such as UDP floods. Which two AWS services should the solutions architect utilize to meet these requirements? (Select TWO.)
Select all that apply
A Solutions Architect is designing the multi-account governance and security framework for an enterprise using AWS Organizations. The organization consists of separate Organizational Units (OUs) for Core Services, Production Workloads, and Development Sandboxes. The compliance team requires that no member account be able to modify or delete centralized AWS CloudTrail and AWS Config configurations. Additionally, corporate users must authenticate using an external SAML 2.0 identity provider to access target member accounts using temporary credentials, minimizing administrative overhead in individual accounts. Finally, these controls must not restrict management functions or billing administrative tasks in the management account. Which two actions should the Solutions Architect take to meet these requirements? (Select TWO.)
Select all that apply
A company is running a web application on Amazon EC2 instances deployed across multiple Availability Zones in a single AWS Region. The application requires a shared file system that allows concurrent read and write access from all EC2 instances, while maintaining high availability and durability across the entire region. Which storage service should a Solutions Architect recommend?
A logistics company wants to ingest GPS coordinate telemetry from a fleet of 50,000 delivery vehicles. The telemetry data must be stored in Amazon S3 in near-real-time (within 5 minutes) for operational dashboarding. The system must scale automatically to handle changes in traffic throughout the day while requiring minimal management of infrastructure. Which solution should a solutions architect recommend to meet these requirements?
A financial services company hosts a latency-sensitive market data API on Amazon EC2 instances behind an Application Load Balancer (ALB) in the us-east-1 Region. Customers in London and Tokyo are experiencing connection timeouts and high latency when accessing the API. The client applications require static IP addresses to comply with their strict egress firewall policies. Additionally, the network design must minimize TCP connection establishment latency and bypass the routing inefficiencies of the public internet. Which solution should a solutions architect recommend to optimize the network performance for the global clients?
A financial company hosts an auditing application on AWS. The application stores large transaction logs that must be retained for compliance. In the event of a regional outage, the company needs to recover the application in a secondary AWS Region. The recovery solution must achieve a Recovery Time Objective (RTO) of minutes and a Recovery Point Objective (RPO) of hour.
Which storage and disaster recovery configuration meets these requirements?
A company is setting up a hybrid network to migrate large application payloads from its on-premises environment to a VPC in the us-east-1 Region. The transfer process requires a secure, encrypted connection with a minimum throughput of . Which solution should the solutions architect propose to meet this throughput requirement?
A media company needs to securely back up large video archives from its on-premises data center to Amazon S3. The daily backup transfers require a secure, encrypted connection over the internet with a minimum throughput of . Which network architecture should a solutions architect design to meet these throughput and security requirements?
A graphic design firm stores finished project assets averaging in an Amazon S3 Standard bucket. The assets are frequently accessed for the first after creation. After , they are rarely accessed but must remain immediately retrievable. The firm requires all assets to be permanently deleted after creation. Which two actions should a solutions architect configure in the S3 Lifecycle policy to meet these requirements in the most cost-effective manner? (Choose two.)
Select all that apply
A logistics company is optimizing the deployment costs of its application portfolio on AWS. The portfolio consists of the following workloads:
- A legacy enterprise resource planning (ERP) system hosted on Amazon EC2 instances that must run and cannot tolerate any service interruptions.
- A batch image-transcoding application hosted on AWS Fargate that processes files uploaded throughout the day, where tasks can be interrupted and retried without affecting the final output.
- A set of AWS Lambda functions that execute periodically to process API event requests.
- An Amazon RDS for PostgreSQL database instance that stores transactional data and must remain online continuously.
Which strategy should a solutions architect recommend to achieve the most cost-effective solution?
A digital assets platform hosts a collaborative content creation application on Amazon EC2 instances distributed across three Availability Zones. The application requires a shared storage solution that supports concurrent read and write operations from all instances while maintaining high availability and durability. Additionally, the platform must archive finalized media assets. These archived assets must be stored with maximum durability, and the platform must guarantee that any archived asset can be retrieved within a Recovery Time Objective (RTO) of 5 minutes. Which combination of storage solutions meets these requirements?
A healthcare provider runs a radiology application that uploads medical imaging files and associated metadata to Amazon S3. The daily data patterns are as follows:
* High-resolution MRI scans (average size ) are accessed frequently by radiologists for the first . After , the scans are rarely accessed but must be retained for to comply with local regulations. The retrieval time for these files must not exceed .
* Scan metadata reports (average size ) are queried frequently for the first to generate analytics. After , these reports are no longer needed and should be deleted.
Which combination of Amazon S3 Lifecycle configurations will meet these requirements in the most cost-effective manner? (Select TWO.)
Select all that apply