All practice questions
1964 questions
An online auction platform experiences sudden, massive surges in traffic during the final minutes of high-value auctions. The application runs on Amazon EC2 instances in an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The instances use a custom launch template that takes () to download application libraries and start the service. Outbound API calls to external payment gateways are routed through a single NAT Gateway in Availability Zone . During auction finales, the ALB immediately returns errors to new requests. Additionally, the ASG launches far more instances than needed during a surge because the scaling policy triggers additional instances before the first batch is fully functional. Which combination of actions will resolve these scaling and fault-tolerance issues with the lowest operational overhead?
A company is implementing a federated access solution using an on-premises SAML 2.0 compliant Identity Provider (IdP) for their AWS Organizations environment. While testing the integration, a user successfully authenticates against the identity provider and selects a role named FederatedAdminRole in a target member account. However, the redirection to the AWS Management Console fails, and the user receives the following error message: 'Access denied. Action: sts:AssumeRoleWithSAML is not authorized.' The Solutions Architect verifies that the SAML identity provider is correctly created in the IAM console of the target account, and the user's SAML assertion contains the correct role and provider ARNs. Which configuration issue is the most likely cause of this error?
A media company runs its video encoding application on Amazon EC2 instances in private subnets across multiple Availability Zones in a VPC in the `us-west-2` Region. The instances download of raw video files monthly from an Amazon S3 bucket located in `us-west-2`. The VPC route tables currently direct all S3-bound traffic through NAT Gateways.
The company also generates of transcoded video logs monthly on the EC2 instances, which are uploaded to a secondary S3 bucket in the `us-east-1` Region for long-term archival. These logs are currently uploaded over the internet through the NAT Gateways. The archival logs are rarely accessed but must be retained for at least .
Which combination of actions will reduce the data transfer and storage costs most effectively? (Select TWO.)
Select all that apply
BioPharma Nexus is modernizing its legacy drug discovery simulation application by migrating it from on-premises servers to Amazon ECS on AWS Fargate. The application is deployed across multiple private subnets in a Workload VPC. The container images are hosted in an Amazon ECR repository in a centralized Shared Services AWS account. The tasks also retrieve database credentials from AWS Secrets Manager in the Workload account, which are encrypted using a customer managed AWS KMS key in the Workload account.
To comply with strict security standards, no internet gateways or NAT gateways are allowed in either VPC. An AWS Transit Gateway connects the Workload VPC and the Shared Services VPC. Interface VPC endpoints for ECR (api and dkr), Secrets Manager, and KMS are established in the Shared Services VPC. The Route 53 Private Hosted Zones (PHZs) for these endpoints are currently associated only with the Shared Services VPC.
When deploying the ECS tasks in the Workload VPC, they fail to transition to the RUNNING state, displaying the error: 'ResourceInitializationError: unable to pull secrets or registry auth'.
Which of the following solutions will resolve the initialization error and allow the tasks to run successfully?
A smart energy utility provider is designing its AWS multi-account governance structure using AWS Organizations. The provider wants to automate the creation of new accounts for regional grid monitoring applications while enforcing strict guardrails. Specifically, they must prevent any member account from disabling AWS CloudTrail and ensure that a centralized security team can access all accounts using a pre-configured IAM role.
Which combination of actions should the Solutions Architect take to implement this governance model? (Select TWO.)
Select all that apply
A global agricultural technology platform is preparing to migrate its core crop-yield analysis and logistics coordination system to AWS. The on-premises infrastructure includes:
* VMware vSphere VMs running Red Hat Enterprise Linux (RHEL) and Windows Server. These VMs host the API layers and distributed processing nodes. The team requires deep mapping of network dependencies (TCP connections) between these servers to group them into application stacks.
* bare-metal servers running Oracle Solaris, hosting legacy databases and proprietary data processing engines. These servers are located in a highly secure zone with no outbound internet connectivity, and the OS is not supported by the AWS Application Discovery Agent.
All outbound traffic from the VMware vSphere environment must go through an on-premises HTTP proxy. The platform team wants to use AWS Migration Hub as the single pane of glass to plan the migration, group servers, and track the migration status of these workloads.
Which combination of discovery mechanisms and tracking setup should a solutions architect recommend to satisfy these requirements?
An airline company is designing a new global reservation system. The architecture must deploy across a primary AWS Region and a secondary AWS Region for disaster recovery. The database layer consists of an online transaction processing (OLTP) workload that handles active seat reservations.
The solution must satisfy the following requirements:
- Workload & Performance: Low-latency reservation writes () under high traffic, with horizontal read scaling in the primary Region to handle spike searches from customers.
- Disaster Recovery: A target Recovery Point Objective (RPO) of and a Recovery Time Objective (RTO) of in the secondary Region.
- Cross-Account Archiving: Completed reservation receipts must be archived to an Amazon S3 bucket owned by a centralized compliance account (`Compliance-Acct`).
- Data Security: Archived files must be encrypted at rest using an AWS KMS key managed by the reservation application's production account (`Reservation-Acct`). Auditors operating in `Compliance-Acct` must be able to decrypt the receipts.
Which combination of storage and database strategy steps will satisfy these requirements? (Select TWO.)
Select all that apply
A company is designing a multi-account network architecture on AWS consisting of three spoke VPCs in the us-east-1 region with CIDR blocks , , and . The architecture must support hybrid connectivity to an on-premises data center using an AWS Direct Connect connection. Additionally, all spoke VPCs must route outbound internet traffic through a centralized egress VPC to inspect traffic and control costs. Which of the following network designs meets these requirements with the least operational complexity?
A company needs to migrate of data from an on-premises SMB file share to Amazon EFS. The migration must be completed within . The company has an active AWS Direct Connect connection, but due to production workloads, only of bandwidth can be allocated for this migration. All data must be encrypted at rest using an AWS Key Management Service (AWS KMS) customer managed key that can be shared with a secondary auditing AWS account. Which migration strategy will meet these requirements within the specified timeline?
A digital ticketing platform's reservation service runs on Amazon EC2 instances within an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The instances are deployed in private subnets and require 6 minutes to retrieve static configuration assets and initialize the application server. During unannounced concert announcements, the platform experiences sudden flash traffic spikes, leading to HTTP 503 Service Unavailable errors on the ALB before new instances are fully operational. Furthermore, outbound API calls to third-party payment gateways fail during an outage of a single Availability Zone because all private subnets route outbound traffic through a single NAT Gateway. Which combination of actions should a solutions architect take to improve the scalability and fault tolerance of the platform? (Select TWO.)
Select all that apply
A company is implementing a multi-account strategy using AWS Organizations. The company wants to centralize access management to all AWS accounts by integrating AWS IAM Identity Center with their external identity provider (IdP), Okta, which supports SAML 2.0 and SCIM. The solutions architect needs to configure automatic synchronization of users and groups from Okta to AWS, and assign permissions to these users. Which two configurations should the solutions architect implement to meet these requirements?
Select all that apply
An enterprise is establishing centralized security monitoring across its multi-account environment using AWS Organizations. A solutions architect needs to configure Amazon GuardDuty so that all security alerts are consolidated into a dedicated Security Tooling member account. The solution must ensure that member accounts cannot disable GuardDuty or modify its configurations, while allowing the Security Tooling account to manage the service.
Arrange the following steps in the correct chronological sequence to implement this governance and security architecture.
Drag items to arrange them in the correct order
An automotive manufacturing company is migrating its legacy telemetry processing servers ( virtual machines running on-premises hypervisors) to AWS using AWS Application Migration Service (MGN). The migration must use a dedicated AWS Direct Connect connection connected via a transit virtual interface (VIF) to an AWS Transit Gateway. The target staging area VPC has no direct internet access, and all data replication traffic must be kept entirely private. The migration team has installed the replication agent on the source virtual machines, but the agent fails to establish a connection with the replication servers in the staging area VPC. Which of the following configuration steps must be performed to establish private replication connectivity and resolve the issue? (Select TWO.)
Select all that apply
A healthcare software provider is planning to migrate its legacy patient portal and clinical analytics platform to AWS. The on-premises infrastructure consists of 80 VMware vSphere VMs running supported Linux and Windows operating systems, and 10 physical bare-metal servers running legacy AIX. The security team prohibits installing any software agents on the virtualized database VMs due to compliance requirements, but requires identifying system configurations and CPU/memory utilization. For the remaining VMs, the migration team must identify active network connections, running processes, and inbound/outbound traffic destinations to map dependencies. The migration progress must be tracked centrally alongside a third-party migration tool. Which combination of discovery mechanisms and tracking tools should the solutions architect recommend?
An enterprise is using AWS Organizations to manage its multi-account environment. The security team wants to restrict developers in the Sandbox organizational unit (OU) to launching Amazon EC2 instances only in the us-east-1 and us-west-2 Regions, and prevent them from launching GPU-based instance types (such as p or g families). The solution must prevent non-compliant resource creation even if local administrators have full administrative access within their accounts. Which strategy meets these requirements with the least administrative overhead?
A medical device manufacturing company is planning to migrate its core supply chain and regulatory compliance systems to AWS. The on-premises environment consists of two distinct segments:
1. A cluster of VMware vSphere 7.0 virtual machines (VMs) running supported Enterprise Linux operating systems inside a secure network zone. These VMs have no direct internet access but can communicate outbound through an authenticated HTTP/HTTPS proxy. The company's compliance policy strictly prohibits installing any software at the hypervisor level (ESXi hosts), but permits guest-level agent installations.
2. Several physical bare-metal servers running a highly customized legacy Linux kernel that does not support the installation of the AWS Application Discovery Agent.
The migration team must discover the server configurations, monitor CPU and memory utilization for right-sizing, map network dependencies (specifically active TCP connections between servers), and track the overall migration status in AWS Migration Hub. The team also wants to integrate this tracking with their existing Jira Service Management platform for change management.
Which two actions should a solutions architect recommend to satisfy these discovery and tracking requirements? (Select two.)
Select all that apply
A financial company is planning to migrate a critical payment application from an on-premises VMware vSphere cluster to VMware Cloud on AWS (VMC). The application consists of application server virtual machines (VMs) that can tolerate a brief service interruption (less than minutes) during switchover, and transactional database VMs that must remain online with zero downtime and zero data loss (, ) during the migration.
The company's AWS multi-account environment is structured as follows:
* Account A hosts the VMC on AWS Software-Defined Data Center (SDDC).
* Account B hosts a Shared Services VPC containing Active Directory servers and Amazon Route 53 Private Hosted Zones (PHZs).
* Account C hosts native production spoke VPCs.
A customer-managed AWS Transit Gateway (TGW) in a central network account connects the Shared Services VPC and the Account C production spoke VPCs. Physical connectivity to the on-premises datacenter is established via a AWS Direct Connect connection terminated on a customer-managed Direct Connect Gateway (DXGW).
The target architecture must enable bidirectional DNS resolution between all environments, allow on-premises administrators to manage the SDDC VMs post-migration, and enable private communication between SDDC VMs and native AWS resources.
Which combination of migration techniques and network configurations will meet these requirements?
A company is designing a new financial reporting platform. The platform requires a database to handle a bursty OLTP transaction history workload with dynamic, auto-scaling read capability. For caching, the application requires sub-key eviction, persistence, and Multi-AZ replication. Finally, financial reports must be exported to an Amazon S3 bucket located in a separate, dedicated audit AWS account. These exports must be encrypted at rest using key material controlled by the company, and the audit account must have permissions to immediately read the files. Which two database and storage configurations should a Solutions Architect select to satisfy these requirements?
Select all that apply
A healthcare software company is designing a new patient record archiving platform. The application stores high-resolution medical scan files as object storage and a metadata catalog as an OLTP database. The metadata database must support read operations across two AWS Regions with a disaster recovery target of near-zero RPO and an RTO of under . The system must automatically scale read capacity during peak query hours. Additionally, the scan files must be shared securely with an external auditor's AWS account, requiring encryption using keys that support cross-account policy delegation. Which database and storage strategy meets these requirements?
A media broadcasting company is migrating its critical live-stream metadata ingest applications, consisting of 12 legacy servers, from an on-premises data center to AWS using AWS Application Migration Service (MGN). The replication must occur over a private network connection using an AWS Direct Connect (DX) connection with a private virtual interface attached to an AWS Transit Gateway. Due to strict security compliance, neither the on-premises servers nor the staging subnets in the replication VPC can have outbound internet access. Which two configuration steps must a solutions architect perform to establish replication while meeting these requirements? (Select TWO.)
Select all that apply