All practice questions
1964 questions
A media company operates a video transcoding application on Amazon EC2 instances in an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The instances require 7 minutes to download custom profiles and initialize the transcoding daemon before they can accept tasks. During scheduled flash promotional events, the application experiences sudden, massive surges in traffic. The ASG scales out, but it continuously launches unnecessary instances, leading to excessive costs. Additionally, the ALB drops connection requests during the first few minutes of the event. Which combination of actions will resolve the over-provisioning issue and prevent connection drops?
AeroVigil Systems is modernizing an on-premises network security monitoring tool by migrating the workload to Amazon ECS. The application is a packet-inspection agent that requires direct access to the host's physical network interfaces to sniff and analyze network traffic in promiscuous mode. To meet high availability requirements, the containerized workload must be distributed across multiple Availability Zones. Additionally, the solutions architect must ensure compliance with the following enterprise constraints:
1. All container images must be securely stored and pulled from an Amazon Elastic Container Registry (ECR) repository located in a central Shared Services AWS account.
2. The ECS tasks must resolve internal server endpoints using a Route 53 Private Hosted Zone (PHZ) for internal.aerovigil.com that is managed in the Shared Services AWS account.
3. The design must minimize operational overhead where possible, without compromising the core packet-sniffing functionality.
Which architecture should the solutions architect recommend to satisfy these requirements?
An enterprise implements a multi-account strategy using AWS Organizations. Users authenticate via an external corporate Identity Provider (IdP) using SAML 2.0. A solutions architect configures direct SAML federation to each member account by creating an IAM SAML identity provider and a federated IAM role in each account. The security team requires that federated users must only be allowed to assume the role if the authentication request originates from the corporate network range of , and once authenticated, they must be prevented from performing any actions if they leave the corporate network. The solutions architect implements a Service Control Policy (SCP) at the root level of the organization that denies all actions () if the request context does not originate from . The security team discovers that federated users are still able to successfully perform the initial authentication and obtain active AWS session credentials from outside the corporate network, although they cannot run any subsequent commands after the role is assumed. Which of the following modifications should the solutions architect make to ensure the entire authentication flow and subsequent actions are restricted to the corporate network?
An international automotive logistics enterprise is migrating its legacy ERP and distribution scheduling workloads comprising physical servers from an on-premises data center to AWS. Security policies mandate that all migration traffic must be completely private, bypassing the public internet. The hybrid network architecture consists of a AWS Direct Connect connection linked to a Direct Connect Gateway, which is attached to an AWS Transit Gateway. The Transit Gateway routes traffic to a target spoke VPC and a dedicated replication staging area VPC across multiple Availability Zones. The migration team has installed the AWS Application Migration Service (AWS MGN) replication agent on the source servers and configured the replication template to use private IP addresses. However, replication fails to initiate. The agent logs show that the source servers cannot connect to either the AWS MGN control plane endpoints or the replication servers in the staging VPC. Which configuration steps should the solutions architect implement to establish replication connectivity while adhering to the security requirements?
NovusPay is modernizing its transaction processing engine by migrating it from on-premises virtual machines to Amazon ECS on AWS Fargate in a production AWS account. The container images will be stored in a centralized Amazon ECR repository located in a separate Shared Services AWS account. To comply with strict financial regulations, the ECS tasks must run in private subnets with no route to the internet, and all network traffic to download container images and decrypt keys must be routed privately within the AWS network. The ECR repository must be encrypted at rest, and the production ECS tasks must be able to pull images securely. Which combination of actions should a solutions architect take to meet these requirements? (Select TWO.)
Select all that apply
An organization is modernizing its legacy logistics tracking application by migrating its backend logic to AWS Lambda functions fronted by Amazon API Gateway. The Lambda functions must access an Amazon RDS for PostgreSQL database located in a private subnet of a VPC, and must also invoke external carrier APIs over the internet. Additionally, the application must write encrypted daily tracking reports to an S3 bucket in a separate billing-focused AWS account managed by a compliance team.
The system regularly experiences sudden, high-volume bursts of requests. The modernization architecture must meet the following constraints:
- High Availability: Internet-bound outbound traffic from the Lambda functions must remain functional even during an Availability Zone outage.
- Security: The compliance reports in S3 must be encrypted using a key managed by the compliance account, with permission safely granted to the logistics Lambda function.
- Resource Protection: A sudden surge in tracking API requests must not exhaust the execution capacity of other critical serverless workloads running in the same regional AWS account.
- Deployment Safety: Deployments of new Lambda function versions must shift traffic progressively and rollback automatically if execution errors spike.
Which of the following architectural designs satisfies all of these requirements?
A multinational retail company uses a centralized CI/CD pipeline in a Tooling AWS account to deploy and update infrastructure across multiple target accounts in an AWS Organization. The pipeline uses AWS CloudFormation StackSets to deploy standard Amazon EC2 instances and associated security groups. Recently, developers in target accounts have manually modified security group ingress rules to troubleshoot connectivity issues. These manual changes have created security vulnerabilities and caused subsequent CI/CD pipeline updates to fail due to undetected configuration drift. The company needs a solution that prevents manual modifications to resources managed by CloudFormation, ensures that deployment templates are securely shared and accessible cross-account, and automatically alerts the DevOps team if drift is detected. Which solution should the solutions architect implement to meet these requirements?
An enterprise operates a multi-account environment within AWS Organizations consisting of 80 member accounts. The security team requires all AWS CloudTrail API activity logs to be consolidated into a single Amazon S3 bucket located in a dedicated Security account. The logs must be encrypted at rest using a customer managed key (KMS CMK) to comply with regulatory standards. The solution must also prevent member accounts from modifying or disabling the logging configuration. Which TWO actions must the solutions architect perform to implement this solution?
Select all that apply
A healthcare provider stores of patient medical imaging records in an Amazon S3 bucket in the `us-east-1` region. The records are accessed frequently during the first . After , access drops to less than of the records per month, but the records must be retained indefinitely. When an archived record is requested by a physician, it must be retrieved within . The provider wants to minimize both storage and data retrieval costs. Which of the following lifecycle policies represents the most cost-effective and architecturally sound configuration?
Quantex Analytics is modernizing its on-premises portfolio risk simulation engine by migrating to AWS. The current application runs on VMware virtual machines and suffers from scaling limitations during peak market hours. The modernized workload will be deployed as containerized tasks using Amazon ECS on Amazon EC2 instances across multiple Availability Zones to ensure high availability. The application consists of microservices that require low-latency communication and must be tuned with specific kernel parameters (such as net.core.somaxconn) at the container level. The container images must be securely pulled from a centralized Amazon ECR repository in a shared services AWS account. Security policies dictate that all image traffic must remain entirely within the private network without traversing the public internet, and the overall system design must maintain a Recovery Time Objective (RTO) of under 10 minutes and eliminate single points of network failure. Which combination of actions should the solutions architect take to meet these requirements? (Select TWO.)
Select all that apply
An online multiplayer gaming studio is planning to migrate its hybrid game engine and account management system to AWS. The on-premises environment consists of:
* 150 virtual machines (VMs) hosted on VMware vSphere running standard CentOS and Windows Server.
* 10 bare-metal physical servers running FreeBSD for legacy matchmaking lobbies.
* 5 bare-metal physical servers running IBM AIX for legacy transaction processing.
The studio's security policy strictly prohibits installing third-party agents on any database virtual machines running on VMware. However, the studio requires deep network connection dependency mapping and process-level details for the non-database VMs on VMware to optimize the target cloud architecture. Additionally, they want to track the overall migration progress in a single dashboard, including servers migrated using a custom third-party migration tool.
Which combination of actions should the solutions architect recommend to discover this inventory and track the migration? (Select TWO.)
Select all that apply
A company is designing a hybrid network architecture to connect multiple spoke VPCs in the us-west-2 Region to their on-premises datacenter. The network design must satisfy the following requirements:
- Enable transitive VPC-to-VPC routing and hybrid VPC-to-premises routing.
- Resolve private DNS domains bidirectionally between the AWS environment and the on-premises datacenter.
- Maintain high availability and minimize single points of failure.
Which of the following actions should the Solutions Architect take to satisfy these requirements? (Select TWO.)
Select all that apply
An enterprise needs to migrate of data from an on-premises NFS file system to an Amazon FSx for NetApp ONTAP file system in a target AWS account. The enterprise has a dedicated network connection to AWS. The migration must be completed within . During this period, the on-premises file system will remain active, generating approximately of incremental changes. The target file system must encrypt all data at rest using a customer managed key (CMK) in AWS KMS. Which of the following migration strategies is the most efficient and meets these requirements?
A pharmaceutical company operates a multi-account AWS environment with spoke VPCs distributed across the `us-east-1` and `us-west-2` Regions. The on-premises network is connected to AWS via a AWS Direct Connect connection. The company requires a highly available network architecture that minimizes administrative overhead and meets the following criteria:
1. All outbound internet traffic from the spoke VPCs must be centralized and routed through a cluster of security appliances in a dedicated Transit VPC in each region.
2. Spoke VPCs must resolve DNS queries for on-premises domain names ending in `.corp` via the Direct Connect connection.
3. On-premises hosts must resolve resource records in an AWS Route 53 Private Hosted Zone (PHZ) named `aws.internal`.
Which hybrid and multi-account network architecture should a solutions architect design to satisfy these requirements?
A company is designing a federated identity solution for its developers who authenticate via an external SAML 2.0 compliant Identity Provider (IdP). The developers require single sign-on (SSO) access to multiple member accounts within their AWS Organizations environment. The solution must support automated user provisioning, minimize administrative overhead, and avoid manual creation of IAM users in each account. Which configuration strategy should the solutions architect recommend to meet these requirements?
An organization is establishing federated identity access across its multi-account AWS environment using an on-premises PingFederate Identity Provider (IdP). The Solutions Architect needs to set up a configuration that allows external partners to authenticate via the IdP and assume a specific role called PartnerDeveloperRole in target AWS accounts. The configuration must support a maximum session duration of 12 hours for the federated sessions.
Which of the following actions must the Solutions Architect perform to successfully configure this federation? (Select TWO.)
Select all that apply
A solutions architect is establishing a governed multi-account environment for an enterprise using AWS Control Tower. The architect needs to initialize the landing zone, enforce corporate compliance guardrails, and onboard the first set of application team accounts. Arrange the steps to design and implement this multi-account governance structure in the correct chronological sequence.
Drag items to arrange them in the correct order
A global logistics enterprise is designing a new cloud-native supply chain tracking and routing platform. The platform handles an OLTP workload consisting of real-time package status transitions and route assignments. The system must support up to and during peak hours, with database read latency kept below . The disaster recovery requirements specify a Recovery Time Objective (RTO) of less than and a Recovery Point Objective (RPO) of less than . Additionally, an analytics dashboard operating in a separate, dedicated AWS account must be able to securely read data from the database with minimal performance impact on the primary OLTP application. All data must be encrypted at rest. Which database and storage strategy meets these requirements with the lowest operational complexity?
A financial services company is planning to migrate VMware-based virtual machines (VMs) containing transactional databases and application servers from its on-premises data center to a VMware Cloud on AWS (VMC) SDDC. The migration has strict requirements: a near-zero recovery time objective (RTO), zero data loss during cutover, and the preservation of existing IP addresses due to hardcoded application configurations. The hybrid network architecture is managed across multiple AWS accounts: a central AWS Transit Gateway (TGW) in a Shared Services account is connected to on-premises via an AWS Direct Connect (DX) Gateway with a Transit VIF, and multiple application VPCs are attached to this central TGW. The VMC SDDC is connected via VMware Cloud on AWS Transit Connect (VTGW), which is peered with the central TGW. During initial configuration, replication traffic between the on-premises VMware HCX instance and the HCX Cloud destination in the VMC SDDC fails to establish connectivity. Which configuration change must the solutions architect implement to resolve the connectivity issues and enable zero-downtime migrations over the Direct Connect link?
A financial services organization is modernizing its payment processing pipeline. The pipeline receives high-volume transaction notifications from an external payment gateway through Amazon API Gateway and routes them to AWS Lambda functions. The Lambda functions process the transactions and update a highly utilized Amazon RDS PostgreSQL database located in a private subnet. The processed transactions must also be archived to an Amazon S3 bucket in a separate, central security audit AWS account for long-term retention.
The architecture must satisfy the following constraints:
1. Prevent sudden transaction bursts from exhausting the concurrency limits of other critical workloads in the AWS account.
2. Avoid overwhelming the RDS PostgreSQL database connection pool.
3. Ensure high availability for the egress network path from the Lambda functions to external verification endpoints.
4. Encrypt the archived S3 objects and allow the central security audit account to decrypt them.
5. Provide a safe deployment mechanism for new Lambda function versions with automated rollback capabilities.
Which TWO strategies should the Solutions Architect implement to meet these requirements? (Select TWO.)
Select all that apply