CertSafari

    Free AWS Certified CloudOps Engineer - Associate (SOA-C03) Sample Questions

    35 free sample questions from our bank of 364+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Monitoring, Logging, Analysis, Remediation, and Performance Optimization

    Subdomain 1.1: Implement metrics, alarms, and filters by using AWS monitoring and logging services.

    1.An engineer is setting up the CloudWatch agent on a new EC2 instance for the first time and needs the instance to be able to push metrics and logs to CloudWatch and to retrieve its configuration from Systems Manager Parameter Store. Which two IAM actions should the engineer take?(Select 2)

    1. A.Attach the `CloudWatchAgentServerPolicy` managed policy to the instance's IAM role so the agent can publish metrics and logs to CloudWatch.
    2. B.Attach the `AmazonSSMManagedInstanceCore` managed policy to the same role so the instance can communicate with Systems Manager and retrieve stored parameters.
    3. C.Grant the instance's IAM role full `AdministratorAccess`, since the CloudWatch agent requires unrestricted permissions across every AWS service to start.
    4. D.Embed a long-term IAM access key directly inside the agent's JSON configuration file, since EC2 instance roles cannot supply credentials to the agent.
    5. E.Skip attaching any IAM role, since the CloudWatch agent authenticates using the instance's public IP address rather than AWS credentials.
    6. F.Create an IAM user with console access and share its password with the agent process, since only console users can publish custom metrics.
    Show answer & explanation

    Correct answers: A, B — Attach the `CloudWatchAgentServerPolicy` managed policy to the instance's IAM role so the agent can publish metrics and logs to CloudWatch.; Attach the `AmazonSSMManagedInstanceCore` managed policy to the same role so the instance can communicate with Systems Manager and retrieve stored parameters.

    • A. Attaching `CloudWatchAgentServerPolicy` is correct because it grants exactly the permissions the agent needs to publish metrics and logs to CloudWatch from the instance.
    • B. Attaching `AmazonSSMManagedInstanceCore` is correct because it lets the instance register with Systems Manager and read its stored configuration parameter from Parameter Store.
    • C. Granting full `AdministratorAccess` is incorrect because it far exceeds the least-privilege permissions the agent needs and is not a requirement for the agent to start.
    • D. Embedding a long-term access key is incorrect because instance roles do supply temporary credentials to the agent automatically, making a hardcoded key both unnecessary and a security risk.
    • E. Skipping the IAM role is incorrect because the CloudWatch agent authenticates using AWS SDK credentials from the instance role, not the instance's public IP address.
    • F. Sharing an IAM user's console password is incorrect because the agent uses programmatic credentials from an attached role, not interactive console login credentials.

    Subdomain 1.1: Implement metrics, alarms, and filters by using AWS monitoring and logging services.

    2.A team wants a CPU utilization alarm to trigger only when the threshold is breached in 3 out of the last 5 evaluation periods, rather than requiring every single period to breach, in order to tolerate brief spikes. Which alarm setting supports this?

    1. A.Configure the alarm's "datapoints to alarm" setting to 3 out of an evaluation period count of 5, enabling M-out-of-N evaluation instead of requiring every period to breach.
    2. B.Configure the alarm's period to 5 minutes and its evaluation periods to 3, since multiplying these two values alone produces M-out-of-N behavior.
    3. C.Create five separate alarms, one per evaluation period, and manually count how many of them are currently in ALARM state using a scheduled Lambda function.
    4. D.Enable anomaly detection on the metric, since anomaly detection bands are the only CloudWatch mechanism that can ever tolerate brief, temporary threshold spikes at all times.
    Show answer & explanation

    Correct answer: A — Configure the alarm's "datapoints to alarm" setting to 3 out of an evaluation period count of 5, enabling M-out-of-N evaluation instead of requiring every period to breach.

    • A. Setting "datapoints to alarm" to 3 out of 5 evaluation periods is correct because this is the native M-out-of-N feature that lets an alarm require only a subset of recent periods to breach before entering ALARM.
    • B. Just setting a period and evaluation-period count is incorrect because those values alone define the total lookback window, not the fraction of periods within it that must breach before alarming.
    • C. Building five separate alarms with a custom counting Lambda is incorrect because it recreates, with far more complexity, functionality that the native datapoints-to-alarm setting already provides directly.
    • D. Enabling anomaly detection is incorrect because anomaly detection bands flag statistically unusual behavior relative to historical patterns; they are not the mechanism for configuring an M-out-of-N breach requirement.

    Subdomain 1.1: Implement metrics, alarms, and filters by using AWS monitoring and logging services.

    3.An engineer configures a metric alarm to notify an SNS topic ARN that was mistyped and does not exist, then saves the alarm without any validation error. What does this behavior indicate about how CloudWatch handles alarm actions?

    1. A.CloudWatch does not validate that an action target exists when an alarm is created, so an alarm with a nonexistent SNS topic ARN saves successfully but never delivers a notification.
    2. B.CloudWatch always validates SNS topic ARNs at alarm creation time and would have rejected the save, so the alarm must be referencing a valid topic under a completely different AWS account.
    3. C.CloudWatch automatically creates a placeholder SNS topic matching the mistyped ARN the first time the alarm changes state, then delivers the notification to that new topic.
    4. D.CloudWatch silently redirects notifications for any invalid action target to the account's root email address as a built-in fallback delivery mechanism.
    Show answer & explanation

    Correct answer: A — CloudWatch does not validate that an action target exists when an alarm is created, so an alarm with a nonexistent SNS topic ARN saves successfully but never delivers a notification.

    • A. This is correct because CloudWatch explicitly does not test or validate that alarm action targets, such as an SNS topic ARN, actually exist, so a save succeeds while notifications for that action silently fail to deliver.
    • B. This is incorrect because CloudWatch does not perform this kind of existence validation at save time, which is precisely why the mistyped, nonexistent ARN was accepted in the first place.
    • C. This is incorrect because CloudWatch has no behavior that auto-creates a placeholder SNS topic to match a misconfigured action; a nonexistent target simply results in a failed delivery attempt.
    • D. This is incorrect because CloudWatch has no fallback mechanism that redirects failed alarm action deliveries to a root account email address.

    Subdomain 1.3: Implement performance optimization strategies for compute, storage, and database resources.

    4.A storage audit finds dozens of EBS volumes attached to a fleet of EC2 instances that are tagged `environment=archive` and have shown near-zero read/write activity in CloudWatch for the past six months, alongside several completely unattached volumes left over from terminated instances. Which actions reduce ongoing EBS cost for this fleet? (Select TWO.)(Select 2)

    1. A.Migrate the low-activity, tagged archive volumes from their current SSD type to sc1 Cold HDD, which is priced for exactly this infrequently accessed access pattern.
    2. B.Identify and delete the unattached leftover volumes after confirming with tags that they are no longer needed, since unattached volumes still incur storage charges.
    3. C.Leave the unattached volumes in place indefinitely as a safety measure, since AWS documentation states that EBS automatically stops billing once a volume is detached.
    4. D.Convert every archive volume's type to io2 Block Express, since the highest-performance IOPS tier is always the most cost-efficient choice for long-term storage.
    5. E.Enable EBS Multi-Attach on each archive volume so multiple future instances can share it, which AWS documentation states reduces the per-volume storage rate.
    Show answer & explanation

    Correct answers: A, B — Migrate the low-activity, tagged archive volumes from their current SSD type to sc1 Cold HDD, which is priced for exactly this infrequently accessed access pattern.; Identify and delete the unattached leftover volumes after confirming with tags that they are no longer needed, since unattached volumes still incur storage charges.

    • A. sc1 is priced for infrequently accessed, throughput-oriented data and is far cheaper per gigabyte than SSD tiers, so moving genuinely idle archive volumes there directly reduces their ongoing storage cost while keeping them attachable.
    • B. EBS volumes continue to incur storage charges whether or not they are attached to a running instance, so removing confirmed-unneeded leftover volumes stops unnecessary spend.
    • C. Detaching a volume from an instance does not stop its billing; EBS charges for provisioned storage regardless of attachment state, so leaving unattached volumes in place keeps accruing cost.
    • D. io2 Block Express is priced for the highest sustained IOPS and lowest latency tier and costs more than general-purpose or HDD types; it is not a cost-efficient choice for rarely accessed archive data.
    • E. EBS Multi-Attach lets multiple Nitro instances share one io1/io2 volume concurrently for clustering use cases; it has no effect on the per-gigabyte storage price and does not apply to sc1 volumes at all.

    Subdomain 1.3: Implement performance optimization strategies for compute, storage, and database resources.

    5.A company stores 50 TB of compliance logs in S3 that are accessed daily for the first 30 days, occasionally for the following 90 days, and then almost never but must be retained for 7 years for audits. The team wants to minimize storage cost automatically without manually tracking access patterns. Which combination of actions should they take? (Select TWO.)(Select 2)

    1. A.Create an S3 Lifecycle rule that transitions objects from S3 Standard to S3 Standard-IA after 30 days, matching the drop-off in access frequency.
    2. B.Add a second lifecycle transition rule that moves objects from S3 Standard-IA to S3 Glacier Deep Archive after 120 days, ahead of the 7-year retention window.
    3. C.Manually export a monthly access report and have an engineer move objects between storage classes by hand based on that report each time.
    4. D.Store all 50 TB permanently in S3 Standard so every object stays instantly retrievable at consistent low latency for the full 7-year retention period.
    5. E.Enable S3 Versioning on the bucket, since versioning by itself is documented to automatically transition older object versions into lower-cost storage classes.
    Show answer & explanation

    Correct answers: A, B — Create an S3 Lifecycle rule that transitions objects from S3 Standard to S3 Standard-IA after 30 days, matching the drop-off in access frequency.; Add a second lifecycle transition rule that moves objects from S3 Standard-IA to S3 Glacier Deep Archive after 120 days, ahead of the 7-year retention window.

    • A. Transitioning to Standard-IA after the 30-day period of frequent access matches the described drop-off in access and reduces storage cost for objects that are only occasionally read afterward.
    • B. Moving to Glacier Deep Archive at day 120 (after the 30-day plus 90-day active-and-occasional window) fits data that must be retained for years but is almost never retrieved, minimizing long-term storage cost automatically.
    • C. A manual monthly process requires ongoing engineer effort and human judgment, which is exactly what the team wants to avoid by asking for an automatic, hands-off solution.
    • D. Keeping all data in S3 Standard for 7 years guarantees fast retrieval but is the most expensive option and ignores the described access pattern entirely, defeating the cost-minimization goal.
    • E. Versioning preserves prior object versions when objects are overwritten or deleted; it does not move current data between storage classes on its own and must be paired with a lifecycle rule to do so.

    Subdomain 1.3: Implement performance optimization strategies for compute, storage, and database resources.

    6.A rendering farm of Linux EC2 instances in a single Region needs a shared file system so hundreds of instances can concurrently read and write the same project files with standard file-locking semantics, and the workload's throughput needs scale up and down unpredictably throughout the day. Which storage solution fits best?

    1. A.Amazon EFS using Elastic throughput mode, which automatically scales throughput up or down with workload activity and supports concurrent multi-instance NFS access.
    2. B.A single Amazon EBS io2 volume shared across all instances using EBS Multi-Attach, since Multi-Attach volumes provide POSIX file-locking across every attached instance.
    3. C.An Amazon S3 bucket mounted with a third-party FUSE driver, since S3 natively supports POSIX file locking and concurrent write access identical to a file system.
    4. D.Amazon FSx for Windows File Server, since it is the AWS-native choice for concurrent multi-instance file sharing regardless of the operating system involved.
    Show answer & explanation

    Correct answer: A — Amazon EFS using Elastic throughput mode, which automatically scales throughput up or down with workload activity and supports concurrent multi-instance NFS access.

    • A. EFS is a managed, elastic NFS file system built for exactly this pattern: many instances across a Region can mount it concurrently with standard file locking, and Elastic throughput mode is designed for unpredictable, spiky performance needs without manual provisioning.
    • B. EBS Multi-Attach lets multiple Nitro instances attach the same io1/io2 volume, but it does not provide a file system or coordinate POSIX file locking between instances; the instances would need their own cluster-aware file system layered on top.
    • C. S3 is an object store, not a POSIX file system; third-party FUSE drivers can approximate file access but do not provide true POSIX file locking or the concurrent read/write semantics this rendering workload needs.
    • D. FSx for Windows File Server uses the SMB protocol and is designed for Windows-based workloads; it is not the natural fit for a fleet of Linux instances that need standard NFS file-locking semantics.

    Subdomain 1.2: Identify and remediate issues by using monitoring and availability metrics.

    7.A CloudOps engineer wants a single alert to fire only when both an EC2 instance's CPU utilization alarm and its status check failure alarm are simultaneously in ALARM state, so noisy single-metric spikes stop paging the on-call team. Which CloudWatch feature should the engineer configure?

    1. A.A composite alarm with a rule expression that requires both underlying alarms to be in ALARM state before it changes state
    2. B.A single metric alarm on a math expression that averages the CPU utilization and status check metrics together
    3. C.An EventBridge rule that matches either alarm's state-change event and forwards both to the same SNS topic
    4. D.Two separate CloudWatch dashboards, one per alarm, viewed side by side so an on-call engineer manually correlates state changes
    Show answer & explanation

    Correct answer: A — A composite alarm with a rule expression that requires both underlying alarms to be in ALARM state before it changes state

    • A. Composite alarms evaluate the alarm states of other alarms using a rule expression such as AND, so the composite only enters ALARM when every referenced alarm is also in ALARM, which is exactly the noise-reduction behavior described.
    • B. Averaging a percentage metric with a binary pass/fail status check metric produces a meaningless blended value and cannot represent the logical AND of two independent alarm states.
    • C. Matching on either alarm's event is a logical OR, so a page would still fire on a single alarm going into ALARM state, which does not achieve the requirement.
    • D. Dashboards only visualize data and never evaluate conditions or send notifications, so this cannot replace an automated combined alarm.

    Subdomain 1.2: Identify and remediate issues by using monitoring and availability metrics.

    8.A CloudOps engineer built an EventBridge rule with an event pattern targeting a Lambda function, but the function never receives any invocations even though matching events are visible in CloudTrail. Which of the following are valid root causes the engineer should investigate? (Select TWO.)(Select 2)

    1. A.The event pattern JSON does not match the structure of the incoming events, so EventBridge quietly skips routing them to the target
    2. B.The Lambda function's resource-based policy does not grant the events.amazonaws.com principal permission to invoke the function
    3. C.The Lambda function's execution role is missing the logs:CreateLogGroup permission needed to write invocation output to CloudWatch Logs
    4. D.The EventBridge rule and the Lambda function target were created in two different AWS partitions within the same commercial account
    5. E.The Lambda function is configured with reserved concurrency set to a positive value that still leaves capacity for new invocations
    Show answer & explanation

    Correct answers: A, B — The event pattern JSON does not match the structure of the incoming events, so EventBridge quietly skips routing them to the target; The Lambda function's resource-based policy does not grant the events.amazonaws.com principal permission to invoke the function

    • A. If the pattern's field values or structure do not align with the actual event content, EventBridge silently does not match the event, so the target is never invoked even though the source events exist.
    • B. EventBridge needs an explicit invoke permission on the Lambda function's resource policy; without it, delivery to the target fails even when the rule matches, which is a common misconfiguration.
    • C. Missing logging permissions would prevent the function from writing log output, but it does not prevent EventBridge from invoking the function in the first place, so this would not explain zero invocations.
    • D. Rules and their targets are created within the same standard partition as the account by default, and cross-partition rule creation is not a realistic misconfiguration for this scenario.
    • E. A positive reserved concurrency value simply guarantees capacity for the function; it does not block invocations, so this would not cause the function to never be invoked.

    Subdomain 1.2: Identify and remediate issues by using monitoring and availability metrics.

    9.A CloudOps engineer wants to automatically detect a specific error string appearing in application logs and trigger a Lambda-based remediation function within minutes of the error occurring, using only native CloudWatch capabilities. Which two actions together achieve this? (Select TWO.)(Select 2)

    1. A.Create a CloudWatch Logs metric filter that increments a custom metric each time the error string appears in the log group
    2. B.Create a CloudWatch alarm on that metric that invokes the Lambda function through an SNS topic once the threshold is breached
    3. C.Enable CloudTrail data events for the log group so every log line is recorded as a discrete management event
    4. D.Configure AWS Config to evaluate the log group against a managed rule that checks for the error string once every twenty-four hours
    5. E.Enable VPC Flow Logs on the application's subnet so the error string is captured alongside network traffic records
    Show answer & explanation

    Correct answers: A, B — Create a CloudWatch Logs metric filter that increments a custom metric each time the error string appears in the log group; Create a CloudWatch alarm on that metric that invokes the Lambda function through an SNS topic once the threshold is breached

    • A. A metric filter scans incoming log events for a pattern and increments a custom metric whenever it finds a match, turning an unstructured log string into a numeric CloudWatch metric that can be alarmed on.
    • B. Once the filter produces a metric, a CloudWatch alarm on that metric can invoke the Lambda function through an SNS topic as soon as the threshold is breached, closing the loop from log event to remediation within minutes.
    • C. CloudTrail data events record data-plane API activity such as object-level S3 access; they do not scan or capture application log line content, so this does not help detect the error string.
    • D. A daily Config rule evaluation runs far too infrequently to trigger remediation within minutes of the error occurring, and Config rules evaluate resource configuration rather than log content.
    • E. VPC Flow Logs capture network traffic metadata such as source, destination, and port; they do not contain application log content and cannot be used to detect an error string in the logs.

    Domain 2: Reliability and Business Continuity

    Subdomain 2.2: Implement highly available and resilient environments.

    10.A CloudOps engineer notices that when one EC2 instance behind an Application Load Balancer starts returning HTTP 500 errors, the target stays marked healthy for almost two minutes before the load balancer stops sending it traffic, causing a visible spike in failed customer requests. The health check interval is currently 30 seconds with an unhealthy threshold of 2. Which change reduces detection time while keeping the check reliable against transient blips?

    1. A.Lower the health check interval to 10 seconds and keep the unhealthy threshold at 2 consecutive failed checks before marking the target out of service.
    2. B.Switch the target group health check protocol from HTTP to TCP so the load balancer only confirms that the listening port is still accepting connections.
    3. C.Increase the health check timeout to 60 seconds so slow responses during a transient error are not counted as an immediate health check failure.
    4. D.Raise the unhealthy threshold to 5 consecutive failed checks so a single misbehaving instance is confirmed unhealthy before it is removed from rotation.
    Show answer & explanation

    Correct answer: A — Lower the health check interval to 10 seconds and keep the unhealthy threshold at 2 consecutive failed checks before marking the target out of service.

    • A. Shortening the interval means each consecutive failure is detected sooner, so two consecutive failures at 10-second spacing are confirmed in roughly 20 seconds instead of 60, cutting detection time without removing the requirement for repeated failures.
    • B. A TCP check only verifies the port accepts a connection; it would not detect application-layer 500 responses at all, so unhealthy instances serving errors could remain in service indefinitely.
    • C. Lengthening the timeout gives a struggling target more time to respond before a check counts as failed, which slows detection of a genuinely broken instance rather than speeding it up.
    • D. Requiring five consecutive failures before removal extends the time an error-returning instance stays in rotation, worsening the exact symptom the engineer is trying to fix.

    Subdomain 2.2: Implement highly available and resilient environments.

    11.During a scale-in event, an Auto Scaling group terminates instances behind an Application Load Balancer, and several in-flight customer checkout requests are cut off mid-transaction, producing client errors. Which target group setting should the team increase so in-flight requests can complete before a terminating instance stops receiving new connections and is removed?

    1. A.Increase the target group's deregistration delay so the load balancer stops sending new requests to the target but keeps existing connections open long enough to finish.
    2. B.Increase the health check unhealthy threshold count so more consecutive failed checks are required before the target is marked as unhealthy and drained.
    3. C.Increase the Auto Scaling group's default cooldown period so no further scaling activities are triggered immediately after the scale-in event completes.
    4. D.Increase the load balancer's idle timeout value so connections that have been open the longest are never closed automatically while they wait for the next incoming request.
    Show answer & explanation

    Correct answer: A — Increase the target group's deregistration delay so the load balancer stops sending new requests to the target but keeps existing connections open long enough to finish.

    • A. Deregistration delay (connection draining) controls how long a target that is being deregistered continues to complete existing in-flight requests before the connection is forcibly closed, which is exactly the gap causing dropped checkouts here.
    • B. The unhealthy threshold governs how many failed health checks are needed before a target is flagged unhealthy; it does not affect what happens to in-flight requests during a planned deregistration triggered by scale-in.
    • C. The scaling cooldown period only delays additional scaling actions after one completes; it has no effect on whether an already-terminating instance finishes requests already in progress.
    • D. Idle timeout closes connections that have been inactive for too long; it does not keep a deregistering target reachable for active requests, so it would not prevent the described drops.

    Subdomain 2.2: Implement highly available and resilient environments.

    12.A workload runs in a VPC with private subnets in three Availability Zones, and instances in each private subnet route outbound internet traffic through a NAT gateway. The team currently has a single NAT gateway placed in one Availability Zone shared by all three private subnets. During a failure of that Availability Zone, instances in the other two zones also lose outbound internet connectivity. How should the design be corrected for zonal fault tolerance?

    1. A.Deploy one NAT gateway per Availability Zone, each in its own public subnet, and route each private subnet's outbound traffic through the NAT gateway in the same zone.
    2. B.Replace the single NAT gateway with a single NAT instance running on a larger EC2 instance type, since NAT instances are inherently resilient to Availability Zone failures.
    3. C.Keep the single shared NAT gateway but enable cross-zone load balancing on it, since that setting extends a NAT gateway's availability guarantee across all zones.
    4. D.Remove the NAT gateway entirely and instead attach an internet gateway directly to each private subnet, since internet gateways are redundant across every Availability Zone by default.
    Show answer & explanation

    Correct answer: A — Deploy one NAT gateway per Availability Zone, each in its own public subnet, and route each private subnet's outbound traffic through the NAT gateway in the same zone.

    • A. A NAT gateway is a zonal resource, so the resilient pattern is one NAT gateway per Availability Zone with each private subnet's route table pointing at the NAT gateway in its own zone, ensuring a single zone's failure only affects that zone's outbound traffic.
    • B. A NAT instance is a single EC2 instance in one Availability Zone regardless of its size, so it does not gain cross-zone resilience and would still be a single point of failure for that zone.
    • C. Cross-zone load balancing is a setting on Elastic Load Balancing target distribution; it has no meaning for a NAT gateway, which is inherently scoped to a single Availability Zone.
    • D. Attaching an internet gateway directly to a private subnet would expose its instances to inbound internet traffic and remove the private subnet's isolation, which is the opposite of the intended design and not how internet gateways are used with private subnets.

    Subdomain 2.1: Implement scalability and elasticity.

    13.An analytics dashboard queries a production RDS for PostgreSQL database heavily for reporting, and this read traffic is starting to compete with the application's own transactional queries on the same instance. The team wants to offload the reporting queries to separate infrastructure without changing the write path. Which approach fits?

    1. A.Create one or more RDS read replicas and point the reporting dashboard at a replica instead of at the primary DB instance directly.
    2. B.Enable RDS Multi-AZ and send the reporting queries to the standby instance, since Multi-AZ standbys accept read traffic in this configuration.
    3. C.Enable storage autoscaling on the primary instance, since additional allocated storage increases the read query throughput available to the dashboard.
    4. D.Configure DynamoDB auto scaling on the primary instance, since Application Auto Scaling manages read throughput for RDS engines as well as DynamoDB.
    Show answer & explanation

    Correct answer: A — Create one or more RDS read replicas and point the reporting dashboard at a replica instead of at the primary DB instance directly.

    • A. A read replica is a read-only copy kept in sync asynchronously, and directing reporting queries at it offloads that read load from the primary without touching the write path.
    • B. A Multi-AZ standby exists for failover and does not accept application read traffic, so redirecting reporting queries there is not a valid way to offload reads.
    • C. Storage autoscaling increases available disk space when free space runs low, but it has no effect on query throughput or the read contention described here.
    • D. DynamoDB auto scaling is a DynamoDB-specific Application Auto Scaling integration and does not apply to relational RDS engines like PostgreSQL.

    Subdomain 2.1: Implement scalability and elasticity.

    14.For a DynamoDB table configured with auto scaling on a provisioned-capacity table, within what range can the target utilization value be set for a scaling policy?

    1. A.The target utilization can be set to any value between 20 and 90 percent of the provisioned read or write capacity.
    2. B.The target utilization can be set to any value between 50 and 100 percent of the provisioned read or write capacity.
    3. C.The target utilization is fixed at exactly 70 percent by DynamoDB and cannot be changed by the customer at all.
    4. D.The target utilization can be set to any value between 0 and 100 percent, with no minimum or maximum boundary enforced.
    Show answer & explanation

    Correct answer: A — The target utilization can be set to any value between 20 and 90 percent of the provisioned read or write capacity.

    • A. DynamoDB auto scaling accepts a target utilization value between 20 and 90 percent, which bounds how aggressively the target-tracking policy reacts to changing capacity consumption.
    • B. The valid range tops out at 90 percent, not 100, and the lower bound is 20 percent rather than 50, so this range does not match the actual configurable boundaries.
    • C. 70 percent is a commonly used example target in AWS documentation, but it is a configurable value the customer chooses, not a value DynamoDB fixes automatically.
    • D. DynamoDB enforces both a floor of 20 percent and a ceiling of 90 percent on target utilization, so an unbounded 0 to 100 percent range is not accurate.

    Subdomain 2.3: Implement backup and restore strategies.

    15.A company's compliance requirement states that in the event of a database failure, at most five minutes of committed transactions may be lost. The RDS for PostgreSQL database already has automated backups enabled with the default retention period. Which restore method should the team plan to use to meet this requirement?

    1. A.Point-in-time restore, because RDS uploads transaction logs to Amazon S3 every five minutes, allowing a restore to any point within the backup retention window.
    2. B.Restore from the most recent daily automated snapshot, because automated snapshots capture the full state of the database at the start of the configured backup window each day.
    3. C.Restore from a manually created DB snapshot taken immediately before the failure was detected, because manual snapshots always reflect the most recent committed transaction.
    4. D.Promote a Multi-AZ standby instance to primary, because the standby always contains every transaction committed up to the exact moment the primary instance failed.
    Show answer & explanation

    Correct answer: A — Point-in-time restore, because RDS uploads transaction logs to Amazon S3 every five minutes, allowing a restore to any point within the backup retention window.

    • A. Automated backups combined with transaction logs uploaded to Amazon S3 roughly every five minutes let RDS reconstruct the database up to a very recent point, which is exactly the five-minute recovery point objective the compliance requirement describes.
    • B. A daily automated snapshot alone only represents the database state at the time that snapshot was taken, so relying on it without transaction log replay could lose up to a full day of committed transactions rather than five minutes.
    • C. A manual snapshot only captures the database at the moment it was created; unless one happened to be taken within five minutes of the failure, it cannot guarantee the required recovery point, and manual snapshots are not created automatically on that cadence.
    • D. A Multi-AZ standby protects against instance or Availability Zone failure through synchronous replication, but it is a high-availability mechanism, not a restore method, and it does not help recover from logical data corruption that has already replicated to the standby.

    Subdomain 2.3: Implement backup and restore strategies.

    16.A company runs Amazon FSx for Windows File Server for its shared user directories and wants automated, scheduled backups without writing custom scripts, along with the ability to restore to a new file system if the original is damaged. Which approach meets this requirement?

    1. A.Add the FSx for Windows File Server file system as a resource in an AWS Backup plan, since AWS Backup natively supports scheduled backups and restores for that FSx deployment type.
    2. B.Configure the Windows guest operating system's Volume Shadow Copy Service to run nightly and copy the resulting shadow copies to an S3 bucket using a scheduled task.
    3. C.Enable Amazon FSx File Gateway on a separate on-premises server to continuously cache and forward every write to a secondary FSx file system in another AWS Region entirely.
    4. D.Rely on the default automatic daily backups that FSx for Windows File Server creates and retains at no cost for the entire life of the file system, with no configuration required at all.
    Show answer & explanation

    Correct answer: A — Add the FSx for Windows File Server file system as a resource in an AWS Backup plan, since AWS Backup natively supports scheduled backups and restores for that FSx deployment type.

    • A. AWS Backup includes native, first-class support for Amazon FSx for Windows File Server, so adding the file system as a resource in a backup plan provides scheduled, automated backups and a supported restore-to-new-file-system workflow without custom scripting.
    • B. Using guest-level Volume Shadow Copy Service and manually shipping the results to S3 reintroduces custom scripting and operational overhead that AWS Backup's native FSx integration is designed to eliminate.
    • C. FSx File Gateway is a mechanism for on-premises access to Amazon FSx, not a Region-to-Region backup or replication feature for an existing FSx for Windows File Server deployment.
    • D. FSx for Windows File Server does support built-in daily automatic backups, but they are retained for a limited period rather than indefinitely, and they still benefit from being centrally scheduled and managed through AWS Backup for consistency with other resources.

    Subdomain 2.3: Implement backup and restore strategies.

    17.A company operating multiple AWS accounts under AWS Organizations must enforce that every account creates DynamoDB and RDS backups on a consistent schedule, and that backups cannot be deleted before their retention period expires even by an account administrator. Which two actions together satisfy both requirements?(Select 2)

    1. A.Use AWS Backup's cross-account management within AWS Organizations to apply a single backup policy that enforces the schedule across every member account automatically.
    2. B.Apply AWS Backup Vault Lock in compliance mode on the backup vaults so retention periods cannot be shortened or backups deleted early, even by the root user.
    3. C.Grant each account administrator an IAM policy that manually schedules DynamoDB and RDS snapshots through the console once per week during a maintenance window.
    4. D.Store all backups in Amazon S3 Glacier Deep Archive buckets under the default bucket policy, relying on that storage class alone to lower long-term retention cost.
    5. E.Configure Amazon EventBridge rules independently in each account to email administrators a reminder whenever a scheduled backup job has not run.
    Show answer & explanation

    Correct answers: A, B — Use AWS Backup's cross-account management within AWS Organizations to apply a single backup policy that enforces the schedule across every member account automatically.; Apply AWS Backup Vault Lock in compliance mode on the backup vaults so retention periods cannot be shortened or backups deleted early, even by the root user.

    • A. AWS Backup's cross-account management feature, built on AWS Organizations, lets an administrator define one backup policy that automatically applies consistent scheduling to DynamoDB, RDS, and other supported resources across every member account, which is exactly the consistent, org-wide enforcement being asked for.
    • B. Backup Vault Lock in compliance mode makes a vault's retention settings immutable and prevents recovery points from being deleted before their retention period expires, even by an account's own administrators, which satisfies the requirement that backups cannot be deleted early.
    • C. Manual, console-driven snapshot scheduling by each account administrator depends on individual follow-through rather than an enforced policy, so it does not guarantee a consistent schedule across every account the way an organization-wide backup policy does.
    • D. Choosing a storage class for long-term retention addresses cost, not whether a consistent backup schedule is enforced across accounts or whether early deletion is prevented.
    • E. Email reminders about missed backups are a monitoring aid after the fact; they do not enforce that backups are actually taken on schedule or block early deletion the way a policy and vault lock do.

    Domain 3: Deployment, Provisioning, and Automation

    Subdomain 3.2: Automate the management of existing resources.

    18.A team needs an EventBridge rule to invoke a Step Functions state machine only when a CodePipeline execution enters the `FAILED` state for pipelines tagged `production`, ignoring failures from any other pipeline. What should the event pattern include to achieve this precise filtering?

    1. A.A pattern matching the CodePipeline state-change source and detail type, with `detail.state` set to `FAILED` and a filter on the pipeline name for production.
    2. B.A pattern matching only the source `aws.codepipeline`, with no detail-level filtering, relying on the state machine to check the state and tag itself.
    3. C.A schedule expression that runs every five minutes and calls the CodePipeline API to list any pipeline executions that failed recently.
    4. D.A pattern matching `detail-type` equal to `AWS API Call via CloudTrail` for any `codepipeline:*` action, filtered by the caller's IAM user.
    Show answer & explanation

    Correct answer: A — A pattern matching the CodePipeline state-change source and detail type, with `detail.state` set to `FAILED` and a filter on the pipeline name for production.

    • A. EventBridge event patterns can match specific fields within the event detail, so filtering on the pipeline state-change source, the `FAILED` value for `detail.state`, and a production-specific identifier such as pipeline name or tag ensures the rule only matches the exact failures the team cares about.
    • B. Matching only the source without detail-level filtering would invoke the state machine for every CodePipeline state change across every pipeline, pushing filtering work into the state machine that EventBridge's pattern matching is built to handle upfront.
    • C. Polling every five minutes for failed executions reintroduces latency and API calls that a native state-change event and precise pattern match avoid, and it still requires writing logic to filter to only production pipelines.
    • D. Matching CloudTrail API call events for any CodePipeline action captures far more than failure state transitions, such as start or update calls, and filtering by IAM caller does not correspond to filtering by pipeline tag or execution outcome.

    Subdomain 3.2: Automate the management of existing resources.

    19.A team configured a Config rule with an attached Systems Manager Automation remediation and automatic remediation enabled, but the remediation keeps failing with an access-denied error when the runbook tries to modify the non-compliant resource. Which two checks should the team perform first to diagnose this? (Select TWO.)(Select 2)

    1. A.Confirm the IAM role assumed by the remediation action has permissions for the specific API calls the runbook's steps perform.
    2. B.Confirm the runbook's input parameters correctly reference the non-compliant resource identifier that Config passes to it.
    3. C.Confirm the Config rule's evaluation frequency is set to a value lower than five minutes, since slower evaluation always causes access denials.
    4. D.Confirm the S3 bucket storing Config's configuration snapshots has public read access enabled for the remediation role to retrieve them.
    5. E.Confirm AWS Config conformance packs are disabled, since conformance packs override and block Automation remediation permissions.
    Show answer & explanation

    Correct answers: A, B — Confirm the IAM role assumed by the remediation action has permissions for the specific API calls the runbook's steps perform.; Confirm the runbook's input parameters correctly reference the non-compliant resource identifier that Config passes to it.

    • A. An access-denied error during remediation execution most directly points to the IAM role the remediation assumes lacking permission for the API calls its runbook steps actually make, so verifying and correcting that role's policy is a primary diagnostic step.
    • B. If the runbook's parameters do not correctly map to the resource identifier Config supplies (for example, an incorrect resource ID reference), the runbook can fail on the wrong resource or with a malformed request, so checking the parameter mapping is a reasonable next diagnostic step.
    • C. Config rule evaluation frequency controls how often compliance is checked; it has no relationship to whether the remediation role has the IAM permissions needed to modify a resource, so this is not a cause of access-denied errors.
    • D. Config's snapshot bucket permissions govern who can read stored configuration history exports; the remediation role does not need public read access to that bucket to modify the actual non-compliant resource, so this is not relevant to the described failure.
    • E. Conformance packs are a deployment and grouping mechanism for rules and remediations; they do not override or block IAM permissions granted to a remediation role, so disabling them would not resolve an access-denied error.

    Subdomain 3.2: Automate the management of existing resources.

    20.A company wants an EBS-volume tagging remediation to run automatically the moment AWS Config finds a volume missing the `CostCenter` tag, deployed consistently to every account in an AWS Organization, using a rule the company writes itself rather than only AWS managed rules. Which two statements are correct design facts for this rollout? (Select TWO.)(Select 2)

    1. A.AWS Config lets you attach a Systems Manager Automation remediation action to a custom rule using the identical mechanism used for managed rules.
    2. B.A CloudFormation StackSet can deploy the same Config rule and remediation action to every account in the organization from one central template.
    3. C.Custom Config rules cannot use automatic remediation at all, so a person must manually trigger the tagging action in every account each time.
    4. D.Because the custom rule's evaluation logic runs in Lambda, its remediation action must also be a second Lambda function instead of an Automation runbook.
    5. E.StackSets exclude the AWS Config rule resource type, so Config rules always require a separate manual deployment step per account.
    Show answer & explanation

    Correct answers: A, B — AWS Config lets you attach a Systems Manager Automation remediation action to a custom rule using the identical mechanism used for managed rules.; A CloudFormation StackSet can deploy the same Config rule and remediation action to every account in the organization from one central template.

    • A. Config remediation actions attach the same way to custom rules as to managed rules, so this is an accurate statement about the platform's capability.
    • B. Deploying via a StackSet is the documented way to roll the same rule and remediation configuration out to every account in an organization from a central template.
    • C. Automatic remediation is available on custom rules just as it is on managed rules, so this claim about a hard restriction is incorrect.
    • D. Remediation actions are independent of how the rule evaluates compliance; an Automation runbook can remediate a Lambda-backed custom rule without needing a second function.
    • E. AWS Config rules are a supported CloudFormation resource type and can be deployed through StackSets, so this exclusion claim is incorrect.

    Subdomain 3.1: Provision and maintain cloud resources.

    21.An operations team notices that a CloudFormation stack update they submitted is taking longer than expected. Before the change actually modifies any resources, they want to see exactly which resources will be added, modified, or replaced, including whether any replacement would cause data loss. What should they use?

    1. A.Create a change set for the stack update and review the proposed add, modify, or replace actions before executing it.
    2. B.Enable drift detection on the stack and compare its reported drift results against the currently submitted template version.
    3. C.Open the stack's event history in the console and read through the events generated by the previous stack update.
    4. D.Export the stack's outputs and diff them against values recorded during the stack's last successful update operation.
    Show answer & explanation

    Correct answer: A — Create a change set for the stack update and review the proposed add, modify, or replace actions before executing it.

    • A. A change set previews exactly which resources CloudFormation will add, modify, or replace, and flags replacements that could cause data loss, before any change is applied.
    • B. Drift detection compares live resource state against the template for resources already deployed; it does not preview the effect of a pending update.
    • C. Event history only records what happened during past stack operations, so it cannot show the impact of an update that has not run yet.
    • D. Stack outputs are values exported after a successful deployment and do not describe which resources a pending update would add, modify, or replace.

    Subdomain 3.1: Provision and maintain cloud resources.

    22.What does AWS Resource Access Manager (RAM) fundamentally enable an AWS account owner to do?

    1. A.Share resources that the account owns with specific other accounts, an organizational unit, or an entire Organization.
    2. B.Automatically replicate every resource in the account into every other member account of the same AWS Organization.
    3. C.Create IAM users directly inside another account without that account's own administrator ever granting any permissions.
    4. D.Convert a standalone AWS account automatically into a full member account of an AWS Organization.
    Show answer & explanation

    Correct answer: A — Share resources that the account owns with specific other accounts, an organizational unit, or an entire Organization.

    • A. AWS RAM lets a resource owner create a resource share that grants other accounts, an OU, or the whole organization access to use resources the owner already created, without duplicating them.
    • B. RAM shares existing resources for other accounts to use; it does not automatically copy or replicate resources into every member account of an organization.
    • C. Creating IAM users in another account still requires that account's own administrative permissions; RAM has no mechanism to bypass another account's IAM controls.
    • D. Joining an AWS Organization is managed through AWS Organizations invitations and account management, which is unrelated to what AWS RAM does with resource sharing.

    Subdomain 3.1: Provision and maintain cloud resources.

    23.A company plans to use CloudFormation StackSets with service-managed permissions to deploy a required security baseline stack across every account in its AWS Organization automatically, including accounts created in the future. Which statements about this configuration are correct? (Choose two.)(Select 3)

    1. A.Service-managed permissions require the StackSet administrator account to have trusted access enabled with AWS Organizations.
    2. B.Automatic deployment can create stack instances in new accounts as soon as they join a targeted organizational unit.
    3. C.Self-managed permissions must first be manually configured in every single target account before service-managed mode is enabled.
    4. D.Service-managed StackSets can only target the organization's designated management account and no other accounts.
    5. E.Service-managed permissions remove the need to manually create an execution role in each target account.
    Show answer & explanation

    Correct answers: A, B, E — Service-managed permissions require the StackSet administrator account to have trusted access enabled with AWS Organizations.; Automatic deployment can create stack instances in new accounts as soon as they join a targeted organizational unit.; Service-managed permissions remove the need to manually create an execution role in each target account.

    • A. Service-managed StackSets depend on trusted access being enabled between the StackSet administrator and AWS Organizations so CloudFormation can manage permissions across the organization on the customer's behalf.
    • B. With automatic deployment enabled, a new account that joins a targeted OU automatically receives a stack instance without any manual per-account action, matching the future-account requirement.
    • C. Self-managed and service-managed are alternative permission models; self-managed setup in every account is not a prerequisite for choosing service-managed mode.
    • D. Service-managed StackSets are designed to target member accounts across an organization or specific OUs, not only the management account itself.
    • E. Service-managed permissions rely on the Organizations trust relationship instead of a manually created execution role in each target account, removing that per-account setup step.

    Domain 4: Security and Compliance

    Subdomain 4.1: Implement and manage security and compliance tools and policies.

    24.A retailer's workforce identities live in an external SAML 2.0 identity provider, and the security team wants employees to sign in once through that provider and land in the AWS Management Console with temporary credentials scoped to a specific IAM role, without creating IAM users for each employee. Which approach achieves this?

    1. A.Configure the identity provider as a SAML provider in IAM, create a role that trusts it, and let `sts:AssumeRoleWithSAML` issue temporary console credentials.
    2. B.Create an IAM user for each employee with a randomly generated password, then have the identity provider auto-fill that password during the SAML sign-in flow.
    3. C.Attach the SAML metadata document directly to an S3 bucket policy so the identity provider can grant console access without involving IAM roles at all.
    4. D.Enable AWS Config aggregation for the identity provider's directory so every employee record is treated as a valid AWS principal automatically.
    Show answer & explanation

    Correct answer: A — Configure the identity provider as a SAML provider in IAM, create a role that trusts it, and let `sts:AssumeRoleWithSAML` issue temporary console credentials.

    • A. Registering the SAML provider in IAM and creating a role that trusts it is the standard federation pattern; the provider's assertion is exchanged via `AssumeRoleWithSAML` for temporary, role-scoped credentials.
    • B. Creating an IAM user per employee is exactly the long-term-credential overhead federation is meant to avoid, and SAML assertions are not designed to auto-fill IAM console passwords.
    • C. An S3 bucket policy governs access to objects in that bucket; it has no role in authenticating console sign-ins or issuing temporary credentials to federated users.
    • D. AWS Config aggregates configuration and compliance data across accounts; it has no function for authenticating external identities or granting console access.

    Subdomain 4.1: Implement and manage security and compliance tools and policies.

    25.An enterprise already manages all of its employee accounts in an on-premises Active Directory and wants AWS IAM Identity Center to use those existing users and groups, rather than recreating identities directly inside IAM Identity Center. Which configuration approach meets this requirement?

    1. A.Connect IAM Identity Center to the on-premises Active Directory as an external identity source, so existing users and groups are used for sign-in and access assignment.
    2. B.Export a CSV file of Active Directory users once and bulk-import it into IAM Identity Center's built-in directory, then manually re-sync the file every quarter.
    3. C.Create a matching IAM user in every AWS account for each Active Directory account, then configure IAM Identity Center to authenticate against those IAM users directly.
    4. D.Attach an SCP to the organization root that references the Active Directory domain name, which AWS Organizations then uses to synchronize identities automatically.
    Show answer & explanation

    Correct answer: A — Connect IAM Identity Center to the on-premises Active Directory as an external identity source, so existing users and groups are used for sign-in and access assignment.

    • A. IAM Identity Center supports connecting to an external identity source, including Active Directory, so that existing users and groups continue to be the source of truth instead of duplicating identities.
    • B. A one-time CSV import followed by manual quarterly re-syncs does not keep identities current, defeats the goal of using the existing directory live, and is not how Identity Center's directory integration is designed to work.
    • C. Creating IAM users in every account is exactly the long-term-credential, per-account overhead that Identity Center and federation are meant to eliminate, and Identity Center does not authenticate against individual IAM users this way.
    • D. SCPs are permission guardrails for IAM users and roles in member accounts; they have no mechanism for referencing or synchronizing an external directory's identities.

    Subdomain 4.1: Implement and manage security and compliance tools and policies.

    26.A team wants any S3 bucket found without default encryption enabled to be corrected automatically, without a human manually applying the fix each time AWS Config detects the noncompliant configuration. Which two elements of an AWS Config rule setup are required to achieve automatic remediation?(Select 2)

    1. A.A Config rule, such as the managed `S3_BUCKET_SERVER_SIDE_ENCRYPTION_ENABLED` rule, that evaluates each bucket's configuration and marks it compliant or noncompliant.
    2. B.A remediation configuration that targets an SSM document (or similar automation) and is set to trigger automatically whenever the rule reports noncompliance.
    3. C.A manually scheduled Lambda function that an engineer must invoke by hand each time they notice a noncompliant bucket appear in the Config dashboard.
    4. D.A permanent disabling of S3 Block Public Access account-wide, since automatic remediation requires public access to be allowed during the correction process.
    5. E.An SCP that denies `s3:CreateBucket` across the account, since preventing new buckets from being created is what AWS Config calls automatic remediation.
    Show answer & explanation

    Correct answers: A, B — A Config rule, such as the managed `S3_BUCKET_SERVER_SIDE_ENCRYPTION_ENABLED` rule, that evaluates each bucket's configuration and marks it compliant or noncompliant.; A remediation configuration that targets an SSM document (or similar automation) and is set to trigger automatically whenever the rule reports noncompliance.

    • A. The Config rule is the detection half of the pipeline: it evaluates each bucket against the encryption requirement and produces the compliance status that triggers any remediation.
    • B. A remediation configuration linking the rule to an automation document, with automatic triggering enabled, is what turns a noncompliant finding into a corrective action without manual intervention.
    • C. A remediation an engineer must invoke by hand is manual, not automatic, which is the opposite of what the team is asking for in this scenario.
    • D. Disabling Block Public Access has nothing to do with enabling encryption remediation, and automatic remediation does not require public access to be permitted during the fix.
    • E. Blocking new bucket creation with an SCP does not correct existing noncompliant buckets and is not what AWS Config remediation configurations refer to as automatic remediation.

    Subdomain 4.2: Implement strategies to protect data and infrastructure.

    27.A platform team runs workloads on EC2, hosts container images in Amazon ECR, and deploys several AWS Lambda functions, and wants continuous vulnerability visibility across all three without scheduling manual scans. Which two statements accurately describe how Amazon Inspector supports this environment? (Select TWO.)(Select 2)

    1. A.Inspector automatically discovers and continuously rescans eligible EC2 instances, ECR container images, and Lambda functions as changes and new CVEs appear.
    2. B.Inspector calculates a risk score for each finding by adjusting the base CVSS score using details of the specific environment the vulnerable resource runs in.
    3. C.Inspector requires an administrator to manually trigger a new scan for each EC2 instance every time a new CVE is published affecting that particular instance type.
    4. D.Inspector only supports scanning EC2 instances and does not have any capability to scan container images stored in ECR or AWS Lambda function code.
    5. E.Inspector automatically deletes any Lambda function found to have a critical vulnerability finding, without requiring administrator confirmation first.
    Show answer & explanation

    Correct answers: A, B — Inspector automatically discovers and continuously rescans eligible EC2 instances, ECR container images, and Lambda functions as changes and new CVEs appear.; Inspector calculates a risk score for each finding by adjusting the base CVSS score using details of the specific environment the vulnerable resource runs in.

    • A. Inspector's continuous scanning model automatically rescans resources in response to changes, new packages, patches, and newly published CVEs, without manual scheduling.
    • B. Inspector produces a risk score tailored to the resource's actual network exposure and environment, adjusting the base CVSS score rather than reporting it unmodified.
    • C. This contradicts Inspector's continuous, automatic rescanning model, which does not require an administrator to manually trigger scans per instance per CVE.
    • D. Inspector explicitly supports EC2 instances, ECR container images, and Lambda functions, so this description of EC2-only support is incorrect.
    • E. Inspector reports findings for review and remediation; it does not automatically delete or modify the vulnerable resource itself.

    Subdomain 4.2: Implement strategies to protect data and infrastructure.

    28.An organization with dozens of AWS accounts under AWS Organizations wants a single security team to see aggregated findings and compliance status across every account and region from one place. Which two configurations should the team put in place? (Select TWO.)(Select 2)

    1. A.Designate a delegated administrator account for AWS Security Hub and configure cross-Region aggregation so findings from every linked account and Region roll up centrally.
    2. B.Enable AWS Config with an aggregator configured in the designated account so configuration and compliance data from every member account and Region is collected centrally.
    3. C.Require every account owner to individually email a weekly PDF export of their own local GuardDuty findings to the central security team's shared mail inbox each week.
    4. D.Configure each account to send its own CloudTrail logs to a locally stored S3 bucket that only that account's own local administrators are ever permitted to read.
    5. E.Disable Security Hub in every member account except one, so that only that single account in the entire organization ever generates any security findings at all.
    Show answer & explanation

    Correct answers: A, B — Designate a delegated administrator account for AWS Security Hub and configure cross-Region aggregation so findings from every linked account and Region roll up centrally.; Enable AWS Config with an aggregator configured in the designated account so configuration and compliance data from every member account and Region is collected centrally.

    • A. A Security Hub delegated administrator with cross-Region aggregation is the designed mechanism for centrally viewing findings across an organization's accounts and Regions.
    • B. A Config aggregator in the delegated account centralizes configuration and compliance data across the organization, complementing Security Hub's findings aggregation.
    • C. Manual weekly email exports do not scale, are error-prone, and do not provide the near-real-time centralized visibility the security team needs.
    • D. Locally scoped, per-account CloudTrail buckets that only local administrators can read work against the goal of centralized, organization-wide visibility.
    • E. Disabling Security Hub everywhere except one account would stop findings from being generated in every other account, the opposite of aggregating all accounts' findings.

    Domain 5: Networking and Content Delivery

    Subdomain 5.1: Implement and optimize networking features and connectivity.

    29.An engineer creates a new subnet inside an existing VPC that already has an internet gateway attached, and launches an EC2 instance in the subnet with a public IP address assigned. The instance cannot reach the internet. The main route table for the VPC only routes local VPC traffic. What is the most likely cause, and what should the engineer do to fix it?

    1. A.The new subnet is still associated with the main route table, which lacks a route to the internet gateway; associate a route table that has one.
    2. B.The instance's public IP address was allocated after launch, so it must be released and manually reassigned through the Elastic IP console first.
    3. C.The internet gateway needs a security group attached that allows outbound traffic from the subnet's CIDR range before any instance can reach the internet.
    4. D.Internet gateways only route traffic for instances launched in the account's default VPC, so a custom VPC subnet can never reach an internet gateway.
    Show answer & explanation

    Correct answer: A — The new subnet is still associated with the main route table, which lacks a route to the internet gateway; associate a route table that has one.

    • A. New subnets are implicitly associated with the VPC's main route table unless explicitly assigned elsewhere, and if that route table has no route to the internet gateway, traffic to the internet is dropped; creating or updating a route table with a default route to the gateway resolves it.
    • B. Public IP addresses assigned at launch are attached immediately and do not require a separate reassignment step through Elastic IP allocation, so this is not the cause of the connectivity failure.
    • C. Internet gateways are not attached to security groups and do not filter traffic themselves; access control for instance traffic is handled by the instance's own security group and the subnet's network ACL, not the gateway.
    • D. An internet gateway attached to a VPC serves every subnet in that VPC that is routed to it, regardless of whether the VPC is the account's default VPC or a custom VPC created later.

    Subdomain 5.1: Implement and optimize networking features and connectivity.

    30.A network engineer is designing the VPC for a new three-tier web application. Public-facing load balancers must be reachable from the internet, application servers must run in subnets with no direct internet route, and the database tier must never route to or from the internet in either direction. Select the components the engineer should include to meet these requirements. (Select THREE.)(Select 3)

    1. A.A public subnet with a route table that sends default traffic to an internet gateway, used for the load balancers.
    2. B.Private subnets for the application tier with a route table that sends default outbound traffic to a NAT gateway in the public subnet.
    3. C.Isolated private subnets for the database tier with a route table that contains only the local VPC route and no default route.
    4. D.A single shared subnet for all three tiers, secured only by per-instance security groups instead of using subnet-level route table separation.
    5. E.An internet gateway route added directly to the database tier's route table so backups can be pushed to an external service.
    6. F.A NAT gateway placed in the database tier's subnet so database instances can resolve external package repositories directly.
    Show answer & explanation

    Correct answers: A, B, C — A public subnet with a route table that sends default traffic to an internet gateway, used for the load balancers.; Private subnets for the application tier with a route table that sends default outbound traffic to a NAT gateway in the public subnet.; Isolated private subnets for the database tier with a route table that contains only the local VPC route and no default route.

    • A. A public subnet routed to an internet gateway is the correct place for internet-facing load balancers, since they must accept inbound connections from clients on the internet.
    • B. Application servers need outbound-only internet access for tasks like patching, so a private subnet routing default traffic to a NAT gateway matches the stated requirement of no direct internet route while still allowing egress.
    • C. The database tier should sit in isolated private subnets whose route table has no path to the internet at all, which satisfies the requirement that this tier never routes to or from the internet.
    • D. Collapsing all three tiers into one subnet removes the network-level segmentation the scenario requires; security groups alone do not stop the database tier's route table from having internet reachability if one is added later.
    • E. Adding an internet gateway route to the database tier's route table directly violates the stated requirement that the database tier never routes to or from the internet, regardless of the intended use case.
    • F. Placing a NAT gateway in the database subnet gives that tier an outbound path to the internet, which again contradicts the requirement that the database tier have no internet route in either direction.

    Subdomain 5.3: Troubleshoot network connectivity issues.

    31.An operations engineer finds that an EC2 instance in a private subnet can send outbound requests to an external API over port 443, but the responses never arrive back at the instance. The security group allows all outbound traffic and inbound traffic from the API's IP range on port 443. What is the most likely cause?

    1. A.The network ACL associated with the subnet lacks an inbound rule that permits the ephemeral port range used for the return traffic
    2. B.The route table for the private subnet is missing a route to the NAT gateway that handles outbound internet traffic
    3. C.The security group is missing an explicit inbound rule for the ephemeral ports used by the returning response packets
    4. D.The instance's elastic network interface has source/destination checking enabled, which silently drops the asymmetric return traffic path
    Show answer & explanation

    Correct answer: A — The network ACL associated with the subnet lacks an inbound rule that permits the ephemeral port range used for the return traffic

    • A. Network ACLs are stateless, so the return traffic on high-numbered ephemeral ports must be explicitly permitted inbound even though the original request was allowed outbound; a missing ephemeral rule blocks the reply while the outbound request still succeeds. This matches the described symptom exactly.
    • B. A missing NAT gateway route would prevent the outbound request from leaving the subnet at all, so the request would never reach the external API in the first place, which contradicts the scenario where the request is sent successfully.
    • C. Security groups are stateful, so they automatically allow the return traffic for a connection that was permitted outbound; no explicit inbound ephemeral rule is needed at the security group layer, so this is not the cause.
    • D. Source/destination checking only affects whether an instance can forward traffic not addressed to itself, such as for NAT or router configurations, and has no bearing on ephemeral port handling for the instance's own connections.

    Subdomain 5.3: Troubleshoot network connectivity issues.

    32.After deploying an updated version of a JavaScript file to the S3 origin behind a CloudFront distribution, users continue to receive the old version even after refreshing their browsers. The object's `Cache-Control` header specifies a one-hour max-age, but the deployment happened only minutes ago. What should the engineer do to serve the new version immediately?

    1. A.Create a CloudFront invalidation for the object's path so that cached copies at edge locations are removed before the TTL expires
    2. B.Wait for the browser's local cache to expire, since CloudFront itself always serves the newest version regardless of edge cache state
    3. C.Increase the object's `Cache-Control` max-age value in S3, since a longer TTL forces CloudFront to re-fetch the object sooner
    4. D.Restart the CloudFront distribution from the console, since a restart clears all cached content across every edge location instantly
    Show answer & explanation

    Correct answer: A — Create a CloudFront invalidation for the object's path so that cached copies at edge locations are removed before the TTL expires

    • A. An invalidation request explicitly removes the specified object from CloudFront edge caches before its TTL naturally expires, which is the documented way to force edge locations to fetch the updated version from the origin immediately.
    • B. CloudFront caches objects at edge locations for the duration of the configured TTL and does not automatically re-check the origin for a fresher version before that TTL expires, so simply waiting on the browser side would not bypass the edge cache.
    • C. Increasing the max-age value makes CloudFront cache the object for longer, which is the opposite of what is needed here and would make stale content persist even further past the current one-hour setting.
    • D. CloudFront distributions do not have a restart action, and there is no console operation called a distribution restart; clearing cached content at scale is done specifically through invalidations or cache-key changes, not a restart.

    Subdomain 5.2: Configure domains, DNS services, and content delivery.

    33.A central networking account manages a Route 53 Resolver outbound endpoint and a forwarding rule for the domain shared-services.internal, which points to an on-premises DNS server. Ten application accounts in the same AWS Organization need their VPCs to resolve that domain without each account building its own endpoint. What should the networking team do?

    1. A.Share the Resolver rule with the application accounts using AWS Resource Access Manager, then have each application account associate the shared rule with its own VPCs.
    2. B.Export the Resolver rule as an AWS CloudFormation StackSet and deploy an independent copy of the outbound endpoint into every application account.
    3. C.Create a VPC peering connection between the networking account and each application account so their instances query the central account's VPC Resolver directly, per account.
    4. D.Publish the forwarding rule as a Route 53 public hosted zone record so any VPC in the organization can resolve shared-services.internal through recursive DNS.
    Show answer & explanation

    Correct answer: A — Share the Resolver rule with the application accounts using AWS Resource Access Manager, then have each application account associate the shared rule with its own VPCs.

    • A. AWS Resource Access Manager lets a Resolver rule created in one account be shared and then associated with VPCs in other accounts, so a single outbound endpoint can serve every application account without duplication.
    • B. Deploying an independent copy of the endpoint into every application account duplicates infrastructure and the Direct Connect or VPN path instead of reusing the endpoint that already exists.
    • C. VPC peering forwards IP traffic between VPCs but does not by itself change which Resolver an instance uses for DNS; associating a shared Resolver rule is still required.
    • D. shared-services.internal is a private, non-public domain, so publishing it in a public hosted zone would expose internal names and still would not deliver the private forwarding behavior the on-premises server provides.

    Subdomain 5.2: Configure domains, DNS services, and content delivery.

    34.A security analyst is investigating a spike in DNS traffic for a public hosted zone and enables Route 53 query logging to CloudWatch Logs. Which two details will each logged entry provide that help the analyst pinpoint the source and nature of the spike? (Select 2)(Select 2)

    1. A.The DNS response code Route 53 returned for the query, such as NOERROR or NXDOMAIN, which helps identify repeated failed lookups.
    2. B.The Route 53 edge location that responded to the query, letting the analyst see which geographic locations are receiving the traffic.
    3. C.The public IP address and account ID of the AWS customer that owns the EC2 instance which originally issued the DNS query.
    4. D.The full HTTP request body of any web request the client made after resolving the domain name, including headers and cookies, in this log entry.
    5. E.The IAM role or user credentials the client authenticated with before performing the DNS lookup against the hosted zone.
    6. F.A machine learning-generated threat score indicating the likelihood that the specific query is part of a coordinated attack.
    Show answer & explanation

    Correct answers: A, B — The DNS response code Route 53 returned for the query, such as NOERROR or NXDOMAIN, which helps identify repeated failed lookups.; The Route 53 edge location that responded to the query, letting the analyst see which geographic locations are receiving the traffic.

    • A. Each log entry includes the DNS response code returned, such as NOERROR or NXDOMAIN, so an analyst can spot bursts of failed lookups that often indicate scanning or misconfigured clients.
    • B. Each entry records which Route 53 edge location answered the query, giving the analyst geographic insight into where the spike in traffic is originating from.
    • C. Public hosted zone query logs record the resolver's IP address that submitted the query, not the originating EC2 instance's identity or AWS account, since DNS queries do not carry that information.
    • D. Route 53 query logs capture only DNS query and response metadata; they contain no visibility into any subsequent HTTP requests a client makes after resolving a name.
    • E. DNS queries are not authenticated with IAM credentials, so no such credential information exists to be recorded in a query log entry.
    • F. Route 53 query logs are raw structured log entries; they do not include any built-in machine-learning threat scoring for individual queries.

    Subdomain 5.2: Configure domains, DNS services, and content delivery.

    35.An architecture team is documenting when to choose AWS Global Accelerator instead of Amazon CloudFront for a new workload. Which two statements correctly describe a situation where Global Accelerator is the better fit? (Select 2)(Select 2)

    1. A.The workload uses a non-HTTP TCP or UDP protocol that needs network-layer acceleration and failover, which CloudFront's HTTP/HTTPS model does not address.
    2. B.The application needs fixed static IP addresses at the entry point because downstream clients or firewalls allow-list specific IP addresses rather than domain names.
    3. C.The primary goal is to cache static images and video so that repeat requests are served from a location physically close to end users around the world.
    4. D.The workload needs to reduce origin load for frequently requested, cacheable HTTP content by storing copies of that content near end users.
    5. E.The application requires signed URLs or signed cookies to restrict which viewers can retrieve individual private files based on a time-limited signature, per requested file.
    6. F.The team wants to apply AWS WAF web ACL rules to inspect and filter malicious HTTP request patterns before they ever reach the origin servers.
    Show answer & explanation

    Correct answers: A, B — The workload uses a non-HTTP TCP or UDP protocol that needs network-layer acceleration and failover, which CloudFront's HTTP/HTTPS model does not address.; The application needs fixed static IP addresses at the entry point because downstream clients or firewalls allow-list specific IP addresses rather than domain names.

    • A. Global Accelerator operates at the network layer and can accelerate and fail over any TCP or UDP traffic, which fits a non-HTTP protocol that CloudFront's HTTP and HTTPS caching model was not designed to serve.
    • B. Global Accelerator provides fixed static anycast IP addresses for its accelerator, which is exactly what a client or firewall relying on IP allow-listing needs instead of a domain name that can change.
    • C. Caching static images and video for nearby delivery is CloudFront's core use case; Global Accelerator does not cache content at all, so it would not help with this goal.
    • D. Reducing origin load through edge caching of cacheable HTTP content is a CloudFront strength, not something Global Accelerator provides since it forwards traffic rather than caching it.
    • E. Signed URLs and signed cookies are CloudFront features for restricting access to cached private content; Global Accelerator has no equivalent per-file, time-limited access control mechanism.
    • F. AWS WAF web ACLs attach to CloudFront distributions, Application Load Balancers, and API Gateway to inspect HTTP traffic; Global Accelerator does not integrate with WAF for HTTP-layer filtering.

    Want the full experience?

    These are just samples. Practice the full AWS Certified CloudOps Engineer - Associate (SOA-C03) question bank in quiz mode — free, no signup, with domain practice and exam simulation.