AWS Certified Solutions Architect – Associate (SAA-C03) practice questions
211 free questions with answers and explanations.
- 151.A financial institution is building a new trading platform on AWS. They need to store highly sensitive customer trading data in Amazon S3. Due to strict regulatory compliance, all data at rest must be encrypted using encryption keys that are managed and controlled solely by the financial institution, and they must have an audit trail of all key usage. Which S3 encryption option should be chosen?Design Secure Architectures
- 152.A security auditor needs to regularly review all API calls made to an AWS account, including who made the call, when, from where, and which resources were affected. This audit trail must be stored securely and be centrally accessible for multiple accounts within an AWS Organization. Which AWS service should be used to meet these requirements?Design Secure Architectures
- 153.A global company uses AWS Organizations to manage multiple AWS accounts. They want to ensure that no account within any Organizational Unit (OU) can inadvertently or maliciously disable AWS CloudTrail logging. This policy must apply to all existing and future accounts automatically. Which AWS Organizations feature should be used?Design Secure Architectures
- 154.A global e-commerce company uses Amazon CloudFront to deliver its web application content. They have noticed an increasing number of automated attacks, including SQL injection and cross-site scripting (XSS), targeting their application endpoints. They need a scalable solution that can effectively block these types of attacks without introducing significant latency and that can be integrated directly with CloudFront. Which AWS service should they implement?Design Secure Architectures
- 155.A software company is deploying a new web application using AWS Elastic Beanstalk. The application needs to connect to an Amazon RDS MySQL database. To enhance security, the company wants to restrict database access only to the Elastic Beanstalk instances. How should a Solutions Architect configure the security groups to achieve this?Design Secure Architectures
- 156.A software development company uses AWS CodeCommit for source code management. They need to enforce a policy where only developers from a specific IAM group can push code to certain repositories, and only after their code has been reviewed and approved. Additionally, they want to ensure that all changes to these repositories are logged for auditing purposes. How can these requirements be met most effectively?Design Secure Architectures
- 157.A global manufacturing company wants to implement a robust disaster recovery strategy for its critical data stored in Amazon S3. They need to ensure that in the event of an entire AWS Region becoming unavailable, their data remains accessible and is automatically replicated to another AWS Region. The solution must provide strong consistency for replicated objects and maintain object metadata. Which S3 feature should the Solutions Architect recommend?Design Secure Architectures
- 158.A company is building a new application that will store highly sensitive customer data in an Amazon DynamoDB table. Due to compliance requirements, all data must be encrypted at rest, and the encryption keys must be managed by the customer. The solution must also integrate seamlessly with AWS Key Management Service (KMS) for key lifecycle management. Which DynamoDB encryption option should be implemented?Design Secure Architectures
- 159.A financial institution requires that all data stored in Amazon S3 must be encrypted at rest with encryption keys managed and controlled by the institution itself, not by AWS. Which S3 encryption option should be chosen?Design Secure Architectures
- 160.A global consulting firm is migrating its internal knowledge base application to AWS. The application uses a multi-tier architecture with an Application Load Balancer (ALB) distributing traffic to Amazon EC2 instances in private subnets. The EC2 instances need to fetch updates from the internet (e.g., OS patches, package updates) but must not be directly accessible from the internet. Which solution should be implemented to allow outbound internet access while maintaining security?Design Secure Architectures
- 161.A company is migrating its on-premises LDAP directory to AWS and needs a managed directory service that can integrate with existing Windows applications and provide single sign-on (SSO) capabilities. Which AWS directory service should they choose?Design Secure Architectures
- 162.A media company is building a serverless application using AWS Lambda functions and Amazon DynamoDB. The Lambda functions need to read and write data to DynamoDB, and also upload processed files to an Amazon S3 bucket. The security team requires that the Lambda functions only have the absolute minimum permissions necessary for their operations. Which approach should be used to grant these permissions?Design Secure Architectures
- 163.A compliance officer needs to ensure that all API calls made to AWS services across an entire multi-account organization are logged and centrally stored for audit purposes. The logs must be immutable and retained for 7 years. Which solution MOST effectively meets these requirements?Design Secure Architectures
- 164.A company is deploying a new web application on AWS that requires sensitive user data to be stored in an Amazon S3 bucket. The company's security policy mandates that all data stored in S3 must be encrypted at rest using a customer-managed encryption key (CMK) that they control. Additionally, they need to ensure that access to this key is strictly controlled and audited. Which S3 encryption option should they choose to meet these requirements?Design Secure Architectures
- 165.A global media company uses AWS Organizations to manage over 100 AWS accounts. They need to ensure that all API calls made to AWS services across the entire organization are consistently logged to a central Amazon S3 bucket in a dedicated security account. This setup must apply to all existing and newly created accounts automatically. Which feature of AWS CloudTrail should be used?Design Secure Architectures
- 166.A healthcare startup is building a new application on AWS that handles Protected Health Information (PHI). They need to ensure that all sensitive data stored in Amazon DynamoDB is encrypted at rest to comply with HIPAA regulations. Which encryption option should they choose to meet this requirement with minimal operational overhead?Design Secure Architectures
- 167.A large enterprise uses AWS Organizations to manage multiple AWS accounts. They want to enforce a baseline set of security controls across all member accounts, such as disallowing the creation of IAM users without MFA and preventing the use of unencrypted S3 buckets. This enforcement must apply to new accounts automatically and cannot be overridden by individual account administrators. Which AWS Organizations feature should be used?Design Secure Architectures
- 168.An organization is migrating sensitive payment processing applications to AWS. These applications require a highly isolated network environment where no internet traffic is permitted, and all inbound and outbound traffic must be explicitly controlled and logged. They need to ensure that the application instances cannot reach the internet and the internet cannot reach them. Which networking design best achieves this level of isolation?Design Secure Architectures
- 169.A healthcare provider is storing patient records in an Amazon S3 bucket. Due to regulatory compliance, all access to these records must be logged, and the logs themselves must be protected from tampering. The logs should also be easily queryable for audit purposes. Which solution should the Solutions Architect recommend?Design Secure Architectures
- 170.A startup is deploying a new serverless application that uses AWS Lambda functions, Amazon API Gateway, and Amazon DynamoDB. The application needs to store and retrieve API keys, database credentials, and other sensitive configuration parameters. These secrets must be rotated automatically and securely, and access to them should be restricted to only the necessary Lambda functions. Which AWS service is purpose-built to manage these requirements?Design Secure Architectures
- 171.A manufacturing company uses AWS IoT Core to collect data from factory sensors. This data is sensitive and must be securely stored and processed. They need to ensure that messages published to AWS IoT Core are encrypted end-to-end between the devices and the IoT Core service, and that only authorized devices can publish messages. Which two mechanisms are essential to achieve this?Design Secure Architectures
- 172.A company is migrating a legacy application to AWS. The application uses a traditional relational database that needs to reside in a private subnet and only be accessible from application servers in another private subnet. The application servers occasionally need to download software updates and security patches from the internet. However, no inbound internet access should be allowed to the application or database servers. Which networking component is required to enable outbound internet access for the application servers while maintaining strict inbound isolation?Design Secure Architectures
- 173.A financial services company is migrating its on-premises applications to AWS. They need to ensure that all data in transit between their Amazon EC2 instances and Amazon S3 buckets within the same AWS region is encrypted. Which of the following is the MOST cost-effective and secure way to meet this requirement?Design Secure Architectures
- 174.An organization is migrating sensitive payment processing applications to AWS. These applications require a highly secure, isolated network environment that is logically separated from other corporate networks and the internet. They also need to establish a dedicated, private network connection to AWS from their on-premises data center. Which combination of AWS networking services should a Solutions Architect recommend to meet these requirements?Design Secure Architectures
- 175.A software development company uses AWS CodeCommit for source code management. They need to ensure that only authorized developers can push code to specific repositories and that all pushes are authenticated using strong credentials. Which combination of AWS services and features should be used?Design Secure Architectures
- 176.A large enterprise uses AWS Organizations to manage multiple AWS accounts. They want to ensure that all AWS accounts within their organization adhere to a strict security policy that prohibits the creation of Amazon S3 buckets that are publicly accessible. This policy must be enforced at the organizational level and prevent any account from overriding it. Which AWS service should be used to implement this control?Design Secure Architectures
- 177.A highly regulated organization is deploying a new application that processes protected health information (PHI). The application uses Amazon SQS for message queuing. The security team mandates that all messages in SQS queues must be encrypted at rest and in transit. Which solution ensures both requirements are met?Design Secure Architectures
- 178.A global e-commerce company uses Amazon CloudFront to deliver its web application content. To protect against common web exploits and bot traffic, they have implemented AWS WAF. The company observes an increase in sophisticated bot attacks that bypass WAF by cycling through different IP addresses and using legitimate-looking request headers. They need a solution that can identify and mitigate these advanced bot attacks without impacting legitimate user traffic. Which AWS service should they integrate with CloudFront and WAF?Design Secure Architectures
- 179.A global media company uses Amazon S3 to store large volumes of video and image assets. They need to ensure that all objects uploaded to a specific S3 bucket are encrypted at rest using a key that they fully control and manage, including rotation policies. The solution must integrate seamlessly with existing AWS services and allow for auditing of key usage. Which S3 encryption option should they choose?Design Secure Architectures
- 180.A media company is building a serverless application using AWS Lambda functions and Amazon DynamoDB. The Lambda functions need to access sensitive configuration parameters, such as API keys and database credentials, without hardcoding them into the function code or exposing them in environment variables. The solution must provide secure storage, automatic rotation, and integration with Lambda's execution environment. Which AWS service should they use?Design Secure Architectures
- 181.A large enterprise is migrating a legacy application to AWS that uses an Active Directory (AD) for user authentication. The application requires Kerberos and LDAP for authentication and authorization. The enterprise wants to minimize the management overhead of the directory service while integrating it with their existing on-premises AD. Which AWS service should be used?Design Secure Architectures
- 182.A healthcare startup is building a new application on AWS that handles Protected Health Information (PHI). The application uses Amazon DynamoDB to store patient data. Due to compliance requirements, all data at rest in DynamoDB must be encrypted. The security team also requires that the encryption keys are managed by a service that allows for easy integration with other AWS services and provides audit trails for key usage. Which encryption option should the startup choose for DynamoDB?Design Secure Architectures
- 183.A global consulting firm is migrating its internal knowledge base application to AWS. The application runs on EC2 instances in a private subnet. These instances need to download software updates regularly from vendor websites on the internet. However, the security policy strictly prohibits any inbound internet connections to these EC2 instances. Which AWS networking component should be implemented to allow the EC2 instances to initiate outbound connections to the internet while preventing any unsolicited inbound traffic?Design Secure Architectures
- 184.A global company needs to distribute sensitive content to its users worldwide while ensuring that only authenticated users can access the content and that all data is encrypted in transit. The solution must also prevent direct access to the origin S3 bucket. Which AWS services and configuration should be used?Design Secure Architectures
- 185.A company is hosting a public-facing web application on AWS. They need to ensure that the application's underlying EC2 instances are only accessible from the Application Load Balancer (ALB) and that no direct internet access is allowed to the instances. Additionally, the instances need to make outbound connections to third-party APIs. Which network configuration correctly implements these security requirements?Design Secure Architectures
- 186.A global consulting firm is migrating its internal knowledge base application to AWS. The application runs on Amazon EC2 instances in private subnets and needs to access external APIs on the internet for data enrichment. However, these EC2 instances should not be directly accessible from the internet. Which solution should the Solutions Architect implement to allow outbound internet access while maintaining security?Design Secure Architectures
- 187.A global media company uses AWS Organizations to manage over 100 AWS accounts. They need to establish a centralized logging solution for all API calls made to AWS services across all accounts for auditing and security analysis. The solution must ensure that logs are immutable and stored in a central, secure S3 bucket in a dedicated logging account. Which feature should be implemented?Design Secure Architectures
- 188.A global media company uses AWS Organizations to manage over 100 AWS accounts. They need to ensure that all S3 buckets across all accounts enforce encryption at rest for newly uploaded objects, regardless of the individual account configurations. Which AWS Organizations feature should be used to centrally enforce this security control?Design Secure Architectures
- 189.A company is hosting a public-facing web application on AWS using Amazon EC2 instances behind an Application Load Balancer (ALB). The EC2 instances are in private subnets, and the ALB is in public subnets. The security team requires that all traffic to the EC2 instances must originate from the ALB and that no other inbound traffic is allowed. How should the security groups be configured?Design Secure Architectures
- 190.A global enterprise needs to securely share large datasets stored in an Amazon S3 bucket with external partners for a limited time. The partners do not have AWS accounts, and the solution must not require them to install any special software or manage credentials. Which is the most secure and efficient way to achieve this?Design Secure Architectures
- 191.A highly regulated organization is building a new application on AWS that processes protected health information (PHI). The data will be stored in an Amazon DynamoDB table. Due to strict compliance requirements, all data must be encrypted at rest using a dedicated encryption key that the organization has full control over, including its creation, rotation, and access policies. Which DynamoDB encryption option meets these requirements?Design Secure Architectures
- 192.A financial institution is migrating its on-premises data warehouse to AWS. The data warehouse contains highly sensitive customer financial records that must be encrypted at rest. The security team requires that the encryption keys be managed and rotated automatically by an AWS service, and that they have an audit trail of key usage. Which encryption option for Amazon S3 buckets best meets these requirements?Design Secure Architectures
- 193.A startup is building a new application that processes sensitive user data and stores it in an Amazon DynamoDB table. Due to compliance requirements, all data in the DynamoDB table must be encrypted at rest using a customer-managed key (CMK) from AWS Key Management Service (KMS). Which DynamoDB encryption option should the Solutions Architect recommend?Design Secure Architectures
- 194.A company is migrating a legacy application to AWS. The application uses a traditional relational database that needs to be accessible from private subnets within a VPC. The application servers in the private subnets also need to download software updates from the internet but should not be directly exposed to public inbound traffic. Which networking component should be used to enable outbound internet connectivity for the private subnets?Design Secure Architectures
- 195.A global gaming company is developing a new multiplayer online game. The game server architecture needs to provide extremely low latency for players worldwide, with consistent performance regardless of their geographical location. The solution must also offer automatic routing to the nearest healthy game server in case of regional outages. Which AWS service is best suited to meet these requirements for game traffic?Design High-Performing Architectures
- 196.A global online gaming company needs to store petabytes of user-generated content (UGC), including video clips, screenshots, and game replays. This content is frequently accessed for the first 30 days, then less frequently for the next 60 days, and rarely accessed afterward, but must be retained for 5 years. The company wants to minimize storage costs while ensuring data availability. Which Amazon S3 storage class is most suitable for this use case, combined with S3 Lifecycle policies?Design Resilient Architectures
- 197.A financial services company needs to store critical transaction logs for compliance, requiring immutability and long-term retention. The logs must be protected from accidental deletion or modification for 7 years, even by root users. After 7 years, the logs should be automatically archived to a lower-cost storage class. Which combination of AWS services and features should be used?Design Resilient Architectures
- 198.A global SaaS company is building a new microservices platform on AWS. They need a highly scalable, fully managed service to send notifications to various endpoints (e.g., email, SMS, other microservices) when certain events occur within their system. The service must support fan-out messaging to multiple subscribers simultaneously. Which AWS service should they choose?Design Resilient Architectures
- 199.A media company is building a new content delivery platform for video-on-demand (VOD) services. They need to store petabytes of video files, which are accessed frequently by viewers worldwide. The solution must provide high availability, durability, and low latency for content delivery, while also being cost-effective for large-scale storage. Which AWS storage solution is most appropriate?Design High-Performing Architectures
- 200.A global manufacturing company uses a critical application that processes real-time sensor data from factories located in different continents. The application uses Amazon DynamoDB to store operational data. To ensure continuous availability and low-latency access for users worldwide, the company needs to provide fast, local read and write access to the DynamoDB table from multiple AWS regions. Which DynamoDB feature should they implement?Design Resilient Architectures