1. An online gaming company's backend microservices communicate synchronously, leading to cascading failures when a single service experiences high load or becomes unavailable. The company wants to improve the system's resilience and scalability by decoupling these services. Which AWS service should they integrate to facilitate asynchronous communication between microservices?
Continuously Improve Existing Solutions
A.AWS AppSync
B.Amazon EventBridge
C.AWS Step Functions
D.Amazon SQS
Show answerAnswer
D. Amazon SQS
Amazon SQS (Simple Queue Service) is a fully managed message queuing service that enables you to decouple and scale microservices, distributed systems, and serverless applications. It allows services to communicate asynchronously, preventing cascading failures and improving overall system resilience.
2. A software development company is migrating its CI/CD pipeline from an on-premises Jenkins server to AWS. The company requires a fully managed solution that integrates seamlessly with source control (AWS CodeCommit), provides automated build and test capabilities, and supports continuous deployment to various AWS environments (e.g., EC2, Lambda, ECS). The solution must also allow for custom build environments using Docker images. Which AWS service combination is the MOST suitable for this modernization?
Accelerate Workload Migration and Modernization
A.AWS Developer Tools, Amazon EC2, and AWS Lambda.
B.AWS CloudFormation, AWS OpsWorks, and AWS Config.
C.AWS CodePipeline, AWS CodeBuild, AWS CodeDeploy, and AWS CodeCommit.
D.AWS CodeStar, AWS Elastic Beanstalk, and Amazon S3.
Show answerAnswer
C. AWS CodePipeline, AWS CodeBuild, AWS CodeDeploy, and AWS CodeCommit.
AWS CodePipeline orchestrates the entire CI/CD workflow. AWS CodeBuild provides fully managed build and test services, supporting custom Docker images. AWS CodeDeploy automates application deployments to various AWS compute services, and AWS CodeCommit serves as the managed source control. This combination provides a comprehensive, fully managed, and integrated CI/CD solution.
3. A global manufacturing company is modernizing its on-premises data processing pipeline. The current pipeline uses a proprietary scheduling system and processes large batches of data daily, taking several hours to complete. The company wants to move this workload to AWS, improve scalability, reduce operational overhead, and allow for more dynamic, event-driven processing without a complete re-architecture of the core processing logic. Which AWS service combination offers the MOST effective modernization strategy?
Accelerate Workload Migration and Modernization
A.Migrate to AWS Batch for job orchestration and Amazon S3 for data storage.
B.Refactor to AWS Lambda functions triggered by Amazon SQS.
C.Rehost on Amazon ECS with Fargate and use Amazon EFS for shared storage.
D.Migrate to Amazon EC2 instances and use Auto Scaling Groups.
Show answerAnswer
A. Migrate to AWS Batch for job orchestration and Amazon S3 for data storage.
AWS Batch is specifically designed for running large-scale batch computing workloads efficiently, handling job orchestration, scheduling, and scaling. Storing data in Amazon S3 provides highly scalable and durable storage, aligning with the goal of reducing operational overhead and enabling dynamic processing by decoupling storage from compute.
4. A financial institution processes millions of transactions daily. Their existing on-premises data warehouse struggles to ingest and process data fast enough to provide near real-time analytics for fraud detection. The current batch processing system has a latency of several hours, making it ineffective for identifying fraudulent activities as they occur. The company needs a highly scalable, fully managed data analytics platform on AWS that can ingest and process high-volume, streaming transaction data with sub-second latency, allowing for immediate fraud detection. Which AWS service combination should the Solutions Architect recommend to build this real-time data platform?
Continuously Improve Existing Solutions
A.Amazon S3 for data lake, AWS Glue for ETL, and Amazon Athena for querying.
B.Amazon Kinesis Data Streams for ingestion, Amazon Kinesis Data Analytics for Apache Flink for processing, and Amazon Redshift for analytics.
C.Amazon MSK for ingestion, Amazon EMR for processing, and Amazon QuickSight for visualization.
D.AWS DataSync for data transfer, Amazon EC2 for processing, and Amazon DynamoDB for storage.
Show answerAnswer
B. Amazon Kinesis Data Streams for ingestion, Amazon Kinesis Data Analytics for Apache Flink for processing, and Amazon Redshift for analytics.
This combination provides a robust, fully managed real-time analytics pipeline. Kinesis Data Streams ingests high-volume streaming data. Kinesis Data Analytics for Apache Flink processes this data with sub-second latency for real-time fraud detection. Amazon Redshift can then be used for historical analysis and aggregated reporting.
5. A company is migrating a complex, multi-tier enterprise application from on-premises to AWS. The application uses Microsoft SQL Server as its database backend and requires high performance and availability. The company wants to leverage AWS managed services to reduce the operational burden of database administration, while also ensuring compatibility with their existing SQL Server tools and expertise. Which AWS database service should be chosen?
Accelerate Workload Migration and Modernization
A.Amazon Redshift
B.Amazon RDS for SQL Server
C.Amazon Aurora PostgreSQL-Compatible Edition
D.Amazon DynamoDB
Show answerAnswer
B. Amazon RDS for SQL Server
Amazon RDS for SQL Server is a fully managed relational database service that supports Microsoft SQL Server. It provides high availability, scalability, automated backups, and patching, significantly reducing operational burden while maintaining compatibility with existing SQL Server applications and tools.
6. A global manufacturing company is modernizing its on-premises data processing pipeline. The pipeline involves several sequential steps: data ingestion, data transformation, and data loading into a data warehouse. Each step is implemented as a separate, long-running application. The company needs a fully managed solution to orchestrate these steps, handle retries, manage dependencies, and provide clear visibility into the overall workflow execution. Which AWS service should be used for orchestration?
Accelerate Workload Migration and Modernization
A.AWS Step Functions
B.AWS Data Pipeline
C.Amazon SQS Standard Queue
D.Amazon EventBridge
Show answerAnswer
A. AWS Step Functions
AWS Step Functions is a serverless workflow service that allows you to orchestrate complex, long-running processes involving multiple steps. It provides built-in error handling, retries, parallel execution capabilities, and visual workflow management, perfectly suiting the need for orchestrating sequential data processing steps with visibility and reliability.
7. A global online learning platform serves video content to millions of users worldwide. The current architecture serves videos directly from Amazon S3. Users in geographically distant regions experience high latency and buffering issues, leading to a poor user experience. The company wants to improve content delivery performance, reduce latency for global users, and offload traffic from their S3 bucket to optimize costs. Which AWS service should the Solutions Architect recommend?
Continuously Improve Existing Solutions
A.Use an AWS Global Accelerator to improve network performance between users and S3.
B.Migrate video storage to Amazon EBS volumes attached to EC2 instances in multiple regions.
C.Utilize Amazon CloudFront to distribute video content globally.
D.Implement Amazon S3 Transfer Acceleration for faster uploads to S3.
Show answerAnswer
C. Utilize Amazon CloudFront to distribute video content globally.
Amazon CloudFront is a global content delivery network (CDN) that caches content at edge locations close to users. This significantly reduces latency and buffering for global users by serving content from the nearest edge location, and it offloads traffic from the origin S3 bucket, improving performance and reducing costs.
8. A global e-commerce company uses Amazon S3 for storing product images, videos, and customer-uploaded content. With petabytes of data, they need a way to regularly audit and report on the objects stored in their buckets, including metadata, object size, and encryption status, for compliance and cost optimization. The current method of listing objects using the S3 API is too slow and expensive for their scale. Which AWS service should the Solutions Architect recommend to efficiently gather this information?
Continuously Improve Existing Solutions
A.Develop a custom AWS Lambda function to traverse all S3 buckets and collect object details.
B.Enable Amazon CloudWatch Logs for S3 access logs and analyze them with Amazon Athena.
C.Configure AWS Config rules to monitor S3 bucket changes and report on object properties.
D.Utilize Amazon S3 Inventory to generate daily or weekly reports of object metadata.
Show answerAnswer
D. Utilize Amazon S3 Inventory to generate daily or weekly reports of object metadata.
Amazon S3 Inventory provides a flat-file list of objects in an S3 bucket, including metadata, object size, and encryption status. It's designed for large-scale auditing and reporting, offering a more efficient and cost-effective solution compared to repeatedly listing objects via the S3 API or custom scripts.
9. A large e-commerce company operates a legacy order processing system that frequently experiences outages during peak sales events, leading to significant lost revenue. The system is a monolithic application running on a single, oversized on-premises server. The company wants to migrate this system to AWS to improve reliability, scalability, and reduce operational overhead, but they cannot afford a complete rewrite due to business-critical deadlines. They need a solution that allows for incremental modernization while keeping the existing system operational during the transition. Which approach should the Solutions Architect recommend?
Continuously Improve Existing Solutions
A.Rewrite the entire application from scratch as a serverless microservices architecture on AWS Lambda and Amazon DynamoDB, then switch over to the new system once complete.
B.Perform a 'lift and shift' of the entire monolithic application to a single Amazon EC2 instance, and then scale up the instance type during peak events.
C.Implement the Strangler Fig Pattern by gradually extracting microservices from the monolith and deploying them on AWS Lambda or Amazon ECS, redirecting traffic as services are migrated.
D.Migrate the monolithic application to a containerized environment using Amazon EKS, and then use Kubernetes horizontal pod autoscaling to handle peak loads.
Show answerAnswer
C. Implement the Strangler Fig Pattern by gradually extracting microservices from the monolith and deploying them on AWS Lambda or Amazon ECS, redirecting traffic as services are migrated.
The Strangler Fig Pattern allows for incremental modernization of a monolithic application without a complete rewrite, which aligns with the company's need to keep the existing system operational and avoid a 'big bang' migration. This approach mitigates risk and allows for continuous delivery of value.
10. A research institution is migrating a high-performance computing (HPC) cluster to AWS. The cluster consists of tightly coupled applications that require ultra-low latency networking (sub-millisecond) and high inter-node bandwidth for inter-process communication (MPI). The existing on-premises cluster uses InfiniBand interconnects. Which AWS EC2 instance type and networking feature combination BEST meets these demanding requirements?
Accelerate Workload Migration and Modernization
A.C7g instances with Elastic Network Adapters (ENA)
B.R6gn instances with ENA Express
C.M6i instances with Enhanced Networking (Intel 82599 Virtual Function)
D.Hpc6a instances with Elastic Fabric Adapter (EFA)
Show answerAnswer
D. Hpc6a instances with Elastic Fabric Adapter (EFA)
Hpc6a instances are specifically designed for HPC workloads, offering high core counts and memory. The Elastic Fabric Adapter (EFA) is a network interface that enables HPC applications to achieve lower and more consistent latency and higher throughput than traditional TCP networking, similar to on-premises HPC clusters with InfiniBand, making it ideal for tightly coupled MPI workloads.
11. A large enterprise has several applications deployed on Amazon EC2 instances within a single VPC. These applications frequently communicate with each other, but the current network configuration relies heavily on security groups, which have become complex and difficult to manage as the number of applications grows. The enterprise wants to improve its network security posture by implementing a more centralized and granular traffic inspection and filtering mechanism. The solution must provide visibility into inter-application traffic and allow for dynamic policy updates without modifying individual application security groups. Which AWS service should be used to achieve this?
Continuously Improve Existing Solutions
A.VPC Flow Logs with Amazon GuardDuty.
B.AWS WAF (Web Application Firewall) on an Application Load Balancer.
C.NACLs (Network Access Control Lists) at the subnet level.
D.AWS Network Firewall.
Show answerAnswer
D. AWS Network Firewall.
AWS Network Firewall is a fully managed network firewall service that allows you to deploy and manage network protections across all your Amazon VPCs. It provides centralized traffic inspection (L3-L7), granular filtering rules, intrusion prevention, and can be integrated with AWS Firewall Manager for policy enforcement across multiple accounts. This directly addresses the need for centralized, granular inspection and dynamic policy updates for inter-application traffic.
12. A startup is building a new real-time analytics platform. Their existing data ingestion pipeline uses Amazon Kinesis Data Streams to collect high-volume, high-velocity streaming data. They need to perform continuous SQL queries on these fast-moving data streams to generate real-time dashboards and trigger alerts based on specific data patterns, without managing any underlying servers or infrastructure. The solution must be highly available and scalable to handle spikes in data volume. Which AWS service should a Solutions Architect recommend?
Continuously Improve Existing Solutions
A.Amazon EMR with Apache Spark Streaming.
B.Amazon Redshift with streaming ingestion.
C.Amazon Kinesis Data Analytics for Apache Flink.
D.AWS Lambda with custom stream processing logic.
Show answerAnswer
C. Amazon Kinesis Data Analytics for Apache Flink.
Amazon Kinesis Data Analytics for Apache Flink is a fully managed service that allows you to process and analyze streaming data in real time using Apache Flink. It supports continuous SQL queries directly on streaming data, is serverless, highly available, and automatically scales to handle varying data volumes, making it ideal for real-time analytics and alerting without managing infrastructure.
13. A large enterprise is planning to migrate hundreds of on-premises applications to AWS. The applications vary widely in complexity, from simple web servers to monolithic enterprise resource planning (ERP) systems with tightly coupled databases. The enterprise's primary goal is to minimize downtime during migration and optimize costs post-migration. They have a limited internal team with AWS expertise. Which migration strategy should the enterprise prioritize for the majority of its applications to achieve these goals efficiently?
Accelerate Workload Migration and Modernization
A.Refactor (Re-architect) all applications to be cloud-native, utilizing microservices and serverless technologies from the outset.
B.Rehost (Lift-and-Shift) using AWS Server Migration Service (SMS) for all applications, followed by manual re-architecture.
C.Replatform (Lift-Tinker-and-Shift) where applicable, leveraging managed services like Amazon RDS and AWS Elastic Beanstalk, combined with rehost for simpler applications.
D.Repurchase (Drop-and-Shop) by replacing all existing applications with SaaS solutions, and decommission the on-premises infrastructure.
Show answerAnswer
C. Replatform (Lift-Tinker-and-Shift) where applicable, leveraging managed services like Amazon RDS and AWS Elastic Beanstalk, combined with rehost for simpler applications.
Replatforming allows for some optimization and cost savings by moving to managed services without a complete re-architecture, balancing the need for modernization with minimizing initial effort. Combining it with rehosting for simpler applications provides a pragmatic approach given the varied complexity and limited internal expertise.
14. A global media company is modernizing its on-premises content delivery network (CDN) to AWS. The existing CDN relies on a custom-built caching layer that serves petabytes of video content globally. The company wants to ensure low-latency access for viewers worldwide, minimize data transfer costs out of AWS, and maintain fine-grained control over caching behavior, including invalidation strategies. Which combination of AWS services should the company use to achieve these goals?
Accelerate Workload Migration and Modernization
A.Amazon EBS for storage, AWS Transit Gateway for network connectivity, and Amazon CloudFront for content delivery.
B.Amazon EC2 instances with Nginx for caching, Amazon S3 for storage, and Amazon Route 53 for DNS.
C.Amazon S3 Glacier Deep Archive for storage, Amazon CloudFront for content delivery, and AWS WAF for security.
D.Amazon S3 for storage, Amazon CloudFront for content delivery, and AWS Global Accelerator for routing.
Show answerAnswer
D. Amazon S3 for storage, Amazon CloudFront for content delivery, and AWS Global Accelerator for routing.
Amazon S3 provides highly durable and scalable object storage for petabytes of content. Amazon CloudFront is a global CDN that ensures low-latency access and minimizes data transfer costs by caching content at edge locations worldwide, offering fine-grained control over caching and invalidation. AWS Global Accelerator improves performance and availability by directing traffic to optimal endpoints over the AWS global network, further enhancing the CDN solution.
15. A global manufacturing company has an existing data processing pipeline that relies on a self-managed Apache Spark cluster running on Amazon EC2 instances. The cluster requires constant monitoring, manual scaling adjustments, and patching, leading to high operational overhead and occasional resource bottlenecks during peak processing times. The company wants to improve the agility and cost-efficiency of its data processing by migrating to a fully managed, scalable, and serverless Spark solution on AWS. The solution must support existing Spark jobs without significant code changes. Which AWS service should a Solutions Architect recommend?
Continuously Improve Existing Solutions
A.Amazon Redshift Spectrum
B.AWS Glue
C.Amazon Kinesis Data Analytics for Apache Flink
D.Amazon EMR on EC2
Show answerAnswer
B. AWS Glue
AWS Glue is a serverless data integration service that makes it easy to discover, prepare, and combine data for analytics, machine learning, and application development. It supports Apache Spark, allowing existing Spark jobs to run without significant code changes, and handles all provisioning, scaling, and patching, thus reducing operational overhead.
16. A global manufacturing company has an existing data processing pipeline that relies on a self-managed Apache Spark cluster running on-premises. This cluster is difficult to scale, prone to resource contention, and requires significant operational effort for patching, monitoring, and maintenance. The company wants to migrate their Spark workloads to AWS to improve scalability, reduce operational overhead, and leverage a fully managed service for big data processing. They need a solution that is compatible with their existing Spark jobs and can easily integrate with Amazon S3 for data storage. Which AWS service should the Solutions Architect recommend?
Continuously Improve Existing Solutions
A.AWS Batch
B.Amazon EMR
C.Amazon Redshift
D.AWS Glue
Show answerAnswer
B. Amazon EMR
Amazon EMR is a fully managed cluster platform that simplifies running big data frameworks like Apache Spark, Hadoop, and Presto. It provides elastic scalability, reduces operational overhead compared to self-managed clusters, and integrates seamlessly with Amazon S3, making it ideal for migrating existing Spark workloads.
17. An enterprise is performing a large-scale migration of legacy Windows Server applications to AWS. Many of these applications have hardcoded IP addresses or rely on specific DNS names that are currently managed by an on-premises Active Directory and DNS infrastructure. The enterprise wants to maintain these existing hostnames and IP addresses during the migration to minimize application refactoring while moving to a fully managed DNS solution in AWS. Which approach BEST facilitates this requirement?
Accelerate Workload Migration and Modernization
A.Use AWS Managed Microsoft AD and configure custom DNS records in Route 53 Public Hosted Zones.
B.Extend the on-premises Active Directory to AWS EC2 and use AWS Directory Service for Microsoft Active Directory, integrated with Route 53 Resolver.
C.Re-architect applications to use dynamic DNS updates and AWS Cloud Map for service discovery.
D.Migrate Windows Servers to Amazon EC2 and configure each instance to use Amazon Route 53 for DNS resolution.
Show answerAnswer
B. Extend the on-premises Active Directory to AWS EC2 and use AWS Directory Service for Microsoft Active Directory, integrated with Route 53 Resolver.
Extending the on-premises Active Directory to AWS using AWS Directory Service for Microsoft Active Directory allows the enterprise to maintain existing user identities, group policies, and DNS records. Integrating this with Route 53 Resolver (specifically inbound and outbound endpoints) enables seamless resolution of both on-premises and AWS-hosted DNS records, supporting the requirement to maintain existing hostnames and IP addresses without application refactoring.
18. A financial institution uses an on-premises data warehouse for its analytics and reporting needs. The data warehouse struggles to scale with increasing data volumes and query complexity, leading to slow report generation and frustrated business users. Maintaining the infrastructure and licenses is also becoming prohibitively expensive. The institution wants to migrate to a fully managed, cost-effective, and scalable cloud-native data warehousing solution on AWS that can handle petabytes of data and complex analytical queries efficiently. Which AWS service is the MOST appropriate for this requirement?
Continuously Improve Existing Solutions
A.Amazon DynamoDB
B.Amazon Athena
C.Amazon Redshift
D.Amazon RDS for PostgreSQL
Show answerAnswer
C. Amazon Redshift
Amazon Redshift is a fully managed, petabyte-scale data warehouse service that is optimized for complex analytical queries on large datasets. It is designed for high performance and cost-effectiveness, making it ideal for replacing traditional on-premises data warehouses.
19. A global manufacturing company has an existing data processing pipeline that relies on a single, large Apache Spark cluster running on Amazon EC2 instances. This cluster is over-provisioned to handle peak loads, leading to high costs during off-peak times. The company wants to optimize costs and improve efficiency by dynamically scaling resources based on workload demands. The solution must support Spark workloads and allow for granular control over compute resources. Which architectural change should the solutions architect recommend?
Continuously Improve Existing Solutions
A.Migrate the Spark workloads to AWS Glue for serverless ETL processing.
B.Deploy the Spark cluster on Amazon ECS with Fargate for serverless containers.
C.Utilize Amazon EMR with EC2 Spot Instances and managed scaling.
D.Re-implement the data processing logic using AWS Lambda functions.
Show answerAnswer
C. Utilize Amazon EMR with EC2 Spot Instances and managed scaling.
Amazon EMR is a managed service for running big data frameworks like Spark. EMR's managed scaling feature automatically adjusts the number of instances based on workload, and the use of EC2 Spot Instances can significantly reduce costs for fault-tolerant Spark jobs, directly addressing the cost optimization and dynamic scaling requirements.
20. A global manufacturing company has an existing data processing pipeline that relies on a self-managed Apache Spark cluster running on-premises. The cluster is difficult to scale, costly to maintain, and experiences frequent resource contention, leading to delayed data analytics. The company wants to migrate this workload to AWS to improve scalability, reduce operational overhead, and accelerate data processing. Which AWS service should they use for their Spark workloads?
Continuously Improve Existing Solutions
A.Amazon Redshift
B.Amazon EMR
C.AWS Lambda
D.AWS Glue
Show answerAnswer
B. Amazon EMR
Amazon EMR (Elastic MapReduce) is a fully managed service that makes it easy to run big data frameworks like Apache Spark, Hadoop, and Presto. It provides scalable, cost-effective, and highly available clusters, eliminating the operational overhead of self-managing Spark on-premises.
21. A financial institution uses an on-premises data warehouse that struggles to scale with increasing data volumes and query complexity, leading to batch processing delays. They want to migrate to AWS to improve performance and enable real-time analytics capabilities. The solution must support petabyte-scale data, complex SQL queries, and integrate with existing business intelligence (BI) tools. Which AWS service is the most appropriate for this requirement?
Continuously Improve Existing Solutions
A.Amazon S3 with Amazon Athena.
B.Amazon DynamoDB with DynamoDB Accelerator (DAX).
C.Amazon Redshift.
D.Amazon RDS for PostgreSQL.
Show answerAnswer
C. Amazon Redshift.
Amazon Redshift is a fully managed, petabyte-scale data warehouse service that is optimized for complex analytical queries and integrates well with standard SQL-based BI tools. It directly addresses the scaling and performance issues of an on-premises data warehouse for analytical workloads.
22. A large e-commerce company operates a monolithic application on Amazon EC2 instances that processes millions of customer orders daily. The application is experiencing frequent performance bottlenecks during peak sales events, leading to slow order processing and customer dissatisfaction. The company wants to incrementally modernize the application without a complete rewrite, focusing on the order processing module first. The new order processing module will be developed as a microservice. Which architectural pattern should the company adopt to integrate the new microservice with the existing monolith while ensuring continuous operation?
Continuously Improve Existing Solutions
A.Database per service
B.Strangler Fig Pattern
C.Decomposition by subdomain
D.Shared database pattern
Show answerAnswer
B. Strangler Fig Pattern
The Strangler Fig Pattern is ideal for incrementally refactoring a monolithic application into microservices. It involves gradually replacing specific functionalities of the monolith with new services, redirecting traffic to the new services as they become ready, without interrupting the existing system.
23. A global manufacturing company operates a critical enterprise resource planning (ERP) application on-premises, using a proprietary database and application server. The application is essential for daily operations, but its infrastructure is aging, making it difficult to patch, scale, and recover from failures. The company wants to migrate this ERP system to AWS to improve reliability, reduce maintenance burden, and enable future innovation, but they have a strict requirement that the application and database must remain tightly coupled and managed as a single unit, similar to their current setup, to simplify operations and support. A full re-architecture into microservices is not an immediate option. Which AWS migration strategy should the Solutions Architect recommend?
Continuously Improve Existing Solutions
A.Re-host the entire ERP application, including its proprietary database, onto dedicated Amazon EC2 instances, leveraging AWS Backint Agent for backups.
B.Re-factor the ERP application into a serverless architecture using AWS Lambda and Amazon DynamoDB, decoupling the application and database.
C.Replace the ERP application with a SaaS solution available in the AWS Marketplace.
D.Re-platform the application and database to run on Amazon EC2 instances within an Auto Scaling group and use Amazon RDS for the database.
Show answerAnswer
A. Re-host the entire ERP application, including its proprietary database, onto dedicated Amazon EC2 instances, leveraging AWS Backint Agent for backups.
Re-hosting (lift and shift) the tightly coupled proprietary ERP application and its database onto dedicated EC2 instances preserves the existing architecture, meets the 'managed as a single unit' requirement, and immediately benefits from AWS infrastructure reliability and management tools like AWS Backint Agent for backups.
24. A global media company uses AWS Organizations to manage multiple accounts. They want to ensure that all accounts within a specific Organizational Unit (OU) adhere to strict security policies, such as disallowing the creation of IAM users with administrative permissions and preventing the use of unapproved AWS regions. These policies must be enforced at the account level, regardless of the IAM permissions granted to individual users or roles within those accounts. Which AWS service or feature should a Solutions Architect recommend to implement these preventative controls?
Continuously Improve Existing Solutions
A.IAM Roles with explicit Deny policies.
B.Service Control Policies (SCPs).
C.IAM Permission Boundaries.
D.AWS Config rules with auto-remediation.
Show answerAnswer
B. Service Control Policies (SCPs).
Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization, or for specific OUs. They are preventative controls that apply to all identities, including the root user, within affected accounts.
25. A company is migrating a critical, high-performance web application to AWS. The application uses a custom caching layer that stores session data and frequently accessed database query results. The company wants to modernize this caching layer to be highly available, scalable, and fully managed to reduce operational overhead. Which AWS service should be used?
Accelerate Workload Migration and Modernization
A.Utilize Amazon ElastiCache for Redis in a Cluster Mode enabled configuration.
B.Deploy a custom caching solution on Amazon EC2 instances with Auto Scaling.
C.Use Amazon S3 for storing cached objects with lifecycle policies.
D.Store cached data in an Amazon DynamoDB table with on-demand capacity.
Show answerAnswer
A. Utilize Amazon ElastiCache for Redis in a Cluster Mode enabled configuration.
Amazon ElastiCache for Redis, especially in a Cluster Mode enabled configuration, provides a fully managed, highly available, and scalable in-memory data store suitable for caching session data and query results. It significantly reduces operational overhead compared to a self-managed solution.
A pattern where microservices communicate without waiting for an immediate response, typically using message queues or event buses to improve resilience and scalability.
Decouples services, reducing dependencies.
Prevents cascading failures.
Improves system resilience, scalability, and responsiveness.
A suite of fully managed AWS services that automate the software release process. CodeCommit for source control, CodeBuild for compiling/testing, CodeDeploy for deploying, and CodePipeline for orchestrating the workflow.
A fully managed service that enables developers, scientists, and engineers to easily and efficiently run hundreds of thousands of batch computing jobs on AWS.
Dynamically provisions compute resources.
Manages job queueing, scheduling, and execution.
Integrates with other AWS services like S3 and EC2.
Amazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency, high transfer speeds, and developer-friendly tools.
Caches content at edge locations worldwide.
Reduces latency and improves user experience.
Offloads traffic from origin servers (e.g., S3, EC2).
Amazon S3 Inventory provides a scheduled, flat-file list of objects in an S3 bucket or a shared prefix. It helps you manage your storage by auditing and reporting on the replication and encryption status of your objects.
Generates daily or weekly reports of object metadata.
Supports CSV, ORC, or Parquet output formats.
Useful for auditing, compliance, and cost optimization at scale.
A technique for incrementally transforming a monolithic application into a microservices architecture by gradually replacing specific functionalities with new services, while the old system continues to operate.
Enables modernization without a complete rewrite.
Reduces risk by allowing phased migration.
Traffic redirection is key to cut over to new services.
A network interface for Amazon EC2 instances that enables customers to run applications requiring high levels of inter-node communications at scale on AWS, like HPC and machine learning.
Provides lower and more consistent latency than traditional TCP.
Supports OS-bypass capabilities for MPI and NCCL.
Similar performance to on-premises InfiniBand networks.
AWS Network Firewall is a managed service that makes it easy to deploy essential network protections for all of your Amazon Virtual Private Clouds (VPCs). It provides stateful inspection, intrusion prevention, and web filtering.
Fully managed network firewall service.
Provides stateful inspection (L3-L7).
Centralized deployment across VPCs via a firewall endpoint.
A framework outlining different strategies an organization can adopt when migrating applications to the cloud, each with varying levels of effort, cost, and cloud benefits.
Developed by AWS to categorize migration approaches.
Helps organizations choose the most appropriate strategy for each application.
Impacts cost, complexity, and time-to-value for cloud adoption.
A system of distributed servers (network of PoPs) that delivers web content and static assets to users based on their geographic location, providing high availability and performance.
Reduces latency by caching content closer to users.
Offloads origin servers, reducing load and costs.
Enhances security with DDoS protection and WAF integration.
A serverless data integration service that makes it easy to discover, prepare, and combine data for analytics, machine learning, and application development, supporting Apache Spark.
Amazon EMR is a managed cluster platform that simplifies running big data frameworks, such as Apache Hadoop and Apache Spark, on AWS to process vast amounts of data.
Fully managed service for big data frameworks.
Provides elastic scalability for Spark clusters.
Reduces operational overhead compared to self-managed clusters.
AWS Directory Service for Microsoft Active Directory (Managed AD) with Route 53 Resolver
Flip card
AWS Managed Microsoft AD provides a fully managed, highly available Active Directory. Route 53 Resolver enables hybrid DNS resolution between on-premises DNS and AWS DNS, allowing resources in both environments to resolve hostnames.
Extends or creates Active Directory in AWS.
Manages DNS for AD-joined instances.
Route 53 Resolver bridges on-premises and AWS DNS for seamless name resolution.
Amazon EMR is a managed cluster platform that simplifies running big data frameworks, such as Apache Spark and Hadoop, on AWS to process and analyze vast amounts of data.
Optimized for big data frameworks like Spark.
Offers managed scaling to adjust resources based on load.
Supports EC2 Spot Instances for cost optimization.
Moving an application and its components to the cloud with minimal or no changes. It's often the fastest migration strategy, preserving existing architecture and operational models.
Minimal application changes required.
Faster migration time.
Leverages existing licenses and operational processes.
Policies that define the maximum available permissions for all accounts in an AWS Organization or a specific Organizational Unit (OU). They are preventative guardrails.
Applied at the OU or account level in AWS Organizations.
Preventative controls, not detective.
Affects all IAM users and roles, including the root user.
A fully managed in-memory data store and caching service that supports Redis and Memcached, designed to accelerate application performance by retrieving data from fast, managed in-memory caches.
Supports both Redis and Memcached engines.
Provides high availability with replication and failover.
Offers automatic scaling, patching, and backups, reducing operational burden.
AWS Database Migration Service (DMS) can migrate databases to AWS with Change Data Capture (CDC) to keep source and target databases synchronized during migration.
Supports homogeneous and heterogeneous database migrations.
CDC enables continuous replication, minimizing downtime during cutover.
Ideal for migrating critical applications requiring high availability.
AWS provides options, such as Extended Security Updates (ESU) for Windows Server and SQL Server, to allow customers to continue running applications on unsupported operating systems in EC2.
Enables migration of legacy workloads to AWS without immediate OS upgrades.
Helps bridge the gap for applications with strict OS dependencies.
Reduces immediate re-architecture costs but is a temporary solution.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.