AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityMedium

A financial institution is migrating a legacy monolithic application to AWS. The application currently processes millions of transactions daily and requires extremely low latency and high throughput. The institution also has a strict requirement for data to be encrypted at rest and in transit, and for all data access to be audited. The solutions architect needs to design a solution that provides high availability and scalability, while ensuring strict security and compliance. Which architecture pattern and AWS services should be recommended?

  1. ARefactor the application into serverless functions using AWS Step Functions, store data in Amazon S3 with server-side encryption, and use AWS Shield Advanced for protection. Configure AWS Config for auditing.
  2. BRehost the application on Amazon EC2 instances within an Auto Scaling group and use an Amazon RDS for PostgreSQL database with encryption at rest. Implement AWS CloudTrail for auditing.
  3. CDecompose the monolith into microservices using AWS Lambda and Amazon API Gateway, store data in Amazon DynamoDB with encryption at rest, and use AWS KMS for key management. Implement AWS GuardDuty for auditing.
  4. DReplatform the application to run on Amazon ECS with Fargate, use Amazon Aurora PostgreSQL-Compatible Edition with encryption at rest and in transit, and integrate with AWS Secrets Manager for credentials. Enable AWS CloudTrail and Amazon CloudWatch Logs for auditing.
Show answer & explanation

Correct answer: D. Replatform the application to run on Amazon ECS with Fargate, use Amazon Aurora PostgreSQL-Compatible Edition with encryption at rest and in transit, and integrate with AWS Secrets Manager for credentials. Enable AWS CloudTrail and Amazon CloudWatch Logs for auditing.

Replatforming to Amazon ECS on Fargate provides scalability and high availability for containerized applications. Amazon Aurora PostgreSQL-Compatible Edition offers high performance, scalability, and built-in encryption for data at rest and in transit. AWS Secrets Manager securely manages credentials, and CloudTrail/CloudWatch Logs provide comprehensive auditing.

Why the other options are wrong

  • A. Refactoring into serverless functions with Step Functions is a significant architectural change (refactor) that may be too complex for an initial migration. S3 is an object storage, not typically a transactional database for a monolithic application, and AWS Shield Advanced is for DDoS protection, not general auditing.
  • B. Rehosting on EC2/RDS might not provide the desired scalability and high throughput for millions of transactions, and RDS encryption at rest does not cover in-transit encryption by default for client connections.
  • C. Decomposing to Lambda/DynamoDB is a good serverless approach, but the question implies migrating a 'monolithic application' which often suggests a replatforming or rehosting first step, rather than immediate refactoring. GuardDuty is for threat detection, not primary auditing of data access.

Replatforming

Migrating an application to the cloud with minimal changes to leverage cloud-native features, often involving containerization or managed databases.

  • Also known as 'lift-and-tinker'.
  • Balances effort with cloud benefits.
  • Commonly uses managed services like RDS, ECS, EKS.

Memory trick: Choose your 'R' wisely: Rehost, Replatform, Refactor, Repurchase, Retire.

More Design Solutions for Organizational Complexity questions