AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsHard

A software-as-a-service (SaaS) provider is building a new multi-tenant application that requires strong tenant isolation, both logically and physically, to meet regulatory compliance requirements. Each tenant's data must be completely separate from other tenants, and their application resources should not be shared at the EC2 instance level. The solution needs to be highly scalable, cost-efficient, and minimize operational overhead. Which multi-tenancy model and corresponding AWS services would best achieve these goals?

  1. ABridge tenancy model with shared application tier and separate VPCs per tenant.
  2. BHybrid tenancy model with shared compute and separate S3 buckets per tenant.
  3. CPooled tenancy model with shared EC2 instances and separate databases per tenant.
  4. DSiloed tenancy model with separate AWS accounts per tenant, managed by AWS Organizations.
Show answer & explanation

Correct answer: D. Siloed tenancy model with separate AWS accounts per tenant, managed by AWS Organizations.

A Siloed tenancy model with separate AWS accounts per tenant provides the strongest logical and physical isolation, meeting the strict regulatory and data separation requirements. AWS Organizations facilitates centralized management of these accounts, enabling billing consolidation and policy enforcement across tenants while minimizing operational overhead for individual account setup.

Why the other options are wrong

  • A. A bridge tenancy model with a shared application tier and separate VPCs per tenant improves network isolation but still shares compute resources at some level, failing to provide complete physical isolation at the EC2 instance level for application resources. This model is less suitable for strict regulatory compliance requiring strong physical separation.
  • B. A hybrid tenancy model with shared compute and separate S3 buckets per tenant provides data isolation for objects in S3 but fails to provide physical isolation of application resources at the compute level. Shared compute resources are explicitly against the requirement for non-shared EC2 instance level resources.
  • C. A pooled tenancy model with shared EC2 instances and separate databases per tenant does not meet the requirement for physical isolation of application resources at the EC2 instance level. While databases are separate, the shared compute environment introduces potential for 'noisy neighbor' issues and doesn't provide the strongest isolation.

Siloed Multi-Tenancy on AWS

A multi-tenancy model where each tenant has dedicated, isolated resources, often in separate AWS accounts, providing the highest level of security and compliance.

  • Strongest isolation level (logical and physical).
  • Each tenant has dedicated compute, storage, and network resources.
  • Often implemented with separate AWS accounts per tenant.
  • Managed centrally using AWS Organizations for billing and governance.
  • Ideal for strict regulatory compliance and high security requirements.

Memory trick: Siloed is separate, Pooled is shared, Bridge is hybrid, always isolate sensitive data.

More Design for New Solutions questions