AWS Certified Solutions Architect - Associate (SAA-C03) — Questions and Answers
Question 1: An application serves static assets globally. Which AWS service reduces latency for users worldwide by caching content at edge locations?
- Amazon API Gateway
- Amazon CloudFront (Correct answer)
- Elastic Load Balancing
- AWS Global Accelerator
Correct answer: Amazon CloudFront
Amazon CloudFront is a CDN that caches content at 400+ Points of Presence globally, reducing origin load and delivering assets from the nearest edge location.
Question 2: An architect wants to decouple a producer microservice from multiple consumer microservices using a fan-out pattern. Which combination of AWS services achieves this?
- SNS to SQS (Correct answer)
- SQS to SNS
- SQS to SQS
- EventBridge to Kinesis
Correct answer: SNS to SQS
SNS publishes a message once and fans it out to multiple SQS queues, decoupling producers from consumers.
Question 3: What RTO (Recovery Time Objective) characteristic distinguishes a warm standby DR strategy from a pilot light strategy?
- Warm standby requires more manual steps than pilot light
- Warm standby has a longer RTO because more services need to start
- Both strategies have the same RTO
- Warm standby has a shorter RTO because a scaled-down but fully functional environment is already running (Correct answer)
Correct answer: Warm standby has a shorter RTO because a scaled-down but fully functional environment is already running
In warm standby, a fully functional but scaled-down replica is always running, so failover only requires scaling up rather than starting services from scratch.
Question 4: A company wants to run containers without managing the underlying EC2 instances. Which combination of services achieves this?
- AWS Batch with EC2 Spot
- Amazon ECS with EC2 launch type
- Amazon ECS with AWS Fargate (Correct answer)
- Amazon EKS with self-managed node groups
Correct answer: Amazon ECS with AWS Fargate
ECS with the Fargate launch type is a serverless compute engine that runs containers without provisioning or managing EC2 instances.
Question 5: Which AWS X-Ray feature helps teams understand the impact of code changes on latency without introducing load into production?
- X-Ray sampling rules set to 100% on the production service
- X-Ray groups and filter expressions applied to existing trace data from a staging environment (Correct answer)
- X-Ray encryption configuration audit
- X-Ray daemon log injection
Correct answer: X-Ray groups and filter expressions applied to existing trace data from a staging environment
Analyzing X-Ray traces from a staging environment with filter expressions gives accurate latency profiling without any production risk.
Question 6: Which AWS service enables you to distribute incoming application traffic across multiple targets, such as EC2 instances, in multiple Availability Zones?
- AWS Global Accelerator
- Elastic Load Balancing (Correct answer)
- Amazon CloudFront
- Amazon Route 53
Correct answer: Elastic Load Balancing
Elastic Load Balancing automatically distributes incoming traffic across multiple targets in one or more Availability Zones to increase fault tolerance.
Question 7: What is the advantage of using AWS Lambda over EC2 for event-driven, short-duration tasks from a cost optimization perspective?
- Lambda bills in 1ms increments with no charge when idle, unlike EC2 which accrues cost while running (Correct answer)
- Lambda has free unlimited storage
- Lambda instances are reserved and always cheaper
- Lambda uses cheaper hardware than EC2
Correct answer: Lambda bills in 1ms increments with no charge when idle, unlike EC2 which accrues cost while running
Lambda charges only for the compute time consumed during function execution (rounded to 1 ms), whereas EC2 charges per second/hour regardless of whether the instance is actively processing requests.
Question 8: A company requires that all data stored in S3 be encrypted at rest using keys they fully control. Which option satisfies this requirement?
- SSE-KMS with AWS managed keys
- SSE-C (customer-provided keys) (Correct answer)
- SSE-S3
- Client-side encryption with AWS managed keys
Correct answer: SSE-C (customer-provided keys)
SSE-C allows customers to provide and manage their own encryption keys, giving them full control outside of AWS Key Management Service.
Question 9: Which AWS Global Infrastructure feature ensures that an EC2 instance placed in a specific Availability Zone is physically isolated from instances in other AZs within the same Region?
- AZ physical separation (Correct answer)
- Placement groups
- Security groups
- VPC peering
Correct answer: AZ physical separation
Each Availability Zone is a physically distinct location with independent power, cooling, and networking, providing fault isolation from other AZs in the Region.
Question 10: Which AWS service provides a centralized view of security alerts and compliance status across multiple AWS accounts and services?
- Amazon Inspector
- Amazon GuardDuty
- AWS Security Hub (Correct answer)
- AWS Config
Correct answer: AWS Security Hub
AWS Security Hub aggregates, organizes, and prioritizes security findings from multiple AWS services into a single dashboard.
Question 11: Which metric does the AWS Well-Architected Tool produce after completing a workload review?
- A cost optimization score out of 1000
- A count of high-risk issues (HRIs) per pillar (Correct answer)
- A Trusted Advisor check count
- A security posture percentage for each resource
Correct answer: A count of high-risk issues (HRIs) per pillar
The Well-Architected Tool surfaces High Risk Issues (HRIs) and Medium Risk Issues (MRIs) per pillar, guiding remediation priority.
Question 12: An architect wants to improve the read performance of a relational database without scaling the primary instance. Which AWS solution achieves this?
- Enable automated backups
- Add RDS Read Replicas and direct read traffic to them (Correct answer)
- Enable Multi-AZ on RDS
- Increase the RDS instance storage
Correct answer: Add RDS Read Replicas and direct read traffic to them
RDS Read Replicas asynchronously replicate data from the primary and allow read-heavy workloads to offload queries, improving overall throughput without upgrading the primary instance.
Question 13: A team uses AWS Config rules to detect EC2 instances running unsupported OS versions. When a non-compliant instance is found, the remediation should automatically invoke SSM Run Command. What Config feature enables this?
- Config Remediation Actions (Correct answer)
- Config Conformance Packs
- Config Aggregator
- Config Delivery Channel
Correct answer: Config Remediation Actions
AWS Config Remediation Actions allow you to associate an SSM Automation document with a rule so non-compliant resources are automatically corrected.
Question 14: Which S3 storage class is the most cost-effective for data that is accessed infrequently but must be retrieved within milliseconds?
- S3 Standard-Infrequent Access (Correct answer)
- S3 Standard
- S3 One Zone-IA
- S3 Glacier Instant Retrieval
Correct answer: S3 Standard-Infrequent Access
S3 Standard-IA offers lower storage costs than S3 Standard with millisecond retrieval, designed for data accessed less than once a month.
Question 15: What does the AWS Shared Responsibility Model state is the customer's responsibility when using Amazon RDS?
- Patching the database engine software
- Managing the underlying EC2 hypervisor
- Replacing failed hardware in the data center
- Configuring security groups and managing database user access (Correct answer)
Correct answer: Configuring security groups and managing database user access
AWS manages the database engine patching and hardware, while customers are responsible for network access controls and database-level user permissions.
Question 16: Which S3 feature automatically transitions objects to cheaper storage classes based on their age, reducing long-term storage costs?
- S3 Object Lock
- S3 Lifecycle Policies (Correct answer)
- S3 Intelligent-Tiering
- S3 Replication
Correct answer: S3 Lifecycle Policies
S3 Lifecycle Policies define rules that automatically transition objects to lower-cost storage classes (e.g., Standard → IA → Glacier) or expire them based on object age.
Question 17: Which Route 53 routing policy sends traffic to the healthiest endpoint and can automatically failover when a primary endpoint becomes unhealthy?
- Geolocation routing
- Weighted routing
- Latency routing
- Failover routing (Correct answer)
Correct answer: Failover routing
Route 53 Failover routing directs traffic to a primary resource and automatically routes to a secondary resource when health checks detect a failure.
Question 18: When an AWS diagram shows a Transit Gateway icon at the center with multiple VPCs and on-premises connections radiating outward, this represents what topology?
- A hub-and-spoke network topology centralizing connectivity through Transit Gateway (Correct answer)
- An AWS Direct Connect redundant circuit layout
- A multi-region active-active failover design
- A full-mesh VPC peering configuration
Correct answer: A hub-and-spoke network topology centralizing connectivity through Transit Gateway
Transit Gateway acts as a hub, creating a hub-and-spoke topology where all VPCs and on-premises networks connect through a central gateway.
Question 19: What is the minimum number of Availability Zones recommended when designing a highly available architecture on AWS?
- 3
- 1
- 2 (Correct answer)
- 4
Correct answer: 2
AWS recommends deploying across at least 2 Availability Zones so that if one AZ fails, the application continues running in the other.
Question 20: What AWS feature allows an Auto Scaling group to replace unhealthy EC2 instances automatically without manual intervention?
- Target tracking
- Predictive scaling
- Scheduled scaling
- Health check replacement (Correct answer)
Correct answer: Health check replacement
Auto Scaling groups perform periodic health checks and automatically terminate and replace any instance that fails the check.
Question 21: Which AWS networking feature provides a private, dedicated network connection between an on-premises data center and AWS, bypassing the public internet?
- AWS Site-to-Site VPN
- AWS Direct Connect (Correct answer)
- AWS Transit Gateway
- AWS PrivateLink
Correct answer: AWS Direct Connect
AWS Direct Connect establishes a dedicated private network connection from on-premises to AWS, offering consistent bandwidth and latency.
Question 22: When an AWS diagram shows an EC2 instance icon inside a box labeled 'ASG', what architecture pattern does this depict?
- A Spot Instance pool configuration
- A dedicated EC2 host with reserved capacity
- An EC2 instance inside a container orchestration cluster
- EC2 instances managed by an Auto Scaling Group for elasticity (Correct answer)
Correct answer: EC2 instances managed by an Auto Scaling Group for elasticity
ASG stands for Auto Scaling Group; EC2 icons within an ASG box indicate instances that are automatically scaled based on demand.
Question 23: An architect designs a multi-AZ architecture for an RDS database. Which statement about automated failover is correct?
- Failover updates the DB endpoint DNS record to point to the standby (Correct answer)
- Failover requires a manual snapshot restore
- Failover takes approximately 30 minutes to complete
- Failover requires the application connection string to change
Correct answer: Failover updates the DB endpoint DNS record to point to the standby
During Multi-AZ failover, Amazon RDS automatically updates the DNS record of the DB endpoint to resolve to the standby instance, allowing the application to reconnect without a code change.
Question 24: An architect wants to reduce NAT Gateway data processing costs. Which design change could help for traffic that stays within AWS?
- Enable VPC Flow Logs to identify top consumers
- Use S3 Transfer Acceleration instead
- Switch to an Internet Gateway
- Use VPC Gateway Endpoints for S3 and DynamoDB to bypass NAT Gateway (Correct answer)
Correct answer: Use VPC Gateway Endpoints for S3 and DynamoDB to bypass NAT Gateway
VPC Gateway Endpoints route traffic to S3 and DynamoDB directly through the AWS network without traversing a NAT Gateway, eliminating NAT data processing charges for those services.
Question 25: Which AWS service continuously evaluates resource configurations against desired compliance rules and can automatically remediate non-compliant resources?
- AWS Security Hub
- AWS Config with Config Rules and Remediation Actions (Correct answer)
- AWS Trusted Advisor
- Amazon GuardDuty
Correct answer: AWS Config with Config Rules and Remediation Actions
AWS Config Rules evaluate resource configurations on change or schedule, and Remediation Actions can invoke SSM Automation to auto-fix non-compliant resources.
Question 26: Which AWS CloudTrail feature ensures that log files have not been tampered with after delivery to S3?
- S3 Object Lock
- Log file integrity validation (Correct answer)
- CloudTrail Lake immutable queries
- CloudTrail Insights
Correct answer: Log file integrity validation
CloudTrail log file integrity validation creates a digitally signed digest file every hour so you can verify logs were not altered or deleted.
Question 27: A cross-functional team is designing a shared services VPC that must be accessed by 20 application VPCs in the same account. Which connectivity model scales best while avoiding complex route management?
- VPN tunnels from each application VPC to the shared VPC
- Internet Gateway-based routing with security groups
- VPC peering between all 20 application VPCs and the shared VPC
- AWS Transit Gateway connecting all VPCs through a central hub (Correct answer)
Correct answer: AWS Transit Gateway connecting all VPCs through a central hub
Transit Gateway acts as a hub, eliminating the need to manage hundreds of individual peering connections as VPC count grows.
Question 28: Which EC2 instance purchasing model is best suited for a batch processing workload that can tolerate interruptions in exchange for the lowest possible cost?
- Spot Instances (Correct answer)
- Dedicated Instances
- On-Demand Instances
- Reserved Instances
Correct answer: Spot Instances
EC2 Spot Instances use spare AWS capacity at up to 90% discount; they can be interrupted with a 2-minute warning, making them ideal for fault-tolerant batch jobs.
Question 29: An EC2 Auto Scaling group must replace instances whose status checks fail without any human intervention. Which Auto Scaling health check type should be enabled alongside EC2 status checks?
- AWS Config health check
- ELB health check (Correct answer)
- CloudWatch alarm-based health check
- Custom health check via Lambda
Correct answer: ELB health check
Enabling ELB health checks in the Auto Scaling group causes it to terminate and replace instances that the load balancer marks as unhealthy, beyond just EC2 status checks.
Question 30: On an AWS network topology diagram, what does a NAT Gateway symbol positioned between a private subnet and an Internet Gateway indicate?
- The subnet is part of a VPN-only connection
- Private instances can initiate outbound internet connections without being directly reachable from the internet (Correct answer)
- The NAT Gateway replaces the Internet Gateway for all traffic
- Private instances can receive inbound internet traffic
Correct answer: Private instances can initiate outbound internet connections without being directly reachable from the internet
A NAT Gateway allows outbound internet access for private subnet resources while blocking unsolicited inbound connections from the internet.
Question 31: Which AWS tool provides downloadable SOC 2 Type II reports and ISO 27001 certificates for use in customer audits?
- AWS Trusted Advisor
- AWS Well-Architected Tool
- AWS Audit Manager
- AWS Artifact (Correct answer)
Correct answer: AWS Artifact
AWS Artifact is a self-service portal where customers can download AWS compliance reports such as SOC 2 Type II, ISO certifications, and PCI AOC documents.
Question 32: Which AWS service can be used to implement a dead-letter queue to capture messages that repeatedly fail processing in an SQS-based architecture?
- Amazon EventBridge
- Amazon Kinesis
- Amazon SNS
- Amazon SQS itself (Correct answer)
Correct answer: Amazon SQS itself
SQS supports dead-letter queues, which are separate SQS queues where messages that exceed the maxReceiveCount are automatically moved for later inspection.
Question 33: Which Amazon RDS feature automatically creates a standby replica in a different Availability Zone and promotes it if the primary fails?
- RDS Proxy
- Read Replicas
- Multi-AZ deployment (Correct answer)
- Aurora Global Database
Correct answer: Multi-AZ deployment
RDS Multi-AZ maintains a synchronous standby replica in a different AZ and automatically fails over to it during outages.
Question 34: GDPR Article 17 grants users the 'right to erasure.' Which S3 capability most directly supports complying with this requirement?
- S3 Object Lock in Compliance mode
- S3 batch operations to delete specific objects on demand (Correct answer)
- S3 Lifecycle policies to transition objects to Glacier
- S3 Intelligent-Tiering
Correct answer: S3 batch operations to delete specific objects on demand
S3 Batch Operations can target and permanently delete specific objects (e.g., a user's data) across large buckets, enabling compliance with GDPR right-to-erasure requests.
Question 35: An architect wants an S3-based static website to withstand the failure of an entire AWS Region. Which feature should be configured?
- S3 Transfer Acceleration
- S3 Versioning
- S3 Cross-Region Replication (Correct answer)
- S3 Lifecycle Policies
Correct answer: S3 Cross-Region Replication
S3 Cross-Region Replication asynchronously copies objects to a bucket in another Region, enabling region-level fault tolerance.
Question 36: An application requires a shared file system accessible by multiple EC2 instances simultaneously across multiple Availability Zones. Which storage solution should be used?
- Amazon S3
- Instance Store
- Amazon EFS (Correct answer)
- Amazon EBS gp3
Correct answer: Amazon EFS
Amazon EFS is a fully managed NFS file system that can be mounted concurrently by multiple EC2 instances across AZs.
Question 37: An architect is deploying a content-heavy website and wants to reduce origin server load. After enabling CloudFront, which cache behavior setting maximizes cache hit ratio?
- Set the TTL to 0 for all objects
- Forward all headers and query strings to origin
- Disable caching entirely for dynamic pages
- Minimize the number of headers and query strings forwarded to origin (Correct answer)
Correct answer: Minimize the number of headers and query strings forwarded to origin
Forwarding fewer headers and query strings increases the likelihood that multiple requests match the same cached object, raising the cache hit ratio and reducing origin requests.
Question 38: An architect needs to analyze AWS spending patterns and forecast future costs. Which AWS tool provides this capability?
- AWS Trusted Advisor
- AWS Pricing Calculator
- AWS Cost Explorer (Correct answer)
- AWS Budgets
Correct answer: AWS Cost Explorer
AWS Cost Explorer provides an interactive interface to visualize, understand, and forecast your AWS costs and usage over time with up to 12 months of historical data.
Question 39: An architect must ensure data in transit between on-premises systems and AWS meets NIST 800-52 TLS requirements. What is the recommended approach?
- Use HTTP with IP whitelisting
- Configure AWS services to use TLS 1.2 or higher and disable older protocol versions (Correct answer)
- Use AWS Direct Connect without encryption
- Enable VPC Flow Logs
Correct answer: Configure AWS services to use TLS 1.2 or higher and disable older protocol versions
NIST SP 800-52 mandates TLS 1.2 minimum; AWS services support enforcing minimum TLS versions via security policies on load balancers, API Gateway, and CloudFront.
Question 40: In welding aluminum alloys, what is the main cause of porosity in the weld metal?
- Hydrogen dissolved in the molten pool that becomes insoluble upon solidification (Correct answer)
- CO2 from flux decomposition trapped in the weld
- Oxygen reacting with aluminum to form Al2O3 bubbles
- Nitrogen absorption from the atmosphere
Correct answer: Hydrogen dissolved in the molten pool that becomes insoluble upon solidification
Hydrogen is highly soluble in molten aluminum but nearly insoluble in solid aluminum; upon solidification, the excess hydrogen forms pores that are trapped in the weld metal.
Question 41: Which AWS Well-Architected Framework pillar specifically addresses the ability to protect information, systems, and assets while delivering business value?
- Reliability
- Operational Excellence
- Performance Efficiency
- Security (Correct answer)
Correct answer: Security
The Security pillar of the AWS Well-Architected Framework covers protecting information, systems, and assets through risk assessments and mitigation strategies.
Question 42: An application must maintain session state even if the EC2 instance serving a user is replaced. Which solution achieves this with the least application change?
- Store sessions in an EC2 instance store
- Write sessions to local disk with snapshots
- Store sessions in Amazon ElastiCache (Correct answer)
- Use sticky sessions on the load balancer
Correct answer: Store sessions in Amazon ElastiCache
Storing session data in ElastiCache externalizes state from EC2 instances so any instance can serve returning users regardless of which instance previously handled them.
Question 43: How does professional liability insurance protect Architecting on AWS Certification practitioners in non-destructive testing methods?
- It covers financial losses from claims of negligence, errors, or omissions in services (Correct answer)
- It covers natural disaster damage to office buildings
- It protects against theft of office equipment
- It pays employee health insurance premiums
Correct answer: It covers financial losses from claims of negligence, errors, or omissions in services
Professional liability insurance protects practitioners from financial consequences of claims alleging negligence or mistakes in professional services, covering legal defense costs and settlements.
Question 44: A company needs to ensure RDS Multi-AZ failover completes within 60 seconds during maintenance events. Which action most directly reduces failover time?
- Switch to a provisioned IOPS SSD storage type
- Enable Enhanced Monitoring
- Enable RDS Proxy to absorb connection storms (Correct answer)
- Increase instance storage IOPS
Correct answer: Enable RDS Proxy to absorb connection storms
RDS Proxy maintains a warm connection pool and absorbs the reconnection spike during failover, making the failover effectively transparent to applications.
Question 45: Which CloudFront feature allows an architect to serve different content to users based on the type of device they are using (mobile vs. desktop)?
- Signed URLs
- Cache Behaviors with query strings
- Lambda@Edge (Correct answer)
- CloudFront Origin Groups
Correct answer: Lambda@Edge
Lambda@Edge runs serverless functions at CloudFront edge locations and can inspect request headers (like User-Agent) to customize responses based on device type.
Question 46: The DevOps team of a company wants to monitor a web application in greater detail because it has been having intermittent problems recently. In order to gather more advanced monitoring data, which AWS monitoring service should be used to collect the data?
- AWS Config
- AWS Trusted Advisor
- Amazon Inspector
- Amazon CloudWatch (Correct answer)
Correct answer: Amazon CloudWatch
Amazon CloudWatch is a monitoring and management service offered by Amazon that was developed to gather specific information regarding the performance of applications, resources, and infrastructure. The other services do not place as much of an emphasis on advanced monitoring as CloudWatch does.
Question 47: Which Amazon EC2 feature allows multiple instance types to be used within the same Auto Scaling group, enabling lower cost by mixing On-Demand and Spot capacity?
- Dedicated Tenancy
- Placement groups
- Mixed Instances Policy (Correct answer)
- Burstable instances
Correct answer: Mixed Instances Policy
Mixed Instances Policy in Auto Scaling lets you specify multiple instance types and blend On-Demand and Spot Instances to optimize cost and availability simultaneously.
Question 48: A company must prove to auditors that no IAM root account API calls occurred in the past 90 days. Which approach provides this evidence MOST efficiently?
- Check AWS Trusted Advisor root account activity
- Run an IAM credential report
- Query CloudTrail Lake with SQL for root user events (Correct answer)
- Export all CloudTrail logs to S3 and grep manually
Correct answer: Query CloudTrail Lake with SQL for root user events
CloudTrail Lake allows SQL-based queries over event history, making it straightforward to filter for `userIdentity.type = Root` within a date range.
Question 49: Which AWS Well-Architected Tool feature allows teams to compare their workload against AWS best practices across five pillars?
- Config conformance packs
- Security Hub standards
- Trusted Advisor checks
- Well-Architected Review milestones (Correct answer)
Correct answer: Well-Architected Review milestones
The Well-Architected Tool guides teams through a questionnaire and records milestone snapshots showing improvement over time across all five pillars.
Question 50: What is the purpose of peer review in Architecting on AWS Certification joint design & preparation?
- To create competition and rivalry between colleagues
- To determine promotion rankings within the organization
- To reduce individual workloads through delegation
- To evaluate work quality through assessment by qualified colleagues for continuous improvement (Correct answer)
Correct answer: To evaluate work quality through assessment by qualified colleagues for continuous improvement
Peer review provides objective quality assessment by qualified professionals, identifying strengths and improvement areas while promoting accountability and continuous quality enhancement.
Question 51: A production Aurora cluster must undergo minor version upgrades with zero downtime. Which Aurora feature allows applying upgrades without interrupting read/write operations?
- Aurora Serverless v2 auto-pause
- Aurora Global Database failover
- Aurora Backtrack
- Aurora Zero-Downtime Patching (ZDP) (Correct answer)
Correct answer: Aurora Zero-Downtime Patching (ZDP)
Aurora Zero-Downtime Patching preserves existing connections and in-flight transactions during minor version upgrades, enabling maintenance with no observable downtime.
Question 52: Which performance pillar best practice involves choosing the right AWS storage type for an I/O-intensive OLTP database workload?
- Using Amazon EBS Provisioned IOPS (io1/io2) volumes for consistent, low-latency I/O (Correct answer)
- Using S3 for all database files
- Using EFS for shared database storage
- Using instance store for the OS and EBS for logs only
Correct answer: Using Amazon EBS Provisioned IOPS (io1/io2) volumes for consistent, low-latency I/O
Provisioned IOPS EBS volumes (io1/io2) deliver consistent, low-latency performance and are specifically designed for I/O-intensive OLTP databases requiring predictable IOPS.
Question 53: Which AWS global infrastructure component caches content at locations close to end users to reduce latency for web applications?
- AWS Outposts
- AWS Local Zones
- AWS Wavelength Zones
- Amazon CloudFront Edge Locations (Correct answer)
Correct answer: Amazon CloudFront Edge Locations
CloudFront Edge Locations are globally distributed points of presence that cache content and serve it from the location nearest to the user.
Question 54: What is the role of standard operating procedures in Architecting on AWS Certification joint design & preparation?
- To satisfy management preferences with no practical value
- To restrict professional creativity and innovation
- To create unnecessary paperwork for management
- To document step-by-step instructions ensuring consistency and quality across all practitioners (Correct answer)
Correct answer: To document step-by-step instructions ensuring consistency and quality across all practitioners
SOPs provide standardized instructions for routine tasks, ensuring consistent quality, safety, and efficiency regardless of which qualified person performs the work.
Question 55: Which AWS architectural principle recommends designing systems assuming that components will fail?
- Design for failure (Correct answer)
- Design for simplicity
- Design for performance
- Design for cost
Correct answer: Design for failure
AWS Well-Architected Framework's reliability pillar advises designing systems to expect and automatically recover from component failures.
Question 56: Which IAM entity should applications running on EC2 use to securely access other AWS services without storing long-term credentials?
- IAM user with access keys stored in the instance
- IAM group permissions
- Root account credentials
- IAM role attached to the EC2 instance (Correct answer)
Correct answer: IAM role attached to the EC2 instance
IAM roles attached to EC2 instances provide temporary, automatically-rotated credentials, eliminating the need to store long-term access keys.
Question 57: What is the purpose of Amazon S3 Intelligent-Tiering storage class?
- To encrypt all stored objects by default
- To automatically move objects between access tiers based on changing access patterns, optimizing cost (Correct answer)
- To replicate objects across three Regions automatically
- To provide the lowest possible latency for all S3 objects
Correct answer: To automatically move objects between access tiers based on changing access patterns, optimizing cost
S3 Intelligent-Tiering monitors object access and automatically moves objects between Frequent and Infrequent Access tiers (and archive tiers) to save costs without performance impact.
Question 58: Which Elastic Beanstalk deployment policy swaps environment URLs only after the new environment passes health checks, enabling non-destructive testing of new application versions?
- Rolling with additional batch
- Blue/Green (URL swap) (Correct answer)
- Immutable
- All at once
Correct answer: Blue/Green (URL swap)
Elastic Beanstalk blue/green deploys the new version to a cloned environment and only swaps the CNAME after health checks pass, leaving the old environment intact for rollback.
Question 59: An application uses DynamoDB and must remain available if an Availability Zone fails. Which DynamoDB feature handles this automatically?
- DynamoDB Global Tables
- DynamoDB Streams
- DynamoDB built-in multi-AZ replication (Correct answer)
- DynamoDB Accelerator (DAX)
Correct answer: DynamoDB built-in multi-AZ replication
DynamoDB automatically replicates data across three Availability Zones in a Region, providing built-in high availability with no additional configuration.
Question 60: What is the primary metallurgical reason for preheating high-carbon or alloy steels before welding?
- To slow the cooling rate of the HAZ, reducing martensite formation and hydrogen diffusion (Correct answer)
- To stabilize the austenite phase during solidification
- To increase the tensile strength of the weld metal
- To reduce the heat input required to achieve full penetration
Correct answer: To slow the cooling rate of the HAZ, reducing martensite formation and hydrogen diffusion
Preheat slows HAZ cooling, reducing martensite formation and keeping the steel above the temperature at which hydrogen diffusion stalls, allowing hydrogen to escape before cracking can initiate.
Question 61: Which AWS service enables you to centrally manage and enforce compliance rules across multiple AWS accounts by evaluating resource configurations?
- AWS Config (Correct answer)
- AWS Trusted Advisor
- AWS CloudTrail
- Amazon Inspector
Correct answer: AWS Config
AWS Config continuously monitors and records resource configurations and evaluates them against desired compliance rules.
Question 62: An architect wants to validate that an application degrades gracefully when DynamoDB throttling occurs, without exceeding read capacity in production. What is the safest approach?
- Use FIS to inject DynamoDB throttle errors on a test table that mirrors production schema (Correct answer)
- Disable DAX caching to amplify read load
- Temporarily lower the table's provisioned capacity and observe the application
- Switch the billing mode from on-demand to provisioned with a low cap
Correct answer: Use FIS to inject DynamoDB throttle errors on a test table that mirrors production schema
FIS can simulate DynamoDB throttle exceptions on a dedicated test table, letting you observe graceful degradation without touching the production table.
Question 63: A company subject to FedRAMP must use FIPS 140-2 validated encryption endpoints. How should architects configure AWS SDK clients to meet this requirement?
- Enable S3 Transfer Acceleration endpoints
- Use AWS FIPS endpoints for the relevant services (Correct answer)
- Configure SDK retry logic to maximum
- Enable VPC Flow Logs on all subnets
Correct answer: Use AWS FIPS endpoints for the relevant services
AWS publishes FIPS 140-2 validated service endpoints (e.g., s3-fips.us-east-1.amazonaws.com) that SDK clients must explicitly target to meet FedRAMP cryptographic requirements.
Question 64: A team wants to test a new Lambda function version in production without routing any customer traffic to it. Which approach allows non-destructive validation?
- Use Lambda aliases with 0% traffic weight on the new version (Correct answer)
- Deploy to a separate AWS account and use VPC peering
- Replace the existing function and monitor CloudWatch alarms
- Use AWS Config rules to validate the function before deployment
Correct answer: Use Lambda aliases with 0% traffic weight on the new version
Lambda weighted aliases let you assign 0% traffic to a new version so it can be invoked directly for testing without affecting live users.
Question 65: An architect wants to calibrate CloudFront cache behavior so that dynamic API responses are never cached while static assets are cached for 24 hours. How should cache policies be configured?
- Set a single default TTL of 0 for all origins
- Enable Origin Shield for all origins
- Use Lambda@Edge to set Cache-Control headers
- Use separate cache behaviors with CachingDisabled policy for the API path and a custom TTL policy for static paths (Correct answer)
Correct answer: Use separate cache behaviors with CachingDisabled policy for the API path and a custom TTL policy for static paths
CloudFront supports multiple cache behaviors per distribution; assigning CachingDisabled to the /api/* path and a custom TTL policy to /static/* provides precise per-path cache control.
AWS Certified Solutions Architect - Associate (SAA-C03)
The AWS Certified Solutions Architect - Associate exam validates the ability to design and implement distributed systems on AWS, covering secure, resilient, high-performing, and cost-optimized architectures. It targets individuals with at least one year of hands-on experience designing AWS cloud solutions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds