AWS Certified Solutions Architect - Associate Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 AWS Certified Solutions Architect - Associate flashcards as text
A company wants to run containers without managing the underlying EC2 instances. Which combination of services achieves this?
Answer: Amazon ECS with AWS Fargate
ECS with the Fargate launch type is a serverless compute engine that runs containers without provisioning or managing EC2 instances.
An architect needs to give a third-party auditor read-only access to specific AWS resources without sharing long-term credentials. Which IAM feature should be used?
Answer: Create an IAM role with a trust policy for the auditor's account
An IAM role with a cross-account trust policy allows the auditor to assume the role using their own credentials, eliminating the need for long-term shared keys.
Which AWS service provides DDoS protection automatically for all AWS customers at no additional cost?
Answer: AWS Shield Standard
AWS Shield Standard is automatically enabled for all AWS customers at no charge and protects against common Layer 3 and Layer 4 DDoS attacks.
A Lambda function needs to access an RDS database in a private subnet. What configuration is required?
Answer: Deploy Lambda in the same VPC and private subnet with appropriate security groups
Configuring a Lambda function to run inside a VPC with access to the private subnet where RDS resides, and allowing the security group, enables private connectivity.
An application must process streaming clickstream data in real time and store raw events for later batch analysis. Which combination of services is most appropriate?
Answer: Amazon Kinesis Data Streams + Amazon S3
Kinesis Data Streams ingests real-time streaming data at scale, and S3 provides cost-effective durable storage for raw events for batch analysis.
A company wants to centrally manage and enforce compliance policies across all AWS accounts in their organization. Which service provides this capability?
Answer: AWS Control Tower with AWS Organizations SCPs
AWS Control Tower with Organizations Service Control Policies (SCPs) provides centralized governance and guardrails enforced across all member accounts.
A web application hosted on EC2 behind an ALB needs to serve users globally with low latency. The architect also needs to protect it from SQL injection and cross-site scripting attacks. Which services should be combined?
Answer: Amazon CloudFront + AWS WAF
CloudFront caches content at edge locations globally for low latency, and AWS WAF attached to the CloudFront distribution filters SQLi and XSS attacks at the edge.