โ† All Architecting on AWS Certification Flashcard Decks

Joint Design & Preparation Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Joint Design & Preparation flashcards as text
  1. A team is jointly designing a multi-tier application on AWS and needs to ensure that the web tier can scale independently of the database tier. Which architectural pattern best supports this requirement?

    Answer: Decoupled architecture using Auto Scaling groups with SQS between tiers

    Decoupling tiers with SQS allows each layer to scale independently without being blocked by the other tier's capacity.

  2. During joint architecture planning for a global SaaS application, the team must reduce latency for international users without duplicating the entire backend. Which AWS service combination achieves this?

    Answer: Route 53 latency-based routing with regional API Gateway endpoints and a single primary database

    Latency-based routing with regional API endpoints serves requests from the nearest region while keeping the database centralized.

  3. Two teams are jointly preparing a disaster recovery strategy. The RTO is 1 hour and RPO is 15 minutes. Which DR strategy meets these requirements most cost-effectively?

    Answer: Warm standby with a scaled-down but running environment in a secondary region

    A warm standby keeps core services running at reduced capacity, enabling recovery within 1 hour while continuous replication satisfies the 15-minute RPO.

  4. A cross-functional team is designing a shared services VPC that must be accessed by 20 application VPCs in the same account. Which connectivity model scales best while avoiding complex route management?

    Answer: AWS Transit Gateway connecting all VPCs through a central hub

    Transit Gateway acts as a hub, eliminating the need to manage hundreds of individual peering connections as VPC count grows.

  5. During joint design sessions, the security team requires that all inter-service communication within a microservices architecture be mutually authenticated. Which approach best satisfies this on AWS?

    Answer: AWS App Mesh with mTLS enabled between Envoy proxies

    App Mesh with mTLS enforces mutual certificate-based authentication between services at the application layer, not just network layer.

  6. A team jointly planning a data lake architecture needs to separate raw, curated, and consumption zones. Which AWS service combination provides the best foundation for this?

    Answer: S3 with distinct prefixes or buckets per zone, AWS Glue for ETL, and Athena for querying

    S3 provides durable, scalable storage for each zone while Glue transforms data between zones and Athena enables serverless SQL querying.

  7. During architecture preparation, the team must choose an approach for managing secrets used by Lambda functions that access RDS. Which option follows AWS best practices?

    Answer: Use AWS Secrets Manager with automatic rotation and grant Lambda the secretsmanager:GetSecretValue permission

    Secrets Manager provides centralized secret storage with automatic rotation, and fine-grained IAM policies control which functions can retrieve each secret.