← All Architecting on AWS Certification Flashcard Decks

Mixed Deck — All Architecting on AWS Certification Topics Flashcards

100 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All Architecting on AWS Certification Topics flashcards as text
  1. What type of weld discontinuity is described as a planar defect running parallel to the fusion line, caused by poor inter-run fusion during multi-pass welding?

    Answer: Lack of inter-run fusion (cold lap)

    Cold lap (lack of inter-run fusion) occurs when the previous weld bead is not fully remelted, creating a planar, unbonded interface that acts as a severe stress concentrator.

  2. An architect needs to validate that all newly launched EC2 instances comply with a CIS benchmark before they serve production traffic. Which service can scan AMIs and running instances for security benchmark compliance?

    Answer: Amazon Inspector

    Amazon Inspector automatically assesses EC2 instances and container images against security benchmarks and CVE databases, providing findings with severity scores.

  3. Which VPC feature allows two VPCs to route traffic between each other using private IPv4 or IPv6 addresses, as if they were within the same network?

    Answer: VPC Peering

    VPC Peering creates a networking connection between two VPCs enabling instances to communicate using private IP addresses, but it is non-transitive and limited to two VPCs per connection.

  4. What welding defect is characterized by a groove melted into the base metal adjacent to the weld toe that is not filled by weld metal?

    Answer: Undercut

    Undercut is a groove or channel melted into the base metal at the weld toe caused by excessive amperage, improper electrode angle, or travel speed, creating a stress concentration.

  5. Which AWS service provides automated security assessments to identify vulnerabilities and deviations from best practices in EC2 instances and applications?

    Answer: Amazon Inspector

    Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices.

  6. An architect wants to improve the read performance of a relational database without scaling the primary instance. Which AWS solution achieves this?

    Answer: Add RDS Read Replicas and direct read traffic to them

    RDS Read Replicas asynchronously replicate data from the primary and allow read-heavy workloads to offload queries, improving overall throughput without upgrading the primary instance.

  7. Which EC2 purchasing option offers up to 90% discount compared to On-Demand pricing in exchange for a flexible one- or three-year commitment to a specific instance family and Region?

    Answer: Compute Savings Plans

    Compute Savings Plans offer up to 66% savings (EC2 Instance Savings Plans up to 72%) by committing to a consistent compute usage ($/hour) for 1 or 3 years with flexibility across instance families, sizes, and Regions.

  8. A company wants to deploy a multi-tier web application with automatic scaling. Which AWS service combination provides the BEST approach for the web and application tiers?

    Answer: Elastic Load Balancing with Auto Scaling groups and RDS Multi-AZ

    ELB with Auto Scaling groups distributes traffic and scales capacity automatically, while RDS Multi-AZ provides database high availability.

  9. An EC2 Auto Scaling group must replace instances whose status checks fail without any human intervention. Which Auto Scaling health check type should be enabled alongside EC2 status checks?

    Answer: ELB health check

    Enabling ELB health checks in the Auto Scaling group causes it to terminate and replace instances that the load balancer marks as unhealthy, beyond just EC2 status checks.

  10. What AWS feature lets you set a monthly cost threshold and receive an email notification when projected spend exceeds it?

    Answer: AWS Budgets alert

    AWS Budgets allows you to set cost or usage thresholds and sends alerts via SNS or email when they are breached.

  11. A company wants to replicate an RDS MySQL database to a different AWS Region for disaster recovery. Which feature should they use?

    Answer: RDS Cross-Region Read Replica

    RDS Cross-Region Read Replicas asynchronously copy data to another region, enabling DR failover.

  12. Which AWS service provides recommendations to help you follow AWS best practices for cost, security, fault tolerance, and performance?

    Answer: AWS Trusted Advisor

    AWS Trusted Advisor inspects your AWS environment and provides real-time guidance to provision resources following AWS best practices across five categories.

  13. A Solutions Architect needs to ensure that traffic between EC2 instances in a VPC and an S3 bucket does not traverse the public internet. What should be configured?

    Answer: Gateway VPC Endpoint for S3

    A Gateway VPC Endpoint for S3 routes traffic from the VPC directly to S3 over the AWS private network without using the internet.

  14. A web application needs to serve static assets globally with the lowest possible latency. Which combination is optimal?

    Answer: S3 as origin with Amazon CloudFront distribution

    CloudFront caches S3 objects at 400+ edge locations worldwide, delivering assets to users from the nearest point of presence.

  15. In AWS architecture diagrams, CloudFront is typically depicted at which location relative to the origin services?

    Answer: At the edge, outside the VPC, between end users and the origin

    CloudFront is drawn at the edge of the architecture between users and the origin, representing its role as a global CDN with edge locations.

  16. A security team wants to automatically assess EC2 instances for known software vulnerabilities and unintended network exposure. Which AWS service is purpose-built for this?

    Answer: Amazon Inspector

    Amazon Inspector automatically scans EC2 instances and container images for software vulnerabilities and unintended network exposure.

  17. What is a near-miss report in Architecting on AWS Certification safety management?

    Answer: Documentation of an event that could have resulted in harm but did not

    A near-miss report documents events where an injury, damage, or loss almost occurred. These reports provide valuable data for preventing future incidents by identifying systemic weaknesses before actual harm occurs.

  18. An architect is designing a multi-region architecture to meet GDPR data residency requirements. Which AWS feature most directly restricts where data is replicated?

    Answer: AWS Organizations Service Control Policies (SCPs) denying actions outside allowed regions

    SCPs can deny API actions (like S3 replication or EC2 launch) to non-approved regions, enforcing GDPR data residency at the account or OU level.

  19. What is the purpose of peer review in Architecting on AWS Certification joint design & preparation?

    Answer: To evaluate work quality through assessment by qualified colleagues for continuous improvement

    Peer review provides objective quality assessment by qualified professionals, identifying strengths and improvement areas while promoting accountability and continuous quality enhancement.

  20. An architect must confirm that Route 53 health checks correctly mark an endpoint unhealthy before switching DNS. What is the safest test method?

    Answer: Configure a health check against a test endpoint that returns a non-200 status and verify the health check transitions to unhealthy

    Testing health check logic against a dedicated test endpoint that deliberately returns an unhealthy response validates the behavior without touching live DNS records.