AWS Certified Solutions Architect - Associate Free Sample Questions

Covers designing secure access and workloads, scalable, highly available architectures, high-performing storage and compute solutions, and cost-optimized database and storage choices.

20 free sample questions270 in the full practice test Other version: SAA-C02(301)

Try simulator

SAA-C03 Sample Questions

  1. Question 1

    A financial services company is deploying a critical trading application on AWS that requires extremely low latency communication between a set of Amazon EC2 instances. The application is sensitive to network jitter and must be deployed in a way that minimizes the network path between instances. The architecture must also be resilient to the failure of a single underlying server rack within an Availability Zone. Which deployment strategy should a solutions architect recommend?

    Answer and explanation

    Correct answer: C

    A partition placement group provides the best balance for this scenario. It spreads instances across distinct underlying hardware (partitions/racks) within an Availability Zone, reducing correlated failures. At the same time, it keeps the instances geographically close within that AZ, which is crucial for low-latency communication. A cluster placement group offers the lowest latency but places instances on the same rack, making it vulnerable to a single rack failure. A spread placement group across multiple AZs would introduce higher latency, which is not suitable for the trading application's requirements.

  2. Question 2

    Multiple answers

    A company is migrating its on-premises data warehouse to Amazon Redshift. The security team has mandated that all data loaded into Redshift from Amazon S3 must be encrypted in transit and that the connection must not traverse the public internet. The EC2 instances that orchestrate the COPY commands are located in a private subnet within the same Region as the Redshift cluster and the S3 bucket.

    Which combination of actions will meet these security requirements? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    A gateway VPC endpoint for Amazon S3 allows traffic from the VPC to S3 to travel over the AWS private network, avoiding the public internet. This is a critical component for meeting the security requirement.

    Enhanced VPC Routing forces all COPY and UNLOAD traffic between the Redshift cluster and data repositories (like S3) to go through the VPC. When used with a VPC endpoint, it ensures the traffic stays on the AWS private network.

  3. Question 3

    A healthcare provider uses an application that processes patient data. The application runs on Amazon EC2 instances and stores data in an Amazon RDS for PostgreSQL database. To comply with regulations, all database credentials must be rotated every 30 days without causing application downtime. The application code cannot be modified to handle credential rotation logic. Which solution provides the MOST secure and automated way to meet this requirement?

    Answer and explanation

    Correct answer: B

    AWS Secrets Manager is the ideal service for this use case. It provides native integration with Amazon RDS for automated credential rotation, which updates the secret in Secrets Manager and the password in the database simultaneously. Since the application cannot be modified, using IAM authentication or an RDS Proxy would not work. By granting the EC2 instance's IAM role permission to read the secret, the application can fetch the current credentials at runtime without hardcoding them.

  4. Question 4

    A company is designing a cost-optimization strategy for its stateless, containerized web application running on Amazon ECS with the EC2 launch type. The application experiences predictable traffic, requiring a baseline of 10 instances during business hours (9 AM - 5 PM) and 2 instances overnight and on weekends. It can also tolerate interruptions for non-baseline capacity. Which combination of purchasing options offers the LOWEST cost while meeting the application's availability requirements?

    Answer and explanation

    Correct answer: D

    This is the most cost-effective strategy. Purchasing Reserved Instances for the 2 instances that run 24/7 provides the highest discount for the constant baseline. For the predictable peak during business hours, Scheduled Scaling can be used to increase the desired capacity. Using Spot Instances for this additional capacity provides significant savings, and is appropriate because the stateless application can tolerate interruptions. This blended approach correctly matches purchasing options to usage patterns.

  5. Question 5

    A retail company has a global application with a backend running in us-east-1. The application uses an Amazon Aurora database. Users in Europe and Asia are experiencing high read latency. The company wants to improve the read performance for these users with minimal application changes and provide a disaster recovery solution that allows for a failover to another region in under a minute. Which database architecture should be implemented?

    Answer and explanation

    Correct answer: C

    Amazon Aurora Global Database is specifically designed for this use case. It provides low-latency global reads by placing read replicas in different regions, which have a typical replication lag of under a second. It also offers a robust disaster recovery solution, allowing for a failover to a secondary region in typically less than one minute. This meets both the performance and resiliency requirements with minimal application changes, as the application can use region-specific endpoints.

  6. Question 6

    A solutions architect is designing a system to process a continuous stream of IoT data. The data must be processed in the order it is received for each IoT device. The system must also be able to handle sudden spikes in data volume and store the raw data durably for later batch analysis. The solution should be serverless and cost-effective. Which architecture best meets these requirements?

    Answer and explanation

    Correct answer: B

    This architecture meets all requirements. Kinesis Data Streams is designed for high-volume streaming data. Using the device ID as the partition key ensures that data from each device is processed in order. AWS Lambda provides scalable, serverless processing. Kinesis Data Firehose is the simplest, most cost-effective way to durably store the raw streaming data in Amazon S3 for later analysis.

  7. Question 7

    True or False: When using an Amazon S3 gateway endpoint in a VPC, you can use an endpoint policy to restrict access to specific S3 buckets, but you cannot restrict access based on specific S3 object-level API actions like s3:GetObject.

    Answer and explanation

    Correct answer: B

    This statement is false. A VPC endpoint policy is an IAM resource policy that you attach to an endpoint. You can use this policy to control access to the service. The policy can restrict access to specific resources (like S3 buckets) and also to specific API actions (like s3:GetObject or s3:PutObject). This allows for granular control over what actions can be performed on which resources through the endpoint.

  8. Question 8

    A company has a legacy monolithic application running on a large, memory-optimized Amazon EC2 instance. The application writes temporary data to a local disk during processing. The company wants to make the application highly available by running a standby instance in a different Availability Zone. The standby instance must be able to take over quickly and have access to the same temporary data if a failure occurs. The application cannot be refactored to use object storage. Which storage solution should be used for the temporary data to ensure high availability?

    Answer and explanation

    Correct answer: C

    Amazon EFS provides a shared file system that can be mounted concurrently by multiple EC2 instances, even across different Availability Zones. This makes it the perfect solution for this scenario. Both the primary and standby instances can read and write to the same EFS file system, ensuring that the temporary data is always available to the active instance. EBS volumes are tied to a single AZ, and instance stores are ephemeral and cannot be shared.

  9. Question 9

    A development team is using AWS Organizations to manage multiple AWS accounts. The central security team wants to enforce a preventative control that denies any IAM user or role in member accounts from disabling AWS CloudTrail or modifying its configuration. This rule must be enforced even by the root user of the member accounts. How can this be achieved?

    Answer and explanation

    Correct answer: B

    Service Control Policies (SCPs) are the correct tool for this requirement. SCPs are a type of organization policy that you can use to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts in your organization. An explicit Deny in an SCP overrides any Allow from IAM policies and applies to all principals in the account, including the root user. This makes them ideal for enforcing security guardrails.

  10. Question 10

    A gaming company is launching a new mobile game. The backend API is built using AWS Lambda and Amazon API Gateway. The company anticipates massive, unpredictable traffic spikes globally. The data for player leaderboards is stored in Amazon DynamoDB. To ensure a low-latency user experience, the company wants to cache database responses at the edge. Which service should be used to provide this caching capability with the least amount of architectural change?

    Answer and explanation

    Correct answer: A

    Enabling caching directly on the API Gateway stage is the simplest and most integrated solution. It allows you to cache the responses from your backend Lambda function, reducing the number of calls made to the function and the downstream DynamoDB table. This provides a low-latency experience for frequently requested data without requiring significant changes to the Lambda function or adding another service like ElastiCache to manage.