A financial services company is modernizing its on-premises data warehouse to AWS. The current system uses a legacy ETL tool that is not cloud-native. The company wants to build a new data lake on Amazon S3 and use a combination of serverless and managed services for ingestion, processing, and analytics. A key requirement is to provide business analysts with a unified SQL interface to query both structured data in Amazon Redshift and semi-structured data (JSON, Parquet) in the data lake. The solution must enforce fine-grained access control at the table and column level for all queries. Which solution meets these requirements most effectively?
Answer and explanation
Correct answer: B
This is the optimal solution. Amazon Redshift Spectrum allows querying data in Amazon S3 directly from Redshift, providing a unified SQL interface. AWS Lake Formation provides a centralized way to manage fine-grained permissions (table, column, row-level) for data in both the S3 data lake (via the AWS Glue Data Catalog) and Amazon Redshift. This approach meets all requirements for a unified interface and granular access control with managed services.
Question 2
Multiple answers
A large media organization operates a global video-on-demand platform. The architecture uses AWS Elemental MediaConvert for transcoding, Amazon S3 for storage, and Amazon CloudFront for delivery. The master video files are stored in an S3 bucket in the us-east-1 Region. To improve transcoding performance and resilience, the company wants to distribute the transcoding workload across us-east-1, eu-west-1, and ap-southeast-1. The goal is to automatically route an incoming transcoding job to the Region with the lowest processing load and ensure the output is available globally with low latency. Which architecture should be implemented to achieve this?
(Select TWO).
Answer and explanation
Correct answers: A, C
Combining S3 CRR with an EventBridge global endpoint provides a robust, resilient, and load-distributed solution. CRR ensures the source media is available locally in each processing Region, reducing latency and data transfer costs for transcoding. The EventBridge global endpoint with its health-checking and failover capabilities allows for intelligent routing of job requests to the healthiest and most available Region, effectively distributing the load.
Question 3
A hospital is deploying a critical patient records application on AWS, which must comply with HIPAA regulations. The architecture consists of an Application Load Balancer (ALB), an Amazon EC2 Auto Scaling group, and an Amazon Aurora PostgreSQL database. A recent security audit requires that all network traffic between the application servers and the database be inspected for potential SQL injection attacks by a third-party virtual appliance. This inspection must occur without traffic leaving the VPC, and the solution must be highly available. The architecture is deployed across three Availability Zones.
Which networking design meets these requirements?
Answer and explanation
Correct answer: B
This is the correct architecture for transparently inserting a fleet of security appliances into a network path. The Gateway Load Balancer is specifically designed for this purpose, acting as a transparent bump-in-the-wire. It allows you to scale the appliance fleet while the GWLB endpoints in each AZ provide a highly available, fixed next-hop for routing. This ensures all traffic from the application servers to the database is inspected without any changes to the application code and maintains high availability.
Question 4
A consultant is reviewing an existing AWS environment for a fast-growing startup. The startup has a single AWS account where all resources (dev, test, prod) are deployed within a single default VPC. This has led to IAM policies becoming overly complex and has caused several accidental terminations of production resources. The startup wants to implement a multi-account structure that improves security, provides cost allocation visibility, and establishes guardrails without slowing down developers. Which of the following is the most effective strategy to recommend?
Answer and explanation
Correct answer: C
AWS Control Tower is the most comprehensive and recommended solution for establishing a secure, well-architected multi-account environment. It automates the setup of a landing zone using best practices, including creating a foundational set of OUs, accounts (Log Archive, Audit), centralized logging with AWS CloudTrail and AWS Config, and a set of guardrails using SCPs. This directly addresses the startup's need for better security, cost visibility, and governance without requiring extensive manual setup.
Question 5
An e-commerce company's primary application runs on Amazon EC2 instances within an Auto Scaling group and uses an Amazon RDS for MySQL Multi-AZ database. During a recent peak sales event, the RDS instance's CPU utilization reached 100%, causing significant latency and transaction failures. The preliminary analysis shows that 80% of the database operations are read queries from the product catalog. The company needs to improve the application's performance and reliability, especially during traffic spikes, while minimizing changes to the application code. What is the MOST effective solution?
Answer and explanation
Correct answer: D
Given that 80% of the load is from read-heavy product catalog queries, implementing a caching layer is the most effective strategy. Amazon ElastiCache for Redis provides an in-memory data store with sub-millisecond latency. By caching frequently accessed data, the application can significantly reduce the read load on the primary RDS database, freeing up its CPU for write operations. This directly addresses the root cause of the performance bottleneck and is more effective than just scaling the database, which may still become a bottleneck under extreme load.
Question 6
A manufacturing firm is migrating its on-premises SAP S/4HANA environment to AWS. The production environment is business-critical and has a very low tolerance for downtime. The Recovery Time Objective (RTO) is 15 minutes, and the Recovery Point Objective (RPO) is 5 minutes. The firm needs a disaster recovery (DR) solution that enables failover to a different AWS Region. The solution must be cost-effective during normal operations. Which DR strategy should the solutions architect recommend?
Answer and explanation
Correct answer: D
AWS Elastic Disaster Recovery (DRS) is specifically designed for this use case. It provides low-RPO, low-RTO disaster recovery at a minimal cost. DRS continuously replicates block-level data to a lightweight staging area in the target Region. This keeps costs low because full-size recovery instances are not running. During a DR event, DRS automates the process of launching recovery instances, allowing the environment to be brought online within minutes, thus meeting the strict RTO and RPO requirements in a cost-effective manner. This is more cost-effective than Warm Standby and faster than Backup and Restore.
Question 7
A company has a hybrid cloud setup with an on-premises data center connected to an AWS VPC via AWS Direct Connect. An application running on-premises needs to privately and securely upload large data files directly into an Amazon S3 bucket. The company's security policy prohibits any data from traversing the public internet. Which configuration will allow the on-premises application to access the S3 bucket while adhering to the security policy?
Answer and explanation
Correct answer: C
This is the correct solution for private S3 access from on-premises over Direct Connect. A gateway VPC endpoint for S3 is only accessible from within the VPC itself, not from an on-premises network. An interface VPC endpoint for S3, however, places an Elastic Network Interface (ENI) with a private IP address inside your VPC. This ENI can be reached from your on-premises network over a Direct Connect private VIF. By configuring DNS appropriately, the on-premises application can resolve the S3 endpoint to this private IP, ensuring all traffic stays on the private network path.
Question 8
True or False: When using AWS Organizations, a Service Control Policy (SCP) that explicitly denies an action (e.g., ec2:RunInstances) in an Organizational Unit (OU) can be overridden by an IAM policy attached to a user within an account in that OU that explicitly allows the same action.
Answer and explanation
Correct answer: B
This is false. In AWS Organizations, SCPs act as guardrails and define the maximum permissions available to an account. An explicit deny in an SCP always takes precedence over any allow in an IAM policy. If an SCP denies an action, no principal in the affected account can perform that action, regardless of their IAM permissions. The effective permissions are the intersection of what the SCP allows and what the IAM policy allows.
Question 9
Multiple answers
A solutions architect is designing a centralized logging solution for a large enterprise with hundreds of AWS accounts managed under AWS Organizations. The requirements are:
All AWS CloudTrail logs from all member accounts must be aggregated into a central Amazon S3 bucket in a dedicated 'Log Archive' account.
The solution should automatically enforce this configuration for any new accounts added to the organization.
Member accounts must not be able to disable or modify their CloudTrail configuration.
The central security team needs to query these logs using Amazon Athena from a separate 'Audit' account.
Arrange the following steps in the correct order to implement this solution.
Answer and explanation
Correct answers: A, B, C, D
This must be the first step. Creating an organization trail from the management account is the feature that automatically enables CloudTrail on all member accounts (including new ones) and configures them to send logs to the central bucket.
This step is a prerequisite for creating the organization trail. The destination S3 bucket must exist and have the correct permissions to accept logs from the entire organization.
This step ensures that member accounts cannot tamper with the logging configuration, fulfilling a key security requirement.
This final step enables the cross-account query capability for the security team, completing the solution. The correct order is: Create and configure the bucket -> Create the organization trail -> Apply SCPs for enforcement -> Grant cross-account read access for auditing.