AI Cert Prep
Type to search documentation.

Start with AWS

AWS Services Practice Exam

An 80-item independent practice exam across eight AWS service domains, shared by all five certification tracks, with full explanations and a timed interactive mode.

An 80-item independent practice exam across the AWS service surface that the five certification tracks share. It is built at associate depth — scenario stems, plausible distractors, and explanations that say why the other three options fail. It is not an official AWS practice exam, contains no official exam questions, and is not affiliated with, endorsed by or approved by AWS.

One bank serves all five tracks because the underlying service knowledge is the same; only the emphasis differs. Use the domain table below to read your result against the exam you are actually sitting.

Instructions

  • Time: 160 minutes if you run it timed — two minutes per item, matching the associate pacing of 65 items in 130 minutes. Take it untimed the first time.
  • Items: 80, all multiple choice with a single correct answer out of four.
  • No guessing penalty: an unanswered item is scored incorrect, so answer everything and flag what you want to revisit.
  • Target: at least 75% raw before you book an associate exam, and 65% before a foundational one — this bank is pitched harder than CLF-C02 or AIF-C01.

Domain distribution

#DomainItems
1Compute and Containers6
2Storage and Data Management11
3Networking and Content Delivery15
4Databases11
5Serverless and Application Integration10
6Security, Identity and Compliance9
7Monitoring, Operations and Deployment13
8Cost Management and Multi-Account Governance5
 Total80

These are service domains, not any exam’s official blueprint. To map a weak result onto your own exam:

Your examRead these domains hardest
Cloud Practitioner2, 3, 4, 6, 8 — and treat depth beyond the explanation as optional
Solutions Architect – AssociateAll eight; 3, 4 and 6 carry the most weight
CloudOps Engineer – Associate7 first, then 3, 6 and 8
Developer – Associate5 and 6 first, then 7
AI Practitioner6 and 8 for the governance items; the rest is background

Score interpretation

Associate exams are scored on a scaled 100–1,000 range with a 720 pass mark; the two foundational exams pass at 700. AWS does not publish how a raw percentage maps to a scaled score, so the figure below is indicative only. Your raw percentage is the real signal.

Raw scoreReading
under 55%Not ready. Go back to the note pages for your two weakest domains before re-sitting.
55–69%Foundational-ready, associate-risky. Fine for CLF-C02 or AIF-C01; keep studying for an associate exam.
70–79%Approaching the associate line. Close the two weakest domains and re-sit timed.
80% and aboveStrong. Book with confidence, and use the explanations for the handful you missed.

Before you start

Sit this early, not last. Its job is diagnostic: two weak domains after 80 items tell you where the next ten hours of study go, which is worth far more than a flattering score at the end of your preparation. Then work every explanation — including the ones you got right, because a right answer for a wrong reason fails on the next variant.

Interactive mode

Take the practice exam

80 questions · one at a time · 160-minute countdown · results with per-domain breakdown and full correction at the end. Your progress is saved in this browser if you leave the page.

All questions (review mode)

Options are listed one per line. The answer and explanation stay hidden until you click Show answer. Use the interactive mode above for a timed sitting.

  1. Q1D3 · Networking and Content DeliverySelect one

    What is the fundamental difference between Security Groups and Network ACLs (NACLs) in a VPC?

    • A. Security Groups operate at the subnet level; NACLs operate at the instance level
    • B. Security Groups are stateful and instance-level; NACLs are stateless and subnet-level
    • C. Security Groups support deny rules; NACLs only support allow rules
    • D. Security Groups are evaluated in numbered order; NACLs evaluate all rules simultaneously
    Show answer

    Answer: B.

    Security Groups are stateful (response traffic is automatically allowed) and apply at the instance/ENI level. NACLs are stateless (return traffic must be explicitly allowed) and apply at the subnet level. NACLs support both allow and deny rules and evaluate rules in ascending numerical order — the first match wins. Security Groups only support allow rules.

  2. Q2D4 · DatabasesSelect one

    Your RDS production database must survive an Availability Zone failure with automatic failover and no data loss. Which RDS feature should you enable?

    • A. Read Replicas in another AZ
    • B. RDS Multi-AZ deployment
    • C. RDS automated backups with 7-day retention
    • D. Aurora Global Database
    Show answer

    Answer: B.

    RDS Multi-AZ creates a synchronous standby replica in a different AZ. Every write is replicated to the standby before being acknowledged (no data loss). RDS automatically fails over to the standby within 1–2 minutes if the primary fails. Read Replicas use asynchronous replication and are for read scaling, not HA failover — they can lag behind the primary and are not promoted automatically.

  3. Q3D2 · Storage and Data ManagementSelect one

    You have S3 objects whose access frequency is unpredictable — sometimes accessed daily, sometimes not for months. Which storage class automatically minimizes cost without manual management?

    • A. S3 Standard-IA
    • B. S3 One Zone-IA
    • C. S3 Intelligent-Tiering
    • D. S3 Glacier Instant Retrieval
    Show answer

    Answer: C.

    S3 Intelligent-Tiering automatically moves objects between access tiers (Frequent, Infrequent, Archive Instant Access) based on actual access patterns, with no retrieval fees or performance impact. Standard-IA and One Zone-IA require you to know that objects will be infrequently accessed and charge retrieval fees — they are not self-optimizing. Glacier has retrieval delays unsuitable for unpredictable access.

  4. Q4D6 · Security, Identity and ComplianceSelect one

    A Lambda function needs to read records from a DynamoDB table. What is the correct, secure way to grant it the necessary permissions?

    • A. Embed AWS access keys as environment variables in the Lambda function configuration
    • B. Store credentials in Parameter Store and retrieve them at runtime
    • C. Attach an IAM execution role with DynamoDB permissions to the Lambda function
    • D. Create an IAM user, generate access keys, and pass them in the Lambda code
    Show answer

    Answer: C.

    Lambda functions should always use IAM execution roles — never hardcoded credentials. You attach an IAM role with the required permissions (e.g., dynamodb:GetItem, dynamodb:Query) to the Lambda function, and the Lambda service automatically provides short-lived temporary credentials via the metadata endpoint. This eliminates long-term credential management and rotation. Embedding or storing static access keys is an anti-pattern and a security risk.

  5. Q5D3 · Networking and Content DeliverySelect one

    Private subnet EC2 instances need to download OS updates from the internet. They should NOT be reachable from the internet. Which component enables this?

    • A. Internet Gateway in the private subnet
    • B. VPC Endpoint for the package repository
    • C. NAT Gateway in a public subnet, with a route in the private subnet's route table
    • D. Elastic IP attached directly to the private instances
    Show answer

    Answer: C.

    A NAT Gateway placed in a public subnet enables outbound-only internet access for private subnet instances. The private subnet's route table points 0.0.0.0/0 to the NAT Gateway; the NAT Gateway translates the source IP to its own Elastic IP for outbound traffic but blocks all inbound connections initiated from the internet. Internet Gateways enable two-way communication — attaching one to a private subnet would make it public. Elastic IPs on private instances would expose them to the internet.

  6. Q6D7 · Monitoring, Operations and DeploymentSelect one

    Which CloudWatch metric for EC2 instances is NOT available by default and requires the CloudWatch Agent to be installed?

    • A. CPU Utilization
    • B. Network In/Out
    • C. RAM (Memory) Utilization
    • D. Disk Read/Write Bytes (EBS)
    Show answer

    Answer: C.

    RAM utilization is not a default CloudWatch metric because the AWS hypervisor cannot observe memory usage inside the guest OS. To collect RAM, disk space, or other OS-level metrics, you must install the CloudWatch Agent on the instance and configure it to publish custom metrics. CPU Utilization, Network In/Out, and EBS Disk metrics are collected at the hypervisor level and reported automatically without any agent.

  7. Q7D5 · Serverless and Application IntegrationSelect one

    You need to decouple a high-traffic write API from a slower downstream processor. Messages must be processed in strict order and each message processed exactly once. Which SQS queue type should you use?

    • A. SQS Standard Queue — it provides the highest throughput
    • B. SQS FIFO Queue — it guarantees ordering and exactly-once processing
    • C. SQS Standard Queue with message deduplication enabled
    • D. SNS Topic with SQS Standard Queue subscription
    Show answer

    Answer: B.

    SQS FIFO (First-In, First-Out) queues guarantee strict message ordering and exactly-once processing with deduplication. SQS Standard queues offer higher throughput but only provide best-effort ordering and at-least-once delivery (a message can be delivered more than once). Use FIFO when message order and deduplication are business requirements (financial transactions, sequential workflows). Note that FIFO queues have a throughput limit of 3,000 messages/second with batching.

  8. Q8D4 · DatabasesSelect one

    Your web application behind an ALB uses EC2 instances that store user session data in local memory. Sessions are lost when the load balancer routes a user to a different instance. What is the correct architectural fix?

    • A. Enable sticky sessions (session affinity) on the ALB to always route each user to the same instance
    • B. Move session state to a shared external store such as ElastiCache (Redis) or DynamoDB
    • C. Increase the number of EC2 instances to reduce the chance of routing to a new one
    • D. Switch from ALB to NLB which preserves source IP and maintains session consistency
    Show answer

    Answer: B.

    The correct fix is to externalize session state to a shared, stateless store (ElastiCache Redis or DynamoDB) so that any instance can serve any user's request. Sticky sessions are a short-term workaround that defeats horizontal scaling — if the "sticky" instance fails, the user's session is still lost. Making the application stateless by externalizing session data is the foundational pattern for scalable, resilient web architectures on AWS.

  9. Q9D7 · Monitoring, Operations and DeploymentSelect one

    Which Elastic Beanstalk deployment policy deploys the new version to a completely fresh set of instances without touching the current production fleet, enabling instant rollback?

    • A. All at once
    • B. Rolling
    • C. Rolling with additional batch
    • D. Immutable
    Show answer

    Answer: D.

    Immutable deployments launch a new Auto Scaling Group with the new version running alongside the existing production fleet. If deployment validation passes, traffic shifts to the new instances and the old ones are terminated. Rollback is instant — just terminate the new ASG. All at once deploys to all instances simultaneously (fast but causes downtime). Rolling and Rolling with additional batch update the existing fleet in batches (reduced capacity or full capacity respectively), but rolling back requires a new deployment.

  10. Q10D7 · Monitoring, Operations and DeploymentSelect one

    A CloudFormation stack manages an RDS database. You want to ensure the database is NOT deleted when the stack is deleted, and that a final snapshot is taken automatically. Which setting achieves this?

    • A. Set DeletionPolicy: Retain on the RDS resource
    • B. Set DeletionPolicy: Snapshot on the RDS resource
    • C. Enable Multi-AZ on the RDS resource in the template
    • D. Add a stack termination protection policy
    Show answer

    Answer: B.

    DeletionPolicy: Snapshot causes CloudFormation to take a final DB snapshot before deleting the RDS instance when the stack is deleted — giving you a restore point even after the infrastructure is decommissioned. DeletionPolicy: Retain keeps the resource running after stack deletion (no snapshot). Stack termination protection prevents the stack from being deleted entirely but does not create snapshots. DeletionPolicy: Snapshot is the recommended best practice for any production RDS instance managed by CloudFormation.

  11. Q11D6 · Security, Identity and ComplianceSelect one

    A company needs to give an external auditor read-only access to specific S3 buckets in their AWS account, without creating a permanent IAM user. What is the correct approach?

    • A. Create an IAM user with read-only S3 permissions and share the credentials
    • B. Make the S3 buckets public and share the bucket URLs
    • C. Create an IAM role with S3 read-only permissions and allow the auditor's AWS account to assume it via STS
    • D. Generate a Pre-signed URL for each S3 object and send them to the auditor
    Show answer

    Answer: C.

    IAM roles with cross-account trust policies are the correct pattern for granting temporary, scoped access to external parties. The auditor's AWS account assumes the role via STS AssumeRole, receives temporary credentials scoped to S3 read-only, and those credentials expire automatically. Creating a permanent IAM user shares long-term credentials. Making buckets public exposes them to everyone. Pre-signed URLs grant access to individual objects, not a structured audit of buckets.

  12. Q12D3 · Networking and Content DeliverySelect one

    Your CloudFront distribution serves content from an S3 bucket. You want to ensure users can ONLY access S3 content through CloudFront — not directly via the S3 URL. Which CloudFront feature achieves this?

    • A. Enable S3 Transfer Acceleration on the bucket
    • B. Configure an Origin Access Control (OAC) and update the S3 bucket policy to allow only the CloudFront distribution
    • C. Enable versioning on the S3 bucket
    • D. Set the S3 bucket policy to deny all public access
    Show answer

    Answer: B.

    Origin Access Control (OAC) is the modern mechanism to restrict S3 bucket access exclusively to a specific CloudFront distribution. CloudFront signs requests to S3 using SigV4; the bucket policy is updated to allow s3:GetObject only from the CloudFront service principal with the specific distribution ARN. All direct S3 access returns 403. Transfer Acceleration speeds up uploads, not access control. Simply denying public access without OAC would also block CloudFront.

  13. Q13D3 · Networking and Content DeliverySelect one

    You have 15 VPCs across 3 AWS accounts that all need to communicate with each other and with your on-premises network via Direct Connect. What is the most operationally efficient architecture?

    • A. Create VPC peering connections between every pair of VPCs (full mesh)
    • B. Deploy a Transit Gateway and attach all VPCs and the Direct Connect gateway to it
    • C. Use a VPN connection between each VPC and on-premises
    • D. Deploy a NAT Gateway in each VPC to route traffic between them
    Show answer

    Answer: B.

    AWS Transit Gateway acts as a central regional hub that enables transitive routing between all attached VPCs and on-premises connections. With 15 VPCs, a full mesh of VPC peering connections would require up to 105 individual peering connections, each managed separately — this does not scale. VPC peering is also non-transitive, requiring direct connections between every pair. Transit Gateway supports thousands of attachments, enables transitive routing, and integrates natively with Direct Connect and VPN.

  14. Q14D4 · DatabasesSelect one

    Your application writes data that must be immediately readable by any subsequent read from the same client. Which DynamoDB read consistency mode is required?

    • A. Eventual consistency — it achieves consistency within 1 second which is sufficient
    • B. Strongly consistent reads — they always reflect the latest successful write
    • C. DynamoDB Streams — they provide real-time change capture for immediate reads
    • D. DAX (DynamoDB Accelerator) — it caches writes and makes them immediately readable
    Show answer

    Answer: B.

    Strongly consistent reads in DynamoDB always return the most up-to-date data, reflecting all writes that received a successful response. Eventual consistency (the default) may return slightly stale data from a replica that has not yet received the latest write. If your application requires read-your-writes consistency (a client immediately reads what it just wrote), strongly consistent reads are mandatory. Note that strongly consistent reads consume twice the RCUs and are not available via GSIs.

  15. Q15D5 · Serverless and Application IntegrationSelect one

    A startup needs to process millions of clickstream events from their website in real time. Multiple teams need to independently analyze the same stream — one for fraud detection, one for recommendations, one for billing. Which service best fits this use case?

    • A. SQS Standard Queue — each team subscribes to the same queue
    • B. SQS FIFO Queue — it guarantees ordering for the event stream
    • C. Kinesis Data Streams — multiple independent consumers can process the same stream simultaneously
    • D. SNS Topic — it fans out events to all subscribers
    Show answer

    Answer: C.

    Kinesis Data Streams is designed exactly for this pattern: high-throughput ingestion of streaming data that multiple independent consumers process simultaneously at their own pace from the same stream. Kinesis retains data for 24 hours (up to 365 days), enabling replay. SQS messages are consumed and deleted — once one consumer reads a message, it is no longer available to others. SNS fan-out to SQS could work but adds complexity; Kinesis natively handles multiple consumers on a single stream with the Enhanced Fan-Out feature.

  16. Q16D7 · Monitoring, Operations and DeploymentSelect one

    You are about to update a CloudFormation stack that manages a production environment. You want to see exactly which resources will be modified, replaced, or deleted before committing the change. What should you use?

    • A. Deploy the template to a staging stack first and compare the outputs
    • B. Enable CloudFormation drift detection on the stack
    • C. Create a CloudFormation ChangeSet and review it before executing
    • D. Use the AWS Config service to preview configuration changes
    Show answer

    Answer: C.

    CloudFormation ChangeSets preview the impact of a template change before execution — showing which resources will be Added, Modified in-place, or Replaced (deleted and recreated). Resource replacement is critical to review because it means data loss or downtime for stateful resources like RDS databases. Drift detection identifies resources that were changed outside of CloudFormation, not future changes. Always create and review a ChangeSet before updating production stacks.

  17. Q17D3 · Networking and Content DeliverySelect one

    Your application tier runs in private subnets. EC2 instances must access DynamoDB without their traffic leaving the Amazon network (compliance requirement). What is the correct solution?

    • A. Deploy a NAT Gateway so instances can reach DynamoDB over the internet
    • B. Create a VPC Interface Endpoint for DynamoDB
    • C. Create a VPC Gateway Endpoint for DynamoDB
    • D. Enable VPC Flow Logs to monitor and restrict DynamoDB traffic
    Show answer

    Answer: C.

    A VPC Gateway Endpoint for DynamoDB (and S3) routes traffic privately within the Amazon network by adding an entry to the subnet's route table — traffic never leaves AWS. Gateway Endpoints are free of charge. Interface Endpoints use PrivateLink (ENIs with private IPs) and are used for most other services, but not DynamoDB or S3. A NAT Gateway routes traffic through the internet, violating the compliance requirement. VPC Flow Logs are an observability tool, not a routing mechanism.

  18. Q18D6 · Security, Identity and ComplianceSelect one

    You need to encrypt data stored in S3 and require a full audit log of every encryption and decryption operation for compliance. Which S3 encryption option meets this requirement?

    • A. SSE-S3 (Server-Side Encryption with S3-Managed Keys)
    • B. SSE-KMS (Server-Side Encryption with AWS KMS-Managed Keys)
    • C. SSE-C (Server-Side Encryption with Customer-Provided Keys)
    • D. Client-side encryption before uploading to S3
    Show answer

    Answer: B.

    SSE-KMS uses AWS KMS to manage encryption keys and automatically generates a CloudTrail audit record for every KMS API call — every encryption and decryption operation is logged with the caller identity, timestamp, and key used. This is the only option that provides a built-in, tamper-evident audit trail for key usage. SSE-S3 uses AWS-managed keys with no per-operation audit trail. SSE-C means you manage the keys externally; AWS does not log usage. Client-side encryption is entirely outside AWS visibility.

  19. Q19D3 · Networking and Content DeliverySelect one

    A global e-commerce company needs to route users to the nearest AWS region to minimize latency. Failover to another region should happen automatically if a regional endpoint becomes unhealthy. Which Route 53 routing policy combination achieves this?

    • A. Simple routing with multiple values — Route 53 returns all IPs and the client picks the nearest
    • B. Geolocation routing — directs users to a specific region based on their country
    • C. Latency-based routing with health checks — routes to the lowest-latency healthy region
    • D. Weighted routing with equal weights across all regions
    Show answer

    Answer: C.

    Latency-based routing directs each request to the AWS region that provides the lowest measured network latency for that user, globally. Combining it with Route 53 health checks ensures that if a regional endpoint fails its health check, Route 53 automatically removes it from DNS responses and routes to the next-lowest-latency healthy region. Geolocation routing assigns traffic by country/continent regardless of latency. Simple routing does not consider latency or health. Weighted routing splits traffic by configured percentages, not by latency.

  20. Q20D4 · DatabasesSelect one

    Your Lambda function connects to an RDS database. During peak traffic, you observe "too many connections" errors because thousands of Lambda invocations each try to open a new database connection. What is the correct architectural fix?

    • A. Increase the max_connections parameter on the RDS instance
    • B. Switch to a larger RDS instance class to support more connections
    • C. Add RDS Read Replicas to distribute connection load
    • D. Deploy RDS Proxy between Lambda and RDS to pool and multiplex connections
    Show answer

    Answer: D.

    RDS Proxy maintains a persistent pool of connections to the RDS database and multiplexes many application connections (Lambda invocations) onto a much smaller set of actual database connections. This solves the Lambda-RDS connection exhaustion problem at its root, without requiring a larger database. Increasing max_connections only defers the problem. Read Replicas distribute reads but each replica also has a connection limit and does not help with write connections. RDS Proxy also improves failover speed during Multi-AZ events.

  21. Q21D1 · Compute and ContainersSelect one

    Your application experiences predictable traffic spikes every weekday at 9 AM and drops at 6 PM. CPU utilization also spikes unpredictably during the day. Which combination of Auto Scaling policies handles both patterns optimally?

    • A. Two Simple Scaling policies: one for the morning spike and one for the evening drop
    • B. Scheduled Scaling to pre-warm capacity before 9 AM and scale in after 6 PM, combined with Target Tracking to handle unpredictable intra-day CPU spikes
    • C. A single Target Tracking policy targeting 50% CPU — it handles both scheduled and unpredictable load automatically
    • D. Manual scaling adjustments made by the operations team each morning and evening
    Show answer

    Answer: B.

    Scheduled Scaling pre-emptively adjusts capacity at known times — scaling out before 9 AM prevents the cold-start latency penalty of reactive scaling during the morning rush. Target Tracking then maintains the desired CPU utilization throughout the day by responding to unpredictable spikes in real time. A single Target Tracking policy cannot anticipate predictable patterns — it only reacts after the metric breaches the threshold, causing a lag. Combining the two policies gives you both predictability and reactivity.

  22. Q22D2 · Storage and Data ManagementSelect one

    A financial trading platform requires consistent, sub-millisecond I/O latency for its database volumes with no burstable performance — throughput must be guaranteed regardless of volume size. Which EBS volume type is correct?

    • A. gp3 — it provides a configurable baseline of 3,000 IOPS and 125 MB/s throughput for most workloads
    • B. st1 — Throughput Optimized HDD delivers the highest sequential throughput at low cost
    • C. io2 Block Express — it provides up to 256,000 IOPS with consistent, provisioned performance independent of volume size
    • D. sc1 — Cold HDD is the lowest-latency option for infrequently accessed data
    Show answer

    Answer: C.

    io2 (Provisioned IOPS SSD) and io2 Block Express are designed for I/O-intensive workloads requiring consistent, predictable, sub-millisecond performance — the IOPS you provision is what you get, regardless of volume size or accumulated I/O credits. gp3 provides a solid baseline (3,000 IOPS) but is designed for general-purpose workloads, not guaranteed high-performance databases. st1 and sc1 are HDD-based with much higher latency and are optimized for sequential throughput, not transaction-heavy databases.

  23. Q23D2 · Storage and Data ManagementSelect one

    You store compliance documents in S3 that must be retained for 7 years. For the first 30 days they are actively accessed; then rarely for 90 days; then never. You want the lowest possible storage cost. What lifecycle policy achieves this?

    • A. Store everything in S3 Standard for 7 years — reliability justifies the cost for compliance data
    • B. Transition to Standard-IA after 30 days, then to Glacier Flexible Retrieval after 90 days, then delete after 7 years
    • C. Store in S3 One Zone-IA immediately — compliance documents do not need multi-AZ durability
    • D. Enable S3 Intelligent-Tiering and let AWS automatically manage all transitions
    Show answer

    Answer: B.

    S3 lifecycle policies automate cost optimization by transitioning objects through storage classes as they age. Standard for the first 30 days handles active access with no retrieval fees. Standard-IA from day 30–90 reduces storage cost for occasional access. Glacier Flexible Retrieval from day 90 onward provides the lowest cost for dormant archive data (minutes-to-hours retrieval is acceptable since documents are rarely accessed). A delete rule at 7 years prevents indefinite accumulation. One Zone-IA sacrifices the multi-AZ durability guarantee that compliance data typically requires.

  24. Q24D7 · Monitoring, Operations and DeploymentSelect one

    A CloudWatch Alarm monitoring an EC2 instance's CPU shows the state "INSUFFICIENT_DATA" immediately after creation. What does this state mean?

    • A. The alarm has detected a problem and is about to transition to ALARM state
    • B. There are not enough data points yet to evaluate the alarm — the metric has not reported enough samples for the evaluation period
    • C. The EC2 instance is stopped and CloudWatch cannot collect metrics from a stopped instance
    • D. The alarm threshold is incorrectly configured and must be recalibrated
    Show answer

    Answer: B.

    INSUFFICIENT_DATA is the initial state for a newly created alarm, and also occurs when the metric stops reporting data (e.g., an instance is terminated or a custom metric stops publishing). It means the alarm cannot make an evaluation because there are not enough data points within the evaluation window — not that a problem was detected. CloudWatch Alarms transition: INSUFFICIENT_DATA → OK (threshold not breached) or INSUFFICIENT_DATA → ALARM (threshold breached), depending on what the metric reports once sufficient data accumulates.

  25. Q25D6 · Security, Identity and ComplianceSelect one

    An IAM user has an identity policy that allows s3:DeleteObject on all S3 buckets. The S3 bucket also has a resource-based policy that explicitly denies s3:DeleteObject for that user. What happens when the user tries to delete an object?

    • A. The action is allowed — identity policies take precedence over resource-based policies
    • B. The action is allowed — the most permissive policy always wins when there is a conflict
    • C. The action is denied — an explicit Deny in any applicable policy always overrides any Allow
    • D. The result is undefined — AWS requires a manual review when policies conflict
    Show answer

    Answer: C.

    The IAM policy evaluation order is deterministic: an explicit Deny anywhere in the policy evaluation chain always overrides any Allow, regardless of which policy type contains it. The evaluation logic checks: (1) Is there an explicit Deny? → Deny immediately. (2) Is there an explicit Allow? → Allow. (3) Neither → implicit Deny. This makes explicit Deny rules a powerful security mechanism for enforcing hard boundaries (e.g., preventing deletion of critical resources even by administrators), since no Allow rule can override them.

  26. Q26D3 · Networking and Content DeliverySelect one

    You are planning a VPC with CIDR 10.0.0.0/16. You create a public subnet with CIDR 10.0.1.0/24. How many IP addresses are actually available for EC2 instances in this subnet?

    • A. 256 — all addresses in the /24 block are available
    • B. 254 — AWS reserves the network address and broadcast address
    • C. 251 — AWS reserves 5 IP addresses per subnet for networking purposes
    • D. 248 — AWS reserves 5 addresses plus 3 additional ELB addresses
    Show answer

    Answer: C.

    AWS always reserves exactly 5 IP addresses in every subnet: x.x.x.0 (network address), x.x.x.1 (VPC router), x.x.x.2 (DNS server), x.x.x.3 (reserved for future use), and x.x.x.255 (broadcast address). For a /24 subnet with 256 total addresses, 256 − 5 = 251 are usable by your resources. This reservation applies to every subnet regardless of size — a /28 subnet (16 total addresses) has only 11 usable addresses. Always account for this when sizing subnets, especially smaller ones.

  27. Q27D5 · Serverless and Application IntegrationSelect one

    Your Lambda function processes critical payment transactions. Cold starts are unacceptable — the function must respond within 100ms even on the first invocation. Which Lambda feature eliminates cold starts?

    • A. Reserved Concurrency — it reserves a fixed number of concurrent executions for the function
    • B. Provisioned Concurrency — it keeps a specified number of execution environments initialized and ready to respond immediately
    • C. Lambda@Edge — it deploys the function to edge locations closer to users
    • D. Increasing memory to 10 GB — more memory reduces initialization time proportionally
    Show answer

    Answer: B.

    Provisioned Concurrency pre-initializes a specified number of Lambda execution environments, keeping them "warm" and ready to serve requests with no initialization delay. Cold starts occur because Lambda must download and initialize the execution environment on first invocation — Provisioned Concurrency eliminates this by doing that work in advance. Reserved Concurrency limits how many concurrent executions a function can have (a cap, not a warm-up). More memory speeds up initialization but does not eliminate it. Provisioned Concurrency has an additional cost but is essential for latency-sensitive functions.

  28. Q28D4 · DatabasesSelect one

    Your application must serve users globally with low read latency from any region, and must tolerate a region becoming entirely unavailable without data loss. Which DynamoDB feature enables this?

    • A. DynamoDB Read Replicas — create asynchronous replicas in multiple regions for read scaling
    • B. DynamoDB Multi-AZ — enables automatic failover within a region across three AZs
    • C. DynamoDB Global Tables — provides multi-region, multi-active replication with automatic conflict resolution
    • D. DynamoDB DAX — in-memory caching reduces read latency to microseconds globally
    Show answer

    Answer: C.

    DynamoDB Global Tables replicates data across multiple AWS regions with multi-active (multi-master) writes — any region can accept both reads and writes, and changes propagate to all other regions within seconds. If a region becomes unavailable, your application automatically routes to another region with no data loss for committed writes. Read Replicas are an RDS concept, not DynamoDB. Multi-AZ is a single-region HA feature. DAX accelerates reads within a single region but does not provide cross-region availability.

  29. Q29D4 · DatabasesSelect one

    Your application needs to cache database query results and also store user session data that must survive a cache node restart. Which ElastiCache engine should you choose?

    • A. Memcached — it is simpler and scales horizontally across many nodes for maximum throughput
    • B. Redis — it supports persistence, replication, and data structure types like hashes and sorted sets, making it suitable for both caching and durable session storage
    • C. Either engine works equally well — both support persistence and replication
    • D. Neither — session data should always be stored in RDS, not ElastiCache
    Show answer

    Answer: B.

    Redis supports persistence (snapshots and AOF logs), replication (primary-replica), and rich data structures (strings, hashes, lists, sorted sets, sets) — making it the correct choice when cached data must survive node restarts or when you need shared session storage. Memcached is a pure in-memory cache with no persistence, no replication, and only simple key-value storage — data is permanently lost if a node fails or restarts. For scenarios requiring only horizontal scaling of a simple cache (and data loss on restart is acceptable), Memcached is simpler and marginally faster.

  30. Q30D8 · Cost Management and Multi-Account GovernanceSelect one

    A company uses AWS Organizations with multiple member accounts. They want to prevent any account in the "Development" organizational unit from launching resources in the us-east-1 region, even if an account administrator grants themselves permission. What achieves this?

    • A. Apply an IAM permission boundary to every user in every Development account
    • B. Create a Service Control Policy (SCP) that denies all actions with a condition on the us-east-1 region and attach it to the Development OU
    • C. Use AWS Config rules in each account to detect and auto-remediate us-east-1 resources
    • D. Configure CloudTrail to alert when us-east-1 resources are created
    Show answer

    Answer: B.

    Service Control Policies (SCPs) are the only mechanism that can restrict permissions for all principals in an AWS account — including the account's own root user and administrators. An SCP attached to an OU applies to all accounts within it as a maximum permission boundary: even if an account grants full AdministratorAccess, the SCP prevents actions it denies. IAM permission boundaries require being applied to every user individually — administrators can bypass them by not applying them to new users. Config rules are reactive (detect after creation), not preventive.

  31. Q31D1 · Compute and ContainersSelect one

    You are building a containerized microservices application. Each service needs to scale independently, and the team wants to avoid managing EC2 instances entirely. Which setup is most appropriate?

    • A. ECS with EC2 launch type — gives full control over the underlying instances for customization
    • B. ECS with Fargate launch type — AWS manages all underlying infrastructure; you only define task CPU and memory
    • C. Elastic Beanstalk with Docker — provides PaaS simplicity with automatic container management
    • D. EC2 with Docker installed manually — full control with the lowest possible cost
    Show answer

    Answer: B.

    ECS with Fargate is the serverless container option: you define the CPU and memory for each task, and AWS provisions, scales, and patches the underlying infrastructure. There are no EC2 instances to manage, patch, or right-size. Each ECS service scales independently based on its own CloudWatch metrics or custom scaling policies. The EC2 launch type requires managing and patching a cluster of EC2 instances. Elastic Beanstalk with Docker works for simpler single-container deployments but does not provide the per-service independent scaling that microservices require.

  32. Q32D2 · Storage and Data ManagementSelect one

    You enable S3 Cross-Region Replication (CRR) on a bucket that already has 10,000 objects. Which statement about CRR behaviour is correct?

    • A. CRR automatically replicates all 10,000 existing objects to the destination bucket immediately upon activation
    • B. CRR only replicates objects created or modified after replication is enabled; existing objects must be copied separately using S3 Batch Operations
    • C. CRR replicates all objects but only after the first new object is uploaded to the source bucket
    • D. CRR requires the source and destination buckets to have the same name to activate successfully
    Show answer

    Answer: B.

    CRR is prospective — it replicates objects created or modified after replication is configured. Existing objects at the time of enabling CRR are not replicated automatically. To replicate pre-existing objects, you must run a separate S3 Batch Operations job using the S3 ReplicateObject operation. Additionally, CRR requires versioning to be enabled on both source and destination buckets, and the IAM role used for replication must have read permissions on the source and write permissions on the destination.

  33. Q33D7 · Monitoring, Operations and DeploymentSelect one

    You deploy an EC2 instance via CloudFormation with a user data script that installs application dependencies. The stack completes successfully but the application is not working because the install script failed silently. How do you make CloudFormation wait for the script to succeed before marking the stack complete?

    • A. Add a DependsOn attribute from the EC2 instance to the application — CloudFormation will wait for both
    • B. Use the cfn-signal helper script with a CreationPolicy on the EC2 resource, so CloudFormation only marks the instance complete after receiving a success signal
    • C. Add a 5-minute wait condition using AWS::CloudFormation::WaitCondition before the application resources
    • D. Enable CloudFormation drift detection — it will detect when the application is not running as expected
    Show answer

    Answer: B.

    cfn-signal combined with a CreationPolicy is the correct pattern. The CreationPolicy on the EC2 resource tells CloudFormation to wait for N success signals within a timeout before marking the resource CREATE_COMPLETE. The user data script calls cfn-signal --success true after confirming the install succeeded (or cfn-signal --success false on failure). Without this, CloudFormation marks the instance complete the moment the EC2 service reports it as running — before user data has finished executing. DependsOn only controls creation order, not success conditions.

  34. Q34D4 · DatabasesSelect one

    Which AWS service provides a managed connection pool for RDS databases, improves failover times during Multi-AZ events, and supports IAM-based database authentication — all without changing application code?

    • A. Amazon ElastiCache — it caches query results to reduce database connection frequency
    • B. AWS Database Migration Service — it manages connections during database migrations
    • C. Amazon RDS Proxy — it sits between applications and RDS, managing connection pooling, failover, and IAM auth transparently
    • D. AWS Systems Manager Parameter Store — it stores and rotates database credentials securely
    Show answer

    Answer: C.

    RDS Proxy is a fully managed database proxy that addresses three problems simultaneously: it pools and multiplexes application connections onto fewer actual database connections (solving Lambda and ECS connection exhaustion); it maintains the connection pool during Multi-AZ failover, reducing application-visible downtime from minutes to seconds; and it supports IAM-based database authentication so applications never handle database passwords. It requires no application code changes — you simply point your connection string at the proxy endpoint instead of the RDS endpoint.

  35. Q35D7 · Monitoring, Operations and DeploymentSelect one

    A new AWS CloudTrail trail is created in your account. A security engineer asks: "Does CloudTrail cover ALL API calls across ALL regions automatically?" What is the correct answer?

    • A. Yes — CloudTrail is a global service and automatically captures all API calls across all regions
    • B. No — by default a trail only covers the region it was created in; you must enable "Apply trail to all regions" to capture events globally
    • C. Yes — but only for AWS managed services; EC2 and VPC events require a separate trail
    • D. No — CloudTrail only captures console actions; CLI and SDK calls require a separate configuration
    Show answer

    Answer: B.

    A CloudTrail trail is regional by default — it only captures events in the region where it was created. To capture API activity across all regions in a single trail, you must explicitly enable "Apply trail to all regions" (or create an organization trail in AWS Organizations, which covers all accounts and all regions). Additionally, some global services (IAM, STS, CloudFront) log events to us-east-1 by default — you must enable "Include global service events" to capture them. CloudTrail captures all API call methods: console, CLI, SDK, and direct HTTP.

  36. Q36D6 · Security, Identity and ComplianceSelect one

    You need to encrypt an 8 GB file before storing it in S3 using AWS KMS. The KMS API rejects the request because KMS cannot directly encrypt data larger than 4 KB. What is the correct approach?

    • A. Split the file into 4 KB chunks, encrypt each chunk with KMS separately, and reassemble after upload
    • B. Use envelope encryption: generate a data key via KMS, encrypt the file locally with the data key, upload the encrypted file and the encrypted data key to S3
    • C. Upgrade to KMS Custom Key Store which supports files up to 100 GB
    • D. Use SSE-S3 instead — it has no size limit and uses stronger AES-256 encryption
    Show answer

    Answer: B.

    Envelope encryption is how KMS handles large data: you call KMS GenerateDataKey to get a plaintext data key and an encrypted copy of that key. You use the plaintext key to encrypt the large file locally (with AES-256), then discard the plaintext key. You store the encrypted file alongside the encrypted data key in S3. To decrypt, you call KMS Decrypt on the encrypted data key to recover the plaintext key, then decrypt the file locally. KMS itself only ever handles the small data key — never the large payload. This is the pattern used by all AWS services that integrate with KMS.

  37. Q37D5 · Serverless and Application IntegrationSelect one

    An SQS message is received by Consumer A, which starts processing it. Before Consumer A finishes and deletes the message, the visibility timeout expires. What happens?

    • A. The message is permanently deleted from the queue since it was already delivered once
    • B. The message becomes visible again in the queue and can be received and processed by Consumer A or another consumer
    • C. The message is moved to a Dead Letter Queue after the visibility timeout expires
    • D. The queue pauses delivery of all messages until Consumer A explicitly extends the visibility timeout
    Show answer

    Answer: B.

    The visibility timeout is the period during which SQS hides a received message from other consumers, giving the consumer time to process and delete it. If the consumer does not delete the message within this window, SQS assumes the processing failed and makes the message visible again — enabling retry by the same or a different consumer. This is SQS's at-least-once delivery guarantee. Messages only go to the Dead Letter Queue after exceeding the maxReceiveCount (maximum number of receive attempts). To prevent premature re-visibility on long jobs, consumers should extend the timeout using ChangeMessageVisibility.

  38. Q38D3 · Networking and Content DeliverySelect one

    Your CloudFront distribution serves a JavaScript file (app.js) that was recently updated. Users are still receiving the old cached version. What is the fastest way to force CloudFront to serve the new file?

    • A. Wait for the TTL to expire — CloudFront will automatically fetch the new version from the origin
    • B. Create a CloudFront cache invalidation for the path /app.js to immediately purge the cached copy from all edge locations
    • C. Delete and recreate the CloudFront distribution — this clears all caches instantly
    • D. Change the S3 bucket region — CloudFront will detect the origin change and refetch all files
    Show answer

    Answer: B.

    Cache invalidation tells CloudFront to immediately purge the specified path from all edge location caches, forcing the next request for that file to fetch a fresh copy from the origin. Invalidations are charged per path (with a free tier of 1,000 paths per month). Waiting for TTL expiry is free but slow. For static assets with versioning, a better long-term pattern is to use version-stamped filenames (app.v2.js) — the new filename bypasses cache entirely without needing invalidations, while the old file expires naturally. Recreating the distribution causes significant downtime and DNS propagation delay.

  39. Q39D1 · Compute and ContainersSelect one

    A data engineering team runs large-scale, fault-tolerant batch jobs on EC2 that can be interrupted and resumed from a checkpoint. Which purchasing model dramatically reduces cost while accepting the risk of interruption?

    • A. Reserved Instances — 3-year commitment provides the maximum discount for batch workloads
    • B. Dedicated Hosts — physical isolation ensures batch jobs are never interrupted by other tenants
    • C. Spot Instances — bid on unused EC2 capacity at up to 90% discount; AWS can reclaim with 2-minute warning
    • D. On-Demand with Auto Scaling — scale down when not needed to minimize hourly charges
    Show answer

    Answer: C.

    Spot Instances offer up to 90% discount compared to On-Demand by utilizing AWS's spare EC2 capacity. The tradeoff is interruptibility: AWS can reclaim Spot capacity with a 2-minute warning. Fault-tolerant batch workloads that checkpoint progress are ideal Spot candidates — if interrupted, the job resumes from the last checkpoint on a new Spot instance. Spot is not suitable for stateful workloads, databases, or anything that cannot tolerate interruption. Reserved Instances offer ~75% discount but require a 1–3 year commitment and are suited for steady-state workloads, not variable batch jobs.

  40. Q40D7 · Monitoring, Operations and DeploymentSelect one

    A security audit requires that all administrative SSH access to EC2 instances be logged, audited, and require no open inbound ports on Security Groups. Which AWS feature replaces traditional bastion host SSH access?

    • A. EC2 Instance Connect — provides browser-based SSH that still requires port 22 open in the Security Group
    • B. AWS Systems Manager Session Manager — provides browser and CLI shell access with no inbound ports, full session logging to CloudWatch and S3
    • C. AWS Direct Connect — provides a dedicated private connection that bypasses Security Group rules
    • D. VPC Flow Logs — captures SSH traffic for auditing without requiring port 22 to be open
    Show answer

    Answer: B.

    AWS Systems Manager Session Manager establishes shell sessions over the SSM API (outbound HTTPS from the instance to SSM endpoints) — no inbound port 22 or 3389 required. Sessions are fully logged to CloudWatch Logs and S3 with IAM-controlled access, satisfying compliance requirements for session auditing. Access is controlled via IAM policies, supporting MFA enforcement and just-in-time access patterns. EC2 Instance Connect still requires port 22 in the Security Group. Direct Connect is a network connectivity service. Flow Logs are observability, not access control.

  41. Q41D4 · DatabasesSelect one

    Your primary RDS database is in us-east-1. Compliance requires a full copy of the database to be available in eu-west-1 for disaster recovery, with a recovery time objective (RTO) of under 30 minutes. Which feature meets this requirement?

    • A. RDS Multi-AZ deployment with both AZs in us-east-1 — provides sub-2-minute automatic failover
    • B. An RDS Read Replica in eu-west-1 — can be promoted to a standalone database in under 30 minutes if the primary region fails
    • C. Daily automated RDS backups with cross-region copy enabled — restore in eu-west-1 within the 30-minute window
    • D. RDS snapshot shared with the eu-west-1 account — restore manually when disaster occurs
    Show answer

    Answer: B.

    RDS Cross-Region Read Replicas asynchronously replicate data to another region and can be promoted to a standalone primary database within minutes — well within a 30-minute RTO. Multi-AZ only operates within a single region and does not protect against regional failures. Daily automated backup restoration typically takes 30–60+ minutes for large databases, depending on size and IOPS — unreliable for a 30-minute RTO. Manual snapshot restoration is even slower and requires human intervention. Cross-region Read Replicas are the standard pattern for cross-region DR with aggressive RTOs.

  42. Q42D5 · Serverless and Application IntegrationSelect one

    You publish a single event to an SNS topic. You need that event to simultaneously trigger a Lambda function, send an email notification, and queue the event for batch processing in SQS. How does SNS handle this?

    • A. SNS delivers the event to only one subscriber — you must chain three separate SNS topics
    • B. SNS fan-out: it delivers the message to all subscribed endpoints simultaneously — Lambda, email (SES), and SQS all receive the same message in parallel
    • C. SNS delivers the message sequentially to each subscriber — Lambda runs first, then email, then SQS
    • D. SNS requires a separate topic per subscriber type — one for Lambda, one for email, one for SQS
    Show answer

    Answer: B.

    SNS is a pub/sub fan-out service: one message published to a topic is simultaneously delivered to all subscriptions in parallel. A single SNS publish triggers the Lambda invocation, the email delivery, and the SQS message enqueue — all at the same time, without any ordering dependency. This fan-out pattern is fundamental to event-driven AWS architectures: decouple producers from consumers, and add new consumers without touching the producer. SNS supports subscriptions to Lambda, SQS, HTTP/HTTPS endpoints, email, SMS, and mobile push — all on the same topic simultaneously.

  43. Q43D3 · Networking and Content DeliverySelect one

    Your web application needs a load balancer that routes requests based on URL path (/api/* → API service, /static/* → S3 origin) and also performs TLS termination. Which AWS load balancer type is correct?

    • A. Network Load Balancer (NLB) — it provides the best performance for HTTPS traffic with TLS offloading
    • B. Classic Load Balancer — it supports both HTTP/HTTPS and can be configured with path-based rules
    • C. Application Load Balancer (ALB) — it operates at Layer 7 and natively supports path-based routing rules and TLS termination
    • D. Gateway Load Balancer — it is designed for high-performance routing across multiple origins
    Show answer

    Answer: C.

    ALB operates at Layer 7 (HTTP/HTTPS) and makes routing decisions based on the content of the request — URL path, hostname, HTTP headers, query parameters, or source IP. Path-based routing rules (/api/* → Target Group A, /static/* → Target Group B) are a native ALB feature. ALB also terminates TLS (SSL certificates managed via ACM) and forwards decrypted HTTP to backends. NLB operates at Layer 4 (TCP/UDP) — it does not inspect HTTP content or support path-based routing. The Classic Load Balancer is legacy. Gateway Load Balancer is for deploying third-party network appliances.

  44. Q44D7 · Monitoring, Operations and DeploymentSelect one

    A developer wants to measure the number of failed login attempts in their application and alarm when it exceeds 100 in 5 minutes. CloudWatch does not have a default metric for this. What is the correct approach?

    • A. Enable detailed monitoring on the EC2 instance — it exposes application-level metrics at 1-minute granularity
    • B. Use CloudTrail to count IAM authentication failures — it automatically publishes this metric to CloudWatch
    • C. Publish a custom metric to CloudWatch using the PutMetricData API from within the application, then create an alarm on that metric
    • D. Deploy a CloudWatch agent on the EC2 instance — it automatically discovers application failure counts
    Show answer

    Answer: C.

    CloudWatch custom metrics allow any application or service to publish business or application-level metrics via the PutMetricData API. The application code increments a counter on each failed login and periodically calls PutMetricData with the count. You then create a CloudWatch Alarm on this custom metric with a threshold of 100 within a 5-minute period, triggering an SNS notification. The CloudWatch Agent can collect OS-level metrics (RAM, disk) and log data, but it does not understand application business logic. Detailed monitoring only increases the frequency of existing AWS service metrics — it does not add new application-level metrics.

  45. Q45D4 · DatabasesSelect one

    A read-heavy DynamoDB table serves thousands of requests per second. Many requests read the same 50 popular items repeatedly, consuming significant RCUs. Which solution reduces read costs and latency for these popular items?

    • A. Create a Global Secondary Index on the popular items' attributes — GSI reads are free of charge
    • B. Enable DynamoDB Streams — streaming the changes reduces repeated read requests
    • C. Place DynamoDB Accelerator (DAX) in front of the table — it caches item-level reads in memory with microsecond latency, absorbing repeated reads without consuming RCUs
    • D. Switch to DynamoDB On-Demand capacity mode — it automatically reduces cost for repeated reads
    Show answer

    Answer: C.

    DynamoDB Accelerator (DAX) is a fully managed, in-memory cache specifically built for DynamoDB. It intercepts GetItem and Query calls, returning cached results in microseconds without consuming RCUs on the underlying table. For hot items read repeatedly (product catalog, leaderboards, reference data), DAX dramatically reduces both cost (no RCU consumption for cache hits) and latency (milliseconds → microseconds). DAX is API-compatible with DynamoDB — application code only needs to point to the DAX cluster endpoint instead of the DynamoDB endpoint. GSIs require their own RCU capacity and do not cache.

  46. Q46D2 · Storage and Data ManagementSelect one

    A user needs temporary, time-limited access to download a specific private object from an S3 bucket without having AWS credentials. What is the simplest secure solution?

    • A. Make the S3 bucket public temporarily, share the URL, then make it private again
    • B. Create an IAM user with S3 read permissions and share the access keys
    • C. Generate an S3 Pre-signed URL with a short expiration time — it embeds temporary credentials in the URL itself
    • D. Use CloudFront with a signed cookie that allows access to the specific object
    Show answer

    Answer: C.

    S3 Pre-signed URLs grant temporary, scoped access to a specific object without requiring the requester to have AWS credentials. The URL is generated by a principal with s3:GetObject permission and includes an embedded cryptographic signature along with an expiration timestamp (seconds to 7 days). Anyone with the URL can access the object until expiration — after which the URL becomes invalid. This is ideal for short-lived file sharing, download links in applications, and granting partners temporary access to specific files. Making the bucket public is a security risk. Sharing IAM user credentials grants permanent, account-level access.

  47. Q47D3 · Networking and Content DeliverySelect one

    You want to add custom HTTP response headers (e.g., Content-Security-Policy, X-Frame-Options) to every response served by your CloudFront distribution, without modifying your origin server. Which feature achieves this?

    • A. CloudFront Origin Shield — it adds headers to requests forwarded to the origin
    • B. CloudFront Response Headers Policy — it adds or modifies HTTP headers in CloudFront's responses to viewers
    • C. AWS WAF rules attached to the CloudFront distribution — they can inject security headers
    • D. S3 bucket metadata — headers defined in S3 object metadata are automatically forwarded by CloudFront
    Show answer

    Answer: B.

    CloudFront Response Headers Policies define headers that CloudFront adds to responses it sends to viewers — completely independently of what the origin returns. You configure a policy with security headers (Content-Security-Policy, X-Frame-Options, Strict-Transport-Security, X-XSS-Protection) and attach it to a cache behavior. CloudFront injects these headers into every response before it reaches the viewer. This avoids modifying origin servers, applies consistently to all content including cached responses, and is managed centrally via the CloudFront configuration. Lambda@Edge could also achieve this but Response Headers Policies are purpose-built and require no code.

  48. Q48D6 · Security, Identity and ComplianceSelect one

    What is the key operational difference between AWS Secrets Manager and SSM Parameter Store SecureString for storing database credentials?

    • A. Parameter Store uses stronger encryption than Secrets Manager — it uses AES-512 vs AES-256
    • B. Secrets Manager supports automatic secret rotation with built-in Lambda integrations for RDS, Redshift, and DocumentDB; Parameter Store does not support automatic rotation
    • C. Parameter Store integrates with more AWS services; Secrets Manager only works with RDS
    • D. Secrets Manager is free; Parameter Store charges per API call for SecureString parameters
    Show answer

    Answer: B.

    The critical differentiator is automatic rotation. Secrets Manager has built-in rotation support with pre-built Lambda functions for RDS (MySQL, PostgreSQL, Oracle, SQL Server), Redshift, and DocumentDB — it rotates credentials on a schedule, updates the secret, and simultaneously updates the database password with no application downtime. SSM Parameter Store SecureString requires you to implement rotation manually. Secrets Manager is the correct choice whenever automatic rotation is a requirement. Parameter Store (standard parameters) is free and suitable for configuration values and manually rotated secrets; Secrets Manager has a per-secret monthly fee.

  49. Q49D1 · Compute and ContainersSelect one

    You are launching a high-performance computing (HPC) cluster where all EC2 instances must communicate with each other at the lowest possible network latency and highest throughput. Which EC2 placement strategy achieves this?

    • A. Spread Placement Group — distributes instances across distinct underlying hardware for maximum fault tolerance
    • B. Partition Placement Group — divides instances into logical partitions that do not share hardware
    • C. Cluster Placement Group — packs instances into a single AZ on the same underlying hardware rack for ultra-low network latency
    • D. No placement group — EC2 automatically co-locates instances that communicate frequently
    Show answer

    Answer: C.

    A Cluster Placement Group packs instances physically close together within a single AZ — typically on the same network switch rack. This delivers the lowest network latency (sub-10ms, single-digit microseconds with Elastic Fabric Adapter) and highest aggregate network bandwidth (up to 100 Gbps). It is specifically designed for tightly-coupled, latency-sensitive workloads like HPC simulations, distributed machine learning training, and financial modeling. The tradeoff is reduced fault tolerance — all instances share the same physical infrastructure. Spread groups prioritize fault tolerance by separating instances; Partition groups are designed for large distributed databases like HDFS or Cassandra.

  50. Q50D8 · Cost Management and Multi-Account GovernanceSelect one

    AWS Trusted Advisor flags one of your EC2 instances as "underutilized" with average CPU below 5% over the last 14 days. What should your team do?

    • A. Ignore it — low CPU is a sign of good headroom and spare capacity for traffic spikes
    • B. Immediately terminate the instance — Trusted Advisor recommendations should always be followed immediately
    • C. Investigate whether the instance is still needed; if so, consider downsizing to a smaller instance type or using Auto Scaling to reduce capacity during off-peak hours
    • D. Move the instance to a Reserved Instance purchasing model — it is more cost-efficient for consistently low utilization
    Show answer

    Answer: C.

    Trusted Advisor's underutilized instance check identifies cost optimization opportunities, but the correct response is investigation, not immediate action. The instance may be underutilized because it handles unpredictable spikes (low average doesn't mean low peak), it's a standby/failover instance, or it genuinely is waste. If truly unused, terminate it. If legitimately needed but oversized, downsize it (EC2 supports instance type changes on stopped instances). Auto Scaling can eliminate the need for always-on instances for variable workloads. Buying a Reserved Instance for a chronically underutilized instance commits you to paying for waste for 1–3 years.

  51. Q51D5 · Serverless and Application IntegrationSelect one

    An SQS consumer receives a message, starts processing it, but crashes before deleting it. The message keeps reappearing and failing. After how many failures should the message stop blocking healthy processing, and where should it go?

    • A. After 1 failure — the message is automatically deleted to prevent queue poisoning
    • B. After the maxReceiveCount threshold — the message is moved to a Dead Letter Queue (DLQ) for isolated inspection and debugging
    • C. After 24 hours — SQS automatically expires the message based on its retention period
    • D. Messages never move automatically — an operator must manually delete poison messages
    Show answer

    Answer: B.

    A Dead Letter Queue (DLQ) is a separate SQS queue that receives messages that have exceeded the maxReceiveCount — the configured maximum number of failed delivery attempts. This separates "poison pill" messages (messages that consistently cause consumer crashes) from the healthy flow of new messages, so they do not block processing indefinitely. The DLQ allows developers to inspect, replay, or discard failed messages independently. Without a DLQ, a poison message would cycle forever, consuming consumer capacity.

  52. Q52D5 · Serverless and Application IntegrationSelect one

    Multiple Lambda functions across your account share the same 200 MB set of Python dependencies. Packaging these dependencies with every function wastes storage and slows deployments. What is the correct solution?

    • A. Store the dependencies in an S3 bucket and download them at Lambda cold start using the INIT phase
    • B. Create a Lambda Layer containing the shared dependencies and attach it to all functions that need them
    • C. Build a Docker container image that includes all functions and their shared dependencies in a single image
    • D. Increase the Lambda function memory to 10 GB so the runtime can load large dependency packages faster
    Show answer

    Answer: B.

    Lambda Layers are versioned archives (ZIP files) of shared code, libraries, or data that you attach to one or more Lambda functions. The layer content is extracted to /opt in the function's execution environment and is immediately accessible at runtime — no download required. A single layer can be shared across dozens of functions, reducing total deployment package size, enabling centralized dependency version management, and speeding up function deployments. Functions can use up to 5 layers simultaneously. Layers are ideal for shared runtimes, ML model files, and common utility libraries.

  53. Q53D4 · DatabasesSelect one

    You need to query a DynamoDB table by an attribute that is not the primary key. You want the queries to return items sorted by a timestamp. Which index type is most appropriate, and what is its key constraint?

    • A. Global Secondary Index (GSI) — can be created on any attribute and can be added after table creation, with its own read/write capacity
    • B. Local Secondary Index (LSI) — can be defined on any attribute, can be added after table creation, and shares the table's provisioned capacity
    • C. Local Secondary Index (LSI) — must use the same partition key as the table but can use a different sort key, and must be created at table creation time
    • D. Global Secondary Index (GSI) — must use the same partition key as the table and requires the sort key to be a timestamp attribute
    Show answer

    Answer: C.

    LSIs and GSIs both enable querying on non-primary-key attributes but have important differences. An LSI must share the table's partition key and allows a different sort key — it is scoped to a single partition and supports strongly consistent reads. Critically, LSIs can only be created when the table is created; you cannot add them later. A GSI can use any attribute as its partition key and sort key, can be created after table creation, and has its own separate throughput capacity. For sorting by timestamp within a specific user's data (same partition key, different sort key), an LSI is the right choice and must be defined upfront.

  54. Q54D6 · Security, Identity and ComplianceSelect one

    A security audit finds that EC2 instances can retrieve IAM role credentials from the instance metadata endpoint without any authentication, creating a risk if an attacker gains code execution on the instance. What AWS feature mitigates this?

    • A. Disable the instance metadata service entirely — applications should use IAM user access keys instead
    • B. Enforce IMDSv2 (Instance Metadata Service v2) — requires a session-oriented token obtained via a PUT request before metadata can be accessed
    • C. Place the EC2 instance in a private subnet — instances without public IPs cannot access the metadata endpoint
    • D. Enable VPC Flow Logs — this logs all metadata requests and alerts on unauthorized access attempts
    Show answer

    Answer: B.

    IMDSv2 adds a session-oriented token requirement to the metadata endpoint (169.254.169.254). The caller must first make a PUT request to get a time-limited token, then include that token in subsequent GET requests. This defends against Server-Side Request Forgery (SSRF) attacks — a common web application vulnerability where an attacker tricks the server into making requests on their behalf, including to the metadata endpoint to steal IAM credentials. IMDSv1 (no token required) should be disabled on all instances. IMDSv2 can be enforced at the instance level, the AMI level, or account-wide via an IAM condition key.

  55. Q55D2 · Storage and Data ManagementSelect one

    A financial services company must ensure that audit log files stored in S3 cannot be deleted or modified for 7 years, even by account administrators, to meet regulatory compliance requirements. Which S3 feature enforces this?

    • A. S3 Versioning with MFA Delete — requires MFA authentication to permanently delete any object version
    • B. S3 Object Lock with Compliance mode and a 7-year retention period — prevents any user, including root, from deleting or overwriting objects before the retention period expires
    • C. S3 bucket policies with an explicit Deny on s3:DeleteObject for all principals
    • D. S3 Cross-Region Replication — replicates every object to a second bucket, ensuring a backup always exists
    Show answer

    Answer: B.

    S3 Object Lock in Compliance mode enforces a Write Once Read Many (WORM) model. Once an object is locked with a retention period, no user — including the AWS root account — can delete or overwrite it before the period expires, and the retention period itself cannot be shortened. This is specifically designed for regulatory compliance scenarios (SEC Rule 17a-4, FINRA, CFTC). Governance mode is less strict — privileged users with special IAM permissions can still override it. MFA Delete and bucket policies can be bypassed by the root account or through policy changes; Compliance mode Object Lock cannot.

  56. Q56D1 · Compute and ContainersSelect one

    Your ECS tasks need to communicate directly with other services using their own private IP addresses and Security Group rules, rather than sharing the host EC2 instance's network interface. Which ECS networking mode enables this?

    • A. bridge — creates a virtual bridge network so each container gets its own internal IP
    • B. host — shares the EC2 host's network namespace so the task uses the host IP directly
    • C. awsvpc — assigns each task its own Elastic Network Interface (ENI) and private IP address from the VPC subnet
    • D. overlay — uses Docker Swarm's overlay networking to span multiple hosts
    Show answer

    Answer: C.

    The awsvpc network mode assigns each ECS task its own ENI, private IP address, and Security Group — treating each task like a first-class VPC resource. This enables precise per-task Security Group rules (rather than sharing the host EC2 instance's Security Group across all containers), VPC Flow Log visibility at the task level, and direct integration with Application Load Balancers by IP address. awsvpc is required for Fargate tasks, which have no underlying EC2 host. The bridge mode uses Docker's internal bridge and requires dynamic port mapping, making Security Group rules harder to manage.

  57. Q57D3 · Networking and Content DeliverySelect one

    You want to route 10% of production traffic to a new application version for canary testing, while 90% continues going to the stable version. Both versions are deployed as separate target groups behind Route 53. Which routing policy achieves this?

    • A. Failover routing — primary target receives all traffic; secondary receives traffic only on health check failure
    • B. Latency-based routing — Route 53 automatically shifts traffic toward the version with lower response time
    • C. Weighted routing — assign weight 90 to the stable version and weight 10 to the new version, giving proportional traffic distribution
    • D. Geolocation routing — route 10% of geographic regions to the new version and the rest to the stable version
    Show answer

    Answer: C.

    Route 53 Weighted routing lets you control what percentage of DNS responses point to each record by assigning integer weights. A weight of 90 vs 10 means the stable version receives 90/(90+10) = 90% of traffic and the new version receives 10%. This is the standard pattern for blue/green gradual cutover and canary releases at the DNS layer. Weights can be updated in real time without deployment — increasing the new version's weight gradually as confidence grows. Failover routing is binary (primary or secondary). Latency-based routing picks based on network performance, not an intentional traffic split.

  58. Q58D5 · Serverless and Application IntegrationSelect one

    A developer needs to deploy Lambda functions with the same custom runtime across 20 different functions. The runtime is 150 MB. Packaging it with every function wastes storage and causes slow deployments. After creating a Lambda Layer, what limits apply?

    • A. A function can use only 1 layer; the layer must be in the same AWS account as the function
    • B. A function can use up to 5 layers simultaneously; total unzipped size of all layers plus the function code cannot exceed 250 MB
    • C. Layers are limited to 10 MB — for larger shared libraries, use an EFS file system mounted to the Lambda function
    • D. A layer can only be shared within the same AWS Region; cross-region layer sharing requires manual replication
    Show answer

    Answer: B.

    Lambda functions can attach up to 5 layers simultaneously, and the total unzipped size of the deployment package (function code + all layers) is limited to 250 MB. Each individual layer can be up to 250 MB unzipped. Layers can be shared across accounts (you can make a layer public or share it with specific account IDs) and across functions in the same region. For very large models or datasets (>250 MB), EFS is indeed the solution — but for standard libraries and runtimes under 250 MB, layers are the right tool. Layers are versioned and immutable once published.

  59. Q59D3 · Networking and Content DeliverySelect one

    Your application's VPC Flow Logs show that traffic from a specific source IP is reaching the EC2 instance (ACCEPT for inbound) but the application is still not responding to those connections. Where should you investigate next?

    • A. The Network ACL — if flow logs show ACCEPT, the NACL is allowing it, so the problem must be there
    • B. The Security Group — flow logs record ACCEPT/REJECT at the ENI level before Security Groups are evaluated
    • C. The application or OS level — the traffic is reaching the instance's network interface, so the network path is clear; the issue is likely within the OS (firewall, wrong port) or the application itself
    • D. The route table — ACCEPT in flow logs means the packet arrived at the EC2 host but the route table may be dropping it before delivery
    Show answer

    Answer: C.

    VPC Flow Logs capture traffic at the ENI level. An ACCEPT entry means the traffic passed both NACL and Security Group checks and arrived at the instance's network interface. If the connection is still failing, the problem is inside the operating system: the application may not be listening on the port, the OS firewall (iptables/Windows Firewall) may be blocking it, the application may have crashed, or it may be listening on localhost (127.0.0.1) rather than all interfaces (0.0.0.0). REJECT in flow logs would indicate a network-level block; ACCEPT means the network delivered the packet successfully.

  60. Q60D6 · Security, Identity and ComplianceSelect one

    A junior developer in your team has been granted IAM permissions to create and manage IAM roles and policies. You want to ensure they cannot create roles with more permissions than they themselves have — preventing privilege escalation. What mechanism achieves this?

    • A. Require MFA for all IAM operations — this adds a confirmation step before any privilege escalation
    • B. Use IAM Permission Boundaries — attach a boundary to any role the developer creates, limiting the effective permissions to the intersection of the boundary and the role's identity policy
    • C. Create an SCP in AWS Organizations that limits IAM actions — this applies to the entire account
    • D. Enable IAM Access Analyzer — it automatically detects and removes overly permissive roles
    Show answer

    Answer: B.

    IAM Permission Boundaries are an advanced feature that sets the maximum permissions a role or user can have, regardless of what identity policies allow. When a developer creates a new role, you require (via an IAM condition) that the new role has a specific permission boundary attached. The role's effective permissions become the intersection of its identity policies AND the boundary — meaning even if the developer accidentally or maliciously grants AdministratorAccess in the role's policy, the boundary caps the actual permissions. This prevents privilege escalation without restricting what identity policies the developer can write.

  61. Q61D2 · Storage and Data ManagementSelect one

    You are uploading a 50 GB file to S3 using the standard PutObject API call. The upload fails after 45 minutes at 80% completion due to a network interruption. You must restart from scratch. Which S3 feature eliminates this problem for large files?

    • A. S3 Transfer Acceleration — routes uploads through CloudFront edge locations for more resilient connections
    • B. S3 Versioning — keeps previous upload attempts so the next upload can resume from the last version
    • C. S3 Multipart Upload — splits the file into parts (up to 10,000) that are uploaded independently; only failed parts need to be retried
    • D. S3 Replication — automatically retries failed uploads by replicating from a temporary staging bucket
    Show answer

    Answer: C.

    Multipart Upload breaks large objects into up to 10,000 individual parts that are uploaded independently and in parallel. If a part fails, only that specific part needs to be retried — not the entire file. Parts can be uploaded in parallel across multiple connections, significantly improving throughput. Once all parts are successfully uploaded, a CompleteMultipartUpload call assembles them into the final S3 object. Multipart Upload is recommended for files over 100 MB and required for files over 5 GB (the single PutObject limit). Abort Incomplete Multipart Upload lifecycle rules clean up abandoned in-progress uploads to avoid paying for partial part storage.

  62. Q62D8 · Cost Management and Multi-Account GovernanceSelect one

    Your organization has 40 AWS accounts. You need to deploy a new IAM role with read-only S3 access across all accounts simultaneously to implement a centralized auditing solution. Manually deploying to each account would take hours. What is the most efficient approach?

    • A. Write a shell script that iterates over all accounts using the AWS CLI and creates the role in each one sequentially
    • B. Use CloudFormation StackSets — deploy a single CloudFormation template across all accounts and regions from the management account
    • C. Share an IAM role from the management account with all member accounts using cross-account role assumption
    • D. Use AWS Config Aggregator — it can push IAM role configurations to all accounts from a central account
    Show answer

    Answer: B.

    CloudFormation StackSets extend CloudFormation to deploy stacks across multiple AWS accounts and regions simultaneously from a single management or delegated administrator account. You define the template once (the IAM role definition) and specify the target accounts or Organizational Units. StackSets handles creating, updating, and deleting stack instances across all targets. With AWS Organizations integration, you can automatically deploy to new accounts as they are created. A shell script would work but is slow, error-prone, and hard to update consistently. Config Aggregator is for collecting compliance data, not deploying resources.

  63. Q63D2 · Storage and Data ManagementSelect one

    Users in Asia-Pacific are complaining of slow S3 upload speeds when uploading large files to your us-east-1 bucket. The files are user-generated content that must be stored in us-east-1. Which S3 feature improves upload performance for geographically distant users?

    • A. S3 Cross-Region Replication — create a replica bucket in ap-southeast-1 and replicate objects back to us-east-1
    • B. S3 Transfer Acceleration — routes uploads through the nearest CloudFront edge location and over AWS's optimized backbone network to the destination bucket
    • C. CloudFront with S3 as origin — caches the files at edge locations closer to users
    • D. S3 Intelligent-Tiering — reduces latency by pre-positioning frequently accessed objects in lower-latency storage
    Show answer

    Answer: B.

    S3 Transfer Acceleration uses CloudFront's globally distributed edge locations as upload entry points. Instead of a user in Tokyo uploading directly to a bucket in us-east-1 over the public internet (traversing many unpredictable network hops), the upload goes to the nearest CloudFront edge in Tokyo and then travels over AWS's optimized private backbone network to us-east-1 — consistently faster and more reliable. Transfer Acceleration is enabled per bucket and uses a distinct endpoint (bucket.s3-accelerate.amazonaws.com). It charges extra per GB transferred. CloudFront is for content delivery (downloads), not accelerating uploads to a specific region.

  64. Q64D3 · Networking and Content DeliverySelect one

    An organization already has a 10 Gbps AWS Direct Connect connection to us-east-1. They want to connect their on-premises network to another 3 AWS regions without ordering additional physical connections. What is the most cost-effective solution?

    • A. Order separate Direct Connect connections to each of the 3 additional regions — each region requires its own physical connection
    • B. Use a Transit Gateway in each region connected via VPN tunnels over the public internet
    • C. Use Direct Connect Gateway — attach the single Direct Connect connection to a Direct Connect Gateway and connect it to Virtual Private Gateways or Transit Gateways in all 4 regions
    • D. Use VPC Peering between the us-east-1 VPC (connected to Direct Connect) and VPCs in the other 3 regions
    Show answer

    Answer: C.

    AWS Direct Connect Gateway is a globally available resource that allows a single Direct Connect connection to access VPCs in any AWS region (except China). You attach the Direct Connect connection to the Direct Connect Gateway, then associate it with Virtual Private Gateways or Transit Gateways in multiple regions. Traffic between on-premises and any connected region flows over the Direct Connect connection and AWS's backbone — without additional physical connections or per-region Direct Connect fees. VPC Peering only works between VPCs and does not extend Direct Connect connectivity. A VPN over the internet would be slower and less reliable than the existing Direct Connect.

  65. Q65D4 · DatabasesSelect one

    Your Aurora database handles a predictable daily traffic pattern: low reads overnight, peak reads during business hours. You want Aurora to automatically scale the number of read replicas based on load, without manual intervention or pre-provisioned idle capacity. Which feature enables this?

    • A. Aurora Multi-AZ — it automatically adds read replicas during high-load periods and removes them at night
    • B. Aurora Auto Scaling — monitors a CloudWatch metric (like average CPU or connections per instance) and automatically adds or removes Aurora Replicas within configured min/max bounds
    • C. RDS Read Replica promotion — manually promote read replicas during peak hours and demote them overnight
    • D. Aurora Serverless v2 — it scales the database engine capacity continuously, eliminating the need for read replicas entirely
    Show answer

    Answer: B.

    Aurora Auto Scaling automatically adjusts the number of Aurora Replica instances (read replicas) based on CloudWatch metrics — typically AverageCPUUtilization or DatabaseConnections. You define a scaling policy with minimum and maximum replica counts and a target metric value. Aurora adds replicas when load increases and removes them when load drops, with the Aurora endpoint automatically routing read traffic across all healthy replicas. Aurora Serverless v2 scales compute capacity within a single instance but uses a different architecture — for read-heavy workloads that benefit from horizontal read scaling, Aurora Replicas with Auto Scaling is the standard pattern.

  66. Q66D3 · Networking and Content DeliverySelect one

    You need to add custom authentication logic to a CloudFront distribution — checking a proprietary token in the request header before allowing access to content. The logic must run as close to the viewer as possible. Which service is purpose-built for this?

    • A. API Gateway Lambda authorizer — create a Lambda function that validates the token and attach it to the API Gateway in front of CloudFront
    • B. Lambda@Edge — deploy a Lambda function that runs at CloudFront edge locations in response to viewer requests, before the request reaches the origin
    • C. AWS WAF — create a custom WAF rule that validates the token header using a regex match condition
    • D. CloudFront signed URLs — replace the proprietary token system with CloudFront's built-in URL signing mechanism
    Show answer

    Answer: B.

    Lambda@Edge deploys Lambda functions to CloudFront edge locations worldwide and executes them in response to four CloudFront event types: viewer request (before cache check), origin request (cache miss, going to origin), origin response (response from origin), and viewer response (before returning to viewer). For custom authentication, a Viewer Request trigger intercepts every incoming request at the edge, validates the token, and either forwards the request or returns a 403 — without any latency from a round-trip to the origin. Lambda@Edge functions must be deployed to us-east-1 (they are globally replicated by CloudFront). WAF can match patterns but cannot execute arbitrary business logic for token validation.

  67. Q67D7 · Monitoring, Operations and DeploymentSelect one

    Your application logs are stored in CloudWatch Logs. You need to find all ERROR log entries that appeared within the last hour, count them by error code, and identify the top 5 most frequent errors — all without exporting logs to another service. Which tool handles this interactively?

    • A. CloudWatch Metrics — create a metric filter on the log group to count ERROR occurrences
    • B. CloudWatch Logs Insights — run an interactive SQL-like query directly against the log group to filter, aggregate, and visualize results
    • C. AWS Athena — query the CloudWatch Logs data using standard SQL from the Athena console
    • D. CloudWatch Contributor Insights — automatically identifies the top contributors to log volume
    Show answer

    Answer: B.

    CloudWatch Logs Insights is an interactive log analytics service built into CloudWatch. It uses a purpose-built query language to filter (filter @message like /ERROR/), extract fields, compute statistics (stats count(*) by errorCode), sort results, and visualize time-series distributions — all directly against your CloudWatch Log Groups with no data export required. Queries complete in seconds to minutes depending on data volume. Metric Filters are great for ongoing alerting but are not interactive. Athena queries S3, not CloudWatch Logs directly (though you can export logs to S3 first). Contributor Insights is for identifying top traffic sources, not ad-hoc log analysis.

  68. Q68D2 · Storage and Data ManagementSelect one

    Multiple EC2 instances in different Availability Zones need to share access to the same file system simultaneously — reading and writing the same files concurrently. Which AWS storage service is designed for this use case?

    • A. EBS — attach the same EBS volume to all instances that need shared access
    • B. S3 — mount the S3 bucket as a file system on all instances using an S3 FUSE driver
    • C. Amazon EFS (Elastic File System) — a fully managed NFS file system that can be mounted concurrently on thousands of EC2 instances across multiple AZs
    • D. DynamoDB — store file metadata and content as items for concurrent access across instances
    Show answer

    Answer: C.

    Amazon EFS is a managed NFS (Network File System) that provides shared file storage accessible simultaneously from multiple EC2 instances, ECS tasks, Lambda functions, and on-premises servers. Unlike EBS volumes (which can only be attached to one EC2 instance at a time, with the exception of EBS Multi-Attach for io2 volumes with strict limitations), EFS is designed for concurrent multi-instance access with POSIX-compliant file semantics. EFS automatically scales from gigabytes to petabytes and replicates data across multiple AZs for durability. It is the standard choice for shared file storage in microservices, CMS platforms, and HPC workloads.

  69. Q69D8 · Cost Management and Multi-Account GovernanceSelect one

    AWS Compute Savings Plans offer a more flexible discount mechanism than Standard Reserved Instances. What is the key flexibility advantage, and what commitment do they require?

    • A. Savings Plans require no commitment — you pay per hour only when you use compute resources
    • B. Savings Plans require a commitment to a minimum $/hour spend for 1 or 3 years, but the discount applies to any EC2 instance type, size, OS, region, and also Lambda and Fargate — unlike Standard RIs which are locked to a specific configuration
    • C. Savings Plans provide a higher discount than Standard Reserved Instances for the same configuration
    • D. Savings Plans are identical to Convertible Reserved Instances — both allow changing instance type while maintaining a discount
    Show answer

    Answer: B.

    Compute Savings Plans commit you to a minimum hourly spend (e.g., $10/hour) for 1 or 3 years. In exchange, you receive a discount (up to 66%) that applies to any EC2 compute usage regardless of instance family, size, OS, tenancy, or region — and also to AWS Lambda and AWS Fargate. Standard Reserved Instances are locked to a specific instance type, OS, and AZ or region. Convertible RIs allow changing instance configuration but only within EC2 and at a lower discount than Standard RIs. Savings Plans are now the recommended approach for most workloads because of their flexibility. EC2 Instance Savings Plans offer higher discounts but are scoped to a specific instance family in one region.

  70. Q70D7 · Monitoring, Operations and DeploymentSelect one

    Your team uses AWS CodeBuild to build and test a Node.js application. How does CodeBuild know which commands to run during the install, build, and test phases?

    • A. CodeBuild automatically detects the language and runs standard commands (npm install, npm test) without any configuration
    • B. You define a buildspec.yml file at the root of the repository — it specifies phases (install, pre_build, build, post_build), the commands to run in each, and the artifacts to export
    • C. Build instructions are defined in the CodePipeline stage configuration, not in the source repository
    • D. CodeBuild uses the Dockerfile at the repository root to determine build and test commands
    Show answer

    Answer: B.

    buildspec.yml is the build specification file that CodeBuild reads from the root of your source repository. It defines the phases of the build: install (install build tools), pre_build (preparation like ECR login), build (compile and test the application), and post_build (packaging, tagging, notifications). Each phase lists shell commands in order. The artifacts section specifies which files to export as build output for downstream stages in CodePipeline. Without a buildspec.yml, CodeBuild cannot determine what to do and the build will fail. The buildspec can alternatively be provided inline in the CodeBuild project configuration if you prefer not to commit it to the repository.

  71. Q71D5 · Serverless and Application IntegrationSelect one

    Your API Gateway receives the same set of expensive database queries repeatedly from thousands of users. Each query takes 500ms on the backend. You want to serve repeated requests instantly without hitting the database. Which API Gateway feature handles this?

    • A. API Gateway throttling — limit the rate of incoming requests so fewer database queries are needed
    • B. API Gateway caching — enable a cache on the stage with a configurable TTL; identical requests are served from the cache without invoking the backend
    • C. API Gateway usage plans — limit each client to a maximum request rate, reducing total database load
    • D. CloudFront in front of API Gateway — CloudFront caches API responses at edge locations globally
    Show answer

    Answer: B.

    API Gateway has a built-in response cache that can be enabled per stage with a configurable TTL (0 to 3600 seconds). When caching is enabled, API Gateway checks whether a cached response exists for the incoming request (based on the request URL, query parameters, and headers you configure as cache keys). On a cache hit, it returns the cached response immediately — without invoking the Lambda function or hitting the backend database. Cache capacity is configurable from 0.5 GB to 237 GB. This dramatically reduces backend load and latency for read-heavy APIs with repeated identical requests. Cache invalidation can be triggered by clients with the Cache-Control: max-age=0 header if you configure it.

  72. Q72D8 · Cost Management and Multi-Account GovernanceSelect one

    A new regulatory requirement mandates that all production EC2 instances must have a specific compliance tag (Environment=Production) applied. You need to continuously audit this and automatically remediate non-compliant instances by adding the missing tag. Which AWS services work together to achieve this?

    • A. CloudTrail detects untagged instances and Lambda automatically applies tags in response to CloudTrail events
    • B. AWS Config rule detects non-compliant instances; an SSM Automation remediation document automatically applies the required tag when non-compliance is detected
    • C. Trusted Advisor checks tagging compliance and sends SNS notifications to prompt manual remediation
    • D. AWS Service Catalog enforces tags at provisioning time, preventing untagged instances from being launched
    Show answer

    Answer: B.

    AWS Config + SSM Automation is the standard pattern for detect-and-remediate compliance workflows. A Config rule evaluates all EC2 instances against the required-tags managed rule. When it finds a non-compliant instance, it triggers an automatic remediation action — an SSM Automation document that calls the EC2 CreateTags API to apply the missing tag. The remediation can be set to automatic (immediate) or manually approved. CloudTrail only logs API calls after the fact. Trusted Advisor identifies tagging issues but has no automated remediation. Service Catalog is preventive (controls what users can deploy) but cannot remediate existing resources.

  73. Q73D2 · Storage and Data ManagementSelect one

    You are designing a data lake on S3. Analysts run ad-hoc SQL queries against large Parquet files using Amazon Athena. A query scanning 10 TB of unpartitioned data takes 8 minutes and costs $50. What is the most effective architectural change to reduce both query time and cost?

    • A. Switch from Parquet to CSV — text formats are faster to scan than columnar binary formats
    • B. Partition the S3 data by date and other commonly filtered columns, and ensure the Athena queries include partition filters so only relevant partitions are scanned
    • C. Increase the Athena query engine version — newer versions scan data 10x faster
    • D. Enable S3 Transfer Acceleration on the data lake bucket — faster data retrieval reduces query time
    Show answer

    Answer: B.

    Athena is billed per TB of data scanned. Two techniques dramatically reduce scan volume: partitioning and columnar formats. Partitioning organizes data into folder prefixes by frequently filtered attributes (year=2024/month=03/day=15/). When a query includes WHERE year=2024 AND month=03, Athena only scans partitions matching those values — skipping all other data entirely. Columnar formats like Parquet also help (Athena only reads the specific columns referenced in the query, not every column in every row). Together, partitioning + Parquet can reduce query costs by 90%+. Athena pricing is entirely based on data scanned — faster engine versions do not change the cost model.

  74. Q74D7 · Monitoring, Operations and DeploymentSelect one

    Your application uses CloudFormation to manage production infrastructure. A junior engineer accidentally runs a delete-stack command against the production stack. How should you have prevented this?

    • A. Enable CloudFormation drift detection — it alerts on changes before they are applied
    • B. Enable Stack Termination Protection — a stack with termination protection cannot be deleted until protection is explicitly disabled by an authorized user
    • C. Set DeletionPolicy: Retain on all resources — the stack can be deleted but all resources persist
    • D. Use IAM policies to remove cloudformation:DeleteStack permissions from all users except administrators
    Show answer

    Answer: B.

    Stack Termination Protection is a CloudFormation feature that prevents a stack from being deleted, even by users who have the cloudformation:DeleteStack IAM permission. Before any deletion can proceed, an authorized user must first explicitly disable termination protection — adding a deliberate confirmation step that catches accidental deletions. DeletionPolicy: Retain preserves resources after stack deletion but still allows the stack itself to be deleted (you just lose CloudFormation management of those resources). IAM policy restrictions reduce the number of people who can delete but cannot prevent an authorized administrator from doing it accidentally. Termination protection is the most direct safeguard.

  75. Q75D5 · Serverless and Application IntegrationSelect one

    Your application is experiencing occasional Lambda cold starts of 3–4 seconds that are impacting user experience. The function runs Java with a large initialization class hierarchy. You cannot switch runtimes. What approaches reduce cold start impact without Provisioned Concurrency?

    • A. Increase the Lambda timeout to 30 seconds — cold starts always complete within this window
    • B. Increase Lambda memory allocation — higher memory provides proportionally more CPU during initialization, reducing cold start duration; also consider using Lambda SnapStart for Java which takes a snapshot after initialization
    • C. Switch from event-based invocation to polling — polling keeps the function warm by invoking it continuously
    • D. Deploy the function in a VPC — VPC functions start faster than non-VPC functions due to pre-warmed ENIs
    Show answer

    Answer: B.

    Lambda allocates CPU proportional to memory — doubling memory roughly doubles the available CPU for initialization, which can significantly reduce cold start time for CPU-intensive JVM startup. AWS Lambda SnapStart (available for Java) takes a snapshot of the initialized execution environment and restores it on cold starts, reducing Java cold starts from seconds to milliseconds. For VPC functions, AWS has pre-warmed ENI creation since 2019, so VPC no longer adds meaningful cold start overhead. Provisioned Concurrency is the most reliable solution but has an ongoing cost. Continuous polling would generate unnecessary invocations and cost money without meaningfully keeping the function warm for user traffic.

  76. Q76D6 · Security, Identity and ComplianceSelect one

    You need to centrally enforce that all EBS volumes in your AWS Organization are encrypted, and automatically encrypt any unencrypted volume that is created — without writing custom Lambda functions or Config remediation scripts. What is the simplest native mechanism?

    • A. Use an SCP to deny ec2:CreateVolume unless the Encrypted parameter is set to true
    • B. Enable EBS Encryption by Default at the account level — any new EBS volume or snapshot created in that account is automatically encrypted using the account's default KMS key, without any additional configuration
    • C. Deploy a CloudFormation StackSet with a Config rule and remediation that forces encryption on all new volumes
    • D. Configure an EventBridge rule that triggers a Lambda function to encrypt volumes when ec2:CreateVolume is detected in CloudTrail
    Show answer

    Answer: B.

    EBS Encryption by Default is a per-account, per-region setting that, once enabled, automatically encrypts all newly created EBS volumes, snapshots, and AMIs — no changes to your application code, CloudFormation templates, or launch processes required. The encryption uses the account's default AWS-managed KMS key (or a customer-managed key you specify). Existing unencrypted volumes are not affected retroactively, but all new volumes are covered immediately. This is the lowest-friction path to enforcing encryption. For an Organization-wide rollout, use a CloudFormation StackSet or AWS Config conformance pack to enable this setting in all accounts, rather than managing it account by account.

  77. Q77D7 · Monitoring, Operations and DeploymentSelect one

    Your AWS Systems Manager Patch Manager is configured to patch all EC2 instances tagged with PatchGroup=Production every Sunday at 2 AM. An instance was patched but is now failing health checks due to a bad kernel update. How should you handle rollback?

    • A. Use Patch Manager to uninstall the specific patch — Patch Manager supports patch rollback for all patch types
    • B. Restore the EC2 instance from an AMI snapshot taken before the maintenance window, or restore from an EBS snapshot; Patch Manager does not natively support patch rollback
    • C. Use SSM Run Command to run yum downgrade on the affected package on the instance
    • D. Terminate the instance and let Auto Scaling launch a fresh instance from the pre-patch AMI
    Show answer

    Answer: B.

    AWS Systems Manager Patch Manager does not provide a native "undo patching" or rollback capability — it applies patches but cannot reverse them with a single click. The correct recovery approaches depend on your backup strategy: if you take AMI snapshots before maintenance windows (a best practice), restore the instance from the pre-patch AMI. If you have EBS snapshots, restore the root volume. In an Auto Scaling Group, terminating the bad instance causes ASG to replace it with a new instance from the current launch template AMI. Running yum downgrade manually via Run Command is technically possible for specific packages but is risky and not scalable. This is why pre-patch AMI snapshots are critical.

  78. Q78D2 · Storage and Data ManagementSelect one

    You need to process 100,000 structured records from S3 (CSV files), join them with reference data from a RDS database, apply business transformations, and load the results into Redshift daily. The processing takes 2 hours. Which AWS service handles this serverless ETL pipeline most naturally?

    • A. AWS Lambda — write transformation code in Python; Lambda can process large datasets with 15-minute function chaining
    • B. Amazon EMR — provision a Spark cluster for the daily 2-hour job, scaling it down after completion
    • C. AWS Glue — serverless, fully managed ETL service with native connectors to S3, RDS, and Redshift; runs PySpark jobs without managing cluster infrastructure
    • D. AWS Step Functions — orchestrate the data movement between S3, RDS, and Redshift using native service integrations
    Show answer

    Answer: C.

    AWS Glue is purpose-built for serverless ETL workloads. It provides native connectors to S3, RDS (via JDBC), Redshift, DynamoDB, and many other sources. You write transformation logic in PySpark or Python Shell scripts; Glue handles provisioning, scaling, and managing the underlying Spark infrastructure. The Glue Data Catalog stores schema metadata for all sources and targets. Glue jobs can be scheduled, triggered by events, or run on demand. Lambda is limited to 15 minutes per function and 10 GB memory — unsuitable for 2-hour batch jobs. EMR works but requires more operational setup and is typically chosen when you need full Spark ecosystem control. Step Functions orchestrates workflow logic but does not perform data transformation itself.

  79. Q79D3 · Networking and Content DeliverySelect one

    Your organization is approaching the default service limit of 5 VPCs per region. Several teams have submitted requests to create new VPCs for new projects. What is the correct process to resolve this?

    • A. Delete unused VPCs from older projects — the limit cannot be increased and 5 per region is an absolute maximum
    • B. Submit an AWS Support request to increase the VPC per-region limit — most service quotas can be increased beyond the default via a support case or the Service Quotas console
    • C. Use VPC Peering to combine multiple projects into shared VPCs — this avoids needing more VPCs
    • D. Migrate all workloads to a single us-east-1 region — each region has an independent 5 VPC limit, so consolidation is required
    Show answer

    Answer: B.

    The default limit of 5 VPCs per region is a soft limit — it exists as a default guardrail, not a hard technical maximum. You can request an increase through the AWS Service Quotas console (Service Quotas → Amazon VPC → VPCs per Region → Request quota increase) or by opening an AWS Support case. AWS typically approves reasonable increases promptly. Many large organizations run dozens or hundreds of VPCs per region. Hard limits (which cannot be increased) are noted explicitly in the AWS documentation. Understanding the difference between soft limits (adjustable defaults) and hard limits (absolute maximums) is important for planning scalable AWS architectures.

  80. Q80D1 · Compute and ContainersSelect one

    An EC2 Auto Scaling Group is running instances launched from an old AMI. You need to update all running instances to use a new AMI (with the latest security patches) while maintaining application availability. Which ASG feature handles this without manual instance replacement?

    • A. Update the Launch Template to use the new AMI — ASG automatically replaces all running instances immediately
    • B. Use Instance Refresh — ASG gradually replaces running instances with new instances from the updated Launch Template, respecting a configurable minimum healthy percentage during the rollout
    • C. Create a new ASG with the new AMI and use Route 53 weighted routing to shift traffic from the old ASG to the new one
    • D. Terminate all instances simultaneously — ASG automatically launches replacements from the updated Launch Template
    Show answer

    Answer: B.

    Instance Refresh is the ASG feature designed specifically for rolling AMI updates. After you update the Launch Template to reference the new AMI, you initiate an Instance Refresh. ASG replaces instances in batches, ensuring that at least the configured minimum healthy percentage of capacity remains in service throughout the rollout. For example, with 10 instances and a 90% minimum healthy threshold, ASG replaces 1 instance at a time — waiting for the new instance to pass health checks before replacing the next one. This maintains availability while systematically replacing the entire fleet. Instance Refresh also supports automatic rollback if the new instances fail health checks, and integrates with launch template version management.

Last updated Sep 18, 2026