A company\\’s website hosted on Amazon EC2 instances processes classified data stored in Amazon S3 Due to
security concerns, the company requires a private and secure connection between its EC2 resources and Amazon S3
Which solution meets these requirements?
A. Set up S3 bucket policies to allow access from a VPC endpoint.
B. Set up an IAM policy to grant read-write access to the S3 bucket.
C. Set up a NAT gateway to access resources outside the private subnet.
D. Set up an access key ID and a secret access key to access the S3 bucket
Correct Answer: A

A company plans to deploy a new application in AWS that reads and writes information to a database. The company
wants to deploy the application in two different AWS Regions with each application writing to a database in their Region.
The databases in the Two Regions needs to keep We data synchronized What should be used to meet these
A. Use Amazon Athena with Amazon S3 Cross-Region Replication
B. Use AWS Database Migration Service (AWS DMS] with change data capture between an RDS for MySQL cluster in
each Region
C. Use Amazon DynamoDB with global tables
D. Use Amazon RDS for PostgreSQL cluster with a Cross-Region Read Replica
Correct Answer: A

A company has copied 1 PB of data from a colocation facility to an Amazon S3 bucket in the us-east-1 Region using an
AWS Direct Connect link. The company now wants to copy the data to another S3 bucket in the us-west-2 Region. The
colocation facility does not allow the use AWS Snowball. What should a solutions architect recommend to accomplish
A. Order a Snowball Edge device to copy the data from one Region to another Region.
B. Transfer contents from the source S3 bucket to a target S3 bucket using the S3 console.
C. Use the aws S3 sync command to copy data from the source bucket to the destination bucket.
D. Add a cross-Region replication configuration to copy objects across S3 buckets in different Reg.
Correct Answer: B

A company has a large dataset for its online advertising business stored in an Amazon RDS for MySQL
DB instance in a single Availability Zone. The company wants business reporting queries to run without
impacting the write operations to the production DB instance.
Which solution meets these requirements?
A. Deploy RDS read replicas to process the business reporting queries.
B. Scale out the DB instance horizontally by placing it behind an Elastic Load Balancer
C. Scale up the DB instance to a larger instance type to handle write operations and queries.
D. Deploy the DB instance in multiple Availability Zones to process the business reporting queries.
Correct Answer: A

A company wants to deploy an additional Amazon Aurora MySQL DB cluster for development purposes. The cluster will
be used several times a week for a few minutes upon to debug production query issues. The company wants to keep
overhead low for this resource. Which solution meets the company\\’s requirements MOST cost-effectively?
A. Purchas a Reserved Instance for the DB instances.
B. Run the DB instances on Aurora Serverless
C. Create a stop/start schedule for the DB instances.
D. Create an AWS Lambda function to stop DB instances it there are no active connections
Correct Answer: D

A solutions architect is designing a customer-facing application. The application is expected to have a variable amount
of reads and writes depending on the time of year and clearly defined access patterns throughout the year.
Management requires that database auditing and scaling be managed in the AWS Cloud. The Recovery Point Objective
(RPO) must be less than 5 hours. Which solutions can accomplish this? (Select TWO.)
A. Use Amazon DynamoDB with auto scaling. Use on-demand backups and AWS CloudTrail.
B. Use Amazon DynamoDB with auto scaling. Use on-demand backups and Amazon DynamoDB Streams.
C. Use Amazon Redshift Configure concurrency scaling. Enable audit logging. Perform database snapshots every 4
D. Use Amazon RDS with Provisioned IOPS. Enable the database auditing parameter. Perform database snapshots
every 5 hours.
E. Use Amazon RDS with auto scaling. Enable the database auditing parameter. Configure the backup retention period
to at least 1 day.
Correct Answer: AB

A company has a build server that is in an Auto Scaling group and often has multiple Linux instances running. The build
server requires consistent shared NFS storage for jobs and configurations. Which storage option should a solution
architect recommend?
A. Amazon S3
B. Amazon FSx
C. Amazon Elastic Block Store (Amazon EBS)
D. Amazon Elastic File System (Amazon EFS)
Correct Answer: D

As part of budget planning, management wants a report of AWS billed items listed by user. The data will
be used to create department budgets. A solutions architect needs to determine the most efficient way to
obtain this report information.
Which solution meets these requirements?
A. Run a query with Amazon Athena to generate the report.
B. Create a report in Cost Explorer and download the report.
C. Access the bill details from the billing dashboard and download the bill.
D. Modify a cost budget in AWS Budgets to alert with Amazon Simple Email Service (Amazon SES).
Correct Answer: D

A company is running its application in a single region on Amazon EC2 with Amazon Elastic Block Store
(Amazon EBS) and S3 as part of the storage design.
What should be done to reduce data transfer costs?
A. Create a copy of the compute environment in another AWS Region
B. Convert the application to run on [email protected]
C. Create an Amazon CloudFront distribution with Amazon S3 as the origin
D. Replicate Amazon S3 data to buckets in AWS Regions closer to the requester.
Correct Answer: C

The financial application at a company stores monthly reports in an Amazon S3 bucket. The vice president of finance
has mandated that all access to these reports be logged and that any modifications to the log files be detected Which
actions can a solutions architect take to meet these requirements7
A. Use S3 server access logging on the bucket that houses the reports with the read and write data events and log file
validation options enabled.
B. Use S3 server access logging on the bucket that houses the reports with the read and write management events and
log file validation options enabled
C. Use AWS CloudTrail to create a new trail. Configure the trail to log read and write data events on the S3 bucket that
houses the reports Log these events to a new bucket, and enable log file validation
D. Use AWS CloudTrail to create a new trail. Configure the trail to log read and write management events on the S3
bucket that houses the reports. Log these events to a new bucket, and enable log file validation.
Correct Answer: C

A company wants to migrate la accounting system from an on-premises data center to the AWS Cloud in a single AWS
Region Data security and an immutable audit log are the top priorities. The company must monitor all AWS activities for
compliance auditing. The company has enabled AWS CloudTrail but wants to make sure it meets these requirements
Which actions should a solutions architect take to protect and secure CloudTrail? (Select TWO.)
A. Enable CloudTrail log tile validation
B. Install the CloudTrail Processing Library
C. Enable logging of insights events in CloudTrail
D. Enable custom logging from the on-premises resources
E. Create an AWS Config rule to monitor whether CloudTrail is configured to use server-side encryption with AWS KMS
managed encryption keys (SSE-KMS)
Correct Answer: CE

A solutions architect is helping a developer design a new ecommerce shopping cart application using AWS services.
The developer is unsure of the current database schema and expects to make changes as the ecommerce site grows.
The solution needs to be highly resilient and capable of automatically scaling read and write capacity. Which database
solution meets these requirements?
A. Amazon Aurora PostgreSQL
B. Amazon DynamoDB with on-demand enabled
C. Amazon DynamoDB with DynamoDB Streams enabled
D. Amazon SQS and Amazon Aurora PostgreSQL
Correct Answer: A

A product team is creating a new application that will store a large amount of data The data will be analyzed hourly and
modified by multiple Amazon EC2 Linux instances The application team believes the amount of space needed will
continue to grow for the next 6 months Which set of actions should a solutions architect take to support these needs\\’?
A. Store the data in an Amazon EBS volume Mount the EBS volume on the application instances
B. Store the data in an Amazon EFS file system Mount the file system on the application instances
C. Store the data in Amazon S3 Glacier Update the vault policy to allow access to the application instances
D. Store the data in Amazon S3 Standard-Infrequent Access (S3 Standard-IA) Update the bucket policy to allow access
to the application instances
Correct Answer: B
Amazon Elastic File System Amazon Elastic File System (Amazon EFS) provides a simple, scalable, fully managed
elastic NFS file system for use with AWS Cloud services and on-premises resources. It is built to scale on demand to
petabytes without disrupting applications, growing and shrinking automatically as you add and remove files, eliminating
the need to provision and manage capacity to accommodate growth. Amazon EFS is designed to provide massively
parallel shared access to thousands of Amazon EC2 instances, enabling your applications to achieve high levels of
aggregate throughput and IOPS with consistent low latencies.
Amazon EFS is well suited to support a broad spectrum of use cases from home directories to business-critical
applications. Customers can use EFS to lift-and-shift existing enterprise applications to the AWS Cloud. Other use
cases include: big data analytics, web serving and content management, application development and testing, media
and entertainment workflows, database backups, and container storage. Amazon EFS is a regional service storing data
within and across multiple Availability Zones (AZs) for high availability and durability. Amazon EC2 instances can
access your file system across AZs, regions, and VPCs, while on-premises servers can access using AWS Direct
Connect or AWS VPN.

