Question 1001
A company wants EC2 instances to obtain temporary credentials to call AWS APIs without hardcoding access keys anywhere on the instance. What should be used?
- ❌ A. Store IAM user access keys in a config file on the instance
- ✅ B. Attach an IAM role to the EC2 instance profile
- ❌ C. Use the root account credentials
- ❌ D. Pass access keys as user data
Question 1002
A company needs a customer-managed KMS key where key material never leaves a dedicated single-tenant HSM under their exclusive control, required for strict compliance reasons, while still integrating with S3 and RDS encryption via a KMS custom key store.
- ❌ A. AWS KMS with AWS managed keys
- ✅ B. AWS CloudHSM as a KMS custom key store
- ❌ C. SSE-S3
- ❌ D. Secrets Manager
Question 1003
A company wants to let a mobile app's users sign in with Facebook/Google and obtain scoped, temporary AWS credentials to access specific S3 objects directly.
- ❌ A. IAM Identity Center
- ✅ B. Amazon Cognito Identity Pools
- ❌ C. STS AssumeRole with a hardcoded IAM user
- ❌ D. Directory Service
Question 1004
A company wants to centrally deploy and enforce consistent AWS WAF web ACLs and Shield Advanced protections automatically to every new ALB created across 50 accounts in an Organization, without manual per-account setup.
- ❌ A. AWS Config
- ✅ B. AWS Firewall Manager
- ❌ C. IAM Access Analyzer
- ❌ D. Amazon Macie
Question 1005
A company wants an automated way to verify whether their S3 buckets, EBS volumes, and RDS instances comply with an internal policy requiring encryption at rest, flagging any non-compliant resource within minutes of creation.
- ✅ A. AWS Config with Config Rules and auto-remediation
- ❌ B. Amazon Inspector
- ❌ C. AWS CloudTrail
- ❌ D. AWS Trusted Advisor
Question 1006
A company needs to grant a Lambda function the ability to read from one specific S3 bucket only, following least privilege, without granting access to any other bucket.
- ❌ A. Attach AmazonS3FullAccess managed policy
- ✅ B. Create an IAM role with a policy scoped to that bucket's ARN and attach it to the Lambda function
- ❌ C. Use root credentials in environment variables
- ❌ D. Enable public access on the bucket
Question 1007
A financial company must ensure database credentials used by an application are never stored in code or config files, and are automatically rotated every 24 hours without downtime.
- ❌ A. Hardcode in application code
- ✅ B. AWS Secrets Manager with automatic rotation
- ❌ C. Store in a public S3 bucket
- ❌ D. Systems Manager Parameter Store SecureString without rotation
Question 1008
A company's security team wants every IAM principal across the Organization to be denied the ability to delete CloudTrail trails or S3 access logs, regardless of any permissions granted at the account level.
- ❌ A. IAM policy per user
- ✅ B. Service Control Policy (SCP) explicit deny at the Organization root
- ❌ C. Resource-based policy only
- ❌ D. GuardDuty
Question 1009
A three-tier application's web tier is public, app tier is private, and database tier is private. Which security group configuration correctly restricts database access?
- ❌ A. DB security group allows inbound from 0.0.0.0/0
- ✅ B. DB security group allows inbound only from the app tier's security group on the DB port
- ❌ C. DB security group allows inbound from the web tier
- ❌ D. DB has no security group
Question 1010
A company wants continuous, ML-based threat detection across VPC Flow Logs, DNS logs, and CloudTrail to identify potentially compromised EC2 instances or unauthorized API calls.
- ❌ A. AWS Config
- ✅ B. Amazon GuardDuty
- ❌ C. AWS Trusted Advisor
- ❌ D. AWS Shield
Question 1011
A company must automatically discover and classify PII, PHI, and financial data stored across dozens of S3 buckets on an ongoing basis.
- ✅ A. Amazon Macie
- ❌ B. AWS Shield
- ❌ C. Amazon Inspector
- ❌ D. AWS Artifact
Question 1012
An internet-facing application is being hit with repeated SQLi and XSS attempts. The team wants to block these at the edge using managed rule sets without writing custom signatures.
- ❌ A. Security Groups
- ✅ B. AWS WAF with AWS Managed Rules
- ❌ C. Network ACLs
- ❌ D. VPC Flow Logs
Question 1013
A company wants guaranteed DDoS cost protection (SLA-backed credits) and 24/7 access to AWS's DDoS Response Team for a business-critical application.
- ❌ A. AWS Shield Standard (free tier)
- ✅ B. AWS Shield Advanced
- ❌ C. AWS WAF
- ❌ D. GuardDuty
Question 1014
A company wants every new EBS volume created in a region to be encrypted automatically, with no way for a developer to accidentally launch an unencrypted volume.
- ✅ A. Enable EBS encryption by default for the account/region
- ❌ B. Rely on developers to check a box each time
- ❌ C. Enable S3 default encryption
- ❌ D. Enable RDS encryption
Question 1015
A healthcare company must guarantee that AWS itself cannot access the plaintext of stored objects, retaining full external control of encryption keys outside AWS's key management.
- ❌ A. SSE-S3
- ❌ B. SSE-KMS with AWS managed key
- ✅ C. Client-side encryption with customer-held keys before upload
- ❌ D. Default encryption
Question 1016
A company wants to let a business partner's application privately call a specific internal API hosted behind an NLB in the company's VPC, without peering VPCs or exposing anything to the public internet.
- ❌ A. VPC Peering
- ✅ B. AWS PrivateLink (VPC Endpoint Service backed by NLB)
- ❌ C. Internet Gateway
- ❌ D. Transit Gateway
Question 1017
A company running microservices on ECS wants all inter-service traffic encrypted with mutual TLS, enforced transparently at the infrastructure layer rather than in each service's code.
- ❌ A. Security Groups only
- ❌ B. AWS Certificate Manager alone
- ✅ C. A service mesh (e.g., AWS App Mesh) with mTLS
- ❌ D. NAT Gateway
Question 1018
A company wants a single place to see, across all accounts, a unified view of GuardDuty findings, Security Hub standards compliance, and Config rule violations.
- ❌ A. AWS Trusted Advisor
- ✅ B. AWS Security Hub
- ❌ C. Amazon Macie
- ❌ D. AWS Artifact
Question 1019
A company wants to require that all IAM users authenticate with a hardware security key (like a YubiKey) in addition to their password before accessing the AWS Console.
- ❌ A. Virtual MFA only
- ✅ B. IAM policy conditions with MFA + a U2F/FIDO security key device registered for the user
- ❌ C. SMS-based MFA
- ❌ D. No MFA, rely on strong passwords
Question 1020
A company wants to ensure temporary credentials issued via AssumeRole for a third-party auditor automatically expire after exactly 1 hour and cannot be used beyond that regardless of the auditor's actions.
- ✅ A. Set the IAM role's maximum session duration accordingly and issue credentials via STS AssumeRole
- ❌ B. Use permanent IAM user access keys
- ❌ C. Disable the role after use manually
- ❌ D. Use root account credentials
Question 1021
An application stores session state on local EC2 disk, breaking when Auto Scaling replaces instances. What is the correct fix for statelessness?
- ❌ A. Use larger instances
- ✅ B. Externalize session state to ElastiCache or DynamoDB
- ❌ C. Turn off Auto Scaling
- ❌ D. Use Spot only
Question 1022
New instances launched by an ASG receive traffic from the ALB before the app is ready, causing 5xx errors. What should be configured?
- ❌ A. Nothing, this is expected
- ✅ B. ELB health checks with an appropriate health check grace period on the ASG
- ❌ C. Remove the target group
- ❌ D. Use only EC2 status checks
Question 1023
A producer service occasionally sends bursts far exceeding what a downstream consumer can handle. The team wants automatic buffering and retry with at-least-once delivery, fully managed.
- ❌ A. Direct synchronous HTTP calls
- ✅ B. Amazon SQS Standard Queue between producer and consumer
- ❌ C. Amazon CloudFront
- ❌ D. AWS Direct Connect
Question 1024
A global app must route users to the lowest-latency healthy region automatically, failing over if a region's health check fails.
- ❌ A. Simple routing
- ✅ B. Latency-based routing with Route 53 health checks
- ❌ C. Weighted routing only
- ❌ D. Geolocation routing only
Question 1025
A company needs near-zero RPO for their Aurora database if an entire AWS region fails, with fast promotion of a secondary region.
- ❌ A. Same-region read replicas
- ✅ B. Aurora Global Database
- ❌ C. Nightly manual snapshots
- ❌ D. Standard automated backups
Question 1026
A single NAT Gateway in one AZ becomes a single point of failure for private subnet instances in other AZs during an AZ outage.
- ❌ A. Use a NAT instance instead
- ✅ B. Deploy one NAT Gateway per AZ, routing each AZ's private subnets to its own NAT Gateway
- ❌ C. Remove the NAT Gateway
- ❌ D. Use one large NAT Gateway shared across AZs
Question 1027
A globally distributed app needs a DynamoDB table replicated automatically across multiple regions with low-latency local reads/writes in each.
- ❌ A. DAX
- ✅ B. DynamoDB Global Tables
- ❌ C. DynamoDB Streams alone
- ❌ D. On-demand backup and restore
Question 1028
A batch workload on Spot Instances must gracefully checkpoint work before a 2-minute interruption notice expires.
- ❌ A. Ignore the notice
- ✅ B. Poll the instance metadata service for the interruption notice and checkpoint before termination
- ❌ C. Switch to On-Demand permanently
- ❌ D. Disable monitoring
Question 1029
A team wants to proactively and safely inject real failures (AZ outage, instance termination, latency) into production-like environments to validate resilience assumptions.
- ❌ A. AWS Trusted Advisor
- ✅ B. AWS Fault Injection Service (chaos engineering)
- ❌ C. Amazon Inspector
- ❌ D. CloudWatch Alarms alone
Question 1030
Repeated synchronous calls to a frequently-failing downstream service are causing cascading timeouts across the whole system.
- ❌ A. Increase all timeouts indefinitely
- ✅ B. Implement a circuit breaker with backoff/retry and fail fast when the breaker is open
- ❌ C. Remove timeouts entirely
- ❌ D. Add more synchronous retries with no backoff
Question 1031
A non-critical archival backup workload needs an RTO of several hours and the absolute lowest cost DR option.
- ❌ A. Multi-Site Active-Active
- ✅ B. Backup and Restore
- ❌ C. Warm Standby
- ❌ D. Pilot Light
Question 1032
An ASG must replace instances that fail a custom application health check endpoint behind an ALB, not just EC2 instance status checks.
- ❌ A. EC2 status checks only
- ✅ B. Enable ELB health checks on the ASG pointing at the target group's health check
- ❌ C. CloudWatch Logs subscription
- ❌ D. Manual replacement
Question 1033
A company needs an RDS database to automatically fail over to a synchronously-replicated standby in a different AZ within ~60-120 seconds with zero committed-transaction data loss.
- ❌ A. Read Replica promotion
- ✅ B. Multi-AZ deployment
- ❌ C. Automated backups only
- ❌ D. RDS Proxy alone
Question 1034
A serverless app (API Gateway + Lambda) is throttled during spikes, dropping requests. Team wants to smooth bursts and process asynchronously.
- ❌ A. Increase Lambda memory only
- ✅ B. Buffer requests via SQS between API Gateway and Lambda, with appropriately sized throttling limits
- ❌ C. Remove API Gateway
- ❌ D. Unlimited concurrency with no queue
Question 1035
Order-placement and fulfillment services must be decoupled so an hour-long fulfillment outage loses no orders, with poison messages set aside after 3 failed attempts.
- ❌ A. SNS with no DLQ
- ✅ B. SQS queue with redrive policy to a DLQ at maxReceiveCount=3
- ❌ C. Kinesis with 24h retention only
- ❌ D. Direct synchronous invocation
Question 1036
A static S3-hosted website needs to survive a regional S3 outage by failing over to a bucket in a second region.
- ❌ A. Same-Region Replication alone
- ✅ B. Cross-Region Replication plus Route 53 failover routing between the two endpoints
- ❌ C. Versioning alone
- ❌ D. CloudFront alone with a single origin
Question 1037
An app needs sub-millisecond in-memory caching with support for sorted sets and pub/sub, for a real-time leaderboard.
- ❌ A. RDS
- ✅ B. ElastiCache for Redis
- ❌ C. S3
- ❌ D. DAX
Question 1038
An HPC workload needs tightly-coupled, low-latency inter-node communication between EC2 instances in the same AZ.
- ✅ A. Cluster placement group
- ❌ B. Spread placement group
- ❌ C. Dedicated Hosts
- ❌ D. Multi-AZ deployment
Question 1039
A rendering farm needs a POSIX-compliant, extremely high-throughput, sub-millisecond-latency shared file system backed by S3 as the data repository.
- ❌ A. EFS
- ✅ B. FSx for Lustre
- ❌ C. EBS Multi-Attach
- ❌ D. S3 Standard
Question 1040
Millions of clickstream events per second must be ingested and independently consumed/replayed by multiple downstream applications.
- ❌ A. SQS
- ✅ B. Kinesis Data Streams
- ❌ C. SNS
- ❌ D. AWS Batch
Question 1041
A read-heavy Aurora MySQL workload needs microsecond caching for repeated identical queries beyond what read replicas alone provide.
- ❌ A. Aurora Global Database
- ❌ B. RDS Proxy
- ✅ C. ElastiCache in front of the database
- ❌ D. Multi-AZ only
Question 1042
A memory-intensive in-memory database (like SAP HANA) needs an EC2 family with a very high memory-to-vCPU ratio.
- ❌ A. C-family
- ✅ B. R-family
- ❌ C. T-family
- ❌ D. G-family
Question 1043
A team needs serverless ETL on massive S3 datasets using Apache Spark, without managing infrastructure.
- ✅ A. AWS Glue
- ❌ B. self-managed EMR clusters
- ❌ C. Data Pipeline
- ❌ D. Athena
Question 1044
Analysts want ad-hoc SQL directly on Parquet data in S3 without provisioning any database.
- ❌ A. RDS
- ✅ B. Athena
- ❌ C. DynamoDB
- ❌ D. Glue
Question 1045
A workload needs single-digit-millisecond latency at any scale with a flexible schema and highly unpredictable, spiky traffic.
- ❌ A. RDS Provisioned IOPS
- ✅ B. DynamoDB on-demand capacity
- ❌ C. Redshift
- ❌ D. Aurora Serverless v1
Question 1046
Large sequential I/O for a Hadoop HDFS-style workload needs high throughput at the lowest cost, not high IOPS.
- ❌ A. io2
- ✅ B. st1 (Throughput Optimized HDD)
- ❌ C. gp3
- ❌ D. sc1
Question 1047
A streaming company wants edge caching plus the ability to run lightweight custom logic (like header rewrites) at edge locations globally.
- ❌ A. S3 Transfer Acceleration alone
- ✅ B. CloudFront with Lambda@Edge or CloudFront Functions
- ❌ C. Global Accelerator alone
- ❌ D. Route 53 latency routing alone
Question 1048
A non-HTTP TCP gaming app needs improved global network performance with static anycast IPs and health-based routing to the optimal endpoint.
- ❌ A. CloudFront
- ✅ B. Global Accelerator
- ❌ C. Route 53 latency routing
- ❌ D. Direct Connect
Question 1049
A data warehouse needs OLAP queries across petabytes with columnar storage and MPP.
- ❌ A. RDS
- ✅ B. Redshift
- ❌ C. DynamoDB
- ❌ D. Neptune
Question 1050
An HPC cluster needs higher network throughput between instances using OS-bypass technology beyond standard ENA.
- ✅ A. Elastic Fabric Adapter (EFA)
- ❌ B. Standard ENA only
- ❌ C. NAT Gateway
- ❌ D. VPC Peering
Question 1051
A relational DB workload with many small random IOPS needs the best general-purpose price/performance EBS volume.
- ❌ A. io2
- ✅ B. gp3
- ❌ C. st1
- ❌ D. sc1
Question 1052
A company has a steady-state, predictable EC2 workload for 3 years, committed to a specific instance family/region, and wants the absolute maximum discount.
- ✅ A. Standard Reserved Instances (3-year, all upfront)
- ❌ B. Compute Savings Plans
- ❌ C. Spot Instances
- ❌ D. On-Demand
Question 1053
A company wants deep discounts (up to 90%) but needs flexibility to run workloads across EC2, Fargate, and Lambda under one commitment, since instance types/services may shift over time.
- ❌ A. Standard Reserved Instances
- ✅ B. Compute Savings Plans
- ❌ C. Convertible RIs only
- ❌ D. Spot Instances
Question 1054
A company wants automated recommendations to identify idle load balancers, underutilized EC2 instances, and unattached EBS volumes for cost savings.
- ❌ A. AWS Budgets
- ✅ B. AWS Trusted Advisor cost optimization checks
- ❌ C. AWS Config
- ❌ D. CloudWatch
Question 1055
A company wants to be alerted by email BEFORE the month ends if spend is forecasted to exceed a threshold.
- ❌ A. Cost Explorer
- ✅ B. AWS Budgets with forecasted alerts
- ❌ C. Trusted Advisor
- ❌ D. Cost and Usage Report
Question 1056
A company wants to right-size EC2 instances by getting specific downsize recommendations based on actual CPU/memory utilization history.
- ✅ A. AWS Compute Optimizer
- ❌ B. AWS Config
- ❌ C. CloudWatch Logs
- ❌ D. Trusted Advisor security checks
Question 1057
Log data is rarely accessed (quarterly, for compliance audits) and can tolerate up to 12 hours retrieval time. Minimize storage cost.
- ❌ A. S3 Standard-IA
- ✅ B. S3 Glacier Deep Archive
- ❌ C. S3 One Zone-IA
- ❌ D. S3 Intelligent-Tiering
Question 1058
A company transfers large volumes of data nightly from on-premises to AWS on a recurring, dedicated basis and wants to reduce cost/variability vs. internet transfer.
- ✅ A. AWS Direct Connect
- ❌ B. VPN over internet
- ❌ C. Snowball for every transfer
- ❌ D. S3 Transfer Acceleration
Question 1059
A company wants to eliminate NAT Gateway data processing charges for EC2-to-S3 traffic from a private subnet.
- ❌ A. NAT Instance instead
- ✅ B. Gateway VPC Endpoint for S3
- ❌ C. Interface VPC Endpoint for S3 only
- ❌ D. A second NAT Gateway
Question 1060
A Redshift cluster used only for weekday business-hours reporting sits idle nights/weekends. Reduce cost.
- ❌ A. Reserved Nodes running 24/7
- ✅ B. Pause cluster off-hours or use Redshift Serverless
- ❌ C. Bigger cluster
- ❌ D. Enable Multi-AZ
Question 1061
Dev/test EC2 environments run only 8am-6pm weekdays and are idle otherwise.
- ❌ A. Reserved Instances for dev/test
- ✅ B. Automatically stop/start via Instance Scheduler or Lambda+EventBridge
- ❌ C. Spot only
- ❌ D. Leave running continuously
Question 1062
Dev/test/staging Aurora databases have unpredictable, intermittent usage and sit idle much of the time, but must auto-scale on demand.
- ❌ A. Large provisioned instances
- ✅ B. Aurora Serverless v2
- ❌ C. Reserved Instances
- ❌ D. Multi-AZ provisioned
Question 1063
A company with 20+ accounts wants one consolidated bill and automatic sharing of RI/Savings Plans discounts across all accounts.
- ❌ A. Separate billing, no sharing
- ✅ B. AWS Organizations with Consolidated Billing
- ❌ C. Manual reconciliation
- ❌ D. AWS Budgets only
Question 1064
A company wants to avoid S3 storage costs for data with genuinely unknown or changing access patterns, without manually choosing a storage class or writing lifecycle rules.
- ❌ A. S3 Standard only
- ✅ B. S3 Intelligent-Tiering
- ❌ C. S3 One Zone-IA
- ❌ D. Glacier Instant Retrieval only
Question 1065
A company wants to reduce cross-AZ data transfer charges between an application tier and an RDS Multi-AZ database while keeping the HA benefits of Multi-AZ.
- ❌ A. Remove Multi-AZ entirely to save cost
- ✅ B. Keep Multi-AZ standby for HA, but co-locate app instances with the primary's AZ where possible to minimize cross-AZ read/write traffic
- ❌ C. Use a NAT Gateway
- ❌ D. Enable S3 Transfer Acceleration