Amazon AWS Solutions Architect Professional SAP-C02 Hybrid DNS Segmentation Endpoints Practice Test

 

Domain 1.1 • 25 original questions

This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on hybrid dns segmentation endpoints and network troubleshooting through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

Contoso Retail is changing its media processing platform as part of a production readiness review. Which AWS approach best enables the team to resolve on-premises private names from VPC workloads and selected private AWS names from the data center while keeping administration centralized across accounts? The current estate includes 20 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  2. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  3. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  4. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership

Correct answer: B

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while keeping administration centralized across accounts.

B: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

C: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while keeping administration centralized across accounts.

D: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while keeping administration centralized across accounts.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 2

An architecture board at Lucerne Publishing asks the principal solutions architect to design IP addressing that supports future VPC growth and centralized routing while keeping administration centralized across accounts for a global web application. Which recommendation is most appropriate? The current estate includes 27 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  2. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  3. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  4. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing

Correct answer: D

Why: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while keeping administration centralized across accounts.

B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while keeping administration centralized across accounts.

C: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while keeping administration centralized across accounts.

D: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Learning point: Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing. Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 3

For a order-processing system at A. Datum Analytics, a hybrid connectivity redesign identifies one priority: keep AWS service traffic private while providing evidence for network troubleshooting while keeping administration centralized across accounts. Which AWS design should the team choose? The current estate includes 34 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  2. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  3. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  4. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access

Correct answer: D

Why: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while keeping administration centralized across accounts.

B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while keeping administration centralized across accounts.

C: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while keeping administration centralized across accounts.

D: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Learning point: Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access. AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 4

Wide World Importers has already validated the surrounding application components. The remaining architecture requirement for its analytics pipeline is to resolve on-premises private names from VPC workloads and selected private AWS names from the data center while preserving AWS-native auditability and measurable health signals. Which option is best? The current estate includes 41 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  2. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  3. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  4. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations

Correct answer: C

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while preserving AWS-native auditability and measurable health signals.

B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while preserving AWS-native auditability and measurable health signals.

C: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while preserving AWS-native auditability and measurable health signals.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 5

Which solution is the strongest match for the following professional-level architecture requirement: design IP addressing that supports future VPC growth and centralized routing while preserving AWS-native auditability and measurable health signals? The current estate includes 48 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  2. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations

Correct answer: C

Why: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while preserving AWS-native auditability and measurable health signals.

B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while preserving AWS-native auditability and measurable health signals.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

D: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while preserving AWS-native auditability and measurable health signals.

Learning point: Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing. Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 6

During a cost optimization workshop at Blue Yonder Airlines, the security architect is designing a global web application. The requirement is to keep AWS service traffic private while providing evidence for network troubleshooting while preserving AWS-native auditability and measurable health signals. Which architecture is the best fit? The current estate includes 8 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  2. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  3. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  4. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs

Correct answer: C

Why: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while preserving AWS-native auditability and measurable health signals.

B: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while preserving AWS-native auditability and measurable health signals.

C: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while preserving AWS-native auditability and measurable health signals.

Learning point: Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access. AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 7

City Power operates a order-processing system. In a global expansion project, the cloud platform architect must resolve on-premises private names from VPC workloads and selected private AWS names from the data center without relying on a one-off operator runbook. Which option should be recommended? The current estate includes 15 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  2. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  3. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  4. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing

Correct answer: A

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

B: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without relying on a one-off operator runbook.

C: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without relying on a one-off operator runbook.

D: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without relying on a one-off operator runbook.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 8

A site reliability architect at Proseware Labs is reviewing a analytics pipeline. The business requires the team to design IP addressing that supports future VPC growth and centralized routing without relying on a one-off operator runbook. Which design most directly satisfies the requirement? The current estate includes 22 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  2. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing

Correct answer: C

Why: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without relying on a one-off operator runbook.

B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without relying on a one-off operator runbook.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

D: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without relying on a one-off operator runbook.

Learning point: Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing. Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 9

Southridge Video is changing its media processing platform as part of a migration wave planning session. Which AWS approach best enables the team to keep AWS service traffic private while providing evidence for network troubleshooting without relying on a one-off operator runbook? The current estate includes 29 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  2. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing

Correct answer: B

Why: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without relying on a one-off operator runbook.

B: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without relying on a one-off operator runbook.

D: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without relying on a one-off operator runbook.

Learning point: Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access. AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 10

Which AWS architecture principle or service combination best addresses this requirement for Woodgrove Bank: resolve on-premises private names from VPC workloads and selected private AWS names from the data center while keeping the pattern scalable as the organization adds accounts? The current estate includes 36 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  2. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  3. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  4. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts

Correct answer: C

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

B: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

C: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 11

For a order-processing system at Relecloud Systems, a security design review identifies one priority: design IP addressing that supports future VPC growth and centralized routing while keeping the pattern scalable as the organization adds accounts. Which AWS design should the team choose? The current estate includes 43 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  2. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  3. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  4. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation

Correct answer: B

Why: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

Learning point: Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing. Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 12

Fabrikam Health has already validated the surrounding application components. The remaining architecture requirement for its analytics pipeline is to keep AWS service traffic private while providing evidence for network troubleshooting while keeping the pattern scalable as the organization adds accounts. Which option is best? The current estate includes 3 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  2. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  3. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  4. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access

Correct answer: D

Why: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

C: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

D: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Learning point: Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access. AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 13

While conducting a production readiness review, the cloud financial management lead at Trey Research needs to resolve on-premises private names from VPC workloads and selected private AWS names from the data center without granting broad administrator permissions. Which architecture decision best matches the stated constraints? The current estate includes 10 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  2. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  3. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  4. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads

Correct answer: A

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

B: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without granting broad administrator permissions.

C: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without granting broad administrator permissions.

D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without granting broad administrator permissions.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work without granting broad administrator permissions.

Question 14

During a architecture review at Northwind Media, the security architect is designing a global web application. The requirement is to design IP addressing that supports future VPC growth and centralized routing without granting broad administrator permissions. Which architecture is the best fit? The current estate includes 17 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  2. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs

Correct answer: C

Why: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without granting broad administrator permissions.

B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without granting broad administrator permissions.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without granting broad administrator permissions.

Learning point: Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing. Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. In this variant, the decision also has to work without granting broad administrator permissions.

Question 15

Coho Financial is documenting its target-state architecture. Which choice most accurately addresses the need to keep AWS service traffic private while providing evidence for network troubleshooting without granting broad administrator permissions? The current estate includes 24 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  2. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  3. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  4. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration

Correct answer: A

Why: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

B: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without granting broad administrator permissions.

C: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without granting broad administrator permissions.

D: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without granting broad administrator permissions.

Learning point: Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access. AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. In this variant, the decision also has to work without granting broad administrator permissions.

Question 16

A site reliability architect at Lamna Healthcare is reviewing a analytics pipeline. The business requires the team to resolve on-premises private names from VPC workloads and selected private AWS names from the data center while preferring managed AWS capabilities over bespoke infrastructure. Which design most directly satisfies the requirement? The current estate includes 31 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  2. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate

Correct answer: D

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

B: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 17

Fourth Coffee is changing its media processing platform as part of a new workload design. Which AWS approach best enables the team to design IP addressing that supports future VPC growth and centralized routing while preferring managed AWS capabilities over bespoke infrastructure? The current estate includes 38 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  2. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation

Correct answer: C

Why: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing. Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 18

An architecture board at Consolidated Messenger asks the principal solutions architect to keep AWS service traffic private while providing evidence for network troubleshooting while preferring managed AWS capabilities over bespoke infrastructure for a global web application. Which recommendation is most appropriate? The current estate includes 45 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  2. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  3. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  4. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations

Correct answer: A

Why: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

B: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

C: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access. AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 19

For a order-processing system at Litware Manufacturing, a global expansion project identifies one priority: resolve on-premises private names from VPC workloads and selected private AWS names from the data center while enabling the pattern to be reused consistently across organizational units. Which AWS design should the team choose? The current estate includes 5 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  2. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  3. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  4. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads

Correct answer: B

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

B: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

C: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 20

A principal architect asks which AWS approach is intended to design IP addressing that supports future VPC growth and centralized routing while enabling the pattern to be reused consistently across organizational units. What is the best answer? The current estate includes 12 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  2. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation

Correct answer: C

Why: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

B: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

Learning point: Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing. Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 21

While conducting a migration wave planning session, the cloud financial management lead at Tailspin Logistics needs to keep AWS service traffic private while providing evidence for network troubleshooting while enabling the pattern to be reused consistently across organizational units. Which architecture decision best matches the stated constraints? The current estate includes 19 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  2. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  3. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  4. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access

Correct answer: D

Why: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

B: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

C: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

D: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Learning point: Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access. AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 22

During a post-incident architecture review at Alpine Sports, the security architect is designing a global web application. The requirement is to resolve on-premises private names from VPC workloads and selected private AWS names from the data center without introducing an unrelated application rewrite. Which architecture is the best fit? The current estate includes 26 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  2. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  3. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations
  4. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate

Correct answer: D

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without introducing an unrelated application rewrite.

B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without introducing an unrelated application rewrite.

C: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of without introducing an unrelated application rewrite.

D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 23

Adventure Works operates a order-processing system. In a security design review, the cloud platform architect must design IP addressing that supports future VPC growth and centralized routing without introducing an unrelated application rewrite. Which option should be recommended? The current estate includes 33 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  2. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  3. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  4. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration

Correct answer: B

Why: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without introducing an unrelated application rewrite.

B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

C: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without introducing an unrelated application rewrite.

D: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to design IP addressing that supports future VPC growth and centralized routing under the additional constraint of without introducing an unrelated application rewrite.

Learning point: Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing. Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 24

A site reliability architect at VanArsdel Energy is reviewing a analytics pipeline. The business requires the team to keep AWS service traffic private while providing evidence for network troubleshooting without introducing an unrelated application rewrite. Which design most directly satisfies the requirement? The current estate includes 40 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  2. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  3. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  4. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation

Correct answer: A

Why: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without introducing an unrelated application rewrite.

C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without introducing an unrelated application rewrite.

D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to keep AWS service traffic private while providing evidence for network troubleshooting under the additional constraint of without introducing an unrelated application rewrite.

Learning point: Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access. AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 25

Following an acquisition, Contoso Retail is rationalizing its media processing platform. The architecture board documented two acceptance criteria: resolve on-premises private names from VPC workloads and selected private AWS names from the data center; and the solution must do so while minimizing manual intervention during steady-state operations. Which target-state recommendation should the migration architect approve? The current estate includes 47 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  2. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  3. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  4. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance

Correct answer: C

Why: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

Option review:

A: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while minimizing manual intervention during steady-state operations.

B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while minimizing manual intervention during steady-state operations.

C: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

D: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to resolve on-premises private names from VPC workloads and selected private AWS names from the data center under the additional constraint of while minimizing manual intervention during steady-state operations.

Learning point: Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate. Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. In this variant, the decision also has to work while minimizing manual intervention during steady-state operations.

Popular posts

img