Amazon AWS Solutions Architect Professional SAP-C02 Cost Visibility Tagging Purchasing Practice Test

 

Domain 1.5 • 30 original questions

This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on cost visibility tagging purchasing and rightsizing through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

While conducting a migration wave planning session, the cloud financial management lead at Tailspin Logistics needs to forecast future spend and alert teams before budgets are exceeded while keeping administration centralized across accounts. Which architecture decision best matches the stated constraints? The current estate includes 40 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  2. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  3. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  4. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts

Correct answer: D

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping administration centralized across accounts.

B: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping administration centralized across accounts.

C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping administration centralized across accounts.

D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 2

During a post-incident architecture review at Alpine Sports, the security architect is designing a customer-facing API. The requirement is to compare Reserved Instances and Savings Plans for a stable production footprint while keeping administration centralized across accounts. Which architecture is the best fit? The current estate includes 47 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  2. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  3. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  4. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration

Correct answer: A

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping administration centralized across accounts.

C: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping administration centralized across accounts.

D: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping administration centralized across accounts.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 3

Adventure Works operates a healthcare records application. In a security design review, the cloud platform architect must identify oversized compute resources and costly storage patterns before changing the architecture while keeping administration centralized across accounts. Which option should be recommended? The current estate includes 7 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  2. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  3. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  4. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths

Correct answer: A

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

B: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping administration centralized across accounts.

C: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping administration centralized across accounts.

D: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping administration centralized across accounts.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 4

A site reliability architect at VanArsdel Energy is reviewing a enterprise ERP system. The business requires the team to forecast future spend and alert teams before budgets are exceeded while preserving AWS-native auditability and measurable health signals. Which design most directly satisfies the requirement? The current estate includes 14 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration

Correct answer: B

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while preserving AWS-native auditability and measurable health signals.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while preserving AWS-native auditability and measurable health signals.

D: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while preserving AWS-native auditability and measurable health signals.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 5

Which solution is the strongest match for the following professional-level architecture requirement: compare Reserved Instances and Savings Plans for a stable production footprint while preserving AWS-native auditability and measurable health signals? The current estate includes 21 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  2. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  3. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  4. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload

Correct answer: C

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while preserving AWS-native auditability and measurable health signals.

B: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while preserving AWS-native auditability and measurable health signals.

C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

D: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while preserving AWS-native auditability and measurable health signals.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 6

An architecture board at Lucerne Publishing asks the principal solutions architect to identify oversized compute resources and costly storage patterns before changing the architecture while preserving AWS-native auditability and measurable health signals for a customer-facing API. Which recommendation is most appropriate? The current estate includes 28 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  2. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  3. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  4. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing

Correct answer: A

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while preserving AWS-native auditability and measurable health signals.

C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while preserving AWS-native auditability and measurable health signals.

D: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while preserving AWS-native auditability and measurable health signals.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 7

For a healthcare records application at A. Datum Analytics, a hybrid connectivity redesign identifies one priority: forecast future spend and alert teams before budgets are exceeded without relying on a one-off operator runbook. Which AWS design should the team choose? The current estate includes 35 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  2. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  3. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  4. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations

Correct answer: C

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without relying on a one-off operator runbook.

B: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without relying on a one-off operator runbook.

C: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without relying on a one-off operator runbook.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 8

Wide World Importers has already validated the surrounding application components. The remaining architecture requirement for its enterprise ERP system is to compare Reserved Instances and Savings Plans for a stable production footprint without relying on a one-off operator runbook. Which option is best? The current estate includes 42 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  4. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads

Correct answer: D

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without relying on a one-off operator runbook.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without relying on a one-off operator runbook.

C: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without relying on a one-off operator runbook.

D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 9

While conducting a new workload design, the cloud financial management lead at Bellows University needs to identify oversized compute resources and costly storage patterns before changing the architecture without relying on a one-off operator runbook. Which architecture decision best matches the stated constraints? The current estate includes 49 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  2. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out
  3. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  4. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership

Correct answer: D

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without relying on a one-off operator runbook.

B: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without relying on a one-off operator runbook.

C: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without relying on a one-off operator runbook.

D: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 10

Which AWS architecture principle or service combination best addresses this requirement for Blue Yonder Airlines: forecast future spend and alert teams before budgets are exceeded while keeping the pattern scalable as the organization adds accounts? The current estate includes 9 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  2. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  3. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  4. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate

Correct answer: C

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

C: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 11

City Power operates a healthcare records application. In a global expansion project, the cloud platform architect must compare Reserved Instances and Savings Plans for a stable production footprint while keeping the pattern scalable as the organization adds accounts. Which option should be recommended? The current estate includes 16 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  2. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations

Correct answer: A

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

B: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 12

A site reliability architect at Proseware Labs is reviewing a enterprise ERP system. The business requires the team to identify oversized compute resources and costly storage patterns before changing the architecture while keeping the pattern scalable as the organization adds accounts. Which design most directly satisfies the requirement? The current estate includes 23 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  2. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  3. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  4. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations

Correct answer: B

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

C: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

D: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 13

Southridge Video is changing its data lake platform as part of a migration wave planning session. Which AWS approach best enables the team to forecast future spend and alert teams before budgets are exceeded without granting broad administrator permissions? The current estate includes 30 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  4. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access

Correct answer: B

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without granting broad administrator permissions.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without granting broad administrator permissions.

D: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without granting broad administrator permissions.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work without granting broad administrator permissions.

Question 14

An architecture board at Woodgrove Bank asks the principal solutions architect to compare Reserved Instances and Savings Plans for a stable production footprint without granting broad administrator permissions for a customer-facing API. Which recommendation is most appropriate? The current estate includes 37 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  2. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  3. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  4. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out

Correct answer: C

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without granting broad administrator permissions.

B: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without granting broad administrator permissions.

C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

D: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without granting broad administrator permissions.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work without granting broad administrator permissions.

Question 15

Relecloud Systems is documenting its target-state architecture. Which choice most accurately addresses the need to identify oversized compute resources and costly storage patterns before changing the architecture without granting broad administrator permissions? The current estate includes 44 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations
  2. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  3. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  4. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering

Correct answer: B

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without granting broad administrator permissions.

B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without granting broad administrator permissions.

D: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without granting broad administrator permissions.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work without granting broad administrator permissions.

Question 16

Fabrikam Health has already validated the surrounding application components. The remaining architecture requirement for its enterprise ERP system is to forecast future spend and alert teams before budgets are exceeded while preferring managed AWS capabilities over bespoke infrastructure. Which option is best? The current estate includes 4 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  4. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload

Correct answer: B

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

D: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 17

While conducting a production readiness review, the cloud financial management lead at Trey Research needs to compare Reserved Instances and Savings Plans for a stable production footprint while preferring managed AWS capabilities over bespoke infrastructure. Which architecture decision best matches the stated constraints? The current estate includes 11 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  2. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  3. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  4. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs

Correct answer: C

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

B: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 18

During a architecture review at Northwind Media, the security architect is designing a customer-facing API. The requirement is to identify oversized compute resources and costly storage patterns before changing the architecture while preferring managed AWS capabilities over bespoke infrastructure. Which architecture is the best fit? The current estate includes 18 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  2. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  3. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  4. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership

Correct answer: D

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

D: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 19

Coho Financial operates a healthcare records application. In a hybrid connectivity redesign, the cloud platform architect must forecast future spend and alert teams before budgets are exceeded while enabling the pattern to be reused consistently across organizational units. Which option should be recommended? The current estate includes 25 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate

Correct answer: B

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 20

A principal architect asks which AWS approach is intended to compare Reserved Instances and Savings Plans for a stable production footprint while enabling the pattern to be reused consistently across organizational units. What is the best answer? The current estate includes 32 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  2. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  3. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  4. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads

Correct answer: D

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

C: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 21

Fourth Coffee is changing its data lake platform as part of a new workload design. Which AWS approach best enables the team to identify oversized compute resources and costly storage patterns before changing the architecture while enabling the pattern to be reused consistently across organizational units? The current estate includes 39 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  2. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  3. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  4. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs

Correct answer: A

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

C: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 22

An architecture board at Consolidated Messenger asks the principal solutions architect to forecast future spend and alert teams before budgets are exceeded without introducing an unrelated application rewrite for a customer-facing API. Which recommendation is most appropriate? The current estate includes 46 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out
  2. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  3. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  4. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs

Correct answer: C

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without introducing an unrelated application rewrite.

B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without introducing an unrelated application rewrite.

C: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of without introducing an unrelated application rewrite.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 23

For a healthcare records application at Litware Manufacturing, a global expansion project identifies one priority: compare Reserved Instances and Savings Plans for a stable production footprint without introducing an unrelated application rewrite. Which AWS design should the team choose? The current estate includes 6 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  2. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  3. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  4. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads

Correct answer: D

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without introducing an unrelated application rewrite.

B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without introducing an unrelated application rewrite.

C: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of without introducing an unrelated application rewrite.

D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 24

Humongous Insurance has already validated the surrounding application components. The remaining architecture requirement for its enterprise ERP system is to identify oversized compute resources and costly storage patterns before changing the architecture without introducing an unrelated application rewrite. Which option is best? The current estate includes 13 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  2. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads

Correct answer: A

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

B: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without introducing an unrelated application rewrite.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without introducing an unrelated application rewrite.

D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of without introducing an unrelated application rewrite.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 25

Following an acquisition, Tailspin Logistics is rationalizing its data lake platform. The architecture board documented two acceptance criteria: forecast future spend and alert teams before budgets are exceeded; and the solution must do so while minimizing manual intervention during steady-state operations. Which target-state recommendation should the cloud financial management lead approve? The current estate includes 20 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  2. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  3. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  4. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts

Correct answer: D

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

Option review:

A: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while minimizing manual intervention during steady-state operations.

B: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while minimizing manual intervention during steady-state operations.

C: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while minimizing manual intervention during steady-state operations.

D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work while minimizing manual intervention during steady-state operations.

Question 26

Following an acquisition, Alpine Sports is rationalizing its customer-facing API. The architecture board documented two acceptance criteria: compare Reserved Instances and Savings Plans for a stable production footprint; and the solution must do so while minimizing manual intervention during steady-state operations. Which target-state recommendation should the security architect approve? The current estate includes 27 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  2. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  3. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  4. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload

Correct answer: B

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

Option review:

A: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while minimizing manual intervention during steady-state operations.

B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

C: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while minimizing manual intervention during steady-state operations.

D: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while minimizing manual intervention during steady-state operations.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work while minimizing manual intervention during steady-state operations.

Question 27

Following an acquisition, Adventure Works is rationalizing its healthcare records application. The architecture board documented two acceptance criteria: identify oversized compute resources and costly storage patterns before changing the architecture; and the solution must do so while minimizing manual intervention during steady-state operations. Which target-state recommendation should the cloud platform architect approve? The current estate includes 34 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  2. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  3. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  4. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths

Correct answer: B

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

Option review:

A: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while minimizing manual intervention during steady-state operations.

B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

C: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while minimizing manual intervention during steady-state operations.

D: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while minimizing manual intervention during steady-state operations.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work while minimizing manual intervention during steady-state operations.

Question 28

Following an acquisition, VanArsdel Energy is rationalizing its enterprise ERP system. The architecture board documented two acceptance criteria: forecast future spend and alert teams before budgets are exceeded; and the solution must do so while keeping future troubleshooting straightforward with native telemetry. Which target-state recommendation should the site reliability architect approve? The current estate includes 41 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  4. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation

Correct answer: B

Why: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while keeping future troubleshooting straightforward with native telemetry.

Option review:

A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This directly addresses the primary requirement and remains appropriate while keeping future troubleshooting straightforward with native telemetry.

C: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to forecast future spend and alert teams before budgets are exceeded under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

Learning point: Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts. AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. In this variant, the decision also has to work while keeping future troubleshooting straightforward with native telemetry.

Question 29

Following an acquisition, Contoso Retail is rationalizing its data lake platform. The architecture board documented two acceptance criteria: compare Reserved Instances and Savings Plans for a stable production footprint; and the solution must do so while keeping future troubleshooting straightforward with native telemetry. Which target-state recommendation should the migration architect approve? The current estate includes 48 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  2. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  3. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out
  4. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads

Correct answer: D

Why: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while keeping future troubleshooting straightforward with native telemetry.

Option review:

A: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

C: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to compare Reserved Instances and Savings Plans for a stable production footprint under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This directly addresses the primary requirement and remains appropriate while keeping future troubleshooting straightforward with native telemetry.

Learning point: Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads. AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. In this variant, the decision also has to work while keeping future troubleshooting straightforward with native telemetry.

Question 30

Following an acquisition, Lucerne Publishing is rationalizing its customer-facing API. The architecture board documented two acceptance criteria: identify oversized compute resources and costly storage patterns before changing the architecture; and the solution must do so while keeping future troubleshooting straightforward with native telemetry. Which target-state recommendation should the principal solutions architect approve? The current estate includes 8 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out
  2. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  3. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  4. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership

Correct answer: D

Why: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while keeping future troubleshooting straightforward with native telemetry.

Option review:

A: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

C: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to identify oversized compute resources and costly storage patterns before changing the architecture under the additional constraint of while keeping future troubleshooting straightforward with native telemetry.

D: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This directly addresses the primary requirement and remains appropriate while keeping future troubleshooting straightforward with native telemetry.

Learning point: Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership. Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. In this variant, the decision also has to work while keeping future troubleshooting straightforward with native telemetry.

Popular posts

img