Amazon AWS Solutions Architect Professional SAP-C02 Least Privilege Network Security Encryption Practice Test
Domain 2.3 • 25 original questions
This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on least privilege network security encryption and attack mitigation through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
A principal solutions architect at Fabrikam Health is reviewing a customer-facing API. The business requires the team to separate human and workload credentials while eliminating unnecessary standing access while minimizing ongoing operational burden. Which design most directly satisfies the requirement? The current estate includes 8 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: B
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while minimizing ongoing operational burden.
Option review:
A: Capacity planning must include service quotas, and Route 53 routing policies should be selected based on health, latency, geography, or other stated routing goals. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while minimizing ongoing operational burden.
B: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while minimizing ongoing operational burden.
C: Replication supports continuity, backups protect against logical loss, and monitoring/automation reduce detection and recovery time for common failures. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while minimizing ongoing operational burden.
D: AWS Well-Architected decisions should balance reliability, security, operational excellence, performance efficiency, and cost instead of optimizing a single pillar in isolation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while minimizing ongoing operational burden.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work while minimizing ongoing operational burden.
Trey Research is changing its healthcare records application as part of a global expansion project. Which AWS approach best enables the team to express network policy at the appropriate subnet and workload layers while minimizing ongoing operational burden? The current estate includes 15 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: B
Why: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while minimizing ongoing operational burden.
Option review:
A: Performance architecture should start from access patterns and measurable objectives, not from one default storage service. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while minimizing ongoing operational burden.
B: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while minimizing ongoing operational burden.
C: Versioned infrastructure and automated deployment pipelines reduce drift and make failed changes repeatable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while minimizing ongoing operational burden.
D: Data-transfer architecture can materially affect cost; expenditure controls and service selection should be designed with traffic flows and business value in mind. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while minimizing ongoing operational burden.
Learning point: Use narrowly scoped security groups and network ACLs as required, and use VPC endpoints or PrivateLink for supported private service integrations. Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. In this variant, the decision also has to work while minimizing ongoing operational burden.
An architecture board at Northwind Media asks the enterprise architect to protect a public application from common web exploits and volumetric attacks while encrypting data end to end while minimizing ongoing operational burden for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 22 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: B
Why: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while minimizing ongoing operational burden.
Option review:
A: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while minimizing ongoing operational burden.
B: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while minimizing ongoing operational burden.
C: Managed services and Systems Manager can reduce custom infrastructure administration while keeping configuration and operational tasks repeatable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while minimizing ongoing operational burden.
D: Professional solution design combines multiple patterns so capacity, failure, and latency are isolated rather than propagated across the stack. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while minimizing ongoing operational burden.
Learning point: Use KMS/service-native encryption and TLS for data protection, with AWS WAF, Shield, and managed security services as appropriate for the threat model. Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. In this variant, the decision also has to work while minimizing ongoing operational burden.
For a data lake platform at Coho Financial, a migration wave planning session identifies one priority: separate human and workload credentials while eliminating unnecessary standing access while supporting automated and repeatable deployment. Which AWS design should the team choose? The current estate includes 29 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.
Correct answer: B
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while supporting automated and repeatable deployment.
Option review:
A: Capacity planning must include service quotas, and Route 53 routing policies should be selected based on health, latency, geography, or other stated routing goals. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while supporting automated and repeatable deployment.
B: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while supporting automated and repeatable deployment.
C: Professional architectures should treat upgrades as controlled changes with measurable entry, success, and rollback conditions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while supporting automated and repeatable deployment.
D: AWS Well-Architected decisions should balance reliability, security, operational excellence, performance efficiency, and cost instead of optimizing a single pillar in isolation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while supporting automated and repeatable deployment.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work while supporting automated and repeatable deployment.
A principal architect asks which AWS approach is intended to express network policy at the appropriate subnet and workload layers while supporting automated and repeatable deployment. What is the best answer? The current estate includes 36 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while supporting automated and repeatable deployment.
Option review:
A: AWS Well-Architected decisions should balance reliability, security, operational excellence, performance efficiency, and cost instead of optimizing a single pillar in isolation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while supporting automated and repeatable deployment.
B: Replication supports continuity, backups protect against logical loss, and monitoring/automation reduce detection and recovery time for common failures. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while supporting automated and repeatable deployment.
C: Professional solution design combines multiple patterns so capacity, failure, and latency are isolated rather than propagated across the stack. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while supporting automated and repeatable deployment.
D: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while supporting automated and repeatable deployment.
Learning point: Use narrowly scoped security groups and network ACLs as required, and use VPC endpoints or PrivateLink for supported private service integrations. Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. In this variant, the decision also has to work while supporting automated and repeatable deployment.
While conducting a security design review, the cloud platform architect at Fourth Coffee needs to protect a public application from common web exploits and volumetric attacks while encrypting data end to end while supporting automated and repeatable deployment. Which architecture decision best matches the stated constraints? The current estate includes 43 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: C
Why: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while supporting automated and repeatable deployment.
Option review:
A: Purpose-built databases and caching patterns improve performance when selected for the actual data model, access pattern, and consistency requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while supporting automated and repeatable deployment.
B: Professional solution design combines multiple patterns so capacity, failure, and latency are isolated rather than propagated across the stack. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while supporting automated and repeatable deployment.
C: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while supporting automated and repeatable deployment.
D: Data-transfer architecture can materially affect cost; expenditure controls and service selection should be designed with traffic flows and business value in mind. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while supporting automated and repeatable deployment.
Learning point: Use KMS/service-native encryption and TLS for data protection, with AWS WAF, Shield, and managed security services as appropriate for the threat model. Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. In this variant, the decision also has to work while supporting automated and repeatable deployment.
During a modernization initiative at Consolidated Messenger, the site reliability architect is designing a enterprise ERP system. The requirement is to separate human and workload credentials while eliminating unnecessary standing access with an explicit rollback or recovery path if the change fails. Which architecture is the best fit? The current estate includes 3 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: D
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate with an explicit rollback or recovery path if the change fails.
Option review:
A: AWS global and regional infrastructure plus health-aware routing can preserve application availability when a location or component fails. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of with an explicit rollback or recovery path if the change fails.
B: A continuity design is incomplete until failover and restore procedures are tested and measured against business recovery objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of with an explicit rollback or recovery path if the change fails.
C: Managed-service adoption is valuable when it reduces undifferentiated operations without violating control, performance, or portability requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of with an explicit rollback or recovery path if the change fails.
D: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate with an explicit rollback or recovery path if the change fails.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work with an explicit rollback or recovery path if the change fails.
Litware Manufacturing operates a data lake platform. In a production readiness review, the migration architect must express network policy at the appropriate subnet and workload layers with an explicit rollback or recovery path if the change fails. Which option should be recommended? The current estate includes 10 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: C
Why: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate with an explicit rollback or recovery path if the change fails.
Option review:
A: Performance architecture should start from access patterns and measurable objectives, not from one default storage service. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of with an explicit rollback or recovery path if the change fails.
B: Storage tiering reduces cost when lifecycle transitions match real access patterns, minimum-storage-duration rules, and retrieval expectations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of with an explicit rollback or recovery path if the change fails.
C: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate with an explicit rollback or recovery path if the change fails.
D: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of with an explicit rollback or recovery path if the change fails.
Learning point: Use narrowly scoped security groups and network ACLs as required, and use VPC endpoints or PrivateLink for supported private service integrations. Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. In this variant, the decision also has to work with an explicit rollback or recovery path if the change fails.
A principal solutions architect at Humongous Insurance is reviewing a customer-facing API. The business requires the team to protect a public application from common web exploits and volumetric attacks while encrypting data end to end with an explicit rollback or recovery path if the change fails. Which design most directly satisfies the requirement? The current estate includes 17 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: A
Why: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate with an explicit rollback or recovery path if the change fails.
Option review:
A: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate with an explicit rollback or recovery path if the change fails.
B: Capacity planning must include service quotas, and Route 53 routing policies should be selected based on health, latency, geography, or other stated routing goals. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of with an explicit rollback or recovery path if the change fails.
C: AWS Well-Architected decisions should balance reliability, security, operational excellence, performance efficiency, and cost instead of optimizing a single pillar in isolation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of with an explicit rollback or recovery path if the change fails.
D: Managed services and Systems Manager can reduce custom infrastructure administration while keeping configuration and operational tasks repeatable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of with an explicit rollback or recovery path if the change fails.
Learning point: Use KMS/service-native encryption and TLS for data protection, with AWS WAF, Shield, and managed security services as appropriate for the threat model. Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. In this variant, the decision also has to work with an explicit rollback or recovery path if the change fails.
Which solution is the strongest match for the following professional-level architecture requirement: separate human and workload credentials while eliminating unnecessary standing access without introducing an unrelated application rewrite? The current estate includes 24 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.
Correct answer: C
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of without introducing an unrelated application rewrite.
B: Rightsizing addresses resource efficiency first; pricing models then reduce the cost of the correctly sized usage pattern. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of without introducing an unrelated application rewrite.
C: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
D: Managed-service adoption is valuable when it reduces undifferentiated operations without violating control, performance, or portability requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of without introducing an unrelated application rewrite.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work without introducing an unrelated application rewrite.
An architecture board at Alpine Sports asks the enterprise architect to express network policy at the appropriate subnet and workload layers without introducing an unrelated application rewrite for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 31 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: Performance architecture should start from access patterns and measurable objectives, not from one default storage service. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of without introducing an unrelated application rewrite.
B: Purpose-built databases and caching patterns improve performance when selected for the actual data model, access pattern, and consistency requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of without introducing an unrelated application rewrite.
C: Storage tiering reduces cost when lifecycle transitions match real access patterns, minimum-storage-duration rules, and retrieval expectations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of without introducing an unrelated application rewrite.
D: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Learning point: Use narrowly scoped security groups and network ACLs as required, and use VPC endpoints or PrivateLink for supported private service integrations. Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. In this variant, the decision also has to work without introducing an unrelated application rewrite.
For a data lake platform at Adventure Works, a new workload design identifies one priority: protect a public application from common web exploits and volumetric attacks while encrypting data end to end without introducing an unrelated application rewrite. Which AWS design should the team choose? The current estate includes 38 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.
Correct answer: D
Why: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: Professional architectures should treat upgrades as controlled changes with measurable entry, success, and rollback conditions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of without introducing an unrelated application rewrite.
B: Storage tiering reduces cost when lifecycle transitions match real access patterns, minimum-storage-duration rules, and retrieval expectations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of without introducing an unrelated application rewrite.
C: AWS Well-Architected decisions should balance reliability, security, operational excellence, performance efficiency, and cost instead of optimizing a single pillar in isolation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of without introducing an unrelated application rewrite.
D: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Learning point: Use KMS/service-native encryption and TLS for data protection, with AWS WAF, Shield, and managed security services as appropriate for the threat model. Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. In this variant, the decision also has to work without introducing an unrelated application rewrite.
VanArsdel Energy has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to separate human and workload credentials while eliminating unnecessary standing access while preserving least-privilege administration. Which option is best? The current estate includes 45 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: D
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while preserving least-privilege administration.
Option review:
A: A continuity design is incomplete until failover and restore procedures are tested and measured against business recovery objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while preserving least-privilege administration.
B: Elastic scaling and asynchronous decoupling reduce cascading failures and allow components to recover or scale independently. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while preserving least-privilege administration.
C: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while preserving least-privilege administration.
D: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while preserving least-privilege administration.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work while preserving least-privilege administration.
While conducting a global expansion project, the cloud platform architect at Contoso Retail needs to express network policy at the appropriate subnet and workload layers while preserving least-privilege administration. Which architecture decision best matches the stated constraints? The current estate includes 5 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: C
Why: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while preserving least-privilege administration.
Option review:
A: Reliability depends on matching redundancy to the required failure domain and using managed failover where it reduces operational risk. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while preserving least-privilege administration.
B: Professional architectures should treat upgrades as controlled changes with measurable entry, success, and rollback conditions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while preserving least-privilege administration.
C: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while preserving least-privilege administration.
D: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while preserving least-privilege administration.
Learning point: Use narrowly scoped security groups and network ACLs as required, and use VPC endpoints or PrivateLink for supported private service integrations. Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. In this variant, the decision also has to work while preserving least-privilege administration.
Which AWS architecture principle or service combination best addresses this requirement for Lucerne Publishing: protect a public application from common web exploits and volumetric attacks while encrypting data end to end while preserving least-privilege administration? The current estate includes 12 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: A
Why: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while preserving least-privilege administration.
Option review:
A: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while preserving least-privilege administration.
B: Elastic scaling and asynchronous decoupling reduce cascading failures and allow components to recover or scale independently. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while preserving least-privilege administration.
C: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while preserving least-privilege administration.
D: Data-transfer architecture can materially affect cost; expenditure controls and service selection should be designed with traffic flows and business value in mind. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while preserving least-privilege administration.
Learning point: Use KMS/service-native encryption and TLS for data protection, with AWS WAF, Shield, and managed security services as appropriate for the threat model. Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. In this variant, the decision also has to work while preserving least-privilege administration.
Correct answer: C
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while keeping the design elastic as demand changes.
Option review:
A: Storage tiering reduces cost when lifecycle transitions match real access patterns, minimum-storage-duration rules, and retrieval expectations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while keeping the design elastic as demand changes.
B: Managed services and Systems Manager can reduce custom infrastructure administration while keeping configuration and operational tasks repeatable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while keeping the design elastic as demand changes.
C: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while keeping the design elastic as demand changes.
D: Elastic scaling and asynchronous decoupling reduce cascading failures and allow components to recover or scale independently. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while keeping the design elastic as demand changes.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work while keeping the design elastic as demand changes.
A principal solutions architect at Wide World Importers is reviewing a customer-facing API. The business requires the team to express network policy at the appropriate subnet and workload layers while keeping the design elastic as demand changes. Which design most directly satisfies the requirement? The current estate includes 26 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while keeping the design elastic as demand changes.
Option review:
A: Data-transfer architecture can materially affect cost; expenditure controls and service selection should be designed with traffic flows and business value in mind. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while keeping the design elastic as demand changes.
B: Instance families provide different resource profiles; elasticity and rightsizing align capacity to workload behavior instead of static peak estimates. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while keeping the design elastic as demand changes.
C: AWS global and regional infrastructure plus health-aware routing can preserve application availability when a location or component fails. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while keeping the design elastic as demand changes.
D: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while keeping the design elastic as demand changes.
Learning point: Use narrowly scoped security groups and network ACLs as required, and use VPC endpoints or PrivateLink for supported private service integrations. Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. In this variant, the decision also has to work while keeping the design elastic as demand changes.
Bellows University is changing its healthcare records application as part of a security design review. Which AWS approach best enables the team to protect a public application from common web exploits and volumetric attacks while encrypting data end to end while keeping the design elastic as demand changes? The current estate includes 33 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: B
Why: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while keeping the design elastic as demand changes.
Option review:
A: Managed services and Systems Manager can reduce custom infrastructure administration while keeping configuration and operational tasks repeatable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while keeping the design elastic as demand changes.
B: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while keeping the design elastic as demand changes.
C: Professional architectures should treat upgrades as controlled changes with measurable entry, success, and rollback conditions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while keeping the design elastic as demand changes.
D: AWS Well-Architected decisions should balance reliability, security, operational excellence, performance efficiency, and cost instead of optimizing a single pillar in isolation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while keeping the design elastic as demand changes.
Learning point: Use KMS/service-native encryption and TLS for data protection, with AWS WAF, Shield, and managed security services as appropriate for the threat model. Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. In this variant, the decision also has to work while keeping the design elastic as demand changes.
An architecture board at Blue Yonder Airlines asks the enterprise architect to separate human and workload credentials while eliminating unnecessary standing access while using managed services when they satisfy the requirement for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 40 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: B
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while using managed services when they satisfy the requirement.
Option review:
A: A continuity design is incomplete until failover and restore procedures are tested and measured against business recovery objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while using managed services when they satisfy the requirement.
B: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while using managed services when they satisfy the requirement.
C: Instance families provide different resource profiles; elasticity and rightsizing align capacity to workload behavior instead of static peak estimates. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while using managed services when they satisfy the requirement.
D: Professional architectures should treat upgrades as controlled changes with measurable entry, success, and rollback conditions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while using managed services when they satisfy the requirement.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work while using managed services when they satisfy the requirement.
City Power is documenting its target-state architecture. Which choice most accurately addresses the need to express network policy at the appropriate subnet and workload layers while using managed services when they satisfy the requirement? The current estate includes 47 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: A
Why: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while using managed services when they satisfy the requirement.
Option review:
A: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while using managed services when they satisfy the requirement.
B: Elastic scaling and asynchronous decoupling reduce cascading failures and allow components to recover or scale independently. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while using managed services when they satisfy the requirement.
C: Rightsizing addresses resource efficiency first; pricing models then reduce the cost of the correctly sized usage pattern. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while using managed services when they satisfy the requirement.
D: Replication supports continuity, backups protect against logical loss, and monitoring/automation reduce detection and recovery time for common failures. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while using managed services when they satisfy the requirement.
Learning point: Use narrowly scoped security groups and network ACLs as required, and use VPC endpoints or PrivateLink for supported private service integrations. Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. In this variant, the decision also has to work while using managed services when they satisfy the requirement.
Proseware Labs has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to protect a public application from common web exploits and volumetric attacks while encrypting data end to end while using managed services when they satisfy the requirement. Which option is best? The current estate includes 7 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: C
Why: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while using managed services when they satisfy the requirement.
Option review:
A: Reliability depends on matching redundancy to the required failure domain and using managed failover where it reduces operational risk. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while using managed services when they satisfy the requirement.
B: Purpose-built databases and caching patterns improve performance when selected for the actual data model, access pattern, and consistency requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while using managed services when they satisfy the requirement.
C: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while using managed services when they satisfy the requirement.
D: A continuity design is incomplete until failover and restore procedures are tested and measured against business recovery objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while using managed services when they satisfy the requirement.
Learning point: Use KMS/service-native encryption and TLS for data protection, with AWS WAF, Shield, and managed security services as appropriate for the threat model. Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. In this variant, the decision also has to work while using managed services when they satisfy the requirement.
While conducting a hybrid connectivity redesign, the cloud platform architect at Southridge Video needs to separate human and workload credentials while eliminating unnecessary standing access while keeping observability sufficient to validate the result. Which architecture decision best matches the stated constraints? The current estate includes 14 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.
Correct answer: B
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while keeping observability sufficient to validate the result.
Option review:
A: Versioned infrastructure and automated deployment pipelines reduce drift and make failed changes repeatable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while keeping observability sufficient to validate the result.
B: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while keeping observability sufficient to validate the result.
C: Instance families provide different resource profiles; elasticity and rightsizing align capacity to workload behavior instead of static peak estimates. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while keeping observability sufficient to validate the result.
D: AWS global and regional infrastructure plus health-aware routing can preserve application availability when a location or component fails. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while keeping observability sufficient to validate the result.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work while keeping observability sufficient to validate the result.
During a resilience assessment at Woodgrove Bank, the site reliability architect is designing a enterprise ERP system. The requirement is to express network policy at the appropriate subnet and workload layers while keeping observability sufficient to validate the result. Which architecture is the best fit? The current estate includes 21 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: A
Why: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while keeping observability sufficient to validate the result.
Option review:
A: Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. This directly addresses the primary requirement and remains appropriate while keeping observability sufficient to validate the result.
B: Reliability depends on matching redundancy to the required failure domain and using managed failover where it reduces operational risk. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while keeping observability sufficient to validate the result.
C: AWS global and regional infrastructure plus health-aware routing can preserve application availability when a location or component fails. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while keeping observability sufficient to validate the result.
D: Managed-service adoption is valuable when it reduces undifferentiated operations without violating control, performance, or portability requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to express network policy at the appropriate subnet and workload layers under the additional constraint of while keeping observability sufficient to validate the result.
Learning point: Use narrowly scoped security groups and network ACLs as required, and use VPC endpoints or PrivateLink for supported private service integrations. Security groups and NACLs control network flows at different layers, while VPC endpoints avoid unnecessary public paths to supported services. In this variant, the decision also has to work while keeping observability sufficient to validate the result.
Relecloud Systems operates a data lake platform. In a new workload design, the migration architect must protect a public application from common web exploits and volumetric attacks while encrypting data end to end while keeping observability sufficient to validate the result. Which option should be recommended? The current estate includes 28 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.
Correct answer: D
Why: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while keeping observability sufficient to validate the result.
Option review:
A: AWS Well-Architected decisions should balance reliability, security, operational excellence, performance efficiency, and cost instead of optimizing a single pillar in isolation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while keeping observability sufficient to validate the result.
B: Instance families provide different resource profiles; elasticity and rightsizing align capacity to workload behavior instead of static peak estimates. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while keeping observability sufficient to validate the result.
C: Capacity planning must include service quotas, and Route 53 routing policies should be selected based on health, latency, geography, or other stated routing goals. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to protect a public application from common web exploits and volumetric attacks while encrypting data end to end under the additional constraint of while keeping observability sufficient to validate the result.
D: Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. This directly addresses the primary requirement and remains appropriate while keeping observability sufficient to validate the result.
Learning point: Use KMS/service-native encryption and TLS for data protection, with AWS WAF, Shield, and managed security services as appropriate for the threat model. Encryption protects confidentiality, while AWS WAF, Shield, and related managed services mitigate web and network attacks at scale. In this variant, the decision also has to work while keeping observability sufficient to validate the result.
Following an acquisition, Fabrikam Health is rationalizing its customer-facing API. The architecture board documented two acceptance criteria: separate human and workload credentials while eliminating unnecessary standing access; and the solution must do so while avoiding a single manual recovery dependency. Which target-state recommendation should the principal solutions architect approve? The current estate includes 35 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: A
Why: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while avoiding a single manual recovery dependency.
Option review:
A: Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. This directly addresses the primary requirement and remains appropriate while avoiding a single manual recovery dependency.
B: Reliability depends on matching redundancy to the required failure domain and using managed failover where it reduces operational risk. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while avoiding a single manual recovery dependency.
C: Rightsizing addresses resource efficiency first; pricing models then reduce the cost of the correctly sized usage pattern. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while avoiding a single manual recovery dependency.
D: AWS global and regional infrastructure plus health-aware routing can preserve application availability when a location or component fails. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to separate human and workload credentials while eliminating unnecessary standing access under the additional constraint of while avoiding a single manual recovery dependency.
Learning point: Use IAM roles or other temporary-credential patterns with least privilege, and automate patch compliance through Systems Manager or managed-service patching. Temporary scoped credentials reduce secret exposure, and automated patch workflows improve compliance without expanding application privileges. In this variant, the decision also has to work while avoiding a single manual recovery dependency.
Popular posts
Recent Posts
