Amazon AWS Solutions Architect Professional SAP-C02 Continuous Improvement Architecture Review Practice Test

 

Domain 3.1-3.5 • 25 original questions

This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on continuous improvement architecture review and well-architected tradeoffs through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

An architecture board at Northwind Media asks the site reliability architect to create a remediation roadmap that addresses the highest business risk first while using measurable evidence before and after remediation for a machine learning inference service. Which recommendation is most appropriate? The current estate includes 11 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics
  2. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  3. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  4. Use centralized CloudWatch observability with actionable alarms and event-driven or Systems Manager automation for known remediation paths

Correct answer: C

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

Option review:

A: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while using measurable evidence before and after remediation.

B: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while using measurable evidence before and after remediation.

C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

D: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while using measurable evidence before and after remediation.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work while using measurable evidence before and after remediation.

Question 2

For a payment platform at Coho Financial, a migration wave planning session identifies one priority: test a proposed performance or cost change before rolling it across a large estate while using measurable evidence before and after remediation. Which AWS design should the team choose? The current estate includes 18 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  2. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  3. Treat service quotas as reliability dependencies: monitor headroom, request increases early, and test recovery capacity in the target environment
  4. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain

Correct answer: B

Why: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

Option review:

A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while using measurable evidence before and after remediation.

B: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

C: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while using measurable evidence before and after remediation.

D: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while using measurable evidence before and after remediation.

Learning point: Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels. Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. In this variant, the decision also has to work while using measurable evidence before and after remediation.

Question 3

Lamna Healthcare has already validated the surrounding application components. The remaining architecture requirement for its IoT ingestion service is to automate safe responses while retaining human approval for higher-risk actions while using measurable evidence before and after remediation. Which option is best? The current estate includes 25 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  2. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation
  3. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  4. Define measurable KPIs/SLOs, instrument the relevant components, and use CloudWatch or service metrics to isolate the actual bottleneck before changing architecture

Correct answer: C

Why: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

Option review:

A: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while using measurable evidence before and after remediation.

B: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while using measurable evidence before and after remediation.

C: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

D: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while using measurable evidence before and after remediation.

Learning point: Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it. Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. In this variant, the decision also has to work while using measurable evidence before and after remediation.

Question 4

While conducting a security design review, the network architect at Fourth Coffee needs to create a remediation roadmap that addresses the highest business risk first without making unrelated architecture changes. Which architecture decision best matches the stated constraints? The current estate includes 32 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  2. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures
  3. Use Cost Explorer, Compute Optimizer, Trusted Advisor, and service inventory data to identify idle or overprovisioned resources, then remove or rightsize them safely
  4. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation

Correct answer: A

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

Option review:

A: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

B: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of without making unrelated architecture changes.

C: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of without making unrelated architecture changes.

D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of without making unrelated architecture changes.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work without making unrelated architecture changes.

Question 5

Which AWS architecture principle or service combination best addresses this requirement for Consolidated Messenger: test a proposed performance or cost change before rolling it across a large estate without making unrelated architecture changes? The current estate includes 39 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Define measurable KPIs/SLOs, instrument the relevant components, and use CloudWatch or service metrics to isolate the actual bottleneck before changing architecture
  2. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  3. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  4. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation

Correct answer: C

Why: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

Option review:

A: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of without making unrelated architecture changes.

B: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of without making unrelated architecture changes.

C: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of without making unrelated architecture changes.

Learning point: Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels. Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. In this variant, the decision also has to work without making unrelated architecture changes.

Question 6

Litware Manufacturing operates a payment platform. In a production readiness review, the cloud financial management lead must automate safe responses while retaining human approval for higher-risk actions without making unrelated architecture changes. Which option should be recommended? The current estate includes 46 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  2. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  3. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  4. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation

Correct answer: C

Why: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

Option review:

A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of without making unrelated architecture changes.

B: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of without making unrelated architecture changes.

C: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of without making unrelated architecture changes.

Learning point: Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it. Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. In this variant, the decision also has to work without making unrelated architecture changes.

Question 7

A security architect at Humongous Insurance is reviewing a IoT ingestion service. The business requires the team to create a remediation roadmap that addresses the highest business risk first while preserving the workload service objective during the improvement. Which design most directly satisfies the requirement? The current estate includes 6 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  2. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics
  3. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures
  4. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact

Correct answer: D

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

Option review:

A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while preserving the workload service objective during the improvement.

B: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while preserving the workload service objective during the improvement.

C: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while preserving the workload service objective during the improvement.

D: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work while preserving the workload service objective during the improvement.

Question 8

Tailspin Logistics is changing its batch settlement service as part of a hybrid connectivity redesign. Which AWS approach best enables the team to test a proposed performance or cost change before rolling it across a large estate while preserving the workload service objective during the improvement? The current estate includes 13 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  2. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints
  3. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  4. Treat service quotas as reliability dependencies: monitor headroom, request increases early, and test recovery capacity in the target environment

Correct answer: C

Why: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

Option review:

A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while preserving the workload service objective during the improvement.

B: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while preserving the workload service objective during the improvement.

C: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

D: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while preserving the workload service objective during the improvement.

Learning point: Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels. Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. In this variant, the decision also has to work while preserving the workload service objective during the improvement.

Question 9

An architecture board at Alpine Sports asks the site reliability architect to automate safe responses while retaining human approval for higher-risk actions while preserving the workload service objective during the improvement for a machine learning inference service. Which recommendation is most appropriate? The current estate includes 20 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use centralized CloudWatch observability with actionable alarms and event-driven or Systems Manager automation for known remediation paths
  2. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain
  3. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  4. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints

Correct answer: C

Why: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

Option review:

A: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while preserving the workload service objective during the improvement.

B: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while preserving the workload service objective during the improvement.

C: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

D: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while preserving the workload service objective during the improvement.

Learning point: Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it. Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. In this variant, the decision also has to work while preserving the workload service objective during the improvement.

Question 10

Adventure Works is documenting its target-state architecture. Which choice most accurately addresses the need to create a remediation roadmap that addresses the highest business risk first with a staged validation path before full rollout? The current estate includes 27 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics
  2. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  3. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures
  4. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints

Correct answer: B

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

Option review:

A: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of with a staged validation path before full rollout.

B: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

C: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of with a staged validation path before full rollout.

D: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of with a staged validation path before full rollout.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work with a staged validation path before full rollout.

Question 11

VanArsdel Energy has already validated the surrounding application components. The remaining architecture requirement for its IoT ingestion service is to test a proposed performance or cost change before rolling it across a large estate with a staged validation path before full rollout. Which option is best? The current estate includes 34 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation
  2. Use Cost and Usage Reports or equivalent detailed billing data with cost-allocation tags, Budgets, and alarms to analyze transfer charges and assign ownership
  3. Treat service quotas as reliability dependencies: monitor headroom, request increases early, and test recovery capacity in the target environment
  4. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels

Correct answer: D

Why: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

Option review:

A: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of with a staged validation path before full rollout.

B: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of with a staged validation path before full rollout.

C: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of with a staged validation path before full rollout.

D: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

Learning point: Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels. Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. In this variant, the decision also has to work with a staged validation path before full rollout.

Question 12

While conducting a global expansion project, the network architect at Contoso Retail needs to automate safe responses while retaining human approval for higher-risk actions with a staged validation path before full rollout. Which architecture decision best matches the stated constraints? The current estate includes 41 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  2. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints
  3. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  4. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics

Correct answer: A

Why: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

Option review:

A: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

B: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of with a staged validation path before full rollout.

C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of with a staged validation path before full rollout.

D: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of with a staged validation path before full rollout.

Learning point: Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it. Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. In this variant, the decision also has to work with a staged validation path before full rollout.

Question 13

During a multi-account governance review at Lucerne Publishing, the enterprise architect is designing a machine learning inference service. The requirement is to create a remediation roadmap that addresses the highest business risk first while reducing repetitive manual operations. Which architecture is the best fit? The current estate includes 48 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use observed growth trends to add replication, load balancing, and Auto Scaling or managed elastic features that can replace failed capacity
  2. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  3. Use Cost and Usage Reports or equivalent detailed billing data with cost-allocation tags, Budgets, and alarms to analyze transfer charges and assign ownership
  4. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact

Correct answer: D

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Option review:

A: Growth planning should combine replication and elastic scaling so the system maintains capacity and recovers automatically as demand changes. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while reducing repetitive manual operations.

B: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while reducing repetitive manual operations.

C: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while reducing repetitive manual operations.

D: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work while reducing repetitive manual operations.

Question 14

  1. Datum Analytics operates a payment platform. In a migration wave planning session, the cloud financial management lead must test a proposed performance or cost change before rolling it across a large estate while reducing repetitive manual operations. Which option should be recommended? The current estate includes 8 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.
  2. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  3. Use centralized CloudWatch observability with actionable alarms and event-driven or Systems Manager automation for known remediation paths
  4. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain
  5. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures

Correct answer: A

Why: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Option review:

A: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

B: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while reducing repetitive manual operations.

C: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while reducing repetitive manual operations.

D: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while reducing repetitive manual operations.

Learning point: Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels. Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. In this variant, the decision also has to work while reducing repetitive manual operations.

Question 15

A principal architect asks which AWS approach is intended to automate safe responses while retaining human approval for higher-risk actions while reducing repetitive manual operations. What is the best answer? The current estate includes 15 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  2. Define measurable KPIs/SLOs, instrument the relevant components, and use CloudWatch or service metrics to isolate the actual bottleneck before changing architecture
  3. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  4. Use Cost Explorer, Compute Optimizer, Trusted Advisor, and service inventory data to identify idle or overprovisioned resources, then remove or rightsize them safely

Correct answer: C

Why: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Option review:

A: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while reducing repetitive manual operations.

B: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while reducing repetitive manual operations.

C: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

D: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while reducing repetitive manual operations.

Learning point: Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it. Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. In this variant, the decision also has to work while reducing repetitive manual operations.

Question 16

Bellows University is changing its batch settlement service as part of a security design review. Which AWS approach best enables the team to create a remediation roadmap that addresses the highest business risk first while retaining AWS-native traceability for the change? The current estate includes 22 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  2. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints
  3. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  4. Use centralized CloudWatch observability with actionable alarms and event-driven or Systems Manager automation for known remediation paths

Correct answer: C

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

Option review:

A: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while retaining AWS-native traceability for the change.

B: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while retaining AWS-native traceability for the change.

C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

D: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while retaining AWS-native traceability for the change.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work while retaining AWS-native traceability for the change.

Question 17

An architecture board at Blue Yonder Airlines asks the site reliability architect to test a proposed performance or cost change before rolling it across a large estate while retaining AWS-native traceability for the change for a machine learning inference service. Which recommendation is most appropriate? The current estate includes 29 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  2. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  3. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures
  4. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints

Correct answer: A

Why: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

Option review:

A: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

B: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while retaining AWS-native traceability for the change.

C: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while retaining AWS-native traceability for the change.

D: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while retaining AWS-native traceability for the change.

Learning point: Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels. Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. In this variant, the decision also has to work while retaining AWS-native traceability for the change.

Question 18

For a payment platform at City Power, a production readiness review identifies one priority: automate safe responses while retaining human approval for higher-risk actions while retaining AWS-native traceability for the change. Which AWS design should the team choose? The current estate includes 36 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics
  2. Use the AWS global delivery or managed service that matches the workload protocol and access pattern, such as CloudFront for cacheable content or Global Accelerator for network-path optimization
  3. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  4. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it

Correct answer: D

Why: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

Option review:

A: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while retaining AWS-native traceability for the change.

B: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while retaining AWS-native traceability for the change.

C: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while retaining AWS-native traceability for the change.

D: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

Learning point: Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it. Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. In this variant, the decision also has to work while retaining AWS-native traceability for the change.

Question 19

Proseware Labs has already validated the surrounding application components. The remaining architecture requirement for its IoT ingestion service is to create a remediation roadmap that addresses the highest business risk first while prioritizing the highest-risk bottleneck first. Which option is best? The current estate includes 43 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use the AWS global delivery or managed service that matches the workload protocol and access pattern, such as CloudFront for cacheable content or Global Accelerator for network-path optimization
  2. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  3. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain
  4. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact

Correct answer: D

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Option review:

A: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while prioritizing the highest-risk bottleneck first.

B: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while prioritizing the highest-risk bottleneck first.

C: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while prioritizing the highest-risk bottleneck first.

D: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.

Question 20

Which solution is the strongest match for the following professional-level architecture requirement: test a proposed performance or cost change before rolling it across a large estate while prioritizing the highest-risk bottleneck first? The current estate includes 3 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use Cost and Usage Reports or equivalent detailed billing data with cost-allocation tags, Budgets, and alarms to analyze transfer charges and assign ownership
  2. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation
  3. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  4. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels

Correct answer: D

Why: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Option review:

A: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while prioritizing the highest-risk bottleneck first.

B: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while prioritizing the highest-risk bottleneck first.

C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while prioritizing the highest-risk bottleneck first.

D: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Learning point: Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels. Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.

Question 21

During a resilience assessment at Woodgrove Bank, the enterprise architect is designing a machine learning inference service. The requirement is to automate safe responses while retaining human approval for higher-risk actions while prioritizing the highest-risk bottleneck first. Which architecture is the best fit? The current estate includes 10 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  2. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  3. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  4. Use the AWS global delivery or managed service that matches the workload protocol and access pattern, such as CloudFront for cacheable content or Global Accelerator for network-path optimization

Correct answer: A

Why: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Option review:

A: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

B: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while prioritizing the highest-risk bottleneck first.

C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while prioritizing the highest-risk bottleneck first.

D: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while prioritizing the highest-risk bottleneck first.

Learning point: Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it. Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.

Question 22

Relecloud Systems operates a payment platform. In a new workload design, the cloud financial management lead must create a remediation roadmap that addresses the highest business risk first while keeping rollback practical if the change regresses the workload. Which option should be recommended? The current estate includes 17 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use observed growth trends to add replication, load balancing, and Auto Scaling or managed elastic features that can replace failed capacity
  2. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  3. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  4. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints

Correct answer: B

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

Option review:

A: Growth planning should combine replication and elastic scaling so the system maintains capacity and recovers automatically as demand changes. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while keeping rollback practical if the change regresses the workload.

B: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

C: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while keeping rollback practical if the change regresses the workload.

D: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while keeping rollback practical if the change regresses the workload.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.

Question 23

A security architect at Fabrikam Health is reviewing a IoT ingestion service. The business requires the team to test a proposed performance or cost change before rolling it across a large estate while keeping rollback practical if the change regresses the workload. Which design most directly satisfies the requirement? The current estate includes 24 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation
  2. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  3. Use Cost Explorer, Compute Optimizer, Trusted Advisor, and service inventory data to identify idle or overprovisioned resources, then remove or rightsize them safely
  4. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels

Correct answer: D

Why: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

Option review:

A: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while keeping rollback practical if the change regresses the workload.

B: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while keeping rollback practical if the change regresses the workload.

C: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to test a proposed performance or cost change before rolling it across a large estate under the additional constraint of while keeping rollback practical if the change regresses the workload.

D: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

Learning point: Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels. Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.

Question 24

Trey Research is changing its batch settlement service as part of a global expansion project. Which AWS approach best enables the team to automate safe responses while retaining human approval for higher-risk actions while keeping rollback practical if the change regresses the workload? The current estate includes 31 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Use Cost Explorer, Compute Optimizer, Trusted Advisor, and service inventory data to identify idle or overprovisioned resources, then remove or rightsize them safely
  2. Use the AWS global delivery or managed service that matches the workload protocol and access pattern, such as CloudFront for cacheable content or Global Accelerator for network-path optimization
  3. Use centralized CloudWatch observability with actionable alarms and event-driven or Systems Manager automation for known remediation paths
  4. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it

Correct answer: D

Why: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

Option review:

A: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while keeping rollback practical if the change regresses the workload.

B: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while keeping rollback practical if the change regresses the workload.

C: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to automate safe responses while retaining human approval for higher-risk actions under the additional constraint of while keeping rollback practical if the change regresses the workload.

D: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

Learning point: Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it. Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.

Question 25

Following an acquisition, Northwind Media is rationalizing its machine learning inference service. The architecture board documented two acceptance criteria: create a remediation roadmap that addresses the highest business risk first; and the solution must do so while basing the recommendation on observed utilization or telemetry. Which target-state recommendation should the site reliability architect approve? The current estate includes 38 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures
  2. Define measurable KPIs/SLOs, instrument the relevant components, and use CloudWatch or service metrics to isolate the actual bottleneck before changing architecture
  3. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  4. Use Cost Explorer, Compute Optimizer, Trusted Advisor, and service inventory data to identify idle or overprovisioned resources, then remove or rightsize them safely

Correct answer: C

Why: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while basing the recommendation on observed utilization or telemetry.

Option review:

A: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while basing the recommendation on observed utilization or telemetry.

B: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while basing the recommendation on observed utilization or telemetry.

C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This directly addresses the primary requirement and remains appropriate while basing the recommendation on observed utilization or telemetry.

D: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a remediation roadmap that addresses the highest business risk first under the additional constraint of while basing the recommendation on observed utilization or telemetry.

Learning point: Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact. Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. In this variant, the decision also has to work while basing the recommendation on observed utilization or telemetry.

Popular posts

img