Amazon AWS Solutions Architect Professional SAP-C02 Cross-Account Identity Encryption Practice Test

 

Domain 1.2 • 25 original questions

This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on cross-account identity encryption and central security controls through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

An architecture board at Blue Yonder Airlines asks the site reliability architect to integrate an enterprise identity provider with AWS account access and permission sets while keeping administration centralized across accounts for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 25 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  2. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  3. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  4. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs

Correct answer: C

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while keeping administration centralized across accounts.

B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while keeping administration centralized across accounts.

C: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while keeping administration centralized across accounts.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 2

For a data lake platform at City Power, a production readiness review identifies one priority: use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal while keeping administration centralized across accounts. Which AWS design should the team choose? The current estate includes 32 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  2. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out

Correct answer: B

Why: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while keeping administration centralized across accounts.

B: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while keeping administration centralized across accounts.

D: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while keeping administration centralized across accounts.

Learning point: Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload. KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 3

Proseware Labs has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to aggregate security findings and API audit records from many accounts into a security account while keeping administration centralized across accounts. Which option is best? The current estate includes 39 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  2. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  3. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  4. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations

Correct answer: B

Why: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

Option review:

A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while keeping administration centralized across accounts.

B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.

C: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while keeping administration centralized across accounts.

D: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while keeping administration centralized across accounts.

Learning point: Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration. Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. In this variant, the decision also has to work while keeping administration centralized across accounts.

Question 4

While conducting a hybrid connectivity redesign, the network architect at Southridge Video needs to integrate an enterprise identity provider with AWS account access and permission sets while preserving AWS-native auditability and measurable health signals. Which architecture decision best matches the stated constraints? The current estate includes 46 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations
  2. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  3. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  4. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access

Correct answer: D

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while preserving AWS-native auditability and measurable health signals.

B: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while preserving AWS-native auditability and measurable health signals.

C: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while preserving AWS-native auditability and measurable health signals.

D: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 5

Which AWS architecture principle or service combination best addresses this requirement for Woodgrove Bank: use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal while preserving AWS-native auditability and measurable health signals? The current estate includes 6 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  2. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  3. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads
  4. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate

Correct answer: B

Why: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while preserving AWS-native auditability and measurable health signals.

B: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while preserving AWS-native auditability and measurable health signals.

D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while preserving AWS-native auditability and measurable health signals.

Learning point: Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload. KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 6

Relecloud Systems operates a data lake platform. In a new workload design, the cloud financial management lead must aggregate security findings and API audit records from many accounts into a security account while preserving AWS-native auditability and measurable health signals. Which option should be recommended? The current estate includes 13 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  2. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  3. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations
  4. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts

Correct answer: B

Why: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

Option review:

A: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while preserving AWS-native auditability and measurable health signals.

B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.

C: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while preserving AWS-native auditability and measurable health signals.

D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while preserving AWS-native auditability and measurable health signals.

Learning point: Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration. Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.

Question 7

A security architect at Fabrikam Health is reviewing a customer-facing API. The business requires the team to integrate an enterprise identity provider with AWS account access and permission sets without relying on a one-off operator runbook. Which design most directly satisfies the requirement? The current estate includes 20 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation
  2. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  3. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  4. Match Savings Plans or Reserved Instances to predictable committed usage and use Spot Instances only for interruption-tolerant workloads

Correct answer: C

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without relying on a one-off operator runbook.

B: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without relying on a one-off operator runbook.

C: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without relying on a one-off operator runbook.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 8

Trey Research is changing its healthcare records application as part of a global expansion project. Which AWS approach best enables the team to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal without relying on a one-off operator runbook? The current estate includes 27 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  2. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  3. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  4. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts

Correct answer: B

Why: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without relying on a one-off operator runbook.

B: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

C: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without relying on a one-off operator runbook.

D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without relying on a one-off operator runbook.

Learning point: Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload. KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 9

An architecture board at Northwind Media asks the site reliability architect to aggregate security findings and API audit records from many accounts into a security account without relying on a one-off operator runbook for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 34 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  4. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration

Correct answer: D

Why: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Option review:

A: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without relying on a one-off operator runbook.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without relying on a one-off operator runbook.

C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without relying on a one-off operator runbook.

D: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.

Learning point: Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration. Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. In this variant, the decision also has to work without relying on a one-off operator runbook.

Question 10

Coho Financial is documenting its target-state architecture. Which choice most accurately addresses the need to integrate an enterprise identity provider with AWS account access and permission sets while keeping the pattern scalable as the organization adds accounts? The current estate includes 41 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  4. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out

Correct answer: A

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

C: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

D: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 11

Lamna Healthcare has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal while keeping the pattern scalable as the organization adds accounts. Which option is best? The current estate includes 48 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out
  2. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  3. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  4. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts

Correct answer: B

Why: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

B: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

Learning point: Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload. KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 12

While conducting a security design review, the network architect at Fourth Coffee needs to aggregate security findings and API audit records from many accounts into a security account while keeping the pattern scalable as the organization adds accounts. Which architecture decision best matches the stated constraints? The current estate includes 8 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  2. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts
  3. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  4. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations

Correct answer: A

Why: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

Option review:

A: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.

B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

C: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while keeping the pattern scalable as the organization adds accounts.

Learning point: Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration. Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.

Question 13

During a modernization initiative at Consolidated Messenger, the enterprise architect is designing a enterprise ERP system. The requirement is to integrate an enterprise identity provider with AWS account access and permission sets without granting broad administrator permissions. Which architecture is the best fit? The current estate includes 15 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  2. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  3. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  4. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration

Correct answer: A

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without granting broad administrator permissions.

C: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without granting broad administrator permissions.

D: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without granting broad administrator permissions.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work without granting broad administrator permissions.

Question 14

Litware Manufacturing operates a data lake platform. In a production readiness review, the cloud financial management lead must use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal without granting broad administrator permissions. Which option should be recommended? The current estate includes 22 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate
  2. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  3. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  4. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations

Correct answer: C

Why: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without granting broad administrator permissions.

B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without granting broad administrator permissions.

C: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

D: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without granting broad administrator permissions.

Learning point: Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload. KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. In this variant, the decision also has to work without granting broad administrator permissions.

Question 15

A principal architect asks which AWS approach is intended to aggregate security findings and API audit records from many accounts into a security account without granting broad administrator permissions. What is the best answer? The current estate includes 29 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations
  2. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  3. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  4. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration

Correct answer: D

Why: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Option review:

A: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without granting broad administrator permissions.

B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without granting broad administrator permissions.

C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without granting broad administrator permissions.

D: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.

Learning point: Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration. Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. In this variant, the decision also has to work without granting broad administrator permissions.

Question 16

Tailspin Logistics is changing its healthcare records application as part of a hybrid connectivity redesign. Which AWS approach best enables the team to integrate an enterprise identity provider with AWS account access and permission sets while preferring managed AWS capabilities over bespoke infrastructure? The current estate includes 36 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  2. Use Compute Optimizer and service visibility tools for rightsizing, and enforce cost-allocation tags for business ownership
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing

Correct answer: A

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

D: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 17

An architecture board at Alpine Sports asks the site reliability architect to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal while preferring managed AWS capabilities over bespoke infrastructure for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 43 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  2. Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths
  3. Create a non-overlapping CIDR and subnet segmentation plan, then connect only the required networks through controlled routing
  4. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload

Correct answer: D

Why: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

B: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

D: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload. KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 18

For a data lake platform at Adventure Works, a new workload design identifies one priority: aggregate security findings and API audit records from many accounts into a security account while preferring managed AWS capabilities over bespoke infrastructure. Which AWS design should the team choose? The current estate includes 3 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  2. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations
  3. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  4. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering

Correct answer: A

Why: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

Option review:

A: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.

B: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

C: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

D: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.

Learning point: Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration. Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.

Question 19

VanArsdel Energy has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to integrate an enterprise identity provider with AWS account access and permission sets while enabling the pattern to be reused consistently across organizational units. Which option is best? The current estate includes 10 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  2. Use AWS Resource Access Manager and supported shared-resource patterns under Organizations
  3. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  4. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts

Correct answer: C

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

B: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

C: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 20

Which solution is the strongest match for the following professional-level architecture requirement: use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal while enabling the pattern to be reused consistently across organizational units? The current estate includes 17 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access
  2. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  3. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  4. Use Cost Explorer, Budgets, Cost and Usage Reports, and related AWS cost tools for analysis, forecasting, and alerts

Correct answer: B

Why: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

B: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

Learning point: Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload. KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 21

During a multi-account governance review at Lucerne Publishing, the enterprise architect is designing a enterprise ERP system. The requirement is to aggregate security findings and API audit records from many accounts into a security account while enabling the pattern to be reused consistently across organizational units. Which architecture is the best fit? The current estate includes 24 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  2. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  3. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out
  4. Use Route 53 Resolver inbound and outbound endpoints with forwarding rules, and share rules where appropriate

Correct answer: A

Why: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

Option review:

A: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.

B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

C: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of while enabling the pattern to be reused consistently across organizational units.

Learning point: Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration. Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.

Question 22

  1. Datum Analytics operates a data lake platform. In a migration wave planning session, the cloud financial management lead must integrate an enterprise identity provider with AWS account access and permission sets without introducing an unrelated application rewrite. Which option should be recommended? The current estate includes 31 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.
  2. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  3. Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance
  4. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  5. Use VPC Flow Logs and related network troubleshooting tools, and use the appropriate VPC endpoint or PrivateLink integration for private service access

Correct answer: A

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

B: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without introducing an unrelated application rewrite.

C: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without introducing an unrelated application rewrite.

D: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of without introducing an unrelated application rewrite.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 23

A security architect at Wide World Importers is reviewing a customer-facing API. The business requires the team to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal without introducing an unrelated application rewrite. Which design most directly satisfies the requirement? The current estate includes 38 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  2. Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload
  3. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out
  4. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing

Correct answer: B

Why: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without introducing an unrelated application rewrite.

B: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

C: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without introducing an unrelated application rewrite.

D: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to use customer-controlled encryption keys for sensitive workloads while automating public certificate renewal under the additional constraint of without introducing an unrelated application rewrite.

Learning point: Use AWS KMS for controlled encryption keys and ACM for managed TLS certificates, with key policies and rotation/governance appropriate to the workload. KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 24

Bellows University is changing its healthcare records application as part of a security design review. Which AWS approach best enables the team to aggregate security findings and API audit records from many accounts into a security account without introducing an unrelated application rewrite? The current estate includes 45 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration
  2. Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations
  3. Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering
  4. Choose the least-complex DR pattern that demonstrably meets the required RTO and RPO, validating replication frequency and recovery automation

Correct answer: A

Why: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

Option review:

A: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.

B: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without introducing an unrelated application rewrite.

C: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without introducing an unrelated application rewrite.

D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to aggregate security findings and API audit records from many accounts into a security account under the additional constraint of without introducing an unrelated application rewrite.

Learning point: Aggregate CloudTrail and security-service findings centrally, using services such as Security Hub, Inspector, and organization-level logging with delegated security administration. Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. In this variant, the decision also has to work without introducing an unrelated application rewrite.

Question 25

Following an acquisition, Blue Yonder Airlines is rationalizing its enterprise ERP system. The architecture board documented two acceptance criteria: integrate an enterprise identity provider with AWS account access and permission sets; and the solution must do so while minimizing manual intervention during steady-state operations. Which target-state recommendation should the site reliability architect approve? The current estate includes 5 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs
  2. Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access
  3. Use AWS Backup or service-native backup features with policy-based retention, protected copies, and regular restore testing
  4. Use health checks, load balancing, Auto Scaling or managed multi-AZ capabilities so failed capacity is replaced automatically and the architecture can scale out

Correct answer: B

Why: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

Option review:

A: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while minimizing manual intervention during steady-state operations.

B: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.

C: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while minimizing manual intervention during steady-state operations.

D: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to integrate an enterprise identity provider with AWS account access and permission sets under the additional constraint of while minimizing manual intervention during steady-state operations.

Learning point: Use IAM Identity Center with the external identity source and permission sets, or assume-role patterns for scoped cross-account access. Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. In this variant, the decision also has to work while minimizing manual intervention during steady-state operations.

Popular posts

img