Amazon AWS Solutions Architect Professional SAP-C02 Global Network Topology Regions Practice Test
Domain 1.1 • 26 original questions
This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on global network topology regions and multi-vpc connectivity through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
A principal solutions architect at Humongous Insurance is reviewing a IoT ingestion service. The business requires the team to balance user latency and failure isolation when selecting deployment locations while keeping administration centralized across accounts. Which design most directly satisfies the requirement? The current estate includes 15 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
Option review:
A: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while keeping administration centralized across accounts.
B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while keeping administration centralized across accounts.
C: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while keeping administration centralized across accounts.
D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work while keeping administration centralized across accounts.
Tailspin Logistics is changing its batch settlement service as part of a hybrid connectivity redesign. Which AWS approach best enables the team to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections while keeping administration centralized across accounts? The current estate includes 22 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: B
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
Option review:
A: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while keeping administration centralized across accounts.
B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while keeping administration centralized across accounts.
D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while keeping administration centralized across accounts.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work while keeping administration centralized across accounts.
An architecture board at Alpine Sports asks the enterprise architect to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection while keeping administration centralized across accounts for a machine learning inference service. Which recommendation is most appropriate? The current estate includes 29 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: A
Why: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while keeping administration centralized across accounts.
C: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while keeping administration centralized across accounts.
D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while keeping administration centralized across accounts.
Learning point: Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths. Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. In this variant, the decision also has to work while keeping administration centralized across accounts.
For a payment platform at Adventure Works, a new workload design identifies one priority: balance user latency and failure isolation when selecting deployment locations while preserving AWS-native auditability and measurable health signals. Which AWS design should the team choose? The current estate includes 36 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: C
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while preserving AWS-native auditability and measurable health signals.
B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while preserving AWS-native auditability and measurable health signals.
C: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while preserving AWS-native auditability and measurable health signals.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.
A principal architect asks which AWS approach is intended to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections while preserving AWS-native auditability and measurable health signals. What is the best answer? The current estate includes 43 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: D
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
Option review:
A: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while preserving AWS-native auditability and measurable health signals.
B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while preserving AWS-native auditability and measurable health signals.
C: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while preserving AWS-native auditability and measurable health signals.
D: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.
While conducting a global expansion project, the cloud platform architect at Contoso Retail needs to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection while preserving AWS-native auditability and measurable health signals. Which architecture decision best matches the stated constraints? The current estate includes 3 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.
Correct answer: B
Why: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
Option review:
A: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while preserving AWS-native auditability and measurable health signals.
B: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
C: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while preserving AWS-native auditability and measurable health signals.
D: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while preserving AWS-native auditability and measurable health signals.
Learning point: Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths. Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.
During a multi-account governance review at Lucerne Publishing, the site reliability architect is designing a machine learning inference service. The requirement is to balance user latency and failure isolation when selecting deployment locations without relying on a one-off operator runbook. Which architecture is the best fit? The current estate includes 10 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: B
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without relying on a one-off operator runbook.
B: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
C: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without relying on a one-off operator runbook.
D: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without relying on a one-off operator runbook.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work without relying on a one-off operator runbook.
Correct answer: B
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without relying on a one-off operator runbook.
B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
C: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without relying on a one-off operator runbook.
D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without relying on a one-off operator runbook.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work without relying on a one-off operator runbook.
A principal solutions architect at Wide World Importers is reviewing a IoT ingestion service. The business requires the team to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection without relying on a one-off operator runbook. Which design most directly satisfies the requirement? The current estate includes 24 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: A
Why: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without relying on a one-off operator runbook.
C: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without relying on a one-off operator runbook.
D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without relying on a one-off operator runbook.
Learning point: Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths. Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. In this variant, the decision also has to work without relying on a one-off operator runbook.
Which solution is the strongest match for the following professional-level architecture requirement: balance user latency and failure isolation when selecting deployment locations while keeping the pattern scalable as the organization adds accounts? The current estate includes 31 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: C
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
Option review:
A: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
C: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
D: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.
An architecture board at Blue Yonder Airlines asks the enterprise architect to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections while keeping the pattern scalable as the organization adds accounts for a machine learning inference service. Which recommendation is most appropriate? The current estate includes 38 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: B
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
Option review:
A: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
C: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.
For a payment platform at City Power, a production readiness review identifies one priority: choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection while keeping the pattern scalable as the organization adds accounts. Which AWS design should the team choose? The current estate includes 45 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.
Correct answer: D
Why: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
Option review:
A: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
B: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
C: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
D: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
Learning point: Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths. Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.
Proseware Labs has already validated the surrounding application components. The remaining architecture requirement for its IoT ingestion service is to balance user latency and failure isolation when selecting deployment locations without granting broad administrator permissions. Which option is best? The current estate includes 5 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: A
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
Option review:
A: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without granting broad administrator permissions.
C: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without granting broad administrator permissions.
D: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without granting broad administrator permissions.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work without granting broad administrator permissions.
While conducting a hybrid connectivity redesign, the cloud platform architect at Southridge Video needs to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections without granting broad administrator permissions. Which architecture decision best matches the stated constraints? The current estate includes 12 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: A
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
Option review:
A: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
B: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without granting broad administrator permissions.
C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without granting broad administrator permissions.
D: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without granting broad administrator permissions.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work without granting broad administrator permissions.
Which AWS architecture principle or service combination best addresses this requirement for Woodgrove Bank: choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection without granting broad administrator permissions? The current estate includes 19 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: A
Why: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without granting broad administrator permissions.
C: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without granting broad administrator permissions.
D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without granting broad administrator permissions.
Learning point: Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths. Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. In this variant, the decision also has to work without granting broad administrator permissions.
Relecloud Systems operates a payment platform. In a new workload design, the migration architect must balance user latency and failure isolation when selecting deployment locations while preferring managed AWS capabilities over bespoke infrastructure. Which option should be recommended? The current estate includes 26 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: C
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
Option review:
A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
B: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
C: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
D: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.
A principal solutions architect at Fabrikam Health is reviewing a IoT ingestion service. The business requires the team to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections while preferring managed AWS capabilities over bespoke infrastructure. Which design most directly satisfies the requirement? The current estate includes 33 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: B
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
Option review:
A: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
C: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.
Trey Research is changing its batch settlement service as part of a global expansion project. Which AWS approach best enables the team to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection while preferring managed AWS capabilities over bespoke infrastructure? The current estate includes 40 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.
Correct answer: A
Why: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
C: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
D: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
Learning point: Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths. Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.
An architecture board at Northwind Media asks the enterprise architect to balance user latency and failure isolation when selecting deployment locations while enabling the pattern to be reused consistently across organizational units for a machine learning inference service. Which recommendation is most appropriate? The current estate includes 47 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
Option review:
A: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
B: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.
Coho Financial is documenting its target-state architecture. Which choice most accurately addresses the need to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections while enabling the pattern to be reused consistently across organizational units? The current estate includes 7 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.
Correct answer: C
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
Option review:
A: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
C: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.
Lamna Healthcare has already validated the surrounding application components. The remaining architecture requirement for its IoT ingestion service is to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection while enabling the pattern to be reused consistently across organizational units. Which option is best? The current estate includes 14 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: A
Why: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
B: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
C: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
Learning point: Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths. Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.
While conducting a security design review, the cloud platform architect at Fourth Coffee needs to balance user latency and failure isolation when selecting deployment locations without introducing an unrelated application rewrite. Which architecture decision best matches the stated constraints? The current estate includes 21 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: D
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without introducing an unrelated application rewrite.
B: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without introducing an unrelated application rewrite.
C: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of without introducing an unrelated application rewrite.
D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work without introducing an unrelated application rewrite.
During a modernization initiative at Consolidated Messenger, the site reliability architect is designing a machine learning inference service. The requirement is to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections without introducing an unrelated application rewrite. Which architecture is the best fit? The current estate includes 28 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: D
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without introducing an unrelated application rewrite.
B: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without introducing an unrelated application rewrite.
C: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of without introducing an unrelated application rewrite.
D: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work without introducing an unrelated application rewrite.
Litware Manufacturing operates a payment platform. In a production readiness review, the migration architect must choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection without introducing an unrelated application rewrite. Which option should be recommended? The current estate includes 35 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.
Correct answer: B
Why: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without introducing an unrelated application rewrite.
B: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without introducing an unrelated application rewrite.
D: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to choose between Direct Connect and internet-based VPN for a sustained high-throughput hybrid connection under the additional constraint of without introducing an unrelated application rewrite.
Learning point: Use redundant Direct Connect connectivity for predictable private bandwidth and retain Site-to-Site VPN as appropriate for backup or lower-volume paths. Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. In this variant, the decision also has to work without introducing an unrelated application rewrite.
Following an acquisition, Humongous Insurance is rationalizing its IoT ingestion service. The architecture board documented two acceptance criteria: balance user latency and failure isolation when selecting deployment locations; and the solution must do so while minimizing manual intervention during steady-state operations. Which target-state recommendation should the principal solutions architect approve? The current estate includes 42 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.
Option review:
A: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while minimizing manual intervention during steady-state operations.
B: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while minimizing manual intervention during steady-state operations.
C: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to balance user latency and failure isolation when selecting deployment locations under the additional constraint of while minimizing manual intervention during steady-state operations.
D: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.
Learning point: Select Regions and Availability Zones by measuring user/network latency, service availability, data requirements, and failure-isolation needs. AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. In this variant, the decision also has to work while minimizing manual intervention during steady-state operations.
Following an acquisition, Tailspin Logistics is rationalizing its batch settlement service. The architecture board documented two acceptance criteria: connect dozens of VPCs across multiple accounts without building a full mesh of peering connections; and the solution must do so while minimizing manual intervention during steady-state operations. Which target-state recommendation should the network architect approve? The current estate includes 49 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: B
Why: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.
Option review:
A: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while minimizing manual intervention during steady-state operations.
B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.
C: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while minimizing manual intervention during steady-state operations.
D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to connect dozens of VPCs across multiple accounts without building a full mesh of peering connections under the additional constraint of while minimizing manual intervention during steady-state operations.
Learning point: Use AWS Transit Gateway or another hub-and-spoke AWS network design instead of a growing full mesh of VPC peering. Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. In this variant, the decision also has to work while minimizing manual intervention during steady-state operations.
Popular posts
Recent Posts
