Amazon AWS Solutions Architect Professional SAP-C02 Migration Identity Databases Governance Practice Test

 

Domain 4.2 • 24 original questions

This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on migration identity databases governance and security through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

While conducting a new workload design, the cloud financial management lead at Bellows University needs to support phased coexistence with the existing directory and workforce identity provider while fitting the change into a repeatable migration wave. Which architecture decision best matches the stated constraints? The current estate includes 26 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Select the AWS storage service whose access protocol, durability, throughput, sharing model, and hybrid requirements match the application
  2. Classify each workload using the 7Rs and document the business and technical rationale for the selected disposition
  3. Use TCO analysis plus dependency-aware wave planning to prioritize migrations and group workloads that should move together
  4. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration

Correct answer: D

Why: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while fitting the change into a repeatable migration wave.

Option review:

A: AWS storage services expose different block, file, object, and hybrid semantics; the correct target depends on how the application reads and writes data. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while fitting the change into a repeatable migration wave.

B: The 7Rs provide a portfolio decision framework; the right choice depends on constraints, value, risk, and desired modernization depth. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while fitting the change into a repeatable migration wave.

C: Migration sequence and business case should account for dependencies, operational readiness, transition costs, and expected steady-state economics. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while fitting the change into a repeatable migration wave.

D: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while fitting the change into a repeatable migration wave.

Learning point: Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration. Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. In this variant, the decision also has to work while fitting the change into a repeatable migration wave.

Question 2

During a cost optimization workshop at Blue Yonder Airlines, the security architect is designing a IoT ingestion service. The requirement is to migrate a large relational database with low downtime while converting the schema to a different database engine while fitting the change into a repeatable migration wave. Which architecture is the best fit? The current estate includes 33 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Select ECS or EKS according to orchestration requirements and use Fargate when serverless container compute meets the workload needs
  2. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required
  3. Select the purpose-built managed database that matches relational, key-value, search, or other access patterns, retaining self-managed EC2 only when required controls justify it
  4. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration

Correct answer: B

Why: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while fitting the change into a repeatable migration wave.

Option review:

A: AWS container options provide different levels of Kubernetes compatibility, AWS-native orchestration, and infrastructure ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while fitting the change into a repeatable migration wave.

B: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while fitting the change into a repeatable migration wave.

C: Database replatforming should balance access model, compatibility, scale, availability, and the operational burden the organization is willing to own. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while fitting the change into a repeatable migration wave.

D: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while fitting the change into a repeatable migration wave.

Learning point: Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required. DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. In this variant, the decision also has to work while fitting the change into a repeatable migration wave.

Question 3

City Power operates a batch settlement service. In a global expansion project, the cloud platform architect must preserve centralized governance as migration waves create more workload accounts while fitting the change into a repeatable migration wave. Which option should be recommended? The current estate includes 40 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Choose purpose-built storage and database services per component, using managed elasticity and caching where they fit the access pattern
  2. Select the purpose-built managed database that matches relational, key-value, search, or other access patterns, retaining self-managed EC2 only when required controls justify it
  3. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  4. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone

Correct answer: D

Why: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while fitting the change into a repeatable migration wave.

Option review:

A: Modernization often improves scalability and operations by replacing one generalized data platform with services optimized for object, file, key-value, relational, or cache workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while fitting the change into a repeatable migration wave.

B: Database replatforming should balance access model, compatibility, scale, availability, and the operational burden the organization is willing to own. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while fitting the change into a repeatable migration wave.

C: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while fitting the change into a repeatable migration wave.

D: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while fitting the change into a repeatable migration wave.

Learning point: Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone. A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. In this variant, the decision also has to work while fitting the change into a repeatable migration wave.

Question 4

A site reliability architect at Proseware Labs is reviewing a machine learning inference service. The business requires the team to support phased coexistence with the existing directory and workforce identity provider with a defined cutover and rollback checkpoint. Which design most directly satisfies the requirement? The current estate includes 47 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use AWS Application Migration Service for supported rehost migrations and discovery tooling to understand server and dependency scope
  2. Choose purpose-built storage and database services per component, using managed elasticity and caching where they fit the access pattern
  3. Select the AWS storage service whose access protocol, durability, throughput, sharing model, and hybrid requirements match the application
  4. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration

Correct answer: D

Why: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate with a defined cutover and rollback checkpoint.

Option review:

A: Application Migration Service is designed for lift-and-shift server migration with continuous replication and controlled cutover. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of with a defined cutover and rollback checkpoint.

B: Modernization often improves scalability and operations by replacing one generalized data platform with services optimized for object, file, key-value, relational, or cache workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of with a defined cutover and rollback checkpoint.

C: AWS storage services expose different block, file, object, and hybrid semantics; the correct target depends on how the application reads and writes data. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of with a defined cutover and rollback checkpoint.

D: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate with a defined cutover and rollback checkpoint.

Learning point: Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration. Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. In this variant, the decision also has to work with a defined cutover and rollback checkpoint.

Question 5

Which solution is the strongest match for the following professional-level architecture requirement: migrate a large relational database with low downtime while converting the schema to a different database engine with a defined cutover and rollback checkpoint? The current estate includes 7 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use appropriate Direct Connect or VPN connectivity, Route 53/DNS coexistence, encryption, and tightly scoped network/security controls for the migration path
  2. Choose purpose-built storage and database services per component, using managed elasticity and caching where they fit the access pattern
  3. Use event-driven integration with services such as SQS, SNS, EventBridge, Step Functions, and Lambda to decouple components and remove server management where appropriate
  4. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required

Correct answer: D

Why: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate with a defined cutover and rollback checkpoint.

Option review:

A: Migration networks often coexist with production; connectivity, DNS, encryption, and access controls must be designed for both the transition and final state. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of with a defined cutover and rollback checkpoint.

B: Modernization often improves scalability and operations by replacing one generalized data platform with services optimized for object, file, key-value, relational, or cache workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of with a defined cutover and rollback checkpoint.

C: Serverless and managed integration services can isolate failures, buffer bursts, and eliminate undifferentiated server operations for suitable workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of with a defined cutover and rollback checkpoint.

D: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate with a defined cutover and rollback checkpoint.

Learning point: Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required. DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. In this variant, the decision also has to work with a defined cutover and rollback checkpoint.

Question 6

An architecture board at Woodgrove Bank asks the principal solutions architect to preserve centralized governance as migration waves create more workload accounts with a defined cutover and rollback checkpoint for a IoT ingestion service. Which recommendation is most appropriate? The current estate includes 14 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone
  2. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  3. Select ECS or EKS according to orchestration requirements and use Fargate when serverless container compute meets the workload needs
  4. Classify each workload using the 7Rs and document the business and technical rationale for the selected disposition

Correct answer: A

Why: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate with a defined cutover and rollback checkpoint.

Option review:

A: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate with a defined cutover and rollback checkpoint.

B: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of with a defined cutover and rollback checkpoint.

C: AWS container options provide different levels of Kubernetes compatibility, AWS-native orchestration, and infrastructure ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of with a defined cutover and rollback checkpoint.

D: The 7Rs provide a portfolio decision framework; the right choice depends on constraints, value, risk, and desired modernization depth. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of with a defined cutover and rollback checkpoint.

Learning point: Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone. A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. In this variant, the decision also has to work with a defined cutover and rollback checkpoint.

Question 7

For a batch settlement service at Relecloud Systems, a security design review identifies one priority: support phased coexistence with the existing directory and workforce identity provider without weakening the landing-zone security baseline. Which AWS design should the team choose? The current estate includes 21 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Select EC2, Elastic Beanstalk, ECS, EKS, or Fargate based on runtime constraints, orchestration requirements, portability, and desired operational ownership
  2. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required
  3. Use migration discovery and assessment tooling such as Migration Hub and application inventory data to build a dependency-aware portfolio assessment
  4. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration

Correct answer: D

Why: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate without weakening the landing-zone security baseline.

Option review:

A: Compute and container choices should match application packaging and the amount of infrastructure and orchestration control the team actually needs. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of without weakening the landing-zone security baseline.

B: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of without weakening the landing-zone security baseline.

C: Migration planning starts with reliable inventory, ownership, dependency, and utilization data so scope and sequencing reflect the real estate. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of without weakening the landing-zone security baseline.

D: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate without weakening the landing-zone security baseline.

Learning point: Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration. Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. In this variant, the decision also has to work without weakening the landing-zone security baseline.

Question 8

Fabrikam Health has already validated the surrounding application components. The remaining architecture requirement for its machine learning inference service is to migrate a large relational database with low downtime while converting the schema to a different database engine without weakening the landing-zone security baseline. Which option is best? The current estate includes 28 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration
  2. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  3. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required
  4. Select the purpose-built managed database that matches relational, key-value, search, or other access patterns, retaining self-managed EC2 only when required controls justify it

Correct answer: C

Why: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate without weakening the landing-zone security baseline.

Option review:

A: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of without weakening the landing-zone security baseline.

B: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of without weakening the landing-zone security baseline.

C: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate without weakening the landing-zone security baseline.

D: Database replatforming should balance access model, compatibility, scale, availability, and the operational burden the organization is willing to own. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of without weakening the landing-zone security baseline.

Learning point: Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required. DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. In this variant, the decision also has to work without weakening the landing-zone security baseline.

Question 9

While conducting a production readiness review, the cloud financial management lead at Trey Research needs to preserve centralized governance as migration waves create more workload accounts without weakening the landing-zone security baseline. Which architecture decision best matches the stated constraints? The current estate includes 35 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration
  2. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone
  3. Select the AWS storage service whose access protocol, durability, throughput, sharing model, and hybrid requirements match the application
  4. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required

Correct answer: B

Why: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate without weakening the landing-zone security baseline.

Option review:

A: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of without weakening the landing-zone security baseline.

B: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate without weakening the landing-zone security baseline.

C: AWS storage services expose different block, file, object, and hybrid semantics; the correct target depends on how the application reads and writes data. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of without weakening the landing-zone security baseline.

D: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of without weakening the landing-zone security baseline.

Learning point: Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone. A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. In this variant, the decision also has to work without weakening the landing-zone security baseline.

Question 10

Which AWS architecture principle or service combination best addresses this requirement for Northwind Media: support phased coexistence with the existing directory and workforce identity provider while preserving data integrity through cutover? The current estate includes 42 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  2. Use event-driven integration with services such as SQS, SNS, EventBridge, Step Functions, and Lambda to decouple components and remove server management where appropriate
  3. Use AWS Application Migration Service for supported rehost migrations and discovery tooling to understand server and dependency scope
  4. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration

Correct answer: D

Why: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while preserving data integrity through cutover.

Option review:

A: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while preserving data integrity through cutover.

B: Serverless and managed integration services can isolate failures, buffer bursts, and eliminate undifferentiated server operations for suitable workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while preserving data integrity through cutover.

C: Application Migration Service is designed for lift-and-shift server migration with continuous replication and controlled cutover. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while preserving data integrity through cutover.

D: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while preserving data integrity through cutover.

Learning point: Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration. Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. In this variant, the decision also has to work while preserving data integrity through cutover.

Question 11

Coho Financial operates a batch settlement service. In a hybrid connectivity redesign, the cloud platform architect must migrate a large relational database with low downtime while converting the schema to a different database engine while preserving data integrity through cutover. Which option should be recommended? The current estate includes 49 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use event-driven integration with services such as SQS, SNS, EventBridge, Step Functions, and Lambda to decouple components and remove server management where appropriate
  2. Classify each workload using the 7Rs and document the business and technical rationale for the selected disposition
  3. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required
  4. Select EC2, Elastic Beanstalk, ECS, EKS, or Fargate based on runtime constraints, orchestration requirements, portability, and desired operational ownership

Correct answer: C

Why: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while preserving data integrity through cutover.

Option review:

A: Serverless and managed integration services can isolate failures, buffer bursts, and eliminate undifferentiated server operations for suitable workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while preserving data integrity through cutover.

B: The 7Rs provide a portfolio decision framework; the right choice depends on constraints, value, risk, and desired modernization depth. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while preserving data integrity through cutover.

C: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while preserving data integrity through cutover.

D: Compute and container choices should match application packaging and the amount of infrastructure and orchestration control the team actually needs. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while preserving data integrity through cutover.

Learning point: Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required. DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. In this variant, the decision also has to work while preserving data integrity through cutover.

Question 12

A site reliability architect at Lamna Healthcare is reviewing a machine learning inference service. The business requires the team to preserve centralized governance as migration waves create more workload accounts while preserving data integrity through cutover. Which design most directly satisfies the requirement? The current estate includes 9 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Select ECS or EKS according to orchestration requirements and use Fargate when serverless container compute meets the workload needs
  2. Use TCO analysis plus dependency-aware wave planning to prioritize migrations and group workloads that should move together
  3. Use AWS Application Migration Service for supported rehost migrations and discovery tooling to understand server and dependency scope
  4. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone

Correct answer: D

Why: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while preserving data integrity through cutover.

Option review:

A: AWS container options provide different levels of Kubernetes compatibility, AWS-native orchestration, and infrastructure ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while preserving data integrity through cutover.

B: Migration sequence and business case should account for dependencies, operational readiness, transition costs, and expected steady-state economics. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while preserving data integrity through cutover.

C: Application Migration Service is designed for lift-and-shift server migration with continuous replication and controlled cutover. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while preserving data integrity through cutover.

D: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while preserving data integrity through cutover.

Learning point: Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone. A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. In this variant, the decision also has to work while preserving data integrity through cutover.

Question 13

Fourth Coffee is changing its payment platform as part of a new workload design. Which AWS approach best enables the team to support phased coexistence with the existing directory and workforce identity provider while minimizing business interruption during migration? The current estate includes 16 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use TCO analysis plus dependency-aware wave planning to prioritize migrations and group workloads that should move together
  2. Select EC2, Elastic Beanstalk, ECS, EKS, or Fargate based on runtime constraints, orchestration requirements, portability, and desired operational ownership
  3. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration
  4. Select ECS or EKS according to orchestration requirements and use Fargate when serverless container compute meets the workload needs

Correct answer: C

Why: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while minimizing business interruption during migration.

Option review:

A: Migration sequence and business case should account for dependencies, operational readiness, transition costs, and expected steady-state economics. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while minimizing business interruption during migration.

B: Compute and container choices should match application packaging and the amount of infrastructure and orchestration control the team actually needs. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while minimizing business interruption during migration.

C: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while minimizing business interruption during migration.

D: AWS container options provide different levels of Kubernetes compatibility, AWS-native orchestration, and infrastructure ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while minimizing business interruption during migration.

Learning point: Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration. Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. In this variant, the decision also has to work while minimizing business interruption during migration.

Question 14

An architecture board at Consolidated Messenger asks the principal solutions architect to migrate a large relational database with low downtime while converting the schema to a different database engine while minimizing business interruption during migration for a IoT ingestion service. Which recommendation is most appropriate? The current estate includes 23 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required
  2. Use AWS Application Migration Service for supported rehost migrations and discovery tooling to understand server and dependency scope
  3. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone
  4. Select the AWS storage service whose access protocol, durability, throughput, sharing model, and hybrid requirements match the application

Correct answer: A

Why: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while minimizing business interruption during migration.

Option review:

A: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while minimizing business interruption during migration.

B: Application Migration Service is designed for lift-and-shift server migration with continuous replication and controlled cutover. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while minimizing business interruption during migration.

C: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while minimizing business interruption during migration.

D: AWS storage services expose different block, file, object, and hybrid semantics; the correct target depends on how the application reads and writes data. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while minimizing business interruption during migration.

Learning point: Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required. DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. In this variant, the decision also has to work while minimizing business interruption during migration.

Question 15

Litware Manufacturing is documenting its target-state architecture. Which choice most accurately addresses the need to preserve centralized governance as migration waves create more workload accounts while minimizing business interruption during migration? The current estate includes 30 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone
  2. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration
  3. Use event-driven integration with services such as SQS, SNS, EventBridge, Step Functions, and Lambda to decouple components and remove server management where appropriate
  4. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required

Correct answer: A

Why: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while minimizing business interruption during migration.

Option review:

A: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while minimizing business interruption during migration.

B: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while minimizing business interruption during migration.

C: Serverless and managed integration services can isolate failures, buffer bursts, and eliminate undifferentiated server operations for suitable workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while minimizing business interruption during migration.

D: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while minimizing business interruption during migration.

Learning point: Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone. A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. In this variant, the decision also has to work while minimizing business interruption during migration.

Question 16

Humongous Insurance has already validated the surrounding application components. The remaining architecture requirement for its machine learning inference service is to support phased coexistence with the existing directory and workforce identity provider while accounting for workload dependencies before sequencing the move. Which option is best? The current estate includes 37 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use migration discovery and assessment tooling such as Migration Hub and application inventory data to build a dependency-aware portfolio assessment
  2. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration
  3. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  4. Use AWS Application Migration Service for supported rehost migrations and discovery tooling to understand server and dependency scope

Correct answer: B

Why: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while accounting for workload dependencies before sequencing the move.

Option review:

A: Migration planning starts with reliable inventory, ownership, dependency, and utilization data so scope and sequencing reflect the real estate. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while accounting for workload dependencies before sequencing the move.

B: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while accounting for workload dependencies before sequencing the move.

C: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while accounting for workload dependencies before sequencing the move.

D: Application Migration Service is designed for lift-and-shift server migration with continuous replication and controlled cutover. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while accounting for workload dependencies before sequencing the move.

Learning point: Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration. Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. In this variant, the decision also has to work while accounting for workload dependencies before sequencing the move.

Question 17

While conducting a migration wave planning session, the cloud financial management lead at Tailspin Logistics needs to migrate a large relational database with low downtime while converting the schema to a different database engine while accounting for workload dependencies before sequencing the move. Which architecture decision best matches the stated constraints? The current estate includes 44 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use migration discovery and assessment tooling such as Migration Hub and application inventory data to build a dependency-aware portfolio assessment
  2. Use TCO analysis plus dependency-aware wave planning to prioritize migrations and group workloads that should move together
  3. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required
  4. Choose purpose-built storage and database services per component, using managed elasticity and caching where they fit the access pattern

Correct answer: C

Why: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while accounting for workload dependencies before sequencing the move.

Option review:

A: Migration planning starts with reliable inventory, ownership, dependency, and utilization data so scope and sequencing reflect the real estate. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while accounting for workload dependencies before sequencing the move.

B: Migration sequence and business case should account for dependencies, operational readiness, transition costs, and expected steady-state economics. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while accounting for workload dependencies before sequencing the move.

C: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while accounting for workload dependencies before sequencing the move.

D: Modernization often improves scalability and operations by replacing one generalized data platform with services optimized for object, file, key-value, relational, or cache workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while accounting for workload dependencies before sequencing the move.

Learning point: Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required. DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. In this variant, the decision also has to work while accounting for workload dependencies before sequencing the move.

Question 18

During a post-incident architecture review at Alpine Sports, the security architect is designing a IoT ingestion service. The requirement is to preserve centralized governance as migration waves create more workload accounts while accounting for workload dependencies before sequencing the move. Which architecture is the best fit? The current estate includes 4 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use AWS Application Migration Service for supported rehost migrations and discovery tooling to understand server and dependency scope
  2. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone
  3. Use migration discovery and assessment tooling such as Migration Hub and application inventory data to build a dependency-aware portfolio assessment
  4. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required

Correct answer: B

Why: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while accounting for workload dependencies before sequencing the move.

Option review:

A: Application Migration Service is designed for lift-and-shift server migration with continuous replication and controlled cutover. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while accounting for workload dependencies before sequencing the move.

B: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while accounting for workload dependencies before sequencing the move.

C: Migration planning starts with reliable inventory, ownership, dependency, and utilization data so scope and sequencing reflect the real estate. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while accounting for workload dependencies before sequencing the move.

D: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while accounting for workload dependencies before sequencing the move.

Learning point: Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone. A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. In this variant, the decision also has to work while accounting for workload dependencies before sequencing the move.

Question 19

Adventure Works operates a batch settlement service. In a security design review, the cloud platform architect must support phased coexistence with the existing directory and workforce identity provider while keeping governance consistent across destination accounts. Which option should be recommended? The current estate includes 11 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use appropriate Direct Connect or VPN connectivity, Route 53/DNS coexistence, encryption, and tightly scoped network/security controls for the migration path
  2. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration
  3. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  4. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required

Correct answer: B

Why: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while keeping governance consistent across destination accounts.

Option review:

A: Migration networks often coexist with production; connectivity, DNS, encryption, and access controls must be designed for both the transition and final state. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while keeping governance consistent across destination accounts.

B: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate while keeping governance consistent across destination accounts.

C: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while keeping governance consistent across destination accounts.

D: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of while keeping governance consistent across destination accounts.

Learning point: Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration. Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. In this variant, the decision also has to work while keeping governance consistent across destination accounts.

Question 20

A principal architect asks which AWS approach is intended to migrate a large relational database with low downtime while converting the schema to a different database engine while keeping governance consistent across destination accounts. What is the best answer? The current estate includes 18 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required
  2. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  3. Select EC2, Elastic Beanstalk, ECS, EKS, or Fargate based on runtime constraints, orchestration requirements, portability, and desired operational ownership
  4. Use event-driven integration with services such as SQS, SNS, EventBridge, Step Functions, and Lambda to decouple components and remove server management where appropriate

Correct answer: A

Why: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while keeping governance consistent across destination accounts.

Option review:

A: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate while keeping governance consistent across destination accounts.

B: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while keeping governance consistent across destination accounts.

C: Compute and container choices should match application packaging and the amount of infrastructure and orchestration control the team actually needs. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while keeping governance consistent across destination accounts.

D: Serverless and managed integration services can isolate failures, buffer bursts, and eliminate undifferentiated server operations for suitable workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of while keeping governance consistent across destination accounts.

Learning point: Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required. DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. In this variant, the decision also has to work while keeping governance consistent across destination accounts.

Question 21

Contoso Retail is changing its payment platform as part of a production readiness review. Which AWS approach best enables the team to preserve centralized governance as migration waves create more workload accounts while keeping governance consistent across destination accounts? The current estate includes 25 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone
  2. Use event-driven integration with services such as SQS, SNS, EventBridge, Step Functions, and Lambda to decouple components and remove server management where appropriate
  3. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  4. Select the purpose-built managed database that matches relational, key-value, search, or other access patterns, retaining self-managed EC2 only when required controls justify it

Correct answer: A

Why: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while keeping governance consistent across destination accounts.

Option review:

A: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate while keeping governance consistent across destination accounts.

B: Serverless and managed integration services can isolate failures, buffer bursts, and eliminate undifferentiated server operations for suitable workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while keeping governance consistent across destination accounts.

C: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while keeping governance consistent across destination accounts.

D: Database replatforming should balance access model, compatibility, scale, availability, and the operational burden the organization is willing to own. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of while keeping governance consistent across destination accounts.

Learning point: Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone. A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. In this variant, the decision also has to work while keeping governance consistent across destination accounts.

Question 22

An architecture board at Lucerne Publishing asks the principal solutions architect to support phased coexistence with the existing directory and workforce identity provider without forcing an unrelated refactor before the migration can proceed for a IoT ingestion service. Which recommendation is most appropriate? The current estate includes 32 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Use event-driven integration with services such as SQS, SNS, EventBridge, Step Functions, and Lambda to decouple components and remove server management where appropriate
  2. Use migration discovery and assessment tooling such as Migration Hub and application inventory data to build a dependency-aware portfolio assessment
  3. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  4. Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration

Correct answer: D

Why: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate without forcing an unrelated refactor before the migration can proceed.

Option review:

A: Serverless and managed integration services can isolate failures, buffer bursts, and eliminate undifferentiated server operations for suitable workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

B: Migration planning starts with reliable inventory, ownership, dependency, and utilization data so scope and sequencing reflect the real estate. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

C: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to support phased coexistence with the existing directory and workforce identity provider under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

D: Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. This directly addresses the primary requirement and remains appropriate without forcing an unrelated refactor before the migration can proceed.

Learning point: Integrate IAM Identity Center or Directory Service with the enterprise identity source and use temporary least-privilege roles during migration. Federated identity and role-based access preserve centralized governance and avoid proliferating long-lived local credentials during migration. In this variant, the decision also has to work without forcing an unrelated refactor before the migration can proceed.

Question 23

For a batch settlement service at A. Datum Analytics, a hybrid connectivity redesign identifies one priority: migrate a large relational database with low downtime while converting the schema to a different database engine without forcing an unrelated refactor before the migration can proceed. Which AWS design should the team choose? The current estate includes 39 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use AWS Application Migration Service for supported rehost migrations and discovery tooling to understand server and dependency scope
  2. Use event-driven integration with services such as SQS, SNS, EventBridge, Step Functions, and Lambda to decouple components and remove server management where appropriate
  3. Choose DataSync, Transfer Family, S3 transfer features, or Snow Family according to source protocol, bandwidth, data volume, and migration window
  4. Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required

Correct answer: D

Why: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate without forcing an unrelated refactor before the migration can proceed.

Option review:

A: Application Migration Service is designed for lift-and-shift server migration with continuous replication and controlled cutover. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

B: Serverless and managed integration services can isolate failures, buffer bursts, and eliminate undifferentiated server operations for suitable workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

C: AWS provides online and offline data-transfer services; the correct choice depends on data size, network capacity, protocol, and acceptable transfer duration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to migrate a large relational database with low downtime while converting the schema to a different database engine under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

D: DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. This directly addresses the primary requirement and remains appropriate without forcing an unrelated refactor before the migration can proceed.

Learning point: Use AWS DMS for ongoing data replication and AWS SCT when heterogeneous schema conversion is required. DMS supports database data movement and change replication; SCT assists with schema and code conversion when source and target engines differ. In this variant, the decision also has to work without forcing an unrelated refactor before the migration can proceed.

Question 24

Wide World Importers has already validated the surrounding application components. The remaining architecture requirement for its machine learning inference service is to preserve centralized governance as migration waves create more workload accounts without forcing an unrelated refactor before the migration can proceed. Which option is best? The current estate includes 46 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use appropriate Direct Connect or VPN connectivity, Route 53/DNS coexistence, encryption, and tightly scoped network/security controls for the migration path
  2. Select the AWS storage service whose access protocol, durability, throughput, sharing model, and hybrid requirements match the application
  3. Choose purpose-built storage and database services per component, using managed elasticity and caching where they fit the access pattern
  4. Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone

Correct answer: D

Why: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate without forcing an unrelated refactor before the migration can proceed.

Option review:

A: Migration networks often coexist with production; connectivity, DNS, encryption, and access controls must be designed for both the transition and final state. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

B: AWS storage services expose different block, file, object, and hybrid semantics; the correct target depends on how the application reads and writes data. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

C: Modernization often improves scalability and operations by replacing one generalized data platform with services optimized for object, file, key-value, relational, or cache workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to preserve centralized governance as migration waves create more workload accounts under the additional constraint of without forcing an unrelated refactor before the migration can proceed.

D: A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. This directly addresses the primary requirement and remains appropriate without forcing an unrelated refactor before the migration can proceed.

Learning point: Use Organizations and Control Tower with a defined account/OU model, guardrails, and delegated administration for the migration landing zone. A governed landing zone gives migration teams repeatable account baselines and prevents each wave from inventing its own security and governance model. In this variant, the decision also has to work without forcing an unrelated refactor before the migration can proceed.

Popular posts

img