Amazon AWS Solutions Architect Professional SAP-C02 Security Improvement Secrets Least Privilege Practice Test

 

Domain 3.2 • 25 original questions

This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on security improvement secrets least privilege traceability patching and backup through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a modernization initiative at Consolidated Messenger, the enterprise architect is designing a enterprise ERP system. The requirement is to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while using measurable evidence before and after remediation. Which architecture is the best fit? The current estate includes 38 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use Cost Explorer, Compute Optimizer, Trusted Advisor, and service inventory data to identify idle or overprovisioned resources, then remove or rightsize them safely
  2. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain
  3. Use centralized CloudWatch observability with actionable alarms and event-driven or Systems Manager automation for known remediation paths
  4. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements

Correct answer: D

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

Option review:

A: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while using measurable evidence before and after remediation.

B: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while using measurable evidence before and after remediation.

C: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while using measurable evidence before and after remediation.

D: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while using measurable evidence before and after remediation.

Question 2

Litware Manufacturing operates a data lake platform. In a production readiness review, the cloud financial management lead must prioritize repeatable automated responses to well-understood security findings while using measurable evidence before and after remediation. Which option should be recommended? The current estate includes 45 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  2. Treat service quotas as reliability dependencies: monitor headroom, request increases early, and test recovery capacity in the target environment
  3. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  4. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures

Correct answer: A

Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

Option review:

A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

B: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while using measurable evidence before and after remediation.

C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while using measurable evidence before and after remediation.

D: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while using measurable evidence before and after remediation.

Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while using measurable evidence before and after remediation.

Question 3

A security architect at Humongous Insurance is reviewing a customer-facing API. The business requires the team to formalize patching and backup so both can be measured against policy rather than handled ad hoc while using measurable evidence before and after remediation. Which design most directly satisfies the requirement? The current estate includes 5 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  2. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation
  3. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  4. Treat service quotas as reliability dependencies: monitor headroom, request increases early, and test recovery capacity in the target environment

Correct answer: B

Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

Option review:

A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while using measurable evidence before and after remediation.

B: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.

C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while using measurable evidence before and after remediation.

D: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while using measurable evidence before and after remediation.

Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while using measurable evidence before and after remediation.

Question 4

Tailspin Logistics is changing its healthcare records application as part of a hybrid connectivity redesign. Which AWS approach best enables the team to apply stronger controls to sensitive regulated data without creating permanent administrator credentials without making unrelated architecture changes? The current estate includes 12 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  2. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  3. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  4. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics

Correct answer: A

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

Option review:

A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

B: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of without making unrelated architecture changes.

C: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of without making unrelated architecture changes.

D: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of without making unrelated architecture changes.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work without making unrelated architecture changes.

Question 5

Which AWS architecture principle or service combination best addresses this requirement for Alpine Sports: prioritize repeatable automated responses to well-understood security findings without making unrelated architecture changes? The current estate includes 19 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Treat service quotas as reliability dependencies: monitor headroom, request increases early, and test recovery capacity in the target environment
  2. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  3. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  4. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation

Correct answer: D

Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

Option review:

A: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of without making unrelated architecture changes.

B: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of without making unrelated architecture changes.

C: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of without making unrelated architecture changes.

D: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work without making unrelated architecture changes.

Question 6

For a data lake platform at Adventure Works, a new workload design identifies one priority: formalize patching and backup so both can be measured against policy rather than handled ad hoc without making unrelated architecture changes. Which AWS design should the team choose? The current estate includes 26 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  2. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures
  3. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation
  4. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain

Correct answer: C

Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

Option review:

A: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of without making unrelated architecture changes.

B: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of without making unrelated architecture changes.

C: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.

D: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of without making unrelated architecture changes.

Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work without making unrelated architecture changes.

Question 7

VanArsdel Energy has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while preserving the workload service objective during the improvement. Which option is best? The current estate includes 33 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  2. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  3. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain
  4. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation

Correct answer: B

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

Option review:

A: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while preserving the workload service objective during the improvement.

B: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

C: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while preserving the workload service objective during the improvement.

D: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while preserving the workload service objective during the improvement.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while preserving the workload service objective during the improvement.

Question 8

While conducting a global expansion project, the network architect at Contoso Retail needs to prioritize repeatable automated responses to well-understood security findings while preserving the workload service objective during the improvement. Which architecture decision best matches the stated constraints? The current estate includes 40 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  2. Define measurable KPIs/SLOs, instrument the relevant components, and use CloudWatch or service metrics to isolate the actual bottleneck before changing architecture
  3. Use the AWS global delivery or managed service that matches the workload protocol and access pattern, such as CloudFront for cacheable content or Global Accelerator for network-path optimization
  4. Use Cost and Usage Reports or equivalent detailed billing data with cost-allocation tags, Budgets, and alarms to analyze transfer charges and assign ownership

Correct answer: A

Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

Option review:

A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

B: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while preserving the workload service objective during the improvement.

C: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while preserving the workload service objective during the improvement.

D: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while preserving the workload service objective during the improvement.

Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while preserving the workload service objective during the improvement.

Question 9

During a multi-account governance review at Lucerne Publishing, the enterprise architect is designing a enterprise ERP system. The requirement is to formalize patching and backup so both can be measured against policy rather than handled ad hoc while preserving the workload service objective during the improvement. Which architecture is the best fit? The current estate includes 47 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  2. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics
  3. Use Cost and Usage Reports or equivalent detailed billing data with cost-allocation tags, Budgets, and alarms to analyze transfer charges and assign ownership
  4. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation

Correct answer: D

Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

Option review:

A: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while preserving the workload service objective during the improvement.

B: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while preserving the workload service objective during the improvement.

C: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while preserving the workload service objective during the improvement.

D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.

Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while preserving the workload service objective during the improvement.

Question 10

  1. Datum Analytics is documenting its target-state architecture. Which choice most accurately addresses the need to apply stronger controls to sensitive regulated data without creating permanent administrator credentials with a staged validation path before full rollout? The current estate includes 7 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.
  2. Use the AWS global delivery or managed service that matches the workload protocol and access pattern, such as CloudFront for cacheable content or Global Accelerator for network-path optimization
  3. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  4. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  5. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements

Correct answer: B

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

Option review:

A: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of with a staged validation path before full rollout.

B: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of with a staged validation path before full rollout.

D: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of with a staged validation path before full rollout.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work with a staged validation path before full rollout.

Question 11

A security architect at Wide World Importers is reviewing a customer-facing API. The business requires the team to prioritize repeatable automated responses to well-understood security findings with a staged validation path before full rollout. Which design most directly satisfies the requirement? The current estate includes 14 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  2. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  3. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  4. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain

Correct answer: C

Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

Option review:

A: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of with a staged validation path before full rollout.

B: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of with a staged validation path before full rollout.

C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

D: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of with a staged validation path before full rollout.

Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work with a staged validation path before full rollout.

Question 12

Bellows University is changing its healthcare records application as part of a security design review. Which AWS approach best enables the team to formalize patching and backup so both can be measured against policy rather than handled ad hoc with a staged validation path before full rollout? The current estate includes 21 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use centralized CloudWatch observability with actionable alarms and event-driven or Systems Manager automation for known remediation paths
  2. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation
  3. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain
  4. Define measurable KPIs/SLOs, instrument the relevant components, and use CloudWatch or service metrics to isolate the actual bottleneck before changing architecture

Correct answer: B

Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

Option review:

A: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of with a staged validation path before full rollout.

B: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.

C: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of with a staged validation path before full rollout.

D: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of with a staged validation path before full rollout.

Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work with a staged validation path before full rollout.

Question 13

An architecture board at Blue Yonder Airlines asks the site reliability architect to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while reducing repetitive manual operations for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 28 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures
  2. Treat service quotas as reliability dependencies: monitor headroom, request increases early, and test recovery capacity in the target environment
  3. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics
  4. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements

Correct answer: D

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Option review:

A: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while reducing repetitive manual operations.

B: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while reducing repetitive manual operations.

C: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while reducing repetitive manual operations.

D: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while reducing repetitive manual operations.

Question 14

For a data lake platform at City Power, a production readiness review identifies one priority: prioritize repeatable automated responses to well-understood security findings while reducing repetitive manual operations. Which AWS design should the team choose? The current estate includes 35 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  2. Use Systems Manager or service-native configuration automation, and run controlled failure scenarios to validate recovery procedures
  3. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  4. Benchmark candidate instance families or scaling designs under representative load, then rightsize using observed CPU, memory, network, and storage characteristics

Correct answer: C

Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Option review:

A: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while reducing repetitive manual operations.

B: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while reducing repetitive manual operations.

C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

D: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while reducing repetitive manual operations.

Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while reducing repetitive manual operations.

Question 15

A principal architect asks which AWS approach is intended to formalize patching and backup so both can be measured against policy rather than handled ad hoc while reducing repetitive manual operations. What is the best answer? The current estate includes 42 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  2. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints
  3. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  4. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation

Correct answer: D

Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Option review:

A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while reducing repetitive manual operations.

B: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while reducing repetitive manual operations.

C: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while reducing repetitive manual operations.

D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.

Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while reducing repetitive manual operations.

Question 16

While conducting a hybrid connectivity redesign, the network architect at Southridge Video needs to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while retaining AWS-native traceability for the change. Which architecture decision best matches the stated constraints? The current estate includes 49 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.

  1. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  2. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  3. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  4. Treat service quotas as reliability dependencies: monitor headroom, request increases early, and test recovery capacity in the target environment

Correct answer: A

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

Option review:

A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

B: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while retaining AWS-native traceability for the change.

C: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while retaining AWS-native traceability for the change.

D: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while retaining AWS-native traceability for the change.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while retaining AWS-native traceability for the change.

Question 17

During a resilience assessment at Woodgrove Bank, the enterprise architect is designing a enterprise ERP system. The requirement is to prioritize repeatable automated responses to well-understood security findings while retaining AWS-native traceability for the change. Which architecture is the best fit? The current estate includes 9 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  2. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  3. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  4. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation

Correct answer: C

Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

Option review:

A: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while retaining AWS-native traceability for the change.

B: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while retaining AWS-native traceability for the change.

C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while retaining AWS-native traceability for the change.

Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while retaining AWS-native traceability for the change.

Question 18

Relecloud Systems operates a data lake platform. In a new workload design, the cloud financial management lead must formalize patching and backup so both can be measured against policy rather than handled ad hoc while retaining AWS-native traceability for the change. Which option should be recommended? The current estate includes 16 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.

  1. Use Cost Explorer, Compute Optimizer, Trusted Advisor, and service inventory data to identify idle or overprovisioned resources, then remove or rightsize them safely
  2. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it
  3. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints
  4. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation

Correct answer: D

Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

Option review:

A: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while retaining AWS-native traceability for the change.

B: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while retaining AWS-native traceability for the change.

C: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while retaining AWS-native traceability for the change.

D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.

Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while retaining AWS-native traceability for the change.

Question 19

A security architect at Fabrikam Health is reviewing a customer-facing API. The business requires the team to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while prioritizing the highest-risk bottleneck first. Which design most directly satisfies the requirement? The current estate includes 23 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.

  1. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  2. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  3. Define measurable KPIs/SLOs, instrument the relevant components, and use CloudWatch or service metrics to isolate the actual bottleneck before changing architecture
  4. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain

Correct answer: B

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Option review:

A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while prioritizing the highest-risk bottleneck first.

B: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

C: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while prioritizing the highest-risk bottleneck first.

D: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while prioritizing the highest-risk bottleneck first.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.

Question 20

Which solution is the strongest match for the following professional-level architecture requirement: prioritize repeatable automated responses to well-understood security findings while prioritizing the highest-risk bottleneck first? The current estate includes 30 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.

  1. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  2. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels
  3. Use observed growth trends to add replication, load balancing, and Auto Scaling or managed elastic features that can replace failed capacity
  4. Use Cost and Usage Reports or equivalent detailed billing data with cost-allocation tags, Budgets, and alarms to analyze transfer charges and assign ownership

Correct answer: A

Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Option review:

A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

B: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while prioritizing the highest-risk bottleneck first.

C: Growth planning should combine replication and elastic scaling so the system maintains capacity and recovers automatically as demand changes. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while prioritizing the highest-risk bottleneck first.

D: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while prioritizing the highest-risk bottleneck first.

Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.

Question 21

An architecture board at Northwind Media asks the site reliability architect to formalize patching and backup so both can be measured against policy rather than handled ad hoc while prioritizing the highest-risk bottleneck first for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 37 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.

  1. Adopt a deployment strategy with health checks, progressive exposure, and automated rollback that matches the application and capacity constraints
  2. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain
  3. Use observed growth trends to add replication, load balancing, and Auto Scaling or managed elastic features that can replace failed capacity
  4. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation

Correct answer: D

Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Option review:

A: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while prioritizing the highest-risk bottleneck first.

B: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while prioritizing the highest-risk bottleneck first.

C: Growth planning should combine replication and elastic scaling so the system maintains capacity and recovers automatically as demand changes. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while prioritizing the highest-risk bottleneck first.

D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.

Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.

Question 22

For a data lake platform at Coho Financial, a migration wave planning session identifies one priority: apply stronger controls to sensitive regulated data without creating permanent administrator credentials while keeping rollback practical if the change regresses the workload. Which AWS design should the team choose? The current estate includes 44 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.

  1. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  2. Use centralized CloudWatch observability with actionable alarms and event-driven or Systems Manager automation for known remediation paths
  3. Use the AWS global delivery or managed service that matches the workload protocol and access pattern, such as CloudFront for cacheable content or Global Accelerator for network-path optimization
  4. Test changes against performance and cost objectives using representative traffic, then adopt only changes that preserve required service levels

Correct answer: A

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

Option review:

A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

B: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while keeping rollback practical if the change regresses the workload.

C: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while keeping rollback practical if the change regresses the workload.

D: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while keeping rollback practical if the change regresses the workload.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.

Question 23

Lamna Healthcare has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to prioritize repeatable automated responses to well-understood security findings while keeping rollback practical if the change regresses the workload. Which option is best? The current estate includes 4 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.

  1. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  2. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  3. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  4. Use Cost and Usage Reports or equivalent detailed billing data with cost-allocation tags, Budgets, and alarms to analyze transfer charges and assign ownership

Correct answer: C

Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

Option review:

A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while keeping rollback practical if the change regresses the workload.

B: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while keeping rollback practical if the change regresses the workload.

C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

D: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while keeping rollback practical if the change regresses the workload.

Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.

Question 24

While conducting a security design review, the network architect at Fourth Coffee needs to formalize patching and backup so both can be measured against policy rather than handled ad hoc while keeping rollback practical if the change regresses the workload. Which architecture decision best matches the stated constraints? The current estate includes 11 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.

  1. Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation
  2. Perform a structured Well-Architected-style review using operational telemetry, security findings, and reliability evidence, then prioritize risks by business impact
  3. Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation
  4. Use observed growth trends to add replication, load balancing, and Auto Scaling or managed elastic features that can replace failed capacity

Correct answer: C

Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

Option review:

A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while keeping rollback practical if the change regresses the workload.

B: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while keeping rollback practical if the change regresses the workload.

C: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.

D: Growth planning should combine replication and elastic scaling so the system maintains capacity and recovers automatically as demand changes. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while keeping rollback practical if the change regresses the workload.

Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.

Question 25

Following an acquisition, Consolidated Messenger is rationalizing its enterprise ERP system. The architecture board documented two acceptance criteria: apply stronger controls to sensitive regulated data without creating permanent administrator credentials; and the solution must do so while basing the recommendation on observed utilization or telemetry. Which target-state recommendation should the enterprise architect approve? The current estate includes 18 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.

  1. Identify each required component that lacks redundancy and replace or redesign it with multi-AZ, managed HA, or redundant paths appropriate to the failure domain
  2. Analyze the stable post-rightsizing usage baseline, then purchase the commitment model that matches flexibility and term requirements
  3. Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements
  4. Use event-driven monitoring and approved automation runbooks for repeatable remediations, with logging, guardrails, and human approval where risk requires it

Correct answer: C

Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while basing the recommendation on observed utilization or telemetry.

Option review:

A: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while basing the recommendation on observed utilization or telemetry.

B: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while basing the recommendation on observed utilization or telemetry.

C: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while basing the recommendation on observed utilization or telemetry.

D: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while basing the recommendation on observed utilization or telemetry.

Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while basing the recommendation on observed utilization or telemetry.

Popular posts

img