Amazon AWS Solutions Architect Professional SAP-C02 Security Improvement Secrets Least Privilege Practice Test
Domain 3.2 • 25 original questions
This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on security improvement secrets least privilege traceability patching and backup through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a modernization initiative at Consolidated Messenger, the enterprise architect is designing a enterprise ERP system. The requirement is to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while using measurable evidence before and after remediation. Which architecture is the best fit? The current estate includes 38 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: D
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.
Option review:
A: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while using measurable evidence before and after remediation.
B: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while using measurable evidence before and after remediation.
C: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while using measurable evidence before and after remediation.
D: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while using measurable evidence before and after remediation.
Litware Manufacturing operates a data lake platform. In a production readiness review, the cloud financial management lead must prioritize repeatable automated responses to well-understood security findings while using measurable evidence before and after remediation. Which option should be recommended? The current estate includes 45 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: A
Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.
Option review:
A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.
B: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while using measurable evidence before and after remediation.
C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while using measurable evidence before and after remediation.
D: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while using measurable evidence before and after remediation.
Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while using measurable evidence before and after remediation.
A security architect at Humongous Insurance is reviewing a customer-facing API. The business requires the team to formalize patching and backup so both can be measured against policy rather than handled ad hoc while using measurable evidence before and after remediation. Which design most directly satisfies the requirement? The current estate includes 5 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: B
Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.
Option review:
A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while using measurable evidence before and after remediation.
B: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while using measurable evidence before and after remediation.
C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while using measurable evidence before and after remediation.
D: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while using measurable evidence before and after remediation.
Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while using measurable evidence before and after remediation.
Tailspin Logistics is changing its healthcare records application as part of a hybrid connectivity redesign. Which AWS approach best enables the team to apply stronger controls to sensitive regulated data without creating permanent administrator credentials without making unrelated architecture changes? The current estate includes 12 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.
Correct answer: A
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.
Option review:
A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.
B: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of without making unrelated architecture changes.
C: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of without making unrelated architecture changes.
D: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of without making unrelated architecture changes.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work without making unrelated architecture changes.
Which AWS architecture principle or service combination best addresses this requirement for Alpine Sports: prioritize repeatable automated responses to well-understood security findings without making unrelated architecture changes? The current estate includes 19 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.
Option review:
A: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of without making unrelated architecture changes.
B: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of without making unrelated architecture changes.
C: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of without making unrelated architecture changes.
D: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.
Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work without making unrelated architecture changes.
For a data lake platform at Adventure Works, a new workload design identifies one priority: formalize patching and backup so both can be measured against policy rather than handled ad hoc without making unrelated architecture changes. Which AWS design should the team choose? The current estate includes 26 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.
Correct answer: C
Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.
Option review:
A: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of without making unrelated architecture changes.
B: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of without making unrelated architecture changes.
C: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate without making unrelated architecture changes.
D: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of without making unrelated architecture changes.
Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work without making unrelated architecture changes.
VanArsdel Energy has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while preserving the workload service objective during the improvement. Which option is best? The current estate includes 33 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: B
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.
Option review:
A: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while preserving the workload service objective during the improvement.
B: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.
C: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while preserving the workload service objective during the improvement.
D: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while preserving the workload service objective during the improvement.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while preserving the workload service objective during the improvement.
While conducting a global expansion project, the network architect at Contoso Retail needs to prioritize repeatable automated responses to well-understood security findings while preserving the workload service objective during the improvement. Which architecture decision best matches the stated constraints? The current estate includes 40 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: A
Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.
Option review:
A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.
B: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while preserving the workload service objective during the improvement.
C: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while preserving the workload service objective during the improvement.
D: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while preserving the workload service objective during the improvement.
Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while preserving the workload service objective during the improvement.
During a multi-account governance review at Lucerne Publishing, the enterprise architect is designing a enterprise ERP system. The requirement is to formalize patching and backup so both can be measured against policy rather than handled ad hoc while preserving the workload service objective during the improvement. Which architecture is the best fit? The current estate includes 47 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: D
Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.
Option review:
A: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while preserving the workload service objective during the improvement.
B: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while preserving the workload service objective during the improvement.
C: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while preserving the workload service objective during the improvement.
D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while preserving the workload service objective during the improvement.
Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while preserving the workload service objective during the improvement.
Correct answer: B
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.
Option review:
A: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of with a staged validation path before full rollout.
B: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.
C: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of with a staged validation path before full rollout.
D: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of with a staged validation path before full rollout.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work with a staged validation path before full rollout.
A security architect at Wide World Importers is reviewing a customer-facing API. The business requires the team to prioritize repeatable automated responses to well-understood security findings with a staged validation path before full rollout. Which design most directly satisfies the requirement? The current estate includes 14 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: C
Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.
Option review:
A: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of with a staged validation path before full rollout.
B: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of with a staged validation path before full rollout.
C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.
D: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of with a staged validation path before full rollout.
Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work with a staged validation path before full rollout.
Bellows University is changing its healthcare records application as part of a security design review. Which AWS approach best enables the team to formalize patching and backup so both can be measured against policy rather than handled ad hoc with a staged validation path before full rollout? The current estate includes 21 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: B
Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.
Option review:
A: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of with a staged validation path before full rollout.
B: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate with a staged validation path before full rollout.
C: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of with a staged validation path before full rollout.
D: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of with a staged validation path before full rollout.
Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work with a staged validation path before full rollout.
An architecture board at Blue Yonder Airlines asks the site reliability architect to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while reducing repetitive manual operations for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 28 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: D
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.
Option review:
A: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while reducing repetitive manual operations.
B: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while reducing repetitive manual operations.
C: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while reducing repetitive manual operations.
D: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while reducing repetitive manual operations.
For a data lake platform at City Power, a production readiness review identifies one priority: prioritize repeatable automated responses to well-understood security findings while reducing repetitive manual operations. Which AWS design should the team choose? The current estate includes 35 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: C
Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.
Option review:
A: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while reducing repetitive manual operations.
B: Configuration automation reduces drift, while failure exercises reveal gaps in monitoring, dependencies, and operational recovery knowledge. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while reducing repetitive manual operations.
C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.
D: Rightsizing and high-performance compute choices should be validated against real workload characteristics and performance objectives. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while reducing repetitive manual operations.
Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while reducing repetitive manual operations.
A principal architect asks which AWS approach is intended to formalize patching and backup so both can be measured against policy rather than handled ad hoc while reducing repetitive manual operations. What is the best answer? The current estate includes 42 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: D
Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.
Option review:
A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while reducing repetitive manual operations.
B: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while reducing repetitive manual operations.
C: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while reducing repetitive manual operations.
D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while reducing repetitive manual operations.
Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while reducing repetitive manual operations.
While conducting a hybrid connectivity redesign, the network architect at Southridge Video needs to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while retaining AWS-native traceability for the change. Which architecture decision best matches the stated constraints? The current estate includes 49 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.
Correct answer: A
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.
Option review:
A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.
B: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while retaining AWS-native traceability for the change.
C: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while retaining AWS-native traceability for the change.
D: A redundant design is not reliable if quotas prevent it from scaling or failing over when needed. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while retaining AWS-native traceability for the change.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while retaining AWS-native traceability for the change.
During a resilience assessment at Woodgrove Bank, the enterprise architect is designing a enterprise ERP system. The requirement is to prioritize repeatable automated responses to well-understood security findings while retaining AWS-native traceability for the change. Which architecture is the best fit? The current estate includes 9 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: C
Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.
Option review:
A: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while retaining AWS-native traceability for the change.
B: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while retaining AWS-native traceability for the change.
C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.
D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while retaining AWS-native traceability for the change.
Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while retaining AWS-native traceability for the change.
Relecloud Systems operates a data lake platform. In a new workload design, the cloud financial management lead must formalize patching and backup so both can be measured against policy rather than handled ad hoc while retaining AWS-native traceability for the change. Which option should be recommended? The current estate includes 16 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.
Correct answer: D
Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.
Option review:
A: Cost optimization begins by measuring utilization and identifying resources whose size or existence is not justified by workload demand. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while retaining AWS-native traceability for the change.
B: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while retaining AWS-native traceability for the change.
C: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while retaining AWS-native traceability for the change.
D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while retaining AWS-native traceability for the change.
Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while retaining AWS-native traceability for the change.
A security architect at Fabrikam Health is reviewing a customer-facing API. The business requires the team to apply stronger controls to sensitive regulated data without creating permanent administrator credentials while prioritizing the highest-risk bottleneck first. Which design most directly satisfies the requirement? The current estate includes 23 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: B
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.
Option review:
A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while prioritizing the highest-risk bottleneck first.
B: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.
C: Performance work should start with measurable objectives and evidence so remediation targets the limiting component rather than the most visible one. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while prioritizing the highest-risk bottleneck first.
D: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while prioritizing the highest-risk bottleneck first.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.
Which solution is the strongest match for the following professional-level architecture requirement: prioritize repeatable automated responses to well-understood security findings while prioritizing the highest-risk bottleneck first? The current estate includes 30 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: A
Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.
Option review:
A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.
B: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while prioritizing the highest-risk bottleneck first.
C: Growth planning should combine replication and elastic scaling so the system maintains capacity and recovers automatically as demand changes. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while prioritizing the highest-risk bottleneck first.
D: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while prioritizing the highest-risk bottleneck first.
Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.
An architecture board at Northwind Media asks the site reliability architect to formalize patching and backup so both can be measured against policy rather than handled ad hoc while prioritizing the highest-risk bottleneck first for a enterprise ERP system. Which recommendation is most appropriate? The current estate includes 37 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: D
Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.
Option review:
A: Deployment improvements should reduce blast radius and make unhealthy releases detectable and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while prioritizing the highest-risk bottleneck first.
B: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while prioritizing the highest-risk bottleneck first.
C: Growth planning should combine replication and elastic scaling so the system maintains capacity and recovers automatically as demand changes. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while prioritizing the highest-risk bottleneck first.
D: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while prioritizing the highest-risk bottleneck first.
Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while prioritizing the highest-risk bottleneck first.
For a data lake platform at Coho Financial, a migration wave planning session identifies one priority: apply stronger controls to sensitive regulated data without creating permanent administrator credentials while keeping rollback practical if the change regresses the workload. Which AWS design should the team choose? The current estate includes 44 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.
Correct answer: A
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.
Option review:
A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.
B: Monitoring should produce useful signals and, where safe, trigger repeatable remediation instead of relying on manual observation of every component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while keeping rollback practical if the change regresses the workload.
C: AWS global and managed services can improve latency and reduce operational burden when selected for the application protocol and caching or routing model. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while keeping rollback practical if the change regresses the workload.
D: Optimization should be validated against the workload objectives so savings or speed improvements do not create new reliability or performance problems. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while keeping rollback practical if the change regresses the workload.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.
Lamna Healthcare has already validated the surrounding application components. The remaining architecture requirement for its customer-facing API is to prioritize repeatable automated responses to well-understood security findings while keeping rollback practical if the change regresses the workload. Which option is best? The current estate includes 4 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: C
Why: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.
Option review:
A: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while keeping rollback practical if the change regresses the workload.
B: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while keeping rollback practical if the change regresses the workload.
C: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.
D: Granular billing data, allocation tags, and alerts provide the visibility needed to explain spend and drive accountable cost remediation. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to prioritize repeatable automated responses to well-understood security findings under the additional constraint of while keeping rollback practical if the change regresses the workload.
Learning point: Use CloudTrail and AWS security/configuration services for traceability and findings, with AWS Config/EventBridge/automation for controlled remediation. Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.
While conducting a security design review, the network architect at Fourth Coffee needs to formalize patching and backup so both can be measured against policy rather than handled ad hoc while keeping rollback practical if the change regresses the workload. Which architecture decision best matches the stated constraints? The current estate includes 11 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: C
Why: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.
Option review:
A: Traceability, centralized findings, and safe automation help teams detect policy drift and reduce time to remediate recurring security issues. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while keeping rollback practical if the change regresses the workload.
B: Continuous improvement is most effective when recommendations are grounded in measurable risk and workload evidence across multiple architectural dimensions. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while keeping rollback practical if the change regresses the workload.
C: Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. This directly addresses the primary requirement and remains appropriate while keeping rollback practical if the change regresses the workload.
D: Growth planning should combine replication and elastic scaling so the system maintains capacity and recovers automatically as demand changes. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to formalize patching and backup so both can be measured against policy rather than handled ad hoc under the additional constraint of while keeping rollback practical if the change regresses the workload.
Learning point: Use Systems Manager Patch Manager or managed-service patching and policy-based backup services with compliance reporting and restore validation. Patching and backups need defined schedules, scope, compliance evidence, isolation, and testing to be dependable security controls. In this variant, the decision also has to work while keeping rollback practical if the change regresses the workload.
Following an acquisition, Consolidated Messenger is rationalizing its enterprise ERP system. The architecture board documented two acceptance criteria: apply stronger controls to sensitive regulated data without creating permanent administrator credentials; and the solution must do so while basing the recommendation on observed utilization or telemetry. Which target-state recommendation should the enterprise architect approve? The current estate includes 18 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: C
Why: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while basing the recommendation on observed utilization or telemetry.
Option review:
A: Reliability improves when critical single points of failure are removed and failover mechanisms match the intended failure scope. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while basing the recommendation on observed utilization or telemetry.
B: Commitments are most effective after rightsizing and when the organization understands which usage is predictably sustained. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while basing the recommendation on observed utilization or telemetry.
C: Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. This directly addresses the primary requirement and remains appropriate while basing the recommendation on observed utilization or telemetry.
D: Automation is most valuable for well-understood recurring actions when it remains observable, controlled, and reversible. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to apply stronger controls to sensitive regulated data without creating permanent administrator credentials under the additional constraint of while basing the recommendation on observed utilization or telemetry.
Learning point: Store secrets in Secrets Manager or Parameter Store as appropriate, enforce least privilege, and review access against data sensitivity and regulatory requirements. Secret management and least privilege reduce credential exposure and unnecessary authority, especially for regulated or sensitive workloads. In this variant, the decision also has to work while basing the recommendation on observed utilization or telemetry.
Popular posts
Recent Posts
