AWS Certified Solutions Architect – Associate — All Questions
The figures these questions turn on, pooled by value and printable, with a side to write them from memory: the cram packet, $6.99 →
400 questions
An application running on EC2 instances needs to read objects from an S3 bucket. What is the most secure way to grant this access?
- a.Store long-lived credentials in a file on the instance
- b.Make the S3 bucket public and filter by source IP
- c.Attach an IAM role to the EC2 instances with a policy granting least-privilege S3 read access✓
- d.Embed an IAM user's access keys in the application code
IAM roles provide temporary, automatically rotated credentials to EC2 instances via the instance metadata service, eliminating the need to store long-lived keys. Scoping the role's policy to only the required bucket and actions follows the principle of least privilege. Hard-coded access keys and public buckets create serious security risks and violate the Security pillar of the Well-Architected Framework.
A company must encrypt data at rest in S3 while retaining full control over the key material, key rotation policy, and the ability to audit every key usage via CloudTrail. Which option best meets this requirement?
- a.Client-side encryption with a hard-coded static key
- b.Server-side encryption with Amazon S3 managed keys (SSE-S3)
- c.Server-side encryption with AWS KMS customer managed keys (SSE-KMS)✓
- d.No encryption, relying on bucket policies only
SSE-KMS with a customer managed key lets you define rotation, key policies, and grants while logging each decrypt/encrypt call in CloudTrail for auditing. SSE-S3 encrypts data but gives you no control over or visibility into the key. Bucket policies control access but do not encrypt data at rest.
A web application behind an Application Load Balancer is being targeted by SQL injection and cross-site scripting attempts at the HTTP layer. Which service should be added to filter this malicious traffic?
- a.A network ACL on the public subnet
- b.Amazon GuardDuty
- c.AWS WAF with managed rule groups✓
- d.AWS Shield Standard
AWS WAF inspects HTTP/HTTPS requests and can block SQL injection and XSS using AWS managed rule groups attached to the ALB. Shield Standard protects against network/transport-layer DDoS, not application-layer exploits. NACLs operate on IP/port and cannot parse request content.
An RDS database must be reachable only from application servers in a private subnet and never from the internet. Which configuration achieves this?
- a.Open the database security group to 0.0.0.0/0 on port 3306
- b.Place the database in a private subnet and set its security group to allow inbound traffic only from the application tier's security group✓
- c.Attach an internet gateway route to the database subnet
- d.Place the database in a public subnet with an Elastic IP
Deploying RDS in a private subnet with no route to an internet gateway keeps it unreachable from the internet. Referencing the application tier's security group as the source in the database security group restricts access to just those instances, following least privilege. Opening 0.0.0.0/0 or using public subnets would expose the database.
An application needs to retrieve database credentials at runtime, and the credentials must be automatically rotated on a schedule. Which service is purpose-built for this?
- a.AWS Secrets Manager✓
- b.Amazon S3 with encryption
- c.AWS Systems Manager Parameter Store standard parameters
- d.IAM instance profile tags
Secrets Manager stores credentials encrypted with KMS and provides native automatic rotation, including built-in integration with RDS to rotate database passwords. Standard Parameter Store parameters can hold secrets but do not offer managed rotation. Storing credentials in S3 or tags is insecure and lacks rotation.
A mobile and web application needs user sign-up, sign-in, and federated identity with Google and Apple, returning tokens the app can use to call an API. Which service should be used?
- a.Amazon Cognito user pools with identity federation✓
- b.AWS KMS
- c.AWS IAM users, one per end user
- d.AWS Directory Service
Amazon Cognito user pools provide managed user directories, sign-up/sign-in flows, and federation with social and enterprise identity providers, issuing JWT tokens for authorizing API calls. Creating an IAM user per application end user does not scale and is not intended for app-user authentication. KMS handles encryption keys, not identity.
A security team wants to allow developers to launch EC2 instances but must ensure they cannot detach or modify IAM policies. Which approach follows AWS best practice?
- a.Grant developers the AdministratorAccess managed policy
- b.Attach a least-privilege IAM policy granting only the specific EC2 actions needed, with no IAM write permissions✓
- c.Give every developer full IAM permissions and monitor with CloudTrail
- d.Share the root account credentials for convenience
Least privilege means granting only the specific permissions required for the task, so a scoped policy allowing EC2 launch actions without IAM write access is correct. AdministratorAccess and root credentials violate least privilege and separation of duties. Monitoring after over-permissioning does not prevent misuse.
A company wants its RDS database to automatically fail over to a standby in another Availability Zone with minimal downtime during an AZ outage. Which feature provides this?
- a.Manual snapshots taken hourly
- b.Storing backups in S3 Glacier
- c.RDS Multi-AZ deployment with a synchronous standby✓
- d.A read replica in the same AZ
RDS Multi-AZ maintains a synchronous standby replica in a second Availability Zone and automatically fails over to it if the primary fails, providing high availability. Read replicas are for scaling reads and are asynchronous, not automatic failover. Snapshots and Glacier backups aid recovery but do not deliver automatic failover.
To decouple a fluctuating order-processing workload so that a spike in orders does not overwhelm the processing tier, which service should sit between the producers and consumers?
- a.Amazon SQS queue that the processing tier polls✓
- b.An EBS volume shared across instances
- c.A single large EC2 instance for all processing
- d.Amazon Route 53 latency routing
Amazon SQS buffers messages, letting the processing tier consume at its own pace and absorbing spikes without dropping work, which improves resilience and enables independent scaling. A single instance is a bottleneck and single point of failure. Route 53 handles DNS routing and EBS is block storage, neither of which decouples the tiers.
A stateless web tier runs on EC2 across two Availability Zones. The architecture must automatically replace unhealthy instances and adjust capacity to demand. Which combination achieves this?
- a.An Application Load Balancer only, with fixed instances
- b.Manually launching instances when alarms fire
- c.A single EC2 instance with a static Elastic IP
- d.An Auto Scaling group spanning both AZs behind an Application Load Balancer with health checks✓
An Auto Scaling group distributed across multiple AZs launches replacement instances when health checks fail and scales in or out based on demand, while the ALB spreads traffic across healthy targets. A single instance or manual intervention cannot self-heal. An ALB alone does not replace failed instances or change capacity.
Want these explained in order? AWS Solutions Architect Associate (SAA-C03) — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →
A shared file system must be mounted concurrently by hundreds of Linux EC2 instances across multiple Availability Zones, and it must scale storage automatically. Which service fits best?
- a.Amazon EFS mounted from all instances✓
- b.A single S3 bucket mounted as a block device
- c.Amazon EBS volume attached to each instance
- d.Instance store volumes
Amazon EFS is a fully managed, elastic NFS file system that many instances across multiple AZs can mount simultaneously, scaling capacity automatically. A standard EBS volume attaches to one instance in one AZ, and instance store is ephemeral. S3 is object storage and is not a POSIX file system for concurrent block mounts.
A company needs a relational database that provides MySQL compatibility, replicates six copies of data across three Availability Zones, and offers fast automated failover. Which service best meets this?
- a.Amazon Redshift
- b.Amazon Aurora✓
- c.A self-managed MySQL cluster on a single EC2 instance
- d.Amazon DynamoDB
Aurora is MySQL- and PostgreSQL-compatible and stores six copies of data across three AZs, providing high durability and fast failover to a replica. A single EC2 MySQL instance is a single point of failure. DynamoDB is a NoSQL key-value store and Redshift is a data warehouse, neither of which is a MySQL-compatible relational OLTP database.
A global application must route users to a healthy Region and fail over automatically to a secondary Region if the primary becomes unavailable. Which approach provides this DNS-level resilience?
- a.A single Elastic IP in one Region
- b.A NAT gateway in each subnet
- c.An Application Load Balancer spanning Regions
- d.Amazon Route 53 with health checks and failover routing policy✓
Route 53 failover routing uses health checks to detect an unhealthy primary endpoint and automatically returns the secondary Region's record, enabling cross-Region DNS failover. An ALB cannot span multiple Regions. Elastic IPs and NAT gateways are single-Region constructs and do not provide global failover.
A read-heavy application repeatedly runs the same expensive database queries, causing high latency. Which addition most improves read performance with minimal application change?
- a.Increase the RDS instance storage size
- b.Move the database to a larger EBS magnetic volume
- c.Add Amazon ElastiCache to cache frequent query results in memory✓
- d.Enable S3 Transfer Acceleration
ElastiCache (Redis or Memcached) stores frequently accessed query results in memory, serving repeated reads with sub-millisecond latency and offloading the database. Growing storage or using magnetic EBS does not reduce query latency for hot data. S3 Transfer Acceleration speeds S3 uploads and is unrelated to database queries.
A media company serves large video files to a global audience and wants to reduce latency and origin load by caching content near users. Which service should be used?
- a.A larger EC2 instance in one Region
- b.Amazon CloudFront✓
- c.Amazon EFS
- d.An internet gateway
CloudFront is a content delivery network that caches content at edge locations worldwide, lowering latency for global viewers and offloading requests from the origin. A single larger instance still serves from one Region with no edge caching. EFS is regional file storage and an internet gateway only provides connectivity, neither of which delivers a global CDN.
An application needs a fully managed NoSQL database delivering single-digit millisecond latency at any scale, with the option of microsecond reads via an in-memory cache. Which combination fits?
- a.Amazon DynamoDB with DynamoDB Accelerator (DAX)✓
- b.Amazon Aurora Serverless
- c.Amazon Redshift with concurrency scaling
- d.Amazon RDS with a read replica
DynamoDB provides consistent single-digit millisecond latency at scale, and DAX is a purpose-built in-memory cache that reduces read latency to microseconds for eventually consistent reads. RDS and Aurora are relational engines, not NoSQL. Redshift is an analytics data warehouse, not a low-latency operational key-value store.
A company ingests a high-throughput, continuous stream of clickstream data that must be processed in near real time by multiple consumers. Which service is designed for this?
- a.Amazon Kinesis Data Streams✓
- b.Amazon S3 event notifications
- c.Amazon SQS standard queue
- d.Amazon Athena
Kinesis Data Streams is built for high-throughput, ordered, real-time streaming data that multiple consumers can read concurrently while retaining records for replay. SQS is a decoupling queue where a message is typically processed once, not a multi-consumer stream. Athena queries data at rest in S3 and does not ingest live streams.
A latency-sensitive TCP-based application needs to route users over the AWS global network to the nearest healthy Regional endpoint using static anycast IP addresses. Which service provides this?
- a.Amazon CloudFront
- b.Amazon Route 53 weighted routing
- c.AWS Global Accelerator✓
- d.AWS Direct Connect
AWS Global Accelerator provides static anycast IP addresses and routes traffic over the AWS backbone to the closest healthy endpoint, improving performance for TCP/UDP applications. CloudFront is optimized for cacheable HTTP content, not arbitrary TCP endpoints. Direct Connect is a private on-premises link, and weighted DNS does not use the AWS global network for transport.
A fault-tolerant batch-processing job can be interrupted and resumed and runs at flexible times. Which EC2 purchasing option minimizes cost for this workload?
- a.A three-year Reserved Instance for steady 24/7 use
- b.EC2 Spot Instances✓
- c.A Dedicated Host
- d.On-Demand Instances
Spot Instances offer the deepest discount (up to about 90% off On-Demand) and are ideal for interruption-tolerant, flexible workloads like batch jobs. On-Demand costs the most for intermittent work, and Reserved Instances or Dedicated Hosts commit you to capacity better suited to steady-state, always-on usage.
Data is stored in S3 with unpredictable and changing access patterns, and the team wants to minimize cost without manually moving objects or writing lifecycle rules. Which storage class fits best?
- a.S3 Glacier Deep Archive
- b.S3 One Zone-Infrequent Access
- c.S3 Intelligent-Tiering✓
- d.S3 Standard for everything
S3 Intelligent-Tiering automatically moves objects between access tiers based on usage, optimizing cost when access patterns are unknown or changing, with no retrieval fees for the frequent and infrequent tiers. S3 Standard misses savings on cold data, Glacier Deep Archive adds retrieval latency unsuitable for unpredictable access, and One Zone-IA reduces resilience by storing in a single AZ.
A company must transfer 80 TB of data from an on-premises data center to S3, and its internet link would take months to upload that volume. Which option is most cost- and time-effective?
- a.Use S3 Transfer Acceleration over the same link
- b.Provision a permanent Direct Connect line just for this one-time migration
- c.Use AWS Snowball to physically ship the data to AWS✓
- d.Upload directly over the existing internet connection
AWS Snowball provides a physical, ruggedized device to move large datasets offline, which is faster and cheaper than saturating a slow internet link for a one-time 80 TB transfer. Direct internet upload and Transfer Acceleration are still bound by limited bandwidth. Provisioning Direct Connect for a single migration is costly and slow to set up relative to Snowball.
A company runs a predictable, steady baseline of compute across EC2 and Fargate and wants the best discount while retaining flexibility to change instance families and Regions. Which commitment model is most appropriate?
- a.Pay On-Demand rates continuously
- b.Standard Reserved Instances locked to one instance type
- c.Spot Instances for the steady baseline
- d.Compute Savings Plans with a one- or three-year hourly spend commitment✓
Compute Savings Plans offer discounts comparable to Reserved Instances in exchange for an hourly spend commitment, while flexibly applying across instance families, sizes, Regions, and even Fargate and Lambda. Standard RIs lock you to a specific instance type and Region, reducing flexibility. On-Demand forgoes savings, and Spot is unsuitable for a steady baseline that must not be interrupted.
An application in Account A must read objects from an S3 bucket owned by Account B. What is the recommended way to grant this cross-account access?
- a.Define an IAM role in Account B that trusts Account A, and have the application assume it via STS for temporary credentials✓
- b.Make the bucket public so any account can read it
- c.Create an IAM user in Account B and email its access keys to Account A
- d.Copy the bucket's KMS key material into Account A
Cross-account access is best implemented with an IAM role in the resource-owning account (B) whose trust policy allows the calling account (A) to assume it, returning temporary STS credentials scoped to least privilege. Sharing long-lived access keys or making the bucket public violates security best practices, and KMS key material cannot be exported.
A compliance rule requires that every object uploaded to an S3 bucket must be encrypted, and any unencrypted upload must be rejected. How can this be enforced?
- a.Turn on S3 Transfer Acceleration
- b.Attach a bucket policy that denies s3:PutObject requests lacking the required server-side encryption header✓
- c.Enable S3 versioning on the bucket
- d.Rely on IAM policies attached to each individual user
A bucket policy with an explicit Deny on PutObject when the encryption header/condition is absent rejects any unencrypted upload at the bucket level, enforcing the requirement uniformly regardless of who uploads. Versioning protects against overwrite, Transfer Acceleration only speeds uploads, and per-user IAM policies do not guarantee bucket-wide enforcement.
An organization with dozens of AWS accounts must prevent any account from disabling CloudTrail or using unapproved Regions, as a guardrail that even account administrators cannot override. Which feature enforces this centrally?
- a.A permissions boundary on one IAM user
- b.Service Control Policies (SCPs) applied through AWS Organizations✓
- c.Tagging each account
- d.A security group rule
SCPs in AWS Organizations set the maximum available permissions for member accounts, so even an account administrator cannot exceed them, making them ideal for organization-wide guardrails like protecting CloudTrail or restricting Regions. Permissions boundaries apply to individual principals, security groups filter network traffic, and tags do not enforce permissions.
A third-party SaaS vendor needs limited, temporary access to resources in your account to perform monitoring. What is the most secure way to grant it?
- a.Add the vendor's IP address to a security group
- b.Share your root credentials over a secure channel
- c.Create an IAM role the vendor can assume, protected with an external ID and scoped to least privilege✓
- d.Create an IAM user for the vendor with a permanent access key
A cross-account IAM role that the vendor assumes provides temporary credentials, and requiring an external ID prevents the confused-deputy problem where another of the vendor's customers could trick it into assuming your role. Permanent access keys and root credentials are long-lived and dangerous, and a security group rule only controls network reachability, not API permissions.
A security team wants to continuously monitor for anomalous API activity, credential compromise, and communication with known malicious IPs across the account, using machine learning and threat intelligence. Which service is purpose-built for this?
- a.Amazon Inspector
- b.AWS WAF
- c.Amazon GuardDuty✓
- d.AWS Config
Amazon GuardDuty is a managed threat-detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs with machine learning and threat intelligence to surface compromised credentials, reconnaissance, and malicious communication. AWS Config tracks resource configuration compliance, WAF filters web requests, and Inspector scans workloads for software vulnerabilities.
A company wants to guarantee that every new EBS volume and snapshot created in a Region is encrypted, without relying on users to select encryption each time. What should be configured?
- a.EBS encryption by default for the account in that Region, backed by a KMS key✓
- b.A bucket policy
- c.A security group rule
- d.An IAM permissions boundary
Enabling EBS encryption by default at the account/Region level ensures all newly created volumes and snapshots are automatically encrypted with a KMS key, removing reliance on manual selection. Bucket policies apply to S3, security groups control traffic, and permissions boundaries limit IAM permissions rather than enforce volume encryption.
Instances in a private subnet must access Amazon S3 without their traffic traversing the public internet or a NAT gateway. Which solution meets this most securely and cost-effectively?
- a.Create a VPC gateway endpoint for S3 and route bucket traffic through it✓
- b.Assign public IP addresses to the instances
- c.Deploy a proxy server in a public subnet
- d.Route S3 traffic through an internet gateway
A VPC gateway endpoint for S3 lets private instances reach S3 over the AWS network without an internet gateway or NAT, improving security and avoiding NAT data-processing charges. Public IPs and internet-gateway routing expose traffic to the internet, and a proxy adds cost and complexity without the private-path guarantee.
According to AWS security best practices, how should the account root user be protected and used?
- a.Disable MFA to simplify account recovery
- b.Enable MFA on the root user, use it only for the few tasks that require it, and manage daily work through IAM roles and users✓
- c.Use the root user for all daily administration
- d.Create root access keys and embed them in automation
Best practice is to lock down the root user with MFA, avoid using it for routine tasks, and perform day-to-day work with least-privilege IAM identities and roles. Using root daily, creating root access keys, or disabling MFA all dramatically increase the blast radius if credentials are exposed.
On-premises servers need to call AWS APIs, and the security team wants to avoid distributing long-lived IAM access keys to them. What should be used?
- a.Create one shared access key for all servers
- b.Make the target S3 buckets public
- c.Hard-code an IAM user's keys in each server's configuration
- d.Use IAM Roles Anywhere so servers exchange certificates for short-lived credentials✓
IAM Roles Anywhere lets non-AWS workloads exchange X.509 certificates for temporary IAM credentials, eliminating long-lived keys on-premises. Hard-coding keys or sharing a single key spreads long-lived secrets that are hard to rotate and audit, and making buckets public removes access control entirely.
A team wants to identify S3 buckets, roles, and other resources that are shared with external accounts or the public, and to validate that IAM policies follow least privilege. Which tool helps?
- a.AWS Shield
- b.IAM Access Analyzer✓
- c.Amazon Macie
- d.Amazon Cognito
IAM Access Analyzer identifies resources whose policies grant access to external principals and can validate and refine policies toward least privilege. Macie discovers and classifies sensitive data in S3, Shield mitigates DDoS, and Cognito handles application user authentication, none of which perform external-access analysis.
Instances in a private subnet must download OS patches from the internet but must not accept any inbound connections initiated from the internet. Which component provides this?
- a.An egress-only internet gateway for IPv4 traffic
- b.A public IP address on each instance
- c.An internet gateway attached directly to the private subnet
- d.A NAT gateway in a public subnet with a route from the private subnet✓
A NAT gateway allows instances in a private subnet to initiate outbound IPv4 connections (such as fetching patches) while blocking unsolicited inbound traffic. An internet gateway or public IPs would make instances directly reachable, and an egress-only internet gateway serves IPv6 traffic, not IPv4.
A three-tier app has web instances that must reach app-tier instances on port 8080. How should the app tier's security group be configured to follow least privilege?
- a.Allow all inbound traffic from the entire VPC CIDR
- b.Allow inbound port 8080 with the web tier's security group as the source✓
- c.Allow inbound port 8080 from 0.0.0.0/0
- d.Disable the security group and rely on a network ACL
Referencing the web tier's security group as the source restricts inbound traffic to exactly those instances and adapts automatically as instances scale, which is the least-privilege pattern. Opening 0.0.0.0/0 or the whole VPC CIDR is overly permissive, and NACLs are coarse, stateless subnet filters that cannot reference security groups.
An auditor requires a complete, tamper-resistant record of every API call made in the AWS account, including who made it and when, stored durably for years. Which service provides this?
- a.AWS Config rules
- b.AWS CloudTrail with logs delivered to a protected S3 bucket✓
- c.VPC Flow Logs
- d.Amazon CloudWatch metrics
CloudTrail records management and data-plane API activity across the account, and delivering the trail to an S3 bucket (optionally with log-file validation and Object Lock) gives a durable, tamper-evident audit history. CloudWatch metrics show performance data, VPC Flow Logs capture network traffic, and Config tracks configuration state, not full API call history.
A company must encrypt traffic in transit between clients and its Application Load Balancer and wants AWS to manage certificate provisioning and renewal at no additional cost. What should be used?
- a.A self-signed certificate rotated manually each year
- b.IPsec tunnels to each client
- c.An AWS Certificate Manager (ACM) certificate on an HTTPS listener of the ALB✓
- d.Client-side encryption of every request payload
ACM provisions and automatically renews public TLS certificates at no extra charge, and attaching one to the ALB's HTTPS listener encrypts traffic in transit with minimal operational overhead. Self-signed certificates require manual rotation and are not trusted, per-request client-side encryption is unnecessary complexity, and IPsec to every client is impractical for web traffic.
A team needs to store a small, rarely changing API token securely and encrypted, and wants the lowest-cost option that does not require automatic rotation. Which service fits best?
- a.Hard-code it in the application
- b.Store it in a public S3 bucket
- c.AWS Systems Manager Parameter Store as an encrypted SecureString parameter✓
- d.AWS Secrets Manager with automatic rotation enabled
For a static secret that does not need managed rotation, a Parameter Store SecureString encrypted with KMS stores it securely at the lowest cost. Secrets Manager also encrypts secrets but charges more per secret and is best when you need built-in rotation. Hard-coding or using a public bucket exposes the secret.
Certain sensitive fields must be encrypted by the application before they are ever sent to and stored in DynamoDB, so that even AWS operators cannot read the plaintext. Which approach meets this?
- a.Store the fields in plaintext but restrict table access with IAM
- b.Rely solely on DynamoDB's built-in encryption at rest
- c.Client-side encryption of the sensitive fields using a KMS data key before writing to DynamoDB✓
- d.Encrypt only the network connection with TLS
Client-side encryption (for example with the AWS Database Encryption SDK using a KMS data key) ensures fields are encrypted before leaving the application, so the service only ever stores ciphertext. DynamoDB's built-in encryption at rest protects storage but AWS manages that layer, TLS only protects data in transit, and IAM restricts access but does not encrypt the field values.
A regulated workload requires single-tenant, FIPS 140-2 Level 3 validated hardware where the customer has exclusive control of the cryptographic keys. Which service meets this requirement?
- a.AWS KMS with an AWS managed key
- b.AWS CloudHSM✓
- c.AWS Secrets Manager
- d.Amazon S3 SSE-S3
AWS CloudHSM provides dedicated, single-tenant hardware security modules that are FIPS 140-2 Level 3 validated and give the customer sole control of the keys. KMS is multi-tenant (though it can be backed by a custom key store on CloudHSM), SSE-S3 uses AWS-managed keys, and Secrets Manager stores secrets rather than providing dedicated HSM hardware.
When a new order is placed, several independent systems (billing, inventory, analytics) must each receive a copy of the event and process it at their own pace. Which pattern delivers this reliably?
- a.Write the event to an EBS volume the systems read
- b.Direct synchronous API calls from the order service to each system
- c.Publish the event to an SNS topic that fans out to a separate SQS queue subscribed by each system✓
- d.A single SQS queue shared by all three systems
An SNS topic with multiple SQS subscribers (the fan-out pattern) delivers a copy of each event to every consumer's own queue, so each system processes independently and durably. A single shared queue means only one consumer gets each message, synchronous calls tightly couple the services so they fail together, and EBS cannot be shared this way.
Showing 40 of 400