AWS Certified Solutions Architect – Associate — All Questions
The figures these questions turn on, pooled by value and printable, with a side to write them from memory: the cram packet, $6.99 →
96 questions
A company wants its RDS database to automatically fail over to a standby in another Availability Zone with minimal downtime during an AZ outage. Which feature provides this?
- a.Manual snapshots taken hourly
- b.Storing backups in S3 Glacier
- c.RDS Multi-AZ deployment with a synchronous standby✓
- d.A read replica in the same AZ
RDS Multi-AZ maintains a synchronous standby replica in a second Availability Zone and automatically fails over to it if the primary fails, providing high availability. Read replicas are for scaling reads and are asynchronous, not automatic failover. Snapshots and Glacier backups aid recovery but do not deliver automatic failover.
To decouple a fluctuating order-processing workload so that a spike in orders does not overwhelm the processing tier, which service should sit between the producers and consumers?
- a.Amazon SQS queue that the processing tier polls✓
- b.An EBS volume shared across instances
- c.A single large EC2 instance for all processing
- d.Amazon Route 53 latency routing
Amazon SQS buffers messages, letting the processing tier consume at its own pace and absorbing spikes without dropping work, which improves resilience and enables independent scaling. A single instance is a bottleneck and single point of failure. Route 53 handles DNS routing and EBS is block storage, neither of which decouples the tiers.
A stateless web tier runs on EC2 across two Availability Zones. The architecture must automatically replace unhealthy instances and adjust capacity to demand. Which combination achieves this?
- a.An Application Load Balancer only, with fixed instances
- b.Manually launching instances when alarms fire
- c.A single EC2 instance with a static Elastic IP
- d.An Auto Scaling group spanning both AZs behind an Application Load Balancer with health checks✓
An Auto Scaling group distributed across multiple AZs launches replacement instances when health checks fail and scales in or out based on demand, while the ALB spreads traffic across healthy targets. A single instance or manual intervention cannot self-heal. An ALB alone does not replace failed instances or change capacity.
A shared file system must be mounted concurrently by hundreds of Linux EC2 instances across multiple Availability Zones, and it must scale storage automatically. Which service fits best?
- a.Amazon EFS mounted from all instances✓
- b.A single S3 bucket mounted as a block device
- c.Amazon EBS volume attached to each instance
- d.Instance store volumes
Amazon EFS is a fully managed, elastic NFS file system that many instances across multiple AZs can mount simultaneously, scaling capacity automatically. A standard EBS volume attaches to one instance in one AZ, and instance store is ephemeral. S3 is object storage and is not a POSIX file system for concurrent block mounts.
A company needs a relational database that provides MySQL compatibility, replicates six copies of data across three Availability Zones, and offers fast automated failover. Which service best meets this?
- a.Amazon Redshift
- b.Amazon Aurora✓
- c.A self-managed MySQL cluster on a single EC2 instance
- d.Amazon DynamoDB
Aurora is MySQL- and PostgreSQL-compatible and stores six copies of data across three AZs, providing high durability and fast failover to a replica. A single EC2 MySQL instance is a single point of failure. DynamoDB is a NoSQL key-value store and Redshift is a data warehouse, neither of which is a MySQL-compatible relational OLTP database.
A global application must route users to a healthy Region and fail over automatically to a secondary Region if the primary becomes unavailable. Which approach provides this DNS-level resilience?
- a.A single Elastic IP in one Region
- b.A NAT gateway in each subnet
- c.An Application Load Balancer spanning Regions
- d.Amazon Route 53 with health checks and failover routing policy✓
Route 53 failover routing uses health checks to detect an unhealthy primary endpoint and automatically returns the secondary Region's record, enabling cross-Region DNS failover. An ALB cannot span multiple Regions. Elastic IPs and NAT gateways are single-Region constructs and do not provide global failover.
When a new order is placed, several independent systems (billing, inventory, analytics) must each receive a copy of the event and process it at their own pace. Which pattern delivers this reliably?
- a.Write the event to an EBS volume the systems read
- b.Direct synchronous API calls from the order service to each system
- c.Publish the event to an SNS topic that fans out to a separate SQS queue subscribed by each system✓
- d.A single SQS queue shared by all three systems
An SNS topic with multiple SQS subscribers (the fan-out pattern) delivers a copy of each event to every consumer's own queue, so each system processes independently and durably. A single shared queue means only one consumer gets each message, synchronous calls tightly couple the services so they fail together, and EBS cannot be shared this way.
A workload must process uploaded jobs asynchronously and automatically scale processing with the backlog, without managing servers. Which decoupled design fits best?
- a.Run a single always-on EC2 instance polling a database
- b.Store jobs in DynamoDB and process them manually
- c.Place jobs in an SQS queue that triggers a Lambda function to process each message✓
- d.Have clients call a Lambda function synchronously and wait for completion
An SQS queue as an event source for Lambda decouples producers from processing and scales the number of concurrent Lambda executions with the queue backlog, all serverless. A single EC2 poller is a bottleneck and single point of failure, synchronous invocation removes the buffering benefit, and manual processing does not scale.
A gaming application needs a database that provides low-latency reads and writes to users in multiple Regions with active-active multi-Region replication. Which option provides this natively?
- a.A single-Region RDS instance
- b.Amazon Redshift
- c.An EC2-hosted database with manual backups
- d.Amazon DynamoDB global tables✓
DynamoDB global tables replicate data across multiple Regions with multi-active read/write access and automatic conflict resolution, giving low-latency local access and Regional resilience. A single-Region RDS instance has no cross-Region active-active writes, Redshift is an analytics warehouse, and a self-managed database would require building replication and failover manually.
A team wants to protect S3 objects from accidental overwrites and deletions so any previous version can be restored. Which feature should be enabled?
- a.S3 Intelligent-Tiering
- b.Requester Pays
- c.S3 Versioning, optionally with MFA delete✓
- d.S3 Transfer Acceleration
S3 Versioning retains every version of an object, so an accidental overwrite or delete can be undone by restoring a prior version, and MFA delete adds protection against permanent deletion. Transfer Acceleration speeds uploads, Intelligent-Tiering optimizes cost, and Requester Pays shifts data-transfer billing, none of which protect against data loss.
Want these explained in order? AWS Solutions Architect Associate (SAA-C03) — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →
For disaster recovery and compliance, objects written to an S3 bucket in us-east-1 must be automatically copied to a bucket in eu-west-1. Which feature achieves this?
- a.S3 Cross-Region Replication (CRR)✓
- b.Enabling static website hosting
- c.S3 lifecycle transition to Glacier
- d.S3 event notifications to SNS
S3 Cross-Region Replication automatically and asynchronously copies newly written objects to a bucket in a different Region, supporting DR and data-residency needs. Lifecycle transitions change storage class within a Region, event notifications only signal changes, and website hosting serves content rather than replicating it.
An RDS deployment currently uses only read replicas for scaling. The team is surprised that a primary-instance failure caused downtime. What change provides automatic failover for high availability?
- a.Add more read replicas in the same AZ
- b.Increase the primary instance size
- c.Take more frequent snapshots
- d.Convert the deployment to Multi-AZ so a synchronous standby can fail over automatically✓
Read replicas scale read traffic and use asynchronous replication; they are not an automatic failover target. A Multi-AZ deployment maintains a synchronous standby that RDS promotes automatically if the primary fails, providing high availability. Larger instances or more snapshots do not deliver automatic failover.
Behind a load balancer, an instance occasionally becomes unhealthy but still receives user traffic, causing errors. What ensures traffic is sent only to healthy instances?
- a.Move all the instances into a single Availability Zone
- b.Increase the instance size
- c.Configure Elastic Load Balancer health checks so unhealthy targets are automatically removed from rotation✓
- d.Give each instance a static Elastic IP
Load balancer health checks continuously probe targets and stop routing to any that fail, so users are served only by healthy instances (and Auto Scaling can replace them). Elastic IPs, larger instances, and consolidating into one AZ do not detect health and would reduce, not improve, resilience.
To survive the loss of an entire Availability Zone with no manual intervention, how should a stateless application fleet be deployed?
- a.A single large instance with a standby powered off
- b.Two instances in the same AZ behind a load balancer
- c.All instances in one AZ with frequent backups
- d.An Auto Scaling group spanning multiple AZs behind a load balancer, so capacity is redistributed if an AZ fails✓
An Auto Scaling group across multiple AZs behind a load balancer automatically launches replacement capacity in the healthy AZs if one AZ fails, with no manual action. Concentrating instances in a single AZ, a powered-off standby, or two instances in the same AZ all leave the workload exposed to an AZ-level outage.
A company wants Route 53 to return several healthy IP addresses for its endpoints and stop returning any that fail health checks, giving simple client-side load spreading and improved availability. Which routing policy fits?
- a.Latency routing to one Region only
- b.Multivalue answer routing with health checks✓
- c.Simple routing with a single record
- d.Geolocation routing
Multivalue answer routing returns up to eight healthy records at random and omits any that fail their associated health checks, improving availability with basic load spreading. Simple routing returns one static record with no health awareness, geolocation routes by user location, and latency routing optimizes for lowest latency rather than returning multiple healthy answers.
Some messages repeatedly fail processing and are blocking an SQS queue by being retried endlessly. What is the recommended way to isolate these poison messages for later inspection?
- a.Configure a dead-letter queue with a maxReceiveCount redrive policy✓
- b.Increase the visibility timeout to several days
- c.Delete the main queue and recreate it
- d.Switch consumers to long polling
A dead-letter queue with a redrive policy moves a message aside after it exceeds the maxReceiveCount, so poison messages stop blocking the main queue and can be inspected separately. Recreating the queue loses messages, a longer visibility timeout just delays retries, and long polling reduces empty receives but does not isolate failures.
A payment workflow requires that messages be processed in the exact order they are sent and that duplicates are not introduced. Which SQS configuration meets this?
- a.An SQS FIFO queue✓
- b.A standard queue with a dead-letter queue
- c.A standard queue with best-effort ordering
- d.An SNS standard topic
SQS FIFO queues guarantee first-in-first-out ordering and exactly-once processing with deduplication, which suits strict-order payment workflows. Standard queues provide only best-effort ordering and at-least-once delivery, and an SNS standard topic is a pub/sub notification service without ordering guarantees.
A company wants to route events from many AWS services and SaaS partners to different targets based on the event content, using rules and schemas without running any polling infrastructure. Which service fits best?
- a.Amazon Kinesis Data Streams
- b.AWS Step Functions
- c.Amazon EventBridge✓
- d.Amazon SQS
Amazon EventBridge is a serverless event bus that ingests events from AWS services and SaaS partners and routes them to targets using content-based rules, with a schema registry. SQS is a point-to-point queue, Step Functions orchestrates workflows, and Kinesis is for high-throughput streaming rather than rule-based event routing.
An enterprise must centrally schedule, enforce, and audit backups across EBS, RDS, DynamoDB, and EFS with consistent retention policies. Which service provides this?
- a.CloudWatch alarms
- b.AWS Backup with backup plans and policies✓
- c.S3 lifecycle rules
- d.Manual backup scripts on each service
AWS Backup centralizes backup scheduling, retention, and compliance reporting across many AWS services from one place, replacing per-service scripts. Custom scripts are error-prone and hard to audit, S3 lifecycle rules apply only to S3 objects, and CloudWatch alarms monitor metrics rather than manage backups.
An architecture uses a single NAT gateway in one AZ for outbound internet from private subnets in three AZs. How should this be made resilient to an AZ failure?
- a.Remove the NAT gateway and give instances public IPs
- b.Replace the NAT gateway with a single larger instance
- c.Route all subnets through the one NAT gateway with a backup Elastic IP
- d.Deploy a NAT gateway in each AZ and route each private subnet to the NAT gateway in its own AZ✓
A NAT gateway is AZ-scoped, so a single one is a single point of failure; deploying one per AZ and routing each private subnet to its local NAT gateway removes the cross-AZ dependency and survives an AZ outage. A larger instance or extra Elastic IP does not add AZ redundancy, and public IPs would expose the instances.
A company wants to host a highly available static website with minimal operational overhead and no servers to patch or scale. Which architecture is most resilient?
- a.Two EC2 instances in one AZ
- b.A single EC2 web server with a static IP
- c.Store the site in S3 and serve it globally through CloudFront✓
- d.An on-premises server replicated nightly
Hosting a static site in S3 (durable across multiple AZs by design) and serving it via CloudFront provides high availability, global caching, and no servers to manage. A single EC2 server or two instances in one AZ introduce failure points, and an on-premises server with nightly replication offers far weaker availability.
An application must remain available even if an entire AWS Region becomes unavailable, with the ability to serve users from a second Region. Which approach provides Regional resilience?
- a.Increase the instance sizes in one Region so it has enough spare capacity to absorb a Regional failure
- b.Deploy all resources across three Availability Zones within a single Region and rely on AZ isolation for outages
- c.Deploy the workload in two Regions with data replication and use Route 53 to fail over between them✓
- d.Take frequent EBS snapshots in the primary Region so the environment can be rebuilt quickly after an outage
Running the workload in two Regions with cross-Region data replication and Route 53 failover lets traffic shift to the healthy Region if one Region fails, providing Regional resilience. Multi-AZ within one Region survives an AZ failure but not a full Region outage, larger instances do not address Regional loss, and snapshots in the failed Region may be unreachable during the outage.
A stateless application behind an Application Load Balancer must add capacity automatically when average CPU rises and remove it when demand falls, keeping at least two instances running. Which configuration provides this?
- a.An Auto Scaling group with a minimum of two, a target-tracking policy on average CPU, and the ALB as its target✓
- b.A single large instance that is manually resized whenever the operations team observes sustained high CPU load
- c.A scheduled action that doubles the fleet every morning and halves it every night regardless of actual demand
- d.Two fixed instances with no scaling, sized for the highest traffic the application has ever received to date
An Auto Scaling group with a minimum size of two and a target-tracking policy on average CPU adds and removes instances automatically in response to real demand while keeping a floor for availability. A manually resized instance and a fixed pair do not scale, and a purely scheduled double/halve ignores actual load and can under- or over-provision.
A company needs a load balancer that handles millions of requests per second for a TCP-based application, preserves the client source IP, and provides ultra-low latency with a static IP per Availability Zone. Which load balancer fits?
- a.A Classic Load Balancer running in TCP passthrough mode for backward compatibility with older applications
- b.A Network Load Balancer✓
- c.An Application Load Balancer configured with host-based and path-based routing rules for the TCP application
- d.A gateway load balancer that inserts third-party virtual appliances into the traffic path for inspection
A Network Load Balancer operates at layer 4, scales to millions of requests per second with ultra-low latency, can preserve the client source IP, and provides a static IP per AZ. An ALB is layer 7 for HTTP/HTTPS, the Classic Load Balancer is legacy, and a Gateway Load Balancer is for inserting inspection appliances, not general TCP load balancing.
A company wants HTTP path-based routing so that requests to /api go to one target group and requests to /images go to another, all behind a single entry point. Which load balancer supports this?
- a.A Gateway Load Balancer, which routes based on the request path to different pools of inspection appliances
- b.An Application Load Balancer with listener rules that route by URL path to different target groups✓
- c.A Network Load Balancer, which inspects the URL path of each TCP segment to choose the target group
- d.A Classic Load Balancer, which supports modern path-based and host-based routing to multiple target groups
An Application Load Balancer operates at layer 7 and supports listener rules that route by URL path (and host) to different target groups, exactly matching the requirement. NLB is layer 4 and cannot parse URL paths, the Classic Load Balancer lacks modern content-based routing, and a Gateway Load Balancer distributes traffic to appliances rather than doing path-based application routing.
A global company wants users to be directed to the Regional endpoint that gives them the lowest network latency, automatically. Which Route 53 routing policy provides this?
- a.Latency-based routing, which returns the Region that provides the lowest latency for each requesting user✓
- b.Weighted routing, which sends a fixed percentage of users to each Region regardless of their network latency
- c.Multivalue answer routing, which returns several Regional records at random for the client to choose among
- d.Failover routing, which sends all users to the primary Region until it is unhealthy and then to the secondary
Latency-based routing directs each user to the Region that offers the lowest latency from their location, improving performance for a global audience. Weighted routing splits traffic by percentage, failover routing is for active-passive DR, and multivalue routing returns multiple healthy records without optimizing for latency.
A company runs an active-passive setup with a primary web endpoint and a standby endpoint in another Region. Route 53 must send all traffic to the primary while it is healthy and automatically switch to the standby if the primary fails. Which policy and feature combination is correct?
- a.Simple routing with two IP addresses in one record so clients retry the second address after the first fails
- b.Weighted routing with equal weights so both endpoints receive traffic and one absorbs the load if the other fails
- c.Latency routing so the standby is used only when it happens to offer lower latency than the primary endpoint
- d.Failover routing with health checks on the primary so DNS returns the standby only when the primary is unhealthy✓
Failover routing with a health check on the primary returns the primary while healthy and switches to the standby when the health check fails, matching the active-passive requirement. Weighted routing would send traffic to both continuously, latency routing does not implement active-passive failover, and simple routing with multiple IPs has no health awareness.
An order-intake API must never lose an order even if the downstream processing service is temporarily down. Which design ensures durability and decoupling?
- a.Log each order to the application's local disk and have an operator replay the log after an outage manually
- b.Have the API write each order to an SQS queue that the processing service consumes when it is available✓
- c.Have the API call the processing service synchronously and return an error to the customer if it is down
- d.Store orders in an in-memory cache on the API instances until the processing service comes back online
Writing orders to an SQS queue decouples intake from processing and durably retains messages until the consumer is available, so nothing is lost during a downstream outage. Synchronous calls fail when the downstream is down, an in-memory cache is lost if an instance restarts, and manual local-log replay is fragile and not durable across instance failures.
A notification system must deliver each published event to an email endpoint, an SQS queue for processing, and an HTTPS webhook simultaneously. Which service natively fans a single message out to all three?
- a.Amazon SQS, by configuring a single queue with three different consumers polling it in parallel for the same message
- b.Amazon Kinesis Data Streams, which duplicates each record to email, queue, and webhook consumers automatically
- c.Amazon EventBridge Scheduler, which sends the event to each of the three destinations on a recurring schedule
- d.Amazon SNS, which delivers each published message to all subscribed endpoints including email, SQS, and HTTPS✓
Amazon SNS is a pub/sub service that pushes each published message to all subscribers, and it supports email, SQS, HTTPS, Lambda, and more as subscription types. A single SQS queue delivers each message to only one consumer, Kinesis is for streaming data rather than multi-protocol fan-out, and EventBridge Scheduler triggers actions on a schedule, not per-message fan-out.
A company's RDS MySQL database is a single point of failure, and the business requires automatic failover within a couple of minutes if the primary or its Availability Zone fails, with no data loss on committed transactions. Which option meets this?
- a.Increase the primary's instance size and provisioned IOPS so it is far less likely to fail in the first place
- b.Add several read replicas across Availability Zones and promote one manually if the primary instance fails
- c.Take automated snapshots every five minutes and restore from the latest snapshot when the primary fails
- d.Convert the database to a Multi-AZ deployment with a synchronous standby that fails over automatically✓
A Multi-AZ deployment keeps a synchronous standby in another AZ and fails over to it automatically, typically within a couple of minutes, preserving committed transactions. Read replicas are asynchronous and require manual promotion, restoring from snapshots loses recent data and takes longer, and a bigger instance does not provide automatic failover.
A reporting workload runs heavy read queries that are hurting the performance of the transactional primary database, and the team also wants those reads to survive the loss of the primary's Availability Zone. Which combination best fits?
- a.Enable Multi-AZ so the synchronous standby absorbs the reporting reads while the primary handles writes only
- b.Take frequent snapshots and run the reporting queries against a database restored from the latest snapshot
- c.Add read replicas in different Availability Zones and direct reporting reads to them✓
- d.Move the reporting queries to the same primary but schedule them for off-peak hours to reduce contention
Read replicas offload read traffic from the primary and, when placed in different Availability Zones, keep serving reads even if one AZ (including the primary's) is affected. Multi-AZ standbys do not serve read traffic, restoring from snapshots gives stale data and operational overhead, and scheduling reads on the primary still competes with transactional writes.
A gaming leaderboard must provide single-digit millisecond reads and writes to players in North America, Europe, and Asia, with each Region able to accept writes locally and replicate to the others. Which database feature provides this?
- a.A single Amazon RDS instance in one Region with read replicas placed in the other two Regions for local reads
- b.An EC2-hosted database in one Region fronted by CloudFront to cache leaderboard reads at edge locations
- c.Amazon Redshift with cross-Region snapshot copy so each Region can query the latest analytical data locally
- d.Amazon DynamoDB global tables with a table replica in each of the three Regions✓
DynamoDB global tables replicate a table across multiple Regions with multi-active read/write access and low latency in each Region, exactly fitting a globally distributed leaderboard. RDS read replicas cannot accept local writes in each Region, Redshift is an analytics warehouse, and caching reads via CloudFront does not provide local low-latency writes or multi-Region write acceptance.
A company stores critical objects in S3 Standard and wants to know how durable that storage is and what protects against the loss of a single facility. Which statement is correct?
- a.S3 Standard stores objects in a single Availability Zone, so a second copy in another bucket is required for durability
- b.S3 Standard requires the customer to enable replication before any redundancy across facilities is provided at all
- c.S3 Standard automatically stores objects redundantly across multiple Availability Zones for very high durability✓
- d.S3 Standard keeps only one copy but compensates with frequent integrity checks that rebuild lost objects on demand
S3 Standard is designed for very high durability by automatically storing data redundantly across multiple Availability Zones, so the loss of one facility does not lose data. It is not single-AZ (that is One Zone-IA), it does not require customer-enabled replication for baseline redundancy, and it does not keep only a single copy.
A team wants any accidental deletion or overwrite of important S3 objects to be recoverable, and wants deleted objects to be retrievable rather than permanently gone. Which feature should be enabled?
- a.S3 Intelligent-Tiering, which retains deleted objects in a cold tier from which they can be recovered later
- b.S3 Versioning, which preserves previous versions and adds a delete marker instead of permanently removing objects✓
- c.S3 Cross-Region Replication, which restores a deleted object automatically from the destination bucket when needed
- d.S3 Transfer Acceleration, which keeps a rollback copy of each overwritten object at the nearest edge location
S3 Versioning retains every version and, on delete, adds a delete marker rather than erasing the object, so prior versions and deleted objects remain recoverable. Cross-Region Replication copies new objects but does not by itself restore deletions in the source, Intelligent-Tiering only optimizes cost, and Transfer Acceleration is an upload-speed feature with no rollback capability.
For disaster recovery, a company must keep a copy of all objects written to its primary bucket in a bucket located in a second Region, and existing objects at the time replication is enabled should also be copied. What must be configured?
- a.A one-time manual copy of the bucket contents, after which new objects will replicate on their own automatically
- b.S3 event notifications that trigger a Lambda function to occasionally copy random objects to the other Region
- c.S3 lifecycle rules that transition objects to the second Region as they age past a configured number of days
- d.S3 Cross-Region Replication with a rule to replicate new objects, plus S3 Batch Replication for existing objects✓
Cross-Region Replication automatically copies newly written objects to a destination bucket in another Region, and S3 Batch Replication (or batch copy) handles objects that existed before replication was enabled. A one-time manual copy does not keep future objects in sync, lifecycle rules change storage class within a Region, and ad hoc Lambda copying is not a reliable replication mechanism.
A batch of messages is failing repeatedly and being redelivered endlessly from an SQS queue, blocking healthy messages behind them. What is the standard way to set aside these failing messages for later analysis?
- a.Enable long polling on the consumers so that failing messages are naturally skipped during each poll cycle
- b.Increase the queue's visibility timeout to several hours so the failing messages are hidden for longer periods
- c.Configure a dead-letter queue with a redrive policy so messages exceeding the max receive count are moved aside✓
- d.Purge the entire queue periodically to remove the failing messages along with everything else waiting in it
A dead-letter queue with a redrive policy moves a message aside once it exceeds the configured maxReceiveCount, unblocking the main queue and preserving the failing messages for investigation. A longer visibility timeout only delays redelivery, long polling reduces empty responses but does not skip poison messages, and purging the queue destroys good messages too.
A financial application must process transactions in strict order and never process the same transaction twice, even under retries. Which messaging option guarantees ordering and deduplication?
- a.An SQS FIFO queue with content-based deduplication and message group IDs✓
- b.An SQS standard queue, which guarantees strict ordering and exactly-once delivery for financial transactions
- c.An SNS standard topic subscribed by the processing service, which preserves the publish order of messages
- d.A Kinesis Data Stream with a single shard, which guarantees no message is ever delivered more than once
An SQS FIFO queue provides first-in-first-out ordering and exactly-once processing with deduplication (via content-based dedup or dedup IDs) and message group IDs for ordered groups. Standard queues offer only best-effort ordering and at-least-once delivery, an SNS standard topic does not guarantee order, and a single-shard Kinesis stream orders records but does not provide SQS-style deduplication of consumer processing.
A team wants to route events from AWS services and SaaS partners to different targets based on the event's content, with schema discovery and no servers to manage. Which service is the right fit?
- a.Amazon Kinesis Data Firehose, which filters streaming events and delivers each to a different downstream target
- b.AWS Step Functions, which polls each source service and branches events to targets based on their content
- c.Amazon EventBridge, which routes events to targets using content-based rules and offers a schema registry✓
- d.Amazon SQS, using message attributes and multiple queues to pattern-match each event to the correct destination
Amazon EventBridge is a serverless event bus that matches events with content-based rules and routes them to many target types, and it includes a schema registry for discovery. SQS is a point-to-point queue without content-based routing, Step Functions orchestrates workflows rather than acting as an event router, and Firehose loads streaming data to a few destinations, not rule-based multi-target routing.
An enterprise must centrally schedule and enforce backups with defined retention across EBS, RDS, DynamoDB, and EFS, and demonstrate compliance in audits. Which service provides this?
- a.S3 lifecycle policies applied to every service's data so old backups transition and expire according to the rules
- b.CloudWatch alarms that notify the team when a resource has not been backed up within the required window
- c.Per-service cron jobs on an EC2 instance that call each service's snapshot API on the required schedule nightly
- d.AWS Backup with backup plans that define schedules and retention and produce compliance reports✓
AWS Backup centralizes backup scheduling, retention, and compliance across many AWS services from a single place with audit reporting. Custom cron jobs are error-prone and hard to audit, S3 lifecycle rules apply only to S3 objects, and CloudWatch alarms only notify rather than perform and govern backups.
A private subnet in each of three Availability Zones currently routes outbound internet traffic through a single NAT gateway in one AZ. If that AZ fails, all outbound access is lost. How should the design be made resilient?
- a.Add a second Elastic IP to the existing NAT gateway so it can continue operating if its Availability Zone fails
- b.Deploy a NAT gateway in each Availability Zone and point each private subnet's route to the NAT gateway in its own AZ✓
- c.Route all three private subnets through two NAT gateways placed in the same Availability Zone for redundancy
- d.Replace the NAT gateway with a NAT instance on a larger EC2 type so it can tolerate an Availability Zone outage
NAT gateways are AZ-scoped, so deploying one per AZ and routing each private subnet to its local NAT gateway removes the single-AZ dependency and survives an AZ failure. Adding an Elastic IP does not add AZ redundancy, a larger NAT instance still lives in one AZ and is a single point of failure, and two NAT gateways in the same AZ both fail together.
Showing 40 of 96