Solutions Architect - Associate Practice Questions
Prepare for SAA-C03 with more than an answer.
Unlock the full exam and previous versions
- v1AWS Certified Solutions Architect - Associate 270 questions Current
- SAA-C02Legacy AWS Certified Solutions Architect - Associate 301 questions Locked
- Exam fee
- $150 USD
- Level
- Associate
- Valid for
- 3 years
Domains covered on the exam 4
- Design Secure Architectures30%
- Design Resilient Architectures26%
- Design High-Performing Architectures24%
- Design Cost-Optimized Architectures20%
- 1
A company is using Amazon S3 Intelligent-Tiering for a dataset with unpredictable access patterns. The data is rarely accessed after 90 days. To further reduce costs, the company wants to automatically archive data that has not been accessed for 180 days to the lowest-cost storage suitable for long-term retention, where retrieval times of several hours are acceptable. Which actions should be taken? (Select TWO)
Show answer details
Correct answer: B, C
S3 Intelligent-Tiering has optional, opt-in capabilities to automatically archive data. The first step is to activate the Archive Access or Deep Archive Access tiers in the storage class configuration.
Once activated, you can configure the Deep Archive Access tier to automatically move objects that have not been accessed for a specified period (e.g., 180 days) to S3 Glacier Deep Archive, which is the lowest-cost S3 storage class.
- 2
A company is deploying an internal application on Amazon EC2 instances that needs to access several AWS services, including Amazon S3 and Amazon DynamoDB. According to security best practices, a solutions architect must provide credentials to the application without storing long-term access keys on the instances. What is the most secure and recommended method to grant these permissions?
Show answer details
Correct answer: B
The best practice for granting permissions to applications running on EC2 instances is to use IAM roles. You create a role with the required permissions policies and then attach this role to the instance via an instance profile. The AWS SDKs and CLI on the instance can then automatically retrieve temporary credentials from the instance metadata service, eliminating the need to manage and store long-term access keys on the instance itself.
- 3
A solutions architect is designing a networking strategy for a company that has hundreds of VPCs across multiple AWS accounts in a single region. The company needs to enable inter-VPC communication and also provide a single point of connectivity to their on-premises network via AWS Direct Connect. The solution must be scalable and avoid complex VPC peering configurations.
Which service should be the central component of this design?
Show answer details
Correct answer: B
AWS Transit Gateway is designed to solve this exact problem. It acts as a central hub (a cloud router) that connects VPCs and on-premises networks. This hub-and-spoke model simplifies management and scales easily, as each new VPC only needs to connect to the Transit Gateway instead of being peered with every other VPC. It also provides a single connection point for the on-premises network.
- 4
A media company is streaming a major live event to a global audience. The company uses an Application Load Balancer (ALB) in front of a fleet of EC2 instances. During the event, a DDoS attack is detected. The company has AWS Shield Advanced. Which AWS service should be used in conjunction with the ALB to provide immediate, automated mitigation against common application-layer attacks like SQL injection and cross-site scripting?
Show answer details
Correct answer: C
AWS WAF (Web Application Firewall) is the service designed to protect web applications from common web exploits. It integrates directly with Application Load Balancers, Amazon CloudFront, and API Gateway. By applying managed rule sets (e.g., for SQL injection) and custom rules, it can filter and block malicious traffic at the application layer (Layer 7). While AWS Shield Advanced provides DDoS protection, AWS WAF provides the specific application-layer filtering needed.
- 5
Case Study
A global shipping company, 'GlobalShip', runs its primary logistics management platform in the
eu-west-1AWS Region. The platform is critical for operations and consists of a web front end on Amazon EC2 instances behind an Application Load Balancer, an order processing service on AWS Fargate, and an Amazon Aurora PostgreSQL database. Static assets like shipping labels and documents are stored in Amazon S3.Business Requirements:
Management has mandated a disaster recovery (DR) plan with a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of less than 1 second. The DR site will be in theus-east-1Region. The solution must provide a single, consistent entry point for global users and automatically fail over in the event of a regional outage.Technical Constraints:
- The database must support transactional consistency.
- The solution should minimize data transfer costs during normal operations.
- Failover must be automatic, requiring no manual intervention.
Which architecture should the solutions architect propose to meet all these requirements?
graph TD subgraph eu-west-1 (Primary) ALB1[ALB] Fargate1[Fargate] AuroraW[Aurora Writer] S3_EU[S3 Bucket] end subgraph us-east-1 (DR) ALB2[ALB] Fargate2[Fargate] AuroraR[Aurora Reader] S3_US[S3 Bucket] end User --> AGA AGA{AWS Global Accelerator} --> ALB1 AGA --> ALB2 AuroraW -- Replication --> AuroraR S3_EU -- CRR --> S3_USShow answer details
Correct answer: C
This solution meets all requirements. Amazon Aurora Global Database provides an RPO of less than 1 second through physical replication and an RTO of less than 1 minute, which fits the 15-minute RTO requirement. AWS Global Accelerator provides a static entry point and automatic, rapid failover (within a minute) based on health checks, satisfying the automatic failover requirement. S3 CRR handles the static assets. A pilot light or warm standby deployment in the DR region ensures resources are ready to be scaled up, meeting the RTO. Route 53 failover can have longer DNS propagation delays, and DynamoDB does not meet the transactional consistency requirement of a relational database like Aurora PostgreSQL.
- 6
A financial services company is deploying a critical trading application on AWS that requires extremely low latency communication between a set of Amazon EC2 instances. The application is sensitive to network jitter and must be deployed in a way that minimizes the network path between instances. The architecture must also be resilient to the failure of a single underlying server rack within an Availability Zone. Which deployment strategy should a solutions architect recommend?
Show answer details
Correct answer: C
A partition placement group provides the best balance for this scenario. It spreads instances across distinct underlying hardware (partitions/racks) within an Availability Zone, reducing correlated failures. At the same time, it keeps the instances geographically close within that AZ, which is crucial for low-latency communication. A cluster placement group offers the lowest latency but places instances on the same rack, making it vulnerable to a single rack failure. A spread placement group across multiple AZs would introduce higher latency, which is not suitable for the trading application's requirements.
- 7
A company is migrating its on-premises data warehouse to Amazon Redshift. The security team has mandated that all data loaded into Redshift from Amazon S3 must be encrypted in transit and that the connection must not traverse the public internet. The EC2 instances that orchestrate the
COPYcommands are located in a private subnet within the same Region as the Redshift cluster and the S3 bucket.Which combination of actions will meet these security requirements? (Select TWO)
Show answer details
Correct answer: A, B
A gateway VPC endpoint for Amazon S3 allows traffic from the VPC to S3 to travel over the AWS private network, avoiding the public internet. This is a critical component for meeting the security requirement.
Enhanced VPC Routing forces all COPY and UNLOAD traffic between the Redshift cluster and data repositories (like S3) to go through the VPC. When used with a VPC endpoint, it ensures the traffic stays on the AWS private network.
- 8
A healthcare provider uses an application that processes patient data. The application runs on Amazon EC2 instances and stores data in an Amazon RDS for PostgreSQL database. To comply with regulations, all database credentials must be rotated every 30 days without causing application downtime. The application code cannot be modified to handle credential rotation logic. Which solution provides the MOST secure and automated way to meet this requirement?
Show answer details
Correct answer: B
AWS Secrets Manager is the ideal service for this use case. It provides native integration with Amazon RDS for automated credential rotation, which updates the secret in Secrets Manager and the password in the database simultaneously. Since the application cannot be modified, using IAM authentication or an RDS Proxy would not work. By granting the EC2 instance's IAM role permission to read the secret, the application can fetch the current credentials at runtime without hardcoding them.
- 9
A company is designing a cost-optimization strategy for its stateless, containerized web application running on Amazon ECS with the EC2 launch type. The application experiences predictable traffic, requiring a baseline of 10 instances during business hours (9 AM - 5 PM) and 2 instances overnight and on weekends. It can also tolerate interruptions for non-baseline capacity. Which combination of purchasing options offers the LOWEST cost while meeting the application's availability requirements?
Show answer details
Correct answer: D
This is the most cost-effective strategy. Purchasing Reserved Instances for the 2 instances that run 24/7 provides the highest discount for the constant baseline. For the predictable peak during business hours, Scheduled Scaling can be used to increase the desired capacity. Using Spot Instances for this additional capacity provides significant savings, and is appropriate because the stateless application can tolerate interruptions. This blended approach correctly matches purchasing options to usage patterns.
- 10
A retail company has a global application with a backend running in
us-east-1. The application uses an Amazon Aurora database. Users in Europe and Asia are experiencing high read latency. The company wants to improve the read performance for these users with minimal application changes and provide a disaster recovery solution that allows for a failover to another region in under a minute. Which database architecture should be implemented?Show answer details
Correct answer: C
Amazon Aurora Global Database is specifically designed for this use case. It provides low-latency global reads by placing read replicas in different regions, which have a typical replication lag of under a second. It also offers a robust disaster recovery solution, allowing for a failover to a secondary region in typically less than one minute. This meets both the performance and resiliency requirements with minimal application changes, as the application can use region-specific endpoints.
