Skip to content

Solutions Architect Professional Practice Questions

Prepare for SAP-C02 with more than an answer.

349 questions in the full set19 sample questionsUpdated Feb 3, 2026

Unlock the full exam and previous versions

  • v1AWS Certified Solutions Architect Professional 349 questions Current
  • SAP-C01Legacy AWS Certified Solutions Architect - Professional 704 questions Locked
Exam fee
$300 USD
Time limit
180 minutes
Level
Professional
Valid for
3 years
Domains covered on the exam 4
  1. Design Solutions for Organizational Complexity26%
  2. Design for New Solutions29%
  3. Continuous Improvement for Existing Solutions25%
  4. Accelerate Workload Migration and Modernization20%
  1. 1

    An IoT company collects telemetry data from millions of devices. The data is streamed into Amazon Kinesis Data Streams. A fleet of EC2 instances consumes the data for real-time anomaly detection. The company has observed that during certain times of the day, the EC2 fleet cannot keep up with the data volume, leading to an increase in the IteratorAgeMilliseconds metric for the Kinesis stream. The company needs to scale the consumer fleet automatically based on the processing delay. Which scaling strategy is the MOST appropriate?

    Show answer details

    Correct answer: D

    The IteratorAgeMilliseconds metric is the most direct indicator of consumer processing lag. It measures the age of the last record processed, so a rising value means the consumers are falling behind. Basing the scaling policy on this metric ensures that the consumer fleet scales precisely when it needs to, in direct response to its processing performance against the stream. A step scaling policy is appropriate as it allows for more aggressive scaling actions if the iterator age continues to climb, ensuring a rapid response to processing backlogs.

  2. 2

    A company has a hybrid architecture where an on-premises data center is connected to AWS via a 10 Gbps AWS Direct Connect connection. Multiple VPCs are attached to a central Transit Gateway for inter-VPC and on-premises communication. The network team needs to inspect all traffic flowing between the on-premises network and all VPCs for malicious activity. The inspection must be done by a centralized fleet of next-generation firewall (NGFW) appliances deployed in a dedicated 'Inspection VPC'. The solution must be highly available and scalable.

    What is the most effective way to configure the routing to enforce this traffic inspection?

    Show answer details

    Correct answer: A

    This routing configuration creates a centralized inspection model. By directing all traffic from on-premises destined for the VPCs (via a default route or specific routes) to the Inspection VPC first, and likewise directing all traffic from the VPCs destined for on-premises to the Inspection VPC, you force all traffic through the NGFW appliances. The Inspection VPC then has routes to send the inspected traffic to its final destination (either back to the Transit Gateway for the workloads VPCs or for the on-premises network). Using separate TGW route tables for on-prem, workload VPCs, and the inspection VPC allows for this granular control.

  3. 3

    A company runs a critical application on AWS that uses an Amazon Aurora global database with a primary Region in us-east-1 and a secondary Region in eu-west-1. The application endpoints are managed via Amazon Route 53. During a disaster recovery test, the team initiated a manual, planned failover of the global database from us-east-1 to eu-west-1. While the database failover itself completed successfully, the application experienced several hours of downtime because the application servers continued to send write traffic to the old primary in us-east-1. A solutions architect needs to design a solution to automate the application-level failover to match the database failover. Which solution will be the MOST reliable?

    Show answer details

    Correct answer: C

    This is the most direct and reliable event-driven approach. Amazon RDS and Aurora emit detailed events to Amazon EventBridge for significant lifecycle changes, including failovers. The specific event RDS-EVENT-0191 signals the successful completion of a failover for a global database cluster. By creating an EventBridge rule to capture this specific event, you can trigger a Lambda function precisely when the database failover is complete. The Lambda function can then reliably perform the necessary downstream actions, such as updating DNS records in Route 53, to redirect application traffic.

  4. 4

    A company is migrating its entire on-premises VMware environment to AWS. The migration team has decided to use AWS Application Migration Service (MGN) for the migration. The on-premises environment consists of approximately 500 servers. The security team requires that all data replication traffic from the on-premises data center to the AWS replication staging area must be private and encrypted, and must not traverse the public internet. The company has an existing AWS Direct Connect connection. What steps must be taken to ensure the replication traffic meets the security requirements? (Select TWO)

    Show answer details

    Correct answer: C, D

    To ensure private replication, you must avoid the public endpoints of the AWS MGN service. This is achieved by creating interface VPC endpoints (powered by AWS PrivateLink) for the MGN service within your VPC. This provides private IPs for the service. Then, during the installation of the AWS Replication Agent on the on-premises servers, you must explicitly configure them to communicate with these private endpoints over your Direct Connect private VIF. This combination ensures that all control and data replication traffic remains on the private network.

  5. 5

    A company is using Amazon S3 as a data lake. Different teams within the company own and produce datasets, storing them in separate S3 buckets within their own AWS accounts. A central data science team, operating from its own AWS account, needs read-only access to all of these datasets for analytics purposes. The company wants a scalable and manageable solution to grant this cross-account access without using IAM users and access keys. The solution must provide a centralized way to manage data access permissions. Which AWS service should be used to build this solution?

    Show answer details

    Correct answer: C

    AWS Lake Formation is designed for this exact use case. It allows you to build a secure data lake and provides a centralized console to manage permissions and access control for data stored in Amazon S3. The data-producing accounts (producers) can register their data locations and then use Lake Formation's simplified grant/revoke mechanism to share specific tables or databases with the data science account (consumer). This method is more scalable and manageable than maintaining hundreds of IAM roles or S3 bucket policies, and it provides fine-grained access control.

  6. 6

    A financial services company is modernizing its on-premises data warehouse to AWS. The current system uses a legacy ETL tool that is not cloud-native. The company wants to build a new data lake on Amazon S3 and use a combination of serverless and managed services for ingestion, processing, and analytics. A key requirement is to provide business analysts with a unified SQL interface to query both structured data in Amazon Redshift and semi-structured data (JSON, Parquet) in the data lake. The solution must enforce fine-grained access control at the table and column level for all queries. Which solution meets these requirements most effectively?

    Show answer details

    Correct answer: B

    This is the optimal solution. Amazon Redshift Spectrum allows querying data in Amazon S3 directly from Redshift, providing a unified SQL interface. AWS Lake Formation provides a centralized way to manage fine-grained permissions (table, column, row-level) for data in both the S3 data lake (via the AWS Glue Data Catalog) and Amazon Redshift. This approach meets all requirements for a unified interface and granular access control with managed services.

  7. 7

    A large media organization operates a global video-on-demand platform. The architecture uses AWS Elemental MediaConvert for transcoding, Amazon S3 for storage, and Amazon CloudFront for delivery. The master video files are stored in an S3 bucket in the us-east-1 Region. To improve transcoding performance and resilience, the company wants to distribute the transcoding workload across us-east-1, eu-west-1, and ap-southeast-1. The goal is to automatically route an incoming transcoding job to the Region with the lowest processing load and ensure the output is available globally with low latency. Which architecture should be implemented to achieve this?

    (Select TWO).

    Show answer details

    Correct answer: A, C

    Combining S3 CRR with an EventBridge global endpoint provides a robust, resilient, and load-distributed solution. CRR ensures the source media is available locally in each processing Region, reducing latency and data transfer costs for transcoding. The EventBridge global endpoint with its health-checking and failover capabilities allows for intelligent routing of job requests to the healthiest and most available Region, effectively distributing the load.

  8. 8

    A hospital is deploying a critical patient records application on AWS, which must comply with HIPAA regulations. The architecture consists of an Application Load Balancer (ALB), an Amazon EC2 Auto Scaling group, and an Amazon Aurora PostgreSQL database. A recent security audit requires that all network traffic between the application servers and the database be inspected for potential SQL injection attacks by a third-party virtual appliance. This inspection must occur without traffic leaving the VPC, and the solution must be highly available. The architecture is deployed across three Availability Zones.

    Which networking design meets these requirements?

    Show answer details

    Correct answer: B

    This is the correct architecture for transparently inserting a fleet of security appliances into a network path. The Gateway Load Balancer is specifically designed for this purpose, acting as a transparent bump-in-the-wire. It allows you to scale the appliance fleet while the GWLB endpoints in each AZ provide a highly available, fixed next-hop for routing. This ensures all traffic from the application servers to the database is inspected without any changes to the application code and maintains high availability.

  9. 9

    A consultant is reviewing an existing AWS environment for a fast-growing startup. The startup has a single AWS account where all resources (dev, test, prod) are deployed within a single default VPC. This has led to IAM policies becoming overly complex and has caused several accidental terminations of production resources. The startup wants to implement a multi-account structure that improves security, provides cost allocation visibility, and establishes guardrails without slowing down developers. Which of the following is the most effective strategy to recommend?

    Show answer details

    Correct answer: C

    AWS Control Tower is the most comprehensive and recommended solution for establishing a secure, well-architected multi-account environment. It automates the setup of a landing zone using best practices, including creating a foundational set of OUs, accounts (Log Archive, Audit), centralized logging with AWS CloudTrail and AWS Config, and a set of guardrails using SCPs. This directly addresses the startup's need for better security, cost visibility, and governance without requiring extensive manual setup.

Create an account to continue.