Démarrer avec AWS
AWS Services Practice Exam
An 80-item independent practice exam across eight AWS service domains, shared by all five certification tracks, with full explanations and a timed interactive mode.
An 80-item independent practice exam across the AWS service surface that the five certification tracks share. It is built at associate depth — scenario stems, plausible distractors, and explanations that say why the other three options fail. It is not an official AWS practice exam, contains no official exam questions, and is not affiliated with, endorsed by or approved by AWS.
One bank serves all five tracks because the underlying service knowledge is the same; only the emphasis differs. Use the domain table below to read your result against the exam you are actually sitting.
Instructions
- Time: 160 minutes if you run it timed — two minutes per item, matching the associate pacing of 65 items in 130 minutes. Take it untimed the first time.
- Items: 80, all multiple choice with a single correct answer out of four.
- No guessing penalty: an unanswered item is scored incorrect, so answer everything and flag what you want to revisit.
- Target: at least 75% raw before you book an associate exam, and 65% before a foundational one — this bank is pitched harder than CLF-C02 or AIF-C01.
Domain distribution
| # | Domain | Items |
|---|---|---|
| 1 | Compute and Containers | 6 |
| 2 | Storage and Data Management | 11 |
| 3 | Networking and Content Delivery | 15 |
| 4 | Databases | 11 |
| 5 | Serverless and Application Integration | 10 |
| 6 | Security, Identity and Compliance | 9 |
| 7 | Monitoring, Operations and Deployment | 13 |
| 8 | Cost Management and Multi-Account Governance | 5 |
| Total | 80 |
These are service domains, not any exam’s official blueprint. To map a weak result onto your own exam:
| Your exam | Read these domains hardest |
|---|---|
| Cloud Practitioner | 2, 3, 4, 6, 8 — and treat depth beyond the explanation as optional |
| Solutions Architect – Associate | All eight; 3, 4 and 6 carry the most weight |
| CloudOps Engineer – Associate | 7 first, then 3, 6 and 8 |
| Developer – Associate | 5 and 6 first, then 7 |
| AI Practitioner | 6 and 8 for the governance items; the rest is background |
Score interpretation
Associate exams are scored on a scaled 100–1,000 range with a 720 pass mark; the two foundational exams pass at 700. AWS does not publish how a raw percentage maps to a scaled score, so the figure below is indicative only. Your raw percentage is the real signal.
| Raw score | Reading |
|---|---|
| under 55% | Not ready. Go back to the note pages for your two weakest domains before re-sitting. |
| 55–69% | Foundational-ready, associate-risky. Fine for CLF-C02 or AIF-C01; keep studying for an associate exam. |
| 70–79% | Approaching the associate line. Close the two weakest domains and re-sit timed. |
| 80% and above | Strong. Book with confidence, and use the explanations for the handful you missed. |
Before you start
Sit this early, not last. Its job is diagnostic: two weak domains after 80 items tell you where the next ten hours of study go, which is worth far more than a flattering score at the end of your preparation. Then work every explanation — including the ones you got right, because a right answer for a wrong reason fails on the next variant.
Interactive mode
Take the practice exam
80 questions · one at a time · 160-minute countdown · results with per-domain breakdown and full correction at the end. Your progress is saved in this browser if you leave the page.
By domain
| Domain | Correct | Score |
|---|
Correction
All questions (review mode)
Options are listed one per line. The answer and explanation stay hidden until you click Show answer. Use the interactive mode above for a timed sitting.
What is the fundamental difference between Security Groups and Network ACLs (NACLs) in a VPC?
Show answer
Answer: B.
Security Groups are stateful (response traffic is automatically allowed) and apply at the instance/ENI level. NACLs are stateless (return traffic must be explicitly allowed) and apply at the subnet level. NACLs support both allow and deny rules and evaluate rules in ascending numerical order — the first match wins. Security Groups only support allow rules.
Your RDS production database must survive an Availability Zone failure with automatic failover and no data loss. Which RDS feature should you enable?
Show answer
Answer: B.
RDS Multi-AZ creates a synchronous standby replica in a different AZ. Every write is replicated to the standby before being acknowledged (no data loss). RDS automatically fails over to the standby within 1–2 minutes if the primary fails. Read Replicas use asynchronous replication and are for read scaling, not HA failover — they can lag behind the primary and are not promoted automatically.
You have S3 objects whose access frequency is unpredictable — sometimes accessed daily, sometimes not for months. Which storage class automatically minimizes cost without manual management?
Show answer
Answer: C.
S3 Intelligent-Tiering automatically moves objects between access tiers (Frequent, Infrequent, Archive Instant Access) based on actual access patterns, with no retrieval fees or performance impact. Standard-IA and One Zone-IA require you to know that objects will be infrequently accessed and charge retrieval fees — they are not self-optimizing. Glacier has retrieval delays unsuitable for unpredictable access.
A Lambda function needs to read records from a DynamoDB table. What is the correct, secure way to grant it the necessary permissions?
Show answer
Answer: C.
Lambda functions should always use IAM execution roles — never hardcoded credentials. You attach an IAM role with the required permissions (e.g., dynamodb:GetItem, dynamodb:Query) to the Lambda function, and the Lambda service automatically provides short-lived temporary credentials via the metadata endpoint. This eliminates long-term credential management and rotation. Embedding or storing static access keys is an anti-pattern and a security risk.
Private subnet EC2 instances need to download OS updates from the internet. They should NOT be reachable from the internet. Which component enables this?
Show answer
Answer: C.
A NAT Gateway placed in a public subnet enables outbound-only internet access for private subnet instances. The private subnet's route table points 0.0.0.0/0 to the NAT Gateway; the NAT Gateway translates the source IP to its own Elastic IP for outbound traffic but blocks all inbound connections initiated from the internet. Internet Gateways enable two-way communication — attaching one to a private subnet would make it public. Elastic IPs on private instances would expose them to the internet.
Which CloudWatch metric for EC2 instances is NOT available by default and requires the CloudWatch Agent to be installed?
Show answer
Answer: C.
RAM utilization is not a default CloudWatch metric because the AWS hypervisor cannot observe memory usage inside the guest OS. To collect RAM, disk space, or other OS-level metrics, you must install the CloudWatch Agent on the instance and configure it to publish custom metrics. CPU Utilization, Network In/Out, and EBS Disk metrics are collected at the hypervisor level and reported automatically without any agent.
You need to decouple a high-traffic write API from a slower downstream processor. Messages must be processed in strict order and each message processed exactly once. Which SQS queue type should you use?
Show answer
Answer: B.
SQS FIFO (First-In, First-Out) queues guarantee strict message ordering and exactly-once processing with deduplication. SQS Standard queues offer higher throughput but only provide best-effort ordering and at-least-once delivery (a message can be delivered more than once). Use FIFO when message order and deduplication are business requirements (financial transactions, sequential workflows). Note that FIFO queues have a throughput limit of 3,000 messages/second with batching.
Your web application behind an ALB uses EC2 instances that store user session data in local memory. Sessions are lost when the load balancer routes a user to a different instance. What is the correct architectural fix?
Show answer
Answer: B.
The correct fix is to externalize session state to a shared, stateless store (ElastiCache Redis or DynamoDB) so that any instance can serve any user's request. Sticky sessions are a short-term workaround that defeats horizontal scaling — if the "sticky" instance fails, the user's session is still lost. Making the application stateless by externalizing session data is the foundational pattern for scalable, resilient web architectures on AWS.
Which Elastic Beanstalk deployment policy deploys the new version to a completely fresh set of instances without touching the current production fleet, enabling instant rollback?
Show answer
Answer: D.
Immutable deployments launch a new Auto Scaling Group with the new version running alongside the existing production fleet. If deployment validation passes, traffic shifts to the new instances and the old ones are terminated. Rollback is instant — just terminate the new ASG. All at once deploys to all instances simultaneously (fast but causes downtime). Rolling and Rolling with additional batch update the existing fleet in batches (reduced capacity or full capacity respectively), but rolling back requires a new deployment.
A CloudFormation stack manages an RDS database. You want to ensure the database is NOT deleted when the stack is deleted, and that a final snapshot is taken automatically. Which setting achieves this?
Show answer
Answer: B.
DeletionPolicy: Snapshot causes CloudFormation to take a final DB snapshot before deleting the RDS instance when the stack is deleted — giving you a restore point even after the infrastructure is decommissioned. DeletionPolicy: Retain keeps the resource running after stack deletion (no snapshot). Stack termination protection prevents the stack from being deleted entirely but does not create snapshots. DeletionPolicy: Snapshot is the recommended best practice for any production RDS instance managed by CloudFormation.
A company needs to give an external auditor read-only access to specific S3 buckets in their AWS account, without creating a permanent IAM user. What is the correct approach?
Show answer
Answer: C.
IAM roles with cross-account trust policies are the correct pattern for granting temporary, scoped access to external parties. The auditor's AWS account assumes the role via STS AssumeRole, receives temporary credentials scoped to S3 read-only, and those credentials expire automatically. Creating a permanent IAM user shares long-term credentials. Making buckets public exposes them to everyone. Pre-signed URLs grant access to individual objects, not a structured audit of buckets.
Your CloudFront distribution serves content from an S3 bucket. You want to ensure users can ONLY access S3 content through CloudFront — not directly via the S3 URL. Which CloudFront feature achieves this?
Show answer
Answer: B.
Origin Access Control (OAC) is the modern mechanism to restrict S3 bucket access exclusively to a specific CloudFront distribution. CloudFront signs requests to S3 using SigV4; the bucket policy is updated to allow s3:GetObject only from the CloudFront service principal with the specific distribution ARN. All direct S3 access returns 403. Transfer Acceleration speeds up uploads, not access control. Simply denying public access without OAC would also block CloudFront.
You have 15 VPCs across 3 AWS accounts that all need to communicate with each other and with your on-premises network via Direct Connect. What is the most operationally efficient architecture?
Show answer
Answer: B.
AWS Transit Gateway acts as a central regional hub that enables transitive routing between all attached VPCs and on-premises connections. With 15 VPCs, a full mesh of VPC peering connections would require up to 105 individual peering connections, each managed separately — this does not scale. VPC peering is also non-transitive, requiring direct connections between every pair. Transit Gateway supports thousands of attachments, enables transitive routing, and integrates natively with Direct Connect and VPN.
Your application writes data that must be immediately readable by any subsequent read from the same client. Which DynamoDB read consistency mode is required?
Show answer
Answer: B.
Strongly consistent reads in DynamoDB always return the most up-to-date data, reflecting all writes that received a successful response. Eventual consistency (the default) may return slightly stale data from a replica that has not yet received the latest write. If your application requires read-your-writes consistency (a client immediately reads what it just wrote), strongly consistent reads are mandatory. Note that strongly consistent reads consume twice the RCUs and are not available via GSIs.
A startup needs to process millions of clickstream events from their website in real time. Multiple teams need to independently analyze the same stream — one for fraud detection, one for recommendations, one for billing. Which service best fits this use case?
Show answer
Answer: C.
Kinesis Data Streams is designed exactly for this pattern: high-throughput ingestion of streaming data that multiple independent consumers process simultaneously at their own pace from the same stream. Kinesis retains data for 24 hours (up to 365 days), enabling replay. SQS messages are consumed and deleted — once one consumer reads a message, it is no longer available to others. SNS fan-out to SQS could work but adds complexity; Kinesis natively handles multiple consumers on a single stream with the Enhanced Fan-Out feature.
You are about to update a CloudFormation stack that manages a production environment. You want to see exactly which resources will be modified, replaced, or deleted before committing the change. What should you use?
Show answer
Answer: C.
CloudFormation ChangeSets preview the impact of a template change before execution — showing which resources will be Added, Modified in-place, or Replaced (deleted and recreated). Resource replacement is critical to review because it means data loss or downtime for stateful resources like RDS databases. Drift detection identifies resources that were changed outside of CloudFormation, not future changes. Always create and review a ChangeSet before updating production stacks.
Your application tier runs in private subnets. EC2 instances must access DynamoDB without their traffic leaving the Amazon network (compliance requirement). What is the correct solution?
Show answer
Answer: C.
A VPC Gateway Endpoint for DynamoDB (and S3) routes traffic privately within the Amazon network by adding an entry to the subnet's route table — traffic never leaves AWS. Gateway Endpoints are free of charge. Interface Endpoints use PrivateLink (ENIs with private IPs) and are used for most other services, but not DynamoDB or S3. A NAT Gateway routes traffic through the internet, violating the compliance requirement. VPC Flow Logs are an observability tool, not a routing mechanism.
You need to encrypt data stored in S3 and require a full audit log of every encryption and decryption operation for compliance. Which S3 encryption option meets this requirement?
Show answer
Answer: B.
SSE-KMS uses AWS KMS to manage encryption keys and automatically generates a CloudTrail audit record for every KMS API call — every encryption and decryption operation is logged with the caller identity, timestamp, and key used. This is the only option that provides a built-in, tamper-evident audit trail for key usage. SSE-S3 uses AWS-managed keys with no per-operation audit trail. SSE-C means you manage the keys externally; AWS does not log usage. Client-side encryption is entirely outside AWS visibility.
A global e-commerce company needs to route users to the nearest AWS region to minimize latency. Failover to another region should happen automatically if a regional endpoint becomes unhealthy. Which Route 53 routing policy combination achieves this?
Show answer
Answer: C.
Latency-based routing directs each request to the AWS region that provides the lowest measured network latency for that user, globally. Combining it with Route 53 health checks ensures that if a regional endpoint fails its health check, Route 53 automatically removes it from DNS responses and routes to the next-lowest-latency healthy region. Geolocation routing assigns traffic by country/continent regardless of latency. Simple routing does not consider latency or health. Weighted routing splits traffic by configured percentages, not by latency.
Your Lambda function connects to an RDS database. During peak traffic, you observe "too many connections" errors because thousands of Lambda invocations each try to open a new database connection. What is the correct architectural fix?
Show answer
Answer: D.
RDS Proxy maintains a persistent pool of connections to the RDS database and multiplexes many application connections (Lambda invocations) onto a much smaller set of actual database connections. This solves the Lambda-RDS connection exhaustion problem at its root, without requiring a larger database. Increasing max_connections only defers the problem. Read Replicas distribute reads but each replica also has a connection limit and does not help with write connections. RDS Proxy also improves failover speed during Multi-AZ events.
Your application experiences predictable traffic spikes every weekday at 9 AM and drops at 6 PM. CPU utilization also spikes unpredictably during the day. Which combination of Auto Scaling policies handles both patterns optimally?
Show answer
Answer: B.
Scheduled Scaling pre-emptively adjusts capacity at known times — scaling out before 9 AM prevents the cold-start latency penalty of reactive scaling during the morning rush. Target Tracking then maintains the desired CPU utilization throughout the day by responding to unpredictable spikes in real time. A single Target Tracking policy cannot anticipate predictable patterns — it only reacts after the metric breaches the threshold, causing a lag. Combining the two policies gives you both predictability and reactivity.
A financial trading platform requires consistent, sub-millisecond I/O latency for its database volumes with no burstable performance — throughput must be guaranteed regardless of volume size. Which EBS volume type is correct?
Show answer
Answer: C.
io2 (Provisioned IOPS SSD) and io2 Block Express are designed for I/O-intensive workloads requiring consistent, predictable, sub-millisecond performance — the IOPS you provision is what you get, regardless of volume size or accumulated I/O credits. gp3 provides a solid baseline (3,000 IOPS) but is designed for general-purpose workloads, not guaranteed high-performance databases. st1 and sc1 are HDD-based with much higher latency and are optimized for sequential throughput, not transaction-heavy databases.
You store compliance documents in S3 that must be retained for 7 years. For the first 30 days they are actively accessed; then rarely for 90 days; then never. You want the lowest possible storage cost. What lifecycle policy achieves this?
Show answer
Answer: B.
S3 lifecycle policies automate cost optimization by transitioning objects through storage classes as they age. Standard for the first 30 days handles active access with no retrieval fees. Standard-IA from day 30–90 reduces storage cost for occasional access. Glacier Flexible Retrieval from day 90 onward provides the lowest cost for dormant archive data (minutes-to-hours retrieval is acceptable since documents are rarely accessed). A delete rule at 7 years prevents indefinite accumulation. One Zone-IA sacrifices the multi-AZ durability guarantee that compliance data typically requires.
A CloudWatch Alarm monitoring an EC2 instance's CPU shows the state "INSUFFICIENT_DATA" immediately after creation. What does this state mean?
Show answer
Answer: B.
INSUFFICIENT_DATA is the initial state for a newly created alarm, and also occurs when the metric stops reporting data (e.g., an instance is terminated or a custom metric stops publishing). It means the alarm cannot make an evaluation because there are not enough data points within the evaluation window — not that a problem was detected. CloudWatch Alarms transition: INSUFFICIENT_DATA → OK (threshold not breached) or INSUFFICIENT_DATA → ALARM (threshold breached), depending on what the metric reports once sufficient data accumulates.
An IAM user has an identity policy that allows s3:DeleteObject on all S3 buckets. The S3 bucket also has a resource-based policy that explicitly denies s3:DeleteObject for that user. What happens when the user tries to delete an object?
Show answer
Answer: C.
The IAM policy evaluation order is deterministic: an explicit Deny anywhere in the policy evaluation chain always overrides any Allow, regardless of which policy type contains it. The evaluation logic checks: (1) Is there an explicit Deny? → Deny immediately. (2) Is there an explicit Allow? → Allow. (3) Neither → implicit Deny. This makes explicit Deny rules a powerful security mechanism for enforcing hard boundaries (e.g., preventing deletion of critical resources even by administrators), since no Allow rule can override them.
You are planning a VPC with CIDR 10.0.0.0/16. You create a public subnet with CIDR 10.0.1.0/24. How many IP addresses are actually available for EC2 instances in this subnet?
Show answer
Answer: C.
AWS always reserves exactly 5 IP addresses in every subnet: x.x.x.0 (network address), x.x.x.1 (VPC router), x.x.x.2 (DNS server), x.x.x.3 (reserved for future use), and x.x.x.255 (broadcast address). For a /24 subnet with 256 total addresses, 256 − 5 = 251 are usable by your resources. This reservation applies to every subnet regardless of size — a /28 subnet (16 total addresses) has only 11 usable addresses. Always account for this when sizing subnets, especially smaller ones.
Your Lambda function processes critical payment transactions. Cold starts are unacceptable — the function must respond within 100ms even on the first invocation. Which Lambda feature eliminates cold starts?
Show answer
Answer: B.
Provisioned Concurrency pre-initializes a specified number of Lambda execution environments, keeping them "warm" and ready to serve requests with no initialization delay. Cold starts occur because Lambda must download and initialize the execution environment on first invocation — Provisioned Concurrency eliminates this by doing that work in advance. Reserved Concurrency limits how many concurrent executions a function can have (a cap, not a warm-up). More memory speeds up initialization but does not eliminate it. Provisioned Concurrency has an additional cost but is essential for latency-sensitive functions.
Your application must serve users globally with low read latency from any region, and must tolerate a region becoming entirely unavailable without data loss. Which DynamoDB feature enables this?
Show answer
Answer: C.
DynamoDB Global Tables replicates data across multiple AWS regions with multi-active (multi-master) writes — any region can accept both reads and writes, and changes propagate to all other regions within seconds. If a region becomes unavailable, your application automatically routes to another region with no data loss for committed writes. Read Replicas are an RDS concept, not DynamoDB. Multi-AZ is a single-region HA feature. DAX accelerates reads within a single region but does not provide cross-region availability.
Your application needs to cache database query results and also store user session data that must survive a cache node restart. Which ElastiCache engine should you choose?
Show answer
Answer: B.
Redis supports persistence (snapshots and AOF logs), replication (primary-replica), and rich data structures (strings, hashes, lists, sorted sets, sets) — making it the correct choice when cached data must survive node restarts or when you need shared session storage. Memcached is a pure in-memory cache with no persistence, no replication, and only simple key-value storage — data is permanently lost if a node fails or restarts. For scenarios requiring only horizontal scaling of a simple cache (and data loss on restart is acceptable), Memcached is simpler and marginally faster.
A company uses AWS Organizations with multiple member accounts. They want to prevent any account in the "Development" organizational unit from launching resources in the us-east-1 region, even if an account administrator grants themselves permission. What achieves this?
Show answer
Answer: B.
Service Control Policies (SCPs) are the only mechanism that can restrict permissions for all principals in an AWS account — including the account's own root user and administrators. An SCP attached to an OU applies to all accounts within it as a maximum permission boundary: even if an account grants full AdministratorAccess, the SCP prevents actions it denies. IAM permission boundaries require being applied to every user individually — administrators can bypass them by not applying them to new users. Config rules are reactive (detect after creation), not preventive.
You are building a containerized microservices application. Each service needs to scale independently, and the team wants to avoid managing EC2 instances entirely. Which setup is most appropriate?
Show answer
Answer: B.
ECS with Fargate is the serverless container option: you define the CPU and memory for each task, and AWS provisions, scales, and patches the underlying infrastructure. There are no EC2 instances to manage, patch, or right-size. Each ECS service scales independently based on its own CloudWatch metrics or custom scaling policies. The EC2 launch type requires managing and patching a cluster of EC2 instances. Elastic Beanstalk with Docker works for simpler single-container deployments but does not provide the per-service independent scaling that microservices require.
You enable S3 Cross-Region Replication (CRR) on a bucket that already has 10,000 objects. Which statement about CRR behaviour is correct?
Show answer
Answer: B.
CRR is prospective — it replicates objects created or modified after replication is configured. Existing objects at the time of enabling CRR are not replicated automatically. To replicate pre-existing objects, you must run a separate S3 Batch Operations job using the S3 ReplicateObject operation. Additionally, CRR requires versioning to be enabled on both source and destination buckets, and the IAM role used for replication must have read permissions on the source and write permissions on the destination.
You deploy an EC2 instance via CloudFormation with a user data script that installs application dependencies. The stack completes successfully but the application is not working because the install script failed silently. How do you make CloudFormation wait for the script to succeed before marking the stack complete?
Show answer
Answer: B.
cfn-signal combined with a CreationPolicy is the correct pattern. The CreationPolicy on the EC2 resource tells CloudFormation to wait for N success signals within a timeout before marking the resource CREATE_COMPLETE. The user data script calls cfn-signal --success true after confirming the install succeeded (or cfn-signal --success false on failure). Without this, CloudFormation marks the instance complete the moment the EC2 service reports it as running — before user data has finished executing. DependsOn only controls creation order, not success conditions.
Which AWS service provides a managed connection pool for RDS databases, improves failover times during Multi-AZ events, and supports IAM-based database authentication — all without changing application code?
Show answer
Answer: C.
RDS Proxy is a fully managed database proxy that addresses three problems simultaneously: it pools and multiplexes application connections onto fewer actual database connections (solving Lambda and ECS connection exhaustion); it maintains the connection pool during Multi-AZ failover, reducing application-visible downtime from minutes to seconds; and it supports IAM-based database authentication so applications never handle database passwords. It requires no application code changes — you simply point your connection string at the proxy endpoint instead of the RDS endpoint.
A new AWS CloudTrail trail is created in your account. A security engineer asks: "Does CloudTrail cover ALL API calls across ALL regions automatically?" What is the correct answer?
Show answer
Answer: B.
A CloudTrail trail is regional by default — it only captures events in the region where it was created. To capture API activity across all regions in a single trail, you must explicitly enable "Apply trail to all regions" (or create an organization trail in AWS Organizations, which covers all accounts and all regions). Additionally, some global services (IAM, STS, CloudFront) log events to us-east-1 by default — you must enable "Include global service events" to capture them. CloudTrail captures all API call methods: console, CLI, SDK, and direct HTTP.
You need to encrypt an 8 GB file before storing it in S3 using AWS KMS. The KMS API rejects the request because KMS cannot directly encrypt data larger than 4 KB. What is the correct approach?
Show answer
Answer: B.
Envelope encryption is how KMS handles large data: you call KMS GenerateDataKey to get a plaintext data key and an encrypted copy of that key. You use the plaintext key to encrypt the large file locally (with AES-256), then discard the plaintext key. You store the encrypted file alongside the encrypted data key in S3. To decrypt, you call KMS Decrypt on the encrypted data key to recover the plaintext key, then decrypt the file locally. KMS itself only ever handles the small data key — never the large payload. This is the pattern used by all AWS services that integrate with KMS.
An SQS message is received by Consumer A, which starts processing it. Before Consumer A finishes and deletes the message, the visibility timeout expires. What happens?
Show answer
Answer: B.
The visibility timeout is the period during which SQS hides a received message from other consumers, giving the consumer time to process and delete it. If the consumer does not delete the message within this window, SQS assumes the processing failed and makes the message visible again — enabling retry by the same or a different consumer. This is SQS's at-least-once delivery guarantee. Messages only go to the Dead Letter Queue after exceeding the maxReceiveCount (maximum number of receive attempts). To prevent premature re-visibility on long jobs, consumers should extend the timeout using ChangeMessageVisibility.
Your CloudFront distribution serves a JavaScript file (app.js) that was recently updated. Users are still receiving the old cached version. What is the fastest way to force CloudFront to serve the new file?
Show answer
Answer: B.
Cache invalidation tells CloudFront to immediately purge the specified path from all edge location caches, forcing the next request for that file to fetch a fresh copy from the origin. Invalidations are charged per path (with a free tier of 1,000 paths per month). Waiting for TTL expiry is free but slow. For static assets with versioning, a better long-term pattern is to use version-stamped filenames (app.v2.js) — the new filename bypasses cache entirely without needing invalidations, while the old file expires naturally. Recreating the distribution causes significant downtime and DNS propagation delay.
A data engineering team runs large-scale, fault-tolerant batch jobs on EC2 that can be interrupted and resumed from a checkpoint. Which purchasing model dramatically reduces cost while accepting the risk of interruption?
Show answer
Answer: C.
Spot Instances offer up to 90% discount compared to On-Demand by utilizing AWS's spare EC2 capacity. The tradeoff is interruptibility: AWS can reclaim Spot capacity with a 2-minute warning. Fault-tolerant batch workloads that checkpoint progress are ideal Spot candidates — if interrupted, the job resumes from the last checkpoint on a new Spot instance. Spot is not suitable for stateful workloads, databases, or anything that cannot tolerate interruption. Reserved Instances offer ~75% discount but require a 1–3 year commitment and are suited for steady-state workloads, not variable batch jobs.
A security audit requires that all administrative SSH access to EC2 instances be logged, audited, and require no open inbound ports on Security Groups. Which AWS feature replaces traditional bastion host SSH access?
Show answer
Answer: B.
AWS Systems Manager Session Manager establishes shell sessions over the SSM API (outbound HTTPS from the instance to SSM endpoints) — no inbound port 22 or 3389 required. Sessions are fully logged to CloudWatch Logs and S3 with IAM-controlled access, satisfying compliance requirements for session auditing. Access is controlled via IAM policies, supporting MFA enforcement and just-in-time access patterns. EC2 Instance Connect still requires port 22 in the Security Group. Direct Connect is a network connectivity service. Flow Logs are observability, not access control.
Your primary RDS database is in us-east-1. Compliance requires a full copy of the database to be available in eu-west-1 for disaster recovery, with a recovery time objective (RTO) of under 30 minutes. Which feature meets this requirement?
Show answer
Answer: B.
RDS Cross-Region Read Replicas asynchronously replicate data to another region and can be promoted to a standalone primary database within minutes — well within a 30-minute RTO. Multi-AZ only operates within a single region and does not protect against regional failures. Daily automated backup restoration typically takes 30–60+ minutes for large databases, depending on size and IOPS — unreliable for a 30-minute RTO. Manual snapshot restoration is even slower and requires human intervention. Cross-region Read Replicas are the standard pattern for cross-region DR with aggressive RTOs.
You publish a single event to an SNS topic. You need that event to simultaneously trigger a Lambda function, send an email notification, and queue the event for batch processing in SQS. How does SNS handle this?
Show answer
Answer: B.
SNS is a pub/sub fan-out service: one message published to a topic is simultaneously delivered to all subscriptions in parallel. A single SNS publish triggers the Lambda invocation, the email delivery, and the SQS message enqueue — all at the same time, without any ordering dependency. This fan-out pattern is fundamental to event-driven AWS architectures: decouple producers from consumers, and add new consumers without touching the producer. SNS supports subscriptions to Lambda, SQS, HTTP/HTTPS endpoints, email, SMS, and mobile push — all on the same topic simultaneously.
Your web application needs a load balancer that routes requests based on URL path (/api/* → API service, /static/* → S3 origin) and also performs TLS termination. Which AWS load balancer type is correct?
Show answer
Answer: C.
ALB operates at Layer 7 (HTTP/HTTPS) and makes routing decisions based on the content of the request — URL path, hostname, HTTP headers, query parameters, or source IP. Path-based routing rules (/api/* → Target Group A, /static/* → Target Group B) are a native ALB feature. ALB also terminates TLS (SSL certificates managed via ACM) and forwards decrypted HTTP to backends. NLB operates at Layer 4 (TCP/UDP) — it does not inspect HTTP content or support path-based routing. The Classic Load Balancer is legacy. Gateway Load Balancer is for deploying third-party network appliances.
A developer wants to measure the number of failed login attempts in their application and alarm when it exceeds 100 in 5 minutes. CloudWatch does not have a default metric for this. What is the correct approach?
Show answer
Answer: C.
CloudWatch custom metrics allow any application or service to publish business or application-level metrics via the PutMetricData API. The application code increments a counter on each failed login and periodically calls PutMetricData with the count. You then create a CloudWatch Alarm on this custom metric with a threshold of 100 within a 5-minute period, triggering an SNS notification. The CloudWatch Agent can collect OS-level metrics (RAM, disk) and log data, but it does not understand application business logic. Detailed monitoring only increases the frequency of existing AWS service metrics — it does not add new application-level metrics.
A read-heavy DynamoDB table serves thousands of requests per second. Many requests read the same 50 popular items repeatedly, consuming significant RCUs. Which solution reduces read costs and latency for these popular items?
Show answer
Answer: C.
DynamoDB Accelerator (DAX) is a fully managed, in-memory cache specifically built for DynamoDB. It intercepts GetItem and Query calls, returning cached results in microseconds without consuming RCUs on the underlying table. For hot items read repeatedly (product catalog, leaderboards, reference data), DAX dramatically reduces both cost (no RCU consumption for cache hits) and latency (milliseconds → microseconds). DAX is API-compatible with DynamoDB — application code only needs to point to the DAX cluster endpoint instead of the DynamoDB endpoint. GSIs require their own RCU capacity and do not cache.
A user needs temporary, time-limited access to download a specific private object from an S3 bucket without having AWS credentials. What is the simplest secure solution?
Show answer
Answer: C.
S3 Pre-signed URLs grant temporary, scoped access to a specific object without requiring the requester to have AWS credentials. The URL is generated by a principal with s3:GetObject permission and includes an embedded cryptographic signature along with an expiration timestamp (seconds to 7 days). Anyone with the URL can access the object until expiration — after which the URL becomes invalid. This is ideal for short-lived file sharing, download links in applications, and granting partners temporary access to specific files. Making the bucket public is a security risk. Sharing IAM user credentials grants permanent, account-level access.
You want to add custom HTTP response headers (e.g., Content-Security-Policy, X-Frame-Options) to every response served by your CloudFront distribution, without modifying your origin server. Which feature achieves this?
Show answer
Answer: B.
CloudFront Response Headers Policies define headers that CloudFront adds to responses it sends to viewers — completely independently of what the origin returns. You configure a policy with security headers (Content-Security-Policy, X-Frame-Options, Strict-Transport-Security, X-XSS-Protection) and attach it to a cache behavior. CloudFront injects these headers into every response before it reaches the viewer. This avoids modifying origin servers, applies consistently to all content including cached responses, and is managed centrally via the CloudFront configuration. Lambda@Edge could also achieve this but Response Headers Policies are purpose-built and require no code.
What is the key operational difference between AWS Secrets Manager and SSM Parameter Store SecureString for storing database credentials?
Show answer
Answer: B.
The critical differentiator is automatic rotation. Secrets Manager has built-in rotation support with pre-built Lambda functions for RDS (MySQL, PostgreSQL, Oracle, SQL Server), Redshift, and DocumentDB — it rotates credentials on a schedule, updates the secret, and simultaneously updates the database password with no application downtime. SSM Parameter Store SecureString requires you to implement rotation manually. Secrets Manager is the correct choice whenever automatic rotation is a requirement. Parameter Store (standard parameters) is free and suitable for configuration values and manually rotated secrets; Secrets Manager has a per-secret monthly fee.
You are launching a high-performance computing (HPC) cluster where all EC2 instances must communicate with each other at the lowest possible network latency and highest throughput. Which EC2 placement strategy achieves this?
Show answer
Answer: C.
A Cluster Placement Group packs instances physically close together within a single AZ — typically on the same network switch rack. This delivers the lowest network latency (sub-10ms, single-digit microseconds with Elastic Fabric Adapter) and highest aggregate network bandwidth (up to 100 Gbps). It is specifically designed for tightly-coupled, latency-sensitive workloads like HPC simulations, distributed machine learning training, and financial modeling. The tradeoff is reduced fault tolerance — all instances share the same physical infrastructure. Spread groups prioritize fault tolerance by separating instances; Partition groups are designed for large distributed databases like HDFS or Cassandra.
AWS Trusted Advisor flags one of your EC2 instances as "underutilized" with average CPU below 5% over the last 14 days. What should your team do?
Show answer
Answer: C.
Trusted Advisor's underutilized instance check identifies cost optimization opportunities, but the correct response is investigation, not immediate action. The instance may be underutilized because it handles unpredictable spikes (low average doesn't mean low peak), it's a standby/failover instance, or it genuinely is waste. If truly unused, terminate it. If legitimately needed but oversized, downsize it (EC2 supports instance type changes on stopped instances). Auto Scaling can eliminate the need for always-on instances for variable workloads. Buying a Reserved Instance for a chronically underutilized instance commits you to paying for waste for 1–3 years.
An SQS consumer receives a message, starts processing it, but crashes before deleting it. The message keeps reappearing and failing. After how many failures should the message stop blocking healthy processing, and where should it go?
Show answer
Answer: B.
A Dead Letter Queue (DLQ) is a separate SQS queue that receives messages that have exceeded the maxReceiveCount — the configured maximum number of failed delivery attempts. This separates "poison pill" messages (messages that consistently cause consumer crashes) from the healthy flow of new messages, so they do not block processing indefinitely. The DLQ allows developers to inspect, replay, or discard failed messages independently. Without a DLQ, a poison message would cycle forever, consuming consumer capacity.
Multiple Lambda functions across your account share the same 200 MB set of Python dependencies. Packaging these dependencies with every function wastes storage and slows deployments. What is the correct solution?
Show answer
Answer: B.
Lambda Layers are versioned archives (ZIP files) of shared code, libraries, or data that you attach to one or more Lambda functions. The layer content is extracted to /opt in the function's execution environment and is immediately accessible at runtime — no download required. A single layer can be shared across dozens of functions, reducing total deployment package size, enabling centralized dependency version management, and speeding up function deployments. Functions can use up to 5 layers simultaneously. Layers are ideal for shared runtimes, ML model files, and common utility libraries.
You need to query a DynamoDB table by an attribute that is not the primary key. You want the queries to return items sorted by a timestamp. Which index type is most appropriate, and what is its key constraint?
Show answer
Answer: C.
LSIs and GSIs both enable querying on non-primary-key attributes but have important differences. An LSI must share the table's partition key and allows a different sort key — it is scoped to a single partition and supports strongly consistent reads. Critically, LSIs can only be created when the table is created; you cannot add them later. A GSI can use any attribute as its partition key and sort key, can be created after table creation, and has its own separate throughput capacity. For sorting by timestamp within a specific user's data (same partition key, different sort key), an LSI is the right choice and must be defined upfront.
A security audit finds that EC2 instances can retrieve IAM role credentials from the instance metadata endpoint without any authentication, creating a risk if an attacker gains code execution on the instance. What AWS feature mitigates this?
Show answer
Answer: B.
IMDSv2 adds a session-oriented token requirement to the metadata endpoint (169.254.169.254). The caller must first make a PUT request to get a time-limited token, then include that token in subsequent GET requests. This defends against Server-Side Request Forgery (SSRF) attacks — a common web application vulnerability where an attacker tricks the server into making requests on their behalf, including to the metadata endpoint to steal IAM credentials. IMDSv1 (no token required) should be disabled on all instances. IMDSv2 can be enforced at the instance level, the AMI level, or account-wide via an IAM condition key.
A financial services company must ensure that audit log files stored in S3 cannot be deleted or modified for 7 years, even by account administrators, to meet regulatory compliance requirements. Which S3 feature enforces this?
Show answer
Answer: B.
S3 Object Lock in Compliance mode enforces a Write Once Read Many (WORM) model. Once an object is locked with a retention period, no user — including the AWS root account — can delete or overwrite it before the period expires, and the retention period itself cannot be shortened. This is specifically designed for regulatory compliance scenarios (SEC Rule 17a-4, FINRA, CFTC). Governance mode is less strict — privileged users with special IAM permissions can still override it. MFA Delete and bucket policies can be bypassed by the root account or through policy changes; Compliance mode Object Lock cannot.
Your ECS tasks need to communicate directly with other services using their own private IP addresses and Security Group rules, rather than sharing the host EC2 instance's network interface. Which ECS networking mode enables this?
Show answer
Answer: C.
The awsvpc network mode assigns each ECS task its own ENI, private IP address, and Security Group — treating each task like a first-class VPC resource. This enables precise per-task Security Group rules (rather than sharing the host EC2 instance's Security Group across all containers), VPC Flow Log visibility at the task level, and direct integration with Application Load Balancers by IP address. awsvpc is required for Fargate tasks, which have no underlying EC2 host. The bridge mode uses Docker's internal bridge and requires dynamic port mapping, making Security Group rules harder to manage.
You want to route 10% of production traffic to a new application version for canary testing, while 90% continues going to the stable version. Both versions are deployed as separate target groups behind Route 53. Which routing policy achieves this?
Show answer
Answer: C.
Route 53 Weighted routing lets you control what percentage of DNS responses point to each record by assigning integer weights. A weight of 90 vs 10 means the stable version receives 90/(90+10) = 90% of traffic and the new version receives 10%. This is the standard pattern for blue/green gradual cutover and canary releases at the DNS layer. Weights can be updated in real time without deployment — increasing the new version's weight gradually as confidence grows. Failover routing is binary (primary or secondary). Latency-based routing picks based on network performance, not an intentional traffic split.
A developer needs to deploy Lambda functions with the same custom runtime across 20 different functions. The runtime is 150 MB. Packaging it with every function wastes storage and causes slow deployments. After creating a Lambda Layer, what limits apply?
Show answer
Answer: B.
Lambda functions can attach up to 5 layers simultaneously, and the total unzipped size of the deployment package (function code + all layers) is limited to 250 MB. Each individual layer can be up to 250 MB unzipped. Layers can be shared across accounts (you can make a layer public or share it with specific account IDs) and across functions in the same region. For very large models or datasets (>250 MB), EFS is indeed the solution — but for standard libraries and runtimes under 250 MB, layers are the right tool. Layers are versioned and immutable once published.
Your application's VPC Flow Logs show that traffic from a specific source IP is reaching the EC2 instance (ACCEPT for inbound) but the application is still not responding to those connections. Where should you investigate next?
Show answer
Answer: C.
VPC Flow Logs capture traffic at the ENI level. An ACCEPT entry means the traffic passed both NACL and Security Group checks and arrived at the instance's network interface. If the connection is still failing, the problem is inside the operating system: the application may not be listening on the port, the OS firewall (iptables/Windows Firewall) may be blocking it, the application may have crashed, or it may be listening on localhost (127.0.0.1) rather than all interfaces (0.0.0.0). REJECT in flow logs would indicate a network-level block; ACCEPT means the network delivered the packet successfully.
A junior developer in your team has been granted IAM permissions to create and manage IAM roles and policies. You want to ensure they cannot create roles with more permissions than they themselves have — preventing privilege escalation. What mechanism achieves this?
Show answer
Answer: B.
IAM Permission Boundaries are an advanced feature that sets the maximum permissions a role or user can have, regardless of what identity policies allow. When a developer creates a new role, you require (via an IAM condition) that the new role has a specific permission boundary attached. The role's effective permissions become the intersection of its identity policies AND the boundary — meaning even if the developer accidentally or maliciously grants AdministratorAccess in the role's policy, the boundary caps the actual permissions. This prevents privilege escalation without restricting what identity policies the developer can write.
You are uploading a 50 GB file to S3 using the standard PutObject API call. The upload fails after 45 minutes at 80% completion due to a network interruption. You must restart from scratch. Which S3 feature eliminates this problem for large files?
Show answer
Answer: C.
Multipart Upload breaks large objects into up to 10,000 individual parts that are uploaded independently and in parallel. If a part fails, only that specific part needs to be retried — not the entire file. Parts can be uploaded in parallel across multiple connections, significantly improving throughput. Once all parts are successfully uploaded, a CompleteMultipartUpload call assembles them into the final S3 object. Multipart Upload is recommended for files over 100 MB and required for files over 5 GB (the single PutObject limit). Abort Incomplete Multipart Upload lifecycle rules clean up abandoned in-progress uploads to avoid paying for partial part storage.
Your organization has 40 AWS accounts. You need to deploy a new IAM role with read-only S3 access across all accounts simultaneously to implement a centralized auditing solution. Manually deploying to each account would take hours. What is the most efficient approach?
Show answer
Answer: B.
CloudFormation StackSets extend CloudFormation to deploy stacks across multiple AWS accounts and regions simultaneously from a single management or delegated administrator account. You define the template once (the IAM role definition) and specify the target accounts or Organizational Units. StackSets handles creating, updating, and deleting stack instances across all targets. With AWS Organizations integration, you can automatically deploy to new accounts as they are created. A shell script would work but is slow, error-prone, and hard to update consistently. Config Aggregator is for collecting compliance data, not deploying resources.
Users in Asia-Pacific are complaining of slow S3 upload speeds when uploading large files to your us-east-1 bucket. The files are user-generated content that must be stored in us-east-1. Which S3 feature improves upload performance for geographically distant users?
Show answer
Answer: B.
S3 Transfer Acceleration uses CloudFront's globally distributed edge locations as upload entry points. Instead of a user in Tokyo uploading directly to a bucket in us-east-1 over the public internet (traversing many unpredictable network hops), the upload goes to the nearest CloudFront edge in Tokyo and then travels over AWS's optimized private backbone network to us-east-1 — consistently faster and more reliable. Transfer Acceleration is enabled per bucket and uses a distinct endpoint (bucket.s3-accelerate.amazonaws.com). It charges extra per GB transferred. CloudFront is for content delivery (downloads), not accelerating uploads to a specific region.
An organization already has a 10 Gbps AWS Direct Connect connection to us-east-1. They want to connect their on-premises network to another 3 AWS regions without ordering additional physical connections. What is the most cost-effective solution?
Show answer
Answer: C.
AWS Direct Connect Gateway is a globally available resource that allows a single Direct Connect connection to access VPCs in any AWS region (except China). You attach the Direct Connect connection to the Direct Connect Gateway, then associate it with Virtual Private Gateways or Transit Gateways in multiple regions. Traffic between on-premises and any connected region flows over the Direct Connect connection and AWS's backbone — without additional physical connections or per-region Direct Connect fees. VPC Peering only works between VPCs and does not extend Direct Connect connectivity. A VPN over the internet would be slower and less reliable than the existing Direct Connect.
Your Aurora database handles a predictable daily traffic pattern: low reads overnight, peak reads during business hours. You want Aurora to automatically scale the number of read replicas based on load, without manual intervention or pre-provisioned idle capacity. Which feature enables this?
Show answer
Answer: B.
Aurora Auto Scaling automatically adjusts the number of Aurora Replica instances (read replicas) based on CloudWatch metrics — typically AverageCPUUtilization or DatabaseConnections. You define a scaling policy with minimum and maximum replica counts and a target metric value. Aurora adds replicas when load increases and removes them when load drops, with the Aurora endpoint automatically routing read traffic across all healthy replicas. Aurora Serverless v2 scales compute capacity within a single instance but uses a different architecture — for read-heavy workloads that benefit from horizontal read scaling, Aurora Replicas with Auto Scaling is the standard pattern.
You need to add custom authentication logic to a CloudFront distribution — checking a proprietary token in the request header before allowing access to content. The logic must run as close to the viewer as possible. Which service is purpose-built for this?
Show answer
Answer: B.
Lambda@Edge deploys Lambda functions to CloudFront edge locations worldwide and executes them in response to four CloudFront event types: viewer request (before cache check), origin request (cache miss, going to origin), origin response (response from origin), and viewer response (before returning to viewer). For custom authentication, a Viewer Request trigger intercepts every incoming request at the edge, validates the token, and either forwards the request or returns a 403 — without any latency from a round-trip to the origin. Lambda@Edge functions must be deployed to us-east-1 (they are globally replicated by CloudFront). WAF can match patterns but cannot execute arbitrary business logic for token validation.
Your application logs are stored in CloudWatch Logs. You need to find all ERROR log entries that appeared within the last hour, count them by error code, and identify the top 5 most frequent errors — all without exporting logs to another service. Which tool handles this interactively?
Show answer
Answer: B.
CloudWatch Logs Insights is an interactive log analytics service built into CloudWatch. It uses a purpose-built query language to filter (filter @message like /ERROR/), extract fields, compute statistics (stats count(*) by errorCode), sort results, and visualize time-series distributions — all directly against your CloudWatch Log Groups with no data export required. Queries complete in seconds to minutes depending on data volume. Metric Filters are great for ongoing alerting but are not interactive. Athena queries S3, not CloudWatch Logs directly (though you can export logs to S3 first). Contributor Insights is for identifying top traffic sources, not ad-hoc log analysis.
Multiple EC2 instances in different Availability Zones need to share access to the same file system simultaneously — reading and writing the same files concurrently. Which AWS storage service is designed for this use case?
Show answer
Answer: C.
Amazon EFS is a managed NFS (Network File System) that provides shared file storage accessible simultaneously from multiple EC2 instances, ECS tasks, Lambda functions, and on-premises servers. Unlike EBS volumes (which can only be attached to one EC2 instance at a time, with the exception of EBS Multi-Attach for io2 volumes with strict limitations), EFS is designed for concurrent multi-instance access with POSIX-compliant file semantics. EFS automatically scales from gigabytes to petabytes and replicates data across multiple AZs for durability. It is the standard choice for shared file storage in microservices, CMS platforms, and HPC workloads.
AWS Compute Savings Plans offer a more flexible discount mechanism than Standard Reserved Instances. What is the key flexibility advantage, and what commitment do they require?
Show answer
Answer: B.
Compute Savings Plans commit you to a minimum hourly spend (e.g., $10/hour) for 1 or 3 years. In exchange, you receive a discount (up to 66%) that applies to any EC2 compute usage regardless of instance family, size, OS, tenancy, or region — and also to AWS Lambda and AWS Fargate. Standard Reserved Instances are locked to a specific instance type, OS, and AZ or region. Convertible RIs allow changing instance configuration but only within EC2 and at a lower discount than Standard RIs. Savings Plans are now the recommended approach for most workloads because of their flexibility. EC2 Instance Savings Plans offer higher discounts but are scoped to a specific instance family in one region.
Your team uses AWS CodeBuild to build and test a Node.js application. How does CodeBuild know which commands to run during the install, build, and test phases?
Show answer
Answer: B.
buildspec.yml is the build specification file that CodeBuild reads from the root of your source repository. It defines the phases of the build: install (install build tools), pre_build (preparation like ECR login), build (compile and test the application), and post_build (packaging, tagging, notifications). Each phase lists shell commands in order. The artifacts section specifies which files to export as build output for downstream stages in CodePipeline. Without a buildspec.yml, CodeBuild cannot determine what to do and the build will fail. The buildspec can alternatively be provided inline in the CodeBuild project configuration if you prefer not to commit it to the repository.
Your API Gateway receives the same set of expensive database queries repeatedly from thousands of users. Each query takes 500ms on the backend. You want to serve repeated requests instantly without hitting the database. Which API Gateway feature handles this?
Show answer
Answer: B.
API Gateway has a built-in response cache that can be enabled per stage with a configurable TTL (0 to 3600 seconds). When caching is enabled, API Gateway checks whether a cached response exists for the incoming request (based on the request URL, query parameters, and headers you configure as cache keys). On a cache hit, it returns the cached response immediately — without invoking the Lambda function or hitting the backend database. Cache capacity is configurable from 0.5 GB to 237 GB. This dramatically reduces backend load and latency for read-heavy APIs with repeated identical requests. Cache invalidation can be triggered by clients with the Cache-Control: max-age=0 header if you configure it.
A new regulatory requirement mandates that all production EC2 instances must have a specific compliance tag (Environment=Production) applied. You need to continuously audit this and automatically remediate non-compliant instances by adding the missing tag. Which AWS services work together to achieve this?
Show answer
Answer: B.
AWS Config + SSM Automation is the standard pattern for detect-and-remediate compliance workflows. A Config rule evaluates all EC2 instances against the required-tags managed rule. When it finds a non-compliant instance, it triggers an automatic remediation action — an SSM Automation document that calls the EC2 CreateTags API to apply the missing tag. The remediation can be set to automatic (immediate) or manually approved. CloudTrail only logs API calls after the fact. Trusted Advisor identifies tagging issues but has no automated remediation. Service Catalog is preventive (controls what users can deploy) but cannot remediate existing resources.
You are designing a data lake on S3. Analysts run ad-hoc SQL queries against large Parquet files using Amazon Athena. A query scanning 10 TB of unpartitioned data takes 8 minutes and costs $50. What is the most effective architectural change to reduce both query time and cost?
Show answer
Answer: B.
Athena is billed per TB of data scanned. Two techniques dramatically reduce scan volume: partitioning and columnar formats. Partitioning organizes data into folder prefixes by frequently filtered attributes (year=2024/month=03/day=15/). When a query includes WHERE year=2024 AND month=03, Athena only scans partitions matching those values — skipping all other data entirely. Columnar formats like Parquet also help (Athena only reads the specific columns referenced in the query, not every column in every row). Together, partitioning + Parquet can reduce query costs by 90%+. Athena pricing is entirely based on data scanned — faster engine versions do not change the cost model.
Your application uses CloudFormation to manage production infrastructure. A junior engineer accidentally runs a delete-stack command against the production stack. How should you have prevented this?
Show answer
Answer: B.
Stack Termination Protection is a CloudFormation feature that prevents a stack from being deleted, even by users who have the cloudformation:DeleteStack IAM permission. Before any deletion can proceed, an authorized user must first explicitly disable termination protection — adding a deliberate confirmation step that catches accidental deletions. DeletionPolicy: Retain preserves resources after stack deletion but still allows the stack itself to be deleted (you just lose CloudFormation management of those resources). IAM policy restrictions reduce the number of people who can delete but cannot prevent an authorized administrator from doing it accidentally. Termination protection is the most direct safeguard.
Your application is experiencing occasional Lambda cold starts of 3–4 seconds that are impacting user experience. The function runs Java with a large initialization class hierarchy. You cannot switch runtimes. What approaches reduce cold start impact without Provisioned Concurrency?
Show answer
Answer: B.
Lambda allocates CPU proportional to memory — doubling memory roughly doubles the available CPU for initialization, which can significantly reduce cold start time for CPU-intensive JVM startup. AWS Lambda SnapStart (available for Java) takes a snapshot of the initialized execution environment and restores it on cold starts, reducing Java cold starts from seconds to milliseconds. For VPC functions, AWS has pre-warmed ENI creation since 2019, so VPC no longer adds meaningful cold start overhead. Provisioned Concurrency is the most reliable solution but has an ongoing cost. Continuous polling would generate unnecessary invocations and cost money without meaningfully keeping the function warm for user traffic.
You need to centrally enforce that all EBS volumes in your AWS Organization are encrypted, and automatically encrypt any unencrypted volume that is created — without writing custom Lambda functions or Config remediation scripts. What is the simplest native mechanism?
Show answer
Answer: B.
EBS Encryption by Default is a per-account, per-region setting that, once enabled, automatically encrypts all newly created EBS volumes, snapshots, and AMIs — no changes to your application code, CloudFormation templates, or launch processes required. The encryption uses the account's default AWS-managed KMS key (or a customer-managed key you specify). Existing unencrypted volumes are not affected retroactively, but all new volumes are covered immediately. This is the lowest-friction path to enforcing encryption. For an Organization-wide rollout, use a CloudFormation StackSet or AWS Config conformance pack to enable this setting in all accounts, rather than managing it account by account.
Your AWS Systems Manager Patch Manager is configured to patch all EC2 instances tagged with PatchGroup=Production every Sunday at 2 AM. An instance was patched but is now failing health checks due to a bad kernel update. How should you handle rollback?
Show answer
Answer: B.
AWS Systems Manager Patch Manager does not provide a native "undo patching" or rollback capability — it applies patches but cannot reverse them with a single click. The correct recovery approaches depend on your backup strategy: if you take AMI snapshots before maintenance windows (a best practice), restore the instance from the pre-patch AMI. If you have EBS snapshots, restore the root volume. In an Auto Scaling Group, terminating the bad instance causes ASG to replace it with a new instance from the current launch template AMI. Running yum downgrade manually via Run Command is technically possible for specific packages but is risky and not scalable. This is why pre-patch AMI snapshots are critical.
You need to process 100,000 structured records from S3 (CSV files), join them with reference data from a RDS database, apply business transformations, and load the results into Redshift daily. The processing takes 2 hours. Which AWS service handles this serverless ETL pipeline most naturally?
Show answer
Answer: C.
AWS Glue is purpose-built for serverless ETL workloads. It provides native connectors to S3, RDS (via JDBC), Redshift, DynamoDB, and many other sources. You write transformation logic in PySpark or Python Shell scripts; Glue handles provisioning, scaling, and managing the underlying Spark infrastructure. The Glue Data Catalog stores schema metadata for all sources and targets. Glue jobs can be scheduled, triggered by events, or run on demand. Lambda is limited to 15 minutes per function and 10 GB memory — unsuitable for 2-hour batch jobs. EMR works but requires more operational setup and is typically chosen when you need full Spark ecosystem control. Step Functions orchestrates workflow logic but does not perform data transformation itself.
Your organization is approaching the default service limit of 5 VPCs per region. Several teams have submitted requests to create new VPCs for new projects. What is the correct process to resolve this?
Show answer
Answer: B.
The default limit of 5 VPCs per region is a soft limit — it exists as a default guardrail, not a hard technical maximum. You can request an increase through the AWS Service Quotas console (Service Quotas → Amazon VPC → VPCs per Region → Request quota increase) or by opening an AWS Support case. AWS typically approves reasonable increases promptly. Many large organizations run dozens or hundreds of VPCs per region. Hard limits (which cannot be increased) are noted explicitly in the AWS documentation. Understanding the difference between soft limits (adjustable defaults) and hard limits (absolute maximums) is important for planning scalable AWS architectures.
An EC2 Auto Scaling Group is running instances launched from an old AMI. You need to update all running instances to use a new AMI (with the latest security patches) while maintaining application availability. Which ASG feature handles this without manual instance replacement?
Show answer
Answer: B.
Instance Refresh is the ASG feature designed specifically for rolling AMI updates. After you update the Launch Template to reference the new AMI, you initiate an Instance Refresh. ASG replaces instances in batches, ensuring that at least the configured minimum healthy percentage of capacity remains in service throughout the rollout. For example, with 10 instances and a 90% minimum healthy threshold, ASG replaces 1 instance at a time — waiting for the new instance to pass health checks before replacing the next one. This maintains availability while systematically replacing the entire fleet. Instance Refresh also supports automatic rollback if the new instances fail health checks, and integrates with launch template version management.
Dernière mise à jour le 18 sept. 2026