Was :
$90
Today :
$50
Was :
$108
Today :
$60
Was :
$126
Today :
$70
Amazon SAA-C03 Exam Dumps – Pass AWS Certified Solutions Architect Associate in First Attempt
Welcome to MyCertsHub, your trusted destination for premium and updated Amazon SAA-C03 exam dumps. If you're preparing for the AWS Certified Solutions Architect – Associate (SAA-C03) certification, you've come to the right place.
We provide a comprehensive and real-exam based SAA-C03 study package designed to help you pass the SAA-C03 exam on your first attempt with confidence. Our SAA-C03 Dumps are compiled and verified by AWS professionals and updated regularly to reflect the latest exam syllabus.
What Is the AWS Certified Solutions Architect – Associate (SAA-C03)?
The SAA-C03 exam is designed for individuals with hands-on experience in designing cost-effective, scalable, and highly available AWS systems. Passing this certification validates your ability to architect and deploy secure and robust applications on AWS technologies.
At MyCertsHub, we make your preparation journey easy, efficient, and effective by providing real SAA-C03 exam questions and answers in PDF format—fully compatible with all your devices.
What’s Included in Our SAA-C03 Dumps Package?
Updated & Verified Exam Questions
Realistic SAA-C03 Practice Test
Detailed Explanations for Every Answer
PDF Format for Easy Access Anywhere
Instant Download After Purchase
100% Passing Guarantee
24/7 Customer Support
Why Choose MyCertsHub for SAA-C03 Preparation?
Real Exam Questions
Our SAA-C03 dumps are based on the actual exam pattern, ensuring you practice with questions similar to what you’ll face in the real AWS exam.
Regularly Updated Content
We continuously update our Amazon SAA-C03 study material to match AWS’s latest blueprint and question trends.
Instant Download – Anytime, Anywhere
All materials are provided in PDF format, making it easy to study on any device at your convenience.
100% Passing & Money-Back Guarantee
We’re confident in the accuracy and quality of our dumps. If you don't pass the exam, you’re covered by our full money-back guarantee.
Affordable Pricing
Get premium content at a fraction of the cost with lifetime updates and unlimited downloads.
Download Now & Start Preparing Today!
Don’t risk your certification journey with outdated or incomplete material. Download the most reliable Amazon SAA-C03 exam dumps from MyCertsHub and take the first step toward becoming a certified AWS Solutions Architect.
Start your preparation with confidence, quality, and guaranteed success — only at MyCertsHub.
FAQ
Amazon SAA-C03 Frequently Asked Questions
A: The Amazon AWS Certified Solutions Architect – Associate (SAA-C03) certification is one of the most recognized cloud computing certifications for IT professionals who want to validate their ability to design secure, scalable, resilient, and cost-effective solutions on AWS. This AWS Associate Certification focuses on core cloud concepts, architecture best practices, networking, storage, security, and disaster recovery strategies.
The Amazon SAA-C03 exam evaluates your knowledge of AWS services such as Amazon EC2, Amazon S3, Amazon RDS, AWS Lambda, Amazon VPC, Route 53, and Elastic Load Balancing. Candidates are expected to understand how these services work together to build reliable cloud environments.
Earning the AWS Certified Solutions Architect Associate Certification can help professionals enhance their cloud skills, improve career prospects, and qualify for cloud-focused roles. Whether you are a system administrator, developer, or aspiring cloud architect, the SAA-C03 certification is an excellent step in the Amazon AWS Certification Path.
For effective AWS Certification Preparation, many candidates use MyCertsHub, which provides updated SAA-C03 Practice Questions, SAA-C03 Practice Tests, and study resources designed to help learners understand real-world AWS Solutions Architecture concepts.
A: Yes, the Amazon SAA-C03 exam can be challenging, especially for candidates who have limited hands-on experience with AWS services. The exam tests more than theoretical knowledge; it focuses heavily on real-world cloud architecture scenarios and requires candidates to select the most efficient, secure, and cost-effective solutions.
Topics such as AWS Security Services, High Availability, Disaster Recovery, Networking, Storage, and Cost Optimization frequently appear in SAA-C03 Exam Questions. Candidates often struggle with scenario-based questions involving Amazon VPC configurations, IAM permissions, Auto Scaling strategies, and multi-tier application architectures.
The best way to overcome these challenges is to combine hands-on AWS experience with structured study materials. Reviewing a quality SAA-C03 Study Guide, completing realistic SAA-C03 Practice Tests, and analyzing SAA-C03 Practice Questions can significantly improve your readiness.
Successful candidates typically spend several weeks learning AWS services and practicing exam-style questions. MyCertsHub helps simplify this process by providing updated learning materials, AWS Practice Exams, and carefully structured Amazon SAA-C03 Exam Questions that mirror the style and complexity of the actual certification exam.
A: The best study materials for the Amazon SAA-C03 exam include official AWS documentation, hands-on labs, video training courses, practice exams, and realistic SAA-C03 Practice Questions. A balanced preparation strategy helps candidates develop both conceptual knowledge and practical problem-solving skills.
Start by reviewing AWS core services such as Amazon EC2, Amazon S3, AWS Lambda, Amazon RDS, CloudFront, Route 53, and Elastic Load Balancing. Understanding how these services interact in real-world cloud environments is essential for success.
Next, focus on scenario-based learning. Most Amazon SAA-C03 Exam Questions require candidates to evaluate multiple solutions and select the best architectural approach. Regular practice with AWS Exam Questions and Answers helps build confidence and improve decision-making skills.
Many candidates also use SAA-C03 Dumps PDF resources as supplementary study tools to identify common exam topics. However, these should never replace genuine learning and hands-on practice.
MyCertsHub provides comprehensive AWS Certification Preparation resources, including SAA-C03 Practice Tests, updated study materials, and detailed explanations that help candidates strengthen their understanding of AWS architecture, security, networking, and cloud optimization concepts.
A:
The Amazon AWS Certified Solutions Architect – Associate (SAA-C03) exam typically contains 65 questions and must be completed within 130 minutes. The exam includes both multiple-choice and multiple-response questions designed to assess your ability to architect solutions using AWS services.
Rather than testing memorization, the exam emphasizes practical application. Many questions present business scenarios involving security, scalability, availability, and cost optimization. Candidates must determine the most effective AWS solution based on specific requirements.
The exam covers several major domains, including:
Design Secure Architectures
Design Resilient Architectures
Design High-Performing Architectures
Design Cost-Optimized Architectures
You may encounter questions involving Amazon VPC networking, IAM policies, EC2 deployment strategies, Auto Scaling configurations, storage solutions, and disaster recovery planning.
To become familiar with the format, candidates should regularly complete SAA-C03 Practice Tests under timed conditions. MyCertsHub offers realistic AWS Practice Exams and SAA-C03 Exam Questions that help users experience the structure and difficulty level of the actual Amazon AWS Exam before test day.
A: SAA-C03 Practice Questions and Practice Tests are extremely valuable, but they should not be the only component of your preparation strategy. The Amazon SAA-C03 exam measures your ability to apply AWS knowledge in real-world situations, making conceptual understanding just as important as exam practice.
Practice tests help identify weak areas, improve time management, and familiarize candidates with the format of Amazon SAA-C03 Exam Questions. They are particularly useful for learning how AWS services are combined to solve business challenges.
However, relying solely on SAA-C03 Dumps PDF or memorized answers can be risky because AWS frequently updates services and best practices. Candidates should also gain hands-on experience with Amazon EC2, S3, Lambda, VPC, RDS, and Route 53 while studying architecture design principles.
A successful preparation plan typically includes official AWS resources, practical labs, study guides, and consistent practice testing. MyCertsHub supports this approach by offering updated SAA-C03 Practice Questions, detailed explanations, AWS Practice Exams, and learning resources that help candidates build the skills required to pass the AWS Certified Solutions Architect Associate Certification and advance their cloud computing careers.
Amazon SAA-C03 Sample Question Answers
Question # 1
A company's marketing data is uploaded from multiple sources to an Amazon S3 bucket A series ot data preparation jobs aggregate the data for reporting The data preparation jobsneed to run at regular intervals in parallel A few jobs need to run in a specific order laterThe company wants to remove the operational overhead of job error handling retry logic,and state managementWhich solution will meet these requirements?
A. Use an AWS Lambda function to process the data as soon as the data is uploaded tothe S3 bucket Invoke Other Lambda functions at regularly scheduled intervals B. Use Amazon Athena to process the data Use Amazon EventBndge Scheduler to invokeAthena on a regular internal C. Use AWS Glue DataBrew to process the data Use an AWS Step Functions statemachine to run the DataBrew data preparation jobs D. Use AWS Data Pipeline to process the data. Schedule Data Pipeline to process the dataonce at midnight.
Answer: C
Explanation: AWS Glue DataBrew is a visual data preparation tool that allows you to
easily clean, normalize, and transform your data without writing any code. You can create
and run data preparation jobs on your data stored in Amazon S3, Amazon Redshift, or
other data sources. AWS Step Functions is a service that lets you coordinate multiple AWS
services into serverless workflows. You can use Step Functions to orchestrate your
DataBrew jobs, define the order and parallelism of execution, handle errors and retries, and
monitor the state of your workflow. By using AWS Glue DataBrew and AWS Step
Functions, you can meet the requirements of the company with minimal operational
overhead, as you do not need to write any code, manage any servers, or deal with complex
dependencies.
References:
AWS Glue DataBrew
AWS Step Functions
Orchestrate AWS Glue DataBrew jobs using AWS Step Functions
Question # 2
A research company uses on-premises devices to generate data for analysis. Thecompany wants to use the AWS Cloud to analyze the data. The devices generate .csv filesand support writing the data to SMB file share. Company analysts must be able to use SQLcommands to query the data. The analysts will run queries periodically throughout the day.Which combination of steps will meet these requirements MOST cost-effectively? (SelectTHREE.)
A. Deploy an AWS Storage Gateway on premises in Amazon S3 File Gateway mode. B. Deploy an AWS Storage Gateway on premises in Amazon FSx File Gateway mode. C. Set up an AWS Glue crawler to create a table based on the data that is in Amazon S3. D. Set up an Amazon EMR cluster with EMR Fife System (EMRFS) to query the data thatis in Amazon S3. Provide access to analysts. E. Set up an Amazon Redshift cluster to query the data that is in Amazon S3. Provideaccess to analysts. F. Set up Amazon Athena to query the data that is in Amazon S3. Provide access toanalysts.
Answer: A,C,F
Explanation: To meet the requirements of the use case in a cost-effective way, the
following steps are recommended:
Deploy an AWS Storage Gateway on premises in Amazon S3 File Gateway mode.
This will allow the company to write the .csv files generated by the devices to an
SMB file share, which will be stored as objects in Amazon S3 buckets. AWS
Storage Gateway is a hybrid cloud storage service that integrates on-premises
environments with AWS storage. Amazon S3 File Gateway mode provides a
seamless way to connect to Amazon S3 and access a virtually unlimited amount of
cloud storage1.
Set up an AWS Glue crawler to create a table based on the data that is in Amazon
S3. This will enable the company to use standard SQL to query the data stored in
Amazon S3 buckets. AWS Glue is a serverless data integration service that
simplifies data preparation and analysis. AWS Glue crawlers can automatically
discover and classify data from various sources, and create metadata tables in the
AWS Glue Data Catalog2. The Data Catalog is a central repository that stores
information about data sources and how to access them3.
Set up Amazon Athena to query the data that is in Amazon S3. This will provide
the company analysts with a serverless and interactive query service that can
analyze data directly in Amazon S3 using standard SQL. Amazon Athena is
integrated with the AWS Glue Data Catalog, so users can easily point Athena at
the data source tables defined by the crawlers. Amazon Athena charges only for
the queries that are run, and offers a pay-per-query pricing model, which makes it
a cost-effective option for periodic queries4.
The other options are not correct because they are either not cost-effective or not suitable
for the use case. Deploying an AWS Storage Gateway on premises in Amazon FSx File
Gateway mode is not correct because this mode provides low-latency access to fully
managed Windows file shares in AWS, which is not required for the use case. Setting up
an Amazon EMR cluster with EMR File System (EMRFS) to query the data that is in
Amazon S3 is not correct because this option involves setting up and managing a cluster of
EC2 instances, which adds complexity and cost to the solution. Setting up an Amazon
Redshift cluster to query the data that is in Amazon S3 is not correct because this option
also involves provisioning and managing a cluster of nodes, which adds overhead and cost
to the solution.
References:
What is AWS Storage Gateway?
What is AWS Glue?
AWS Glue Data Catalog
What is Amazon Athena?
Question # 3
A company website hosted on Amazon EC2 instances processes classified data stored inThe application writes data to Amazon Elastic Block Store (Amazon EBS) volumes Thecompany needs to ensure that all data that is written to the EBS volumes is encrypted atrest.Which solution will meet this requirement?
A. Create an 1AM role that specifies EBS encryption Attach the role to the EC2 instances B. Create the EBS volumes as encrypted volumes Attach the EBS volumes to the EC2instances C. Create an EC2 instance tag that has a key of Encrypt and a value of True Tag allinstances that require encryption at the EBS level D. Create an AWS Key Management Service (AWS KMS) key policy that enforces EBSencryption in the account Ensure that the key policy is active
Answer: B
Explanation: The simplest and most effective way to ensure that all data that is written to
the EBS volumes is encrypted at rest is to create the EBS volumes as encrypted volumes.
You can do this by selecting the encryption option when you create a new EBS volume, or
by copying an existing unencrypted volume to a new encrypted volume. You can also
specify the AWS KMS key that you want to use for encryption, or use the default AWSmanaged
key. When you attach the encrypted EBS volumes to the EC2 instances, the data
will be automatically encrypted and decrypted by the EC2 host. This solution does not
require any additional IAM roles, tags, or policies. References:
Amazon EBS encryption
Creating an encrypted EBS volume
Encrypting an unencrypted EBS volume
Question # 4
A company has Amazon EC2 instances that run nightly batch jobs to process data. TheEC2 instances run in an Auto Scaling group that uses On-Demand billing. If a job fails onone instance: another instance will reprocess the job. The batch jobs run between 12:00AM and 06 00 AM local time every day.Which solution will provide EC2 instances to meet these requirements MOST cost-effectively'?
A. Purchase a 1-year Savings Plan for Amazon EC2 that covers the instance family of theAuto Scaling group that the batch job uses. B. Purchase a 1-year Reserved Instance for the specific instance type and operatingsystem of the instances in the Auto Scaling group that the batch job uses. C. Create a new launch template for the Auto Scaling group Set the instances to SpotInstances Set a policy to scale out based on CPU usage. D. Create a new launch template for the Auto Scaling group Increase the instance size Seta policy to scale out based on CPU usage.
Answer: C
Explanation: This option is the most cost-effective solution because it leverages the Spot
Instances, which are unused EC2 instances that are available at up to 90% discount
compared to On-Demand prices. Spot Instances can be interrupted by AWS when the
demand for On-Demand instances increases, but since the batch jobs are fault-tolerant and
can be reprocessed by another instance, this is not a major issue. By using a launch
template, the company can specify the configuration of the Spot Instances, such as the
instance type, the operating system, and the user data. By using an Auto Scaling group,
the company can automatically scale the number of Spot Instances based on the CPU
usage, which reflects the load of the batch jobs. This way, the company can optimize the
performance and the cost of the EC2 instances for the nightly batch jobs.
A. Purchase a 1-year Savings Plan for Amazon EC2 that covers the instance family of the
Auto Scaling group that the batch job uses. This option is not optimal because it requires a
commitment to a consistent amount of compute usage per hour for a one-year term,
regardless of the instance type, size, region, or operating system. This can limit the flexibility and scalability of the Auto Scaling group and result in overpaying for unused
compute capacity. Moreover, Savings Plans do not provide a capacity reservation, which
means the company still needs to reserve capacity with On-Demand Capacity
Reservations and pay lower prices with Savings Plans.
B. Purchase a 1-year Reserved Instance for the specific instance type and operating
system of the instances in the Auto Scaling group that the batch job uses. This option is not
ideal because it requires a commitment to a specific instance configuration for a one-year
term, which can reduce the flexibility and scalability of the Auto Scaling group and result in
overpaying for unused compute capacity. Moreover, Reserved Instances do not provide a
capacity reservation, which means the company still needs to reserve capacity with On-
Demand Capacity Reservations and pay lower prices with Reserved Instances.
D. Create a new launch template for the Auto Scaling group Increase the instance size Set
a policy to scale out based on CPU usage. This option is not cost-effective because it does
not take advantage of the lower prices of Spot Instances. Increasing the instance size can
improve the performance of the batch jobs, but it can also increase the cost of the On-
Demand instances. Moreover, scaling out based on CPU usage can result in launching
more instances than needed, which can also increase the cost of the system.
References:
1 Spot Instances - Amazon Elastic Compute Cloud
2 Launch templates - Amazon Elastic Compute Cloud
3 Auto Scaling groups - Amazon EC2 Auto Scaling
[4] Savings Plans - Amazon EC2 Reserved Instances and Other AWS Reservation
Models
Question # 5
A company hosts a three-tier web application in the AWS Cloud. A Multi-AZ Amazon RDSfor MySQL server forms the database layer. Amazon ElastiCache forms the cache layer.The company wants a caching strategy that adds or updates data in the cache when acustomer adds an item to the database. The data in the cache must always match the datain the database.Which solution will meet these requirements?
A. Implement the lazy loading caching strategy B. Implement the write-through caching strategy. C. Implement the adding TTL caching strategy. D. Implement the AWS AppConfig caching strategy.
Answer: B
Explanation: A write-through caching strategy adds or updates data in the cache
whenever data is written to the database. This ensures that the data in the cache is always
consistent with the data in the database. A write-through caching strategy also reduces the
cache miss penalty, as data is always available in the cache when it is requested.
However, a write-through caching strategy can increase the write latency, as data has to be
written to both the cache and the database. A write-through caching strategy is suitable for
applications that require high data consistency and low read latency.
A lazy loading caching strategy only loads data into the cache when it is requested, and
updates the cache when there is a cache miss. This can result in stale data in the cache,
as data is not updated in the cache when it is changed in the database. A lazy loading
caching strategy is suitable for applications that can tolerate some data inconsistency and
have a low cache miss rate.
An adding TTL caching strategy assigns a time-to-live (TTL) value to each data item in the cache, and removes the data from the cache when the TTL expires. This can help prevent
stale data in the cache, as data is periodically refreshed from the database. However, an
adding TTL caching strategy can also increase the cache miss rate, as data can be evicted
from the cache before it is requested. An adding TTL caching strategy is suitable for
applications that have a high cache hit rate and can tolerate some data inconsistency.
An AWS AppConfig caching strategy is not a valid option, as AWS AppConfig is a service
that enables customers to quickly deploy validated configurations to applications of any
size and scale. AWS AppConfig does not provide a caching layer for web applications.
References: Caching strategies - Amazon ElastiCache, Caching for high-volume workloads
with Amazon ElastiCache
Question # 6
A company wants to analyze and troubleshoot Access Denied errors and Unauthonzederrors that are related to 1AM permissions The company has AWS CloudTrail turned onWhich solution will meet these requirements with the LEAST effort?
A. Use AWS Glue and write custom scripts to query CloudTrail logs for the errors B. Use AWS Batch and write custom scripts to query CloudTrail logs for the errors C. Search CloudTrail logs with Amazon Athena queries to identify the errors D. Search CloudTrail logs with Amazon QuickSight. Create a dashboard to identify the errors.
Answer: C
Explanation: This solution meets the following requirements:
It is the least effort, as it does not require any additional AWS services, custom
scripts, or data processing steps. Amazon Athena is a serverless interactive query
service that allows you to analyze data in Amazon S3 using standard SQL. You
can use Athena to query CloudTrail logs directly from the S3 bucket where they
are stored, without any data loading or transformation. You can also use the AWS
Management Console, the AWS CLI, or the Athena API to run and manage your
queries.
It is effective, as it allows you to filter, aggregate, and join CloudTrail log data using
SQL syntax. You can use various SQL functions and operators to specify the
criteria for identifying Access Denied and Unauthorized errors, such as the error
code, the user identity, the event source, the event name, the event time, and the
resource ARN. You can also use subqueries, views, and common table
expressions to simplify and optimize your queries.
It is flexible, as it allows you to customize and save your queries for future use.
You can also export the query results to other formats, such as CSV or JSON, or
integrate them with other AWS services, such as Amazon QuickSight, for further
analysis and visualization.
References:
Querying AWS CloudTrail Logs - Amazon Athena
Analyzing Data in S3 using Amazon Athena | AWS Big Data Blog
Troubleshoot IAM permisson access denied or unauthorized errors | AWS re:Post
Question # 7
A global company runs its applications in multiple AWS accounts in AWS Organizations.The company's applications use multipart uploads to upload data to multiple Amazon S3buckets across AWS Regions. The company wants to report on incomplete multipartuploads for cost compliance purposes.Which solution will meet these requirements with the LEAST operational overhead?
A. Configure AWS Config with a rule to report the incomplete multipart upload object count. B. Create a service control policy (SCP) to report the incomplete multipart upload objectcount. C. Configure S3 Storage Lens to report the incomplete multipart upload object count. D. Create an S3 Multi-Region Access Point to report the incomplete multipart upload objectcount.
Answer: C
Explanation: S3 Storage Lens is a cloud storage analytics feature that provides
organization-wide visibility into object storage usage and activity across multiple AWS
accounts in AWS Organizations. S3 Storage Lens can report the incomplete multipart
upload object count as one of the metrics that it collects and displays on an interactive
dashboard in the S3 console. S3 Storage Lens can also export metrics in CSV or Parquet
format to an S3 bucket for further analysis. This solution will meet the requirements with the
least operational overhead, as it does not require any code development or policy changes.
References:
1 explains how to use S3 Storage Lens to gain insights into S3 storage usage and
activity.
2 describes the concept and benefits of multipart uploads.
Question # 8
A company has stored 10 TB of log files in Apache Parquet format in an Amazon S3 bucketThe company occasionally needs to use SQL to analyze the log files Which solution willmeet these requirements MOST cost-effectively?
A. Create an Amazon Aurora MySQL database Migrate the data from the S3 bucket intoAurora by using AWS Database Migration Service (AWS DMS) Issue SQL statements tothe Aurora database. B. Create an Amazon Redshift cluster Use Redshift Spectrum to run SQL statementsdirectly on the data in the S3 bucket C. Create an AWS Glue crawler to store and retrieve table metadata from the S3 bucketUse Amazon Athena to run SQL statements directly on the data in the S3 bucket D. Create an Amazon EMR cluster Use Apache Spark SQL to run SQL statements directlyon the data in the S3 bucket
Answer: C
Explanation: AWS Glue is a serverless data integration service that can crawl, catalog,
and prepare data for analysis. AWS Glue can automatically discover the schema and
partitioning of the data stored in Apache Parquet format in S3, and create a table in the
AWS Glue Data Catalog. Amazon Athena is a serverless interactive query service that can
run SQL queries directly on data in S3, without requiring any data loading or
transformation. Athena can use the table metadata from the AWS Glue Data Catalog to
query the data in S3. By using AWS Glue and Athena, you can analyze the log files in S3
most cost-effectively, as you only pay for the resources consumed by the crawler and the
queries, and you do not need to provision or manage any servers or clusters.
References:
AWS Glue
Amazon Athena
Analyzing Data in S3 using Amazon Athena
Question # 9
A pharmaceutical company is developing a new drug. The volume of data that the company generates has grown exponentially over the past few months. The company'sresearchers regularly require a subset of the entire dataset to be immediately available withminimal lag. However the entire dataset does not need to be accessed on a daily basis. Allthe data currently resides in on-premises storage arrays, and the company wants to reduceongoing capital expenses.Which storage solution should a solutions architect recommend to meet theserequirements?
A. Run AWS DataSync as a scheduled cron job to migrate the data to an Amazon S3bucket on an ongoing basis. B. Deploy an AWS Storage Gateway file gateway with an Amazon S3 bucket as the targetstorage Migrate the data to the Storage Gateway appliance. C. Deploy an AWS Storage Gateway volume gateway with cached volumes with anAmazon S3 bucket as the target storage. Migrate the data to the Storage Gatewayappliance. D. Configure an AWS Site-to-Site VPN connection from the on-premises environment toAWS. Migrate data to an Amazon Elastic File System (Amazon EFS) file system.
Answer: C
Explanation: AWS Storage Gateway is a hybrid cloud storage service that allows you to
seamlessly integrate your on-premises applications with AWS cloud storage. Volume
Gateway is a type of Storage Gateway that presents cloud-backed iSCSI block storage
volumes to your on-premises applications. Volume Gateway operates in either cache mode
or stored mode. In cache mode, your primary data is stored in Amazon S3, while retaining
your frequently accessed data locally in the cache for low latency access. In stored mode,
your primary data is stored locally and your entire dataset is available for low latency
access on premises while also asynchronously getting backed up to Amazon S3.
For the pharmaceutical company’s use case, cache mode is the most suitable option, as it
meets the following requirements:
It reduces the need to scale the on-premises storage infrastructure, as most of the
data is stored in Amazon S3, which is scalable, durable, and cost-effective.
It provides low latency access to the subset of the data that the researchers
regularly require, as it is cached locally in the Storage Gateway appliance.
It does not require the entire dataset to be accessed on a daily basis, as it is
stored in Amazon S3 and can be retrieved on demand.
It offers flexible data protection and recovery options, as it allows taking point-intime
copies of the volumes using AWS Backup, which are stored in AWS as
Amazon EBS snapshots.
Therefore, the solutions architect should recommend deploying an AWS Storage Gateway
volume gateway with cached volumes with an Amazon S3 bucket as the target storage and
migrating the data to the Storage Gateway appliance.
References:
Volume Gateway | Amazon Web Services
How Volume Gateway works (architecture) - AWS Storage Gateway
A company runs a three-tier web application in a VPC across multiple Availability Zones.Amazon EC2 instances run in an Auto Scaling group for the application tier.The company needs to make an automated scaling plan that will analyze each resource'sdaily and weekly historical workload trends. The configuration must scale resourcesappropriately according to both the forecast and live changes in utilization.Which scaling strategy should a solutions architect recommend to meet theserequirements?
A. Implement dynamic scaling with step scaling based on average CPU utilization from theEC2 instances. B. Enable predictive scaling to forecast and scale. Configure dynamic scaling with targettracking. C. Create an automated scheduled scaling action based on the traffic patterns of the webapplication. D. Set up a simple scaling policy. Increase the cooldown period based on the EC2 instancestartup time
Answer: B
Explanation:
This solution meets the requirements because it allows the company to use both predictive
scaling and dynamic scaling to optimize the capacity of its Auto Scaling group. Predictive
scaling uses machine learning to analyze historical data and forecast future traffic patterns.
It then adjusts the desired capacity of the group in advance of the predicted changes.
Dynamic scaling uses target tracking to maintain a specified metric (such as CPU
utilization) at a target value. It scales the group in or out as needed to keep the metric close to the target. By using both scaling methods, the company can benefit from faster, simpler,
and more accurate scaling that responds to both forecasted and live changes in utilization.
References:
Predictive scaling for Amazon EC2 Auto Scaling
[Target tracking scaling policies for Amazon EC2 Auto Scaling
Question # 11
A company deployed a serverless application that uses Amazon DynamoDB as a databaselayer The application has experienced a large increase in users. The company wants toimprove database response time from milliseconds to microseconds and to cache requeststo the database.Which solution will meet these requirements with the LEAST operational overhead?
A. Use DynamoDB Accelerator (DAX). B. Migrate the database to Amazon Redshift. C. Migrate the database to Amazon RDS. D. Use Amazon ElastiCache for Redis.
Answer: A
Explanation: DynamoDB Accelerator (DAX) is a fully managed, highly available caching
service built for Amazon DynamoDB. DAX delivers up to a 10 times performance
improvement—from milliseconds to microseconds—even at millions of requests per
second. DAX does all the heavy lifting required to add in-memory acceleration to your
DynamoDB tables, without requiring developers to manage cache invalidation, data
population, or cluster management. Now you can focus on building great applications for
your customers without worrying about performance at scale. You do not need to modify
application logic because DAX is compatible with existing DynamoDB API calls. This
solution will meet the requirements with the least operational overhead, as it does not
require any code development or manual intervention. References:
1 provides an overview of Amazon DynamoDB Accelerator (DAX) and its benefits.
2 explains how to use DAX with DynamoDB for in-memory acceleration.
Question # 12
An online video game company must maintain ultra-low latency for its game servers. Thegame servers run on Amazon EC2 instances. The company needs a solution that canhandle millions of UDP internet traffic requests each second.Which solution will meet these requirements MOST cost-effectively?
A. Configure an Application Load Balancer with the required protocol and ports for theinternet traffic. Specify the EC2 instances as the targets. B. Configure a Gateway Load Balancer for the internet traffic. Specify the EC2 instances asthe targets. C. Configure a Network Load Balancer with the required protocol and ports for the internettraffic. Specify the EC2 instances as the targets. D. Launch an identical set of game servers on EC2 instances in separate AWS Regions. Route internet traffic to both sets of EC2 instances.
Answer: C
Explanation: The most cost-effective solution for the online video game company is to
configure a Network Load Balancer with the required protocol and ports for the internet
traffic and specify the EC2 instances as the targets. This solution will enable the company
to handle millions of UDP requests per second with ultra-low latency and high performance.
A Network Load Balancer is a type of Elastic Load Balancing that operates at the
connection level (Layer 4) and routes traffic to targets (EC2 instances, microservices, or
containers) within Amazon VPC based on IP protocol data. A Network Load Balancer is
ideal for load balancing of both TCP and UDP traffic, as it is capable of handling millions of
requests per second while maintaining high throughput at ultra-low latency. A Network
Load Balancer also preserves the source IP address of the clients to the back-end
applications, which can be useful for logging or security purposes1.
Question # 13
A company maintains an Amazon RDS database that maps users to cost centers. Thecompany has accounts in an organization in AWS Organizations. The company needs asolution that will tag all resources that are created in a specific AWS account in theorganization. The solution must tag each resource with the cost center ID of the user whocreated the resource.Which solution will meet these requirements?
A. Move the specific AWS account to a new organizational unit (OU) in Organizations fromthe management account. Create a service control policy (SCP) that requires all existingresources to have the correct cost center tag before the resources are created. Apply the SCP to the new OU. B. Create an AWS Lambda function to tag the resources after the Lambda function looksup the appropriate cost center from the RDS database. Configure an Amazon EventBridgerule that reacts to AWS CloudTrail events to invoke the Lambda function. C. Create an AWS CloudFormation stack to deploy an AWS Lambda function. Configurethe Lambda function to look up the appropriate cost center from the RDS database and totag resources. Create an Amazon EventBridge scheduled rule to invoke theCloudFormation stack. D. Create an AWS Lambda function to tag the resources with a default value. Configure anAmazon EventBridge rule that reacts to AWS CloudTrail events to invoke the Lambdafunction when a resource is missing the cost center tag.
Answer: B
Explanation: AWS Lambda is a serverless compute service that lets you run code without
provisioning or managing servers. Lambda can be used to tag resources with the cost
center ID of the user who created the resource, by querying the RDS database that maps
users to cost centers. Amazon EventBridge is a serverless event bus service that enables
event-driven architectures. EventBridge can be configured to react to AWS CloudTrail
events, which are recorded API calls made by or on behalf of the AWS account.
EventBridge can invoke the Lambda function when a resource is created in the specific
AWS account, passing the user identity and resource information as parameters. This
solution will meet the requirements, as it enables automatic tagging of resources based on
the user and cost center mapping.
References:
1 provides an overview of AWS Lambda and its benefits.
2 provides an overview of Amazon EventBridge and its benefits.
3 explains the concept and benefits of AWS CloudTrail events.
Question # 14
A company is designing a tightly coupled high performance computing (HPC) environmentin the AWS Cloud The company needs to include features that will optimize the HPCenvironment for networking and storage.Which combination of solutions will meet these requirements? (Select TWO )
A. Create an accelerator in AWS Global Accelerator. Configure custom routing for theaccelerator. B. Create an Amazon FSx for Lustre file system. Configure the file system with scratchstorage. C. Create an Amazon CloudFront distribution. Configure the viewer protocol policy to beHTTP and HTTPS. D. Launch Amazon EC2 instances. Attach an Elastic Fabric Adapter (EFA) to theinstances. E. Create an AWS Elastic Beanstalk deployment to manage the environment.
Answer: B,D
Explanation: These two solutions will optimize the HPC environment for networking and
storage. Amazon FSx for Lustre is a fully managed service that provides cost-effective,
high-performance, scalable storage for compute workloads. It is built on the world’s most
popular high-performance file system, Lustre, which is designed for applications that
require fast storage, such as HPC and machine learning. By configuring the file system
with scratch storage, you can achieve sub-millisecond latencies, up to hundreds of GBs/s
of throughput, and millions of IOPS. Scratch file systems are ideal for temporary storage
and shorter-term processing of data. Data is not replicated and does not persist if a file
server fails. For more information, see Amazon FSx for Lustre.
Elastic Fabric Adapter (EFA) is a network interface for Amazon EC2 instances that enables
customers to run applications requiring high levels of inter-node communications at scale
on AWS. Its custom-built operating system (OS) bypass hardware interface enhances the
performance of inter-instance communications, which is critical to scaling HPC and
machine learning applications. EFA provides a low-latency, low-jitter channel for interinstance
communications, enabling your tightly-coupled HPC or distributed machine
learning applications to scale to thousands of cores. EFA uses libfabric interface and
libfabric APIs for communications, which are supported by most HPC programming
models. For more information, see Elastic Fabric Adapter. The other solutions are not suitable for optimizing the HPC environment for networking and
storage. AWS Global Accelerator is a networking service that helps you improve the
availability, performance, and security of your public applications by using the AWS global
network. It provides two global static public IPs, deterministic routing, fast failover, and TCP
termination at the edge for your application endpoints. However, it does not support OSbypass
capabilities or high-performance file systems that are required for HPC and
machine learning applications. For more information, see AWS Global Accelerator.
Amazon CloudFront is a content delivery network (CDN) service that securely delivers
data, videos, applications, and APIs to customers globally with low latency, high transfer
speeds, all within a developer-friendly environment. CloudFront is integrated with AWS
services such as Amazon S3, Amazon EC2, AWS Elemental Media Services, AWS Shield,
AWS WAF, and AWS Lambda@Edge. However, CloudFront is not designed for HPC and
machine learning applications that require high levels of inter-node communications and
fast storage. For more information, see [Amazon CloudFront].
AWS Elastic Beanstalk is an easy-to-use service for deploying and scaling web
applications and services developed with Java, .NET, PHP, Node.js, Python, Ruby, Go,
and Docker on familiar servers such as Apache, Nginx, Passenger, and IIS. You can
simply upload your code and Elastic Beanstalk automatically handles the deployment, from
capacity provisioning, load balancing, auto-scaling to application health monitoring.
However, Elastic Beanstalk is not optimized for HPC and machine learning applications
that require OS-bypass capabilities and high-performance file systems. For more
information, see [AWS Elastic Beanstalk].
References: Amazon FSx for Lustre, Elastic Fabric Adapter, AWS Global Accelerator,
[Amazon CloudFront], [AWS Elastic Beanstalk].
Question # 15
A company is running a photo hosting service in the us-east-1 Region. The service enablesusers across multiple countries to upload and view photos. Some photos are heavilyviewed for months, and others are viewed for less than a week. The application allowsuploads of up to 20 MB for each photo. The service uses the photo metadata to determinewhich photos to display to each user.Which solution provides the appropriate user access MOST cost-effectively?
A. Store the photos in Amazon DynamoDB. Turn on DynamoDB Accelerator (DAX) tocache frequently viewed items. B. Store the photos in the Amazon S3 Intelligent-Tiering storage class. Store the photometadata and its S3 location in DynamoDB. C. Store the photos in the Amazon S3 Standard storage class. Set up an S3 Lifecyclepolicy to move photos older than 30 days to the S3 Standard-Infrequent Access (S3Standard-IA) storage class. Use the object tags to keep track of metadata. D. Store the photos in the Amazon S3 Glacier storage class. Set up an S3 Lifecycle policyto move photos older than 30 days to the S3 Glacier Deep Archive storage class. Store thephoto metadata and its S3 location in Amazon OpenSearch Service.
Answer: B
Explanation: This solution provides the appropriate user access most cost-effectively
because it uses the Amazon S3 Intelligent-Tiering storage class, which automatically
optimizes storage costs by moving data to the most cost-effective access tier when access patterns change, without performance impact or operational overhead1. This storage class
is ideal for data with unknown, changing, or unpredictable access patterns, such as photos
that are heavily viewed for months or less than a week. By storing the photo metadata and
its S3 location in DynamoDB, the application can quickly query and retrieve the relevant
photos for each user. DynamoDB is a fast, scalable, and fully managed NoSQL database
service that supports key-value and document data models2.
A company is designing a new web application that will run on Amazon EC2 Instances. Theapplication will use Amazon DynamoDB for backend data storage. The application trafficwill be unpredictable. T company expects that the application read and write throughput tothe database will be moderate to high. The company needs to scale in response toapplication traffic.Which DynamoDB table configuration will meet these requirements MOST cost-effectively?
A. Configure DynamoDB with provisioned read and write by using the DynamoDBStandard table class. Set DynamoDB auto scaling to a maximum defined capacity. B. Configure DynamoDB in on-demand mode by using the DynamoDB Standard tableclass. C. Configure DynamoDB with provisioned read and write by using the DynamoDBStandard Infrequent Access (DynamoDB Standard-IA) table class. Set DynamoDB autoscaling to a maximum defined capacity. D. Configure DynamoDB in on-demand mode by using the DynamoDB Standard InfrequentAccess (DynamoDB Standard-IA) table class.
Answer: B
Explanation: The most cost-effective DynamoDB table configuration for the web
application is to configure DynamoDB in on-demand mode by using the DynamoDB
Standard table class. This configuration will allow the company to scale in response to
application traffic and pay only for the read and write requests that the application performs
on the table.
On-demand mode is a flexible billing option that can handle thousands of requests per
second without capacity planning. On-demand mode automatically adjusts the table’s
capacity based on the incoming traffic, and charges only for the read and write requests
that are actually performed. On-demand mode is suitable for applications with
unpredictable or variable workloads, or applications that prefer the ease of paying for only
what they use1.
The DynamoDB Standard table class is the default and recommended table class for most
workloads. The DynamoDB Standard table class offers lower throughput costs than the
DynamoDB Standard-Infrequent Access (DynamoDB Standard-IA) table class, and is more
cost-effective for tables where throughput is the dominant cost. The DynamoDB Standard
table class also offers the same performance, durability, and availability as the DynamoDB
Standard-IA table class2. The other options are not correct because they are either not cost-effective or not suitable
for the use case. Configuring DynamoDB with provisioned read and write by using the
DynamoDB Standard table class, and setting DynamoDB auto scaling to a maximum
defined capacity is not correct because this configuration requires manual estimation and
management of the table’s capacity, which adds complexity and cost to the solution.
Provisioned mode is a billing option that requires users to specify the amount of read and
write capacity units for their tables, and charges for the reserved capacity regardless of
usage. Provisioned mode is suitable for applications with predictable or stable workloads,
or applications that require finer-grained control over their capacity settings1. Configuring
DynamoDB with provisioned read and write by using the DynamoDB Standard-Infrequent
Access (DynamoDB Standard-IA) table class, and setting DynamoDB auto scaling to a
maximum defined capacity is not correct because this configuration is not cost-effective for
tables with moderate to high throughput. The DynamoDB Standard-IA table class offers
lower storage costs than the DynamoDB Standard table class, but higher throughput costs.
The DynamoDB Standard-IA table class is optimized for tables where storage is the
dominant cost, such as tables that store infrequently accessed data2. Configuring
DynamoDB in on-demand mode by using the DynamoDB Standard-Infrequent Access
(DynamoDB Standard-IA) table class is not correct because this configuration is not costeffective
for tables with moderate to high throughput. As mentioned above, the DynamoDB
Standard-IA table class has higher throughput costs than the DynamoDB Standard table
class, which can offset the savings from lower storage costs.
References:
Table classes - Amazon DynamoDB
Read/write capacity mode - Amazon DynamoDB
Question # 17
A company's web application that is hosted in the AWS Cloud recently increased inpopularity. The web application currently exists on a single Amazon EC2 instance in asingle public subnet. The web application has not been able to meet the demand of theincreased web traffic.The company needs a solution that will provide high availability and scalability to meet theincreased user demand without rewriting the web application.Which combination of steps will meet these requirements? (Select TWO.)
A. Replace the EC2 instance with a larger compute optimized instance. B. Configure Amazon EC2 Auto Scaling with multiple Availability Zones in private subnets. C. Configure a NAT gateway in a public subnet to handle web requests. D. Replace the EC2 instance with a larger memory optimized instance. E. Configure an Application Load Balancer in a public subnet to distribute web traffic
Answer: B,E
Explanation:
These two steps will meet the requirements because they will provide high availability and
scalability for the web application without rewriting it. Amazon EC2 Auto Scaling allows you
to automatically adjust the number of EC2 instances in response to changes in demand. By
configuring Auto Scaling with multiple Availability Zones in private subnets, you can ensure
that your web application is distributed across isolated and fault-tolerant locations, and that
your instances are not directly exposed to the internet. An Application Load Balancer
operates at the application layer and distributes incoming web traffic across multiple
targets, such as EC2 instances, containers, or Lambda functions. By configuring an
Application Load Balancer in a public subnet, you can enable your web application to
handle requests from the internet and route them to the appropriate targets in the private
subnets.
References:
What is Amazon EC2 Auto Scaling?
What is an Application Load Balancer?
Question # 18
A company is designing a web application on AWS The application will use a VPNconnection between the company's existing data centers and the company's VPCs. Thecompany uses Amazon Route 53 as its DNS service. The application must use privateDNS records to communicate with the on-premises services from a VPC. Which solutionwill meet these requirements in the MOST secure manner?
A. Create a Route 53 Resolver outbound endpoint. Create a resolver rule. Associate theresolver rule with the VPC B. Create a Route 53 Resolver inbound endpoint. Create a resolver rule. Associate theresolver rule with the VPC. C. Create a Route 53 private hosted zone. Associate the private hosted zone with the VPC. D. Create a Route 53 public hosted zone. Create a record for each service to allow servicecommunication.
Answer: A
Explanation: To meet the requirements of the web application in the most secure manner,
the company should create a Route 53 Resolver outbound endpoint, create a resolver rule,
and associate the resolver rule with the VPC. This solution will allow the application to use
private DNS records to communicate with the on-premises services from a VPC. Route 53
Resolver is a service that enables DNS resolution between on-premises networks and
AWS VPCs. An outbound endpoint is a set of IP addresses that Resolver uses to forward
DNS queries from a VPC to resolvers on an on-premises network. A resolver rule is a rule
that specifies the domain names for which Resolver forwards DNS queries to the IP
addresses that you specify in the rule. By creating an outbound endpoint and a resolver
rule, and associating them with the VPC, the company can securely resolve DNS queries
for the on-premises services using private DNS records12.
The other options are not correct because they do not meet the requirements or are not
secure. Creating a Route 53 Resolver inbound endpoint, creating a resolver rule, and
associating the resolver rule with the VPC is not correct because this solution will allow
DNS queries from on-premises networks to access resources in a VPC, not vice versa. An
inbound endpoint is a set of IP addresses that Resolver uses to receive DNS queries from
resolvers on an on-premises network1. Creating a Route 53 private hosted zone and
associating it with the VPC is not correct because this solution will only allow DNS
resolution for resources within the VPC or other VPCs that are associated with the same
hosted zone. A private hosted zone is a container for DNS records that are only accessible
from one or more VPCs3. Creating a Route 53 public hosted zone and creating a record for
each service to allow service communication is not correct because this solution will expose the on-premises services to the public internet, which is not secure. A public hosted
zone is a container for DNS records that are accessible from anywhere on the internet3.
References:
Resolving DNS queries between VPCs and your network - Amazon Route 53
Working with rules - Amazon Route 53
Working with private hosted zones - Amazon Route 53
Question # 19
A media company stores movies in Amazon S3. Each movie is stored in a single video filethat ranges from 1 GB to 10 GB in size.The company must be able to provide the streaming content of a movie within 5 minutes ofa user purchase. There is higher demand for movies that are less than 20 years old thanfor movies that are more than 20 years old. The company wants to minimize hostingservice costs based on demand.Which solution will meet these requirements?
A. Store all media content in Amazon S3. Use S3 Lifecycle policies to move media datainto the Infrequent Access tier when the demand for a movie decreases. B. Store newer movie video files in S3 Standard Store older movie video files in S3Standard-Infrequent Access (S3 Standard-IA). When a user orders an older movie, retrievethe video file by using standard retrieval. C. Store newer movie video files in S3 Intelligent-Tiering. Store older movie video files inS3 Glacier Flexible Retrieval. When a user orders an older movie, retrieve the video file byusing expedited retrieval. D. Store newer movie video files in S3 Standard. Store older movie video files in S3 GlacierFlexible Retrieval. When a user orders an older movie, retrieve the video file by using bulkretrieval.
Answer: C
Explanation: This solution will meet the requirements of minimizing hosting service costs
based on demand and providing the streaming content of a movie within 5 minutes of a user purchase. S3 Intelligent-Tiering is a storage class that automatically optimizes storage
costs by moving data to the most cost-effective access tier when access patterns
change. It is suitable for data with unknown, changing, or unpredictable access patterns,
such as newer movies that may have higher demand1. S3 Glacier Flexible Retrieval is a
storage class that provides low-cost storage for archive data that is retrieved
asynchronously. It offers flexible data retrieval options from minutes to hours, and free bulk
retrievals in 5-12 hours. It is ideal for backup, disaster recovery, and offsite data storage
needs2. By using expedited retrieval, the user can access the older movie video file in 1-5
minutes, which meets the requirement of 5 minutes3.
Amazon S3 Glacier Flexible Retrieval and Glacier Deep Archive Retrieval …1, Amazon S3
Glacier Flexible Retrieval section3: Amazon S3 Glacier Flexible Retrieval and Glacier Deep
Archive Retrieval …1, Retrieval Rates section.
Question # 20
A business application is hosted on Amazon EC2 and uses Amazon S3 for encryptedobject storage. The chief information security officer has directed that no application trafficbetween the two services should traverse the public internet.Which capability should the solutions architect use to meet the compliance requirements?
A. AWS Key Management Service (AWS KMS) B. VPC endpoint C. Private subnet D. Virtual private gateway
To meet security requirements, a company needs to encrypt all of its application data intransit while communicating with an Amazon RDS MySQL DB instance. A recent securityaudit revealed that encryption at rest is enabled using AWS Key Management Service(AWS KMS), but data in transit is not enabled.What should a solutions architect do to satisfy the security requirements?
A. Enable 1AM database authentication on the database. B. Provide self-signed certificates. Use the certificates in all connections to the RDSinstance. C. Take a snapshot of the RDS instance. Restore the snapshot to a new instance withencryption enabled. D. Download AWS-provided root certificates. Provide the certificates in all connections tothe RDS instance.
Answer: D
Explanation: To satisfy the security requirements, the solutions architect should download
AWS-provided root certificates and provide the certificates in all connections to the RDS
instance. This will enable SSL/TLS encryption for data in transit between the application
and the RDS instance. SSL/TLS encryption provides a layer of security by encrypting data
that moves between the client and the server. Amazon RDS creates an SSL certificate and installs the certificate on the DB instance when the instance is provisioned. The application
can use the AWS-provided root certificates to verify the identity of the DB instance and
establish a secure connection1.
The other options are not correct because they do not enable encryption for data in transit
or are not relevant for the use case. Enabling IAM database authentication on the database
is not correct because this option only provides a method of authentication, not encryption.
IAM database authentication allows users to use AWS Identity and Access Management
(IAM) users and roles to access a database, instead of using a database user name and
password2. Providing self-signed certificates is not correct because this option is not
secure or reliable. Self-signed certificates are certificates that are signed by the same entity
that issued them, instead of by a trusted certificate authority (CA). Self-signed certificates
can be easily forged or compromised, and are not recognized by most browsers and
applications3. Taking a snapshot of the RDS instance and restoring it to a new instance
with encryption enabled is not correct because this option only enables encryption at rest,
not encryption in transit. Encryption at rest protects data that is stored on disk, but does not
protect data that is moving between the client and the server4.
References:
Using SSL/TLS to encrypt a connection to a DB instance - Amazon Relational
Database Service
IAM database authentication for MySQL and PostgreSQL - Amazon Relational
Database Service
What are self-signed certificates?
Encrypting Amazon RDS resources - Amazon Relational Database Service
Question # 22
A company stores text files in Amazon S3. The text files include customer chat messages,date and time information, and customer personally identifiable information (Pll).The company needs a solution to provide samples of the conversations to an externalservice provider for quality control. The external service provider needs to randomly picksample conversations up to the most recent conversation. The company must not sharethe customer Pll with the external service provider. The solution must scale when thenumber of customer conversations increases.Which solution will meet these requirements with the LEAST operational overhead?
A. Create an Object Lambda Access Point. Create an AWS Lambda function that redactsthe Pll when the function reads the file. Instruct the external service provider to access theObject Lambda Access Point. B. Create a batch process on an Amazon EC2 instance that regularly reads all new files,redacts the Pll from the files, and writes the redacted files to a different S3 bucket. Instructthe external service provider to access the bucket that does not contain the Pll. C. Create a web application on an Amazon EC2 instance that presents a list of the files,redacts the Pll from the files, and allows the external service provider to download newversions of the files that have the Pll redacted. D. Create an Amazon DynamoDB table. Create an AWS Lambda function that reads onlythe data in the files that does not contain Pll. Configure the Lambda function to store thenon-PII data in the DynamoDB table when a new file is written to Amazon S3. Grant theexternal service provider access to the DynamoDB table.
Answer: A
Explanation: The correct solution is to create an Object Lambda Access Point and an
AWS Lambda function that redacts the PII when the function reads the file. This way, the
company can use the S3 Object Lambda feature to modify the S3 object content on the fly,
without creating a copy or changing the original object. The external service provider can
access the Object Lambda Access Point and get the redacted version of the file. This
solution has the least operational overhead because it does not require any additional
storage, processing, or synchronization. The solution also scales automatically with the
number of customer conversations and the demand from the external service provider. The
other options are incorrect because: Option B is using a batch process on an EC2 instance to read, redact, and write
the files to a different S3 bucket. This solution has more operational overhead
because it requires managing the EC2 instance, the batch process, and the
additional S3 bucket. It also introduces latency and inconsistency between the
original and the redacted files.
Option C is using a web application on an EC2 instance to present, redact, and
download the files. This solution has more operational overhead because it
requires managing the EC2 instance, the web application, and the download
process. It also exposes the original files to the web application, which increases
the risk of leaking the PII.
Option D is using a DynamoDB table and a Lambda function to store the non-PII
data from the files. This solution has more operational overhead because it
requires managing the DynamoDB table, the Lambda function, and the data
transformation. It also changes the format and the structure of the original files,
which may affect the quality control process.
References:
S3 Object Lambda
Object Lambda Access Point
Lambda function
Question # 23
A company wants to deploy its containerized application workloads to a VPC across threeAvailability Zones. The company needs a solution that is highly available across AvailabilityZones. The solution must require minimal changes to the application.Which solution will meet these requirements with the LEAST operational overhead?
A. Use Amazon Elastic Container Service (Amazon ECS). Configure Amazon ECS ServiceAuto Scaling to use target tracking scaling. Set the minimum capacity to 3. Set the taskplacement strategy type to spread with an Availability Zone attribute. B. Use Amazon Elastic Kubernetes Service (Amazon EKS) self-managed nodes. ConfigureApplication Auto Scaling to use target tracking scaling. Set the minimum capacity to 3. C. Use Amazon EC2 Reserved Instances. Launch three EC2 instances in a spreadplacement group. Configure an Auto Scaling group to use target tracking scaling. Set theminimum capacity to 3. D. Use an AWS Lambda function. Configure the Lambda function to connect to a VPC.Configure Application Auto Scaling to use Lambda as a scalable target. Set the minimumcapacity to 3.
Answer: A
Explanation: The company wants to deploy its containerized application workloads to a
VPC across three Availability Zones, with high availability and minimal changes to the
application. The solution that will meet these requirements with the least operational
overhead is:
Use Amazon Elastic Container Service (Amazon ECS). Amazon ECS is a fully
managed container orchestration service that allows you to run and scale
containerized applications on AWS. Amazon ECS eliminates the need for you to
install, operate, and scale your own cluster management infrastructure. Amazon
ECS also integrates with other AWS services, such as VPC, ELB,
CloudFormation, CloudWatch, IAM, and more.
Configure Amazon ECS Service Auto Scaling to use target tracking scaling.
Amazon ECS Service Auto Scaling allows you to automatically adjust the number
of tasks in your service based on the demand or custom metrics. Target tracking
scaling is a policy type that adjusts the number of tasks in your service to keep a
specified metric at a target value. For example, you can use target tracking scaling
to maintain a target CPU utilization or request count per task for your service.
Set the minimum capacity to 3. This ensures that your service always has at least
three tasks running across three Availability Zones, providing high availability and
fault tolerance for your application.
Set the task placement strategy type to spread with an Availability Zone attribute.
This ensures that your tasks are evenly distributed across the Availability Zones in
your cluster, maximizing the availability of your service.
This solution will provide high availability across Availability Zones, require minimal
changes to the application, and reduce the operational overhead of managing your own
cluster infrastructure.
References: Amazon Elastic Container Service
Amazon ECS Service Auto Scaling
Target Tracking Scaling Policies for Amazon ECS Services
Amazon ECS Task Placement Strategies
Question # 24
A company needs to use its on-premises LDAP directory service to authenticate its usersto the AWS Management Console. The directory service is not compatible with SecurityAssertion Markup Language (SAML).Which solution meets these requirements?
A. Enable AWS 1AM Identity Center (AWS Single Sign-On) between AWS and the onpremisesLDAP. B. Create an 1AM policy that uses AWS credentials, and integrate the policy into LDAP. C. Set up a process that rotates the I AM credentials whenever LDAP credentials areupdated. D. Develop an on-premises custom identity broker application or process that uses AWSSecurity Token Service (AWS STS) to get short-lived credentials.
Answer: D
Explanation: The solution that meets the requirements is to develop an on-premises
custom identity broker application or process that uses AWS Security Token Service (AWS
STS) to get short-lived credentials. This solution allows the company to use its existing LDAP directory service to authenticate its users to the AWS Management Console, without
requiring SAML compatibility. The custom identity broker application or process can act as
a proxy between the LDAP directory service and AWS STS, and can request temporary
security credentials for the users based on their LDAP attributes and roles. The users can
then use these credentials to access the AWS Management Console via a sign-in URL
generated by the identity broker. This solution also enhances security by using short-lived
credentials that expire after a specified duration.
The other solutions do not meet the requirements because they either require SAML
compatibility or do not provide access to the AWS Management Console. Enabling AWS
IAM Identity Center (AWS Single Sign-On) between AWS and the on-premises LDAP
would require the LDAP directory service to support SAML 2.0, which is not the case for
this scenario. Creating an IAM policy that uses AWS credentials and integrating the policy
into LDAP would not provide access to the AWS Management Console, but only to the
AWS APIs. Setting up a process that rotates the IAM credentials whenever LDAP
credentials are updated would also not provide access to the AWS Management Console,
but only to the AWS CLI. Therefore, these solutions are not suitable for the given
requirements.
Question # 25
A company wants to migrate its on-premises Microsoft SQL Server Enterprise editiondatabase to AWS. The company's online application uses the database to processtransactions. The data analysis team uses the same production database to run reports foranalytical processing. The company wants to reduce operational overhead by moving tomanaged services wherever possible.Which solution will meet these requirements with the LEAST operational overhead?
A. Migrate to Amazon RDS for Microsoft SQL Server. Use read replicas for reportingpurposes. B. Migrate to Microsoft SQL Server on Amazon EC2. Use Always On read replicas forreporting purposes. C. Migrate to Amazon DynamoDB. Use DynamoDB on-demand replicas for reportingpurposes. D. Migrate to Amazon Aurora MySQL. Use Aurora read replicas for reporting purposes.
Answer: A
Explanation: Amazon RDS for Microsoft SQL Server is a fully managed service that offers
SQL Server 2014, 2016, 2017, and 2019 editions while offloading database administration
tasks such as backups, patching, and scaling. Amazon RDS supports read replicas, which
are read-only copies of the primary database that can be used for reporting purposes
without affecting the performance of the online application. This solution will meet the
requirements with the least operational overhead, as it does not require any code changes
or manual intervention.
References:
1 provides an overview of Amazon RDS for Microsoft SQL Server and its benefits.
2 explains how to create and use read replicas with Amazon RDS.
Feedback That Matters: Reviews of Our Amazon SAA-C03 Dumps
Luka JohnsonAug 14, 2026
Mycertshub gave me the exact prep I needed to confidently pass the SAA-C03 exam on my first try.
Jorge WhiteAug 13, 2026
The practice questions for SAA-C03 on Mycertshub felt just like the real test—super helpful!
Noah BaileyAug 13, 2026
I owe my AWS certification success to the clear, concise material from Mycertshub.
Justin RossAug 12, 2026
Mycertshub's SAA-C03 resources are a must-have for anyone serious about passing the exam.
Aaron AndersonAug 12, 2026
Excellent exam dumps, Mycertshub helped me focus on the right topics for SAA-C03.
Travis JamesAug 11, 2026
After using Mycertshub, I walked into the SAA-C03 exam feeling totally prepared.
Titus KimAug 11, 2026
The format and explanations at Mycertshub made studying for the AWS SAA-C03 smooth and stress-free.
Ishat SeshadriAug 10, 2026
Trusted study material, Mycertshub helped me master tough SAA-C03 concepts with ease.
Taahid DeoAug 10, 2026
Great platform! The SAA-C03 questions were updated, relevant, and boosted my confidence.
Pranab MohanAug 09, 2026
Passed SAA-C03 today, and it's all thanks to the solid prep I got from Mycertshub!