Amazon Web ServicesProfessional levelSAP-C02

SAP-C02 exam dumps: 677 free AWS Solutions Architect Professional practice questions

Free SAP-C02 practice questions for the AWS Certified Solutions Architect - Professional exam, with the correct answer and a full explanation for every option. Read the first 10 below, browse all 677 by number, or take a timed practice exam.

Question bank last updated December 2024

Free SAP-C02 practice questions

Questions 1 to 10 of 677

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

SAP-C02 Question 1

Single answer

Your organization has a multi-account AWS environment with accounts for different business units and environments (e.g., production, staging, development). The organization wants to enforce consistent security policies across all accounts, such as requiring encryption for all S3 buckets and restricting the creation of publicly accessible RDS instances. Additionally, each business unit needs the flexibility to manage their own resources within their accounts. Which solution would best address these requirements?

  1. A

    Use AWS Organizations with Service Control Policies (SCPs) to enforce security policies across all accounts, while allowing each account to manage its own resources.

  2. B

    Use AWS Config rules in each account to enforce security policies, and centralize compliance reporting using AWS Config Aggregators.

  3. C

    Set up AWS IAM roles in each account with strict policies, and manually ensure that all accounts comply with the security requirements.

  4. D

    Create a single AWS account for the entire organization and use tags to segregate resources by business unit, applying security policies at the account level.

Show answer and explanation

Correct answer: A

Explanation

AWS Organizations with Service Control Policies (SCPs) is the most effective solution for enforcing consistent security policies across a multi-account AWS environment. SCPs provide centralized control over permissions, ensuring that accounts adhere to organizational security requirements while allowing them to manage their own resources within those boundaries. This approach is scalable, reduces management overhead, and aligns with AWS best practices for multi-account setups.

  • A. Correct.

    This is the correct solution. AWS Organizations with SCPs enable you to enforce security policies across all accounts by applying restrictions at the organization level. SCPs ensure compliance while still allowing individual accounts the flexibility to manage their own resources within the defined boundaries.

  • B. Incorrect.

    While AWS Config can be used to enforce and monitor compliance, managing rules independently across multiple accounts can be operationally complex. AWS Config Aggregators help centralize reporting, but they do not enforce policies as effectively as SCPs at the organizational level.

  • C. Incorrect.

    This approach requires significant manual effort and lacks the centralized governance provided by AWS Organizations and SCPs. It is prone to human error and does not scale well for large organizations.

  • D. Incorrect.

    Using a single AWS account for the entire organization and relying on tags to segregate resources is not a recommended practice for multi-account environments. It sacrifices security isolation and governance, and it doesn't effectively enforce organizational-level policies.

SAP-C02 Question 2

Select 3

Your organization is a multinational company with multiple business units, each requiring independent AWS accounts for cost isolation and resource management. However, the central IT team needs to enforce security policies, manage billing, and provide shared services such as DNS and logging across all accounts. Which combination of AWS services and features can best address these requirements?

  1. A

    AWS Organizations with Service Control Policies (SCPs) to enforce security policies

  2. B

    AWS Resource Access Manager (RAM) to share resources across accounts

  3. C

    AWS Identity and Access Management (IAM) roles for cross-account access

  4. D

    AWS Control Tower to establish a landing zone and govern the accounts

  5. E

    AWS Cost Explorer to monitor and track billing for individual accounts

Show answer and explanation

Correct answers: A, B, D

Explanation

The combination of AWS Organizations with SCPs, AWS Resource Access Manager, and AWS Control Tower addresses the organization's needs by enabling centralized governance, resource sharing, and account setup. These services work together to manage security, enforce policies, and provide shared services across multiple AWS accounts, ensuring compliance and operational efficiency. IAM roles or Cost Explorer, while valuable in specific contexts, do not address the broader challenges of organizational complexity.

  • A. Correct.

    AWS Organizations with SCPs is a core service for managing multiple accounts. SCPs help enforce security policies across accounts, ensuring compliance with organizational requirements.

  • B. Correct.

    AWS Resource Access Manager (RAM) enables sharing of resources like VPC subnets, Transit Gateways, and Route 53 Resolver rules across AWS accounts, which is critical for shared services.

  • C. Incorrect.

    While IAM roles allow cross-account access, they do not centrally enforce security policies or manage shared services. They are more suitable for specific access use cases rather than organizational governance.

  • D. Correct.

    AWS Control Tower provides a comprehensive solution for setting up a well-architected multi-account environment (landing zone) with governance and security in place, aligning with the organization's needs.

  • E. Incorrect.

    AWS Cost Explorer is useful for cost monitoring but does not help in enforcing security policies, managing shared services, or setting up accounts. It is not a solution for organizational complexity.

SAP-C02 Question 3

Select 4

An enterprise company is undergoing a multi-account strategy transformation to align with AWS best practices. They aim to centralize governance, maintain security and compliance, and enable individual business units to operate independently. The organization also wants to implement cost controls and share common resources, such as networking infrastructure and logging solutions. Which combination of AWS services and features should be used to achieve these objectives?

  1. A

    AWS Organizations with Service Control Policies (SCPs)

  2. B

    AWS Control Tower for account provisioning and governance

  3. C

    AWS Lambda functions for automating cost allocation tags

  4. D

    AWS Resource Access Manager (RAM) for sharing resources across accounts

  5. E

    Amazon CloudFront for distributing content securely across accounts

  6. F

    AWS Config for compliance monitoring across accounts

Show answer and explanation

Correct answers: A, B, D, F

Explanation

To design a robust multi-account architecture for a large enterprise, AWS Organizations with SCPs is essential for centralized governance and compliance enforcement. AWS Control Tower provides an easy way to set up and manage a secure multi-account environment, ensuring alignment with best practices. Resource sharing is facilitated by AWS RAM, allowing common resources to be used efficiently across accounts. Finally, AWS Config plays a crucial role in monitoring compliance and security posture across all accounts. These services collectively address governance, security, resource sharing, and compliance requirements in a multi-account strategy.

  • A. Correct.

    Correct. AWS Organizations with SCPs is a critical part of centralizing governance and enforcing compliance across multiple AWS accounts.

  • B. Correct.

    Correct. AWS Control Tower simplifies the setup and management of a secure multi-account environment, aligning with the organization’s governance and compliance needs.

  • C. Incorrect.

    Incorrect. While AWS Lambda can be used for automation, it is not a direct solution for centralizing governance, security, or resource sharing in a multi-account setup.

  • D. Correct.

    Correct. AWS Resource Access Manager (RAM) enables sharing common resources like networking and logging solutions across accounts.

  • E. Incorrect.

    Incorrect. Amazon CloudFront is a CDN service and is not directly related to centralizing governance, security, or resource sharing in a multi-account strategy.

  • F. Correct.

    Correct. AWS Config provides compliance monitoring and auditing capabilities, which are essential for maintaining security and compliance across multiple accounts.

SAP-C02 Question 4

Single answer

A multinational organization has multiple AWS accounts for its business units, each with its own application workloads. The organization wants to centralize governance, enforce compliance rules, and manage permissions across all accounts. Additionally, they need to ensure that each business unit retains some level of autonomy for managing their respective resources. Which AWS solution would best address these requirements?

  1. A

    Use AWS Control Tower to set up a multi-account environment with guardrails and delegate permissions to accounts via service control policies (SCPs).

  2. B

    Use AWS IAM Identity Center (formerly AWS SSO) to centrally manage user permissions and enable resource management across all accounts.

  3. C

    Use AWS Organizations to create a multi-account structure, apply service control policies (SCPs), and link accounts for centralized billing.

  4. D

    Use AWS Config to monitor resource compliance and enforce rules across all accounts while allowing individual accounts to self-manage their resources.

Show answer and explanation

Correct answer: A

Explanation

AWS Control Tower is the best solution for this scenario as it is specifically designed to set up and manage a secure, multi-account AWS environment. It provides features like guardrails (SCPs and Config rules) for governance and compliance while allowing accounts to retain autonomy for resource management. While other options provide partial functionality, they do not offer the complete centralized governance and compliance framework required.

  • A. Correct.

    Correct: AWS Control Tower provides a comprehensive solution for setting up and governing a multi-account environment. It enables centralized governance using guardrails (SCPs and Config rules) while allowing individual accounts to manage their own resources.

  • B. Incorrect.

    Incorrect: While AWS IAM Identity Center can centrally manage user permissions across accounts, it does not provide the governance or compliance enforcement features required for this scenario.

  • C. Incorrect.

    Incorrect: AWS Organizations helps in creating a multi-account structure and implementing SCPs, but it does not provide a full governance and compliance framework like AWS Control Tower does.

  • D. Incorrect.

    Incorrect: AWS Config is useful for monitoring compliance and enforcing rules, but it does not handle centralized governance, account setup, or permissions management as described in the scenario.

SAP-C02 Question 5

Select 3

An organization with multiple business units has adopted AWS Organizations to manage their cloud resources. They need to ensure that each business unit has strict control over its own AWS accounts while adhering to the organization's security and compliance requirements. Additionally, they want to centralize billing and enforce specific policies across all accounts. Which combination of approaches should they implement to meet these requirements?

  1. A

    Use Service Control Policies (SCPs) to enforce security and compliance requirements across all accounts in the organization.

  2. B

    Enable consolidated billing in AWS Organizations to centralize billing and manage costs across all accounts.

  3. C

    Grant full administrative access to each business unit's AWS accounts without applying any restrictions to allow autonomy.

  4. D

    Use Organizational Units (OUs) to group accounts by business units and apply SCPs at the OU level.

  5. E

    Enable AWS Single Sign-On (AWS SSO) to manage user access centrally across all accounts in the organization.

Show answer and explanation

Correct answers: A, B, D

Explanation

To address the organization's requirements, a combination of Service Control Policies (SCPs) and Organizational Units (OUs) within AWS Organizations ensures that security and compliance policies are enforced at the appropriate level for each business unit. Enabling consolidated billing centralizes cost management across all accounts. Granting unrestricted administrative access contradicts governance requirements, and while AWS SSO is helpful for user access management, it does not directly address billing or policy enforcement.

  • A. Correct.

    Service Control Policies (SCPs) are a core feature of AWS Organizations and are used to enforce compliance and security requirements at the organizational, OU, or account level. This ensures that all accounts adhere to the organization's policies.

  • B. Correct.

    Consolidated billing is a feature of AWS Organizations that allows the organization to centralize billing across all accounts, providing a single billing entity and cost management benefits.

  • C. Incorrect.

    Granting full administrative access without restrictions contradicts the organization's need to enforce security and compliance requirements. This approach does not align with best practices for governance.

  • D. Correct.

    Using Organizational Units (OUs) to group accounts by business units allows the organization to apply SCPs at the OU level, ensuring that policies are enforced for specific groups of accounts while maintaining flexibility.

  • E. Incorrect.

    While AWS SSO can help manage user access centrally, it does not address the need for enforcing security and compliance policies or centralizing billing, which are the key requirements in this scenario.

SAP-C02 Question 6

Select 2

Your company operates a multi-account architecture in AWS with a centralized networking account used for routing and connectivity. You are tasked with designing a solution to allow secure and scalable communication between application workloads running in multiple VPCs across different AWS accounts. The solution must minimize the complexity of managing routes and support potential future growth in the number of VPCs. Which of the following strategies should you implement?

  1. A

    Use AWS Transit Gateway in the networking account to establish inter-VPC connectivity and share it across accounts using Resource Access Manager (RAM).

  2. B

    Set up VPC Peering between all VPCs across accounts to achieve direct connectivity.

  3. C

    Deploy a centralized AWS PrivateLink endpoint in the networking account, and connect all VPCs to this endpoint for communication.

  4. D

    Use AWS Direct Connect Gateway to connect all VPCs across accounts.

  5. E

    Implement a hub-and-spoke architecture with an AWS Transit Gateway in the networking account for centralized connectivity.

Show answer and explanation

Correct answers: A, E

Explanation

AWS Transit Gateway is the recommended solution for establishing scalable and centralized connectivity between multiple VPCs across accounts. It allows you to manage connectivity in a hub-and-spoke architecture, which simplifies route management and supports the integration of additional VPCs as the network grows. Resource Access Manager (RAM) enables sharing the Transit Gateway with other accounts, further reducing complexity. VPC Peering and AWS PrivateLink are less scalable options for this use case, while AWS Direct Connect Gateway is not relevant for inter-VPC connectivity.

  • A. Correct.

    This is correct. AWS Transit Gateway provides scalable and centralized connectivity for multiple VPCs across accounts. Using AWS Resource Access Manager (RAM), you can share the Transit Gateway with other accounts, reducing complexity in route management.

  • B. Incorrect.

    This is incorrect. VPC Peering requires explicit creation and management of peering connections between each pair of VPCs, which becomes impractical and unscalable as the number of VPCs grows.

  • C. Incorrect.

    This is incorrect. AWS PrivateLink is designed for exposing specific services or applications across VPCs, not for general-purpose network connectivity between VPCs.

  • D. Incorrect.

    This is incorrect. AWS Direct Connect Gateway is used to connect an on-premises network to multiple VPCs, not for inter-VPC connectivity within AWS.

  • E. Correct.

    This is correct. A hub-and-spoke architecture with AWS Transit Gateway simplifies network management by centralizing connectivity, improves scalability, and supports future growth in the number of VPCs.

SAP-C02 Question 7

Select 2

Your company hosts a multi-tier web application in AWS. The application is deployed across multiple Availability Zones in a VPC and uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in an Auto Scaling group. The application must connect securely to an on-premises database over a highly available network connection. Latency and bandwidth are critical considerations. Which combination of steps would you take to meet these requirements?

  1. A

    Establish a Direct Connect connection between your on-premises environment and AWS.

  2. B

    Use a VPN connection over the public internet to connect your VPC to the on-premises environment.

  3. C

    Configure a Direct Connect gateway to allow access to multiple VPCs in your account.

  4. D

    Enable AWS Transit Gateway to manage connectivity between on-premises and AWS resources.

  5. E

    Deploy a NAT gateway in the VPC for outbound connectivity to the on-premises environment.

Show answer and explanation

Correct answers: A, C

Explanation

To meet the requirements of high availability, low latency, and high bandwidth for connecting the VPC to an on-premises database, using AWS Direct Connect is the most appropriate solution. Additionally, a Direct Connect gateway allows for scalability across multiple VPCs, enabling a more efficient and robust design. VPN connections over the public internet and NAT gateways do not satisfy the latency and bandwidth criteria, while AWS Transit Gateway is not necessary for the specific use case of hybrid connectivity in this scenario.

  • A. Correct.

    Direct Connect provides a dedicated, private, high-bandwidth, and low-latency connection between your on-premises environment and AWS, which is suitable for critical applications requiring consistent performance.

  • B. Incorrect.

    A VPN connection over the public internet does not provide the low latency and high bandwidth required by the scenario. It may be suitable for less critical workloads or as a backup to Direct Connect.

  • C. Correct.

    A Direct Connect gateway allows you to share a single Direct Connect connection across multiple VPCs, ensuring a scalable and efficient architecture for hybrid connectivity.

  • D. Incorrect.

    While AWS Transit Gateway is a useful service for managing complex network architectures, it is not required in this scenario because the focus is on connecting the on-premises environment to AWS, which can be achieved with Direct Connect and a Direct Connect gateway.

  • E. Incorrect.

    A NAT gateway is used for enabling outbound internet access for instances in a private subnet and is not relevant to establishing secure, low-latency connectivity between AWS and on-premises resources.

SAP-C02 Question 8

Single answer

A company has on-premises data centers across multiple locations and wants to establish secure, low-latency connectivity to its AWS environment. They have strict compliance requirements that mandate all traffic between their data centers and AWS be encrypted and private. Additionally, the company requires consistent performance for high-bandwidth workloads, and they plan to scale their cloud environment significantly over time. Which is the most appropriate network connectivity strategy?

  1. A

    Use AWS Direct Connect with a private virtual interface (VIF) and enable MACsec encryption for compliance.

  2. B

    Establish an AWS Site-to-Site VPN connection between the on-premises data centers and the AWS environment.

  3. C

    Leverage the AWS Global Accelerator for secure, low-latency connections to AWS.

  4. D

    Use public internet connectivity with SSL/TLS encryption for all data transfers to maintain compliance.

Show answer and explanation

Correct answer: A

Explanation

The best solution for this scenario is AWS Direct Connect with a private virtual interface (VIF) and MACsec encryption. AWS Direct Connect provides a dedicated, private connection between the on-premises data centers and AWS, ensuring low latency, high bandwidth, and consistent performance. Enabling MACsec encryption ensures that the connection complies with the strict requirement for encrypted and private traffic. This makes it the most suitable option for the company's needs.

  • A. Correct.

    Using AWS Direct Connect with a private virtual interface (VIF) provides a dedicated, high-bandwidth connection with consistent performance. Additionally, enabling MACsec encryption ensures compliance with the requirement for encrypted and private traffic.

  • B. Incorrect.

    While an AWS Site-to-Site VPN provides secure and encrypted traffic, it relies on the internet, which can lead to higher latency and inconsistent performance. This option is not ideal for high-bandwidth workloads or scalability.

  • C. Incorrect.

    AWS Global Accelerator optimizes traffic routing for applications and provides low-latency connections, but it does not provide dedicated private connectivity or encryption for compliance requirements.

  • D. Incorrect.

    Using public internet connectivity with SSL/TLS encryption can encrypt data in transit but does not meet the requirement for private connectivity. Additionally, the public internet does not provide consistent performance for high-bandwidth workloads.

SAP-C02 Question 9

Select 3

A company wants to deploy a hybrid cloud solution to connect their on-premises data center with AWS. They require high bandwidth, low latency, and secure communication between their data center and AWS services. Which combination of networking strategies should the company implement to achieve these requirements?

  1. A

    Set up an AWS Direct Connect connection between the on-premises data center and AWS.

  2. B

    Use a Site-to-Site VPN connection over the public internet.

  3. C

    Enable Direct Connect Gateway to access multiple AWS Regions using a single connection.

  4. D

    Configure VPC Peering between the on-premises data center and AWS VPC.

  5. E

    Implement AWS Transit Gateway to manage connectivity between on-premises, multiple VPCs, and Direct Connect.

Show answer and explanation

Correct answers: A, C, E

Explanation

To meet the requirements of high bandwidth, low latency, and secure communication, the company should use AWS Direct Connect for a dedicated private connection. By enabling Direct Connect Gateway, they can extend this connection to multiple AWS Regions. Additionally, AWS Transit Gateway offers a scalable solution to manage connectivity between on-premises, multiple VPCs, and Direct Connect, making it an ideal strategy for hybrid cloud architectures.

  • A. Correct.

    Correct: AWS Direct Connect provides a dedicated, high-bandwidth, and low-latency private connection between the on-premises data center and AWS, meeting the requirements of the scenario.

  • B. Incorrect.

    Incorrect: A Site-to-Site VPN connection over the public internet is secure but does not meet the high bandwidth and low latency requirements specified in the scenario.

  • C. Correct.

    Correct: Direct Connect Gateway allows the company to connect to multiple AWS Regions using a single Direct Connect connection, which is efficient for hybrid cloud architectures.

  • D. Incorrect.

    Incorrect: VPC Peering is used for connecting VPCs and is not applicable for connecting an on-premises data center to AWS.

  • E. Correct.

    Correct: AWS Transit Gateway simplifies and centralizes network management for hybrid environments, allowing the company to manage connectivity between on-premises, multiple VPCs, and Direct Connect efficiently.

SAP-C02 Question 10

Select 3

Your company operates a hybrid cloud environment with applications hosted on both AWS and an on-premises data center. The on-premises applications need to communicate with AWS services over a secure and consistent network connection. Additionally, for disaster recovery purposes, AWS services should failover to a secondary AWS Region if the primary Region becomes unavailable. Which combination of network connectivity strategies would best meet these requirements?

  1. A

    Establish a Direct Connect connection between the on-premises data center and the primary AWS Region, and configure a backup VPN connection.

  2. B

    Use AWS Global Accelerator to route traffic between the on-premises data center and AWS Regions.

  3. C

    Enable VPC peering between the primary and secondary AWS Regions to facilitate disaster recovery.

  4. D

    Set up a secondary Direct Connect connection to the secondary AWS Region for failover.

  5. E

    Implement AWS Transit Gateway to manage connectivity between the on-premises data center and multiple AWS Regions.

Show answer and explanation

Correct answers: A, D, E

Explanation

To meet the requirements of secure and consistent connectivity between the on-premises data center and AWS, Direct Connect with a backup VPN provides high-bandwidth and redundant connections. For disaster recovery, a secondary Direct Connect ensures failover to a secondary Region. AWS Transit Gateway facilitates centralized and scalable management of hybrid and multi-Region connectivity, making it a key component of the overall architecture.

  • A. Correct.

    Establishing a Direct Connect connection ensures a secure, high-bandwidth connection between the on-premises data center and AWS. A backup VPN provides redundancy in case the Direct Connect becomes unavailable, fulfilling the requirement for secure and consistent connectivity.

  • B. Incorrect.

    AWS Global Accelerator is used to improve application availability and performance but does not provide direct connectivity between an on-premises data center and AWS Regions.

  • C. Incorrect.

    VPC peering is a point-to-point connection between two VPCs. It does not provide the scalability or centralized management needed for disaster recovery across multiple Regions.

  • D. Correct.

    Setting up a secondary Direct Connect to the secondary AWS Region ensures that there is a reliable failover path for disaster recovery, meeting the requirement for network redundancy.

  • E. Correct.

    AWS Transit Gateway simplifies and scales the management of hybrid connectivity between on-premises data centers and multiple AWS Regions. It is particularly useful for handling complex network architectures.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

What the SAP-C02 exam covers

Official AWS Certified Solutions Architect - Professional exam domains and weightings.

  • Design Solutions for Organizational Complexity

    26% of exam

  • Design for New Solutions

    29% of exam

  • Continuous Improvement for Existing Solutions

    25% of exam

  • Accelerate Workload Migration and Modernization

    20% of exam

SAP-C02 practice questions 1 to 100 of 677

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 7 pages of up to 100 questions.

  1. 1.Your organization has a multi-account AWS environment with accounts for different business units and...
  2. 2.Your organization is a multinational company with multiple business units, each requiring independent AWS...
  3. 3.An enterprise company is undergoing a multi-account strategy transformation to align with AWS best practices....
  4. 4.A multinational organization has multiple AWS accounts for its business units, each with its own application...
  5. 5.An organization with multiple business units has adopted AWS Organizations to manage their cloud resources....
  6. 6.Your company operates a multi-account architecture in AWS with a centralized networking account used for...
  7. 7.Your company hosts a multi-tier web application in AWS. The application is deployed across multiple...
  8. 8.A company has on-premises data centers across multiple locations and wants to establish secure, low-latency...
  9. 9.A company wants to deploy a hybrid cloud solution to connect their on-premises data center with AWS. They...
  10. 10.Your company operates a hybrid cloud environment with applications hosted on both AWS and an on-premises data...
  11. 11.Your company is migrating a legacy on-premises application to AWS. The application requires access to...
  12. 12.An organization is running a multi-tier application on AWS. The application has multiple EC2 instances in an...
  13. 13.A financial services company wants to modernize its on-premises data analytics platform by migrating to AWS....
  14. 14.An organization is running a critical web application on Amazon EC2 instances behind an Application Load...
  15. 15.A company is hosting a multi-tier application on AWS using an Auto Scaling group for the application servers...
  16. 16.Your organization is designing a global application that requires low-latency access for users distributed...
  17. 17.Your organization operates a global e-commerce platform and requires a highly available architecture that...
  18. 18.Your organization is planning to deploy a global application with users distributed across multiple...
  19. 19.Your company is planning to launch a globally distributed application with stringent requirements on low...
  20. 20.You are designing a global multi-region application architecture for a financial services company. The...
  21. 21.A company has multiple VPCs in the us-east-1 region that need to communicate with resources in an on-premises...
  22. 22.A company has deployed an application across multiple AWS Regions to serve a global customer base. The...
  23. 23.An organization is hosting sensitive financial applications on Amazon ECS using the Fargate launch type. The...
  24. 24.A company has a hybrid architecture with several on-premises data centers connected to AWS through AWS Direct...
  25. 25.A company has deployed a multi-tier application in AWS. The application consists of a front-end service...
  26. 26.An organization operates a hybrid cloud environment with applications running in both AWS and their...
  27. 27.A company has a hybrid cloud architecture with workloads running both on-premises and in AWS. The company...
  28. 28.An organization has a hybrid cloud architecture with workloads running both on AWS and in an on-premises data...
  29. 29.Your organization has a hybrid environment with workloads running both in AWS and on-premises. The...
  30. 30.A company has a hybrid architecture with workloads running both on AWS and in its on-premises data centers....
  31. 31.A company has deployed a multi-tier web application across multiple AWS accounts and VPCs. The application...
  32. 32.You are designing a multi-tier architecture for an application hosted on AWS. The application consists of a...
  33. 33.Your company has a multi-account AWS setup with multiple VPCs across different AWS Regions. You have been...
  34. 34.Your company has deployed multiple applications across three AWS accounts, each operating within its own VPC....
  35. 35.Your company has deployed a multi-tier application across multiple Amazon VPCs in the same AWS Region. The...
  36. 36.You are a Solutions Architect for a media company, and your security team wants to monitor network traffic to...
  37. 37.A company is running a multi-tier web application on AWS, and they need to monitor traffic to and from their...
  38. 38.An organization is running a mission-critical application on AWS, and they want to monitor network traffic...
  39. 39.A company is running multiple applications in an Amazon VPC and needs to monitor network traffic for security...
  40. 40.An organization runs a critical application on AWS that handles sensitive financial data. The organization is...
  41. 41.A financial institution is migrating its core banking application to AWS. The application processes highly...
  42. 42.Your company operates a multi-account AWS environment and has recently adopted AWS Organizations for...
  43. 43.A financial services company is designing a highly secure web application that processes sensitive customer...
  44. 44.Your company is building a multi-tier web application that processes sensitive customer data. The application...
  45. 45.A financial services company is building a new web application that handles sensitive customer data,...
  46. 46.A large e-commerce company is running its production workloads on Amazon EC2 instances with an Auto Scaling...
  47. 47.Your company runs a multi-tier web application in AWS. The application uses an Auto Scaling group for the...
  48. 48.A company is running a multi-tier web application on AWS, consisting of an Application Load Balancer (ALB) in...
  49. 49.A company is running a multi-tier web application using Amazon EC2 instances in an Auto Scaling group behind...
  50. 50.A company is migrating its on-premises data analytics platform to AWS. The platform processes large volumes...
  51. 51.Your organization has implemented AWS IAM Identity Center (AWS Single Sign-On) to manage access to multiple...
  52. 52.An organization is using AWS IAM Identity Center (AWS Single Sign-On) to manage access to AWS accounts and...
  53. 53.A company is migrating its workforce to a centralized identity management solution using AWS IAM Identity...
  54. 54.Your organization uses AWS IAM Identity Center (AWS Single Sign-On) to manage user access across multiple AWS...
  55. 55.Your organization has implemented AWS IAM Identity Center (AWS Single Sign-On) to centralize access...
  56. 56.An organization is hosting a web application in a VPC. The web application consists of an Application Load...
  57. 57.Your company is hosting a web application in a VPC that consists of public and private subnets. The web...
  58. 58.Your organization is hosting a multi-tier web application in a VPC. The architecture includes a public-facing...
  59. 59.Your company is hosting a multi-tier web application in a VPC. The application consists of a public-facing...
  60. 60.A company is hosting a multi-tier web application in a VPC. The application has a public-facing load balancer...
  61. 61.A financial services company needs to implement a secure solution to encrypt sensitive customer data stored...
  62. 62.Your company is building a secure financial application that must store sensitive customer data, such as...
  63. 63.Your organization requires a secure method to manage SSL/TLS certificates for its web applications and ensure...
  64. 64.Your organization is running an application that uses HTTPS for secure communication. The application needs...
  65. 65.A financial services company uses an application that requires secure communication between its web servers...
  66. 66.Your company operates a multi-account AWS environment using AWS Organizations. Recently, a third-party...
  67. 67.A financial institution has strict compliance requirements and needs to ensure that sensitive data stored in...
  68. 68.An organization is using multiple AWS accounts to isolate workloads and has enabled AWS Organizations. The...
  69. 69.An organization has recently migrated its workloads to AWS and wants to ensure compliance with industry...
  70. 70.Your organization has recently adopted AWS Security Hub to enhance its security posture. You are tasked with...
  71. 71.You are designing a new multi-tier application architecture on AWS that must provide high availability and...
  72. 72.You are designing a multi-region application for an e-commerce platform that must provide high availability...
  73. 73.A company is running an e-commerce application that experiences unpredictable traffic spikes. The application...
  74. 74.A financial services company is designing a mission-critical trading application that processes real-time...
  75. 75.A company is designing a mission-critical application hosted on AWS. The application must achieve high...
  76. 76.A company is using an Amazon RDS MySQL database to store transactional data for their e-commerce application....
  77. 77.A company is designing a highly available application on AWS that requires a relational database for...
  78. 78.A company is migrating its on-premises application to AWS. The application requires a shared file system that...
  79. 79.A company is running a multi-tier e-commerce application on AWS. The application consists of an Application...
  80. 80.A company is modernizing its on-premises data analytics platform by migrating to AWS. The current setup...
  81. 81.A financial services company runs a critical payment processing application on AWS. The company has a strict...
  82. 82.A global e-commerce company runs its critical order-processing application on AWS using an Amazon RDS...
  83. 83.A retail company runs an e-commerce platform on AWS. To meet business continuity requirements, they have a...
  84. 84.A company runs a critical e-commerce platform on AWS. The platform uses an RDS database for transactional...
  85. 85.A company is running a critical multi-tier application on AWS. The application uses an Amazon RDS database...
  86. 86.A company runs a critical e-commerce application in a single AWS Region. To meet compliance requirements, the...
  87. 87.A financial services company runs a critical application in a single AWS Region. They have strict regulatory...
  88. 88.A global e-commerce company wants to implement a disaster recovery strategy for their order processing...
  89. 89.A financial services company needs to implement a disaster recovery strategy for their application hosted on...
  90. 90.A company runs critical workloads on-premises and wants to implement a disaster recovery strategy using AWS....
  91. 91.A company runs a critical application on Amazon RDS using an Aurora PostgreSQL cluster. The company must...
  92. 92.A large enterprise needs a backup and disaster recovery solution for its on-premises databases. The solution...
  93. 93.A company uses Amazon RDS for their production database. They want to ensure minimal downtime and data loss...
  94. 94.A company uses Amazon RDS for a mission-critical production database. They require a robust backup and...
  95. 95.A company runs a critical application on Amazon RDS for PostgreSQL with high availability enabled. The...
  96. 96.An organization is planning to set up a multi-account AWS environment to manage its diverse business units,...
  97. 97.A company is planning to design a multi-account AWS environment to manage its workloads across different...
  98. 98.Your organization has multiple teams that require isolated AWS accounts for their projects. The security team...
  99. 99.Your organization is planning to implement a multi-account AWS environment to improve security, cost...
  100. 100.A company is migrating its on-premises data warehouse to AWS to handle large-scale analytical workloads. They...

SAP-C02 exam dumps FAQ

Are these SAP-C02 dumps real exam questions?

No. These are original practice questions written to the AWS Certified Solutions Architect - Professional exam objectives, not questions copied from a live exam. Memorising leaked questions violates Amazon Web Services's candidate agreement and stops working the moment the question pool rotates. Use this bank to check your understanding of each domain and to find the topics you still need to study.

How many SAP-C02 practice questions are there?

677 questions, each with the correct answer, an explanation of the answer, and a note on why every other option is wrong. The first 10 are on this page and every question has its own page linked below.

Are the SAP-C02 exam dumps free?

Yes. Every question, answer and explanation on this page and the linked question pages is free to read without an account. A free HydraNode account adds timed practice exams, scoring and progress tracking across attempts.

How do I take a timed SAP-C02 practice test?

Sign in and start the AWS Certified Solutions Architect - Professional exam on HydraNode. A session gives you 75 questions drawn from this bank in 180 minutes, then a score report with a per-question review.

What topics does the SAP-C02 exam cover?

The official exam domains are: Design Solutions for Organizational Complexity; Design for New Solutions; Continuous Improvement for Existing Solutions; Accelerate Workload Migration and Modernization.