Day 57 of 70 · Week 8
Day 57 / 70 Week 8 of 14 Phase 5: Practice Exams & Exam Technique

Full-Length Mock Exam 1 — 75 Questions Timed

🕑 ~55 min read · 75 exam questions · full-curriculum coverage
Exam Simulation Pacing & Stamina Baseline Scoring

Recap — From DMS Detail to Exam Retrieval

Day 56 closed the migration phase on the single highest-yield topic in the curriculum: DMS, worth three to four questions on a typical sitting. The hooks that matter are full load versus CDC, replication instance sizing, LOB handling, and the DMS plus SCT pattern for heterogeneous migrations. That day was about understanding the mechanism well enough to reason from it — why full load plus CDC is the configuration most minimal-downtime scenarios are describing, and why a 95% SCT conversion still leaves manual remediation work.

Today tests something different. Knowing a mechanism and retrieving it under a 2.4-minute-per-question clock are separate skills, and the second one is what the exam actually measures. This mock extends that retrieval pressure across the whole curriculum rather than just the migration phase, because the real exam does not tell you which domain a question belongs to before you answer it.

Sitting Protocol — Simulating Real Conditions

The value of this mock is entirely in how faithfully you reproduce the conditions of the real sitting. A practice exam taken with a browser tab open to the AWS documentation, or paused halfway through to answer a Slack message, produces a score that tells you almost nothing. It measures your ability to look things up, which is not a skill the exam rewards. The 180-minute clock is not a formality; it is the constraint that forces the trade-offs the exam is designed to test — when to commit to an answer you are 70% sure of, when to flag and move on, and when a question is genuinely worth three minutes of reasoning.

Set a timer for 180 minutes and do not stop it. Answer all 75 questions in sequence without checking any answer until the clock expires or you have completed the set. The reveal buttons on each question are there for the review pass, not the sitting pass; using them mid-exam converts a diagnostic into a study session and destroys the pacing data you are trying to collect. If you finish early, use the remaining time to revisit flagged questions rather than to start reviewing answers — the real exam gives you that same option, and learning to spend surplus time on flagged items rather than on premature confidence is part of the skill.

The average budget works out to 2.4 minutes per question across 75 questions in 180 minutes, but that average is misleading if you apply it uniformly. Short direct-knowledge questions should take well under a minute, which buys you the four to five minutes that a dense multi-service scenario legitimately needs. The flag-and-review technique exists precisely to exploit that asymmetry: answer the fast questions fast, flag anything that requires reconstructing an architecture in your head, and return to the flagged set with the time you banked. If you find yourself at question 40 with less than 90 minutes remaining, you are behind and should start flagging more aggressively rather than reading more carefully.

Do not look anything up. Not the SCP evaluation order, not the TGW peering MTU, not the difference between Compute and EC2 Instance Savings Plans. Every one of those facts has a day page behind it, and the point of this sitting is to find out which ones you can retrieve cold. A wrong answer you arrived at honestly is worth more to you today than a right answer you looked up, because only the first one tells you where to spend the next four days of review. Record your raw correct count when you finish, and note which questions you flagged — the flag pattern itself is diagnostic, since it shows where your confidence and your accuracy diverge.

Finally, treat the sitting as a stamina exercise in its own right. Three hours of sustained scenario reading is genuinely tiring, and the questions you miss at minute 160 are often missed for attentional reasons rather than knowledge gaps. If you notice your accuracy degrading in the last twenty questions, that is real data about exam-day risk, and it is the reason the later mocks in this phase exist. Sit this one straight through, in one block, the way you would sit the real thing.

The Exam — 75 Questions, Full Curriculum

Answer all 75 in one sitting before revealing any answer. The questions span multi-account governance, hybrid networking, compute and containers, databases and storage, observability and SRE, disaster recovery, migration, and cost optimization — the full arc of Days 1 through 56, not just the recent material.

Q1. A company wants a dedicated account that only aggregates CloudTrail logs from every other account and cannot be modified by workload teams. Where should this account live?

A. Directly under the root, alongside Production
B. In a dedicated Security OU with a restrictive SCP
C. Inside the Workloads/Prod OU for proximity to the data it audits
D. In the management account itself
Correct answer: B. Log-archive and audit accounts belong in a dedicated Security OU protected by SCPs that deny deletion or modification of logging resources, isolated from workload OUs.

Q2. A developer holds an IAM policy granting s3:*, but an SCP on their OU denies s3:DeleteBucket. What happens when they call DeleteBucket?

A. It succeeds because IAM policies take precedence
B. It is denied — SCPs set the ceiling and an explicit Deny always wins
C. It succeeds only in the management account
D. It depends on the S3 bucket policy
Correct answer: B. Effective permission is the intersection of IAM and SCP; an explicit Deny in either always overrides an Allow.

Q3. A region-restriction SCP denies all actions outside two approved regions. Shortly after it is attached, engineers report they can no longer manage IAM users or update Route 53 records. What is the most likely cause?

A. The SCP was attached to the management account
B. The SCP does not exempt global services such as IAM, Route 53, CloudFront, and Support
C. IAM users are always blocked by region SCPs
D. Route 53 requires a separate service-linked role
Correct answer: B. Global services are not region-scoped, so a naive region-restriction SCP breaks them unless those services are explicitly exempted.

Q4. What is the key difference between a mandatory and an elective Control Tower guardrail?

A. Mandatory guardrails cost extra
B. Mandatory guardrails cannot be disabled and are always enforced; elective guardrails are optional best practices you can turn on or off
C. Elective guardrails only apply to the management account
D. There is no functional difference
Correct answer: B. Mandatory guardrails are always active; elective and strongly recommended guardrails can be enabled per OU based on governance needs.

Q5. An enterprise wants engineers to log in once via corporate Okta and assume the correct role in any of 40 AWS accounts without individual IAM users. What is the best-practice solution?

A. Create an IAM user per engineer per account
B. IAM Identity Center with SAML federation from Okta and permission sets
C. Share a single root-account access key
D. Use AWS Organizations SCPs alone
Correct answer: B. IAM Identity Center is purpose-built for centralized SSO across an Organization, provisioning short-lived federated roles instead of long-lived IAM users.

Q6. A delegated admin role can create IAM roles for developers. How do you prevent them from creating a role with AdministratorAccess?

A. Attach a Deny statement to every developer role individually
B. Require the delegated admin to set a permission boundary on every role they create, capping maximum permissions
C. Remove iam:CreateRole entirely
D. Use MFA enforcement only
Correct answer: B. Enforcing a mandatory permission boundary via a condition requiring iam:PermissionsBoundary on CreateRole is the standard pattern to prevent privilege escalation by delegated admins.

Q7. A company wants every application account to use a common, centrally managed VPC without each account owning its own VPC. What is the mechanism?

A. VPC Peering between every pair of accounts
B. Share subnets from a central VPC using AWS RAM
C. Transit Gateway alone, with each account keeping its own VPC
D. Copy the VPC configuration manually into every account
Correct answer: B. RAM subnet sharing lets many accounts launch resources into subnets owned by a single central VPC, reducing IP management and networking overhead versus peering or per-account VPCs.

Q8. You need Dev and Prod VPCs to both reach a Shared-Services VPC, but never reach each other. How do you design TGW route tables?

A. A single flat TGW route table with all routes propagated
B. Separate TGW route tables for Dev and Prod that each only propagate Shared-Services routes, with no propagation between Dev and Prod
C. VPC Peering directly between Dev and Prod
D. Use only Security Groups to block traffic
Correct answer: B. TGW route table segmentation is the standard way to implement network isolation between spokes while still allowing shared access to common services.

Q9. After creating a TGW peering attachment between two regions, spoke VPCs still cannot reach each other. What is most likely missing?

A. Route propagation is disabled for peering attachments — static routes must be added manually
B. The TGWs are in different Availability Zones
C. Peering does not support cross-region traffic at all
D. Security groups always block inter-region traffic
Correct answer: A. Unlike VPC and TGW attachments, TGW peering attachments require manually created static routes in each TGW route table — automatic propagation is not supported.

Q10. What is the standard pattern for forcing all internet-bound traffic from multiple VPCs through a single AWS Network Firewall?

A. Deploy Network Firewall independently in every VPC
B. Centralized inspection VPC attached to Transit Gateway, with spoke route tables directing 0.0.0.0/0 to the TGW
C. Use only NACLs on each spoke subnet
D. Network Firewall cannot inspect cross-VPC traffic
Correct answer: B. The centralized inspection VPC pattern routes all spoke egress through TGW into a shared Network Firewall, avoiding per-VPC firewall duplication and cost.

Q11. A company needs the highest-resiliency Direct Connect design for a mission-critical workload. What should they provision?

A. A single 10 Gbps DX connection
B. Two DX connections at two different DX locations, each terminating on separate devices, with BGP failover and a VPN backup
C. One DX connection plus a second identical connection at the same location
D. Public VIF only, since it is cheaper
Correct answer: B. AWS's resiliency model for DX requires diversity across DX locations and devices plus BGP-based failover; a VPN backup adds a layer for the rare case both DX paths fail.

Q12. On-prem servers need to resolve names in a private Route 53 hosted zone. What do you configure?

A. A Route 53 Resolver outbound endpoint
B. A Route 53 Resolver inbound endpoint, with on-prem DNS forwarding queries to it
C. A public hosted zone instead
D. NAT Gateway DNS forwarding
Correct answer: B. Inbound endpoints expose AWS private DNS to on-prem resolvers; outbound endpoints do the reverse, letting AWS resources resolve on-prem names.

Q13. Two companies with overlapping CIDR ranges (both 10.0.0.0/16) need one to consume a specific API hosted in the other's VPC. What connectivity option works despite the overlap?

A. VPC Peering
B. Transit Gateway peering
C. AWS PrivateLink (Interface Endpoint / Endpoint Service)
D. Direct Connect
Correct answer: C. PrivateLink only requires ENI-level connectivity in the consumer VPC and never merges route tables or CIDRs, so it works even with fully overlapping IP ranges — unlike peering or TGW.

Q14. When should you choose PrivateLink over Transit Gateway for cross-account connectivity?

A. When you need full bidirectional network-level reachability between VPCs
B. When exposing a single specific service to many consumers without merging networks or worrying about CIDR overlap
C. When connecting on-prem to AWS
D. Never — TGW always replaces PrivateLink
Correct answer: B. PrivateLink is service-level exposure (one service, many consumers, no shared routing); TGW is network-level connectivity for broad multi-VPC and on-prem routing.

Q15. Why does Fargate's awsvpc network mode assign each task its own ENI?

A. To reduce cost
B. To give each task an isolated security group and IP, avoiding port-mapping conflicts of bridge mode
C. It is required for CloudWatch Logs
D. To enable Spot pricing
Correct answer: B. awsvpc mode gives every task first-class networking — its own ENI, private IP, and security group — enabling fine-grained per-task security instead of shared host-level rules.

Q16. A workload requires DaemonSets for log collection on every node. Which EKS compute option should you avoid?

A. Managed node groups
B. Self-managed EC2 node groups
C. EKS Fargate profiles — Fargate does not support DaemonSets
D. Cluster Autoscaler on EC2
Correct answer: C. Fargate pods run in isolated micro-VMs with no shared node, so DaemonSets, which require a persistent per-node agent, are not supported.

Q17. An application takes 4 minutes to bootstrap before it can serve traffic, causing scale-out to lag demand spikes. What reduces this latency?

A. Increase the ASG cooldown period
B. Use a Warm Pool of pre-initialized stopped instances so scale-out promotes them instead of booting cold
C. Switch to Spot Instances
D. Add a lifecycle hook on launch
Correct answer: B. Warm pools keep instances pre-initialized so the ASG can bring them into service in seconds instead of re-running the full bootstrap sequence.

Q18. What ALB feature enables a canary deployment shifting a small percentage of traffic to a new version before full cutover?

A. Sticky sessions
B. Weighted target groups on a single listener rule
C. Cross-zone load balancing
D. Connection draining
Correct answer: B. Weighted target groups let one routing rule split traffic by percentage across two target groups — the standard ALB-native canary and blue/green mechanism.

Q19. A Lambda function reading from Kinesis is overwhelming a downstream RDS database with connections during traffic spikes. What limits this safely?

A. Increase Lambda timeout
B. Set reserved concurrency on the function to cap max concurrent executions
C. Increase the Kinesis shard count
D. Switch RDS to Multi-AZ
Correct answer: B. Reserved concurrency caps how many instances of the function can run simultaneously, directly bounding the number of concurrent downstream connections.

Q20. A high-volume IoT pipeline needs to run millions of short workflow executions per day as cheaply as possible, and can tolerate at-least-once execution. Which Step Functions type fits?

A. Standard Workflows
B. Express Workflows
C. Both are identical in cost
D. Neither — use SQS only
Correct answer: B. Express Workflows are priced per execution and duration for high-volume, short-duration workloads and provide at-least-once semantics, versus Standard's exactly-once but costlier per-transition pricing.

Q21. A team has deep existing Kubernetes tooling and multi-cloud portability requirements. Which AWS compute platform best fits?

A. ECS with EC2 launch type
B. Amazon EKS
C. AWS Lambda
D. AWS Batch on Fargate
Correct answer: B. EKS runs standard Kubernetes, preserving existing tooling and manifests and easing multi-cloud portability, unlike ECS's AWS-proprietary orchestration model.

Q22. A global app needs a secondary region readable with sub-second replication lag and the ability to promote to primary in under a minute during a regional outage. Which database fits?

A. RDS Multi-AZ with a cross-region read replica
B. Aurora Global Database
C. DynamoDB Global Tables only
D. RDS read replica with async replication
Correct answer: B. Aurora Global Database is purpose-built for this: storage-layer cross-region replication with typical sub-second lag and managed failover promoting the secondary in under a minute.

Q23. A team needs to upgrade RDS MySQL from 5.7 to 8.0 with minimal risk and a fast rollback path. What should they use?

A. In-place major version upgrade during a maintenance window
B. RDS Blue/Green Deployments to validate on a synced green environment before switchover
C. Read replica promotion
D. Multi-AZ failover
Correct answer: B. Blue/Green Deployments create a fully replicated green environment on the new version, validated before a fast, low-risk switchover — reducing the blast radius of major upgrades.

Q24. A DynamoDB table using OrderStatus (5 possible values) as the partition key is throttling under high write volume even though total table capacity is high. Why?

A. The table needs Global Tables
B. Low-cardinality partition keys create hot partitions since a partition's throughput is capped regardless of table-level capacity
C. On-demand mode is not enabled
D. DynamoDB does not support high write volume
Correct answer: B. Each partition has its own throughput ceiling; a key with only 5 distinct values concentrates all writes onto a handful of partitions, causing throttling even with ample table-level capacity.

Q25. A gaming leaderboard needs microsecond read latency for the same items requested extremely frequently. What should sit in front of DynamoDB?

A. ElastiCache for Redis, self-managed
B. Amazon DAX
C. CloudFront caching of API responses only
D. DynamoDB Accelerator is not a real service — use RDS instead
Correct answer: B. DAX is a managed, DynamoDB-API-compatible in-memory cache purpose-built to shave read latency for hot items without application-level cache logic.

Q26. An object needs the lowest storage cost, is rarely accessed, and a 12-hour retrieval time is acceptable, but it must survive loss of an entire AZ.

A. S3 One Zone-IA
B. S3 Glacier Deep Archive
C. S3 Glacier Flexible Retrieval (Bulk)
D. S3 Standard-IA
Correct answer: B. Glacier Deep Archive is the lowest-cost class, replicated across 3+ AZs so it survives an AZ loss, unlike One Zone-IA, with retrieval times up to 12 hours matching the requirement.

Q27. A session store must survive a node failure without losing data and support automatic failover. Which caching engine and configuration fits?

A. Memcached with auto discovery
B. Redis with cluster mode enabled and replicas per shard
C. Memcached with multiple nodes
D. Redis without replicas
Correct answer: B. Only Redis supports replication and automatic failover; Memcached has no replication and node failure means data loss for those keys.

Q28. An application needs single-digit-millisecond reads and writes at massive unpredictable scale with a flexible schema, across multiple regions actively writing. What fits best?

A. Aurora Global Database
B. DynamoDB Global Tables
C. RDS with cross-region read replicas
D. ElastiCache alone as the system of record
Correct answer: B. DynamoDB Global Tables provide multi-active, multi-region writes at single-digit-millisecond latency with a flexible schema — a fit that Aurora Global DB (single writer region) and RDS replicas do not match.

Q29. On-call engineers are fatigued by alarms firing on isolated latency spikes that self-resolve. What reduces noise while still catching real incidents?

A. Delete the latency alarm
B. A composite alarm requiring both the latency alarm and the error-rate alarm to be in ALARM state
C. Lower the alarm threshold
D. Increase the evaluation period to 24 hours
Correct answer: B. Composite alarms let you require correlated signals before paging, cutting single-metric false positives while preserving sensitivity to genuine multi-symptom incidents.

Q30. Internal CloudWatch metrics show healthy servers, but customers report the login page is broken. What monitoring gap does this reveal?

A. Missing X-Ray tracing
B. No outside-in synthetic monitoring of the actual user flow
C. Missing VPC Flow Logs
D. Insufficient EC2 instance count
Correct answer: B. Server-side health metrics do not verify end-to-end user experience; Synthetics canaries probe from outside the infrastructure, catching failures invisible to internal metrics.

Q31. A microservices app has growing p99 latency but it is unclear which of 12 services is the bottleneck. What AWS service pinpoints this?

A. CloudWatch Logs Insights alone
B. AWS X-Ray, using the service map to isolate the slow hop
C. VPC Flow Logs
D. AWS Config
Correct answer: B. X-Ray's distributed tracing and service map visualize per-hop latency across the full call chain, directly identifying the bottleneck service that aggregate metrics cannot isolate.

Q32. An organization wants every account's application logs centrally searchable in a dedicated logging account in near-real time. What is the mechanism?

A. Manually export logs nightly via S3
B. CloudWatch Logs subscription filters streaming to Kinesis Data Firehose in the central logging account
C. CloudTrail only
D. Increase log retention in each account
Correct answer: B. Subscription filters push log events in near-real time to a destination, commonly Kinesis Firehose or Streams, in a centralized account, enabling org-wide log aggregation.

Q33. A team wants to safely test EC2 instance failure in production without risking an uncontrolled outage. What FIS feature guarantees the experiment halts if things go wrong?

A. IAM permission boundaries
B. Stop conditions tied to CloudWatch alarms
C. Increasing the blast radius
D. Manual monitoring only
Correct answer: B. FIS stop conditions automatically abort a running experiment the moment a linked CloudWatch alarm enters ALARM state, capping the blast radius of chaos testing.

Q34. A team has documented DR runbooks but has never tested them under simulated failure. What is the recommended next step before relying on them?

A. Trust the documentation as-is
B. Run a Game Day exercise using FIS to simulate the failure and validate the runbook and automated recovery actually work
C. Increase backup frequency only
D. Skip testing to avoid production risk
Correct answer: B. Untested runbooks are unverified assumptions; a Game Day exercises the real failure mode against real infrastructure to confirm RTO and RPO targets are actually achievable.

Q35. An active-active app needs sub-second failover at the network layer when a region's health checks fail, independent of DNS TTL and caching issues.

A. Route 53 latency-based routing alone
B. AWS Global Accelerator, which uses static anycast IPs and reroutes at the AWS network edge instantly
C. CloudFront alone
D. A single-region NLB
Correct answer: B. Global Accelerator uses anycast IPs and AWS's global network for near-instant failover, avoiding client-side DNS caching delays inherent to Route 53-only failover.

Q36. A workload can tolerate an RTO of 15 minutes and RPO of 5 minutes, but the business wants to minimize standing infrastructure cost. Which DR pattern fits best?

A. Backup and Restore
B. Pilot Light
C. Multi-Site Active-Active
D. No DR strategy needed
Correct answer: B. Pilot Light keeps only core data continuously replicated and minimal infrastructure running, scaling up the rest on failover — matching a roughly 15-minute RTO at much lower cost than warm standby or active-active.

Q37. A critical financial system needs failover control that itself will not fail if an entire AWS region goes down, plus proof the standby region is actually ready to serve traffic.

A. Route 53 simple health-check failover only
B. Route 53 Application Recovery Controller (readiness checks plus a highly available routing control cluster)
C. CloudWatch Alarms triggering a Lambda failover
D. Global Accelerator alone
Correct answer: B. ARC's routing control cluster is deliberately distributed across regions and partitions for resilience of the failover mechanism itself, and readiness checks validate standby capacity before you rely on it.

Q38. You want most users routed to the AWS region with the lowest network latency for them, automatically.

A. Weighted routing
B. Latency-based routing policy
C. Simple routing
D. Geolocation routing
Correct answer: B. Latency-based routing uses AWS's latency measurements between users and regions to route each request to the lowest-latency healthy endpoint.

Q39. A company needs ransomware-resilient backups that cannot be deleted even by a compromised admin account. What should they configure?

A. Standard EBS snapshots only
B. AWS Backup with a cross-account copy into an isolated account, in a vault with Backup Vault Lock enabled
C. S3 versioning only
D. Increase snapshot frequency
Correct answer: B. Cross-account isolation prevents a compromised primary account from touching backups, and Vault Lock makes the retention policy immutable — even the root user cannot delete locked backups before expiry.

Q40. Which best exemplifies the Reliability pillar's failure management best practice?

A. Using the largest possible instance type
B. Automatically testing recovery procedures via Game Days and setting quantified RTO/RPO targets
C. Manually reviewing logs weekly
D. Avoiding all managed services
Correct answer: B. Failure management is about anticipating failure, testing recovery via Game Days, and having quantified, validated RTO and RPO — not just provisioning bigger resources.

Q41. A team manually SSHes into servers to apply emergency patches, occasionally causing config drift. Which Operational Excellence practice addresses this?

A. Increase server count
B. Perform operations as code using SSM Automation documents and runbooks instead of manual SSH changes
C. Disable CloudTrail logging
D. Add more IAM users
Correct answer: B. Operations as code — codifying operational procedures such as SSM Automation — eliminates ad hoc manual changes and the drift and error they introduce.

Q42. A workload requires near-zero RTO and RPO and budget is not the primary constraint. Which DR strategy and supporting service pairing fits?

A. Backup and Restore with AWS Backup
B. Pilot Light with manual DNS updates
C. Multi-Site Active-Active with Route 53 ARC and DynamoDB Global Tables or Aurora Global Database
D. Warm standby without health checks
Correct answer: C. Near-zero RTO and RPO demands live traffic serving from multiple regions with deterministic, tested failover control and multi-region-write-capable data services.

Q43. A data center lease expires in 6 months, forcing a fast migration, but two legacy apps have unresolved software licensing blockers. What is the correct 7 Rs plan?

A. Refactor everything to serverless
B. Rehost the majority via MGN to meet the deadline; Retain the two blocked apps until licensing is resolved
C. Repurchase all applications as SaaS
D. Retire every application
Correct answer: B. Under a tight deadline, Rehost is the fastest path for most apps; apps with real blockers should be explicitly Retained rather than forced into a rushed migration.

Q44. A migration team needs to map network dependencies between individual processes on each server before planning application groupings for migration waves. What captures this?

A. Agentless Discovery Connector only
B. Agent-based discovery, which captures process-to-process network connections
C. AWS Config
D. CloudTrail
Correct answer: B. Agent-based discovery installs a lightweight agent per server and captures fine-grained, process-level network connections; agentless discovery only gives VM-level inventory and utilization.

Q45. A company needs to rehost 200 on-prem VMs to EC2 as fast as possible with minimal application changes and minimal cutover downtime.

A. AWS DataSync
B. AWS Application Migration Service (MGN)
C. AWS Schema Conversion Tool
D. AWS DMS
Correct answer: B. MGN is purpose-built for server rehost: continuous replication lets you test extensively and cut over with just minutes of downtime, without re-architecting the application.

Q46. SCT reports a 92% automatic conversion rate for an Oracle-to-PostgreSQL migration. What does this mean for the remaining 8%?

A. The migration is essentially complete and can proceed unattended
B. Complex objects like certain stored procedures and functions could not be auto-converted and need manual developer remediation before cutover
C. SCT failed and DMS cannot be used
D. 8% of the data will be lost during migration
Correct answer: B. SCT's conversion percentage reflects schema and code objects only; a high percentage still commonly leaves complex procedural logic that must be manually rewritten before the heterogeneous migration is production-ready.

Q47. A company needs to continuously sync a large on-prem NFS file share into Amazon EFS, on a schedule, without writing custom scripts.

A. AWS DMS
B. AWS DataSync
C. AWS Snowball Edge
D. AWS Storage Gateway File Gateway
Correct answer: B. DataSync is purpose-built for automated, scheduled, validated file and object transfer between on-prem file systems and AWS storage services like EFS, FSx, and S3.

Q48. An enterprise wants to eliminate its physical backup tape infrastructure while keeping existing backup software unchanged.

A. File Gateway
B. Volume Gateway (stored mode)
C. Tape Gateway (Virtual Tape Library)
D. AWS Backup only
Correct answer: C. Tape Gateway presents a virtual tape library interface compatible with existing backup software, letting you retire physical tape hardware without changing backup workflows.

Q49. A company must migrate 2 PB of data from a facility with no viable network uplink for bulk transfer. What is the appropriate approach?

A. AWS DataSync over the internet
B. Direct Connect provisioned overnight
C. Multiple AWS Snowball Edge Storage Optimized devices, or Snowmobile for the full 2 PB in one engagement
D. AWS Storage Gateway
Correct answer: C. At petabyte scale with no adequate network path, physical offline transfer via Snow Family devices is the standard, cost-effective solution.

Q50. A hospital must keep patient data physically on-premises for regulatory reasons while still using native AWS APIs for its applications.

A. AWS Local Zones
B. AWS Wavelength
C. AWS Outposts
D. Standard AWS Region with encryption
Correct answer: C. Outposts physically places AWS-managed infrastructure inside the customer's own data center, satisfying strict data-residency requirements while retaining native AWS service APIs.

Q51. A team wants to move VMware VMs to AWS infrastructure fastest, keeping the exact same hypervisor-level configuration and VMware management tools, with no P2V or V2V conversion.

A. AWS MGN (Rehost to native EC2)
B. VMware Cloud on AWS (Relocate)
C. AWS Schema Conversion Tool
D. AWS DataSync
Correct answer: B. Relocate via VMware Cloud on AWS is the only 7 Rs strategy that moves the VM without converting it out of the VMware format, unlike Rehost which lands on native EC2 and AMIs.

Q52. A migration needs to move 300 TB of historical data plus ongoing daily deltas of about 50 GB, with a network link capped at 500 Mbps.

A. Transfer everything, including historical data, over the 500 Mbps link
B. Use Snowball Edge for the 300 TB bulk historical transfer, then DMS CDC or DataSync over the network link for ongoing deltas
C. Wait for the network link to be upgraded before starting
D. Use Snowmobile for the entire migration
Correct answer: B. This hybrid pattern — offline bulk transfer for the large historical dataset, then network-based CDC or incremental sync for the small ongoing delta — is a standard, exam-tested approach to large migrations over constrained links.

Q53. A company runs a steady-state, predictable production fleet but wants maximum flexibility to change instance families and regions over the commitment period.

A. EC2 Instance Savings Plans
B. Compute Savings Plans
C. Standard Reserved Instances
D. Spot Instances
Correct answer: B. Compute Savings Plans apply across any instance family, region, and OS, and even Fargate and Lambda usage, trading a slightly lower discount than EC2 Instance Savings Plans for maximum flexibility.

Q54. A company suspects many EC2 instances are oversized relative to actual CPU and memory utilization but does not know which ones. What AWS service directly recommends right-sizing changes?

A. AWS Config
B. AWS Compute Optimizer
C. AWS Trusted Advisor cost checks only
D. CloudWatch Alarms
Correct answer: B. Compute Optimizer analyzes historical utilization and provides specific instance-type right-sizing recommendations with projected savings, more targeted than Trusted Advisor's general cost checks.

Q55. Finance wants to see AWS spend broken out per business unit, but resources are inconsistently tagged today. What should be enforced first?

A. Enable Cost Explorer only
B. Enforce a mandatory tagging policy, for example via SCP or Config, requiring cost-allocation tags at resource creation, then activate those tags for cost allocation reporting
C. Use a single shared account for all business units
D. Manually track spend in a spreadsheet
Correct answer: B. Cost allocation reporting is only as good as tag hygiene; enforcing mandatory tags at creation time is the prerequisite before per-business-unit cost reports become meaningful.

Q56. A migration must cut over with near-zero downtime and the source database cannot be taken offline. Which DMS configuration is being described?

A. Full Load only
B. Full Load plus Change Data Capture
C. A one-time snapshot export to S3
D. Native database backup and restore
Correct answer: B. Full Load plus CDC takes the snapshot while caching concurrent changes, applies them when the load completes, then streams ongoing changes — the configuration minimal-downtime scenarios describe.

Q57. A DMS task migrating a table with large binary objects is running far slower than expected and repeatedly failing on a handful of rows. What is the most likely cause?

A. The replication instance is in the wrong region
B. LOB handling settings and replication instance sizing are inadequate for the large object volume
C. CDC is not enabled
D. The target schema was created by SCT
Correct answer: B. Large object handling is a known DMS tuning area: LOB mode settings and replication instance capacity both materially affect throughput and failure rates on LOB-heavy tables.

Q58. A heterogeneous migration from Oracle to Aurora PostgreSQL needs both schema conversion and ongoing data replication. Which tool pairing is correct?

A. DMS for schema, SCT for data
B. SCT for schema conversion, DMS for data migration
C. DataSync for both
D. MGN for both
Correct answer: B. SCT converts schema, views, stored procedures, and functions between engines; DMS moves the data itself, including ongoing CDC.

Q59. A company wants a single pane of glass tracking migration progress across MGN, DMS, and DataSync tasks for a large portfolio. What provides this?

A. AWS Config
B. AWS Migration Hub
C. AWS Trusted Advisor
D. CloudWatch dashboards only
Correct answer: B. Migration Hub centrally tracks migration progress across the AWS migration tooling, giving portfolio-level visibility rather than per-tool views.

Q60. A workload runs fault-tolerant batch processing that can be interrupted and restarted. Cost is the dominant concern. What purchasing option fits best?

A. On-Demand Instances
B. Spot Instances with a mixed-instance ASG and interruption handling
C. Standard Reserved Instances
D. Dedicated Hosts
Correct answer: B. Spot suits interruptible, fault-tolerant work at the deepest discount; a mixed-instance ASG diversifies capacity pools and the two-minute interruption notice allows graceful handling.

Q61. An organization wants to prevent any account from creating resources outside two approved regions, while still allowing IAM and Route 53 administration. What is the correct approach?

A. An IAM policy attached to every role in every account
B. An SCP attached at the OU level that denies actions outside the approved regions but exempts global services
C. AWS Config rules alone
D. A permission boundary on the root user
Correct answer: B. Region restriction is an OU-level guardrail concern; an SCP is the enforcement point, and global services must be exempted or account operations break.

Q62. A company needs a shared services VPC reachable from 30 spoke VPCs across three AWS accounts, with centralized egress inspection. Which combination is most appropriate?

A. Full-mesh VPC peering plus per-VPC NAT gateways
B. A Transit Gateway with a shared services and inspection VPC, plus RAM sharing where cross-account attachment is needed
C. PrivateLink endpoints to every spoke
D. A single flat VPC with all workloads in it
Correct answer: B. TGW replaces the unmanageable peering mesh, and a centralized inspection VPC handles egress; RAM lets other accounts attach without owning the TGW.

Q63. An application must serve reads from the region closest to each user while keeping a single writer region for consistency. Which database pattern fits?

A. DynamoDB Global Tables with multi-active writes
B. Aurora Global Database with a primary writer region and secondary read-only regions
C. A single-region RDS instance with CloudFront in front
D. ElastiCache Global Datastore as the system of record
Correct answer: B. Aurora Global Database keeps a single writer region while serving low-latency reads from secondary regions — the fit when multi-active writes are not required.

Q64. A team needs to know whether a standby region could actually absorb production traffic before declaring it a valid failover target. What validates this continuously?

A. Route 53 health checks on the primary only
B. Route 53 ARC readiness checks
C. CloudWatch Synthetics canaries against the primary
D. AWS Config conformance packs
Correct answer: B. ARC readiness checks continuously audit whether a standby region has the capacity and configuration to take over, turning an assumption into a monitored fact.

Q65. A company wants to detect when an S3 bucket becomes publicly accessible and automatically remediate it. Which combination is appropriate?

A. CloudTrail alone
B. An AWS Config rule with an automatic remediation action, plus SCP guardrails and Block Public Access
C. A CloudWatch dashboard
D. Trusted Advisor checks only
Correct answer: B. Config rules detect the non-compliant state and can trigger automatic remediation, while SCPs and Block Public Access prevent the state from being reached in the first place.

Q66. A workload's p99 latency spikes every day at the same time and the team wants an alarm that adapts to normal daily patterns rather than a fixed threshold. What should they use?

A. A static threshold alarm set to the daily peak
B. A CloudWatch anomaly detection band on the latency metric
C. A composite alarm with no member alarms
D. A Synthetics canary
Correct answer: B. Anomaly detection learns the metric's normal pattern, including daily seasonality, and alarms on deviation from that band rather than a fixed number.

Q67. A company needs to prove to auditors that a specific backup vault's contents cannot be deleted for seven years, even by an administrator. What enforces this?

A. An IAM policy denying s3:DeleteObject
B. AWS Backup Vault Lock in compliance mode
C. S3 Object Lock on a separate bucket
D. A CloudTrail trail with log file validation
Correct answer: B. Vault Lock enforces WORM immutability on the vault's recovery points, and in compliance mode the policy cannot be removed even by the root user before expiry.

Q68. A team is choosing between a Warm Standby and a Pilot Light DR strategy. What is the essential difference?

A. Warm Standby has no data replication
B. Warm Standby runs a scaled-down but fully functional copy of the stack; Pilot Light keeps only core data replicated with minimal infrastructure running
C. Pilot Light has a lower RTO than active-active
D. They are identical in cost and RTO
Correct answer: B. Warm Standby keeps a scaled-down working stack ready to scale up, giving a lower RTO than Pilot Light, which must build out most of the stack on failover.

Q69. A company wants to reduce the cost of a large, rarely accessed S3 dataset without knowing its future access pattern. Which storage class avoids ongoing manual tiering decisions?

A. S3 Standard
B. S3 Intelligent-Tiering
C. S3 One Zone-IA
D. S3 Glacier Deep Archive
Correct answer: B. Intelligent-Tiering moves objects between access tiers automatically based on observed usage, removing the need to guess or manually manage lifecycle transitions.

Q70. A company needs cross-region object replication for compliance data residency, but the source and destination buckets are in the same region for a different dataset. Which feature covers the same-region case?

A. Cross-Region Replication (CRR)
B. Same-Region Replication (SRR)
C. S3 Transfer Acceleration
D. S3 Lifecycle transitions
Correct answer: B. SRR replicates objects between buckets in the same region, useful for log aggregation or separating production and test copies; CRR handles the cross-region case.

Q71. A company is migrating a self-managed MySQL database to Amazon RDS with minimal application change. Which of the 7 Rs does this represent?

A. Rehost
B. Replatform
C. Refactor
D. Repurchase
Correct answer: B. Moving a self-managed database to a managed service without re-architecting the application is the classic lift-tinker-and-shift Replatform example.

Q72. A company wants to enforce that all new EC2 instances in production carry a CostCenter tag, blocking creation when the tag is absent. What is the most direct enforcement mechanism?

A. A CloudWatch alarm on untagged resources
B. An SCP or IAM condition requiring the tag on RunInstances, backed by a Config rule for detection
C. A monthly manual audit
D. Cost Explorer grouping by tag
Correct answer: B. Preventive controls such as SCP or IAM conditions block the untagged creation outright, while Config rules provide the detective layer for anything that slips through.

Q73. A team needs to run a controlled experiment that terminates 20% of an ECS service's tasks to verify the service recovers within its target RTO. What should they use?

A. A manual rolling restart
B. AWS Fault Injection Service with an experiment template and a stop condition tied to an error-rate alarm
C. A CloudWatch Synthetics canary
D. An Auto Scaling scheduled action
Correct answer: B. FIS runs controlled fault injection with a defined blast radius and stop conditions that abort the experiment if production stability degrades.

Q74. A company needs to expose an internal microservice to 40 partner accounts without giving them network-level access to the VPC. What is the appropriate design?

A. VPC peering with each partner account
B. A PrivateLink endpoint service with an NLB in front of the microservice, and interface endpoints in each consumer account
C. A Transit Gateway shared via RAM with all partners
D. A public ALB with IP allowlisting
Correct answer: B. PrivateLink exposes exactly one service to many consumers over ENI-backed endpoints, with no route table sharing, no CIDR coordination, and no broad network reachability.

Q75. A company is preparing for a regional failover and wants the failover decision itself to be deterministic and auditable rather than driven by ad hoc health-check behavior. What provides this?

A. Route 53 failover routing with a single health check
B. Route 53 ARC routing controls, which let an operator flip traffic deterministically and record the action
C. Global Accelerator endpoint groups alone
D. A CloudWatch alarm triggering an SNS notification
Correct answer: B. ARC routing controls give an explicit, auditable failover action on a control plane that is itself resilient to regional failure, rather than relying on implicit health-check behavior.

Scoring Guide

Count your raw correct answers out of 75. As a rule of thumb — not an official AWS figure — a raw score of roughly 72% or better (about 54 of 75) is a reasonable proxy for exam-ready on this material, and scores in the 60-70% band usually indicate one or two domains dragging the total down rather than broad weakness. Because the real exam is scaled rather than raw-scored, treat this number as a directional signal, not a prediction.

More useful than the total is the distribution. Group your misses by domain — multi-account governance, networking, compute, databases, observability and SRE, DR, migration, cost — and note which domain contributed the most errors. Also record which questions you flagged, since a high flag rate in a domain you ultimately scored well in suggests a confidence problem rather than a knowledge problem, and those need different remediation. Write both numbers down before you look at any explanation; the raw score and the domain histogram are the inputs tomorrow's review depends on.

Preview — What the Score Does Not Tell You

A raw score and a domain histogram tell you where you lost points, but they do not tell you why. A question missed because you did not know that TGW peering attachments require static routes is a different problem from one missed because you narrowed it to two plausible answers and picked the wrong one, and the two demand completely different remediation. The first is a content gap you can close by rereading a day page; the second is a distractor-recognition problem that rereading will not fix.

Day 58 is built entirely around that distinction. The work is distractor analysis: for every miss, and for every question you got right by luck or elimination, articulating why the correct answer is right and why each wrong option is wrong, then tagging each miss by domain to find the weakest area. Bring the raw score, the domain histogram, and the flag list from today into that session — they are the raw material the analysis runs on.