Mock Exam 1 Distractor Analysis & Weak Domain Review
Recap: What the Baseline Score Actually Tells You
Mock Exam 1 was a 75-question, 180-minute timed run under real conditions — no pausing, no notes — and its main product was not a score but a baseline. That baseline is only useful if you treat it as a measurement of two different things at once. The first is content coverage: which domains the questions you missed actually came from. The second is something the raw score hides completely, which is how many of your correct answers were correct for the right reason. A question you answered by eliminating two obviously wrong options and guessing between the remaining two is not evidence of understanding, and it will not survive a slightly different framing on the real exam.
This day extends the mock exam rather than repeating it. The ~2.4 minutes per question average you internalized yesterday is a pacing constraint, not an analysis method; the scenario questions that needed more time are exactly the ones whose distractors deserve the most scrutiny now. The work here is forensic: for every question, reconstruct why the correct answer is correct and why each wrong option was engineered to look correct. That reconstruction is what converts a score into a study plan.
Foundations You'll Need Today
Today's work is forensic: you are going to take apart wrong answers and name the trick that built them. That only works if you already hold a few structural facts about AWS steady in your head, because most of the fourteen patterns are variations on the same handful of confusions. Here are the ones this day actually leans on.
Organizations, OUs, and the Management Account
AWS Organizations is the feature that lets one company treat many separate AWS accounts as a single managed group. The account that creates the organization is the management account, and it sits at the top of a tree. Below it you create organizational units, or OUs — folders that group accounts by purpose, such as a Security OU holding your logging and audit accounts, or a Workloads OU holding the accounts that run applications. The reason this matters is that policies can be attached to an OU and they then apply to every account inside it, including accounts you add later. The management account is the exception to almost every rule: it is not subject to the restrictions that apply to the accounts beneath it, which is exactly why AWS tells you to keep it empty of workloads and use it only for organization-level administration.
SCPs, IAM Policies, and Permission Boundaries
These three all look like "permission documents" and they behave completely differently, which is why they generate so many wrong answers. An IAM policy is attached to an identity — a user, a group, or a role — and it grants that identity the ability to do things. A service control policy, or SCP, is attached to an OU or an account inside Organizations, and it does the opposite job: it sets a ceiling on what the accounts underneath are allowed to do at all. An SCP never grants anything. If an SCP allows only two services and the account's own IAM policy allows twenty, the account can use two. A permission boundary is the same idea applied to a single identity rather than a whole account: it caps what that one role or user can ever be granted, no matter what other policies say. The practical takeaway is that ceilings and grants are different mechanisms, and a question about preventing something "even if the account administrator tries to allow it" is asking for a ceiling.
Security Groups and Network ACLs
Both of these control which network traffic is allowed to reach your resources, and they operate at different levels. A security group is attached to a resource — typically an EC2 instance or the network interface it uses — and it is stateful, meaning if you allow traffic in, the reply traffic is automatically allowed back out. A network ACL is attached to a subnet, applies to everything in that subnet including instances launched later, and is stateless, meaning you have to write rules for both directions. When a question says "every instance in the subnet" or "before it reaches any instance," it is pointing at the subnet-level control, not the per-instance one.
VPC Endpoints: Gateway vs Interface
By default, traffic from your VPC to an AWS service like S3 travels over the public internet. A VPC endpoint is a way to reach that service privately, without leaving the AWS network. There are two kinds, and they are not interchangeable. A Gateway endpoint is a route-table entry that connects your VPC to exactly two services: S3 and DynamoDB. Nothing else. An Interface endpoint creates a private network interface inside your subnet and can front any service that supports it, including your own services published through a load balancer — this is the mechanism known as PrivateLink. If a question is about exposing a custom internal service, or about a service other than S3 or DynamoDB, the Gateway endpoint is the trap.
RTO, RPO, and the DR Strategy Ladder
Disaster recovery planning is organized around two numbers. RTO, recovery time objective, is how long the business can tolerate being down. RPO, recovery point objective, is how much data loss is acceptable, expressed as a span of time — an RPO of five minutes means you can lose at most the last five minutes of writes. AWS offers a spectrum of strategies that trade cost against those numbers. At the cheap end, Backup and Restore means you keep backups and rebuild when something breaks, which takes hours to days. Pilot Light keeps a minimal copy of core systems running and scales up on failure. Warm Standby keeps a scaled-down but fully functional copy ready to take over. Multi-Site Active-Active runs full capacity in more than one place at once and is the most expensive. The exam almost always gives you an RTO and an RPO and asks for the cheapest strategy that still meets them, which means the cheapest option overall is usually wrong.
With that grounding, here's why today is about naming the trick rather than memorizing more services: nearly every distractor you met on Mock Exam 1 was built by quietly swapping one of these mechanisms for a neighboring one, and you cannot spot the swap until you can tell the neighbors apart.
The Method: Four Sentences Per Question
The reason most people plateau after a mock exam is that they review answers instead of reviewing decisions. Reading the explanation for a question you missed feels productive, and it does close the specific fact you didn't know, but it leaves untouched the reasoning process that produced the wrong choice. If the same reasoning process shows up on the next mock in a different costume, you will miss that question too. The fix is to force the reasoning into the open where you can inspect it, and the cheapest way to do that is a fixed written format applied to every question without exception.
The format is four sentences. First, state in your own words why the correct answer is correct — not the explanation's wording, yours. Second, for each distractor, state the specific scenario in which that option would actually be the right answer. This second step is the one people skip, and it is the one that pays. A distractor is almost never nonsense; it is a real AWS capability that solves a different problem, or solves this problem at a cost the question's constraints rule out. Naming the scenario where it wins is what separates "I know PrivateLink is for service exposure" from "I know PrivateLink is the answer when CIDRs overlap and I only need one service."
Third, tag the question by domain and by sub-topic, using the same four domains the exam blueprint uses. Fourth, mark whether you got it right, wrong, or right-by-elimination. That last category is the one that inflates scores and hides gaps, and it should be counted as a miss for planning purposes. A mock exam where you scored 72% but 15 of those correct answers were elimination guesses is a 57% exam with better luck than average.
| Outcome | What it means | What to do with it |
|---|---|---|
| Wrong | Content gap or reasoning gap, unknown which | Write all four sentences; the distractor scenarios usually reveal which |
| Right by elimination | Partial knowledge; you knew what was wrong but not what was right | Treat as a miss; the correct answer's mechanism is the gap |
| Right by luck | No signal at all | Treat as a miss and re-read the source material for that topic |
| Right and confident | Genuine understanding | Skip, unless the distractor scenarios surprise you |
The Fourteen Distractor Patterns
What follows is not a list of facts to memorize but a catalog of the ways a plausible-sounding option gets built. Each entry names the pattern, explains why it is tempting, gives the tell that separates it from the correct answer, and notes how it typically appeared on Mock Exam 1. Read them as a set: the same handful of construction techniques account for the overwhelming majority of wrong answers on this exam, and once you can name the technique while reading an option, you stop evaluating it on vibes.
1. The Right Service, Wrong Scope
This is the most common pattern on the exam and the one that costs the most points, because the option names a service that genuinely belongs in the solution. The question is not whether the service is relevant but whether it is being applied at the right level of the hierarchy. A typical form: the scenario asks how to prevent a specific class of action across an entire organization, and one option proposes an IAM policy attached to a role in each account. IAM is absolutely part of the answer space, but an IAM policy is scoped to an identity, not to an organizational unit, so it cannot express an org-wide ceiling. The correct answer is the SCP, and the tell is the word "across all accounts" or "regardless of what the account's own administrators do."
The inverse form is equally common: the scenario asks how to grant a specific team access to one bucket, and an option proposes an SCP. SCPs never grant anything — they only cap. If the question is about enabling access rather than bounding it, any SCP-shaped answer is wrong on mechanism alone. On Mock Exam 1 this pattern showed up most often in the governance questions, where both an SCP and an IAM policy were offered and the deciding phrase was whether the constraint had to survive a hostile account administrator.
2. The Service That Solves a Different Problem
Here the distractor is a real service with a real purpose, just not this purpose. The classic pair is AWS DataSync and AWS DMS. Both move data, both are managed, both appear in migration scenarios, and the exam knows that. The tell is whether the source is a database or a file system. DataSync moves files and objects between NFS, SMB, HDFS, and S3/EFS/FSx; it has no concept of a schema, a table, or a change stream. DMS moves rows between databases and understands full load versus change data capture. A question that mentions "ongoing changes" or "minimal downtime cutover" for a database is a DMS question, and DataSync is the trap.
The same construction appears with Storage Gateway and DataSync, with MGN and DMS, and with Snowball and Direct Connect. In each case the two services overlap in the story they tell — hybrid data movement, migration, connectivity — and diverge in the mechanism. The reliable move is to identify the noun the question is actually about: file, row, server, or byte stream. That noun picks the service.
3. The Correct Answer With One Fatal Constraint Violation
This pattern is nastier than the previous two because the option is architecturally sound. It would work. It just violates a constraint the question stated in passing, usually in the first sentence. A scenario says the company has a strict data residency requirement and one option proposes a multi-region active-active design with cross-region replication. The design is excellent and it is wrong, because replication moves data out of the required jurisdiction. The constraint was stated once, early, and never repeated.
The tell is that the option is longer and more sophisticated than the others. Exam writers tend to build the constraint-violating distractor as a genuinely good architecture, because a bad architecture is easy to reject. When you find yourself admiring an option, go back and re-read the scenario's first two sentences looking for the requirement it breaks. On Mock Exam 1 this pattern concentrated in the resilience and migration domains, where cost ceilings and residency rules were the constraints most often violated.
4. The Manual Answer in an Automation Question
Whenever a scenario contains the words "automatically," "without manual intervention," or "at scale," any option that requires a human step is wrong regardless of how well it otherwise fits. The distractor here is usually a perfectly valid operational procedure — update the DNS record, run the failover script, promote the replica — that a competent engineer would actually perform. It is wrong because the question asked for a mechanism, not a procedure.
The tell is a verb that implies a person: "the team updates," "an operator promotes," "administrators rotate." Compare that against options phrased as capabilities: "Route 53 health checks remove the endpoint," "the secondary is promoted automatically." On Mock Exam 1 the automation-versus-manual fork appeared most often in the DR questions, where a manual promotion step was offered alongside an automated failover mechanism and the scenario had explicitly ruled out human latency.
5. The Cheaper Option That Misses the RTO
Cost is the most reliable lever an exam writer has, because almost every scenario can be made to sound cost-sensitive. The pattern is a DR strategy that is genuinely cheaper and genuinely insufficient. Backup and Restore is the cheapest option on the spectrum and it has an RTO measured in hours to days; if the scenario states a 15-minute RTO, Backup and Restore is not a candidate no matter how much the question talks about minimizing spend. The correct answer is the cheapest strategy that still satisfies the stated RTO and RPO, which is usually Pilot Light or Warm Standby.
The tell is a stated recovery objective. If the scenario gives you numbers, the numbers are the constraint and cost is secondary. If the scenario gives you no numbers and only says "minimize cost," then cost is the constraint and you should pick the cheapest option that meets the availability requirement. Reading which of the two the question actually supplied is the whole skill.
6. The Over-Engineered Answer
The mirror image of pattern five. A scenario describes a modest workload with a modest requirement and one option proposes multi-region active-active with Global Accelerator, DynamoDB Global Tables, and Route 53 ARC. Every component is real and the design would work, but it is disproportionate to the stated need, and the exam treats unnecessary complexity as a defect. The correct answer is usually the simplest design that satisfies the requirement, often a single-region Multi-AZ deployment.
The tell is that the option requires you to accept capabilities the scenario never asked for. If the question never mentions multiple regions, an answer that spans regions is adding scope. On Mock Exam 1 this pattern was most visible in the database questions, where Aurora Global Database and DynamoDB Global Tables were offered for workloads whose stated requirement was a single-region read-scaling problem that read replicas would have solved.
7. The Service That Exists But Doesn't Do That
Some distractors are not misapplied, they are simply false. The option names a real AWS service and attributes a capability to it that the service does not have. The most frequently tested instance is the claim that a Gateway VPC endpoint can front an arbitrary service. Gateway endpoints support S3 and DynamoDB and nothing else; every other service requires an Interface endpoint, which is ENI-backed and billed hourly. A question about exposing a custom internal API through a VPC endpoint is testing exactly this, and the Gateway endpoint option is the trap.
Other recurring instances: the claim that SCPs grant permissions, that permission boundaries grant permissions, that Memcached replicates, that Fargate supports DaemonSets, that TGW peering attachments propagate routes automatically. Each of these is a real service with a real limitation that the distractor quietly removes. The tell is that the option sounds slightly too convenient — the service does the thing you wish it did rather than the thing it does.
8. The Right Answer at the Wrong Layer
This pattern is about the OSI-ish layering of AWS controls. A scenario asks how to block traffic from a specific CIDR range and one option proposes a security group rule. Security groups are stateful and operate at the instance/ENI level; they can absolutely block a CIDR, so the option is not false. But if the scenario describes traffic that must be blocked before it reaches any instance — or describes a subnet-wide requirement — the correct layer is the network ACL or the Network Firewall, not the security group. The tell is the scope word: "all instances in the subnet," "before reaching the VPC," "centrally."
The same layering confusion appears with IAM versus SCP versus permission boundary, with ALB versus NLB versus Global Accelerator, and with CloudWatch alarms versus composite alarms. In each case the distractor is a control that works at a finer or coarser granularity than the requirement demands. Naming the required scope first, then matching the control to it, resolves these quickly.
9. The Legacy Service That Was Replaced
AWS retires and supersedes services, and the exam keeps the old names in circulation as distractors. The clearest current example is server migration: AWS Server Migration Service and CloudEndure Migration have been superseded by AWS Application Migration Service, and a question about rehosting servers at scale expects MGN. An option naming SMS is not wrong because SMS never worked, but because it is no longer the recommended tool and the exam tests current guidance.
The tell is a service name you recognize from older study material. When you see one, ask whether you have seen it in any recent AWS documentation or in the current curriculum. If the answer is no, it is probably the distractor. The same logic applies to Classic Load Balancer in scenarios that describe path-based routing, and to EC2-Classic-era networking assumptions in scenarios about VPC design.
10. The Option That Ignores the Stated Blast Radius
Some scenarios tell you exactly how much of the system is allowed to be affected, and one distractor quietly affects more. A question about testing failure tolerance in production offers an option that terminates instances across an entire Auto Scaling Group; the correct answer uses a fault injection experiment with a stop condition and a bounded target selection. Both options test failure tolerance. Only one respects the constraint that production must keep serving traffic.
The tell is a quantity or a scope qualifier in the scenario — "one instance," "a single AZ," "without customer impact" — that the distractor does not honor. On Mock Exam 1 this pattern appeared in the chaos engineering and change management questions, where the difference between a controlled experiment and an uncontrolled outage was the presence of stop conditions tied to alarms.
11. The Answer That Fixes the Symptom
When a scenario describes a problem, some options address the observable symptom rather than the cause. A DynamoDB table is throttling and one option proposes increasing the table's provisioned capacity. If the throttling is caused by a low-cardinality partition key concentrating writes onto a few partitions, raising table-level capacity does not help, because the limit being hit is per-partition. The correct answer changes the key design. The distractor is attractive because it is the first thing an operator would try.
The tell is that the option scales a resource rather than changing a design. Scaling is the right answer when the constraint is genuinely capacity; it is the wrong answer when the constraint is distribution, cardinality, or a hard per-unit limit. The exam tests this distinction most often with DynamoDB partition keys, Lambda concurrency, and Kinesis shard counts.
12. The Option That Requires a Capability the Service Lacks
Distinct from pattern seven, this one is about a capability that exists in a sibling service. The scenario needs cross-region writes with conflict resolution and one option proposes Aurora Global Database. Aurora Global Database does support multi-region replication, but the primary region is the only writer in the standard configuration; multi-active writes are a different feature with different constraints. The correct answer for multi-region multi-active writes is DynamoDB Global Tables with last-writer-wins resolution. The distractor borrows the sibling's headline capability.
The tell is a requirement for concurrent writes in more than one region. Any relational option should be scrutinized hard at that point, because relational multi-region write patterns are the exception rather than the rule on this exam. The same borrowing happens with ElastiCache Redis versus Memcached (replication), with ALB versus NLB (static IPs), and with S3 replication versus S3 versioning (deletion protection).
13. The Correct Mechanism With the Wrong Trigger
This pattern gets the service right and the event wrong. A scenario asks how to react when an object lands in S3 and one option proposes a CloudWatch alarm on a bucket metric. CloudWatch is the right family of service for monitoring, but a bucket metric alarm is a threshold on aggregate behavior, not a per-object event. The correct answer is an S3 event notification to Lambda, SQS, or EventBridge. The distractor is monitoring where the requirement is event handling.
The tell is a word like "when," "on arrival," "immediately after," or "per object." Those words describe events, and events are handled by event sources, not by metric thresholds. The inverse also appears: a scenario asks for a sustained condition to be detected and one option proposes an event notification, when the requirement is a threshold over time and the correct answer is an alarm. On Mock Exam 1 this fork showed up in the observability questions, where subscription filters, metric filters, and alarms were all offered for the same log-processing requirement.
14. The Answer That Works Only in the Management Account
The final pattern is a governance trap. Some options describe a control that would work perfectly if applied in the AWS Organizations management account, and the scenario has explicitly placed the workload somewhere else. The management account is immune to SCPs, so an SCP-based control described as protecting the management account is incoherent. Conversely, an option that proposes running a workload in the management account to simplify permissions is wrong on best practice, because the management account should hold no workloads.
The tell is any mention of the management account, the root user, or the organization's root OU. These are the places where the normal rules invert, and the exam uses them to test whether you know the exceptions. On Mock Exam 1 this pattern appeared in the multi-account governance questions, where the correct answer consistently kept the management account empty and pushed enforcement into OUs via SCPs and Control Tower guardrails.
Hands-On Lab: Build the Weak-Spot Ledger (60 min)
Open Mock Exam 1 and work through all 75 questions in order, but do not re-answer them. Instead, build a ledger. For each question, record four fields: the question number, the domain tag, your outcome (wrong, right-by-elimination, right-by-luck, or right-and-confident), and the pattern number from the catalog above that best describes the distractor that nearly caught you or did catch you. The pattern number is the field that matters most, because it converts 75 individual mistakes into a distribution across fourteen recurring techniques.
For every question where your outcome was wrong or right-by-elimination, write the four sentences described earlier. Sentence one: why the correct answer is correct, in your own words. Sentences two through four: for each distractor, the specific scenario in which that option would be the right answer. If you cannot construct such a scenario for a distractor, that is itself a finding — it means you do not yet understand what the service is for, and that topic goes on the review list regardless of whether you got the question right.
When the ledger is complete, produce two summaries. The first is a domain histogram: how many misses fall into each of the four exam domains. The second is a pattern histogram: how many misses fall into each of the fourteen patterns. The domain histogram tells you what to study. The pattern histogram tells you how you are being fooled, which is a different and often more actionable piece of information. A candidate who misses ten questions across four domains but eight of them are pattern one has a scoping problem, not a content problem, and the fix is different.
Finally, write a one-page cheat sheet containing only the pattern tells — the phrases and scope words that reliably distinguish the correct answer from each distractor family. Keep it to one page. This sheet is the artifact you will extend after Mock Exam 2 and the one you will re-read the morning of the exam, so it should contain triggers rather than explanations. "Across all accounts" means SCP. "Per object" means event notification. "Minimal downtime" plus a database means DMS with CDC. Those three lines are worth more on exam day than a page of service descriptions.
Drill: Fifteen Questions Built From These Patterns
Each question below is constructed around one of the fourteen patterns. The tempting wrong answer is deliberately present as an option. Answer before revealing, and when you reveal, name the pattern before reading the explanation.
Q1. A company wants to guarantee that no account in its organization can ever launch resources in an unapproved region, even if an account administrator attaches a policy that allows it. Which control enforces this?
Q2. A team must migrate a 4 TB on-premises Oracle database to Aurora PostgreSQL with under five minutes of downtime and must keep the target current until cutover. Which combination is required?
Q3. A healthcare provider must keep all patient data within its home country. It wants a highly available, low-latency application for users in that country. Which design satisfies the requirement?
Q4. A company needs its standby region to take over within seconds of a regional failure, with no human decision in the loop. Which approach meets this?
Q5. A workload has an RTO of 15 minutes and an RPO of 5 minutes. The business wants the lowest standing infrastructure cost that still meets those targets. Which DR strategy fits?
Q6. A small internal reporting application runs on a single EC2 instance and is used by twelve employees during business hours. The team wants high availability with minimal operational overhead. What should they implement?
Q7. A company wants to expose an internal microservice to consumers in other accounts without VPC peering and without worrying about overlapping CIDR ranges. Which mechanism should it use?
Q8. A security team must block traffic from a specific external CIDR range before it reaches any instance in a subnet, and the rule must apply to every instance in that subnet including ones launched later. Where should the rule live?
Q9. A company must rehost 300 physical and virtual servers to EC2 with minimal downtime and minimal application change. Which service should it use?
Q10. A team wants to validate that its production service survives the loss of a single EC2 instance, without risking customer impact. What should it do?
Q11. A DynamoDB table is throttling writes during peak hours. The table's provisioned write capacity is well above the observed write volume, and the partition key is a status field with six possible values. What should be changed?
Q12. A global gaming application needs users in three regions to read and write the same player state with single-digit-millisecond latency, accepting last-writer-wins semantics. Which data store fits?
Q13. A company needs to run a validation Lambda every time a new object is uploaded to a specific S3 prefix. What should it configure?
Q14. A company wants to ensure that its log-archive account cannot have its CloudTrail trail deleted by anyone, including the account's own administrators. Where should the protection be applied?
Q15. A company is migrating 200 TB of historical data from a data center with a 200 Mbps uplink, plus roughly 40 GB of daily changes, and needs the cutover within six weeks. Which approach is most appropriate?
Preview: Turning the Ledger Into a Study Plan
The ledger you built today tells you which patterns fooled you and which domains the misses came from, but it does not yet tell you what to do about it. That gap is the open question. A domain histogram showing eight misses in multi-account governance could mean you do not understand SCPs, or it could mean you understand SCPs perfectly and keep falling for pattern one's scope inversion when the question is phrased around organizational units. Those two diagnoses lead to completely different study sessions, and picking the wrong one wastes a day you cannot spare.
Tomorrow's deep review targets Domain 1 specifically — Organizations, Transit Gateway, Direct Connect, and the multi-account governance material from Weeks 1 and 2 — and the point of scoping it to one domain is to test whether the misses were content gaps or pattern gaps. If re-doing the Week 1 and 2 questions after today's pattern work produces a large jump, the problem was technique. If it does not, the problem is the material, and the review needs to go deeper than re-reading summaries.