Day 61 of 70 · Week 9
Day 61 / 70 Week 9 of 14 Phase 5: Practice Exams & Exam Technique

Full-Length Mock Exam 2 — 75 Questions Timed

🕑 ~60 min read · 2 services covered
Tutorials Dojo Exam Simulation

Recap

Day 60 was a targeted pass over Weeks 3-6 — Aurora, DynamoDB, FIS, Route 53 ARC — aimed squarely at the Domain 2 weak areas that Mock Exam 1's distractor analysis surfaced. That review was deliberate and narrow: you re-read the mechanisms behind the questions you missed, then re-answered them with the reasoning written out rather than guessed. The limitation of that work is that it happened at low speed, with notes open, and with the option to stop and think. None of those conditions exist on the real exam.

Today tests whether the same material is retrievable under time pressure, mixed with everything else in the curriculum, and without the ability to look anything up. The score matters less than the pattern of misses — but you only get a trustworthy pattern if you sit the full 180 minutes honestly.

Sitting Protocol

This is a 75-question, 180-minute sitting. That is 2.4 minutes per question on average, and the average is misleading: the SAP-C02 question mix is not uniform. A meaningful share of questions are short direct-knowledge checks that should take 30-45 seconds, which buys time for the long multi-paragraph scenarios that can legitimately consume four or five minutes each. If you spend 2.4 minutes on every question in order, you will run out of time on the scenarios at the end. The pacing instinct you are building today is to recognize quickly which kind of question you are looking at and spend accordingly.

The mechanics of the sitting matter as much as the content. Set a single 180-minute timer and do not pause it. Do not open documentation, do not search for a service limit, do not check an answer after each question. The Reveal Answer buttons on each card exist so you can self-check, but using them mid-sitting converts this into a study session and destroys the measurement. Answer all 75 first, then come back and reveal. If you genuinely cannot decide between two options, pick one, note the question number on paper, and move on — that is exactly what the flag-and-review feature on the real exam is for, and the discipline of deferring a hard question rather than burning four minutes on it is a skill worth rehearsing.

There is a second reason not to stop early. Exam stamina is real and it is trainable. The last twenty questions of a 180-minute sitting feel different from the first twenty — attention narrows, and the temptation to skim a long scenario and pattern-match on a keyword grows. That degradation is what produces the "I knew this and still got it wrong" misses. Sitting the full duration, even when you are confident you have passed, is the only way to find out where your attention actually breaks down.

Finally, treat the environment as part of the simulation. One sitting, no interruptions, no second monitor with notes, no phone. If you would not have it available in a Pearson VUE testing room or through OnVUE proctoring, do not have it available now. The point of Mock Exam 2 is not to learn anything new — it is to produce a clean, honest data point that Day 62 can act on.

The Exam — 75 Questions

Answer all 75 before revealing any answer. Questions span the full curriculum through Day 60: multi-account governance, hybrid networking, compute and containers, databases and storage, observability and SRE, disaster recovery, migration, and cost optimization.

Q1. A company is building a new AWS Organization and wants a dedicated account that aggregates CloudTrail logs from every member account. Workload teams must not be able to disable or delete the logging configuration. Where should this account be placed?

A. In the management account, since it already has the broadest permissions
B. In a dedicated Security OU protected by an SCP that denies modification of logging resources
C. Inside the Workloads/Prod OU so it is close to the accounts it audits
D. In a standalone account outside the Organization to isolate it
Correct answer: B. Log-archive and audit accounts belong in a dedicated Security OU with SCPs that deny deletion or modification of logging resources, keeping them isolated from workload OUs and from the SCP-immune management account.

Q2. A developer's IAM policy grants s3:*. An SCP attached to their OU contains an explicit Deny for s3:DeleteBucket. The developer calls DeleteBucket on a bucket they own. What is the result?

A. The call succeeds because the IAM policy grants the action
B. The call is denied — an explicit Deny in an SCP always overrides an Allow
C. The call succeeds only if the bucket policy also allows it
D. The call succeeds because SCPs do not apply to IAM users
Correct answer: B. Effective permissions are the intersection of IAM and SCPs, and an explicit Deny in either always wins over any Allow.

Q3. An organization wants to restrict all member accounts to two approved AWS Regions, but the first version of the SCP broke IAM and Route 53 operations. What is the most likely cause?

A. The SCP was attached to the wrong OU
B. The region-restriction SCP did not exempt global services such as IAM, Route 53, CloudFront, and Support
C. SCPs cannot restrict Regions at all
D. The management account needs the SCP attached first
Correct answer: B. Region-restriction SCPs must exempt global services, whose endpoints live outside any single Region, or account operations break.

Q4. A company wants engineers to authenticate once against corporate Okta and then assume the appropriate role in any of 40 AWS accounts, with no per-account IAM users. Which solution meets this?

A. IAM users created per engineer in each account, federated to Okta
B. IAM Identity Center with SAML federation from Okta and permission sets assigned to groups
C. A shared root-account access key distributed to engineers
D. SCPs alone, with no identity layer
Correct answer: B. IAM Identity Center is purpose-built for centralized SSO across an Organization, provisioning short-lived federated roles per account instead of long-lived IAM users.

Q5. A delegated admin role is allowed to create IAM roles for developers. Security wants to guarantee the delegate can never create a role with AdministratorAccess. What is the standard control?

A. Attach a Deny statement to every developer role after creation
B. Require a permission boundary on every role the delegate creates, enforced by a condition on iam:PermissionsBoundary
C. Remove iam:CreateRole from the delegate entirely
D. Enforce MFA on the delegate's console login
Correct answer: B. A mandatory permission boundary caps the maximum permissions of any role the delegate creates, preventing privilege escalation without removing their ability to work.

Q6. A central network account owns a VPC. Three application accounts need to launch EC2 instances into that VPC's private subnets without owning the VPC or managing its routing. What should be used?

A. VPC peering between the central VPC and each application account
B. AWS RAM subnet sharing from the central account to the application accounts
C. A Transit Gateway with a separate VPC in each application account
D. Copying the VPC configuration into each application account
Correct answer: B. RAM subnet sharing lets participant accounts launch resources into subnets owned by a central VPC, avoiding per-account VPCs and peering meshes.

Q7. A company wants automated account provisioning with a baseline of guardrails, plus the ability to layer custom Terraform-driven account customizations on top. Which combination fits?

A. AWS Organizations alone with manual account creation
B. AWS Control Tower for the landing zone and guardrails, with Account Factory for Terraform for pipeline-driven provisioning and customization
C. IAM Identity Center with permission sets per account
D. A single shared account with IAM roles per team
Correct answer: B. Control Tower automates the landing zone and guardrails; AFT extends it with pipeline-driven account provisioning and customizations for Terraform-standardized teams.

Q8. Dev and Prod VPCs both need to reach a Shared-Services VPC, but must never reach each other. How should Transit Gateway route tables be designed?

A. One flat TGW route table with all attachments propagating into it
B. Separate TGW route tables for Dev and Prod, each propagating only Shared-Services routes, with no Dev-to-Prod propagation
C. VPC peering directly between Dev and Prod with security groups blocking traffic
D. A single route table with a blackhole route for the Prod CIDR
Correct answer: B. TGW route table segmentation is the standard isolation mechanism: each spoke's route table propagates only the routes it should see.

Q9. After creating a Transit Gateway peering attachment between two Regions, spoke VPCs still cannot reach each other. What is the most likely cause?

A. TGW peering does not support cross-Region traffic
B. Peering attachments do not support route propagation — static routes must be added to each TGW route table
C. The TGWs are in different Availability Zones
D. Security groups block inter-Region traffic by default
Correct answer: B. Unlike VPC and TGW attachments, TGW peering attachments require manually created static routes in each TGW route table.

Q10. A company wants all internet-bound traffic from a dozen spoke VPCs inspected by a single AWS Network Firewall deployment. What is the standard architecture?

A. Deploy Network Firewall independently in every spoke VPC
B. A centralized inspection VPC attached to Transit Gateway, with spoke route tables directing 0.0.0.0/0 to the TGW
C. NACLs on each spoke subnet configured to inspect traffic
D. A NAT Gateway per spoke with firewall rules attached
Correct answer: B. The centralized inspection VPC pattern routes all spoke egress through TGW into a shared Network Firewall, avoiding per-VPC duplication and cost.

Q11. A mission-critical workload requires the highest-resiliency Direct Connect design. What should be provisioned?

A. A single 10 Gbps DX connection with a VPN backup
B. Two DX connections at two different DX locations, terminating on separate devices, with BGP failover and a VPN backup
C. Two identical DX connections at the same DX location
D. A Public VIF only, since it is cheaper
Correct answer: B. AWS's DX resiliency model requires diversity across locations and devices with BGP failover; a VPN backup covers the rare case both DX paths fail.

Q12. On-premises servers need to resolve names in a private Route 53 hosted zone. What must be configured?

A. A Route 53 Resolver outbound endpoint
B. A Route 53 Resolver inbound endpoint, with on-prem DNS forwarding queries to it
C. A public hosted zone with the same records
D. A NAT Gateway with DNS forwarding enabled
Correct answer: B. Inbound endpoints expose AWS private DNS to on-prem resolvers; outbound endpoints do the reverse direction.

Q13. Two companies both use 10.0.0.0/16. One needs to consume a specific API hosted in the other's VPC. Which connectivity option works despite the overlap?

A. VPC peering
B. Transit Gateway peering
C. AWS PrivateLink with an endpoint service and interface endpoint
D. Direct Connect with a private VIF
Correct answer: C. PrivateLink requires only ENI-level connectivity in the consumer VPC and never merges route tables or CIDRs, so overlapping ranges are not a problem.

Q14. A team needs to expose one internal microservice to 30 consumer accounts without giving those accounts any network-level reachability to the rest of the VPC. What is the right choice?

A. Transit Gateway with a shared route table
B. PrivateLink endpoint service consumed via interface endpoints
C. VPC peering with restrictive security groups
D. A public ALB with IP allowlisting
Correct answer: B. PrivateLink is service-level exposure: consumers reach exactly one service and nothing else in the provider VPC.

Q15. Which statement correctly distinguishes Gateway endpoints from Interface endpoints?

A. Gateway endpoints are ENI-backed and billed hourly; interface endpoints are free
B. Gateway endpoints support only S3 and DynamoDB, use route table entries, and are free; interface endpoints are ENI-backed and billed
C. Both are ENI-backed and billed identically
D. Gateway endpoints work for any AWS service
Correct answer: B. Gateway endpoints exist only for S3 and DynamoDB, are implemented as route table entries, and carry no hourly charge; interface endpoints are ENI-backed and billed.

Q16. An ECS Fargate service uses awsvpc network mode. What does this give each task?

A. A shared host network namespace with port mapping
B. Its own ENI, private IP, and security group
C. A public IP by default
D. Access to the underlying EC2 host's instance profile
Correct answer: B. awsvpc mode gives every task first-class networking — its own ENI, private IP, and security group — enabling per-task security instead of shared host rules.

Q17. A workload requires a DaemonSet on every node for log collection. Which EKS compute option should be avoided?

A. Managed node groups
B. Self-managed EC2 node groups
C. EKS Fargate profiles
D. Karpenter-provisioned nodes
Correct answer: C. Fargate pods run in isolated micro-VMs with no shared node, so DaemonSets — which require a persistent per-node agent — are not supported.

Q18. An application takes four minutes to bootstrap before it can serve traffic, causing scale-out to lag demand spikes. What reduces this latency?

A. Increase the ASG cooldown period
B. Use a warm pool of pre-initialized stopped instances
C. Switch the ASG to Spot Instances
D. Add a lifecycle hook on launch
Correct answer: B. Warm pools keep instances pre-initialized so scale-out promotes them in seconds instead of re-running the full bootstrap sequence.

Q19. An instance must drain in-flight connections and upload final logs to S3 before termination. What ASG feature enables this?

A. A launch lifecycle hook
B. A termination lifecycle hook that holds the instance in Terminating:Wait
C. A scheduled scaling action
D. Instance protection
Correct answer: B. Termination lifecycle hooks pause the instance in Terminating:Wait so drain and cleanup scripts can complete before the instance is destroyed.

Q20. A team wants to shift 10% of production traffic to a new task set for a canary release, using only ALB features. What should they configure?

A. Sticky sessions on the listener
B. Weighted target groups on a single listener rule
C. Cross-zone load balancing
D. Connection draining with a long timeout
Correct answer: B. Weighted target groups let one routing rule split traffic by percentage across two target groups — the ALB-native canary mechanism.

Q21. A Lambda function reading from Kinesis is overwhelming a downstream RDS instance with connections during spikes. What limits this safely?

A. Increase the Lambda timeout
B. Set reserved concurrency on the function to cap concurrent executions
C. Increase the Kinesis shard count
D. Move RDS to Multi-AZ
Correct answer: B. Reserved concurrency caps how many instances of the function run simultaneously, directly bounding concurrent downstream connections.

Q22. A latency-sensitive function suffers cold starts during traffic ramps. Which feature eliminates them?

A. Reserved concurrency
B. Provisioned concurrency
C. Increasing the memory allocation
D. Enabling X-Ray tracing
Correct answer: B. Provisioned concurrency pre-warms execution environments so invocations are served without initialization latency.

Q23. A high-volume IoT pipeline runs millions of short workflow executions per day and can tolerate at-least-once semantics. Which Step Functions type fits?

A. Standard Workflows
B. Express Workflows
C. Both are priced identically
D. Neither — use SQS only
Correct answer: B. Express Workflows are priced per execution and duration for high-volume, short-duration workloads and provide at-least-once semantics.

Q24. A team has deep existing Kubernetes tooling and a multi-cloud portability requirement. Which AWS compute platform best fits?

A. ECS with the EC2 launch type
B. Amazon EKS
C. AWS Lambda
D. AWS Batch on Fargate
Correct answer: B. EKS runs standard Kubernetes, preserving existing tooling and manifests and easing multi-cloud portability.

Q25. A global application needs a secondary Region readable with sub-second replication lag and promotable to primary in under a minute during a Regional outage. Which database fits?

A. RDS Multi-AZ with a cross-Region read replica
B. Aurora Global Database
C. DynamoDB Global Tables
D. RDS with asynchronous read replicas
Correct answer: B. Aurora Global Database replicates at the storage layer with typical sub-second lag and supports managed failover promoting the secondary Region in under a minute.

Q26. A team needs to upgrade RDS MySQL from 5.7 to 8.0 with minimal risk and a fast rollback path. What should they use?

A. An in-place major version upgrade during a maintenance window
B. RDS Blue/Green Deployments, validating the green environment before switchover
C. Promoting a read replica
D. A Multi-AZ failover
Correct answer: B. Blue/Green Deployments create a fully replicated green environment on the new version, validated before a fast, low-risk switchover.

Q27. Which statement about RDS Multi-AZ is correct?

A. It scales read throughput by serving reads from the standby
B. It provides HA via a synchronous standby with automatic failover on the same endpoint, but does not scale reads
C. It replicates asynchronously and can lose transactions on failover
D. It requires the application to change its connection string on failover
Correct answer: B. Multi-AZ is for availability: synchronous standby, automatic failover, same endpoint — and the standby does not serve read traffic.

Q28. A DynamoDB table uses a status attribute with five possible values as its partition key and throttles under high write volume despite ample table-level capacity. Why?

A. The table needs Global Tables enabled
B. Low-cardinality partition keys create hot partitions, and each partition has its own throughput ceiling
C. On-demand capacity mode is not enabled
D. DynamoDB does not support high write volume
Correct answer: B. Each partition has its own throughput ceiling; a key with only five distinct values concentrates writes onto a handful of partitions.

Q29. A gaming leaderboard needs microsecond read latency for a small set of extremely hot items. What should sit in front of DynamoDB?

A. A self-managed ElastiCache for Redis cluster
B. Amazon DAX
C. CloudFront caching of API responses
D. DynamoDB Accelerator is not a real service
Correct answer: B. DAX is a managed, DynamoDB-API-compatible in-memory cache purpose-built to cut read latency for hot items without application-level cache logic.

Q30. An application needs single-digit-millisecond reads and writes at massive, unpredictable scale with a flexible schema, and multiple Regions actively writing. What fits best?

A. Aurora Global Database
B. DynamoDB Global Tables
C. RDS with cross-Region read replicas
D. ElastiCache as the system of record
Correct answer: B. DynamoDB Global Tables provide multi-active, multi-Region writes at single-digit-millisecond latency with a flexible schema.

Q31. An object is rarely accessed, a 12-hour retrieval time is acceptable, and it must survive the loss of an entire Availability Zone at the lowest possible storage cost. Which class fits?

A. S3 One Zone-IA
B. S3 Glacier Deep Archive
C. S3 Glacier Flexible Retrieval (Bulk)
D. S3 Standard-IA
Correct answer: B. Glacier Deep Archive is the lowest-cost class, is replicated across multiple AZs (unlike One Zone-IA), and supports retrieval times up to 12 hours.

Q32. A session store must survive a node failure without losing data and support automatic failover. Which caching engine and configuration fits?

A. Memcached with auto discovery
B. Redis with cluster mode enabled and replicas per shard
C. Memcached with multiple nodes
D. Redis without replicas
Correct answer: B. Only Redis supports replication and automatic failover; Memcached has no replication, so node failure means data loss for those keys.

Q33. On-call engineers are fatigued by alarms firing on isolated latency spikes that self-resolve. What reduces noise while still catching real incidents?

A. Delete the latency alarm
B. A composite alarm requiring both the latency alarm and the error-rate alarm to be in ALARM
C. Lower the alarm threshold
D. Increase the evaluation period to 24 hours
Correct answer: B. Composite alarms require correlated signals before paging, cutting single-metric false positives while preserving sensitivity to genuine multi-symptom incidents.

Q34. Internal CloudWatch metrics show healthy servers, but customers report the login page is broken. What monitoring gap does this reveal?

A. Missing X-Ray tracing
B. No outside-in synthetic monitoring of the actual user flow
C. Missing VPC Flow Logs
D. Insufficient EC2 instance count
Correct answer: B. Server-side health metrics do not verify end-to-end user experience; Synthetics canaries probe from outside the infrastructure and catch failures invisible to internal metrics.

Q35. A microservices application has growing p99 latency, but it is unclear which of twelve services is the bottleneck. What pinpoints it?

A. CloudWatch Logs Insights alone
B. AWS X-Ray, using the service map to isolate the slow hop
C. VPC Flow Logs
D. AWS Config
Correct answer: B. X-Ray's distributed tracing and service map visualize per-hop latency across the full call chain, isolating the bottleneck that aggregate metrics cannot.

Q36. An organization wants every account's application logs centrally searchable in a dedicated logging account in near-real time. What is the mechanism?

A. Manually exporting logs nightly to S3
B. CloudWatch Logs subscription filters streaming to Kinesis Data Firehose in the central logging account
C. CloudTrail only
D. Increasing log retention in each account
Correct answer: B. Subscription filters push log events in near-real time to a destination such as Kinesis Data Firehose in a centralized account, enabling org-wide aggregation.

Q37. A team wants to test EC2 instance failure in production without risking an uncontrolled outage. What FIS feature guarantees the experiment halts if things go wrong?

A. IAM permission boundaries
B. Stop conditions tied to CloudWatch alarms
C. Increasing the blast radius
D. Manual monitoring only
Correct answer: B. FIS stop conditions automatically abort a running experiment the moment a linked CloudWatch alarm enters ALARM state, capping the blast radius.

Q38. A team has documented DR runbooks but has never tested them under simulated failure. What is the recommended next step before relying on them?

A. Trust the documentation as-is
B. Run a Game Day using FIS to simulate the failure and validate the runbook and automated recovery
C. Increase backup frequency only
D. Skip testing to avoid production risk
Correct answer: B. Untested runbooks are unverified assumptions; a Game Day exercises the real failure mode against real infrastructure to confirm RTO/RPO targets are achievable.

Q39. An active-active application needs sub-second failover at the network layer when a Region's health checks fail, independent of DNS TTL and client caching. What should be used?

A. Route 53 latency-based routing alone
B. AWS Global Accelerator, using static anycast IPs and rerouting at the AWS network edge
C. CloudFront alone
D. A single-Region network load balancer
Correct answer: B. Global Accelerator uses anycast IPs and the AWS global network for near-instant failover, avoiding client-side DNS caching delays.

Q40. A workload can tolerate an RTO of 15 minutes and an RPO of 5 minutes, and the business wants to minimize standing infrastructure cost. Which DR pattern fits best?

A. Backup and Restore
B. Pilot Light
C. Multi-Site Active-Active
D. No DR strategy needed
Correct answer: B. Pilot Light keeps only core data continuously replicated and minimal infrastructure running, scaling up the rest on failover — matching a ~15-minute RTO at much lower cost than warm standby or active-active.

Q41. A critical financial system needs failover control that itself will not fail if an entire Region goes down, plus proof the standby Region is actually ready to serve traffic. What should be used?

A. Route 53 simple health-check failover only
B. Route 53 Application Recovery Controller with readiness checks and a routing control cluster
C. CloudWatch Alarms triggering a Lambda failover
D. Global Accelerator alone
Correct answer: B. ARC's routing control cluster is distributed across Regions and partitions for resilience of the failover mechanism itself, and readiness checks validate standby capacity before you rely on it.

Q42. You want most users routed to the AWS Region with the lowest network latency for them, automatically. Which Route 53 policy fits?

A. Weighted routing
B. Latency-based routing
C. Simple routing
D. Geolocation routing
Correct answer: B. Latency-based routing uses AWS latency measurements between users and Regions to route each request to the lowest-latency healthy endpoint.

Q43. A company needs ransomware-resilient backups that cannot be deleted even by a compromised admin account. What should they configure?

A. Standard EBS snapshots only
B. AWS Backup with cross-account copy into an isolated account, in a vault with Backup Vault Lock enabled
C. S3 versioning only
D. Increased snapshot frequency
Correct answer: B. Cross-account isolation prevents a compromised primary account from touching backups, and Vault Lock makes the retention policy immutable.

Q44. Which practice best exemplifies the Reliability pillar's failure management area?

A. Using the largest possible instance type
B. Automatically testing recovery procedures via Game Days and setting quantified RTO/RPO targets
C. Manually reviewing logs weekly
D. Avoiding all managed services
Correct answer: B. Failure management is about anticipating failure, testing recovery, and having quantified, validated RTO/RPO — not provisioning bigger resources.

Q45. A team manually SSHes into servers to apply emergency patches, occasionally causing configuration drift. Which Operational Excellence practice addresses this?

A. Increase server count
B. Perform operations as code using SSM Automation documents instead of manual SSH changes
C. Disable CloudTrail logging
D. Add more IAM users
Correct answer: B. Operations as code — codifying procedures such as SSM Automation documents — eliminates ad hoc manual changes and the drift they introduce.

Q46. A workload requires near-zero RTO and RPO, and budget is not the primary constraint. Which DR strategy and supporting services fit?

A. Backup and Restore with AWS Backup
B. Pilot Light with manual DNS updates
C. Multi-Site Active-Active with Route 53 ARC and DynamoDB Global Tables or Aurora Global Database
D. Warm standby without health checks
Correct answer: C. Near-zero RTO/RPO demands live traffic serving from multiple Regions with deterministic, tested failover control and multi-Region-write-capable data services.

Q47. A data center lease expires in six months, forcing a fast migration, but two legacy applications have unresolved software licensing blockers. What is the correct 7 Rs plan?

A. Refactor everything to serverless
B. Rehost the majority via MGN to meet the deadline, and Retain the two blocked applications until licensing is resolved
C. Repurchase all applications as SaaS
D. Retire every application
Correct answer: B. Under a tight deadline, Rehost is the fastest path for most applications; applications with real blockers should be explicitly Retained rather than forced into a rushed migration.

Q48. A migration team needs to map network dependencies between individual processes on each server before planning migration waves. What captures this?

A. Agentless Discovery Connector only
B. Agent-based discovery, which captures process-to-process network connections
C. AWS Config
D. CloudTrail
Correct answer: B. Agent-based discovery installs a lightweight agent per server and captures fine-grained, process-level network connections; agentless discovery only gives VM-level inventory and utilization.

Q49. A company needs to rehost 200 on-premises VMs to EC2 as fast as possible with minimal application changes and minimal cutover downtime. What should they use?

A. AWS DataSync
B. AWS Application Migration Service (MGN)
C. AWS Schema Conversion Tool
D. AWS DMS
Correct answer: B. MGN is purpose-built for server rehost: continuous replication lets you test extensively and cut over with minutes of downtime, without re-architecting the application.

Q50. SCT reports a 92% automatic conversion rate for an Oracle-to-PostgreSQL migration. What does this mean for the remaining 8%?

A. The migration is essentially complete and can proceed unattended
B. Complex objects such as certain stored procedures and functions could not be auto-converted and need manual developer remediation
C. SCT failed and DMS cannot be used
D. 8% of the data will be lost during migration
Correct answer: B. SCT's conversion percentage reflects schema and code objects only; a high percentage still commonly leaves complex procedural logic that must be manually rewritten.

Q51. A company needs to continuously sync a large on-premises NFS file share into Amazon EFS on a schedule, without writing custom scripts. What should they use?

A. AWS DMS
B. AWS DataSync
C. AWS Snowball Edge
D. AWS Storage Gateway File Gateway
Correct answer: B. DataSync is purpose-built for automated, scheduled, validated file and object transfer between on-premises file systems and AWS storage services such as EFS, FSx, and S3.

Q52. An enterprise wants to eliminate its physical backup tape infrastructure while keeping existing backup software unchanged. What should they deploy?

A. File Gateway
B. Volume Gateway in stored mode
C. Tape Gateway, presenting a virtual tape library
D. AWS Backup only
Correct answer: C. Tape Gateway presents a virtual tape library interface compatible with existing backup software, letting you retire physical tape hardware without changing backup workflows.

Q53. A company must migrate 2 PB of data from a facility with no viable network uplink for bulk transfer. What is the appropriate approach?

A. AWS DataSync over the internet
B. Direct Connect provisioned overnight
C. Multiple AWS Snowball Edge Storage Optimized devices, or Snowmobile for the full 2 PB in one engagement
D. AWS Storage Gateway
Correct answer: C. At petabyte scale with no adequate network path, physical offline transfer via Snow Family devices is the standard, cost-effective solution.

Q54. A hospital must keep patient data physically on-premises for regulatory reasons while still using native AWS APIs such as EC2, EBS, and RDS for its applications. What should they deploy?

A. AWS Local Zones
B. AWS Wavelength
C. AWS Outposts
D. A standard AWS Region with encryption at rest
Correct answer: C. Outposts physically places AWS-managed infrastructure inside the customer's own data center, satisfying strict data-residency requirements while retaining native AWS service APIs.

Q55. A team wants to move VMware VMs to AWS infrastructure fastest, keeping the exact same hypervisor-level configuration and VMware management tools, with no conversion. Which strategy applies?

A. Rehost to native EC2 using MGN
B. Relocate to VMware Cloud on AWS
C. Replatform using the Schema Conversion Tool
D. Repurchase as SaaS
Correct answer: B. Relocate via VMware Cloud on AWS is the only 7 Rs strategy that moves the VM without converting it out of the VMware format.

Q56. A migration must move 300 TB of historical data plus ongoing daily deltas of about 50 GB, over a link capped at 500 Mbps. What is the recommended approach?

A. Transfer everything, including historical data, over the 500 Mbps link
B. Use Snowball Edge for the 300 TB bulk historical transfer, then DMS CDC or DataSync over the network link for ongoing deltas
C. Wait for the network link to be upgraded before starting
D. Use Snowmobile for the entire migration
Correct answer: B. The hybrid pattern — offline bulk transfer for the large historical dataset, then network-based CDC for the small ongoing delta — is the standard approach to large migrations over constrained links.

Q57. A company runs a steady-state, predictable production fleet but wants maximum flexibility to change instance families and Regions over the commitment period. What should they buy?

A. EC2 Instance Savings Plans
B. Compute Savings Plans
C. Standard Reserved Instances
D. Spot Instances
Correct answer: B. Compute Savings Plans apply across any instance family, Region, and OS, and even cover Fargate and Lambda usage, trading a slightly lower discount for maximum flexibility.

Q58. A company suspects many EC2 instances are oversized relative to actual utilization but does not know which ones. What AWS service directly recommends right-sizing changes?

A. AWS Config
B. AWS Compute Optimizer
C. AWS Trusted Advisor cost checks only
D. CloudWatch Alarms
Correct answer: B. Compute Optimizer analyzes historical utilization and provides specific instance-type right-sizing recommendations with projected savings.

Q59. Finance wants AWS spend broken out per business unit, but resources are inconsistently tagged today. What should be enforced first?

A. Enable Cost Explorer only
B. Enforce a mandatory tagging policy via SCP or Config rules requiring cost-allocation tags at resource creation, then activate those tags for cost allocation reporting
C. Use a single shared account for all business units
D. Manually track spend in a spreadsheet
Correct answer: B. Cost allocation reporting is only as good as tag hygiene; enforcing mandatory tags at creation time is the prerequisite before per-business-unit reports become meaningful.

Q60. A workload is fault-tolerant and interruptible, and the team wants the deepest possible compute discount with graceful handling of interruptions. What should they use?

A. On-Demand Instances
B. Spot Instances in a mixed-instance ASG, with a Spot interruption handler
C. Standard Reserved Instances
D. Dedicated Hosts
Correct answer: B. Spot offers the deepest discount for interruptible workloads; a mixed-instance ASG diversifies capacity pools and the interruption handler drains work during the two-minute notice.

Q61. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and ongoing replication until cutover. Which combination of tools is required?

A. AWS DataSync for the schema and AWS Backup for the data
B. AWS SCT to convert the schema and code, plus AWS DMS with full load and CDC to move and continuously replicate the data
C. AWS MGN to replicate the database server, then a manual export
D. Snowball Edge for the data and manual schema rewriting
Correct answer: B. Heterogeneous engine migrations pair SCT for schema and procedural code conversion with DMS for the data itself, using full load plus CDC to keep the target current until cutover.

Q62. A DMS task is configured for Full Load only against a production database that cannot be taken offline. What is the problem?

A. Full Load is slower than CDC and should always be avoided
B. Full Load takes a point-in-time snapshot with no mechanism to capture changes during the copy, so the target is stale by the time the load finishes
C. Full Load requires the target to be read-only
D. Full Load cannot be used with heterogeneous migrations
Correct answer: B. Full Load alone has no change capture, so writes during the copy are lost and the target is already stale at completion — implying a maintenance window proportional to dataset size.

Q63. A company wants a single pane of glass tracking migration progress across discovery, database migration, and server migration tools. What provides this?

A. AWS Migration Hub
B. AWS Config
C. AWS Trusted Advisor
D. AWS Cost Explorer
Correct answer: A. Migration Hub centrally tracks migration progress across the AWS migration toolset, giving one view of application status across waves.

Q64. A workload needs single-digit-millisecond latency to on-premises industrial control systems inside a manufacturing plant, and the company is willing to own AWS-managed hardware on site. What fits?

A. A Local Zone in the nearest metro
B. AWS Outposts in the plant
C. AWS Wavelength at the telco edge
D. A standard Region with Global Accelerator
Correct answer: B. Outposts places AWS-managed infrastructure inside the customer's facility, delivering the lowest latency to on-premises systems while retaining native AWS APIs.

Q65. A company wants to reduce S3 storage cost for a large log archive with unpredictable access patterns, without manually tuning lifecycle transitions. Which class fits?

A. S3 Standard
B. S3 Intelligent-Tiering
C. S3 One Zone-IA
D. S3 Glacier Deep Archive
Correct answer: B. Intelligent-Tiering automatically moves objects between access tiers based on observed access patterns, removing the need to guess at lifecycle transition points.

Q66. A company needs objects replicated to a second Region for DR, and the replication must be asynchronous and automatic for new objects. What should they configure?

A. S3 Same-Region Replication
B. S3 Cross-Region Replication with versioning enabled on source and destination
C. A nightly AWS Backup job for the bucket
D. A lifecycle rule transitioning objects to Glacier
Correct answer: B. CRR asynchronously replicates new objects to a bucket in another Region and requires versioning on both source and destination buckets.

Q67. A team wants to detect when a production resource is created without the required Environment tag, and prevent it. What is the most direct control?

A. A CloudWatch alarm on tag metrics
B. An SCP or AWS Config rule that denies resource creation without the required tag
C. A weekly manual audit
D. Enabling Cost Explorer
Correct answer: B. Enforcing tag requirements at creation time via SCP conditions or Config rules prevents untagged resources from existing at all, rather than detecting them after the fact.

Q68. A company wants to forecast next quarter's AWS spend and get purchase recommendations for Savings Plans. Which service provides this?

A. AWS Budgets
B. AWS Cost Explorer
C. AWS Compute Optimizer
D. AWS Trusted Advisor
Correct answer: B. Cost Explorer visualizes and forecasts spend and surfaces Savings Plans and Reserved Instance purchase recommendations based on historical usage.

Q69. A team needs the most granular billing data available to feed a custom FinOps dashboard. What should they use?

A. AWS Budgets alerts
B. The Cost and Usage Report (CUR)
C. Cost Explorer's default monthly view
D. Trusted Advisor cost checks
Correct answer: B. The Cost and Usage Report provides the most granular billing data, including line-item detail suitable for custom BI and FinOps tooling.

Q70. A company wants to be alerted when forecasted spend for a project will exceed its monthly budget, before the overspend happens. What should they configure?

A. A CloudWatch billing alarm on actual spend only
B. An AWS Budget with a forecasted-spend alert threshold
C. A Trusted Advisor cost check
D. A Cost Explorer saved report
Correct answer: B. AWS Budgets supports forecasted-spend alerts, which fire before the threshold is actually crossed — unlike actual-spend alarms.

Q71. A company wants a single account to hold all backup copies, isolated so that a compromise of any workload account cannot delete them. What should they configure?

A. Backups in each workload account with S3 versioning
B. AWS Backup cross-account copy into a dedicated, isolated backup account with Vault Lock
C. EBS snapshots shared to the management account
D. A nightly export to on-premises tape
Correct answer: B. Cross-account copy into an isolated backup account removes the workload account's ability to delete backups, and Vault Lock makes retention immutable.

Q72. A team wants to validate that a standby Region can actually serve production traffic before declaring it a valid failover target. What should they configure?

A. A Route 53 health check on the primary Region only
B. Route 53 ARC readiness checks validating standby capacity and configuration
C. A CloudWatch dashboard for the standby Region
D. A manual quarterly review
Correct answer: B. ARC readiness checks continuously validate that the standby Region has the capacity and configuration required to take over, turning an assumption into a monitored fact.

Q73. A company wants to shift 5% of traffic to a canary deployment and automatically remove it from rotation if it starts failing. What combination should they use?

A. Weighted routing with a health check on the canary endpoint
B. Latency-based routing with a failover record
C. Simple routing with a long TTL
D. Geoproximity routing with a bias value
Correct answer: A. Weighted routing shifts a controlled percentage of traffic, and an attached health check automatically pulls the canary endpoint out of DNS responses when it fails.

Q74. A company needs to prove that its recovery procedures actually meet a 15-minute RTO, not just document them. What is the most direct way to establish this?

A. Increase backup frequency
B. Run a Game Day that simulates the failure and measures actual recovery time against the target
C. Add a second Availability Zone
D. Enable X-Ray tracing on the recovery path
Correct answer: B. Only an exercised failure produces a measured recovery time; a Game Day converts the documented RTO claim into an observed result.

Q75. A company is choosing between a warm standby and a pilot light for a workload with a 5-minute RTO requirement. Which is correct?

A. Pilot Light, because it is cheaper and always meets a 5-minute RTO
B. Warm Standby, because a scaled-down but fully running replica can be scaled up in minutes, whereas pilot light typically implies tens of minutes
C. Backup and Restore, because RTO does not depend on the DR pattern
D. Either, since both have identical RTO characteristics
Correct answer: B. Warm standby keeps a scaled-down but fully running replica, so failover is a scale-up measured in minutes; pilot light keeps only core data replicated and typically lands in the tens of minutes.

Scoring Guide

Count your correct answers out of 75 and divide by 75 to get a raw percentage. As a rule of thumb — not an official AWS figure — a raw score of roughly 72% or better is a reasonable proxy for exam-ready on SAP-C02, since the real exam is scaled and the passing threshold is not published. Anything below about 65% raw means the weak-domain list from this sitting should drive the next several days of study rather than being treated as noise.

Record two things before you close the page: the raw score, and the domain breakdown of your misses. The score tells you whether you are trending toward readiness; the breakdown tells you what to do about it. A 70% score concentrated in one domain is a very different situation from a 70% score spread evenly across all four, and only the breakdown distinguishes them.

Preview

You now have a raw score and a list of missed questions, and the list is the more valuable of the two. The open question is what to do with it: a miss can mean you did not know the fact, or that you knew it and the distractor pulled you off it, or that you ran out of time and guessed. Those three causes require completely different remediation, and a raw score cannot tell them apart.

Day 62 is the distractor analysis pass for this sitting. For every missed question — and every question you answered correctly by elimination rather than by knowing — you will write out why the correct option is right and why each distractor is wrong, then tag each miss by domain. That tagging is what turns today's score into a study plan.