Day 64 was a targeted deep review of cost optimization — Savings Plans versus Reserved Instances versus Spot, Compute Optimizer right-sizing recommendations, and the FinOps tagging and budget machinery that makes cost allocation meaningful. That review was deliberately narrow: it took the Domain 4 weak areas flagged by Mock Exam 2 and drilled them in isolation, with no time pressure and no penalty for pausing to look something up. Today removes both of those affordances. The material is the same material you have been studying for nine weeks, but the question is no longer whether you know it — it is whether you can retrieve it, under a clock, in the order the exam chooses to ask. That is a different skill, and it is the one this sitting is designed to measure.
Sitting Protocol
This is a full-length sitting: 75 questions in 180 minutes. That is an average budget of roughly 2.4 minutes per question, and the average is misleading in both directions. A short direct-knowledge question — which service provides a virtual tape library, which routing policy uses AWS latency measurements — should take you well under a minute, and banking that time is the entire point of answering it quickly rather than second-guessing. A four-sentence scenario describing a regulated workload with a stated RTO, a stated budget constraint, and three plausible-sounding distractors will legitimately consume three to four minutes. The pacing technique that survives contact with the real exam is to answer the fast questions fast, flag anything that needs a second pass, and never let a single hard question eat the time budget of three easy ones.
The conditions matter as much as the questions. Do not pause the clock. Do not open a browser tab to check a service limit. Do not stop at question 40 because you are tired and finish tomorrow — the fatigue curve is part of what you are training, and the last twenty questions of a real sitting are answered by a different, more depleted version of you than the first twenty. Do not check answers as you go, either. The Reveal Answer button on each card is there for the review pass, not the sitting pass; using it mid-exam converts a measurement into a study session and destroys the score's diagnostic value. Set a timer for 180 minutes, work straight through, and only then begin checking.
When you do check, resist the urge to grade yourself question by question in the order you answered them. Record the raw correct count first, then go back and mark which domain each miss belongs to — multi-account governance and networking, resilient architectures, migration and modernization, or cost control. The raw score tells you whether you are close; the domain distribution tells you what to do about it. A 58 out of 75 with all the misses clustered in migration tooling is a very different situation from a 58 with the misses scattered evenly, and only the second one suggests a broad knowledge problem rather than a specific gap.
The Exam — 75 Questions
Work through all 75 questions before revealing any answers. The questions span the full curriculum to this point: multi-account governance and SCP mechanics, hybrid networking and Transit Gateway design, compute and container platforms, the database and storage selection matrix, observability and chaos engineering, disaster recovery patterns, migration tooling, and cost optimization. Difficulty is mixed deliberately — most are multi-sentence scenarios, and a handful are short direct-knowledge checks that should take seconds.
Q1. A company's security team wants a dedicated AWS account that aggregates CloudTrail logs from every other account in the organization and cannot be altered by workload teams. Where should this account be placed?
A. Directly under the organization root, alongside the production OU
B. In a dedicated Security OU protected by SCPs that deny modification of logging resources
C. Inside the Workloads/Prod OU so it sits close to the accounts it audits
D. In the AWS Organizations management account
Correct answer: B. Log-archive and audit accounts belong in a dedicated Security OU guarded by SCPs that deny deletion or modification of logging resources, isolating them from workload OUs.
Q2. A developer holds an IAM policy granting s3:*, but the SCP attached to their OU contains an explicit Deny for s3:DeleteBucket. What happens when they call DeleteBucket?
A. It succeeds, because IAM policies take precedence over SCPs
B. It is denied — SCPs set the permission ceiling and an explicit Deny always wins
C. It succeeds only if the bucket policy also allows it
D. It succeeds only in the management account
Correct answer: B. Effective permissions are the intersection of IAM and SCP; an explicit Deny in either always overrides an Allow.
Q3. An organization wants engineers to authenticate once through corporate Okta and then assume the appropriate role in any of 40 AWS accounts, with no per-account IAM users. Which solution fits?
A. Create an IAM user per engineer in each account
B. IAM Identity Center with SAML federation from Okta and permission sets
C. Share a single root-account access key across the team
D. Rely on AWS Organizations SCPs alone
Correct answer: B. IAM Identity Center is purpose-built for centralized SSO across an Organization, provisioning short-lived federated roles instead of long-lived IAM users.
Q4. A delegated admin role can create IAM roles for developers. How do you prevent that role from creating a role with AdministratorAccess attached?
A. Attach a Deny statement to every developer role individually
B. Require a permission boundary on every role the delegated admin creates, capping maximum permissions
C. Remove iam:CreateRole from the delegated admin entirely
D. Enforce MFA on the delegated admin role
Correct answer: B. Enforcing a mandatory permission boundary via a condition requiring iam:PermissionsBoundary on CreateRole is the standard pattern for preventing privilege escalation by delegated admins.
Q5. A company wants every application account to launch resources into a common, centrally managed VPC without each account owning its own VPC. Which mechanism achieves this?
A. VPC peering between every pair of accounts
B. Share subnets from a central VPC using AWS Resource Access Manager
C. A Transit Gateway alone, with each account keeping its own VPC
D. Copy the VPC configuration manually into every account
Correct answer: B. RAM subnet sharing lets many accounts launch resources into subnets owned by a single central VPC, avoiding per-account VPCs and peering meshes.
Q6. Which combination best represents a mature multi-account governance baseline?
A. A single flat account with IAM users per team
B. Control Tower landing zone, OU-based SCPs, IAM Identity Center SSO, and RAM-shared networking
C. One AWS account per employee
D. SCPs only, with no account separation
Correct answer: B. Enterprise governance combines automated account provisioning, policy guardrails, centralized identity, and shared network plumbing.
Q7. Dev and Prod VPCs must both reach a Shared-Services VPC but must never reach each other. How should Transit Gateway route tables be designed?
A. A single flat TGW route table with all routes propagated
B. Separate TGW route tables for Dev and Prod that each propagate only Shared-Services routes
C. VPC peering directly between Dev and Prod
D. Security groups alone to block traffic between them
Correct answer: B. TGW route table segmentation is the standard way to isolate spokes while still allowing shared access to common services.
Q8. After creating a Transit Gateway peering attachment between two regions, spoke VPCs still cannot reach each other. What is most likely missing?
A. Route propagation is not supported on peering attachments — static routes must be added manually
B. The TGWs are in different Availability Zones
C. Peering does not support cross-region traffic at all
D. Security groups always block inter-region traffic by default
Correct answer: A. Unlike VPC and TGW attachments, TGW peering attachments require manually created static routes in each TGW route table.
Q9. What is the standard pattern for forcing all internet-bound traffic from many VPCs through a single AWS Network Firewall?
A. Deploy Network Firewall independently in every VPC
B. A centralized inspection VPC attached to Transit Gateway, with spoke route tables directing 0.0.0.0/0 to the TGW
C. Use only NACLs on each spoke subnet
D. Network Firewall cannot inspect cross-VPC traffic
Correct answer: B. The centralized inspection VPC pattern routes all spoke egress through TGW into a shared Network Firewall, avoiding per-VPC duplication and cost.
Q10. A company needs the highest-resiliency Direct Connect design for a mission-critical workload. What should they provision?
A. A single 10 Gbps DX connection
B. Two DX connections at two different DX locations, each terminating on separate devices, with BGP failover and a VPN backup
C. One DX connection plus a second identical connection at the same location
D. A Public VIF only, since it is cheaper
Correct answer: B. AWS's DX resiliency model requires diversity across locations and devices plus BGP failover; a VPN backup covers the rare case both DX paths fail.
Q11. On-premises servers need to resolve names in a private Route 53 hosted zone. What do you configure?
A. A Route 53 Resolver outbound endpoint
B. A Route 53 Resolver inbound endpoint, with on-prem DNS forwarding queries to it
C. A public hosted zone instead
D. NAT Gateway DNS forwarding
Correct answer: B. Inbound endpoints expose AWS private DNS to on-prem resolvers; outbound endpoints do the reverse.
Q12. Two companies with fully overlapping CIDR ranges (both 10.0.0.0/16) need one to consume a specific API hosted in the other's VPC. Which connectivity option works despite the overlap?
A. VPC peering
B. Transit Gateway peering
C. AWS PrivateLink with an Interface Endpoint and endpoint service
D. Direct Connect
Correct answer: C. PrivateLink requires only ENI-level connectivity in the consumer VPC and never merges route tables or CIDRs, so overlapping ranges are not a problem.
Q13. When should you choose PrivateLink over Transit Gateway for cross-account connectivity?
A. When you need full bidirectional network-level reachability between VPCs
B. When exposing a single specific service to many consumers without merging networks or worrying about CIDR overlap
C. When connecting on-premises networks to AWS
D. Never — TGW always replaces PrivateLink
Correct answer: B. PrivateLink is service-level exposure; TGW is network-level connectivity for broad multi-VPC and on-prem routing.
Q14. Why does Fargate's awsvpc network mode assign each task its own ENI?
A. To reduce cost
B. To give each task an isolated security group and IP, avoiding the port-mapping conflicts of bridge mode
C. It is required for CloudWatch Logs
D. To enable Spot pricing
Correct answer: B. awsvpc mode gives every task first-class networking — its own ENI, private IP, and security group — enabling per-task security instead of shared host rules.
Q15. A workload requires DaemonSets for log collection on every node. Which EKS compute option should you avoid?
A. Managed node groups
B. Self-managed EC2 node groups
C. EKS Fargate profiles — Fargate does not support DaemonSets
D. Cluster Autoscaler on EC2
Correct answer: C. Fargate pods run in isolated micro-VMs with no shared node, so DaemonSets, which require a persistent per-node agent, are not supported.
Q16. An application takes four minutes to bootstrap before it can serve traffic, causing scale-out to lag demand spikes. What reduces this latency?
A. Increase the ASG cooldown period
B. Use a warm pool of pre-initialized stopped instances so scale-out promotes them instead of booting cold
C. Switch to Spot Instances
D. Add a lifecycle hook on launch
Correct answer: B. Warm pools keep instances pre-initialized so the ASG can bring them into service in seconds instead of re-running the full bootstrap sequence.
Q17. Which ALB feature enables a canary deployment that shifts a small percentage of traffic to a new version before full cutover?
A. Sticky sessions
B. Weighted target groups on a single listener rule
C. Cross-zone load balancing
D. Connection draining
Correct answer: B. Weighted target groups let one routing rule split traffic by percentage across two target groups — the ALB-native canary mechanism.
Q18. A Lambda function reading from Kinesis is overwhelming a downstream RDS database with connections during traffic spikes. What limits this safely?
A. Increase the Lambda timeout
B. Set reserved concurrency on the function to cap maximum concurrent executions
C. Increase the Kinesis shard count
D. Switch RDS to Multi-AZ
Correct answer: B. Reserved concurrency caps how many instances of the function can run simultaneously, directly bounding concurrent downstream connections.
Q19. A high-volume IoT pipeline needs millions of short workflow executions per day as cheaply as possible and can tolerate at-least-once execution. Which Step Functions type fits?
A. Standard Workflows
B. Express Workflows
C. Both are identical in cost
D. Neither — use SQS only
Correct answer: B. Express Workflows are priced per execution and duration for high-volume, short-duration workloads and provide at-least-once semantics.
Q20. A team has deep existing Kubernetes tooling and multi-cloud portability requirements. Which AWS compute platform best fits?
A. ECS with the EC2 launch type
B. Amazon EKS
C. AWS Lambda
D. AWS Batch on Fargate
Correct answer: B. EKS runs standard Kubernetes, preserving existing tooling and manifests and easing multi-cloud portability.
Q21. A global application needs a secondary region readable with sub-second replication lag and promotable to primary in under a minute during a regional outage. Which database fits?
A. RDS Multi-AZ with a cross-region read replica
B. Aurora Global Database
C. DynamoDB Global Tables only
D. RDS read replica with asynchronous replication
Correct answer: B. Aurora Global Database uses storage-layer cross-region replication with typical sub-second lag and managed failover promoting the secondary in under a minute.
Q22. A team needs to upgrade RDS MySQL from 5.7 to 8.0 with minimal risk and a fast rollback path. What should they use?
A. An in-place major version upgrade during a maintenance window
B. RDS Blue/Green Deployments to validate on a synchronized green environment before switchover
C. Read replica promotion
D. Multi-AZ failover
Correct answer: B. Blue/Green Deployments create a fully replicated green environment on the new version, validated before a fast, low-risk switchover.
Q23. A DynamoDB table using OrderStatus (five possible values) as the partition key is throttling under high write volume even though total table capacity is high. Why?
A. The table needs Global Tables enabled
B. Low-cardinality partition keys create hot partitions, since a partition's throughput is capped regardless of table-level capacity
C. On-demand mode is not enabled
D. DynamoDB does not support high write volume
Correct answer: B. Each partition has its own throughput ceiling; a key with only five distinct values concentrates writes onto a handful of partitions.
Q24. A gaming leaderboard needs microsecond read latency for the same items requested extremely frequently. What should sit in front of DynamoDB?
A. Self-managed ElastiCache for Redis
B. Amazon DAX
C. CloudFront caching of API responses only
D. RDS instead of DynamoDB
Correct answer: B. DAX is a managed, DynamoDB-API-compatible in-memory cache purpose-built to shave read latency for hot items without application-level cache logic.
Q25. An object needs the lowest storage cost, is rarely accessed, and a 12-hour retrieval time is acceptable, but it must survive the loss of an entire Availability Zone. Which class fits?
A. S3 One Zone-IA
B. S3 Glacier Deep Archive
C. S3 Glacier Flexible Retrieval (Bulk)
D. S3 Standard-IA
Correct answer: B. Glacier Deep Archive is the lowest-cost class, replicated across multiple AZs, with retrieval times up to 12 hours matching the requirement.
Q26. A session store must survive a node failure without losing data and support automatic failover. Which caching engine and configuration fits?
A. Memcached with auto discovery
B. Redis with cluster mode enabled and replicas per shard
C. Memcached with multiple nodes
D. Redis without replicas
Correct answer: B. Only Redis supports replication and automatic failover; Memcached has no replication, so node failure means data loss for those keys.
Q27. An application needs single-digit-millisecond reads and writes at massive unpredictable scale with a flexible schema, across multiple regions actively writing. What fits best?
A. Aurora Global Database
B. DynamoDB Global Tables
C. RDS with cross-region read replicas
D. ElastiCache alone as the system of record
Correct answer: B. DynamoDB Global Tables provide multi-active, multi-region writes at single-digit-millisecond latency with a flexible schema.
Q28. On-call engineers are fatigued by alarms firing on isolated latency spikes that self-resolve. What reduces noise while still catching real incidents?
A. Delete the latency alarm
B. A composite alarm requiring both the latency alarm and the error-rate alarm to be in ALARM state
C. Lower the alarm threshold
D. Increase the evaluation period to 24 hours
Correct answer: B. Composite alarms let you require correlated signals before paging, cutting single-metric false positives while preserving sensitivity to genuine incidents.
Q29. Internal CloudWatch metrics show healthy servers, but customers report the login page is broken. What monitoring gap does this reveal?
A. Missing X-Ray tracing
B. No outside-in synthetic monitoring of the actual user flow
C. Missing VPC Flow Logs
D. Insufficient EC2 instance count
Correct answer: B. Server-side health metrics do not verify end-to-end user experience; Synthetics canaries probe from outside the infrastructure.
Q30. A microservices application has growing p99 latency but it is unclear which of twelve services is the bottleneck. What AWS service pinpoints this?
A. CloudWatch Logs Insights alone
B. AWS X-Ray, using the service map to isolate the slow hop
C. VPC Flow Logs
D. AWS Config
Correct answer: B. X-Ray's distributed tracing and service map visualize per-hop latency across the full call chain, directly identifying the bottleneck service.
Q31. An organization wants every account's application logs centrally searchable in a dedicated logging account in near-real time. What is the mechanism?
A. Manually export logs nightly via S3
B. CloudWatch Logs subscription filters streaming to Kinesis Data Firehose in the central logging account
C. CloudTrail only
D. Increase log retention in each account
Correct answer: B. Subscription filters push log events in near-real time to a destination in a centralized account, enabling org-wide log aggregation.
Q32. A team wants to safely test EC2 instance failure in production without risking an uncontrolled outage. What FIS feature guarantees the experiment halts if things go wrong?
A. IAM permission boundaries
B. Stop conditions tied to CloudWatch alarms
C. Increasing the blast radius
D. Manual monitoring only
Correct answer: B. FIS stop conditions automatically abort a running experiment the moment a linked CloudWatch alarm enters ALARM state, capping the blast radius.
Q33. A team has documented DR runbooks but has never tested them under simulated failure. What is the recommended next step before relying on them?
A. Trust the documentation as-is
B. Run a Game Day exercise using FIS to simulate the failure and validate the runbook and automated recovery
C. Increase backup frequency only
D. Skip testing to avoid production risk
Correct answer: B. Untested runbooks are unverified assumptions; a Game Day exercises the real failure mode against real infrastructure to confirm RTO/RPO targets are achievable.
Q34. An active-active application needs sub-second failover at the network layer when a region's health checks fail, independent of DNS TTL and caching issues. What should it use?
A. Route 53 latency-based routing alone
B. AWS Global Accelerator, which uses static anycast IPs and reroutes at the AWS network edge
C. CloudFront alone
D. A single-region Network Load Balancer
Correct answer: B. Global Accelerator uses anycast IPs and AWS's global network for near-instant failover, avoiding client-side DNS caching delays.
Q35. A workload can tolerate an RTO of 15 minutes and RPO of 5 minutes, but the business wants to minimize standing infrastructure cost. Which DR pattern fits best?
A. Backup and Restore
B. Pilot Light
C. Multi-Site Active-Active
D. No DR strategy needed
Correct answer: B. Pilot Light keeps only core data continuously replicated and minimal infrastructure running, scaling up the rest on failover — matching a ~15-minute RTO at much lower cost.
Q36. A critical financial system needs failover control that itself will not fail if an entire AWS region goes down, plus proof the standby region is actually ready to serve traffic. What should it use?
A. Route 53 simple health-check failover only
B. Route 53 Application Recovery Controller with readiness checks and a highly available routing control cluster
C. CloudWatch Alarms triggering a Lambda failover
D. Global Accelerator alone
Correct answer: B. ARC's routing control cluster is distributed across regions and partitions for resilience of the failover mechanism itself, and readiness checks validate standby capacity.
Q37. You want most users routed to the AWS region with the lowest network latency for them, automatically. Which routing policy fits?
A. Weighted routing
B. Latency-based routing
C. Simple routing
D. Geolocation routing
Correct answer: B. Latency-based routing uses AWS's latency measurements between users and regions to route each request to the lowest-latency healthy endpoint.
Q38. A company needs ransomware-resilient backups that cannot be deleted even by a compromised admin account. What should they configure?
A. Standard EBS snapshots only
B. AWS Backup with a cross-account copy into an isolated account, in a vault with Backup Vault Lock enabled
C. S3 versioning only
D. Increase snapshot frequency
Correct answer: B. Cross-account isolation prevents a compromised primary account from touching backups, and Vault Lock makes the retention policy immutable.
Q39. Which best exemplifies the Reliability pillar's failure management best practice?
A. Using the largest possible instance type
B. Automatically testing recovery procedures via Game Days and setting quantified RTO/RPO targets
C. Manually reviewing logs weekly
D. Avoiding all managed services
Correct answer: B. Failure management is about anticipating failure, testing recovery, and having quantified, validated RTO/RPO — not just provisioning bigger resources.
Q40. A team manually SSHes into servers to apply emergency patches, occasionally causing configuration drift. Which Operational Excellence practice addresses this?
A. Increase server count
B. Perform operations as code using SSM Automation documents instead of manual SSH changes
C. Disable CloudTrail logging
D. Add more IAM users
Correct answer: B. Operations as code — codifying operational procedures such as SSM Automation — eliminates ad hoc manual changes and the drift they introduce.
Q41. A workload requires near-zero RTO and RPO and budget is not the primary constraint. Which DR strategy and supporting service pairing fits?
A. Backup and Restore with AWS Backup
B. Pilot Light with manual DNS updates
C. Multi-Site Active-Active with Route 53 ARC and DynamoDB Global Tables or Aurora Global Database
D. Warm standby without health checks
Correct answer: C. Near-zero RTO/RPO demands live traffic serving from multiple regions with deterministic, tested failover control and multi-region-write-capable data services.
Q42. A data center lease expires in six months, forcing a fast migration, but two legacy applications have unresolved software licensing blockers. What is the correct 7 Rs plan?
A. Refactor everything to serverless
B. Rehost the majority via MGN to meet the deadline; Retain the two blocked applications until licensing is resolved
C. Repurchase all applications as SaaS
D. Retire every application
Correct answer: B. Under a tight deadline, Rehost is the fastest path for most applications; applications with real blockers should be explicitly Retained.
Q43. A migration team needs to map network dependencies between individual processes on each server before planning application groupings. What captures this?
A. Agentless Discovery Connector only
B. Agent-based discovery, which captures process-to-process network connections
C. AWS Config
D. CloudTrail
Correct answer: B. Agent-based discovery installs a lightweight agent per server and captures fine-grained, process-level network connections; agentless discovery only gives VM-level inventory.
Q44. A company needs to rehost 200 on-premises VMs to EC2 as fast as possible with minimal application changes and minimal cutover downtime. What should they use?
A. AWS DataSync
B. AWS Application Migration Service (MGN)
C. AWS Schema Conversion Tool
D. AWS DMS
Correct answer: B. MGN is purpose-built for server rehost: continuous replication lets you test extensively and cut over with minutes of downtime, without re-architecting.
Q45. SCT reports a 92% automatic conversion rate for an Oracle-to-PostgreSQL migration. What does this mean for the remaining 8%?
A. The migration is essentially complete and can proceed unattended
B. Complex objects such as certain stored procedures and functions could not be auto-converted and need manual developer remediation before cutover
C. SCT failed and DMS cannot be used
D. 8% of the data will be lost during migration
Correct answer: B. SCT's conversion percentage reflects schema and code objects only; a high percentage still commonly leaves complex procedural logic that must be manually rewritten.
Q46. A company needs to continuously sync a large on-premises NFS file share into Amazon EFS on a schedule, without writing custom scripts. What should they use?
A. AWS DMS
B. AWS DataSync
C. AWS Snowball Edge
D. AWS Storage Gateway File Gateway
Correct answer: B. DataSync is purpose-built for automated, scheduled, validated file and object transfer between on-premises file systems and AWS storage services.
Q47. An enterprise wants to eliminate its physical backup tape infrastructure while keeping existing backup software unchanged. What should they use?
A. File Gateway
B. Volume Gateway in stored mode
C. Tape Gateway, presenting a virtual tape library
D. AWS Backup only
Correct answer: C. Tape Gateway presents a virtual tape library interface compatible with existing backup software, letting you retire physical tape hardware without changing workflows.
Q48. A company must migrate 2 PB of data from a facility with no viable network uplink for bulk transfer. What is the appropriate approach?
A. AWS DataSync over the internet
B. Direct Connect provisioned overnight
C. Multiple AWS Snowball Edge Storage Optimized devices, or Snowmobile for the full 2 PB in one engagement
D. AWS Storage Gateway
Correct answer: C. At petabyte scale with no adequate network path, physical offline transfer via Snow Family devices is the standard, cost-effective solution.
Q49. A hospital must keep patient data physically on-premises for regulatory reasons while still using native AWS APIs such as EC2, EBS, and RDS for its applications. What should it deploy?
A. AWS Local Zones
B. AWS Wavelength
C. AWS Outposts
D. A standard AWS Region with encryption
Correct answer: C. Outposts physically places AWS-managed infrastructure inside the customer's own data center, satisfying strict data-residency requirements while retaining native AWS service APIs.
Q50. A team wants to move VMware VMs to AWS infrastructure fastest, keeping the exact same hypervisor-level configuration and VMware management tools, with no conversion. Which strategy fits?
A. AWS MGN, rehosting to native EC2
B. VMware Cloud on AWS, the Relocate strategy
C. AWS Schema Conversion Tool
D. AWS DataSync
Correct answer: B. Relocate via VMware Cloud on AWS is the only 7 Rs strategy that moves the VM without converting it out of the VMware format.
Q51. A migration needs to move 300 TB of historical data plus ongoing daily deltas of about 50 GB, with a network link capped at 500 Mbps. What is the recommended approach?
A. Transfer everything, including historical data, over the 500 Mbps link
B. Use Snowball Edge for the 300 TB bulk historical transfer, then DMS CDC or DataSync over the network link for ongoing deltas
C. Wait for the network link to be upgraded before starting
D. Use Snowmobile for the entire migration
Correct answer: B. The hybrid pattern — offline bulk transfer for the large historical dataset, then network-based incremental sync for the small ongoing delta — is standard for large migrations over constrained links.
Q52. A company runs a steady-state, predictable production fleet but wants maximum flexibility to change instance families and regions over the commitment period. What should they buy?
A. EC2 Instance Savings Plans
B. Compute Savings Plans
C. Standard Reserved Instances
D. Spot Instances
Correct answer: B. Compute Savings Plans apply across any instance family, region, and OS, and even cover Fargate and Lambda usage, trading a slightly lower discount for maximum flexibility.
Q53. A company suspects many EC2 instances are oversized relative to actual CPU and memory utilization but does not know which ones. What AWS service directly recommends right-sizing changes?
A. AWS Config
B. AWS Compute Optimizer
C. AWS Trusted Advisor cost checks only
D. CloudWatch Alarms
Correct answer: B. Compute Optimizer analyzes historical utilization and provides specific instance-type right-sizing recommendations with projected savings.
Q54. Finance wants to see AWS spend broken out per business unit, but resources are inconsistently tagged today. What should be enforced first?
A. Enable Cost Explorer only
B. Enforce a mandatory tagging policy via SCP or Config rules requiring cost-allocation tags at resource creation, then activate those tags for cost allocation reporting
C. Use a single shared account for all business units
D. Manually track spend in a spreadsheet
Correct answer: B. Cost allocation reporting is only as good as tag hygiene; enforcing mandatory tags at creation time is the prerequisite before per-business-unit reports become meaningful.
Q55. Which DMS configuration supports a near-zero-downtime cutover while the source database remains online and accepting writes?
A. Full Load only
B. Full Load plus Change Data Capture
C. CDC only, with no initial load
D. A one-time snapshot export to S3
Correct answer: B. Full Load plus CDC takes the snapshot while caching concurrent changes, applies them when the load completes, then streams CDC forward — the configuration for minimal-downtime cutovers.
Q56. A company is migrating from Oracle to Aurora PostgreSQL. Which tool combination handles the schema and the data respectively?
A. DMS for schema, SCT for data
B. SCT for schema conversion, DMS for the data migration
C. DataSync for both
D. MGN for both
Correct answer: B. SCT converts schema, views, stored procedures, and functions between engines; DMS moves the data itself, including ongoing changes via CDC.
Q57. A workload's data must be replicated to a second region with a recovery point objective measured in seconds and a recovery time objective under a minute, and the database is PostgreSQL-compatible. What should be used?
A. RDS automated backups copied cross-region
B. Aurora Global Database
C. A nightly logical dump to S3 with cross-region replication
D. Multi-AZ within a single region
Correct answer: B. Aurora Global Database replicates at the storage layer with typical sub-second lag and supports managed failover promoting the secondary region in under a minute.
Q58. An application writes to DynamoDB from two active regions simultaneously. What conflict resolution behavior should the team expect from Global Tables?
A. The write is rejected in both regions
B. Last-writer-wins, based on the timestamp of the write
C. The application must implement its own merge logic before writing
D. Writes are serialized through a single leader region
Correct answer: B. DynamoDB Global Tables use last-writer-wins conflict resolution, which is why designs that need deterministic merges often partition writes by key.
Q59. A team needs to run a batch job that can be interrupted and restarted, and wants to minimize compute cost. Which purchasing option fits best?
A. On-Demand Instances
B. Spot Instances, with a mixed-instance ASG or Spot Fleet for capacity diversification
C. Standard Reserved Instances
D. Dedicated Hosts
Correct answer: B. Spot suits fault-tolerant, interruptible workloads at a steep discount; diversifying across instance types and pools reduces the chance of simultaneous interruption.
Q60. A company wants a single pane of glass for backup policy across EBS volumes, RDS databases, DynamoDB tables, and EFS file systems, with cross-account copies. What should they use?
A. Per-service native snapshot schedules configured individually
B. AWS Backup with a backup plan and cross-account copy
C. AWS DataSync tasks per service
D. S3 lifecycle policies
Correct answer: B. AWS Backup centralizes policy-based backup across services from one console, including schedules, lifecycle, and cross-region or cross-account copy.
Q61. A company needs to prove to auditors that a specific IAM role could never have exceeded a defined set of permissions, even if its attached policies were later broadened. What should have been used?
A. An SCP attached to the account
B. A permissions boundary attached to the role
C. A resource-based policy on each target resource
D. MFA enforcement on the role
Correct answer: B. A permissions boundary caps the maximum permissions an IAM entity can ever hold, independent of what its identity policies later allow.
Q62. A workload running on EKS needs per-pod IAM permissions without distributing long-lived credentials to pods. What is the standard mechanism?
A. Store IAM user access keys in a Kubernetes Secret
B. IAM Roles for Service Accounts, using AssumeRoleWithWebIdentity against the cluster's OIDC provider
C. Attach an instance profile to every node and share it across pods
D. Use the cluster's root credentials
Correct answer: B. IRSA federates the pod's service account to an IAM role via the cluster OIDC provider, issuing short-lived credentials scoped to that pod.
Q63. A company wants to enforce that no resource can be created in any account outside two approved AWS Regions, while keeping IAM, Route 53, CloudFront, and Support working. What must the SCP do?
A. Deny all actions outside the two Regions with no exceptions
B. Deny all actions outside the two Regions while exempting global services such as IAM, Route 53, CloudFront, and Support
C. Allow all actions and rely on IAM policies for Region restriction
D. Apply the restriction only to the management account
Correct answer: B. Region-restriction SCPs must exempt global services, or they break account operations that depend on endpoints outside any single Region.
Q64. A company wants to detect and remediate unencrypted EBS volumes automatically across all accounts in an OU. Which combination fits?
A. CloudTrail alone
B. AWS Config rules with automatic remediation, deployed through a conformance pack or Control Tower guardrail
C. Trusted Advisor checks only
D. VPC Flow Logs
Correct answer: B. Config rules evaluate resource configuration continuously and can trigger automatic remediation, and conformance packs or Control Tower guardrails scale that across an OU.
Q65. A team needs to expose an internal microservice to consumers in twenty other accounts, and the consumer VPCs have overlapping CIDR ranges with the provider VPC. What should they use?
A. VPC peering between each consumer and the provider
B. A PrivateLink endpoint service with Interface Endpoints in each consumer VPC
C. A Transit Gateway shared through RAM
D. A Direct Connect connection per consumer
Correct answer: B. PrivateLink exposes a single service through ENI-backed endpoints without merging route tables or CIDRs, so overlapping address space is not a blocker.
Q66. A company needs to connect 40 VPCs and two on-premises data centers with segmented routing, where production VPCs must not reach development VPCs. What is the most operationally sustainable design?
A. Full-mesh VPC peering between all 40 VPCs
B. A Transit Gateway with separate route tables per environment segment, plus Direct Connect or VPN attachments for on-premises
C. A single VPC with 40 subnets
D. PrivateLink endpoints between every pair of VPCs
Correct answer: B. TGW replaces the peering mesh with a hub, and per-segment route tables implement the isolation requirement without per-pair configuration.
Q67. A company wants to reduce the blast radius of a compromised workload account. Which control most directly limits what that account can do even if its IAM policies are misconfigured?
A. Enabling CloudTrail in the account
B. An SCP attached to the account's OU that denies sensitive actions such as leaving the organization or disabling logging
C. Increasing the account's service quotas
D. Adding more IAM users to the account
Correct answer: B. SCPs set the permission ceiling for every principal in the account, so they constrain damage even when identity policies are too permissive.
Q68. A team wants to know whether a planned failover to a standby region would actually succeed, before an incident forces the question. What should they configure?
A. A CloudWatch dashboard for the standby region
B. Route 53 ARC readiness checks that continuously validate the standby region's capacity and configuration
C. A weekly manual review of the standby region's console
D. A larger instance type in the standby region
Correct answer: B. ARC readiness checks continuously verify that a standby region has the capacity and configuration required to take over, turning an assumption into a monitored fact.
Q69. A company wants to reduce the cost of a steady-state production fleet without losing the ability to change instance families next year. Which commitment is the best fit?
A. A three-year Standard Reserved Instance for the current instance family
B. A Compute Savings Plan
C. Spot Instances for the production fleet
D. On-Demand with no commitment
Correct answer: B. Compute Savings Plans apply across instance families, Regions, and operating systems, preserving flexibility while still discounting steady-state usage.
Q70. A company needs to move 50 TB of data from an on-premises data center to S3 over an existing 1 Gbps Direct Connect link, with the transfer completing within a week and no application changes. What is the simplest appropriate approach?
A. AWS Snowball Edge devices
B. AWS DataSync over the Direct Connect link, with a scheduled task and integrity validation
C. AWS Storage Gateway Volume Gateway
D. AWS DMS
Correct answer: B. With adequate bandwidth and a one-week window, DataSync handles the transfer online with scheduling, encryption, and integrity validation, avoiding the logistics of shipping devices.
Q71. A company wants to detect when a workload's latency deviates from its normal pattern without manually tuning a static threshold. What CloudWatch feature fits?
A. A static threshold alarm set to the historical maximum
B. Anomaly detection bands on the metric, which learn the expected pattern and alarm on deviation
C. A composite alarm combining two static thresholds
D. A dashboard widget
Correct answer: B. Anomaly detection builds a model of the metric's expected behavior and alarms when the value falls outside the band, removing the need to hand-tune a static threshold.
Q72. A team wants to run a controlled experiment that terminates a percentage of ECS tasks in production to verify the service self-heals within its target RTO. What should they use?
A. A manual termination performed by an engineer during business hours
B. AWS Fault Injection Service with an experiment template and a stop condition tied to an error-rate alarm
C. A CloudWatch alarm that pages the on-call engineer
D. A load test against the service
Correct answer: B. FIS runs controlled chaos experiments with mandatory stop conditions, so the experiment aborts automatically if the linked alarm enters ALARM state.
Q73. A company needs a database that supports complex multi-table transactions with strong consistency, and the workload is a traditional ERP system. Which service fits?
A. DynamoDB with Global Tables
B. Amazon Aurora, with Multi-AZ for high availability
C. ElastiCache for Redis as the system of record
D. S3 with object locking
Correct answer: B. Relational workloads with multi-table transactions and strong consistency belong on a relational engine; Aurora provides that with a self-healing, multi-AZ storage layer.
Q74. A company wants to reduce the risk of a major database version upgrade by validating the new version against production-shaped traffic before cutover. What should they use?
A. An in-place upgrade during a maintenance window
B. RDS Blue/Green Deployments, which maintain a synchronized green environment for validation before a fast switchover
C. A read replica promoted to primary
D. A logical dump restored into a new instance
Correct answer: B. Blue/Green Deployments keep a fully synchronized green environment on the new version, so the upgrade can be validated before a fast, low-risk switchover.
Q75. A company wants to ensure that a compromised workload account cannot delete the organization's centralized backups. What is the most direct control?
A. Enable S3 versioning on the backup bucket
B. Copy backups cross-account into an isolated backup account and enable Backup Vault Lock on the destination vault
C. Increase the backup frequency
D. Restrict the workload account's IAM policies to read-only
Correct answer: B. Cross-account isolation puts the backups outside the compromised account's reach, and Vault Lock makes the retention policy immutable even for administrators.
Scoring Guide
Count your raw correct answers out of 75. As a rule of thumb — not an official AWS figure — a raw score of roughly 72% or better (about 54 of 75) is a reasonable proxy for exam-ready on this material, and scores in the mid-60s suggest you are close but still leaking points on specific domains rather than broadly. Treat the threshold as a directional signal, not a promise: the real exam's scaled scoring is not a simple percentage, and a practice question bank is not the same instrument as the live exam.
More useful than the raw number is the distribution. Tally your misses by domain — multi-account governance and networking, resilient architectures, migration and modernization, cost control — and note which domain produced the most misses. If one domain accounts for more than half of your errors, that is where the next review block should go, regardless of what the total score says. If the misses are spread evenly across all four, the problem is retrieval speed and stamina rather than a specific knowledge gap, and the fix is more timed sittings rather than more reading.
Preview
This sitting produces two artifacts: a raw score and a list of which domains the misses came from. Neither is actionable on its own. A score of 56 tells you that you are not yet where you need to be, but it does not tell you whether the problem is that you did not know the material or that you knew it and could not retrieve it fast enough under a clock — and those two problems have completely different remedies. The domain tally narrows it somewhat, but it still does not distinguish a question you missed because the concept was unfamiliar from one you missed because two plausible answers looked equally correct and you picked the wrong one.
Day 66 is built to close that gap. It takes the raw output of this sitting and turns it into a diagnosis: which questions cost you the most time, whether the delay was a content gap or overthinking, and which distractor patterns you keep falling for. The pacing data matters as much as the correctness data here — a question you answered correctly after four minutes of deliberation is a different signal than one you answered correctly in thirty seconds, and only the timing record can tell you which is which.