Day 66 of 70 · Week 10
Day 66 / 70 Week 10 of 14 Phase 5: Practice Exams & Exam Technique

Mock Exam 3 Distractor Analysis & Timing/Pacing Strategy

🕑 ~58 min read · 2 services covered
Distractor Analysis Exam Pacing

Recap

Mock Exam 3 was the consistency check: the third full 75-question timed run, and the first one where the score should have stopped bouncing around and started trending toward the 80%+ target range. That is a different kind of result than Mock Exam 1 or 2 produced. A rising score on a third attempt can mean the deep reviews worked, or it can mean the question bank has become familiar enough that pattern recognition is doing work that understanding should be doing. Those two explanations look identical on a score report and they fail in opposite directions on exam day.

This is the same service opposite failure mode problem in its purest form. The same mock exam that proves your content gaps are closing can also be quietly teaching you to answer by shape rather than by reasoning, and the only instrument that separates the two is the timing data you have been ignoring. Mock Exam 3 is the last run where you still have enough runway to act on what the clock says, so the analysis today is deliberately split: half of it is the distractor patterns that keep costing you points, and half of it is the per-question time data that tells you whether those points were lost to ignorance or to overthinking.

Foundations You'll Need Today

Today's analysis is about why wrong answers are wrong, and almost every distractor pattern below is built on a prerequisite concept that the exam assumes you already know cold. If you are coming to this curriculum from a foundational background, the patterns will read as arbitrary trivia rather than as consequences of how AWS actually works. So before the patterns, here are the five ideas this specific day leans on hardest.

AWS Organizations, OUs, and SCPs

AWS Organizations is the mechanism that lets one company treat many separate AWS accounts as a single managed group. Instead of logging into forty accounts individually, you create the Organization once, invite or create the accounts into it, and then administer them from a central place. Inside the Organization you arrange accounts into organizational units, or OUs, which are just folders: a Security OU, a Workloads OU, a Sandbox OU. The point of the folders is that you can attach rules to a folder and have those rules apply to everything inside it.

Those rules are called Service Control Policies, or SCPs. An SCP is not a grant of permission; it is a ceiling. It says "no principal in any account under this OU may ever do these things," and it applies on top of whatever IAM policies already exist. That is why SCPs are the answer whenever a question says a restriction must apply to administrators too, or must not be removable by workload teams. The one structural exception worth memorizing is that SCPs do not apply to the management account, which is the account that owns the Organization. That single fact is the reason several of today's distractors are wrong.

IAM Roles, Trust Policies, and Permission Boundaries

An IAM role is an identity that does not belong to a person. It is a set of permissions that something can temporarily assume: an EC2 instance, a Lambda function, or a user in another account. A role has two separate policy documents, and confusing them is a common source of wrong answers. The trust policy answers "who is allowed to assume this role?" and the permissions policy answers "once assumed, what can this role do?" A role that trusts the security team's account but grants only read access is a completely normal and useful construction.

A permission boundary is a different idea: it is a maximum-permissions cap attached to an identity. If a developer is allowed to create IAM roles, a permission boundary lets you say "you may create roles, but no role you create may ever exceed these permissions," which preserves the delegation while removing the ability to escalate to full administrator. This is the mechanism behind the least-privilege pattern later today, and it is the reason "just remove the permission" is usually the wrong answer when a question asks you to keep a capability while constraining it.

RTO, RPO, and the DR Strategy Ladder

Two numbers drive every disaster recovery question. Recovery Time Objective, or RTO, is how long the business can tolerate the system being down. Recovery Point Objective, or RPO, is how much data the business can tolerate losing, expressed as an amount of time: an RPO of five minutes means you may lose up to the last five minutes of writes. These are business decisions, not technical ones, and the exam gives them to you precisely so you can use them as filters.

The four standard DR strategies form a ladder from cheapest-and-slowest to most-expensive-and-fastest: Backup and Restore, then Pilot Light, then Warm Standby, then Multi-Site Active-Active. Backup and Restore has almost no standing cost and an RTO measured in hours. Pilot Light keeps data continuously replicated and a minimal core running, giving an RTO in the tens of minutes. Warm Standby runs a scaled-down but fully functional copy, and Active-Active runs everything everywhere. The reason this matters today is that a distractor will often name the cheapest rung of the ladder and attach a correct cost claim to it, while the question's stated RTO quietly rules that rung out.

Route 53 Resolver Endpoints: Inbound vs Outbound

DNS is the system that turns a name like db.internal.example.com into an IP address. AWS runs a DNS resolver inside every VPC so that resources in that VPC can look names up. A private hosted zone is a set of DNS records that only resolves from inside the VPCs you associate with it, which is how internal service names stay invisible to the public internet.

The hybrid problem is that on-premises servers and AWS resources often need to resolve each other's names, and the two directions require different pieces of infrastructure. A Route 53 Resolver inbound endpoint is a set of IP addresses inside your VPC that on-premises DNS servers can forward queries to, so on-premises can resolve AWS names. An outbound endpoint is the reverse: it lets AWS resources forward queries out to your on-premises DNS servers. The naming is from AWS's point of view, which is why it feels backwards at first. The reliable habit is to ask who is asking and who is answering before choosing an endpoint type.

DynamoDB Partition Keys and Hot Partitions

DynamoDB is a managed NoSQL database that stores data across many physical partitions behind the scenes. Every item in a table has a partition key, and DynamoDB uses the value of that key to decide which partition the item lives on. Crucially, each partition has its own throughput ceiling, and the table-level capacity number you configure is divided across however many partitions the table currently has.

This creates a failure mode that looks like a capacity problem but is not one. If your partition key has only a handful of distinct values, say a status field with five possible states, then every item with the same status lands on the same partition. All the write traffic for that status concentrates on one partition, that partition hits its own ceiling, and the table throttles even though the table-level capacity is far above the total observed throughput. The fix is structural rather than quantitative: redesign the key so its values spread evenly, for example by combining the status with a high-cardinality value like a customer ID. This is the mechanism behind the "solves the symptom" pattern below.

With that grounding, here is why the exam's wrong answers are wrong in the specific ways they are, and what each pattern is actually testing.

Distractor Patterns From Mock Exam 3

Each entry below is a recurring wrong-answer shape rather than a single question. The exam reuses a small number of these shapes across every domain, which is why a distractor you fell for on a networking question will reappear wearing a database costume three sections later. For each one, the useful work is naming the tell that separates it from the correct answer, because the tell is what you actually apply under time pressure.

Pattern 1: The Single-Account Answer to a Multi-Account Question

The most common distractor family on this exam is an option that solves the stated problem correctly but does so inside one account. A question describes forty accounts, a central security team, and a requirement that no workload team can disable logging, and one option reads something like "create an IAM role in each account with a trust policy allowing the security team to assume it." That option is not wrong in the sense of being impossible. It is wrong because it requires forty separate trust policies, forty separate role definitions, and forty separate places for drift to accumulate, and the question's framing about a central team is the tell that the examiner wants an Organizations-level mechanism.

The tell is almost always a phrase about scale or central control: "across all accounts," "without per-account configuration," "cannot be modified by workload teams." When you see one of those, eliminate any option whose implementation is per-account, even if the option is technically functional. On Mock Exam 3 this shape showed up in the governance questions and again in a networking question about sharing a VPC, where the tempting answer was VPC peering between every pair of accounts and the correct answer was RAM subnet sharing from a central network account.

Pattern 2: The Service That Exists But Does Not Do That

This pattern is more dangerous than the first because it requires you to know a service well enough to know its boundary. The distractor names a real AWS service, describes a plausible-sounding capability, and the capability is simply not something that service does. "Use AWS Config to block the API call" is the canonical example: Config evaluates and reports, it does not deny. "Use CloudTrail to alert on the change" is the same shape, because CloudTrail records what happened after the fact and has no enforcement path.

The tell is a verb mismatch. Read the option and ask what the verb requires: prevention, detection, or notification. SCPs, permission boundaries, and resource policies prevent. Config rules, GuardDuty, and CloudTrail detect. SNS, EventBridge, and CloudWatch alarms notify. If the question says "prevent" or "ensure that no one can," any option whose verb is detect or notify is a distractor regardless of how well the service fits the domain. Mock Exam 3 leaned on this in the SCP section, where an option proposed using an IAM policy to restrict a region for an entire account, which fails because IAM policies cannot constrain the account's own root user or the services that do not honor identity policies.

Pattern 3: The Cheaper Option That Violates a Stated Constraint

Cost questions are where this pattern lives, and it is the one that most often survives a first pass because the arithmetic in the option is genuinely correct. A question states an RTO of fifteen minutes and an RPO of five minutes, and one option is Backup and Restore with a note that it is the lowest-cost approach. The cost claim is true. The option is still wrong because Backup and Restore cannot meet a fifteen-minute RTO for a workload of any real size, and the question gave you the RTO precisely so you would use it as a filter.

The tell is that the question contains a number you have not yet used. SAP-C02 rarely includes a constraint for decoration. If you find yourself choosing an option without having referenced the RTO, the RPO, the latency target, or the throughput figure in your reasoning, go back and check whether the option you picked actually satisfies it. On Mock Exam 3 this appeared in the DR section and again in a DynamoDB question where the cheap option was provisioned capacity with auto scaling for a workload the question had described as wildly unpredictable.

Pattern 4: The Right Service With the Wrong Configuration Mode

Here the service is correct and the mode is wrong, which makes the option feel like a near-miss and therefore hard to eliminate. Storage Gateway is the classic host: a question about replacing physical tape infrastructure offers File Gateway, Volume Gateway in stored mode, and Tape Gateway, and only the last one preserves the existing backup software's workflow. The service family is right in all three options, so the discriminator has to be the interface the workload actually speaks.

The tell is the word describing the existing interface: file, block, or tape. Ask what the on-premises system presents today and match the mode to it rather than to the general category. The same shape appears with DMS migration types, where Full Load and Full Load plus CDC are both correct DMS configurations and only one satisfies a minimal-downtime requirement, and with Step Functions Standard versus Express, where both are correct workflow types and only one fits a high-volume short-duration workload. Mock Exam 3 used this in the migration section and in a caching question where Redis and Memcached were both plausible until the question mentioned failover.

Pattern 5: The Answer That Adds a Hop Nobody Asked For

Some distractors are architecturally sound and simply insert an unnecessary component. A question asks how to let on-premises servers resolve names in a private hosted zone, and one option proposes a Route 53 Resolver outbound endpoint with a forwarding rule. That is a real pattern, it is documented, and it solves the inverse problem. The correct answer is an inbound endpoint, because the direction of the query is what determines which endpoint type you need.

The tell is to restate the question as a direction: who is asking, and who is answering. Inbound endpoints answer queries coming from outside AWS. Outbound endpoints ask queries going to outside AWS. Once you have written the direction down, the extra-hop options eliminate themselves. This pattern also shows up in hybrid connectivity, where an option will route traffic through a Transit Gateway when the requirement is to expose a single service and the correct answer is PrivateLink, and in observability, where an option proposes X-Ray when the question is about verifying a user-facing flow from outside the infrastructure and the correct answer is a Synthetics canary.

Pattern 6: The Manual Step Hidden Inside an Automated-Sounding Option

This one is designed to catch candidates who are pattern-matching on the word "automated." An option will describe an automated pipeline and then include a clause like "with an operator approving the failover in the console" or "after the on-call engineer updates the DNS record." The automation is real, but the recovery path still depends on a human being awake and available, which contradicts any question that specifies an RTO measured in seconds or minutes.

The tell is a human subject in the option's verb. Scan for "operator," "engineer," "administrator," "manually," and "approves." If the question's RTO is under about fifteen minutes, any option containing one of those words is almost certainly wrong, because the human response time alone consumes the budget. Mock Exam 3 used this in the multi-region section, where the tempting answer was a Lambda triggered by a CloudWatch alarm to update Route 53, and the correct answer was Global Accelerator or Route 53 ARC depending on whether the question emphasized network-layer failover or auditable failover control.

Pattern 7: The Over-Permissive Fix for a Least-Privilege Question

When a question describes a privilege escalation risk, one distractor will always be the blunt instrument: remove the permission entirely, or attach AdministratorAccess and rely on review. Removing iam:CreateRole from a delegated admin does eliminate the escalation, and it also eliminates the delegation the question asked you to preserve. The correct answer is a permission boundary enforced by a condition on the create call, which caps the new role's maximum permissions without removing the ability to create roles at all.

The tell is whether the question asks you to preserve a capability while constraining it. If it does, any option that removes the capability is wrong, and any option that leaves it unconstrained is also wrong. The answer has to be a constraint mechanism: permission boundaries, SCPs, or a condition key. Mock Exam 3 used this shape in the IAM section and in a Control Tower question where the tempting answer was to disable an elective guardrail rather than to understand that mandatory guardrails cannot be disabled at all.

Pattern 8: The Correct Answer to a Different Question

This is the most expensive pattern to fall for because the option is not merely plausible, it is a well-formed answer to a question the examiner did not ask. A question about reducing alert fatigue offers "lower the alarm threshold" and "increase the evaluation period to twenty-four hours," both of which are real techniques for changing alarm behavior, and neither of which addresses the stated problem of correlated false positives. The correct answer is a composite alarm requiring two signals to be in ALARM simultaneously.

The tell is to reread the question's problem statement after you have picked an answer and confirm that your choice addresses that specific problem rather than a neighboring one. This is also the pattern that produces the most second-guessing, which is why it belongs in the flag-and-review set rather than the answer-now set. On Mock Exam 3 it appeared in the observability section and in a cost question where the tempting answer was Compute Optimizer for a problem that was actually about tag hygiene, and the correct answer was enforcing cost allocation tags before any reporting could be meaningful.

Pattern 9: The Distractor That Is True Only in the Management Account

Organizations questions have a dedicated distractor family built around the management account's special status. An option will propose applying an SCP to the management account, or running a workload there because it has the broadest permissions, or using it as the log archive. Each of these is wrong for a specific structural reason: SCPs do not apply to the management account, workloads there cannot be constrained by the org's own guardrails, and the log archive belongs in a dedicated Security OU account precisely so that workload teams cannot reach it.

The tell is the phrase "management account" or "root account" appearing in an option that also contains a governance verb. If the option is doing anything other than billing, Organizations administration, or org-wide services like IAM Identity Center, it is a distractor. Mock Exam 3 used this in the governance section, and it is worth noting that the same logic extends to the root user of any account, which is why the mandatory Control Tower guardrail against root access keys exists.

Pattern 10: The Option That Solves the Symptom

Some distractors address the visible failure rather than its cause. A DynamoDB table is throttling under high write volume, and one option proposes increasing the table's provisioned capacity. That will help for a while and then stop helping, because the throttling is caused by a low-cardinality partition key concentrating writes onto a handful of partitions, and each partition has its own throughput ceiling regardless of the table-level number. The correct answer is to redesign the key.

The tell is whether the option changes a quantity or a structure. Quantity changes (more capacity, bigger instance, more replicas) are the tempting answers; structural changes (better key design, different routing, different replication topology) are usually the correct ones when the question describes a workload that has already been scaled up and is still failing. Mock Exam 3 used this in the DynamoDB section and in a Lambda question where the tempting answer was to increase the function timeout and the correct answer was reserved concurrency to cap downstream connections.

Pattern 11: The Cross-Region Answer to a Cross-AZ Question

Availability and durability questions are separated by a scope word, and the distractors exploit candidates who read past it. A question about surviving the loss of an Availability Zone offers a cross-region read replica, and a question about surviving a regional outage offers Multi-AZ. Both options are real architectures and both are wrong for the stated scope, because Multi-AZ does not protect against a regional event and a cross-region replica does not provide automatic failover within a region.

The tell is the scope noun: AZ, region, or account. Underline it mentally before reading the options, then eliminate anything whose blast-radius coverage is larger or smaller than what was asked. This pattern is closely related to Pattern 3, since the scope word is often the constraint the cheap option violates, but it is worth separating because the scope word appears in questions that have nothing to do with cost. Mock Exam 3 used it in the Aurora and S3 sections, where the correct answers were Aurora Global Database and Glacier Deep Archive respectively, and the tempting answers were RDS Multi-AZ and One Zone-IA.

Pattern 12: The Answer That Ignores the Existing Investment

Migration questions frequently include a constraint about what the organization already has: a team with deep Kubernetes experience, an existing VMware estate, backup software that must keep working, a Terraform-based provisioning pipeline. One distractor will propose the architecturally cleanest target that discards that investment, and it will be wrong because the question's framing made the investment a requirement rather than a preference.

The tell is a sentence in the question about the team's skills or the existing tooling. When you see one, the correct answer is usually the option that preserves it: EKS rather than ECS for the Kubernetes team, VMware Cloud on AWS rather than MGN for the estate that must not be converted, Tape Gateway rather than File Gateway for the backup software that speaks tape, AFT rather than hand-rolled account provisioning for the Terraform shop. Mock Exam 3 used this in the compute and migration sections, and it is the pattern most likely to be missed by candidates who have memorized service capabilities without reading the organizational context.

Pattern 13: The Distractor With a Plausible Number Attached

Numbers in options are a signal, and the exam uses them both ways. A correct option may cite a real limit, and a distractor may cite a number that sounds authoritative and is simply not the relevant one. Transit Gateway peering's 1500-byte MTU cap is a real figure that appears in correct answers about inter-region peering; a distractor might attach the same number to a question about intra-region attachments, where it does not apply.

The tell is whether the number is doing work in the option or decorating it. If removing the number leaves the option's logic intact, the number is decoration and you should evaluate the option on its mechanism. If removing the number breaks the option, the number is load-bearing and you need to know whether it is the right figure for the stated context. Mock Exam 3 used this in the networking section, and the practical defense is to keep a short list of the limits you have actually seen cited in the curriculum rather than memorizing numbers in isolation.

Pattern 14: The Option That Confuses Detection With Recovery

Resilience questions often describe a failure and ask what to do about it, and the distractors split between noticing and recovering. An option will propose a CloudWatch alarm on error rate, which is a detection mechanism, when the question asks how the system should behave during the failure. The correct answer is usually a degradation or failover behavior: a circuit breaker, a queue that absorbs the load, a health check that removes the endpoint, or a routing control that shifts traffic.

The tell is the question's verb again, but at a higher level than Pattern 2. Ask whether the question is asking you to observe, to prevent, or to survive. Observability questions want metrics, traces, and canaries. Prevention questions want SCPs, boundaries, and policies. Survival questions want redundancy, graceful degradation, and tested failover. Mock Exam 3 used this in the SRE section, where the tempting answer to a Game Day question was to increase backup frequency and the correct answer was to actually run the exercise and validate the runbook.

Pattern 15: The Timing Tell — Which Patterns Cost You the Clock

The second half of today's analysis is not about content at all. When you review Mock Exam 3's per-question timing, the slow questions cluster into two groups that require opposite remedies. The first group is slow because you did not know the material: you read the options twice, eliminated two, and guessed between the remaining pair. The second group is slow because you knew the material and could not commit, usually because two options were both defensible and you were hunting for a tiebreaker the question had already given you.

The remedy for the first group is content review, and the domain tagging from the previous analysis days tells you where to spend it. The remedy for the second group is a decision rule, not more studying. If you consistently lose time on Pattern 8 and Pattern 3, the fix is to write the constraint down before reading the options so the tiebreaker is visible on the first pass. If you lose time on Pattern 6 and Pattern 14, the fix is to classify the question's verb before reading the options. Both are mechanical habits, and both are worth more in the last week than another pass through the service documentation.

Hands-On Lab / Practical Action (45 min)

Pull up your Mock Exam 3 results and build two artifacts from them. The first is a pattern tally: go through every question you missed and every question you answered correctly but flagged as uncertain, and assign each one to one of the fifteen patterns above. Most people find that three or four patterns account for the majority of their misses, and that the distribution is different from what they expected. If Pattern 3 and Pattern 11 dominate, your problem is constraint-reading rather than service knowledge, and the fix is a reading habit rather than more study time.

The second artifact is a timing table. If your practice platform records per-question time, export it; if it does not, reconstruct it from your flagging behavior and your memory of where the clock felt tight. Sort the questions into four buckets: fast and correct, fast and wrong, slow and correct, slow and wrong. Fast and wrong is the most urgent bucket because it means you are confidently applying a wrong rule, and those are the misses that will not self-correct with more practice. Slow and correct is the second priority, because those are the questions where a decision rule would buy back minutes you can spend on the genuinely hard items.

Then write the decision rules down. For each of your top three patterns, write one sentence that starts with a trigger and ends with an action: "when the question says prevent, eliminate any option whose verb is detect or notify," or "when the question gives an RTO, write it down before reading the options." Keep these on the same page as your weak-spot cheat sheet, because they are the same kind of artifact and they will be reviewed together on the final day. The test of a good decision rule is that it is mechanical enough to apply while tired, which is the state you will be in during the last twenty questions of the real exam.

Finally, re-time yourself on the ten slowest questions from Mock Exam 3 with the decision rules in hand. You are not trying to get them right this time, since you have already seen the answers. You are measuring whether the rule shortens the deliberation, and if it does not, the rule is too abstract to be useful and needs to be rewritten as something more concrete. A rule that saves you thirty seconds across ten questions is worth roughly five minutes of exam time, which is the difference between finishing with a review pass and finishing with the clock at zero.

Scenario Question Drills (20 min)

Q1. A company with 40 AWS accounts wants a central security team to be able to read CloudTrail logs from every account, and no workload team may be able to disable or delete the logging. Which approach satisfies this?

A. Create an IAM role in each of the 40 accounts with a trust policy allowing the security team to assume it, and document the setup in a runbook.
B. Deliver logs to a dedicated log-archive account in a Security OU, protected by SCPs that deny deletion or modification of logging resources.
C. Enable CloudTrail in the management account and use CloudTrail Lake to query all accounts.
D. Use AWS Config rules in each account to detect and remediate any attempt to disable logging.
Correct answer: B. The question's framing about a central team and a prohibition on workload teams is the tell for an Organizations-level mechanism. Option A is the single-account answer to a multi-account question (Pattern 1) and requires 40 separate trust policies. Option D is the detect-not-prevent distractor (Pattern 2), since Config reports rather than denies.

Q2. A regulated workload must not be able to launch resources outside two approved AWS Regions, and the restriction must apply to every principal in the account including administrators. What should be used?

A. An IAM policy attached to every role in the account denying actions outside the two Regions.
B. An SCP attached to the account's OU denying actions outside the two Regions, exempting global services such as IAM, Route 53, CloudFront, and Support.
C. An AWS Config rule that detects out-of-Region resource creation and triggers a Lambda to delete the resource.
D. A CloudTrail trail with an EventBridge rule that notifies the security team when out-of-Region calls occur.
Correct answer: B. The requirement that the restriction apply to administrators is the tell that an identity policy is insufficient, since IAM policies cannot constrain the account's own root user. Options C and D are detect-and-notify answers to a prevent question (Pattern 2).

Q3. A workload can tolerate an RTO of 15 minutes and an RPO of 5 minutes, and the business wants to minimize standing infrastructure cost. Which DR strategy fits?

A. Backup and Restore, since it has the lowest standing cost of any DR strategy.
B. Pilot Light, with core data continuously replicated and minimal standby infrastructure scaled up on failover.
C. Multi-Site Active-Active, since it guarantees the lowest RTO and RPO.
D. Warm Standby with a full-scale replica running in the secondary Region at all times.
Correct answer: B. Option A is the cheaper option that violates a stated constraint (Pattern 3): its cost claim is true, but it cannot meet a 15-minute RTO for a real workload. Option C satisfies the RTO but ignores the cost constraint, and Option D is more standing infrastructure than the requirement justifies.

Q4. An enterprise wants to retire its physical backup tape infrastructure while keeping its existing backup software and workflows unchanged. What should be deployed?

A. File Gateway presenting an S3 bucket as an NFS share.
B. Volume Gateway in stored mode presenting iSCSI block storage.
C. Tape Gateway presenting a virtual tape library compatible with existing backup software.
D. AWS Backup with a cross-account copy into an isolated backup account.
Correct answer: C. The service family is right in options A, B, and C, so the discriminator is the interface the workload speaks (Pattern 4). The question specifies tape and unchanged backup software, which only Tape Gateway preserves.

Q5. On-premises DNS servers need to resolve names in a private Route 53 hosted zone hosted in a VPC. What must be configured?

A. A Route 53 Resolver outbound endpoint with a forwarding rule for the private zone.
B. A Route 53 Resolver inbound endpoint, with the on-premises resolvers forwarding queries to it.
C. A public hosted zone containing the same records, resolvable from anywhere.
D. A NAT Gateway with DNS forwarding enabled in the VPC.
Correct answer: B. Restate the question as a direction: on-premises is asking, AWS is answering, so an inbound endpoint is required. Option A is the extra-hop distractor (Pattern 5) that solves the inverse problem, and Option D names a capability NAT Gateway does not have.

Q6. A critical system must fail over between Regions within seconds when a Region becomes unhealthy, and the failover must not depend on DNS TTLs or client-side caching. What should be used?

A. Route 53 latency-based routing with health checks on both Regions.
B. A CloudWatch alarm that triggers a Lambda function to update the Route 53 record set.
C. AWS Global Accelerator with endpoint groups in both Regions, using static anycast IPs.
D. An Application Load Balancer in each Region with cross-Region health checks.
Correct answer: C. The explicit exclusion of DNS TTL and client caching eliminates Option A. Option B is the manual step hidden inside an automated-sounding option (Pattern 6), since the Lambda path still depends on alarm evaluation and a human-visible control plane.

Q7. A delegated admin role can create IAM roles for developers. The security team wants to keep that delegation but prevent the admin from creating a role with AdministratorAccess. What should be enforced?

A. Remove iam:CreateRole from the delegated admin role.
B. Require a permission boundary on every role the admin creates, enforced by a condition on iam:PermissionsBoundary in the CreateRole call.
C. Attach an explicit Deny for AdministratorAccess to every developer role after creation.
D. Require MFA for the delegated admin role and review created roles weekly.
Correct answer: B. The question asks you to preserve the delegation while constraining it, which makes Option A the over-permissive fix in reverse (Pattern 7): it eliminates the escalation by eliminating the capability. Option C is a detect-and-remediate answer to a prevent question.

Q8. On-call engineers are paged repeatedly by isolated latency spikes that resolve on their own, and the team wants to page only when a genuine incident is underway. What should be configured?

A. Lower the latency alarm threshold so spikes are caught earlier.
B. Increase the alarm's evaluation period to 24 hours so transient spikes are averaged out.
C. A composite alarm that enters ALARM only when both the latency alarm and the error-rate alarm are in ALARM state.
D. Delete the latency alarm and rely on customer support tickets as the signal.
Correct answer: C. Options A and B are correct answers to a different question (Pattern 8): both change alarm behavior, neither addresses correlated false positives. Option D removes the signal entirely rather than correlating it.

Q9. A company wants a dedicated account that aggregates CloudTrail logs from every account and cannot be modified by workload teams. Where should this account live, and how should it be protected?

A. In the management account, since it already has the broadest permissions in the Organization.
B. In a dedicated Security OU with an SCP that denies deletion or modification of logging resources.
C. Inside the Workloads/Prod OU so it is close to the data it audits.
D. In a standalone account outside the Organization, with cross-account access granted to the security team.
Correct answer: B. Option A is the management-account distractor (Pattern 9): SCPs do not apply there, so the account cannot be constrained by the Organization's own guardrails. Option C places the log archive inside the OU whose members it is meant to be protected from.

Q10. A DynamoDB table using a five-value status attribute as its partition key is throttling under high write volume even though the table's provisioned capacity is well above observed throughput. What should be done?

A. Increase the table's provisioned write capacity units.
B. Switch the table to on-demand capacity mode.
C. Redesign the partition key as a composite key that spreads writes across many partitions.
D. Enable DynamoDB Accelerator (DAX) in front of the table.
Correct answer: C. The question states that capacity is already above observed throughput, which is the tell that the problem is structural rather than quantitative (Pattern 10). Options A and B change a quantity; Option D addresses read latency, not write hot partitions.

Q11. An object is rarely accessed, must survive the loss of an entire Availability Zone, and a 12-hour retrieval time is acceptable. Cost is the primary concern. Which storage class fits?

A. S3 One Zone-IA.
B. S3 Glacier Deep Archive.
C. S3 Standard-IA.
D. S3 Intelligent-Tiering.
Correct answer: B. The scope noun is Availability Zone, and Option A is the cross-AZ answer that fails it (Pattern 11) because One Zone-IA does not survive an AZ loss. Option C is durable but not the lowest cost, and Option D optimizes transitions rather than minimizing storage cost.

Q12. A team has deep existing Kubernetes tooling and multi-cloud portability requirements, and is choosing a container platform on AWS. Which fits best?

A. Amazon ECS with the EC2 launch type.
B. Amazon EKS with managed node groups.
C. AWS Lambda with container image packaging.
D. AWS Batch on Fargate.
Correct answer: B. The question states the team's existing investment, which is the tell for Pattern 12. ECS is architecturally sound but discards the Kubernetes tooling and portability requirement, and Lambda and Batch do not run standard Kubernetes workloads.

Q13. After creating a Transit Gateway peering attachment between two Regions, spoke VPCs in each Region still cannot reach each other. What is the most likely cause?

A. The two Transit Gateways are in different Availability Zones.
B. Peering attachments do not support route propagation, so static routes must be added to each TGW route table.
C. Inter-Region peering is not supported and a Direct Connect connection is required.
D. Security groups in the spoke VPCs are blocking inter-Region traffic by default.
Correct answer: B. This is the same service opposite failure mode shape: VPC and TGW attachments propagate routes, peering attachments do not. Option C is a plausible-sounding but false limitation, and Option D misattributes a routing gap to security groups.

Q14. A team has documented DR runbooks with stated RTO and RPO targets but has never exercised them. What should be done before relying on them?

A. Increase backup frequency so the RPO target is more likely to be met.
B. Add a CloudWatch alarm on replication lag so failures are detected sooner.
C. Run a Game Day using AWS Fault Injection Service to simulate the failure and validate that the runbook and automated recovery actually work.
D. Document the runbook in more detail and have it reviewed by the architecture team.
Correct answer: C. Options A and B confuse detection with recovery (Pattern 14): both improve noticing, neither validates that recovery works. Option D improves the documentation of an unverified procedure, which is the assumption the question is asking you to test.

Q15. Finance wants AWS spend broken out per business unit, but resources are inconsistently tagged today. What should be done first?

A. Enable AWS Compute Optimizer to identify over-provisioned instances and reduce spend.
B. Enforce a mandatory tagging policy requiring cost allocation tags at resource creation, then activate those tags for cost allocation reporting.
C. Enable Cost Explorer and group by account, since each business unit has its own account.
D. Build a Cost and Usage Report and reconcile it manually against a spreadsheet of business unit ownership.
Correct answer: B. Option A is the correct answer to a different question (Pattern 8): Compute Optimizer reduces spend but does not attribute it. Option D produces granular data that is still unattributable without tag hygiene, which is the prerequisite the question is asking about.

Preview

The uncomfortable question this analysis leaves open is whether the patterns you just tallied are actually gone, or whether you have simply learned to recognize them in the specific phrasing Mock Exam 3 used. Pattern recognition trained on one question bank is a fragile asset. It survives a re-read of the same exam and collapses the moment the same underlying trap is dressed in different vocabulary, which is exactly what a different vendor's question bank will do to you.

Mock Exam 4 is the test of that fragility, and it is deliberately scheduled as a full 75-question timed run from a different source than the first three. If your score holds or improves, the decision rules you wrote today are doing real work. If it drops, the drop is diagnostic rather than discouraging: it tells you which patterns you learned as shapes rather than as principles, and those are the ones to rewrite before Mock Exam 5. Sit it under the same conditions as the previous three, with the decision rules on a separate page you do not consult until the review.

Sources