Mock Exam 3 Distractor Analysis & Timing/Pacing Strategy
Recap
Mock Exam 3 was the consistency check: the third full 75-question timed run, and the first one where the score should have stopped bouncing around and started trending toward the 80%+ target range. That is a different kind of result than Mock Exam 1 or 2 produced. A rising score on a third attempt can mean the deep reviews worked, or it can mean the question bank has become familiar enough that pattern recognition is doing work that understanding should be doing. Those two explanations look identical on a score report and they fail in opposite directions on exam day.
This is the same service opposite failure mode problem in its purest form. The same mock exam that proves your content gaps are closing can also be quietly teaching you to answer by shape rather than by reasoning, and the only instrument that separates the two is the timing data you have been ignoring. Mock Exam 3 is the last run where you still have enough runway to act on what the clock says, so the analysis today is deliberately split: half of it is the distractor patterns that keep costing you points, and half of it is the per-question time data that tells you whether those points were lost to ignorance or to overthinking.
Foundations You'll Need Today
Today's analysis is about why wrong answers are wrong, and almost every distractor pattern below is built on a prerequisite concept that the exam assumes you already know cold. If you are coming to this curriculum from a foundational background, the patterns will read as arbitrary trivia rather than as consequences of how AWS actually works. So before the patterns, here are the five ideas this specific day leans on hardest.
AWS Organizations, OUs, and SCPs
AWS Organizations is the mechanism that lets one company treat many separate AWS accounts as a single managed group. Instead of logging into forty accounts individually, you create the Organization once, invite or create the accounts into it, and then administer them from a central place. Inside the Organization you arrange accounts into organizational units, or OUs, which are just folders: a Security OU, a Workloads OU, a Sandbox OU. The point of the folders is that you can attach rules to a folder and have those rules apply to everything inside it.
Those rules are called Service Control Policies, or SCPs. An SCP is not a grant of permission; it is a ceiling. It says "no principal in any account under this OU may ever do these things," and it applies on top of whatever IAM policies already exist. That is why SCPs are the answer whenever a question says a restriction must apply to administrators too, or must not be removable by workload teams. The one structural exception worth memorizing is that SCPs do not apply to the management account, which is the account that owns the Organization. That single fact is the reason several of today's distractors are wrong.
IAM Roles, Trust Policies, and Permission Boundaries
An IAM role is an identity that does not belong to a person. It is a set of permissions that something can temporarily assume: an EC2 instance, a Lambda function, or a user in another account. A role has two separate policy documents, and confusing them is a common source of wrong answers. The trust policy answers "who is allowed to assume this role?" and the permissions policy answers "once assumed, what can this role do?" A role that trusts the security team's account but grants only read access is a completely normal and useful construction.
A permission boundary is a different idea: it is a maximum-permissions cap attached to an identity. If a developer is allowed to create IAM roles, a permission boundary lets you say "you may create roles, but no role you create may ever exceed these permissions," which preserves the delegation while removing the ability to escalate to full administrator. This is the mechanism behind the least-privilege pattern later today, and it is the reason "just remove the permission" is usually the wrong answer when a question asks you to keep a capability while constraining it.
RTO, RPO, and the DR Strategy Ladder
Two numbers drive every disaster recovery question. Recovery Time Objective, or RTO, is how long the business can tolerate the system being down. Recovery Point Objective, or RPO, is how much data the business can tolerate losing, expressed as an amount of time: an RPO of five minutes means you may lose up to the last five minutes of writes. These are business decisions, not technical ones, and the exam gives them to you precisely so you can use them as filters.
The four standard DR strategies form a ladder from cheapest-and-slowest to most-expensive-and-fastest: Backup and Restore, then Pilot Light, then Warm Standby, then Multi-Site Active-Active. Backup and Restore has almost no standing cost and an RTO measured in hours. Pilot Light keeps data continuously replicated and a minimal core running, giving an RTO in the tens of minutes. Warm Standby runs a scaled-down but fully functional copy, and Active-Active runs everything everywhere. The reason this matters today is that a distractor will often name the cheapest rung of the ladder and attach a correct cost claim to it, while the question's stated RTO quietly rules that rung out.
Route 53 Resolver Endpoints: Inbound vs Outbound
DNS is the system that turns a name like db.internal.example.com into an IP address. AWS runs a DNS resolver inside every VPC so that resources in that VPC can look names up. A private hosted zone is a set of DNS records that only resolves from inside the VPCs you associate with it, which is how internal service names stay invisible to the public internet.
The hybrid problem is that on-premises servers and AWS resources often need to resolve each other's names, and the two directions require different pieces of infrastructure. A Route 53 Resolver inbound endpoint is a set of IP addresses inside your VPC that on-premises DNS servers can forward queries to, so on-premises can resolve AWS names. An outbound endpoint is the reverse: it lets AWS resources forward queries out to your on-premises DNS servers. The naming is from AWS's point of view, which is why it feels backwards at first. The reliable habit is to ask who is asking and who is answering before choosing an endpoint type.
DynamoDB Partition Keys and Hot Partitions
DynamoDB is a managed NoSQL database that stores data across many physical partitions behind the scenes. Every item in a table has a partition key, and DynamoDB uses the value of that key to decide which partition the item lives on. Crucially, each partition has its own throughput ceiling, and the table-level capacity number you configure is divided across however many partitions the table currently has.
This creates a failure mode that looks like a capacity problem but is not one. If your partition key has only a handful of distinct values, say a status field with five possible states, then every item with the same status lands on the same partition. All the write traffic for that status concentrates on one partition, that partition hits its own ceiling, and the table throttles even though the table-level capacity is far above the total observed throughput. The fix is structural rather than quantitative: redesign the key so its values spread evenly, for example by combining the status with a high-cardinality value like a customer ID. This is the mechanism behind the "solves the symptom" pattern below.
With that grounding, here is why the exam's wrong answers are wrong in the specific ways they are, and what each pattern is actually testing.
Distractor Patterns From Mock Exam 3
Each entry below is a recurring wrong-answer shape rather than a single question. The exam reuses a small number of these shapes across every domain, which is why a distractor you fell for on a networking question will reappear wearing a database costume three sections later. For each one, the useful work is naming the tell that separates it from the correct answer, because the tell is what you actually apply under time pressure.
Pattern 1: The Single-Account Answer to a Multi-Account Question
The most common distractor family on this exam is an option that solves the stated problem correctly but does so inside one account. A question describes forty accounts, a central security team, and a requirement that no workload team can disable logging, and one option reads something like "create an IAM role in each account with a trust policy allowing the security team to assume it." That option is not wrong in the sense of being impossible. It is wrong because it requires forty separate trust policies, forty separate role definitions, and forty separate places for drift to accumulate, and the question's framing about a central team is the tell that the examiner wants an Organizations-level mechanism.
The tell is almost always a phrase about scale or central control: "across all accounts," "without per-account configuration," "cannot be modified by workload teams." When you see one of those, eliminate any option whose implementation is per-account, even if the option is technically functional. On Mock Exam 3 this shape showed up in the governance questions and again in a networking question about sharing a VPC, where the tempting answer was VPC peering between every pair of accounts and the correct answer was RAM subnet sharing from a central network account.
Pattern 2: The Service That Exists But Does Not Do That
This pattern is more dangerous than the first because it requires you to know a service well enough to know its boundary. The distractor names a real AWS service, describes a plausible-sounding capability, and the capability is simply not something that service does. "Use AWS Config to block the API call" is the canonical example: Config evaluates and reports, it does not deny. "Use CloudTrail to alert on the change" is the same shape, because CloudTrail records what happened after the fact and has no enforcement path.
The tell is a verb mismatch. Read the option and ask what the verb requires: prevention, detection, or notification. SCPs, permission boundaries, and resource policies prevent. Config rules, GuardDuty, and CloudTrail detect. SNS, EventBridge, and CloudWatch alarms notify. If the question says "prevent" or "ensure that no one can," any option whose verb is detect or notify is a distractor regardless of how well the service fits the domain. Mock Exam 3 leaned on this in the SCP section, where an option proposed using an IAM policy to restrict a region for an entire account, which fails because IAM policies cannot constrain the account's own root user or the services that do not honor identity policies.
Pattern 3: The Cheaper Option That Violates a Stated Constraint
Cost questions are where this pattern lives, and it is the one that most often survives a first pass because the arithmetic in the option is genuinely correct. A question states an RTO of fifteen minutes and an RPO of five minutes, and one option is Backup and Restore with a note that it is the lowest-cost approach. The cost claim is true. The option is still wrong because Backup and Restore cannot meet a fifteen-minute RTO for a workload of any real size, and the question gave you the RTO precisely so you would use it as a filter.
The tell is that the question contains a number you have not yet used. SAP-C02 rarely includes a constraint for decoration. If you find yourself choosing an option without having referenced the RTO, the RPO, the latency target, or the throughput figure in your reasoning, go back and check whether the option you picked actually satisfies it. On Mock Exam 3 this appeared in the DR section and again in a DynamoDB question where the cheap option was provisioned capacity with auto scaling for a workload the question had described as wildly unpredictable.
Pattern 4: The Right Service With the Wrong Configuration Mode
Here the service is correct and the mode is wrong, which makes the option feel like a near-miss and therefore hard to eliminate. Storage Gateway is the classic host: a question about replacing physical tape infrastructure offers File Gateway, Volume Gateway in stored mode, and Tape Gateway, and only the last one preserves the existing backup software's workflow. The service family is right in all three options, so the discriminator has to be the interface the workload actually speaks.
The tell is the word describing the existing interface: file, block, or tape. Ask what the on-premises system presents today and match the mode to it rather than to the general category. The same shape appears with DMS migration types, where Full Load and Full Load plus CDC are both correct DMS configurations and only one satisfies a minimal-downtime requirement, and with Step Functions Standard versus Express, where both are correct workflow types and only one fits a high-volume short-duration workload. Mock Exam 3 used this in the migration section and in a caching question where Redis and Memcached were both plausible until the question mentioned failover.
Pattern 5: The Answer That Adds a Hop Nobody Asked For
Some distractors are architecturally sound and simply insert an unnecessary component. A question asks how to let on-premises servers resolve names in a private hosted zone, and one option proposes a Route 53 Resolver outbound endpoint with a forwarding rule. That is a real pattern, it is documented, and it solves the inverse problem. The correct answer is an inbound endpoint, because the direction of the query is what determines which endpoint type you need.
The tell is to restate the question as a direction: who is asking, and who is answering. Inbound endpoints answer queries coming from outside AWS. Outbound endpoints ask queries going to outside AWS. Once you have written the direction down, the extra-hop options eliminate themselves. This pattern also shows up in hybrid connectivity, where an option will route traffic through a Transit Gateway when the requirement is to expose a single service and the correct answer is PrivateLink, and in observability, where an option proposes X-Ray when the question is about verifying a user-facing flow from outside the infrastructure and the correct answer is a Synthetics canary.
Pattern 6: The Manual Step Hidden Inside an Automated-Sounding Option
This one is designed to catch candidates who are pattern-matching on the word "automated." An option will describe an automated pipeline and then include a clause like "with an operator approving the failover in the console" or "after the on-call engineer updates the DNS record." The automation is real, but the recovery path still depends on a human being awake and available, which contradicts any question that specifies an RTO measured in seconds or minutes.
The tell is a human subject in the option's verb. Scan for "operator," "engineer," "administrator," "manually," and "approves." If the question's RTO is under about fifteen minutes, any option containing one of those words is almost certainly wrong, because the human response time alone consumes the budget. Mock Exam 3 used this in the multi-region section, where the tempting answer was a Lambda triggered by a CloudWatch alarm to update Route 53, and the correct answer was Global Accelerator or Route 53 ARC depending on whether the question emphasized network-layer failover or auditable failover control.
Pattern 7: The Over-Permissive Fix for a Least-Privilege Question
When a question describes a privilege escalation risk, one distractor will always be the blunt instrument: remove the permission entirely, or attach AdministratorAccess and rely on review. Removing iam:CreateRole from a delegated admin does eliminate the escalation, and it also eliminates the delegation the question asked you to preserve. The correct answer is a permission boundary enforced by a condition on the create call, which caps the new role's maximum permissions without removing the ability to create roles at all.
The tell is whether the question asks you to preserve a capability while constraining it. If it does, any option that removes the capability is wrong, and any option that leaves it unconstrained is also wrong. The answer has to be a constraint mechanism: permission boundaries, SCPs, or a condition key. Mock Exam 3 used this shape in the IAM section and in a Control Tower question where the tempting answer was to disable an elective guardrail rather than to understand that mandatory guardrails cannot be disabled at all.
Pattern 8: The Correct Answer to a Different Question
This is the most expensive pattern to fall for because the option is not merely plausible, it is a well-formed answer to a question the examiner did not ask. A question about reducing alert fatigue offers "lower the alarm threshold" and "increase the evaluation period to twenty-four hours," both of which are real techniques for changing alarm behavior, and neither of which addresses the stated problem of correlated false positives. The correct answer is a composite alarm requiring two signals to be in ALARM simultaneously.
The tell is to reread the question's problem statement after you have picked an answer and confirm that your choice addresses that specific problem rather than a neighboring one. This is also the pattern that produces the most second-guessing, which is why it belongs in the flag-and-review set rather than the answer-now set. On Mock Exam 3 it appeared in the observability section and in a cost question where the tempting answer was Compute Optimizer for a problem that was actually about tag hygiene, and the correct answer was enforcing cost allocation tags before any reporting could be meaningful.
Pattern 9: The Distractor That Is True Only in the Management Account
Organizations questions have a dedicated distractor family built around the management account's special status. An option will propose applying an SCP to the management account, or running a workload there because it has the broadest permissions, or using it as the log archive. Each of these is wrong for a specific structural reason: SCPs do not apply to the management account, workloads there cannot be constrained by the org's own guardrails, and the log archive belongs in a dedicated Security OU account precisely so that workload teams cannot reach it.
The tell is the phrase "management account" or "root account" appearing in an option that also contains a governance verb. If the option is doing anything other than billing, Organizations administration, or org-wide services like IAM Identity Center, it is a distractor. Mock Exam 3 used this in the governance section, and it is worth noting that the same logic extends to the root user of any account, which is why the mandatory Control Tower guardrail against root access keys exists.
Pattern 10: The Option That Solves the Symptom
Some distractors address the visible failure rather than its cause. A DynamoDB table is throttling under high write volume, and one option proposes increasing the table's provisioned capacity. That will help for a while and then stop helping, because the throttling is caused by a low-cardinality partition key concentrating writes onto a handful of partitions, and each partition has its own throughput ceiling regardless of the table-level number. The correct answer is to redesign the key.
The tell is whether the option changes a quantity or a structure. Quantity changes (more capacity, bigger instance, more replicas) are the tempting answers; structural changes (better key design, different routing, different replication topology) are usually the correct ones when the question describes a workload that has already been scaled up and is still failing. Mock Exam 3 used this in the DynamoDB section and in a Lambda question where the tempting answer was to increase the function timeout and the correct answer was reserved concurrency to cap downstream connections.
Pattern 11: The Cross-Region Answer to a Cross-AZ Question
Availability and durability questions are separated by a scope word, and the distractors exploit candidates who read past it. A question about surviving the loss of an Availability Zone offers a cross-region read replica, and a question about surviving a regional outage offers Multi-AZ. Both options are real architectures and both are wrong for the stated scope, because Multi-AZ does not protect against a regional event and a cross-region replica does not provide automatic failover within a region.
The tell is the scope noun: AZ, region, or account. Underline it mentally before reading the options, then eliminate anything whose blast-radius coverage is larger or smaller than what was asked. This pattern is closely related to Pattern 3, since the scope word is often the constraint the cheap option violates, but it is worth separating because the scope word appears in questions that have nothing to do with cost. Mock Exam 3 used it in the Aurora and S3 sections, where the correct answers were Aurora Global Database and Glacier Deep Archive respectively, and the tempting answers were RDS Multi-AZ and One Zone-IA.
Pattern 12: The Answer That Ignores the Existing Investment
Migration questions frequently include a constraint about what the organization already has: a team with deep Kubernetes experience, an existing VMware estate, backup software that must keep working, a Terraform-based provisioning pipeline. One distractor will propose the architecturally cleanest target that discards that investment, and it will be wrong because the question's framing made the investment a requirement rather than a preference.
The tell is a sentence in the question about the team's skills or the existing tooling. When you see one, the correct answer is usually the option that preserves it: EKS rather than ECS for the Kubernetes team, VMware Cloud on AWS rather than MGN for the estate that must not be converted, Tape Gateway rather than File Gateway for the backup software that speaks tape, AFT rather than hand-rolled account provisioning for the Terraform shop. Mock Exam 3 used this in the compute and migration sections, and it is the pattern most likely to be missed by candidates who have memorized service capabilities without reading the organizational context.
Pattern 13: The Distractor With a Plausible Number Attached
Numbers in options are a signal, and the exam uses them both ways. A correct option may cite a real limit, and a distractor may cite a number that sounds authoritative and is simply not the relevant one. Transit Gateway peering's 1500-byte MTU cap is a real figure that appears in correct answers about inter-region peering; a distractor might attach the same number to a question about intra-region attachments, where it does not apply.
The tell is whether the number is doing work in the option or decorating it. If removing the number leaves the option's logic intact, the number is decoration and you should evaluate the option on its mechanism. If removing the number breaks the option, the number is load-bearing and you need to know whether it is the right figure for the stated context. Mock Exam 3 used this in the networking section, and the practical defense is to keep a short list of the limits you have actually seen cited in the curriculum rather than memorizing numbers in isolation.
Pattern 14: The Option That Confuses Detection With Recovery
Resilience questions often describe a failure and ask what to do about it, and the distractors split between noticing and recovering. An option will propose a CloudWatch alarm on error rate, which is a detection mechanism, when the question asks how the system should behave during the failure. The correct answer is usually a degradation or failover behavior: a circuit breaker, a queue that absorbs the load, a health check that removes the endpoint, or a routing control that shifts traffic.
The tell is the question's verb again, but at a higher level than Pattern 2. Ask whether the question is asking you to observe, to prevent, or to survive. Observability questions want metrics, traces, and canaries. Prevention questions want SCPs, boundaries, and policies. Survival questions want redundancy, graceful degradation, and tested failover. Mock Exam 3 used this in the SRE section, where the tempting answer to a Game Day question was to increase backup frequency and the correct answer was to actually run the exercise and validate the runbook.
Pattern 15: The Timing Tell — Which Patterns Cost You the Clock
The second half of today's analysis is not about content at all. When you review Mock Exam 3's per-question timing, the slow questions cluster into two groups that require opposite remedies. The first group is slow because you did not know the material: you read the options twice, eliminated two, and guessed between the remaining pair. The second group is slow because you knew the material and could not commit, usually because two options were both defensible and you were hunting for a tiebreaker the question had already given you.
The remedy for the first group is content review, and the domain tagging from the previous analysis days tells you where to spend it. The remedy for the second group is a decision rule, not more studying. If you consistently lose time on Pattern 8 and Pattern 3, the fix is to write the constraint down before reading the options so the tiebreaker is visible on the first pass. If you lose time on Pattern 6 and Pattern 14, the fix is to classify the question's verb before reading the options. Both are mechanical habits, and both are worth more in the last week than another pass through the service documentation.
Hands-On Lab / Practical Action (45 min)
Pull up your Mock Exam 3 results and build two artifacts from them. The first is a pattern tally: go through every question you missed and every question you answered correctly but flagged as uncertain, and assign each one to one of the fifteen patterns above. Most people find that three or four patterns account for the majority of their misses, and that the distribution is different from what they expected. If Pattern 3 and Pattern 11 dominate, your problem is constraint-reading rather than service knowledge, and the fix is a reading habit rather than more study time.
The second artifact is a timing table. If your practice platform records per-question time, export it; if it does not, reconstruct it from your flagging behavior and your memory of where the clock felt tight. Sort the questions into four buckets: fast and correct, fast and wrong, slow and correct, slow and wrong. Fast and wrong is the most urgent bucket because it means you are confidently applying a wrong rule, and those are the misses that will not self-correct with more practice. Slow and correct is the second priority, because those are the questions where a decision rule would buy back minutes you can spend on the genuinely hard items.
Then write the decision rules down. For each of your top three patterns, write one sentence that starts with a trigger and ends with an action: "when the question says prevent, eliminate any option whose verb is detect or notify," or "when the question gives an RTO, write it down before reading the options." Keep these on the same page as your weak-spot cheat sheet, because they are the same kind of artifact and they will be reviewed together on the final day. The test of a good decision rule is that it is mechanical enough to apply while tired, which is the state you will be in during the last twenty questions of the real exam.
Finally, re-time yourself on the ten slowest questions from Mock Exam 3 with the decision rules in hand. You are not trying to get them right this time, since you have already seen the answers. You are measuring whether the rule shortens the deliberation, and if it does not, the rule is too abstract to be useful and needs to be rewritten as something more concrete. A rule that saves you thirty seconds across ten questions is worth roughly five minutes of exam time, which is the difference between finishing with a review pass and finishing with the clock at zero.
Scenario Question Drills (20 min)
Q1. A company with 40 AWS accounts wants a central security team to be able to read CloudTrail logs from every account, and no workload team may be able to disable or delete the logging. Which approach satisfies this?
Q2. A regulated workload must not be able to launch resources outside two approved AWS Regions, and the restriction must apply to every principal in the account including administrators. What should be used?
Q3. A workload can tolerate an RTO of 15 minutes and an RPO of 5 minutes, and the business wants to minimize standing infrastructure cost. Which DR strategy fits?
Q4. An enterprise wants to retire its physical backup tape infrastructure while keeping its existing backup software and workflows unchanged. What should be deployed?
Q5. On-premises DNS servers need to resolve names in a private Route 53 hosted zone hosted in a VPC. What must be configured?
Q6. A critical system must fail over between Regions within seconds when a Region becomes unhealthy, and the failover must not depend on DNS TTLs or client-side caching. What should be used?
Q7. A delegated admin role can create IAM roles for developers. The security team wants to keep that delegation but prevent the admin from creating a role with AdministratorAccess. What should be enforced?
Q8. On-call engineers are paged repeatedly by isolated latency spikes that resolve on their own, and the team wants to page only when a genuine incident is underway. What should be configured?
Q9. A company wants a dedicated account that aggregates CloudTrail logs from every account and cannot be modified by workload teams. Where should this account live, and how should it be protected?
Q10. A DynamoDB table using a five-value status attribute as its partition key is throttling under high write volume even though the table's provisioned capacity is well above observed throughput. What should be done?
Q11. An object is rarely accessed, must survive the loss of an entire Availability Zone, and a 12-hour retrieval time is acceptable. Cost is the primary concern. Which storage class fits?
Q12. A team has deep existing Kubernetes tooling and multi-cloud portability requirements, and is choosing a container platform on AWS. Which fits best?
Q13. After creating a Transit Gateway peering attachment between two Regions, spoke VPCs in each Region still cannot reach each other. What is the most likely cause?
Q14. A team has documented DR runbooks with stated RTO and RPO targets but has never exercised them. What should be done before relying on them?
Q15. Finance wants AWS spend broken out per business unit, but resources are inconsistently tagged today. What should be done first?
Preview
The uncomfortable question this analysis leaves open is whether the patterns you just tallied are actually gone, or whether you have simply learned to recognize them in the specific phrasing Mock Exam 3 used. Pattern recognition trained on one question bank is a fragile asset. It survives a re-read of the same exam and collapses the moment the same underlying trap is dressed in different vocabulary, which is exactly what a different vendor's question bank will do to you.
Mock Exam 4 is the test of that fragility, and it is deliberately scheduled as a full 75-question timed run from a different source than the first three. If your score holds or improves, the decision rules you wrote today are doing real work. If it drops, the drop is diagnostic rather than discouraging: it tells you which patterns you learned as shapes rather than as principles, and those are the ones to rewrite before Mock Exam 5. Sit it under the same conditions as the previous three, with the decision rules on a separate page you do not consult until the review.
Sources
- AWS Well-Architected Framework — pillar structure used to tag weak domains during distractor analysis.
- AWS Prescriptive Guidance — Migration Strategies — the 7 Rs framing referenced in the migration pattern entries.
- Amazon CloudWatch — Alarms and Composite Alarms — alarm semantics behind the alert-fatigue pattern.
- Amazon Route 53 — Routing Policies — routing and health-check behavior referenced in the failover patterns.
- Amazon S3 — Storage Classes — durability and retrieval characteristics behind the scope-word pattern.