Day 67 of 70 · Week 10
Day 67 / 70 Week 10 of 14 Phase 5: Practice Exams & Exam Technique

Full-Length Mock Exam 4 — 75 Questions Timed

🕑 ~75 min read · 75 exam questions · full-curriculum coverage
Exam Simulation Timed Practice Flag-and-Review

Where We Are

Mock Exam 3 gave you more than a score. It gave you time-per-question data, and the analysis on Day 66 turned that into a concrete flag-and-skip strategy: which question shapes you answer on first pass, which ones you mark and return to, and how much slack you need to leave for the second pass. That work was diagnostic. It told you where retrieval was slow and where it was confident.

Today you test whether that retrieval holds up under the conditions that actually matter. Not a review session, not a set of drills you can pause — a single 180-minute sitting, 75 questions, no notes, no lookups, no stopping to check an answer mid-exam. The score is the least interesting output. What you want out of today is evidence about stamina, pacing instinct, and whether the flag-and-review technique survives contact with a full-length paper.

Sitting Protocol

Treat this as the real thing. The SAP-C02 exam gives you 180 minutes for 75 questions, which is an average budget of about 2.4 minutes per question. That average is misleading in both directions: a short direct-knowledge question should take you well under a minute, and a four-sentence architecture scenario with four plausible options can legitimately consume four or five. The budget only works if you spend it unevenly on purpose.

Set a timer for 180 minutes and start it before you read question one. Do not pause it. Do not open a second tab, a notes file, or the AWS documentation. Do not check an answer after each question — the Reveal Answer buttons are there for the review pass, not the sitting. If you catch yourself reasoning "I'll just confirm this one thing," that is exactly the behavior the real exam forbids, and practicing it now builds a habit you cannot afford on exam day.

Work in two passes. On the first pass, answer everything you can resolve in under roughly 90 seconds and flag the rest without answering them. Flagging is not failure; it is triage. A question you half-answer and move past costs you the time you spent and still leaves you uncertain, whereas a flagged question costs nothing until you return to it with a clear head and a known amount of remaining time. Aim to finish the first pass with at least 40 minutes left on the clock.

On the second pass, work the flagged questions in the order you marked them. By this point you have seen the whole paper, and later questions sometimes reframe an earlier one — a scenario about Transit Gateway route table segmentation can quietly clarify a flagged question about shared-services VPC isolation. If a flagged question still resists after a focused two minutes, commit to your best answer and move on. There is no penalty for a wrong answer, so an unanswered question is strictly worse than a guessed one.

Why simulate the conditions rather than just work through the questions at your own pace? Because the failure mode this exam punishes is not ignorance, it is degradation under load. Retrieval that is fluent in a quiet review session gets slower at question 55 when you are tired and the clock is visible. Stamina is trainable, but only by actually running the distance. A sitting you abandon at question 40 because you got curious about an answer teaches you nothing about whether you can hold pace for 75.

When the 180 minutes are up, or when you have answered all 75, stop. Score yourself honestly, then use the Reveal Answer buttons to work through every question — including the ones you got right. The scoring guide below tells you how to convert a raw count into a rough readiness signal, and the preview explains what tomorrow does with the misses.

Mock Exam 4 — 75 Questions

Coverage spans the full curriculum to this point: multi-account governance and SCP mechanics, hybrid networking and Transit Gateway design, compute and container platforms, database selection and global replication, observability and chaos engineering, disaster recovery patterns, migration tooling, and cost optimization. Difficulty is mixed deliberately — most items are two-to-four-sentence scenarios, with a handful of short direct-knowledge questions to keep the pacing realistic.

Q1. A regulated enterprise needs a dedicated AWS account that aggregates CloudTrail logs from every other account, and workload teams must not be able to disable or delete those logs. Where should the account live, and what enforces the protection?

A. In the management account, protected by IAM policies on the root user
B. In a dedicated Security OU with an SCP that denies deletion or modification of logging resources
C. Inside the Workloads/Prod OU so it sits close to the systems it audits
D. In a standalone account outside the Organization, with cross-account log delivery
Correct answer: B. Log-archive and audit accounts belong in a dedicated Security OU guarded by SCPs that deny deletion or modification of logging resources, isolating them from workload OUs whose teams could otherwise tamper with evidence.

Q2. A developer holds an IAM policy granting s3:*. An SCP attached to their OU contains an explicit Deny for s3:DeleteBucket. The developer calls DeleteBucket on a bucket they own. What is the result?

A. It succeeds, because the IAM policy is more specific
B. It is denied — the effective permission is the intersection of IAM and SCP, and an explicit Deny always wins
C. It succeeds only if the bucket policy also allows it
D. It depends on whether the account is in the management account
Correct answer: B. SCPs set the permission ceiling and never grant access on their own; an explicit Deny in either the SCP or the IAM policy overrides any Allow.

Q3. A company wants engineers to authenticate once against corporate Okta and then assume the appropriate role in any of 40 AWS accounts, with no per-account IAM users. Which solution fits?

A. An IAM user per engineer replicated into each account
B. IAM Identity Center with SAML federation from Okta and permission sets assigned per account
C. A shared root-account access key distributed to the team
D. SCPs alone, with no identity layer
Correct answer: B. IAM Identity Center is purpose-built for centralized SSO across an Organization, provisioning short-lived federated roles per assigned account instead of long-lived IAM users.

Q4. A delegated admin role is allowed to create IAM roles for developers. You must prevent them from creating a role with AdministratorAccess. What is the standard control?

A. Attach a Deny statement to every developer role after creation
B. Require a permission boundary on every role they create, enforced by a condition on iam:PermissionsBoundary
C. Remove iam:CreateRole from the delegated admin entirely
D. Enforce MFA on the delegated admin role
Correct answer: B. A mandatory permission boundary caps the maximum permissions of any role the delegate creates, which is the standard pattern for preventing privilege escalation by delegated admins.

Q5. A central network account owns a VPC, and three application accounts must launch EC2 instances into its private subnets without owning a VPC themselves. What is the mechanism?

A. VPC peering between every pair of accounts
B. Share the subnets from the central VPC using AWS RAM
C. Replicate the VPC configuration into each application account
D. Attach each application account to the central VPC with a Transit Gateway
Correct answer: B. RAM subnet sharing lets many accounts launch resources into subnets owned by a single central VPC, avoiding per-account VPCs and peering meshes.

Q6. Which Control Tower guardrail type cannot be disabled once enabled?

A. Elective guardrails
B. Mandatory guardrails
C. Strongly recommended guardrails
D. Custom SCPs
Correct answer: B. Mandatory guardrails are always enforced and cannot be turned off; elective and strongly recommended guardrails are optional best practices enabled per OU.

Q7. A region-restriction SCP denies all actions outside two approved regions. Shortly after it is attached, account operations break. What is the most likely cause?

A. The SCP was attached to the management account
B. The SCP did not exempt global services such as IAM, Route 53, CloudFront, and Support
C. Region-restriction SCPs are not supported by AWS Organizations
D. The SCP needs an accompanying IAM policy to take effect
Correct answer: B. Region-restriction SCPs must exempt global services, or they break account operations that depend on endpoints outside the approved regions.

Q8. Dev and Prod VPCs must both reach a Shared-Services VPC but must never reach each other. How should Transit Gateway route tables be designed?

A. One flat TGW route table with all routes propagated
B. Separate TGW route tables for Dev and Prod, each propagating only Shared-Services routes, with no propagation between Dev and Prod
C. VPC peering directly between Dev and Prod, with Security Groups blocking traffic
D. A single route table with a blackhole route for the Dev CIDR
Correct answer: B. TGW route table segmentation is the standard way to isolate spokes while still allowing shared access to common services.

Q9. After creating a Transit Gateway peering attachment between two regions, spoke VPCs still cannot reach each other. What is most likely missing?

A. Static routes in each TGW route table — peering attachments do not support route propagation
B. A second peering attachment in the reverse direction
C. Security group rules allowing inter-region traffic
D. A Direct Connect connection between the regions
Correct answer: A. Unlike VPC and TGW attachments, TGW peering attachments require manually created static routes in each TGW route table; automatic propagation is not supported.

Q10. A company wants all internet-bound traffic from a dozen spoke VPCs inspected by a single AWS Network Firewall. What is the standard pattern?

A. Deploy Network Firewall independently in every spoke VPC
B. A centralized inspection VPC attached to Transit Gateway, with spoke route tables directing 0.0.0.0/0 to the TGW
C. NACLs on each spoke subnet configured to inspect egress
D. A NAT Gateway per spoke with firewall rules attached
Correct answer: B. The centralized inspection VPC pattern routes all spoke egress through TGW into a shared Network Firewall, avoiding per-VPC firewall duplication and cost.

Q11. A mission-critical workload needs the highest-resiliency Direct Connect design. What should be provisioned?

A. A single 10 Gbps DX connection
B. Two DX connections at two different DX locations, terminating on separate devices, with BGP failover and a VPN backup
C. Two identical connections at the same DX location
D. A Public VIF only, since it is cheaper
Correct answer: B. AWS's resiliency model for DX requires diversity across DX locations and devices plus BGP-based failover; a VPN backup covers the rare case both DX paths fail.

Q12. On-premises servers need to resolve names in a private Route 53 hosted zone. What do you configure?

A. A Route 53 Resolver outbound endpoint
B. A Route 53 Resolver inbound endpoint, with on-prem DNS forwarding queries to it
C. A public hosted zone mirroring the private one
D. A NAT Gateway with DNS forwarding enabled
Correct answer: B. Inbound endpoints expose AWS private DNS to on-prem resolvers; outbound endpoints do the reverse, letting AWS resources resolve on-prem names.

Q13. Two companies both use 10.0.0.0/16. One must consume a specific API hosted in the other's VPC. Which connectivity option works despite the overlap?

A. VPC peering
B. Transit Gateway peering
C. AWS PrivateLink with an Interface Endpoint and Endpoint Service
D. Direct Connect with a Private VIF
Correct answer: C. PrivateLink requires only ENI-level connectivity in the consumer VPC and never merges route tables or CIDRs, so it works with fully overlapping IP ranges.

Q14. When is PrivateLink the better choice over Transit Gateway for cross-account connectivity?

A. When you need full bidirectional network-level reachability between VPCs
B. When exposing a single specific service to many consumers without merging networks or worrying about CIDR overlap
C. When connecting an on-premises data center to AWS
D. Never — TGW always replaces PrivateLink
Correct answer: B. PrivateLink is service-level exposure — one service, many consumers, no shared routing — while TGW provides network-level connectivity for broad multi-VPC and on-prem routing.

Q15. Which endpoint type uses route table entries rather than ENIs and is available only for S3 and DynamoDB?

A. Interface endpoint
B. Gateway endpoint
C. Gateway Load Balancer endpoint
D. VPC peering endpoint
Correct answer: B. Gateway endpoints serve S3 and DynamoDB only, are configured via route table entries rather than ENIs, and carry no hourly charge.

Q16. An ECS Fargate service uses awsvpc network mode. What does that give each task?

A. A shared host ENI with port mapping
B. Its own ENI, private IP, and security group
C. A public IP by default
D. A dedicated NAT Gateway
Correct answer: B. awsvpc mode gives every task first-class networking — its own ENI, private IP, and security group — enabling per-task security instead of shared host-level rules.

Q17. A workload requires a DaemonSet on every node for log collection. Which EKS compute option should be avoided?

A. Managed node groups
B. Self-managed EC2 node groups
C. EKS Fargate profiles
D. Cluster Autoscaler on EC2
Correct answer: C. Fargate pods run in isolated micro-VMs with no shared node, so DaemonSets — which require a persistent per-node agent — are not supported.

Q18. An application takes four minutes to bootstrap before it can serve traffic, so scale-out lags demand spikes. What reduces that latency?

A. Increase the ASG cooldown period
B. Use a warm pool of pre-initialized stopped instances
C. Switch the fleet to Spot Instances
D. Add a lifecycle hook on launch
Correct answer: B. Warm pools keep instances pre-initialized so the ASG can bring them into service in seconds instead of re-running the full bootstrap sequence.

Q19. Which ALB feature enables a canary deployment that shifts a small percentage of traffic to a new version before full cutover?

A. Sticky sessions
B. Weighted target groups on a single listener rule
C. Cross-zone load balancing
D. Connection draining
Correct answer: B. Weighted target groups let one routing rule split traffic by percentage across two target groups — the ALB-native canary and blue/green mechanism.

Q20. A Lambda function reading from Kinesis is overwhelming a downstream RDS instance with connections during spikes. What limits this safely?

A. Increase the Lambda timeout
B. Set reserved concurrency on the function to cap concurrent executions
C. Increase the Kinesis shard count
D. Move RDS to Multi-AZ
Correct answer: B. Reserved concurrency caps how many instances of the function run simultaneously, directly bounding the number of concurrent downstream connections.

Q21. A high-volume IoT pipeline runs millions of short workflow executions per day and can tolerate at-least-once semantics. Which Step Functions type fits?

A. Standard Workflows
B. Express Workflows
C. Both are identical in cost
D. Neither — use SQS only
Correct answer: B. Express Workflows are priced per execution and duration for high-volume, short-duration workloads and provide at-least-once semantics, unlike Standard's exactly-once but costlier per-transition pricing.

Q22. A team has deep existing Kubernetes tooling and a multi-cloud portability requirement. Which AWS compute platform best fits?

A. ECS with the EC2 launch type
B. Amazon EKS
C. AWS Lambda
D. AWS Batch on Fargate
Correct answer: B. EKS runs standard Kubernetes, preserving existing tooling and manifests and easing multi-cloud portability, unlike ECS's AWS-proprietary orchestration model.

Q23. A global application needs a secondary region readable with sub-second replication lag and promotable to primary in under a minute during a regional outage. Which database fits?

A. RDS Multi-AZ with a cross-region read replica
B. Aurora Global Database
C. DynamoDB Global Tables only
D. RDS read replica with asynchronous replication
Correct answer: B. Aurora Global Database replicates at the storage layer across regions with typical sub-second lag and managed failover promoting the secondary in under a minute.

Q24. A team must upgrade RDS MySQL from 5.7 to 8.0 with minimal risk and a fast rollback path. What should they use?

A. An in-place major version upgrade during a maintenance window
B. RDS Blue/Green Deployments to validate on a synchronized green environment before switchover
C. Read replica promotion
D. A Multi-AZ failover
Correct answer: B. Blue/Green Deployments create a fully replicated green environment on the new version, validated before a fast, low-risk switchover, reducing the blast radius of major upgrades.

Q25. A DynamoDB table uses OrderStatus — five possible values — as its partition key and throttles under high write volume despite ample table-level capacity. Why?

A. The table needs Global Tables enabled
B. Low-cardinality partition keys create hot partitions, since each partition has its own throughput ceiling
C. On-demand capacity mode is not enabled
D. DynamoDB does not support high write volume
Correct answer: B. Each partition has its own throughput ceiling; a key with only five distinct values concentrates all writes onto a handful of partitions, causing throttling even with ample table-level capacity.

Q26. A gaming leaderboard needs microsecond read latency for the same items requested extremely frequently. What should sit in front of DynamoDB?

A. A self-managed ElastiCache for Redis cluster
B. Amazon DAX
C. CloudFront caching of API responses only
D. RDS with a read replica
Correct answer: B. DAX is a managed, DynamoDB-API-compatible in-memory cache purpose-built to shave read latency for hot items without application-level cache logic.

Q27. An object is rarely accessed, needs the lowest storage cost, tolerates a 12-hour retrieval time, and must survive the loss of an entire Availability Zone. Which S3 class fits?

A. S3 One Zone-IA
B. S3 Glacier Deep Archive
C. S3 Glacier Flexible Retrieval (Bulk)
D. S3 Standard-IA
Correct answer: B. Glacier Deep Archive is the lowest-cost class, replicated across three or more AZs — so it survives an AZ loss, unlike One Zone-IA — with retrieval times up to 12 hours.

Q28. A session store must survive a node failure without losing data and support automatic failover. Which caching engine and configuration fits?

A. Memcached with auto discovery
B. Redis with cluster mode enabled and replicas per shard
C. Memcached with multiple nodes
D. Redis without replicas
Correct answer: B. Only Redis supports replication and automatic failover; Memcached has no replication, so node failure means data loss for those keys.

Q29. An application needs single-digit-millisecond reads and writes at massive unpredictable scale with a flexible schema, across multiple regions actively writing. What fits best?

A. Aurora Global Database
B. DynamoDB Global Tables
C. RDS with cross-region read replicas
D. ElastiCache alone as the system of record
Correct answer: B. DynamoDB Global Tables provide multi-active, multi-region writes at single-digit-millisecond latency with a flexible schema — a fit Aurora Global DB (single writer region) and RDS replicas do not match.

Q30. Which S3 feature replicates objects asynchronously to a bucket in another region for disaster recovery?

A. Same-Region Replication (SRR)
B. Cross-Region Replication (CRR)
C. S3 Transfer Acceleration
D. S3 Intelligent-Tiering
Correct answer: B. CRR replicates objects asynchronously to a bucket in a different region, commonly for DR or data-residency requirements; SRR stays within one region.

Q31. On-call engineers are fatigued by alarms firing on isolated latency spikes that self-resolve. What reduces noise while still catching real incidents?

A. Delete the latency alarm
B. A composite alarm requiring both the latency alarm and the error-rate alarm to be in ALARM state
C. Lower the alarm threshold
D. Increase the evaluation period to 24 hours
Correct answer: B. Composite alarms let you require correlated signals before paging, cutting single-metric false positives while preserving sensitivity to genuine multi-symptom incidents.

Q32. Internal CloudWatch metrics show healthy servers, but customers report the login page is broken. What monitoring gap does this reveal?

A. Missing X-Ray tracing
B. No outside-in synthetic monitoring of the actual user flow
C. Missing VPC Flow Logs
D. Insufficient EC2 instance count
Correct answer: B. Server-side health metrics do not verify end-to-end user experience; Synthetics canaries probe from outside the infrastructure, catching failures invisible to internal metrics.

Q33. A microservices application has growing p99 latency, but it is unclear which of twelve services is the bottleneck. What pinpoints it?

A. CloudWatch Logs Insights alone
B. AWS X-Ray, using the service map to isolate the slow hop
C. VPC Flow Logs
D. AWS Config
Correct answer: B. X-Ray's distributed tracing and service map visualize per-hop latency across the full call chain, directly identifying the bottleneck service that aggregate metrics cannot isolate.

Q34. An organization wants every account's application logs centrally searchable in a dedicated logging account in near-real time. What is the mechanism?

A. Manually export logs nightly to S3
B. CloudWatch Logs subscription filters streaming to Kinesis Data Firehose in the central logging account
C. CloudTrail only
D. Increase log retention in each account
Correct answer: B. Subscription filters push log events in near-real time to a destination — commonly Kinesis Firehose or Streams — in a centralized account, enabling org-wide log aggregation.

Q35. A team wants to safely test EC2 instance failure in production without risking an uncontrolled outage. What FIS feature guarantees the experiment halts if things go wrong?

A. IAM permission boundaries
B. Stop conditions tied to CloudWatch alarms
C. Increasing the blast radius
D. Manual monitoring only
Correct answer: B. FIS stop conditions automatically abort a running experiment the moment a linked CloudWatch alarm enters ALARM state, capping the blast radius of chaos testing.

Q36. A team has documented DR runbooks but has never tested them under simulated failure. What is the recommended next step before relying on them?

A. Trust the documentation as-is
B. Run a Game Day exercise using FIS to simulate the failure and validate the runbook and automated recovery
C. Increase backup frequency only
D. Skip testing to avoid production risk
Correct answer: B. Untested runbooks are unverified assumptions; a Game Day exercises the real failure mode against real infrastructure to confirm RTO and RPO targets are actually achievable.

Q37. An active-active application needs sub-second failover at the network layer when a region's health checks fail, independent of DNS TTL and caching issues. What should be used?

A. Route 53 latency-based routing alone
B. AWS Global Accelerator, which uses static anycast IPs and reroutes at the AWS network edge
C. CloudFront alone
D. A single-region Network Load Balancer
Correct answer: B. Global Accelerator uses anycast IPs and AWS's global network for near-instant failover, avoiding the client-side DNS caching delays inherent to Route 53-only failover.

Q38. A workload tolerates an RTO of 15 minutes and an RPO of 5 minutes, but the business wants to minimize standing infrastructure cost. Which DR pattern fits best?

A. Backup and Restore
B. Pilot Light
C. Multi-Site Active-Active
D. No DR strategy needed
Correct answer: B. Pilot Light keeps only core data continuously replicated and minimal infrastructure running, scaling up the rest on failover — matching a roughly 15-minute RTO at much lower cost than warm standby or active-active.

Q39. A critical financial system needs failover control that itself will not fail if an entire AWS region goes down, plus proof the standby region is actually ready to serve traffic. What should be configured?

A. Route 53 simple health-check failover only
B. Route 53 Application Recovery Controller with readiness checks and a highly available routing control cluster
C. CloudWatch Alarms triggering a Lambda failover
D. Global Accelerator alone
Correct answer: B. ARC's routing control cluster is deliberately distributed across regions and partitions for resilience of the failover mechanism itself, and readiness checks validate standby capacity before you rely on it.

Q40. You want most users routed to the AWS region with the lowest network latency for them, automatically. Which Route 53 policy fits?

A. Weighted routing
B. Latency-based routing
C. Simple routing
D. Geolocation routing
Correct answer: B. Latency-based routing uses AWS's latency measurements between users and regions to route each request to the lowest-latency healthy endpoint.

Q41. A company needs ransomware-resilient backups that cannot be deleted even by a compromised admin account. What should they configure?

A. Standard EBS snapshots only
B. AWS Backup with a cross-account copy into an isolated account, in a vault with Backup Vault Lock enabled
C. S3 versioning only
D. Increased snapshot frequency
Correct answer: B. Cross-account isolation prevents a compromised primary account from touching backups, and Vault Lock makes the retention policy immutable — even the root user cannot delete locked backups before expiry.

Q42. Which best exemplifies the Reliability pillar's failure-management best practice?

A. Using the largest possible instance type
B. Automatically testing recovery procedures via Game Days and setting quantified RTO/RPO targets
C. Manually reviewing logs weekly
D. Avoiding all managed services
Correct answer: B. Failure management is about anticipating failure, testing recovery through Game Days, and having quantified, validated RTO and RPO — not just provisioning bigger resources.

Q43. A team manually SSHes into servers to apply emergency patches, occasionally causing configuration drift. Which Operational Excellence practice addresses this?

A. Increase server count
B. Perform operations as code using SSM Automation documents instead of manual SSH changes
C. Disable CloudTrail logging
D. Add more IAM users
Correct answer: B. Operations as code — codifying operational procedures such as SSM Automation documents — eliminates ad hoc manual changes and the drift and error they introduce.

Q44. A workload requires near-zero RTO and RPO, and budget is not the primary constraint. Which DR strategy and supporting service pairing fits?

A. Backup and Restore with AWS Backup
B. Pilot Light with manual DNS updates
C. Multi-Site Active-Active with Route 53 ARC and DynamoDB Global Tables or Aurora Global Database
D. Warm standby without health checks
Correct answer: C. Near-zero RTO and RPO demand live traffic serving from multiple regions with deterministic, tested failover control and multi-region-write-capable data services.

Q45. A data center lease expires in six months, forcing a fast migration, but two legacy applications have unresolved software licensing blockers. What is the correct 7 Rs plan?

A. Refactor everything to serverless
B. Rehost the majority via MGN to meet the deadline; Retain the two blocked applications until licensing is resolved
C. Repurchase all applications as SaaS
D. Retire every application
Correct answer: B. Under a tight deadline, Rehost is the fastest path for most applications; applications with real blockers should be explicitly Retained rather than forced into a rushed migration.

Q46. A migration team needs to map network dependencies between individual processes on each server before planning migration waves. What captures this?

A. Agentless Discovery Connector only
B. Agent-based discovery, which captures process-to-process network connections
C. AWS Config
D. CloudTrail
Correct answer: B. Agent-based discovery installs a lightweight agent per server and captures fine-grained, process-level network connections; agentless discovery only gives VM-level inventory and utilization.

Q47. A company needs to rehost 200 on-premises VMs to EC2 as fast as possible with minimal application changes and minimal cutover downtime. What should they use?

A. AWS DataSync
B. AWS Application Migration Service (MGN)
C. AWS Schema Conversion Tool
D. AWS DMS
Correct answer: B. MGN is purpose-built for server rehost: continuous replication lets you test extensively and cut over with just minutes of downtime, without re-architecting the application.

Q48. SCT reports a 92% automatic conversion rate for an Oracle-to-PostgreSQL migration. What does this mean for the remaining 8%?

A. The migration is essentially complete and can proceed unattended
B. Complex objects such as certain stored procedures and functions could not be auto-converted and need manual developer remediation before cutover
C. SCT failed and DMS cannot be used
D. 8% of the data will be lost during migration
Correct answer: B. SCT's conversion percentage reflects schema and code objects only; a high percentage still commonly leaves complex procedural logic that must be manually rewritten before the heterogeneous migration is production-ready.

Q49. A company needs to continuously sync a large on-premises NFS file share into Amazon EFS on a schedule, without writing custom scripts. What should they use?

A. AWS DMS
B. AWS DataSync
C. AWS Snowball Edge
D. AWS Storage Gateway File Gateway
Correct answer: B. DataSync is purpose-built for automated, scheduled, validated file and object transfer between on-premises file systems and AWS storage services such as EFS, FSx, and S3.

Q50. An enterprise wants to eliminate its physical backup tape infrastructure while keeping existing backup software unchanged. What should they deploy?

A. File Gateway
B. Volume Gateway in stored mode
C. Tape Gateway (Virtual Tape Library)
D. AWS Backup only
Correct answer: C. Tape Gateway presents a virtual tape library interface compatible with existing backup software, letting you retire physical tape hardware without changing backup workflows.

Q51. A company must migrate 2 PB of data from a facility with no viable network uplink for bulk transfer. What is the appropriate approach?

A. AWS DataSync over the internet
B. Direct Connect provisioned overnight
C. Multiple AWS Snowball Edge Storage Optimized devices, or Snowmobile for the full 2 PB in one engagement
D. AWS Storage Gateway
Correct answer: C. At petabyte scale with no adequate network path, physical offline transfer via Snow Family devices is the standard, cost-effective solution.

Q52. A hospital must keep patient data physically on-premises for regulatory reasons while still using native AWS APIs such as EC2, EBS, and RDS. What should they deploy?

A. AWS Local Zones
B. AWS Wavelength
C. AWS Outposts
D. A standard AWS Region with encryption at rest
Correct answer: C. Outposts physically places AWS-managed infrastructure inside the customer's own data center, satisfying strict data-residency requirements while retaining native AWS service APIs.

Q53. A team wants to move VMware VMs to AWS infrastructure fastest, keeping the exact same hypervisor-level configuration and VMware management tools, with no conversion. Which strategy fits?

A. Rehost to native EC2 with AWS MGN
B. Relocate with VMware Cloud on AWS
C. AWS Schema Conversion Tool
D. AWS DataSync
Correct answer: B. Relocate via VMware Cloud on AWS is the only 7 Rs strategy that moves the VM without converting it out of the VMware format, unlike Rehost which lands on native EC2 and AMIs.

Q54. A migration must move 300 TB of historical data plus ongoing daily deltas of about 50 GB, over a link capped at 500 Mbps. What is the recommended approach?

A. Transfer everything, including historical data, over the 500 Mbps link
B. Use Snowball Edge for the 300 TB bulk historical transfer, then DMS CDC or DataSync over the network link for ongoing deltas
C. Wait for the network link to be upgraded before starting
D. Use Snowmobile for the entire migration
Correct answer: B. This hybrid pattern — offline bulk transfer for the large historical dataset, then network-based CDC or incremental sync for the small ongoing delta — is a standard approach to large migrations over constrained links.

Q55. A company runs a steady-state, predictable production fleet but wants maximum flexibility to change instance families and regions over the commitment period. What should they buy?

A. EC2 Instance Savings Plans
B. Compute Savings Plans
C. Standard Reserved Instances
D. Spot Instances
Correct answer: B. Compute Savings Plans apply across any instance family, region, and OS, and even to Fargate and Lambda usage, trading a slightly lower discount than EC2 Instance Savings Plans for maximum flexibility.

Q56. A company suspects many EC2 instances are oversized relative to actual CPU and memory utilization but does not know which ones. What AWS service directly recommends right-sizing changes?

A. AWS Config
B. AWS Compute Optimizer
C. AWS Trusted Advisor cost checks only
D. CloudWatch Alarms
Correct answer: B. Compute Optimizer analyzes historical utilization and provides specific instance-type right-sizing recommendations with projected savings, more targeted than Trusted Advisor's general cost checks.

Q57. Finance wants AWS spend broken out per business unit, but resources are inconsistently tagged today. What should be enforced first?

A. Enable Cost Explorer only
B. Enforce a mandatory tagging policy requiring cost-allocation tags at resource creation, then activate those tags for cost allocation reporting
C. Use a single shared account for all business units
D. Manually track spend in a spreadsheet
Correct answer: B. Cost allocation reporting is only as good as tag hygiene; enforcing mandatory tags at creation time via SCP or Config rules is the prerequisite before per-business-unit cost reports become meaningful.

Q58. Which Spot Instance behavior must an application be designed to handle?

A. A 30-minute termination notice
B. A two-minute interruption notice before the instance is reclaimed
C. Immediate termination with no notice
D. Automatic conversion to On-Demand pricing
Correct answer: B. Spot Instances deliver a two-minute interruption notice, which is why fault-tolerant workloads pair them with interruption handlers and mixed-instance Auto Scaling Groups.

Q59. A migration is homogeneous — both source and target are PostgreSQL. Which tool moves the data with minimal downtime?

A. AWS Schema Conversion Tool
B. AWS Database Migration Service with full load plus change data capture
C. AWS DataSync
D. AWS Snowball Edge
Correct answer: B. Homogeneous migrations need no schema conversion, so DMS with full load plus CDC handles the data move and keeps the target current with minimal downtime.

Q60. A DMS task must migrate a table containing large binary objects and is failing repeatedly. What is the most likely cause?

A. The replication instance is in the wrong region
B. LOB handling requires specific task settings and adequate replication instance storage and memory
C. DMS does not support binary columns
D. CDC must be disabled for LOB tables
Correct answer: B. Large object handling in DMS depends on task-level LOB settings and sufficient replication instance resources; undersized instances or default LOB modes are a common cause of repeated task failures.

Q61. Which statement about SCPs is correct?

A. SCPs grant permissions to IAM identities in member accounts
B. SCPs define the maximum available permissions but never grant access on their own
C. SCPs apply to the management account as well as member accounts
D. SCPs replace the need for IAM policies entirely
Correct answer: B. SCPs set the permission ceiling for accounts in an OU but never grant access by themselves, and they do not apply to the management account.

Q62. A company wants pipeline-driven account provisioning layered on top of Control Tower's baseline guardrails, for teams already standardized on Terraform. What should they adopt?

A. Manual account creation through the Organizations console
B. Account Factory for Terraform (AFT)
C. A custom Lambda that calls Organizations APIs
D. AWS RAM
Correct answer: B. AFT extends Control Tower with pipeline-driven account provisioning and customizations for teams standardized on Terraform.

Q63. Which STS API is used by EKS pods to obtain credentials through IAM Roles for Service Accounts?

A. AssumeRole
B. AssumeRoleWithWebIdentity
C. AssumeRoleWithSAML
D. GetSessionToken
Correct answer: B. IRSA uses OIDC federation, and the pod exchanges its projected service account token via AssumeRoleWithWebIdentity.

Q64. What is the maximum MTU across an inter-region Transit Gateway peering attachment?

A. 9001 bytes
B. 1500 bytes
C. 8500 bytes
D. 1280 bytes
Correct answer: B. Inter-region TGW peering caps MTU at 1500 bytes, which matters for workloads that assume jumbo frames within a region.

Q65. Which Direct Connect virtual interface type connects a DX connection to a Transit Gateway, enabling access to many VPCs?

A. Private VIF
B. Transit VIF
C. Public VIF
D. Hosted VIF
Correct answer: B. A Transit VIF associates the DX connection with a Transit Gateway, giving reachability to many VPCs rather than a single VPC as with a Private VIF.

Q66. A Lambda function must reach a private RDS instance in a VPC. What must be configured?

A. A public IP on the function
B. VPC configuration on the function, with subnets and a security group that can reach the database
C. An internet gateway on the VPC
D. A NAT Gateway only
Correct answer: B. Attaching the function to VPC subnets with an appropriate security group is what gives it network reachability to the private database.

Q67. Which service provides a query language over CloudWatch Logs for ad-hoc analysis without standing up additional infrastructure?

A. AWS Config
B. CloudWatch Logs Insights
C. AWS X-Ray
D. Amazon Athena
Correct answer: B. Logs Insights provides a purpose-built query language over CloudWatch Logs for ad-hoc analysis without additional infrastructure.

Q68. Which AWS Backup feature enforces write-once-read-many immutability on a backup vault?

A. Lifecycle policies
B. Backup Vault Lock
C. Cross-region copy
D. Backup plans
Correct answer: B. Vault Lock makes the retention policy immutable, so even the root user cannot delete locked backups before their expiry.

Q69. A workload needs single-digit-millisecond latency to on-premises industrial control systems inside a manufacturing plant, and the company is willing to own the hardware. What fits?

A. AWS Local Zones
B. AWS Wavelength
C. AWS Outposts
D. A standard AWS Region with Global Accelerator
Correct answer: C. Outposts places AWS-managed infrastructure in the customer's own facility, which is what delivers single-digit-millisecond latency to on-premises control systems.

Q70. Which statement about Aurora Global Database is correct?

A. It replicates using MySQL binlog shipping
B. It replicates at the storage layer, typically with sub-second cross-region lag
C. It requires a separate writer in every region by default
D. It cannot be promoted during a regional outage
Correct answer: B. Aurora Global Database replicates at the storage layer rather than through binlog shipping, which is what delivers typical sub-second cross-region lag and sub-minute promotion.

Q71. A team needs to shift 5% of production traffic to a canary deployment and automatically pull it from rotation if it fails health checks. Which combination fits?

A. Route 53 simple routing with no health checks
B. Route 53 weighted routing combined with a health check on the canary endpoint
C. Route 53 geolocation routing
D. A single ALB target group with sticky sessions
Correct answer: B. Weighted routing shifts a controlled percentage of traffic, and the attached health check removes the canary from DNS responses automatically when it fails.

Q72. Which service continuously validates that a standby region actually has the capacity and configuration to take over before you rely on it?

A. AWS Config
B. Route 53 ARC readiness checks
C. CloudWatch Synthetics
D. AWS Trusted Advisor
Correct answer: B. ARC readiness checks validate that a standby region has the capacity and configuration to serve traffic, so failover is not a leap of faith.

Q73. A company wants to reduce cost on a fault-tolerant batch workload that can be interrupted. What is the most cost-effective compute purchase option?

A. On-Demand Instances
B. Spot Instances, ideally through a mixed-instance Auto Scaling Group or Spot Fleet
C. Standard Reserved Instances
D. Dedicated Hosts
Correct answer: B. Spot Instances offer the deepest discount for interruptible work, and diversifying across instance types and pools through a mixed-instance ASG or Spot Fleet reduces interruption frequency.

Q74. Which statement about DynamoDB Global Tables conflict resolution is correct?

A. Conflicts are resolved by a quorum vote across regions
B. Conflicts are resolved with last-writer-wins semantics
C. Conflicts cause the write to fail and must be retried by the application
D. Global Tables do not support concurrent writes to the same item
Correct answer: B. Global Tables use last-writer-wins conflict resolution, which is why applications with concurrent multi-region writes to the same item need to design around that behavior.

Q75. A migration team needs to track progress across MGN, DMS, and DataSync in one place. What should they use?

A. AWS Config
B. AWS Migration Hub
C. AWS Trusted Advisor
D. AWS Compute Optimizer
Correct answer: B. Migration Hub centrally tracks migration progress across tools, giving one view of application status regardless of which service is doing the work.

Scoring Guide

Count your correct answers out of 75 and convert to a percentage. As a rule of thumb — not an official AWS figure — a raw score of roughly 72% or better on a full-length mock is a reasonable proxy for exam readiness, and scores consistently above 85% suggest you are comfortably ahead of the line. Treat the threshold as a signal, not a guarantee: a mock exam is a sample, and the real paper will weight domains differently.

More useful than the headline number is the shape of the misses. Group them by domain — multi-account governance, networking, compute, databases, SRE and DR, migration, cost — and note which domain produced the most. A single weak domain dragging an otherwise strong score down is a very different problem from a broad scattering of misses, and it calls for a different response. Record both the raw score and the domain breakdown before you start reviewing answers; tomorrow's work depends on that data being accurate.

What Comes Next

You now have two things: a raw score, and a list of the domains that produced your misses. Neither is actionable on its own. A score tells you where you stand but not why, and a domain breakdown tells you where the damage is concentrated but not what kind of damage it is — a conceptual gap, a misread question, or a service you have never actually used.

Tomorrow's work is distractor analysis and flag-and-review refinement, and it acts directly on today's output. The point is to separate the misses you can fix by rereading a section from the ones that reveal a genuine misunderstanding of how a service behaves, and to look at the questions you flagged and see whether the flag was earned or whether you were simply avoiding a topic. That distinction is what turns a mock exam score into a study plan.