Day 69 / 70Week 10 of 14Phase 5: Practice Exams & Exam Technique
Full-Length Mock Exam 5 — 75 Questions Timed
🕑 ~75 min read · 2 services covered
Tutorials DojoExam Simulation
Recap
Day 68 was the final distractor-analysis pass, and its output was a short list of question shapes that reliably cost you a second look: the ones where two answers are both technically true and the discriminator is a single word in the requirement, and the ones where a plausible-sounding service appears in a distractor precisely because it is adjacent to the right answer. That analysis is only worth anything if it survives contact with a clock. Knowing which questions you tend to overthink is a different skill from being able to notice, mid-exam, that you are overthinking one right now.
Today you test whether you can retrieve all of it under time pressure. This is the fifth and final full-length sitting, and it is the last chance to find a pacing problem before the real thing. Treat the score as secondary to the pacing data — a 78% with even time distribution is a better signal than an 85% that came from sprinting the first forty questions and guessing the last ten.
Sitting Protocol
Run this exactly as you would run the real exam, because the point of a fifth sitting is not to learn content — you have already covered the content — but to rehearse the conditions under which you will retrieve it. That means 180 minutes on a timer, 75 questions, no pausing, no notes, no browser tabs, and no checking an answer until the full sitting is over. The average budget is roughly 2.4 minutes per question, but that average is a trap if you apply it uniformly. Short direct-knowledge questions should take well under a minute, and the long multi-paragraph scenarios will legitimately consume three to four. The budget is a total, not a per-question entitlement.
The flag-and-review technique is what makes the total budget workable. Answer every question in order on the first pass, but when a question resists you — when you have narrowed it to two and cannot find the discriminator — pick the better of the two, flag it, and move on. Do not spend four minutes on question 12 to protect a single point while leaving questions 60 through 75 unread. The second pass, with whatever time remains, is where flagged questions get a fresh read; a question that felt ambiguous at minute 20 often resolves instantly at minute 150 because a later question has primed the relevant distinction.
Two behaviors undermine the simulation and both are worth naming explicitly. The first is stopping early once you have answered everything, which hides whether your pacing actually holds for the full duration — the real exam does not end when you feel done, and fatigue in the last third is a real variable you want to have measured at least once. The second is looking things up mid-sitting. A lookup converts a retrieval failure into a recognition success, which feels better and teaches you nothing; the entire diagnostic value of this sitting is in seeing which facts you cannot produce from memory under load. If you catch yourself wanting to check something, write the question number down and check it after the timer expires.
Set up the environment before you start: one screen, notifications off, a clock visible, and a single sheet of paper for question numbers you want to revisit in analysis. When the 180 minutes expire, stop. Score it, then do the domain tagging — the sitting produces two artifacts, a raw score and a list of which domains the misses cluster in, and tomorrow's session consumes the second one.
The Exam — 75 Questions
Answer all 75 in one sitting before revealing any answer. Reveal is per-question so you can self-check afterward, but the sitting itself should be uninterrupted.
Q1. A company has 40 AWS accounts under AWS Organizations. The security team needs a single account that aggregates CloudTrail logs from every account, and workload teams must not be able to disable or delete that logging. Where should the log-archive account live, and what enforces the protection?
A. In the management account, protected by IAM policies
B. In a dedicated Security OU with an SCP that denies deletion or modification of logging resources
C. In the Workloads/Prod OU so it is close to the data it audits
D. In a standalone account outside the organization
Correct answer: B. Log-archive and audit accounts belong in a dedicated Security OU guarded by SCPs that deny deletion or modification of logging resources, isolating them from workload OUs. The management account is immune to SCPs and should stay workload-free.
Q2. A developer's IAM policy grants s3:*. An SCP attached to their OU contains an explicit Deny for s3:DeleteBucket. The developer calls DeleteBucket on a bucket they own. What is the result?
A. It succeeds, because IAM policies take precedence over SCPs
B. It is denied — SCPs set the permission ceiling and an explicit Deny always wins
C. It succeeds only if the bucket policy also allows it
D. It succeeds in the management account but is denied elsewhere
Correct answer: B. Effective permissions are the intersection of IAM and SCPs. An explicit Deny in either always overrides an Allow, so the SCP deny wins regardless of the IAM grant.
Q3. A company wants to enforce a region-restriction policy across all accounts so that no resource can be created outside us-east-1 and us-west-2. After deploying the SCP, users report they can no longer manage IAM users or update Route 53 records. What is the most likely cause?
A. The SCP was attached to the wrong OU
B. The region-restriction SCP did not exempt global services such as IAM, Route 53, CloudFront, and Support
C. SCPs cannot restrict regions
D. The accounts need to be re-enrolled in Control Tower
Correct answer: B. Region-restriction SCPs must exempt global services, whose endpoints are not tied to a region. Omitting the exemption breaks IAM, Route 53, CloudFront, and Support operations.
Q4. An enterprise wants engineers to authenticate once against corporate Okta and then assume the appropriate role in any of 40 AWS accounts, with no per-account IAM users. Which solution meets this with least operational overhead?
A. Create an IAM user per engineer in each account
B. IAM Identity Center with SAML federation from Okta and permission sets
C. Share a single root access key across the team
D. Use SCPs to grant cross-account access
Correct answer: B. IAM Identity Center is purpose-built for centralized SSO across an organization, provisioning short-lived federated roles per account instead of long-lived IAM users.
Q5. A delegated admin role is allowed to create IAM roles for developers. Security wants to guarantee the delegate can never create a role with AdministratorAccess. What is the standard control?
A. Attach a Deny statement to every developer role individually
B. Require a permission boundary on every role the delegate creates, enforced by a condition on iam:PermissionsBoundary
C. Remove iam:CreateRole entirely
D. Enforce MFA on the delegate role
Correct answer: B. A mandatory permission boundary caps the maximum permissions of any role the delegate creates, preventing privilege escalation. Enforcing it via a condition on CreateRole is the standard pattern.
Q6. A central network account owns a VPC. Three application accounts need to launch EC2 instances into that VPC's private subnets without owning the VPC or managing its route tables. What should be used?
A. VPC peering between every pair of accounts
B. AWS RAM subnet sharing from the central VPC
C. Copy the VPC configuration into each account
D. A Transit Gateway with no attachments
Correct answer: B. RAM subnet sharing lets multiple accounts launch resources into subnets owned by a single central VPC, avoiding per-account VPCs and peering meshes.
Q7. A company is deploying AWS Control Tower. They want a guardrail that prevents any account from creating root user access keys, and it must not be possible to disable it. Which guardrail category applies?
A. Elective guardrail
B. Mandatory guardrail
C. Strongly recommended guardrail
D. Custom Config rule
Correct answer: B. Mandatory guardrails are always enforced and cannot be disabled. Elective and strongly recommended guardrails are optional best practices enabled per OU.
Q8. A company needs to connect 30 VPCs across three accounts plus an on-premises data center, with strict isolation between production and non-production traffic. Which connectivity model scales best?
A. Full-mesh VPC peering between all 30 VPCs
B. A Transit Gateway with separate route tables for production and non-production, plus a Direct Connect Transit VIF
C. A single VPC with all workloads in it
D. PrivateLink between every pair of VPCs
Correct answer: B. A Transit Gateway hub-and-spoke with segmented route tables replaces an unmanageable peering mesh and enforces isolation, while a Transit VIF connects on-premises to the same hub.
Q9. Two VPCs are attached to Transit Gateways in different regions, and a TGW peering attachment has been created between them. Spoke VPCs still cannot reach each other. What is the most likely cause?
A. TGW peering does not support cross-region traffic
B. Peering attachments do not propagate routes — static routes must be added to each TGW route table
C. The TGWs are in different Availability Zones
D. Security groups always block inter-region traffic
Correct answer: B. Unlike VPC and TGW attachments, TGW peering attachments require manually created static routes in each TGW route table; automatic propagation is not supported.
Q10. A security team wants all internet-bound traffic from 12 spoke VPCs inspected by a single AWS Network Firewall, with no per-VPC firewall deployment. What is the standard architecture?
A. Deploy Network Firewall in every spoke VPC
B. A centralized inspection VPC attached to Transit Gateway, with spoke route tables sending 0.0.0.0/0 to the TGW
C. Use NACLs on each spoke subnet
D. Route all traffic through a NAT Gateway in each VPC
Correct answer: B. The centralized inspection VPC pattern routes all spoke egress through TGW into a shared Network Firewall, avoiding per-VPC duplication and cost.
Q11. A company needs the highest-resiliency Direct Connect design for a mission-critical workload. Which provisioning meets AWS's resiliency model?
A. A single 10 Gbps connection
B. Two connections at two different DX locations, terminating on separate devices, with BGP failover and a VPN backup
C. Two identical connections at the same location
D. A Public VIF only
Correct answer: B. DX resiliency requires diversity across locations and devices plus BGP failover; a VPN backup covers the rare case both DX paths fail.
Q12. On-premises servers need to resolve names in a private Route 53 hosted zone. What must be configured?
A. A Route 53 Resolver outbound endpoint
B. A Route 53 Resolver inbound endpoint, with on-prem DNS forwarding queries to it
C. A public hosted zone instead
D. NAT Gateway DNS forwarding
Correct answer: B. Inbound endpoints expose AWS private DNS to on-premises resolvers; outbound endpoints do the reverse, letting AWS resources resolve on-premises names.
Q13. Two companies both use 10.0.0.0/16. Company A needs to consume a specific API hosted in Company B's VPC. Which connectivity option works despite the overlap?
A. VPC peering
B. Transit Gateway peering
C. AWS PrivateLink with an Interface Endpoint and Endpoint Service
D. Direct Connect
Correct answer: C. PrivateLink requires only ENI-level connectivity in the consumer VPC and never merges route tables or CIDRs, so it works with fully overlapping IP ranges — unlike peering or TGW.
Q14. A team needs to expose one internal microservice to 20 consumer accounts without giving those accounts any network-level reachability to the rest of the VPC. What should they use?
A. VPC peering to each consumer account
B. A PrivateLink endpoint service, with each consumer creating an Interface Endpoint
C. A Transit Gateway shared via RAM
D. A public ALB with IP allowlisting
Correct answer: B. PrivateLink is service-level exposure: one service, many consumers, no shared routing. TGW and peering are network-level and would grant broader reachability.
Q15. A company needs S3 and DynamoDB access from private subnets with no internet gateway, no NAT, and no per-hour endpoint charges. What should they use?
A. Interface Endpoints for S3 and DynamoDB
B. Gateway Endpoints for S3 and DynamoDB
C. A NAT Gateway
D. VPC peering to an S3 VPC
Correct answer: B. Gateway endpoints support only S3 and DynamoDB, use route table entries rather than ENIs, and carry no hourly charge — unlike Interface Endpoints.
Q16. An ECS service runs on Fargate with awsvpc network mode. A security review asks why each task has its own ENI and security group rather than sharing the host's. What is the reason?
A. It reduces cost
B. It gives each task an isolated IP and security group, avoiding the port-mapping conflicts of bridge mode
C. It is required for CloudWatch Logs
D. It enables Spot pricing
Correct answer: B. awsvpc mode gives every task first-class networking — its own ENI, private IP, and security group — enabling per-task security instead of shared host-level rules.
Q17. A Kubernetes workload requires a DaemonSet on every node for log collection. Which EKS compute option should be avoided?
A. Managed node groups
B. Self-managed EC2 node groups
C. EKS Fargate profiles
D. Cluster Autoscaler on EC2
Correct answer: C. Fargate pods run in isolated micro-VMs with no shared node, so DaemonSets — which require a persistent per-node agent — are not supported.
Q18. An application takes four minutes to bootstrap before it can serve traffic, causing scale-out to lag demand spikes. What reduces the time to serve?
A. Increase the ASG cooldown period
B. Use a Warm Pool of pre-initialized stopped instances
C. Switch to Spot Instances
D. Add a lifecycle hook on launch
Correct answer: B. Warm pools keep instances pre-initialized so the ASG can bring them into service in seconds instead of re-running the full bootstrap sequence.
Q19. An instance must drain in-flight connections and upload final logs to S3 before it terminates. What ASG feature makes this possible?
A. A launch template user-data script
B. A lifecycle hook that pauses the instance in Terminating:Wait
C. A target group health check
D. A scheduled scaling action
Correct answer: B. Lifecycle hooks pause an instance in Pending:Wait or Terminating:Wait so bootstrap or drain scripts can run before it enters service or terminates.
Q20. A team wants to shift 10% of production traffic to a new task set for a canary release, using only ALB features. What should they configure?
A. Sticky sessions
B. Weighted target groups on a single listener rule
C. Cross-zone load balancing
D. Connection draining
Correct answer: B. Weighted target groups let one routing rule split traffic by percentage across two target groups — the ALB-native canary and blue/green mechanism.
Q21. A Lambda function reading from Kinesis is overwhelming a downstream RDS instance with connections during traffic spikes. What limits this safely?
A. Increase the Lambda timeout
B. Set reserved concurrency on the function to cap concurrent executions
C. Increase the Kinesis shard count
D. Switch RDS to Multi-AZ
Correct answer: B. Reserved concurrency caps how many instances of the function can run simultaneously, directly bounding concurrent downstream connections.
Q22. A latency-sensitive Lambda function suffers cold starts during traffic ramps. Which configuration removes the cold-start penalty?
A. Increase the memory allocation
B. Configure provisioned concurrency
C. Set reserved concurrency to zero
D. Move the function into a VPC
Correct answer: B. Provisioned concurrency pre-warms execution environments so invocations are served without the initialization latency of a cold start.
Q23. A high-volume IoT pipeline runs millions of short workflow executions per day and can tolerate at-least-once execution. Cost is the primary constraint. Which Step Functions type fits?
A. Standard Workflows
B. Express Workflows
C. Both are identical in cost
D. Neither — use SQS only
Correct answer: B. Express Workflows are priced per execution and duration for high-volume, short-duration workloads and provide at-least-once semantics, versus Standard's exactly-once but costlier per-transition pricing.
Q24. A team has deep existing Kubernetes tooling and a multi-cloud portability requirement. Which AWS compute platform best fits?
A. ECS with the EC2 launch type
B. Amazon EKS
C. AWS Lambda
D. AWS Batch on Fargate
Correct answer: B. EKS runs standard Kubernetes, preserving existing tooling and manifests and easing multi-cloud portability, unlike ECS's AWS-proprietary orchestration model.
Q25. A global application needs a secondary region readable with sub-second replication lag and promotable to primary in under a minute during a regional outage. Which database fits?
A. RDS Multi-AZ with a cross-region read replica
B. Aurora Global Database
C. DynamoDB Global Tables only
D. RDS read replica with async replication
Correct answer: B. Aurora Global Database uses storage-layer cross-region replication with typical sub-second lag and managed failover promoting the secondary in under a minute.
Q26. A team needs to upgrade RDS MySQL from 5.7 to 8.0 with minimal risk and a fast rollback path. What should they use?
A. In-place major version upgrade during a maintenance window
B. RDS Blue/Green Deployments to validate on a synced green environment before switchover
C. Read replica promotion
D. Multi-AZ failover
Correct answer: B. Blue/Green Deployments create a fully replicated green environment on the new version, validated before a fast, low-risk switchover.
Q27. A team needs a database that scales read throughput without affecting write availability, and can tolerate asynchronous replication. Which RDS feature fits?
A. Multi-AZ deployment
B. Read replicas
C. A larger instance class
D. Automated backups
Correct answer: B. Read replicas scale read throughput asynchronously. Multi-AZ is for HA with a synchronous standby and does not scale reads.
Q28. A DynamoDB table uses OrderStatus (five possible values) as its partition key and throttles under high write volume even though table-level capacity is high. Why?
A. The table needs Global Tables
B. Low-cardinality partition keys create hot partitions, since each partition has its own throughput ceiling
C. On-demand mode is not enabled
D. DynamoDB does not support high write volume
Correct answer: B. Each partition has its own throughput ceiling; a key with only five distinct values concentrates writes onto a handful of partitions, causing throttling despite ample table-level capacity.
Q29. A gaming leaderboard needs microsecond read latency for the same hot items requested extremely frequently. What should sit in front of DynamoDB?
A. Self-managed ElastiCache for Redis
B. Amazon DAX
C. CloudFront caching of API responses only
D. A larger DynamoDB table
Correct answer: B. DAX is a managed, DynamoDB-API-compatible in-memory cache purpose-built to shave read latency for hot items without application-level cache logic.
Q30. An application needs single-digit-millisecond reads and writes at massive, unpredictable scale with a flexible schema, across multiple regions actively writing. What fits best?
A. Aurora Global Database
B. DynamoDB Global Tables
C. RDS with cross-region read replicas
D. ElastiCache alone as the system of record
Correct answer: B. DynamoDB Global Tables provide multi-active, multi-region writes at single-digit-millisecond latency with a flexible schema — a fit Aurora Global DB (single writer region) and RDS replicas do not match.
Q31. An object is rarely accessed, must survive the loss of an entire Availability Zone, and a 12-hour retrieval time is acceptable. Cost must be minimized. Which S3 class fits?
A. S3 One Zone-IA
B. S3 Glacier Deep Archive
C. S3 Glacier Flexible Retrieval (Bulk)
D. S3 Standard-IA
Correct answer: B. Glacier Deep Archive is the lowest-cost class and is replicated across multiple AZs, so it survives an AZ loss — unlike One Zone-IA — with retrieval times up to 12 hours.
Q32. A session store must survive a node failure without losing data and support automatic failover. Which caching engine and configuration fits?
A. Memcached with auto discovery
B. Redis with cluster mode enabled and replicas per shard
C. Memcached with multiple nodes
D. Redis without replicas
Correct answer: B. Only Redis supports replication and automatic failover; Memcached has no replication, so node failure means data loss for those keys.
Q33. A company needs to move 300 TB of historical data plus ongoing daily deltas of about 50 GB into AWS, over a link capped at 500 Mbps. What is the recommended approach?
A. Transfer everything, including historical data, over the 500 Mbps link
B. Use Snowball Edge for the 300 TB bulk transfer, then DMS CDC or DataSync over the network for ongoing deltas
C. Wait for the link to be upgraded before starting
D. Use Snowmobile for the entire migration
Correct answer: B. The hybrid pattern — offline bulk transfer for the large historical dataset, then network-based CDC or incremental sync for the small ongoing delta — is standard for large migrations over constrained links.
Q34. A company must migrate 2 PB of data from a facility with no viable network uplink for bulk transfer. What is the appropriate approach?
A. AWS DataSync over the internet
B. Multiple AWS Snowball Edge Storage Optimized devices, or Snowmobile for the full 2 PB in one engagement
C. Direct Connect provisioned overnight
D. AWS Storage Gateway
Correct answer: B. At petabyte scale with no adequate network path, physical offline transfer via Snow Family devices is the standard, cost-effective solution.
Q35. A company needs to rehost 200 on-premises VMs to EC2 as fast as possible with minimal application changes and minimal cutover downtime. Which service?
A. AWS DataSync
B. AWS Application Migration Service (MGN)
C. AWS Schema Conversion Tool
D. AWS DMS
Correct answer: B. MGN is purpose-built for server rehost: continuous block-level replication lets you test extensively and cut over with minutes of downtime, without re-architecting the application.
Q36. A migration team needs to map network dependencies between individual processes on each on-premises server before planning migration waves. What captures this?
A. Agentless Discovery Connector only
B. Agent-based discovery, which captures process-to-process network connections
C. AWS Config
D. CloudTrail
Correct answer: B. Agent-based discovery installs a lightweight agent per server and captures fine-grained, process-level network connections; agentless discovery only gives VM-level inventory and utilization.
Q37. A data center lease expires in six months, forcing a fast migration, but two legacy applications have unresolved software licensing blockers. What is the correct 7 Rs plan?
A. Refactor everything to serverless
B. Rehost the majority via MGN to meet the deadline; Retain the two blocked applications until licensing is resolved
C. Repurchase all applications as SaaS
D. Retire every application
Correct answer: B. Under a tight deadline, Rehost is the fastest path for most applications; applications with real blockers should be explicitly Retained rather than forced into a rushed migration.
Q38. A team wants to move VMware VMs to AWS infrastructure while keeping the exact same hypervisor-level configuration and VMware management tools, with no conversion. Which strategy?
A. Rehost to native EC2 with MGN
B. Relocate to VMware Cloud on AWS
C. Use the AWS Schema Conversion Tool
D. Use AWS DataSync
Correct answer: B. Relocate via VMware Cloud on AWS is the only 7 Rs strategy that moves the VM without converting it out of the VMware format, unlike Rehost which lands on native EC2 and AMIs.
Q39. SCT reports a 92% automatic conversion rate for an Oracle-to-PostgreSQL migration. What does this mean for the remaining 8%?
A. The migration is essentially complete and can proceed unattended
B. Complex objects such as certain stored procedures and functions could not be auto-converted and need manual developer remediation before cutover
C. SCT failed and DMS cannot be used
D. 8% of the data will be lost during migration
Correct answer: B. SCT's conversion percentage reflects schema and code objects only; a high percentage still commonly leaves complex procedural logic that must be manually rewritten before the migration is production-ready.
Q40. A company needs to continuously sync a large on-premises NFS file share into Amazon EFS on a schedule, without writing custom scripts. Which service?
A. AWS DMS
B. AWS DataSync
C. AWS Snowball Edge
D. AWS Storage Gateway File Gateway
Correct answer: B. DataSync is purpose-built for automated, scheduled, validated file and object transfer between on-premises file systems and AWS storage services such as EFS, FSx, and S3.
Q41. An enterprise wants to eliminate its physical backup tape infrastructure while keeping existing backup software unchanged. Which Storage Gateway type?
A. File Gateway
B. Volume Gateway in stored mode
C. Tape Gateway (Virtual Tape Library)
D. AWS Backup only
Correct answer: C. Tape Gateway presents a virtual tape library interface compatible with existing backup software, letting you retire physical tape hardware without changing backup workflows.
Q42. A hospital must keep patient data physically on-premises for regulatory reasons while still using native AWS APIs such as EC2, EBS, and RDS. Which service?
A. AWS Local Zones
B. AWS Wavelength
C. AWS Outposts
D. A standard AWS Region with encryption
Correct answer: C. Outposts physically places AWS-managed infrastructure inside the customer's own data center, satisfying strict data-residency requirements while retaining native AWS service APIs.
Q43. A manufacturing plant requires single-digit-millisecond latency to on-premises industrial control systems, and the company does not want to own or operate hardware. Which option fits?
A. AWS Outposts
B. An AWS Local Zone in the nearest metro
C. AWS Wavelength
D. A standard Region with Global Accelerator
Correct answer: B. Local Zones place AWS compute and storage in specific metro areas for low-latency access without the customer owning hardware, unlike Outposts which is customer-site infrastructure.
Q44. A company runs a steady-state, predictable production fleet but wants maximum flexibility to change instance families and regions over the commitment period. Which commitment?
A. EC2 Instance Savings Plans
B. Compute Savings Plans
C. Standard Reserved Instances
D. Spot Instances
Correct answer: B. Compute Savings Plans apply across any instance family, region, and OS, and even to Fargate and Lambda usage, trading a slightly lower discount than EC2 Instance Savings Plans for maximum flexibility.
Q45. A company suspects many EC2 instances are oversized relative to actual CPU and memory utilization but does not know which ones. Which service directly recommends right-sizing changes?
A. AWS Config
B. AWS Compute Optimizer
C. AWS Trusted Advisor cost checks only
D. CloudWatch Alarms
Correct answer: B. Compute Optimizer analyzes historical utilization and provides specific instance-type right-sizing recommendations with projected savings, more targeted than Trusted Advisor's general cost checks.
Q46. Finance wants AWS spend broken out per business unit, but resources are inconsistently tagged today. What should be enforced first?
A. Enable Cost Explorer only
B. Enforce a mandatory tagging policy requiring cost-allocation tags at resource creation, then activate those tags for cost allocation reporting
C. Use a single shared account for all business units
D. Track spend manually in a spreadsheet
Correct answer: B. Cost allocation reporting is only as good as tag hygiene; enforcing mandatory tags at creation time via SCP or Config rules is the prerequisite before per-business-unit reports become meaningful.
Q47. A workload can tolerate an RTO of 15 minutes and an RPO of 5 minutes, but the business wants to minimize standing infrastructure cost. Which DR pattern fits best?
A. Backup and Restore
B. Pilot Light
C. Multi-Site Active-Active
D. No DR strategy needed
Correct answer: B. Pilot Light keeps only core data continuously replicated and minimal infrastructure running, scaling up the rest on failover — matching a roughly 15-minute RTO at much lower cost than warm standby or active-active.
Q48. A workload requires near-zero RTO and RPO, and budget is not the primary constraint. Which DR strategy and supporting services fit?
A. Backup and Restore with AWS Backup
B. Pilot Light with manual DNS updates
C. Multi-Site Active-Active with Route 53 ARC and DynamoDB Global Tables or Aurora Global Database
D. Warm standby without health checks
Correct answer: C. Near-zero RTO and RPO demand live traffic serving from multiple regions with deterministic, tested failover control and multi-region-write-capable data services.
Q49. A critical financial system needs failover control that itself will not fail if an entire AWS Region goes down, plus proof the standby Region is actually ready to serve traffic. What should they use?
A. Route 53 simple health-check failover only
B. Route 53 Application Recovery Controller with readiness checks and a routing control cluster
C. CloudWatch Alarms triggering a Lambda failover
D. Global Accelerator alone
Correct answer: B. ARC's routing control cluster is deliberately distributed across regions and partitions for resilience of the failover mechanism itself, and readiness checks validate standby capacity before you rely on it.
Q50. An active-active application needs sub-second failover at the network layer when a Region's health checks fail, independent of DNS TTL and client caching. What should they use?
A. Route 53 latency-based routing alone
B. AWS Global Accelerator, which uses static anycast IPs and reroutes at the AWS network edge
C. CloudFront alone
D. A single-Region NLB
Correct answer: B. Global Accelerator uses anycast IPs and AWS's global network for near-instant failover, avoiding client-side DNS caching delays inherent to Route 53-only failover.
Q51. A company needs ransomware-resilient backups that cannot be deleted even by a compromised admin account. What should they configure?
A. Standard EBS snapshots only
B. AWS Backup with a cross-account copy into an isolated account, in a vault with Backup Vault Lock enabled
C. S3 versioning only
D. Increase snapshot frequency
Correct answer: B. Cross-account isolation prevents a compromised primary account from touching backups, and Vault Lock makes the retention policy immutable — even the root user cannot delete locked backups before expiry.
Q52. On-call engineers are fatigued by alarms firing on isolated latency spikes that self-resolve. What reduces noise while still catching real incidents?
A. Delete the latency alarm
B. A composite alarm requiring both the latency alarm and the error-rate alarm to be in ALARM state
C. Lower the alarm threshold
D. Increase the evaluation period to 24 hours
Correct answer: B. Composite alarms let you require correlated signals before paging, cutting single-metric false positives while preserving sensitivity to genuine multi-symptom incidents.
Q53. Internal CloudWatch metrics show healthy servers, but customers report the login page is broken. What monitoring gap does this reveal?
A. Missing X-Ray tracing
B. No outside-in synthetic monitoring of the actual user flow
C. Missing VPC Flow Logs
D. Insufficient EC2 instance count
Correct answer: B. Server-side health metrics do not verify end-to-end user experience; Synthetics canaries probe from outside the infrastructure, catching failures invisible to internal metrics.
Q54. A microservices application has growing p99 latency, but it is unclear which of 12 services is the bottleneck. What pinpoints this?
A. CloudWatch Logs Insights alone
B. AWS X-Ray, using the service map to isolate the slow hop
C. VPC Flow Logs
D. AWS Config
Correct answer: B. X-Ray's distributed tracing and service map visualize per-hop latency across the full call chain, directly identifying the bottleneck service that aggregate metrics cannot isolate.
Q55. An organization wants every account's application logs centrally searchable in a dedicated logging account in near-real time. What is the mechanism?
A. Manually export logs nightly via S3
B. CloudWatch Logs subscription filters streaming to Kinesis Data Firehose in the central logging account
C. CloudTrail only
D. Increase log retention in each account
Correct answer: B. Subscription filters push log events in near-real time to a destination, commonly Kinesis Firehose or Streams, in a centralized account, enabling org-wide log aggregation.
Q56. A team wants to safely test EC2 instance failure in production without risking an uncontrolled outage. What FIS feature guarantees the experiment halts if things go wrong?
A. IAM permission boundaries
B. Stop conditions tied to CloudWatch alarms
C. Increasing the blast radius
D. Manual monitoring only
Correct answer: B. FIS stop conditions automatically abort a running experiment the moment a linked CloudWatch alarm enters ALARM state, capping the blast radius of chaos testing.
Q57. A team has documented DR runbooks but has never tested them under simulated failure. What is the recommended next step before relying on them?
A. Trust the documentation as-is
B. Run a Game Day exercise using FIS to simulate the failure and validate the runbook and automated recovery
C. Increase backup frequency only
D. Skip testing to avoid production risk
Correct answer: B. Untested runbooks are unverified assumptions; a Game Day exercises the real failure mode against real infrastructure to confirm RTO and RPO targets are actually achievable.
Q58. A team manually SSHes into servers to apply emergency patches, occasionally causing configuration drift. Which Operational Excellence practice addresses this?
A. Increase server count
B. Perform operations as code using SSM Automation documents instead of manual SSH changes
C. Disable CloudTrail logging
D. Add more IAM users
Correct answer: B. Operations as code — codifying operational procedures such as SSM Automation — eliminates ad hoc manual changes and the drift and error they introduce.
Q59. Which best exemplifies the Reliability pillar's failure management best practice?
A. Using the largest possible instance type
B. Automatically testing recovery procedures via Game Days and setting quantified RTO and RPO targets
C. Manually reviewing logs weekly
D. Avoiding all managed services
Correct answer: B. Failure management is about anticipating failure, testing recovery through Game Days, and having quantified, validated RTO and RPO — not just provisioning bigger resources.
Q60. A company needs a dedicated private network connection into AWS for a single VPC, with no Transit Gateway involved. Which Direct Connect virtual interface?
A. Private VIF
B. Transit VIF
C. Public VIF
D. Hosted VIF to a partner
Correct answer: A. A Private VIF connects a Direct Connect connection to a single VPC via a virtual private gateway. Transit VIFs are used when connecting to a Transit Gateway.
Q61. A company wants to connect a Direct Connect connection to a Transit Gateway so that many VPCs can use it. Which virtual interface type is required?
A. Private VIF
B. Transit VIF
C. Public VIF
D. No VIF is needed
Correct answer: B. A Transit VIF connects Direct Connect to a Transit Gateway, which then provides reachability to many attached VPCs.
Q62. A company needs to reach public AWS service endpoints such as S3 over Direct Connect without traversing the internet. Which virtual interface?
A. Private VIF
B. Transit VIF
C. Public VIF
D. A VPN over the DX connection
Correct answer: C. Public VIFs provide access to AWS public service endpoints over the dedicated connection, keeping that traffic off the public internet.
Q63. A company needs to connect two VPCs in the same Region that have non-overlapping CIDRs, with the lowest possible cost and no shared services requirement. What is the simplest option?
A. VPC peering
B. A Transit Gateway
C. AWS PrivateLink
D. Direct Connect
Correct answer: A. For a small number of VPCs with non-overlapping CIDRs and no hub requirement, VPC peering is the simplest and cheapest option; TGW adds cost and complexity that only pays off at scale.
Q64. A company needs to share a Transit Gateway with other accounts in the organization so their VPCs can attach to it. What is the mechanism?
A. VPC peering between the accounts
B. AWS Resource Access Manager (RAM)
C. An SCP granting ec2:AttachVpnGateway
D. A shared VPC via AWS Organizations
Correct answer: B. AWS RAM shares the Transit Gateway with other accounts in the organization, letting their VPCs create attachments to the shared hub.
Q65. A company needs to run a containerized workload with no EC2 instances to manage, per-task IAM roles, and per-task security groups. Which combination fits?
A. ECS on EC2 with bridge networking
B. ECS on Fargate with awsvpc network mode and a task IAM role
C. EKS with self-managed nodes
D. Lambda with a container image
Correct answer: B. Fargate removes EC2 management, awsvpc gives each task its own ENI and security group, and the task IAM role scopes permissions per task.
Q66. A team needs to run a batch job that can be interrupted and restarted, at the lowest possible compute cost. Which purchasing option fits?
A. On-Demand Instances
B. Spot Instances with a mixed-instance ASG and an interruption handler
C. Standard Reserved Instances
D. Dedicated Hosts
Correct answer: B. Spot Instances offer the deepest discount for fault-tolerant, interruptible workloads; a mixed-instance ASG diversifies capacity and the interruption handler drains work on the two-minute notice.
Q67. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Q68. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Q69. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Q70. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Q71. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Q72. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Q73. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Q74. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Q75. A company needs to migrate a 4 TB Oracle database to Aurora PostgreSQL with minimal downtime and wants to know how much of the schema will convert automatically. Which combination of tools?
A. AWS DMS only
B. AWS SCT for schema conversion and assessment, then AWS DMS with CDC for the data
C. AWS DataSync
D. AWS MGN
Correct answer: B. SCT handles the heterogeneous schema and code conversion and reports the conversion percentage; DMS with CDC moves the data with minimal downtime. SCT handles schema, DMS handles data.
Scoring Guide
Score the sitting by raw correct count out of 75, then convert to a percentage. As a rule of thumb — not an official AWS figure — a raw score of roughly 72% or better is a reasonable proxy for exam-ready, and anything above 85% is comfortable. Below 65% means the sitting found real gaps and the domain tagging matters more than the number.
More useful than the total is the distribution. Group the misses by domain — organizational governance, network design, resilient architecture, migration, cost — and note whether they cluster or scatter. A scattered set of misses usually means pacing or reading errors rather than content gaps; a tight cluster means a specific topic needs another pass. Write both numbers down: the raw score and the domain with the most misses. Tomorrow's session consumes the second one.
Preview
This sitting produced two artifacts: a raw score and a list of domains where the misses clustered. Neither is actionable on its own. A score tells you whether you are close, but not what to do about it; a domain list tells you where the gaps are, but not whether they are content gaps or pacing artifacts. The open question is what to actually do with the remaining time before the exam — and specifically, what not to do.
Tomorrow is the final review day, and it is deliberately light. It acts on today's data by narrowing the last pass to the specific weak spots the domain tagging surfaced, confirming exam-day logistics, and then stopping. The instinct to cram new material in the final 24 hours is the one thing that reliably makes exam-day performance worse, and tomorrow's session is structured around resisting it.
Sources
AWS Well-Architected Framework — Reliability and Operational Excellence pillars
AWS Organizations, SCP, and Control Tower documentation
Amazon VPC, Transit Gateway, Direct Connect, and PrivateLink documentation
Amazon ECS, EKS, Lambda, and EC2 Auto Scaling documentation
Amazon Aurora, RDS, DynamoDB, ElastiCache, and S3 documentation
AWS Backup, Route 53 ARC, and AWS Fault Injection Service documentation
AWS Application Migration Service, DMS, SCT, DataSync, and Snow Family documentation
AWS Compute Optimizer, Savings Plans, and Cost Explorer documentation