Architecting on AWS Certification Cheat Sheet 2026
The 30 highest-yield Architecting on AWS Certification facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
65 questions
130 min time limit
72.00% to pass
- Which CloudWatch metric would an architect monitor to detect that an Application Load Balancer has no healthy targets available? → HealthyHostCount
- An architect needs to automate evidence collection for PCI DSS, HIPAA, and NIST 800-53 frameworks continuously. Which AWS service is purpose-built for this? → AWS Audit Manager
- Which AWS service can be used to implement a dead-letter queue to capture messages that repeatedly fail processing in an SQS-based architecture? → Amazon SQS itself
- Which AWS networking feature provides a private, dedicated network connection between an on-premises data center and AWS, bypassing the public internet? → AWS Direct Connect
- What AWS feature allows an Auto Scaling group to replace unhealthy EC2 instances automatically without manual intervention? → Health check replacement
- Which non-destructive testing (NDT) method is most effective for detecting planar, surface-breaking cracks at weld toes in ferritic steel? → Magnetic particle testing (MT)
- An architect wants to improve the read performance of a relational database without scaling the primary instance. Which AWS solution achieves this? → Add RDS Read Replicas and direct read traffic to them
- Which EC2 instance purchasing model is best suited for a batch processing workload that can tolerate interruptions in exchange for the lowest possible cost? → Spot Instances
- Which pricing model offers the highest discount on AWS Lambda compared to paying per invocation at on-demand rates? → Lambda Compute Savings Plans
- Which AWS Direct Connect connection type is provided by an AWS partner and shares bandwidth with other customers? → Hosted connection
- Which AWS service can automatically remediate a non-compliant resource by invoking an AWS Systems Manager Automation document? → AWS Config automatic remediation
- Which Application Load Balancer feature allows routing of requests to different target groups based on URL path patterns? → Path-based routing
- An architect needs to route user requests to the nearest AWS Region to minimize latency. Which Route 53 routing policy should be used? → Latency-based routing
- A company needs to detect and remediate configuration drift on EC2 instances automatically. Which AWS service is MOST appropriate? → AWS Systems Manager State Manager
- An architect wants to right-size EC2 instances based on historical CPU and memory utilization. Which AWS service provides these recommendations? → AWS Compute Optimizer
- Which shielding gas mixture is preferred for GMAW of austenitic stainless steel to minimize carbon pickup and carbide precipitation? → Ar + 5% O2 or Ar + 2% CO2
- A company must prove to auditors that no IAM root account API calls occurred in the past 90 days. Which approach provides this evidence MOST efficiently? → Query CloudTrail Lake with SQL for root user events
- In an AWS architecture blueprint, a box with the label 'VPC Peering' connecting two VPC boundaries represents what connectivity type? → A direct private network connection between two VPCs enabling resource communication
- An architect needs to connect dozens of VPCs and on-premises networks through a central hub with minimal operational overhead. Which service is best suited? → AWS Transit Gateway
- A joint design team must architect a real-time analytics pipeline ingesting 500,000 events per second. Which AWS service is designed for this ingestion scale? → Amazon Kinesis Data Streams
- An architect must ensure data in transit between on-premises systems and AWS meets NIST 800-52 TLS requirements. What is the recommended approach? → Configure AWS services to use TLS 1.2 or higher and disable older protocol versions
- What is the primary metallurgical reason for preheating high-carbon or alloy steels before welding? → To slow the cooling rate of the HAZ, reducing martensite formation and hydrogen diffusion
- Which AWS service enables centralized management of firewall rules across multiple accounts and VPCs in an AWS Organization? → AWS Firewall Manager
- An architect must ensure CloudTrail is enabled in every region for every new account added to an AWS Organization. What is the MOST scalable solution? → Create an organization-level CloudTrail trail in the management account
- Which AWS service provides a managed way to store, rotate, and audit database credentials to help meet SOC 2 access-control requirements? → AWS Secrets Manager
- Which AWS service continuously evaluates resource configurations against desired compliance rules and can automatically remediate non-compliant resources? → AWS Config with Config Rules and Remediation Actions
- Which VPC feature allows instances in a private subnet to initiate outbound internet traffic without exposing them to inbound connections? → NAT Gateway
- Which S3 feature ensures that a specific version of an object cannot be deleted or overwritten for a defined retention period? → S3 Object Lock in Compliance mode
- What does Amazon CloudFront's Origin Access Control (OAC) accomplish? → It restricts S3 bucket access so only CloudFront can read objects
- What is a near-miss report in Architecting on AWS Certification safety management? → Documentation of an event that could have resulted in harm but did not
Turn these facts into recall:
Was this helpful?