Joint Design & Preparation Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Joint Design & Preparation flashcards as text
A joint design team must architect a real-time analytics pipeline ingesting 500,000 events per second. Which AWS service is designed for this ingestion scale?
Answer: Amazon Kinesis Data Streams
Kinesis Data Streams is designed for real-time, high-throughput data streaming and scales by adding shards to handle millions of records per second.
During joint preparation, the team discovers that their on-premises Active Directory must authenticate users for AWS Management Console access. Which service enables this without syncing all credentials to AWS?
Answer: AWS IAM Identity Center with AD Connector as the identity source
IAM Identity Center with AD Connector federates authentication to on-premises AD so users log in with existing credentials without syncing passwords to AWS.
A cross-team architecture review requires a cost-optimized compute strategy for a batch workload that runs 6 hours per night and can tolerate interruptions. Which EC2 purchasing option is most appropriate?
Answer: Spot Instances with checkpointing to S3
Spot Instances offer up to 90% savings, and checkpointing allows the batch job to resume from the last saved state if interrupted.
During joint design, the team needs to expose a REST API that aggregates data from three backend Lambda functions. Which service orchestrates this with the least custom code?
Answer: API Gateway with separate integrations per route mapped to each Lambda
API Gateway natively routes each HTTP method/path to a different Lambda integration, handling request/response transformation without custom aggregation code.
Two teams are jointly designing a multi-account AWS environment following AWS Organizations best practices. Which account structure isolates production workloads most effectively?
Answer: Separate AWS accounts for production, staging, and development within an AWS Organization
Separate accounts provide the strongest blast-radius isolation because IAM boundaries, service quotas, and billing are completely independent per account.
During joint capacity preparation, the team finds that their DynamoDB table experiences hot partition issues during flash sales. Which design change resolves this?
Answer: Add a random suffix to partition keys to distribute writes across multiple partitions
Write sharding by appending a random suffix distributes hot-key traffic across multiple partitions, eliminating the throttling caused by a single partition absorbing all writes.
A joint architecture team is preparing their monitoring strategy and needs to detect when application errors exceed a threshold and automatically notify on-call engineers. Which combination achieves this?
Answer: CloudWatch Logs metric filter → CloudWatch Alarm → SNS topic → PagerDuty subscription
A metric filter extracts error counts from logs, the alarm triggers when the threshold is breached, and SNS delivers the alert to the on-call notification system in near real time.