โ† All Architecting on AWS Certification Flashcard Decks

Joint Design & Preparation Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Joint Design & Preparation flashcards as text
  1. A joint design team must ensure that sensitive PII stored in S3 is never accidentally made public. Which preventive control enforces this at the organization level?

    Answer: AWS Organizations SCP blocking s3:PutBucketAcl with public grants, plus S3 Block Public Access enabled at the account level

    SCPs enforce guardrails across all accounts in the organization while S3 Block Public Access provides a second layer of defense at the account level.

  2. During joint preparation for a high-availability web application, the team must design for an AZ failure. Which architecture ensures the application remains available during a single AZ outage?

    Answer: Auto Scaling group spanning three AZs behind an Application Load Balancer

    Distributing instances across multiple AZs behind an ALB ensures traffic is automatically redirected to healthy AZs if one fails.

  3. Two teams are jointly architecting a solution where a third-party partner needs read-only access to specific S3 buckets in your AWS account without receiving long-term credentials. Which mechanism should be used?

    Answer: Configure an IAM role with a trust policy allowing the partner's AWS account to assume it via cross-account role assumption

    Cross-account role assumption grants temporary, scoped credentials via STS without requiring long-term access keys to be shared.

  4. During joint design, the team needs to implement a CI/CD pipeline that automatically deploys to ECS Fargate when code is pushed to CodeCommit. Which AWS-native service combination builds this pipeline?

    Answer: CodePipeline orchestrating CodeBuild for the image build and CodeDeploy for the ECS deployment

    CodePipeline connects source, build, and deploy stages natively, with CodeBuild building Docker images and CodeDeploy managing blue/green ECS deployments.

  5. A joint architecture team is preparing a cost governance strategy for a multi-team AWS environment. Which approach provides the most granular cost visibility per team without requiring separate accounts?

    Answer: Apply consistent resource tags per team and use Cost Explorer tag-based cost allocation reports

    Tag-based cost allocation in Cost Explorer breaks down spending by team, project, or environment using tags applied consistently to all resources.

  6. During joint preparation, the security architect requires that all API calls made within the AWS environment be logged immutably for 7 years to satisfy audit requirements. Which solution achieves this?

    Answer: Enable CloudTrail logging to an S3 bucket with Object Lock in Compliance mode and a 7-year retention policy

    CloudTrail captures all API calls, and S3 Object Lock in Compliance mode prevents deletion or modification of log objects for the specified retention period.

  7. A cross-team design session identifies that a microservice needs to process a large file uploaded to S3, but processing takes 20 minutes. Which architecture avoids Lambda timeout limits for this workload?

    Answer: Trigger an AWS Step Functions workflow from an S3 event notification that invokes a Fargate task for the long-running processing

    Step Functions orchestrates a Fargate task which has no timeout limit, allowing arbitrarily long processing while Lambda handles only the lightweight trigger.