Associate Certified Solutions Architect - Associate Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Associate Certified Solutions Architect - Associate flashcards as text
A company needs its AWS Lambda functions to access an Amazon RDS database in a private subnet. What must be configured to allow this?
Answer: Configure the Lambda function to run inside the VPC and attach it to the private subnet's security group
Attaching a Lambda function to a VPC with the correct subnet and security group configuration allows it to communicate with RDS in the private subnet.
A Solutions Architect needs to migrate a petabyte-scale dataset from an on-premises data center to S3 within two weeks. The available internet connection is 1 Gbps. Which migration service should be used?
Answer: AWS Snowball Edge Storage Optimized
AWS Snowball Edge physically ships storage appliances to the data center, enabling petabyte-scale transfers that far exceed what a 1 Gbps connection can deliver in two weeks.
An application requires a NoSQL database that can deliver single-digit millisecond reads at any scale with no capacity planning required. Which AWS service should be used?
Answer: Amazon DynamoDB with on-demand capacity mode
DynamoDB in on-demand mode automatically scales read and write capacity to any level with consistent single-digit millisecond latency and no capacity management.
A company's EC2-based application must be protected from common web exploits such as SQL injection and cross-site scripting. Which AWS service provides this protection at the application layer?
Answer: AWS WAF attached to the ALB
AWS WAF can be attached to an ALB (or CloudFront) to inspect HTTP requests and block known web exploits like SQL injection and XSS.
A company has an S3 bucket used as a static website origin behind CloudFront. The company wants to ensure that users can only access content via CloudFront and not directly via the S3 endpoint. What is the recommended configuration?
Answer: Use an Origin Access Control (OAC) on the CloudFront distribution and restrict the bucket policy to OAC only
Origin Access Control restricts S3 bucket access so only CloudFront can read objects, preventing users from bypassing CloudFront with direct S3 URLs.
An architect is designing a disaster recovery strategy for an RTO of 15 minutes and an RPO of 5 minutes. Which DR strategy best meets these requirements?
Answer: Warm Standby
Warm Standby keeps a scaled-down but fully functional environment running in the DR region, enabling rapid scale-out and recovery within minutes.
A company's application writes large files to S3 and the uploads sometimes fail midway due to network interruptions. Which S3 feature reduces upload failures for large objects?
Answer: S3 Multipart Upload
Multipart Upload splits large objects into smaller parts uploaded independently, so only failed parts need to be retried rather than restarting the entire upload.