Solutions Architect Cloud Architecture & Design Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Solutions Architect Cloud Architecture & Design flashcards as text
A company requires that no internet traffic ever traverse the public internet when accessing Amazon S3 from within a VPC. What must be configured?
Answer: VPC Gateway Endpoint for S3
A VPC Gateway Endpoint for S3 routes traffic from within the VPC to S3 through the AWS private network without requiring a NAT Gateway or internet gateway.
An architect must design a system where multiple microservices publish events and multiple consumers receive only the events relevant to them. Which pattern best fits?
Answer: AWS EventBridge with event bus and rules
Amazon EventBridge event bus with rules allows producers to publish events and consumers to define filter rules, decoupling services in a scalable fan-out pattern.
A company needs to run a containerized application without managing the underlying EC2 instances. Which AWS compute option is fully serverless for containers?
Answer: AWS Fargate
AWS Fargate is a serverless compute engine for containers that removes the need to provision, configure, or scale EC2 instances.
Which AWS storage option provides a fully managed shared file system accessible by multiple Linux EC2 instances simultaneously using the NFS protocol?
Answer: Amazon EFS
Amazon EFS is a managed NFS file system that can be mounted concurrently by thousands of EC2 instances across multiple AZs.
An e-commerce application experiences predictable traffic spikes every Friday evening. Which Auto Scaling strategy minimizes cost while ensuring capacity is ready before the spike?
Answer: Scheduled scaling to pre-provision capacity before the spike
Scheduled scaling allows you to proactively set desired capacity at specific times, ensuring instances are ready before the known traffic spike begins.
A Solutions Architect needs to enforce that IAM users in the organization cannot disable AWS CloudTrail logs. What is the most effective control?
Answer: Create an AWS Organizations Service Control Policy (SCP) that denies cloudtrail:StopLogging
An SCP applied at the AWS Organizations root or OU level acts as a guardrail that cannot be overridden by any IAM policy in member accounts.
A web application needs session state to persist even when users are routed to different EC2 instances by a load balancer. What is the recommended stateless architecture approach?
Answer: Store session state in Amazon ElastiCache (Redis) shared by all instances
Externalizing session state to a shared ElastiCache Redis cluster makes each instance stateless so any instance can serve any user request.