AWS Solutions Architect Professional practice exam questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

AWS Solutions Architect Professional practice exam: 1024 questions with full explanations

4 domains 1024 questions 180 min exam
Questions on the exam
75
Time allowed
180 minutes format →
Passing score
750 of 1000 — vendor, checked September 28, 2026 detail →
Exam fee
$300 — vendor, checked September 28, 2026 detail →

1024 practice exam questions for AWS Certified Solutions Architect – Professional, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.

Not sure where you stand? Take the free 5-min AWS Solutions Architect Professional readiness check →

AWS Solutions Architect Professional certification: requirements, cost and exam format → ·  AWS Solutions Architect Professional exam format →  ·  AWS Solutions Architect Professional passing score →  · AWS Solutions Architect Professional exam cost →

Questions by domain

Sample questions

Use blue-green environments with expand-contract schema: Which architecture best satisfies both requirements?

Design for New Solutions Medium
A financial services group is releasing a customer-facing payment service. Deployment must support rollback without rebuilding the previous version, and database changes must support old and new application versions during traffic transition. Rolling deployments currently mix versions and have caused schema errors. The pipeline can provision a separate environment and run health checks, but rollback actions must be configured. Which architecture best satisfies both requirements?
  1. Continue rolling deployment and run a CloudFormation change set before each release.
    A change set previews infrastructure changes, but rolling deployment still mixes versions and does not ensure schema compatibility.
  2. Use a canary release while applying an irreversible schema change before compatibility testing.
    Canary traffic limits exposure, but an irreversible schema change can prevent reliable rollback to the previous application.
  3. Replace the old environment in place and restore its previous AMI if errors occur.
    In-place replacement can leave partial changes and does not provide a separately validated environment or safe schema transition.
  4. Use blue-green environments with expand-contract schema changes, validate green, then shift traffic. ✓
    A separate validated environment enables traffic reversal, while expand-contract changes keep the schema compatible with both application versions.
The trap
Infrastructure preview does not solve version mixing. Irreversible schema changes undermine rollback. AMI restoration is not an atomic application rollback.

All 297 Design for New Solutions questions →

Modify the SCP to exclude the approved provisioning: What should the architect do?

Design Solutions for Organizational Complexity Medium
An insurance company places production accounts in a Workloads OU and security tooling in a Security OU. A service team reports that an IAM policy allowing a role to create an S3 bucket is ineffective in one production account. The role has an attached identity policy granting the action, but the Workloads OU has an SCP denying all S3 creation except through the approved provisioning account. The team wants the smallest governance change that preserves the restriction while permitting the approved workflow. What should the architect do?
  1. Attach AdministratorAccess to the role in the production account.
    A broader identity policy cannot override the applicable explicit deny from the SCP.
  2. Modify the SCP to exclude the approved provisioning principal. ✓
    A narrowly scoped SCP condition exception preserves the deny for other principals while allowing the approved workflow.
  3. Create a permissions boundary allowing S3 bucket creation.
    A permissions boundary defines a maximum permission set; it cannot override the SCP's explicit deny.
  4. Move the account into the Security OU.
    Moving the account changes its inherited governance broadly and does not specifically authorize only the approved workflow.
The trap
A boundary cannot grant permissions or defeat an SCP. Identity allows cannot override an explicit SCP deny. OU relocation is broader than the required targeted exception.

All 266 Design Solutions for Organizational Complexity questions →

Deploy one NAT gateway per Availability Zone and route: Which architecture best satisfies both constraints?

Continuous Improvement for Existing Solutions Hard
An industrial manufacturer operates an application in two Availability Zones. Both private subnets currently route outbound package downloads through one NAT gateway in a third subnet. A zone outage must not prevent the surviving application zone from reaching required AWS APIs, and the company also wants to reduce avoidable cross-zone processing and improve recovery simplicity. The application is stateless; its relational database is a classic Multi-AZ DB instance. The architect must change only the outbound network design. Which architecture best satisfies both constraints?
  1. Deploy one NAT gateway per Availability Zone and route each private subnet to its local gateway. ✓
    Zonal NAT gateways remove the single-zone dependency and avoid routing private-subnet egress through another Availability Zone.
  2. Replace private subnets with public subnets and assign public addresses to application instances.
    Public addressing changes exposure and routing rather than providing private, zonally resilient outbound access required by the design.
  3. Move the NAT gateway into the database subnet and route application traffic through the classic standby during failure.
    NAT placement does not make the database standby an egress device, and the standby cannot serve application traffic.
  4. Add a second route to the existing NAT gateway and retain both private subnets on that gateway.
    Additional routes to one NAT gateway preserve the single dependency and cannot provide independent outbound access during its zone failure.
The trap
The database standby is neither an egress path nor read target. Multiple routes do not remove one NAT gateway dependency. Public exposure does not solve private zonal egress resilience.

All 256 Continuous Improvement for Existing Solutions questions →

Deploy recommendations separately: Which architecture best limits migration scope?

Accelerate Workload Migration and Modernization Medium
A media streaming company is extracting recommendations from a monolith. Playback must remain uninterrupted, the new capability must deploy independently, and temporary recommendation delays are acceptable. The monolith must remain for unrelated functions. Recommendation calls are synchronous, but viewing events can be asynchronous. Which architecture best limits migration scope?
  1. Deploy recommendations separately, route calls there, and queue viewing events. ✓
    A separate service enables independent deployment, selective routing preserves the monolith, and a queue handles delay-tolerant events.
  2. Publish recommendation calls to SNS and have playback clients consume the topic.
    SNS supports asynchronous notification, not the required synchronous recommendation request-response path.
  3. Replicate the monolith and shift all traffic with weighted DNS.
    This broad cutover does not isolate recommendations and can affect unrelated playback functions.
  4. Move the monolith to Lambda while keeping synchronous recommendation database calls.
    This expands migration scope and leaves recommendation processing coupled to synchronous application behavior.
The trap
Uses whole-application routing instead of capability extraction. Changes the runtime without creating a bounded capability. Confuses event fan-out with synchronous service routing.

All 205 Accelerate Workload Migration and Modernization questions →

Commit only to the measured baseline with a Compute: Which approach is most appropriate?

Design for New Solutions Easy
An energy provider is launching a compute-heavy analytics service. Forecasting is uncertain: the steady baseline may increase, but seasonal bursts are unpredictable and the team does not want unused commitments if adoption is slow. Workloads run on eligible EC2 usage, and the company can tolerate normal on-demand pricing for capacity above the baseline. Finance asks for a purchasing approach that balances savings with elasticity rather than maximizing a discount based on an unverified forecast. Which approach is most appropriate?
  1. Use a budget threshold as a guaranteed hard spending cap for all compute usage.
    Budgets monitor configured thresholds and actions but do not universally guarantee an immediate service-wide spend cap.
  2. Run all analytics on Spot Instances without fallback capacity or interruption handling.
    Spot can reduce cost for interruptible workloads, but using it exclusively conflicts with workloads needing dependable baseline capacity.
  3. Commit only to the measured baseline with a Compute Savings Plan and keep uncertain peaks on demand. ✓
    A baseline commitment can reduce eligible steady usage cost while on-demand capacity preserves flexibility for uncertain growth.
  4. Purchase commitments for the highest projected seasonal demand before production measurements exist.
    Overcommitting against an uncertain forecast risks paying for unused commitment when adoption or seasonal demand is lower.
The trap
Budget alerts are not universal cost enforcement. Spot interruptions require resilient fallback design. Forecast uncertainty makes peak commitment risky.

All 297 Design for New Solutions questions →

Inspection-originated reachability can bypass intended: Which concern is most important?

Design Solutions for Organizational Complexity Medium
A digital payments provider centralizes VPC connectivity through a Transit Gateway. Production, analytics, and inspection VPCs use separate TGW route tables, and attachment propagation is disabled by default. Security review confirms that production cannot initiate routes toward analytics. However, the inspection VPC can initiate connections toward production, and inspection appliances require symmetric flow paths. The provider asks for the residual risk in the design, assuming security groups and network ACLs remain unchanged. Which concern is most important?
  1. Inspection-originated reachability can bypass intended initiation boundaries. ✓
    Separate route tables constrain propagated routes, but explicit inspection routes can still permit unwanted initiation toward production.
  2. Transit Gateway automatically permits every VPC to route through every attachment.
    Transit Gateway reachability depends on route-table association and propagation rather than automatic universal connectivity.
  3. Security groups are stateless and therefore cannot protect inspection traffic.
    Security groups are stateful; the stated residual issue concerns routing direction and appliance path symmetry.
  4. Route53 DNS policies will automatically block production traffic.
    DNS routing selects answers and does not enforce packet-level reachability or application authorization.
The trap
Security groups are stateful, unlike network ACLs. DNS decisions do not replace network traffic controls. TGW routing is controlled by associations and propagation.

All 266 Design Solutions for Organizational Complexity questions →

Inventory unattached volumes: Which action should the provider add?

Continuous Improvement for Existing Solutions Easy
A managed service provider terminated several EC2 instances after a customer migration. Monthly cost reports still show EBS volume charges, but the operations team cannot map those volumes to running instances. The provider already uses Cost Explorer, activates cost-allocation tags for current resources, and scans instance inventories daily. Historical chargeback must be explainable, and cleanup must not delete data that remains required for recovery. Which action should the provider add?
  1. Inventory unattached volumes, review snapshots and owners, then approve deletion or retention. ✓
    This identifies residual EBS resources while ownership and recovery review prevents unsafe deletion.
  2. Delete all unattached volumes immediately after instance termination.
    An unattached volume can still contain data needed for recovery, so immediate deletion risks data loss.
  3. Use CloudTrail records alone to determine current volume ownership and charges.
    CloudTrail records API activity but is not a complete current inventory or billing-attribution source for EBS volumes.
  4. Assume activated cost-allocation tags automatically identify every historical unattached volume owner and retain no inventory.
    Activated tags do not guarantee complete historical attribution or replace an inventory of current unattached volumes.
The trap
Unattached storage can still be required. API history is not a complete cost inventory. Tags do not guarantee complete historical attribution.

All 256 Continuous Improvement for Existing Solutions questions →

Authentication still depends on reachable directory: Which residual risk should the architect identify?

Accelerate Workload Migration and Modernization Hard
An analytics company migrates a Windows-based shared file workload to Amazon FSx for Windows File Server. The design uses AWS Managed Microsoft AD, SMB encryption, encryption at rest, scheduled backups, and a Multi-AZ file-system deployment. Analytics instances access shares from two Availability Zones. The security team asks which material risk remains after these controls, because the workload cannot authenticate users when directory services are unavailable. Which residual risk should the architect identify?
  1. Encryption at rest prevents concurrent file sharing.
    Encryption protects stored data and does not prevent authorized clients from sharing files concurrently.
  2. Authentication still depends on reachable directory services during outages. ✓
    SMB authentication and authorization depend on Active Directory, so a directory-service disruption can block access even when FSx remains healthy.
  3. Multi-AZ deployment prevents access from another Availability Zone.
    A Multi-AZ FSx deployment supports highly available access across Availability Zones.
  4. Scheduled backups guarantee recovery from every accidental overwrite without data loss.
    Backups provide recovery points, but their schedule and restoration process do not guarantee zero data loss.
The trap
Encryption does not change SMB concurrency semantics. Multi-AZ deployment supports cross-zone access. Backups do not guarantee point-in-time, zero-loss recovery.

All 205 Accelerate Workload Migration and Modernization questions →

AWS Solutions Architect Professional exam: the facts

How many questions are on the AWS Solutions Architect Professional exam?

75, as published by the exam vendor.

How long is the AWS Solutions Architect Professional exam?

180 minutes. Across 75 questions that is about 144 seconds per question.

What topics does the AWS Solutions Architect Professional exam cover?

4 domains: Design for New Solutions, Design Solutions for Organizational Complexity, Continuous Improvement for Existing Solutions, Accelerate Workload Migration and Modernization. Weights: Design for New Solutions 29%, Design Solutions for Organizational Complexity 26%, Continuous Improvement for Existing Solutions 25%, Accelerate Workload Migration and Modernization 20%.

How many AWS Solutions Architect Professional practice exam questions does Certsqill have?

1024, spread across 4 exam domains. Every one shows all options, which is correct, and why each of the others is not.

Would you pass AWS Solutions Architect Professional today?

Five minutes, and you get a score per domain — not one number, but which section to open tonight.

Test your AWS Solutions Architect Professional readiness — free
Certsqill AWS Solutions Architect Professional question bank · 1024 questions across 4 domains · Every answer, right and wrong, comes with its own explanation.