AWS Solutions Architect Professional practice exam: 1024 questions with full explanations
- Questions on the exam
- 75
- Time allowed
- 180 minutes format →
- Passing score
- 750 of 1000 — vendor, checked September 28, 2026 detail →
- Exam fee
- $300 — vendor, checked September 28, 2026 detail →
1024 practice exam questions for AWS Certified Solutions Architect – Professional, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.
Not sure where you stand? Take the free 5-min AWS Solutions Architect Professional readiness check →
AWS Solutions Architect Professional certification: requirements, cost and exam format → · AWS Solutions Architect Professional exam format → · AWS Solutions Architect Professional passing score → · AWS Solutions Architect Professional exam cost →
Questions by domain
- Design for New Solutions — 297 questions →
- Design Solutions for Organizational Complexity — 266 questions →
- Continuous Improvement for Existing Solutions — 256 questions →
- Accelerate Workload Migration and Modernization — 205 questions →
Sample questions
Use blue-green environments with expand-contract schema: Which architecture best satisfies both requirements?
- Continue rolling deployment and run a CloudFormation change set before each release.A change set previews infrastructure changes, but rolling deployment still mixes versions and does not ensure schema compatibility.
- Use a canary release while applying an irreversible schema change before compatibility testing.Canary traffic limits exposure, but an irreversible schema change can prevent reliable rollback to the previous application.
- Replace the old environment in place and restore its previous AMI if errors occur.In-place replacement can leave partial changes and does not provide a separately validated environment or safe schema transition.
- Use blue-green environments with expand-contract schema changes, validate green, then shift traffic. ✓A separate validated environment enables traffic reversal, while expand-contract changes keep the schema compatible with both application versions.
All 297 Design for New Solutions questions →
Modify the SCP to exclude the approved provisioning: What should the architect do?
- Attach AdministratorAccess to the role in the production account.A broader identity policy cannot override the applicable explicit deny from the SCP.
- Modify the SCP to exclude the approved provisioning principal. ✓A narrowly scoped SCP condition exception preserves the deny for other principals while allowing the approved workflow.
- Create a permissions boundary allowing S3 bucket creation.A permissions boundary defines a maximum permission set; it cannot override the SCP's explicit deny.
- Move the account into the Security OU.Moving the account changes its inherited governance broadly and does not specifically authorize only the approved workflow.
All 266 Design Solutions for Organizational Complexity questions →
Deploy one NAT gateway per Availability Zone and route: Which architecture best satisfies both constraints?
- Deploy one NAT gateway per Availability Zone and route each private subnet to its local gateway. ✓Zonal NAT gateways remove the single-zone dependency and avoid routing private-subnet egress through another Availability Zone.
- Replace private subnets with public subnets and assign public addresses to application instances.Public addressing changes exposure and routing rather than providing private, zonally resilient outbound access required by the design.
- Move the NAT gateway into the database subnet and route application traffic through the classic standby during failure.NAT placement does not make the database standby an egress device, and the standby cannot serve application traffic.
- Add a second route to the existing NAT gateway and retain both private subnets on that gateway.Additional routes to one NAT gateway preserve the single dependency and cannot provide independent outbound access during its zone failure.
All 256 Continuous Improvement for Existing Solutions questions →
Deploy recommendations separately: Which architecture best limits migration scope?
- Deploy recommendations separately, route calls there, and queue viewing events. ✓A separate service enables independent deployment, selective routing preserves the monolith, and a queue handles delay-tolerant events.
- Publish recommendation calls to SNS and have playback clients consume the topic.SNS supports asynchronous notification, not the required synchronous recommendation request-response path.
- Replicate the monolith and shift all traffic with weighted DNS.This broad cutover does not isolate recommendations and can affect unrelated playback functions.
- Move the monolith to Lambda while keeping synchronous recommendation database calls.This expands migration scope and leaves recommendation processing coupled to synchronous application behavior.
All 205 Accelerate Workload Migration and Modernization questions →
Commit only to the measured baseline with a Compute: Which approach is most appropriate?
- Use a budget threshold as a guaranteed hard spending cap for all compute usage.Budgets monitor configured thresholds and actions but do not universally guarantee an immediate service-wide spend cap.
- Run all analytics on Spot Instances without fallback capacity or interruption handling.Spot can reduce cost for interruptible workloads, but using it exclusively conflicts with workloads needing dependable baseline capacity.
- Commit only to the measured baseline with a Compute Savings Plan and keep uncertain peaks on demand. ✓A baseline commitment can reduce eligible steady usage cost while on-demand capacity preserves flexibility for uncertain growth.
- Purchase commitments for the highest projected seasonal demand before production measurements exist.Overcommitting against an uncertain forecast risks paying for unused commitment when adoption or seasonal demand is lower.
All 297 Design for New Solutions questions →
Inspection-originated reachability can bypass intended: Which concern is most important?
- Inspection-originated reachability can bypass intended initiation boundaries. ✓Separate route tables constrain propagated routes, but explicit inspection routes can still permit unwanted initiation toward production.
- Transit Gateway automatically permits every VPC to route through every attachment.Transit Gateway reachability depends on route-table association and propagation rather than automatic universal connectivity.
- Security groups are stateless and therefore cannot protect inspection traffic.Security groups are stateful; the stated residual issue concerns routing direction and appliance path symmetry.
- Route53 DNS policies will automatically block production traffic.DNS routing selects answers and does not enforce packet-level reachability or application authorization.
All 266 Design Solutions for Organizational Complexity questions →
Inventory unattached volumes: Which action should the provider add?
- Inventory unattached volumes, review snapshots and owners, then approve deletion or retention. ✓This identifies residual EBS resources while ownership and recovery review prevents unsafe deletion.
- Delete all unattached volumes immediately after instance termination.An unattached volume can still contain data needed for recovery, so immediate deletion risks data loss.
- Use CloudTrail records alone to determine current volume ownership and charges.CloudTrail records API activity but is not a complete current inventory or billing-attribution source for EBS volumes.
- Assume activated cost-allocation tags automatically identify every historical unattached volume owner and retain no inventory.Activated tags do not guarantee complete historical attribution or replace an inventory of current unattached volumes.
All 256 Continuous Improvement for Existing Solutions questions →
Authentication still depends on reachable directory: Which residual risk should the architect identify?
- Encryption at rest prevents concurrent file sharing.Encryption protects stored data and does not prevent authorized clients from sharing files concurrently.
- Authentication still depends on reachable directory services during outages. ✓SMB authentication and authorization depend on Active Directory, so a directory-service disruption can block access even when FSx remains healthy.
- Multi-AZ deployment prevents access from another Availability Zone.A Multi-AZ FSx deployment supports highly available access across Availability Zones.
- Scheduled backups guarantee recovery from every accidental overwrite without data loss.Backups provide recovery points, but their schedule and restoration process do not guarantee zero data loss.
All 205 Accelerate Workload Migration and Modernization questions →
AWS Solutions Architect Professional exam: the facts
How many questions are on the AWS Solutions Architect Professional exam?
75, as published by the exam vendor.
How long is the AWS Solutions Architect Professional exam?
180 minutes. Across 75 questions that is about 144 seconds per question.
What topics does the AWS Solutions Architect Professional exam cover?
4 domains: Design for New Solutions, Design Solutions for Organizational Complexity, Continuous Improvement for Existing Solutions, Accelerate Workload Migration and Modernization. Weights: Design for New Solutions 29%, Design Solutions for Organizational Complexity 26%, Continuous Improvement for Existing Solutions 25%, Accelerate Workload Migration and Modernization 20%.
How many AWS Solutions Architect Professional practice exam questions does Certsqill have?
1024, spread across 4 exam domains. Every one shows all options, which is correct, and why each of the others is not.
Would you pass AWS Solutions Architect Professional today?
Five minutes, and you get a score per domain — not one number, but which section to open tonight.
Test your AWS Solutions Architect Professional readiness — free