AWS Solutions Architect Professional Design Solutions for Organizational Complexity: 266 practice questions
12 of the 266 Design Solutions for Organizational Complexity questions in the Certsqill AWS Solutions Architect Professional bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for AWS Solutions Architect Professional? Take the free 5-min readiness check →
1. Exercise regional failover regularly: Select TWO actions that best satisfy the requirements.
Select two. More than one option is correct — every correct one is ticked below.
- Exercise regional failover regularly, including DNS, dependencies, credentials, and application artifacts. ✓End-to-end exercises measure actual recovery feasibility and expose missing components beyond database replication.
- Use synchronous replication to the standby database and eliminate recovery testing.Replication does not validate DNS, dependencies, credentials, or application recovery, so testing remains necessary.
- Maintain only backups and provision the application after an outage.Backup restoration protects recoverability but provisioning and dependency reconstruction conflict with the twenty-minute recovery objective.
- Keep only the database and deployment templates ready, then scale the application during recovery.This pilot-light design requires application provisioning and scaling, creating unnecessary recovery delay for the stated objective.
- Operate a reduced-capacity warm standby application stack in another Region. ✓A functional reduced-capacity stack minimizes startup work while meeting the stated recovery time and budget constraint.
Use warm standby plus tested end-to-end recovery because the target requires rapid, reduced-capacity regional service.
2. Modify the SCP to exclude the approved provisioning: What should the architect do?
- Attach AdministratorAccess to the role in the production account.A broader identity policy cannot override the applicable explicit deny from the SCP.
- Modify the SCP to exclude the approved provisioning principal. ✓A narrowly scoped SCP condition exception preserves the deny for other principals while allowing the approved workflow.
- Create a permissions boundary allowing S3 bucket creation.A permissions boundary defines a maximum permission set; it cannot override the SCP's explicit deny.
- Move the account into the Security OU.Moving the account changes its inherited governance broadly and does not specifically authorize only the approved workflow.
Modify the SCP narrowly; an identity policy cannot override its explicit deny.
3. Inspection-originated reachability can bypass intended: Which concern is most important?
- Inspection-originated reachability can bypass intended initiation boundaries. ✓Separate route tables constrain propagated routes, but explicit inspection routes can still permit unwanted initiation toward production.
- Transit Gateway automatically permits every VPC to route through every attachment.Transit Gateway reachability depends on route-table association and propagation rather than automatic universal connectivity.
- Security groups are stateless and therefore cannot protect inspection traffic.Security groups are stateful; the stated residual issue concerns routing direction and appliance path symmetry.
- Route53 DNS policies will automatically block production traffic.DNS routing selects answers and does not enforce packet-level reachability or application authorization.
Residual risk is inspection-originated routing toward production and possible asymmetric appliance paths.
4. Activate approved tags: Which approach best meets the requirement?
- Activate approved tags, validate pilot billing, then continue migration. ✓Early activation and validation establishes usable allocation before expanding migration and preserves a clear rollback boundary.
- Migrate every workload, then reconstruct historical allocation from resource names.Names do not reliably replace activated cost allocation tags and cannot ensure complete historical attribution.
- Apply tags only during monthly invoice review.Delayed tagging postpones allocation evidence and cannot support finance’s requirement before subsequent migration.
- Use a Savings Plan to assign charges automatically to business units.Savings Plans affect eligible commitment pricing but do not create business-unit cost allocation or historical tagging.
Activate and validate cost tags during the pilot before expanding migration, retaining a tested rollback boundary.
5. Grant the workload role permission to call sts: Select TWO required changes or validations.
Select two. More than one option is correct — every correct one is ticked below.
- Use an IAM allow without changing or validating the KMS key policy.Cross-account KMS use requires compatible key-policy authorization as well as caller permissions.
- Grant the workload role permission to call sts:AssumeRole on the central role. ✓The workload role needs caller-side authorization in addition to the target role's trust policy.
- Validate or update the central role permissions and KMS key policy for the required S3 and KMS operations. ✓After assumption, the central role must authorize S3 access, and the KMS key policy must permit the cross-account key operations together with the caller's permissions.
- Attach AdministratorAccess only to the workload role.Broad workload permissions do not establish role trust or authorize the central role and KMS key for the required cross-account operations.
- Embed access keys for the central bucket in the workload application.Long-lived credentials violate the stated design direction and create rotation and exposure risks.
The caller needs AssumeRole permission, and the central role plus KMS key policy must authorize resource use.
6. Cross-Region recovery for the application database: What should the architect identify?
- Cross-Region recovery for the application database. ✓Server replication alone cannot restore the application when its required database cluster has no recovery-Region implementation.
- A larger staging subnet for replicated servers.Additional subnet capacity does not provide the database service required by the recovered application.
- A read-only connection to the source database.A source-Region dependency remains a failure point if the source Region is unavailable.
- A second DNS routing policy for the same records.DNS routing cannot create or recover an unavailable database cluster in the recovery Region.
The database also requires a verified cross-Region recovery design.
7. Automate account provisioning with an approved baseline: Select TWO actions.
Select two. More than one option is correct — every correct one is ticked below.
- Automate account provisioning with an approved baseline product. ✓Automated provisioning consistently deploys the required network and logging baseline while reducing manual setup variance.
- Put every account in one OU to simplify inheritance.A single OU cannot express different preventive requirements for production and experimentation accounts.
- Place newly vended accounts in the appropriate governed OU. ✓OU placement applies the intended inherited organizational guardrails to accounts with similar policy requirements.
- Use RAM to grant each account ownership of the baseline.RAM shares supported resources but does not replace account provisioning, OU governance, or baseline deployment.
- Share the platform account’s administrator role with every workload team.Role sharing expands privilege and does not establish repeatable account vending or inherited preventive controls.
Governed OU placement plus automated baseline provisioning provides the smallest complete account-vending change.
8. Deploy AZ-redundant inbound endpoints and configure: Which architecture best satisfies the decisive constraint
- Use Route 53 DNS routing to select an endpoint by URL path.DNS routing selects DNS answers and does not inspect HTTP URL paths or replace redundant Resolver endpoint configuration.
- Deploy AZ-redundant inbound endpoints and configure branches with both IPs. ✓Inbound endpoints receive on-premises queries; using addresses in two Availability Zones and configuring both addresses removes the single-endpoint dependency. Resolver rules can be shared with application VPCs.
- Configure only outbound endpoints because AWS must resolve on-premises names.Outbound endpoints forward VPC-originated queries to on-premises; on-premises clients require inbound endpoints to query AWS private names.
- Replace inbound endpoints with a NAT gateway.NAT provides address translation and does not receive or forward private DNS queries.
Use redundant inbound endpoints, configure both addresses at branches, and share Resolver rules.
9. Use AWS Budgets for the approved forecast threshold alert: Select TWO actions that directly address these requ
Select two. More than one option is correct — every correct one is ticked below.
- Use AWS Budgets for the approved forecast threshold alert. ✓Budgets monitors configured thresholds and forecasts, providing the requested alert without implying an absolute spending cap.
- Use Spot capacity for the steady baseline compute workload.Steady baseline workloads generally require more predictable capacity than interruptible Spot capacity provides.
- Query the configured Cost and Usage Report for unit-level allocation. ✓The configured report supplies granular billing dimensions needed to analyze shared platform consumption by business unit.
- Treat a budget threshold as an immediate universal spend cap.Budgets monitors configured thresholds and actions but does not universally guarantee an immediate spending stop.
- Assume activated tags automatically repair all prior untagged billing.Tag activation does not automatically backfill every historical cost record that lacked the allocation tag.
Use the detailed Cost and Usage Report for allocation and Budgets for configured forecast monitoring.
10. The SCP explicit deny overrides the role’s delete allow: What should the architect conclude?
- The SCP explicit deny overrides the role’s delete allow. ✓An applicable explicit deny in the member account prevents deletion despite the role’s identity-policy allow.
- The role policy grants deletion because identity allows override SCPs.Identity-policy allows cannot override an applicable explicit deny imposed by an organizational SCP.
- The SCP grants read access but not deletion access.SCPs define maximum permissions and do not grant the read permission observed through the role policy.
- The archive workflow only needs a different IAM group.Changing groups does not bypass the organization-level explicit deny applying to the member account.
The SCP’s explicit deletion deny prevails; the approved workflow needs a narrowly governed organizational exception.
11. Use a warm standby in another Region with continuous: Which design best satisfies these constraints?
- Use a warm standby in another Region with continuous database replication and tested failover. ✓A cross-Region warm standby reduces outage-time provisioning, while continuous replication and measured failover testing can demonstrate the five-minute RPO and 20-minute RTO.
- Use pilot light in another Region, then provision application capacity and validate dependencies after detecting the outage.Pilot light requires more outage-time provisioning and validation than warm standby, increasing operational burden and threatening the 20-minute RTO.
- Restore the latest nightly backup after the outage.Nightly backups cannot meet an RPO under five minutes and require substantial outage-time recovery work.
- Maintain active-active applications but rebuild the database from backups and change DNS whenever the primary Region fails.Active-active application capacity cannot compensate for backup recovery that misses the RPO and a multi-step outage-time database and routing process.
Use a measured cross-Region warm standby with continuous replication.
12. Create an organization trail to the protected log archive: Which action is most appropriate?
- Give each application account administrator access to the log-archive bucket.Application administrator access could allow modification of centrally retained evidence and violates separation of duties.
- Aggregate AWS Config data into the log-archive account and disable account-level CloudTrail trails.Config aggregation reports resource configuration and compliance; it does not replace CloudTrail API activity, and disabling trails removes evidence.
- Create an organization trail to the protected log archive. ✓An organization trail centralizes API activity in the dedicated archive while preserving separation from workload administrators.
- Share the archive account through RAM and let each workload account write directly to it.RAM sharing does not create centralized CloudTrail governance or prevent workload administrators from influencing records.
Use an organization trail writing to the protected log archive.
254 more Design Solutions for Organizational Complexity questions
The remaining 254 questions in this domain are part of the full AWS Solutions Architect Professional bank — 1024 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your AWS Solutions Architect Professional readiness — freeOther AWS Solutions Architect Professional domains
- Design for New Solutions — 297 questions →
- Continuous Improvement for Existing Solutions — 256 questions →
- Accelerate Workload Migration and Modernization — 205 questions →
- All 1024 AWS Solutions Architect Professional questions →
- AWS Solutions Architect Professional certification: requirements, cost and exam format →