AWS Solutions Architect Professional practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

AWS Solutions Architect Professional Design Solutions for Organizational Complexity: 266 practice questions

AWS Solutions Architect Professional 266 questions 12 shown free

12 of the 266 Design Solutions for Organizational Complexity questions in the Certsqill AWS Solutions Architect Professional bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for AWS Solutions Architect Professional? Take the free 5-min readiness check →

1. Exercise regional failover regularly: Select TWO actions that best satisfy the requirements.

Medium
A regional healthcare network runs a patient scheduling service in us-east-1. The business requires recovery within 20 minutes, an RPO of 5 minutes, and continued operation at 40% capacity during regional disruption. The approved recovery budget supports a reduced-capacity duplicate environment, but not a full active-active deployment. The database currently replicates asynchronously, with observed lag below 3 minutes. A recovery exercise must include DNS, credentials, dependencies, and application artifacts. Select TWO actions that best satisfy the requirements.

Select two. More than one option is correct — every correct one is ticked below.

  1. Exercise regional failover regularly, including DNS, dependencies, credentials, and application artifacts. ✓
    End-to-end exercises measure actual recovery feasibility and expose missing components beyond database replication.
  2. Use synchronous replication to the standby database and eliminate recovery testing.
    Replication does not validate DNS, dependencies, credentials, or application recovery, so testing remains necessary.
  3. Maintain only backups and provision the application after an outage.
    Backup restoration protects recoverability but provisioning and dependency reconstruction conflict with the twenty-minute recovery objective.
  4. Keep only the database and deployment templates ready, then scale the application during recovery.
    This pilot-light design requires application provisioning and scaling, creating unnecessary recovery delay for the stated objective.
  5. Operate a reduced-capacity warm standby application stack in another Region. ✓
    A functional reduced-capacity stack minimizes startup work while meeting the stated recovery time and budget constraint.
The trap
Pilot light requires more recovery preparation than warm standby. Backup restoration alone cannot meet the stated recovery time. Replication alone does not prove end-to-end recovery.

Use warm standby plus tested end-to-end recovery because the target requires rapid, reduced-capacity regional service.

2. Modify the SCP to exclude the approved provisioning: What should the architect do?

Medium
An insurance company places production accounts in a Workloads OU and security tooling in a Security OU. A service team reports that an IAM policy allowing a role to create an S3 bucket is ineffective in one production account. The role has an attached identity policy granting the action, but the Workloads OU has an SCP denying all S3 creation except through the approved provisioning account. The team wants the smallest governance change that preserves the restriction while permitting the approved workflow. What should the architect do?
  1. Attach AdministratorAccess to the role in the production account.
    A broader identity policy cannot override the applicable explicit deny from the SCP.
  2. Modify the SCP to exclude the approved provisioning principal. ✓
    A narrowly scoped SCP condition exception preserves the deny for other principals while allowing the approved workflow.
  3. Create a permissions boundary allowing S3 bucket creation.
    A permissions boundary defines a maximum permission set; it cannot override the SCP's explicit deny.
  4. Move the account into the Security OU.
    Moving the account changes its inherited governance broadly and does not specifically authorize only the approved workflow.
The trap
A boundary cannot grant permissions or defeat an SCP. Identity allows cannot override an explicit SCP deny. OU relocation is broader than the required targeted exception.

Modify the SCP narrowly; an identity policy cannot override its explicit deny.

3. Inspection-originated reachability can bypass intended: Which concern is most important?

Medium
A digital payments provider centralizes VPC connectivity through a Transit Gateway. Production, analytics, and inspection VPCs use separate TGW route tables, and attachment propagation is disabled by default. Security review confirms that production cannot initiate routes toward analytics. However, the inspection VPC can initiate connections toward production, and inspection appliances require symmetric flow paths. The provider asks for the residual risk in the design, assuming security groups and network ACLs remain unchanged. Which concern is most important?
  1. Inspection-originated reachability can bypass intended initiation boundaries. ✓
    Separate route tables constrain propagated routes, but explicit inspection routes can still permit unwanted initiation toward production.
  2. Transit Gateway automatically permits every VPC to route through every attachment.
    Transit Gateway reachability depends on route-table association and propagation rather than automatic universal connectivity.
  3. Security groups are stateless and therefore cannot protect inspection traffic.
    Security groups are stateful; the stated residual issue concerns routing direction and appliance path symmetry.
  4. Route53 DNS policies will automatically block production traffic.
    DNS routing selects answers and does not enforce packet-level reachability or application authorization.
The trap
Security groups are stateful, unlike network ACLs. DNS decisions do not replace network traffic controls. TGW routing is controlled by associations and propagation.

Residual risk is inspection-originated routing toward production and possible asymmetric appliance paths.

4. Activate approved tags: Which approach best meets the requirement?

Hard
A financial services group is moving workloads into separate business-unit accounts. Existing resources lack consistent cost allocation tags, and finance needs reliable business-unit reporting before migrating the next portfolio. The group will use Cost and Usage Reports for detailed allocation. A pilot migration contains three applications, each with a tested rollback procedure. The migration team proposes tagging everything after all workloads move, while finance proposes activating approved tags before the pilot and validating the report before continuing. Which approach best meets the requirement?
  1. Activate approved tags, validate pilot billing, then continue migration. ✓
    Early activation and validation establishes usable allocation before expanding migration and preserves a clear rollback boundary.
  2. Migrate every workload, then reconstruct historical allocation from resource names.
    Names do not reliably replace activated cost allocation tags and cannot ensure complete historical attribution.
  3. Apply tags only during monthly invoice review.
    Delayed tagging postpones allocation evidence and cannot support finance’s requirement before subsequent migration.
  4. Use a Savings Plan to assign charges automatically to business units.
    Savings Plans affect eligible commitment pricing but do not create business-unit cost allocation or historical tagging.
The trap
Monthly review occurs after the required decision point. Unactivated tags do not reliably reconstruct historical costs. Commitment discounts are not allocation mechanisms.

Activate and validate cost tags during the pilot before expanding migration, retaining a tested rollback boundary.

5. Grant the workload role permission to call sts: Select TWO required changes or validations.

Easy
An energy provider has a central security account and multiple workload accounts. A workload role must access a central S3 bucket and use a KMS key owned by the security account. Security proposes a role in the security account whose trust policy names the workload role, then grants the workload role access only through its identity policy. The provider must avoid long-lived credentials and ensure both cross-account S3 and KMS access work. Select TWO required changes or validations.

Select two. More than one option is correct — every correct one is ticked below.

  1. Use an IAM allow without changing or validating the KMS key policy.
    Cross-account KMS use requires compatible key-policy authorization as well as caller permissions.
  2. Grant the workload role permission to call sts:AssumeRole on the central role. ✓
    The workload role needs caller-side authorization in addition to the target role's trust policy.
  3. Validate or update the central role permissions and KMS key policy for the required S3 and KMS operations. ✓
    After assumption, the central role must authorize S3 access, and the KMS key policy must permit the cross-account key operations together with the caller's permissions.
  4. Attach AdministratorAccess only to the workload role.
    Broad workload permissions do not establish role trust or authorize the central role and KMS key for the required cross-account operations.
  5. Embed access keys for the central bucket in the workload application.
    Long-lived credentials violate the stated design direction and create rotation and exposure risks.
The trap
Embedded credentials are unnecessary and create avoidable secret risk. An IAM allow cannot override a restrictive KMS key policy. AdministratorAccess cannot replace trust and resource-policy requirements.

The caller needs AssumeRole permission, and the central role plus KMS key policy must authorize resource use.

6. Cross-Region recovery for the application database: What should the architect identify?

Easy
A managed service provider replicates a customer’s application servers to a recovery Region using AWS Elastic Disaster Recovery. During a controlled test, replication lag remains below the customer’s five-minute RPO, but the recovered servers cannot serve requests because the application depends on a database cluster that is not present in the recovery Region. DNS records and recovery runbooks are already tested. The customer asks which missing component explains the failed recovery. What should the architect identify?
  1. Cross-Region recovery for the application database. ✓
    Server replication alone cannot restore the application when its required database cluster has no recovery-Region implementation.
  2. A larger staging subnet for replicated servers.
    Additional subnet capacity does not provide the database service required by the recovered application.
  3. A read-only connection to the source database.
    A source-Region dependency remains a failure point if the source Region is unavailable.
  4. A second DNS routing policy for the same records.
    DNS routing cannot create or recover an unavailable database cluster in the recovery Region.
The trap
Network capacity does not provide database recovery. Routing cannot replace an unreplicated application dependency. A source connection does not provide independent regional recovery.

The database also requires a verified cross-Region recovery design.

7. Automate account provisioning with an approved baseline: Select TWO actions.

Medium
A media streaming company uses a landing zone with separate OUs for production and experimentation. The platform team must vend accounts with a standard network baseline, mandatory logging, and approved instance products. New accounts should inherit the correct preventive controls immediately, while workload teams retain autonomy inside their accounts. The current process creates accounts manually and emails setup instructions. The company wants the smallest complete change, not a redesign of application permissions. Select TWO actions.

Select two. More than one option is correct — every correct one is ticked below.

  1. Automate account provisioning with an approved baseline product. ✓
    Automated provisioning consistently deploys the required network and logging baseline while reducing manual setup variance.
  2. Put every account in one OU to simplify inheritance.
    A single OU cannot express different preventive requirements for production and experimentation accounts.
  3. Place newly vended accounts in the appropriate governed OU. ✓
    OU placement applies the intended inherited organizational guardrails to accounts with similar policy requirements.
  4. Use RAM to grant each account ownership of the baseline.
    RAM shares supported resources but does not replace account provisioning, OU governance, or baseline deployment.
  5. Share the platform account’s administrator role with every workload team.
    Role sharing expands privilege and does not establish repeatable account vending or inherited preventive controls.
The trap
Resource sharing is not account vending. Shared administration undermines workload-account autonomy. OU design should reflect policy needs, not mere administrative simplicity.

Governed OU placement plus automated baseline provisioning provides the smallest complete account-vending change.

8. Deploy AZ-redundant inbound endpoints and configure: Which architecture best satisfies the decisive constraint

Hard
A public-sector agency hosts internal applications in AWS and must resolve private AWS service names from on-premises networks. Existing VPCs use Route 53 Resolver outbound endpoints for AWS-to-on-premises queries. On-premises users currently send queries to an AWS inbound endpoint, but only one endpoint IP is configured at branch sites. The agency requires resilient inbound resolution across two Availability Zones and wants centralized forwarding rules shared with application VPCs. Which architecture best satisfies the decisive constraints?
  1. Use Route 53 DNS routing to select an endpoint by URL path.
    DNS routing selects DNS answers and does not inspect HTTP URL paths or replace redundant Resolver endpoint configuration.
  2. Deploy AZ-redundant inbound endpoints and configure branches with both IPs. ✓
    Inbound endpoints receive on-premises queries; using addresses in two Availability Zones and configuring both addresses removes the single-endpoint dependency. Resolver rules can be shared with application VPCs.
  3. Configure only outbound endpoints because AWS must resolve on-premises names.
    Outbound endpoints forward VPC-originated queries to on-premises; on-premises clients require inbound endpoints to query AWS private names.
  4. Replace inbound endpoints with a NAT gateway.
    NAT provides address translation and does not receive or forward private DNS queries.
The trap
NAT is not a DNS resolver endpoint. DNS routing does not perform HTTP path routing. Resolver endpoint direction is reversed.

Use redundant inbound endpoints, configure both addresses at branches, and share Resolver rules.

9. Use AWS Budgets for the approved forecast threshold alert: Select TWO actions that directly address these requ

Medium
An analytics company runs a shared data platform for three business units. Finance needs monthly unit-level allocation and platform recovery spending visibility. The Cost and Usage Report contains account, service, and activated cost-allocation-tag fields. Measurements show steady baseline compute demand, highly variable batch demand, and interruptible batch workers. Finance also requires historical billing analysis and alerts when forecast spending crosses an approved threshold. Select TWO actions that directly address these requirements.

Select two. More than one option is correct — every correct one is ticked below.

  1. Use AWS Budgets for the approved forecast threshold alert. ✓
    Budgets monitors configured thresholds and forecasts, providing the requested alert without implying an absolute spending cap.
  2. Use Spot capacity for the steady baseline compute workload.
    Steady baseline workloads generally require more predictable capacity than interruptible Spot capacity provides.
  3. Query the configured Cost and Usage Report for unit-level allocation. ✓
    The configured report supplies granular billing dimensions needed to analyze shared platform consumption by business unit.
  4. Treat a budget threshold as an immediate universal spend cap.
    Budgets monitors configured thresholds and actions but does not universally guarantee an immediate spending stop.
  5. Assume activated tags automatically repair all prior untagged billing.
    Tag activation does not automatically backfill every historical cost record that lacked the allocation tag.
The trap
Spot is better suited to resilient interruptible work. Budget alerts are not guaranteed hard spending limits. Activation does not guarantee historical backfill.

Use the detailed Cost and Usage Report for allocation and Budgets for configured forecast monitoring.

10. The SCP explicit deny overrides the role’s delete allow: What should the architect conclude?

Hard
A university research team uses AWS Organizations. A member account role has an identity policy allowing access to an S3 research bucket. The organization’s SCP excerpt is: {"Effect":"Deny","Action":"s3:DeleteObject","Resource":"*"}. A researcher can read objects but cannot delete them, even though the role policy includes both actions. The team must preserve the deletion guardrail while allowing a separate archival workflow to remove objects after approval. What should the architect conclude?
  1. The SCP explicit deny overrides the role’s delete allow. ✓
    An applicable explicit deny in the member account prevents deletion despite the role’s identity-policy allow.
  2. The role policy grants deletion because identity allows override SCPs.
    Identity-policy allows cannot override an applicable explicit deny imposed by an organizational SCP.
  3. The SCP grants read access but not deletion access.
    SCPs define maximum permissions and do not grant the read permission observed through the role policy.
  4. The archive workflow only needs a different IAM group.
    Changing groups does not bypass the organization-level explicit deny applying to the member account.
The trap
A different group remains subject to the SCP. SCPs can impose permission ceilings over member accounts. SCPs restrict; identity policies grant.

The SCP’s explicit deletion deny prevails; the approved workflow needs a narrowly governed organizational exception.

11. Use a warm standby in another Region with continuous: Which design best satisfies these constraints?

Easy
An online marketplace must recover its checkout service in 20 minutes after a Regional outage, with an RPO under five minutes. The relational database contains orders and inventory; payment authorization is external. The operations team has only two engineers per shift and wants the least complex recovery process that still meets the availability requirement. Which design best satisfies these constraints?
  1. Use a warm standby in another Region with continuous database replication and tested failover. ✓
    A cross-Region warm standby reduces outage-time provisioning, while continuous replication and measured failover testing can demonstrate the five-minute RPO and 20-minute RTO.
  2. Use pilot light in another Region, then provision application capacity and validate dependencies after detecting the outage.
    Pilot light requires more outage-time provisioning and validation than warm standby, increasing operational burden and threatening the 20-minute RTO.
  3. Restore the latest nightly backup after the outage.
    Nightly backups cannot meet an RPO under five minutes and require substantial outage-time recovery work.
  4. Maintain active-active applications but rebuild the database from backups and change DNS whenever the primary Region fails.
    Active-active application capacity cannot compensate for backup recovery that misses the RPO and a multi-step outage-time database and routing process.
The trap
The recovery point is too old. More recovery work occurs during the outage. Application availability does not fix inadequate database recovery.

Use a measured cross-Region warm standby with continuous replication.

12. Create an organization trail to the protected log archive: Which action is most appropriate?

Easy
A global retailer has separate production accounts and a dedicated log-archive account. Security requires organization-wide API activity retained centrally, while application teams must not delete or alter the central records. The exhibit shows: Log archive—S3 retention enabled; Production accounts—independent CloudTrail trails; Security account—read-only analysts. The company wants one centrally governed design without granting application administrators access to the archive. Which action is most appropriate?
  1. Give each application account administrator access to the log-archive bucket.
    Application administrator access could allow modification of centrally retained evidence and violates separation of duties.
  2. Aggregate AWS Config data into the log-archive account and disable account-level CloudTrail trails.
    Config aggregation reports resource configuration and compliance; it does not replace CloudTrail API activity, and disabling trails removes evidence.
  3. Create an organization trail to the protected log archive. ✓
    An organization trail centralizes API activity in the dedicated archive while preserving separation from workload administrators.
  4. Share the archive account through RAM and let each workload account write directly to it.
    RAM sharing does not create centralized CloudTrail governance or prevent workload administrators from influencing records.
The trap
Config does not replace CloudTrail API activity. Workload administrators should not control the evidence archive. Resource sharing is not centralized audit governance.

Use an organization trail writing to the protected log archive.

254 more Design Solutions for Organizational Complexity questions

The remaining 254 questions in this domain are part of the full AWS Solutions Architect Professional bank — 1024 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your AWS Solutions Architect Professional readiness — free

Other AWS Solutions Architect Professional domains

Part of the Certsqill AWS Solutions Architect Professional question bank · Design Solutions for Organizational Complexity · Every answer, right and wrong, comes with its own explanation.