AWS Solutions Architect Handbook SAA-C03, from zero Bipin Singh
Scenarios & real-world use cases

Scenario practice: security and resilience

7 min readChapter 44 of 48By Bipin Singh

These original questions follow the SAA-C03 style. Read each scenario, decide on your answer, then open the explanation. The reasoning matters more than the letter — study why each wrong option is wrong.

Q1 — Application access to S3

An application on EC2 instances in a private subnet must read objects from an S3 bucket. The security team forbids long-term credentials on the instances and wants traffic to stay off the internet. Which TWO steps meet these requirements?

Show answer

Answer: B and C. A role provides temporary credentials automatically (no stored keys), and the gateway endpoint keeps S3 traffic on the AWS network at no extra cost. A stores long-term keys. D sends traffic out through NAT to S3's public endpoint, and NAT gateways don't support security groups. E is insecure.

Q2 — Preventing actions across accounts

A company with 40 AWS accounts in AWS Organizations must ensure that no one — including account administrators — can disable CloudTrail or use Regions outside Europe. What should the solutions architect do?

Show answer

Answer: B. SCPs set maximum permissions for every principal in member accounts, including their root users, and can't be overridden from inside the account. A depends on every admin not removing the policy. C detects but doesn't prevent. D detects threats, it doesn't restrict actions.

Q3 — Workforce sign-in

Employees authenticate with the company's existing identity provider. They need console and CLI access to 25 AWS accounts with different permissions per team, with the least administrative effort. Which solution should be used?

Show answer

Answer: B. IAM Identity Center provides central workforce access to many accounts with federation and permission sets. A is high effort and insecure. C is for application end users, not AWS account access. D violates every best practice.

Q4 — Encrypting an existing database

An Amazon RDS for MySQL instance was created without encryption. Compliance now requires encryption at rest with a customer managed KMS key, with minimal data loss. What should be done?

Show answer

Answer: B. Encryption must be chosen at creation; the supported path is snapshot → encrypted copy → restore. To minimise data loss, stop writes or use DMS replication for the final cutover. A isn't possible. C isn't supported (a replica of an unencrypted instance can't be encrypted). D is unrelated.

Q5 — Protecting a web application

A public web application behind an Application Load Balancer is receiving SQL injection attempts and occasional floods of requests from a few IP addresses. Which solution addresses both with the least operational overhead?

Show answer

Answer: B. WAF managed rules block SQLi patterns, and rate-based rules automatically block IPs exceeding a threshold. A and C are high effort and reactive. D scans for software vulnerabilities; it doesn't block requests.

Q6 — Private admin access

Operations staff need shell access to EC2 instances in private subnets. The security team wants no inbound ports open, no bastion hosts, no SSH keys, and full session logging. What should be used?

Show answer

Answer: B. Session Manager needs no inbound ports or keys, is controlled by IAM, and logs sessions to CloudWatch Logs or S3. The other options all involve open ports or key management.

Q7 — Losing orders during spikes

An order service receives orders synchronously from the web tier. During flash sales the order service slows down and orders are lost. Which change best improves resilience?

Show answer

Answer: B. The queue durably buffers orders and decouples the tiers; workers scale with the backlog. A raises the ceiling but still loses orders when it's exceeded. C doesn't address the bottleneck. D pushes to an HTTP endpoint that may be overloaded; SNS retries are limited, and there's no buffering.

Q8 — Surviving an AZ failure

A web application runs on a single EC2 instance with a MySQL database on the same instance. It must stay available if an Availability Zone fails, with minimal operational overhead. Which design is best?

Show answer

Answer: B. It removes both single points of failure with automatic failover and managed services. A and D need manual recovery; C doesn't address AZ failure at all.

Q9 — Choosing a DR strategy

A company's application must recover in another Region within 4 hours, and may lose up to 1 hour of data. Leadership wants the lowest cost. Which strategy fits?

Show answer

Answer: C. RPO 1 hour and RTO 4 hours are met by hourly cross-Region backups plus automated rebuilds, at the lowest cost. A and B meet the targets but cost more. D doesn't protect against a Region-level event.

Q10 — Global relational database with fast DR

A global e-commerce company needs a relational database with low-latency reads in three continents, and Regional disaster recovery with an RPO of seconds and an RTO of about a minute. Which solution meets these requirements?

Show answer

Answer: B. Aurora Global Database replicates with typical sub-second lag and supports fast promotion of a secondary Region. A can work but promotion is slower and replication lag is higher. C isn't relational. D doesn't cover Regional failure or global reads.

Q11 — Lambda overwhelming the database

A serverless API uses Lambda functions that connect to an Amazon RDS for PostgreSQL database. Under load the database runs out of connections. What should be done with the least code change?

Show answer

Answer: B. RDS Proxy pools and reuses connections; the functions only change their endpoint. A worsens the problem. C is a large redesign. D throttles the API severely.

Q12 — Immutable backups

Auditors require that backups of EC2, RDS and EFS can't be deleted or altered by anyone, including administrators, for 1 year, and that they're kept in a separate account. Which solution meets this?

Show answer

Answer: B. Vault Lock in compliance mode enforces WORM retention that even root can't override, and AWS Backup handles all three services with cross-account copies. A can be changed by admins. C protects versions but allows deletion by privileged users unless Object Lock is used, and requires custom exports. D is manual and doesn't prevent deletion.

Bipin Singh
Written by Bipin Singh

Senior Full-Stack Engineer · AI & AWS. I design and run production systems on AWS — serverless, data and AI.

Work with me