Scenario practice: security and resilience
These original questions follow the SAA-C03 style. Read each scenario, decide on your answer, then open the explanation. The reasoning matters more than the letter — study why each wrong option is wrong.
Q1 — Application access to S3
An application on EC2 instances in a private subnet must read objects from an S3 bucket. The security team forbids long-term credentials on the instances and wants traffic to stay off the internet. Which TWO steps meet these requirements?
- A. Create an IAM user and store its access keys in the application configuration
- B. Attach an IAM role with S3 read permissions to the instances via an instance profile
- C. Create a gateway VPC endpoint for S3 and add it to the private subnet route table
- D. Route traffic through a NAT gateway with a restrictive security group
- E. Make the bucket public but restrict access by IP address
Show answer
Answer: B and C. A role provides temporary credentials automatically (no stored keys), and the gateway endpoint keeps S3 traffic on the AWS network at no extra cost. A stores long-term keys. D sends traffic out through NAT to S3's public endpoint, and NAT gateways don't support security groups. E is insecure.
Q2 — Preventing actions across accounts
A company with 40 AWS accounts in AWS Organizations must ensure that no one — including account administrators — can disable CloudTrail or use Regions outside Europe. What should the solutions architect do?
- A. Create an IAM policy denying these actions and attach it to every user
- B. Apply service control policies to the organizational units with explicit denies
- C. Use AWS Config rules to detect and alert on violations
- D. Enable GuardDuty in all accounts
Show answer
Answer: B. SCPs set maximum permissions for every principal in member accounts, including their root users, and can't be overridden from inside the account. A depends on every admin not removing the policy. C detects but doesn't prevent. D detects threats, it doesn't restrict actions.
Q3 — Workforce sign-in
Employees authenticate with the company's existing identity provider. They need console and CLI access to 25 AWS accounts with different permissions per team, with the least administrative effort. Which solution should be used?
- A. Create IAM users in each account and synchronise passwords
- B. AWS IAM Identity Center connected to the identity provider, with permission sets assigned per account
- C. Amazon Cognito user pools with SAML federation
- D. Share the root user credentials of each account with team leads
Show answer
Answer: B. IAM Identity Center provides central workforce access to many accounts with federation and permission sets. A is high effort and insecure. C is for application end users, not AWS account access. D violates every best practice.
Q4 — Encrypting an existing database
An Amazon RDS for MySQL instance was created without encryption. Compliance now requires encryption at rest with a customer managed KMS key, with minimal data loss. What should be done?
- A. Enable encryption on the running instance from the console
- B. Take a snapshot, copy the snapshot with encryption using the customer managed key, restore a new instance from it, then switch the application
- C. Create an encrypted read replica of the unencrypted instance and promote it
- D. Enable S3 default encryption for RDS backups
Show answer
Answer: B. Encryption must be chosen at creation; the supported path is snapshot → encrypted copy → restore. To minimise data loss, stop writes or use DMS replication for the final cutover. A isn't possible. C isn't supported (a replica of an unencrypted instance can't be encrypted). D is unrelated.
Q5 — Protecting a web application
A public web application behind an Application Load Balancer is receiving SQL injection attempts and occasional floods of requests from a few IP addresses. Which solution addresses both with the least operational overhead?
- A. Deploy third-party IDS software on each EC2 instance
- B. Attach AWS WAF to the ALB with SQL injection managed rules and a rate-based rule
- C. Use network ACLs to block every attacker IP manually
- D. Enable Amazon Inspector on the instances
Show answer
Answer: B. WAF managed rules block SQLi patterns, and rate-based rules automatically block IPs exceeding a threshold. A and C are high effort and reactive. D scans for software vulnerabilities; it doesn't block requests.
Q6 — Private admin access
Operations staff need shell access to EC2 instances in private subnets. The security team wants no inbound ports open, no bastion hosts, no SSH keys, and full session logging. What should be used?
- A. A bastion host in a public subnet restricted to office IPs
- B. AWS Systems Manager Session Manager
- C. AWS Client VPN with SSH key distribution
- D. Open port 22 in the security group only during maintenance windows
Show answer
Answer: B. Session Manager needs no inbound ports or keys, is controlled by IAM, and logs sessions to CloudWatch Logs or S3. The other options all involve open ports or key management.
Q7 — Losing orders during spikes
An order service receives orders synchronously from the web tier. During flash sales the order service slows down and orders are lost. Which change best improves resilience?
- A. Increase the instance size of the order service
- B. Place an Amazon SQS queue between the web tier and the order service, and scale order workers on queue depth
- C. Add a second web tier in another Region
- D. Use Amazon SNS to send orders directly to the order service over HTTP
Show answer
Answer: B. The queue durably buffers orders and decouples the tiers; workers scale with the backlog. A raises the ceiling but still loses orders when it's exceeded. C doesn't address the bottleneck. D pushes to an HTTP endpoint that may be overloaded; SNS retries are limited, and there's no buffering.
Q8 — Surviving an AZ failure
A web application runs on a single EC2 instance with a MySQL database on the same instance. It must stay available if an Availability Zone fails, with minimal operational overhead. Which design is best?
- A. Take hourly AMIs and restore them in another AZ when needed
- B. Move the application to an Auto Scaling group across two AZs behind an ALB, and move the database to Amazon RDS Multi-AZ
- C. Use a larger instance with an io2 EBS volume
- D. Run a second instance in another AZ and switch DNS manually
Show answer
Answer: B. It removes both single points of failure with automatic failover and managed services. A and D need manual recovery; C doesn't address AZ failure at all.
Q9 — Choosing a DR strategy
A company's application must recover in another Region within 4 hours, and may lose up to 1 hour of data. Leadership wants the lowest cost. Which strategy fits?
- A. Multi-site active/active
- B. Warm standby with a scaled-down copy always running
- C. Backup and restore: hourly backups copied to the DR Region, infrastructure rebuilt from CloudFormation templates when needed
- D. No DR — rely on Multi-AZ
Show answer
Answer: C. RPO 1 hour and RTO 4 hours are met by hourly cross-Region backups plus automated rebuilds, at the lowest cost. A and B meet the targets but cost more. D doesn't protect against a Region-level event.
Q10 — Global relational database with fast DR
A global e-commerce company needs a relational database with low-latency reads in three continents, and Regional disaster recovery with an RPO of seconds and an RTO of about a minute. Which solution meets these requirements?
- A. RDS for MySQL with cross-Region read replicas
- B. Amazon Aurora Global Database
- C. Amazon DynamoDB global tables
- D. RDS Multi-AZ in the primary Region
Show answer
Answer: B. Aurora Global Database replicates with typical sub-second lag and supports fast promotion of a secondary Region. A can work but promotion is slower and replication lag is higher. C isn't relational. D doesn't cover Regional failure or global reads.
Q11 — Lambda overwhelming the database
A serverless API uses Lambda functions that connect to an Amazon RDS for PostgreSQL database. Under load the database runs out of connections. What should be done with the least code change?
- A. Increase the Lambda timeout
- B. Place Amazon RDS Proxy between Lambda and the database
- C. Replace RDS with DynamoDB
- D. Use reserved concurrency of 1 on all functions
Show answer
Answer: B. RDS Proxy pools and reuses connections; the functions only change their endpoint. A worsens the problem. C is a large redesign. D throttles the API severely.
Q12 — Immutable backups
Auditors require that backups of EC2, RDS and EFS can't be deleted or altered by anyone, including administrators, for 1 year, and that they're kept in a separate account. Which solution meets this?
- A. Manual snapshots with IAM policies denying deletion
- B. AWS Backup with cross-account copies to a vault protected by AWS Backup Vault Lock in compliance mode
- C. S3 versioning on a bucket holding exported backups
- D. Daily scripts that copy snapshots to another Region
Show answer
Answer: B. Vault Lock in compliance mode enforces WORM retention that even root can't override, and AWS Backup handles all three services with cross-account copies. A can be changed by admins. C protects versions but allows deletion by privileged users unless Object Lock is used, and requires custom exports. D is manual and doesn't prevent deletion.