SAA-C01 Exam Details

  • Exam Code
    :SAA-C01
  • Exam Name
    :AWS Certified Solutions Architect - Associate (SAA-C01)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :424 Q&As
  • Last Updated
    :Jun 04, 2025

Amazon SAA-C01 Online Questions & Answers

  • Question 111:

    A three-tier application is being created to host small news articles. The application is expected to serve millions of users. When breaking news occurs, the site must handle very large spikes in traffic without significantly impacting database performance.

    Which design meets these requirements while minimizing costs?

    A. Use Auto Scaling groups to increase the number of Amazon EC2 instances delivering the web application
    B. Use Auto Scaling groups to increase the size of the Amazon RDS instances delivering the database
    C. Use Amazon DynamoDB strongly consistent reads to adjust for the increase in traffic
    D. Use Amazon DynamoDB Accelerator (DAX) to cache read operations to the database

  • Question 112:

    A company wants to improve latency by hosting images within a public Amazon S3 bucket fronted by an Amazon CloudFront distribution. The company wants to restrict access to the S3 bucket to include the CloudFront distribution only, while also allowing CloudFront to continue proper functionality.

    What should be done after making the bucket private to restrict access with the LEAST operational overhead?

    A. Create a CloudFront origin access identity and create a security group that allows access from CloudFront.
    B. Create a CloudFront origin access identity and update the bucket policy to grant access to it.
    C. Create a bucket policy restricting all access to the bucket to include CloudFront IPs only.
    D. Enable the CloudFront option to restrict viewer access and update the bucket policy to allow the distribution.

  • Question 113:

    An application running in a private subnet accesses an Amazon DynamoDB table. There is a security requirement that the data never leave the AWS network. How should this requirement be met?

    A. Configure a network ACL on DynamoDB to limit traffic to the private subnet
    B. Enable DynamoDB encryption at rest using an AWS KMS key
    C. Add a NAT gateway and configure the route table on the private subnet
    D. Create a VPC endpoint for DynamoDB and configure the endpoint policy

  • Question 114:

    A Solutions Architect is designing a microservice to process records from Amazon Kinesis Streams. The metadata must be stored in Amazon DynamoDB. The microservice must be capable of concurrently processing 10,000 records daily as they arrive in the Kinesis stream.

    The MOST scalable way to design the microservice is:

    A. As an AWS Lambda function.
    B. As a process on an Amazon EC2 instance.
    C. As a Docker container running on Amazon ECS.
    D. As a Docker container on an EC2 instance.

  • Question 115:

    A corporate web application is deployed within an Amazon Virtual Private Cloud (VPC) and is connected to the corporate data center via an iPsec VPN. The application must authenticate against the on-premises LDAP server. After authentication, each logged-in user can only access an Amazon Simple Storage Space (S3) keyspace specific to that user.

    Which two approaches can satisfy these objectives? (Choose two.)

    A. Develop an identity broker that authenticates against IAM security Token service to assume a IAM role in order to get temporary AWS security credentials The application calls the identity broker to get AWS temporary security credentials with access to the appropriate S3 bucket.
    B. The application authenticates against LDAP and retrieves the name of an IAM role associated with the user. The application then calls the IAM Security Token Service to assume that IAM role. The application can use the temporary credentials to access the appropriate S3 bucket.
    C. Develop an identity broker that authenticates against LDAP and then calls IAM Security Token Service to get IAM federated user credentials. The application calls the identity broker to get IAM federated user credentials with access to the appropriate S3 bucket.
    D. The application authenticates against LDAP the application, then calls the AWS identity and Access Management (IAM) Security service to log in to IAM using the LDAP credentials, the application can use the IAM temporary credentials to access the appropriate S3 bucket.
    E. The application authenticates against IAM Security Token Service using the LDAP credentials, the application uses those temporary AWS security credentials to access the appropriate S3 bucket.

  • Question 116:

    A company is designing a new application to collect data on user behavior for analysis at a later time. Amazon Kinesis Data Streams will be used to receive user interaction events. What should be done to ensure the event data is retained indefinitely?

    A. Configure the stream to write records to an attached Amazon EBS volume.
    B. Configure an Amazon Kinesis Data Firehose delivery stream to store data on Amazon S3.
    C. Configure the stream data retention period to retain the data indefinitely.
    D. Configure an Amazon EC2 consumer to read from the data stream and store records in Amazon SQS.

  • Question 117:

    An on-premises database is experiencing significant performance problems when running SQL queries. With 10 users, the lookups are performing as expected. As the number of users increases, the lookups take three times longer than expected to return values to an application.

    Which action should a Solutions Architect take to maintain performance as the user count increases?

    A. Use Amazon SQS.
    B. Deploy Multi-AZ RDS MySQL
    C. Configure Amazon RDS with additional read replicas.
    D. Migrate from MySQL to RDS Microsoft SQL Server.

  • Question 118:

    A Solutions Architect is designing a public-facing web application for employees to upload images to their social media account. The application consists of multiple Amazon EC2 instances behind an elastic load balancer, an Amazon S3 bucket where uploaded images are stored, and an Amazon DynamoDB table for storing image metadata.

    Which AWS service can the Architect use to automate the process of updating metadata in the DynamoDB table upon image upload?

    A. Amazon CloudWatch
    B. AWS CloudFormation
    C. AWS Lambda
    D. Amazon SQS

  • Question 119:

    A Solutions Architect is designing a multicontainer-based web application. Parts of the web application, /orders and /sale-event, must scale independently while maintaining a single Fully Qualified Domain Name. Which AWS services will help the Architect build this platform? (Select TWO.)

    A. Amazon ELB Application Load Balancer
    B. Amazon ELB Classic Load Balancer
    C. Amazon EC2 Container Service
    D. Amazon DynamoDB
    E. Amazon SQS

  • Question 120:

    A web application experiences high compute costs due to serving a high amount of static web content. How should the web server architecture be designed to be the MOST cost-efficient?

    A. Create an Auto Scaling group to scale out based on average CPU usage.
    B. Create an Amazon CloudFront distribution to pull static content from an Amazon S3 bucket.
    C. Leverage Reserved Instances to add additional capacity at a significantly lower price.
    D. Create a multi-region deployment using an Amazon Route 53 geolocation routing policy.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SAA-C01 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.