SAA-C01 Exam Details

  • Exam Code
    :SAA-C01
  • Exam Name
    :AWS Certified Solutions Architect - Associate (SAA-C01)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :424 Q&As
  • Last Updated
    :Jun 04, 2025

Amazon SAA-C01 Online Questions & Answers

  • Question 131:

    You are implementing AWS Direct Connect. You intend to use AWS public service end points such as

    Amazon S3, across the AWS Direct Connect link. You want other Internet traffic to use your existing link to an Internet Service Provider. What is the correct way to configure AWS Direct connect for access to services such as Amazon S3?

    A. Configure a public Interface on your AWS Direct Connect link. Configure a static route via your AWS Direct Connect link that points to Amazon S3 Advertise a default route to AWS using BGP.
    B. Create a private interface on your AWS Direct Connect link. Configure a static route via your AWS Direct connect link that points to Amazon S3 Configure specific routes to your network in your VPC,
    C. Create a public interface on your AWS Direct Connect link. Redistribute BGP routes into your existing routing infrastructure advertise specific routes for your network to AWS.
    D. Create a private interface on your AWS Direct connect link. Redistribute BGP routes into your existing routing infrastructure and advertise a default route to AWS.

  • Question 132:

    A Solutions Architect is designing solution with AWS Lambda where different environments require different database passwords. What should the Architect do to accomplish this in a secure and scalable way?

    A. Create a Lambda function for each individual environment.
    B. Use Amazon DynamoDB to store environmental variables.
    C. Use encrypted AWS Lambda environmental variables.
    D. Implement a dedicated Lambda function for distributing variables.

  • Question 133:

    A company is running its application in a single region on Amazon EC2 with Amazon EBS and Amazon S3 part of the storage design. What should be done to reduce data transfer costs?

    A. Create a copy of the compute environment in another region
    B. Convert the application to run on Lambda@Edge
    C. Create an Amazon CloudFront distribution with Amazon S3 as the origin
    D. Replicate Amazon S3 data to buckets in regions closer to the requester

  • Question 134:

    A team is launching a marketing campaign and the peak database read activity in Amazon Aurora for MySQL is expected to increase. A Solutions Architect decides to add two Read Replicas to the cluster. How should the Solutions Architect ensure that the connections for read activities are load balanced?

    A. Reader endpoint for Amazon Aurora
    B. Cluster endpoint for Amazon Aurora
    C. Primary DB instance endpoint for Amazon Aurora
    D. Replica DB instances endpoint for Aurora

  • Question 135:

    A 3-tier e-commerce web application is current deployed on-premises and will be migrated to AWS for greater scalability and elasticity. The web server currently shares read-only data using a network distributed file system The app server tier uses a clustering mechanism for discovery and shared session state that depends on IP multicast The database tier uses shared-storage clustering to provide database fall over capability, and uses several read slaves for scaling Data on all servers and the distributed file system directory is backed up weekly to off-site tapes. Which AWS storage and database architecture meets the requirements of the application?

    A. Web servers: store read-only data in S3, and copy from S3 to root volume at boot time. App servers: share state using a combination of DynamoDB and IP unicast. Database: use RDS with multi- AZ deployment and one or more read replicas. Backup: web servers, app servers, and database backed up weekly to Glacier using snapshots.
    B. Web servers: store read-only data in an EC2 NFS server, mount to each web server at boot time. App servers: share state using a combination of DynamoDB and IP multicast. Database: use RDS with multi-AZ deployment and one or more Read Replicas. Backup: web and app servers backed up weekly via AMIs, database backed up via DB snapshots.
    C. Web servers: store read-only data in S3, and copy from S3 to root volume at boot time. App servers: share state using a combination of DynamoDB and IP unicast. Database: use RDS with multi- AZ deployment and one or more Read Replicas. Backup: web and app servers backed up weekly via AMIs, database backed up via DB snapshots.
    D. Web servers: store read-only data in S3, and copy from S3 to root volume at boot time. App servers: share state using a combination of DynamoDB and IP unicast. Database: use RDS with multi- AZ deployment. Backup: web and app servers backed up weekly via AMIs, database backed up via DB snapshots.

  • Question 136:

    A Solutions Architect is designing a solution that will include a database in Amazon RDS. Corporate security policy mandates that the database, its logs, and its backups are all encrypted. Which is the MOST efficient option to fulfill the security policy using Amazon RDS?

    A. Launch an Amazon RDS instance with encryption enabled. Enable encryption for logs and backups.
    B. Launch an Amazon RDS instance. Enable encryption for database, logs and backups.
    C. Launch an Amazon RDS instance with encryption enabled. Logs and backups are automatically encrypted.
    D. Launch an Amazon RDS instance. Enable encryption for backups. Encrypt logs with a database-engine feature.

  • Question 137:

    A Solutions Architect needs to build a resilient data warehouse using Amazon Redshift. The Architect needs to rebuild the Redshift cluster in another region. Which approach can the Architect take to address this requirement?

    A. Modify the Redshift cluster and configure cross-region snapshots to the other region.
    B. Modify the Redshift cluster to take snapshots of the Amazon EBS volumes each day, sharing those snapshots with the other region.
    C. Modify the Redshift cluster and configure the backup and specify the Amazon S3 bucket in the other region.
    D. Modify the Redshift cluster to use AWS Snowball in export mode with data delivered to the other region.

  • Question 138:

    A company requires operating system permission on a relational database server.

    What should a Solutions Architect suggest as a configuration for a highly available database architecture?

    A. Multiple EC2 instances in a database replication configuration that uses two Availability Zones.
    B. A standalone Amazon EC2 instance with a selected database installed.
    C. Amazon RDS in a Multi-AZ configuration with Provisioned IOPS.
    D. Multiple EC2 instances in a replication configuration that uses two placement groups.

  • Question 139:

    A company has an Amazon RDS-managed online transaction processing system that has very heavy read and write. The Solutions Architect notices throughput issues with the system. How can the responsiveness of the primary database be improved?

    A. Use asynchronous replication for standby to maximize throughput during peak demand.
    B. Offload SELECT queries that can tolerate stale data to READ replica.
    C. Offload SELECT and UPDATE queries to READ replica.
    D. Offload SELECT query that needs the most current data to READ replica.

  • Question 140:

    A solutions Architect is designing a new workload where an AWS Lambda function will access an Amazon DynamoDB table. What is the MOST secure means of granting the Lambda function access to the DynamoDB table?

    A. Create an identity and access management (IAM) role with the necessary permissions to access the DynamoDB table, and assign the role to the Lambda function.
    B. Create a DynamoDB user name and password and give them to the Developer to use in the Lambda function.
    C. Create an identity and access management (IAM) user, and create access and secret keys for the user. Give the user the necessary permissions to access the DynamoDB table. Have the Developer use these keys to access the resources.
    D. Create an identity and access management (IAM) role allowing access from AWS Lambda and assign the role to the DynamoDB table.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SAA-C01 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.