SAA-C02 Exam Details

  • Exam Code
    :SAA-C02
  • Exam Name
    :AWS Certified Solutions Architect - Associate (SAA-C02)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :1080 Q&As
  • Last Updated
    :Jun 04, 2025

Amazon SAA-C02 Online Questions & Answers

  • Question 661:

    A company's database is hosted on an Amazon Aurora MySQL DB cluster in the us-east-1 Region. The database is 4 TB in size. The company needs to expand its disaster recovery strategy to the us-west-2 Region. The company must have the ability to fail over to us-west-2 with a recovery time objective (RTO) of 15 minutes.

    What should a solutions architect recommend to meet these requirements?

    A. Create a Multi-Region Aurora MySQL DB cluster in us-east-1 and use-west-2. Use an Amazon Route 53 health check to monitor us-east-1 and fail over to us-west-2 upon failure.
    B. Take a snapshot of the DB cluster in us-east-1. Configure an Amazon EventBridge (Amazon CloudWatch Events) rule that invokes an AWS Lambda function upon receipt of resource events. Configure the Lambda function to copy the snapshot to us-west-2 and restore the snapshot in us-west- 2 when failure is detected.
    C. Create an AWS CloudFormation script to create another Aurora MySQL DB cluster in us-west-2 in case of failure. Configure an Amazon EventBridge (Amazon CloudWatch Events) rule that invokes an AWS Lambda function upon receipt of resource events. Configure the Lambda function to deploy the AWS CloudFormation stack in us-west-2 when failure is detected.
    D. Recreate the database as an Aurora global database with the primary DB cluster in us-east-1 and a secondary DB cluster in us-west-2. Configure an Amazon EventBridge (Amazon CloudWatch Events) rule that invokes an AWS Lambda function upon receipt of resource events. Configure the Lambda function to promote the DB cluster in us-west-2 when failure is detected.

  • Question 662:

    A company's near-real-time streaming application is running on AWS As (he data is ingested a job runs on the data and takes 30 minutes to complete The workload frequently experiences high latency due to large amounts of incoming data A solutions architect needs to design a scalable and serverless solution to enhance performance

    Which combination of steps should the solutions architect take? (Select TWO)

    A. Use Amazon Kinesis Data Firehose to ingest the data
    B. Use AWS Lambda with AWS Step Functions to process the data
    C. Use AWS Database Migration Service (AWS DMS) to ingest the data
    D. Use Amazon EC2 instances in an Auto Scaling group to process the data
    E. Use AWS Fargate with Amazon Elastic Container Service (Amazon ECS) to process the data.

  • Question 663:

    A company is building a mobile app on AWS. The company wants to expand its reach to millions of users The company needs to build a platform so that authorized users can watch the company's content on their mobile devices

    What should a solutions architect recommend to meet these requirements?

    A. Publish content to a public Amazon S3 bucket. Use AWS Key Management Service (AWS KMS) keys to stream content.
    B. Set up IPsec VPN between the mobile app and the AWS environment to stream content
    C. Use Amazon CloudFront Provide signed URLs to stream content.
    D. Set up AWS Client VPN between the mobile app and the AWS environment to stream content.

  • Question 664:

    A company is building a payment application that must be highly available even during regional service disruptions A solutions architect must design a data storage solution that can be easily replicated and used in other AWS Regions. The application also requires low-latency atomicity, consistency, isolation, and durability (ACID) transactions that need to be immediately available to generate reports The development team also needs to use SQL. Which data storage solution meets these requirements'?

    A. Amazon Aurora Global Database
    B. Amazon DynamoDB global tables
    C. Amazon S3 with cross-Region replication and Amazon Athena
    D. MySQL on Amazon EC2 instances with Amazon Elastic Block Store (Amazon EBS) snapshot replication

  • Question 665:

    A company recently launched a variety of new workloads on Amazon EC2 instances in its AWS account. The company needs to create a strategy to access and administer the instances remotely and securely. The company needs to implement a repeatable process that works with native AWS services and follows the AWS WellArchitected Framework.

    Which solution will meet these requirements with the LEAST operational overhead?

    A. Use the EC2 serial console to directly access the terminal interface of each instance for administration.
    B. Attach the appropriate 1AM role to each existing instance and new instance. Use AWS Systems Manager Session Manager to establish a remote SSH session.
    C. Create an administrative SSH key pair. Load the public key into each EC2 instance. Deploy a bastion host in a public subnet to provide a tunnel for administration of each instance.
    D. Establish an AWS Site-to-Site VPN connection. Instruct administrators to use their local on-premises machines to connect directly to the instances by using SSH keys across the VPN tunnel.

  • Question 666:

    A company collects 10 GB of telemetry data dairy from various machines. The company stores the data in an Amazon S3 bucket in a source data account.

    The company has hired several consuming agencies to use this data for analysis. Each agency needs read access to the data for its analysis. The company must share the data from tie source data account by choosing a solution that maximizes security and operational efficiency. Which solution will meet these requirements?

    A. Configure S3 global tables to replicate data tor each agency
    B. Make the S3 bucket public for a limited time Inform only the agencies
    C. Configure cross-account access for the S3 bucket to the accounts that the agencies own.
    D. Set up an IAM user for each analyst In the source data account Grant each user access to the S3 bucket

  • Question 667:

    A company plans to store sensitive user data on Amazon S3. Internal security compliance requirement mandata encryption of data before sending it to Amazon S3. What should a solution architect recommend to satisfy these requirements?

    A. Server-side encryption with customer-provided encryption keys
    B. Client-side encryption with Amazon S3 managed encryption keys
    C. Server-side encryption with keys stored in AWS key Management Service (AWS KMS)
    D. Client-side encryption with a master key stored in AWS Key Management Service (AWS KMS)

  • Question 668:

    A company has thousands of edge devices that collectively generate 1 TB of status alerts each day Each alert is approximately 2 KB in size A solutions architect needs to implement a solution to ingest and store the alerts for future analysis. The company wants a highly available solution However the company needs to minimize costs and does not want to manage additional infrastructure Additionally, the company wants to keep 14 days of data available for immediate analysis and archive any data older than 14 days What is the MOST operationally efficient solution that meets these requirements?

    A. Create an Amazon Kinesis Data Firehose delivery stream to ingest the alerts Configure the Kinesis Data Firehose stream to deliver the alerts to an Amazon S3 bucket Set up an S3 LifecycJe configuration to transition data to Amazon S3 Glacier after 14 days
    B. Launch Amazon EC2 instances across two Availability Zones and place them behind an Elastic Load Balancer to ingest the alerts Create a script on the EC2 instances that will store the alerts in an Amazon S3 bucket Set up an S3 Lifecycle configuration to transition data to Amazon S3 Glacier after 14 days
    C. Create an Amazon Kinesis Data Firehose delivery stream to ingest the alerts Configure the Kinesis Data Firehose stream to deliver the alerts to an Amazon Elasticsearch Service (Amazon ES) cluster Set up the Amazon ES cluster to take manual snapshots every day and delete data from the cluster that is older than 14 days
    D. Create an Amazon Simple Queue Service (Amazon SQS) standard queue to ingest the alerts and set the message retention penod to 14 days Configure consumers to poll the SQS queue check the age of the message and analyze the message data as needed if the message is 14 days old, the consumer should copy the message to an Amazon S3 bucket and delete the message from the SQS queue

  • Question 669:

    A company sells ringtones created from clips of popular songs. The files containing the ringtones are stored in Amazon S3 Standard and are at least 123 KB m size The company has millions of files but downloads are infrequent for ringtones older than 90 days The company needs to save money on storage while keeping the most accessed files readily available for its users. Which action should the company take to meet these requirements MOST cost-effectively?

    A. Configure S3 Standard-infrequent Access (S3 Standard-IA) storage for the initial storage tier of the objects
    B. Move the files to S3 Intelligent-Tiering and configure it to move objects to a less expensive storage tier after 90 days
    C. Configure S3 inventory to manage objects and move them to S3 Standard-infrequent Access (S3 Standard-IA) after 90 days
    D. Implement an S3 Lifecycle policy that moves the objects from S3 Standard to S3 Standard- Infrequent Access (S3 Standard-IA) after 90 days

  • Question 670:

    A company has an application running as a service in Amazon Elastic Container Service (Amazon EC2) using the Amazon launch type. The application code makes AWS API calls to publish messages to Amazon Simple Queue Service

    (Amazon SQS).

    What is the MOST secure method of giving the application permission to publish messages to Amazon SQS?

    A. Use AWS identity and Access Management (IAM) to grant SQS permissions to the role used by the launch configuration for the Auto Scaling group of the ECS cluster.
    B. Create a new IAM user with SQS permissions. The update the task definition to declare the access key ID and secrect access key as environment variables.
    C. Create a new IAM role with SQS permissions. The update the task definition to use this role for the task role setting.
    D. Update the security group used by the ECS cluster to allow access to Amazon SQS

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SAA-C02 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.