SAP-C02 Exam Details

  • Exam Code
    :SAP-C02
  • Exam Name
    :AWS Certified Solutions Architect - Professional (SAP-C02)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :874 Q&As
  • Last Updated
    :Jul 12, 2026

Amazon SAP-C02 Online Questions & Answers

  • Question 131:

    A company runs applications in hundreds of production AWS accounts. The company uses AWS Organizations with all features enabled and has a centralized backup operation that uses AWS Backup.

    The company is concerned about ransomware attacks. To address this concern, the company has created a new policy that all backups must be resilient to breaches of privileged-user credentials in any production account.

    Which combination of steps will meet this new requirement? (Select THREE.)

    A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts.
    B. Add an SCP that restricts the modification of AWS Backup vaults.
    C. Implement AWS Backup Vault Lock in compliance mode.
    D. Configure the backup frequency, lifecycle, and retention period to ensure that at least one backup always exists in the cold tier.
    E. Configure AWS Backup to write all backups to an Amazon S3 bucket in a designated non-production account. Ensure that the S3 bucket has S3 Object Lock enabled.
    F. Implement least privilege access for the IAM service role that is assigned to AWS Backup.

  • Question 132:

    A company is planning a large event where a promotional offer will be introduced.

    The company's website is hosted on AWS and backed by an Amazon RDS for PostgreSQL DB instance.

    The website explains the promotion and includes a sign-up page that collects user information and preferences Management expects large and unpredictable volumes of traffic periodically which will create many database writes A solutions architect needs to build a solution that does not change the underlying data model and ensures that submissions are not dropped before they are committed to the database.

    Which solutions meets these requirements'?

    A. Immediately before the event, scale up the existing DB instance to meet the anticipated demand. Then scale down after the event
    B. Use Amazon SQS to decouple the application and database layers Configure an AWS Lambda function to write items from the queue into the database
    C. Migrate to Amazon DynamoDB and manage throughput capacity with automatic scaling
    D. Use Amazon ElastiCache for Memcached to increase write capacity to the DB instance

  • Question 133:

    A company wants to migrate its website from an on-premises data center onto AWS At the same time it wants to migrate the website to a containerized microservice-based architecture to improve the availability and cost efficiency.

    The company's security policy states that privileges and network permissions must be configured according to best practice, using least privilege

    A solutions architect must create a containerized architecture that meets the security requirements and has deployed the application to an Amazon ECS cluster.

    What steps are required after the deployment to meet the requirements? (Select TWO.)

    A. Create tasks using the bridge network mode
    B. Create tasks using the awsvpc network mode
    C. Apply security groups to Amazon EC2 instances and use IAM roles for EC2 instances to access other resources
    D. Apply security groups to the tasks, and pass IAM credentials into the container at launch time to access other resources
    E. Apply security groups to the tasks; and use IAM roles for tasks to access other resources

  • Question 134:

    A company runs a web application on AWS. The web application delivers static content from an Amazon

    S3 bucket that is behind an Amazon CloudFront distribution. The application serves dynamic content by using an Application Load Balancer (ALB) that distributes requests to a fleet of Amazon EC2 instances in Auto Scaling groups. The application uses a domain name setup in Amazon Route 53.

    Some users reported occasional issues when the users attempted to access the website during peak hours. An operations team found that the ALB sometimes returned HTTP 503 Service Unavailable errors.

    The company wants to display a custom error message page when these errors occur. The page should be displayed immediately for this error code.

    Which solution will meet these requirements with the LEAST operational overhead?

    A. Set up a Route 53 failover routing policy. Configure a health check to determine the status of the ALB endpoint and to fail over to the failover S3 bucket endpoint.
    B. Create a second CloudFront distribution and an S3 static website to host the custom error page. Set up a Route 53 failover routing policy. Use an active-passive configuration between the two distributions.
    C. Create a CloudFront origin group that has two origins. Set the ALB endpoint as the primary origin. For the secondary origin, set an S3 bucket that is configured to host a static website Set up origin failover for the CloudFront distribution. Update the S3 static website to incorporate the custom error page.
    D. Create a CloudFront function that validates each HTTP response code that the ALB returns. Create an S3 static website in an S3 bucket. Upload the custom error page to the S3 bucket as a failover. Update the function to read the S3 bucket and to serve the error page to the end users.

  • Question 135:

    A company has a data lake in Amazon S3 that needs to be accessed by hundreds of applications across many AWS accounts. The company's information security policy states that the S3 bucket must not be accessed over the public internet and that each application should have the minimum permissions necessary to function.

    To meet these requirements, a solutions architect plans to use an S3 access point that is restricted to specific VPCs tor each application.

    Which combination of steps should the solutions architect take to implement this solution? (Select TWO.)

    A. Create an S3 access point for each application in the AWS account that owns the S3 bucket. Configure each access point to be accessible only from the application's VPC. Update the bucket policy to require access from an access point.
    B. Create an interface endpoint for Amazon S3 in each application's VPC. Configure the endpoint policy to allow access to an S3 access point. Create a VPC gateway attachment for the S3 endpoint.
    C. Create a gateway endpoint lor Amazon S3 in each application's VPC. Configure the endpoint policy to allow access to an S3 access point. Specify the route table that is used to access the access point.
    D. Create an S3 access point for each application in each AWS account and attach the access points to the S3 bucket. Configure each access point to be accessible only from the application's VPC. Update the bucket policy to require access from an access point.
    E. Create a gateway endpoint for Amazon S3 in the data lake's VPC. Attach an endpoint policy to allow access to the S3 bucket. Specify the route table that is used to access the bucket.

  • Question 136:

    A company is planning to migrate its on-premises VMware cluster of 120 VMS to AWS. The VMS have many different operating systems and many custom software packages installed. The company also has an on-premises NFS server that is 10 TB in size. The company has set up a 10 GbpsAWS Direct Connect connection to AWS for the migration.

    Which solution will complete the migration to AWS in the LEAST amount of time?

    A. Export the on-premises VMS and copy them to an Amazon S3 bucket. Use VM Import/Export to create AMIS from the VM images that are stored in Amazon S3. Order an AWS Snowball Edge device. Copy the NFS server data to the device. Restore the NFS server data to an Amazon EC2 instance that has NFS configured.
    B. Configure AWS Application Migration Service with a connection to the VMware cluster. Create a replication job for the VMS. Create an Amazon Elastic File System (Amazon EFS) file system. Configure AWS DataSync to copy the NFS server data to the EFS file system over the Direct Connect connection.
    C. Recreate the VMS on AWS as Amazon EC2 instances. Install all the required software packages. Create an Amazon FSx for Lustre file system. Configure AWS DataSync to copy the NFS server data to the FSx for Lustre file system over the Direct Connect connection.
    D. Order two AWS Snowball Edge devices. Copy the VMS and the NFS server data to the devices. Run VM Import/Export after the data from the devices is loaded to an Amazon S3 bucket. Create an Amazon Elastic File System (Amazon EFS) file system. Copy the NFS server data from Amazon S3 to the EFS file system.

  • Question 137:

    A solutions architect needs to implement a client-side encryption mechanism for objects that will be stored in a new Amazon S3 bucket. The solutions architect created a CMK that is stored in AWS Key Management Service (AWS KMS) for this purpose.

    The solutions architect created the following IAM policy and attached it to an IAM role:

    During tests, me solutions architect was able to successfully get existing test objects m the S3 bucket.

    However, attempts to upload a new object resulted in an error message. The error message stated that me action was forbidden.

    Which action must me solutions architect add to the IAM policy to meet all the requirements?

    A. Kms:GenerateDataKey
    B. KmsGetKeyPolpcy
    C. kmsGetPubKKey
    D. kms:SKjn

  • Question 138:

    A global company operates a platform that serves customers across multiple AWS Regions. The platform stores customer behavioral data. For data residency compliance, the company must ensure that personally identifiable information (PII) data remains within the Region where the data is collected.

    Additionally, the company must ensure that cross-Region data analysis uses only anonymized datasets.

    Which solution will meet these requirements?

    A. Deploy AWS Outposts in each Region to keep data on premises. Store data in Amazon S3 on Outposts. Use AWS Glue DataBrew to anonymize PII data. Analyze cross-Region data by using Amazon Athena.
    B. Deploy Amazon Aurora PostgreSQL clusters in separate Regions. Use AWS Glue DataBrew to anonymize PII data. Analyze cross-Region data by using Amazon Redshift Serverless.
    C. Deploy Amazon Aurora PostgreSQL clusters in separate Regions. Use AWS Lambda functions to anonymize PII data before replication. Use AWS PrivateLink to connect Amazon QuickSight to cross-Region databases for analysis.
    D. Deploy Amazon S3 buckets in each Region. Enable S3 Block Public Access and bucket policies to prevent cross-Region replication. Use Amazon Macie to anonymize data. Analyze cross-Region data by using Amazon Athena.

  • Question 139:

    A company deploys workloads in multiple AWS accounts. Each account has a VPC with VPC flow logs published in text log format to a centralized Amazon S3 bucket. Each log file is compressed with gzip compression. The company must retain the log files indefinitely.

    A security engineer occasionally analyzes the logs by using Amazon Athena to query the VPC flow logs.

    The query performance is degrading over time as the number of ingested logs is growing. A solutions architect must improve the performance of the log analysis and reduce the storage space that the VPC flow logs use.

    Which solution will meet these requirements with the LARGEST performance improvement?

    A. Create an AWS Lambda function to decompress the gzip files and to compress the files with bzip2 compression. Subscribe the Lambda function to an s3:ObjectCreated:Put S3 event notification for the S3 bucket.
    B. Enable S3 Transfer Acceleration for the S3 bucket. Create an S3 Lifecycle configuration to move files to the S3 Intelligent-Tiering storage class as soon as the files are uploaded.
    C. Update the VPC flow log configuration to store the files in Apache Parquet format. Specify hourly partitions for the log files.
    D. Create a new Athena workgroup without data usage control limits. Use Athena engine version 2.

  • Question 140:

    A video streaming company recently launched a mobile app for video sharing. The app uploads various files to an Amazon S3 bucket in the us-east-1 Region. The files range in size from 1 GB to 10 GB.

    Users who access the app from Australia have experienced uploads that take long periods of time Sometimes the files fail to completely upload for these users .

    A solutions architect must improve the app' performance for these uploads Which solutions will meet these requirements? (Select TWO.)

    A. Enable S3 Transfer Acceleration on the S3 bucket Configure the app to use the Transfer Acceleration endpoint for uploads
    B. Configure an S3 bucket in each Region to receive the uploads. Use S3 Cross-Region Replication to copy the files to the distribution S3 bucket.
    C. Set up Amazon Route 53 with latency-based routing to route the uploads to the nearest S3 bucket Region.
    D. Configure the app to break the video files into chunks Use a multipart upload to transfer files to Amazon S3.
    E. Modify the app to add random prefixes to the files before uploading

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SAP-C02 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.