SAP-C02 Sample Questions & Answers
Building new solutions that keep the business running carries the top share, just ahead of network connectivity and security controls across complex organizations, improving existing operations and performance, and planning workload migration and modernization.
Launch the full SAP-C02 simulator →Showing 9 of 19 free samples.
- Question 1Intermediate
Continuous Improvement for Existing Solutions · Determine a strategy to improve performance
An e-commerce company's primary application runs on Amazon EC2 instances within an Auto Scaling group and uses an Amazon RDS for MySQL Multi-AZ database. During a recent peak sales event, the RDS instance's CPU utilization reached 100%, causing significant latency and transaction failures. The preliminary analysis shows that 80% of the database operations are read queries from the product catalog. The company needs to improve the application's performance and reliability, especially during traffic spikes, while minimizing changes to the application code. What is the MOST effective solution?
Show answer & explanation
Correct answer: D
Given that 80% of the load is from read-heavy product catalog queries, implementing a caching layer is the most effective strategy. Amazon ElastiCache for Redis provides an in-memory data store with sub-millisecond latency. By caching frequently accessed data, the application can significantly reduce the read load on the primary RDS database, freeing up its CPU for write operations. This directly addresses the root cause of the performance bottleneck and is more effective than just scaling the database, which may still become a bottleneck under extreme load.
- Question 2Intermediate
Design for New Solutions · Design a solution to ensure business continuity
A manufacturing firm is migrating its on-premises SAP S/4HANA environment to AWS. The production environment is business-critical and has a very low tolerance for downtime. The Recovery Time Objective (RTO) is 15 minutes, and the Recovery Point Objective (RPO) is 5 minutes. The firm needs a disaster recovery (DR) solution that enables failover to a different AWS Region. The solution must be cost-effective during normal operations. Which DR strategy should the solutions architect recommend?
Show answer & explanation
Correct answer: D
AWS Elastic Disaster Recovery (DRS) is specifically designed for this use case. It provides low-RPO, low-RTO disaster recovery at a minimal cost. DRS continuously replicates block-level data to a lightweight staging area in the target Region. This keeps costs low because full-size recovery instances are not running. During a DR event, DRS automates the process of launching recovery instances, allowing the environment to be brought online within minutes, thus meeting the strict RTO and RPO requirements in a cost-effective manner. This is more cost-effective than Warm Standby and faster than Backup and Restore.
- Question 3Intermediate
Design Solutions for Organizational Complexity · Architect network connectivity strategies
A company has a hybrid cloud setup with an on-premises data center connected to an AWS VPC via AWS Direct Connect. An application running on-premises needs to privately and securely upload large data files directly into an Amazon S3 bucket. The company's security policy prohibits any data from traversing the public internet. Which configuration will allow the on-premises application to access the S3 bucket while adhering to the security policy?
Show answer & explanation
Correct answer: C
This is the correct solution for private S3 access from on-premises over Direct Connect. A gateway VPC endpoint for S3 is only accessible from within the VPC itself, not from an on-premises network. An interface VPC endpoint for S3, however, places an Elastic Network Interface (ENI) with a private IP address inside your VPC. This ENI can be reached from your on-premises network over a Direct Connect private VIF. By configuring DNS appropriately, the on-premises application can resolve the S3 endpoint to this private IP, ensuring all traffic stays on the private network path.
- Question 4Beginner
Design Solutions for Organizational Complexity · Prescribe security controls
True or False: When using AWS Organizations, a Service Control Policy (SCP) that explicitly denies an action (e.g.,
ec2:RunInstances) in an Organizational Unit (OU) can be overridden by an IAM policy attached to a user within an account in that OU that explicitly allows the same action.Show answer & explanation
Correct answer: B
This is false. In AWS Organizations, SCPs act as guardrails and define the maximum permissions available to an account. An explicit deny in an SCP always takes precedence over any allow in an IAM policy. If an SCP denies an action, no principal in the affected account can perform that action, regardless of their IAM permissions. The effective permissions are the intersection of what the SCP allows and what the IAM policy allows.
- Question 5AdvancedSelect 4
Design Solutions for Organizational Complexity · Design a multi-account AWS environment
A solutions architect is designing a centralized logging solution for a large enterprise with hundreds of AWS accounts managed under AWS Organizations. The requirements are:
- All AWS CloudTrail logs from all member accounts must be aggregated into a central Amazon S3 bucket in a dedicated 'Log Archive' account.
- The solution should automatically enforce this configuration for any new accounts added to the organization.
- Member accounts must not be able to disable or modify their CloudTrail configuration.
- The central security team needs to query these logs using Amazon Athena from a separate 'Audit' account.
Arrange the following steps in the correct order to implement this solution.
Show answer & explanation
Correct answers: A, B, C, D
This must be the first step. Creating an organization trail from the management account is the feature that automatically enables CloudTrail on all member accounts (including new ones) and configures them to send logs to the central bucket.
This step is a prerequisite for creating the organization trail. The destination S3 bucket must exist and have the correct permissions to accept logs from the entire organization.
This step ensures that member accounts cannot tamper with the logging configuration, fulfilling a key security requirement.
This final step enables the cross-account query capability for the security team, completing the solution. The correct order is: Create and configure the bucket -> Create the organization trail -> Apply SCPs for enforcement -> Grant cross-account read access for auditing.
- Question 6Advanced
Design for New Solutions · Determine security controls based on requirements
A company is deploying a containerized application on Amazon EKS. The application consists of multiple microservices that need to communicate with each other within the cluster. For compliance reasons, all network traffic between pods must be logged and inspected. Additionally, the company wants to implement fine-grained network policies to restrict communication, for example, allowing the 'frontend' pods to talk to the 'backend' pods on a specific port, but not vice-versa. The solution should integrate natively with Kubernetes and provide rich observability features like a service map. Which combination of services and tools should be used?
Show answer & explanation
Correct answer: C
AWS App Mesh is a service mesh that provides application-level networking, making it easy to manage microservice communications. It uses Envoy proxies to handle all traffic, providing a perfect point for logging, inspection, and policy enforcement. App Mesh allows for fine-grained traffic control (e.g., routing, retries) and integrates with AWS services like CloudWatch and X-Ray for deep observability, including service maps. This solution meets all requirements for traffic logging, fine-grained policy enforcement, and native Kubernetes integration with rich observability.
- Question 7Intermediate
Continuous Improvement for Existing Solutions · Determine a strategy to improve performance
A data analytics team is experiencing performance issues with their Amazon Redshift cluster. The cluster is used for both short, interactive queries from BI dashboards and long-running, complex ETL jobs that run overnight. During business hours, the dashboard queries are often queued behind the ETL jobs, leading to slow dashboard load times. The team needs a solution to prioritize the short, interactive queries during the day without creating and managing a separate cluster. Which Amazon Redshift feature should be implemented?
Show answer & explanation
Correct answer: B
Workload Management (WLM) is the Redshift feature designed specifically for managing and prioritizing different types of queries. By creating separate queues for BI users and ETL jobs, you can allocate resources and set priorities independently. Short Query Acceleration (SQA) is a key part of WLM that uses machine learning to identify short-running queries and move them to a dedicated queue, allowing them to bypass longer-running queries. This directly solves the problem of dashboard queries getting stuck behind ETL jobs.
- Question 8Intermediate
Continuous Improvement for Existing Solutions · Determine a strategy to improve performance
A global logistics company uses a central Amazon S3 bucket to store shipping manifests. These manifests are generated by applications in multiple AWS Regions (
ap-northeast-1,eu-central-1,us-west-2) and must be uploaded to a single S3 bucket located inus-east-1for centralized processing. Due to the large distances, uploads from the remote Regions are slow and occasionally fail. The company needs a solution to accelerate the uploads and improve reliability without changing the application logic that writes to the standard S3 endpoint. What should the solutions architect configure?Show answer & explanation
Correct answer: D
Amazon S3 Transfer Acceleration is the ideal service for this scenario. It uses the globally distributed AWS edge locations to accelerate uploads to S3 over long distances. Once enabled on the bucket, you must change the application endpoint to the special
[bucket-name].s3-accelerate.amazonaws.comendpoint. Data is then ingested at a nearby edge location and travels over the optimized AWS global network to the S3 bucket. This improves speed and reliability for geographically dispersed uploads. While the prompt asks for no change to the logic, changing an endpoint is a configuration change, not a logic change, and is the required step to use the feature. - Question 9Intermediate
Accelerate Workload Migration and Modernization · Determine opportunities for modernization and enhancements
A financial institution is migrating a legacy monolithic application to a microservices architecture on AWS. They have chosen to use AWS Lambda for the compute layer. During the migration, both the old monolith (running on EC2) and the new Lambda-based microservices need to coexist and share data from a central Amazon RDS for PostgreSQL database. A critical requirement is to prevent the new, potentially buggy or inefficient Lambda functions from overwhelming the database with too many connections, which could impact the stability of the legacy application. Which solution provides the most reliable connection management for the Lambda functions?
Show answer & explanation
Correct answer: D
Amazon RDS Proxy is a fully managed, highly available database proxy that is specifically designed to solve this problem. It establishes and maintains a pool of connections to the RDS database and serves connection requests from the Lambda functions from this pool. This allows thousands of Lambda executions to share a much smaller number of database connections, preventing the database from being exhausted. It also improves resilience by gracefully handling database failovers. This is the most robust and manageable solution for serverless applications connecting to relational databases.
Ready for the real thing?
The full SAP-C02 simulator has every exam-style question, timed mode, and instant scoring.