AWS Solutions Architect Associate sample questions with answers
10 free AWS Solutions Architect Associate sample questions across the exam's domains, each with its answer and an explanation. No account needed.
AWS Solutions Architect Associate sample questions
AWS Certified Solutions Architect – Associate, Amazon Web Services (AWS).
Question 1
Domain: Design Secure Architectures
A regulated company must ensure that no one in any of its member accounts can launch EC2 instances outside the eu-west-1 and eu-central-1 Regions, even if an account administrator writes a permissive IAM policy.
Which policy type should the architect use to prevent this action across all member accounts, regardless of the IAM permissions granted inside them?
- A permissions boundary attached to the management account's root user
- An IAM identity-based policy attached to every administrator user
- An S3 bucket policy with an aws:RequestedRegion condition that is attached to the logging bucket in each member account
- A service control policy on the organization root that denies ec2:RunInstances outside the approved Regions
Show the answer
Answer: D. A service control policy on the organization root that denies ec2:RunInstances outside the approved Regions
An SCP with a Deny statement and an aws:RequestedRegion condition applies to every principal in the affected accounts, including their administrators, because SCPs bound what IAM policies can grant. Identity policies can be edited by account administrators, and permissions boundaries cannot be applied to the root user.
Checked against: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html
Question 2
Domain: Design Secure Architectures
An audit found that some clients access an S3 bucket over plain HTTP. The security team wants to reject any request that is not made over TLS.
How can the team enforce encryption in transit for the bucket?
- Add a bucket policy that denies all actions when the aws:SecureTransport condition key is false
- Turn on S3 Block Public Access for the bucket and the account so that anonymous requests are rejected
- Change the default encryption to SSE-KMS
- Enable S3 Versioning on the bucket
Show the answer
Answer: A. Add a bucket policy that denies all actions when the aws:SecureTransport condition key is false
The aws:SecureTransport global condition key is true for requests sent over HTTPS, so a bucket policy Deny statement with "Bool": {"aws:SecureTransport": "false"} rejects any plaintext HTTP request. Default encryption and versioning protect data at rest and against overwrites, not the transport.
Checked against: https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html
Question 3
Domain: Design Secure Architectures
EC2 instances in private subnets must upload logs to an S3 bucket. Compliance rules forbid any path to the public internet from these subnets.
How can the architect route traffic from the private instances to S3 without a NAT gateway or public IPs?
- Attach an internet gateway to the private subnet only
- Create a gateway endpoint for S3 and add it to the private subnets' route tables
- Assign an Elastic IP address to each instance and restrict the security group outbound rules to the S3 prefix list
- Create a VPC peering connection to the S3 service VPC
Show the answer
Answer: B. Create a gateway endpoint for S3 and add it to the private subnets' route tables
A gateway endpoint for S3 adds a route (prefix list target) to the selected route tables so that S3 traffic stays on the AWS network with no internet gateway, NAT device or public address, and it can be combined with an endpoint policy and bucket policy conditions to restrict access. S3 is not reachable by VPC peering.
Checked against: https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-endpoints-s3.html
Question 4
Domain: Design Resilient Architectures
Which statement about Amazon SQS FIFO queues is correct?
- They have unlimited throughput like standard queues
- They provide best-effort ordering and at-least-once delivery, and they support nearly unlimited throughput per API action
- They preserve the exact order within a message group and provide exactly-once processing with deduplication
- They cannot be used with dead-letter queues
Show the answer
Answer: C. They preserve the exact order within a message group and provide exactly-once processing with deduplication
FIFO queues guarantee that messages within the same message group are delivered in the order they were sent and that duplicates are not introduced (5-minute deduplication interval); standard queues offer best-effort ordering, at-least-once delivery and nearly unlimited throughput. FIFO queues support dead-letter queues (which must also be FIFO).
Checked against: https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-fifo-queues.html
Question 5
Domain: Design Resilient Architectures
A content management system runs on EC2 instances in three Availability Zones. All instances must read and write the same set of uploaded files with POSIX semantics, and the data must survive the loss of an AZ.
Which storage service meets the requirement?
- Amazon EFS, a Regional NFS file system mounted by instances in all Availability Zones
- Instance store volumes on each node, with rsync jobs that replicate the uploaded files between the three AZs
- Amazon EBS io2 volumes with Multi-Attach
- Amazon S3 mounted through the AWS CLI
Show the answer
Answer: A. Amazon EFS, a Regional NFS file system mounted by instances in all Availability Zones
Amazon EFS provides a shared, elastic NFS file system that instances in multiple AZs mount concurrently and that stores data redundantly across AZs (Regional file systems). EBS Multi-Attach is limited to a single AZ and specific volume types, and instance store is ephemeral.
Checked against: https://docs.aws.amazon.com/efs/latest/ug/whatisefs.html
Question 6
Domain: Design Resilient Architectures
An insurance claim process has eight steps implemented as Lambda functions, some of which must retry on transient errors, some run in parallel and one waits up to five days for a human approval.
Which service should orchestrate the workflow?
- Run all steps in a single Lambda function with a 15-minute timeout
- Use AWS Step Functions to define the sequence, retries, error handling and branching as a state machine
- Chain the Lambda functions by having each function invoke the next one directly, with retry logic coded inside every function
- Use an SQS FIFO queue with one message per step
Show the answer
Answer: B. Use AWS Step Functions to define the sequence, retries, error handling and branching as a state machine
Step Functions is purpose-built for coordinating multi-step, long-running workflows with built-in retry, catch, parallel and choice states and a visual execution history; human approval can be modelled with the .waitForTaskToken callback pattern. Direct Lambda chaining spreads orchestration logic across functions and makes retries and visibility hard.
Checked against: https://docs.aws.amazon.com/step-functions/latest/dg/welcome.html
Question 7
Domain: Design High-Performing Architectures
A self-managed Oracle database on EC2 needs 120,000 IOPS with consistent sub-millisecond latency and the highest available durability for a single volume.
Which EBS volume type is the most appropriate?
- st1 Throughput Optimized HDD
- sc1 Cold HDD
- gp3
- io2 Block Express
Show the answer
Answer: D. io2 Block Express
io2 Block Express provides up to 256,000 IOPS and 4,000 MiB/s per volume with sub-millisecond latency and 99.999% durability, making it the choice for the most demanding databases. gp3 tops out at 16,000 IOPS, and the HDD types are for large sequential throughput, not random I/O.
Checked against: https://docs.aws.amazon.com/ebs/latest/userguide/ebs-volume-types.html
Question 8
Domain: Design High-Performing Architectures
How many IP addresses does AWS reserve in every VPC subnet?
- 2 (the first and last)
- 8 (the first four and the last four)
- 5 (the first four and the last)
- None; all addresses are usable
Show the answer
Answer: C. 5 (the first four and the last)
In each subnet AWS reserves the network address, the VPC router (+1), the DNS server (+2), one for future use (+3) and the broadcast address (last), so a /24 subnet yields 251 usable addresses. This matters when sizing subnets for large Auto Scaling groups or EKS clusters.
Checked against: https://docs.aws.amazon.com/vpc/latest/userguide/subnet-sizing.html
Question 9
Domain: Design Cost-Optimized Architectures
A web fleet spread across three Availability Zones makes millions of small reads per hour to an ElastiCache for Redis cluster with a replica in each AZ, but every instance connects to the primary endpoint. The cross-AZ data transfer line item has become significant.
Which change most reduces the cost of this traffic pattern?
- Move all subnets to a single Availability Zone
- Replace ElastiCache with an S3 bucket
- Enable cross-zone load balancing on the ALB
- Use zonal DNS names or the instances' AZ awareness so each web instance prefers the cache node in its own Availability Zone, and keep the fleet spread across AZs
Show the answer
Answer: D. Use zonal DNS names or the instances' AZ awareness so each web instance prefers the cache node in its own Availability Zone, and keep the fleet spread across AZs
Data transfer between Availability Zones in the same Region is charged per gigabyte in each direction, so chatty cache lookups that cross AZs add up; routing reads to a same-AZ replica keeps the traffic free while preserving multi-AZ resilience. Collapsing into one AZ removes the resilience the fleet was built for.
Checked against: https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/BestPractices.html
Question 10
Domain: Design Cost-Optimized Architectures
A company suspects many of its 400 EC2 instances are larger than necessary but has no data to decide which ones to downsize.
Which service should the architect use to right-size the fleet?
- AWS Pricing Calculator
- AWS Compute Optimizer, which analyses CloudWatch utilisation metrics and recommends instance types and sizes
- AWS Config
- Amazon Inspector
Show the answer
Answer: B. AWS Compute Optimizer, which analyses CloudWatch utilisation metrics and recommends instance types and sizes
Compute Optimizer uses machine learning on historical utilisation to flag over-provisioned and under-provisioned EC2 instances, Auto Scaling groups, EBS volumes, Lambda functions and ECS on Fargate, with projected savings. The Pricing Calculator only estimates cost for a design you specify.
Checked against: https://docs.aws.amazon.com/compute-optimizer/latest/ug/what-is-compute-optimizer.html
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
AWS Solutions Architect Associate course and practice exam: SAA-C03: the exam guide, with the format, cost, pass mark and domains from the vendor.