CloudExamCheap

SAP-C02 Practice Exam: AWS Certified Solutions Architect - Professional

527 questions · 180 min timed mode · AWS · Updated 2026

The boss level of AWS architecture certs. Multi-account, multi-region, multi-headache.

What you'll be tested on

Sample SAP-C02 questions

A company needs to architect a hybrid DNS solution. This solution will use an Amazon Route 53 private hosted zone for the domain cloud.example.com for the resources stored within VPCs. The company has the following DNS resolution requirements: On-premises systems should be able to resolve and connect to cloud.example.com. All VPCs should be able to resolve cloud.example.com. There is already an AWS Direct Connect connection between the on-premises corporate network and AWS Transit Gateway. Which architecture should the company use to meet these requirements with the HIGHEST performance?
  1. Associate the private hosted zone to all the VPCs. Create a Route 53 inbound resolver in the shared services VPC. Attach all VPCs to the transit gateway and create forwarding rules in the on-premises DNS server for cloud.example.com that point to the inbound resolver.
  2. Associate the private hosted zone to all the VPCs. Deploy an Amazon EC2 conditional forwarder in the shared services VPC. Attach all VPCs to the transit gateway and create forwarding rules in the on-premises DNS server for cloud.example.com that point to the conditional forwarder.
  3. Associate the private hosted zone to the shared services VPCreate a Route 53 outbound resolver in the shared services VPAttach all VPCs to the transit gateway and create forwarding rules in the on-premises DNS server for cloud.example.com that point to the outbound resolver.
  4. Associate the private hosted zone to the shared services VPC. Create a Route 53 inbound resolver in the shared services VPC. Attach the shared services VPC to the transit gateway and create forwarding rules in the on-premises DNS server for cloud.example.com that point to the inbound resolver.
Show answerA — Associate the private hosted zone to all the VPCs. Create a Route 53 inbound resolver in the shared services VPC. Attach all VPCs to the transit gateway and create forwarding rules in the on-premises DNS server for cloud.example.com that point to the inbound resolver.
Route 53 Resolver inbound endpoints are the managed, high-performance way to let on-premises DNS servers resolve names in a private hosted zone: the on-premises DNS forwards cloud.example.com queries to the inbound endpoint IPs, reachable over Direct Connect through the transit gateway. Associating the private hosted zone with all VPCs gives every VPC native resolution. An EC2 conditional forwarder (B) adds unmanaged infrastructure and lower performance. An outbound resolver (C) resolves on-premises names from AWS, the wrong direction. Associating the zone only with the shared services VPC (D) breaks resolution for the other VPCs.
A company is providing weather data over a REST-based API to several customers. The API is hosted by Amazon API Gateway and is integrated with different AWS Lambda functions for each API operation. The company uses Amazon Route 53 for DNS and has created a resource record of weather.example.com. The company stores data for the API in Amazon DynamoDB tables. The company needs a solution that will give the API the ability to fail over to a different AWS Region. Which solution will meet these requirements?
  1. Deploy a new set of Lambda functions in a new Region. Update the API Gateway API to use an edge-optimized API endpoint with Lambda functions from both Regions as targets. Convert the DynamoDB tables to global tables.
  2. Deploy a new API Gateway API and Lambda functions in another Region. Change the Route 53 DNS record to a multivalue answer. Add both API Gateway APIs to the answer. Enable target health monitoring. Convert the DynamoDB tables to global tables.
  3. Deploy a new API Gateway API and Lambda functions in another Region. Change the Route 53 DNS record to a failover record. Enable target health monitoring. Convert the DynamoDB tables to global tables.
  4. Deploy a new API Gateway API in a new Region. Change the Lambda functions to global functions. Change the Route 53 DNS record to a multivalue answer. Add both API Gateway APIs to the answer. Enable target health monitoring. Convert the DynamoDB tables to global tables.
Show answerC — Deploy a new API Gateway API and Lambda functions in another Region. Change the Route 53 DNS record to a failover record. Enable target health monitoring. Convert the DynamoDB tables to global tables.
Regional API Gateway endpoints plus Lambda deployed in a second Region, combined with Route 53 failover routing and health checks, is the standard active-passive multi-Region failover design; DynamoDB global tables keep data replicated across Regions. Edge-optimized endpoints (A) are fronted by a single CloudFront distribution and cannot target Lambda in two Regions. Multivalue answer routing (B, D) distributes traffic rather than providing health-checked failover to a standby. There is no such thing as global Lambda functions (D). Failover records with health monitoring route traffic to the secondary only when the primary is unhealthy.
A company uses AWS Organizations with a single OU named Production to manage multiple accounts. All accounts are members of the Production OU. Administrators use deny list SCPs in the root of the organization to manage access to restricted services. The company recently acquired a new business unit and invited the new unit’s existing AWS account to the organization. Once onboarded, the administrators of the new business unit discovered that they are not able to update existing AWS Config rules to meet the company’s policies. Which option will allow administrators to make changes and continue to enforce the current policies without introducing additional long-term maintenance?
  1. Remove the organization’s root SCPs that limit access to AWS Config. Create AWS Service Catalog products for the company’s standard AWS Config rules and deploy them throughout the organization, including the new account.
  2. Create a temporary OU named Onboarding for the new account. Apply an SCP to the Onboarding OU to allow AWS Config actions. Move the new account to the Production OU when adjustments to AWS Config are complete.
  3. Convert the organization’s root SCPs from deny list SCPs to allow list SCPs to allow the required services only. Temporarily apply an SCP to the organization’s root that allows AWS Config actions for principals only in the new account.
  4. Create a temporary OU named Onboarding for the new account. Apply an SCP to the Onboarding OU to allow AWS Config actions. Move the organization’s root SCP to the Production OU. Move the new account to the Production OU when adjustments to AWS Config are complete.
Show answerD — Create a temporary OU named Onboarding for the new account. Apply an SCP to the Onboarding OU to allow AWS Config actions. Move the organization’s root SCP to the Production OU. Move the new account to the Production OU when adjustments to AWS Config are complete.
SCPs use an implicit deny model with deny lists: any SCP that explicitly allows a service does not override a deny higher in the hierarchy. The root deny list SCP blocks AWS Config, so moving that root SCP down to the Production OU removes its effect on the new account while keeping enforcement on all existing accounts in the Production OU. A temporary Onboarding OU with an allow SCP lets the new account adjust Config rules before joining Production. Option B alone fails because the root SCP still applies to the Onboarding OU. Allow lists (C) and removing root SCPs (A) create ongoing maintenance.

Access plans

AccessPrice
3 months$8.99$3.99
1 year$14.99$8.99
Lifetime$24.99$14.99
Practice SAP-C02 now →
Free preview inside — try 5 questions before you pay anything.

FAQ

How many practice questions are in this SAP-C02 bank?
527 questions covering the current SAP-C02 AWS Certified Solutions Architect - Professional syllabus, every one with the correct answer and an explanation.
How long is the real SAP-C02 exam?
The official SAP-C02 exam gives you 180 minutes. Our timed exam mode uses the same limit so the pace feels familiar.
What does SAP-C02 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.