Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 69 pages
Exam (elaborations)

AWS Certified Solutions Architect – Associate (SAA-C03) – Advanced Practice Exam 150 Multiple Choice Questions with Detailed Rationales a well detailed one 2025 / 2026 written and graded A+ upgraded

Document preview thumbnail
Preview 4 out of 69 pages

AWS Certified Solutions Architect – Associate (SAA-C03) – Advanced Practice Exam 150 Multiple Choice Questions with Detailed Rationales a well detailed one 2025 / 2026 written and graded A+ upgraded

Content preview

1




AWS Certified Solutions Architect
– Associate (SAA-C03) – Advanced
Practice Exam 150 Multiple-
Choice Questions with Detailed
Rationales a well detailed one
written and graded
A+ upgraded




Domain 1: Design Secure Architectures (30% of Exam)



Question 1

A company is deploying a critical web application on AWS and requires that all data stored in
Amazon S3 be encrypted at rest using customer-managed encryption keys. The security team

, 2



must maintain full control over the key lifecycle, including the ability to disable, rotate, and
revoke keys at any time. Which approach should a solutions architect recommend?

A. Enable default S3 encryption using SSE-S3
B. Use S3 server-side encryption with SSE-KMS and configure a customer-managed CMK
C. Implement client-side encryption before uploading objects to S3
D. Use S3 server-side encryption with SSE-C and manage keys within the application

-” detailed answer 100 % correct :-”B

Rationale: SSE-KMS with a customer-managed CMK provides full control over the encryption
key lifecycle, including rotation, disabling, and revocation through AWS KMS policies. SSE-S3 (A)
uses AWS-managed keys, not customer-managed. Client-side encryption (C) places the burden
of key management on the application and does not leverage KMS capabilities. SSE-C (D)
requires the customer to provide and manage keys with each request, which is less secure and
more operationally complex than KMS.



Question 2

A solutions architect is designing a VPC architecture for a three-tier application. The web tier
must be accessible from the internet, the application tier must only be accessible from the web
tier, and the database tier must only be accessible from the application tier. The database
contains sensitive customer data. How should the architect design the subnet architecture?

A. All tiers in public subnets with security groups restricting traffic
B. Web tier in public subnets, application and database tiers in private subnets with NAT
gateways
C. Web tier in public subnets, application tier in private subnets, database tier in isolated private
subnets with no internet gateway route
D. All tiers in private subnets with an internet gateway attached to the VPC

-” detailed answer 100 % correct :-”C

Rationale: This follows AWS best practices for three-tier architectures. The web tier in public
subnets allows internet access. The application tier in private subnets (with NAT for outbound
internet if needed) provides isolation. The database tier in isolated private subnets with no
route to an internet gateway provides the highest level of security for sensitive data. Option A
exposes all tiers. Option B does not isolate the database tier from the application tier properly.
Option D would make all tiers inaccessible from the internet.

, 3



Question 3

An application running on EC2 instances needs to access an S3 bucket to read and write objects.
The security policy prohibits storing long-term credentials on EC2 instances or in application
code. What is the most secure way to grant the EC2 instances access to the S3 bucket?

A. Create an IAM user and hardcode the access key and secret key in the application
configuration file
B. Store the credentials in AWS Systems Manager Parameter Store and retrieve them at runtime
C. Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance profile
D. Create an S3 bucket policy that allows public read and write access from the VPC CIDR

-” detailed answer 100 % correct :-”C

Rationale: IAM roles are the AWS best practice for granting EC2 instances access to AWS
services. Instance profiles allow EC2 instances to assume roles and obtain temporary credentials
via the instance metadata service. This eliminates the need to store or manage long-term
credentials. Option A violates security best practices by hardcoding credentials. Option B still
requires credential management and does not leverage IAM roles. Option D creates a significant
security vulnerability.



Question 4

A company uses AWS Organizations to manage multiple AWS accounts. The security team wants
to enforce that all S3 buckets across all accounts in the organization must have default
encryption enabled and block public access. Which approach should a solutions architect
recommend?

A. Create an S3 bucket policy in each account that enforces encryption and blocks public access
B. Use AWS Config rules to detect non-compliant buckets and trigger remediation
C. Implement a service control policy (SCP) in AWS Organizations to enforce these requirements
D. Use AWS Trusted Advisor to monitor and alert on non-compliant S3 buckets

-” detailed answer 100 % correct :-”C

Rationale: Service Control Policies (SCPs) in AWS Organizations allow centralized governance
across all member accounts. An SCP can deny S3 actions that do not meet encryption and public
access requirements, making it enforceable at the organization level. Option A is decentralized
and difficult to maintain. Option B detects issues but does not prevent them. Option D only
provides recommendations, not enforcement.

, 4




Question 5

A solutions architect is designing a system that requires secure transmission of data between an
on-premises data center and a VPC. The company requires high bandwidth, low latency, and a
dedicated private connection that does not traverse the public internet. Which solution should
the architect recommend?

A. Establish a site-to-site VPN connection over the internet
B. Use AWS Direct Connect with a dedicated connection
C. Set up a VPC peering connection between the on-premises network and the VPC
D. Use AWS Transit Gateway with VPN attachments

-” detailed answer 100 % correct :-”B

Rationale: AWS Direct Connect provides a dedicated private network connection from on-
premises to AWS, offering high bandwidth, low latency, and private connectivity that does not
traverse the public internet. Site-to-site VPN (A) traverses the public internet and does not
guarantee the same performance. VPC peering (C) is for VPC-to-VPC connectivity, not on-
premises. Transit Gateway with VPN (D) still uses VPN over the internet, not a dedicated private
connection.



Question 6

An application running on AWS needs to encrypt data stored in an Amazon RDS database. The
security team requires that encryption keys be rotated automatically every 90 days and that key
usage be audited through AWS CloudTrail. Which approach should a solutions architect
recommend?

A. Enable RDS encryption with the default AWS-managed KMS key
B. Enable RDS encryption with a customer-managed CMK and enable automatic key rotation
C. Implement application-level encryption before writing data to RDS
D. Use RDS Transparent Data Encryption (TDE) with a custom key management solution

-” detailed answer 100 % correct :-”B

Rationale: RDS encryption with a customer-managed CMK in AWS KMS provides automatic key
rotation (enabled by default for customer-managed CMKs) and CloudTrail auditing of key usage.
Option A uses AWS-managed keys that do not provide the same level of customer control.
Option C places encryption burden on the application and does not leverage RDS native

Document information

Uploaded on
July 25, 2026
Number of pages
69
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$26.39

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2970
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions