SAP-C01 Sample Questions

SAP-C01 Sample Questions & Answers

Free Solutions Architect - Professional practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full SAP-C01 simulator →

Showing 10 of 20 free samples.

  1. Question 1

    You are designing a photo-sharing mobile app. The application will store all pictures in a single Amazon S3 bucket.
    Users will upload pictures from their mobile device directly to Amazon S3 and will be able to view and download their own pictures directly from Amazon S3.
    You want to configure security to handle potentially millions of users in the most secure manner possible.

    What should your server-side application do when a new user registers on the photo-sharing mobile application?

    Show answer & explanation

    Correct answer: B

    Recording user information in Amazon RDS and creating an IAM role with appropriate permissions provides the most secure approach for mobile app authentication. Using AWS Security Token Service AssumeRole function generates temporary credentials that enhance security by eliminating long-term access keys stored in mobile devices. Temporary credentials automatically expire, reducing security risks if devices are compromised. Storing permanent IAM access keys directly in mobile apps creates significant security vulnerabilities since mobile applications can be reverse-engineered. Long-term credentials from STS contradict the principle of temporary access. DynamoDB could work for user storage, but the question emphasizes security, making the IAM role approach the preferred solution.

  2. Question 2

    A company is building a voting system for a popular TV show, viewers win watch the performances then visit the show's website to vote for their favorite performer. It is expected that in a short period of time after the show has finished the site will receive millions of visitors. The visitors will first login to the site using their Amazon.com credentials and then submit their vote. After the voting is completed the page will display the vote totals. The company needs to build the site such that can handle the rapid influx of traffic while maintaining good performance but also wants to keep costs to a minimum.

    Which of the design patterns below should they use?

    Show answer & explanation

    Correct answer: C

    Using CloudFront with an Elastic Load Balancer and auto-scaled web servers, combined with SQS for vote processing, provides the best architecture for handling massive traffic spikes after a TV show ends. CloudFront distributes traffic globally and caches static content, reducing load on backend servers. The auto-scaling web servers handle authentication via Login with Amazon, then queue votes in SQS for reliable, decoupled processing. SQS provides durability and prevents vote loss during peak traffic periods. Static S3 hosting cannot handle the authentication and complex vote processing requirements. Multi-AZ RDS would become a bottleneck during traffic spikes. DynamoDB direct writes could overwhelm the database without the buffering provided by SQS queues.

  3. Question 3

    A company has a High Performance Computing (HPC) cluster in its on-premises data center, which runs thousands of jobs in parallel for one week every month, processing petabytes of images.
    The images are stored on a network file server, which is replicated to a disaster recovery site. The on-premises data center has reached capacity and has started to spread the jobs out over the course of the month in order to better utilize the cluster, causing a delay in the job completion.
    The company has asked its Solutions Architect to design a cost-effective solution on AWS to scale beyond the current capacity of 5,000 cores and 10 petabytes of data. The solution must require the least amount of management overhead and maintain the current level of durability.

    Which solution will meet the company’s requirements?

    Show answer & explanation

    Correct answer: D

    Amazon EMR with Spark, using a combination of On-Demand and Reserved Instance Task Nodes, provides the optimal solution for processing petabytes of images in parallel HPC workloads. Spark is specifically designed for large-scale data processing and can efficiently handle image processing tasks across distributed compute nodes. EMR automatically manages the cluster infrastructure and scaling. DynamoDB maintains the job queue efficiently for distributed processing. Reserved Instances reduce costs for the predictable monthly workload pattern. AWS Batch is better for containerized jobs, not traditional HPC image processing. SQS with EC2 Spot Fleet lacks the distributed computing framework needed for petabyte-scale image processing. ECS containers add unnecessary overhead for compute-intensive HPC workloads.

  4. Question 4

    A company has an application that uses Amazon EC2 instances in an Auto Scaling group. The Quality Assurance (QA) department needs to launch a large number of short-lived environments to test the application. The application environments are currently launched by the Manager of the department using an AWS CloudFormation template. To launch the stack, the Manager uses a role with permission to use CloudFormation, EC2, and Auto Scaling APIs. The Manager wants to allow testers to launch their own environments, but does not want to grant broad permissions to each user.

    Which set up would achieve these goals?

    Show answer & explanation

    Correct answer: D

    AWS Service Catalog provides the most secure and controlled approach for QA teams to launch standardized environments. Service Catalog enforces governance by restricting users to pre-approved templates while launch constraints ensure consistent resource configurations and permissions. QA users only need Service Catalog permissions, not broad CloudFormation or EC2 access. The existing role can be attached as a launch constraint to maintain proper security boundaries. Direct CloudFormation access would give QA teams too many permissions and could lead to security risks. Elastic Beanstalk lacks the fine-grained control and customization needed for complex application environments. Role assumption approaches complicate access management and increase security complexity. Reference: https://aws.amazon.com/ru/blogs/mt/how-to-launch-secure-and-governed-aws-resources-with-aws-cloudformation-and-aws-service-catalog/

  5. Question 5

    In Amazon IAM, what is the maximum length for a role name?

    Show answer & explanation

    Correct answer: D

    In Amazon IAM, the maximum length for a role name is 64 characters. This limitation applies to all IAM role names to ensure consistent naming conventions and system compatibility. Role names must be unique within an AWS account and can contain alphanumeric characters plus specific special characters like hyphens and underscores. The 64-character limit is sufficient for descriptive role names while maintaining system performance. Other IAM entities have different limits: user names are also limited to 64 characters, while policy names can be up to 128 characters. These limits help maintain AWS service performance and prevent potential security issues with overly long identifiers. Reference: http://docs.aws.amazon.com/IAM/latest/UserGuide/LimitationsQnEntities.html

  6. Question 6

    Within the IAM service a GROUP is regarded as a:

    Show answer & explanation

    Correct answer: C

    In AWS IAM, a group is defined as a collection of users. Groups provide an efficient way to assign permissions to multiple users simultaneously by attaching policies to the group rather than individual users. When users are added to a group, they automatically inherit all permissions assigned to that group. This approach simplifies permission management, especially for users with similar job functions like administrators, developers, or analysts. Groups are not collections of AWS accounts, EC2 instances, or resources - they are specifically collections of IAM users. AWS accounts are managed separately through AWS Organizations, while EC2 instances receive permissions through IAM roles, not groups.

  7. Question 7

    In a VPC, can you modify a set of DHCP options after you create them?

    Show answer & explanation

    Correct answer: A

    No, you cannot modify a set of DHCP options after you create them in AWS VPC. DHCP options sets are immutable once created. If you need to change DHCP configuration for your VPC, you must create a new DHCP options set with the desired settings and associate it with your VPC, then disassociate the old set. This design ensures consistency and prevents configuration conflicts that could disrupt network operations. You can also configure your VPC to use the default DHCP options or no DHCP options at all. The immutable nature of DHCP options prevents accidental changes that could impact all instances in the VPC simultaneously.

  8. Question 8

    To serve Web traffic for a popular product your chief financial officer and IT director have purchased 10 m1. large heavy utilization Reserved Instances (RIs), evenly spread across two availability zones; Route 53 is used to deliver the traffic to an Elastic Load Balancer (ELB). After several months, the product grows even more popular and you need additional capacity. As a result, your company purchases two C3.2xlarge medium utilization Ris. You register the two c3.2xlarge instances with your ELB and quickly find that the ml.large instances are at 100% of capacity and the c3.2xlarge instances have significant capacity that's unused.

    Which option is the most cost effective and uses EC2 capacity most effectively?

    Show answer & explanation

    Correct answer: B

    Using separate ELBs for each instance type with Route 53 weighted round robin provides the optimal solution for maximizing the value of purchased Reserved Instances while adding flexibility for different workloads. This architecture allows you to utilize the existing m1.large RIs while also leveraging more powerful c3.2xlarge instances where needed. Route 53 weighted routing distributes traffic between the different ELBs based on configured weights, optimizing resource utilization. Shutting off the m1.large RIs would waste the significant financial investment already made. Direct routing without ELBs eliminates the health checking and load distribution benefits. Adding more m1.large instances through auto-scaling when c3.2xlarge instances are available would not optimize performance and resource costs.

  9. Question 9Select 2

    A solutions architect is implementing federated access to AWS for users of the company’s mobile application. Due to regulatory and security requirements, the application must use a custom-built solution for authenticating users and must use IAM roles for authorization.

    Which of the following actions would enable authentication and authorization and satisfy the requirements? (Choose two.)

    Show answer & explanation

    Correct answers: D, E

    D,E

    D,E

  10. Question 10

    A user is trying to send custom metrics to CloudWatch using the PutMetricData APIs.

    Which of the below mentioned points should the user needs to take care while sending the data to CloudWatch?

    Show answer & explanation

    Correct answer: D

    D--Explanation:
    With AWS CloudWatch, the user can publish data points for a metric that share not only the same time stamp, but also the same namespace and dimensions. CloudWatch can accept multiple data points in the same PutMetricData call with the same time stamp. The only thing that the user needs to take care of is that the size of a PutMetricData request is limited to 8KB for HTTP GET requests and 40KB for HTTP POST requests.--
    Reference:
    http://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/cloudwatch concepts.html

Ready for the real thing?

The full SAP-C01 simulator has every exam-style question, timed mode, and instant scoring.