{"id":15448,"date":"2026-09-18T05:23:12","date_gmt":"2026-09-18T05:23:12","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15448"},"modified":"2026-09-18T05:23:12","modified_gmt":"2026-09-18T05:23:12","slug":"amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-solutions-architect-professional-sap-c02-exam-dumps\"><b>Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>A company needs to protect an application from unauthorized inbound traffic at the instance level. Which VPC feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security group acts as a virtual firewall for supported resources such as EC2 instances. It controls inbound and outbound traffic using rules based on protocols, ports, and source or destination addresses. Security groups are stateful, meaning return traffic for an allowed connection is automatically permitted. Route tables control traffic paths, NAT gateways provide outbound internet connectivity for private resources, and internet gateways connect VPCs to the internet. Therefore, a security group is the appropriate VPC feature for controlling instance-level network access.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>Which AWS service provides centralized secrets storage with automatic rotation capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS KMS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager is designed to securely store sensitive information such as database passwords, API credentials, and application secrets. It can integrate with supported services to automatically rotate credentials, reducing the need for administrators to manually change passwords. AWS KMS manages encryption keys, Certificate Manager manages certificates, and Macie helps discover sensitive information in S3. Secrets Manager can also provide applications with secrets programmatically, avoiding the need to hard-code credentials. Therefore, AWS Secrets Manager is the appropriate service for centralized secrets management and automated rotation.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>A company wants to deploy resources in a second AWS Region for disaster recovery. Which approach provides the most automated infrastructure deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manually recreate every resource<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use AWS CloudFormation templates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Copy EC2 instance screenshots<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use CloudWatch dashboards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudFormation allows infrastructure to be defined as code and deployed consistently in multiple AWS Regions. Templates can describe networking, compute, databases, security controls, and other resources required by an application. This makes disaster recovery deployments more repeatable and reduces manual configuration errors. Manually recreating resources can be slow and inconsistent, screenshots do not contain infrastructure configuration, and CloudWatch dashboards are used for monitoring rather than deployment. Therefore, CloudFormation templates provide an effective automated approach for recreating infrastructure in a secondary Region.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which service can automatically distribute incoming HTTPS requests across multiple healthy targets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Direct Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Transit Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Application Load Balancer distributes HTTP and HTTPS traffic across registered targets such as EC2 instances, containers, and IP addresses. It performs health checks and can route requests only to healthy targets. It also supports advanced routing based on hostnames, URL paths, and other HTTP attributes. Route 53 provides DNS routing, Direct Connect provides dedicated network connectivity, and Transit Gateway connects networks. Therefore, an Application Load Balancer is the appropriate service for distributing HTTPS application traffic across multiple healthy targets.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>A company stores frequently accessed objects in S3 and wants the storage class to automatically move objects between access tiers based on changing usage. Which option should be selected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Glacier Deep Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Intelligent-Tiering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 One Zone-IA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Standard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Intelligent-Tiering automatically moves objects between access tiers based on changing access patterns. This helps organizations optimize storage costs without manually predicting when individual objects will become less frequently accessed. It is useful when access patterns are unpredictable or change over time. Glacier Deep Archive is intended for long-term archival, One Zone-IA is designed for infrequently accessed data stored in a single Availability Zone, and S3 Standard is intended for frequently accessed data. Therefore, S3 Intelligent-Tiering is the most appropriate choice for automatic tier optimization.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which service can provide centralized visibility into security findings from multiple AWS security services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Hub aggregates security findings from supported AWS security services and third-party products into a centralized view. This helps security teams monitor their overall security posture across accounts and workloads. Security Hub can also evaluate supported security standards and provide findings that help organizations identify areas requiring attention. Amazon S3 provides object storage, Config evaluates resource configurations, and Route 53 provides DNS services. Therefore, AWS Security Hub is the appropriate service for centralized security finding visibility.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>A company requires a database that can automatically scale storage as data grows without manual volume expansion. Which service is a suitable choice?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DynamoDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon FSx<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Neptune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon DynamoDB is a fully managed NoSQL database service designed to provide scalable storage and throughput without requiring customers to manage traditional database storage volumes. It can support workloads that need flexible scaling and predictable performance. EBS requires volume management and resizing for many storage growth scenarios, while FSx provides managed file systems and Neptune provides graph database capabilities. DynamoDB is particularly suitable for applications where data growth and request volume can vary significantly. Therefore, DynamoDB is an appropriate choice for a highly scalable managed database workload.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>Which service allows applications to securely expose APIs to clients while integrating with Lambda functions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon API Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EFS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon API Gateway is a managed service for creating, publishing, securing, monitoring, and managing APIs. It can integrate directly with AWS Lambda, allowing HTTP requests to invoke serverless functions without requiring the application to manage web servers. API Gateway supports features such as authentication, throttling, monitoring, and request handling. Route 53 provides DNS services, DataSync transfers data between storage environments, and EFS provides shared file storage. Therefore, API Gateway is the appropriate service for exposing managed APIs that integrate with Lambda-based applications.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>A company needs to run a relational database with automatic backups, patching, and managed infrastructure. Which service should it use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DynamoDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon RDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon OpenSearch Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Relational Database Service provides managed relational database engines and handles many administrative tasks, including infrastructure provisioning, automated backups, software patching, and certain high-availability configurations. This allows teams to focus more on database usage and application development rather than routine infrastructure management. DynamoDB is a NoSQL database, S3 provides object storage, and OpenSearch Service is designed for search and analytics workloads. Therefore, Amazon RDS is the appropriate service when an organization requires a managed relational database with automated operational capabilities.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which AWS service can automatically detect vulnerabilities in EC2 instances and container images?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Inspector continuously assesses supported AWS workloads for software vulnerabilities and unintended network exposure. It can identify vulnerabilities in supported EC2 instances, container images, and other eligible resources. GuardDuty focuses on detecting suspicious activity and threats, WAF protects web applications from malicious requests, and Shield provides DDoS protection. Inspector is therefore the appropriate service when an organization needs automated vulnerability assessment rather than threat detection or traffic filtering. Its findings can help security teams prioritize remediation of discovered vulnerabilities.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>A company wants to use a private IP address to access a service hosted by another AWS account. Which technology is designed for this use case?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS PrivateLink<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Direct Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3 Transfer Acceleration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS PrivateLink enables private connectivity between consumers and supported services using private IP addresses. A service provider can expose an application through an endpoint service, while consumers create interface VPC endpoints to access that service without requiring direct VPC peering. This design is particularly useful when services are shared across accounts or organizations while maintaining network isolation. CloudFront provides content delivery, Direct Connect provides dedicated network connectivity, and S3 Transfer Acceleration improves S3 transfer performance. Therefore, AWS PrivateLink is the appropriate technology for private service access.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which AWS service can centrally manage compliance and governance controls for a multi-account environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Control Tower<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Control Tower helps organizations establish and govern multi-account AWS environments using automated account provisioning, guardrails, and centralized governance capabilities. It builds on AWS Organizations and can help maintain consistent controls across accounts. Inspector focuses on vulnerability assessment, Macie focuses on sensitive data discovery, and DataSync transfers data between storage systems. Control Tower is particularly useful for enterprises that need standardized account structures and governance controls as their AWS environment grows. Therefore, AWS Control Tower is the appropriate service for centralized multi-account governance.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>A company needs to store billions of key-value records with very low-latency access. Which database is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon RDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Redshift<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DynamoDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Neptune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon DynamoDB is a managed NoSQL database designed to provide low-latency access at scale. It supports key-value and document data models and can handle very large workloads without requiring traditional database server management. RDS provides relational databases, Redshift is designed for analytical data warehousing, and Neptune is optimized for graph relationships. DynamoDB is particularly appropriate for applications such as gaming, retail, mobile applications, and high-volume transactional systems where predictable low-latency performance is required. Therefore, DynamoDB is the best choice for billions of key-value records requiring fast access.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which service should be used to centrally store audit logs for multiple AWS accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Lambda<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EFS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudTrail records API activity and can be configured to deliver audit logs to centralized storage. In multi-account environments, organizations can create centralized logging architectures where activity from multiple accounts is collected for security monitoring, compliance, and investigations. CloudFront provides content delivery, Lambda provides serverless compute, and EFS provides shared file storage. CloudTrail can capture actions performed through the AWS Management Console, CLI, SDKs, and AWS services. Therefore, AWS CloudTrail is the appropriate service for centralized AWS API audit logging.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>A company wants to route users to different application versions using a percentage-based traffic split. Which Route 53 policy should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geolocation routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Failover routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 weighted routing allows DNS traffic to be distributed among multiple endpoints according to assigned weights. This makes it useful for scenarios such as blue-green deployments, gradual releases, and controlled testing of different application versions. For example, an organization can route a small percentage of users to a new version while keeping most users on the existing version. Geolocation routing uses user location, failover routing uses primary and secondary endpoints, and simple routing provides basic DNS responses. Therefore, weighted routing is the correct choice for percentage-based traffic distribution.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which AWS service provides a managed file system optimized for high-performance workloads using the Lustre file system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon FSx for Lustre<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EFS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon FSx for Windows File Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon FSx for Lustre provides a managed file system designed for high-performance computing workloads. Lustre is commonly used for applications requiring high throughput and fast access to large datasets, including machine learning, media processing, and scientific computing. EFS provides elastic file storage for general file-based workloads, S3 provides object storage, and FSx for Windows File Server provides Windows-compatible shared storage. Therefore, FSx for Lustre is the appropriate service when an application requires a high-performance managed file system based on Lustre.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>A company wants to monitor AWS resource configuration changes and determine whether resources comply with internal rules. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Config records and evaluates the configuration of supported AWS resources. It can track configuration changes over time and use Config Rules to determine whether resources comply with defined requirements. This makes Config useful for governance, compliance monitoring, auditing, and configuration management. CloudTrail records API activity, GuardDuty detects suspicious activity, and Security Hub aggregates security findings. Therefore, AWS Config is the appropriate service when an organization needs to monitor resource configurations and evaluate compliance with internal or regulatory requirements.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which AWS service can provide a managed public certificate for an application using HTTPS?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS KMS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudHSM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Certificate Manager, or ACM, provides managed SSL\/TLS certificates that can be used with supported AWS services such as Application Load Balancers and CloudFront. ACM can simplify certificate provisioning and renewal, reducing the administrative work required to maintain HTTPS certificates. KMS manages encryption keys, Secrets Manager stores sensitive application information, and CloudHSM provides dedicated hardware security modules. Therefore, AWS Certificate Manager is the appropriate service for obtaining and managing certificates used to secure supported AWS applications with HTTPS.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>A company needs to transfer a very large dataset to AWS when network bandwidth is limited. Which solution should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Snowball Edge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Kinesis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Database Migration Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Snowball Edge provides physical devices that can be used to transfer large amounts of data to and from AWS. It is useful when transferring the data over the network would take too long because of limited bandwidth or other connectivity constraints. DataSync is better suited for online network-based transfers, Kinesis handles streaming data, and DMS is designed primarily for database migration. Therefore, Snowball Edge is an appropriate solution when a large dataset must be moved to AWS and network connectivity is insufficient for practical online transfer.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which service can automatically rotate secrets used by an application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager provides secure storage and management of sensitive information such as database credentials and API keys. It supports automated secret rotation for supported services and credential types, helping organizations reduce the risks associated with long-lived credentials. CloudTrail records API activity, Config monitors resource configurations, and GuardDuty detects potential threats. Applications can retrieve secrets programmatically without embedding credentials directly in code. Therefore, AWS Secrets Manager is the appropriate service when automatic credential rotation and secure application secret management are required.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 A company needs to protect an application from unauthorized inbound traffic at the instance level. Which VPC feature should be configured? Route table Security group NAT gateway Internet gateway Correct Answer: 2 Explanation A security group [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15448"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15448"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15448\/revisions"}],"predecessor-version":[{"id":15483,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15448\/revisions\/15483"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15448"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15448"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}