{"id":15452,"date":"2026-09-18T05:22:20","date_gmt":"2026-09-18T05:22:20","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15452"},"modified":"2026-09-18T05:22:20","modified_gmt":"2026-09-18T05:22:20","slug":"amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-solutions-architect-professional-sap-c02-exam-dumps\"><b>Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 161<\/b><\/h3>\n<p><b>A company wants to run containers without managing the underlying servers. Which option is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EC2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Fargate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Outposts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Fargate provides serverless compute for containers, allowing organizations to run workloads without provisioning or managing the underlying EC2 instances. Fargate works with services such as Amazon ECS and Amazon EKS and handles the underlying compute infrastructure. EC2 requires customers to manage instances, EBS provides block storage, and Outposts extends AWS infrastructure to customer locations. Therefore, Fargate is the appropriate choice when an organization wants to run containerized workloads while minimizing server management responsibilities.<\/span><\/p>\n<h3><b>Question 162<\/b><\/h3>\n<p><b>Which AWS service provides centralized management of encryption keys with detailed access policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS KMS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Key Management Service provides centralized creation, management, and control of cryptographic keys used to protect data across AWS services and applications. Customer managed KMS keys can have detailed key policies that determine which principals can use or administer them. KMS also integrates with CloudTrail to support auditing of key usage. WAF protects web applications, Inspector assesses vulnerabilities, and GuardDuty detects threats. Therefore, AWS KMS is the appropriate service when an organization requires centralized encryption-key management with granular access controls.<\/span><\/p>\n<h3><b>Question 163<\/b><\/h3>\n<p><b>A company needs to migrate a MySQL database to Amazon Aurora with minimal downtime. Which service should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Database Migration Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Transfer Family<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon AppFlow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Database Migration Service supports migration between many database engines and can use ongoing replication to reduce downtime during migration. For a MySQL-to-Aurora migration, DMS can perform an initial data load and then replicate ongoing changes while the source database remains available. DataSync is designed for file and object transfers, Transfer Family supports managed file transfers, and AppFlow transfers data between supported SaaS applications and AWS services. Therefore, AWS DMS is the appropriate choice for a database migration requiring minimal downtime.<\/span><\/p>\n<h3><b>Question 164<\/b><\/h3>\n<p><b>Which AWS service can provide a managed environment for running Apache Spark and Hadoop workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EMR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon RDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Neptune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EMR is a managed cluster platform designed for big data frameworks such as Apache Spark, Hadoop, Hive, and related technologies. It can process and analyze large datasets using distributed computing resources while integrating with services such as Amazon S3. RDS provides relational databases, Neptune provides graph database capabilities, and SQS provides message queuing. Therefore, Amazon EMR is the appropriate service for organizations that need managed infrastructure for Spark, Hadoop, and other distributed data-processing frameworks.<\/span><\/p>\n<h3><b>Question 165<\/b><\/h3>\n<p><b>A company wants to query data stored in S3 using SQL without managing database servers. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Redshift<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Athena<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon RDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Neptune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Athena is a serverless interactive query service that allows users to analyze data directly in Amazon S3 using standard SQL. Because Athena is serverless, organizations do not need to provision or manage database infrastructure for these queries. It is commonly used for log analysis, data lake exploration, and ad hoc analytics. Redshift is a managed data warehouse, RDS provides relational databases, and Neptune provides graph database capabilities. Therefore, Amazon Athena is the appropriate choice for querying S3 data directly with SQL without managing servers.<\/span><\/p>\n<h3><b>Question 166<\/b><\/h3>\n<p><b>Which AWS service provides a managed data warehouse designed for large-scale analytical queries?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Redshift<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DynamoDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EFS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon MQ<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Redshift is a managed cloud data warehouse designed for large-scale analytics and complex SQL queries across substantial datasets. It uses columnar storage and parallel processing to improve analytical query performance. DynamoDB is a NoSQL database for low-latency transactional workloads, EFS provides shared file storage, and Amazon MQ provides managed message brokers. Redshift can integrate with S3 and other AWS data services to support modern analytics architectures. Therefore, Amazon Redshift is the appropriate service for large-scale analytical data warehousing.<\/span><\/p>\n<h3><b>Question 167<\/b><\/h3>\n<p><b>A company wants to run scheduled serverless tasks without maintaining a scheduler server. Which service combination is suitable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EventBridge Scheduler and AWS Lambda<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3 and EFS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF and Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 and CloudFront<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EventBridge Scheduler can invoke supported AWS targets according to defined schedules, including Lambda functions. This allows organizations to run periodic serverless tasks without maintaining dedicated scheduling servers. Examples include cleanup operations, report generation, periodic data processing, and automated maintenance tasks. S3 and EFS provide storage, WAF and Shield provide security protections, and Route 53 and CloudFront provide DNS and content delivery capabilities. Therefore, EventBridge Scheduler combined with Lambda is an appropriate architecture for scheduled serverless workloads.<\/span><\/p>\n<h3><b>Question 168<\/b><\/h3>\n<p><b>Which AWS service helps manage infrastructure configuration and operational tasks across EC2 instances?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Systems Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Systems Manager provides centralized operational management for EC2 instances and supported hybrid infrastructure. It includes capabilities such as Run Command, Session Manager, Patch Manager, Automation, and Parameter Store. These features allow administrators to execute commands, manage patches, establish secure sessions, automate operational procedures, and store configuration parameters. CloudFront handles content delivery, Route 53 manages DNS, and Artifact provides compliance documentation. Therefore, AWS Systems Manager is the appropriate service for centralized EC2 management and operational automation.<\/span><\/p>\n<h3><b>Question 169<\/b><\/h3>\n<p><b>A company needs to serve static website content globally with low latency. Which architecture is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 with CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RDS with EBS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EFS with NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DynamoDB with Direct Connect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon S3 can host static website content, while Amazon CloudFront distributes cached content through global edge locations. This architecture can provide low-latency access to users in different geographic regions while reducing requests to the S3 origin. RDS and EBS are database and block-storage services, EFS provides file storage, and NAT Gateway provides outbound network connectivity. Therefore, combining S3 with CloudFront is an appropriate architecture for globally distributing static website content efficiently.<\/span><\/p>\n<h3><b>Question 170<\/b><\/h3>\n<p><b>Which AWS service provides managed WebSocket APIs for applications that require persistent client connections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon API Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon API Gateway supports WebSocket APIs that maintain persistent connections between clients and backend applications. This makes it suitable for real-time communication scenarios such as chat applications, notifications, multiplayer interactions, and live updates. API Gateway can integrate with services such as Lambda and other backend components. S3 provides object storage, DataSync transfers data, and EBS provides block storage. Therefore, API Gateway is the appropriate service when applications require managed WebSocket connectivity and real-time communication.<\/span><\/p>\n<h3><b>Question 171<\/b><\/h3>\n<p><b>A company wants to detect configuration drift between deployed infrastructure and its expected configuration. Which service can help?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudFormation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudFormation supports drift detection, which compares the actual configuration of supported resources with the configuration defined in a CloudFormation stack. This can help identify changes made outside the expected infrastructure-as-code process. GuardDuty detects security threats, Macie discovers sensitive data, and Inspector assesses vulnerabilities. Drift detection is particularly useful in environments where infrastructure should remain consistent with approved templates. Therefore, CloudFormation is the appropriate service for identifying configuration differences between deployed resources and their expected definitions.<\/span><\/p>\n<h3><b>Question 172<\/b><\/h3>\n<p><b>Which AWS service can automatically scale compute capacity based on application demand?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EC2 Auto Scaling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EC2 Auto Scaling can automatically increase or decrease the number of EC2 instances according to configured scaling policies and workload demand. Organizations can use metrics such as CPU utilization, request counts, or custom CloudWatch metrics to determine when additional capacity is required. Auto Scaling can also maintain a minimum and maximum capacity range. CloudTrail records activity, Config evaluates configurations, and Artifact provides compliance documents. Therefore, EC2 Auto Scaling is the appropriate service for automatically adjusting compute capacity according to application demand.<\/span><\/p>\n<h3><b>Question 173<\/b><\/h3>\n<p><b>A company needs to connect an application privately to an AWS service without using public internet routing. Which option should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public NAT gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elastic IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC endpoints allow resources in a VPC to access supported AWS services without requiring traffic to traverse the public internet. Gateway endpoints can provide private access to services such as Amazon S3 and DynamoDB, while interface endpoints use AWS PrivateLink for supported services. An internet gateway provides public internet connectivity, a NAT gateway enables outbound internet access, and an Elastic IP provides a public address. Therefore, a VPC endpoint is the appropriate choice when private connectivity to supported AWS services is required.<\/span><\/p>\n<h3><b>Question 174<\/b><\/h3>\n<p><b>Which service provides centralized management of security findings and compliance checks across AWS accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EFS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Transfer Family<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Hub provides centralized visibility into security findings and supported security standards across AWS environments. It can aggregate findings from services such as GuardDuty, Inspector, Macie, and supported third-party products. This gives security teams a consolidated view of potential issues and compliance-related checks. EFS provides file storage, SQS provides message queues, and Transfer Family supports managed file transfers. Therefore, Security Hub is the appropriate service for centralized security findings and security posture visibility across AWS accounts.<\/span><\/p>\n<h3><b>Question 175<\/b><\/h3>\n<p><b>A company wants to archive data that is rarely accessed and must be retained for many years at the lowest practical storage cost. Which option is suitable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Glacier Deep Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Intelligent-Tiering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Standard-IA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Glacier Deep Archive is designed for long-term retention of data that is rarely accessed. It provides a lower storage cost than frequently accessed S3 storage classes and is suitable for compliance archives, long-term backups, and other datasets that may need to be retained for years. S3 Standard is designed for frequent access, Intelligent-Tiering automatically adjusts storage tiers, and Standard-IA is intended for data accessed less frequently but still requiring relatively faster access. Therefore, Glacier Deep Archive is appropriate for long-term archival workloads with infrequent retrieval.<\/span><\/p>\n<h3><b>Question 176<\/b><\/h3>\n<p><b>Which AWS service can centrally manage resource tagging policies across an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Lambda<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Organizations provides centralized management capabilities for multiple AWS accounts and supports organization-wide governance features. Tag policies can be used to help standardize tagging across accounts and improve consistency for resource management, cost allocation, and governance. Inspector focuses on vulnerability assessment, CloudFront provides content delivery, and Lambda provides serverless compute. Centralized tagging policies are particularly useful in large environments where teams need consistent resource metadata. Therefore, AWS Organizations is the appropriate service for organization-level tag policy management.<\/span><\/p>\n<h3><b>Question 177<\/b><\/h3>\n<p><b>A company wants to prevent sensitive data from being accidentally uploaded to unauthorized S3 locations. Which service can help identify sensitive data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Macie helps discover and classify sensitive data stored in Amazon S3. It can identify certain sensitive information types and provide findings that help organizations investigate potentially exposed or improperly stored data. While Macie does not act as a general-purpose upload firewall, its discovery and classification capabilities can help security teams identify sensitive information and improve S3 data protection practices. Route 53 provides DNS, Shield provides DDoS protection, and CloudFront provides content delivery. Therefore, Macie is the appropriate service for identifying sensitive information in S3.<\/span><\/p>\n<h3><b>Question 178<\/b><\/h3>\n<p><b>Which AWS service allows centralized management of VPC flow logs and network traffic analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudWatch Logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudFormation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CodeDeploy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ECR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Flow Logs can be delivered to destinations such as Amazon CloudWatch Logs, where network traffic records can be stored and analyzed. This can help administrators investigate connectivity problems, identify unexpected traffic patterns, and support security investigations. CloudFormation manages infrastructure, CodeDeploy automates application deployments, and ECR stores container images. CloudWatch Logs can be combined with metrics and other monitoring capabilities to improve visibility into network activity. Therefore, Amazon CloudWatch Logs is an appropriate destination for centrally collecting and analyzing VPC Flow Logs.<\/span><\/p>\n<h3><b>Question 179<\/b><\/h3>\n<p><b>A company needs to create a private hosted DNS zone accessible only from selected VPCs. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Direct Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Route 53 supports private hosted zones that provide DNS resolution within associated VPCs. Organizations can use private hosted zones to resolve internal domain names without exposing those records through public DNS. A private hosted zone can be associated with selected VPCs according to the network architecture and access requirements. CloudFront provides content delivery, Direct Connect provides dedicated connectivity, and SQS provides messaging. Therefore, Route 53 is the appropriate service for managing private DNS zones for internal AWS resources.<\/span><\/p>\n<h3><b>Question 180<\/b><\/h3>\n<p><b>A company wants to improve database performance by moving frequently accessed data into memory. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ElastiCache<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon ElastiCache provides managed in-memory data stores that can be used to cache frequently accessed application and database data. By serving repeated requests from memory instead of querying the primary database each time, ElastiCache can reduce database load and improve application response times. S3 provides object storage, EBS provides block storage, and AWS Backup provides centralized backup management. Therefore, ElastiCache is the appropriate service when an application needs an in-memory caching layer to improve database performance.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps and Practice Test Dumps. &nbsp; Question 161 A company wants to run containers without managing the underlying servers. Which option is most appropriate? Amazon EC2 AWS Fargate Amazon EBS AWS Outposts Correct Answer: 2 Explanation AWS Fargate provides serverless compute for containers, allowing [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15452"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15452"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15452\/revisions"}],"predecessor-version":[{"id":15479,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15452\/revisions\/15479"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}