{"id":15455,"date":"2026-09-18T05:21:39","date_gmt":"2026-09-18T05:21:39","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15455"},"modified":"2026-09-18T05:21:39","modified_gmt":"2026-09-18T05:21:39","slug":"amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-solutions-architect-professional-sap-c02-exam-dumps\"><b>Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>A company needs to connect several VPCs and on-premises networks through a centralized network hub. Which AWS service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Transit Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Transit Gateway acts as a centralized network hub that can connect multiple VPCs and on-premises networks. It simplifies network architecture by avoiding a large number of individual VPC peering connections. Transit Gateway can also integrate with VPN and Direct Connect connectivity, making it useful for hybrid and multi-account environments. VPC Peering provides point-to-point connectivity, while NAT Gateway and Internet Gateway serve different connectivity purposes. Therefore, Transit Gateway is appropriate when an organization needs centralized connectivity across multiple networks.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>Which AWS service allows an organization to create isolated virtual networks for its AWS resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon VPC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Direct Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Virtual Private Cloud allows organizations to create logically isolated networks within AWS. A VPC can contain subnets, route tables, security groups, network ACLs, and other networking components that control how resources communicate. Organizations can design public and private subnets and connect the VPC to on-premises environments or other networks. Route 53 provides DNS capabilities, Direct Connect provides dedicated connectivity, and Organizations manages AWS accounts. Therefore, Amazon VPC is the appropriate service for creating isolated virtual networks.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>A company needs to run a large number of independent batch jobs and wants AWS to provision compute resources automatically. Which service is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Batch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Lambda<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Lightsail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Batch is designed to run batch computing workloads at scale. It automatically provisions and manages the required compute resources based on submitted jobs and configured environments. This makes it useful for workloads such as financial calculations, simulations, image processing, and large-scale data processing. SQS provides message queuing, Lambda executes event-driven functions, and Lightsail provides simplified application hosting. Therefore, AWS Batch is the appropriate service when an organization needs managed scheduling and execution of large numbers of batch jobs.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>An organization wants to prevent developers from launching resources outside approved AWS Regions. Which control should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM permissions boundaries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service control policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network ACLs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service control policies in AWS Organizations can establish permission guardrails across accounts, including restrictions on which AWS Regions can be used. An SCP does not directly grant permissions, but it can limit the maximum permissions available to identities within affected accounts. IAM permissions boundaries constrain permissions for individual identities, while security groups and network ACLs control network traffic. Therefore, an SCP is appropriate when an organization wants a centralized organizational restriction preventing resource usage in unapproved Regions.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>Which AWS storage service provides block storage that can be attached to an EC2 instance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EFS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Storage Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Elastic Block Store provides persistent block-level storage volumes that can be attached to EC2 instances. EBS is commonly used for operating system disks, application data, and database workloads that require block storage. EFS provides managed file storage, S3 provides object storage, and Storage Gateway connects on-premises environments with AWS storage services. EBS volumes can offer different performance and cost characteristics depending on the selected volume type. Therefore, Amazon EBS is the appropriate choice for persistent block storage attached to EC2.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>A company needs a managed service for hosting a public or private API and wants built-in throttling and authorization capabilities. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon API Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS App Mesh<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon API Gateway is a managed service for creating, publishing, securing, monitoring, and managing APIs. It supports capabilities such as throttling, authorization, request validation, and integration with services including Lambda and backend applications. CloudFront is primarily a content delivery service, App Mesh manages service-to-service communication, and Route 53 provides DNS services. API Gateway can support REST, HTTP, and WebSocket APIs depending on the required architecture. Therefore, API Gateway is the appropriate choice for managing APIs with integrated controls.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>A company wants to detect unauthorized or suspicious network activity against resources in its AWS environment. Which service provides managed threat detection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon GuardDuty continuously analyzes relevant AWS data sources to identify potential security threats and suspicious activity. It can detect certain indicators such as unusual API behavior, compromised credentials, malicious network activity, and other threat signals. Config focuses on configuration compliance, Artifact provides compliance documentation, and S3 provides object storage. GuardDuty is designed specifically for managed threat detection rather than configuration management or data storage. Therefore, GuardDuty is the appropriate service for detecting suspicious activity within an AWS environment.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>A workload requires a relational database but the company wants AWS to handle backups, patching, and database infrastructure management. Which service is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DynamoDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon RDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon OpenSearch Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon RDS is a managed relational database service that reduces the administrative work required to operate supported database engines. AWS handles tasks such as infrastructure provisioning, automated backups, software patching, and maintenance according to the selected configuration. DynamoDB is a NoSQL database, S3 provides object storage, and OpenSearch is intended for search and analytics workloads. RDS supports several relational database engines and provides features for high availability, scaling, and backup. Therefore, Amazon RDS is appropriate for managed relational database workloads.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>Which AWS service can provide a private connection between a VPC and an S3 bucket without routing traffic through the public internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway VPC endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Global Accelerator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A gateway VPC endpoint provides private connectivity from a VPC to supported AWS services such as Amazon S3 and DynamoDB. Traffic can remain within the AWS network instead of requiring an internet gateway or NAT Gateway. This architecture is particularly useful for private subnets that need access to S3 without public internet connectivity. NAT Gateway is generally used for outbound internet access, Internet Gateway provides internet connectivity, and Global Accelerator optimizes global application traffic. Therefore, a gateway VPC endpoint is appropriate for private S3 access.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>A company needs to run an application on Kubernetes while reducing the operational effort of managing the Kubernetes control plane. Which service should it use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ECS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EKS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Lambda<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Batch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Elastic Kubernetes Service is a managed Kubernetes service that reduces the operational burden of running the Kubernetes control plane. EKS integrates with AWS networking, identity, monitoring, and other services while allowing organizations to use Kubernetes-compatible tooling and workloads. ECS is AWS&#8217;s container orchestration service but does not use Kubernetes, Lambda provides serverless functions, and Batch is designed for batch workloads. Therefore, EKS is appropriate when an organization requires Kubernetes while minimizing control-plane management responsibilities.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>Which AWS service provides centralized management of encryption keys used by AWS workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Key Management Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Key Management Service allows organizations to create and control cryptographic keys used to protect data across AWS services and applications. KMS integrates with services such as S3, EBS, RDS, and many others, enabling encryption and controlled key usage through policies and permissions. Secrets Manager stores sensitive credentials and other secrets, Macie discovers sensitive data, and Certificate Manager manages certificates. Therefore, AWS KMS is the appropriate service for centralized encryption key management.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>A company wants to automatically discover underutilized EC2 resources and receive recommendations for rightsizing. Which service should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Compute Optimizer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudFormation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Compute Optimizer analyzes resource utilization and provides recommendations that can help organizations select more appropriate resource configurations. It can identify potential rightsizing opportunities for supported AWS resources, helping reduce unnecessary costs while maintaining suitable performance. CloudFormation manages infrastructure deployment, Inspector focuses on security vulnerabilities, and Artifact provides compliance documentation. Compute Optimizer is therefore useful when an organization wants data-driven recommendations for improving resource efficiency and identifying potentially oversized resources.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>A company needs to store frequently accessed application data in memory to reduce database latency. Which service is most suitable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ElastiCache<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Glacier<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Storage Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon ElastiCache provides managed in-memory data stores that can be used to cache frequently accessed information and reduce database workload. By keeping commonly requested data in memory, applications can often achieve lower latency and higher throughput than repeatedly querying a database. S3 provides object storage, Glacier storage classes are designed for archival data, and Storage Gateway provides hybrid storage integration. Therefore, ElastiCache is the appropriate choice when an application needs a managed in-memory cache.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>Which AWS service can help an organization establish a multi-account landing zone with centralized governance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Control Tower<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Cognito<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Control Tower helps organizations establish and govern a multi-account AWS environment using a landing zone approach. It provides mechanisms for account provisioning, organizational structure, guardrails, and centralized governance. This is particularly useful for enterprises that want standardized account configurations and controls while allowing individual teams or business units to operate separate accounts. Cognito manages application identities, Inspector performs vulnerability assessment, and DataSync transfers data. Therefore, AWS Control Tower is appropriate for establishing governed multi-account environments.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>A company wants to move large datasets to AWS when network connectivity is too slow or expensive for the initial transfer. Which solution should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Snowball<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Snowball provides physical data transfer appliances that can be used to move large amounts of data to or from AWS when network-based transfer would be impractical. Data is loaded onto the appliance and securely transported to AWS for ingestion. CloudFront accelerates content delivery, WAF protects web applications, and Route 53 provides DNS services. Snowball can be particularly useful when organizations have substantial datasets and limited bandwidth. Therefore, AWS Snowball is appropriate for large-scale offline data migration.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>A company needs to coordinate several AWS Lambda functions and manage retries and workflow state. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EventBridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Step Functions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Step Functions provides workflow orchestration for distributed applications and serverless workloads. It allows organizations to define sequences of tasks, branching logic, retries, error handling, and workflow state. Lambda functions can be integrated into Step Functions workflows, making it useful for coordinating multiple functions without implementing complex orchestration logic inside application code. EventBridge routes events, SQS provides message queues, and SNS provides publish-subscribe messaging. Therefore, Step Functions is the appropriate service for orchestrating Lambda-based workflows.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>A company wants to automatically detect configuration changes and evaluate AWS resources against compliance requirements. Which service is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Config continuously records supported resource configurations and can evaluate resources against compliance rules. Organizations can use Config rules to determine whether resources meet requirements such as encryption, approved configurations, or network restrictions. Config also maintains configuration history, which helps administrators investigate changes over time. CloudTrail records API activity, GuardDuty detects threats, and Shield protects against DDoS attacks. Therefore, AWS Config is the appropriate service for configuration monitoring and compliance evaluation.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>A company wants to distribute messages to several independent consumers so each consumer can process the same notification separately. Which architecture is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS standard queue only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SNS topic with multiple SQS subscriptions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS with multiple volumes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Direct Connect with multiple circuits<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An SNS topic with multiple SQS subscriptions supports a fanout architecture in which one published message can be delivered to multiple independent queues. Each consumer can then process its own copy of the message at its own pace. This approach provides decoupling and allows different applications to consume the same event independently. A single SQS queue distributes messages among consumers rather than giving every consumer a copy. Therefore, SNS combined with multiple SQS queues is appropriate for durable message fanout.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>A company wants to protect an S3 bucket from accidental deletion of objects while retaining the ability to manage retention policies. Which feature should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Object Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Select<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Access Points<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Object Lock can prevent objects from being deleted or overwritten for a configured retention period. It supports retention modes and legal holds for workloads that require stronger protection against accidental or intentional deletion. Transfer Acceleration improves data transfer performance, S3 Select allows applications to retrieve portions of object data, and Access Points simplify access management. Object Lock is especially relevant for compliance and immutable storage requirements. Therefore, S3 Object Lock is the appropriate feature for protecting objects from deletion during retention.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>A company wants to monitor application metrics and trigger an automated action when a metric crosses a defined threshold. Which AWS service should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudWatch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon CloudWatch can collect and monitor metrics from AWS resources and applications. CloudWatch alarms can evaluate metric values against configured thresholds and initiate actions when conditions are met. For example, an alarm can trigger an Auto Scaling policy or send a notification through an integrated service. CloudTrail records API activity, Config evaluates resource configurations, and Macie identifies sensitive data. Therefore, CloudWatch is the appropriate service for monitoring metrics and triggering automated responses based on threshold conditions.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps and Practice Test Dumps. &nbsp; Question 221 A company needs to connect several VPCs and on-premises networks through a centralized network hub. Which AWS service should be used? VPC Peering AWS Transit Gateway NAT Gateway Internet Gateway Correct Answer: 2 Explanation AWS Transit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15455"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15455"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15455\/revisions"}],"predecessor-version":[{"id":15476,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15455\/revisions\/15476"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}