{"id":15456,"date":"2026-09-18T05:21:29","date_gmt":"2026-09-18T05:21:29","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15456"},"modified":"2026-09-18T05:21:29","modified_gmt":"2026-09-18T05:21:29","slug":"amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-solutions-architect-professional-sap-c02-exam-dumps\"><b>Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>A company needs to securely share an S3 object with an external user for a limited period without making the bucket public. Which solution should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 static website hosting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 presigned URL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 presigned URL provides temporary access to a specific S3 object without requiring the recipient to have AWS credentials. The URL is generated with an expiration time and uses the permissions of the identity that created it. This makes it suitable for securely sharing private objects for a limited period. A bucket ACL does not provide the same temporary access model, static website hosting is unrelated to private sharing, and Transfer Acceleration improves transfer performance. Therefore, a presigned URL is the appropriate solution.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>Which AWS service can automatically detect and respond to changes in AWS resource configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EventBridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EventBridge can receive events generated by AWS services, including events related to changes in resources and service activity. Rules can match specific events and invoke targets such as Lambda functions, Step Functions, or SNS. This enables automated responses when defined events occur. AWS Config focuses on recording configurations and evaluating compliance, while CloudTrail records API activity and Organizations manages accounts. Therefore, EventBridge is appropriate when a company needs event-driven automation in response to AWS resource or service changes.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>A workload requires a database that can automatically scale to handle unpredictable traffic without database server management. Which service is a strong choice?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon RDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Aurora<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DynamoDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Redshift<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon DynamoDB is a fully managed NoSQL database designed for highly scalable workloads. It can automatically handle changing traffic when configured with suitable capacity modes and can scale throughput according to application requirements. DynamoDB removes the need to manage database servers, operating systems, or traditional database infrastructure. RDS and Aurora are relational database services, while Redshift is designed primarily for analytics and data warehousing. Therefore, DynamoDB is a strong choice for workloads requiring scalable NoSQL storage without database server administration.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>A company wants to route users to the AWS Region with the lowest network latency. Which Route 53 routing policy should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Failover routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Latency-based routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geolocation routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Route 53 latency-based routing directs DNS requests to the Region that provides the lowest network latency from the user&#8217;s location based on AWS latency measurements. This can improve application responsiveness for globally distributed applications. Failover routing is intended for primary and secondary endpoints, weighted routing distributes traffic according to assigned weights, and geolocation routing uses the geographic location of users or resources. Therefore, latency-based routing is the appropriate choice when the objective is to route users toward the lowest-latency AWS Region.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>A company needs to create an isolated testing environment that can be quickly reproduced from a predefined infrastructure configuration. Which approach is most suitable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manually configure every resource<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use AWS CloudFormation templates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create resources only through the console<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use CloudTrail event history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudFormation enables infrastructure to be defined as code using templates. A template can describe networking, compute, databases, security resources, and other infrastructure components. The same template can then be deployed repeatedly to create consistent environments for development, testing, and production. Manual configuration can introduce differences and requires more administrative effort. CloudTrail records API activity but does not provide infrastructure deployment templates. Therefore, CloudFormation is the most suitable approach for creating reproducible testing environments.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>An organization wants to prevent an IAM user from receiving permissions beyond a predefined maximum, even if additional policies are attached later. Which IAM feature should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM permissions boundary<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM access key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM password policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM permissions boundary defines the maximum permissions that an IAM user or role can receive. Even if identity-based policies grant additional permissions, actions outside the boundary cannot be performed. This is useful for delegating permission management while maintaining organizational guardrails. IAM groups organize users and attach policies, access keys provide programmatic authentication, and password policies control password requirements. Therefore, a permissions boundary is the appropriate feature when administrators need to restrict the maximum permissions available to an identity.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>A company stores critical data in S3 and wants protection against accidental deletion while maintaining multiple historical versions of objects. Which configuration should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Select<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Access Points<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Versioning maintains multiple versions of objects in a bucket. If an object is overwritten or deleted, previous versions can remain available, helping recover from accidental changes or deletions. Versioning is also required for several S3 features, including certain replication and Object Lock configurations. Transfer Acceleration improves transfer speed, S3 Select retrieves portions of object data, and Access Points provide alternative access endpoints. Therefore, enabling S3 Versioning is appropriate when historical object versions and recovery from accidental changes are required.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>Which AWS service can provide a managed private certificate authority for issuing certificates to internal applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private CA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS KMS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Private Certificate Authority provides a managed private certificate authority that organizations can use to issue and manage certificates for internal applications and private resources. It supports use cases such as internal TLS, device authentication, and private application communication. AWS Certificate Manager manages public and private certificates but Private CA provides the certificate authority infrastructure and issuance capabilities. Secrets Manager stores secrets, while KMS manages encryption keys. Therefore, AWS Private CA is appropriate when an organization needs a managed private certificate authority.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>A company wants to move an existing VMware-based data center workload to AWS with minimal application changes. Which service should be evaluated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Application Migration Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VMware Cloud on AWS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Database Migration Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VMware Cloud on AWS allows organizations to run VMware-based workloads on AWS infrastructure using familiar VMware technologies. It can be useful when companies want to extend or migrate existing VMware environments while minimizing changes to applications and operational processes. Application Migration Service is designed for server migration, DataSync focuses on data transfer, and DMS targets database migration. Therefore, VMware Cloud on AWS should be evaluated when an organization wants to move VMware workloads while preserving much of its existing virtualization environment.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>A company needs to send a notification to many subscribers whenever an application event occurs. Which service is designed for this publish-subscribe pattern?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Batch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Simple Notification Service supports a publish-subscribe messaging model in which publishers send messages to a topic and multiple subscribers can receive them. Subscribers can include SQS queues, Lambda functions, HTTP endpoints, and other supported destinations. SQS is primarily a message queue where consumers retrieve messages, while Batch handles batch jobs and EBS provides block storage. SNS is therefore appropriate when one application event needs to be distributed to multiple independent subscribers.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>A company needs to analyze petabytes of structured data using complex SQL queries and business intelligence workloads. Which service is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Athena<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Redshift<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DynamoDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ElastiCache<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Redshift is a managed cloud data warehouse designed for large-scale analytics and complex SQL workloads. It can process substantial volumes of structured and semi-structured data and integrate with business intelligence tools. Athena is useful for serverless SQL queries directly against data in S3, but Redshift is better suited to persistent data warehouse workloads requiring repeated complex analytics. DynamoDB is a NoSQL database, while ElastiCache provides in-memory caching. Therefore, Amazon Redshift is the appropriate service for large-scale analytical data warehousing.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>A company wants to protect an API from excessive requests by limiting the number of requests a client can make within a period. Which capability should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">API Gateway throttling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Lifecycle policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 health checks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EBS snapshots<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon API Gateway provides throttling capabilities that can control the rate at which clients invoke APIs. Throttling helps protect backend services from excessive request volumes and can be configured according to API requirements. It can also work alongside usage plans and quotas for supported API configurations. S3 Lifecycle policies manage object transitions and expiration, Route 53 health checks monitor endpoints, and EBS snapshots provide block-storage backups. Therefore, API Gateway throttling is appropriate for controlling excessive API request rates.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>A company wants to ensure that an S3 bucket can only be accessed through a specific VPC endpoint. Which mechanism should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM password policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket policy with a VPC endpoint condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 private hosted zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 bucket policy can restrict access based on the VPC endpoint through which requests are made. Conditions such as the appropriate VPC endpoint identifier can be included in the policy to deny requests that do not originate through the approved endpoint. Security groups do not directly control S3 bucket access, password policies govern IAM passwords, and private hosted zones provide DNS functionality. Therefore, an S3 bucket policy using a VPC endpoint condition is an effective way to enforce private access through a designated endpoint.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>A company needs to transfer files securely using SFTP while storing the transferred data in Amazon S3. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Transfer Family<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon AppFlow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Snowball<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Transfer Family provides managed file transfer services that support protocols such as SFTP, FTPS, and FTP. It can integrate with Amazon S3, allowing organizations to provide familiar file-transfer workflows while storing the resulting data in AWS storage. DataSync is intended for high-speed data movement between supported storage environments, AppFlow focuses on application data integration, and Snowball provides physical data transfer. Therefore, AWS Transfer Family is the appropriate solution for managed SFTP access to S3.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>A company wants to automatically move infrequently accessed S3 objects to lower-cost storage based on access patterns. Which feature should be evaluated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Intelligent-Tiering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Object Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Access Points<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Intelligent-Tiering automatically moves objects between access tiers based on changing access patterns, helping optimize storage costs without requiring the organization to predict when objects will become infrequently accessed. It is useful for data with uncertain or changing access frequency. Object Lock provides retention protection, Access Points simplify access management, and Transfer Acceleration improves data transfer performance. Therefore, S3 Intelligent-Tiering is the appropriate feature when an organization wants automatic storage-cost optimization based on object access behavior.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>A company wants applications in multiple AWS accounts to access a centrally managed service without creating complex VPC peering relationships. Which solution is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS PrivateLink endpoint service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Flow Logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS PrivateLink can expose a service through an endpoint service, allowing consumers in other VPCs or accounts to connect privately without requiring direct VPC peering. This approach helps service providers offer controlled private connectivity to multiple consumers while limiting network exposure. Internet Gateway provides internet connectivity, NAT Gateway supports outbound internet access from private subnets, and VPC Flow Logs record network traffic information. Therefore, PrivateLink is appropriate for privately sharing a centrally managed service across multiple accounts.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>A company needs to automatically run a Lambda function every day at a specific time. Which AWS service can schedule this invocation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EventBridge Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EventBridge Scheduler allows organizations to create scheduled invocations for supported AWS targets, including Lambda functions. It can use one-time or recurring schedules and supports flexible scheduling requirements. This makes it useful for tasks such as daily processing, periodic maintenance, and scheduled automation. SQS provides message queues, Config evaluates resource configurations, and Inspector performs vulnerability assessment. Therefore, EventBridge Scheduler is the appropriate service for invoking a Lambda function automatically at a defined time.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>A company wants to encrypt EBS volumes and snapshots while maintaining control over the encryption key. Which solution should be selected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS KMS customer managed key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EBS integrates with AWS Key Management Service to encrypt volumes and snapshots. Using a customer managed KMS key gives an organization greater control over key policies, permissions, lifecycle management, and auditing than relying solely on AWS-managed encryption keys. Macie focuses on sensitive data discovery, Shield provides DDoS protection, and GuardDuty detects threats. Therefore, an AWS KMS customer managed key is appropriate when EBS encryption is required together with organizational control over the encryption key.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>A company wants to maintain a warm standby application in another AWS Region for disaster recovery. Which approach is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store only application documentation in the secondary Region<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maintain a scaled-down but functional environment in the secondary Region<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete all resources until a disaster occurs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use only a local Availability Zone backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A warm standby disaster recovery strategy maintains a scaled-down but operational version of the application in another Region. During a disaster, the organization can scale the environment and redirect traffic to the secondary Region. This generally provides faster recovery than rebuilding the entire environment from scratch, although it costs more than a backup-and-restore approach because infrastructure remains active. A local Availability Zone backup does not protect against a Region-wide outage. Therefore, maintaining a functional secondary environment is appropriate for warm standby recovery.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>A company wants to improve security by requiring users to authenticate with more than one factor when accessing AWS resources. Which feature should be enabled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM MFA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Flow Logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM multi-factor authentication adds an additional authentication factor to the login process, helping reduce the risk associated with compromised passwords. MFA can be particularly important for privileged users and sensitive operations. S3 Versioning protects object versions, Config monitors resource configurations, and VPC Flow Logs record network traffic metadata. MFA strengthens identity security by requiring users to provide an additional verification factor beyond their password or primary credential. Therefore, IAM MFA is the appropriate feature for strengthening AWS authentication security.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps and Practice Test Dumps. &nbsp; Question 241 A company needs to securely share an S3 object with an external user for a limited period without making the bucket public. Which solution should be used? S3 bucket ACL S3 static website hosting S3 presigned [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15456"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15456"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15456\/revisions"}],"predecessor-version":[{"id":15475,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15456\/revisions\/15475"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}