{"id":15457,"date":"2026-09-18T05:21:17","date_gmt":"2026-09-18T05:21:17","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15457"},"modified":"2026-09-18T05:21:17","modified_gmt":"2026-09-18T05:21:17","slug":"amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-solutions-architect-professional-sap-c02-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-solutions-architect-professional-sap-c02-exam-dumps\"><b>Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 261<\/b><\/h3>\n<p><b>A company wants to provide temporary access to an S3 object without changing the bucket&#8217;s public access settings. Which option is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 presigned URL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 static website hosting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 presigned URL grants temporary access to a specific S3 object without requiring the object or bucket to become publicly accessible. The URL contains temporary authorization information and can be configured with an expiration period. This makes it useful for applications that need to provide controlled downloads or uploads to users without giving them AWS credentials. Bucket ACLs provide access controls but are not designed for temporary URL-based access. Therefore, a presigned URL is the appropriate solution.<\/span><\/p>\n<h3><b>Question 262<\/b><\/h3>\n<p><b>A company operates an application in several AWS Regions and wants users to be directed to the Region that is geographically closest to them. Which Route 53 routing policy should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Failover routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geolocation routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Simple routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Route 53 geolocation routing directs traffic based on the geographic location of users. Organizations can create routing rules for countries, continents, or other supported geographic areas and direct users to appropriate endpoints. This can be useful when applications need regional content, regulatory separation, or location-specific services. Weighted routing distributes traffic according to assigned percentages, failover routing focuses on primary and secondary endpoints, and simple routing provides basic DNS responses. Therefore, geolocation routing is appropriate when routing decisions depend on user location.<\/span><\/p>\n<h3><b>Question 263<\/b><\/h3>\n<p><b>Which AWS service provides a managed message broker supporting protocols such as AMQP and MQTT?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon MQ<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SQS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon SNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EventBridge<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon MQ is a managed message broker service that supports established messaging technologies such as Apache ActiveMQ and RabbitMQ. It is useful when organizations are migrating applications that already depend on traditional messaging protocols and broker capabilities. SQS provides managed queues, SNS provides publish-subscribe messaging, and EventBridge provides event routing. Amazon MQ can reduce the operational effort associated with managing message brokers while maintaining compatibility with supported messaging applications. Therefore, Amazon MQ is appropriate for workloads requiring traditional managed message-broker functionality.<\/span><\/p>\n<h3><b>Question 264<\/b><\/h3>\n<p><b>A company wants to protect an application from large-scale distributed denial-of-service attacks and requires enhanced visibility and response capabilities. Which service should be evaluated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield Advanced<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Shield Advanced provides enhanced DDoS protection for supported AWS resources. It includes additional detection and mitigation capabilities, visibility into attacks, and features designed for organizations with more demanding DDoS protection requirements. AWS WAF focuses on filtering web requests, GuardDuty provides threat detection, and Config evaluates resource configurations. Shield Advanced is specifically designed for stronger DDoS protection beyond the capabilities provided by Shield Standard. Therefore, Shield Advanced should be evaluated for workloads requiring enhanced DDoS protection and visibility.<\/span><\/p>\n<h3><b>Question 265<\/b><\/h3>\n<p><b>A company needs to maintain a highly available application across Availability Zones and automatically replace unhealthy EC2 instances. Which service combination is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53 and Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EC2 Auto Scaling and Elastic Load Balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail and AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS and Amazon EFS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EC2 Auto Scaling can monitor instance health and replace unhealthy instances while maintaining the desired capacity. Elastic Load Balancing distributes incoming requests across healthy targets and can stop routing traffic to unhealthy instances. Together, these services provide a resilient application architecture across multiple Availability Zones. Route 53 and S3 provide DNS and storage capabilities, while CloudTrail and Config address auditing and configuration management. Therefore, EC2 Auto Scaling combined with Elastic Load Balancing is appropriate for this highly available architecture.<\/span><\/p>\n<h3><b>Question 266<\/b><\/h3>\n<p><b>Which AWS service provides a managed relational database engine compatible with MySQL while reducing administrative tasks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DynamoDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon RDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Neptune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon OpenSearch Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon RDS supports MySQL as a managed relational database engine and handles many infrastructure administration tasks. These include provisioning, automated backups, software patching, and maintenance according to the configured options. DynamoDB is a NoSQL database, Neptune is a graph database, and OpenSearch Service provides search and analytics functionality. RDS is useful when an application requires traditional relational database capabilities without the organization having to manage database servers directly. Therefore, Amazon RDS is the appropriate service for a managed MySQL database.<\/span><\/p>\n<h3><b>Question 267<\/b><\/h3>\n<p><b>A company wants to reduce database load by caching frequently requested data in memory. Which architecture is most suitable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3 directly in front of the database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ElastiCache between the application and database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail between the application and database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config between the application and database<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon ElastiCache can be placed between an application and a database to cache frequently accessed data in memory. When requested data is available in the cache, the application can retrieve it without querying the database, reducing database load and improving response times. S3 is object storage and is not a direct database cache, while CloudTrail and Config provide auditing and configuration capabilities. Therefore, using ElastiCache between the application and database is an appropriate architecture for reducing repeated database queries.<\/span><\/p>\n<h3><b>Question 268<\/b><\/h3>\n<p><b>A company wants to ensure that only encrypted HTTPS traffic can reach an internet-facing Application Load Balancer. Which configuration should be implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure an HTTPS listener and redirect or reject HTTP traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use an S3 bucket policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable DynamoDB encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure an SQS dead-letter queue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Application Load Balancer can use an HTTPS listener with an appropriate TLS certificate to provide encrypted connections. Organizations can configure an HTTP listener to redirect requests to HTTPS or otherwise restrict unencrypted access according to the application design. S3 policies, DynamoDB encryption, and SQS dead-letter queues address different requirements and do not control inbound ALB protocol usage. Therefore, configuring HTTPS and ensuring HTTP traffic is redirected or rejected is the appropriate approach for enforcing encrypted client connections.<\/span><\/p>\n<h3><b>Question 269<\/b><\/h3>\n<p><b>A company needs to automatically detect sensitive information stored in S3 and receive findings about potential data exposure. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Macie is designed to discover and classify sensitive data stored in Amazon S3. It can identify certain types of sensitive information and provide findings that help organizations understand potential data exposure and security risks. Inspector focuses on vulnerability assessment for supported workloads, Shield protects against DDoS attacks, and WAF filters web requests. Therefore, Macie is the appropriate service when the primary requirement is discovering sensitive information in S3 and identifying related risks.<\/span><\/p>\n<h3><b>Question 270<\/b><\/h3>\n<p><b>A company needs to securely connect its corporate network to AWS and wants encrypted connectivity over the public internet. Which solution should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Direct Connect only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Site-to-Site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Peering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Site-to-Site VPN creates encrypted tunnels between an on-premises network and an Amazon VPC over the public internet. It is commonly used when organizations need secure hybrid connectivity without establishing a dedicated private circuit. Direct Connect provides dedicated connectivity but does not itself provide encryption by default. CloudFront is a content delivery service, and VPC Peering connects VPCs rather than an on-premises network. Therefore, Site-to-Site VPN is appropriate when encrypted connectivity over the public internet is required.<\/span><\/p>\n<h3><b>Question 271<\/b><\/h3>\n<p><b>A company wants to automatically invoke a Lambda function when a new object is uploaded to an S3 bucket. Which integration is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Event Notifications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Direct Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon S3 Event Notifications can trigger actions when events occur in an S3 bucket, including object creation. Notifications can integrate with services such as Lambda, SQS, and SNS, enabling event-driven application architectures. This allows a Lambda function to process newly uploaded objects automatically without continuous polling. Direct Connect provides network connectivity, EBS provides block storage, and Organizations manages AWS accounts. Therefore, S3 Event Notifications are appropriate for triggering Lambda when new objects are uploaded.<\/span><\/p>\n<h3><b>Question 272<\/b><\/h3>\n<p><b>A company wants to reduce the cost of running a fault-tolerant, flexible workload that can tolerate interruptions. Which EC2 purchasing option should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reserved Instances<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dedicated Hosts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spot Instances<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">On-Demand Instances<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EC2 Spot Instances use spare AWS compute capacity and can provide significant cost savings compared with On-Demand pricing. Because Spot capacity can be interrupted when AWS needs the capacity back, this option is most appropriate for workloads that are flexible, fault tolerant, or able to retry interrupted tasks. Reserved Instances are useful for predictable long-term workloads, Dedicated Hosts provide dedicated physical capacity, and On-Demand Instances provide flexible capacity without long-term commitments. Therefore, Spot Instances are suitable for interruption-tolerant workloads.<\/span><\/p>\n<h3><b>Question 273<\/b><\/h3>\n<p><b>Which AWS service can provide a managed private DNS namespace for resources inside a VPC?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53 private hosted zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Global Accelerator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Route 53 private hosted zone provides DNS records that can be resolved within associated VPCs. It is useful for applications that need internal domain names for services, databases, load balancers, or other private resources. Private hosted zones can help organizations create clean service naming structures without exposing internal DNS records publicly. CloudFront provides content delivery, Global Accelerator optimizes global application traffic, and WAF filters web requests. Therefore, a Route 53 private hosted zone is appropriate for private DNS resolution within a VPC.<\/span><\/p>\n<h3><b>Question 274<\/b><\/h3>\n<p><b>A company wants to continuously replicate selected objects from an S3 bucket in one Region to another Region for disaster recovery. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Lifecycle<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Cross-Region Replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Access Points<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Select<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Cross-Region Replication can automatically replicate eligible objects from a source bucket to a destination bucket in another AWS Region. This can support disaster recovery, compliance, data locality, and other multi-Region requirements. Lifecycle rules manage object transitions and expiration, Access Points provide alternative access endpoints, and S3 Select allows applications to retrieve portions of object data. Therefore, Cross-Region Replication is the appropriate feature when selected S3 data must be continuously replicated to another Region.<\/span><\/p>\n<h3><b>Question 275<\/b><\/h3>\n<p><b>A company wants to centralize logs from multiple AWS services and applications and perform searches and analysis on those logs. Which solution is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudWatch Logs with a centralized log analysis solution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Snowball<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EBS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon CloudWatch Logs can collect application and AWS service logs in centralized log groups. Organizations can then use CloudWatch capabilities or integrate logs with analytics services such as OpenSearch Service for more advanced searching and analysis. Centralized logging helps teams troubleshoot applications, investigate security events, and monitor operational behavior across multiple environments. Route 53 provides DNS, Snowball handles physical data transfers, and EBS provides block storage. Therefore, CloudWatch Logs with an appropriate centralized analysis architecture is suitable for this requirement.<\/span><\/p>\n<h3><b>Question 276<\/b><\/h3>\n<p><b>A company needs a database that supports graph relationships between entities such as users, products, and connections. Which AWS service should be selected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Neptune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Redshift<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ElastiCache<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Neptune is a managed graph database service designed for workloads that represent highly connected data. It supports graph use cases such as recommendation systems, social networks, knowledge graphs, and relationship analysis. Redshift is a data warehouse, S3 is object storage, and ElastiCache provides in-memory caching. Graph databases are particularly useful when application queries depend heavily on relationships between entities rather than traditional rows and columns. Therefore, Amazon Neptune is the appropriate service for graph-oriented workloads.<\/span><\/p>\n<h3><b>Question 277<\/b><\/h3>\n<p><b>A company wants to automate account provisioning and apply standardized governance controls whenever new AWS accounts are created. Which service should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Control Tower<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Control Tower provides capabilities for establishing and governing multi-account AWS environments. It can help automate account provisioning while applying standardized organizational controls and guardrails. This is useful for enterprises that need consistent security, networking, logging, and governance configurations across newly created accounts. S3 provides object storage, CloudFront provides content delivery, and DataSync handles data transfers. Therefore, Control Tower is appropriate when standardized account creation and centralized governance are required.<\/span><\/p>\n<h3><b>Question 278<\/b><\/h3>\n<p><b>A company wants to identify AWS resources that are generating unnecessary costs because they are significantly underutilized. Which service can provide recommendations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Trusted Advisor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Trusted Advisor provides recommendations across several areas, including cost optimization, security, performance, fault tolerance, and service limits. Depending on account and support-plan capabilities, it can identify certain opportunities to reduce unnecessary spending and improve resource usage. Certificate Manager handles certificates, GuardDuty detects security threats, and Route 53 provides DNS services. Trusted Advisor is therefore useful when an organization wants AWS recommendations covering potential cost-saving opportunities and other best-practice areas.<\/span><\/p>\n<h3><b>Question 279<\/b><\/h3>\n<p><b>A company needs to make an existing application available globally while keeping its backend resources in multiple AWS Regions. Which service can provide static anycast IP addresses and intelligent routing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53 Resolver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Global Accelerator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS DataSync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Global Accelerator provides static anycast IP addresses and routes traffic through the AWS global network to healthy application endpoints. It can distribute traffic across supported resources in multiple AWS Regions and improve availability and performance. Route 53 Resolver handles DNS resolution, DataSync transfers data, and S3 provides object storage. Global Accelerator is particularly useful when applications need stable global entry points and fast failover between regional endpoints. Therefore, AWS Global Accelerator is appropriate for this architecture.<\/span><\/p>\n<h3><b>Question 280<\/b><\/h3>\n<p><b>A company needs to automatically archive large amounts of rarely accessed data for many years at the lowest possible storage cost. Which S3 storage class should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Standard-IA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Glacier Deep Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Intelligent-Tiering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Glacier Deep Archive is designed for long-term retention of data that is rarely accessed and can tolerate longer retrieval times. It is suitable for use cases such as regulatory archives, historical records, and long-term backups where minimizing storage cost is more important than rapid access. S3 Standard is intended for frequently accessed data, Standard-IA targets infrequently accessed data with faster retrieval, and Intelligent-Tiering automatically moves objects between access tiers. Therefore, Glacier Deep Archive is appropriate for long-term, rarely accessed archives.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Solutions Architect &#8211; Professional SAP-C02 Exam Dumps and Practice Test Dumps. &nbsp; Question 261 A company wants to provide temporary access to an S3 object without changing the bucket&#8217;s public access settings. Which option is most appropriate? S3 bucket ACL S3 presigned URL S3 static website hosting S3 Transfer Acceleration [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15457"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15457"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15457\/revisions"}],"predecessor-version":[{"id":15474,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15457\/revisions\/15474"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}