75 free questions · No sign-up required to browse
Comprehensive practice exam for the AWS Certified Solutions Architect - Professional (SAP-C02) certification. Covers complex enterprise architectures, multi-account strategies, migration, and continuous improvement.
A global enterprise requires highly available hybrid connectivity between its on-premises data centers in New York and London to AWS VPCs in us-east-1 and eu-west-2. The solution must provide line-rate encryption and protect against a single AWS Direct Connect location failure. Which architecture meets these requirements with the LEAST operational overhead?
An organization has 50 VPCs across two AWS Regions connected via Transit Gateways (TGW). The TGWs are peered. The security team mandates that all inter-VPC traffic must be inspected by a centralized fleet of third-party firewall appliances. How should the architect design this network?
A company uses AWS Organizations. The network team wants to share a central Transit Gateway (TGW) with all AWS accounts in the organization. They want new accounts to automatically have access to the TGW without manual intervention. What is the MOST efficient solution?
An enterprise has on-premises data centers in the US and Europe. They want to use the AWS global network to route traffic between these two on-premises locations. They have Direct Connect connections in both regions. Which feature should they enable?
A company requires that all API calls to Amazon S3 from their VPC must not traverse the public internet. Furthermore, access to S3 must be restricted to only a specific S3 bucket owned by the company. How should the architect implement this?
All 75 questions with worked answers, mark schemes, and AI tutoring.