A medical company wants to perform transformations on a large amount of clinical trial data that comes from several customers. The company must extract the data from a relational databasethatcontains the customer dat
a. Then the company will transform the data by using a series of complex rules. The company will load the data to Amazon S3 when the transformations are complete.
All data must be encrypted where it is processed before the company stores the data in Amazon S3. All data must be encrypted by using customer-specific keys.
Which solution will meet these requirements with the LEAST amount of operational effort?
Answer : C
AWS Glue jobs are designed for extract, transform, and load (ETL) operations, which are perfect for transforming clinical trial data. AWS Glue integrates with AWS Key Management Service (KMS), allowing for customer-specific encryption keys, fulfilling the encryption requirement with minimal operational effort. Client-side encryption with AWS KMS ensures that the data is encrypted before it is sent to S3, aligning with the security needs specified in the scenario.
Key aspects:
AWS Glue: This managed ETL service simplifies data transformation, reduces operational overhead, and integrates seamlessly with KMS.
CSE-KMS: Client-side encryption with KMS ensures that the data is encrypted with customer-specific keys before it is processed or stored in S3, offering robust security.
Minimal Operational Overhead: Compared to managing an EMR cluster, AWS Glue automates much of the process, making it a lower-effort solution.
AWS Documentation: According to the AWS Well-Architected Framework, encryption with AWS KMS offers strong security controls that meet the needs of industries requiring high levels of confidentiality.
A company needs to accommodate traffic for a web application that the company hosts on AWS, especially during peak usage hours.
The application uses Amazon EC2 instances as web servers, an Amazon RDS DB instance for database operations, and an Amazon S3 bucket to store transaction documents. The application struggles to scale effectively and experiences performance issues.
The company wants to improve the scalability of the application and prevent future performance issues. The company also wants to improve global access speeds to the transaction documents for the company's global users.
Which solution will meet these requirements?
Answer : A
This question centers on improving scalability and global access performance.
Auto Scaling groups enable EC2 instances to scale dynamically in response to demand, ensuring availability during peak hours without manual intervention. Amazon RDS read replicas offload read traffic, improving read throughput and reducing latency on the primary database instance. Deploying Amazon CloudFront with S3 as origin accelerates delivery of static transaction documents globally by caching content at edge locations, reducing latency for users worldwide.
Option B focuses on vertical scaling (larger instances) and caching with ElastiCache, but it does not address global content delivery optimally. AWS Global Accelerator accelerates network traffic but is better suited for accelerating TCP and UDP traffic; CloudFront is generally preferred for HTTP content delivery.
Option C migrates workloads to Lambda and Aurora global databases, which is an advanced and potentially costly redesign that may not be necessary. Option D suggests moving to ECS and multi-AZ RDS but does not address global content delivery efficiently.
Therefore, option A uses proven scalability and caching best practices aligned with AWS Well-Architected Framework pillars for performance and operational excellence.
References:
AWS Well-Architected Framework --- Performance Efficiency Pillar (https://d1.awsstatic.com/whitepapers/architecture/AWS_Well-Architected_Framework.pdf)
Amazon EC2 Auto Scaling (https://docs.aws.amazon.com/autoscaling/ec2/userguide/what-is-amazon-ec2-auto-scaling.html)
Amazon RDS Read Replicas (https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ReadRepl.html)
Amazon CloudFront Overview (https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/Introduction.html)
A company wants to grant an external vendor temporary, limited access to an Amazon S3 bucket to download files. The company does not want the external vendor to have access to the bucket for a long period of time.
Which solution will meet these requirements in the MOST secure way?
Answer : C
Amazon S3 presigned URLs are the most secure fit because they providetime-limited access to specific objectswithout requiring the external vendor to have AWS credentials or direct bucket permissions. AWS documentation states that presigned URLs grant temporary access to private S3 objects and can be used for downloads through a browser or program. This is stronger than creating an IAM user or sharing temporary keys because those methods still expose AWS credentials to a third party. A bucket policy based only on source IP is broader and less precise than object-level, time-bounded access. Presigned URLs let the company control exactlywhich objectcan be downloaded andfor how long, which is exactly what the scenario requires. (AWS Documentation)
============
A company is developing a containerized web application that needs to be highly available and scalable. The application requires access to GPU resources.
Answer : D
Why Option D is Correct:
GPU Access: Only EC2 instances in the GPU family (e.g., P2, P3) can provide GPU resources.
ECS Orchestration: Simplifies container deployment and management.
Why Other Options Are Not Ideal:
Option A: Lambda does not support GPU-based runtimes.
Option B: AWS Fargate does not support GPU-based workloads.
Option C: ECR is a container registry, not an orchestration or execution service.
AWS References:
Amazon ECS with GPU Instances:AWS Documentation - ECS GPU Instances
An ecommerce company runs a transaction processing system within a large application on a set of Amazon EC2 instances behind an Application Load Balancer ALB. The transaction process handles order creation, payment initiation, and inventory updates.
The company has observed performance issues in the transaction workflow as the volume of transactions has increased. The company wants to re-architect the transaction process to introduce horizontal scalability and to improve cost efficiency.
Which solution will meet these requirements?
Answer : A
Option A is the best answer because it introduces both decoupling and horizontal scalability with minimal infrastructure management. API Gateway provides a managed front door for the microservices, Lambda provides serverless compute that scales with request volume, and SQS provides durable buffering between transactional stages such as order creation and payment processing. AWS recommends queue-based decoupling when producers and consumers operate at different speeds or when spikes must be absorbed without losing work. The EKS and EC2 alternatives add significantly more operational burden, and caching does not solve the core workflow-scaling issue. Therefore, a serverless microservices architecture using API Gateway, Lambda, and SQS is the best fit.
============
A company is running a two-tier web-based application in an on-premises data center. The application layer consists of a single server running a stateful application. The application connects to a PostgreSQL database running on a separate server. The user base is expected to grow significantly, so the company is migrating the application and database to AWS. The solution will use Amazon Aurora PostgreSQL, Amazon EC2 Auto Scaling, and Elastic Load Balancing.
Which solution will provide a consistent user experience that will allow the application and database tiers to scale?
Answer : C
The application is described as stateful, which means user sessions or state are likely stored in memory on the application server. When migrating to an Auto Scaling group behind a load balancer, a consistent user experience typically requires session stickiness, so a user's subsequent requests continue to be routed to the same backend instance that holds their session state (unless the application is refactored to externalize session state, which is not stated here). For HTTP/HTTPS web applications, an Application Load Balancer (ALB) is the correct Elastic Load Balancing choice because it operates at Layer 7 and provides built-in support for cookie-based sticky sessions.
On the database side, Aurora PostgreSQL supports scaling read capacity by adding Aurora Replicas, and Aurora Auto Scaling can automatically adjust the number of replicas based on demand. This is the intended mechanism to scale the database tier for growing read traffic while preserving write consistency through a single writer. ''Aurora writers'' do not scale horizontally the same way; Aurora provides one writer endpoint at a time (with fast failover), so auto-scaling ''writers'' is not the right construct for demand-based scaling.
Option C combines the correct load balancer type (ALB) with stickiness and the correct database scaling mechanism (Aurora Replicas with auto scaling). Option A uses an NLB, which is Layer 4 and does not provide the same Layer 7 sticky session behavior expected for a web application pattern. Options B and D incorrectly focus on scaling Aurora writers, which does not address scaling demand patterns as effectively as scaling read replicas.
Therefore, C provides the most consistent user experience for a stateful web tier and enables the database tier to scale using Aurora Replica auto scaling.
A company is migrating an on-premises data center to the AWS Cloud. The company is using Amazon FSx for Windows File Server to perform test deployments into a single Availability Zone. After testing, the company determines that it needs to improve availability and fault tolerance for its shared Windows file system.
Which solution will meet these requirements?
Answer : C
Amazon FSx for Windows File Server supports Multi-AZ deployment for higher availability and automatic failover across Availability Zones. Because the existing file system was created as a Single-AZ deployment, the practical migration path is to create a new Multi-AZ FSx for Windows File Server file system and migrate the data. AWS DataSync is the appropriate managed service for transferring file data between file systems, including SMB-based storage. AWS Transfer Family is for managed file transfer protocols such as SFTP, FTPS, and FTP, not for replicating an FSx Windows file system for migration. AWS DMS is for database migration, not file-system migration. Simply shutting down the existing file system does not convert the deployment type in place.