AWS Solutions Architect Associate Practice Questions
These original AWS Solutions Architect Associate questions practise security, resilience, performance, and cost decisions.
- Choose before reading each answer, then explain why the alternatives miss a requirement.
- They are independent study items, not AWS exam questions, a full mock, or a predictor of the official scaled result.
On this page7 sections
- How to use these questions
- Question 1: secure application access
- Question 2: survive a zone failure and restore deleted data
- Question 3: shared file access
- Question 4: variable, interruptible batch work
- Review the choice against the workload
- Question 5: select storage for infrequent retrieval A company must retain completed project files for several years. Staff rarely retrieve them, and retrieval can take longer than for frequently used data. Which approach best matches the stated access pattern? A. Keep every object on the highest-performance storage tier B. Use a suitable archival storage class with lifecycle rules and a retrieval plan C. Store a separate full copy on every application server D. Delete files immediately after project completion Answer: B. The requirement accepts infrequent access and longer retrieval, so an archival class and lifecycle policy can reduce ongoing storage cost while preserving a defined path to retrieve data. The design still needs retention and recovery decisions. A prioritizes performance the workload does not need, C creates unnecessary copies and operations, and D violates the retention requirement. Question 6: isolate a compromised workload An application server is confirmed to be sending unauthorized traffic. The organization wants to contain the instance while preserving evidence for investigation. Which action best fits the immediate need? A. Delete the instance and its attached data immediately B. Restrict the instance's network access under the response plan and preserve relevant evidence C. Increase the instance size so the application can process requests faster D. Open additional inbound ports for troubleshooting Answer: B. The scenario is about containment and investigation. Limiting network paths can reduce ongoing communication while preserving the state and evidence needed for review. Deleting the instance first may destroy useful evidence. Scaling compute or opening ports does not address the unauthorized traffic and can increase exposure. How to review architecture choices For each answer, state the service category and the workload condition it satisfies. Then identify one tradeoff. For the archive example, retrieval latency is accepted in exchange for lower storage cost. For incident containment, availability may be reduced temporarily to limit exposure. A tradeoff statement helps distinguish a deliberate design from a list of product names. After reviewing a question, change one requirement. If the records are accessed every hour, would the archive remain suitable? If the compromised instance must stay available for a critical business function, what additional isolation or failover action could preserve service safely? The revised facts may change the best answer, which shows whether you learned the decision rule or just the original key. Use these as independent practice, not a forecast of the live exam. The exam combines scored and unscored items, and its scaled score cannot be inferred from an article's examples. Track whether you can explain the design and eliminate distractors, then move to new scenarios across all four domains.
How to use these questions
Read the scenario, identify the requirement, and select an option before reviewing the explanation. Notice whether the item asks for one answer or multiple responses. On a multiple-response item, every chosen option should be supported by the facts. The examples are original and do not copy or reconstruct AWS’s protected test questions.
AWS presents 65 exam questions, including unscored items that are not identified. Four samples cannot simulate that exam or estimate a 720 scaled score. Use them to practise decision logic, then study with the current exam guide and suitable official preparation materials.
Question 1: secure application access
A web application on compute instances needs to read customer files from an object storage bucket. The files must not be public, and the application should have access only to the required bucket. Which design best meets the need?
- Make the bucket public and rely on the application login page to protect files.
- Store a long-lived access key in the application source code and restrict access in the user interface.
- Keep the bucket private and grant the application’s service role the minimum required permissions.
- Copy files to an instance volume and disable logging to reduce exposure.
Correct answer: C. Private storage and a scoped service role let the application retrieve only the needed objects without distributing long-lived credentials. A is publicly exposed. B places credentials in code and user-interface checks do not secure the storage API. D adds unmanaged copies and removes useful audit evidence without solving authorization.
Question 2: survive a zone failure and restore deleted data
An order system must remain available if one Availability Zone fails. It must also recover when an administrator accidentally deletes records. Which pair of design measures addresses both requirements?
- Use a Multi-AZ database configuration for availability and maintain tested backups or point-in-time recovery for accidental deletion.
- Use a read replica as the only protection for both failures.
- Increase the database instance size and distribute application traffic through a load balancer.
- Store database snapshots on the same instance and remove the application health checks.
Correct answer: A. A Multi-AZ design addresses infrastructure availability, while backups or point-in-time recovery provide a way to restore from logical deletion. A read replica may help with reads or failover but can reflect accidental changes. Instance size and a load balancer do not provide a data recovery point. A backup should be separate and tested.
Question 3: shared file access
A fleet of Linux application instances in multiple Availability Zones must concurrently access the same hierarchical directory tree. The files change frequently and need low-latency shared access. Which storage pattern is the best fit?
- Attach a separate block volume to each instance and assume each volume automatically synchronizes.
- Use an object storage bucket as a mounted shared file system without an additional service.
- Use a managed shared file system designed for concurrent access by multiple Linux instances.
- Move the files to an archival storage class and retrieve them for each request.
Correct answer: C. The workload requires a shared hierarchical file system for concurrent Linux clients, which points to a managed file service. Separate block volumes do not automatically synchronize. Object storage provides objects rather than the required file-system semantics. Archival storage is unsuitable for frequent low-latency changes.
Question 4: variable, interruptible batch work
A data team runs batch image processing that can pause and resume without losing work. Demand varies widely, and minimizing compute cost is more important than finishing at an exact time. Which approach is most appropriate?
- Run all processing on fixed, continuously running high-capacity instances.
- Use interruption-tolerant compute capacity for workers, persist progress, and retry interrupted tasks.
- Run the workload on a single instance with no checkpointing and no retry logic.
- Move all input images to a slower archive tier while the job processes them continuously.
Correct answer: B. The workload can tolerate interruption, so interruptible capacity can reduce cost when progress is persisted and tasks can resume. A pays for peak capacity continuously. C loses work and offers no recovery. D may add retrieval delay and does not address compute cost.
Review the choice against the workload
Across the examples, the requirement determines the service pattern. Private access points to scoped identity and permissions. Availability and logical recovery need different controls. Shared file semantics differ from object or block storage. Interruptible compute is suitable only when the workload can resume safely.
After each question, change one fact and predict whether the answer changes. If the Linux clients no longer need a shared directory, object storage may become suitable. If a batch job cannot be interrupted, its compute strategy changes. If data must be restored to a point in time, a backup feature becomes essential even when a database spans zones.
A useful review log records the missed requirement, the distractor’s flaw, and the fact that would make that distractor preferable. This avoids memorizing isolated product choices and builds transferable architecture judgment.
Question 5: select storage for infrequent retrieval A company must retain completed project files for several years. Staff rarely retrieve them, and retrieval can take longer than for frequently used data. Which approach best matches the stated access pattern? A. Keep every object on the highest-performance storage tier B. Use a suitable archival storage class with lifecycle rules and a retrieval plan C. Store a separate full copy on every application server D. Delete files immediately after project completion Answer: B. The requirement accepts infrequent access and longer retrieval, so an archival class and lifecycle policy can reduce ongoing storage cost while preserving a defined path to retrieve data. The design still needs retention and recovery decisions. A prioritizes performance the workload does not need, C creates unnecessary copies and operations, and D violates the retention requirement. Question 6: isolate a compromised workload An application server is confirmed to be sending unauthorized traffic. The organization wants to contain the instance while preserving evidence for investigation. Which action best fits the immediate need? A. Delete the instance and its attached data immediately B. Restrict the instance's network access under the response plan and preserve relevant evidence C. Increase the instance size so the application can process requests faster D. Open additional inbound ports for troubleshooting Answer: B. The scenario is about containment and investigation. Limiting network paths can reduce ongoing communication while preserving the state and evidence needed for review. Deleting the instance first may destroy useful evidence. Scaling compute or opening ports does not address the unauthorized traffic and can increase exposure. How to review architecture choices For each answer, state the service category and the workload condition it satisfies. Then identify one tradeoff. For the archive example, retrieval latency is accepted in exchange for lower storage cost. For incident containment, availability may be reduced temporarily to limit exposure. A tradeoff statement helps distinguish a deliberate design from a list of product names. After reviewing a question, change one requirement. If the records are accessed every hour, would the archive remain suitable? If the compromised instance must stay available for a critical business function, what additional isolation or failover action could preserve service safely? The revised facts may change the best answer, which shows whether you learned the decision rule or just the original key. Use these as independent practice, not a forecast of the live exam. The exam combines scored and unscored items, and its scaled score cannot be inferred from an article's examples. Track whether you can explain the design and eliminate distractors, then move to new scenarios across all four domains.
Question 5: select storage for infrequent retrieval A company must retain completed project files for several years. Staff rarely retrieve them, and retrieval can take longer than for frequently used data. Which approach best matches the stated access pattern? A. Keep every object on the highest-performance storage tier B. Use a suitable archival storage class with lifecycle rules and a retrieval plan C. Store a separate full copy on every application server D. Delete files immediately after project completion Answer: B. The requirement accepts infrequent access and longer retrieval, so an archival class and lifecycle policy can reduce ongoing storage cost while preserving a defined path to retrieve data. The design still needs retention and recovery decisions. A prioritizes performance the workload does not need, C creates unnecessary copies and operations, and D violates the retention requirement. Question 6: isolate a compromised workload An application server is confirmed to be sending unauthorized traffic. The organization wants to contain the instance while preserving evidence for investigation. Which action best fits the immediate need? A. Delete the instance and its attached data immediately B. Restrict the instance's network access under the response plan and preserve relevant evidence C. Increase the instance size so the application can process requests faster D. Open additional inbound ports for troubleshooting Answer: B. The scenario is about containment and investigation. Limiting network paths can reduce ongoing communication while preserving the state and evidence needed for review. Deleting the instance first may destroy useful evidence. Scaling compute or opening ports does not address the unauthorized traffic and can increase exposure. How to review architecture choices For each answer, state the service category and the workload condition it satisfies. Then identify one tradeoff. For the archive example, retrieval latency is accepted in exchange for lower storage cost. For incident containment, availability may be reduced temporarily to limit exposure. A tradeoff statement helps distinguish a deliberate design from a list of product names. After reviewing a question, change one requirement. If the records are accessed every hour, would the archive remain suitable? If the compromised instance must stay available for a critical business function, what additional isolation or failover action could preserve service safely? The revised facts may change the best answer, which shows whether you learned the decision rule or just the original key. Use these as independent practice, not a forecast of the live exam. The exam combines scored and unscored items, and its scaled score cannot be inferred from an article's examples. Track whether you can explain the design and eliminate distractors, then move to new scenarios across all four domains.
Common questions
Are these official AWS exam questions?
No. They are original examples for study.
Can they predict a passing score?
No. They are a short set without an official score conversion.
How many answers can multiple-response questions require?
Two or more correct responses from at least five options.
What should I review after a miss?
Identify the requirement, service tradeoff, and assumption that led to the error.
Is this a full mock exam?
No. The examples do not reproduce the official exam or testing interface.