dc dotCreds
AWS Certified Solutions Architect - Professional

AWS Solutions Architect Professional Practice Test

Start today's 10-question AWS Solutions Architect Professional set with source-backed explanations, local progress, and a fresh rotation every morning.

10 daily web questions Source-backed explanations 7-day score history Questions updated at Jun 17, 2026, 9:57 PM CDT
AWS Solutions Architect Professional icon

AWS Solutions Architect Professional

AWS Certified Solutions Architect - Professional

Why this page works

  • Daily exam-aligned questions
  • Source links on every explanation
  • Local progress saved automatically
  • Email sync path ready for later
  • Apps provide deeper drills when available
One-time unlock

Unlock the full SAP-C02 bank

Get 120 verified questions, every choice explained, Exam Mode, Practice Mode, random tests, readiness tracking, previous scores, and no ads.

Secure checkout by Stripe. Instant unlock on this page. No subscription.

See bundle and PDF options Already Pro? Open dashboard

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Today's 10 AWS Solutions Architect Professional questions

Use this AWS Solutions Architect Professional practice test to review AWS Certified Solutions Architect Professional. Questions rotate daily and each explanation links to the source used to validate the answer.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

120 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Question 1 of 10
Objective SAP-C02-migration Migration and Modernization

When practicing AWS Solutions Architect Professional, which option belongs under Migration and Modernization?

Concept tested: Migration and Modernization (SAP-C02-migration)
Question 2 of 10
Objective SAP-C02-cost Cost Optimization

When practicing AWS Solutions Architect Professional, which option belongs under Cost Optimization?

Concept tested: Cost Optimization (SAP-C02-cost)
Question 3 of 10
Objective SAP-C02-security Security Design

An enterprise wants to establish a secure database connection from an application running in a private subnet on AWS VPC to a database running in their on-premises data center. All network traffic must be encrypted, must not traverse the public internet, and must support high bandwidth (up to 10 Gbps) with consistent network latency. Which solution meets these requirements?

Concept tested: Security Design (SAP-C02-security)
Question 4 of 10
Objective SAP-C02-networking Hybrid and Network Design

A learner is reviewing SAP-C02-networking. What should they remember?

Concept tested: Hybrid and Network Design (SAP-C02-networking)
Question 5 of 10
Objective SAP-C02-resilience Resilient Architectures

When practicing AWS Solutions Architect Professional, which option belongs under Resilient Architectures?

Concept tested: Resilient Architectures (SAP-C02-resilience)
Question 6 of 10
Objective SAP-C02-organizations Organizational Complexity

A multi-national enterprise wants to establish a secure multi-account environment on AWS. They require centralized governance, logging, and security guardrails across 100+ accounts. Additionally, they must ensure that no member account can disable CloudTrail logging or alter the security configurations deployed by the central security team. Which solution meets these requirements?

Concept tested: Organizational Complexity (SAP-C02-organizations)
Question 7 of 10
Objective SAP-C02-migration Migration and Modernization

Which answer is the best source-backed summary of Migration and Modernization for this AWS Certified Solutions Architect - Professional topic?

Concept tested: Migration and Modernization (SAP-C02-migration)
Question 8 of 10
Objective SAP-C02-cost Cost Optimization

What is the safest study takeaway for Cost Optimization?

Concept tested: Cost Optimization (SAP-C02-cost)
Question 9 of 10
Objective SAP-C02-security Security Design

When practicing AWS Solutions Architect Professional, which option belongs under Security Design?

Concept tested: Security Design (SAP-C02-security)
Question 10 of 10
Objective SAP-C02-networking Hybrid and Network Design

When practicing AWS Solutions Architect Professional, which option belongs under Hybrid and Network Design?

Concept tested: Hybrid and Network Design (SAP-C02-networking)
Locked preview

You are viewing today’s free 10. Unlock 110 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SAP-C02 Pro $4.99 one-time

Unlock all 120 AWS Solutions Architect Professional questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question SAP-C02 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Full Practice Test $5.99 one-time

The full SAP-C02 printable set with 120 questions, plus this exam's Pro access on dotCreds.

We will ask for your site email in a quick checkout step, remember it on this browser, and use it again for restore.

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SAP-C02 bank. No ads.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

120 full-bank questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 110 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

No ads

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SAP-C02 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Official exam resources

Use these official AWS resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent AWS practice pages too? AWS practice hub.

Source-backed answer review

The free daily AWS Solutions Architect Professional set includes crawlable question text, answer choices, the correct answer explanation, wrong-answer distractor explanations when the reviewed bank provides them, objective mapping, and source links. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 When practicing AWS Solutions Architect Professional, which option belongs under Migration and Modernization?

Answer choices

  1. A. Migration strategy begins by deleting discovery data.
  2. B. Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.
  3. C. Modernization means every workload must become a single virtual machine.
  4. D. Application dependencies never affect migration order.

Correct answer

Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.

Correct answer: Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations. Architects need to choose practical migration and modernization paths based on constraints and outcomes.

Wrong-answer review

  • A. Migration strategy begins by deleting discovery data.: This distractor describes the idea that Migration strategy begins by deleting discovery data. In "When practicing AWS Solutions Architect Professional, which option belongs under Migration and Modernization?", that misses the required action because the correct response is "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.". On the job, mixing up that distractor with "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations." can lead to the wrong migration and modernization action or troubleshooting path.
  • C. Modernization means every workload must become a single virtual machine.: This distractor describes the idea that Modernization means every workload must become a single virtual machine. In "When practicing AWS Solutions Architect Professional, which option belongs under Migration and Modernization?", that misses the required action because the correct response is "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.". On the job, mixing up that distractor with "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations." can lead to the wrong migration and modernization action or troubleshooting path.

Objective/domain: Migration and Modernization (SAP-C02-migration)

Source: AWS Migration Hub documentation

Question 2 When practicing AWS Solutions Architect Professional, which option belongs under Cost Optimization?

Answer choices

  1. A. Storage tiering is unrelated to cost or access patterns.
  2. B. Cost optimization removes monitoring and budgets.
  3. C. Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility.
  4. D. Cost optimization always selects the most expensive service.

Correct answer

Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility.

Correct answer: Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility. Professional-level design requires defending cost tradeoffs along with reliability, security, and performance.

Wrong-answer review

  • A. Storage tiering is unrelated to cost or access patterns.: This distractor describes the idea that Storage tiering is unrelated to cost or access patterns. In "When practicing AWS Solutions Architect Professional, which option belongs under Cost Optimization?", that misses the required action because the correct response is "Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility.". On the job, mixing up that distractor with "Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility." can lead to the wrong cost optimization action or troubleshooting path.
  • B. Cost optimization removes monitoring and budgets.: This distractor describes the idea that Cost optimization removes monitoring and budgets. In "When practicing AWS Solutions Architect Professional, which option belongs under Cost Optimization?", that misses the required action because the correct response is "Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility.". On the job, mixing up that distractor with "Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility." can lead to the wrong cost optimization action or troubleshooting path.

Objective/domain: Cost Optimization (SAP-C02-cost)

Source: AWS Well-Architected Cost Optimization Pillar

Question 3 An enterprise wants to establish a secure database connection from an application running in a private subnet on AWS VPC to a database running in their on-premises data center. All network traffic must be encrypted, must not traverse the public internet, and must support high bandwidth (up to 10 Gbps) with consistent network latency. Which solution meets these requirements?

Answer choices

  1. A. Deploy an Internet Gateway in the VPC, assign elastic IPs to the database servers, and connect using basic SSL over the public internet.
  2. B. Use AWS Client VPN to establish individual connections from each EC2 instance directly to the on-premises firewall.
  3. C. Establish an AWS Direct Connect connection with a Private Virtual Interface (VIF) to the VPC. Configure AWS Site-to-Site VPN over Direct Connect (using public VIF or transit VIF) to encrypt the traffic using IPsec.
  4. D. Build a VPC Peering connection between the AWS VPC and the on-premises network router using custom routing tables.

Correct answer

Establish an AWS Direct Connect connection with a Private Virtual Interface (VIF) to the VPC. Configure AWS Site-to-Site VPN over Direct Connect (using public VIF or transit VIF) to encrypt the traffic using IPsec.

Correct answer: Establish an AWS Direct Connect connection with a Private Virtual Interface (VIF) to the VPC. Configure AWS Site-to-Site VPN over Direct Connect (using public VIF or transit VIF) to encrypt the traffic using IPsec. A Private VIF over Direct Connect keeps traffic off the public internet, but Direct Connect traffic is not encrypted by default. To secure the link with IPsec encryption while maintaining high speed and bypassing the public internet, you run AWS Site-to-Site VPN over a Direct Connect connection.

Wrong-answer review

  • A. Deploy an Internet Gateway in the VPC, assign elastic IPs to the database servers, and connect using basic SSL over the public internet.: Using an Internet Gateway and public IPs exposes the database to the public internet, violates the privacy requirement, and is highly insecure.
  • B. Use AWS Client VPN to establish individual connections from each EC2 instance directly to the on-premises firewall.: This distractor describes the idea that Use AWS Client VPN to establish individual connections from each EC2 instance directly to the on-premises firewall. In "An enterprise wants to establish a secure database connection from an application running in a private subnet on AWS VPC to a database running in their on-premises data center. All network traffic must be encrypted, must not traverse the public internet, and must support high bandwidth (up to 10 Gbps) with consistent network latency. Which solution meets these requirements?", that misses the required action because the correct response is "Establish an AWS Direct Connect connection with a Private Virtual Interface (VIF) to the VPC. Configure AWS Site-to-Site VPN over Direct Connect (using public VIF or transit VIF) to encrypt the traffic using IPsec.". On the job, mixing up that distractor with "Establish an AWS Direct Connect connection with a Private Virtual Interface (VIF) to the VPC. Configure AWS Site-to-Site VPN over Direct Connect (using public VIF or transit VIF) to encrypt the traffic using IPsec." can lead to the wrong security design action or troubleshooting path.
  • D. Build a VPC Peering connection between the AWS VPC and the on-premises network router using custom routing tables.: This distractor describes the idea that Build a VPC Peering connection between the AWS VPC and the on-premises network router using custom routing tables. In "An enterprise wants to establish a secure database connection from an application running in a private subnet on AWS VPC to a database running in their on-premises data center. All network traffic must be encrypted, must not traverse the public internet, and must support high bandwidth (up to 10 Gbps) with consistent network latency. Which solution meets these requirements?", that misses the required action because the correct response is "Establish an AWS Direct Connect connection with a Private Virtual Interface (VIF) to the VPC. Configure AWS Site-to-Site VPN over Direct Connect (using public VIF or transit VIF) to encrypt the traffic using IPsec.". On the job, mixing up that distractor with "Establish an AWS Direct Connect connection with a Private Virtual Interface (VIF) to the VPC. Configure AWS Site-to-Site VPN over Direct Connect (using public VIF or transit VIF) to encrypt the traffic using IPsec." can lead to the wrong security design action or troubleshooting path.

Objective/domain: Security Design (SAP-C02-security)

Source: Site-to-Site VPN over AWS Direct Connect

Question 4 A learner is reviewing SAP-C02-networking. What should they remember?

Answer choices

  1. A. Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments.
  2. B. Hybrid connectivity is only a naming standard for S3 buckets.
  3. C. VPN and Direct Connect decisions have no impact on architecture.
  4. D. Transit Gateway stores database rows instead of routing traffic.

Correct answer

Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments.

Correct answer: Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments. Professional scenarios often test connectivity, segmentation, routing, and hybrid tradeoffs.

Wrong-answer review

  • B. Hybrid connectivity is only a naming standard for S3 buckets.: This distractor describes the idea that Hybrid connectivity is only a naming standard for S3 buckets. In "A learner is reviewing SAP-C02-networking. What should they remember?", that misses the required action because the correct response is "Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments.". On the job, mixing up that distractor with "Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments." can lead to the wrong hybrid and network design action or troubleshooting path.
  • C. VPN and Direct Connect decisions have no impact on architecture.: This distractor describes the idea that VPN and Direct Connect decisions have no impact on architecture. In "A learner is reviewing SAP-C02-networking. What should they remember?", that misses the required action because the correct response is "Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments.". On the job, mixing up that distractor with "Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments." can lead to the wrong hybrid and network design action or troubleshooting path.

Objective/domain: Hybrid and Network Design (SAP-C02-networking)

Source: AWS Transit Gateway documentation

Question 5 When practicing AWS Solutions Architect Professional, which option belongs under Resilient Architectures?

Answer choices

  1. A. Resilience is only a cost allocation tag.
  2. B. Resilient architecture removes recovery objectives from design.
  3. C. Resilient AWS architectures use failure isolation, backups, multi-AZ or multi-Region patterns, and tested recovery plans.
  4. D. Resilient architecture stores every backup in the failed resource.

Correct answer

Resilient AWS architectures use failure isolation, backups, multi-AZ or multi-Region patterns, and tested recovery plans.

Correct answer: Resilient AWS architectures use failure isolation, backups, multi-AZ or multi-Region patterns, and tested recovery plans. Advanced architecture requires matching availability and recovery patterns to business requirements.

Wrong-answer review

  • A. Resilience is only a cost allocation tag.: This distractor describes the idea that Resilience is only a cost allocation tag. In "When practicing AWS Solutions Architect Professional, which option belongs under Resilient Architectures?", that misses the required action because the correct response is "Resilient AWS architectures use failure isolation, backups, multi-AZ or multi-Region patterns, and tested recovery plans.". On the job, mixing up that distractor with "Resilient AWS architectures use failure isolation, backups, multi-AZ or multi-Region patterns, and tested recovery plans." can lead to the wrong resilient architectures action or troubleshooting path.
  • B. Resilient architecture removes recovery objectives from design.: This distractor describes the idea that Resilient architecture removes recovery objectives from design. In "When practicing AWS Solutions Architect Professional, which option belongs under Resilient Architectures?", that misses the required action because the correct response is "Resilient AWS architectures use failure isolation, backups, multi-AZ or multi-Region patterns, and tested recovery plans.". On the job, mixing up that distractor with "Resilient AWS architectures use failure isolation, backups, multi-AZ or multi-Region patterns, and tested recovery plans." can lead to the wrong resilient architectures action or troubleshooting path.

Objective/domain: Resilient Architectures (SAP-C02-resilience)

Source: AWS Well-Architected Reliability Pillar

Question 6 A multi-national enterprise wants to establish a secure multi-account environment on AWS. They require centralized governance, logging, and security guardrails across 100+ accounts. Additionally, they must ensure that no member account can disable CloudTrail logging or alter the security configurations deployed by the central security team. Which solution meets these requirements?

Answer choices

  1. A. Deploy a custom Python script using AWS SDK (Boto3) on an EC2 instance in a master account that polls all accounts, enables CloudTrail, and checks for compliance every 5 minutes.
  2. B. Enable AWS Organizations and instruct each department head to manually create their AWS account, configure local IAM users, and enable CloudTrail logging to a local S3 bucket.
  3. C. Create a single AWS account, utilize complex IAM policies and resource tags to isolate different workloads, and use IAM boundaries to prevent deletion of CloudTrail.
  4. D. Use AWS Control Tower to set up a Landing Zone, which automatically configures AWS Organizations, AWS IAM Identity Center, centralized logging, and deploys mandatory preventive and detective guardrails (using SCPs and AWS Config rules).

Correct answer

Use AWS Control Tower to set up a Landing Zone, which automatically configures AWS Organizations, AWS IAM Identity Center, centralized logging, and deploys mandatory preventive and detective guardrails (using SCPs and AWS Config rules).

Correct answer: Use AWS Control Tower to set up a Landing Zone, which automatically configures AWS Organizations, AWS IAM Identity Center, centralized logging, and deploys mandatory preventive and detective guardrails (using SCPs and AWS Config rules). AWS Control Tower provides the easiest and most robust way to set up and govern a secure, multi-account AWS environment based on AWS best practices. It configures AWS Organizations and applies mandatory guardrails to prevent modification of security configurations and centralized logging.

Wrong-answer review

  • A. Deploy a custom Python script using AWS SDK (Boto3) on an EC2 instance in a master account that polls all accounts, enables CloudTrail, and checks for compliance every 5 minutes.: This distractor describes the idea that Deploy a custom Python script using AWS SDK (Boto3) on an EC2 instance in a master account that polls all accounts, enables CloudTrail, and checks for compliance every 5 minutes. In "A multi-national enterprise wants to establish a secure multi-account environment on AWS. They require centralized governance, logging, and security guardrails across 100+ accounts. Additionally, they must ensure that no member account can disable CloudTrail logging or alter the security configurations deployed by the central security team. Which solution meets these requirements?", that misses the required action because the correct response is "Use AWS Control Tower to set up a Landing Zone, which automatically configures AWS Organizations, AWS IAM Identity Center, centralized logging, and deploys mandatory preventive and detective guardrails (using SCPs and AWS Config rules).". On the job, mixing up that distractor with "Use AWS Control Tower to set up a Landing Zone, which automatically configures AWS Organizations, AWS IAM Identity Center, centralized logging, and deploys mandatory preventive and detective guardrails (using SCPs and AWS Config rules)." can lead to the wrong organizational complexity action or troubleshooting path.
  • B. Enable AWS Organizations and instruct each department head to manually create their AWS account, configure local IAM users, and enable CloudTrail logging to a local S3 bucket.: Instructing department heads to manually create accounts and configure logging introduces severe administrative overhead and lacks centralized enforcement, meaning local administrators can easily disable or delete CloudTrail logs.
  • C. Create a single AWS account, utilize complex IAM policies and resource tags to isolate different workloads, and use IAM boundaries to prevent deletion of CloudTrail.: A single AWS account strategy with IAM tags does not scale for large enterprises, lacks strong resource isolation, and can quickly hit API rate limits and administrative boundaries compared to a multi-account organization.

Objective/domain: Organizational Complexity (SAP-C02-organizations)

Source: AWS Control Tower User Guide

Question 7 Which answer is the best source-backed summary of Migration and Modernization for this AWS Certified Solutions Architect - Professional topic?

Answer choices

  1. A. Migration strategy begins by deleting discovery data.
  2. B. Modernization means every workload must become a single virtual machine.
  3. C. Application dependencies never affect migration order.
  4. D. Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.

Correct answer

Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.

Correct answer: Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations. Architects need to choose practical migration and modernization paths based on constraints and outcomes.

Wrong-answer review

  • A. Migration strategy begins by deleting discovery data.: This distractor describes the idea that Migration strategy begins by deleting discovery data. In "Which answer is the best source-backed summary of Migration and Modernization for this AWS Certified Solutions Architect - Professional topic?", that misses the required action because the correct response is "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.". On the job, mixing up that distractor with "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations." can lead to the wrong migration and modernization action or troubleshooting path.
  • B. Modernization means every workload must become a single virtual machine.: This distractor describes the idea that Modernization means every workload must become a single virtual machine. In "Which answer is the best source-backed summary of Migration and Modernization for this AWS Certified Solutions Architect - Professional topic?", that misses the required action because the correct response is "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.". On the job, mixing up that distractor with "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations." can lead to the wrong migration and modernization action or troubleshooting path.
  • C. Application dependencies never affect migration order.: This distractor describes the idea that Application dependencies never affect migration order. In "Which answer is the best source-backed summary of Migration and Modernization for this AWS Certified Solutions Architect - Professional topic?", that misses the required action because the correct response is "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations.". On the job, mixing up that distractor with "Migration strategy should assess dependencies, data movement, downtime, refactoring needs, and target-state operations." can lead to the wrong migration and modernization action or troubleshooting path.

Objective/domain: Migration and Modernization (SAP-C02-migration)

Source: AWS Migration Hub documentation

Question 8 What is the safest study takeaway for Cost Optimization?

Answer choices

  1. A. Cost optimization always selects the most expensive service.
  2. B. Cost optimization removes monitoring and budgets.
  3. C. Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility.
  4. D. Storage tiering is unrelated to cost or access patterns.

Correct answer

Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility.

Correct answer: Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility. Professional-level design requires defending cost tradeoffs along with reliability, security, and performance.

Wrong-answer review

  • A. Cost optimization always selects the most expensive service.: This distractor describes the idea that Cost optimization always selects the most expensive service. In "What is the safest study takeaway for Cost Optimization?", that misses the required action because the correct response is "Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility.". On the job, mixing up that distractor with "Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility." can lead to the wrong cost optimization action or troubleshooting path.
  • B. Cost optimization removes monitoring and budgets.: This distractor describes the idea that Cost optimization removes monitoring and budgets. In "What is the safest study takeaway for Cost Optimization?", that misses the required action because the correct response is "Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility.". On the job, mixing up that distractor with "Cost-optimized architecture balances service fit, purchasing models, scaling, storage tiers, and operational visibility." can lead to the wrong cost optimization action or troubleshooting path.

Objective/domain: Cost Optimization (SAP-C02-cost)

Source: AWS Well-Architected Cost Optimization Pillar

Question 9 When practicing AWS Solutions Architect Professional, which option belongs under Security Design?

Answer choices

  1. A. Security architecture starts by sharing root credentials.
  2. B. Least privilege means every role has administrator access.
  3. C. Security architecture applies least privilege, identity boundaries, network controls, encryption, detection, and governance.
  4. D. Encryption and detection are unrelated to workload design.

Correct answer

Security architecture applies least privilege, identity boundaries, network controls, encryption, detection, and governance.

Correct answer: Security architecture applies least privilege, identity boundaries, network controls, encryption, detection, and governance. Security controls must be designed into the architecture instead of bolted on after deployment.

Wrong-answer review

  • A. Security architecture starts by sharing root credentials.: This distractor describes the idea that Security architecture starts by sharing root credentials. In "When practicing AWS Solutions Architect Professional, which option belongs under Security Design?", that misses the required action because the correct response is "Security architecture applies least privilege, identity boundaries, network controls, encryption, detection, and governance.". On the job, mixing up that distractor with "Security architecture applies least privilege, identity boundaries, network controls, encryption, detection, and governance." can lead to the wrong security design action or troubleshooting path.
  • B. Least privilege means every role has administrator access.: This distractor describes the idea that Least privilege means every role has administrator access. In "When practicing AWS Solutions Architect Professional, which option belongs under Security Design?", that misses the required action because the correct response is "Security architecture applies least privilege, identity boundaries, network controls, encryption, detection, and governance.". On the job, mixing up that distractor with "Security architecture applies least privilege, identity boundaries, network controls, encryption, detection, and governance." can lead to the wrong security design action or troubleshooting path.

Objective/domain: Security Design (SAP-C02-security)

Source: AWS Well-Architected Security Pillar

Question 10 When practicing AWS Solutions Architect Professional, which option belongs under Hybrid and Network Design?

Answer choices

  1. A. Hybrid connectivity is only a naming standard for S3 buckets.
  2. B. Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments.
  3. C. Transit Gateway stores database rows instead of routing traffic.
  4. D. VPN and Direct Connect decisions have no impact on architecture.

Correct answer

Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments.

Correct answer: Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments. Professional scenarios often test connectivity, segmentation, routing, and hybrid tradeoffs.

Wrong-answer review

  • A. Hybrid connectivity is only a naming standard for S3 buckets.: This distractor describes the idea that Hybrid connectivity is only a naming standard for S3 buckets. In "When practicing AWS Solutions Architect Professional, which option belongs under Hybrid and Network Design?", that misses the required action because the correct response is "Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments.". On the job, mixing up that distractor with "Hybrid connectivity can use services such as AWS Direct Connect, VPN, Transit Gateway, and route design to connect environments." can lead to the wrong hybrid and network design action or troubleshooting path.

Objective/domain: Hybrid and Network Design (SAP-C02-networking)

Source: AWS Transit Gateway documentation

Where to go after the daily web set

How are AWS Solutions Architect Professional questions generated?

dotCreds builds AWS Solutions Architect Professional practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS Solutions Architect Professional practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.

Why use the app when available?

The web page is the quick daily practice layer. If a dotCreds app is available for AWS Solutions Architect Professional, the app is better for larger banks, focused weak-domain drills, longer review sessions, and mobile study routines.