AWS 346: SAP-C02 timed scenario set
Why this checkpoint matters
Professional-level questions combine several individually correct AWS services and ask for the option that best satisfies all stated constraints. Success requires requirement extraction, service-boundary knowledge, elimination, pacing, and disciplined uncertainty handling. Memorizing isolated facts is not enough.
This checkpoint contains original educational scenarios, not copied or reconstructed certification questions. It evaluates architecture reasoning and then converts every error into practical remediation.
Current exam-version boundary
As of this lesson's review date, AWS says SAP-C03 registration opens October 27, 2026 and the current SAP-C02 exam has its final testing date in November 2026. Candidates must verify the exact current date, exam guide, domains, policies, and scheduling availability on the official certification page before booking.
This lesson remains titled SAP-C02 because it occupies the existing SAP-C02 course checkpoint and preserves its URL. Its reasoning method continues to apply after an exam update, but a future candidate must use the guide for the version actually scheduled. Do not combine domain weights from different exam versions.
Outcomes
You will learn to:
- classify question type and decision scope before comparing answers;
- extract hard requirements, preferences, facts, and distractors;
- eliminate options with one precise contradiction;
- handle single-response and multiple-response items;
- allocate 180 minutes without spending the whole exam on early uncertainty;
- separate knowledge gaps from reading, reasoning, and pacing errors;
- prove remediation with changed scenarios and architecture artifacts.
Simulation rules
Complete the set closed-notes first. Use 48 minutes for the 20 questions below, an average of 2 minutes 24 seconds each. Record start/end time, chosen answer, confidence from 1 to 3, flagged status, and one-sentence rationale. Do not inspect the answer key until the timer ends.
The 20-item drill is a checkpoint, not a statistical predictor of certification success. For final readiness, also complete at least two independent full-length, current-version simulations under the official duration and format.
Use this scratch structure:
SCOPE: one workload / portfolio / organization / migration / incident
MUST: hard constraints and explicit priorities
STATE: data authority, current architecture, failure condition
ASK: design / improve / migrate / troubleshoot / most or least
ELIMINATE: exact contradiction for each rejected option
ANSWER: option(s), confidence, unresolved fact
Pacing method
Run three passes:
- First pass: answer clear items, mark uncertain ones, and avoid rereading loops.
- Second pass: resolve flagged items using explicit constraints and elimination.
- Final pass: verify multiple-response counts, negative wording, unanswered items, and accidental changes.
Set personal checkpoints before the simulation. A useful starting model is 25 percent of available time for roughly 25 percent of questions, 50 percent for half, and 75 percent for three quarters, preserving the last portion for flagged review. Adjust from measured practice, not anxiety.
Original timed scenario set
Choose one answer unless the item says Choose TWO.
1. Organization policy
A company uses an SCP that allows only listed services. A role's identity policy allows a new service, but its call is denied. What is the most direct cause?
- A. The SCP does not grant the role permission.
- B. The service is outside the SCP's effective allow boundary.
- C. IAM propagation requires a new access key.
- D. Resource policies always override SCPs.
2. Cross-account encrypted object
An application role in Account B must read an SSE-KMS S3 object in Account A. The bucket policy allows the role, but reads fail with KMS access denied. What is additionally required?
- A. Public access on the bucket
- B. An allow in the relevant KMS authorization path and identity permissions
- C. An S3 gateway endpoint in Account A
- D. A bucket ACL granting the root user
3. Accepted-order durability
An API must acknowledge an order only after it can survive application-instance failure. Processing may be asynchronous and duplicated delivery is acceptable if effects are idempotent. Which design best fits?
- A. Store the order only in instance memory, then invoke a worker.
- B. Write a durable order/idempotency record and enqueue work before acknowledgement.
- C. Return success before writing, then rely on client retries.
- D. Increase the instance Auto Scaling minimum.
4. Global static entry point
A TCP application needs two regional endpoints, static anycast IP addresses, health-based regional routing, and rapid traffic movement without DNS-cache dependence. Which service is the best fit?
- A. Amazon CloudFront
- B. AWS Global Accelerator
- C. Route 53 private hosted zone
- D. Transit Gateway peering
5. Database recovery
A database needs five-minute RPO across Regions. Nightly snapshots are retained correctly, but no continuous cross-Region copy or replication exists. Which statement is correct?
- A. Multi-AZ automatically meets cross-Region RPO.
- B. Snapshot retention proves the five-minute RPO.
- C. The design cannot meet the stated RPO during most of the day.
- D. DNS failover reduces data loss.
6. Private S3 access
Instances in private subnets transfer large volumes to S3 in the same Region. The company wants to avoid NAT processing for that path without creating endpoint ENIs. What should it use?
- A. S3 gateway endpoint with appropriate route tables and policies
- B. Interface endpoint for EC2 messages
- C. Internet gateway on each private subnet
- D. Global Accelerator endpoint group
7. Queue backlog
An SQS worker fleet has low CPU, rising queue depth, and rapidly increasing age of oldest message. What should be investigated before simply increasing instance size?
- A. Consumer throughput, downstream latency, errors, concurrency, and visibility timeout
- B. Only EC2 average CPU
- C. Route 53 TTL
- D. S3 storage class
8. Migration rollback
After cutover, customers create orders in the target. A defect appears and the team wants to route users back to the source. What is the critical unresolved issue?
- A. Whether the load balancer name changed
- B. How target-side writes will be reconciled and which system is authoritative
- C. Whether source instances have detailed monitoring
- D. Whether the source AMI is encrypted
9. Multi-account evidence, Choose TWO
A security team needs organization-wide audit evidence protected from workload administrators. Which TWO controls best support the requirement?
- A. Organization trail delivered to a restricted log-archive account
- B. Give every workload administrator permission to delete log objects
- C. Separate security/log ownership with retention and integrity controls
- D. Store all logs only on each application's root volume
- E. Disable recording during deployments
10. Hybrid DNS
On-premises clients must resolve selected private Route 53 names, while VPC workloads must forward the corporate zone to on-premises DNS. Which combination fits?
- A. Resolver inbound endpoint for on-premises queries and outbound endpoint/rule for corporate forwarding
- B. Two internet gateways
- C. Public hosted zones for all internal names
- D. NAT gateways with DNS hostnames disabled
11. Cost anomaly
Daily cost rises suddenly in one member account. What is the best first action?
- A. Purchase a three-year commitment immediately.
- B. Attribute change by service/account/usage dimensions, validate usage, and identify owner.
- C. Delete all resources with the highest list price.
- D. Wait for the invoice because operational evidence is irrelevant.
12. Serverless duplicate events
A Lambda function processes at-least-once events and occasionally charges a customer twice. What is the primary design correction?
- A. Increase memory only.
- B. Use a durable idempotency key and conditionally record processing state.
- C. Disable retries globally.
- D. Put credentials in an environment variable.
13. Central inspection asymmetry
Traffic through a stateful inspection appliance enters through one Availability Zone and returns through another path after scaling. Sessions fail intermittently. Which concern is most relevant?
- A. Symmetric routing and appliance-mode/zonal path design
- B. S3 versioning
- C. IAM password age
- D. Lambda layer size
14. Data residency
A design routes EU users to an EU application, but backups replicate to an unapproved Region. Which conclusion is correct?
- A. User geolocation alone proves residency.
- B. The backup path contradicts the residency requirement.
- C. Encryption makes location irrelevant.
- D. A lower DNS TTL fixes the violation.
15. Deployment safety, Choose TWO
A service change includes an incompatible database schema alteration. Which TWO practices most directly reduce rollback risk?
- A. Expand/contract compatible schema evolution
- B. Deploy schema and all consumers atomically without testing
- C. Test mixed-version behavior and preserve a rollback/roll-forward path
- D. Delete old fields before deploying readers
- E. Suppress migration errors
16. Direct Connect resilience
A workload requires connectivity resilience against a single device or location failure. One Direct Connect connection terminates at one location. What is true?
- A. A virtual interface alone removes physical single points.
- B. Additional appropriately diverse connectivity is required.
- C. BGP makes one physical path equivalent to two.
- D. A larger VLAN provides location redundancy.
17. Restore evidence
A team reports that backups are successful every night but has never restored the application. What can the architect conclude?
- A. RTO and RPO are proven.
- B. Backup creation is evidenced, but recoverability and end-to-end objectives remain unproven.
- C. Multi-AZ is unnecessary.
- D. Monitoring can replace restore tests.
18. Container service choice
A team needs Kubernetes APIs and ecosystem compatibility and accepts Kubernetes control/upgrade responsibilities not handled by the provider. Which service boundary fits best?
- A. Amazon ECS because it exposes Kubernetes APIs
- B. Amazon EKS with explicit shared operational ownership
- C. Amazon S3
- D. AWS Organizations
19. CloudFormation drift
A resource property was changed manually but was never explicitly specified in the template. Why can drift evidence be incomplete?
- A. Drift comparison focuses on properties represented in the expected stack configuration.
- B. CloudFormation cannot detect any drift.
- C. Tags prevent drift detection.
- D. Change sets automatically revert every manual change.
20. Architecture improvement
A review finds ten risks. Which prioritization approach is strongest?
- A. Fix the easiest items first regardless of impact.
- B. Rank by business risk/value, effort, dependencies, urgency, and measurable acceptance with owners.
- C. Close all findings after a presentation.
- D. Assign every risk to the architect indefinitely.
Answer key and reasoning
Do not score until the timed attempt ends.
- 1 B: the SCP boundary excludes the service; an identity allow cannot escape it.
- 2 B: S3 and KMS authorization both matter for an SSE-KMS read.
- 3 B: durable state before acknowledgement plus idempotent processing matches the semantics.
- 4 B: Global Accelerator provides static anycast addresses and endpoint health routing for supported regional endpoints.
- 5 C: nightly recovery points cannot prove a five-minute cross-Region objective.
- 6 A: an S3 gateway endpoint uses route-table integration rather than endpoint ENIs.
- 7 A: backlog age reflects end-to-end service rate and failures, not CPU alone.
- 8 B: accepted target writes make data authority and reconciliation the rollback boundary.
- 9 A and C: central restricted evidence and separate ownership resist workload-admin alteration.
- 10 A: inbound and outbound Resolver paths solve opposite query directions.
- 11 B: attribution and owner validation precede safe optimization.
- 12 B: at-least-once delivery requires effect-level idempotency.
- 13 A: stateful inspection requires a symmetric, intentional path.
- 14 B: residency covers copies such as backups, not only the request endpoint.
- 15 A and C: compatible evolution and mixed-version proof retain safe transition options.
- 16 B: resilience requires physically and logically appropriate diversity.
- 17 B: a stored backup is not evidence of a usable restored service.
- 18 B: EKS provides Kubernetes while leaving substantial workload/platform responsibilities.
- 19 A: omitted/defaulted properties can limit what expected-versus-actual comparison proves.
- 20 B: improvement is a governed risk/value decision with acceptance and ownership.
Score interpretation
Calculate overall score, multiple-response score, average seconds per item, flagged-change rate, and confidence calibration. A high-confidence wrong answer is more urgent than a low-confidence wrong answer.
- 18-20: strong checkpoint result; still inspect every uncertain rationale.
- 15-17: conditional pass; remediate weak domains and complete a changed retest.
- 12-14: not ready; reasoning or service-boundary gaps remain material.
- below 12: rebuild prerequisite domains before another timed set.
This local scale is instructional and is not an AWS scaled score or certification prediction.
Error taxonomy and remediation
Classify every wrong or guessed item:
| Error | Evidence | Remediation |
|---|---|---|
| Knowledge | Did not know a service/control boundary | Read primary documentation; create comparison card |
| Requirement extraction | Missed a hard word or response count | Rewrite MUST/ASK fields; do changed scenario |
| Scope | Solved resource issue at wrong account/Region/org level | Draw evaluation or traffic boundary |
| Reasoning | Kept an option contradicted by one requirement | Write elimination proof for every choice |
| Assumption | Added behavior not present in prompt | Mark supplied versus inferred facts |
| Pacing | Spent too long or left item unanswered | Practice bounded first-pass decision |
| Confidence | Confident answer lacked evidence | Explain boundary aloud and verify source |
For each weak topic, produce one architecture diagram or policy/packet/data evaluation, one failure case, one official-source note, and two changed questions. Retest after spacing; do not memorize the option letter.
Final acceptance
Pass this checkpoint only when you achieve at least 15/20, at least 75 percent on multiple-response selections, no unanswered items, and a changed retest of every weak topic at 80 percent or better. Also explain five randomly selected answers orally, including why every distractor fails.