SAP-C02 sample questions with answers

10 free practice questions for the AWS Certified Solutions Architect – Professional exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Design Solutions for Organizational Complexity

A analytics platform moved inter-VPC traffic from VPC peering to a transit gateway. The instances were tuned years ago for jumbo frames and still advertise a 9001-byte interface MTU. Small requests and SSH sessions work, but bulk transfers between the two VPCs now stall part-way through, and packet captures show large frames leaving the source and never arriving. Which change resolves this?

  1. A.

    Raise the transit gateway MTU to 9001 in the attachment options and restart the affected instances so the new value is picked up.

  2. B.

    Add a static route for each VPC CIDR in the transit gateway route table so large frames are no longer sent to a propagated route.

  3. C.

    Enable appliance mode on both transit gateway VPC attachments so that each flow is pinned to one Availability Zone.

  4. D.

    Lower the interface MTU on instances in both VPCs to the maximum the transit gateway supports, and change both VPCs together.

Show answer

Answer: D

A transit gateway carries a smaller maximum frame than VPC peering, so instances still set to the peering-era MTU have their large frames silently discarded.

  • A. The transit gateway's maximum frame size is a service property and cannot be raised in attachment options.
  • B. Static versus propagated routes change which attachment is chosen, not the maximum frame the path will carry.
  • C. Appliance mode pins a flow to one Availability Zone for stateful appliances; it has no effect on frame size.
  • D. Aligning the instance MTU with the transit gateway's supported maximum removes the oversized frames, and changing both VPCs together avoids a mismatch.
Question 2Design Solutions for Organizational Complexity

A shared tooling account hosts a role whose trust policy allows sts:AssumeRole to Principal "AWS": "*" with a condition requiring aws:PrincipalOrgID to equal the company's organization ID. No other condition is present. Members of the organization have a wide range of IAM permissions in their own accounts. Which statement describes the resulting access?

  1. A.

    No principal can assume the role, because a trust policy must name an account or principal ARN explicitly.

  2. B.

    Only the organization management account can assume the role, because aws:PrincipalOrgID is evaluated from the payer account.

  3. C.

    Any principal in the organization whose own IAM policy allows sts:AssumeRole on that role can assume it.

  4. D.

    Any AWS principal anywhere can assume the role, because a wildcard principal overrides the condition.

Show answer

Answer: C

The wildcard principal plus an aws:PrincipalOrgID condition trusts every account in the organization, and each caller still needs its own identity policy permitting the AssumeRole call.

  • A. A wildcard principal with a condition is valid in a trust policy; only ARNs with embedded wildcards are rejected.
  • B. aws:PrincipalOrgID reflects the calling account's organization, not the payer, so every member account satisfies it.
  • C. The condition limits the wildcard to the organization, and the caller still needs its own allow on sts:AssumeRole.
  • D. Conditions restrict the principal element; they are not overridden by a wildcard.
Question 3Design Solutions for Organizational Complexity

An organization root has an SCP allowing only ec2, s3, iam and cloudwatch. The Workloads OU keeps FullAWSAccess. Its child Test OU has an SCP allowing only lambda and dynamodb. An account in the Test OU has FullAWSAccess attached directly. Which services can an administrator in that account use?

  1. A.

    None, because no service is allowed at every level in the path.

  2. B.

    Lambda and DynamoDB, because the policy closest to the account takes precedence.

  3. C.

    EC2, S3, IAM and CloudWatch, because the root policy is inherited by every account.

  4. D.

    All services, because FullAWSAccess is attached directly to the account.

Show answer

Answer: A

SCPs intersect down the tree: a permission is available only if an explicit allow exists at every level from the root to the account, and here the root allow list and the Test OU allow list have no service in common.

  • A. The allow lists at the root and the Test OU have no overlap, so the intersection permits nothing.
  • B. SCPs have no notion of a closest policy winning; every level must allow the action.
  • C. The Test OU's allow list excludes all four of those services, so the root's allow does not survive.
  • D. An account-level allow cannot restore what an ancestor's allow list has already excluded.
Question 4Design Solutions for Organizational Complexity

A baseline StackSet deploys an IAM role named SecurityAuditRole and a CloudWatch log destination into every account. Account administrators have full IAM permissions and have occasionally deleted or edited the role while troubleshooting. The platform team must make that impossible while its own deployment role can still manage the resources. What should it implement?

  1. A.

    An SCP denying IAM actions on the role's ARN, with a condition excluding the deployment role from the deny.

  2. B.

    A resource-based policy on the role denying iam:DeleteRole and iam:UpdateAssumeRolePolicy to the account's administrators.

  3. C.

    An AWS Config rule with an SSM Automation remediation that recreates the role whenever it is deleted.

  4. D.

    A permissions boundary attached to SecurityAuditRole so that it cannot be modified by other principals.

Show answer

Answer: A

Only an SCP sits above an account administrator, and a deny scoped to the protected resource with an aws:PrincipalArn condition excluding the deployment role preserves the automation while blocking everyone else.

  • A. An SCP bounds even an account administrator, and a principal ARN condition preserves the deployment role's access.
  • B. IAM roles have a trust policy, not a general resource policy that can deny management actions to others.
  • C. Recreating the role after deletion is detective and leaves a window in which the control is absent.
  • D. A boundary limits what the role itself can do, not what other principals can do to it.
Question 5Design Solutions for Organizational Complexity

Sixty microservices run in about thirty VPCs across many accounts, several with overlapping CIDR blocks. Teams want service-to-service calls authorised per service with IAM, weighted traffic shifting for releases, and no network-level reachability between VPCs. Which approach fits best?

  1. A.

    Amazon VPC Lattice service networks, with auth policies and weighted target groups per service.

  2. B.

    A full mesh of VPC peering connections with fine-grained subnet routes.

  3. C.

    A transit gateway with one route table per environment and security group rules per service.

  4. D.

    An AWS PrivateLink endpoint service per microservice, consumed by interface endpoints in each caller VPC.

Show answer

Answer: A

VPC Lattice connects at the service layer rather than the network layer, so overlapping CIDRs stop mattering and authorisation and traffic shifting become properties of the service.

  • A. Lattice routes by service rather than by prefix, and adds IAM auth policies and weighted target groups per service.
  • B. Peering cannot be created between overlapping CIDRs and a mesh of thirty VPCs is unmanageable.
  • C. A transit gateway grants network reachability, which the requirements forbid, and cannot route overlapping CIDRs.
  • D. PrivateLink works but needs an endpoint service and endpoints per service pair, with no per-request IAM authorisation or weighting.
Question 6Design Solutions for Organizational Complexity

A company has about thirty project teams working in shared accounts, and each team must access only the resources tagged with its own project code. Today this is expressed as one permission set per team per account, and the number of permission sets has become unmanageable. Every user already carries a project attribute in the corporate directory, and every resource is tagged at creation by a pipeline. Which change reduces the number of policies without loosening access?

  1. A.

    Create one IAM group per project in every account and synchronise directory membership into those groups with a scheduled Lambda function that runs hourly.

  2. B.

    Move each project into its own AWS account so that account boundaries replace the tag comparison, and grant a single administrator permission set per account.

  3. C.

    Enable attribute-based access control in IAM Identity Center and write one permission set whose policy compares the principal tag to the resource tag.

  4. D.

    Create one permission set per account that grants full access, and rely on AWS Config rules to detect and remediate any access to resources tagged for another project.

Show answer

Answer: C

Attribute-based access control replaces the policy-per-team explosion with one policy whose condition compares the session's principal tag to the resource's tag.

  • A. Groups per project per account recreate the same combinatorial growth and add a fragile synchronisation job.
  • B. Re-architecting into thirty accounts is a far larger change than the problem requires and contradicts the shared-account model.
  • C. One policy comparing principal tag to resource tag scales to any number of teams without new permission sets.
  • D. Detecting misuse after the fact is not equivalent to preventing access, and full access violates least privilege.
Question 7Design Solutions for Organizational Complexity

After an acquisition, the parent company must let its shared-services VPC reach two applications in the acquired company's VPC. Both VPCs use 10.0.0.0/16 and neither can be renumbered in the required timeframe. Traffic is one-directional, from parent to the acquired applications. Which design connects them with the least disruption?

  1. A.

    Establish a Site-to-Site VPN between the two VPCs so the tunnel hides the overlapping addresses.

  2. B.

    Attach both VPCs to a transit gateway and place a private NAT gateway in a non-overlapping subnet in front of the applications.

  3. C.

    Create a VPC peering connection and add more specific routes for only the two application subnets.

  4. D.

    Attach both VPCs to one transit gateway and use separate route tables to keep the overlapping ranges apart.

Show answer

Answer: B

Overlapping CIDRs cannot be routed, so the traffic must be translated; a private NAT gateway in a non-overlapping range in front of the targets is the standard pattern.

  • A. A VPN encapsulates packets but does not translate the inner addresses, so the collision persists end to end.
  • B. A private NAT gateway in a non-overlapping range translates the addresses, which is the only way to route between identical CIDRs.
  • C. VPC peering cannot be created at all when the two VPC CIDR blocks overlap, regardless of subnet routes.
  • D. A transit gateway route table cannot hold the same prefix pointing at two attachments, so separate tables do not resolve a collision.
Question 8Design Solutions for Organizational Complexity

A regulator requires that no object in any S3 bucket in a 400-account organization can be read or written over an unencrypted connection, including by principals outside the organization that some bucket policies deliberately allow. Bucket policies are owned by application teams and change constantly. The security team needs a control that team-owned bucket policies cannot weaken. What should it implement?

  1. A.

    A resource control policy on the organization root that denies s3 actions when aws:SecureTransport is false.

  2. B.

    An AWS Config organization rule that flags buckets without a TLS-only statement, with an SSM Automation remediation that rewrites the bucket policy.

  3. C.

    An S3 bucket policy template distributed to every account by a service-managed CloudFormation StackSet on a daily schedule.

  4. D.

    A service control policy on the organization root that denies s3 actions when aws:SecureTransport is false.

Show answer

Answer: A

Only a resource control policy bounds what the resource itself will permit, so it also constrains external principals that a bucket policy grants, which an SCP cannot do.

  • A. An RCP bounds the resource itself, so it reaches external principals that a bucket policy grants.
  • B. Config detects and remediates after the fact, leaving a window in which plaintext requests succeed.
  • C. A distributed template is overwritten by the next team edit and only converges once a day.
  • D. SCPs constrain only IAM principals in member accounts, so an external caller allowed by a bucket policy is unaffected.
Question 9Design Solutions for Organizational Complexity

A role in a member account has an identity policy allowing s3:GetObject on a bucket in the same account. The bucket policy allows the same action to that role. The role also has a permissions boundary that omits Amazon S3 entirely, and an SCP attached to the account's organizational unit allows all actions. What is the result when the role calls GetObject, and why?

  1. A.

    The call is denied, because a permissions boundary that does not allow the action caps the role's effective permissions.

  2. B.

    The call succeeds, because for same-account access an allow in either the identity policy or the resource policy is sufficient.

  3. C.

    The call is denied, because an SCP that allows all actions provides no explicit allow and therefore leaves the request without one.

  4. D.

    The call succeeds, because a permissions boundary only constrains roles created by other principals, not the role's own actions.

Show answer

Answer: A

A permissions boundary is one of the policy types that must allow an action; omitting S3 from the boundary caps the role regardless of its identity or resource policies.

  • A. Effective permissions are the intersection of the identity policy and the boundary, and S3 is missing from the boundary.
  • B. The same-account identity-or-resource rule applies within the chain and cannot override a permissions boundary.
  • C. SCPs never grant permissions; an allow-all SCP satisfies the organizational filter rather than leaving the request unallowed.
  • D. A boundary constrains the entity it is attached to, not only entities that principal creates.
Question 10Design Solutions for Organizational Complexity

A networking account shares three subnets with a participant account through AWS RAM. A participant engineer with administrator permissions in their own account tries to add a route to the subnet's route table, delete an unused shared subnet, and launch an instance into a shared subnet using the VPC's default security group. What is the outcome?

  1. A.

    All three fail, because AWS RAM lets participants view shared subnets and their route tables but never create resources in them.

  2. B.

    The route change and the deletion both fail, and the launch succeeds only with a security group the participant created.

  3. C.

    All three succeed, because administrator permissions in the participant account apply to shared subnets.

  4. D.

    The route change succeeds and the other two fail, because routing is delegated with the subnet.

Show answer

Answer: B

In a shared VPC the owner keeps the VPC, its subnets, route tables and network ACLs; participants may create and manage their own resources in the shared subnets but must use their own security groups.

  • A. Launching and managing their own resources in shared subnets is the entire point of VPC sharing.
  • B. Route tables and subnets stay owner-managed, and participants must create their own security groups.
  • C. Administrator rights in the participant account cannot exceed what the resource owner exposes.
  • D. Routing is exactly what the owner retains, so the route change is the clearest failure of the three.

Keep going with 966 more SAP-C02 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.