
AWSCertified Solutions Architect - Associate
Domain 1Objective 3
Task 1.3: Determine Appropriate Data Security Controls SAA-C03 Practice Questions (Page 2)
Part of the Design Secure Architectures domain, which makes up ~18% of our current practice bank. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~9–15 in this domain), expect 3–5 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
11concepts
Questions 6–10
- 6
A solutions architect needs to enforce a governance rule that restricts all AWS accounts in an organization from using specific AWS services. Which AWS feature should be used to apply this restriction across the entire organization?
Select an answer first - 7
A company runs a web application behind an Application Load Balancer (ALB). The application must be accessible via HTTPS. The company wants to use a public certificate from a trusted CA and have it automatically renewed. What should a solutions architect do?
Select an answer first - 8
A company wants to encrypt traffic between clients and an Application Load Balancer using TLS. Which AWS service should be used to provision and manage the TLS certificate?
Select an answer first - 9
What is the primary role of AWS Key Management Service (AWS KMS) in data security?
Select an answer first - 10
A company wants to protect an Amazon S3 bucket from accidental object deletion and be able to restore previous versions of objects. Which S3 feature should be enabled?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SAA-C03” is a trademark of its owner, used for identification only.