
AWSCertified Solutions Architect - Professional
Domain 3Objective 2
Task 3.2: Determine a Strategy to Improve Security. SAP-C02 Practice Questions (Page 7)
Part of the Content Domain 3: Continuous Improvement for Existing Solutions domain, which makes up ~27% of our current practice bank. AWS does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
Questions 31–33
- 31
Which AWS service records API activity in an AWS account for auditing and security monitoring?
Select an answer first - 32
A company hosts a web application on EC2 instances behind an Application Load Balancer. The application stores user data in an S3 bucket. A security review finds that the S3 bucket is publicly readable and that the EC2 instances have overly permissive security group rules. The company must align with a compliance standard that requires least-privilege access. Which set of actions should the company take?
Select an answer first - 33
A company is migrating a legacy application to AWS. The application currently runs on a single server with a local database. The security team wants to perform a security assessment of the proposed architecture. The architecture includes an Application Load Balancer, EC2 instances in an Auto Scaling group, and an RDS database. Which assessment activity is most important to perform first?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SAP-C02
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SAP-C02” is a trademark of its owner, used for identification only.