1.0 Design Solutions for Organizational Complexity SAP-C02 Practice Quiz
156 exam-style questions covering 26% of the SAP-C02 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the AWS Certified Solutions Architect Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A regulated financial services company has an existing AWS environment that must be redesigned for AWS Global Infrastructure. What should the solutions architect recommend?
- A. Use multiple AWS Regions with Regional service endpoints, data replication, and Route 53 or Global Accelerator routing based on latency and recovery requirements
- B. Skip permission boundaries when delegating IAM administration to development teams
- C. Use IAM password policy to enforce VPC routing decisions
- D. Use S3 server-side encryption only when the bucket is publicly accessible
A multi-Region design can place workloads closer to users and provide Regional failure isolation when data and routing are designed together.
A steering committee asks for a recommendation for AWS Global Infrastructure after a failed proof of concept exposed governance and operational risks. Which design should the solutions architect choose?
- A. Model Regional dependencies, service availability, and data residency before committing to the target Regions
- B. Use a single-AZ deployment to reduce inter-AZ data transfer charges and improve resiliency
- C. Use AWS Compute Optimizer recommendations only after manual application by every team
- D. Place customer gateway IP inside the VPC CIDR range
Professional architecture decisions must account for service availability, legal constraints, and operational dependencies across Regions.
A media platform is reviewing a proposed architecture and finds that the current design does not satisfy AWS Global Infrastructure. What change should be made?
- A. Use AWS Budgets to enforce IAM permission boundaries on engineering teams
- B. Choose Availability Zones within the selected Region for high availability, while reserving multi-Region design for disaster recovery or global latency needs
- C. Connect on-premises with only a single Site-to-Site VPN tunnel for production
- D. Place all traffic through one unmanaged appliance in one Availability Zone
Availability Zones protect against zonal failures inside a Region without adding the operational complexity of active multi-Region operation.
A public sector agency is designing a platform for multiple business units. The requirement focuses on AWS networking concepts. Which architecture decision is most appropriate?
- A. Use AWS WAF as a layer 4 firewall for non-HTTP TCP traffic
- B. Use Transit Gateway for scalable hub-and-spoke routing with segmented route tables
- C. Set RTO to zero by relying on backup and restore as the only DR strategy
- D. Use Spot Instances for the entire stateful database tier to reduce compute cost
Transit Gateway provides centralized routing and segmentation for many VPCs and hybrid attachments.
A steering committee asks for a recommendation for AWS networking concepts after a failed proof of concept exposed governance and operational risks. Which design should the solutions architect choose?
- A. Use Amazon Macie to continuously block all data at rest from leaving the account
- B. Use container networking mode and service discovery choices that match the ECS or EKS deployment model
- C. Use long-lived IAM access keys embedded in EC2 user data for cross-account access
- D. Use AWS Backup as a network configuration drift detection tool
Container services can consume VPC IPs and expose services differently, so networking must be part of the architecture.
A retail organization must choose between several AWS architecture patterns for AWS Global Infrastructure. Which option best satisfies the requirement?
- A. Use a single shared Internet Gateway across multiple VPCs by sharing it via AWS RAM
- B. Use AWS Config rules to grant additional IAM permissions to roles
- C. Place latency-sensitive components in the Region closest to the largest user population and use edge services for global content delivery
- D. Skip AWS Organizations and manage accounts independently with email-based invoices
Regional placement and edge delivery reduce round trips while keeping the origin architecture manageable.
A workload review identifies conflicting requirements across security, availability, cost, and team ownership. Which option best supports AWS networking concepts in a complex organization?
- A. Use scale-up only on a single EC2 instance to handle unpredictable traffic spikes
- B. Use AWS Config rules as a substitute for IAM policy enforcement
- C. Use AWS Direct Connect with redundant connections for predictable private hybrid bandwidth
- D. Disable VPC Flow Logs and rely on application logs alone for network forensics
Direct Connect is designed for dedicated private connectivity when throughput and consistency matter.
A fast-growing startup has an existing AWS environment that must be redesigned for AWS Global Infrastructure. What should the solutions architect recommend?
- A. Use IAM password policy as the authoritative identity provider for federated users
- B. Skip Route 53 Resolver inbound and outbound endpoints for hybrid DNS
- C. Skip cross-account event notifications and rely on per-account email subscriptions
- D. Use Local Zones, Wavelength, or Outposts only when workload latency or residency requirements justify those infrastructure options
Specialized infrastructure should be selected when standard Regions and Availability Zones cannot meet the business requirement.
Key Terms in This Domain
- AWS IAM Identity Center: Workforce identities and SSO across AWS accounts and applications
- AWS Network Firewall: Managed stateful firewall, IDS/IPS, and traffic filtering for VPCs
- AWS Firewall Manager: Centrally configure WAF, Shield, security groups, and Network Firewall org-wide
- AWS Health Dashboard: Service health and account events affecting your AWS resources
- AWS Trusted Advisor: Best-practice checks across cost, performance, security, and limits
- AWS Organizations: Multi-account management with consolidated billing and policies
- Service Control Policy (SCP): Org-level guardrail that limits maximum permissions in member accounts
- AWS Control Tower: Sets up and governs a secure, compliant multi-account environment
- AWS Resource Access Manager: Securely shares AWS resources across accounts and OUs
- Amazon VPC: Logically isolated virtual network for AWS resources
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/aws-solutions-architect-professional/design-solutions-for-organizational-complexity/
<a href="https://quizbuffet.com/aws-solutions-architect-professional/design-solutions-for-organizational-complexity/">AWS Solutions Architect Professional Design Solutions for Organizational Complexity practice quiz on QuizBuffet</a>
Other SAP-C02 Domains
- 2.0 Design for New Solutions
- 3.0 Continuous Improvement for Existing Solutions
- 4.0 Accelerate Workload Migration and Modernization
← Back to SAP-C02 practice test overview
Questions are written against the published SAP-C02 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.