Skip to content

Design Solutions for Organizational Complexity Questions

Practice questions for Design Solutions for Organizational Complexity topic in AWS Certified Solutions Architect - Professional. 52 questions covering this domain.

52 questions12 easy28 medium12 hard
Q1
medium

A growing enterprise wants to create accounts, group them into organizational units, apply governance policies, and simplify billing by using a single...

Q2
easy

A company runs a shared networking model across many AWS accounts. The network team wants to create subnets once and make them usable by selected acco...

Q3
hard

Resources in a VPC must resolve selected on-premises domain names by forwarding queries to corporate DNS servers. The design must use the most specifi...

Q4
medium

A company has dozens of VPCs across accounts and also needs connectivity to its on-premises data center. The network team wants a central hub that sup...

Q5
hard

A global application needs a database design with one write Region and multiple read-only Regions. The company wants replication latency that is typic...

Q6
hard

An organization has a strict audit requirement for a centralized activity log across member accounts, and member accounts must not be able to turn off...

Q7
medium

A company wants to classify and track resources consistently across its AWS organization and use those attributes to support attribute-based access co...

Q8
easy

An enterprise wants the easiest way to set up and govern a secure multi-account AWS environment that follows prescriptive best practices and applies g...

Q9
medium

Instances in private subnets need private connectivity to a supported AWS service without using an internet gateway, NAT device, public IP address, Di...

Q10
easy

On-premises DNS resolvers must resolve names for EC2 instances and records in a Route 53 private hosted zone inside a VPC. Which Route 53 Resolver end...

Q11
medium

Central cloud administrators want distributed teams to provision new AWS accounts quickly by using preapproved account templates while keeping the env...

Q12
hard

A company is ordering a dedicated AWS Direct Connect connection for private connectivity to AWS. Which set of capabilities is required on the customer...

Q13
medium

A relational database needs higher availability with automatic failover to a synchronous standby in another Availability Zone. The standby does not ne...

Q14
medium

An organization needs to automatically enroll new accounts joining AWS Organizations into baseline security services such as GuardDuty and Security Hu...

Q15
easy

Which AWS Organizations policy type centrally restricts the maximum permissions available to principals in member accounts?

Q16
hard

A regulated workload must keep sensitive data unable to leave a chosen set of Regions and prevent VPC traffic from reaching the public internet for AW...

Q17
medium

A company wants centralized findings from GuardDuty, Inspector, Macie, IAM Access Analyzer, and partners across all member accounts in AWS Organizatio...

Q18
hard

A company shares a Transit Gateway across many accounts via RAM. The networking team wants application accounts to attach VPCs without granting them a...

Q19
easy

Which feature of AWS Organizations consolidates billing across all member accounts and can apply volume discounts across the organization?

Q20
medium

A multi-account workload uses AWS Resource Access Manager (RAM). Which AWS resource type CANNOT be shared via RAM and instead requires another mechani...

Sign in to see all 52 questions

Create a free account to browse all questions — completely free during our launch phase.