AWS Architect Pro SAP-C02 Prep practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q21A global company is designing a multi-region architecture with operations in North America, Europe, and Asia. They need to ensure that users experience minimal latency when accessing their application. Which AWS service should they use to route traffic to the nearest regional endpoint?
✓ Correct answer: D. Amazon Route 53 with latency-based routing
Amazon Route 53 with latency-based routing directs users to the AWS Region that provides the lowest latency. This ensures that global users are automatically routed to the closest geographic region, minimizing response times and improving user experience.
Q22A large enterprise is implementing a multi-account strategy on AWS. Which service should they use to enforce security policies consistently across all accounts in the organization?
✓ Correct answer: C. AWS Organizations with Service Control Policies (SCPs)
AWS Organizations with Service Control Policies (SCPs) allows the implementation of guardrails and security controls that apply across multiple accounts in an organization. SCPs define the maximum available permissions for IAM entities within member accounts, ensuring consistent security governance.
Q23A company needs to implement a backup strategy for data stored across multiple AWS accounts and regions. The solution should minimize administrative overhead while ensuring compliance with organizational policies. Which approach is most appropriate?
✓ Correct answer: B. Implement AWS Backup with centralized management in a dedicated administration account
AWS Backup with centralized management allows defining backup policies that can be applied across multiple accounts and regions from a central location. This centralizes backup management, enforces consistent policies, and simplifies administration for enterprise-scale backup operations.
Q24A solutions architect is designing network connectivity between multiple VPCs in different AWS Regions and an on-premises data center. The design must provide transitive routing capabilities with minimum administrative overhead. Which solution should the architect recommend?
✓ Correct answer: A. AWS Transit Gateway with inter-region peering
AWS Transit Gateway with inter-region peering provides a hub-and-spoke model for connecting multiple VPCs across different regions and on-premises networks. It simplifies network architecture by enabling transitive routing through a central gateway, reducing the number of connections needed and minimizing management overhead.
Q25A financial services organization needs to implement a disaster recovery (DR) strategy that ensures critical applications can be recovered within 15 minutes and with minimal data loss. Which DR strategy should they implement?
✓ Correct answer: D. Multi-site active/active architecture
A multi-site active/active architecture distributes traffic across multiple regions simultaneously, providing the fastest recovery time objective (RTO) and minimal recovery point objective (RPO). With data replicated in real-time and applications running in multiple locations, failover can occur within minutes with minimal to no data loss.
Q26An enterprise is implementing a hybrid DNS architecture to allow resources in AWS to resolve on-premises domain names and vice versa. Which service configuration provides the most seamless integration?
✓ Correct answer: C. Amazon Route 53 Resolver with conditional forwarding rules
Amazon Route 53 Resolver with conditional forwarding rules enables bidirectional DNS resolution between AWS and on-premises environments. Inbound endpoints allow on-premises systems to resolve AWS private DNS names, while outbound endpoints allow AWS resources to resolve on-premises DNS names, creating a seamless hybrid DNS architecture.
Q27A company with multiple AWS accounts wants to implement a centralized logging solution to capture and analyze logs from all accounts for security and operational purposes. Which approach provides the most comprehensive solution?
✓ Correct answer: B. Create a dedicated logging account and use AWS CloudTrail organizational trails with CloudWatch Logs and AWS Security Hub
Creating a dedicated logging account with AWS CloudTrail organizational trails, Amazon CloudWatch Logs, and AWS Security Hub provides centralized visibility across the organization. This approach consolidates security findings, CloudTrail logs, and operational metrics in one place for comprehensive monitoring and analysis.
Q28A company is designing an encryption strategy for sensitive data stored across multiple AWS services and accounts. Which approach provides the most centralized control over encryption keys?
✓ Correct answer: A. Use AWS KMS with multi-Region keys in a centralized security account and grant cross-account access
Using AWS KMS with multi-Region keys in a centralized security account enables centralized management of encryption keys while allowing cross-account access. This approach provides a single point of control for key policies, rotation, and access, simplifying compliance and security governance across the organization.
Q29A global enterprise is implementing a multi-account strategy on AWS and needs to ensure consistent governance and compliance. Which combination of services should they implement as a foundation?
✓ Correct answer: D. AWS Control Tower, AWS Organizations, and AWS Config
The combination of AWS Control Tower, AWS Organizations, and AWS Config provides a comprehensive governance framework. Control Tower offers managed account setup and guardrails, Organizations enables policy-based management, and Config provides continuous compliance monitoring and remediation.
Q30A company wants to implement a tagging strategy to track and allocate costs across different departments, projects, and environments. Which AWS service should they use to enforce consistent tagging across all resources?
✓ Correct answer: C. AWS Tag Policies within AWS Organizations
AWS Tag Policies within AWS Organizations allow you to define and enforce standardized tags across your organization. This ensures consistent tagging practices, making cost allocation reports more accurate and enabling better resource governance through properly tagged resources.
Use the free AWS Architect Pro SAP-C02 Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.