exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 450 discussion

A company has a three-tier web application that is in a single server. The company wants to migrate the application to the AWS Cloud. The company also wants the application to align with the AWS Well-Architected Framework and to be consistent with AWS recommended best practices for security, scalability, and resiliency.

Which combination of solutions will meet these requirements? (Choose three.)

  • A. Create a VPC across two Availability Zones with the application's existing architecture. Host the application with existing architecture on an Amazon EC2 instance in a private subnet in each Availability Zone with EC2 Auto Scaling groups. Secure the EC2 instance with security groups and network access control lists (network ACLs).
  • B. Set up security groups and network access control lists (network ACLs) to control access to the database layer. Set up a single Amazon RDS database in a private subnet.
  • C. Create a VPC across two Availability Zones. Refactor the application to host the web tier, application tier, and database tier. Host each tier on its own private subnet with Auto Scaling groups for the web tier and application tier.
  • D. Use a single Amazon RDS database. Allow database access only from the application tier security group.
  • E. Use Elastic Load Balancers in front of the web tier. Control access by using security groups containing references to each layer's security groups.
  • F. Use an Amazon RDS database Multi-AZ cluster deployment in private subnets. Allow database access only from application tier security groups.
Show Suggested Answer Hide Answer
Suggested Answer: CEF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
awsgeek75
Highly Voted 5 months, 2 weeks ago
Selected Answer: CEF
The wording on this question makes things ambiguous for C. But, remember well-architected so: A: Not ideal as it is suggesting using existing architecture but with autoscaling EC2. Doesn't leave room for improvement on scaling or reliability on each tier. B: Single RDS, not well-architected D: Again, single RDS E,F are good options and C is only remaining good one.
upvoted 8 times
awsgeek75
5 months, 2 weeks ago
C is badly worded IMHO because of this part " Refactor the application to host the web tier, application tier, and database tier." The database tier tier just makes it confusing when you don't read E and F.
upvoted 2 times
...
...
Abrar2022
Highly Voted 1 year ago
Selected Answer: CEF
C-scalable and resilient E-high availability of the application F-Multi-AZ configuration provides high availability
upvoted 6 times
...
Burrito69
Most Recent 2 months, 3 weeks ago
remove singles and remove network ACLs
upvoted 3 times
...
jjcode
5 months ago
i would flag this on the test and do it last.
upvoted 5 times
...
argl1995
11 months, 3 weeks ago
option A cannot be the answer as Security group is at instance level whereas a NACL is at the subnet level. Having said that option C is the right one as the VPC cannot span across the regions and here it is mentioned two AZs for which I am guessing it is a default VPC which is created in each region with a subnet in each AZ.
upvoted 2 times
argl1995
11 months, 3 weeks ago
So, CEF is the right answer
upvoted 2 times
...
...
Gooniegoogoo
11 months, 4 weeks ago
How can you create a VPC across 2 AZ? i only see EF here.. if they mean 2 separate VPC then that is different but a VPC cannot span two AZ..
upvoted 1 times
lemur88
10 months ago
A VPC most definitely can span across 2 AZ. You may be thinking of subnets.
upvoted 3 times
...
...
marufxplorer
1 year ago
I also agree with CEF but chatGPT answer is ACE. A and C is the similar Another Logic F is not True because in the question not mentioned about DB
upvoted 1 times
awsgeek75
5 months, 1 week ago
ChatGPT is a language parser. It is not an AWS solution architect!
upvoted 3 times
...
...
TariqKipkemei
1 year ago
Selected Answer: CEF
CEF is best
upvoted 2 times
...
antropaws
1 year ago
Selected Answer: CEF
It's clearly CEF.
upvoted 2 times
...
omoakin
1 year ago
B- to control access to database C-scalable and resilient E-high availability of the application
upvoted 1 times
...
lucdt4
1 year ago
Selected Answer: CEF
CEF A: application's existing architecture is wrong (single AZ) B: single AZ D: Single AZ
upvoted 2 times
...
cloudenthusiast
1 year, 1 month ago
C. This solution follows the recommended architecture pattern of separating the web, application, and database tiers into different subnets. It provides better security, scalability, and fault tolerance. E.By using Elastic Load Balancers (ELBs), you can distribute traffic to multiple instances of the web tier, increasing scalability and availability. Controlling access through security groups allows for fine-grained control and ensures only authorized traffic reaches each layer. F. Deploying an Amazon RDS database in a Multi-AZ configuration provides high availability and automatic failover. Placing the database in private subnets enhances security. Allowing database access only from the application tier security groups limits exposure and follows the principle of least privilege.
upvoted 5 times
mwwt2022
5 months, 2 weeks ago
good explanation
upvoted 2 times
...
...
nosense
1 year, 1 month ago
Selected Answer: CEF
Only this valid for best practices and well architected
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago