AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company operates a large number of applications across a multi-account AWS Organization. The security team needs a comprehensive, centrally managed security solution. The solution must provide proactive and intelligent threat detection for workloads and data, including identifying unusual API activity or potential instance compromises. It must also offer protection for public-facing web applications against common web exploits and DDoS attacks. A key requirement is to aggregate security findings from all accounts and services into a single, designated security tooling account for unified visibility, posture management, and prioritized remediation. Which combination of AWS services should a solutions architect recommend to meet all these requirements most effectively?

  • Implement Amazon GuardDuty for threat detection, AWS WAF for web application protection, AWS Shield Advanced for DDoS mitigation, and AWS Security Hub for centralized findings management.

  • Use AWS Config with conformance packs to enforce security best practices and Amazon Macie to discover and protect sensitive data in Amazon S3.

  • Deploy AWS Network Firewall in each VPC, use VPC Flow Logs for traffic analysis, and stream logs to a central Amazon S3 bucket for manual review.

  • Enable Amazon Inspector in all accounts to scan for vulnerabilities, and use AWS Systems Manager Patch Manager to automate patching.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot