Skip to content
BytePatterns

SAP-C02 · Domain 2: Design for New Solutions · 29% of the exam

Task 2.1: Design a deployment strategy to meet business requirements

How a new system reaches production and rolls back: infrastructure as code and StackSets, CI/CD pipelines, blue/green and canary releases, configuration management with Systems Manager, and managed services that remove provisioning and patching work.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company uses AWS Organizations without AWS Control Tower. Every account in its workloads OU must receive the same baseline: three IAM roles, an AWS Config recorder and a set of Config rules. Accounts created in or moved into the OU later must receive the baseline automatically, and it must be removed from accounts that leave the OU. Which solution requires the LEAST ongoing effort?

  1. AShare a Service Catalog portfolio with the OU so that each account administrator can launch the baseline product
  2. BRun a pipeline that assumes a role in each account listed in the OU and deploys a CloudFormation stack there every night
  3. CCreate a service-managed CloudFormation StackSet that targets the OU with automatic deployment turned on
  4. DCreate an organization conformance pack that contains the Config rules, the configuration recorder and the IAM roles
Show the answer and why
  • AShare a Service Catalog portfolio with the OU so that each account administrator can launch the baseline product

    Incorrect

    Service Catalog lets users launch approved products themselves, so the baseline would depend on someone launching it in each new account, and it would not be removed automatically when an account leaves the OU.

  • BRun a pipeline that assumes a role in each account listed in the OU and deploys a CloudFormation stack there every night

    Incorrect

    This can work, but the company would build and run the pipeline, discover new accounts itself and write its own clean-up for accounts that leave.

  • CCreate a service-managed CloudFormation StackSet that targets the OU with automatic deployment turned on

    Correct

    With service-managed permissions and automatic deployment, StackSets deploys stack instances to accounts added to the target OU and can remove them from accounts that are removed from it.

  • DCreate an organization conformance pack that contains the Config rules, the configuration recorder and the IAM roles

    Incorrect

    A conformance pack is a collection of AWS Config rules and remediation actions. It is not a way to deploy IAM roles or other baseline resources.

"Same stack in every account of an OU, including future ones" is what StackSets with service-managed permissions and automatic deployment is for.

Question 2 · choose 1

A team releases new versions of a payment Lambda function several times a week. A new version must first receive 10% of the traffic for 10 minutes. If the function's error-rate CloudWatch alarm goes off during that time, all traffic must return to the previous version without human action. Which deployment approach meets these requirements?

  1. ADeploy through AWS CodeDeploy with a canary configuration on the function alias and the alarm on the deployment group
  2. BUpdate the function code in place through a CloudFormation stack update with a rollback trigger that watches the error-rate alarm
  3. CPublish the new version and run a scheduled script that raises the alias weight by 10% every 10 minutes
  4. DCreate a new function for each version and use Route 53 weighted records to send 10% of requests to it
Show the answer and why
  • ADeploy through AWS CodeDeploy with a canary configuration on the function alias and the alarm on the deployment group

    Correct

    CodeDeploy shifts Lambda traffic between versions through an alias with canary or linear configurations, and a deployment can be rolled back automatically when a configured CloudWatch alarm is triggered.

  • BUpdate the function code in place through a CloudFormation stack update with a rollback trigger that watches the error-rate alarm

    Incorrect

    Updating the code in place sends all traffic to the new code at once, so there is no 10% phase, even if a rollback trigger can roll the stack back afterward.

  • CPublish the new version and run a scheduled script that raises the alias weight by 10% every 10 minutes

    Incorrect

    Weighted aliases can split traffic, but this script only moves traffic forward. Watching the alarm and rolling back would be custom code that the team must write and run.

  • DCreate a new function for each version and use Route 53 weighted records to send 10% of requests to it

    Incorrect

    Separate functions behind weighted DNS records split traffic only as well as resolvers honor the weights, and cached answers keep sending clients to the new function after a change, so this gives neither a clean split nor an automatic rollback.

Gradual traffic shifting with an automatic, alarm-driven rollback is a managed CodeDeploy feature for Lambda; anything else rebuilds it by hand.

Question 3 · choose 1

A new order platform will use RabbitMQ. The development team has existing producer and consumer code that uses the AMQP 0-9-1 protocol through a RabbitMQ client library, and it must not be rewritten. The operations team does not want to install, patch or back up broker software. Which solution meets these requirements?

  1. AReplace RabbitMQ with Amazon SQS queues and change the producers and consumers to use the SQS API
  2. BUse Amazon MSK and connect the producers and consumers to the Apache Kafka brokers it manages
  3. CRun RabbitMQ in containers on Amazon ECS with AWS Fargate behind a Network Load Balancer
  4. DCreate an Amazon MQ broker for RabbitMQ and point the existing client libraries at its endpoint
Show the answer and why
  • AReplace RabbitMQ with Amazon SQS queues and change the producers and consumers to use the SQS API

    Incorrect

    SQS is fully managed but uses its own API, so the existing AMQP code would have to be rewritten, which is not allowed.

  • BUse Amazon MSK and connect the producers and consumers to the Apache Kafka brokers it manages

    Incorrect

    Amazon MSK runs Apache Kafka, which uses the Kafka protocol, not AMQP 0-9-1, so the RabbitMQ client code would not work.

  • CRun RabbitMQ in containers on Amazon ECS with AWS Fargate behind a Network Load Balancer

    Incorrect

    Fargate removes server management, but the team would still install, upgrade, cluster and back up the broker software in the containers.

  • DCreate an Amazon MQ broker for RabbitMQ and point the existing client libraries at its endpoint

    Correct

    Amazon MQ is a managed message broker service for RabbitMQ that handles the setup, operation and maintenance of brokers, and existing brokers can move to it without rewriting messaging code.

"Keep the protocol, drop the operations" is the managed broker: Amazon MQ. SQS and MSK are managed too, but each speaks a different protocol.

Question 4 · choose 1

An insurance company receives 50,000 scanned claim forms each month. A new system must pull out key-value pairs, such as policy number and claim date, and tables from the scans. The company has no machine learning staff and wants to launch within weeks. Which approach meets these requirements?

  1. ATrain a custom document model in Amazon SageMaker AI on labeled scans and host it on a real-time endpoint
  2. BSend the scans to Amazon Textract and use its form and table analysis to get the fields
  3. CUse Amazon Rekognition text detection on each scan and match the field labels with regular expressions
  4. DUse Amazon Comprehend entity detection on each scan and store the detected entities in a database
Show the answer and why
  • ATrain a custom document model in Amazon SageMaker AI on labeled scans and host it on a real-time endpoint

    Incorrect

    A custom model needs labeled data, machine learning skills and endpoint operations, which the company does not have and which would take far longer than weeks.

  • BSend the scans to Amazon Textract and use its form and table analysis to get the fields

    Correct

    Textract is a managed machine learning service that extracts text, forms as key-value pairs and tables from scanned documents without any model training by the customer.

  • CUse Amazon Rekognition text detection on each scan and match the field labels with regular expressions

    Incorrect

    Rekognition detects text in images and videos, but it does not return form key-value pairs or table structure, so the company would have to build that logic itself.

  • DUse Amazon Comprehend entity detection on each scan and store the detected entities in a database

    Incorrect

    Most Comprehend features take UTF-8 text as input. Only custom classification and custom entity recognition accept images, and those need a custom model trained on annotated examples; neither returns form fields and tables.

Delegating the hard part to AWS means choosing the managed AI service that already does the job: Textract for forms and tables.

Question 5 · choose 1

A platform team of TypeScript developers is designing the infrastructure code for 40 new services. It wants to define infrastructure in TypeScript, with loops, conditions and inheritance, and to publish its own higher-level components, such as a load-balanced service with the company's logging and alarms built in, as versioned packages that every service team imports. Every deployment must still create or update CloudFormation stacks, because the release team reviews and audits changes at the stack level. Which approach meets these requirements?

  1. APackage the shared components as CloudFormation modules in the private registry and include them in each service's templates
  2. BWrite the components as AWS CDK constructs in TypeScript, publish them as packages, and deploy the apps through CloudFormation
  3. CWrite TypeScript scripts with the AWS SDK for JavaScript that create the resources, and share them as internal npm packages
  4. DDefine each service in an AWS SAM template, using its shorthand syntax, and deploy the templates with the SAM CLI
Show the answer and why
  • APackage the shared components as CloudFormation modules in the private registry and include them in each service's templates

    Incorrect

    Modules are reusable, versioned resource configurations that templates include through the CloudFormation registry, so they meet the reuse and stack requirements. They are declared in templates, though, not written as TypeScript code with loops and inheritance.

  • BWrite the components as AWS CDK constructs in TypeScript, publish them as packages, and deploy the apps through CloudFormation

    Correct

    The AWS CDK lets you define reusable cloud components, called constructs, in TypeScript and other languages, using parameters, conditionals, loops, composition and inheritance. You can create and distribute your own constructs, and CDK apps deploy through CloudFormation.

  • CWrite TypeScript scripts with the AWS SDK for JavaScript that create the resources, and share them as internal npm packages

    Incorrect

    The SDK gives TypeScript code a JavaScript API for AWS services, so the language and packaging fit. But scripts that call service APIs directly create resources outside any CloudFormation stack, which the release team needs.

  • DDefine each service in an AWS SAM template, using its shorthand syntax, and deploy the templates with the SAM CLI

    Incorrect

    An AWS SAM template is an extension of CloudFormation, so deployments still go through stacks. But it is a simplified template syntax for serverless resources, not TypeScript code with loops and inheritance.

Three constraints decide it: TypeScript with real programming constructs, shared versioned components, and deployment through CloudFormation stacks. Modules and SAM meet the stack requirement but are template syntax. SDK scripts are TypeScript but bypass CloudFormation. CDK constructs written in TypeScript, published as packages and synthesized into CloudFormation stacks meet all three.

Question 6 · choose 1

A new platform will run EC2 fleets in 40 accounts of one OU across three Regions. Every fleet must launch from a company image that already carries the security team's hardening settings and the latest OS patches, and no image may be released until automated tests pass on it. Today an engineer builds the image by hand once a month, and fleets often launch from outdated images. The company wants a new image built every week and made available in every Region and account automatically, without custom code to maintain. Which solution meets these requirements?

  1. AKeep building the image by hand each month, and run an EC2 Auto Scaling instance refresh every week to roll it out to the fleets
  2. BLaunch fleets from the latest AWS-provided AMI and patch and harden each instance after boot with Systems Manager Patch Manager
  3. CCreate an EC2 Image Builder pipeline on a weekly schedule with hardening and test components and distribution settings for the OU
  4. DHave a weekly Lambda function call CreateImage on a patched reference instance, then copy the AMI to each Region and share it
Show the answer and why
  • AKeep building the image by hand each month, and run an EC2 Auto Scaling instance refresh every week to roll it out to the fleets

    Incorrect

    An instance refresh replaces the instances of an Auto Scaling group, for example to deploy a new AMI from a new launch template. It rolls out an image but does not build, test or distribute one, so the image stays manual and monthly.

  • BLaunch fleets from the latest AWS-provided AMI and patch and harden each instance after boot with Systems Manager Patch Manager

    Incorrect

    Patch Manager automates patching of managed nodes, which keeps running instances current. But each instance starts from an unhardened image and is only fixed after launch, and no tested company image exists.

  • CCreate an EC2 Image Builder pipeline on a weekly schedule with hardening and test components and distribution settings for the OU

    Correct

    Image Builder pipelines run on a schedule, apply build components to a base image, run test components, and distribute the image only if every test succeeds. Distribution settings copy the AMI to target Regions and share it with accounts, organizations and OUs.

  • DHave a weekly Lambda function call CreateImage on a patched reference instance, then copy the AMI to each Region and share it

    Incorrect

    CreateImage and CopyImage can produce and copy AMIs on a schedule, but the company would write and maintain the function, and nothing tests the image before fleets use it.

The constraints are a hardened and patched image at launch, tests before release, a weekly cadence across Regions and accounts, and no custom code. Instance refresh only rolls out an image, Patch Manager fixes instances after launch, and a Lambda function is custom code that skips testing. An Image Builder pipeline builds, tests and distributes the image on a schedule.

Question 7 · choose 1

A new social app must screen user-uploaded images for inappropriate or offensive content before they are shown. The team has no machine learning experience. Which managed service fits?

  1. AAmazon Rekognition moderation APIs
  2. BAmazon Comprehend sentiment detection
  3. CAmazon Textract document analysis
  4. DAmazon Transcribe speech recognition
Show the answer and why
  • AAmazon Rekognition moderation APIs

    Correct

    Rekognition can detect content that is inappropriate, unwanted or offensive, for example in social media.

  • BAmazon Comprehend sentiment detection

    Incorrect

    Comprehend analyzes text, not images.

  • CAmazon Textract document analysis

    Incorrect

    Textract extracts text and data from documents, not inappropriate image content.

  • DAmazon Transcribe speech recognition

    Incorrect

    Transcribe converts speech to text.

Moderating images with a managed service is Amazon Rekognition.

Question 8 · choose 1

A company will keep its on-premises contact center platform for at least three more years. The platform writes each recorded call to an S3 bucket as a two-channel audio file, with the agent and the customer on separate channels, about 20,000 calls a day. A new analytics design needs text transcripts that show who said what and spell the company's product names correctly, and the stored transcripts must not contain card numbers or other personal data. The team has no machine learning staff and will not train, host or patch speech models. Which solution meets these requirements?

  1. ARun Amazon Transcribe batch jobs on the recordings with channel identification, a custom vocabulary and PII redaction
  2. BMove the calls to Amazon Connect and use its conversational analytics to transcribe and analyze each customer conversation
  3. CDeploy a pretrained open-source speech model from SageMaker JumpStart to an endpoint and send the recordings to it
  4. DUse Amazon Comprehend PII detection with redaction on the recordings and store the redacted output in the bucket
Show the answer and why
  • ARun Amazon Transcribe batch jobs on the recordings with channel identification, a custom vocabulary and PII redaction

    Correct

    Channel identification transcribes each channel separately, a custom vocabulary improves accuracy for terms such as brand names, and batch redaction masks PII, including card details, in the transcript. It is a managed service with no models to run.

  • BMove the calls to Amazon Connect and use its conversational analytics to transcribe and analyze each customer conversation

    Incorrect

    Amazon Connect conversational analytics analyzes conversations between customers and agents in Amazon Connect, which suits a contact center running there. This company is keeping its own platform for years.

  • CDeploy a pretrained open-source speech model from SageMaker JumpStart to an endpoint and send the recordings to it

    Incorrect

    JumpStart offers pretrained, open-source models that you deploy and tune, which would transcribe the audio, but the team would then host and operate the model endpoint, which it refuses to do.

  • DUse Amazon Comprehend PII detection with redaction on the recordings and store the redacted output in the bucket

    Incorrect

    Comprehend detects and redacts PII entities in text documents. It does not take audio, so it cannot produce transcripts from the recordings.

Four constraints decide it: keep the current platform, separate speakers and correct product names, no stored personal data, and no models to operate. Amazon Connect analytics needs the calls in Amazon Connect, a JumpStart model must be hosted, and Comprehend works on text, not audio. Amazon Transcribe batch jobs with channel identification, a custom vocabulary and PII redaction meet every constraint.

Question 9 · choose 1

In a new CI/CD design, CodeBuild projects in 30 accounts of one organization build Node.js and Java services. Compliance requires the build environments to run in private subnets with no route to the internet, yet the builds need public npm and Maven Central packages. Internal libraries published by one team must be consumable by builds in every account, and the platform team does not want to run, patch or scale any package server. Which solution meets these requirements?

  1. ATurn on CodeBuild local caching for the projects so that downloaded packages are reused by later builds
  2. BCreate Amazon ECR pull through cache rules for the public registries and point the build tools at the private registry
  3. CRun an open-source package repository manager on EC2 instances in a shared services VPC and share it with the other accounts
  4. DUse AWS CodeArtifact repositories in one domain with external connections, reached through interface VPC endpoints
Show the answer and why
  • ATurn on CodeBuild local caching for the projects so that downloaded packages are reused by later builds

    Incorrect

    A local or S3 cache stores reusable parts of the build environment to speed up later builds. Packages still have to be downloaded from the public registries the first time, which needs a route to the internet, and nothing is shared between accounts.

  • BCreate Amazon ECR pull through cache rules for the public registries and point the build tools at the private registry

    Incorrect

    Pull through cache keeps a private ECR copy of images from upstream container registries such as Docker Hub, Quay and ECR Public. npm and Maven Central are not among the supported upstream registries.

  • CRun an open-source package repository manager on EC2 instances in a shared services VPC and share it with the other accounts

    Incorrect

    A self-hosted repository manager can proxy public registries and host internal packages, but on EC2 the customer manages the guest operating system, its patches and the application software, which the platform team refuses to do.

  • DUse AWS CodeArtifact repositories in one domain with external connections, reached through interface VPC endpoints

    Correct

    An external connection fetches packages from public repositories such as npmjs.com or Maven Central into the CodeArtifact repository. A domain applies permissions across repositories owned by different accounts, and interface endpoints reach CodeArtifact without an internet gateway or NAT device.

Three constraints decide it: no internet route from the builds, public plus internal packages shared across accounts, and nothing to operate. CodeBuild caching still needs the internet for the first download, ECR pull through cache serves container registries, and a self-hosted repository is a server to run. CodeArtifact with external connections, one domain and VPC endpoints meets all three.

Practise domain 2 →Practise all domains →