Skip to content
BytePatterns

SAP-C02 · Domain 3: Continuous Improvement for Existing Solutions · 25% of the exam

Task 3.3: Determine a strategy to improve performance.

Finding and removing bottlenecks: metrics tied to SLAs and KPIs, caching and edge services such as CloudFront and Global Accelerator, placement groups and instance fleets, and managed services that replace self-run components.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A multiplayer game runs its UDP game servers on EC2 instances in two Regions. Players around the world complain about jitter on long internet paths, and some of their corporate firewalls only allow traffic to a fixed list of IP addresses. Which change improves the experience and meets the firewall constraint?

  1. APut an AWS Global Accelerator standard accelerator in front of the game servers in both Regions
  2. BServe the game traffic through an Amazon CloudFront distribution with the game servers as origins
  3. CUse Route 53 latency-based records that point players to the Region with the lowest latency
  4. DMove the game servers to larger instances with enhanced networking in both Regions
Show the answer and why
  • APut an AWS Global Accelerator standard accelerator in front of the game servers in both Regions

    Correct

    Global Accelerator provides static anycast IP addresses and improves TCP and UDP applications by carrying their traffic over the AWS global network to endpoints in the nearest Region.

  • BServe the game traffic through an Amazon CloudFront distribution with the game servers as origins

    Incorrect

    CloudFront speeds up cacheable and dynamic web content. For non-HTTP use cases such as UDP gaming, AWS points to Global Accelerator instead.

  • CUse Route 53 latency-based records that point players to the Region with the lowest latency

    Incorrect

    Latency records pick a Region at DNS time, but traffic still crosses the public internet, and the addresses are not a small fixed list.

  • DMove the game servers to larger instances with enhanced networking in both Regions

    Incorrect

    Enhanced networking speeds up the instance network interface. It does not shorten the internet path that causes the jitter.

Non-HTTP traffic, a global audience and fixed IP addresses point to Global Accelerator.

Question 2 · choose 1

A new contract says that 99.9% of checkout API requests must complete in under 300 ms each month. Today the team alarms on the average latency reported by the Application Load Balancer, and the alarm never fires even though customers complain about slow checkouts. Which change makes the monitoring match the contract?

  1. AAlarm on the Maximum statistic of TargetResponseTime above 300 ms
  2. BAlarm on the p99.9 percentile of TargetResponseTime above 300 ms
  3. CAlarm on the SampleCount statistic of TargetResponseTime above a fixed number
  4. DLower the Average threshold from 300 ms to 100 ms so that the alarm fires earlier
Show the answer and why
  • AAlarm on the Maximum statistic of TargetResponseTime above 300 ms

    Incorrect

    Maximum reacts to a single slow request, so it would fire even when 99.9% of requests are fast and the contract is met.

  • BAlarm on the p99.9 percentile of TargetResponseTime above 300 ms

    Correct

    Percentile statistics show the value below which a given share of data points fall, so p99.9 measures the contract directly; averages hide slow requests.

  • CAlarm on the SampleCount statistic of TargetResponseTime above a fixed number

    Incorrect

    SampleCount counts requests. It says nothing about how long they took.

  • DLower the Average threshold from 300 ms to 100 ms so that the alarm fires earlier

    Incorrect

    A lower average threshold still hides the slowest requests and is not the measure the contract uses.

Translate the SLA into the same statistic: a percentile target needs a percentile alarm.

Question 3 · choose 1

A news site serves HTML pages and 2 TB of images and scripts from a fleet of EC2 web servers behind an Application Load Balancer. Readers on other continents see slow page loads, and most of the web servers' CPU goes to serving the same static files again and again. Which change improves performance the most?

  1. AMove the web servers to the next larger instance size and raise the Auto Scaling group's maximum size
  2. BAdd an Amazon ElastiCache cluster that the web servers use to cache the static files in memory
  3. CPut AWS Global Accelerator in front of the load balancer to route readers over the AWS network
  4. DServe the site through Amazon CloudFront, with the static files moved to Amazon S3 as a second origin
Show the answer and why
  • AMove the web servers to the next larger instance size and raise the Auto Scaling group's maximum size

    Incorrect

    Bigger servers add capacity but still serve every file from one Region, so distant readers stay slow and the repeated work remains.

  • BAdd an Amazon ElastiCache cluster that the web servers use to cache the static files in memory

    Incorrect

    A cache next to the servers saves some disk reads, but every byte still travels from the Region to distant readers.

  • CPut AWS Global Accelerator in front of the load balancer to route readers over the AWS network

    Incorrect

    Global Accelerator improves the network path but does not cache content, so the servers would still serve every file.

  • DServe the site through Amazon CloudFront, with the static files moved to Amazon S3 as a second origin

    Correct

    CloudFront caches content at edge locations close to readers, which cuts latency and takes repeated requests off the origin.

Repeated static content for a global audience belongs at the edge: S3 as the store and CloudFront as the cache.

Question 4 · choose 2

A self-managed PostgreSQL database runs on an EC2 instance with a single 1 TB gp2 volume. At peak, the VolumeQueueLength metric climbs, read and write latency rises, and the instance's EBS bandwidth is close to its limit. The workload is random I/O. Which changes remove the bottleneck? (Choose TWO.)

  1. ATurn on EBS encryption for the volume with a customer managed KMS key
  2. BChange the volume to Throughput Optimized HDD (st1) for higher throughput
  3. CModify the volume to gp3 and provision the IOPS and throughput that the peak needs
  4. DMove to an instance type with more dedicated EBS bandwidth and IOPS
  5. ETake EBS snapshots more often so that each incremental snapshot is smaller
Show the answer and why
  • ATurn on EBS encryption for the volume with a customer managed KMS key

    Incorrect

    Encryption protects the data at rest. It does not add IOPS or bandwidth.

  • BChange the volume to Throughput Optimized HDD (st1) for higher throughput

    Incorrect

    HDD volumes suit large sequential I/O. For random database I/O they deliver far fewer IOPS than SSD volumes.

  • CModify the volume to gp3 and provision the IOPS and throughput that the peak needs

    Correct

    gp3 lets you provision IOPS and throughput independently of volume size, so the volume no longer depends on the size-based baseline of gp2.

  • DMove to an instance type with more dedicated EBS bandwidth and IOPS

    Correct

    Each EBS-optimized instance type has a maximum EBS bandwidth and IOPS; if the instance is at that limit, faster volumes alone cannot help.

  • ETake EBS snapshots more often so that each incremental snapshot is smaller

    Incorrect

    Snapshot frequency affects backups, not the volume's performance during peak load.

A queue on the volume plus an instance at its EBS limit means both sides need more: provisioned gp3 performance and an instance with more EBS bandwidth.

Question 5 · choose 1

A video platform serves viewers worldwide through CloudFront from one origin in us-east-1. During popular launches, many edge locations miss at once and the origin is overloaded. Which CloudFront feature reduces load on the origin?

  1. AField-level encryption for viewer requests
  2. BCloudFront Origin Shield
  3. CA shorter cache TTL
  4. DGeographic restrictions by country
Show the answer and why
  • AField-level encryption for viewer requests

    Incorrect

    Field-level encryption protects data; it does not reduce origin load.

  • BCloudFront Origin Shield

    Correct

    Origin Shield is an additional caching layer that helps minimize the origin's load and improve its availability.

  • CA shorter cache TTL

    Incorrect

    Shorter TTLs send more requests to the origin.

  • DGeographic restrictions by country

    Incorrect

    Blocking countries reduces audience, not cache misses.

An extra central cache layer in front of the origin is Origin Shield.

Question 6 · choose 1

An application caches product data in ElastiCache with lazy loading. Users sometimes see old prices for hours after a price changes in the database. Which caching change addresses this?

  1. ARemove the TTL from all cache entries so they never expire
  2. BRead prices only from read replicas of the database
  3. CWrite price changes to the cache too, and add a TTL
  4. DIncrease the cache node size
Show the answer and why
  • ARemove the TTL from all cache entries so they never expire

    Incorrect

    Without a TTL, stale entries stay even longer.

  • BRead prices only from read replicas of the database

    Incorrect

    Bypassing the cache removes its benefit and adds database load.

  • CWrite price changes to the cache too, and add a TTL

    Correct

    With lazy loading alone, cached data can become stale; write-through and TTL strategies address this.

  • DIncrease the cache node size

    Incorrect

    A larger node holds more data but still serves stale entries.

Stale cache data is fixed with write-through updates and a TTL.

Question 7 · choose 1

A risk analytics grid of 40 nodes in one Availability Zone runs on previous-generation EC2 instances that do not use enhanced networking. The nodes exchange millions of small TCP messages, and monitoring shows the network hitting a packets-per-second ceiling with high and uneven latency between nodes, while CPU stays low. The team must raise packet throughput and lower node-to-node latency without changing the TCP-based application, without paying any extra charge for a networking feature, and with roughly the same instance count and hourly spend. Which change meets these requirements?

  1. ALaunch the existing instance types into a cluster placement group so that the nodes sit close together in the Availability Zone
  2. BPut an AWS Global Accelerator accelerator in front of the nodes so that their traffic travels over the AWS global network
  3. CAttach a second elastic network interface to every node and split the grid's messages across the two interfaces
  4. DMove to current-generation instance types of similar size that support ENA, and make sure enhanced networking is turned on
Show the answer and why
  • ALaunch the existing instance types into a cluster placement group so that the nodes sit close together in the Availability Zone

    Incorrect

    Cluster placement groups suit low-latency traffic between instances, but AWS notes that the lowest latency and the highest packets per second also require an instance type that supports enhanced networking, which these instances lack.

  • BPut an AWS Global Accelerator accelerator in front of the nodes so that their traffic travels over the AWS global network

    Incorrect

    Global Accelerator improves the path from internet clients to applications through AWS edge locations and adds hourly and data transfer charges. It does nothing for traffic between nodes in one zone.

  • CAttach a second elastic network interface to every node and split the grid's messages across the two interfaces

    Incorrect

    Multiple network interfaces serve needs such as management networks, network appliances and dual-homed instances. They do not give these instances enhanced networking or lift their packets-per-second ceiling.

  • DMove to current-generation instance types of similar size that support ENA, and make sure enhanced networking is turned on

    Correct

    Enhanced networking provides higher bandwidth, higher packets per second and consistently lower latency between instances, at no additional charge. All Nitro-based instances use ENA for it, and the change needs no application code changes.

The constraints are more packets per second, lower latency, no application change and no extra networking charge. A cluster placement group helps only together with enhanced networking, Global Accelerator serves internet clients at a cost, and extra interfaces do not change the instance's network performance. Current-generation instances with ENA meet every constraint.

Question 8 · choose 1

A Lambda-based checkout API has a known traffic peak every evening from 6 to 9 PM, and cold starts during the peak hurt conversion. The team wants initialized environments ready for that window only. Which approach fits?

  1. AA longer function timeout
  2. BMoving the function into a VPC
  3. CReserved concurrency set to the peak value during the evening
  4. DProvisioned concurrency scheduled for the evening peak
Show the answer and why
  • AA longer function timeout

    Incorrect

    Timeouts do not prevent cold starts.

  • BMoving the function into a VPC

    Incorrect

    VPC access does not keep environments initialized.

  • CReserved concurrency set to the peak value during the evening

    Incorrect

    Reserved concurrency guarantees and caps concurrency but does not initialize environments in advance.

  • DProvisioned concurrency scheduled for the evening peak

    Correct

    Provisioned concurrency keeps pre-initialized execution environments ready to respond immediately to requests.

Predictable peaks are covered with provisioned concurrency for that time.

Question 9 · choose 1

Server metrics for a web application look healthy, but customers complain that pages load slowly in some countries and browsers. The team wants performance data from actual user sessions. Which tool fits?

  1. AAWS Trusted Advisor performance checks
  2. BCloudWatch RUM for the web application
  3. CVPC Flow Logs for the web subnets
  4. DCloudWatch metrics for the load balancer
Show the answer and why
  • AAWS Trusted Advisor performance checks

    Incorrect

    Trusted Advisor checks accounts, not user page loads.

  • BCloudWatch RUM for the web application

    Correct

    CloudWatch RUM collects client-side performance data from actual user sessions in near real time.

  • CVPC Flow Logs for the web subnets

    Incorrect

    Flow logs record IP traffic, not page load times.

  • DCloudWatch metrics for the load balancer

    Incorrect

    Load balancer metrics are measured on the server side, not in users' browsers.

Real user performance is measured with CloudWatch RUM.

Practise domain 3 →Practise all domains →