Skip to content
BytePatterns

SAP-C02 · Domain 4: Accelerate Workload Migration and Modernization · 20% of the exam

Task 4.1: Select existing workloads and processes for potential migration.

Deciding what moves, how and when: portfolio discovery and assessment, the seven migration strategies, total cost of ownership, and wave planning.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A portfolio assessment of 400 on-premises applications shows 35 applications whose servers averaged under 5% CPU and memory use for the last 90 days and that received no inbound connections in that time. The business confirms that nobody needs them. Which migration strategy should the company assign to these applications?

  1. ARehost, so that they move quickly to Amazon EC2 without changes
  2. BRetain, so that they stay in the data center until a later wave
  3. CRetire, so that their servers are shut down and the data archived where needed
  4. DRelocate, so that the servers move as they are to a cloud version of their platform
Show the answer and why
  • ARehost, so that they move quickly to Amazon EC2 without changes

    Incorrect

    Rehosting moves applications unchanged, which would carry unused applications into AWS and keep paying to host them.

  • BRetain, so that they stay in the data center until a later wave

    Incorrect

    Retain keeps applications in the source environment for now, for example because of compliance, risk or dependencies. It still keeps them running and costing money.

  • CRetire, so that their servers are shut down and the data archived where needed

    Correct

    Retire is the strategy for applications with no business value; AWS guidance names applications with very low use and no inbound connections for 90 days as candidates.

  • DRelocate, so that the servers move as they are to a cloud version of their platform

    Incorrect

    Relocating still moves and runs the applications, only on a different platform, so it keeps paying for something nobody uses.

Not every application should move. Unused applications found in the assessment are retired, which also shrinks the migration.

Question 2 · choose 1

A company is starting its first large migration: about 1,500 VMware virtual machines in two data centers. It needs an inventory of the servers, a map of the dependencies between them, and migration waves that keep dependent servers together. The company has not used any AWS migration service before. Which AWS service should it use for discovery and wave planning?

  1. AAWS Transform, using its discovery, dependency analysis and wave planning capabilities
  2. BAWS Config with an aggregator for all accounts, recording the virtual machines as configuration items
  3. CAWS Compute Optimizer, opting in the data center hosts to receive sizing recommendations
  4. DAWS Trusted Advisor, with its checks extended to the on-premises environment
Show the answer and why
  • AAWS Transform, using its discovery, dependency analysis and wave planning capabilities

    Correct

    AWS Transform collects and analyzes on-premises server inventory, groups applications, identifies dependencies and builds prioritized migration waves.

  • BAWS Config with an aggregator for all accounts, recording the virtual machines as configuration items

    Incorrect

    AWS Config records the configuration of AWS resources. It does not discover virtual machines in a data center or plan migration waves.

  • CAWS Compute Optimizer, opting in the data center hosts to receive sizing recommendations

    Incorrect

    Compute Optimizer analyzes AWS resources that already run in AWS accounts. It cannot inventory on-premises servers.

  • DAWS Trusted Advisor, with its checks extended to the on-premises environment

    Incorrect

    Trusted Advisor inspects an AWS environment against best practices. It has no discovery or wave planning for on-premises servers.

Discovery, dependency mapping and wave planning for a new migration are capabilities of AWS Transform, which AWS now recommends in place of AWS Migration Hub and AWS Application Discovery Service, both of which no longer accept new customers.

Question 3 · choose 1

Before approving a migration budget, the CFO wants a data-driven business case that compares the current on-premises cost of 900 servers with the projected cost on AWS, based on the servers' real utilization, and that compares bringing existing Windows and SQL Server licenses with using license-included instances. Which approach meets this requirement?

  1. AEnter each server's current size into the AWS Pricing Calculator and total the monthly estimates
  2. BRequest an assessment with Migration Evaluator and collect utilization data with its agentless collector
  3. CUse AWS Cost Explorer forecasting on a pilot account to project the cost of the whole server estate
  4. DCreate AWS Budgets for the target accounts and compare those budgets with the current data center costs
Show the answer and why
  • AEnter each server's current size into the AWS Pricing Calculator and total the monthly estimates

    Incorrect

    The Pricing Calculator estimates the cost of AWS services that you describe. Typing in today's sizes ignores actual utilization and does not collect data from the servers.

  • BRequest an assessment with Migration Evaluator and collect utilization data with its agentless collector

    Correct

    Migration Evaluator builds a data-driven business case from discovered on-premises usage, recommends cost-effective AWS alternatives and compares bring-your-own-license with license-included options.

  • CUse AWS Cost Explorer forecasting on a pilot account to project the cost of the whole server estate

    Incorrect

    Cost Explorer forecasts from spend that already happens on AWS. A pilot account says little about 900 servers that have not moved.

  • DCreate AWS Budgets for the target accounts and compare those budgets with the current data center costs

    Incorrect

    Budgets track spend against a limit that you set. They do not estimate what the servers would cost on AWS.

A TCO business case built on real utilization and licensing options is what Migration Evaluator produces.

Question 4 · choose 1

A company is planning migration waves for 600 servers. Its order system runs on 12 servers that share one database cluster with the billing system, which runs on 8 other servers. The two systems must keep low latency to the shared database during and after the migration. How should the wave plan treat these servers?

  1. AMove the order system in the first wave and the billing system in a later wave so that each wave stays small
  2. BOrder the waves by server operating system so that each wave uses one migration runbook
  3. CPut the order servers, the billing servers and the database cluster in the same move group and wave
  4. DMove the database cluster first and leave both systems on premises until the last wave
Show the answer and why
  • AMove the order system in the first wave and the billing system in a later wave so that each wave stays small

    Incorrect

    Splitting systems that share a database leaves one of them talking to the database across the hybrid link between waves, which breaks the latency requirement.

  • BOrder the waves by server operating system so that each wave uses one migration runbook

    Incorrect

    Grouping by operating system ignores the shared database dependency that AWS guidance asks wave planning to account for.

  • CPut the order servers, the billing servers and the database cluster in the same move group and wave

    Correct

    Wave planning groups applications by their infrastructure and application dependencies, such as a shared database, so that servers that must stay together move together.

  • DMove the database cluster first and leave both systems on premises until the last wave

    Incorrect

    Both systems would then reach the database across the hybrid link for most of the migration, which again breaks the latency requirement.

Dependencies decide move groups: servers that share a database and need low latency to it migrate in the same wave.

Question 5 · choose 1

During migration assessment, a manufacturer finds a quality-control application that must process sensor data inside the factory with very low latency to machines on the shop floor. The company still wants AWS APIs and tools for it. Which option fits this workload?

  1. ARefactor it into Lambda functions in a Region near the factory
  2. BRun it on AWS Outposts installed at the factory
  3. CRehost it to EC2 in the nearest Region
  4. DRetire the application
Show the answer and why
  • ARefactor it into Lambda functions in a Region near the factory

    Incorrect

    Functions in a Region are still away from the factory floor.

  • BRun it on AWS Outposts installed at the factory

    Correct

    Outposts extends AWS infrastructure, services and APIs to customer premises for lower latency and local data processing needs.

  • CRehost it to EC2 in the nearest Region

    Incorrect

    A Region far from the factory adds network latency to the machines.

  • DRetire the application

    Incorrect

    The application is needed for quality control.

Workloads that need local processing with AWS tools fit AWS Outposts.

Question 6 · choose 1

A company's migration plan moves SQL Server Enterprise and Oracle workloads into 30 accounts of its organization under its own core-based licenses. The contracts cap the number of cores the company may use, and an audit last year found overuse that cost millions. The licensing team wants one view of license consumption across all accounts and Regions, and launches that would exceed the purchased cores must be stopped before they happen rather than reported afterwards. Which service should the migration plan include to meet these requirements?

  1. ASystems Manager Inventory in every account, synchronized to a central S3 bucket and queried for the installed database software
  2. BService Catalog portfolios that offer only approved database products, shared with every account that runs these workloads
  3. CAWS License Manager with license configurations and hard limits, managed for all accounts of the organization
  4. DThe AWS Config approved-amis-by-id managed rule, deployed to every account with the licensed database AMIs as its parameter
Show the answer and why
  • ASystems Manager Inventory in every account, synchronized to a central S3 bucket and queried for the installed database software

    Incorrect

    Inventory collects metadata from managed nodes into a central bucket, which shows where the software runs. It reports usage after the fact and cannot stop a launch that would exceed the licensed cores.

  • BService Catalog portfolios that offer only approved database products, shared with every account that runs these workloads

    Incorrect

    A portfolio controls which products teams can launch, but it does not count cores against a license contract or stop the hundredth launch once the purchased cores are used up.

  • CAWS License Manager with license configurations and hard limits, managed for all accounts of the organization

    Correct

    License Manager tracks licenses based on vCPUs, cores, sockets or machines across accounts and Regions of an organization. Administrators can set hard limits, so License Manager helps stop noncompliant usage before it happens.

  • DThe AWS Config approved-amis-by-id managed rule, deployed to every account with the licensed database AMIs as its parameter

    Incorrect

    The rule marks running instances whose AMIs are not on the approved list as noncompliant. It detects after launch and knows nothing about how many licensed cores are in use.

The constraints are one view across accounts and Regions, counting by cores, and prevention rather than reporting. Inventory and a Config rule both detect after launch, and a Service Catalog portfolio controls what can be launched but not how much. License Manager with hard limits on license configurations counts cores organization-wide and stops launches that would exceed them.

Question 7 · choose 1

During a migration assessment, a brokerage reviews its pricing application: one feed handler server publishes prices by IP multicast to 25 Linux consumer servers, and the code cannot change this year. The infrastructure team proposes to retain the application on premises because, it says, VPCs cannot carry multicast. The business wants the application in AWS if that is possible without code changes. The data center reaches AWS over AWS Direct Connect. Which assessment outcome is correct?

  1. ARehost the feed handler and all 25 consumers together on Nitro-based instances in subnets of a transit gateway multicast domain
  2. BRetain the application on premises, because VPC networking cannot deliver multicast traffic between EC2 instances
  3. CRefactor the feed handler to publish prices to Amazon MSK topics that the consumers read with Kafka clients
  4. DRehost the feed handler first and leave the consumers on premises to receive the multicast feed over Direct Connect
Show the answer and why
  • ARehost the feed handler and all 25 consumers together on Nitro-based instances in subnets of a transit gateway multicast domain

    Correct

    Rehosting moves the servers without changing the application. A transit gateway multicast domain delivers the feed between the subnets, and a sender must be a Nitro instance. Moving every consumer with the feed handler matters because multicast is not routed over Direct Connect.

  • BRetain the application on premises, because VPC networking cannot deliver multicast traffic between EC2 instances

    Incorrect

    Retain fits applications that cannot or should not move yet, but the premise is wrong: a transit gateway multicast domain routes multicast traffic between subnets of attached VPCs.

  • CRefactor the feed handler to publish prices to Amazon MSK topics that the consumers read with Kafka clients

    Incorrect

    Amazon MSK runs Apache Kafka, which suits a redesigned streaming platform, but moving producers and consumers to Kafka clients is a refactor of the code, which the company cannot do this year.

  • DRehost the feed handler first and leave the consumers on premises to receive the multicast feed over Direct Connect

    Incorrect

    Transit gateway multicast routing is not supported over Direct Connect, Site-to-Site VPN, peering or Connect attachments, so consumers left on premises would stop receiving the feed.

An assessment should test the stated blocker before choosing Retain. AWS Transit Gateway supports multicast domains, so the application can be rehosted without code changes, but the details shape the plan: senders need Nitro instances, and because multicast does not cross Direct Connect or VPN, the feed handler and every consumer belong in the same move group.

Question 8 · choose 1

A bank's portfolio assessment includes COBOL applications on an IBM z/OS mainframe. Leaders want to modernize them on AWS rather than keep the mainframe, and want AWS tooling to help analyze and transform the code. Which option should the plan evaluate?

  1. ARepurchase a SaaS product for every COBOL application
  2. BRetain the mainframe indefinitely
  3. CRehost the mainframe image to EC2 with AWS Transform MGN
  4. DAWS Transform for mainframe modernization
Show the answer and why
  • ARepurchase a SaaS product for every COBOL application

    Incorrect

    Custom banking applications rarely have SaaS equivalents for each one.

  • BRetain the mainframe indefinitely

    Incorrect

    Leaders want to move away from the mainframe.

  • CRehost the mainframe image to EC2 with AWS Transform MGN

    Incorrect

    Server replication rehosts virtual and bare metal servers; it does not run a z/OS mainframe image on EC2.

  • DAWS Transform for mainframe modernization

    Correct

    AWS Transform can modernize and migrate IBM z/OS workloads to AWS.

Mainframe modernization on AWS is evaluated with AWS Transform.

Question 9 · choose 1

A regulator requires an insurer's encryption keys for one workload to stay in a key manager that the insurer controls outside AWS. The insurer wants to know whether the workload can still use AWS services that encrypt with KMS. Which capability addresses this gap?

  1. AA CloudHSM cluster in the workload's VPC as a custom key store
  2. BAWS managed keys for each service
  3. CCustomer managed keys in KMS with automatic rotation turned on
  4. DAn AWS KMS external key store backed by the insurer's key manager
Show the answer and why
  • AA CloudHSM cluster in the workload's VPC as a custom key store

    Incorrect

    CloudHSM runs inside AWS, not in the insurer's own key manager.

  • BAWS managed keys for each service

    Incorrect

    AWS managed keys are kept inside AWS KMS.

  • CCustomer managed keys in KMS with automatic rotation turned on

    Incorrect

    Rotation changes key material but keeps it inside AWS KMS.

  • DAn AWS KMS external key store backed by the insurer's key manager

    Correct

    External key stores protect AWS resources with keys outside of AWS, in an external key management system that you control.

Keys that must stay outside AWS are used through an external key store.

Practise domain 4 →Practise all domains →