Skip to content
BytePatterns

SAP-C02 · Domain 4: Accelerate Workload Migration and Modernization · 20% of the exam

Task 4.2: Determine the optimal migration approach for existing workloads.

Picking the transfer path for each piece: servers with AWS Transform MGN (formerly AWS Application Migration Service), databases with AWS DMS and schema conversion, files and objects online with DataSync or Transfer Family or offline on shipped storage, the network and identity the migration needs, and the account governance it lands in.

Study it

  • Moving servers and databases: AWS Transform MGN, AWS DMS and schema conversion

    Lesson coming

  • Moving data: DataSync, Transfer Family, offline transfer and the network to carry it

    Partly covered by: Moving Data Into AWS, Hybrid Networking & DNS

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company will move a 20 TB Oracle database to Amazon Aurora PostgreSQL. The database takes orders around the clock, and the business allows at most 30 minutes of downtime for the cutover. The schema includes PL/SQL procedures that must be converted. Which migration approach meets these requirements?

  1. ACreate an Aurora PostgreSQL read replica of the Oracle database and promote it to a standalone cluster at cutover
  2. BCopy the Oracle data files to Amazon S3 with AWS DataSync and attach the copied files to the new Aurora cluster
  3. CRun an AWS DMS full-load task only, during the cutover window, after converting the schema
  4. DConvert the schema with DMS Schema Conversion or AWS SCT, then run a DMS full load with change data capture
Show the answer and why
  • ACreate an Aurora PostgreSQL read replica of the Oracle database and promote it to a standalone cluster at cutover

    Incorrect

    Aurora PostgreSQL read replicas can be created from RDS for PostgreSQL DB instances. For a database that is not PostgreSQL-compatible, AWS points to AWS DMS.

  • BCopy the Oracle data files to Amazon S3 with AWS DataSync and attach the copied files to the new Aurora cluster

    Incorrect

    DataSync moves files and objects. Aurora PostgreSQL cannot use Oracle data files, and the engines differ.

  • CRun an AWS DMS full-load task only, during the cutover window, after converting the schema

    Incorrect

    A full load of 20 TB takes far longer than 30 minutes, and without ongoing replication every change made during the load is lost.

  • DConvert the schema with DMS Schema Conversion or AWS SCT, then run a DMS full load with change data capture

    Correct

    Schema conversion translates the Oracle schema and code objects to PostgreSQL, and a DMS task with full load plus ongoing replication keeps the target in sync, so cutover needs only a short pause.

Heterogeneous and near-zero downtime: convert the schema first, then full load plus change data capture with AWS DMS.

Question 2 · choose 3

A bank will rehost 200 servers with AWS Transform MGN and move three databases with AWS DMS. Its security policy requires that migration data must not cross the public internet, that database connections are encrypted, and that no database password appears in task or endpoint definitions. The data center already has an AWS Direct Connect connection. Which actions meet the policy? (Choose THREE.)

  1. ATurn on the Use private IP option in the MGN replication settings so replication travels over Direct Connect
  2. BAllow inbound TCP port 1500 to the staging area subnet from 0.0.0.0/0 so that every source server can connect
  3. CKeep the database credentials in AWS Secrets Manager and reference the secrets from the DMS endpoints
  4. DTurn off encryption on the DMS endpoints so that the full load of the large tables runs faster
  5. EConfigure SSL for the DMS source and target endpoint connections
Show the answer and why
  • ATurn on the Use private IP option in the MGN replication settings so replication travels over Direct Connect

    Correct

    By default MGN replicates over the public internet to public IP addresses. The private IP option routes replication through a private connection such as Direct Connect or a VPN.

  • BAllow inbound TCP port 1500 to the staging area subnet from 0.0.0.0/0 so that every source server can connect

    Incorrect

    Only the source servers need to reach the staging area subnet on port 1500. Opening it to every address widens exposure and does nothing for the policy.

  • CKeep the database credentials in AWS Secrets Manager and reference the secrets from the DMS endpoints

    Correct

    DMS endpoints can authenticate with secrets stored in Secrets Manager, so the passwords never appear in the endpoint definitions.

  • DTurn off encryption on the DMS endpoints so that the full load of the large tables runs faster

    Incorrect

    This removes the encryption that the policy requires for database connections.

  • EConfigure SSL for the DMS source and target endpoint connections

    Correct

    AWS DMS can encrypt connections to source and target endpoints with SSL, which meets the encryption requirement.

Private routing for MGN, SSL on DMS endpoints and Secrets Manager for credentials together cover all three parts of the policy.

Question 3 · choose 1

A company must move 500 TB from an on-premises NFS file server to Amazon S3 within four weeks. Its 10 Gbps AWS Direct Connect connection is mostly idle. Users keep changing files until cutover, so the copy must be refreshed incrementally, with the transfers verified and the bandwidth used capped during business hours. Which solution meets these requirements?

  1. ARun an AWS DataSync task from the NFS share to the bucket over Direct Connect on a schedule, with a bandwidth limit
  2. BSet up an AWS Transfer Family SFTP server and have a script upload the changed files to it over SFTP every night
  3. CUpload the files with S3 Transfer Acceleration from a server in the data center, repeating the upload for changed files
  4. DMount the NFS share on an EC2 instance through a VPN and copy it with a scheduled cp command
Show the answer and why
  • ARun an AWS DataSync task from the NFS share to the bucket over Direct Connect on a schedule, with a bandwidth limit

    Correct

    DataSync copies from NFS to S3, can transfer only the data that changed on later runs, includes data integrity validation, and lets you limit the bandwidth that a task uses.

  • BSet up an AWS Transfer Family SFTP server and have a script upload the changed files to it over SFTP every night

    Incorrect

    Transfer Family serves SFTP users. A custom upload script would have to handle change detection, verification and throttling itself.

  • CUpload the files with S3 Transfer Acceleration from a server in the data center, repeating the upload for changed files

    Incorrect

    Transfer Acceleration speeds up uploads over the internet through edge locations. It does not use the idle Direct Connect link or detect changed files.

  • DMount the NFS share on an EC2 instance through a VPN and copy it with a scheduled cp command

    Incorrect

    A copy command has no built-in incremental transfer, verification or bandwidth limit, and a VPN adds a slower path when Direct Connect is available.

Large online file transfers with incremental runs, verification and throttling are what DataSync does over an existing private link.

Question 4 · choose 1

A company will rehost 120 Linux and Windows servers from VMware to Amazon EC2. The applications must not change, each cutover window is at most one hour, and the team wants to test launched instances before each cutover. Which service meets these requirements?

  1. AAWS DMS, migrating the databases on each server and then recreating the rest of each server on EC2 by hand
  2. BVM Import/Export, exporting each virtual machine and importing it as an AMI during its window
  3. CAWS Transform MGN, replicating the servers continuously and launching test instances before cutover
  4. DAWS DataSync, copying each server's disks to Amazon S3 and launching instances from them
Show the answer and why
  • AAWS DMS, migrating the databases on each server and then recreating the rest of each server on EC2 by hand

    Incorrect

    AWS DMS migrates databases, not whole servers, so the rest of each server would have to be rebuilt manually.

  • BVM Import/Export, exporting each virtual machine and importing it as an AMI during its window

    Incorrect

    Importing images is a one-time copy, so every change made after the export is lost or the server must be stopped for the whole import, which is hard to fit into one hour.

  • CAWS Transform MGN, replicating the servers continuously and launching test instances before cutover

    Correct

    MGN replicates source servers continuously at block level, converts them to run on AWS, supports test launches and gives cutover windows typically measured in minutes.

  • DAWS DataSync, copying each server's disks to Amazon S3 and launching instances from them

    Incorrect

    DataSync transfers files and objects. It does not turn server disks into bootable EC2 instances.

Rehosting many servers with short cutovers and test launches is the job of AWS Transform MGN, formerly AWS Application Migration Service.

Question 5 · choose 1

A company is moving a 2 TB RDS for MySQL DB instance to Aurora MySQL and wants the shortest possible write downtime, without third-party tools or a separate replication instance. Which approach fits?

  1. ATake a snapshot, restore it to Aurora, and accept the hours of changes lost
  2. BCreate an Aurora read replica of the RDS instance, then promote it at cutover
  3. CExport the data with mysqldump over the weekend
  4. DCopy the database files to S3 and attach them to Aurora
Show the answer and why
  • ATake a snapshot, restore it to Aurora, and accept the hours of changes lost

    Incorrect

    Changes made after the snapshot would be lost or need a long freeze.

  • BCreate an Aurora read replica of the RDS instance, then promote it at cutover

    Correct

    Aurora can create a special read replica of an RDS for MySQL instance using binary log replication, which is promoted when you migrate.

  • CExport the data with mysqldump over the weekend

    Incorrect

    An export and import of 2 TB means a long write freeze.

  • DCopy the database files to S3 and attach them to Aurora

    Incorrect

    Aurora does not attach copied database files of an RDS instance.

RDS for MySQL moves to Aurora with minimal downtime through an Aurora read replica.

Question 6 · choose 1

A public website with users worldwide is moving from the company's data center to an Application Load Balancer in AWS. The team wants to send 10% of all users to AWS first, raise the share step by step to 100% over two weeks, and keep the on-premises site, which has public IP addresses and no AWS components, as the fallback. If the AWS endpoint fails its health checks during the rollout, traffic must return to the data center automatically, and no client may need new settings. The domain is hosted in Route 53. Which approach meets these requirements?

  1. ARoute 53 weighted records for the AWS and on-premises endpoints, each with a health check, starting at weights of 10 and 90
  2. BAn AWS Global Accelerator standard accelerator whose endpoint group holds both sites, with endpoint weights moving traffic to AWS
  3. CRoute 53 geolocation records that send one country at a time to AWS until every country has moved
  4. DRoute 53 latency-based records for both sites so that each user reaches whichever site answers faster
Show the answer and why
  • ARoute 53 weighted records for the AWS and on-premises endpoints, each with a health check, starting at weights of 10 and 90

    Correct

    Weighted routing sends each resource a share of traffic that matches its relative weight, which suits testing a new version and moving traffic in steps. With health checks on the records, Route 53 stops returning an unhealthy endpoint, so traffic falls back to the other one.

  • BAn AWS Global Accelerator standard accelerator whose endpoint group holds both sites, with endpoint weights moving traffic to AWS

    Incorrect

    Endpoint weights can manage how much traffic each endpoint gets, but a standard accelerator's endpoints must be load balancers, EC2 instances or Elastic IP addresses in AWS. The on-premises site cannot be an endpoint, so there is nothing to fall back to.

  • CRoute 53 geolocation records that send one country at a time to AWS until every country has moved

    Incorrect

    Geolocation routing chooses resources by the users' location, so it moves whole countries, not a controlled 10% share of all users worldwide.

  • DRoute 53 latency-based records for both sites so that each user reaches whichever site answers faster

    Incorrect

    Latency-based routing serves users from the AWS Region with the lowest latency, based on traffic between users and AWS data centers. It gives no control over the share of users, and latency to a non-AWS site is not measured.

The constraints are a controlled percentage of all users, an on-premises fallback with no AWS components, automatic return on failure and no client changes. Global Accelerator cannot use the data center as an endpoint, and geolocation and latency routing do not control percentages. Weighted records with health checks meet all of them through DNS.

Question 7 · choose 1

A company is moving a 4 TB Oracle order database to Aurora PostgreSQL with an AWS DMS task that runs a full load and then change data capture, and the source keeps taking orders until cutover. Before the Oracle system is switched off, auditors want evidence that every migrated row in the target holds the same data as its source row, including rows changed during the CDC phase, with any mismatches reported. The team will not write comparison scripts and accepts some extra query load on both databases. Which DMS capability meets these requirements?

  1. AThe task's table statistics, comparing the inserts, updates and deletes applied to each table with the source's row counts
  2. BA premigration assessment of the task, with its report kept as evidence for the auditors
  3. CThe task's CDCLatencySource and CDCLatencyTarget metrics, showing that replication kept up until the cutover
  4. DDMS data validation turned on for the task, so that full-load and CDC changes are compared with the source
Show the answer and why
  • AThe task's table statistics, comparing the inserts, updates and deletes applied to each table with the source's row counts

    Incorrect

    Table statistics show how many inserts, deletes and updates DMS applied to each table. Matching counts say nothing about whether each row holds the same data as its source row.

  • BA premigration assessment of the task, with its report kept as evidence for the auditors

    Incorrect

    A premigration assessment evaluates a task before it runs to find problems that might prevent it from running as expected. It does not compare migrated data.

  • CThe task's CDCLatencySource and CDCLatencyTarget metrics, showing that replication kept up until the cutover

    Incorrect

    These metrics help find the cause of replication latency. Low latency shows that changes arrive quickly, not that each target row matches its source row.

  • DDMS data validation turned on for the task, so that full-load and CDC changes are compared with the source

    Correct

    Data validation compares each source row with its target row after the full load and compares incremental changes as they occur, reporting any mismatches. It issues its own queries, which adds load to both databases.

The constraints are row-by-row comparison, coverage of CDC changes, reported mismatches and no custom scripts. Table statistics only count changes, a premigration assessment runs before the move, and latency metrics measure speed. DMS data validation compares every row, including ongoing changes, and reports mismatches.

Question 8 · choose 1

A company's data center uses parts of 10.0.0.0/8 for 4,000 servers. Over a two-year migration, about 60 new VPCs in 30 accounts will attach to one transit gateway that reaches the data center over AWS Direct Connect, with routes propagated into a shared transit gateway route table so that every VPC can reach on-premises systems and shared services. The migrated applications support only IPv4, on-premises servers must keep opening connections to them, and the network team will not operate any address translation. What should guide the choice of the VPC CIDR ranges?

  1. AReuse one range in every VPC and connect each VPC to the data center through private NAT gateways
  2. BBuild the new VPCs with IPv6-only subnets so that their addresses can never overlap any IPv4 network
  3. CChoose ranges that overlap neither the on-premises networks nor each other, sized for growth over the migration
  4. DUse the default VPC that already exists in each account so that no new ranges have to be planned
Show the answer and why
  • AReuse one range in every VPC and connect each VPC to the data center through private NAT gateways

    Incorrect

    A private NAT gateway can enable communication between networks even when their CIDR ranges overlap, which helps when overlap already exists. Here it is the address translation the team will not run, and every VPC would need it.

  • BBuild the new VPCs with IPv6-only subnets so that their addresses can never overlap any IPv4 network

    Incorrect

    IPv6-only subnets have no IPv4 CIDR block, and their resources must communicate over IPv6. The migrated applications support only IPv4.

  • CChoose ranges that overlap neither the on-premises networks nor each other, sized for growth over the migration

    Correct

    A transit gateway does not support routing between VPCs with identical or overlapping CIDRs; routes for an overlapping VPC are not propagated. Unique ranges that also avoid on-premises networks let every VPC and the data center reach each other without translation.

  • DUse the default VPC that already exists in each account so that no new ranges have to be planned

    Incorrect

    Default VPCs need no planning, but every default VPC uses the 172.31.0.0/16 CIDR block, so the VPCs of different accounts overlap one another and cannot all be routed through the transit gateway.

The constraints are full routing through one transit gateway, IPv4-only applications, connections initiated from on premises, and no address translation. Private NAT gateways translate addresses, IPv6-only subnets do not fit IPv4-only applications, and default VPCs all share one range. Unique, non-overlapping ranges are the only option that meets every constraint.

Question 9 · choose 2

A film studio with AWS Enterprise Support is closing a facility. Its 900 TB of finished footage sits on 60 portable NVMe drives that are not connected to any network, and all of it must be in an S3 bucket within three weeks. The facility has a 1 Gbps internet link and no AWS Direct Connect, and staff can carry the drives to another city. Auditors require proof that every object in S3 is bit-for-bit identical to its source file, based on hashes that the studio computes before the drives leave the facility. Which actions meet these requirements? (Choose TWO.)

  1. ATurn on S3 Transfer Acceleration for the bucket and upload the footage over the facility's internet link
  2. BTurn on S3 Object Lock in compliance mode on the bucket so that the uploaded objects cannot be changed
  3. CUpload each file with its precalculated full-object CRC-64/NVME checksum so that S3 verifies it and stores the value
  4. DWrite the footage to virtual tapes through an AWS Storage Gateway Tape Gateway at the facility
  5. EBook a reservation at an AWS Data Transfer Terminal and upload the drives there with the studio's own devices
Show the answer and why
  • ATurn on S3 Transfer Acceleration for the bucket and upload the footage over the facility's internet link

    Incorrect

    Transfer Acceleration speeds up long-distance transfers through edge locations, but it cannot add bandwidth: a fully used 1 Gbps link moves less than 230 TB in three weeks.

  • BTurn on S3 Object Lock in compliance mode on the bucket so that the uploaded objects cannot be changed

    Incorrect

    Object Lock stops object versions from being overwritten or deleted after they are stored. It does not show that what was stored matches the files on the drives.

  • CUpload each file with its precalculated full-object CRC-64/NVME checksum so that S3 verifies it and stores the value

    Correct

    When a precalculated checksum is supplied, including the full object checksum type for multipart uploads, S3 calculates its own value, compares the two before storing the object, and keeps the checksum with the object as evidence.

  • DWrite the footage to virtual tapes through an AWS Storage Gateway Tape Gateway at the facility

    Incorrect

    Tape Gateway replaces physical tape infrastructure for backup software and archives virtual tapes in S3 Glacier storage classes. It does not deliver the files as objects in the bucket, and it would still use the 1 Gbps link.

  • EBook a reservation at an AWS Data Transfer Terminal and upload the drives there with the studio's own devices

    Correct

    Data Transfer Terminal facilities are network-ready locations where customers bring their own storage devices for fast uploads to AWS after reserving a time in the console. The service is available to Enterprise Support customers.

The network rules out any online path in three weeks, so the drives have to travel to a place with fast connectivity, which is what Data Transfer Terminal provides for Enterprise Support customers. Integrity is a separate requirement: supplying the checksums computed at the facility on upload makes S3 reject any object whose data does not match and keeps the checksum with each object for the auditors.

Practise domain 4 →Practise all domains →