pencils ready ✎

AWS MCQs multiple-choice questions with answers & explanations

All 21 AWS quiz questions on one page. Pick an answer in your head, then open Show answer to check it and read why. Want a score and a timer? Take them as a quiz instead.

  1. 1.

    A security group allows inbound TCP 443 from 0.0.0.0/0 and has no outbound rules. What happens to the HTTPS responses sent back to clients?

    easy
    1. AThey are dropped, because no outbound rule allows them
    2. BThey are sent only once an outbound 443 rule is added
    3. CThey are allowed, because security groups are stateful
    4. DThey are allowed only for clients inside the same VPC
    Show answer

    Answer: C (They are allowed, because security groups are stateful)

    Security groups are stateful: return traffic for a connection that an inbound rule allowed is permitted automatically, whatever the outbound rules say. Outbound rules only matter for connections the instance itself initiates. Network ACLs are the stateless ones that need explicit return rules.

  2. 2.

    A custom network ACL on a public subnet allows only inbound TCP 443 and outbound TCP 443. Internet clients cannot complete HTTPS requests to a web server in that subnet. Why?

    mid
    1. AResponses go to client ephemeral ports, which are blocked
    2. BThe security group also needs an outbound rule for 443
    3. CNACL rules only apply to traffic between subnets in a VPC
    4. DInbound 443 needs a higher rule number than outbound 443
    Show answer

    Answer: A (Responses go to client ephemeral ports, which are blocked)

    NACLs are stateless, so the server's responses are evaluated as new outbound traffic. They go to the client's ephemeral port (a high port, not 443), and the outbound rules block that range. Security groups are stateful and don't need an outbound rule for responses.

  3. 3.

    Medical images are read about once a quarter, must be retrievable in milliseconds, and are kept for years. Which S3 storage class is the most cost-effective fit?

    easy
    1. AS3 Standard-IA
    2. BS3 Glacier Instant Retrieval
    3. CS3 Glacier Deep Archive
    4. DS3 Glacier Flexible Retrieval
    Show answer

    Answer: B (S3 Glacier Instant Retrieval)

    S3 Glacier Instant Retrieval is designed for long-lived data accessed about once a quarter that still needs millisecond retrieval, with lower storage cost than Standard-IA. Glacier Flexible Retrieval and Deep Archive are cheaper to store but take minutes to hours to restore.

  4. 4.

    A role has only this policy attached, and no other policies apply. What happens when it calls s3:DeleteObject on arn:aws:s3:::reports/2024.csv?

    mid
    {
      "Version": "2012-10-17",
      "Statement": [
        { "Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::reports/*" },
        { "Effect": "Deny", "Action": "s3:DeleteObject", "Resource": "arn:aws:s3:::reports/*" }
      ]
    }
    1. AAllowed, because the Allow statement is listed first
    2. BAllowed, because s3:* is broader than the Deny
    3. CDenied only if the bucket policy also denies it
    4. DDenied, because an explicit Deny overrides an Allow
    Show answer

    Answer: D (Denied, because an explicit Deny overrides an Allow)

    In AWS policy evaluation an explicit Deny in any applicable policy always wins, regardless of statement order or how broad the Allow is. The role can do every other S3 object action on reports/*, but not DeleteObject.

  5. 5.

    An SQS standard queue has a 30-second visibility timeout. A consumer takes about 90 seconds to process each message and deletes it afterwards. What is the most likely result?

    mid
    1. ASQS extends the visibility timeout to 90 seconds by itself
    2. BMessages reappear and are processed more than once
    3. CThe delete fails and the message moves to the DLQ at once
    4. DMessages are discarded after 30 seconds if not deleted
    Show answer

    Answer: B (Messages reappear and are processed more than once)

    After 30 seconds the message becomes visible again and another consumer receives it while the first is still working, so it is processed twice or more. SQS never extends the timeout on its own; the consumer must call ChangeMessageVisibility or the queue timeout must be raised. Unprocessed messages are not discarded, and they only move to a DLQ after maxReceiveCount receives.

  6. 6.

    You need an RTO of minutes. You keep a scaled-down but fully functional copy of production running in a second Region and scale it up during a disaster. Which DR strategy is this?

    mid
    1. ABackup and restore
    2. BPilot light
    3. CWarm standby
    4. DMulti-site active/active
    Show answer

    Answer: C (Warm standby)

    Warm standby keeps a smaller but working copy that can take traffic immediately and only needs scaling up. Pilot light keeps data replicated and core infrastructure ready, but application servers are switched off, so it can't serve requests until they are started. Active/active serves production traffic from every Region all the time.

  7. 7.

    An existing DynamoDB table uses customerId as its partition key. You now need to query items by email. What can you add to the existing table?

    mid
    1. AA global secondary index with email as partition key
    2. BA local secondary index with email as partition key
    3. CA local secondary index with email as the sort key
    4. DNothing; you have to recreate the table with a new key
    Show answer

    Answer: A (A global secondary index with email as partition key)

    A GSI can use any attribute as its partition key and can be added to an existing table at any time. LSIs must keep the table's partition key and can only be created together with the table, so neither LSI option works.

  8. 8.

    A nightly job needs about 40 minutes of continuous processing in a single run. Which statement about running it as one Lambda invocation is correct?

    easy
    1. AIt works if you raise the function timeout to 60 minutes
    2. BIt works if you give the function the maximum memory
    3. CIt works if the function is invoked asynchronously
    4. DIt won't work; the maximum timeout is 15 minutes
    Show answer

    Answer: D (It won't work; the maximum timeout is 15 minutes)

    A Lambda invocation can run for at most 15 minutes, whatever the memory setting or invocation type. Split the job into smaller chunks orchestrated by Step Functions, or run it as an ECS task on Fargate or with AWS Batch.

  9. 9.

    A partner must allowlist fixed IP addresses for a TCP service you run on EC2. The service also needs very low latency and preservation of the client source IP. Which load balancer fits best?

    mid
    1. AApplication Load Balancer
    2. BNetwork Load Balancer
    3. CGateway Load Balancer
    4. DClassic Load Balancer
    Show answer

    Answer: B (Network Load Balancer)

    An NLB works at layer 4, offers a static IP per AZ (optionally your own Elastic IPs), very low latency and client source IP preservation. An ALB is for HTTP-level routing and has no fixed IPs on its own. A GWLB is for inserting virtual appliances, and the Classic Load Balancer is legacy.

  10. 10.

    Your RDS for PostgreSQL database runs as a Multi-AZ DB instance deployment, and read traffic is overloading the primary. What should you add to offload reads?

    easy
    1. ANothing; send reads to the Multi-AZ standby
    2. BA second Multi-AZ standby in another AZ
    3. COne or more read replicas
    4. DA larger EBS volume on the standby
    Show answer

    Answer: C (One or more read replicas)

    In a Multi-AZ DB instance deployment the standby exists only for failover and serves no read traffic. Read replicas have their own endpoints and are the tool for scaling reads (a Multi-AZ DB cluster deployment, by contrast, does have readable standbys).

  11. 11.

    VPC A is peered with VPC B, and VPC B is peered with VPC C. The CIDRs do not overlap and each peering has its routes configured. Can instances in A reach instances in C?

    easy
    1. AYes, traffic is routed through VPC B automatically
    2. BYes, if VPC B enables forwarding in its route tables
    3. COnly if all three VPCs are in the same AWS account
    4. DNo, peering is not transitive; peer A and C directly
    Show answer

    Answer: D (No, peering is not transitive; peer A and C directly)

    VPC peering is strictly one-to-one and doesn't support transitive routing, regardless of accounts. Either create a peering between A and C, or use a Transit Gateway as a hub when many VPCs need to talk.

  12. 12.

    Instances in a private subnet upload large volumes of data to S3 in the same Region, and NAT gateway data processing charges are high. What is the cheapest fix?

    mid
    1. AAdd an S3 gateway VPC endpoint to the route tables
    2. BEnable S3 Transfer Acceleration on the bucket
    3. CAdd a second NAT gateway in another Availability Zone
    4. DCreate an S3 interface endpoint in every subnet
    Show answer

    Answer: A (Add an S3 gateway VPC endpoint to the route tables)

    A gateway endpoint for S3 routes that traffic privately without the NAT gateway, and gateway endpoints have no charge. An interface endpoint would also bypass NAT but adds hourly and per-GB costs. Transfer Acceleration and another NAT gateway only add cost.

  13. 13.

    In envelope encryption with AWS KMS, what does a GenerateDataKey call return?

    hard
    1. AOnly an encrypted data key; KMS keeps the plaintext
    2. BThe KMS key material itself, for local encryption
    3. CA plaintext data key plus that key encrypted by KMS
    4. DYour payload encrypted inside KMS with the KMS key
    Show answer

    Answer: C (A plaintext data key plus that key encrypted by KMS)

    You use the plaintext data key to encrypt data locally, discard it, and store the encrypted copy next to the ciphertext; later Decrypt recovers the data key. KMS key material never leaves KMS. Returning only the encrypted key is what GenerateDataKeyWithoutPlaintext does.

  14. 14.

    Your app runs in us-east-1 and eu-west-1. You want Route 53 to send each user to whichever Region gives them the lowest latency. Which routing policy do you use?

    easy
    1. AGeolocation routing
    2. BLatency-based routing
    3. CWeighted routing
    4. DMultivalue answer routing
    Show answer

    Answer: B (Latency-based routing)

    Latency-based routing answers with the record for the Region that gives the user the lowest measured latency. Geolocation routes by the user's location, which isn't the same thing as network latency; weighted splits traffic by proportions you set, and multivalue returns several healthy records at random.

  15. 15.

    How much warning does EC2 give before it interrupts a Spot Instance?

    easy
    1. ATwo minutes
    2. BTen minutes
    3. COne hour
    4. DNo warning at all
    Show answer

    Answer: A (Two minutes)

    EC2 issues a Spot interruption notice two minutes before stopping, hibernating or terminating the instance, visible through instance metadata and EventBridge. EC2 may also send an earlier rebalance recommendation when an instance is at elevated risk, but the guaranteed notice is two minutes.

  16. 16.

    An instance has an EBS root volume and an instance store volume holding cached files. What happens to the instance store data when you stop and then start the instance?

    easy
    1. AIt is preserved, just as it is on a reboot
    2. BIt is copied to an EBS snapshot automatically
    3. CIt is preserved only because the root is EBS-backed
    4. DIt is lost, because instance store is ephemeral
    Show answer

    Answer: D (It is lost, because instance store is ephemeral)

    Instance store data survives a reboot but is lost when the instance stops, hibernates or terminates, because the instance usually starts on different hardware. An EBS root volume doesn't change that, and AWS never snapshots instance store automatically.

  17. 17.

    An order workflow may wait days for a human approval using a task token, and every step must run exactly once. Which Step Functions workflow type fits?

    hard
    1. AAsynchronous Express workflow
    2. BSynchronous Express workflow
    3. CStandard workflow
    4. DEither Express type, with Retry configured
    Show answer

    Answer: C (Standard workflow)

    Standard workflows run for up to a year with exactly-once execution and support the .waitForTaskToken callback pattern. Express workflows run for at most five minutes, are at-least-once (asynchronous) or at-most-once (synchronous), and support neither callbacks nor .sync jobs.

  18. 18.

    You move a self-managed MySQL database from an on-premises VM to Amazon RDS for MySQL without changing the application's architecture. Which of the 7 Rs is this?

    easy
    1. ARehost
    2. BReplatform
    3. CRefactor
    4. DRepurchase
    Show answer

    Answer: B (Replatform)

    Replatforming ("lift, tinker and shift") adds targeted optimizations, like moving to a managed database, without redesigning the application. Rehosting would move the VM as it is onto EC2, refactoring redesigns the application, and repurchasing replaces it with a different product.

  19. 19.

    What does a successful sts:AssumeRole call return to the caller?

    mid
    1. AA new IAM user with access keys for the role
    2. BA console password valid for one hour
    3. CLong-term access keys stored on the role
    4. DTemporary credentials with a session token
    Show answer

    Answer: D (Temporary credentials with a session token)

    STS returns an access key ID, a secret access key and a session token that expire after the session duration. Roles never have long-term credentials, which is exactly why they are preferred over IAM users for workloads and cross-account access.

  20. 20.

    A Lambda function uses its execution role to generate an S3 presigned URL with ExpiresIn set to 7 days. What happens?

    hard
    1. AIt stops working when the role session credentials expire
    2. BIt works for the full 7 days, since S3 honors ExpiresIn
    3. CGeneration fails because roles cannot sign presigned URLs
    4. DIt works for 7 days, but only from inside the same VPC
    Show answer

    Answer: A (It stops working when the role session credentials expire)

    A presigned URL is only valid while the credentials that signed it are valid, whichever comes first. Lambda's execution role credentials are temporary and last far less than 7 days, so the URL stops working early. Roles can sign presigned URLs; the 7-day maximum applies to long-term IAM user credentials with Signature Version 4.

  21. 21.

    A process PUTs a new object to S3 and immediately calls ListObjectsV2 on its prefix. What does the listing show?

    mid
    1. AThe object may be missing for a few seconds
    2. BThe object appears only after a HEAD request
    3. CThe object; listings are strongly consistent
    4. DThe object only if versioning is enabled
    Show answer

    Answer: C (The object; listings are strongly consistent)

    S3 provides strong read-after-write consistency for PUT and DELETE, and that includes LIST operations, in all Regions at no extra cost. The eventual consistency described in older material no longer applies to object operations; only bucket configuration changes are eventually consistent.

esc