AWS MCQs multiple-choice questions with answers & explanations
All 21 AWS quiz questions on one page. Pick an answer in your head, then open Show answer to check it and read why. Want a score and a timer? Take them as a quiz instead.
- 1.easy
A security group allows inbound TCP 443 from
0.0.0.0/0and has no outbound rules. What happens to the HTTPS responses sent back to clients?- AThey are dropped, because no outbound rule allows them
- BThey are sent only once an outbound 443 rule is added
- CThey are allowed, because security groups are stateful
- DThey are allowed only for clients inside the same VPC
Show answer
Answer: C (They are allowed, because security groups are stateful)
Security groups are stateful: return traffic for a connection that an inbound rule allowed is permitted automatically, whatever the outbound rules say. Outbound rules only matter for connections the instance itself initiates. Network ACLs are the stateless ones that need explicit return rules.
- 2.mid
A custom network ACL on a public subnet allows only inbound TCP 443 and outbound TCP 443. Internet clients cannot complete HTTPS requests to a web server in that subnet. Why?
- AResponses go to client ephemeral ports, which are blocked
- BThe security group also needs an outbound rule for 443
- CNACL rules only apply to traffic between subnets in a VPC
- DInbound 443 needs a higher rule number than outbound 443
Show answer
Answer: A (Responses go to client ephemeral ports, which are blocked)
NACLs are stateless, so the server's responses are evaluated as new outbound traffic. They go to the client's ephemeral port (a high port, not 443), and the outbound rules block that range. Security groups are stateful and don't need an outbound rule for responses.
- 3.easy
Medical images are read about once a quarter, must be retrievable in milliseconds, and are kept for years. Which S3 storage class is the most cost-effective fit?
- AS3 Standard-IA
- BS3 Glacier Instant Retrieval
- CS3 Glacier Deep Archive
- DS3 Glacier Flexible Retrieval
Show answer
Answer: B (S3 Glacier Instant Retrieval)
S3 Glacier Instant Retrieval is designed for long-lived data accessed about once a quarter that still needs millisecond retrieval, with lower storage cost than Standard-IA. Glacier Flexible Retrieval and Deep Archive are cheaper to store but take minutes to hours to restore.
- 4.mid
A role has only this policy attached, and no other policies apply. What happens when it calls
s3:DeleteObjectonarn:aws:s3:::reports/2024.csv?{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::reports/*" }, { "Effect": "Deny", "Action": "s3:DeleteObject", "Resource": "arn:aws:s3:::reports/*" } ] }- AAllowed, because the Allow statement is listed first
- BAllowed, because s3:* is broader than the Deny
- CDenied only if the bucket policy also denies it
- DDenied, because an explicit Deny overrides an Allow
Show answer
Answer: D (Denied, because an explicit Deny overrides an Allow)
In AWS policy evaluation an explicit
Denyin any applicable policy always wins, regardless of statement order or how broad theAllowis. The role can do every other S3 object action onreports/*, but notDeleteObject. - 5.mid
An SQS standard queue has a 30-second visibility timeout. A consumer takes about 90 seconds to process each message and deletes it afterwards. What is the most likely result?
- ASQS extends the visibility timeout to 90 seconds by itself
- BMessages reappear and are processed more than once
- CThe delete fails and the message moves to the DLQ at once
- DMessages are discarded after 30 seconds if not deleted
Show answer
Answer: B (Messages reappear and are processed more than once)
After 30 seconds the message becomes visible again and another consumer receives it while the first is still working, so it is processed twice or more. SQS never extends the timeout on its own; the consumer must call
ChangeMessageVisibilityor the queue timeout must be raised. Unprocessed messages are not discarded, and they only move to a DLQ aftermaxReceiveCountreceives. - 6.mid
You need an RTO of minutes. You keep a scaled-down but fully functional copy of production running in a second Region and scale it up during a disaster. Which DR strategy is this?
- ABackup and restore
- BPilot light
- CWarm standby
- DMulti-site active/active
Show answer
Answer: C (Warm standby)
Warm standby keeps a smaller but working copy that can take traffic immediately and only needs scaling up. Pilot light keeps data replicated and core infrastructure ready, but application servers are switched off, so it can't serve requests until they are started. Active/active serves production traffic from every Region all the time.
- 7.mid
An existing DynamoDB table uses
customerIdas its partition key. You now need to query items byemail. What can you add to the existing table?- AA global secondary index with email as partition key
- BA local secondary index with email as partition key
- CA local secondary index with email as the sort key
- DNothing; you have to recreate the table with a new key
Show answer
Answer: A (A global secondary index with email as partition key)
A GSI can use any attribute as its partition key and can be added to an existing table at any time. LSIs must keep the table's partition key and can only be created together with the table, so neither LSI option works.
- 8.easy
A nightly job needs about 40 minutes of continuous processing in a single run. Which statement about running it as one Lambda invocation is correct?
- AIt works if you raise the function timeout to 60 minutes
- BIt works if you give the function the maximum memory
- CIt works if the function is invoked asynchronously
- DIt won't work; the maximum timeout is 15 minutes
Show answer
Answer: D (It won't work; the maximum timeout is 15 minutes)
A Lambda invocation can run for at most 15 minutes, whatever the memory setting or invocation type. Split the job into smaller chunks orchestrated by Step Functions, or run it as an ECS task on Fargate or with AWS Batch.
- 9.mid
A partner must allowlist fixed IP addresses for a TCP service you run on EC2. The service also needs very low latency and preservation of the client source IP. Which load balancer fits best?
- AApplication Load Balancer
- BNetwork Load Balancer
- CGateway Load Balancer
- DClassic Load Balancer
Show answer
Answer: B (Network Load Balancer)
An NLB works at layer 4, offers a static IP per AZ (optionally your own Elastic IPs), very low latency and client source IP preservation. An ALB is for HTTP-level routing and has no fixed IPs on its own. A GWLB is for inserting virtual appliances, and the Classic Load Balancer is legacy.
- 10.easy
Your RDS for PostgreSQL database runs as a Multi-AZ DB instance deployment, and read traffic is overloading the primary. What should you add to offload reads?
- ANothing; send reads to the Multi-AZ standby
- BA second Multi-AZ standby in another AZ
- COne or more read replicas
- DA larger EBS volume on the standby
Show answer
Answer: C (One or more read replicas)
In a Multi-AZ DB instance deployment the standby exists only for failover and serves no read traffic. Read replicas have their own endpoints and are the tool for scaling reads (a Multi-AZ DB cluster deployment, by contrast, does have readable standbys).
- 11.easy
VPC A is peered with VPC B, and VPC B is peered with VPC C. The CIDRs do not overlap and each peering has its routes configured. Can instances in A reach instances in C?
- AYes, traffic is routed through VPC B automatically
- BYes, if VPC B enables forwarding in its route tables
- COnly if all three VPCs are in the same AWS account
- DNo, peering is not transitive; peer A and C directly
Show answer
Answer: D (No, peering is not transitive; peer A and C directly)
VPC peering is strictly one-to-one and doesn't support transitive routing, regardless of accounts. Either create a peering between A and C, or use a Transit Gateway as a hub when many VPCs need to talk.
- 12.mid
Instances in a private subnet upload large volumes of data to S3 in the same Region, and NAT gateway data processing charges are high. What is the cheapest fix?
- AAdd an S3 gateway VPC endpoint to the route tables
- BEnable S3 Transfer Acceleration on the bucket
- CAdd a second NAT gateway in another Availability Zone
- DCreate an S3 interface endpoint in every subnet
Show answer
Answer: A (Add an S3 gateway VPC endpoint to the route tables)
A gateway endpoint for S3 routes that traffic privately without the NAT gateway, and gateway endpoints have no charge. An interface endpoint would also bypass NAT but adds hourly and per-GB costs. Transfer Acceleration and another NAT gateway only add cost.
- 13.hard
In envelope encryption with AWS KMS, what does a
GenerateDataKeycall return?- AOnly an encrypted data key; KMS keeps the plaintext
- BThe KMS key material itself, for local encryption
- CA plaintext data key plus that key encrypted by KMS
- DYour payload encrypted inside KMS with the KMS key
Show answer
Answer: C (A plaintext data key plus that key encrypted by KMS)
You use the plaintext data key to encrypt data locally, discard it, and store the encrypted copy next to the ciphertext; later
Decryptrecovers the data key. KMS key material never leaves KMS. Returning only the encrypted key is whatGenerateDataKeyWithoutPlaintextdoes. - 14.easy
Your app runs in
us-east-1andeu-west-1. You want Route 53 to send each user to whichever Region gives them the lowest latency. Which routing policy do you use?- AGeolocation routing
- BLatency-based routing
- CWeighted routing
- DMultivalue answer routing
Show answer
Answer: B (Latency-based routing)
Latency-based routing answers with the record for the Region that gives the user the lowest measured latency. Geolocation routes by the user's location, which isn't the same thing as network latency; weighted splits traffic by proportions you set, and multivalue returns several healthy records at random.
- 15.easy
How much warning does EC2 give before it interrupts a Spot Instance?
- ATwo minutes
- BTen minutes
- COne hour
- DNo warning at all
Show answer
Answer: A (Two minutes)
EC2 issues a Spot interruption notice two minutes before stopping, hibernating or terminating the instance, visible through instance metadata and EventBridge. EC2 may also send an earlier rebalance recommendation when an instance is at elevated risk, but the guaranteed notice is two minutes.
- 16.easy
An instance has an EBS root volume and an instance store volume holding cached files. What happens to the instance store data when you stop and then start the instance?
- AIt is preserved, just as it is on a reboot
- BIt is copied to an EBS snapshot automatically
- CIt is preserved only because the root is EBS-backed
- DIt is lost, because instance store is ephemeral
Show answer
Answer: D (It is lost, because instance store is ephemeral)
Instance store data survives a reboot but is lost when the instance stops, hibernates or terminates, because the instance usually starts on different hardware. An EBS root volume doesn't change that, and AWS never snapshots instance store automatically.
- 17.hard
An order workflow may wait days for a human approval using a task token, and every step must run exactly once. Which Step Functions workflow type fits?
- AAsynchronous Express workflow
- BSynchronous Express workflow
- CStandard workflow
- DEither Express type, with Retry configured
Show answer
Answer: C (Standard workflow)
Standard workflows run for up to a year with exactly-once execution and support the
.waitForTaskTokencallback pattern. Express workflows run for at most five minutes, are at-least-once (asynchronous) or at-most-once (synchronous), and support neither callbacks nor.syncjobs. - 18.easy
You move a self-managed MySQL database from an on-premises VM to Amazon RDS for MySQL without changing the application's architecture. Which of the 7 Rs is this?
- ARehost
- BReplatform
- CRefactor
- DRepurchase
Show answer
Answer: B (Replatform)
Replatforming ("lift, tinker and shift") adds targeted optimizations, like moving to a managed database, without redesigning the application. Rehosting would move the VM as it is onto EC2, refactoring redesigns the application, and repurchasing replaces it with a different product.
- 19.mid
What does a successful
sts:AssumeRolecall return to the caller?- AA new IAM user with access keys for the role
- BA console password valid for one hour
- CLong-term access keys stored on the role
- DTemporary credentials with a session token
Show answer
Answer: D (Temporary credentials with a session token)
STS returns an access key ID, a secret access key and a session token that expire after the session duration. Roles never have long-term credentials, which is exactly why they are preferred over IAM users for workloads and cross-account access.
- 20.hard
A Lambda function uses its execution role to generate an S3 presigned URL with
ExpiresInset to 7 days. What happens?- AIt stops working when the role session credentials expire
- BIt works for the full 7 days, since S3 honors ExpiresIn
- CGeneration fails because roles cannot sign presigned URLs
- DIt works for 7 days, but only from inside the same VPC
Show answer
Answer: A (It stops working when the role session credentials expire)
A presigned URL is only valid while the credentials that signed it are valid, whichever comes first. Lambda's execution role credentials are temporary and last far less than 7 days, so the URL stops working early. Roles can sign presigned URLs; the 7-day maximum applies to long-term IAM user credentials with Signature Version 4.
- 21.mid
A process PUTs a new object to S3 and immediately calls
ListObjectsV2on its prefix. What does the listing show?- AThe object may be missing for a few seconds
- BThe object appears only after a HEAD request
- CThe object; listings are strongly consistent
- DThe object only if versioning is enabled
Show answer
Answer: C (The object; listings are strongly consistent)
S3 provides strong read-after-write consistency for PUT and DELETE, and that includes LIST operations, in all Regions at no extra cost. The eventual consistency described in older material no longer applies to object operations; only bucket configuration changes are eventually consistent.