Karinoya Learning Room

Qualifications · Cloud / AI / Python Success Lab

Cloud Concepts and Shared Responsibility

Read the questions and explanations in English. The lectures (explanatory articles) are available in Japanese only.

View the Japanese version (with lectures) →

Q1 | Characteristics of the cloud

Which of the following is the most appropriate description of the characteristics of cloud computing compared with on-premises?

  1. Borrow only the resources you need, when you need them, and pay only for what you use
  2. Fix the amount of resources to use before deployment and purchase equipment to match that amount
  3. The company's own staff must directly handle equipment installation and power/air-conditioning management
  4. The amount of resources cannot be changed during the contract period, and returns must wait until the period expires
AnswerA. Borrow only the resources you need, when you need them, and pay only for what you use

Cloud computing is a usage model in which IT resources are not owned but borrowed only when needed, in the amount needed, and paid for based on usage. The time from request to availability is short, and billing stops the moment resources are returned. Fixing the required amount before deployment and purchasing equipment, and managing even power and air-conditioning in-house, are both on-premises approaches, and because the amount must be decided in advance, they lead to over-provisioning or capacity shortages. The description that the amount cannot be changed during the contract period is the opposite of the cloud premise that it can be increased or decreased later.

Q2 | Pay-as-you-go

Among the AWS pricing principles, which describes Pay-as-you-go?

  1. Commit to a fixed usage level for a 1-year or 3-year term to lower the unit price
  2. Bundle multiple services into a fixed monthly amount so no overage charges occur
  3. Take a tiered structure in which the unit price per unit falls as usage increases
  4. No upfront payments and no long-term commitments; you pay only for what you use
AnswerD. No upfront payments and no long-term commitments; you pay only for what you use

Pay-as-you-go is the principle of paying only for what you actually use, with no upfront payment and no long-term commitment. Because you can scale to actual demand rather than a forecast, it reduces the risk of over-provisioning. Lowering the unit price in exchange for committing to a usage level over a set term is Save when you commit; the unit price falling as usage increases is Pay less by using more; and bundling into a fixed monthly amount with no overage charges is Flat rate — all of these refer to different principles.

Q3 | Tiered pricing

What is the content of the AWS pricing principle Pay less by using more?

  1. Multiple services are bundled into a fixed monthly charge so that no overage charges occur
  2. It is a scheme in which you pay only for what you actually used, each time, with no upfront payment or long-term contract
  3. The unit price is discounted in exchange for committing to a fixed usage level for a 1-year or 3-year term
  4. A tiered pricing structure is applied in which the unit price per unit falls as usage increases
AnswerD. A tiered pricing structure is applied in which the unit price per unit falls as usage increases

Pay less by using more is the principle that a tiered pricing structure is applied for things like S3 and data transfer, so that the per-GB unit price falls as usage increases. Lowering the unit price in exchange for committing to a usage level over a set term is Save when you commit, which Savings Plans exemplifies. Paying only for what was actually used, each time, is Pay-as-you-go, and bundling into a fixed monthly amount with no overage charges is Flat rate. The four principles serve different purposes, so they are not mutually exclusive and are used in combination.

Q4 | Commitment discounts

Which of the following correctly describes Save when you commit, as exemplified by Savings Plans?

  1. The unit price is lowered for the portion exceeding a certain usage threshold, but only for that portion
  2. The unit price falls in exchange for committing to a fixed usage level for a 1-year or 3-year term
  3. There is no upfront payment or long-term commitment, and usage can be stopped freely at any time
  4. The monthly amount is fixed regardless of usage, and any excess is carried over to the following month
AnswerB. The unit price falls in exchange for committing to a fixed usage level for a 1-year or 3-year term

Save when you commit is the principle that, as with Savings Plans, prices for compute or machine learning services are discounted in exchange for committing to a specific usage level over a 1-year or 3-year term. Fixing the monthly amount so no overage charges occur, with no carry-over mechanism, is Flat rate. A tiered structure in which the unit price falls as usage increases is Pay less by using more. Being able to stop at any time with no commitment is a property of Pay-as-you-go, which is the opposite premise of this commitment-based principle.

Q5 | Foundational level

Among the AWS certifications, which combination is positioned at the Foundational level?

  1. Cloud Practitioner and Developer - Associate
  2. AI Practitioner and Advanced Networking - Specialty
  3. Developer - Associate and Data Engineer - Associate
  4. Cloud Practitioner and AI Practitioner
AnswerD. Cloud Practitioner and AI Practitioner

As of August 2026, the official list of exam guides places two certifications at Foundational: AWS Certified Cloud Practitioner (CLF-C02) and AWS Certified AI Practitioner (AIF-C01). Developer - Associate (DVA-C02) and Data Engineer - Associate (DEA-C01) are both Associate, and Advanced Networking - Specialty (ANS-C01) is Specialty. For certifications whose name ends with a level name, that is a useful clue, but Cloud Practitioner and AI Practitioner have no level name attached, so remember that these two are the Foundational ones.

Q6 | CLF-C02

Which is the official name of the AWS certification indicated by the exam code CLF-C02?

  1. AWS Certified Cloud Practitioner
  2. AWS Certified Data Engineer - Associate
  3. AWS Certified Developer - Associate
  4. AWS Certified AI Practitioner
AnswerA. AWS Certified Cloud Practitioner

CLF-C02 is the exam code for AWS Certified Cloud Practitioner. CLF stands for Cloud Practitioner, and the trailing C02 indicates the revision generation. The code for AWS Certified AI Practitioner is AIF-C01, for AWS Certified Developer - Associate it is DVA-C02, and for AWS Certified Data Engineer - Associate it is DEA-C01. Certification names are sometimes renamed, but the exam code does not change until it is revised, so checking the code is a reliable way to confirm whether study material is current.

Q7 | Exam codes

Which exam code corresponds to the Professional level of Solutions Architect?

  1. SAA-C03
  2. SOA-C03
  3. SAP-C02
  4. SCS-C03
AnswerC. SAP-C02

The exam code for AWS Certified Solutions Architect - Professional is SAP-C02. SAA-C03 is the Associate level of the same Solutions Architect track, SOA-C03 is CloudOps Engineer - Associate, and SCS-C03 is Security - Specialty. The first three letters look similar and can be confusing, but it helps to remember that SAA corresponds to Associate and SAP to Professional.

Q8 | CLF domain weights

Regarding the four domains defined by the Exam Guide for AWS Certified Cloud Practitioner (CLF-C02), which of the following correctly states the relative sizes of the exam weighting?

  1. Cloud Technology and Services is largest, Billing, Pricing, and Support is smallest
  2. Cloud Concepts is largest, Security and Compliance is smallest
  3. Security and Compliance is largest, Cloud Concepts is smallest
  4. Billing, Pricing, and Support is largest, Cloud Technology and Services is smallest
AnswerA. Cloud Technology and Services is largest, Billing, Pricing, and Support is smallest

The CLF-C02 Exam Guide sets Cloud Concepts at 24 percent, Security and Compliance at 30 percent, Cloud Technology and Services at 34 percent, and Billing, Pricing, and Support at 12 percent. So the largest is Cloud Technology and Services, and the smallest is Billing, Pricing, and Support. Being an entry-level certification, one might assume concepts get the most weight, but in fact the domain testing knowledge of services is the largest, followed by security. Study time allocation should follow this same ratio.

Q9 | SAA domain weights

In the Exam Guide for AWS Certified Solutions Architect - Associate (SAA-C03), which domain carries the largest exam weighting?

  1. Design Secure Architectures
  2. Design High-Performing Architectures
  3. Design Resilient Architectures
  4. Design Cost-Optimized Architectures
AnswerA. Design Secure Architectures

The SAA-C03 Exam Guide sets Design Secure Architectures at 30 percent, Design Resilient Architectures at 26 percent, Design High-Performing Architectures at 24 percent, and Design Cost-Optimized Architectures at 20 percent. The largest is designing secure architectures. It is easy to remember the four domain names by mapping them to the Well-Architected pillars, which shows they are ordered security, reliability, performance efficiency, and cost optimization.

Q10 | CloudOps

Which certification began on September 30, 2025 as the successor to the former SysOps Administrator - Associate (SOA-C02)?

  1. AWS Certified DevOps Engineer - Professional (DOP-C02)
  2. AWS Certified CloudOps Engineer - Associate (SOA-C03)
  3. AWS Certified Machine Learning Engineer - Associate (MLA-C01)
  4. AWS Certified Data Engineer - Associate (DEA-C01)
AnswerB. AWS Certified CloudOps Engineer - Associate (SOA-C03)

The operations-focused Associate certification was renamed from SysOps Administrator to CloudOps Engineer, and its exam code also changed from SOA-C02 to SOA-C03. The last day to take the old code was September 29, 2025, and the new code started on September 30, 2025. Data Engineer - Associate and Machine Learning Engineer - Associate are not successors to the operations track; they are separate, newly established certifications in the data and ML domains respectively. DevOps Engineer - Professional is a pre-existing Professional-level certification at a different level.

Q11 | AWS's responsibility

In the shared responsibility model, what falls within the scope of "Security of the Cloud"?

  1. Designing and applying the permissions granted to users and roles using IAM
  2. Protecting the hardware, software, networking, and facilities that run AWS services
  3. Choosing whether to encrypt stored data and deciding the operational policy for that
  4. Addressing vulnerabilities in application software installed on an instance
AnswerB. Protecting the hardware, software, networking, and facilities that run AWS services

AWS officially calls its own responsibility "Security of the Cloud," defined as protecting the infrastructure that runs all the services offered in the AWS Cloud — that is, the hardware, software, networking, and facilities. Addressing vulnerabilities in an application installed on an instance is the customer's responsibility when EC2 is chosen. Choosing data encryption options and granting permissions via IAM remain the customer's tasks no matter which service is chosen, and both belong on the "Security in the Cloud" side.

Q12 | The customer's responsibility

In the shared responsibility model, what is said to determine the breadth of the customer's responsibility (Security in the Cloud)?

  1. It is determined by the Region and Availability Zone where resources are placed
  2. It is determined by the elapsed time since account creation and the monthly spend
  3. It is determined by the type of support plan the customer has contracted
  4. It is determined by the AWS Cloud services the customer selects
AnswerD. It is determined by the AWS Cloud services the customer selects

AWS states explicitly that "customer responsibility will be determined by the AWS Cloud services that a customer selects." This means the amount of configuration work a customer must perform, as part of their security responsibility, varies depending on the service chosen. A support plan determines how technical assistance is received and does not move the line of responsibility. Region and Availability Zone are about placement, and usage duration or spend are about billing — none of these determine the breadth of responsibility.

Q13 | EC2 patching

You are running a Linux virtual server on Amazon EC2. Whose responsibility is it to apply security patches to the guest OS?

  1. AWS's. The OS of a virtual server is included in the platform that AWS operates
  2. AWS's. It is applied automatically as a task incidental to protecting the hardware
  3. The customer's. Guest OS updates and patch application fall within the customer's area of responsibility
  4. The customer's, but responsibility shifts to AWS if a support plan is contracted
AnswerC. The customer's. Guest OS updates and patch application fall within the customer's area of responsibility

AWS officially states that for services requiring configuration such as EC2, the customer manages "guest operating systems (including updates and security patches), any application software or utilities installed on the instances, and configuration of the security groups." So applying patches to the OS is the customer's responsibility. For EC2, what AWS operates extends only to the physical infrastructure and the virtualization layer, not the OS inside the instance. A support plan is a contract for receiving technical assistance and does not shift where responsibility lies.

Q14 | Shared responsibility for S3

For abstracted services such as Amazon S3 or Amazon DynamoDB, which describes the division of responsibility?

  1. AWS operates the infrastructure layer, OS, and platform, and the customer handles data and permissions
  2. The customer operates the platform, and AWS only protects the network
  3. AWS handles data classification and permission settings entirely, and the customer only manages usage
  4. The customer performs OS updates, and AWS handles data classification and encryption settings
AnswerA. AWS operates the infrastructure layer, OS, and platform, and the customer handles data and permissions

For abstracted or managed services, AWS states that "AWS operates the infrastructure layer, the operating system, and platforms, and customers access the endpoints to store and retrieve data." What remains with the customer is managing their own data (including encryption options), classifying assets, and applying appropriate permissions using IAM tools. The customer does not perform OS updates or operate the platform, but data classification and permission settings never leave the customer's hands, regardless of the service.

Q15 | The line moves

What is the shared responsibility model's answer to the question, "Whose responsibility is it to apply patches to the OS?"

  1. Always the customer's. The OS is defined as something the customer runs
  2. Always AWS's. The OS is defined as part of the infrastructure
  3. It varies by Region; in heavily regulated regions it becomes AWS's responsibility
  4. It varies by the service chosen: with EC2 it is the customer, with S3 it is AWS
AnswerD. It varies by the service chosen: with EC2 it is the customer, with S3 it is AWS

The line in the shared responsibility model is not fixed; it moves depending on the service chosen. For a service like EC2, where the customer manages the guest OS, patching is the customer's responsibility, but for a service like S3 or DynamoDB, where AWS operates all the way up through the OS and platform, it becomes AWS's responsibility. So neither "always AWS" nor "always the customer" is correct. Region is a placement choice and does not change the division of responsibility. Keeping this one point in mind lets you estimate the line for an unfamiliar service just by asking whether it leans toward EC2 or toward S3.

Q16 | Physical facilities

In the shared responsibility model, whose responsibility is the physical security of AWS data center buildings and entry controls?

  1. Both the customer's and AWS's. Customers are obligated to enter and inspect the facilities
  2. AWS's. Protecting the facilities is included in Security of the Cloud and is always AWS's responsibility
  3. The customer's. Customers audit the facilities in the Regions they use
  4. It depends on the service chosen; only with EC2 does it fall to the customer
AnswerB. AWS's. Protecting the facilities is included in Security of the Cloud and is always AWS's responsibility

Facilities are explicitly listed under "Security of the Cloud" as part of the infrastructure that runs AWS Cloud services, so they are always AWS's responsibility regardless of which service is used. Customers cannot audit this area themselves or enter and inspect the facilities; instead they confirm it through the third-party certifications and audit reports AWS publishes. This corresponds to the control category called Inherited Controls among the three control classifications — the part that customers fully inherit from AWS. What moves depending on the chosen service is the OS and middleware layer, not the physical layer.

Q17 | Always the customer's

Regardless of the type of service used, which task always remains the customer's responsibility?

  1. Replacing the physical server on which a service runs, in the event of a hardware failure
  2. Protecting the backbone network connecting the Regions
  3. Applying patches to the OS underlying a managed service
  4. Granting permissions via IAM and choosing data encryption options
AnswerD. Granting permissions via IAM and choosing data encryption options

AWS explicitly states that managing one's own data (including encryption options), classifying assets, and applying appropriate permissions using IAM tools remain with the customer even when using abstracted services. Since this never leaves the customer regardless of the service chosen, it serves as a fixed point when thinking about where the line falls. Replacing a physical server and protecting the backbone network are matters of facilities and hardware, and are always on the AWS side. The OS underlying a managed service is operated by AWS, so applying patches to it is not the customer's task.

Q18 | Inherited controls

Among the three control classifications, which correctly describes Inherited Controls?

  1. Controls AWS inherits from the customer, carrying forward the customer's own configuration
  2. Controls that are entirely the customer's responsibility, such as service and zone security
  3. Controls the customer fully inherits from AWS, such as physical and environmental controls
  4. Controls applied separately to both the infrastructure layer and the customer layer
AnswerC. Controls the customer fully inherits from AWS, such as physical and environmental controls

Inherited Controls are officially defined as controls the customer fully inherits from AWS, and physical and environmental controls fall into this category. Controls applied separately to both the infrastructure layer and the customer layer are Shared Controls, and controls that are entirely the customer's responsibility, such as service and zone security, are Customer Specific Controls. Inheritance flows in one direction, from AWS to the customer, not a relationship where AWS carries forward the customer's own settings.

Q19 | Shared controls

Which does AWS officially cite as an example of Shared Controls?

  1. Data center entry/exit controls, power redundancy, and maintaining air conditioning
  2. Hardware procurement, physical server disposal, and cable installation
  3. Service and zone security, and data classification
  4. Patch Management, Configuration Management, and Awareness & Training
AnswerD. Patch Management, Configuration Management, and Awareness & Training

AWS cites Patch Management, Configuration Management, and Awareness & Training as its three examples of Shared Controls. What they have in common is that the same activity is carried out in parallel at both the infrastructure layer and the customer layer — for patch management, for instance, AWS applies patches to its own infrastructure while the customer applies them separately to the guest OS and applications. Entry/exit controls, power redundancy, and hardware procurement and disposal are physical and environmental controls, which the customer inherits from AWS. Service and zone security is an example of Customer Specific Controls.

Q20 | Migration and responsibility

A company moved the data store for its in-house system from a self-managed database on Amazon EC2 to Amazon DynamoDB. From the standpoint of the shared responsibility model, which combination of what changes and what does not change through this migration is correct?

  1. Guest OS patching continues to be the customer's job, and data classification shifts to AWS
  2. Protecting the physical facility shifts to the customer, and granting permissions via IAM also shifts to AWS
  3. Guest OS patching shifts to AWS, and granting permissions via IAM remains with the customer
  4. Both guest OS patching and granting permissions via IAM shift to AWS
AnswerC. Guest OS patching shifts to AWS, and granting permissions via IAM remains with the customer

DynamoDB is an abstracted service, so AWS operates all the way through the infrastructure layer, the OS, and the platform. Guest OS patching, which the customer handled under EC2, becomes AWS's task after the migration. Meanwhile, classifying data, choosing encryption options, and granting permissions via IAM remain with the customer regardless of which service is chosen. Protecting the physical facility is already always AWS's responsibility, so it never shifts to the customer through migration. It helps to organize it as: what moves is the OS/platform layer, and what does not move is data and permissions.

Q21 | Six pillars

As of August 2026, which correctly states the composition of the pillars of the AWS Well-Architected Framework?

  1. Operational Excellence, Security, Portability, Performance Efficiency, Cost Optimization, Sustainability
  2. Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability
  3. Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization
  4. Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability, Interoperability
AnswerB. Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability

The current pillars are the six of Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability. Sustainability was added as the sixth pillar in 2021, so a list of only five pillars without it reflects outdated information from before the addition. Interoperability and Portability are not listed as pillars of the framework; neither appears in the official list. An explanation with an outdated pillar count is also likely to have outdated service names or exam codes, so it can serve as a marker for how current a piece of study material is.

Q22 | Operational Excellence

What does the Operational Excellence pillar focus on?

  1. Eliminating wasteful spending and right-sizing resources against business requirements
  2. Running and monitoring systems, and continually improving processes and procedures
  3. Optimizing the allocation of IT resources and selecting the resource type that fits the requirement
  4. Protecting information and systems, and data integrity and access control
AnswerB. Running and monitoring systems, and continually improving processes and procedures

Operational Excellence is the pillar that focuses on running and monitoring systems, and on continually improving processes and procedures. This includes automating deployments, updating procedures based on post-incident reviews, and making changes in small, frequent steps. Protecting information and systems is Security; optimizing resource allocation and selecting resource types is Performance Efficiency; and eliminating wasteful spending and right-sizing resources is Cost Optimization — all of these point to different pillars.

Q23 | Security

Which of the following initiatives is most appropriately a concern of the Security pillar?

  1. Stopping unused resources and right-sizing instances
  2. Measuring and reducing the environmental impact caused by running a workload
  3. Encrypting data and enforcing access control based on the principle of least privilege
  4. Automating deployment procedures and updating runbooks based on incident reviews
AnswerC. Encrypting data and enforcing access control based on the principle of least privilege

The Security pillar focuses on protecting information and systems, centered on data integrity and access control. Encryption and access control based on least privilege fall squarely under it. Stopping unused resources and right-sizing instances is Cost Optimization; automating deployment and updating runbooks after incident reviews is Operational Excellence; and measuring and reducing environmental impact is Sustainability. Most of what remains the customer's responsibility under the shared responsibility model is handled within this Security pillar.

Q24 | Reliability

Which of the following correctly describes what the Reliability pillar focuses on?

  1. A workload performing its intended function, and recovering quickly from failure
  2. Optimizing the allocation of IT resources and selecting the resource type that fits the need
  3. Running and monitoring systems, and continually improving processes and procedures
  4. Minimizing the environmental impact of running a cloud workload
AnswerA. A workload performing its intended function, and recovering quickly from failure

Reliability is the pillar that focuses on a workload performing its intended function and on how quickly it recovers from failure. Distributing across multiple Availability Zones, automated recovery, and verifying backup and recovery procedures fall here. Its distinguishing feature is that it covers not just preventing breakage but also recovering quickly once something has broken. Optimizing resource allocation is Performance Efficiency; running, monitoring, and continually improving procedures is Operational Excellence; and minimizing environmental impact is Sustainability.

Q25 | Performance efficiency

To meet a latency requirement, you are reselecting the resource type that fits the workload's needs and revisiting the allocation. Which pillar does this initiative primarily belong to?

  1. Cost Optimization. It focuses on eliminating wasteful spending and right-sizing resources
  2. Performance Efficiency. It focuses on optimizing resource allocation and selecting the resource type
  3. Operational Excellence. It focuses on running, monitoring, and continually improving procedures
  4. Reliability. It focuses on performing the intended function and recovering from failure
AnswerB. Performance Efficiency. It focuses on optimizing resource allocation and selecting the resource type

Performance Efficiency is the pillar that focuses on optimizing the allocation of IT resources and on selecting the resource type that fits the workload's needs. Reselecting a resource type to meet a requirement falls squarely under this. Cost Optimization can look like a similar activity, but its aim is eliminating wasteful spending, whereas here the motivation is meeting a latency requirement, so the focus differs. Reliability looks at resilience to failure and Operational Excellence looks at improving procedures — neither is the main concern here.

Q26 | Cost Optimization

Which correctly describes the focus of the Cost Optimization pillar?

  1. A workload performing its intended function, and recovering quickly from failure
  2. Eliminating wasteful spending and right-sizing resources against business requirements
  3. Minimizing the environmental impact of running a cloud workload
  4. Protecting information and systems, and data integrity and access control
AnswerB. Eliminating wasteful spending and right-sizing resources against business requirements

Cost Optimization is the pillar that focuses on eliminating wasteful spending and right-sizing resources against business requirements. Judgments such as stopping unused resources, correcting oversized instances, and choosing appropriate pricing models fall here. The point is not simply to minimize cost but to ask whether value is being obtained commensurate with spending. Protecting information and systems is Security; performing the intended function and recovering is Reliability; and minimizing environmental impact is Sustainability.

Q27 | Sustainability

What does the Sustainability pillar focus on?

  1. Running and monitoring systems, and continually improving processes and procedures
  2. Minimizing the environmental impact of running a cloud workload
  3. A workload performing its intended function, and recovering quickly from failure
  4. Optimizing the allocation of IT resources and selecting the resource type that fits the need
AnswerB. Minimizing the environmental impact of running a cloud workload

Sustainability is the pillar that focuses on minimizing the environmental impact of running a cloud workload. It is the newest pillar, added as the sixth in 2021, and its presence or absence marks the line between current and outdated study material. Optimizing resource allocation and selecting resource types is Performance Efficiency; running, monitoring, and continually improving procedures is Operational Excellence; and performing the intended function and recovering from failure is Reliability — all of these point to different pillars.

Q28 | The sixth pillar

An old article states that "the Well-Architected Framework has five pillars." Which pillar is missing from it?

  1. The pillar covering a workload performing its intended function and recovering from failure
  2. The pillar covering running and monitoring systems and continually improving processes and procedures
  3. The pillar covering optimizing the allocation of IT resources and selecting the resource type
  4. The pillar covering minimizing the environmental impact of running a cloud workload
AnswerD. The pillar covering minimizing the environmental impact of running a cloud workload

The missing one is Sustainability, the pillar covering minimizing the environmental impact of running a cloud workload. Because it was added as the sixth pillar in 2021, articles written before that still list only five. Operational Excellence, Performance Efficiency, and Reliability all existed before the addition, so they appear even in an article listing five pillars. When a basic fact like the number of pillars is out of date in an article, the rest of its content is also likely to be outdated.

Q29 | Not a pillar

Which of the following is NOT listed as a pillar of the AWS Well-Architected Framework?

  1. Interoperability
  2. Performance Efficiency
  3. Cost Optimization
  4. Operational Excellence
AnswerA. Interoperability

The current pillars are the six of Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability, and Interoperability is not included in this list. Different systems being able to connect to one another is an important design concern, but the Well-Architected Framework does not set it up as a standalone pillar. Cost Optimization, Operational Excellence, and Performance Efficiency are all genuine members of the six. Memorizing a term not in the framework as if it were a pillar becomes a source of confusion when narrowing down answer choices.

Q30 | Pillars and their focus

Which of the following pairings of a Well-Architected Framework pillar with its focus is NOT correct?

  1. Operational Excellence - Running and monitoring systems, continually improving processes and procedures
  2. Reliability - Eliminating wasteful spending and right-sizing resources against business requirements
  3. Sustainability - Minimizing the environmental impact of running a cloud workload
  4. Security - Protecting information and systems, data integrity and access control
AnswerB. Reliability - Eliminating wasteful spending and right-sizing resources against business requirements

Eliminating wasteful spending and right-sizing resources against business requirements is the focus of Cost Optimization, not Reliability. Reliability is the pillar that focuses on a workload performing its intended function and on how quickly it recovers from failure. The other three pairings match the official descriptions. Because pillar names sound close to everyday words, matching them by impression alone invites mistakes; memorizing them together with the one-sentence description of their focus prevents stumbling on this type of question.

Q31 | Region

Which of the following correctly describes an AWS Region?

  1. A physical location in the world that contains multiple Availability Zones
  2. A dedicated zone placed inside a telecommunications carrier's network
  3. A location where CloudFront caches and delivers content
  4. A unit for isolating failures, made up of one or more discrete data centers
AnswerA. A physical location in the world that contains multiple Availability Zones

A Region is a physical location in the world where AWS has multiple Availability Zones. Regions have names such as us-east-1 or ap-northeast-1, and are chosen based on data residency and regulatory requirements, distance from users, and pricing. A unit for isolating failures made up of one or more discrete data centers is the description of an Availability Zone. A location where CloudFront caches and delivers content is an Edge Location, and a zone placed inside a telecom carrier's network is a Wavelength Zone.

Q32 | Definition of an AZ

Which is the official definition of an Availability Zone (AZ)?

  1. An intermediate caching layer placed between an edge location and the origin
  2. One or more discrete data centers housed in separate facilities
  3. A logical network partition that spans multiple Regions
  4. A location near a user's city where applications can be run
AnswerB. One or more discrete data centers housed in separate facilities

An Availability Zone is defined as consisting of one or more discrete data centers, each with redundant power, networking, and connectivity, and housed in separate facilities. The key points are that it is not the same as a single data center building but rather a grouping, and that it sits in a different building from other zones. An intermediate layer between an edge location and the origin is a Regional Edge Cache, and a place near a user's city for running applications describes Local Zones — both refer to different mechanisms.

Q33 | At least 3 AZs

Which requirement does AWS officially state regarding the Availability Zones that make up each Region?

  1. As many zones as a customer applies for are allocated, with no upper limit
  2. Made up of at least two zones located within the same facility
  3. Made up of at least three zones that are independent and physically separated
  4. There is one zone per Region, expanded as needed
AnswerC. Made up of at least three zones that are independent and physically separated

AWS officially states that each Region is composed of "a minimum of three, isolated, and physically separate Availability Zones." Because the total number of Regions and zones keeps growing, memorizing those totals is of limited value, but the rule for how many zones a single Region has at minimum is stable and can be used directly as a design assumption. Being located within the same facility contradicts the definition of being housed in separate facilities. Zones are not something customers apply for to increase, nor is there just one per Region.

Q34 | Role of an edge location

Which of the following correctly describes the role of an edge location?

  1. Partitioning IP address ranges within a VPC and controlling routes with route tables
  2. Running applications inside a telecom carrier's facilities to reduce latency
  3. Letting CloudFront deliver content from the location with the lowest latency
  4. Isolating failures within a Region so processing can continue if one side goes down
AnswerC. Letting CloudFront deliver content from the location with the lowest latency

Edge locations are the worldwide network of data centers where CloudFront delivers content. Requests are routed to the edge location with the lowest latency, and delivery happens from there. The key point is that this is not a redundancy unit for increasing availability, but a caching location for redelivering content closer to the user. Isolating failures is the role of an Availability Zone, partitioning IP address ranges is the role of a subnet, and running applications inside carrier facilities is the role of Wavelength Zones.

Q35 | Cache miss

In CloudFront, what happens when the requested content is not cached at the edge location?

  1. It is fetched from the origin, delivered, and cached for next time
  2. It is forwarded to another Availability Zone within the same Region
  3. The request is rejected and an error is returned to the user
  4. The user is asked to wait until the cache is created
AnswerA. It is fetched from the origin, delivered, and cached for next time

A request is routed to the edge location with the lowest latency, and if the content is already there it is delivered immediately. If not, it is fetched from an origin — such as an S3 bucket or an HTTP server — delivered, and also stored in the cache. That is why subsequent requests can be returned directly from the nearby location. A missing cache entry does not turn into an error, nor is the user left waiting. Forwarding to an Availability Zone is a failure-isolation mechanism and is unrelated to the flow of content delivery.

Q36 | Intermediate cache

What is the correct positioning of a Regional Edge Cache?

  1. A caching layer placed between an edge location and the origin
  2. A browser-side mechanism that stores content on the user's own device
  3. A management unit that groups the Availability Zones within a Region
  4. A general term for zones placed inside a telecom carrier's network
AnswerA. A caching layer placed between an edge location and the origin

A Regional Edge Cache is a caching layer positioned between an edge location and the origin. Its role is to reduce the number of times a request has to travel all the way back to the origin when it is not found at the edge. A management unit that groups Availability Zones is a Region, and zones placed inside a telecom carrier's network are Wavelength Zones — both are different concepts. Caching on the user's own device is not an AWS mechanism but a feature of the browser or OS.

Q37 | Multi-AZ

What is the main purpose of a configuration that splits servers of the same role across two or more Availability Zones?

  1. To deliver content to users worldwide from the nearest location
  2. To satisfy regulatory requirements regarding where data resides
  3. To lower the unit price of compute through a usage commitment
  4. So processing can continue even if one zone goes down entirely
AnswerD. So processing can continue even if one zone goes down entirely

An Availability Zone is a failure-isolation unit housed in a separate facility with redundant power and networking. Placing resources of the same role across multiple zones means that even if one zone goes down entirely, the rest can keep processing. This is a Multi-AZ configuration and is the starting point of availability design. Delivering from the nearest location is the role of an edge location; data residency is a factor in choosing a Region; and lowering the unit price through a usage commitment is a pricing matter — none of these is the motivation for splitting across zones.

Q38 | Local Zones

Which correctly describes AWS Local Zones?

  1. An intermediate cache placed in front of the origin to reduce fetch counts
  2. A standard type of zone established to isolate failures within a Region
  3. A mechanism that lets applications run closer to users or workloads
  4. A delivery-only location where CloudFront caches and serves content
AnswerC. A mechanism that lets applications run closer to users or workloads

Local Zones are a mechanism that lets applications run on AWS infrastructure closer to end users or workloads, placed in cities away from a Region. They resemble edge locations in dealing with "nearby," but the difference is that they run the application itself rather than serving as a content-delivery cache. Isolating failures within a Region is an Availability Zone, a delivery-only location is an edge location, and an intermediate cache in front of the origin is a Regional Edge Cache.

Q39 | Wavelength

Where are AWS Wavelength Zones placed?

  1. In a form that partitions the IP address range of a VPC
  2. Between an edge location and the origin
  3. Inside a Region as a failure-isolation unit
  4. Inside a telecommunications carrier's network
AnswerD. Inside a telecommunications carrier's network

Wavelength Zones are zones placed inside a telecommunications carrier's network. Like Local Zones, they are a mechanism for running the application itself close to users, which differs in purpose from an edge location, a delivery point for a content cache. Placed between an edge location and the origin is a Regional Edge Cache; a failure-isolation unit within a Region is an Availability Zone; and partitioning the IP address range of a VPC is a subnet.

Q40 | Availability design

A web server and a database are placed together in a single Availability Zone. You want the service to continue even if that zone fails. What should you consider first?

  1. Switch to a pricing plan that commits to usage, to reduce cost fluctuation
  2. Place servers in another zone in the same Region as well, and distribute traffic across them
  3. Add more servers within the same zone and distribute traffic with a load balancer
  4. Place CloudFront in front and deliver from an edge location
AnswerB. Place servers in another zone in the same Region as well, and distribute traffic across them

An Availability Zone is a failure-isolation unit housed in a separate facility, so preparing for an entire zone going down requires placing resources across zones. Because each Region is composed of at least three isolated zones, distributing across multiple zones within the same Region is possible. Adding more servers within the same zone does not meet the requirement, since if that zone goes down, all of them go down together. CloudFront speeds up delivery, but if the origin stops, dynamic processing cannot continue. Changing the pricing plan is a cost matter unrelated to availability.

Practice: answer the questions on this page

This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.

* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.

This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original