20+ practice questions focused on Resilient Cloud Solutions — one of the most tested topics on the AWS Certified DevOps Engineer Professional DOP-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Resilient Cloud Solutions PracticeA company runs a critical web application on EC2 instances behind an Application Load Balancer (ALB) with Auto Scaling. During a recent traffic spike, the application became unavailable for 10 minutes. Analysis shows that the ALB's healthy host count dropped to zero because the instances failed health checks due to high CPU load. What is the MOST effective design change to improve resilience during future traffic spikes?
Explanation: Predictive scaling uses historical traffic data to forecast future demand and proactively adjust capacity before a spike occurs. This prevents the CPU from reaching critical levels that cause health check failures, ensuring the ALB always has healthy hosts. Scheduled scaling alone would not adapt to unexpected spikes, but predictive scaling combined with dynamic scaling provides both proactive and reactive resilience.
A company uses DynamoDB global tables in two AWS Regions with strong consistency reads. They observe occasional write conflicts that are not being resolved automatically. The application uses DynamoDBMapper with optimistic locking. What should the DevOps engineer do to ensure conflict resolution?
Explanation: DynamoDB global tables resolve conflicts automatically using last-writer-wins (LWW). However, if the application requires custom conflict resolution (e.g., to ensure only the latest version is applied or application-specific logic), LWW is insufficient. DynamoDB Streams can capture all updates, and a Lambda function can compare conflicting versions and apply the appropriate resolution. DynamoDBMapper's optimistic locking uses version attributes with conditional writes, but in global tables each replica may have a different version number; a conditional write in one region can succeed even if a newer write exists in another region, so it does not guarantee that the latest version wins.
A company wants to design a highly available web application using AWS services. The application must be resilient to the failure of an entire AWS Region. Which THREE components should the architecture include? (Choose THREE.)
Explanation: Option B is correct because Amazon Route 53 failover routing policies use health checks to automatically redirect DNS queries from a primary endpoint to a standby endpoint in another Region, which is essential for surviving a full Region outage. Option C is correct because deploying Auto Scaling groups in each Region ensures that compute capacity exists independently in the secondary Region and can scale to absorb traffic after failover, rather than relying on instances in the failed Region. Option E is correct because an Amazon RDS Multi-AZ deployment provides high availability within a Region, while a cross-Region read replica maintains a copy of the data in a second Region that can be promoted to a standalone primary database during a Regional disaster. Option A does not belong because an ALB is a Regional service; an ALB in only one Region cannot provide resilience if that entire Region fails. Option D does not belong because EC2 instances confined to a single Region are unavailable during a Region-wide outage and therefore cannot satisfy the cross-Region resiliency requirement.
A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses an Amazon RDS for MySQL Multi-AZ DB instance for data storage. During an AWS infrastructure event, the primary Availability Zone (AZ) becomes unavailable, and the application experiences downtime. The RDS Multi-AZ failover completes automatically, but the application takes several minutes to reconnect. Which combination of actions would MOST reduce the recovery time for the application during such an event?
Explanation: Amazon RDS Proxy maintains a warm connection pool to the database, so when the RDS Multi-AZ failover occurs, the proxy automatically reconnects to the new primary DB instance without requiring the application to re-establish connections. This eliminates the connection storm and the several-minute delay caused by the application's connection retry logic. The application must be configured to use the RDS Proxy endpoint (not the cluster endpoint) to benefit from this seamless failover.
An AWS Lambda function that processes sensitive data writes objects to an S3 bucket. The security team requires that all objects be encrypted at rest using SSE-S3. The Lambda execution role uses the above IAM policy. Despite the policy, some objects are uploaded without server-side encryption. What is the most likely cause?
Explanation: The IAM policy only allows the PutObject action when the request includes the `x-amz-server-side-encryption` header set to `AES256` (SSE-S3). If the Lambda function omits this header in its PutObject call, the request does not satisfy the IAM condition key `s3:x-amz-server-side-encryption`, and the policy denies the upload. However, the question states that objects are uploaded without encryption, which implies the policy is not being enforced as intended—likely because the Lambda function is not including the required header, and the bucket's default encryption or another mechanism is allowing the upload to succeed despite the policy.
+15 more Resilient Cloud Solutions questions available
Practice all Resilient Cloud Solutions questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Resilient Cloud Solutions. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Resilient Cloud Solutions questions on the DOP-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Resilient Cloud Solutions is tested as part of the AWS Certified DevOps Engineer Professional DOP-C02 blueprint. Practicing with targeted Resilient Cloud Solutions questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free DOP-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Resilient Cloud Solutions is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Resilient Cloud Solutions practice session with instant scoring and detailed explanations.
Start Resilient Cloud Solutions Practice →