Amazon Web Services · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
18% of exam · 6 sample questions below
A company wants to establish a dedicated, low-latency, private connection between its on-premises data center and an AWS VPC. The company does not want to use the public internet. Which AWS service should be used to meet this requirement?
AWS Direct Connect
AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, bypassing the public internet entirely. It satisfies the low-latency and privacy constraints by using a physical cross-connect at an AWS Direct Connect location, delivering consistent network performance rather than variable internet routing.
AWS Virtual Private Gateway
AWS Transit Gateway
VPC Peering
A company has two VPCs in different AWS regions (us-east-1 and eu-west-1) that are peered. Applications in both VPCs need to communicate using private IP addresses. The ping tests are successful, but the latency is significantly higher than expected. Which change is most likely to improve the latency between the VPCs?
Enable DNS resolution for the VPC peering connection.
When a VPC peering connection has DNS resolution enabled in both VPCs, instances can resolve private DNS hostnames of the peer VPC through the Amazon-provided DNS resolver, which returns private IP addresses instead of public ones. This keeps all cross-VPC traffic on the AWS backbone, avoiding the extra latency of routing over the public internet. Without this setting, private DNS names may fail to resolve or map to public endpoints, forcing traffic outside the VPC and adding avoidable round-trip delay.
Use a Transit Gateway instead of VPC Peering for cross-region connectivity.
Increase the MTU on the instances' network interfaces to 9001.
Configure ECMP (Equal-Cost Multi-Path) routing on the VPC peering connection.
A company has an on-premises data center connected to an AWS VPC via an AWS Direct Connect connection. The company's SysOps administrator wants to ensure that traffic from the VPC destined for the on-premises network uses the Direct Connect connection instead of the internet. Which configuration should be used?
Add a route in the VPC route table pointing to the on-premises network via a virtual private gateway (VGW)
The VGW is attached to the VPC and is the entry/exit point for Direct Connect. By adding a route with the on-premises destination and the VGW as the target, traffic is forced through the Direct Connect connection.
Add a route in the VPC route table pointing to the on-premises network via a NAT gateway
Add a route in the VPC route table pointing to the on-premises network via an internet gateway
Add a route in the VPC route table pointing to the on-premises network via a VPC peering connection
A company has two VPCs in the same AWS region. VPC A hosts a web application, and VPC B hosts a database. The SysOps administrator needs to enable private IP communication between the two VPCs without using the public internet. The administrator wants a simple, low-cost solution that uses the AWS network backbone. Which AWS service should be used?
VPC Peering
VPC Peering establishes a direct, logical connection between exactly two VPCs, using a 1:1 relationship that relies on AWS's existing routing infrastructure—no gateways, virtual appliances, or dedicated physical lines are required. Traffic between the peered VPCs uses private IPv4 or IPv6 addresses and stays entirely on the AWS global network, avoiding public-internet exposure and providing low, predictable latency. It is cost-effective for a pair of VPCs because there is no hourly fee or minimum revenue commitment; you pay only for inter-VPC data transfer, which is usually significantly cheaper than traffic traversing the internet. Although VPC peering is non-transitive, that property is irrelevant for a two-VPC architecture, making it the simplest and most operationally efficient solution for this requirement.
AWS Transit Gateway
AWS Direct Connect
AWS Site-to-Site VPN
A company hosts a web application behind an Application Load Balancer (ALB) in us-east-1. Users in Europe report high latency. The SysOps administrator decides to use AWS Global Accelerator to improve performance by directing traffic to the closest edge location. However, the application logs require the original client IP addresses of users. The ALB currently provides the client IP via the X-Forwarded-For header, but the development team warns that Global Accelerator may change the source IP. Which configuration should the administrator choose to meet both performance and logging requirements?
Configure Global Accelerator with an endpoint group that points directly to the ALB. The ALB will continue to receive the original client IP in the X-Forwarded-For header.
Place a Network Load Balancer (NLB) in front of the ALB, and configure Global Accelerator to point to the NLB. The NLB preserves the client IP, and the ALB can still see it in the X-Forwarded-For header.
Global Accelerator preserves the client source IP when the endpoint is an NLB. The NLB passes traffic to the ALB, which can see the original client IP in the X-Forwarded-For header. This satisfies both performance (using Global Accelerator) and logging requirements.
Enable Proxy Protocol v2 on the ALB to ensure client IP addresses are preserved through Global Accelerator.
Use Amazon CloudFront instead of Global Accelerator and configure it to forward the client IP in a custom header.
A company hosts a web application on Amazon EC2 instances in two AWS regions: us-east-1 and eu-west-1. The application is behind an Application Load Balancer (ALB) in each region. The SysOps administrator wants to direct users to the region that provides the lowest latency, automatically routing traffic away from a region if it becomes unhealthy. Which Amazon Route 53 routing policy should be used?
Geolocation routing
Latency routing
Latency routing uses measurements of latency between AWS regions and the user to direct traffic to the region with the lowest latency. When health checks are attached to the ALBs, latency routing automatically avoids unhealthy endpoints by excluding them from responses.
Weighted routing
Failover routing
Want more Networking and Content Delivery practice?
Practice this domain12% of exam · 6 sample questions below
A SysOps administrator manages an Amazon RDS for MySQL instance that experiences high CPU utilization during business hours. The application is read-heavy. Which action will most effectively improve performance and reduce cost?
Enable Multi-AZ deployment.
Scale up the instance size to a larger instance class.
Add a read replica.
A read replica is an asynchronous MySQL replica that continuously syncs changes from the primary and can serve read-only traffic, including SELECT queries and reporting workloads. By routing non-critical reads to the replica, the primary's CPU cycles are freed up for write operations, reducing overall CPU utilization on the primary instance. This is a cost-effective scale-out approach because you add a smaller replica instance rather than resizing the primary, and read replicas can be promoted or removed as demand changes.
Enable automated backups.
A SysOps administrator manages a web application running on Amazon EC2 instances that run 24/7 for the next 12 months. The workload is steady and predictable. Which EC2 purchasing option provides the highest cost savings for this use case?
Standard Reserved Instances
Standard Reserved Instances are ideal for a steady, predictable 24/7 workload because they offer the deepest discount, up to 72% compared to On-Demand, when you commit to a 1-year or 3-year term. You can choose All Upfront, Partial Upfront, or No Upfront payment options, which further optimize cash flow while locking in the lowest hourly rate for a specific instance family and region. For a workload that runs continuously without interruption, this commitment maximizes cost savings while guaranteeing capacity, making it the most economical choice.
Spot Instances
On-Demand Instances
Savings Plans (Compute)
A company runs a large number of EC2 instances across multiple accounts and regions. The finance team needs to track costs per project and department. Each EC2 instance must be tagged with a ProjectID and Department tag. A SysOps administrator needs to ensure that all newly launched EC2 instances are tagged automatically before they can be used, and that existing untagged instances are retroactively tagged. The tags must be propagated to cost reports in AWS Cost Explorer. Which combination of steps will achieve this with the least operational overhead?
Use AWS Config with auto-remediation to tag new instances, and activate the tags as cost allocation tags. For existing instances, run the Tag Editor with a CSV import.
This correctly combines a compliance-driven enforcement mechanism with a retroactive bulk-editing tool. AWS Config can run a managed rule that checks instances for the required tags and, if non-compliant, trigger auto-remediation via an SSM Automation document to apply those tags, covering new and modified resources continuously. Activating those tags in the Billing and Cost Management console makes them appear in cost allocation reports, and the Tag Editor can perform bulk search-and-tag across regions using a CSV import for any existing instances that predate the rule. Together, these steps tag both new and existing resources and ensure cost reporting reflects the tags.
Create an AWS Lambda function that tags instances at launch via CloudTrail events, and use AWS Budgets to enforce tagging.
Use AWS Cost Categories to automatically group costs based on resource tags.
Ensure all AMIs used have tags that propagate to instances, and enable cost allocation tags.
A company runs a batch processing application on Amazon EC2 that runs for 2 hours every night. The workload can tolerate interruptions. Which EC2 purchasing option provides the lowest cost for this use case?
On-Demand Instances
Reserved Instances
Spot Instances
Spot Instances operate using spare EC2 capacity that AWS makes available at a significantly reduced hourly rate—often up to 90% off On-Demand pricing. This is the best fit here because the nightly 2-hour batch is both short and fault-tolerant: if capacity is reclaimed, work can be re-queued or resumed without violating the batch window. You can further reduce interruption risk by using a Spot Fleet with multiple instance types and by implementing checkpointing so progress is saved between runs. The result is a dramatic cost reduction for a workload that would otherwise be idling and paying full price.
Dedicated Hosts
A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application reads data from an Amazon RDS for MySQL database. During peak hours, the database CPU utilization is consistently high, and the application experiences increased latency. The SysOps administrator observes that 90% of database queries are read-only. Which combination of actions will both improve performance and optimize costs?
Enable Multi-AZ for the RDS instance and scale up the instance size
Implement a read replica for the RDS instance and modify the application to route read queries to the read replica
Implementing a read replica creates a separate RDS instance that uses asynchronous replication to maintain a copy of the primary database, and it has its own endpoint that can handle read traffic. By modifying the application to route SELECT queries to the read replica (and keeping write operations on the primary), you offload CPU-intensive read workloads from the primary instance, directly alleviating high CPU utilization. This is a proven pattern for read-heavy applications because it scales read capacity independently and is more cost-effective than scaling up the primary, as you only size the primary for write throughput.
Enable Amazon RDS Performance Insights and increase the storage allocation
Implement Amazon ElastiCache for Memcached in front of the database and migrate read-heavy queries to cache
A company runs a web application on Amazon EC2 instances that are part of an Auto Scaling group. The application's traffic is predictable with regular peaks during business hours and low traffic at night. The SysOps administrator wants to optimize costs while ensuring that performance meets demand. The administrator also needs to minimize manual intervention. Which scaling policy should be used?
Scheduled scaling
Scheduled scaling allows you to define a recurring or one-time schedule to adjust the desired capacity of an Auto Scaling group at a future time. Because the company's workload follows a predictable pattern (e.g., a morning peak), scheduled scaling can proactively add EC2 instances before the traffic arrives, eliminating the lag inherent in reactive methods. After the initial configuration, it runs automatically without manual intervention, making it the most efficient choice for a known, consistent demand curve.
Target tracking scaling
Simple scaling
Manual scaling
Want more Cost and Performance Optimization practice?
Practice this domain20% of exam · 6 sample questions below
A company uses AWS CloudTrail to log API calls across all regions. The SysOps administrator notices that logs for a specific region are missing from the centralized S3 bucket. What is the most likely cause?
The CloudTrail trail is not enabled for that region.
CloudTrail trails are regional resources by default. If the trail was created for a single region, it captures API calls only in that region, and you must explicitly configure a multi-region trail or create separate trails for other regions. The absence of logs for a specific region strongly indicates that no trail is enabled in that region.
The S3 bucket policy denies write access from CloudTrail for that region.
CloudTrail log file validation is disabled.
The IAM role for CloudTrail does not have permissions to write logs from that region.
A SysOps administrator is troubleshooting an application that runs on AWS Lambda. The application occasionally fails with timeout errors. The administrator needs to identify the exact lines of code that are causing the delays. Which AWS service or feature should be used to gather this information?
Enable detailed CloudWatch Logs and search for 'timeout' strings.
Use AWS X-Ray to trace the Lambda function and view segment details.
AWS X-Ray is the correct choice because it provides end-to-end distributed tracing for Lambda invocations, capturing a segment for the entire execution and subsegments for each downstream operation, such as DynamoDB queries, HTTP calls, or custom code blocks. When the X-Ray SDK is installed and the function is instrumented with wrappers or decorators, you can view segment details to see the exact duration of each subsegment, pinpointing which line or API call is slow. Even without custom instrumentation, X-Ray shows the overall execution time and any downstream service traces, but adding subsegments yields the precise line-level breakdown needed for this troubleshooting.
Set a CloudWatch Metric Filter for 'Duration' and create an alarm.
Enable AWS CloudTrail data events for the Lambda function.
A SysOps administrator needs to monitor the CPU utilization of an Amazon EC2 instance fleet and send an alert when the average CPU utilization exceeds 80% for 10 consecutive minutes. The administrator also wants to automatically stop the instance if the CPU utilization remains above 90% for 30 minutes to prevent runaway costs. Which combination of AWS services should be used?
Amazon CloudWatch alarm + AWS Lambda + AWS Systems Manager Automation
Amazon CloudWatch alarm + Amazon Simple Notification Service (SNS) + AWS Lambda
A CloudWatch alarm monitors the CPU metric and publishes to an SNS topic when the threshold is breached. The SNS topic triggers a Lambda function that calls the EC2 StopInstances API to stop the instance. This is a clean, low-overhead solution.
Amazon CloudWatch Logs + Amazon EventBridge + AWS Step Functions
AWS CloudTrail + Amazon EventBridge + AWS CodePipeline
A SysOps administrator manages an Amazon RDS for MySQL instance that handles a critical web application. During peak traffic, the number of database connections exceeds 500 for more than 15 minutes, leading to connection timeouts. The administrator wants to automatically increase the DB instance size when the connection count remains high, and decrease it when the load drops, to balance performance and cost. Which combination of AWS services should be used to achieve this automation with the least operational overhead?
Configure a CloudWatch alarm on DatabaseConnections that triggers an Amazon CloudWatch Events rule, which directly modifies the DB instance class using a CloudFormation custom resource.
Use an AWS Config rule to monitor DatabaseConnections and invoke an AWS Lambda function to scale the RDS instance when the threshold is breached.
Set up an Amazon CloudWatch alarm on the DatabaseConnections metric that triggers an AWS Lambda function to modify the DB instance class via the RDS API.
Correct: you create a CloudWatch alarm on DatabaseConnections with a threshold (e.g., high connections for 5 minutes); when it enters ALARM, it sends a notification to an SNS topic that triggers a Lambda function, or uses an alarm action to invoke Lambda directly. The Lambda function calls the RDS ModifyDBInstance API with the desired DBInstanceClass and the DBInstanceIdentifier, and RDS performs the scaling. This is an event-driven, low-latency pattern that requires no polling and is a supported, commonly used approach for automated RDS instance-class scaling.
Use an AWS Systems Manager Automation runbook to periodically check the DatabaseConnections metric and adjust the RDS instance class if needed.
A SysOps administrator manages an Application Load Balancer (ALB) that distributes traffic to an Auto Scaling group of EC2 instances. The administrator needs to receive a notification whenever the number of unhealthy targets in the ALB target group exceeds a threshold of 2 for at least 5 consecutive minutes. Which solution meets this requirement with the least operational overhead?
Create a CloudWatch alarm on the 'UnHealthyHostCount' metric for the ALB target group, with a threshold of 2 and an evaluation period of 5 minutes. Configure the alarm to send an Amazon SNS notification.
CloudWatch automatically receives the UnHealthyHostCount metric from the ALB's target group, so a CloudWatch alarm can directly monitor unhealthy host counts without any custom code. Setting the threshold to 2 and an evaluation period of 5 minutes triggers the alarm when the count exceeds 2 for that duration, and the alarm's SNS action sends a notification to subscribed endpoints. This is the simplest and most reliable approach because it uses native AWS monitoring.
Enable AWS CloudTrail logging for the ALB and create a CloudWatch metric filter for 'UnHealthyHostCount' events. Then create an alarm on that metric to notify via SNS.
Use an AWS Config rule to evaluate the health of the ALB target group and trigger an SNS notification when non-compliant.
Create an Amazon EventBridge rule that triggers every minute to call the AWS CLI command describe-target-health and send a notification via Lambda if unhealthy count exceeds 2.
A SysOps administrator needs to monitor AWS CloudTrail logs for any calls to the 'CreateUser' API in AWS Identity and Access Management (IAM). When such an API call is detected, the administrator wants to receive a notification within a few minutes and also log the event to a central log group in Amazon CloudWatch Logs. The solution should use minimal custom code. Which combination of services should be used?
Configure AWS CloudTrail to deliver logs to Amazon CloudWatch Logs, create a metric filter for the 'CreateUser' API call, and set up a CloudWatch alarm that sends an Amazon SNS notification.
Use AWS CloudTrail with Amazon EventBridge by creating an event rule that matches the 'CreateUser' API call via the 'aws.cloudtrail' event source, and set the targets to an Amazon SNS topic and a CloudWatch Logs log group.
Amazon EventBridge natively listens for AWS service events, including CloudTrail API calls. By creating a rule with a custom event pattern that matches the specific API call, you can directly send the event to multiple targets (SNS, CloudWatch Logs, Lambda, etc.) without needing metric filters or alarms. This is the recommended low-overhead solution.
Write an AWS Lambda function that is triggered by Amazon S3 events when a new CloudTrail log is delivered to S3. The Lambda parses the log file for 'CreateUser' and if found, sends an SNS notification.
Enable AWS Config and create a custom rule that evaluates CloudTrail trail configurations for events.
Want more Monitoring, Logging, and Remediation practice?
Practice this domain16% of exam · 6 sample questions below
An application uses an Amazon DynamoDB table with on-demand capacity. The SysOps administrator needs to ensure the table remains available during an AWS regional outage. Which strategy should be used?
Enable DynamoDB Accelerator (DAX).
Create a read replica in another region.
Use DynamoDB global tables.
Global tables are DynamoDB's multi-Region replication feature, providing active-active copies of a table in up to six AWS Regions. When enabled, all data mutations are automatically propagated to every replica, and each replica supports both reads and writes with conflict resolution, so application traffic can be failed over to a healthy Region. This availability and automatic synchronization directly address the requirement to survive a regional outage.
Increase read and write capacity units.
A SysOps administrator is testing the failover of an Amazon RDS for PostgreSQL Multi-AZ DB instance. The application currently writes to the primary instance in us-east-1a. Which action will manually trigger a failover to the standby instance in us-east-1b?
Reboot the DB instance and select 'Reboot with failover'.
Selecting 'Reboot with failover' performs a forced failover by rebooting the primary instance and automatically promoting the Multi-AZ standby to primary. Because the standby is kept synchronously replicated through the same Multi-AZ architecture, this operation validates the failover path without any data loss and only incurs a brief availability interruption during the promotion. This is the officially supported method to test failover behavior in an Amazon RDS Multi-AZ deployment.
Modify the DB instance to Single-AZ and then back to Multi-AZ.
Reboot the DB instance without selecting any failover option.
Promote the standby instance using the Amazon RDS console.
A company runs a web application on Amazon EC2 instances in a single Availability Zone. The SysOps administrator wants to increase the availability of the application so that it can survive an Availability Zone failure. Which action is the most effective?
Deploy an additional EC2 instance in the same Availability Zone.
Launch EC2 instances in two different Availability Zones and place them behind an Application Load Balancer.
Launching EC2 instances in two different Availability Zones and placing them behind an Application Load Balancer is the canonical web-tier high availability pattern. The ALB performs continuous health checks and distributes traffic to healthy targets across both AZs. If an entire AZ becomes unhealthy, the ALB automatically reroutes requests to instances in the remaining AZ, preserving the application's availability. This design eliminates the AZ as a single point of failure for the web tier.
Enable termination protection on all EC2 instances.
Use an Amazon RDS Multi-AZ deployment for the database tier.
A company runs a stateful web application on a single Amazon EC2 instance with an Elastic IP address. The SysOps administrator needs to increase availability so that if the instance fails, a new instance can be launched quickly with the same configuration and the same IP address. The administrator also needs to ensure data is not lost. Which solution meets these requirements with the least operational overhead?
Use an Application Load Balancer with an Auto Scaling group and a launch configuration that includes the Elastic IP
Create an AMI from the instance, store data on an Amazon EFS file system, and use an Auto Scaling group with a lifecycle hook to associate the Elastic IP
The AMI provides a pre-configured launch template. EFS provides durable, shared storage for application data. The Auto Scaling group automatically launches a new instance if the current one fails, and the lifecycle hook script associates the Elastic IP to the new instance, ensuring continuity with the same IP.
Create a CloudFormation template that launches a new instance and associates the Elastic IP
Place the instance in an Auto Scaling group with a minimum of 1 and a maximum of 1, and set the health check to replace unhealthy instances
A company runs a critical production database on Amazon RDS for MySQL with a Multi-AZ deployment. The database experiences a primary instance failure. The SysOps administrator needs to understand exactly how the failover process worked and why the application experienced a longer-than-expected downtime. Which AWS service or feature should the administrator use to review detailed events and actions during the failover?
AWS Personal Health Dashboard
The AWS Personal Health Dashboard (PHD) is the correct resource because it surfaces service health events that are specific to your AWS account and resources. For an RDS Multi-AZ failover, PHD provides a detailed event with the exact time, date, affected database instance, and the cause of the failover (e.g., infrastructure maintenance, hardware degradation, or patching). PHD also includes a timeline of activity and often links to related operational guidance, making it the authoritative source for reviewing automated failover details. Unlike generic service health dashboards, PHD filters events down to your particular resources, ensuring you see the actual failover incident that occurred.
Amazon RDS Performance Insights
Amazon CloudWatch Logs
AWS CloudTrail
A company runs a stateless web application on Amazon EC2 instances in an Auto Scaling group with a minimum of 2 and maximum of 10 instances. The instances are behind an Application Load Balancer (ALB). The SysOps administrator needs to ensure that the application can survive the failure of an entire AWS Availability Zone (AZ) in the region. Which configuration is necessary?
Configure the Auto Scaling group with subnets in at least two Availability Zones and ensure the ALB has subnets in the same AZs.
Correctly designed for failure domain isolation: an Auto Scaling group spanning subnets in at least two Availability Zones (AZs) lets EC2 instances be provisioned across independent infrastructure, and an ALB with subnets in those same AZs can route traffic to healthy instances in any AZ. If one AZ becomes unavailable, the ALB continues distributing requests to instances in the remaining AZs, while Auto Scaling replaces failed instances in the other AZs. This provides high availability because the application is stateless and can serve all traffic from a single AZ when needed.
Increase the Auto Scaling group minimum to 10 instances to absorb the failure.
Use larger instance types to handle the load of a failed AZ.
Use multiple Application Load Balancers in different AZs.
Want more Reliability and Business Continuity practice?
Practice this domain18% of exam · 6 sample questions below
A team uses AWS CodeDeploy with a deployment configuration of CodeDeployDefault.OneAtATime to deploy a web application to an Auto Scaling group. Instances are behind an Application Load Balancer. The deployment fails with 'The overall deployment failed because too many individual instances failed deployment.' What is the most likely cause?
The health check grace period on the Auto Scaling group is too short.
The health check grace period on the Auto Scaling group is too short. When a deployment launches new instances, the ASG considers an instance healthy only after the grace period expires; if the period is shorter than the time CodeDeploy needs to install the application and pass its own validation, the ASG will prematurely flag the instance as failing ELB health checks. Auto Scaling then terminates and replaces the instance mid-deployment, which CodeDeploy sees as a failed deployment ("too many individual instances"), and the cycle repeats for each new replacement. The correct fix is to increase the grace period to exceed the typical deployment duration.
The target group deregistration delay is too long.
The CodeDeploy agent is not installed on the instances.
The deployment group is configured to skip the ELB health check.
A development team uses AWS CloudFormation to deploy infrastructure. They want to update a stack but first need to review how the changes will impact existing resources before applying them. Which CloudFormation feature should they use?
Change sets
Change sets in AWS CloudFormation let you create a summary of proposed modifications to a stack without applying them. They provide a preview of exactly which resources will be added, modified, or removed, and indicate whether a change will cause replacement or simple updates. This review capability is especially valuable for production stacks, as it lets you catch unintended destructive actions before they execute.
Stack policies
Condition functions
Custom resources
A company uses AWS CodeDeploy to deploy a new version of an application to EC2 instances in an Auto Scaling group behind an Application Load Balancer. The company requires zero downtime during the deployment. Which deployment configuration should be used?
CodeDeployDefault.AllAtOnce
CodeDeployDefault.OneAtATime
CodeDeployDefault.EC2/OnPremises: BlueGreenDeployment
Create a blue/green deployment by configuring CodeDeploy to launch new instances and shift traffic after validation.
A blue/green deployment with CodeDeploy provisions a new, separate fleet of EC2 instances (green) and installs the new revision on them while the original fleet (blue) continues to serve traffic. After validation of the green instances—through health checks, tests, or a manual approval—you can shift traffic from the blue fleet to the green fleet using an Application Load Balancer. This approach isolates the new version from production traffic until it is verified, and if a problem arises you can instantly reroute traffic back to the blue fleet, ensuring zero downtime.
A company uses AWS CloudFormation to deploy a three-tier web application. The SysOps administrator wants to update a critical parameter, such as the instance type, and ensure that the change is applied without recreating the EC2 instance, if possible. Which CloudFormation stack update feature should be used to achieve this?
Change sets
Change sets are the correct method for previewing CloudFormation updates. They generate a summary of the actions CloudFormation will perform when you execute the change set, explicitly flagging each resource as 'Static' (no change), 'Update' (in-place modification), or 'Replace' (recreation with a new physical ID). This allows you to inspect the exact impact before committing, so you can avoid unintended resource recreation and associated data loss or downtime.
Stack policy
Update with drift detection
Directly edit the stack template and use the update stack action
A company uses AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment strategy is set to CodeDeployDefault.HalfAtATime. The lifecycle hooks for the Auto Scaling group include a test hook that runs during instance launch. During a recent deployment, the deployment failed because the new instances failed the test hook and were not marked as healthy. The SysOps administrator needs to ensure that failed instances are automatically terminated and replaced with new ones from the Auto Scaling group. Which configuration change should the administrator make?
Modify the Auto Scaling group's health check type to ELB
When the health check type is set to ELB, the Auto Scaling group uses the Application Load Balancer's health checks. If the test hook fails, the instance will be marked unhealthy by the ALB, and the Auto Scaling group will terminate and replace it, ensuring only healthy instances remain.
Modify the CodeDeploy deployment configuration to use an increased minimum healthy instance count
Modify the Auto Scaling group's health check grace period to a lower value
Modify the CodeDeploy deployment to ignore the lifecycle hook failure
A company uses AWS CloudFormation to deploy a web application. The template currently hard-codes the EC2 instance type (e.g., t3.medium). The SysOps administrator wants to make the instance type configurable so that different environments (dev, test, prod) can use different instance types without modifying the template each time. Which CloudFormation feature enables this?
Parameters
Parameters are the only CloudFormation construct here that accept runtime input. When you create or update a stack, you supply values, either interactively, via CLI, or via a stack template, and those values are referenced with Ref to set resource properties. Because the same template can be reused with different parameter values, parameters are the correct way to make a stack deployable to multiple environments with different configuration.
Mappings
Conditions
Outputs
Want more Deployment, Provisioning, and Automation practice?
Practice this domain16% of exam · 6 sample questions below
An organization requires that all Amazon S3 buckets be encrypted at rest by default. A SysOps administrator needs to enforce this using AWS Config. Which AWS Config managed rule should be used?
s3-bucket-encryption-enabled
The AWS Config managed rule s3-bucket-encryption-enabled evaluates whether an S3 bucket has default encryption enabled, which is satisfied by configuring either SSE-S3 or SSE-KMS. This ensures new objects written to the bucket are automatically encrypted at rest, directly meeting the organization's encryption requirement. Without this rule, a bucket could store plaintext objects, making it the correct choice.
s3-bucket-ssl-requests-only
s3-bucket-public-read-prohibited
s3-bucket-logging-enabled
A SysOps administrator needs to ensure that all traffic to an Application Load Balancer (ALB) uses encryption. How can this be enforced?
Configure the security group to allow only HTTPS traffic (port 443).
Create a listener that redirects HTTP requests (port 80) to HTTPS (port 443).
An Application Load Balancer listener rule can define a redirect action that responds to every HTTP (port 80) request with a 301 or 302 status and the corresponding HTTPS URL, preserving the path and query parameters. This is the native, supported pattern to force HTTPS because it transparently upgrades the client before the request reaches any target. The redirect action is evaluated before routing to target groups, so no compute resources are needed to enforce the policy.
Use AWS WAF to block HTTP requests.
Configure the ALB to use a custom SSL certificate.
An organization requires that all Amazon S3 buckets block public access entirely. A SysOps administrator needs to ensure that no bucket can be made public, even accidentally. Which approach enforces this control at the organizational level?
Apply an S3 Bucket Policy on each bucket that denies public access.
Use an AWS Config managed rule 's3-bucket-public-read-prohibited' to detect and remediate public buckets.
Enable S3 Block Public Access at the account level and attach an SCP to deny changes to it.
This is the only correct answer because it provides a centralized, preventive, and tamper-proof control. Enabling S3 Block Public Access at the account level immediately denies all public read/write access to every current and future bucket in that account. Attaching an SCP that denies s3:PutAccountPublicAccessBlock and s3:PutBucketPublicAccessBlock prevents users—even those with full S3 permissions—from modifying those settings, because SCPs cannot be overridden by IAM policies within the member account.
Create an IAM policy that denies s3:PutBucketPolicy for all users.
A company's security team requires that all Amazon EC2 instances in a specific AWS account must have the tag 'Environment' set to either 'Production' or 'Test'. Any instance that is launched without this tag or with an invalid value must be automatically terminated within five minutes. Which combination of AWS services can enforce this requirement with minimal manual intervention?
AWS Config with a custom rule and AWS Lambda
A custom AWS Config rule can evaluate EC2 instances when they are created (configuration change trigger) and invoke an AWS Lambda function to terminate instances lacking the required tag or having an invalid value. This provides continuous compliance enforcement.
AWS CloudTrail and Amazon CloudWatch Events
AWS Service Catalog and AWS Organizations
Amazon Inspector and AWS Systems Manager
A company has an AWS account that contains multiple Amazon S3 buckets with sensitive data. A SysOps administrator needs to ensure that all S3 buckets in the account have versioning enabled to protect against accidental deletions. The administrator wants to automatically remediate any bucket that is created without versioning enabled. Which solution should be used?
Use AWS Config with a managed rule (s3-bucket-versioning-enabled) and an automatic remediation action that uses an AWS Systems Manager Automation document to enable versioning
AWS Config's s3-bucket-versioning-enabled managed rule continuously evaluates every bucket in the account, including both existing resources and newly created ones. When a bucket is found noncompliant—whether it never had versioning or had it disabled—an automatic remediation action invokes an AWS Systems Manager Automation document (such as AWS-EnableS3BucketVersioning) to enable versioning immediately. This closed-loop approach ensures ongoing compliance without manual effort, and it covers all buckets regardless of how they were created or modified. AWS Config evaluates configuration changes in near real time, making this a truly detective and corrective control.
Use Amazon CloudWatch Events to detect CreateBucket API calls and trigger an AWS Lambda function to enable versioning
Use AWS CloudTrail to monitor CreateBucket events and send an alert to the SysOps administrator for manual action
Use AWS Service Catalog to enforce versioning on all buckets provisioned through it
A company uses Amazon S3 to store sensitive customer data. A SysOps administrator needs to ensure that any S3 bucket that is incorrectly configured to allow public read access is automatically remediated within five minutes. The administrator wants to use native AWS services with minimal custom code. Which solution should be used?
Use AWS Config with the 's3-bucket-public-read-prohibited' managed rule and configure automatic remediation to block public access.
AWS Config's 's3-bucket-public-read-prohibited' managed rule evaluates every S3 bucket against the defined parameter (blocking public read access) on a continuous basis. Because it is a managed rule, there is no custom code to write or maintain, and when coupled with automatic remediation (using an AWS Systems Manager Automation document that applies the 'block all public access' setting or removes bucket policies), noncompliant buckets are corrected within minutes. This is the only option that provides both automated detection and automated remediation using a pre-built, low-maintenance AWS service, meeting the five-minute requirement without manual intervention.
Create an Amazon EventBridge (CloudWatch Events) rule that triggers an AWS Lambda function to check and fix public read access.
Apply an S3 bucket policy to each bucket that denies public read access.
Use AWS Trusted Advisor to check for public read access and manually remediate when notified.
Want more Security and Compliance practice?
Practice this domainThe SOA-C02 exam has 65 questions and must be completed in 180 minutes. The passing score is 720/1000.
Operations scenario questions and hands-on lab tasks covering monitoring, deployment, security, storage, and cost management on AWS. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 6 domains: Networking and Content Delivery, Cost and Performance Optimization, Monitoring, Logging, and Remediation, Reliability and Business Continuity, Deployment, Provisioning, and Automation, Security and Compliance. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Amazon Web Services SOA-C02 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.