Courseiva

AWS Certified DevOps Engineer Professional DOP-C02 (DOP-C02) — Questions 676–750

1298 questions total · 18pages · All types, answers revealed

Page 9

Page 10 of 18

Page 11
676
MCQhard

A company uses AWS CodeStar to manage software development projects. The team wants to integrate a third-party issue tracking system with CodeStar. Which AWS service should they use to achieve this integration?

A.Amazon API Gateway
B.Amazon CloudWatch Events
C.AWS CodePipeline webhooks
D.Amazon Simple Notification Service (SNS)
AnswerC

AWS CodePipeline webhooks are the native, built-in mechanism for external systems to trigger pipeline executions via an HTTPS POST request. When you create a webhook, CodePipeline generates a dedicated URL and registers a secret token; the external service, such as an issue tracker or a third-party version control system, includes that token in its HTTP call so CodePipeline can verify the request and map the payload to the appropriate pipeline and input variables. This provides secure, bidirectional integration with external tools, enabling an issue tracker to start a pipeline when a pull request or issue is updated, and is the correct service for this scenario.

Why this answer

AWS CodePipeline webhooks allow you to connect external systems, such as a third-party issue tracking system, to your CodePipeline pipeline. When the external system triggers an event (e.g., an issue status change), the webhook sends an HTTP POST request to a configured endpoint in CodePipeline, which then starts the pipeline. This is the native integration mechanism for CodeStar to receive events from outside AWS.

Exam trap

The trap here is that candidates often confuse the purpose of AWS services like SNS or CloudWatch Events, thinking they can directly receive external HTTP callbacks, but they lack native webhook support for third-party systems, whereas CodePipeline webhooks are specifically designed for this integration.

How to eliminate wrong answers

Option A is wrong because Amazon API Gateway is used to create, publish, and manage RESTful APIs, not to directly integrate third-party issue tracking systems with CodeStar; it would require custom Lambda functions and additional overhead. Option B is wrong because Amazon CloudWatch Events (now Amazon EventBridge) is designed to route AWS service events and custom application events, but it cannot natively receive HTTP callbacks from a third-party issue tracking system without an intermediary like API Gateway. Option D is wrong because Amazon Simple Notification Service (SNS) is a pub/sub messaging service that can send notifications, but it does not provide a direct HTTP endpoint for third-party systems to trigger CodePipeline; it would require additional components to translate the webhook call into an SNS message.

677
MCQeasy

A company uses AWS OpsWorks for configuration management of a fleet of EC2 instances running a legacy application. The operations team needs to deploy a new version of the application across all instances without causing downtime. The application runs on each instance and requires a rolling update. Which approach should the team use?

A.Use AWS CodeDeploy to perform a blue/green deployment on the existing instances.
B.Create a new Auto Scaling group with the updated AMI and terminate old instances.
C.Manually update each instance by adding a new layer and reassigning instances.
D.Use the OpsWorks Deploy command to trigger a rolling update across the stack.
AnswerD

The OpsWorks Deploy command triggers the deploy lifecycle stage on the stack, running the deployment recipes that update application code and configuration on each registered instance. Because OpsWorks Stacks lets you configure the batch size and pause time, instances are updated one batch at a time while the remaining instances continue serving traffic, which minimizes downtime during the update. This is the native rolling-update mechanism for an OpsWorks-managed stack and directly addresses the requirement to update the existing fleet with minimal service interruption.

Why this answer

AWS OpsWorks provides a Deploy command that can perform rolling updates across instances in a stack. This command allows you to deploy application code or configuration changes in a controlled manner, updating instances in batches to avoid downtime. It is the native OpsWorks mechanism for rolling deployments, aligning with the requirement to update all instances without downtime.

Exam trap

The trap is confusing OpsWorks deployment methods with AWS CodeDeploy or Auto Scaling; candidates may think CodeDeploy is the default for rolling updates, but OpsWorks has its own Deploy command.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a separate service and cannot directly perform blue/green deployments on existing OpsWorks instances without significant reconfiguration; OpsWorks has its own deployment methods. Option B is wrong because creating a new Auto Scaling group with a new AMI is not a rolling update and would require replacing instances, potentially causing downtime if not managed carefully; it also does not leverage OpsWorks. Option C is wrong because manually updating each instance by adding a layer and reassigning instances is error-prone, not automated, and does not guarantee a rolling update; it could cause downtime.

678
MCQhard

Refer to the exhibit. A DevOps engineer runs the AWS CLI command to get the average TargetResponseTime for an ALB over a 1-hour period. The output shows only three datapoints. What is the most likely reason?

A.The ALB did not receive any requests during most of the 5-minute periods.
B.The metric TargetResponseTime is not available for Application Load Balancers.
C.The command is missing the 'Statistics' parameter with 'Average'.
D.The period of 300 seconds is too large; a smaller period should be used.
AnswerA

The ALB emits TargetResponseTime only when it actually processes requests. For any 5-minute interval in which no request was routed through the load balancer, CloudWatch receives no samples and therefore publishes no datapoint. The get-metric-statistics output contains a datapoint only for each period with at least one request, so periods with no traffic are simply missing from the result rather than appearing as zero. This exactly explains why fewer datapoints than expected are returned.

Why this answer

The command uses a period of 300 seconds (5 minutes), so over a 1-hour period we expect 12 data points if the metric is consistently reported. However, TargetResponseTime is only emitted when the ALB receives at least one request in that interval. The output shows only three data points, indicating that for the majority of the 5-minute periods, the ALB received no requests, so no metric data was published.

Option A correctly identifies this. Option B is incorrect because TargetResponseTime is a valid metric for Application Load Balancers. Option C is incorrect because the command appears to include the necessary parameters to retrieve the average.

Option D is incorrect because a 300-second period is standard; using a smaller period would not produce more data points if there are no requests.

679
MCQeasy

A DevOps engineer is responsible for monitoring a production environment that uses Amazon EC2 Auto Scaling. The engineer notices that the Auto Scaling group has been launching and terminating instances frequently over the past hour. The group uses a dynamic scaling policy based on average CPU utilization. The CloudWatch alarm that triggers scaling is set to a threshold of 70% CPU for scale-out and 30% for scale-in. The engineer checks the CloudWatch metrics and sees that CPU utilization is oscillating between 40% and 60%, never reaching the thresholds. The engineer suspects that the scaling policy is not working correctly. The engineer is considering the following actions: A) Change the scaling policy to use a target tracking policy with a target value of 50% CPU utilization. B) Increase the cooldown period for the scaling policy to 300 seconds. C) Disable the scale-in policy to prevent frequent terminations. D) Use a simple scaling policy instead of a dynamic scaling policy. Which action should the engineer take?

A.Disable the scale-in policy to prevent frequent terminations.
B.Change the scaling policy to use a target tracking policy with a target value of 50% CPU utilization.
C.Use a simple scaling policy instead of a dynamic scaling policy.
D.Increase the cooldown period for the scaling policy to 300 seconds.
AnswerB

Target tracking is a dynamic scaling policy that uses a control loop to continuously compute the required capacity needed to keep the CloudWatch metric at the specified target value. Rather than reacting with binary on/off alarms, it applies proportional adjustments based on the current deviation from 50% CPU utilization, smoothing out capacity changes and preventing the overshoot/undershoot cycle that causes oscillation. This gives the Auto Scaling group a clear, single objective that balances responsiveness with stability.

Why this answer

A target tracking policy automatically adjusts the desired capacity to maintain a target utilization (e.g., 50%), which smooths out oscillations by continuously adapting to load rather than reacting to fixed thresholds. Option A is wrong because disabling scale-in could lead to over-provisioning and increased costs. Option C is wrong because simple scaling policies are more prone to causing oscillations due to step adjustments with cooldowns.

Option D is wrong because increasing the cooldown period only delays scaling actions and does not address the root cause of oscillations; target tracking is more effective.

680
MCQeasy

A company uses AWS CodeBuild to compile and test code. The build process requires a specific version of a library that is not available in the default build environment. Which approach should be used to include this library in the build process?

A.Modify the buildspec file to include the library as a build artifact.
B.Store the compiled library in an Amazon S3 bucket and download it during the build process using the buildspec file.
C.Add an install command in the buildspec file to download and compile the library during each build.
D.Create a custom Docker image that includes the library and use it as the build environment in CodeBuild.
AnswerD

Creating a custom Docker image with the library preinstalled makes the library available at the very start of every build because CodeBuild runs build phases inside that image. Custom images let you pin the exact library version and all transitive runtime dependencies, ensuring reproducibility and eliminating repeated download/compile overhead. This is a best practice when the build consistently requires specialized binaries, libraries, or tools that are not present in CodeBuild's standard managed images.

Why this answer

Creating a custom Docker image that includes the required library ensures the build environment is consistent, reproducible, and avoids repeated download/compile overhead. AWS CodeBuild supports custom Docker images via the `image` field in the buildspec file or the console, allowing you to specify a repository in Amazon ECR or Docker Hub. This approach aligns with infrastructure-as-code best practices by baking dependencies into the environment rather than managing them at build time.

Exam trap

The trap here is that candidates often choose Option B or C because they think 'download during build' is simpler, but they overlook the core DevOps principle of immutable build environments and the inefficiency of re-downloading or recompiling dependencies on every build run.

How to eliminate wrong answers

Option A is wrong because a build artifact is the output of a build process, not a mechanism to include external dependencies; modifying the buildspec to include a library as an artifact would not install it into the build environment. Option B is wrong because while downloading from S3 is possible, it introduces network latency, potential permission issues, and version management overhead; it is a workaround rather than a proper solution for a missing library. Option C is wrong because adding an install command to download and compile the library during each build is inefficient, increases build time, and risks build failures due to network issues or source unavailability; it also violates the principle of using a consistent, pre-configured environment.

681
MCQmedium

Refer to the exhibit. A DevOps engineer runs the CloudWatch Logs Insights query and sees a spike in errors at 12:00. Which action would best help identify the root cause?

A.Add a filter for @logStream to see which log stream has the most errors.
B.Increase the limit to 100 to see more results.
C.Query the logs around 12:00 without aggregation to see the actual error messages.
D.Change the bin time to 1m to get more granular data.
AnswerC

Removing the count() and bin() aggregation and running a query that returns the raw @timestamp and @message fields around 12:00 will display the actual error strings, stack traces, and exception types that caused the spike. This is the definitive method for root-cause analysis because it lets you see exactly what the application logged at the moment of failure, such as a TimeoutException, a 500 Internal Server Error, or a specific failed database call. You can then filter further using regular expressions or parse commands to isolate the common pattern.

Why this answer

The query shows a sudden spike at 12:00. To identify the root cause, the engineer should look at the error messages themselves around that time. Filtering by @timestamp and @message to see the actual error messages will help identify the type of error.

Adding a filter for a specific error pattern or grouping by error message would also help.

682
Multi-Selecteasy

Which TWO are valid deployment configurations in AWS CodeDeploy? (Choose two.)

Select 2 answers
A.Rolling
B.Linear
C.AllAtOnce
D.Canary10Percent5Minutes
E.BlueGreen
AnswersC, D

AllAtOnce is a predefined CodeDeploy deployment configuration that sets the minimum healthy instances to 0, causing the deployment to update every target instance simultaneously. This configuration is valid and useful when you accept full fleet downtime during deployment, such as in development environments or for infrastructure with elastic load balancer deregistration. It is one of the named configurations you can select directly in the AWS CodeDeploy console or CLI.

Why this answer

In AWS CodeDeploy, the valid deployment configurations are predefined traffic-shifting strategies. 'AllAtOnce' is a valid configuration that deploys the new application revision to all instances simultaneously, making it one of the two correct options. 'Canary10Percent5Minutes' is also a valid configuration that shifts 10% of traffic to the new version for 5 minutes before deploying the remainder, making it the second correct option.

Exam trap

The trap here is that candidates confuse deployment types (like BlueGreen or Rolling) with deployment configurations (like AllAtOnce or Canary10Percent5Minutes), leading them to select 'BlueGreen' or 'Rolling' as valid configurations when they are actually deployment methods or strategies in other AWS services.

683
Multi-Selectmedium

A company is designing a resilient architecture for a critical application. Which TWO strategies improve resilience?

Select 2 answers
A.Deploy resources across multiple Availability Zones
B.Use a single large instance instead of multiple smaller ones
C.Use health checks to automatically replace unhealthy resources
D.Disable automated backups to reduce latency
E.Deploy resources in a single Availability Zone
AnswersA, C

Deploying across multiple Availability Zones (AZs) provides infrastructure-level fault isolation because each AZ has independent power, cooling, and network access. This architecture ensures that an outage in one AZ does not take down the entire workload, supporting a higher availability SLA. For example, running EC2 instances in two or more AZs with an Application Load Balancer allows traffic to continue to healthy AZs even if one becomes isolated.

Why this answer

Multi-AZ deployments and health checks with auto-remediation improve resilience by handling failures automatically.

684
MCQhard

An organization uses AWS CodePipeline to deploy a serverless application using AWS Lambda and Amazon API Gateway. The pipeline includes a manual approval action. The team wants to ensure that the approval email is sent to multiple approvers and that any one of them can approve or reject. How should the approval action be configured?

A.Specify multiple email addresses in the 'ApproverEmail' field of the approval action.
B.Set the 'Approvers' field in the approval action to a comma-separated list of IAM user ARNs.
C.Add multiple IAM users to the pipeline's service role.
D.Create an Amazon SNS topic with multiple subscribers, and configure the approval action to use that SNS topic ARN.
AnswerD

This is the correct approach because CodePipeline's manual approval action has an 'SNSTopicArn' configuration field that, when set, causes the pipeline to publish an approval notification to the specified SNS topic. Each email address (or other endpoint) subscribed to that topic receives the notification, and any of those subscribers—assuming they have the necessary IAM permissions—can review and approve or reject the action via the AWS console, CLI, or API. This design cleanly supports multiple approvers and also allows you to use other SNS protocols such as SMS or Lambda for custom notification flows.

Why this answer

AWS CodePipeline's manual approval action can be configured to send notifications through an Amazon SNS topic. By creating an SNS topic with multiple subscribers (e.g., email addresses), any one of the subscribers can receive the approval request and take action (approve or reject). This satisfies the requirement for multiple approvers where any single approver can act.

Exam trap

The trap here is that candidates often assume the 'ApproverEmail' field can accept multiple addresses or that IAM-based approvers can be listed directly, but AWS CodePipeline relies on SNS for multi-approver scenarios, not direct email or IAM lists.

How to eliminate wrong answers

Option A is wrong because the 'ApproverEmail' field in the approval action accepts only a single email address, not multiple; specifying multiple addresses would cause a validation error. Option B is wrong because the 'Approvers' field does not exist in the approval action configuration; CodePipeline uses SNS topics for notifications, not IAM user ARNs. Option C is wrong because adding IAM users to the pipeline's service role does not control who receives approval notifications; the service role defines permissions for the pipeline itself, not approval recipients.

685
MCQeasy

A DevOps engineer is setting up a CI/CD pipeline for a Node.js application. The application must be built, tested, and deployed to an Amazon ECS cluster. The team wants to use AWS CodeBuild to run unit tests and package the application as a Docker image, and AWS CodePipeline to orchestrate the workflow. Which artifact type should CodeBuild output to be used by a subsequent CodePipeline action?

A.A Docker image pushed to Amazon ECR.
B.A zip file containing the application source code.
C.A tarball stored in Amazon S3.
D.A JSON file with the image details.
AnswerD

This is correct because the ECS deploy action in CodePipeline consumes an image definitions file, typically named imagedefinitions.json, formatted as a JSON array mapping each ECS container name to its image URI (for example, [{"name":"web","imageUri":"123456789012.dkr.ecr.us-east-1.amazonaws.com/my-app:latest"}]). CodeBuild generates this file as a pipeline artifact after pushing the image to ECR, and CodePipeline uses it to create/update the task definition and trigger the deployment. The file must be at the artifact root with the recognized name; any other JSON structure or filename will cause the deploy action to fail.

Why this answer

CodePipeline's ECS deploy action requires an input artifact containing an imagedefinitions.json file that specifies the image URI. CodeBuild should produce this JSON file as its output artifact, not merely push the image to ECR. The subsequent deploy action reads the JSON file to determine which image to use, so the correct artifact type is a JSON file with image details.

Exam trap

The trap is that candidates may think CodeBuild passes the Docker image itself as an artifact, but in reality, the artifact is a configuration file (imagedefinitions.json) that tells the ECS deploy action which image to use.

How to eliminate wrong answers

Option B is wrong because a zip file containing the application source code is not a valid artifact type for an ECS deploy action; the deploy action requires image details, not raw source code. Option C is wrong because a tarball stored in Amazon S3, while it can be an artifact, does not provide the image URI and tag information needed by CodePipeline's ECS deploy action; the deploy action specifically expects an imagedefinitions.json file, not a generic archive. Option D is wrong because a JSON file with image details is actually the correct format, but the option does not specify that it must be named imagedefinitions.json and be part of a build output artifact; without that specific file name and structure, the ECS deploy action will fail to parse the deployment details.

686
MCQmedium

A DevOps team uses AWS Elastic Beanstalk to deploy a web application. They want to implement a blue/green deployment strategy to minimize downtime. Which configuration change should they make?

A.Create a new environment and perform a CNAME swap.
B.Set the deployment policy to 'All at once'.
C.Set the deployment policy to 'Rolling' with a batch size of 50%.
D.Set the deployment policy to 'Immutable'.
AnswerA

In a blue/green deployment, you provision a second Elastic Beanstalk environment (the green environment) with the new application version, run tests against it, and then use the Swap Environment URLs feature to atomically redirect the existing CNAME to the new environment. This avoids any downtime during the cutover and leaves the old (blue) environment intact for instant rollback if issues arise after the swap.

Why this answer

Blue/green deployment in AWS Elastic Beanstalk is achieved by creating a separate environment (the 'green' environment) with the new application version, then swapping the CNAME of the existing 'blue' environment to point to the green environment. This CNAME swap is instantaneous and does not require DNS propagation, minimizing downtime. Option A correctly describes this process.

Exam trap

The trap here is that candidates confuse 'Immutable' deployments with blue/green, but immutable still replaces instances in-place rather than performing a CNAME swap between two independent environments.

How to eliminate wrong answers

Option B is wrong because 'All at once' deploys the new version to all instances simultaneously, causing downtime during the deployment. Option C is wrong because 'Rolling' with a batch size of 50% updates instances in batches, which still results in reduced capacity and potential downtime during the transition. Option D is wrong because 'Immutable' deploys a new Auto Scaling group with the new version, but it does not perform a CNAME swap; it replaces the old instances after health checks, which can cause brief downtime and does not provide the instant cutover of blue/green.

687
MCQeasy

A developer is using AWS CloudFormation to deploy a stack that includes an AWS Lambda function. The Lambda function code is stored in an S3 bucket. The CloudFormation template references the S3 bucket and object key. The developer wants to update the Lambda function code by uploading a new zip file to S3 and then updating the stack. The developer updates the S3 object with a new version, but the stack update does not automatically use the new code. What should the developer do to ensure the stack update uses the new code?

A.Enable S3 event notifications to trigger a CloudFormation stack update when the object is updated.
B.Modify the CloudFormation stack policy to allow updates to the Lambda function.
C.Delete the stack and recreate it with the new code.
D.Upload the new code to a different S3 key or specify a new version ID in the CloudFormation template.
AnswerD

CloudFormation tracks the AWS::Lambda::Function Code property using the literal values of S3Bucket, S3Key, and optionally S3ObjectVersion. Uploading new code to a different S3 key—or to the same key with a new object version ID—makes one of those template properties change, so a stack update sees a diff and refreshes the Lambda function's code. This is the standard practice because CloudFormation does not automatically compare content hashes or ETags; it relies on explicit property changes. If you reuse the same key and do not specify a version (or S3 versioning is disabled), CloudFormation will not detect the update and the function continues running old code.

Why this answer

CloudFormation only detects changes to S3 objects if the S3 key or version changes. By uploading the new code with a different key or specifying a new version ID in the template, CloudFormation will recognize the change and update the Lambda function. Option A is incorrect because S3 event notifications do not automatically trigger stack updates for code changes; they are typically used for other automation.

Option B is incorrect because stack policies control whether resources can be updated, but they do not cause CloudFormation to detect the code change; the template reference itself must indicate a new version. Option C is incorrect because deleting and recreating the stack is unnecessary and disruptive; a simple stack update with a new version ID is sufficient.

688
MCQhard

An application running on Amazon ECS Fargate is experiencing intermittent HTTP 503 errors from the Application Load Balancer (ALB). The target group health checks are passing. Which configuration is MOST likely causing this issue?

A.The deregistration delay is set too short, causing connections to be closed before requests complete.
B.The ALB's slow start duration is too long, causing requests to be dropped.
C.The health check interval is set too low, causing targets to be marked unhealthy prematurely.
D.The ALB's circuit breaker is tripping due to high error rates.
AnswerA

The deregistration delay (connection draining) is the time ALB gives in-flight requests to finish after a target is deregistered. On ECS Fargate, when a task is stopped, the ALB stops routing new requests and, if the delay is too short, forcibly closes the connection before long-running requests complete, causing clients to receive 502/503 responses. For high-latency or streaming workloads, the delay must exceed the longest expected request duration.

Why this answer

The intermittent HTTP 503 errors from the ALB, despite health checks passing, indicate that the target (ECS Fargate task) is being deregistered while still processing active requests. A deregistration delay that is too short causes the ALB to close connections to the target before the application has finished responding, resulting in 503 errors for in-flight requests. The default deregistration delay is 300 seconds; setting it too low (e.g., 5 seconds) can cause this issue.

Exam trap

The trap here is that candidates often assume 503 errors are always caused by health check failures or overload, but the question explicitly states health checks are passing, so the issue must be related to connection draining or deregistration behavior rather than target health or load balancing algorithms.

How to eliminate wrong answers

Option B is wrong because slow start gradually increases the number of requests sent to a newly registered target, which can cause transient performance issues but does not directly cause 503 errors; it would more likely cause latency or uneven load distribution. Option C is wrong because a low health check interval would cause targets to be marked unhealthy more frequently, but the question states health checks are passing, so this is not the cause of the 503 errors. Option D is wrong because the ALB circuit breaker (a feature of AWS App Mesh or certain service meshes) is not a standard ALB feature; ALBs do not have a built-in circuit breaker that trips due to high error rates—instead, they rely on health checks and target group settings.

689
MCQhard

A company has a monolith application that takes over an hour to build. The DevOps team wants to implement continuous integration using AWS CodeBuild. The build environment requires a large amount of dependencies that are rarely updated. Which strategy will MINIMIZE build time and cost?

A.Enable Amazon S3 cache for the CodeBuild project to reuse dependencies from previous builds.
B.Store the dependencies in an Amazon S3 bucket and download them at the start of each build.
C.Create a custom Docker image that includes all dependencies and use it as the build environment.
D.Use a larger compute type for the CodeBuild project to speed up the build.
AnswerC

Creating a custom Docker image that pre-installs all dependencies means those dependencies already exist inside the image's local file system when the CodeBuild container starts, so there is no download phase at all. The build can proceed directly to compilation, packaging, and testing, making the build time deterministic and dramatically shorter for a monolith. This image should be stored in Amazon ECR and updated whenever the dependency set changes, ensuring the build environment is both fast and consistent.

Why this answer

By pre-baking all rarely-updated dependencies into a custom Docker image, the build environment is ready instantly without any download or installation steps. This eliminates the overhead of fetching dependencies at build time, which is the primary bottleneck for a monolith with a large dependency set, and minimizes both build duration and cost by reducing compute time.

Exam trap

The trap here is that candidates often assume caching (Option A) or downloading from S3 (Option B) is sufficient, but they overlook that for rarely-updated dependencies, pre-building them into a custom image eliminates the dependency installation step entirely, which is the most time-consuming part of the build.

How to eliminate wrong answers

Option A is wrong because Amazon S3 cache in CodeBuild is designed for caching intermediate build artifacts (e.g., compiled objects) to speed up incremental builds, but it does not eliminate the need to download or install dependencies from scratch on a fresh build environment; the cache must be populated and restored, which still incurs network transfer time and storage costs. Option B is wrong because downloading dependencies from an S3 bucket at the start of each build still requires significant network I/O and time, especially for a large dependency set, and does not reduce the build duration as effectively as having them pre-installed in the environment. Option D is wrong because using a larger compute type (e.g., more vCPUs/memory) only accelerates the build steps themselves (compilation, testing) but does not address the bottleneck of installing dependencies; the dependency installation time remains largely unchanged, and larger instances cost more per minute, increasing overall cost without proportional time savings.

690
MCQeasy

A DevOps engineer is setting up a CI/CD pipeline for a microservices application using AWS CodePipeline. The pipeline includes a Test stage that runs integration tests against a staging environment. The engineer wants to ensure that manual approval is required before deploying to production. Which action should be taken?

A.Configure a CodeCommit approval rule template to block the merge.
B.Use CloudWatch Events to send a notification and wait for a custom signal.
C.Set the pipeline to only run on manual invocation.
D.Add a manual approval action in the pipeline stage before production deployment.
AnswerD

A manual approval action pauses the pipeline at the stage boundary, requiring a nominated approver to review and release the change before production deployment proceeds. This directly satisfies the stem's constraint that manual approval is required before deploying to production, without altering the Test stage or build artefacts.

Why this answer

AWS CodePipeline supports a manual approval action that can be added to any stage. By placing this action in the stage immediately before the production deployment, the pipeline will pause and require an authorized user to manually approve the transition, ensuring that integration tests have passed before any production release occurs.

Exam trap

The trap here is that candidates may confuse repository-level approval mechanisms (like CodeCommit approval rules) with pipeline-level deployment approvals, or assume that manual invocation alone satisfies the requirement for a conditional approval step.

How to eliminate wrong answers

Option A is wrong because CodeCommit approval rule templates are used to enforce code review policies on pull requests within the repository, not to control deployment approvals in a pipeline. Option B is wrong because CloudWatch Events can trigger notifications but cannot natively pause a pipeline and wait for a custom signal; implementing such a wait would require a custom Lambda function and additional complexity, whereas CodePipeline provides a built-in manual approval action. Option C is wrong because setting the pipeline to only run on manual invocation would prevent automated triggers (e.g., from code pushes), but it does not add a conditional approval step before production deployment; the entire pipeline would run without any pause for manual review.

691
MCQmedium

A company uses AWS CloudTrail to log API activity across multiple accounts in AWS Organizations. The security team wants to receive near-real-time notifications for specific high-risk API calls, such as IAM policy changes or S3 bucket policy modifications. What is the MOST efficient and scalable solution?

A.Deliver CloudTrail logs to an S3 bucket, enable S3 Event Notifications to trigger a Lambda function that filters and publishes to SNS.
B.Create a CloudWatch Events rule that matches the specific API calls and publishes to an SNS topic.
C.Use CloudWatch Logs Insights to query CloudTrail logs and set up a metric filter with an alarm.
D.Enable AWS Config rules to detect changes and trigger an SNS notification.
AnswerA

CloudTrail writes log files to S3 as compressed JSON objects, and S3 Event Notifications fire as soon as each object is created, triggering a Lambda function in near-real-time. The Lambda can decompress the log file, parse individual events, and apply precise filters—such as specific event names, source IPs, or IAM principals—before publishing only the high-risk actions to SNS. This serverless, event-driven pattern scales automatically with account activity and avoids the cost and noise of notifying on every raw CloudTrail event, making it both efficient and cost-effective for high-volume accounts.

Why this answer

It uses S3 Event Notifications to trigger a Lambda function in near-real-time when CloudTrail logs are delivered to S3. The Lambda function can filter for specific high-risk API calls (e.g., IAM policy changes, S3 bucket policy modifications) and publish only relevant events to an SNS topic, providing a scalable and cost-effective solution that avoids polling or complex querying.

Exam trap

The trap here is that candidates often assume CloudWatch Events (EventBridge) is the default choice for real-time CloudTrail monitoring, but they overlook that S3 Event Notifications with Lambda provide a more direct and scalable path for filtering high-volume log data without the overhead of streaming all logs to CloudWatch Logs.

How to eliminate wrong answers

Option B is wrong because CloudWatch Events (now Amazon EventBridge) can match specific API calls from CloudTrail, but it does not support near-real-time notifications for all CloudTrail log entries; it relies on CloudTrail delivering logs to CloudWatch Logs, which can introduce latency and is less efficient for high-volume filtering. Option C is wrong because CloudWatch Logs Insights is a query tool for ad-hoc analysis, not a real-time notification mechanism; metric filters and alarms can trigger notifications but require logs to be streamed to CloudWatch Logs, adding complexity and potential delay. Option D is wrong because AWS Config rules detect configuration changes (e.g., resource modifications) but are not designed for real-time API-level monitoring; they evaluate resources periodically or on configuration changes, which may not capture all high-risk API calls and introduces evaluation delays.

692
MCQhard

An organization wants to enforce that all Amazon S3 buckets are encrypted with SSE-S3. Which AWS service can be used to automatically remediate non-compliant buckets?

A.AWS CloudTrail
B.AWS Config rules with auto-remediation
C.IAM policies
D.AWS Service Catalog
AnswerB

AWS Config rules with auto-remediation are the correct choice because they provide continuous monitoring and automated correction. A managed rule like s3-bucket-server-side-encryption-enabled detects non-compliant buckets, and the associated remediation action (via SSM Automation or a custom Lambda) automatically applies SSE-S3 default encryption to the bucket. This is the only option that both detects existing non-compliant buckets and actively modifies their configuration to become compliant, satisfying the organization's requirement in real time.

Why this answer

AWS Config rules can evaluate whether S3 buckets have SSE-S3 encryption enabled and trigger automatic remediation actions via SSM Automation documents. This provides continuous compliance monitoring and enforcement without manual intervention, directly addressing the requirement to automatically remediate non-compliant buckets.

Exam trap

The trap is assuming that IAM policies or CloudTrail can enforce encryption, when only AWS Config provides the evaluation and auto-remediation capability for resource compliance.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail only records API activity and does not evaluate resource compliance or perform remediation. Option C is wrong because IAM policies control access permissions but cannot enforce encryption settings on S3 buckets or automatically remediate misconfigurations. Option D is wrong because AWS Service Catalog is used to create and manage approved IT service catalogs for provisioning, not for compliance monitoring or remediation of existing resources.

693
Multi-Selecthard

A company uses AWS Elastic Beanstalk to deploy a web application. The application experiences high traffic during business hours and low traffic at night. The company wants to configure automatic scaling based on CPU utilization. Which THREE steps are required to achieve this? (Select THREE.)

Select 3 answers
A.Create a CloudWatch alarm that triggers a scaling policy.
B.Set the minimum and maximum number of instances for the auto scaling group.
C.Configure the load balancer health check interval.
D.Set the scale-up and scale-down cooldown periods.
E.Define a scaling trigger based on average CPU utilization.
AnswersB, D, E

Setting the minimum and maximum number of instances for the Auto Scaling group is an absolute prerequisite for any elastic scaling in Elastic Beanstalk. These values define the allowed capacity range that the Auto Scaling group can scale within, and without them the Auto Scaling group cannot adjust its size. Every scaling activity, whether scale-out or scale-in, must respect these boundaries, making this a mandatory configuration element.

Why this answer

Elastic Beanstalk uses Auto Scaling groups to manage the EC2 instances for the application. Setting the minimum and maximum number of instances defines the boundaries within which the Auto Scaling group can scale, ensuring the application can handle high traffic during business hours and scale down during low traffic at night.

Exam trap

The trap here is that candidates often think creating a CloudWatch alarm manually is required, but Elastic Beanstalk handles this automatically when you define the scaling trigger, making Option A an unnecessary step.

694
MCQhard

A DevOps engineer runs the above command and sees that one target is unhealthy with a 503 error. The application is a web server running on port 80. The health check is configured to hit the root path '/'. Which action should the engineer take to resolve the issue?

A.Change the health check port to 443 and use HTTPS
B.Verify that the application on the unhealthy instance is configured to respond to '/' with a 200 status code
C.Increase the health check interval and timeout settings
D.Check the security group rules for the target group to ensure port 80 is open
AnswerB

A 503 status code from the health check endpoint indicates that the target instance is reachable at the HTTP layer, but the application logic serving the root path '/' is returning a Service Unavailable error. Elastic Load Balancing requires a 2xx or 3xx response for the health check to mark the instance healthy; any 4xx or 5xx status counts as unhealthy. Verify that the web server or application is configured to serve '/' with a 200 OK during normal operation and that there are no authentication, redirect, or maintenance-mode rules that cause a 503 on that specific path. This is the correct troubleshooting step because the health check is working as designed—it is detecting an application-level failure.

Why this answer

The health check is configured to hit the root path '/' and expects a 200 status code. A 503 error indicates the application on the unhealthy instance is not serving the correct response for that path. Verifying that the application responds with a 200 status code on '/' directly addresses the root cause of the health check failure.

Exam trap

The trap here is that candidates often confuse network-level issues (like security groups) with application-level HTTP errors (like 503), leading them to check connectivity instead of the application's response logic.

How to eliminate wrong answers

Option A is wrong because changing the health check port to 443 and using HTTPS does not fix a 503 error; it changes the protocol and port, which may not match the application's actual configuration and could cause further failures. Option C is wrong because increasing the health check interval and timeout settings only delays detection or reduces false positives, but does not resolve the underlying issue of the application returning a 503 error. Option D is wrong because a 503 error is an application-level HTTP status code, not a network connectivity issue; security group rules for port 80 would cause a timeout or connection refused, not a 503 response.

695
Multi-Selecthard

A company runs a microservices architecture on Amazon ECS with Fargate. Services communicate via an internal Application Load Balancer (ALB). The operations team notices that occasional traffic spikes cause increased latency and timeouts. The team wants to improve resilience without over-provisioning. Which THREE steps should be taken? (Choose THREE.)

Select 3 answers
A.Increase the CPU and memory limits in the task definitions.
B.Enable ECS Service Connect for inter-service communication to manage traffic distribution.
C.Configure ECS service auto scaling with a target tracking policy based on ALB request count per target.
D.Implement a graceful shutdown handler in the application to handle SIGTERM.
E.Use EC2 launch type with Spot Instances to reduce cost.
AnswersB, C, D

ECS Service Connect provides a resilient service mesh that simplifies inter-service communication by giving each service a stable DNS name and managing traffic distribution at the application layer. It enables fine-grained traffic splitting, automatic retries, and connection draining, which collectively reduce latency and improve reliability between microservices. This is a direct remedy for latency caused by inefficient service-to-service calls, as it optimizes the network path and avoids overloading individual task instances.

Why this answer

B is correct because ECS Service Connect provides built-in traffic management for inter-service communication, including load balancing, retries, and circuit breaking. This helps distribute traffic more evenly during spikes, reducing latency and timeouts without requiring over-provisioning.

Exam trap

The trap here is that candidates often confuse vertical scaling (increasing task resources) with horizontal scaling (adding more tasks), and they may overlook the importance of application-level resilience patterns like graceful shutdowns and service mesh features for traffic management.

696
MCQhard

An application running on Amazon ECS with Fargate experiences intermittent failures. The task definition includes a single container with a health check command. Despite the health check passing, the application occasionally returns HTTP 500 errors. The application logs are sent to CloudWatch Logs. What is the MOST likely root cause?

A.The health check command only checks the process status, not the application's ability to serve requests.
B.The application is missing environment variables that are required for certain requests.
C.The ECS service is configured with a target tracking scaling policy that reacts too slowly.
D.The container port and host port in the task definition do not match the ALB target group port.
AnswerA

Using a process-only health check (e.g., checking that the PID exists) means the ECS/ALB considers the container healthy whenever the runtime is alive, regardless of whether the app can actually serve HTTP traffic. As a result, intermittent 500 errors caused by a hung worker, exhausted connection pool, or an unhandled exception inside request handling remain invisible to the health check, so the task stays in service and keeps receiving traffic. A valid health check should send a real request to the application's endpoint and verify the response code.

Why this answer

A health check command in an ECS task definition typically checks the container process status (e.g., via a shell command or a simple TCP check), not the application's HTTP layer. If the health check passes but the application returns HTTP 500 errors, it indicates the container is running but the application logic is failing (e.g., unhandled exceptions, database connection issues). This mismatch between process-level health and application-level health is a common cause of intermittent failures in containerized applications.

Exam trap

The trap here is that candidates assume a passing health check guarantees the application is fully functional, but AWS specifically tests the distinction between container-level health (process running) and application-level health (HTTP response correctness), which is a key concept for the DOP-C02 exam.

How to eliminate wrong answers

Option B is wrong because missing environment variables would cause consistent failures for specific requests, not intermittent HTTP 500 errors; the application would fail predictably when those variables are accessed. Option C is wrong because a target tracking scaling policy that reacts too slowly would cause performance degradation or timeouts under load, not intermittent HTTP 500 errors when the health check passes; scaling latency affects capacity, not application logic. Option D is wrong because mismatched container port and ALB target group port would cause the ALB health check to fail entirely, not allow the health check to pass while the application intermittently returns HTTP 500 errors; the ALB would mark the target as unhealthy.

697
MCQmedium

A company's application uses Amazon SQS to decouple microservices. During peak hours, the SQS queue backlog grows significantly, causing processing delays. The DevOps team wants to reduce latency without increasing costs unnecessarily. What should the team do?

A.Increase the visibility timeout to allow consumers more time to process messages.
B.Use an SQS queue with priority settings to process high-priority messages first.
C.Increase the SQS queue's throughput by requesting a quota increase.
D.Configure Auto Scaling for the consumer fleet based on the ApproximateNumberOfMessagesVisible metric.
AnswerD

Scaling consumers on ApproximateNumberOfMessagesVisible directly matches fleet capacity to the actual backlog, so added workers drain the queue during peaks and terminate when it empties. This satisfies the latency constraint without over-provisioning, since capacity tracks demand rather than a fixed schedule or CPU proxy.

Why this answer

Scaling the consumer fleet based on the ApproximateNumberOfMessagesVisible metric directly addresses the backlog by adding more processing capacity when the queue grows. This approach reduces latency dynamically without incurring unnecessary costs during off-peak hours, as it only scales up when needed. Auto Scaling with SQS metrics is a cost-effective, elastic solution for handling variable workloads.

Exam trap

The trap here is that candidates may confuse SQS's throughput capabilities with consumer-side scaling, assuming that increasing queue throughput (Option C) solves backlog, when in fact SQS already handles high throughput and the bottleneck is the consumer processing rate.

How to eliminate wrong answers

Option A is wrong because increasing the visibility timeout does not reduce backlog; it only gives consumers more time to process a message, which can actually increase latency if consumers fail or take longer, as messages remain hidden longer. Option B is wrong because standard SQS queues do not support priority settings; FIFO queues offer ordering but not priority-based message selection, and SQS has no built-in priority feature. Option C is wrong because SQS queues already offer virtually unlimited throughput by default (up to 3,000 messages per second for FIFO with batching, and unlimited for standard), so requesting a quota increase is unnecessary and does not address consumer-side processing capacity.

698
MCQhard

A DevOps engineer is troubleshooting an AWS CodeDeploy deployment that fails during the 'BeforeInstall' lifecycle event. The deployment group uses an in-place deployment to an Auto Scaling group. The engineer reviews the logs on the instance and sees that the 'BeforeInstall' script exits with code 1. The script is a shell script that compiles application code. What is the most likely cause of the failure?

A.The script exited with a non-zero exit code
B.The script is not included in the 'files' section of the appspec.yml
C.The script requires dependencies that are not installed on the instance
D.The script is not owned by the root user
AnswerA

CodeDeploy treats any non-zero exit code from a lifecycle event script as a definitive failure, regardless of the underlying cause. When the agent executes a script, it captures the process exit status; if it is not 0, the deployment immediately stops, marks the overall deployment as Failed, and runs any configured OnFailure hooks. This is the direct trigger for the failure, even if the script printed an error message before exiting.

Why this answer

In AWS CodeDeploy, lifecycle event scripts must exit with a status code of 0 to indicate success. Any non-zero exit code, including 1, is interpreted as a failure, causing the deployment to abort. Since the 'BeforeInstall' script exits with code 1, the deployment fails regardless of the script's intent or content.

Exam trap

The trap here is that candidates may overthink the cause (e.g., missing dependencies or file permissions) when the question explicitly states the script exits with code 1, which is the direct and most likely cause of failure in CodeDeploy's lifecycle event execution model.

How to eliminate wrong answers

Option B is wrong because the 'files' section of the appspec.yml specifies which files to copy to the instance, not which scripts to run; lifecycle hooks are defined in the 'hooks' section. Option C is wrong because while missing dependencies could cause a script to fail, the question explicitly states the script exits with code 1, which is a direct exit code failure, not a dependency error (which would typically produce a different error message or exit code). Option D is wrong because script ownership does not affect exit codes; CodeDeploy runs scripts as the root user by default, and a non-root owner would not cause a non-zero exit code unless the script itself checks ownership.

699
Multi-Selectmedium

A company is implementing a CI/CD pipeline for a containerized application using AWS CodePipeline, CodeBuild, and Amazon ECS. The pipeline should automatically deploy to a staging environment and then, after manual approval, to production. The production environment uses an ECS service with rolling update deployment. Which TWO actions are necessary to achieve this?

Select 2 answers
A.Use CloudFormation to deploy the ECS service with a rolling update policy.
B.Add a manual approval stage in CodePipeline between staging and production.
C.Set up an ECS task definition with a sidecar container for health checks.
D.Use the ECS-to-CodePipeline deploy action configured for rolling update.
E.Configure CodeBuild to push the Docker image to Amazon ECR.
AnswersB, D

A manual approval action in CodePipeline pauses the pipeline at that stage until an IAM user with approval permissions reviews and approves or rejects the promotion. This is the standard control gate between staging validation and production release, satisfying the requirement for a deliberate go/no-go decision before any prod traffic is changed.

Why this answer

A manual approval stage in CodePipeline allows a human to review and approve the deployment before it proceeds to production, which is a common requirement for controlled rollouts. Option D is correct because the ECS-to-CodePipeline deploy action (using the ECS deploy provider) natively supports rolling update deployments by updating the ECS service with the new task definition, which aligns with the requirement for a rolling update strategy.

Exam trap

The trap here is that candidates often assume CloudFormation is required for any infrastructure change in a pipeline, but CodePipeline's native ECS deploy action directly updates the service without needing CloudFormation, and the rolling update is a built-in behavior of the ECS service itself.

700
MCQmedium

An application on EC2 instances in an Auto Scaling group uses an ALB. The ALB health checks are failing for some instances, but the instances are healthy from the OS perspective. What is the most likely cause?

A.The ALB idle timeout is too low
B.The security group for the instances does not allow traffic from the ALB
C.The Auto Scaling group cooldown period is too short
D.The ALB cross-zone load balancing is disabled
AnswerB

If the instance security group does not allow inbound traffic from the ALB's security group on the health-check port, the ALB's TCP or HTTP health-check probes are silently dropped. Because the instance never completes the health-check handshake, the target fails the required number of consecutive checks and the ALB marks it unhealthy. This is a classic misconfiguration that often appears right after adding the ALB, and it also blocks normal client traffic routed by the load balancer.

Why this answer

ALB health checks originate from the ALB's nodes and require the instance's security group to permit inbound traffic on the health check port and protocol from the ALB's security group. If the security group does not allow this traffic, the health check fails even though the OS and application are healthy. This is the most common cause of ALB health check failures when instances are otherwise reachable.

Exam trap

DOP-C02 often tests whether candidates jump to scaling or timeout settings when the real issue is a security group rule blocking the ALB's health check traffic, so candidates must check network ACLs and security groups first.

How to eliminate wrong answers

Option A is wrong because the ALB idle timeout affects long-lived connections, not health check success; a low idle timeout would drop idle connections but would not cause health checks to fail. Option C is wrong because the Auto Scaling group cooldown period controls how quickly the ASG launches or terminates instances after a scaling activity; it does not affect ALB health check results. Option D is wrong because cross-zone load balancing affects traffic distribution across AZs, not whether health checks succeed; disabling it does not cause health checks to fail.

701
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. During an incident, a stack update fails with a stack rollback. The engineer needs to prevent the stack from rolling back on future failures and instead retain the resources for debugging. Which CloudFormation feature should the engineer use?

A.Enable drift detection on the stack
B.Use the '--disable-rollback' option when updating the stack
C.Use AWS CloudFormation StackSets to deploy the stack
D.Create a change set before updating instead of direct update
AnswerB

The `--disable-rollback` flag on `aws cloudformation update-stack` instructs CloudFormation to leave the stack in its failed state instead of reverting to the previous successful template. This is the correct way to prevent rollback because it preserves the partially updated resources—including any S3 buckets, EC2 instances, or custom resources—for root-cause analysis and manual remediation. The stack status becomes `UPDATE_FAILED`, and the original resources remain untouched until you intervene.

Why this answer

The `--disable-rollback` option (or `DisableRollback` in the CloudFormation template) instructs AWS CloudFormation to leave the stack in its current state (with the failed resources intact) instead of automatically rolling back to the last known good state. This allows engineers to retain the resources for debugging without the stack being torn down on failure.

Exam trap

The trap here is that candidates often confuse change sets (which preview changes) with the ability to prevent rollback, or mistakenly think drift detection or StackSets can alter rollback behavior, when only the `--disable-rollback` flag directly controls whether resources are retained on failure.

How to eliminate wrong answers

Option A is wrong because drift detection only identifies differences between the stack's actual deployed resources and the expected template configuration; it does not prevent rollback or retain resources after a failed update. Option C is wrong because StackSets are used to deploy stacks across multiple accounts and regions, not to control rollback behavior on a single stack update failure. Option D is wrong because a change set allows you to preview changes before updating, but it does not affect the rollback behavior; if the update fails, the stack will still roll back by default unless `--disable-rollback` is specified.

702
MCQhard

A company uses AWS CodeBuild to compile a Java application. The buildspec.yml includes a pre_build phase that runs unit tests and a build phase that packages the application. Recently, builds have been failing intermittently with 'OutOfMemoryError' during the test phase. The build environment is set to 'BUILD_GENERAL1_SMALL'. What is the MOST cost-effective solution?

A.Split the tests into smaller batches using CodeBuild test splitting.
B.Change the build environment to 'BUILD_GENERAL1_MEDIUM' which has more memory.
C.Configure the buildspec to set MAVEN_OPTS='-Xmx512m' to reduce JVM heap usage.
D.Use multiple CodeBuild jobs to run tests in parallel.
AnswerB

Upgrading to BUILD_GENERAL1_MEDIUM is the correct fix because CodeBuild compute tiers directly define the memory and vCPU available to the build environment: GENERAL1_SMALL provides 3 GB, while GENERAL1_MEDIUM provides 7 GB. This increases the total addressable memory for the Maven JVM, native code, and metaspace, directly resolving the OutOfMemoryError without altering the application or its dependencies. It is also cost-effective because you only pay for builds that use the larger compute type, and the price increase is modest compared to the engineering effort of optimizing memory usage.

Why this answer

The 'BUILD_GENERAL1_SMALL' environment provides only 3 GB of memory, which is insufficient for the unit tests, causing intermittent 'OutOfMemoryError'. Upgrading to 'BUILD_GENERAL1_MEDIUM' (7 GB) directly addresses the memory shortage without architectural changes, and it is the most cost-effective solution because it avoids the complexity and additional costs of parallel jobs or test splitting while still resolving the root cause.

Exam trap

The trap here is that candidates often choose to reduce JVM heap (Option C) thinking it will prevent OutOfMemoryError, but in reality reducing heap makes the problem worse; the correct approach is to increase available memory, not cap it further.

How to eliminate wrong answers

Option A is wrong because CodeBuild test splitting distributes tests across multiple concurrent builds, which increases overall compute time and cost, and does not increase the memory available to a single test process—the JVM still runs out of memory within each split batch. Option C is wrong because setting MAVEN_OPTS='-Xmx512m' reduces the maximum heap size, which would likely worsen the OutOfMemoryError by further restricting available memory; the issue is insufficient total memory, not excessive heap allocation. Option D is wrong because running multiple CodeBuild jobs in parallel multiplies the cost and does not fix the memory limit of the individual build environment; each job still runs on a 'BUILD_GENERAL1_SMALL' instance with only 3 GB of memory.

703
MCQmedium

A media company runs a video processing pipeline on AWS. Raw videos are uploaded to an S3 bucket, which triggers a Lambda function to start an AWS Batch job for transcoding. The Batch job reads the source video from S3, processes it, and writes the output to another S3 bucket. Recently, the company has seen an increase in processing failures. Investigation shows that the Batch jobs are being terminated with a 'TIMEOUT' status after running for exactly 30 minutes. The video files are large, and some jobs legitimately take up to 45 minutes. The Batch job definition has a 'timeout' setting configured. Which action should be taken to resolve this issue?

A.Modify the Batch job definition to increase the 'timeout' value to 3600 seconds (60 minutes).
B.Increase the S3 bucket lifecycle policy to retain videos longer.
C.Increase the Lambda function timeout to 60 minutes.
D.Change the Batch job queue to a different compute environment.
AnswerA

The AWS Batch job definition includes a `timeout` field that sets the maximum duration a job attempt is allowed to run before Batch forcibly terminates it as a timeout. Increasing this value to 3600 seconds (60 minutes) directly accommodates longer video processing tasks, preventing premature termination when the workload legitimately needs more than the current limit. This is the intended control for adjusting how long Batch permits a single job attempt to execute.

Why this answer

The Batch job is being terminated with TIMEOUT after exactly 30 minutes, and the job definition has a timeout setting — this is the Batch job attempt timeout (default 30 minutes if not explicitly set, or set to 1800 seconds). Since legitimate jobs take up to 45 minutes, the fix is to raise the job definition's timeout to at least 3600 seconds (60 minutes) to accommodate the longest jobs with headroom.

Exam trap

DOP-C02 often tests whether candidates can pinpoint the exact configuration parameter responsible for a symptom — here, confusing the Lambda trigger timeout with the Batch job definition timeout, or blaming the compute environment, is the trap.

How to eliminate wrong answers

Option B is wrong because S3 lifecycle policies govern object retention/transition/deletion and have no effect on Batch job execution timeouts. Option C is wrong because the Lambda function only triggers the Batch job submission; the Lambda timeout (max 15 minutes anyway) is unrelated to the Batch job's 30-minute termination, and Lambda cannot be set to 60 minutes. Option D is wrong because changing the job queue or compute environment does not alter the job definition's timeout — the TIMEOUT status comes from the job definition's timeout parameter, not from the compute environment.

704
MCQhard

During an incident, a DevOps engineer needs to quickly revoke access to a set of IAM users who are suspected to be compromised. The users have programmatic access keys and console passwords. The engineer wants to minimize the impact on non-compromised users. Which action should the engineer take FIRST?

A.Delete the compromised IAM users.
B.Attach an IAM policy that explicitly denies all actions to the compromised users.
C.Delete the access keys of the compromised users.
D.Change the IAM password policy to require strong passwords.
AnswerB

Attaching a customer-managed IAM policy with an explicit 'Deny' effect for all actions on all resources immediately revokes both console and programmatic access for the compromised users. IAM's evaluation logic gives explicit denies precedence over any allow, so even if the user still has attached policies with broad permissions, the deny-all policy overrides them. This containment action preserves the user objects and their audit trail for forensic analysis, allowing you to safely investigate and later rotate credentials or delete the users if needed. Unlike disabling keys or changing password policies, this approach covers all access methods simultaneously.

Why this answer

Attaching an explicit Deny policy to the compromised users immediately blocks all API and console actions for those principals while leaving other users untouched, and it is reversible once the incident is resolved. This is the fastest containment step that satisfies least-impact on non-compromised users. Deleting keys or users is more destructive and slower to reverse.

Exam trap

The trap is confusing 'revoke access' with 'delete the identity' — candidates pick key deletion or user deletion, missing that an explicit Deny is the fastest, least-destructive, and most complete containment because it blocks both console and API paths.

How to eliminate wrong answers

Option A is wrong because deleting IAM users is irreversible, destroys audit trail attribution, and may break dependent resources — it is a cleanup step, not a first containment action. Option C is wrong because deleting access keys only stops programmatic access; the compromised console password would still allow console login, leaving a live attack path. Option D is wrong because strengthening the password policy affects all users globally and does nothing to revoke the already-compromised credentials.

705
MCQeasy

A company's DevOps team uses AWS Config to monitor resource compliance. They have created a custom AWS Config rule that triggers an AWS Lambda function to evaluate whether EC2 instances have the 'Environment' tag with value 'Production' or 'Staging'. The rule is set to evaluate resources on configuration changes. However, the team notices that the rule does not trigger when an EC2 instance is launched. The Lambda function's IAM role has the necessary permissions to describe EC2 instances. The CloudWatch Logs for the Lambda function show that it is not being invoked. What is the MOST likely reason?

A.The Lambda function's IAM role does not have permission to write to CloudWatch Logs.
B.The AWS Config rule is set to evaluate resources periodically, not on configuration changes.
C.The AWS Config rule is not configured to trigger on AWS::EC2::Instance resources.
D.The custom rule must be deployed using AWS CloudFormation to be active.
AnswerC

For a custom AWS Config rule to evaluate a resource on configuration changes, the rule's scope must include that resource type. If the rule is defined without AWS::EC2::Instance in its 'Resource types' scope (or if it is scoped to a specific tag/resource ID that does not match), AWS Config will not send evaluation events to the Lambda function for EC2 instances. In this scenario, the rule has the correct trigger type (change) but its scope does not cover EC2 instances, so Config never invokes the Lambda function on instance launch. This is the exact cause of the DevOps team's issue.

Why this answer

For an AWS Config custom rule to fire on resource creation, the rule must specify the resource types it evaluates (e.g., AWS::EC2::Instance) in its scope. If the scope does not include EC2 instances, Config will not invoke the rule's Lambda function when an instance is launched, which matches the symptom that the Lambda is never invoked despite having correct permissions. The trigger type (configuration change) is already stated as correct in the scenario, so the missing piece is the resource scope.

Exam trap

The trap is assuming the problem is IAM or trigger type when the scenario already rules those out; the real cause is the rule's resource-type scope, which is easy to overlook because it is configured separately from the trigger.

How to eliminate wrong answers

Option A is wrong because the scenario states the Lambda role has the necessary permissions, and a CloudWatch Logs write permission issue would still allow invocation (the function would run but fail to log), not prevent invocation entirely. Option B is wrong because the question explicitly states the rule is set to evaluate on configuration changes, so this contradicts the given facts. Option D is wrong because custom Config rules can be created via the console, CLI, or CloudFormation; CloudFormation deployment is not a requirement for the rule to be active.

706
MCQhard

A company's security policy requires that all data in transit between on-premises and AWS is encrypted. Which AWS service provides a dedicated network connection with encryption?

A.AWS Transit Gateway
B.AWS Direct Connect + VPN
C.Amazon VPC peering
D.AWS Site-to-Site VPN over the internet
AnswerB

This pattern combines an AWS Direct Connect private or public virtual interface with an IPSec Site-to-Site VPN to create a dedicated, private, and encrypted link from your data center to AWS. Direct Connect ensures a consistent, low-latency connection that does not traverse the public internet, while the VPN overlay encrypts all IP traffic between your edge and the AWS virtual private gateway. The combination satisfies both the encryption mandate and the need for predictable, dedicated bandwidth, making it the best choice for this scenario.

Why this answer

AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, and when combined with a VPN over that connection, it adds IPsec encryption. This satisfies the requirement for a dedicated connection with encryption. Direct Connect alone is not encrypted, so the VPN overlay is necessary.

Exam trap

DOP-C02 often tests the misconception that Direct Connect is encrypted by default; candidates must remember that encryption requires an additional VPN overlay.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks, but it does not provide a dedicated connection or encryption by itself. Option C is wrong because VPC peering connects VPCs within AWS, not on-premises to AWS, and it does not provide encryption. Option D is wrong because a Site-to-Site VPN over the internet is encrypted but does not provide a dedicated network connection; it uses the public internet.

707
MCQhard

A company runs a critical web application on EC2 instances in an Auto Scaling group. The application uses an Application Load Balancer (ALB) with health checks pointing to /health. Recently, the application experienced intermittent failures where the ALB would mark instances as unhealthy and route traffic away, causing a reduction in capacity. The development team noticed that the /health endpoint occasionally returns HTTP 503 when the application is under heavy load, but the application can recover quickly. The team wants to avoid unnecessary instance replacements while ensuring availability. Which solution should the DevOps engineer implement?

A.Implement a custom health check using Lambda that ignores 503 responses
B.Decrease the unhealthy threshold to mark instances unhealthy faster
C.Increase the health check interval and increase the unhealthy threshold
D.Decrease the health check interval and decrease the healthy threshold
AnswerC

In a target group's health-check settings, increasing the interval spaces out probe requests, while increasing the unhealthy threshold demands more consecutive failures before an instance is marked unhealthy. Together, these settings build a longer smoothing window: sporadic errors such as brief 503s during a rolling deploy or dependency hiccup will not immediately cause a healthy instance to be replaced. The instance remains in service and in rotation until the failures are sustained over an extended period, which is exactly the desired behavior when the goal is to reduce replacement churn. The trade-off is that genuinely dead instances take longer to detect, but that is acceptable in many critical applications that favor stability over instantaneous failover.

Why this answer

Increasing the health check interval and increasing the unhealthy threshold makes the health check less sensitive to transient errors, such as occasional 503 responses under heavy load. This prevents unnecessary instance replacements while maintaining availability. Option A is incorrect because implementing a custom Lambda health check that ignores 503 responses would not leverage the built-in ALB health check tuning and adds complexity.

Option B is incorrect because decreasing the unhealthy threshold would make instances more easily marked unhealthy, worsening the problem. Option D is incorrect because decreasing the health check interval increases the frequency of checks, which might cause more frequent detections of transient errors, and decreasing the healthy threshold does not address the issue of avoiding unnecessary replacements.

708
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The DevOps team needs to receive notifications when stack creation fails. Which approach should be used to automate this monitoring?

A.Create a CloudWatch Events rule that matches CloudFormation 'CREATE_FAILED' stack events and targets an SNS topic.
B.Use AWS Config rules to detect failed stack creations.
C.Enable CloudTrail and create a metric filter for 'CreateStack' API calls.
D.Stream CloudFormation logs to CloudWatch Logs and create a metric filter for 'CREATE_FAILED'.
AnswerA

CloudFormation emits stack status change events to CloudWatch Events (Amazon EventBridge) whenever a stack transitions to a terminal state. A rule can filter for detail-type 'CloudFormation Stack Status Change' and the 'status-detail' of 'CREATE_FAILED', then route the event to an SNS topic. This is the native, event-driven mechanism for receiving notifications about stack creation failures, and it includes the stack name and status in the event payload.

Why this answer

CloudWatch Events (now Amazon EventBridge) can match CloudFormation stack events with the detail-type 'CloudFormation Stack Status Change' and filter for CREATE_FAILED, then target an SNS topic for notification. This is the native, event-driven approach for automating failure alerts without polling or log parsing. It provides near-real-time notification with minimal configuration.

Exam trap

DOP-C02 often tests the misconception that CloudTrail or CloudWatch Logs can directly filter CloudFormation failure statuses; candidates must recognize EventBridge as the native event source for stack status changes.

How to eliminate wrong answers

Option B is wrong because AWS Config rules evaluate resource compliance state, not CloudFormation stack event statuses, and cannot directly detect CREATE_FAILED events. Option C is wrong because CloudTrail logs API calls like CreateStack but does not emit a 'CREATE_FAILED' event; a metric filter on CreateStack would only count API invocations, not failures. Option D is wrong because CloudFormation does not stream stack events to CloudWatch Logs by default; you would need to poll DescribeStackEvents or use EventBridge, making this approach ineffective.

709
MCQmedium

An application running on Amazon EC2 instances in an Auto Scaling group is experiencing intermittent connectivity issues. The DevOps team suspects a security group configuration problem. Which approach should the team use to analyze security group traffic and identify denied requests?

A.Use AWS Config to review security group rules
B.Check AWS CloudTrail for security group modification events
C.Enable AWS Security Hub and review the security findings
D.Enable VPC Flow Logs and query Amazon Athena
AnswerD

VPC Flow Logs capture IP traffic metadata for ENIs in the VPC, recording fields like source address, destination address, port, protocol, and the action — ACCEPT or REJECT — for each connection. By publishing flow logs to Amazon S3 and using Amazon Athena with its SerDe, you can run SQL queries to filter on action = 'REJECT' and aggregate the denied connection attempts by source IP, port, or time. This directly reveals which connections are being blocked, making it the correct way to investigate denied traffic.

Why this answer

VPC Flow Logs capture IP traffic metadata (source, destination, port, protocol, action) for ENIs, subnets, or VPCs, and publishing them to CloudWatch Logs or S3 lets you query with Amazon Athena to identify REJECT entries caused by security group or NACL rules. This is the standard AWS approach for diagnosing denied traffic at the network layer.

Exam trap

The trap is confusing 'audit who changed the rules' (CloudTrail/Config) with 'see which packets were denied' (Flow Logs) — the question asks for traffic analysis, not configuration history.

How to eliminate wrong answers

Option A is wrong because AWS Config records configuration changes and evaluates compliance — it shows what the security group rules are, not which packets were denied by them. Option B is wrong because CloudTrail logs API calls (e.g., AuthorizeSecurityGroupIngress), which tells you who changed rules but not whether traffic was blocked. Option C is wrong because Security Hub aggregates findings from services like GuardDuty and Inspector; it does not provide per-packet flow analysis of denied requests.

710
MCQhard

A company runs a microservices application on Amazon EKS. The application's frontend service needs to communicate with the backend service. The DevOps team wants to implement service-to-service authentication using AWS IAM. Which method should the team use?

A.Configure the backend service as an Amazon RDS database with IAM database authentication.
B.Use AWS App Mesh with mTLS for authentication between services.
C.Create an IAM user with access keys and store them as Kubernetes secrets.
D.Use IAM roles for service accounts (IRSA) to associate an IAM role with each service's Kubernetes service account.
AnswerD

IRSA associates a Kubernetes ServiceAccount with an IAM role by annotating the ServiceAccount with the role ARN and configuring an OIDC trust policy. A projected service account token is exchanged via STS AssumeRoleWithWebIdentity for short-lived AWS credentials, and the AWS SDK automatically reads AWS_ROLE_ARN and AWS_WEB_IDENTITY_TOKEN_FILE. This gives each microservice a distinct IAM role with scoped permissions and no long-lived keys stored in the cluster.

Why this answer

IAM roles for service accounts (IRSA) allows each Kubernetes service account to assume an IAM role with fine-grained permissions, enabling secure service-to-service authentication without managing long-lived credentials. The frontend service can use its associated IAM role to sign AWS API requests (e.g., STS AssumeRole) to authenticate to the backend service, which validates the role via IAM policies. This approach integrates natively with EKS and follows AWS best practices for workload identity.

Exam trap

The trap here is that candidates may confuse mTLS (which provides encryption and certificate-based authentication) with IAM-based authentication, or assume that static IAM users with secrets are acceptable in Kubernetes, when IRSA is the recommended AWS-native approach for pod-level IAM integration.

How to eliminate wrong answers

Option A is wrong because Amazon RDS IAM database authentication is designed for database access, not for service-to-service authentication between microservices on EKS; it does not provide a mechanism for frontend-to-backend communication. Option B is wrong because AWS App Mesh with mTLS provides transport-layer encryption and mutual TLS authentication, but it does not use AWS IAM for authentication; it relies on X.509 certificates, not IAM roles or policies. Option C is wrong because creating an IAM user with access keys and storing them as Kubernetes secrets introduces long-lived static credentials, which violates security best practices (e.g., no automatic rotation, risk of exposure) and does not leverage IAM roles for dynamic, scoped access.

711
Multi-Selecteasy

A DevOps engineer is troubleshooting an AWS CodeDeploy deployment that failed. Which TWO resources should the engineer examine to identify the cause of the failure? (Choose two.)

Select 2 answers
A.EC2 instance system logs
B.CloudWatch Logs for CodeDeploy
C.S3 access logs
D.CloudTrail logs
E.CodeDeploy deployment group configuration
AnswersB, E

CloudWatch Logs for CodeDeploy is the correct source because it centralizes deployment events and error messages. When you configure a log group for the deployment group, lifecycle event execution details—such as BeforeInstall, AfterInstall, ApplicationStart, and the associated script output—are streamed into CloudWatch Logs. This lets you query and filter by deployment ID and instance ID, making it the fastest way to identify which lifecycle hook failed and why, rather than logging into individual instances.

Why this answer

AWS CodeDeploy emits detailed logs about deployment lifecycle events (e.g., BeforeInstall, ApplicationStop) to CloudWatch Logs. These logs contain error messages, script output, and status codes that directly indicate why a deployment step failed, such as a permission issue or a script syntax error. Examining CloudWatch Logs for CodeDeploy is the primary method to diagnose deployment failures.

Exam trap

The trap here is that candidates often confuse CloudTrail (API auditing) with CloudWatch Logs (application-level logging), or they mistakenly think EC2 system logs are relevant for application deployment failures, when in fact CodeDeploy-specific logs are the correct source.

712
Multi-Selecthard

Which THREE components are required to implement a global application that can withstand the failure of an entire AWS Region? (Select THREE.)

Select 3 answers
A.An Application Load Balancer in the primary Region.
B.Amazon CloudFront with multiple origins and origin failover.
C.Amazon DynamoDB Global Tables.
D.Amazon RDS with a single-AZ deployment.
E.Amazon Route 53 with health checks and failover routing policy.
AnswersB, C, E

Amazon CloudFront is a global content delivery network that terminates connections at edge locations and can be configured with multiple origins, including an origin group where the primary origin's failure triggers automatic failover to a secondary origin. This origin failover is initiated when the primary returns specific HTTP error codes or fails connection attempts, making it a key component for routing requests to a healthy Region. Additionally, edge caching shields the origin and improves performance, which is essential for a globally resilient application.

Why this answer

B is correct because Amazon CloudFront with multiple origins and origin failover automatically routes requests to a healthy origin in another Region when the primary origin becomes unavailable, providing a global entry point that survives a full Region failure. C is correct because DynamoDB Global Tables replicate data across Regions in a multi-active configuration, so the application can continue reading and writing to a replica table in a surviving Region. E is correct because Route 53 health checks detect an unhealthy Region endpoint and the failover routing policy then directs DNS queries to the standby Region's endpoint, enabling regional failover.

A is not required because an Application Load Balancer is Region-scoped and cannot by itself provide cross-Region resilience; it would only be part of a single-Region design. D is not required because a single-AZ RDS deployment has no cross-Region (or even cross-AZ) redundancy and would not survive a Region failure.

Exam trap

The trap is selecting Regional services (ALB, single-AZ RDS) as if they provide cross-Region resilience — candidates must recognize that only global services (Route 53, CloudFront, DynamoDB Global Tables) or multi-Region replicated services can survive a full Region failure.

713
Multi-Selectmedium

A company wants to implement a least-privilege security model for its IAM users. Which TWO practices should be applied?

Select 2 answers
A.Use IAM policy conditions to restrict access based on IP address or time of day.
B.Use only resource-based policies to manage permissions.
C.Attach the AdministratorAccess managed policy to all IAM users.
D.Use the AWS account root user for daily administrative tasks.
E.Grant permissions based on the specific actions and resources needed.
AnswersA, E

IAM policy conditions using the Condition element enable you to scope permissions by context keys such as aws:SourceIp or aws:CurrentTime. This allows you to enforce geofencing or business-hours-only access, reducing the blast radius of stolen credentials. For example, a Deny statement with a condition can block all access outside a corporate CIDR range.

Why this answer

IAM policy conditions allow you to restrict access based on attributes like IP address (using the `aws:SourceIp` condition key) or time of day (using `aws:CurrentTime`). This enforces least-privilege by limiting when and from where actions can be performed, reducing the attack surface without over-provisioning permissions.

Exam trap

The trap here is that candidates may think resource-based policies alone are sufficient for least-privilege (Option B), or that broad managed policies like AdministratorAccess can be justified for convenience, but the exam emphasizes that least-privilege requires granting only the specific actions and resources needed (Option E) combined with contextual restrictions (Option A).

714
Multi-Selecteasy

Which TWO tools can be used to manage configuration drift detection for AWS resources? (Choose two.)

Select 2 answers
A.AWS Config
B.AWS Systems Manager Inventory
C.AWS Trusted Advisor
D.AWS CloudTrail
E.AWS CloudFormation Drift Detection
AnswersA, E

AWS Config is the correct service for managing configuration drift because it continuously records and evaluates the configuration of AWS resources against desired baseline rules. When a resource's configuration changes from the recorded baseline, AWS Config flags it as noncompliant, providing a precise, rule-driven mechanism to detect drift. You can define custom or managed rules that represent your desired state, and AWS Config will produce a detailed compliance history and configuration timeline for every tracked resource, enabling automated remediation via Systems Manager Automation or Lambda.

Why this answer

AWS Config continuously monitors and records AWS resource configurations and can detect changes against desired baselines, enabling drift detection through rules and compliance checks. AWS CloudFormation Drift Detection directly compares the current state of a stack's resources with the expected template-defined state to identify configuration drift. Both tools provide native mechanisms to detect when resources deviate from their intended configuration.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Inventory (which collects instance-level software inventory) with configuration drift detection, or they mistakenly think AWS CloudTrail's API logging is sufficient to detect drift, when in fact drift detection requires comparing current state to a desired baseline, not just recording changes.

715
MCQmedium

A company uses AWS Lambda functions to process incoming events from Amazon S3. The operations team notices that some events are not being processed, and there is no error in the Lambda function logs. What is the most likely cause?

A.The Lambda function has reserved concurrency set to a low value, causing throttling.
B.The S3 event notification is configured to send to an SNS topic that is not subscribed to the Lambda function.
C.The S3 bucket policy does not allow the Lambda function to be invoked.
D.The Lambda function has a timeout that is too short.
AnswerA

Reserved concurrency caps the number of concurrent executions for the function. When all slots are busy, Lambda immediately rejects new invocations with a Throttle error. Because the code never starts, no START/END/REPORT lines are emitted, so CloudWatch Logs for the function remain empty. The S3 event notification will retry for a few hours, but each throttled attempt leaves no log.

Why this answer

When a Lambda function has reserved concurrency set to a low value, it limits the number of concurrent executions allowed for that function. If incoming S3 events exceed this limit, the Lambda service throttles the invocations, causing some events to be silently dropped without generating errors in the function logs because the function never actually runs. This matches the symptom of missing events with no error logs.

Exam trap

The trap here is that candidates often assume missing events are due to permission or timeout errors, but the absence of any error logs points to throttling, where the function is never invoked and thus no logs are generated.

How to eliminate wrong answers

Option B is wrong because if the SNS topic is not subscribed to the Lambda function, the event would never reach Lambda, but the question states the Lambda function logs show no errors, implying the function is invoked for some events; the issue is about events not being processed, not about delivery failure. Option C is wrong because if the S3 bucket policy did not allow Lambda invocation, the invocation would fail with an access denied error, which would be logged in CloudTrail or appear as an error in the Lambda logs, contradicting the 'no error' condition. Option D is wrong because a timeout that is too short would cause the function to fail mid-execution and generate a timeout error in the Lambda logs, not silently drop events without any log entries.

716
MCQmedium

A development team is using AWS CodeCommit to store source code and AWS CodePipeline to automate builds and deployments. The team wants to ensure that builds and tests are triggered only when code is pushed to specific branches, and that manual approval is required before deploying to production. Which CodePipeline configuration should the team implement?

A.Configure the source action to trigger on all branches and add a manual approval step before the build stage.
B.Configure the source action with a branch filter for main, and add a manual approval step before the build stage.
C.Use a branch filter on the build action to run only for the main branch, and add a manual approval step before the deploy stage.
D.Configure the source action with a branch filter for main, and add a manual approval step before the production deployment stage.
AnswerD

The source action's branch filter ensures the pipeline only starts when commits are pushed to main, preventing feature branch work from entering the pipeline. The manual approval step immediately preceding the production deployment stage provides a human gate before the final artifact is deployed, meeting the requirement to require approval for production releases while keeping lower environments automated. This arrangement minimizes unnecessary builds and accurately enforces change management only where needed.

Why this answer

CodePipeline source actions support branch filters that restrict which Git branches trigger the pipeline. By filtering on 'main', only pushes to that branch initiate the pipeline. Adding a manual approval step before the production deployment stage ensures that no code reaches production without explicit human sign-off, meeting both requirements precisely.

Exam trap

The trap here is that candidates may confuse where branch filters can be applied (source action only) and where manual approval should be placed (before the production deploy stage, not before build), leading them to select options that filter incorrectly or place approval at the wrong stage.

How to eliminate wrong answers

Option A is wrong because triggering on all branches would cause builds and tests for every push, including feature branches, which violates the requirement to trigger only on specific branches. Option B is wrong because adding the manual approval step before the build stage would require approval before any build runs, even for non-production branches, and does not align with the requirement for approval before deploying to production. Option C is wrong because branch filters cannot be applied to build actions in CodePipeline; branch filtering is a source action configuration, and placing the approval step before the deploy stage is correct, but the filter placement is invalid.

717
MCQeasy

A company uses AWS Elastic Beanstalk to deploy a Java web application. The DevOps team wants to ensure that configuration changes are tracked and can be rolled back if needed. Which Elastic Beanstalk feature should they use?

A.Use AWS CodeCommit to store configuration files and version them.
B.Use AWS CodePipeline with a manual approval stage to track changes.
C.Use AWS CloudFormation change sets to review changes before deployment.
D.Use Elastic Beanstalk saved configurations to capture environment settings and restore them if needed.
AnswerD

Elastic Beanstalk saved configurations provide a native way to snapshot an environment's option settings, environment variables, and solution stack into a re-usable YAML file. You can save a known-good configuration using the console or `eb config save`, and later restore it to the same or a different environment to roll back any undesired changes. Because saved configurations are purpose-built for this scenario, they give you an auditable, restorable record of environment settings without requiring code deployments or external tools.

Why this answer

Elastic Beanstalk saved configurations allow you to capture the environment's configuration settings (e.g., instance type, environment variables, platform version) as a JSON file stored in S3. This enables you to restore or recreate an environment with the exact same settings, providing a straightforward rollback mechanism for configuration changes without relying on external tools or pipelines.

Exam trap

The trap here is that candidates often confuse configuration management with CI/CD pipeline tools, assuming that CodePipeline or CodeCommit can handle environment-specific rollbacks, when in fact Elastic Beanstalk's native saved configurations are the simplest and most direct mechanism for tracking and reverting environment settings.

How to eliminate wrong answers

Option A is wrong because AWS CodeCommit is a Git-based source control service for storing code and configuration files, but it does not natively integrate with Elastic Beanstalk to track or roll back environment-specific settings; it would require manual scripting to apply versions. Option B is wrong because AWS CodePipeline is a CI/CD service that orchestrates build, test, and deploy stages; while it can include a manual approval stage, it is designed for application deployment pipelines, not for tracking or rolling back Elastic Beanstalk environment configuration changes. Option C is wrong because AWS CloudFormation change sets are used to review changes to CloudFormation stacks before execution, but Elastic Beanstalk environments are not managed as CloudFormation stacks by default (unless using the CloudFormation-backed environment option), and change sets do not directly apply to Elastic Beanstalk's native configuration management.

718
MCQmedium

A company uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance. The database password is stored in AWS Secrets Manager. The CloudFormation template needs to reference the secret value dynamically during stack creation. How should the template retrieve the secret?

A.Use a CloudFormation mapping to store the secret ARN.
B.Use a dynamic reference with '{{resolve:secretsmanager:secret-id:secret-string}}' in the template.
C.Hardcode the password in the template as a literal string.
D.Use a CloudFormation parameter with a default value referencing the secret ARN.
AnswerB

The dynamic reference syntax {{resolve:secretsmanager:secret-id:secret-string}} is correct because CloudFormation resolves it to the actual secret value at stack creation or update time. The full syntax allows you to specify a JSON key, version stage, or version ID, giving you precise control over which secret value is injected into a resource property. CloudFormation calls GetSecretValue on your behalf, so the secret never appears in the template, change sets, or the rendered stack template. To use this, ensure the CloudFormation execution role has the secretsmanager:GetSecretValue permission for the target secret.

Why this answer

CloudFormation dynamic references using the 'resolve:secretsmanager' syntax allow the template to retrieve secret values from AWS Secrets Manager at stack creation time. Option B correctly uses this dynamic reference to pull the password securely. Option A (mapping) cannot retrieve secrets dynamically; it only stores static values.

Option C (hardcoding) is insecure and not dynamic. Option D (parameter with default ARN) does not retrieve the secret value; it only passes the ARN string, not the actual secret.

719
Multi-Selecteasy

Which TWO actions can help ensure that an application running on EC2 instances can survive the loss of an entire Availability Zone?

Select 2 answers
A.Deploy all instances in a single Availability Zone for consistency
B.Use an Auto Scaling group with multiple Availability Zones
C.Deploy EC2 instances in at least two Availability Zones
D.Use a larger instance type to handle more load
E.Use CloudWatch alarms to monitor instance health
AnswersB, C

An Auto Scaling group configured across multiple Availability Zones automatically distributes instances among those AZs and enforces the desired capacity by replacing any instance that fails its health checks. This provides both high availability and operational automation: if an entire AZ becomes impaired, the ASG launches replacement instances in the remaining healthy AZs, and it also performs capacity rebalancing when AZs become imbalanced. Combined with an Elastic Load Balancer, this is the standard AWS pattern for building a fault-tolerant, self-healing application tier.

Why this answer

Deploying instances in multiple Availability Zones (AZs) ensures that if one AZ fails, instances in other AZs continue to run. Using an Auto Scaling group with multiple AZs automatically distributes instances across AZs and replaces failed instances, further enhancing resilience. Options B and C are both correct because they achieve multi-AZ deployment.

Option A is incorrect because a single AZ is a single point of failure. Option D is incorrect because instance type does not provide AZ resilience. Option E is incorrect because CloudWatch alarms can detect issues but do not distribute instances across AZs.

720
MCQhard

A team uses AWS CodePipeline with a source action from an Amazon S3 bucket. The pipeline triggers on changes to the S3 bucket, but sometimes runs twice for a single commit. What is the most likely cause?

A.CodePipeline has a deduplication setting that is disabled.
B.S3 event notifications for the same object may be delivered more than once.
C.The S3 bucket has versioning enabled.
D.The pipeline is also triggered by a CloudWatch Events rule.
AnswerB

Amazon S3 event notifications are designed with at-least-once delivery semantics, meaning the same s3:ObjectCreated:Put event can be delivered more than once, especially during retries or internal service-side replication. Each delivered notification is seen by CodePipeline as a new source change, so a single object upload can start duplicate pipeline executions. Versioning is irrelevant to this behavior because the duplicate is a delivery-level retry, not a new object version.

Why this answer

Amazon S3 event notifications are designed for at-least-once delivery, meaning the same event (e.g., an object PUT) can be delivered multiple times. When CodePipeline uses S3 as a source, it relies on these notifications to trigger the pipeline. If S3 sends duplicate notifications for the same object version, CodePipeline will start a new execution for each notification, causing the pipeline to run twice for a single commit.

Exam trap

The trap here is that candidates may assume S3 event notifications are exactly-once, leading them to incorrectly suspect versioning or a missing deduplication setting, rather than recognizing S3's inherent at-least-once delivery behavior.

How to eliminate wrong answers

Option A is wrong because CodePipeline does not have a configurable deduplication setting; deduplication is handled by the source event mechanism, not a pipeline-level toggle. Option C is wrong because S3 versioning, when enabled, creates distinct object versions for each PUT, and CodePipeline triggers on changes to the bucket (including new versions), but versioning alone does not cause duplicate notifications—it actually helps differentiate versions. Option D is wrong because if a CloudWatch Events rule were also triggering the pipeline, it would be an additional trigger source, but the question states the pipeline triggers on S3 bucket changes, and the most likely cause of duplicate runs is duplicate S3 event notifications, not an extra rule.

721
MCQhard

A company uses Amazon CloudWatch Logs to collect application logs from EC2 instances. The security team requires that log data be encrypted at rest using a customer-managed AWS KMS key. The logs are currently being delivered, but they are not encrypted. What is the most likely reason?

A.The IAM role for the EC2 instance does not have kms:Encrypt permission
B.The CloudWatch Logs agent is not configured to encrypt logs
C.The KMS key is disabled
D.The KMS key policy does not allow the CloudWatch Logs service principal
AnswerD

This is the correct cause. CloudWatch Logs acts under the service principal logs.amazonaws.com when performing server-side encryption with an AWS KMS customer managed key. If the KMS key policy does not include a statement granting this principal the kms:Encrypt and kms:DescribeKey actions (and denies are absent), the service cannot encrypt the log events. In such a case, log delivery may continue to succeed but the data is stored without the intended encryption, exactly matching the symptom described.

Why this answer

For CloudWatch Logs to encrypt log data at rest with a customer-managed KMS key, the key policy must grant the CloudWatch Logs service principal the necessary permissions (kms:Encrypt, kms:Decrypt, etc.). If the key policy does not include this, CloudWatch Logs can still ingest the logs but cannot encrypt them, resulting in unencrypted logs. Option A is incorrect: the IAM role for the EC2 instance does not need kms:Encrypt permissions for server-side encryption; that is handled by the CloudWatch Logs service using the key policy.

Option B is incorrect because encryption is configured at the log group level, not in the agent. Option C would cause delivery failures, not just lack of encryption.

722
MCQmedium

A company runs a stateful application on EC2 instances in an Auto Scaling group. The application stores state on local instance storage. During a scaling event, users lose session data. How can the company make the application resilient without modifying the application code?

A.Reduce the Auto Scaling group cooldown period.
B.Enable sticky sessions on the Application Load Balancer.
C.Increase the instance size to reduce scaling events.
D.Use Elastic Block Store (EBS) volumes instead of instance store.
AnswerD

EBS volumes are network-attached block storage that exist independently of the EC2 instance lifecycle, so when an instance terminates the volume can be detached and reattached to a replacement instance. Data written to an EBS volume survives Auto Scaling scale-in as long as the volume's DeleteOnTermination attribute is set to false and the application writes to that mount point. This approach makes application state durable across instance replacements without requiring a distributed storage architecture or application code changes, because the application still sees a standard block device.

Why this answer

Using EBS volumes instead of instance store provides persistent storage that survives instance termination. By attaching an EBS volume to the EC2 instances and configuring the application to store state on that volume (e.g., through the same file path), the data is preserved even when instances are scaled in. This does not require modifying application code, only infrastructure configuration.

Option A is incorrect because reducing the cooldown period does not prevent data loss; it only affects scaling speed. Option B is incorrect because sticky sessions route users to the same instance but do not preserve session data when that instance is terminated during scale-in. Option C is incorrect because larger instances reduce the frequency of scaling events but data loss still occurs when instances are terminated.

Exam trap

The trap is assuming that sticky sessions (session affinity) provide resilience by routing users to the same instance. However, sticky sessions do not prevent data loss when that instance is terminated during scale-in events.

723
MCQhard

A DevOps engineer manages a multi-account AWS Organization. The security team requires that all CloudWatch Logs log groups in every account retain data for at least 400 days and that no developer can shorten that retention. Which combination of actions should the engineer take?

A.Enable CloudWatch Logs data protection and configure a log group policy that blocks retention changes.
B.Set retention on each log group to 400 days using a script, and rely on IAM policies in each account to deny logs:PutRetentionPolicy.
C.Create an AWS Lambda function in each account that runs hourly, detects retention changes, and restores 400 days, and subscribe the function to an Amazon SNS topic.
D.Apply a service control policy in AWS Organizations that denies logs:PutRetentionPolicy and logs:DeleteRetentionPolicy unless the request comes from a designated governance role, and enforce a baseline retention with AWS Config or a CloudFormation StackSet.
AnswerD

SCPs set the maximum permissions for member accounts, so denying retention changes except for a governance role prevents developers from shortening retention. Combined with a StackSet or Config rule that establishes the 400-day baseline, this gives centralized, drift-resistant enforcement across all accounts, including future ones, which matches the requirement.

Why this answer

Service control policies provide preventive guardrails across an AWS Organization, so denying retention policy changes except for a governance role stops developers from shortening retention. A StackSet or AWS Config rule then enforces the 400-day baseline consistently. Reactive scripts, data protection, and per-account IAM policies do not deliver centralized prevention.

Exam trap

The trap here is confusing CloudWatch Logs data protection policies, which mask sensitive data, with retention controls that govern how long log events are stored.

724
MCQhard

A team uses Terraform to manage AWS infrastructure. After a recent update, a state file shows that a security group rule was created, but the rule does not exist in AWS. Running 'terraform plan' shows no changes. What is the most likely cause?

A.The security group rule was imported into state but not defined in configuration.
B.The 'terraform refresh' command was not run before the plan.
C.There is a conflict between multiple Terraform workspaces.
D.The security group rule was added manually via the AWS console and is not managed by Terraform, causing state to be out of sync.
AnswerB

When a resource is deleted outside of Terraform, the state still contains the old resource until a refresh reconciles it with the live AWS inventory. Running terraform plan without a preceding terraform refresh — or with refresh explicitly disabled — lets Terraform compare configuration only against stale state, so it concludes the rule still exists and reports no changes. A manual deletion is exactly the kind of drift that refresh is designed to detect; skipping it hides the missing security group rule from the planner.

Why this answer

If a security group rule was deleted manually from AWS (e.g., via console or CLI), the state file still contains the resource. Without running 'terraform refresh', Terraform does not detect the deletion and assumes the state is accurate. Thus, 'terraform plan' shows no changes because it compares the current state (which still includes the rule) with the configuration (which likely does define it, otherwise plan would show a destroy).

If 'terraform refresh' had been run, the state would be updated to remove the rule, and then plan would show a creation. Option A is incorrect because if the rule were imported into state but not defined in configuration, plan would show a destroy. Option C is incorrect because workspace conflicts typically cause state isolation issues, not missing resources.

Option D is incorrect because adding a rule manually would create it, not cause it to be missing; the scenario states the rule does not exist in AWS.

725
MCQeasy

A company uses AWS OpsWorks for configuration management. They want to ensure that whenever a new instance is added to a layer, it automatically installs the latest security patches and joins a central logging system. What is the most efficient way to achieve this?

A.Schedule a cron job on each instance to check and apply patches daily.
B.Use Chef recipes in a custom OpsWorks layer's Setup lifecycle event.
C.Configure user data scripts in the launch configuration.
D.SSH into each instance and run the commands manually.
AnswerB

The Setup lifecycle event runs recipes when an instance is added to the layer, so security patches and logging-agent configuration apply automatically. This satisfies the requirement for automatic onboarding without manual intervention on each new instance.

Why this answer

AWS OpsWorks uses Chef recipes to automate configuration management. The Setup lifecycle event runs on every instance when it is added to a layer, making it the correct place to install security patches and configure the logging agent. This ensures consistency and automation without manual intervention, and it is the native OpsWorks mechanism for bootstrapping instances.

Exam trap

DOP-C02 often tests the difference between OpsWorks lifecycle events and EC2 user data — candidates may pick user data because it is familiar, but OpsWorks layers require Chef recipes in lifecycle events, not user data scripts.

How to eliminate wrong answers

Option A is wrong because a cron job is a manual, per-instance workaround that does not integrate with OpsWorks lifecycle management and may run at inconsistent times. Option C is wrong because user data scripts are for EC2 launch configurations, not OpsWorks layers; OpsWorks manages instances through Chef, and user data would bypass the layer's configuration management. Option D is wrong because manual SSH is not automated, not scalable, and violates the principle of infrastructure as code.

726
MCQmedium

A company uses AWS CodePipeline for CI/CD. During a production deployment, the pipeline fails at the 'Deploy' stage with an error: 'The deployment failed because the deployment group does not have enough capacity to handle the deployment.' The engineer checks the CodeDeploy deployment group and sees that it is configured with a minimum healthy hosts of 100% and a deployment configuration of 'CodeDeployDefault.OneAtATime'. What is the MOST likely cause?

A.The deployment configuration 'OneAtATime' is not compatible with the deployment group.
B.The target group health check is misconfigured, causing all instances to be unhealthy.
C.The CodeDeploy agent on the instances is not running.
D.The deployment group has only one instance, and the minimum healthy hosts setting prevents the deployment.
AnswerD

CodeDeploy enforces a minimum number of healthy hosts as a safety condition, and when the deployment group has exactly one instance, any positive minimum healthy host count makes an in-place deployment impossible. With a setting of 100% or 1, taking that only instance out of service to deploy to it would reduce the healthy host count to 0, violating the constraint and aborting the deployment at the very start. The error message specifically mentions that the deployment was aborted because the minimum number of healthy hosts was not met.

Why this answer

With a minimum healthy hosts of 100% and a OneAtATime deployment configuration, CodeDeploy must keep all instances healthy during the deployment. If the deployment group contains only one instance, taking it out of service to deploy would drop healthy hosts below 100%, making the deployment impossible. This is the most likely cause of the capacity error.

Exam trap

DOP-C02 often tests the interaction between deployment configuration and minimum healthy hosts — candidates focus on the deployment config alone and miss that 100% minimum healthy hosts with a single instance creates an impossible constraint.

How to eliminate wrong answers

Option A is wrong because OneAtATime is a valid deployment configuration and is compatible with any deployment group; the issue is the combination with 100% minimum healthy hosts and a single instance. Option B is wrong because a misconfigured health check would cause instances to be unhealthy, but the error specifically mentions insufficient capacity, not unhealthy targets. Option C is wrong because a stopped CodeDeploy agent would produce a different error about the agent not being available, not a capacity error.

727
MCQeasy

A DevOps engineer needs to ensure that all API calls made to AWS services are logged for auditing purposes. Which AWS service should be enabled?

A.AWS CloudTrail
B.AWS Config
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerA

AWS CloudTrail is the purpose-built service that records every API call made in your AWS account as an event, including the identity of the caller, the source IP address, the requested action, and the response returned. It supports management events, data events, and CloudTrail Insights events, and it can deliver these immutable audit logs to an S3 bucket or CloudWatch Logs for retention and analysis. As the only option that natively records API activity, CloudTrail is the correct choice for auditing all API calls.

Why this answer

AWS CloudTrail (option A) is the correct service because it records API calls made to AWS services for auditing, governance, and compliance. Option B (AWS Config) is used to evaluate resource configurations against desired policies, not to record API calls. Option C (VPC Flow Logs) captures network traffic information at the VPC level.

Option D (Amazon CloudWatch Logs) is a service for storing and monitoring log files from various sources, but does not itself record API calls.

728
MCQmedium

A development team uses AWS CodeBuild to compile a Java application. The build takes 15 minutes on average, but recently it started taking over 30 minutes. The buildspec.yml file is unchanged. What is the most likely cause?

A.The cache for the build project was cleared, forcing a full dependency download.
B.The build environment was changed from a Linux to a Windows environment.
C.The build project's compute type was downgraded to a smaller instance.
D.The buildspec.yml file was updated to include more build commands.
AnswerA

Clearing a CodeBuild project's cache removes previously downloaded dependency artifacts, such as those stored in the local Maven repository (~/.m2) or in an S3 cache bucket. On the next build, Maven must reach out to remote repositories to re-download every JAR it needs, adding significant network and I/O time on top of the compile itself. Because the buildspec commands are unchanged, the only impact is that dependency resolution is no longer incremental, directly explaining the increased build duration.

Why this answer

The most likely cause is that the build project's cache was cleared, forcing a full dependency download. CodeBuild can cache dependencies (e.g., Maven local repository) to speed up builds. If the cache is invalidated or cleared, the build must re-download all dependencies from the internet, significantly increasing build time from 15 minutes to over 30 minutes, even though the buildspec.yml is unchanged.

Exam trap

The trap here is that candidates may assume a compute type downgrade is the cause, but the sudden change in build time without any configuration change points to cache invalidation, not a gradual performance degradation.

How to eliminate wrong answers

Option B is wrong because changing from a Linux to a Windows environment would require a different buildspec.yml or runtime configuration, and the question states the buildspec.yml is unchanged. Option C is wrong because downgrading the compute type (e.g., from BUILD_GENERAL1_LARGE to BUILD_GENERAL1_SMALL) would cause a consistent increase in build time for all builds, not a sudden change after a period of normal 15-minute builds. Option D is wrong because the question explicitly states the buildspec.yml file is unchanged, so no additional build commands were added.

729
MCQhard

A company has a critical application running on Amazon EC2 instances behind an Application Load Balancer. The application is experiencing intermittent latency spikes. The DevOps team has enabled detailed monitoring on the EC2 instances and is using CloudWatch metrics. They notice that CPU utilization and network traffic are normal during the spikes. Which additional diagnostic step should the team take to identify the root cause?

A.Instrument the application with AWS X-Ray to trace requests and identify bottlenecks.
B.Use CloudWatch Container Insights to monitor the performance of the EC2 instances.
C.Enable CloudWatch Synthetics to create canaries that monitor the application endpoints.
D.Run an AWS Trusted Advisor check to identify performance-related recommendations.
AnswerA

Instrumenting the application with AWS X-Ray creates an end-to-end trace for each user request as it traverses your application, generating a service map and detailed segments/subsegments for each downstream call (e.g., web APIs, SQL queries, external HTTP calls). This lets you pinpoint which specific operation contributes the most latency on EC2, including CPU-bound code vs. I/O wait, and correlate trace data with host metrics. Unlike other options, X-Ray provides the distributed tracing needed to identify and reason about internal request bottlenecks in a complex application.

Why this answer

AWS X-Ray provides end-to-end tracing of requests as they travel through the application. Since CPU and network metrics appear normal, the intermittent latency is likely caused by application-level bottlenecks such as slow database queries, external API calls, or inefficient code paths. X-Ray can trace each request end-to-end and identify the specific service or component introducing delay.

Container Insights (B) is designed for monitoring containerized workloads (Amazon ECS/EKS), not EC2 instances directly. CloudWatch Synthetics (C) creates canaries that monitor external endpoint availability and response times, but it does not trace internal request paths. AWS Trusted Advisor (D) offers general best-practice recommendations but is not a diagnostic tool for real-time latency issues.

730
MCQhard

An organization uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The engineer reviews the deployment logs and finds that the AppSpec file is correctly formatted and the scripts run successfully on some instances. What is the MOST likely cause?

A.The CodeDeploy agent is not installed on some instances.
B.The target group is not configured to route traffic to the instances.
C.The health check grace period for the Auto Scaling group is too short.
D.The IAM role assigned to the EC2 instances does not have sufficient permissions.
AnswerC

The health check grace period for the Auto Scaling group is too short. When an Auto Scaling group launches a new instance, it waits for the health check grace period before evaluating the instance's EC2 health status. If this period expires before CodeDeploy has installed and started the application, the ASG may consider the instance unhealthy and terminate it, interrupting the deployment. This causes the deployment to fail on those instances, even though the CodeDeploy agent and IAM permissions are fine. The correct fix is to increase the ASG health check grace period to cover the full deployment duration, including bootstrapping and application startup.

Why this answer

The error indicates that instances are failing the deployment health check after the AppSpec scripts run successfully. When the health check grace period for the Auto Scaling group is too short, instances may be marked unhealthy before the application has fully started and passed the target group health checks, causing CodeDeploy to consider them failed. This is the most likely cause because the scripts succeed on some instances but the overall deployment fails due to insufficient healthy instances.

Exam trap

The trap here is that candidates often confuse deployment script success with overall deployment health, not realizing that CodeDeploy relies on the target group's health checks (configured via the Auto Scaling group's health check grace period) to determine if an instance is healthy after deployment.

How to eliminate wrong answers

Option A is wrong because if the CodeDeploy agent were not installed on some instances, the deployment logs would show agent connection errors or missing agent events, not successful script execution on those instances. Option B is wrong because the target group not routing traffic would cause health check failures, but the error message specifically mentions 'too few healthy instances' which is a health check issue, not a routing configuration issue; CodeDeploy relies on the target group health checks to determine instance health. Option D is wrong because insufficient IAM permissions would cause the scripts to fail with access denied errors or the agent to fail to download the revision, not succeed on some instances and fail overall due to health checks.

731
MCQeasy

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used?

A.AWS Shield Advanced
B.Amazon GuardDuty
C.AWS Network Firewall
D.AWS WAF
AnswerD

AWS WAF is a web application firewall that integrates directly with an Application Load Balancer to inspect and filter HTTP(S) requests before they are forwarded to your EC2 instances. It provides managed rules specifically designed to detect and block common web exploits, including SQL injection and cross-site scripting, and you can define custom rules to handle unique business logic. This is the appropriate service to stop malicious requests from ever reaching the web server, directly addressing the requirement for protection against web exploits.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. It allows you to create rules that filter and monitor HTTP(S) requests based on conditions such as IP addresses, HTTP headers, URI strings, and SQL injection or cross-site scripting patterns. By integrating with an Application Load Balancer, AWS WAF can inspect incoming traffic and block malicious requests before they reach the EC2 instances.

Exam trap

The trap here is that candidates often confuse AWS WAF with AWS Shield or GuardDuty, mistakenly thinking that DDoS protection or general threat detection covers application-layer attacks like SQL injection and XSS, when in fact only a web application firewall (WAF) can inspect and filter HTTP request payloads at Layer 7.

How to eliminate wrong answers

Option A is wrong because AWS Shield Advanced provides protection against Distributed Denial of Service (DDoS) attacks, not against application-layer exploits like SQL injection or XSS. Option B is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior using VPC Flow Logs, DNS logs, and CloudTrail events, but it does not inspect or filter HTTP request payloads for web exploits. Option C is wrong because AWS Network Firewall is a managed firewall service that filters traffic at the network and transport layers (Layer 3/4) using stateful inspection and intrusion prevention, but it does not provide application-layer (Layer 7) inspection for SQL injection or XSS patterns.

732
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team notices that stack updates sometimes fail because of resource conflicts. The team wants to prevent concurrent updates to the same stack. What should they do?

A.Use an AWS Organizations service control policy to restrict updates
B.Create an IAM policy that denies cloudformation:UpdateStack if a stack update is in progress
C.No action needed; CloudFormation already prevents concurrent stack updates
D.Enable CloudTrail to log all stack update attempts and manually review
AnswerC

No action is required because the CloudFormation service applies a mutual-exclusion lock to each stack: from the moment an UpdateStack call is accepted until the update, rollback, or clean-up finishes, any subsequent UpdateStack, DeleteStack, or ExecuteChangeSet operation on the same stack is rejected with a ValidationError such as 'Stack is currently in an update state'. This built-in serialization prevents concurrent modifications and preserves stack consistency without any downstream code, IAM policy, or auxiliary lock. Therefore, the design is already safe, and adding extra mechanisms is redundant.

Why this answer

AWS CloudFormation inherently prevents concurrent updates to the same stack. When an update operation is initiated, CloudFormation places a lock on the stack, rejecting any subsequent update requests until the current operation completes. This behavior is built into the service and requires no additional configuration, making option C correct.

Exam trap

The trap here is that candidates overthink the problem and assume they need to implement custom concurrency controls (like IAM policies or SCPs), when in fact CloudFormation already handles this natively, making the 'no action needed' answer the correct one.

How to eliminate wrong answers

Option A is wrong because AWS Organizations service control policies (SCPs) are used to centrally control permissions across accounts, not to prevent concurrent stack updates within a single account; they cannot enforce operation-level concurrency controls. Option B is wrong because IAM policies evaluate permissions at the time of the API call, but CloudFormation already rejects concurrent updates at the service level, so an IAM policy denying UpdateStack during an in-progress update is redundant and would require custom logic (e.g., using condition keys like cloudformation:StackStatus) that is not natively supported for this purpose. Option D is wrong because CloudTrail logs API calls for auditing but does not prevent concurrent updates; manual review after the fact does not address the real-time conflict.

733
MCQeasy

A DevOps team uses the above CloudFormation template to create an S3 bucket. What does the bucket policy accomplish?

A.It denies all S3 operations on the bucket unless the request uses HTTPS.
B.It denies all read access to the bucket for anonymous users.
C.It prevents anyone from deleting objects in the bucket.
D.It allows only HTTPS requests to the bucket and denies all HTTP requests.
AnswerA

This statement uses an explicit Deny on all s3:* actions, conditioned on aws:SecureTransport being false. Any request made to the bucket over plain HTTP is therefore blocked regardless of the principal or whether an Allow policy exists; HTTPS requests are not affected by this Deny. The effect is to require TLS for every S3 API operation on the bucket.

Why this answer

The bucket policy uses a Deny effect with a condition that the request must use HTTPS (SecureTransport: false). This denies all S3 operations on the bucket unless the request is sent over HTTPS. Option B is incorrect because the policy does not target anonymous users specifically; it applies to all principals.

Option C is incorrect because the policy denies all actions, not just delete. Option D is incorrect because it allows HTTP requests when the condition is not met, but the Deny overrides; the policy explicitly denies non-HTTPS requests.

734
MCQeasy

A DevOps engineer needs to centrally collect and analyze logs from multiple AWS accounts and on-premises servers. Which AWS service should be used to aggregate logs in a single dashboard?

A.Amazon Athena.
B.Amazon S3.
C.Amazon CloudWatch Logs.
D.Amazon Kinesis Data Firehose.
AnswerC

Amazon CloudWatch Logs is the correct choice because it can centrally aggregate logs from multiple AWS accounts, Regions, and on-premises sources via the CloudWatch Logs agent, Kinesis Data Firehose, or subscription filters. It provides native log analytics with Logs Insights, metric filters to create custom metrics, and CloudWatch Dashboards to visualize log-derived data in real time. This directly satisfies the need for centralized collection, analysis, and dashboard visualization without requiring additional services.

Why this answer

Amazon CloudWatch Logs is the correct service for centrally collecting, storing, and analyzing logs from multiple AWS accounts and on-premises servers, with the ability to visualize them in a single dashboard via CloudWatch Logs Insights and CloudWatch dashboards. It supports cross-account log aggregation through subscription filters and centralized log groups.

Exam trap

The trap is that candidates confuse log storage (S3), log query (Athena), and log streaming (Firehose) with the service that actually provides centralized log collection and dashboards — CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because Amazon Athena is a query service for data in S3 — it can analyze logs but does not natively collect or aggregate them in real time, nor does it provide a dashboard. Option B is wrong because Amazon S3 is object storage; while logs can be archived there, S3 alone does not provide analysis or dashboards. Option D is wrong because Kinesis Data Firehose is a delivery service that streams data to destinations like S3, Redshift, or Splunk — it does not itself provide a dashboard or log analysis.

735
MCQeasy

A DevOps engineer notices that an Amazon RDS for MySQL instance has failed over to a standby replica. The engineer needs to identify the root cause by examining metrics. Which AWS service should the engineer use to view the database load, replication lag, and failover events?

A.AWS CloudTrail
B.Amazon CloudWatch
C.VPC Flow Logs
D.AWS Trusted Advisor
AnswerB

Amazon CloudWatch is the native monitoring service for Amazon RDS, automatically collecting and storing database metrics such as CPU utilization, free memory, read/write throughput, and ReplicaLag for MySQL read replicas. These metrics are published as time-ordered data points and can be visualized on dashboards, trigger alarms via Amazon CloudWatch Alarms, and feed AWS Auto Scaling. With Enhanced Monitoring, it can also expose OS-level metrics, making it the correct source for diagnosing load and replication issues.

Why this answer

Amazon CloudWatch provides RDS metrics including DatabaseConnections, ReplicaLag, ReadIOPS, and failover-related events. CloudWatch alarms and the RDS console's monitoring graphs surface failover events and replication lag, making it the correct service for diagnosing an RDS failover root cause.

Exam trap

DOP-C02 often tests the distinction between CloudWatch (metrics and performance) and CloudTrail (API audit logs) — candidates pick CloudTrail for performance diagnosis when metrics are needed.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API calls and management events (who did what), not performance metrics like database load or replication lag. Option C is wrong because VPC Flow Logs capture IP traffic metadata for network troubleshooting, not database-level metrics. Option D is wrong because AWS Trusted Advisor provides best-practice checks and recommendations, not real-time database performance metrics.

736
MCQmedium

A DevOps engineer needs to audit changes to IAM policies over the past 90 days. The engineer wants to see who made the change, what the change was, and when it occurred. Which AWS tool should be used?

A.AWS Config
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.IAM Access Analyzer
AnswerC

AWS CloudTrail is the correct service for auditing IAM policy changes because it records every API call as an event, including the identity of the requesting principal, the timestamp, source IP, request parameters, and response elements. You can view these events directly in the CloudTrail event history or create a trail for long-term storage in S3 and analysis via CloudWatch Logs or Athena, making it the authoritative audit source.

Why this answer

AWS CloudTrail is the correct choice because it records all API calls made to the AWS environment, including IAM policy changes, and stores them as events with details such as the identity of the caller (IAM user or role), the time of the request, and the request parameters. By querying CloudTrail logs over the past 90 days, the DevOps engineer can audit who made the change, what the change was (e.g., the specific IAM policy document modification), and when it occurred.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to track configuration changes with CloudTrail's ability to provide a detailed audit trail of API calls, leading them to choose AWS Config for auditing who made a change, when in fact Config only shows the state change, not the identity of the actor.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration management and compliance service that tracks resource configuration changes and evaluates them against rules, but it does not record who made the change or the exact API call details; it focuses on the state of resources, not the audit trail of actions. Option B is wrong because Amazon CloudWatch Logs is used to monitor, store, and access log files from AWS resources and applications, but it does not natively capture IAM API calls; it would require custom logging or integration with CloudTrail to obtain such data. Option D is wrong because IAM Access Analyzer is designed to identify resources shared with external entities and analyze access policies for unintended public or cross-account access, not to provide a historical audit trail of who made changes to IAM policies.

737
MCQmedium

A company uses AWS CodePipeline with a source stage from Amazon S3. The pipeline triggers on changes to the S3 bucket. However, the pipeline does not trigger when a new object is uploaded. What is the MOST likely cause?

A.The S3 bucket policy denies the CodePipeline service role.
B.The S3 bucket is in a different AWS Region than the pipeline.
C.The S3 bucket does not have versioning enabled.
D.The S3 bucket does not have an event notification configured to invoke the pipeline.
AnswerD

CodePipeline automatically starts an S3 source only when the bucket is configured with an event notification that sends object-created events to the pipeline's trigger. Typically, this is implemented via an Amazon S3 event notification targeting an Amazon EventBridge rule, or via a CloudWatch Events rule that filters on the bucket's PUT operations. Without that configuration, uploading a new file to the bucket does not cause the pipeline to initiate, leaving it in a 'Succeeded' or previous state until a manual release is triggered. This exactly matches the reported symptom.

Why this answer

CodePipeline does not automatically monitor S3 buckets for new objects. To trigger a pipeline on S3 events, you must explicitly configure an S3 event notification (e.g., s3:ObjectCreated:Put) that sends the event to CloudWatch Events or directly to CodePipeline via Amazon EventBridge. Without this notification, the pipeline will not start when a new object is uploaded.

Exam trap

The trap here is that candidates often assume CodePipeline automatically polls S3 for changes (like GitHub webhooks), but in reality, S3 requires an explicit event notification configuration to trigger the pipeline, and the exam tests this distinction between polling-based and event-driven triggers.

How to eliminate wrong answers

Option A is wrong because the S3 bucket policy denying the CodePipeline service role would cause permission errors (e.g., access denied) when the pipeline tries to fetch source artifacts, not a failure to trigger. Option B is wrong because CodePipeline supports cross-region actions; an S3 source in a different region is allowed as long as the pipeline has a cross-region action configured. Option C is wrong because S3 versioning is not required for pipeline triggers; it is only needed if you want to use specific object versions as source artifacts, but the trigger itself works without versioning.

738
MCQhard

A company uses an Application Load Balancer (ALB) in front of a fleet of EC2 instances. The security team reports that a specific client IP address is sending malicious requests and must be blocked immediately. The ALB's security group only allows HTTP/HTTPS from 0.0.0.0/0. What is the FASTEST way to block traffic from this IP address without affecting other traffic?

A.Create an AWS WAF web ACL with an IP set deny rule and associate it with the ALB.
B.Modify the ALB listener rules to drop requests from the client IP.
C.Update the ALB security group to add a deny rule for the client IP address.
D.Update the VPC route table to drop packets from the client IP.
AnswerA

AWS WAF provides application-layer (Layer 7) inspection and can be associated directly with an ALB. By creating a web ACL that references an IP set containing the offending client IP and setting the default or custom rule action to 'Block', requests from that IP are denied before they reach the ALB. This is the purpose-built, scalable mechanism for IP-based blocking in front of an ALB, and it can be implemented without altering routing or security group configurations.

Why this answer

AWS WAF with an IP set deny rule associated to the ALB is the fastest and most surgical way to block a specific client IP. WAF evaluates requests at the ALB before they reach targets, and an IP match condition with a block action takes effect within seconds without touching security groups or routing. This blocks only the offending IP while all other traffic continues normally.

Exam trap

DOP-C02 often tests the allow-only nature of security groups and the lack of source-IP deny in ALB listener rules — the trap is assuming security groups or listener rules can block a single IP like a firewall ACL.

How to eliminate wrong answers

Option B is wrong because ALB listener rules support only forward, redirect, and fixed-response actions — there is no native 'drop by source IP' rule, and fixed-response would still return a response rather than silently blocking. Option C is wrong because security groups are allow-only; you cannot add a deny rule, and removing 0.0.0.0/0 would break all traffic. Option D is wrong because VPC route tables route by destination CIDR, not source IP, and cannot selectively drop a single client address.

739
MCQhard

A team uses AWS CloudFormation to manage a multi-tier application. They update the stack and receive this error: 'UPDATE_ROLLBACK_FAILED'. The stack is in a state where some resources were updated, then rollback failed. What is the best course of action?

A.Use the 'ContinueUpdateRollback' API or AWS Management Console to resume rollback, and fix any underlying issues.
B.Ignore the error and use the stack as-is.
C.Attempt to continue the update again.
D.Delete the stack and recreate it.
AnswerA

When an update fails and the automatic rollback is also unsuccessful, CloudFormation leaves the stack in the UPDATE_ROLLBACK_FAILED state. The ContinueUpdateRollback API or console action is the designed recovery mechanism; it retries the rollback of resources that failed, allowing you to skip resources with known issues and restore the stack to a usable state before fixing underlying problems and reattempting the update.

Why this answer

The 'UPDATE_ROLLBACK_FAILED' state indicates that CloudFormation attempted to roll back a failed stack update but encountered an error during the rollback process. The correct action is to use the 'ContinueUpdateRollback' API (or the AWS Management Console equivalent) to resume the rollback after fixing the underlying issue that caused the rollback to fail, such as a resource dependency or permission problem. This allows CloudFormation to complete the rollback and return the stack to a known stable state, rather than leaving it in an inconsistent or partially updated condition.

Exam trap

The trap here is that candidates may think they can simply retry the update (Option C) or ignore the error (Option B), not realizing that CloudFormation's state machine requires a specific recovery action—'ContinueUpdateRollback'—to exit the 'UPDATE_ROLLBACK_FAILED' state before any further stack operations are allowed.

How to eliminate wrong answers

Option B is wrong because ignoring the error leaves the stack in an inconsistent 'UPDATE_ROLLBACK_FAILED' state, where some resources may have been updated and others not, leading to potential application instability or security risks. Option C is wrong because attempting to continue the update again is not possible; CloudFormation does not allow a new update operation on a stack in the 'UPDATE_ROLLBACK_FAILED' state—you must first resolve the rollback failure. Option D is wrong because deleting the stack and recreating it is an overly destructive approach that loses the existing stack's state and resources, and it does not address the root cause of the rollback failure; the 'ContinueUpdateRollback' API is the designed recovery mechanism.

740
Multi-Selectmedium

Which TWO are valid use cases for using AWS CodeArtifact in a CI/CD pipeline? (Choose two.)

Select 2 answers
A.Caching dependencies from public repositories to improve build speed and reliability.
B.Storing Docker images that are used by ECS tasks.
C.Hosting npm packages that are consumed by CodeBuild during the build phase.
D.Storing source code archives for use in deployment stages.
E.Hosting static website assets for deployment to S3.
AnswersA, C

CodeArtifact acts as an intermediary upstream repository, caching packages from public registries such as npmjs, Maven Central, or PyPI. When CodeBuild first requests a dependency, CodeArtifact fetches it from the public source and stores a copy in your domain; subsequent builds retrieve the cached copy directly from CodeArtifact. This reduces external network round trips, minimizes build-time latency, and protects against upstream outages or sudden changes in public repositories.

Why this answer

CodeArtifact can act as a proxy cache for public repositories like npm, PyPI, Maven, and NuGet. By caching dependencies locally, it reduces reliance on external sources, improves build speed by avoiding repeated downloads, and increases reliability by insulating the pipeline from outages or rate limits of public registries.

Exam trap

The trap here is that candidates confuse CodeArtifact with a general-purpose artifact store, but it is strictly a package manager repository for language-specific packages (npm, Maven, PyPI, NuGet), not for Docker images, source code, or static assets.

741
MCQeasy

A company wants to automate the recovery of an Amazon RDS DB instance in a different region if the primary region becomes unavailable. Which service should they use?

A.RDS Multi-AZ deployment.
B.RDS cross-region automated backups.
C.RDS read replicas.
D.AWS CloudFormation custom resource.
AnswerB

RDS cross-region automated backups continuously copy automated backups and applicable transaction logs from the source DB instance to a destination AWS Region without manual intervention. This allows the database to be restored to a specific point in time, or to the latest restorable time, in the secondary region, making recovery from a regional outage repeatable and largely automated. Because the backups are managed by RDS and restored through the standard restore workflow, this option directly supports automated cross-region recovery.

Why this answer

RDS cross-region automated backups can be restored to a different region. Option A is incorrect because RDS Multi-AZ only provides failover within the same region. Option C is incorrect because read replicas can be promoted but require manual intervention.

Option D is incorrect because RDS does not support CloudFormation for automated recovery across regions.

742
MCQhard

A company is using AWS CloudFormation to deploy infrastructure. They need to ensure that all resources created by CloudFormation are tagged with a 'CostCenter' tag. The tag must be applied automatically to all resources in the stack. What should they do?

A.Use AWS Service Catalog to enforce tagging on all products.
B.Create an AWS Config rule to detect untagged resources and trigger auto-remediation.
C.Specify the tag in the CloudFormation stack's Tags parameter, which applies the tag to all resources in the stack.
D.Use a custom Lambda function as a CloudFormation hook to tag resources after creation.
AnswerC

When you specify a tag in the Tags parameter of the AWS CloudFormation stack, CloudFormation automatically applies that tag to every resource in the stack that supports tagging during stack creation and update operations. This is a native cloudformation capability that propagates the tag at launch time, ensuring the CostCenter tag is consistently applied without custom code or post-creation processing. Resources that do not support tagging are the only exceptions, but the tag is applied to all taggable resources as part of the stack lifecycle.

Why this answer

CloudFormation allows you to specify stack-level tags in the Tags parameter when creating or updating a stack. These tags are automatically propagated to all resources that support tagging within the stack, ensuring consistent cost allocation without additional custom logic or post-creation remediation.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing a reactive or custom approach (like AWS Config rules or Lambda hooks) when CloudFormation provides a built-in, declarative mechanism to apply tags automatically at stack creation time.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog is a service for creating and managing a catalog of approved products, not for enforcing tags on CloudFormation stacks directly; it can apply tags to provisioned products but does not automatically tag all resources within a stack. Option B is wrong because AWS Config rules are reactive—they detect non-compliant resources after creation and can trigger auto-remediation, but they do not prevent the initial creation of untagged resources and add latency and complexity. Option D is wrong because using a custom Lambda function as a CloudFormation hook to tag resources after creation is an unnecessary workaround; CloudFormation natively supports stack-level tags that are applied at creation time, making a custom hook redundant and less efficient.

743
Multi-Selectmedium

A company uses AWS Organizations to manage multiple accounts. The Security team wants to prevent member accounts from disabling AWS CloudTrail or deleting CloudTrail log files. Which TWO actions should the Security team take in the organization's management account? (Choose TWO.)

Select 2 answers
A.Create an SCP to deny cloudtrail:UpdateTrail.
B.Create an IAM policy in each member account to deny cloudtrail:StopLogging.
C.Create an SCP to deny s3:DeleteObject on the CloudTrail log bucket.
D.Enable AWS CloudTrail from the management account with organization trail.
E.Create an SCP to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail.
AnswersC, E

Denying s3:DeleteObject via an SCP on the CloudTrail log bucket is correct because it directly protects the integrity of historical audit logs. Even if a user in a member account has IAM permissions to call cloudtrail:StopLogging or cloudtrail:DeleteTrail, they cannot destroy the existing evidence stored in S3, and the trail will continue to deliver new logs as long as it is active. This is a critical safeguard because attackers often attempt to delete logs to hide their activity, and SCPs provide a central, unchangeable control across all member accounts.

Why this answer

An SCP that denies s3:DeleteObject on the CloudTrail log bucket prevents member accounts from deleting log files stored in S3, even if they have full administrative permissions. This is a critical control to ensure log integrity and compliance with security policies.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking IAM policies in member accounts can enforce controls, or they overlook that denying UpdateTrail is insufficient because StopLogging and DeleteTrail are separate actions that must also be blocked.

744
MCQhard

A company is using AWS Lambda to process streaming data from Amazon Kinesis. The processing rate is slower than expected, and the engineer needs to monitor the number of records that are failing processing. Which metric should be used to create a CloudWatch alarm?

A.Invocations
B.IteratorAge
C.Errors
D.Throttles
AnswerB

IteratorAge is the correct metric to monitor for Kinesis-triggered Lambda because it directly measures the age of the oldest unprocessed record, reported in milliseconds. When the Lambda consumer can't keep up with the shard's data rate, the iterator age grows, indicating that stream records are sitting unprocessed for longer — a clear sign of a processing bottleneck or backlog. A sustained increase in IteratorAge typically drives alarms for scaling out the Lambda function or increasing the number of shards, making it the definitive indicator of stream processing lag.

Why this answer

The IteratorAge metric measures the age of the last record in the Lambda function's iterator, indicating how far behind real-time the processing is. A high or increasing IteratorAge suggests that records are being retried or stuck due to processing failures, making it the correct metric to monitor for records failing processing in a Kinesis-triggered Lambda.

Exam trap

The trap here is that candidates confuse 'Errors' (Lambda function exceptions) with 'record processing failures' in a Kinesis stream, not realizing that Kinesis retries failed batches internally, so the Lambda may not emit an error metric for each failed record.

How to eliminate wrong answers

Option A (Invocations) is wrong because it counts the total number of function invocations, not failures; a high invocation count could indicate success or failure, but it does not isolate failing records. Option C (Errors) is wrong because it tracks Lambda function errors (e.g., exceptions in code), but Kinesis stream processing failures often result in retries and do not always surface as Lambda errors if the function returns a success after a partial failure. Option D (Throttles) is wrong because it measures when Lambda concurrency limits are exceeded, which is unrelated to record processing failures; throttling would cause slower processing but not directly indicate failed records.

745
MCQmedium

A company is implementing a CI/CD pipeline using AWS CodePipeline to deploy a serverless application using the AWS Serverless Application Model (SAM). The pipeline must build and package the application, then deploy it to multiple environments (dev, test, prod) sequentially with manual approval gates before production. Which stage configuration should be used?

A.Use a single CloudFormation stack with a change set approval step
B.Use a CodeBuild build stage to run 'sam package' and 'sam deploy' commands, then separate deploy stages for each environment with manual approval actions
C.Configure CodePipeline with a deploy action provider set to AWS CloudFormation
D.Use CodeDeploy to deploy the SAM template directly to Lambda
AnswerB

This design completely addresses the SAM pipeline lifecycle: a CodeBuild stage runs `sam package`, which uploads the function code and dependencies to S3 and writes a packaged template that CloudFormation can parse. Each environment's deploy stage then runs `sam deploy` (or uses the packaged template with CloudFormation) under environment-specific parameters, and a manual approval action preceding each higher environment provides the required release gate. Because every stage is a separate CodePipeline stage, approvals are isolated and promotions are sequential, preventing any single action from accidentally deploying to all environments.

Why this answer

It uses a CodeBuild build stage to run 'sam package' and 'sam deploy' commands, which is the recommended approach for SAM-based deployments. The pipeline then separates deploy stages for each environment (dev, test, prod) with manual approval actions before production, satisfying the sequential deployment and manual gate requirements.

Exam trap

The trap here is that candidates often assume the AWS CloudFormation deploy action provider can handle SAM templates directly, but it cannot because SAM templates require the 'sam package' command to transform and upload artifacts before deployment.

How to eliminate wrong answers

Option A is wrong because a single CloudFormation stack cannot deploy to multiple environments sequentially with manual approval gates; it would deploy to one environment only and lacks the multi-environment orchestration. Option C is wrong because the AWS CloudFormation deploy action provider in CodePipeline does not natively support SAM templates; it requires the template to be pre-packaged and uploaded to S3, and it cannot run 'sam package' or 'sam deploy' commands, which are essential for SAM transformations. Option D is wrong because CodeDeploy is designed for deploying applications to EC2, on-premises, or Lambda functions directly, but it cannot handle SAM template packaging, transformation, or multi-environment sequential deployment with manual approval gates.

746
MCQeasy

A DevOps engineer is setting up an AWS CodePipeline to deploy a web application to an EC2 instance using AWS CodeDeploy. The deployment group uses an in-place deployment configuration. The pipeline's deploy stage fails with the error: 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available, or some instances in your deployment group are experiencing problems.' The engineer checks the CodeDeploy logs on the instance and finds that the 'BeforeInstall' lifecycle hook script is failing. The script attempts to download a package from an Amazon S3 bucket that is encrypted with SSE-KMS. What is the MOST likely cause of the failure?

A.The EC2 instance does not have internet access to reach the S3 bucket.
B.The S3 bucket name is misspelled in the 'BeforeInstall' script.
C.The IAM role attached to the EC2 instance lacks the 'kms:Decrypt' permission for the AWS KMS key used to encrypt the S3 object.
D.The CodeDeploy agent does not have permissions to read from the S3 bucket.
AnswerC

In CodeDeploy, lifecycle hook scripts (such as BeforeInstall) run on the target instance and use the instance's IAM role, not the CodeDeploy service role. If the S3 object is encrypted with an AWS KMS customer-managed key, the script's `aws s3 cp` or `aws s3api get-object` call requires both s3:GetObject on the bucket/object and kms:Decrypt permission for that key. Even if s3:GetObject is allowed, lacking kms:Decrypt causes the S3 client to fail with an AccessDeniedException when it attempts to retrieve the plaintext, making the lifecycle hook exit non-zero and the deployment fail. This is the exact scenario that produces a script failure pointing to encryption authorization.

Why this answer

The error occurs because the EC2 instance's IAM role lacks the `kms:Decrypt` permission for the AWS KMS key used to encrypt the S3 object. When the `BeforeInstall` script attempts to download the package, the AWS SDK or CLI on the instance must decrypt the object using the KMS key. Without this permission, the download fails, causing the lifecycle hook to fail and the overall deployment to abort due to too many failed instances.

Exam trap

The trap here is that candidates often assume the CodeDeploy agent handles all S3 access, but the script runs under the instance's IAM role, and missing KMS permissions are a common oversight when using encrypted artifacts.

How to eliminate wrong answers

Option A is wrong because the EC2 instance can access S3 via a VPC endpoint or NAT gateway without requiring internet access; the error is specifically about decryption, not network connectivity. Option B is wrong because a misspelled bucket name would cause a 'NoSuchBucket' error, not a KMS-related decryption failure. Option D is wrong because the CodeDeploy agent itself does not directly read from S3; the script runs under the instance's IAM role, and the agent's permissions are separate from the script's S3 access.

747
MCQmedium

A DevOps team is implementing a CI/CD pipeline using AWS CodePipeline. The pipeline has a Source stage using CodeCommit, a Build stage using CodeBuild, and a Deploy stage using CloudFormation. The team wants to add manual approval before the Deploy stage for production deployments. How should this be configured?

A.Configure a CloudWatch event to send an email on build success.
B.Use a Lambda function to approve based on build status.
C.Add an Approval stage to the pipeline with SNS topic for notification.
D.Create a separate pipeline for production and trigger it manually.
AnswerC

Adding an Approval stage to the CodePipeline with an SNS topic is the correct approach because the approval action pauses all subsequent stage transitions until a designated reviewer clicks Approve (or Reject) in the console or invokes PutApprovalResult. The SNS topic sends email or other notifications to the approver, and the pipeline resumes only after the approval token is returned. This provides a auditable, controlled human decision point that is natively supported by CodePipeline.

Why this answer

AWS CodePipeline natively supports Approval stages that can be configured to pause the pipeline and send a notification via an SNS topic. The SNS topic can be subscribed to by email, SMS, or other endpoints, allowing a manual approver to review the build output and then approve or reject the transition to the Deploy stage. This directly meets the requirement for a manual approval gate before production deployment without custom code or separate pipelines.

Exam trap

The trap here is that candidates often confuse automated notifications (like CloudWatch events or Lambda triggers) with the manual approval action, failing to recognize that CodePipeline's built-in Approval stage is the only native way to pause the pipeline for human intervention before deployment.

How to eliminate wrong answers

Option A is wrong because a CloudWatch event on build success does not provide a manual approval mechanism; it only triggers an automated action or notification, not a pause-and-approve workflow. Option B is wrong because using a Lambda function to approve based on build status would be an automated approval, not a manual one, and it bypasses the human review required for production deployments. Option D is wrong because creating a separate pipeline for production and triggering it manually does not integrate a manual approval stage within the same pipeline; it adds operational overhead and does not leverage CodePipeline's built-in approval action.

748
MCQhard

A company has a multi-region application with an RDS for MySQL database in us-east-1. They want to minimize downtime if the primary region fails. They set up a cross-region read replica in us-west-2. What additional step is needed for automated failover?

A.Create a second read replica in the secondary region
B.Use a custom automation to monitor the primary and promote the replica
C.Configure automatic backup retention on the replica
D.Enable Multi-AZ on the read replica
AnswerB

RDS does not natively perform cross-region automatic failover to a read replica. You must implement custom health monitoring, for example using Route 53 health checks or a Lambda function, to detect primary DB instance or AZ failure; upon detection, the automation invokes PromoteReadReplica to convert the replica into a standalone primary and then updates application DNS or database endpoints to redirect traffic. This is the only way to achieve the stated automated failover objective.

Why this answer

B is correct because RDS cross-region read replicas do not support automatic failover; you must use custom automation (e.g., AWS Lambda, Amazon Route 53 health checks, or a custom script) to detect primary region failure and promote the read replica to a standalone instance. This promotion breaks the replication link and makes the replica a writable primary, enabling failover.

Exam trap

The trap here is that candidates confuse Multi-AZ (which provides automatic failover within a region) with cross-region read replicas (which require manual or custom automation for failover).

How to eliminate wrong answers

Option A is wrong because creating a second read replica in the same secondary region does not enable automated failover; it only adds another read target and does not handle promotion or detection logic. Option C is wrong because automatic backup retention on the replica is a backup configuration, not a failover mechanism; it does not monitor the primary or promote the replica. Option D is wrong because Multi-AZ on a read replica provides high availability within a single region, not cross-region automated failover; it does not detect primary region failure or promote the replica.

749
MCQmedium

A company uses Amazon Inspector to assess the security of EC2 instances. The security team receives an alert that a high-severity vulnerability (CVE-2023-XXXX) was found on an EC2 instance running a critical application. The application is behind an Application Load Balancer (ALB) and uses an Auto Scaling group. The vulnerability has a known patch, but patching requires a reboot. The security team needs to remediate the vulnerability with minimal downtime. Which approach should the team take?

A.Create a new launch template with an updated AMI that includes the patch. Update the Auto Scaling group to use the new launch template and perform a rolling update.
B.Remove the instance from the Auto Scaling group, disable health checks on the ALB, and apply the patch manually.
C.Use AWS Systems Manager Patch Manager to apply the patch on the instance without rebooting, then verify the vulnerability is resolved.
D.Stop the vulnerable instance, apply the patch, and start it again. Re-register it with the ALB.
AnswerA

Creating a new launch template with a fully patched AMI and updating the Auto Scaling group to use it enables an instance refresh, which performs a rolling replacement of all current instances without downtime. This immutable infrastructure pattern guarantees that every launched instance is patched from the start, eliminating any configuration drift. An instance refresh gradually replaces instances while respecting the ASG's health check and minimum capacity, so application availability is maintained throughout the process.

Why this answer

The correct approach is to bake the patch into a new AMI, create a new launch template, and perform a rolling update of the Auto Scaling group. This uses the immutable infrastructure pattern: new instances come up already patched, the ALB drains connections from old instances as they are replaced, and the rolling update maintains capacity throughout — achieving minimal downtime without manual intervention. It also ensures the fix persists across future scaling events and instance replacements.

Exam trap

DOP-C02 often tests whether candidates choose manual in-place patching (which causes downtime and drift) over immutable infrastructure with rolling updates — the trap is picking the option that sounds fastest but violates the ASG lifecycle and minimal-downtime requirement.

How to eliminate wrong answers

Option B is wrong because removing an instance from the ASG and disabling ALB health checks causes the instance to be replaced by the ASG (since it is no longer managed) and creates a window where the ALB cannot route traffic correctly — plus manual patching does not scale and leaves other instances vulnerable. Option C is wrong because the question states the patch requires a reboot, so Patch Manager cannot apply it without rebooting; even if it could, patching in place does not survive instance replacement and is not the minimal-downtime approach for an ASG. Option D is wrong because stopping an instance in an ASG triggers the ASG to replace it (or leaves it unhealthy), and re-registering with the ALB manually is error-prone and causes downtime for that instance.

750
MCQeasy

A DevOps engineer needs to create an IAM policy that allows a user to start and stop EC2 instances, but only for instances that have a specific tag 'Environment=Production'. The current policy allows all actions on all instances. Which modification must be made to enforce the tag-based restriction?

A.Add a Condition block: "Condition": {"StringEquals": {"aws:PrincipalTag/Environment": "Production"}}
B.Change the Action to "ec2:Describe*" and add a NotAction element.
C.Add a Condition block: "Condition": {"StringEquals": {"ec2:ResourceTag/Environment": "Production"}}
D.Add a Condition block: "Condition": {"StringEquals": {"aws:RequestTag/Environment": "Production"}}
AnswerC

This is correct because ec2:ResourceTag/Environment is the IAM condition key that checks the value of the Environment tag on the EC2 resource (instance, volume, etc.) that the request targets, and StringEquals ensures the tag must exactly equal "Production". By adding this Condition block to the policy statement, the allowed actions are only granted when the resource being acted upon carries that tag, effectively scoping permissions to Production instances. This is the standard pattern for tag-based, resource-level access control for EC2.

Why this answer

The `ec2:ResourceTag` condition key allows you to restrict actions based on the tags already attached to the EC2 instance. By using `StringEquals` with `ec2:ResourceTag/Environment` set to `Production`, the policy will only permit the `ec2:StartInstances` and `ec2:StopInstances` actions on instances that currently have that tag. This is the standard AWS mechanism for tag-based resource-level authorization in IAM policies.

Exam trap

The trap here is confusing `ec2:ResourceTag` (tag on the resource) with `aws:RequestTag` (tag in the API request) or `aws:PrincipalTag` (tag on the user), leading candidates to pick a condition key that does not evaluate the instance's existing tags.

How to eliminate wrong answers

Option A is wrong because `aws:PrincipalTag/Environment` checks the tag on the IAM user or role making the request, not the tag on the EC2 instance; this would allow any user with that principal tag to act on any instance, regardless of the instance's tags. Option B is wrong because changing the Action to `ec2:Describe*` would only permit read-only actions (like listing instances), not start/stop operations, and adding a `NotAction` element does not enforce tag-based restrictions—it inverts the action scope, which is irrelevant here. Option D is wrong because `aws:RequestTag/Environment` checks tags that are passed in the API request itself (e.g., when creating a resource), not the tags already present on an existing resource; this would not restrict start/stop actions on existing instances based on their current tags.

Page 9

Page 10 of 18

Page 11