Courseiva

AWS Certified DevOps Engineer Professional DOP-C02 (DOP-C02) — Questions 901–975

1298 questions total · 18pages · All types, answers revealed

Page 12

Page 13 of 18

Page 14
901
MCQmedium

A company is running a production web application on Auto Scaling EC2 instances behind an ALB. They have enabled detailed CloudWatch metrics on the EC2 instances and enabled CloudTrail. Recently, users reported intermittent 503 errors. The operations team reviews CloudWatch dashboards but sees no spike in CPU or memory. What is the MOST likely cause of the 503 errors?

A.Insufficient CloudTrail logging trail configuration
B.The target group has an insufficient number of healthy instances due to health check failures
C.Detailed monitoring is disabled for the EC2 instances
D.The security group for the ALB is misconfigured
AnswerB

The ALB routes requests only to targets that have successfully passed their configured health checks. If health check failures occur—due to an incorrect health check path, a timeout threshold being too low, or an application dependency failing—the corresponding instances are marked unhealthy and removed from the rotation. When the number of healthy targets drops below the minimum needed (typically zero healthy targets in a target group), the ALB returns HTTP 503 Service Unavailable. This can happen without CPU or memory utilization rising, because health checks validate application-level readiness, not just resource utilization.

Why this answer

ALB returns HTTP 503 when no healthy targets are available in the target group to serve the request. If health checks are failing intermittently — due to application-level issues, misconfigured health check paths, or slow responses — targets are marked unhealthy and removed from rotation, leaving insufficient capacity and producing 503s. Because CPU and memory show no spike, the cause is not resource saturation but target availability.

Exam trap

DOP-C02 often tests the distinction between ALB 503 (no healthy targets) and 502 (bad gateway from a target) — candidates chase resource metrics or security group misconfigurations when the real signal is target health check failures.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs API activity for auditing, not application request handling; insufficient trail configuration cannot cause 503 errors. Option C is wrong because detailed monitoring (1-minute metrics) affects metric granularity, not target health — disabling it would not cause 503s, and the scenario says detailed metrics are enabled. Option D is wrong because a misconfigured ALB security group would typically cause connection timeouts or refused connections (and would affect all traffic consistently), not intermittent 503s from the ALB itself.

902
Multi-Selecthard

A company uses AWS CodeBuild to run security scans on code. The scan requires access to a private Amazon ECR repository for downloading scanning tools. The CodeBuild project is configured with a VPC and uses an IAM role. However, the build fails with 'Error: unable to pull image from registry.' Which TWO steps should be taken to resolve this?

Select 2 answers
A.Change the ECR repository policy to allow public access.
B.Remove the VPC configuration from the CodeBuild project so it can access the public internet.
C.Add 'ecr:GetDownloadUrlForLayer' and 'ecr:BatchGetImage' permissions to the CodeBuild service role.
D.Grant 'kms:Decrypt' permissions for the KMS key used by ECR.
E.Create a VPC endpoint for Amazon ECR and associate it with the VPC used by CodeBuild.
AnswersC, E

The CodeBuild service role must include ecr:GetDownloadUrlForLayer and ecr:BatchGetImage, along with ecr:GetAuthorizationToken, to successfully pull a container image from Amazon ECR. BatchGetImage retrieves the image manifest, while GetDownloadUrlForLayer obtains the URLs for each layer, and both are required after CodeBuild calls GetAuthorizationToken to authenticate. Without these permissions, CodeBuild receives an AccessDenied exception and the security scan cannot start.

Why this answer

The CodeBuild service role must have the 'ecr:GetDownloadUrlForLayer' and 'ecr:BatchGetImage' permissions to authorize the retrieval of container image layers from the private ECR repository. Without these permissions, the Docker pull operation fails with 'unable to pull image from registry' even if network connectivity is established.

Exam trap

The trap here is that candidates often focus solely on IAM permissions (Option C) and overlook the VPC endpoint requirement (Option E), or they incorrectly assume removing the VPC (Option B) is the fix, not realizing that VPC endpoints are the correct way to provide private connectivity to ECR.

903
MCQmedium

A company is deploying a stateful application on Amazon EKS. The application requires persistent storage that can be reattached to a new pod if the original pod fails. The cluster spans multiple Availability Zones. Which storage solution provides the BEST resilience and meets these requirements?

A.Amazon S3 bucket with a mountpoint.
B.Amazon EBS with gp3 volume type.
C.EC2 instance store volumes.
D.Amazon EFS file system.
AnswerD

Amazon EFS is a regional, elastic, fully managed NFS file system that is accessible from all Availability Zones in the region. It supports the ReadWriteMany access mode, allowing multiple pods across different nodes and AZs to share the same file system simultaneously. EFS integrates with the EKS CSI driver and provides strong consistency and durability, making it an ideal persistent storage solution for stateful applications deployed on EKS.

Why this answer

Amazon EFS provides a fully managed, regional NFS file system that can be mounted concurrently by multiple pods across different Availability Zones. It is designed for high availability and durability, automatically replicating data across multiple AZs, and supports automatic reattachment to a new pod if the original pod fails, making it the best choice for stateful applications requiring resilient, shared persistent storage on Amazon EKS.

Exam trap

The trap here is that candidates often assume EBS is the default persistent storage for Kubernetes because of its common use with single-node stateful workloads, but they overlook the multi-AZ requirement that makes EBS unsuitable due to its zonal scope, while EFS's regional nature provides the necessary cross-AZ resilience.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service, not a file system; using a mountpoint (e.g., s3fs) introduces POSIX compatibility issues, performance overhead, and does not provide the native file locking or consistent read-after-write semantics required for a stateful application's persistent storage. Option B is wrong because Amazon EBS volumes are tied to a single Availability Zone and cannot be reattached to a pod in a different AZ; if the original pod fails and a replacement pod is scheduled in another AZ, the EBS volume cannot be mounted, breaking resilience across the multi-AZ cluster. Option C is wrong because EC2 instance store volumes are ephemeral and data is lost if the instance stops, terminates, or fails; they do not provide persistent storage that survives pod or node failures.

904
MCQeasy

Refer to the exhibit. A developer has a buildspec.yaml for a React application. The build completes successfully, but the artifacts output is empty. What is the most likely cause?

A.The base-directory specified does not exist after the build phase.
B.The install phase did not run because npm install is not in the correct phase.
C.The artifacts files pattern '**/*' is invalid.
D.The runtime version nodejs 14 is not supported by CodeBuild.
AnswerA

The 'base-directory' value in the artifacts block points to a path that CodeBuild expects to exist when it attempts to upload artifacts after the build phase completes. If your build commands generate output inside 'dist', for example, then specifying a base-directory like 'build' will cause an 'artifact base-directory does not exist' failure because that directory was never created or populated. CodeBuild does not automatically compile or copy files; it simply packages whatever is present under the specified path at that moment. Therefore this is the correct reason for the error, not an invalid pattern or runtime.

Why this answer

The most likely cause is that the `base-directory` specified in the `artifacts` section of the buildspec.yaml does not exist after the build phase completes. CodeBuild uses the `base-directory` to locate the files to package as artifacts; if the directory is missing (e.g., because the build output was written to a different path or the directory name was misspelled), no files are found, resulting in an empty artifacts output. This is a common misconfiguration when the build process generates files in a subdirectory that does not match the declared `base-directory`.

Exam trap

The trap here is that candidates assume an empty artifacts output must be caused by a syntax error in the files pattern or a missing install phase, rather than recognizing that a valid but incorrect `base-directory` path silently produces no artifacts.

How to eliminate wrong answers

Option B is wrong because `npm install` is correctly placed in the `install` phase of the buildspec, and the build completed successfully, indicating the install phase ran without issue. Option C is wrong because the pattern `'**/*'` is a valid glob pattern in CodeBuild that recursively matches all files and directories, so it is not the cause of an empty artifacts output. Option D is wrong because Node.js 14 is a supported runtime version in AWS CodeBuild, and the build succeeded, so runtime support is not the issue.

905
MCQeasy

A DevOps engineer needs to manage configuration files across a fleet of Amazon EC2 instances running Amazon Linux. The configuration files must be updated whenever they change in an S3 bucket. Which AWS service is most suitable for this task?

A.AWS OpsWorks for Chef Automate
B.AWS Systems Manager State Manager
C.AWS CloudFormation
D.AWS Config
AnswerB

AWS Systems Manager State Manager is the correct choice because it creates State Manager associations that run SSM documents on a schedule to enforce and update configuration files across your managed instances. You can specify the exact content and location of files using SSM documents like AWS-RunShellScript or AWS-ApplyAnsibleModules, and the association will ensure that state stays consistent, remediating drift automatically. It supports targeting by tags, integration with Parameter Store for values, and granular rate controls, making it a native, agent-based configuration management service.

Why this answer

AWS Systems Manager State Manager is the most suitable service because it provides a configuration management solution that can automatically apply and maintain the desired state of EC2 instances. It can be configured to run associations on a schedule or in response to events, such as changes to an S3 bucket, using an AWS Lambda trigger or EventBridge rule to invoke the association. This ensures that configuration files are updated whenever they change in the S3 bucket, without requiring manual intervention or a full configuration management platform.

Exam trap

The trap here is that candidates often confuse AWS Config (which only audits and records configuration changes) with Systems Manager State Manager (which actively enforces and applies desired configurations), leading them to select AWS Config as the answer.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks for Chef Automate is a managed Chef server that requires Chef cookbooks and a Chef client agent, which is overkill for simple file synchronization and does not natively integrate with S3 bucket events for automatic updates. Option C is wrong because AWS CloudFormation is an Infrastructure as Code (IaC) service used to provision and manage AWS resources, not to manage runtime configuration files on running instances; it would require custom resources or additional automation to react to S3 changes. Option D is wrong because AWS Config is a service for evaluating resource compliance against rules and recording configuration history, not for actively pushing or updating configuration files on EC2 instances.

906
MCQhard

A company uses AWS CodePipeline to automate deployments. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CodeDeploy). The DevOps engineer notices that the pipeline fails intermittently during the deploy stage with the error: 'The deployment failed because the deployment group does not exist'. What is the most likely cause?

A.The deployment group was deleted or renamed after the pipeline was configured
B.The Auto Scaling group associated with the deployment group has insufficient capacity
C.The CodePipeline service role does not have permission to call CodeDeploy
D.The CodeDeploy application name in the pipeline is misspelled
AnswerA

When a pipeline's deploy action references a CodeDeploy deployment group, CodeDeploy resolves that group by name and deployment group ID at execution time. If the group was deleted or renamed after pipeline configuration, the deploy action fails with a DeploymentGroupDoesNotExist or similar error when CodeDeploy attempts the deployment. The pipeline configuration itself stores the name, not a live reference, so the failure occurs at run time, not when the pipeline is edited. This is the classic cause when the error explicitly indicates the deployment group cannot be found.

Why this answer

The intermittent 'deployment group does not exist' error indicates that the deployment group referenced in the CodePipeline deploy stage configuration is missing at the time of execution. This most commonly occurs when the deployment group has been deleted or renamed after the pipeline was initially configured, causing the pipeline to reference a non-existent resource. Since the error is intermittent, it suggests the deployment group may be deleted and recreated or renamed during certain operations, rather than a permanent misconfiguration.

Exam trap

The trap here is that candidates often assume permission or naming errors cause consistent failures, but the intermittent nature of the error points to a resource lifecycle issue—specifically, the deployment group being deleted or renamed after pipeline configuration.

How to eliminate wrong answers

Option B is wrong because insufficient Auto Scaling group capacity would cause a different error, such as 'InsufficientCapacityException' or 'InstanceLimitExceeded', not 'deployment group does not exist'. Option C is wrong because a missing permission for the CodePipeline service role to call CodeDeploy would result in an 'AccessDeniedException' error, not a 'deployment group does not exist' error. Option D is wrong because a misspelled CodeDeploy application name would cause a consistent failure every time the pipeline runs, not an intermittent error, and the error message would reference the application name, not the deployment group.

907
MCQmedium

A company is designing a disaster recovery strategy for a critical application. They need a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 1 minute. Which AWS database service configuration meets these requirements?

A.RDS MySQL with Multi-AZ and cross-region read replica
B.DynamoDB global tables
C.Aurora Global Database
D.RDS PostgreSQL with cross-region read replica
AnswerC

Aurora Global Database is the correct DR choice because it uses dedicated storage-level replication across regions with a typical RPO of sub-second and an RTO of under 1 minute when you promote a secondary region. The primary and secondary remain fully readable during normal operation, and promotion is a single API call with automatic DNS update, giving the best RTO/RPO among the options.

Why this answer

Aurora Global Database provides a fully managed cross-region disaster recovery solution with typical RPO of 1 second and RTO of 1 minute for regional failover, which meets the required RTO of 15 minutes and RPO of 1 minute. It uses storage-level replication that is asynchronous but very low-latency, and failover can be promoted to the secondary region in under a minute.

Exam trap

Common misconception: Any cross-region read replica (like RDS MySQL or PostgreSQL) can achieve sub-minute RPO and RTO. In reality, manual promotion steps and asynchronous replication lag make them unsuitable for strict 15-minute RTO and 1-minute RPO requirements. Aurora Global Database's storage-level replication achieves RPO of 1 second and RTO under 1 minute, meeting the requirements.

How to eliminate wrong answers

Option A is wrong because RDS MySQL Multi-AZ provides high availability within a single region, not cross-region DR, and cross-region read replicas have asynchronous replication with typical RPO of seconds to minutes but failover requires manual promotion and DNS changes, often exceeding 15 minutes RTO. Option B is wrong because DynamoDB global tables are designed for multi-region active-active workloads with eventual consistency, and while RPO is typically sub-second, RTO for regional failover can be minutes but requires application-side retry logic and does not guarantee 1-minute RPO under all failure scenarios. Option D is wrong because RDS PostgreSQL cross-region read replicas have similar limitations to MySQL: asynchronous replication with variable RPO and manual promotion steps that make achieving 15-minute RTO unreliable.

908
MCQmedium

A company has a serverless application using AWS Lambda functions and Amazon API Gateway. The application has been running fine, but recently users report that some requests are timing out with a 504 error. The Lambda function's timeout is set to 30 seconds, and API Gateway's integration timeout is 29 seconds. The CloudWatch logs for the Lambda function show that the function executes in under 5 seconds on average. What is the MOST likely cause of the 504 errors?

A.The Lambda function is logging too much data, causing delays in log delivery.
B.API Gateway's timeout is set to less than the Lambda function's timeout.
C.The Lambda function is experiencing concurrency limits and requests are being throttled.
D.The Lambda function's memory is too low, causing cold starts to take longer than the timeout.
AnswerC

When the Lambda function's concurrency limit is reached, synchronous invocations from API Gateway are throttled. For proxy integrations, a throttled request is not immediately rejected—the Lambda service may wait for a free concurrency slot while API Gateway's 29-second integration timeout is already counting down; if no slot frees up in time, API Gateway drops the connection and returns a 504. This explains intermittent 504s even though a 5-second function would otherwise succeed, because the delay occurs before the function code ever runs.

Why this answer

Even though the Lambda function runs in under 5 seconds, if it is throttled due to concurrency limits, the function may not be invoked until after API Gateway's 29-second integration timeout has passed. This causes API Gateway to return a 504 error. Option A is incorrect because excessive logging does not cause 504 errors; it may affect performance but not directly cause timeouts.

Option B is incorrect because the Lambda timeout (30s) is actually higher than API Gateway's integration timeout (29s), so the function could complete before API Gateway times out. Option D is incorrect because cold starts typically add only a second or two, not enough to exceed the 29-second integration timeout when average execution is under 5 seconds.

909
Multi-Selecteasy

A DevOps engineer is designing a CI/CD pipeline for a containerized application using AWS CodeBuild and Amazon ECS. Which TWO actions will help reduce the frequency of Docker image pulls from the public Docker Hub registry?

Select 2 answers
A.Create a Docker Hub access token and store it in AWS Secrets Manager
B.Enable CodeBuild local caching for the cache type 'LOCAL_DOCKER_LAYER_CACHE'
C.Store the base image in Amazon ECR and use it in the build
D.Use AWS CodeArtifact as a proxy for Docker Hub
E.Configure CodeBuild to use a VPC with a NAT gateway
AnswersB, C

Enabling CodeBuild local caching with the cache type LOCAL_DOCKER_LAYER_CACHE stores image layers in the build host's local Docker daemon after the first successful build. On subsequent builds, CodeBuild can reuse those locally cached layers instead of pulling them from Docker Hub, which cuts both external network calls and build time. This is the most direct way to reduce Docker Hub pull frequency for a standard container-image CI pipeline.

Why this answer

Option B is correct because enabling CodeBuild local caching with the cache type 'LOCAL_DOCKER_LAYER_CACHE' persists Docker image layers between builds on the same host, so previously pulled base image layers are reused and Docker does not need to re-pull them from Docker Hub. Option C is correct because storing the base image in Amazon ECR and referencing it in the build pulls the image from ECR (a private, AWS-hosted registry) instead of the public Docker Hub registry, directly reducing Docker Hub pulls. Option A is incorrect because a Docker Hub access token in Secrets Manager only authenticates and raises rate limits; it does not reduce the number or frequency of image pulls.

Option D is incorrect because AWS CodeArtifact does not support Docker/OCI registries as a Docker Hub proxy (it supports package formats like npm, Maven, PyPI, NuGet), so it cannot serve as a pull-through cache for Docker images. Option E is incorrect because attaching CodeBuild to a VPC with a NAT gateway only changes network routing for outbound traffic; it does not cache or eliminate Docker Hub image pulls.

Exam trap

Candidates may think that D (CodeArtifact proxy) is correct, but AWS CodeArtifact does not support Docker registries or act as a proxy for Docker Hub. It is intended for software packages like npm, PyPI, Maven, and NuGet, not for container image caching.

910
MCQmedium

A development team uses AWS CodeCommit for source control and AWS CodePipeline for CI/CD. The pipeline has a source stage that pulls from a CodeCommit repository, a build stage using AWS CodeBuild, and a deploy stage that uses AWS CodeDeploy to deploy to an EC2 Auto Scaling group. The team notices that the pipeline frequently fails at the deploy stage with the error 'The deployment failed because the deployment group's deployment configuration specifies a minimum healthy host count of 1, but 0 healthy hosts are available.' What is the MOST likely cause of this issue?

A.The IAM role for CodePipeline does not have sufficient permissions to access the CodeCommit repository.
B.The build artifacts are not being stored in an S3 bucket.
C.The EC2 instances are not registered with a Classic Load Balancer.
D.The CodeDeploy agent is not installed or is not running on the EC2 instances.
AnswerD

The CodeDeploy agent is a daemon installed on EC2 instances that handles deployment instructions, lifecycle events, and reporting instance status to the CodeDeploy service. Without a running agent, the service never receives a heartbeat or a success signal, so the instance is considered unhealthy and the deployment fails with an error like 'No healthy instances found'. This directly matches the symptom described, and verifying agent status with 'sudo service codedeploy-agent status' or checking /var/log/aws/codedeploy-agent/install.log is the first troubleshooting step. Installing or starting the agent on the tagged instances resolves the failure.

Why this answer

The error message indicates that the CodeDeploy deployment is failing because zero healthy hosts are available in the deployment group. The most common cause is that the CodeDeploy agent is not installed or not running on the EC2 instances, preventing them from reporting their health status to the CodeDeploy service. Without a healthy agent, the instances cannot execute the deployment lifecycle hooks, and CodeDeploy considers them unhealthy, leading to the failure.

Exam trap

The trap here is that candidates often confuse deployment failures caused by missing agents with network or load balancer issues, but the specific error about '0 healthy hosts' directly points to the agent not running or not reporting health, not to load balancer registration or pipeline permissions.

How to eliminate wrong answers

Option A is wrong because the IAM role for CodePipeline lacking permissions to access the CodeCommit repository would cause the source stage to fail, not the deploy stage. Option B is wrong because build artifacts not being stored in an S3 bucket would cause the build or source stage to fail, as CodePipeline requires artifacts to be passed between stages; the deploy stage error specifically relates to host health, not artifact storage. Option C is wrong because EC2 instances not being registered with a Classic Load Balancer is not a requirement for CodeDeploy to work; CodeDeploy can deploy to instances directly via tags or Auto Scaling groups, and the error is about host health, not load balancer registration.

911
MCQhard

A media company runs a video transcoding pipeline on AWS. The pipeline uses AWS Step Functions to orchestrate multiple Lambda functions that transcode video files stored in Amazon S3. The company wants to implement a monitoring solution to track the progress of each workflow execution, including which step is currently running, the duration of each step, and any errors. The solution should provide near real-time visibility and allow the team to troubleshoot failed executions quickly. Which solution meets these requirements?

A.Create custom CloudWatch metrics from Lambda functions for each step, and build a CloudWatch dashboard.
B.Use Amazon EventBridge to capture Step Functions execution status changes and build a custom dashboard in CloudWatch.
C.Configure each Lambda function to write logs to CloudWatch Logs with the execution ID, and use CloudWatch Logs Insights to query and visualize.
D.Enable AWS X-Ray tracing on the Step Functions and Lambda functions to get a service map and trace details.
AnswerB

Correct. Amazon EventBridge captures Step Functions execution state changes (e.g., 'ExecutionStarted', 'TaskStateEntered', 'ExecutionFailed') in near real-time. These events can be used to build a CloudWatch dashboard that shows the current step, duration per step, and errors, meeting all requirements without custom instrumentation.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) can capture Step Functions execution state changes (e.g., step started, succeeded, failed). These events can be used to build a custom dashboard in CloudWatch, providing near real-time visibility into workflow progress, step durations, and errors. Option A is incorrect because creating custom metrics from Lambda functions requires additional instrumentation and does not provide workflow-level context easily.

Option C is incorrect because CloudWatch Logs Insights queries are not near real-time; they require searching through logs, and the solution needs real-time visibility. Option D is incorrect because AWS X-Ray provides distributed tracing for individual requests, but it does not offer high-level workflow step tracking with durations and errors aggregated across executions in near real-time.

912
MCQhard

A company is using Amazon RDS for MySQL and needs to monitor the number of slow queries. They have enabled slow query logs. How can they effectively monitor and alert on the number of slow queries per minute?

A.Use RDS Events to send slow query metrics to CloudWatch.
B.Enable RDS Enhanced Monitoring and publish metrics to CloudWatch.
C.Use AWS CloudTrail to monitor SQL queries.
D.Publish slow query logs to CloudWatch Logs, create a metric filter, and set an alarm.
AnswerD

The correct approach is to enable the RDS MySQL slow query log by setting slow_query_log=1 and long_query_time in the DB parameter group, then configure RDS to stream those logs to a CloudWatch Logs log group. Once the log events are flowing, you create a CloudWatch Logs metric filter—patterned to match the slow query log format, such as lines containing 'Query_time'—to count matching events as a custom metric, and then set a CloudWatch alarm to trigger when the count exceeds a threshold.

Why this answer

Slow query logs from RDS MySQL can be published to CloudWatch Logs. Once the logs are in CloudWatch Logs, you can create a metric filter to count the number of slow queries per minute and set a CloudWatch alarm on that metric to alert when the count exceeds a threshold. Option A is incorrect because RDS Events provide notifications about instance events (e.g., failover, maintenance), not slow query metrics.

Option B is incorrect because Enhanced Monitoring provides OS-level metrics (e.g., CPU, memory) but not slow query log data. Option C is incorrect because CloudTrail records API calls made to AWS services, not SQL queries executed within RDS.

913
MCQhard

A DevOps team is implementing a comprehensive logging strategy for a microservices architecture running on Amazon EKS. They need to collect logs from all containers and send them to a centralized log analytics platform. The solution must be agentless and support multi-line log events. Which approach should the team use?

A.Deploy a Fluent Bit DaemonSet on the EKS cluster and configure it to send logs to Amazon CloudWatch Logs.
B.Use the Amazon CloudWatch agent as a sidecar container in each pod to forward logs to CloudWatch Logs.
C.Install the Amazon Kinesis Agent on each EC2 instance and configure it to stream logs to Amazon Kinesis Data Firehose.
D.Deploy a Fluentd DaemonSet on the EKS cluster and configure it to send logs to Amazon S3.
AnswerA

Fluent Bit is a lightweight, high-throughput log processor that runs as a DaemonSet, placing one pod on every cluster node. It automatically discovers and collects container stdout/stderr logs without requiring application-side changes, making it effectively agentless for application teams. It supports multi-line log parsing and its native CloudWatch Logs output plugin streams logs directly to CloudWatch Logs for real-time aggregation. This is the recommended pattern for comprehensive logging on EKS.

Why this answer

Fluent Bit is a lightweight, CNCF-graduated log processor that can be deployed as a DaemonSet on EKS to collect logs from all nodes without requiring sidecar containers. It supports multi-line log events natively via its multiline filter plugin, and it can output directly to Amazon CloudWatch Logs using the cloudwatch_logs output plugin, meeting the agentless requirement since it runs as a Kubernetes DaemonSet rather than as a per-pod sidecar.

Exam trap

The trap here is that candidates often confuse 'agentless' with 'no software at all,' but in Kubernetes, agentless means no sidecar injection per pod; a DaemonSet is considered agentless because it runs as a cluster-level service, not as part of the application deployment.

How to eliminate wrong answers

Option B is wrong because deploying the CloudWatch agent as a sidecar container in each pod is not agentless; it requires modifying every pod definition and increases resource overhead, whereas the requirement specifies an agentless solution. Option C is wrong because the Amazon Kinesis Agent is an EC2-level agent that must be installed on each underlying EC2 instance, which is not agentless and does not integrate with EKS pod-level log collection; it also does not natively support multi-line log events without custom configuration. Option D is wrong because Fluentd is a heavier log collector compared to Fluent Bit, and while it can send logs to Amazon S3, S3 is a storage service, not a centralized log analytics platform; the requirement specifies sending logs to a centralized log analytics platform, which CloudWatch Logs fulfills.

914
MCQeasy

A company is designing a highly available architecture for a web application. The application runs on Amazon EC2 instances in an Auto Scaling group across three Availability Zones. The instances are behind an Application Load Balancer (ALB). Which additional step should the team take to ensure that traffic is evenly distributed across all healthy instances in all Availability Zones?

A.Use Amazon Route 53 weighted routing policy to distribute traffic to each AZ.
B.Configure health checks on the target group to mark instances as unhealthy if they are in an AZ with fewer instances.
C.Enable cross-zone load balancing on the ALB.
D.Configure the ALB to use least outstanding requests routing algorithm.
AnswerC

This ensures even distribution across all instances in all AZs.

Why this answer

By default, ALB distributes traffic evenly across AZs, but cross-zone load balancing must be enabled to distribute traffic evenly across all instances regardless of AZ. Option A is wrong because Route 53 weighted routing is not needed for internal load balancing; the ALB already distributes traffic across AZs. Option B is wrong because configuring health checks to mark instances unhealthy based on AZ instance count would not help with even distribution and could cause unnecessary failures.

Option D is wrong because the least outstanding requests routing algorithm optimizes for request queue depth but does not enable cross-zone load balancing; cross-zone load balancing must be explicitly enabled.

915
Multi-Selectmedium

Which TWO strategies can be used to improve the resilience of an application running on Amazon ECS with Fargate? (Select TWO.)

Select 2 answers
A.Use a single subnet for all tasks to simplify networking.
B.Configure the ECS service to place tasks in multiple Availability Zones.
C.Increase the task memory reservation to handle peak load.
D.Implement a circuit breaker pattern for downstream dependencies.
E.Use scheduled scaling to adjust task count based on historical patterns.
AnswersB, D

Placing tasks in multiple Availability Zones is a core high-availability strategy because each AZ is an isolated, independent failure domain. The ECS service scheduler spreads tasks across the chosen subnets, so when one AZ is impacted by an outage, the tasks in the other AZs continue serving traffic and the service can still meet its desired count. This addresses resilience by ensuring no single infrastructure failure can take down the entire service.

Why this answer

Configuring the ECS service to place tasks in multiple Availability Zones distributes the application across physically separate data centers, so if one AZ fails, the tasks in other AZs continue to run. Option D is correct because implementing a circuit breaker pattern for downstream dependencies prevents cascading failures by detecting faults and failing fast, allowing the system to recover gracefully. Option A is incorrect; using a single subnet for all tasks typically places them in a single Availability Zone, reducing fault tolerance.

Option C is incorrect; increasing task memory reservation helps handle peak load but does not improve resilience against failures. Option E is incorrect; scheduled scaling adjusts capacity based on historical patterns and does not handle unexpected spikes or failures.

916
MCQhard

A company runs a microservices application on Amazon ECS with Fargate. The operations team notices that some services are experiencing intermittent high latency, but CPU and memory metrics appear normal. They need to identify the root cause. Which approach should they use?

A.Enable detailed CloudWatch Logs and use CloudWatch Logs Insights to query logs for slow requests.
B.Use Amazon Managed Service for Prometheus to collect custom metrics and set up dashboards.
C.Set up CloudWatch Synthetics canaries to monitor the endpoints and measure response times.
D.Instrument the application with the AWS X-Ray SDK and use the X-Ray console to analyze traces.
AnswerD

Instrumenting with the AWS X-Ray SDK is the correct approach because X-Ray traces individual requests as they traverse services, generating a trace ID that propagates across HTTP headers and AWS SDK client calls. The X-Ray console provides a service map and trace timelines, segment and subsegment views that break down latency for each downstream call, letting you pinpoint the exact service or resource causing the slowdown. You can also annotate traces with request metadata and set sampling rules to balance overhead and observability.

Why this answer

Intermittent latency with normal CPU and memory metrics points to a distributed tracing problem — the bottleneck is likely in a downstream call, a network hop, or a specific service in the request chain. AWS X-Ray traces requests end-to-end across ECS tasks, Lambda functions, and downstream services, showing exactly where time is spent. This makes it the right tool to pinpoint the root cause of intermittent latency in a microservices architecture.

Exam trap

DOP-C02 often tests the distinction between metrics, logs, and traces — candidates pick CloudWatch Logs or Prometheus because they sound comprehensive, but only X-Ray provides the per-request, cross-service causality needed to diagnose intermittent latency.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights can query logs for slow requests, but it requires the application to already log timing data and does not automatically correlate latency across service boundaries — it is reactive and manual rather than a tracing solution. Option B is wrong because Amazon Managed Service for Prometheus collects metrics, and metrics alone cannot explain why a specific request was slow — they show aggregates, not per-request causality. Option C is wrong because CloudWatch Synthetics canaries measure endpoint response times from the outside but cannot tell you which internal service or call caused the latency, so they detect the symptom rather than diagnose the cause.

917
MCQhard

A company uses AWS CloudFormation to deploy infrastructure. The security team wants to be notified whenever a stack is created, updated, or deleted. They also want to track who made the change. Which combination of services should be used to achieve this?

A.AWS Config rules and Amazon SNS
B.AWS CloudTrail and Amazon CloudWatch Events (now Events) with SNS
C.Amazon S3 event notifications and AWS Lambda
D.AWS Lambda and Amazon DynamoDB
AnswerB

AWS CloudTrail records all CloudFormation management-plane API calls as event payloads, including the calling identity, request parameters, and timestamp. Amazon CloudWatch Events (now EventBridge) can consume those CloudTrail events using a rule that matches on source: aws.cloudformation and specific event names like UpdateStack or DeleteStack. That rule can then route the matched event to an SNS topic, producing immediate, precise notifications of who performed the stack operation and what operation occurred. This is the native, event-driven pattern for CloudFormation activity monitoring.

Why this answer

CloudTrail captures CloudFormation API calls (CreateStack, UpdateStack, DeleteStack) and CloudWatch Events can trigger SNS notifications based on those API calls. Option A is wrong because Config rules evaluate resource compliance, not API events. Option C is wrong because S3 event notifications are for S3 objects.

Option D is wrong because Lambda alone cannot capture who made the change without CloudTrail integration.

918
MCQhard

A developer is troubleshooting a failed CodeBuild build. The build is triggered by a pull request from a forked repository. The buildspec includes a command to fetch pull request references. What is the most likely cause of the failure?

A.The IAM role for CodeBuild does not have permission to read from the repository.
B.The buildspec file is not present in the source code.
C.The CodeBuild project is not configured to allow pull requests from forked repositories.
D.The buildspec contains invalid syntax.
AnswerC

CodeBuild intentionally does not build pull requests from forked repositories unless you explicitly enable the 'Allow pull requests from forked repositories' setting in the project's webhook configuration. Fork PRs are considered untrusted because the entire buildspec, including install commands and environment variable injection, is controlled by the fork author—so CodeBuild requires an opt-in before it will fetch refs such as refs/pull/123/head or refs/pull/123/merge from a fork. When this setting is off, the source client cannot complete the git fetch for the fork PR, producing exactly the kind of git error being troubleshooted.

Why this answer

When a build is triggered by a pull request from a forked repository, CodeBuild requires explicit configuration to allow builds from forks. By default, CodeBuild projects do not accept webhook events from forked repositories. The error occurs because the project lacks the 'Allow pull requests from forked repositories' setting enabled, even though the IAM role and buildspec may be correctly configured.

Exam trap

The trap here is that candidates often assume the failure is due to IAM permissions or buildspec issues, overlooking the specific CodeBuild setting that controls whether pull requests from forked repositories are allowed.

How to eliminate wrong answers

Option A is wrong because the IAM role for CodeBuild typically has permissions to read from the repository when the build is triggered; the failure is specific to forked repository restrictions, not IAM. Option B is wrong because if the buildspec were missing, CodeBuild would fail with a 'buildspec not found' error, but the question states the buildspec includes a command, implying it exists. Option D is wrong because invalid syntax would cause a build failure at the parsing stage, but the question's context of a forked repository pull request points to a configuration-level restriction, not a syntax issue.

919
MCQhard

A company has a monorepo in AWS CodeCommit with multiple microservices. They want to use AWS CodePipeline to build and deploy only the microservice that changed. What is the MOST efficient approach?

A.Configure a single pipeline that always builds all microservices.
B.Create separate CodeCommit repositories for each microservice.
C.Use an AWS Lambda function triggered by CloudWatch Events for CodeCommit to start the specific pipeline for the changed microservice.
D.Use a single pipeline with multiple build actions that each check if their microservice changed.
AnswerC

This is the correct approach because CodeCommit emits CloudWatch Events (EventBridge) on branch pushes, and a Lambda function can use the CodeCommit API to inspect the files changed in that push. The Lambda then maps a changed path prefix (e.g., 'services/order-service/') to the corresponding CodePipeline pipeline and calls StartPipelineExecution with the exact commit ID and branch. This provides path-based, per-service CI/CD while preserving the monorepo, and it only builds the microservice that actually changed, avoiding wasted compute and keeping feedback fast.

Why this answer

It uses an AWS Lambda function triggered by CloudWatch Events (now Amazon EventBridge) on CodeCommit repository events (e.g., push to a specific branch) to detect which microservice changed and then start the corresponding CodePipeline pipeline. This is the most efficient approach as it avoids unnecessary builds of unchanged microservices and does not require splitting the monorepo or adding complex conditional logic within a single pipeline.

Exam trap

The trap here is that candidates may think a single pipeline with conditional build actions (Option D) is efficient, but they miss that the pipeline still triggers on every change, wasting pipeline executions and build minutes for unchanged microservices.

How to eliminate wrong answers

Option A is wrong because building all microservices on every change wastes compute time and resources, and does not scale efficiently. Option B is wrong because it requires splitting the monorepo into separate repositories, which contradicts the stated monorepo requirement and adds operational overhead for managing multiple repos. Option D is wrong because a single pipeline with multiple build actions that each check if their microservice changed still triggers the entire pipeline on any change, and the conditional checks inside build actions are inefficient and do not prevent the pipeline from running for all microservices.

920
MCQmedium

An operations team manages a fleet of Amazon EC2 instances that require periodic software updates. They want to use AWS Systems Manager to apply patches automatically while ensuring that patches are tested before production deployment. Which approach meets these requirements?

A.Use AWS Systems Manager Automation to create a runbook that patches instances one by one.
B.Create a patch baseline and assign it to all instances; enable automatic approval for all patches.
C.Use AWS Systems Manager Run Command to manually run patch commands on test instances, then on production.
D.Use AWS Systems Manager Patch Manager with maintenance windows, and configure a patch baseline that approves patches after a test period.
AnswerD

Patch Manager automates the entire patching process by using a patch baseline to define which patches are approved, when they are approved (e.g., after a test period expressed in days), and how those rules are applied to tagged instance groups. Maintenance windows schedule when the patching runs on test and production fleets, ensuring production patches are installed only after the baseline's approval delay lets the test fleet validate them. This combination provides automation, a testing gate, and controlled rollout windows, which directly satisfies the requirement.

Why this answer

AWS Systems Manager Patch Manager, when combined with maintenance windows and a patch baseline configured with an approval delay after a test period, allows patches to be automatically applied to test instances first and then, after a defined waiting period, to production instances. This ensures patches are tested before production deployment without manual intervention, meeting the requirement for automated, staged patching.

Exam trap

The trap here is that candidates often confuse Run Command (a manual, ad-hoc tool) with Patch Manager (an automated, policy-driven service), or they assume that simply enabling automatic approval (Option B) is sufficient without considering the need for a testing delay.

How to eliminate wrong answers

Option A is wrong because using Automation to patch instances one by one does not inherently provide a test-before-production staging mechanism; it simply serializes patching without a defined approval delay. Option B is wrong because enabling automatic approval for all patches bypasses any testing period, applying patches to all instances immediately without validation. Option C is wrong because Run Command is a manual execution tool, not an automated solution, and it does not enforce a test period before production deployment.

921
Drag & Dropmedium

Drag and drop the steps to configure an AWS Auto Scaling group with a launch template and scaling policies.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create the launch template, then create the Auto Scaling group, then configure network, then set capacities, then add scaling policy.

922
MCQhard

A company is migrating to AWS and has a requirement to encrypt all data at rest and in transit. They are using AWS KMS with Customer Master Keys (CMKs) for encryption. The DevOps engineer has set up an S3 bucket with default encryption using SSE-KMS. The bucket policy allows access only to a specific IAM role. The engineer also enabled S3 bucket versioning and MFA Delete. However, when the engineer tries to download an object using the AWS CLI with the IAM role, the command fails with 'AccessDenied'. The IAM role has the following permissions: s3:GetObject, s3:ListBucket, kms:Decrypt, kms:DescribeKey. What is the most likely missing permission?

A.The IAM role is missing kms:GenerateDataKey permission.
B.The IAM role is missing kms:Encrypt permission.
C.The IAM role is missing kms:CreateGrant permission.
D.The KMS key policy does not grant the IAM role permission to decrypt using the key.
AnswerD

For an IAM role to decrypt an object using a customer managed key, the KMS key policy must explicitly include the role (or an account principal with delegation) in a statement that allows kms:Decrypt. Even if the IAM role's permissions policy grants kms:Decrypt, KMS requires both the IAM policy and the key policy to authorize the action. If the key policy only allows a different principal or restricts access to specific roles, the decryption fails—this is the most direct cause of the error.

Why this answer

When an IAM role has kms:Decrypt but the KMS key policy does not grant that role access to the key, all KMS operations fail with AccessDenied. KMS requires BOTH the IAM policy and the key policy to allow the principal — the key policy is the primary gatekeeper, so a missing grant there is the most likely cause.

Exam trap

DOP-C02 often tests the misconception that IAM permissions alone are sufficient for KMS — candidates forget that the KMS key policy must also grant access, making the key policy the real gatekeeper.

How to eliminate wrong answers

Option A is wrong because kms:GenerateDataKey is only needed for uploads (PutObject), not for downloading/decrypting an existing object. Option B is wrong because kms:Encrypt is required to upload encrypted objects, not to download them. Option C is wrong because kms:CreateGrant is only needed when the caller must delegate key usage to another principal, which is not the case for a simple GetObject.

923
Multi-Selectmedium

A company is using AWS Secrets Manager to rotate database credentials automatically. The DevOps engineer needs to ensure that the rotation process is secure and does not cause downtime. Which THREE steps should the engineer take?

Select 3 answers
A.Disable automatic rotation for the old secret version.
B.Set up CloudWatch alarms to monitor rotation failures.
C.Use a separate database user for rotation that has permissions to change passwords.
D.Configure the Lambda rotation function to use a VPC endpoint for Secrets Manager.
E.Grant the Lambda rotation function IAM permissions to read and update the secret.
AnswersB, C, E

Setting up CloudWatch alarms on the Secrets Manager rotation Lambda function's failure metrics or on the RotationFailed event (via Amazon EventBridge and CloudTrail) is essential because rotation failures can occur silently without directly impacting the application. If a failure goes unnoticed, the secret may remain stale for an extended period; more critically, the Lambda might have created and stored a new version but failed to promote it to AWSCURRENT, leaving the database and Secrets Manager in an inconsistent state. An alarm ensures administrators are notified quickly to prevent both stale credential burnout and potential data-plane outages.

Why this answer

Option B is correct because CloudWatch alarms on the rotation Lambda's errors, invocation failures, and Secrets Manager rotation metrics let the engineer detect and respond to failed rotations before credentials become stale and cause authentication outages. Option C is correct because the rotation Lambda must authenticate to the database using a dedicated rotation user whose credentials are stored in the secret, and that user needs privileges to modify the password of the target user (for example ALTER USER ... IDENTIFIED BY) so the application user's credentials can be changed without manual intervention.

Option E is correct because the Lambda rotation function needs IAM permissions for secretsmanager:GetSecretValue, PutSecretValue, UpdateSecretVersionStage, and DescribeSecret so it can read the current secret, write the new version, and move the AWSCURRENT staging label to complete rotation. Option A is not needed because Secrets Manager automatically deprecates and removes old versions via staging labels; disabling rotation on an old version is not a valid or necessary step. Option D is not required because a VPC endpoint is only needed when the Lambda runs in a private VPC without NAT/internet access; it is an optional network-hardening measure, not one of the three required steps for secure, zero-downtime rotation.

Exam trap

DOP-C02 often tests whether candidates confuse network hardening (VPC endpoints) with the actual functional requirements for secure, zero-downtime secret rotation, causing them to select D instead of the IAM permission option.

924
MCQeasy

An organization wants to grant cross-account access to an S3 bucket in Account A to a user in Account B. Which policy configuration is required?

A.A bucket policy in Account A and an IAM user policy in Account B
B.An S3 bucket ACL granting access to the user in Account B
C.An IAM user policy in Account B allowing access to the bucket
D.A bucket policy in Account A granting access to the user in Account B
AnswerA

Combining a bucket policy in Account A that grants the IAM user ARN from Account B permissions on the target S3 bucket with an IAM user policy in Account B that approves the same actions is the standard method for cross-account S3 access. The bucket policy acts as the resource-based authorization, defining who can interact with the bucket and its objects; the IAM user policy acts as the identity-based authorization, allowing the user to invoke those S3 APIs. Without both explicit allows, the request is denied by AWS's default deny behavior.

Why this answer

Cross-account access to an S3 bucket requires both a resource-based policy (bucket policy) on the bucket in Account A granting access to the user in Account B, and an identity-based policy (IAM user policy) in Account B allowing the user to access the bucket. Option A correctly includes both policies. Option B is incorrect because S3 bucket ACLs are legacy and not recommended for cross-account access.

Option C is missing the bucket policy in Account A, so it is insufficient. Option D is missing the IAM user policy in Account B, so it is insufficient.

925
MCQmedium

A DevOps team uses AWS OpsWorks for configuration management. They have a stack with a custom cookbook that installs and configures an application. After updating the cookbook on GitHub, they need to apply the changes to existing instances without creating new ones. What should the team do?

A.Clone the stack and assign the updated cookbook to the new stack.
B.Use the 'Execute Recipes' feature to run the updated custom recipe on the instances.
C.Update the layer's custom cookbook settings and then reboot the instances.
D.Update the stack's custom cookbook source and click 'Update Dependencies' on the stack.
AnswerB

The Execute Recipes feature in AWS OpsWorks Stacks allows you to run a specified recipe on selected instances immediately. This initiates an ad-hoc Chef run that pulls the latest cookbook from your configured source and executes the recipe's logic, directly applying the changes to the existing instances. It is the intended mechanism for manually applying cookbook updates without recreating or redeploying instances.

Why this answer

AWS OpsWorks provides the 'Execute Recipes' feature, which allows you to run a specific recipe from a cookbook on existing instances without requiring a stack update or instance replacement. This is the direct method to apply changes from an updated custom cookbook to running instances, as it triggers Chef to execute the specified recipe immediately on the selected instances.

Exam trap

The trap here is that candidates often confuse updating the cookbook source (which only stages the new code) with actually executing the recipes, leading them to choose Option D, which does not apply the changes to running instances.

How to eliminate wrong answers

Option A is wrong because cloning the stack creates a new set of instances, which does not apply changes to the existing instances and introduces unnecessary overhead. Option C is wrong because updating the layer's custom cookbook settings only changes the source for future instance provisioning or updates, and rebooting instances does not automatically run the updated recipes; it merely restarts the OS without executing Chef. Option D is wrong because updating the stack's custom cookbook source and clicking 'Update Dependencies' only refreshes the cookbook cache on the instances but does not automatically execute the updated recipes; a separate 'Execute Recipes' action is required to apply the changes.

926
MCQmedium

A DevOps engineer is designing a CI/CD pipeline for a microservices application using AWS CodePipeline. Each microservice has its own CodeCommit repository. The engineer wants to run unit tests in parallel for all services when any repository receives a push, then run integration tests only after all unit tests pass. Which pipeline structure should the engineer use?

A.Create a single pipeline with a parallel action for unit tests, then a serial stage for integration tests
B.Create a single pipeline with a serial stage for unit tests, then integration tests
C.Create one pipeline per microservice, each triggering integration tests via SNS
D.Use AWS CodeBuild batch builds with a fan-out/fan-in pattern
AnswerA

This design uses CodePipeline stages to gate flow: a stage with parallel unit-test actions runs the per-microservice unit suites concurrently, cutting total test wall-clock time, and the stage only completes when every action succeeds. The subsequent integration-test stage is serial relative to unit tests, so integration testing starts only after all unit suites are green, preserving deterministic dependency ordering while still exploiting parallelism where safe.

Why this answer

AWS CodePipeline supports parallel actions within a stage, allowing unit tests for all microservices to run concurrently. After all unit tests succeed, the pipeline transitions to a serial stage for integration tests, ensuring the correct dependency order. This structure minimizes build time while enforcing the required sequential gate.

Exam trap

The trap here is that candidates often confuse parallel actions within a stage with parallel stages, or assume that separate pipelines are needed for each microservice, overlooking CodePipeline's ability to run multiple actions concurrently in a single stage.

How to eliminate wrong answers

Option B is wrong because it runs unit tests serially, which increases overall pipeline duration unnecessarily since there is no dependency between microservice unit tests. Option C is wrong because creating separate pipelines per microservice prevents a single coordinated integration test stage after all unit tests pass; triggering via SNS would require custom orchestration and lose CodePipeline's built-in state management. Option D is wrong because AWS CodePipeline does not natively support fan-out/fan-in patterns; CodeBuild batch builds can parallelize builds but lack the stage-level dependency control needed to run integration tests only after all unit tests complete.

927
MCQhard

A company uses AWS CodeBuild to run integration tests as part of a pipeline. The tests require access to an Amazon RDS database. The RDS instance is in a private subnet with no public access. The CodeBuild project is configured with a VPC. Which additional configuration is necessary to ensure the build can connect to the database?

A.Add an IAM policy that grants the CodeBuild service role access to the RDS instance.
B.Configure the security group for the RDS instance to allow inbound traffic from the security group associated with the CodeBuild project.
C.Create a VPC endpoint for Amazon RDS.
D.Attach a NAT gateway to the private subnet.
AnswerB

The RDS instance's security group must have an inbound rule that allows TCP traffic on the database port (e.g., 3306, 5432) from the security group ID attached to the CodeBuild project's elastic network interface. This is the standard way to permit traffic between AWS resources within a VPC, because security group rules reference other security groups as sources. The CodeBuild project must also be configured with VPC settings (VPC ID, subnets, and security groups) so its ENI is placed in the same network context as the RDS instance, enabling the security group-to-security group allow.

Why this answer

The CodeBuild project is configured with a VPC, meaning it runs inside a private subnet and uses an elastic network interface (ENI) with an associated security group. To allow the build container to connect to the RDS instance, the RDS security group must have an inbound rule that permits traffic on port 3306 (or the appropriate database port) from the CodeBuild security group. This is a standard network-layer access control; no additional IAM or gateway is required for connectivity.

Exam trap

The trap here is that candidates confuse IAM permissions (which control API access) with network security group rules (which control traffic flow), leading them to select Option A, or they mistakenly think a VPC endpoint is needed for database connectivity when it is only for API calls.

How to eliminate wrong answers

Option A is wrong because IAM policies control authentication and authorization for AWS API calls, not network-level traffic; RDS security groups control inbound traffic at the network layer, and IAM does not open ports. Option C is wrong because a VPC endpoint for RDS is used to access the RDS API (e.g., to modify DB instances) from within a VPC without internet traffic, not to connect to the database engine itself; database connections use the database port, not the RDS API endpoint. Option D is wrong because a NAT gateway provides outbound internet access for private subnets, but the RDS instance is in the same VPC, so traffic between CodeBuild and RDS stays within the VPC and does not require internet access.

928
MCQhard

Refer to the exhibit. A developer is using this buildspec.yml in AWS CodeBuild to build and push a Docker image to Amazon ECR. The build fails with the error: 'Error: No region specified'. Which change should the developer make to resolve this error?

A.Add a pre_build command to export AWS_DEFAULT_REGION using the AWS CLI.
B.Set the AWS_DEFAULT_REGION environment variable in the CodeBuild project's environment configuration.
C.Replace $AWS_DEFAULT_REGION with a hardcoded region like us-east-1.
D.Use the AWS_REGION environment variable instead of AWS_DEFAULT_REGION in the buildspec.
AnswerB

Setting AWS_DEFAULT_REGION in the CodeBuild project's environment configuration is the correct fix because CodeBuild injects all project-level environment variables into every phase of the build, making the value available to the AWS CLI, SDKs, and all build commands without any buildspec changes. This approach is explicit, portable, and aligns with AWS best practices for configuring tooling at the project level rather than relying on phase-scoped shell exports.

Why this answer

The error occurs because the $AWS_DEFAULT_REGION environment variable is not set in the CodeBuild project. The developer must explicitly set the AWS_DEFAULT_REGION environment variable in the CodeBuild project configuration.

929
Multi-Selecteasy

A company uses AWS CodePipeline to automate their software release process. They want to add a stage that runs security scanning on the code before deployment. Which two AWS services can be integrated into the pipeline for this purpose? (Choose TWO.)

Select 2 answers
A.Amazon Inspector
B.Amazon GuardDuty
C.Amazon Detective
D.AWS CodeBuild
E.AWS CodeDeploy
AnswersA, D

Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure. Its CodePipeline integration uses the Inspector Scan action to automatically inspect container images stored in Amazon ECR during the pipeline, blocking deployment if critical findings are discovered. This catches CVE-level issues in dependencies and OS packages before release, making it a direct preventive control.

Why this answer

Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure. It can be integrated into a CodePipeline stage to perform automated security scanning on the code or infrastructure before deployment, helping to identify issues early in the SDLC.

Exam trap

The trap here is that candidates often confuse Amazon Inspector (a vulnerability scanner for workloads) with Amazon GuardDuty (a threat detector for account activity), or assume that AWS CodeDeploy includes built-in security scanning capabilities, when in fact it only handles deployment orchestration.

930
MCQmedium

A DevOps engineer is reviewing the IAM policy attached to a CodeBuild service role. The policy allows starting builds and viewing logs. However, when CodeBuild tries to download artifacts from an S3 bucket in the same account, it fails with an access denied error. What is the missing permission?

A.s3:GetObject
B.kms:Decrypt
C.s3:PutObject
D.logs:DescribeLogGroups
AnswerA

To download an object from an S3 bucket, the calling principal must be granted the s3:GetObject action. Without this permission, S3 returns an AccessDenied error even if other S3 actions like ListBucket or PutObject are allowed, so adding s3:GetObject is the minimal and correct fix for a build process that retrieves artifacts.

Why this answer

The error occurs because CodeBuild needs to download artifacts from S3, which requires the s3:GetObject permission on the bucket or object. Without this permission, the service role cannot read the artifact files, even though it can start builds and view logs. The s3:GetObject action is the specific permission that grants read access to S3 objects.

Exam trap

The trap here is that candidates may confuse s3:GetObject with s3:PutObject or assume KMS decryption is always required, but the direct cause is the lack of read access to the S3 object.

How to eliminate wrong answers

Option B is wrong because kms:Decrypt is only needed if the S3 bucket uses server-side encryption with AWS KMS (SSE-KMS), but the question does not mention encryption, so the missing permission is not KMS-related. Option C is wrong because s3:PutObject is for uploading objects to S3, not downloading them; the error is about downloading artifacts, not uploading. Option D is wrong because logs:DescribeLogGroups is for listing CloudWatch log groups, which is unrelated to S3 access; it would not cause an S3 access denied error.

931
MCQmedium

A DevOps engineer is creating a CloudFormation template that includes an AWS Lambda function. The function code is stored in an S3 bucket. The engineer wants to ensure that the Lambda function is updated whenever the code in S3 changes. What should the engineer do?

A.Use AWS CodeDeploy to deploy the Lambda function
B.Reference the S3 object version in the Lambda function's Code property to force an update when the version changes
C.Add a DependsOn clause to the Lambda function resource
D.Use AWS CodePipeline to automatically update the stack when the S3 object changes
AnswerB

In a CloudFormation template, the Lambda function's Code property, when referencing an S3 bucket, can include the S3ObjectVersion attribute. Because CloudFormation treats any template property change as a stack update trigger, explicitly specifying the object version creates a new template value whenever the zip file in S3 is modified. Without this version, CloudFormation compares only the bucket and key, both of which stay constant, so it considers the resource unrmodified and skips the Lambda update—even if the S3 object's contents were replaced. Adding the S3ObjectVersion forces a resource replacement or update, making it the simplest and most direct way to ensure the stack updates on code changes.

Why this answer

Referencing the S3 object version in the Lambda function's Code property (e.g., `S3ObjectVersion`) creates a dependency on that specific version. When the S3 object is updated, its version changes, which triggers CloudFormation to detect a change in the template and update the Lambda function during the next stack update. This ensures the function code is refreshed without manual intervention.

Exam trap

The trap here is that candidates assume any automation tool (CodePipeline or CodeDeploy) can replace the need for explicit version tracking, but CloudFormation requires a property change to trigger an update, and only referencing the S3 object version achieves that directly.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a deployment service for managing traffic shifting and rollbacks, not a mechanism to detect S3 object changes and trigger CloudFormation updates. Option C is wrong because a DependsOn clause only controls resource creation order, not update triggers based on S3 object version changes. Option D is wrong because AWS CodePipeline can automate stack updates, but it requires an external trigger (e.g., S3 event notification or webhook) and does not inherently detect S3 object version changes to update the Lambda function directly.

932
MCQmedium

A company uses AWS CloudTrail to monitor API activity. During an incident, they need to quickly identify any unauthorized IAM role assumption attempts. Which CloudTrail feature should be used to filter and alert on this specific event?

A.Configure VPC Flow Logs to capture traffic to the IAM endpoint.
B.Use S3 event notifications on the CloudTrail bucket for PutObject events.
C.Set up a CloudWatch Logs metric filter on the CloudTrail log group for 'AssumeRole' events.
D.Enable CloudTrail Insights to detect anomalous AssumeRole events.
AnswerD

CloudTrail Insights is the correct choice because it automatically applies machine learning to management events, including IAM AssumeRole, to establish a normal baseline and flag anomalous activity. It requires no manual filter definitions—you simply enable Insights on the trail, and it begins detecting unusual API call rates or error rates, logging them as separate Insights events. This is purpose-built for identifying abnormal role assumption patterns, such as an unexpected spike in AssumeRole calls or a new principal assuming roles outside its normal context.

Why this answer

CloudTrail Insights automatically analyzes management events to detect unusual activity, such as spikes in AssumeRole calls, without requiring manual filter configuration. This feature uses machine learning to establish a baseline and then alerts on deviations, making it ideal for quickly identifying unauthorized role assumption attempts during an incident.

Exam trap

The trap here is that candidates often assume a CloudWatch Logs metric filter (Option C) is the only way to detect specific events, but they overlook that CloudTrail Insights provides automated anomaly detection without requiring manual filter creation, which is faster during an incident.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) at the VPC level, not IAM API calls or CloudTrail events; they cannot filter on specific IAM actions like AssumeRole. Option B is wrong because S3 event notifications on the CloudTrail bucket for PutObject events would trigger on every log file delivery, not on specific event types within those logs, leading to excessive noise and no filtering capability. Option C is wrong because CloudTrail logs are delivered to a CloudWatch Logs log group only if explicitly configured, and a metric filter on that log group for 'AssumeRole' events would require manual setup and ongoing maintenance, whereas the question asks for a feature that can be used quickly during an incident without pre-configuration.

933
MCQeasy

A DevOps engineer needs to manage the configuration of a large number of EC2 instances that are part of a cluster. The instances should have consistent software packages, services, and settings. The engineer wants to use a configuration management tool that integrates with AWS and supports a push-based model. Which service should be used?

A.AWS OpsWorks Stacks
B.AWS CodeCommit
C.AWS Systems Manager Run Command
D.AWS CloudFormation
AnswerC

AWS Systems Manager Run Command is a capability of AWS Systems Manager that lets you securely push commands to managed EC2 instances and on-premises machines without requiring SSH, RDP, or bastion hosts. The SSM Agent polls for commands, executes them, and can report status back, enabling admins to run scripts, install software, or change system settings across a fleet. Features such as tag-based targets, rate controls, and integration with IAM make it specifically designed for this kind of on-demand configuration activity.

Why this answer

AWS Systems Manager Run Command is the correct choice because it provides a push-based configuration management model that allows you to remotely and securely execute commands or scripts across a large fleet of EC2 instances without needing SSH access. It integrates natively with AWS, supports consistent software package installation and service management via SSM documents, and is ideal for maintaining configuration consistency in a cluster.

Exam trap

The trap here is that candidates confuse 'push-based' with agentless models or assume OpsWorks (which uses Chef/Chef push) is push-based, but OpsWorks Stacks primarily relies on pull-based Chef agents, whereas Systems Manager Run Command is the true push-based service for ad-hoc or scheduled configuration tasks.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks Stacks uses a pull-based model (Chef or Puppet agents on instances pull configuration from a central server) rather than a push-based model. Option B is wrong because AWS CodeCommit is a source control service for storing code and configuration files, not a configuration management tool for applying settings to EC2 instances. Option D is wrong because AWS CloudFormation is an Infrastructure as Code (IaC) service for provisioning and managing AWS resources declaratively, not for performing ongoing configuration management or push-based command execution on running instances.

934
Multi-Selecteasy

A DevOps engineer is troubleshooting an issue where an EC2 instance in a private subnet cannot reach the internet. The instance has a route to a NAT gateway. Which TWO of the following should the engineer check? (Choose TWO.)

Select 2 answers
A.The NAT gateway is in the same subnet as the instance
B.The route table of the private subnet has a route to the NAT gateway
C.The internet gateway is attached to the private subnet
D.The instance has a public IP address
E.The security group allows outbound traffic to the internet
AnswersB, E

For a private subnet to reach the internet via a NAT gateway, its route table must contain a route with a destination of 0.0.0.0/0 and a target of the NAT gateway's ID. This route tells the instance's traffic to be forwarded to the NAT gateway, which then performs source NAT using its Elastic IP. Without this specific route, the instance's outbound packets have no defined next hop to the internet, causing connectivity to fail.

Why this answer

Option B is correct because the private subnet's route table must contain a specific route (typically 0.0.0.0/0) pointing to the NAT gateway; without this route, traffic from the instance will never be forwarded to the NAT gateway even if one exists. Option E is correct because security groups are stateful and must have an outbound rule permitting the traffic (e.g., HTTPS/443 or HTTP/80) to the internet; a restrictive outbound rule will silently drop the packets before they leave the instance. Option A is incorrect because a NAT gateway must reside in a public subnet, not the same private subnet as the instance, and it is associated via the route table rather than subnet co-location.

Option C is incorrect because an internet gateway attaches to a VPC, not to a subnet, and private subnets should not have a direct route to an internet gateway. Option D is incorrect because instances in private subnets should not have public IP addresses; outbound internet access via a NAT gateway does not require the instance to have a public IP.

Exam trap

DOP-C02 often tests the misconception that a NAT gateway must be in the same subnet as the instance, or that the instance needs a public IP — both are false, and candidates who confuse NAT gateway placement with instance placement pick the wrong options.

935
Multi-Selecthard

A company uses AWS CodePipeline to deploy a serverless application using AWS SAM. The pipeline includes a build stage that runs 'sam build' and a deploy stage that runs 'sam deploy'. The team wants to automatically test the deployed application before promoting it to production. Which THREE steps should be included in the pipeline?

Select 3 answers
A.Add a stage that runs a performance or load test.
B.Add a stage that automatically rolls back the deployment if tests fail.
C.Add a manual approval stage after testing before promoting to production.
D.Add a stage that deploys the application to a separate production environment.
E.Add a stage after deployment that runs integration tests against the deployed API.
AnswersA, C, E

Running a performance/load test stage (e.g., using AWS CodeBuild with Apache JMeter or Artillery against the deployed API endpoint) validates that the serverless application can sustain expected concurrency and throughput without exceeding Lambda concurrency limits or API Gateway throttling quotas. It catches issues like cold start latency, inadequate memory allocation, or downstream dependency bottlenecks that unit tests miss. In serverless, load tests also confirm that provisioned concurrency or auto-scaling behavior works as intended under spike traffic.

Why this answer

Adding a performance or load test stage after deployment validates that the serverless application can handle expected traffic volumes under AWS SAM's provisioned concurrency and scaling limits. This ensures the application meets non-functional requirements before promotion, catching issues like cold start latency or throttling that unit tests miss.

Exam trap

The trap here is that candidates confuse automatic rollback (Option B) with a valid pipeline step, but AWS CodePipeline requires explicit actions for rollback, and the question specifically asks for steps to include, not automated recovery mechanisms.

936
Multi-Selecteasy

A DevOps team is implementing a CI/CD pipeline for a microservices application deployed on Amazon ECS. They want to automatically build, test, and deploy container images to Amazon ECR and then update the ECS service. Which TWO steps are essential to achieve this goal?

Select 2 answers
A.Use AWS CodeDeploy to update the ECS service with a new task definition.
B.Use AWS Secrets Manager to store Docker credentials.
C.Use AWS CodeBuild to build the Docker image and push it to Amazon ECR.
D.Use AWS X-Ray for tracing.
E.Use Amazon CodeGuru for code review.
AnswersA, C

AWS CodeDeploy provides a native ECS deployment mechanism that can shift traffic from the old to the new task definition using blue/green or rolling configurations with an Application Load Balancer. In a CodePipeline-based CI/CD flow, this is the deployment action that makes the newly built image actually run on the ECS service, so it is essential to the pipeline.

Why this answer

AWS CodeDeploy is the native AWS service for managing ECS rolling or blue/green deployments. It orchestrates the creation of a new ECS task definition, registers it, and updates the ECS service to use the new task definition, ensuring zero-downtime deployments. Option C is correct because AWS CodeBuild can execute build commands from a buildspec.yml file to build a Docker image and push it to Amazon ECR using the built-in AWS CLI or Docker commands, which is a fundamental step in a CI/CD pipeline for containerized applications.

Exam trap

The trap here is that candidates may confuse AWS CodeDeploy with AWS CodePipeline or AWS CloudFormation for updating ECS services, but CodeDeploy is the specific service designed for controlled ECS deployments with traffic shifting and rollback capabilities.

937
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team needs to deploy a stack that includes a Lambda function and an S3 bucket. The Lambda function's code is stored in the S3 bucket. How can the team ensure that the Lambda function is created after the S3 bucket and the code is uploaded?

A.Upload the code to the S3 bucket before creating the stack.
B.Use the Fn::GetAtt intrinsic function to retrieve the bucket name.
C.Define the S3 bucket resource before the Lambda function resource in the template.
D.Use the DependsOn attribute on the Lambda function to depend on the S3 bucket.
AnswerD

The DependsOn attribute explicitly declares a dependency edge from the Lambda function back to the S3 bucket, forcing CloudFormation to wait until the bucket resource has reached CREATE_COMPLETE before it starts provisioning the Lambda function. This is the definitive way to guarantee creation order, especially when the function needs the bucket to exist for side effects such as populating an environment variable, writing to the bucket, or associating permissions, and no implicit dependency exists in the template. Unlike implicit references, DependsOn works even if the bucket is not directly referenced in any property of the Lambda function, making it the correct answer.

Why this answer

The DependsOn attribute explicitly instructs CloudFormation to create the S3 bucket before the Lambda function. Even though CloudFormation automatically determines resource dependencies for certain intrinsic functions, it does not infer dependencies based on code uploads. Using DependsOn ensures the bucket exists and the code is uploaded before the Lambda function is created, preventing a deployment failure when the Lambda references code that is not yet available.

Exam trap

The trap here is that candidates assume CloudFormation automatically orders resources based on template order or implicit references like Fn::GetAtt, but it does not infer dependencies from code uploads or resource definition order, so explicit DependsOn is required for non-attribute-based dependencies.

How to eliminate wrong answers

Option A is wrong because it requires manual intervention outside of the CloudFormation stack, breaking the principle of infrastructure as code and making the deployment non-repeatable and error-prone. Option B is wrong because Fn::GetAtt retrieves an attribute of a resource (e.g., the bucket ARN) but does not create a dependency that ensures the bucket is fully created and the code is uploaded before the Lambda function is created. Option C is wrong because the order of resource definitions in the template does not guarantee creation order; CloudFormation may create resources in parallel or in a different order unless explicit dependencies are defined.

938
MCQhard

A company is running a critical application on Amazon ECS with Fargate. The application generates custom metrics that are published to CloudWatch using the PutMetricData API. Recently, the metrics have been delayed by up to 5 minutes. The DevOps team needs to reduce the latency. What should the team do?

A.Install the CloudWatch agent on the Fargate tasks to collect metrics.
B.Set the StorageResolution parameter to 1 when calling PutMetricData.
C.Publish the metrics as structured logs to CloudWatch Logs and use metric filters.
D.Increase the frequency of PutMetricData calls to every 5 seconds.
AnswerB

Calling PutMetricData with StorageResolution=1 creates a high-resolution custom metric with 1-second granularity, making the data available for CloudWatch alarms in as little as 10 seconds instead of the 60-second standard resolution. This lower storage resolution is the key to detecting critical issues faster because CloudWatch can evaluate alarms at a 10- or 30-second period. Without this parameter, your metrics default to 60-second resolution and alarm latency remains as high as a minute.

Why this answer

Setting the StorageResolution parameter to 1 when calling PutMetricData enables high-resolution metrics with a 1-second granularity. This reduces the latency of metric ingestion and retrieval because CloudWatch processes high-resolution metrics more quickly than standard 60-second resolution metrics, addressing the 5-minute delay.

Exam trap

The trap here is that candidates may think increasing API call frequency or using log-based metrics will reduce latency, but the actual cause is the default 60-second storage resolution, which delays metric availability regardless of how often data is sent.

How to eliminate wrong answers

Option A is wrong because the CloudWatch agent cannot be installed on Fargate tasks; Fargate is a serverless compute engine that does not allow direct installation of agents, and metrics are already being published via PutMetricData, so the agent is unnecessary. Option C is wrong because publishing metrics as structured logs and using metric filters adds additional processing overhead and latency from log ingestion and filter evaluation, which would not reduce the delay and may increase it. Option D is wrong because increasing the frequency of PutMetricData calls to every 5 seconds does not change the resolution or ingestion latency; it may cause throttling from CloudWatch API limits and does not address the underlying delay caused by standard-resolution metric processing.

939
Multi-Selectmedium

A DevOps engineer needs to set up a monitoring solution that can detect and alert on unusual patterns in application metrics. Which TWO AWS services can be used together to achieve this? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty
B.Amazon CloudWatch Alarms
C.Amazon CloudWatch Anomaly Detection
D.AWS CloudTrail
E.AWS Config
AnswersB, C

Amazon CloudWatch Alarms are the action engine that watches a single CloudWatch metric, a math expression, or an anomaly detection band over a specified time period, then transitions to an ALARM state when the observed value breaches a defined threshold. You can configure the alarm to publish to an SNS topic, trigger Auto Scaling, or execute an EC2 action such as a reboot when the anomaly condition persists. In this solution, the alarm consumes the band produced by CloudWatch Anomaly Detection and calls the monitoring hook when unusual metric behavior is detected.

Why this answer

Amazon CloudWatch Anomaly Detection [CORRECT] is correct because it applies machine-learning algorithms to a metric's historical baseline and creates an expected-value band, so it can flag unusual patterns in application metrics without requiring manually tuned static thresholds. Amazon CloudWatch Alarms [CORRECT] is correct because it evaluates a metric or an anomaly-detection band against a defined condition and triggers actions such as Amazon SNS notifications, making it the alerting mechanism that works together with anomaly detection. Used together, Anomaly Detection identifies the deviation and CloudWatch Alarms fires the alert, which directly satisfies the requirement to detect and alert on unusual metric patterns.

Amazon GuardDuty is a threat-detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity, not application metric patterns. AWS CloudTrail records API activity for auditing and governance, and AWS Config evaluates resource configuration compliance, so neither detects anomalies in application metrics or sends metric-based alerts.

Exam trap

DOP-C02 often tests the confusion between security monitoring services (GuardDuty, CloudTrail) and performance monitoring services (CloudWatch), where candidates incorrectly select security tools for anomaly detection in application metrics.

940
MCQmedium

A DevOps engineer needs to enforce encryption in transit for all traffic between a fleet of EC2 instances and an Application Load Balancer (ALB). The ALB is configured with a TLS listener. Which step should the engineer take to ensure end-to-end encryption?

A.Configure the target group to use HTTP protocol
B.Configure the target group to use HTTPS protocol and install a certificate on each EC2 instance
C.Use security group rules to enforce encryption
D.Terminate TLS at the ALB and use HTTP to instances
AnswerB

Configuring the target group for HTTPS forces the ALB to negotiate a TLS session with each EC2 instance, so backend traffic is encrypted as well. Each instance must present a valid certificate that the ALB trusts, typically installed on the instance's web server or TLS terminator, to complete the handshake. This provides encryption in transit across both the client-to-ALB and ALB-to-instance segments.

Why this answer

To enforce end-to-end encryption between the ALB and EC2 instances, the target group must use HTTPS protocol. This requires each EC2 instance to have a TLS certificate installed so that traffic from the ALB to the instances is encrypted. Option A is incorrect because HTTP does not encrypt traffic.

Option C is incorrect because security groups control network access but do not enforce encryption. Option D is incorrect because terminating TLS at the ALB and using HTTP to instances would leave the traffic between ALB and instances unencrypted.

941
Multi-Selecteasy

A DevOps engineer wants to monitor the health of an Auto Scaling group and receive notifications when instances are launched or terminated. Which TWO AWS services can be used together to achieve this?

Select 2 answers
A.AWS CloudTrail.
B.AWS Config.
C.Amazon EventBridge.
D.Amazon SNS.
E.AWS Lambda.
AnswersC, D

Amazon EventBridge is a serverless event bus that can natively consume Auto Scaling group state changes such as EC2 instance launch, terminate, and lifecycle hook notifications. Using event patterns that filter on the aws.autoscaling source and detail types like EC2 Instance Launch Successful, EventBridge matches relevant events in near real time and routes them to targets such as SNS topics for email/SMS alerts. It is the correct service because it provides built-in event ingestion, filtering, and routing without requiring custom code or external monitoring agents, making it ideal for health and lifecycle monitoring.

Why this answer

Amazon EventBridge (option C) is correct because it can capture Auto Scaling group state-change events such as EC2 Instance Launch Successful and EC2 Instance Terminate Successful, and route them to a target for notification. Amazon SNS (option D) is correct because it serves as the notification target, delivering email, SMS, or HTTP messages to subscribers when EventBridge matches those Auto Scaling events. Together, EventBridge detects the launch/termination events and SNS publishes the alerts, which is exactly the monitoring-and-notification pattern requested.

AWS CloudTrail (A) only records API activity for auditing and does not natively push notifications, AWS Config (B) evaluates resource compliance and configuration history rather than real-time launch/terminate alerts, and AWS Lambda (E) is a compute target that could process events but is not itself a notification service.

Exam trap

The trap is selecting CloudTrail or Config for event notifications — candidates confuse auditing/compliance services with real-time event routing and notification, which is EventBridge + SNS.

942
MCQeasy

A company uses AWS Secrets Manager to store database credentials. The security team wants to automatically rotate secrets every 30 days. The database is an Amazon RDS for PostgreSQL instance. The team has configured automatic rotation with a Lambda function that updates the password in RDS and Secrets Manager. However, after the first rotation, the application starts getting database connection errors. The application uses a connection string with the secret ARN and retrieves the secret from Secrets Manager at startup using the AWS SDK. Which of the following is the most likely cause of the connection errors?

A.The Lambda function is not configured with a sufficient timeout and is being throttled.
B.The application caches the secret at startup and does not refresh it after rotation.
C.The Lambda function does not have permission to update the secret in Secrets Manager.
D.The RDS instance has automatic password rotation enabled, which conflicts with Secrets Manager rotation.
AnswerB

The application reads the secret once at startup and holds it in memory, so after rotation the cached credentials no longer match the new RDS password, producing authentication failures. Refreshing the secret from Secrets Manager on each connection, or handling rotation-aware retrieval, resolves the connection errors.

Why this answer

If the application caches the secret at startup, it will not retrieve the updated password after rotation, causing connection errors. Option A is incorrect because a Lambda timeout or throttling would prevent the rotation from completing, but the rotation succeeded (new password set), so the issue is on the application side. Option C is incorrect because if the Lambda lacked permissions to update the secret, the rotation would have failed entirely, not just after the first rotation.

Option D is incorrect because Amazon RDS does not have built-in automatic password rotation; Secrets Manager manages the rotation, so there is no conflict.

943
MCQhard

A company runs a web application on EC2 instances behind an Application Load Balancer. They use Amazon CloudFront for content delivery. The DevOps team notices that some requests are returning HTTP 503 errors intermittently. After checking the CloudFront and ALB logs, they find that the errors originate from the ALB. What is the most likely cause?

A.The SSL certificate on the ALB is expired.
B.The security group for the ALB is blocking traffic from CloudFront.
C.CloudFront is configured to forward an HTTP method that the ALB does not support.
D.The ALB is experiencing a surge in traffic and is scaling up, but during the scaling activity, some requests are rejected.
AnswerD

An ALB returns 503 Service Unavailable when it cannot handle incoming requests due to scaling activity or when all targets are unhealthy. During a traffic surge, the ALB nodes scale up by provisioning additional capacity, and during this scaling activity the ALB may temporarily reject or fail to accept new requests, causing clients to receive 503 responses. This matches the scenario described, making it the correct explanation for the issue.

Why this answer

When an Application Load Balancer (ALB) experiences a sudden surge in traffic that exceeds its current capacity, it may temporarily reject requests with HTTP 503 errors while it scales up. During the scaling activity, the ALB's target group might not have enough healthy registered targets to handle the load, causing the ALB to return 503 responses until new instances are provisioned and pass health checks. This matches the intermittent nature of the errors described in the scenario.

Exam trap

The trap here is that candidates often confuse 503 errors with SSL certificate issues or security group misconfigurations, but the intermittent nature of the errors and the fact that they originate from the ALB (not CloudFront) points directly to capacity scaling limitations rather than configuration errors.

How to eliminate wrong answers

Option A is wrong because an expired SSL certificate on the ALB would cause SSL/TLS handshake failures (e.g., ERR_CERT_DATE_INVALID) and result in 502 Bad Gateway errors from CloudFront, not 503 errors from the ALB. Option B is wrong because if the security group for the ALB were blocking traffic from CloudFront, the ALB would not receive the requests at all, and CloudFront would return 502 errors (or connection timeouts) instead of the ALB returning 503 errors. Option C is wrong because CloudFront forwarding an unsupported HTTP method would cause the ALB to return a 405 Method Not Allowed error, not a 503 Service Unavailable error.

944
MCQmedium

A Lambda function processes SQS messages but sometimes times out after 15 seconds. The function performs a database call that occasionally takes longer. What is the best way to handle this without losing messages?

A.Decrease the SQS visibility timeout to retry faster.
B.Split the batch into smaller batches using partial batch response.
C.Increase the Lambda timeout and increase the SQS visibility timeout, and add a dead-letter queue.
D.Reduce the Lambda reserved concurrency to limit invocations.
AnswerC

The correct remediation is to first raise the Lambda timeout to a value that comfortably covers the actual processing duration for a batch, then set the SQS visibility timeout to at least that same timeout so the queue does not redeliver a message while the function is still processing it. Adding a dead-letter queue to the source SQS provides a safety net: after the configured retries (maxReceiveCount), messages that still fail are diverted to the DLQ, preserving them for analysis instead of silently expiring. This combination directly resolves the timeout issue and handles residual failures cleanly.

Why this answer

The root cause is that the Lambda timeout (15s) is shorter than the occasional database call, and the SQS visibility timeout is likely too short to cover the retry window. Increasing the Lambda timeout gives the function room to finish, increasing the SQS visibility timeout prevents other consumers from picking up the message while it is still being processed, and a dead-letter queue captures messages that repeatedly fail so they are not lost. This combination preserves at-least-once delivery and prevents message loss.

Exam trap

DOP-C02 often tests the relationship between Lambda timeout and SQS visibility timeout — candidates who only increase one or forget the DLQ pick an incomplete fix.

How to eliminate wrong answers

Option A is wrong because decreasing the visibility timeout makes messages visible sooner, causing duplicate processing and potentially more timeouts, not fewer. Option B is wrong because partial batch response helps with batch-level failures but does not address the underlying timeout or the risk of message loss when the visibility timeout expires mid-processing. Option D is wrong because reducing reserved concurrency throttles invocations and can cause SQS messages to age out or hit the DLQ, but it does not fix the timeout root cause.

945
Multi-Selecteasy

A company is designing a CI/CD pipeline for a serverless application using AWS CodePipeline. Which TWO actions are valid ways to deploy an AWS Lambda function?

Select 2 answers
A.Use AWS CloudFormation to update the Lambda function's stack.
B.Use Amazon S3 to trigger the Lambda function deployment.
C.Use AWS CodeBuild to directly deploy the Lambda function.
D.Use AWS CodeCommit to push the Lambda code.
E.Use AWS CodeDeploy to deploy the Lambda function with traffic shifting.
AnswersA, E

CloudFormation is an infrastructure-as-code service that declares the entire serverless application stack, including the Lambda function, IAM role, event source mappings, and environment variables. Updating the stack applies code and configuration changes in a deterministic order and supports rollback on failure, making it a valid CI/CD deployment step. It treats the Lambda function as a managed resource, and can be invoked via CodePipeline or directly. This is a correct approach because it ensures drift-free, auditable releases.

Why this answer

AWS CloudFormation can manage Lambda function deployments as part of a stack update. By defining the Lambda function resource in a CloudFormation template, CodePipeline can trigger a stack update that creates or updates the function, ensuring infrastructure-as-code best practices and consistent deployments.

Exam trap

The trap here is that candidates often confuse build or source control actions (CodeBuild, CodeCommit) with deployment actions, or mistake event-driven invocations (S3 triggers) for deployment mechanisms, leading them to select options that are valid for other purposes but not for deploying Lambda functions.

946
MCQeasy

A company runs a web application on EC2 instances behind an ALB. To improve resilience, they want to automatically replace failed instances and maintain a minimum number of instances. Which AWS service should be used?

A.Amazon EC2 Auto Scaling
B.AWS CloudFormation
C.AWS Elastic Beanstalk
D.AWS Systems Manager
AnswerA

Amazon EC2 Auto Scaling is the service that continuously monitors the health of EC2 instances using EC2 status checks and, when configured, Elastic Load Balancing health checks. If an instance fails these checks, Auto Scaling automatically terminates it and launches a replacement instance to maintain the desired or minimum fleet size. This health-based replacement is an inherent capability of an Auto Scaling group, making it the correct answer for automatically replacing unhealthy instances.

Why this answer

Amazon EC2 Auto Scaling is purpose-built to maintain a desired/minimum number of instances and automatically replace unhealthy ones via health checks integrated with ELB. It continuously monitors instance health and launches replacements when instances fail, ensuring the minimum capacity is preserved. This directly satisfies the resilience requirement without manual intervention.

Exam trap

DOP-C02 often tests the misconception that CloudFormation or Elastic Beanstalk 'does' auto scaling, when in fact Auto Scaling is the underlying service and the others merely orchestrate it — candidates must pick the service that directly provides the capability.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation is an infrastructure-as-code provisioning service — it can create an Auto Scaling group but does not itself perform health-based replacement or maintain minimum instance counts at runtime. Option C is wrong because Elastic Beanstalk is a PaaS layer that abstracts deployment; while it uses Auto Scaling under the hood, it is not the direct service for configuring automatic instance replacement and minimum capacity. Option D is wrong because AWS Systems Manager is for operational management (patching, run commands, parameter store) and does not provide automatic scaling or health-based instance replacement.

947
MCQmedium

A development team is using AWS CodeCommit as a source repository and AWS CodePipeline to automate their CI/CD pipeline. The pipeline includes a build stage that runs on AWS CodeBuild. The team wants to automatically trigger the pipeline when changes are pushed to the 'develop' branch of the CodeCommit repository. Which configuration change should be made to the pipeline?

A.Enable S3 event notifications on the repository to invoke the pipeline.
B.Add a manual approval action before the build stage.
C.Configure the source action to use CodeCommit as the source provider and specify the 'develop' branch.
D.Create a CodeBuild webhook on the CodeCommit repository.
AnswerC

Configuring the source action with CodeCommit as the source provider and specifying the 'develop' branch is exactly how CodePipeline implements automatic change detection for a CodeCommit repository. The action references the repository and branch; on each update to that branch, CodePipeline uses an automatically managed CloudWatch Events rule (or event polling) to trigger a new pipeline execution. This is the recommended native integration, and it ensures every commit to the 'develop' branch starts the pipeline without custom webhooks or manual steps.

Why this answer

CodePipeline's source action can be configured to use CodeCommit as the source provider, and by specifying the 'develop' branch in the source action configuration, the pipeline will automatically start a new execution whenever a change is pushed to that branch. This is the native and recommended way to trigger a pipeline from a CodeCommit repository branch change, without needing additional webhooks or event notifications.

Exam trap

The trap here is that candidates often confuse CodeBuild webhooks (which trigger a build directly) with CodePipeline's native event-driven triggers, leading them to select Option D, even though CodePipeline does not use webhooks for CodeCommit sources.

How to eliminate wrong answers

Option A is wrong because S3 event notifications are not applicable to CodeCommit repositories; CodeCommit uses Git events, not S3 bucket events, and CodePipeline integrates directly with CodeCommit via its source action, not through S3 notifications. Option B is wrong because adding a manual approval action before the build stage would block the pipeline from automatically triggering; it would require manual intervention to proceed, defeating the purpose of automatic triggering on branch pushes. Option D is wrong because CodeBuild webhooks are used to trigger a CodeBuild project directly from a repository, not to trigger a CodePipeline; CodePipeline manages its own polling or event-based triggers for CodeCommit, and creating a separate webhook on CodeCommit would be redundant and not integrated with the pipeline's execution.

948
MCQmedium

A company uses AWS CodePipeline with a multi-branch strategy. The pipeline deploys a Lambda function using CloudFormation. The DevOps engineer notices that when a new branch is created, the pipeline executes but the CloudFormation stack fails because the stack name already exists. What is the MOST efficient way to resolve this issue?

A.Modify the pipeline to use a dynamic stack name parameter, such as the branch name.
B.Hardcode a different stack name for each branch in the pipeline.
C.Delete the existing stack before each deployment.
D.Use the CloudFormation 'Override' parameter to reuse the same stack.
AnswerA

Using a dynamic stack name parameter, such as inserting the branch name into the stack name (e.g., `MyApp-${Branch}`), lets each branch deploy to a unique CloudFormation stack. This isolation prevents resource name collisions when multiple branches are deployed concurrently, supports per-branch rollback and lifecycle management, and eliminates the need to manually reconfigure the pipeline when a new branch is created.

Why this answer

Using a dynamic stack name parameter, such as the branch name, ensures each branch creates a unique CloudFormation stack. This avoids naming conflicts while allowing independent infrastructure per branch. In CodePipeline, you can pass the branch name as a variable (e.g., #{SourceVariables.BranchName}) to the CloudFormation deploy action, making the stack name unique without manual intervention.

Exam trap

The trap here is that candidates may think hardcoding stack names per branch (Option B) is acceptable, but they overlook the operational overhead and lack of automation; AWS expects you to use dynamic parameters to handle multi-branch pipelines efficiently.

How to eliminate wrong answers

Option B is wrong because hardcoding a different stack name for each branch is not scalable or maintainable; it requires manual updates every time a new branch is created, defeating the purpose of a multi-branch pipeline. Option C is wrong because deleting the existing stack before each deployment would destroy the production or main branch stack, causing downtime and loss of stateful resources; it also violates the principle of isolated environments per branch. Option D is wrong because CloudFormation does not have an 'Override' parameter to reuse the same stack; the stack name must be unique within an account and region, and reusing it would still cause a conflict if the stack already exists.

949
MCQeasy

A developer is using AWS CodeBuild to compile code. The build takes a long time because dependencies are downloaded each time. What can the developer do to reduce build time?

A.Split the build into multiple parallel build actions.
B.Use multiple build environments to distribute the work.
C.Enable caching in the build project to store dependencies in Amazon S3.
D.Use a larger compute type for the build project.
AnswerC

Enabling S3 caching in a CodeBuild project stores the dependency cache (e.g., Maven's .m2, npm's node_modules, or Python's pip cache) in an Amazon S3 bucket between builds, so the build only downloads changed or missing packages instead of re-fetching the full dependency set each time. This directly reduces the time spent on network I/O, which is often the dominant cost for builds with many third-party libraries. By setting the 'cache' type to S3 and specifying a bucket, subsequent builds restore the cache at the start, making the compilation faster. This is the recommended approach because it targets the common bottleneck of dependency resolution.

Why this answer

Enabling caching in AWS CodeBuild allows the build project to store frequently downloaded dependencies (e.g., Maven, npm, pip packages) in an Amazon S3 bucket. On subsequent builds, CodeBuild retrieves the cached dependencies from S3 instead of re-downloading them from the internet, which significantly reduces build time. This is the most direct and efficient solution for the described problem of repeated dependency downloads.

Exam trap

The trap here is that candidates often confuse scaling compute resources (Option D) or parallelizing work (Option A) with solving a network-bound dependency download problem, failing to recognize that caching is the only option that directly eliminates redundant downloads.

How to eliminate wrong answers

Option A is wrong because splitting the build into multiple parallel build actions does not address the root cause of repeated dependency downloads; it only parallelizes independent build steps, which may reduce overall wall-clock time but does not eliminate the redundant download overhead. Option B is wrong because using multiple build environments distributes the work across different compute instances but does not cache dependencies; each environment would still download dependencies from scratch, so the total download time remains unchanged. Option D is wrong because using a larger compute type (e.g., more CPU/memory) may speed up the build process itself but does not prevent the repeated download of dependencies; the network-bound download step remains a bottleneck regardless of compute size.

950
MCQeasy

A DevOps engineer is designing a CI/CD pipeline for a microservices application. The team wants to ensure that infrastructure changes are reviewed and approved before deployment. The code is stored in AWS CodeCommit, and the pipeline uses AWS CodePipeline and AWS CloudFormation. What is the BEST way to implement an approval process for infrastructure changes?

A.Use CodeCommit approval rules to require a pull request before any change is merged.
B.Configure IAM policies to require MFA before any CloudFormation stack update.
C.Use CodeBuild to run a script that sends an approval request via Amazon SNS and waits for a response.
D.Add a manual approval step in CodePipeline between the build and deploy stages.
AnswerD

A manual approval action in CodePipeline is a first-class, natively integrated gate that pauses the pipeline execution at a defined stage boundary (e.g., after build, before deploy). When the action runs, CodePipeline sends an SNS notification to the designated approver topic, and the execution remains in a Waiting state until an authorized user explicitly approves or rejects it via the console, CLI, or SDK. This is the intended AWS pattern for a human review gate because it is fully managed, has no custom polling logic, and automatically resumes the pipeline only upon approval — making it superior to any ad-hoc script or external approval mechanism.

Why this answer

A manual approval step in CodePipeline is the native, purpose-built mechanism for gating a pipeline stage on human review. CodePipeline pauses execution and sends an SNS notification to designated approvers; the pipeline resumes only after an approver acts in the console or via the API. This directly satisfies the requirement that infrastructure changes be reviewed and approved before CloudFormation deploys them, and it integrates cleanly with the existing CodeCommit/CodePipeline/CloudFormation toolchain.

Exam trap

DOP-C02 often tests the distinction between repository-level controls (CodeCommit approval rules, pull requests) and pipeline-level controls (manual approval actions), so candidates who conflate 'code review' with 'deployment approval' pick Option A.

How to eliminate wrong answers

Option A is wrong because CodeCommit approval rules govern pull-request merges in the repository, not the deployment of already-merged CloudFormation changes — a change can be approved and merged yet still be deployed without any pipeline-level gate. Option B is wrong because IAM MFA conditions authenticate the caller performing a stack update; they enforce identity strength, not a review-and-approve workflow, and cannot pause a pipeline for a human decision. Option C is wrong because a CodeBuild script that polls SNS for a response is a custom, brittle reimplementation of a feature CodePipeline already provides natively, adding complexity and failure modes without benefit.

951
Multi-Selectmedium

A company runs a stateful web application on EC2 instances behind an ALB. The application stores session data in memory. The company wants to make the application stateless to improve resilience. Which TWO changes should the company make?

Select 2 answers
A.Increase the instance memory to store more sessions
B.Disable sticky sessions on the ALB
C.Enable sticky sessions (session affinity) on the ALB
D.Store session data in Amazon ElastiCache for Redis
E.Use an NLB instead of an ALB
AnswersB, D

Disabling sticky sessions on the ALB is a necessary precondition for a horizontally scalable, fault-tolerant design. With stickiness off, the ALB can route any request to any healthy target, so if an instance fails, the next request can be served by a different instance — assuming the session state is stored externally (for example, in ElastiCache or DynamoDB). This makes the application effectively stateless at the instance level, which also allows Auto Scaling to add or remove instances without worrying about breaking client sessions on a particular host.

Why this answer

To make the application stateless, the company should disable sticky sessions on the ALB (option B) and store session data in Amazon ElastiCache for Redis (option D). Disabling sticky sessions ensures that requests can be routed to any instance, and storing session data externally removes the dependency on in-memory state on individual instances, improving resilience. Option A is incorrect because increasing instance memory does not solve the statefulness issue.

Option C is incorrect because enabling sticky sessions would maintain state on instances. Option E is incorrect because using an NLB does not address session state management.

952
MCQmedium

A company has deployed a containerized application on Amazon ECS with Fargate. The application is fronted by an Application Load Balancer (ALB). The DevOps team is using CloudWatch Container Insights to monitor the ECS cluster. They notice that the 'MemoryUtilized' metric for the service is consistently above 80%, and the 'CPUUtilized' is around 50%. The ALB's 'TargetResponseTime' is increasing over time. The team wants to resolve the performance issue. Which action should the team take?

A.Increase the memory limit for the ECS task definition to allow the container to use more memory.
B.Increase the CPU limit for the ECS task definition to improve performance.
C.Increase the number of ALB targets by adding more availability zones.
D.Increase the desired count of the ECS service to distribute the load across more tasks.
AnswerA

The ECS task definition's memory limit is a hard limit enforced by Docker; when the container's memory utilization consistently exceeds 80%, it is likely approaching or hitting that ceiling, leading to OOM kills or severe performance degradation. Increasing the memory limit lets the container allocate more heap or working set, directly relieving the memory bottleneck. This is a vertical scaling action, and you must also ensure the EC2 instance has enough free memory to support the increased limit.

Why this answer

The metrics show MemoryUtilized consistently above 80% while CPUUtilized is only around 50%, and TargetResponseTime is rising — this is a classic memory-bound bottleneck. When a container approaches its memory limit, the kernel may reclaim page cache, trigger GC pressure, or begin swapping (if enabled), all of which degrade response time. Increasing the memory limit in the task definition gives the container headroom to operate without memory pressure, directly addressing the root cause.

Exam trap

DOP-C02 often tests whether candidates can diagnose the bottleneck from metrics — the trap is picking CPU scaling or horizontal scaling when the data clearly shows memory pressure as the root cause of rising response time.

How to eliminate wrong answers

Option B is wrong because CPUUtilized is only around 50%, so CPU is not the bottleneck — increasing the CPU limit wastes resources and does not address the memory pressure causing the latency. Option C is wrong because adding ALB targets in more availability zones increases redundancy and capacity at the load-balancer level, but the bottleneck is per-task memory, not insufficient targets or AZ coverage. Option D is wrong because scaling out the ECS service adds more tasks, which can help throughput, but each task still hits the same memory ceiling — without raising the memory limit, the underlying per-task memory pressure and rising response time persist.

953
MCQmedium

A DevOps engineer deploys the CloudFormation snippet shown in the exhibit. After the stack is deleted, the engineer checks for the S3 bucket. Which statement best describes the outcome?

A.The bucket is deleted because the stack deletion overrides the DeletionPolicy.
B.The bucket is retained (not deleted) after the stack deletion.
C.The stack deletion fails because the bucket has versioning enabled.
D.The bucket is deleted along with the stack because the DeletionPolicy is not supported for S3 buckets.
AnswerB

When a CloudFormation stack that contains an AWS::S3::Bucket with DeletionPolicy: Retain is deleted, the template's deletion intent is to leave that bucket in place. The bucket, including any objects and versions, remains in your AWS account and is no longer under CloudFormation's management. The stack itself shows DELETE_COMPLETE because CloudFormation treats the Retain policy as a successful completion of the resource deletion step, even though no physical deletion occurred.

Why this answer

S3 bucket versioning has no bearing on this stack's deletion mechanics since the bucket uses DeletionPolicy: Retain, so CloudFormation never attempts to delete the physical bucket. More generally, versioning is a bucket-level data-protection feature; it does not, by itself, cause a CloudFormation stack deletion to fail. However, note that CloudFormation does NOT automatically empty a bucket's object versions and delete markers before deleting it -- if DeletionPolicy were Delete (the default) and the bucket were non-empty (including having any object versions), the stack deletion would fail with a 'bucket not empty' error, requiring a custom resource or manual emptying first.

Because this stack uses Retain, the deletion action is never attempted, so the bucket -- and any versioned objects in it -- persists after the stack is deleted.

Exam trap

The trap here is that candidates assume stack deletion always removes all resources, overlooking that the DeletionPolicy attribute can explicitly override that behavior for supported resource types like S3 buckets.

How to eliminate wrong answers

Option A is wrong because the DeletionPolicy does not get overridden by stack deletion; instead, it is honored to retain the resource. Option C is wrong because enabling versioning on an S3 bucket does not prevent stack deletion or cause it to fail; the DeletionPolicy is the sole factor controlling retention. Option D is wrong because the DeletionPolicy is fully supported for S3 buckets; it is a valid attribute that CloudFormation respects for S3 resources.

954
MCQhard

Refer to the exhibit. Why does the build fail?

A.The CodeBuild role does not have permission to create CloudFront invalidations.
B.The S3 bucket policy denies write access to the CodeBuild role.
C.The CodeBuild project is not associated with the correct service role.
D.The CloudFront distribution ID is incorrect.
AnswerA

The error message in the build log explicitly returns AccessDenied for the CreateInvalidation action, which means the IAM role assumed by CodeBuild does not include a statement allowing cloudfront:CreateInvalidation on the target distribution. Even though the role is correctly associated and used, it lacks this specific identity-based permission, so the aws cloudfront create-invalidation API call fails. This is an IAM policy gap, not a misconfiguration of the project or the distribution.

Why this answer

The build fails because the CodeBuild service role lacks the necessary IAM permission to create a CloudFront invalidation. In AWS CodeBuild, the service role must have explicit permissions for all AWS API calls made during the build, including cloudfront:CreateInvalidation. Without this permission, the AWS CLI command to invalidate the CloudFront distribution returns an AccessDenied error, causing the build to fail.

Exam trap

DOP-C02 often tests the misconception that S3 bucket policies or project role association are the cause of permission errors, when the actual issue is missing specific IAM permissions for the service role.

How to eliminate wrong answers

Option B is wrong because the S3 bucket policy is not the issue; the build likely succeeded in uploading to S3, and the error is related to CloudFront invalidation, not S3 write access. Option C is wrong because the CodeBuild project is associated with a service role (otherwise it couldn't perform any AWS actions), but that role simply lacks the specific CloudFront permission. Option D is wrong because an incorrect CloudFront distribution ID would result in a different error (e.g., NoSuchDistribution), not an access denied error.

955
MCQhard

During a deployment, a new application version on an ECS service starts failing health checks. The previous version is still running. The deployment is a rolling update with a 200% percent start. Which ECS feature should the engineer use to automatically revert to the previous version?

A.ECS deployment circuit breaker
B.ECS service auto recovery
C.ECS managed scaling
D.CloudWatch alarm actions
AnswerA

The ECS deployment circuit breaker is a native ECS feature that continuously monitors the health of a service deployment by watching for failed health checks, crashes, or task startup failures. If it detects that the new version is unhealthy, it automatically cancels the deployment and rolls back the service to the previous stable revision, without manual intervention. This makes it the only option that directly addresses deployment failures as part of the ECS service update path.

Why this answer

(ECS deployment circuit breaker) is correct because it automatically detects failed deployments (e.g., health check failures) and triggers a rollback to the previous version. With a 200% percent start rolling update, the new version starts before the old is stopped; if health checks fail, the circuit breaker initiates a rollback. Option B (ECS service auto recovery) recovers from underlying infrastructure failures, not deployment failures.

Option C (ECS managed scaling) adjusts desired count based on load, not deployment health. Option D (CloudWatch alarm actions) can trigger rollback events but is not an ECS built-in feature; it requires custom automation. Therefore, the correct ECS feature for automatic rollback is the deployment circuit breaker.

956
Multi-Selecthard

Which THREE considerations are important when designing a CI/CD pipeline for a microservices architecture using AWS CodePipeline? (Choose three.)

Select 3 answers
A.All microservices should be deployed using a single pipeline to ensure consistency.
B.Include automated integration tests that validate service-to-service interactions.
C.Use manual approval gates at every stage to ensure quality.
D.Each microservice should have its own pipeline to enable independent deployment.
E.Implement blue/green deployments to reduce downtime and allow quick rollback.
AnswersB, D, E

Automated integration tests that exercise real interactions between services (for example, using contract tests or a dedicated test environment) catch API mismatches, schema changes, and network configuration errors before production. By running these tests early in the CI/CD pipeline, you shift left defect detection, reduce the cost of fixes, and increase confidence that independently deployed services will interoperate correctly.

Why this answer

In a microservices architecture, automated integration tests are essential to validate that service-to-service interactions (e.g., API calls, event-driven communication) work correctly after changes. AWS CodePipeline can run these tests in a dedicated stage using AWS CodeBuild or third-party tools, catching integration failures before deployment to production.

Exam trap

The trap here is that candidates often confuse consistency (Option A) with the need for independent pipelines, or overestimate the value of manual approvals (Option C) in a CI/CD context, failing to recognize that microservices thrive on autonomy and automation.

957
MCQeasy

A DevOps team receives a CloudWatch alarm that an RDS DB instance's CPU utilization has exceeded 90% for 5 minutes. The application is experiencing latency. What is the best immediate step to mitigate the issue?

A.Analyze slow query logs and optimize queries.
B.Enable Multi-AZ deployment for failover.
C.Modify the RDS instance to a larger instance class.
D.Add a read replica to offload read traffic.
AnswerC

Modifying the RDS instance to a larger instance class is the correct immediate response because it directly adds vCPU, memory, and often dedicated EBS bandwidth to handle the current workload. Amazon RDS supports scaling instance classes with minimal downtime, especially for Multi-AZ deployments where a failover masks the restart. This scale-up action provides the compute headroom needed to bring CPU utilization back to acceptable levels and is the standard first step when a CPU alarm indicates that the instance is simply undersized for the traffic.

Why this answer

When an RDS instance's CPU utilization exceeds 90% for 5 minutes and the application is experiencing latency, the immediate step is to scale up the instance to a larger class to provide more CPU capacity. This directly addresses the resource bottleneck without requiring time-consuming analysis or architectural changes, making it the fastest mitigation for an ongoing incident.

Exam trap

The trap here is that candidates often confuse reactive scaling (immediate mitigation) with proactive optimization or architectural changes, leading them to choose slow query analysis or read replicas, which are valid but not immediate fixes for a CPU bottleneck.

How to eliminate wrong answers

Option A is wrong because analyzing slow query logs and optimizing queries is a long-term corrective action, not an immediate mitigation step during an active incident where latency is already occurring. Option B is wrong because enabling Multi-AZ deployment provides high availability and automatic failover, but does not increase CPU capacity or resolve performance issues caused by high utilization. Option D is wrong because adding a read replica offloads read traffic but does not reduce CPU utilization on the primary instance, which is the source of the latency.

958
MCQeasy

A company wants to protect its S3 bucket data from accidental deletion or overwrite. Which feature should be enabled?

A.Enable cross-region replication
B.Apply a bucket policy that denies DeleteObject
C.Enable S3 Versioning
D.Enable MFA Delete
AnswerC

Enabling S3 Versioning is the correct first-line protection because it retains every version of an object, including the original, whenever an overwrite (PUT) or delete (DELETE) occurs. With versioning, an overwritten object's previous version is preserved as a non-current version, and a DELETE action only inserts a deletemarker, leaving all prior versions intact. You can recover accidental changes by simply fetching a previous version, making it the foundational mechanism that enables other features like lifecycle rules, MFA Delete, and point-in-time restores.

Why this answer

S3 Versioning preserves every prior version of an object, so an accidental overwrite creates a new version while the original remains recoverable, and an accidental delete inserts a delete marker rather than removing data. This directly satisfies the requirement to protect against both accidental deletion and overwrite without blocking legitimate writes. Versioning is the foundational control that MFA Delete and replication build upon.

Exam trap

The trap is assuming MFA Delete or a deny-DeleteObject bucket policy is the primary protection — both are secondary controls that depend on versioning already being enabled.

How to eliminate wrong answers

Option A is wrong because cross-region replication copies objects to another bucket but does not protect against deletion or overwrite in the source bucket — a deleted source object can also be deleted at the destination depending on replication configuration. Option B is wrong because a bucket policy denying s3:DeleteObject blocks all deletions, including legitimate ones, and does nothing to prevent overwrites; it is a blunt instrument, not a protection mechanism. Option D is wrong because MFA Delete only adds an extra authentication requirement for permanently deleting versions or suspending versioning — it requires versioning to already be enabled and does not by itself preserve overwritten data.

959
MCQeasy

A DevOps team is using AWS CloudFormation to manage infrastructure. They need to ensure that stack updates are reviewed and approved by a senior engineer before being executed. Which feature should they implement?

A.Stack policies
B.Drift detection
C.Change sets
D.Stack sets
AnswerC

Change sets provide an itemized, read-only prediction of the exact modifications CloudFormation will apply to a stack when an updated template or parameter set is executed, listing each resource as being added, removed, or replaced without actually altering the stack. They are generated by calling CreateChangeSet, allowing the team to inspect the impact in a CI/CD pipeline and then explicitly execute the change set only after human approval. This makes change sets the correct mechanism for implementing a controlled pre-update review and approval workflow.

Why this answer

Change sets allow you to preview the proposed changes to a CloudFormation stack before executing them. This enables a senior engineer to review and approve the changes, ensuring that only validated updates are applied. Without change sets, updates would be applied immediately without a review step.

Exam trap

The trap here is that candidates may confuse change sets with stack policies, assuming both control updates, but stack policies only protect specific resources from modification, not the update approval process itself.

How to eliminate wrong answers

Option A is wrong because stack policies are used to prevent specific stack resources from being updated or deleted during a stack update, not to enforce a review-and-approval workflow. Option B is wrong because drift detection identifies whether a stack's actual resources have diverged from the template, but it does not control or review update execution. Option D is wrong because stack sets allow you to deploy stacks across multiple accounts and regions, but they do not provide a mechanism for reviewing and approving individual stack updates.

960
MCQeasy

A DevOps team is configuring CloudWatch alarms for their production environment. They want to receive notifications when the CPUUtilization metric of an EC2 instance exceeds 90% for three consecutive 5-minute periods. Which combination of settings should they use?

A.Period: 5 minutes; Evaluation periods: 3; Datapoints to alarm: 3
B.Period: 5 minutes; Evaluation periods: 3; Datapoints to alarm: 1
C.Period: 5 minutes; Evaluation periods: 1; Datapoints to alarm: 3
D.Period: 5 minutes; Evaluation periods: 5; Datapoints to alarm: 3
AnswerA

With a 5-minute period, 3 evaluation periods, and 3 datapoints to alarm, the alarm enters ALARM state only when every one of the three most recent 5-minute data points breaches the threshold. This means the metric must be continuously in breach for 15 minutes, filtering out transient spikes and providing a reliable signal of a sustained problem. It is the appropriate setting for production alarms that should page responders only after a consistent degradation.

Why this answer

To alarm when CPUUtilization exceeds 90% for three consecutive 5-minute periods, you need a period of 5 minutes, evaluation periods of 3, and datapoints to alarm of 3. This means CloudWatch evaluates the metric over three consecutive periods, and all three must breach the threshold to trigger the alarm. This configuration exactly matches the requirement.

Exam trap

The trap is confusing 'datapoints to alarm' with 'evaluation periods'; candidates may think that setting datapoints to 1 still requires three periods, but it actually triggers on the first breach.

How to eliminate wrong answers

Option B is wrong because with datapoints to alarm set to 1, the alarm would trigger if any single 5-minute period exceeds 90%, not requiring three consecutive periods. Option C is wrong because with evaluation periods of 1 and datapoints to alarm of 3, it is impossible to have 3 datapoints in 1 period; this configuration is invalid. Option D is wrong because with evaluation periods of 5 and datapoints to alarm of 3, the alarm would trigger if any 3 out of 5 periods breach, not necessarily consecutive, and it evaluates over 5 periods, which is not the requirement.

961
MCQmedium

A company uses AWS CodeDeploy for blue/green deployments to an Auto Scaling group. The deployment fails because the new instances do not pass health checks. The DevOps engineer discovers that the health check URL returns a 503 error. What is the MOST likely cause?

A.The target group health check path is '/health' but the application does not serve that endpoint
B.The CodeDeploy agent on the new instances is not running
C.The security group for the ALB does not allow inbound traffic on port 80
D.The Auto Scaling group health check type is set to EC2 instead of ELB
AnswerA

A 503 response from the ALB health check means the target instance accepted the TCP connection and returned an HTTP response, but the response status code was not a success (2xx/3xx). If the health check path is '/health' and the application does not define that route, the web server returns a 503 error because no handler matches the request. To resolve this, the health check path must be changed to an existing endpoint or the application must implement an endpoint that returns 200 OK on '/health'.

Why this answer

The health check URL returning a 503 error indicates that the application is not responding to the health check endpoint. Since the target group health check path is configured as '/health' but the application does not serve that endpoint, the ALB considers the instances unhealthy, causing CodeDeploy to fail the deployment. This is the most direct cause because the health check is failing at the application layer, not due to infrastructure issues.

Exam trap

The trap here is that candidates may confuse a 503 error with a network-level failure (like a security group blocking traffic) rather than recognizing it as an application-layer response indicating the health check endpoint is missing or misconfigured.

How to eliminate wrong answers

Option B is wrong because if the CodeDeploy agent were not running, the deployment would likely fail earlier (e.g., during the Install event) or the agent would not report success, but the health check failure (503) specifically indicates the application is running but not responding correctly. Option C is wrong because if the security group for the ALB did not allow inbound traffic on port 80, the health check would likely time out or return a connection refused error, not a 503 (Service Unavailable) which is an HTTP response from the application. Option D is wrong because the Auto Scaling group health check type (EC2 vs ELB) affects how ASG replaces unhealthy instances, but it does not directly cause the health check URL to return a 503; the 503 error is a symptom of the application not serving the correct endpoint.

962
MCQmedium

A company uses AWS Key Management Service (KMS) to encrypt data at rest in Amazon S3. The security team wants to ensure that only users with a specific attribute in their SAML assertion can decrypt the data. Which KMS key policy should be used?

A.Create an S3 bucket policy that denies kms:Decrypt unless the request includes a specific tag.
B.Modify the KMS key policy to include a condition that allows kms:Decrypt only if the SAML assertion contains the specific attribute.
C.Attach a resource-based policy to the S3 bucket that allows decryption only for users with the specific attribute.
D.Use an IAM policy that grants kms:Decrypt only if the user has the specific attribute.
AnswerB

KMS key policies are resource-based policies attached directly to the customer master key, and they are evaluated for every KMS API action against that key. The policy can include a Condition block that references SAML-derived session attributes, such as a session tag mapped from an attribute in the SAML assertion, to allow kms:Decrypt only when the expected attribute value is present. This is the correct approach because it centralizes the decryption restriction at the key resource itself, ensuring that any principal attempting to use the key must satisfy the condition regardless of their IAM permissions.

Why this answer

KMS key policies are resource-based policies that can use IAM condition keys. To enforce a requirement based on a SAML assertion, you must first configure the IAM role's trust policy to map the SAML attribute to a session tag using sts:TagSession. Then, the KMS key policy can include a condition such as aws:PrincipalTag/attribute_name to allow kms:Decrypt only when that session tag matches the expected value.

This ensures compliance at the key level, independent of S3 bucket policies. Note that saml:sub and other SAML condition keys are not supported in KMS key policies; they are only valid in IAM trust policies.

Exam trap

A common mistake is to think that S3 bucket policies can control KMS decryption or that KMS key policies can directly inspect SAML assertions. KMS key policies only see the principal (the IAM role or user) and its attributes/tags. To enforce a SAML attribute, you must first map it to a session tag in the role trust policy, then condition on that tag in the KMS key policy.

How to eliminate wrong answers

Option A is wrong because S3 bucket policies cannot deny `kms:Decrypt`; KMS API calls are governed by KMS key policies and IAM policies, not S3 resource policies. Option C is wrong because S3 bucket policies control access to S3 operations (e.g., `s3:GetObject`), not KMS decryption permissions; they cannot enforce conditions on the KMS `Decrypt` action itself. Option D is wrong because IAM policies alone cannot enforce conditions based on SAML assertion attributes unless those attributes are first mapped to IAM session tags or roles; the requirement is to control decryption at the KMS key level, and a KMS key policy with a SAML condition is the direct and correct mechanism.

963
Multi-Selecthard

Which THREE actions should a DevOps engineer take to ensure that AWS CloudFormation stacks are securely managed? (Choose three.)

Select 3 answers
A.Set a DeletionPolicy on the stack to retain resources when the stack is deleted.
B.Use a service role with least privilege when creating the stack.
C.Use IAM policies to restrict CloudFormation actions to specific users and roles.
D.Define a StackSetPolicy to control permissions across accounts.
E.Apply a stack policy to prevent updates to sensitive resources during stack updates.
AnswersB, C, E

A service role is an IAM role that CloudFormation assumes to make API calls on your behalf when creating, updating, or deleting stacks. By specifying a service role with least privilege, you ensure CloudFormation only has the permissions required to provision the intended resources, limiting the impact if a resource definition is malicious or misconfigured. This also enables separation of duties because users can create stacks without holding direct resource permissions, and all actions are attributed to the service role.

Why this answer

Using a service role with least privilege ensures that CloudFormation operates with only the permissions necessary to create, update, and delete resources, rather than inheriting the user's broader permissions. This decouples the user's IAM permissions from the stack's runtime actions, reducing the risk of privilege escalation and unintended resource modifications.

Exam trap

The trap here is that candidates confuse DeletionPolicy (a resource retention setting) with a security control, or they invent a 'StackSetPolicy' option that sounds plausible but does not exist in AWS, leading them to select incorrect answers that seem security-related but are technically invalid.

964
MCQmedium

A company uses AWS WAF to protect a web application behind an Application Load Balancer. The security team notices an increase in false positives blocking legitimate traffic. Which action should be taken to reduce false positives while maintaining security?

A.Remove the rate-based rule that is causing false positives.
B.Replace AWS WAF with AWS Shield Advanced.
C.Adjust the rate-based rule threshold to a higher value.
D.Change the rule action from 'Block' to 'Count'.
AnswerC

Increasing the rate-based rule's threshold is the appropriate response because the rule currently flags legitimate traffic when it should only block genuinely anomalous request floods. AWS WAF rate-based rules count requests that match a rule's conditions from a single source IP over a 1- or 5-minute evaluation window; if your legitimate users share an office IP or traverse a NAT gateway, their aggregate requests can exceed a threshold set too close to peak traffic. By raising the threshold above your historical maximum legitimate request volume per IP, you preserve protection against distributed or bot-driven floods while eliminating false positives from normal usage spikes.

Why this answer

Adjusting the rate-based rule threshold to a higher value allows more legitimate traffic while still blocking excessive requests. Option A: Removing the rule would weaken security. Option B: AWS Shield Advanced is a DDoS protection service, not a replacement for fine-tuning WAF rules.

Option D: Changing action to 'Count' logs requests but does not block them, reducing security.

Exam trap

Candidates often think that changing rule action to 'Count' is a good compromise, but it only logs and does not block, thus reducing security. The correct approach is to adjust the threshold.

965
MCQmedium

A company runs a critical web application on EC2 instances behind an Application Load Balancer (ALB) with Auto Scaling. Users report intermittent 503 errors. CloudWatch metrics show that the ALB's 'RequestCount' is normal, but 'HTTPCode_ELB_5XX_Count' spikes. The 'TargetResponseTime' metric shows occasional high latency. Which troubleshooting step should the DevOps engineer take FIRST?

A.Enable and analyze the ALB access logs stored in S3, filtering for 503 errors and correlating with target response times.
B.Increase the desired capacity of the Auto Scaling group to handle more requests.
C.Disable connection draining on the target group to prevent slow-draining instances from causing errors.
D.Review AWS CloudTrail logs for any recent configuration changes to the ALB.
AnswerA

ALB access logs record per-request target status, target IP and timing, so filtering 503s reveals whether targets returned errors or the load balancer itself failed. This directly correlates the ELB 5XX spike with backend latency, satisfying the stem's need to identify the failing tier first.

Why this answer

ALB access logs capture detailed per-request information including target IP, response time, and the specific error (e.g., 503 due to target connection errors or target timeouts). Analyzing these logs filtered for 503s and correlated with TargetResponseTime reveals whether the errors originate from unhealthy targets, connection limits, or slow responses, making it the correct first diagnostic step.

Exam trap

DOP-C02 often tests whether candidates jump to scaling or configuration changes instead of first using observability data (ALB access logs, CloudWatch metrics) to isolate whether errors originate from the ALB or the targets.

How to eliminate wrong answers

Option B is wrong because increasing Auto Scaling capacity does not address the root cause; if targets are slow or unhealthy, more instances may not help and could mask the issue. Option C is wrong because disabling connection draining would cause in-flight requests to be dropped during scale-in or deployment, likely increasing errors rather than reducing them. Option D is wrong because CloudTrail records API-level configuration changes, not per-request error details; it would not explain intermittent 503s tied to target response times.

966
Matchingmedium

Match each AWS CloudFormation concept to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Collection of AWS resources managed as a single unit

JSON or YAML document describing AWS resources

Preview of changes before applying to a stack

Enables stack creation across multiple accounts and regions

Identifies differences between stack and actual resource configurations

Why these pairings

Change Set previews stack changes; Stack is a resource collection; Stack Set manages stacks across accounts; Template is a JSON/YAML description.

967
MCQhard

Which AWS service is a fully managed source control service?

A.AWS CodeCommit
B.AWS CodeBuild
C.AWS CodeDeploy
D.AWS CodePipeline
E.AWS CloudFormation
F.Amazon EventBridge
AnswerA

AWS CodeCommit is a fully managed source-control service that hosts private Git repositories, supporting branches, commits, pull requests, and merge operations with IAM-based access control. It matches the description of a source-control service because it is the central repository where developers store, version, and collaborate on code. Its native Git compatibility and tight AWS integration enable seamless use with other DevOps services, but its core identity is version control, not building or deploying.

Why this answer

AWS CodeCommit is a fully managed source control service that hosts private Git repositories, providing version control without managing servers. It integrates with IAM for access control and other AWS developer tools. The other services in the list serve different CI/CD pipeline stages.

Exam trap

DOP-C02 often tests the CI/CD service lineup, tricking candidates into confusing CodeCommit (source), CodeBuild (build), CodeDeploy (deploy), and CodePipeline (orchestration) by their similar naming.

How to eliminate wrong answers

Option B is wrong because AWS CodeBuild is a fully managed build service that compiles code and runs tests, not a source control system. Option C is wrong because AWS CodeDeploy automates application deployments to EC2, Lambda, or on-premises instances, not source control. Option D is wrong because AWS CodePipeline orchestrates CI/CD workflows across stages, not a repository.

Option E is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not source control. Option F is wrong because Amazon EventBridge is a serverless event bus for routing events between services, not a source control service.

968
MCQeasy

A company uses Amazon Route 53 to route traffic to an Application Load Balancer. They want to improve availability by routing traffic to multiple ALBs in different AWS Regions. Which routing policy should they use?

A.Latency-based routing policy
B.Weighted routing policy
C.Geolocation routing policy
D.Simple routing policy
AnswerA

Latency-based routing policy uses AWS-measured round-trip time data to direct each user to the endpoint that offers the fastest response, and it supports health checks on each record. When the primary endpoint fails its health check, Route 53 automatically selects the next lowest-latency healthy endpoint, providing seamless active-passive failover without manual intervention. This combination of performance optimization and health-aware failover makes it the correct choice for an application with multiple regional endpoints.

Why this answer

Latency-based routing policy uses AWS-measured round-trip time data to direct each user to the AWS Region offering the fastest response, and each record can have an associated Route 53 health check; when the primary region's endpoint fails its health check, Route 53 automatically routes to the next lowest-latency healthy region. This combination of performance optimization and health-aware failover, without manual intervention, makes it the best fit for improving availability and performance across multiple regional ALBs. (Note: weighted routing policy also supports per-record health checks and will automatically exclude an unhealthy endpoint from rotation, redistributing traffic among the remaining healthy weighted records -- it is not correct that weighted routing requires manual updates to fail over.)

Exam trap

The trap here is that candidates often confuse latency-based routing with geolocation routing, mistakenly thinking that geographic proximity equals low latency, but latency-based routing uses actual network measurements rather than fixed geographic boundaries.

How to eliminate wrong answers

Option B (Weighted routing policy) is wrong because it distributes traffic based on assigned weights (e.g., 80% to one region, 20% to another) and does not consider real-time latency or availability; it is designed for load balancing or testing, not for optimizing user-perceived performance across regions. Option C (Geolocation routing policy) is wrong because it routes traffic based on the geographic location of the user (e.g., country or continent), not on actual network latency or regional health; it can cause traffic to be sent to a distant region if the user's location is mapped there, even if that region is degraded. Option D (Simple routing policy) is wrong because it only supports a single record with multiple values (e.g., multiple IPs) and returns all values in a random order without any health checking or latency awareness, making it unsuitable for active-active multi-region failover.

969
Multi-Selecteasy

A DevOps engineer is tasked with auditing all AWS API calls made in the account for compliance purposes. The engineer needs to ensure that the audit logs are tamper-proof and stored cost-effectively. Which TWO services should the engineer use?

Select 2 answers
A.AWS Config
B.AWS CloudTrail
C.Amazon S3 with Object Lock enabled
D.Amazon CloudWatch Logs
E.AWS KMS
AnswersB, C

AWS CloudTrail is the principal service that logs all management, data, and insight API calls across an AWS account, capturing identity, request context, and response details. It is correct for this scenario because you need API-call logging, but to make the resulting log files truly tamper-proof you must configure CloudTrail to deliver them to an S3 bucket with Object Lock enabled. CloudTrail also supports log file integrity validation, yet that only detects tampering, whereas Object Lock prevents it.

Why this answer

AWS CloudTrail (B) is correct because it is the service that records all AWS API activity in an account as event logs, which is exactly what is needed to audit API calls for compliance. Amazon S3 with Object Lock enabled (C) is correct because CloudTrail delivers its logs to an S3 bucket, and S3 Object Lock provides WORM (write-once-read-many) protection so the logs cannot be altered or deleted, while S3 storage classes keep the cost low for long-term retention. AWS Config (A) is not correct because it records resource configuration changes and compliance state, not the full set of API calls.

Amazon CloudWatch Logs (D) is not correct because it is a log storage and monitoring service, not the API audit trail itself, and it lacks the immutable WORM guarantee. AWS KMS (E) is not correct because it provides encryption key management, which supports security but does not by itself create tamper-proof, cost-effective audit logs.

Exam trap

DOP-C02 often tests the distinction between CloudTrail (audit trail) and Config (configuration compliance), and between CloudWatch Logs (aggregation) and S3 Object Lock (immutability), tricking candidates into picking Config or CloudWatch for tamper-proof audit storage.

970
Multi-Selecthard

A company is designing a secure CI/CD pipeline using AWS CodePipeline, CodeBuild, and CodeDeploy. The pipeline must deploy to an EC2 Auto Scaling group across multiple AWS accounts. The security requirements include: (1) no hardcoded credentials, (2) least privilege for cross-account access, (3) encrypted artifacts. Which THREE steps should the DevOps engineer implement? (Choose THREE.)

Select 3 answers
A.Use a customer-managed KMS key with a cross-account key policy to encrypt artifacts.
B.Store database credentials in AWS Secrets Manager and retrieve them in CodeBuild using the secrets manager action.
C.Store database credentials in AWS Systems Manager Parameter Store and retrieve them in CodeBuild.
D.Use AWS CodeCommit as the source repository with pull request approval rules.
E.Configure CodePipeline to assume an IAM role in the target account using a trust policy.
AnswersA, B, E

Using a customer-managed KMS key with a cross-account key policy is correct because CodePipeline stores build artifacts in S3, which must be encrypted. By default, AWS-managed keys are scoped to a single account, so to share artifacts with a target account you must use a customer-managed key and explicitly grant the target account's principals decrypt permission via a cross-account key policy. This provides secure, auditable cross-account artifact transfer without exposing the key material, and it lets you enforce encryption at rest with full control over key rotation and access.

Why this answer

Using a customer-managed KMS key with a cross-account key policy allows encrypting artifacts in CodePipeline's artifact store, ensuring that only authorized accounts can decrypt them, meeting the requirement for encrypted artifacts and least privilege. Option B is correct because storing database credentials in AWS Secrets Manager and retrieving them in CodeBuild using the secrets manager action avoids hardcoded credentials and provides secure, rotating credentials. Option E is correct because configuring CodePipeline to assume an IAM role in the target account using a trust policy enables cross-account deployment with least privilege, as the pipeline assumes a role with only necessary permissions.

Option C is incorrect because while SSM Parameter Store can store credentials, Secrets Manager is specifically designed for secrets management with automatic rotation and is more appropriate for database credentials. Option D is incorrect because CodeCommit with pull request approval rules is a source control practice, not directly addressing the security requirements of no hardcoded credentials, least privilege cross-account access, or encrypted artifacts.

971
Multi-Selecthard

A company uses DynamoDB global tables for a multi-region application. They notice that write conflicts are occurring. Which TWO strategies can reduce write conflicts?

Select 2 answers
A.Reduce read capacity units to limit concurrent reads
B.Enable DynamoDB Streams with last writer wins
C.Use conditional writes in the application code
D.Increase write capacity units on the table
E.Implement application-level conflict resolution
AnswersC, E

Conditional writes enable optimistic concurrency by allowing the application to assert a precondition—such as an item version or updated timestamp—before the write commits. If the condition evaluates to false because another concurrent write modified the item, DynamoDB rejects the request without overwriting, forcing the application to re-read and retry. This prevents silent data loss from last-writer-wins and is the appropriate DynamoDB-native way to enforce a safe update workflow in a multi-region setup.

Why this answer

Conditional writes prevent overwriting data unless a specified condition is met, thereby reducing write conflicts by ensuring that updates are only applied when the data is in a known state. Application-level conflict resolution allows the application to handle conflicts when they occur, using custom logic to merge or resolve differences, which reduces the impact of conflicts on the database. Option D (increasing write capacity) does not reduce conflicts; it only increases throughput capacity.

Option A (reducing read capacity) is unrelated to write conflicts. Option B (DynamoDB Streams with last writer wins) is the default behavior and does not reduce conflicts; it may cause data loss.

972
MCQmedium

A DevOps team is designing a CI/CD pipeline for a microservices application. Each microservice has its own CodeCommit repository and must be built and deployed independently. The team wants to minimize manual configuration and ensure that adding a new microservice automatically creates the corresponding pipeline stages. Which approach should the team use?

A.Create a separate AWS CodePipeline for each microservice manually using the AWS Management Console.
B.Use the AWS Cloud Development Kit (CDK) to define a pipeline that dynamically discovers repositories.
C.Use a single AWS CodePipeline with multiple stages, each triggered by a different branch of the same repository.
D.Define a CloudFormation template that creates a pipeline for a given repository and invoke it automatically when a new repository is created using EventBridge and Lambda.
AnswerD

The correct approach uses a parameterized AWS CloudFormation template that defines a complete CodePipeline (source, build, deploy) for a given repository, and combines it with an EventBridge rule that detects the `CreateRepository` API call from CodeCommit (via CloudTrail) and triggers a Lambda function. That Lambda function validates the input and invokes `CreateStack` (or `UpdateStack`) with the repository name as a parameter, automatically provisioning a dedicated pipeline for each new microservice as soon as the repo is created. This delivers event-driven, infrastructure-as-code automation, ensuring every pipeline is identical, versioned, and created without human interaction, thereby meeting the scalability and consistency goals of the team.

Why this answer

It uses an event-driven approach: EventBridge detects the creation of a new CodeCommit repository, triggers a Lambda function that invokes a CloudFormation template to create a corresponding CodePipeline. This fully automates pipeline provisioning for new microservices without manual intervention, aligning with the requirement to minimize manual configuration.

Exam trap

The trap here is that candidates may choose Option B (CDK) thinking it provides dynamic discovery, but CDK is a compile-time tool that cannot react to runtime events like repository creation, whereas EventBridge and Lambda provide true event-driven automation.

How to eliminate wrong answers

Option A is wrong because manually creating a separate CodePipeline for each microservice via the console violates the requirement to minimize manual configuration and does not scale. Option B is wrong because the AWS CDK cannot dynamically discover repositories at runtime; it requires explicit repository references in the code and does not automatically react to new repository creation events. Option C is wrong because using a single pipeline with multiple stages triggered by different branches of the same repository assumes all microservices share a single repository, contradicting the requirement that each microservice has its own CodeCommit repository and must be built and deployed independently.

973
MCQhard

A company runs a microservices architecture on Amazon ECS with Fargate. The operations team wants to collect custom application metrics (e.g., request latency per service) and visualize them in CloudWatch dashboards. The team also needs to set CloudWatch alarms based on these metrics. Which solution requires the LEAST amount of code changes and operational overhead?

A.Use the CloudWatch Embedded Metric Format to emit custom metrics as JSON log entries.
B.Deploy a StatsD daemon as a sidecar container and configure the application to send metrics to StatsD, then forward to CloudWatch.
C.Modify the application code to use the AWS SDK to call PutMetricData API directly.
D.Install the CloudWatch Agent on each Fargate task as a sidecar container to collect custom metrics.
AnswerA

The CloudWatch Embedded Metric Format encodes custom metric values inside a structured JSON log event; when the Fargate task's awslogs driver sends that log to CloudWatch Logs, CloudWatch automatically extracts the declared metrics into the specified namespace for graphing and alarms. This requires no separate daemon, sidecar, or SDK call—developers only add a serialization layer to application logging, making it the minimal-code path you asked for.

Why this answer

The CloudWatch Embedded Metric Format allows applications to emit metrics as structured JSON logs, which CloudWatch automatically extracts into metrics and logs. This requires minimal code changes (just log format). Option B is wrong because publishing to CloudWatch via PutMetricData requires the AWS SDK and more code changes.

Option C is wrong because CloudWatch Agent on Fargate is not supported (requires EC2). Option D is wrong because using a sidecar container for StatsD adds complexity and overhead.

974
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. The user requests an object from the 'example-bucket' bucket, specifically from the 'confidential' folder, over HTTP (not HTTPS). The source IP is within the 10.0.0.0/24 range. What will be the result of this request?

A.Denied, because the user does not have s3:GetObject permission on the confidential folder.
B.Allowed, because the Deny statement only applies to HTTPS.
C.Allowed, because the source IP is within the allowed range.
D.Denied, because the request uses HTTP and the Deny statement blocks it.
AnswerD

This is correct because an HTTP request sets the aws:SecureTransport context key to false, and the Deny statement is scoped to exactly that condition. The policy likely contains an Allow for the S3 action on the folder, but the explicit Deny for non-secure transport takes precedence under AWS's evaluation logic. As a result, the user's GET request over HTTP is denied, while the same request sent over HTTPS would be allowed if the other permissions match.

Why this answer

The IAM policy includes a Deny statement that blocks s3:GetObject when the request is not over HTTPS (aws:SecureTransport is false). Since the request uses HTTP, the condition evaluates to true and the explicit Deny overrides any Allow. Therefore the request is denied regardless of the source IP being in the allowed range.

Exam trap

DOP-C02 often tests the misconception that an Allow with matching IP or resource conditions can override an explicit Deny, when in fact explicit Deny always wins — candidates must remember the evaluation order.

How to eliminate wrong answers

Option A is wrong because the user does have s3:GetObject permission on the confidential folder via an Allow statement — the denial is due to the transport condition, not missing permissions. Option B is wrong because the Deny statement applies to non-HTTPS (HTTP) requests, not HTTPS; the condition aws:SecureTransport: false matches HTTP, so the Deny blocks HTTP, not HTTPS. Option C is wrong because while the source IP is within the allowed range, the explicit Deny for non-secure transport takes precedence over any Allow, so the IP condition does not save the request.

975
MCQhard

A company runs a critical application on Amazon ECS with Fargate. The application is deployed across multiple Availability Zones and uses an Application Load Balancer (ALB) as the front-end. During a recent incident, users experienced intermittent connectivity failures. The DevOps team suspects that tasks are being stopped due to resource exhaustion. Which combination of metrics and actions should the team use to diagnose and prevent recurrence?

A.Monitor CPU and memory utilization metrics in CloudWatch; increase the task size (CPU and memory) in the task definition.
B.Set up CloudWatch Logs for the application and check for out-of-memory errors; then increase the number of tasks.
C.Monitor NetworkPacketsIn and NetworkPacketsOut metrics in CloudWatch; increase the number of tasks.
D.Monitor the ALB error metrics (5xx count) and scale the ECS service based on request count.
AnswerA

Fargate task-level CPU and memory metrics in CloudWatch reveal resource exhaustion causing task stops; raising the task definition's CPU and memory values gives tasks sufficient headroom, directly addressing the suspected exhaustion constraint and preventing recurrence.

Why this answer

CPU and memory utilization metrics in CloudWatch directly indicate resource exhaustion, which is the suspected cause of tasks being stopped. Increasing the task size (CPU and memory) in the task definition provides more resources per task, preventing the OOM killer or CPU throttling from stopping tasks, without changing the number of tasks or scaling logic.

Exam trap

The trap here is that candidates confuse horizontal scaling (increasing task count) with vertical scaling (increasing task size), assuming that adding more tasks resolves resource exhaustion when the actual issue is insufficient resources per task.

How to eliminate wrong answers

Option B is wrong because while CloudWatch Logs can show out-of-memory errors, increasing the number of tasks does not address resource exhaustion per task—it only distributes load across more tasks, which may still fail if each task is under-provisioned. Option C is wrong because NetworkPacketsIn and NetworkPacketsOut measure network throughput, not CPU or memory exhaustion; high network metrics do not cause tasks to be stopped due to resource exhaustion. Option D is wrong because ALB 5xx errors and request count scaling address load balancing and traffic spikes, not the root cause of tasks being stopped due to insufficient CPU or memory per task.

Page 12

Page 13 of 18

Page 14